FAQEU

EU AI Act FRIA FAQ

Article 27 does not make every high-risk AI deployer run a FRIA. It targets specified deployers before the first use of Article 6(2) Annex III high-risk systems, with the Annex III point 2 critical-infrastructure area carved out.

This page helps check the trigger, covered deployer types, assessment contents, DPIA link, notification step, update triggers, and evidence records.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

A is the EU AI Act Article 27 fundamental rights impact assessment for certain uses of high-risk AI systems. Apply three checks: whether the system is an Article 6(2) Annex III high-risk system, whether the Annex III critical-infrastructure carve-out applies, and whether the deployer is one of the categories named in Article 27. Regulation (EU) 2026/1744, published on 24 July 2026 and entering into force on 27 July 2026, moves the applicable Chapter III duties for Annex III systems to 2 December 2027.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

When does Article 27 require a FRIA?

Article 27 requires the assessment before deployment of a high-risk AI system referred to in Article 6(2), which points to the Annex III high-risk areas. The rule expressly excludes high-risk AI systems intended to be used in the area listed in point 2 of Annex III, the critical-infrastructure area.

The trigger then depends on the deployer. A is required for deployers that are bodies governed by public law, private entities providing public services, and deployers of high-risk systems in Annex III points 5(b) and 5(c), which cover creditworthiness or credit scoring and risk assessment or pricing for life and health insurance.

The duty applies to the first use. A deployer may rely on a previous or an existing provider assessment in a similar case, but it remains responsible for checking that the system, process, affected groups, risks, oversight, and mitigations match its own deployment. If a required element changes or becomes outdated during use, the deployer must update the information.

  • Start with Article 6(2): confirm that the system is an Annex III high-risk AI system.
  • Check the carve-out: Annex III point 2 critical-infrastructure systems are excluded from Article 27 , even though they may still be high-risk and are registered at national level under Article 49(5).
  • Check the deployer category: public-law bodies, private entities providing public services, and deployers using Annex III point 5(b) or 5(c) systems are the Article 27 categories.
  • Do not treat a provider's high-risk classification memo as a ; Article 27 is a deployer-side assessment of the specific use.
  • After completing the , notify the of the results by submitting the completed Article 27 template, unless the Article 46(1) exemption from notification applies.

Does every EU AI Act high-risk system need a ?

No. Article 27 applies to specified deployers before deploying Article 6(2) Annex III high-risk systems, with an express exception for the Annex III point 2 critical-infrastructure area. Product-safety high-risk systems classified under Article 6(1), and Annex III systems outside the named deployer categories, should still be assessed for other AI Act duties, but Article 27 is not automatically triggered by the high-risk label alone.

Which deployers are named in Article 27?

Article 27 names deployers that are bodies governed by public law, private entities providing public services, and deployers of high-risk systems referred to in Annex III points 5(b) and 5(c). Recital 96 explains that private public-service examples can be linked to public-interest tasks such as education, healthcare, social services, housing, and administration of justice.

What happens to critical-infrastructure AI systems under Annex III point 2?

Article 27 excludes high-risk AI systems intended for the Annex III point 2 critical-infrastructure area from the duty. That does not remove all AI Act obligations: Annex III point 2 covers safety components in critical digital infrastructure, road traffic, and water, gas, heating, or electricity supply, and Article 49(5) says those high-risk systems are registered at national level.

When does the EU AI Act duty start to apply?

Regulation (EU) 2026/1744, published on 24 July 2026 and entering into force on 27 July 2026, moves Chapter III Sections 1 to 3 to 2 December 2027 for Article 6(2) Annex III high-risk systems. Because Article 27 covers specified Annex III deployments, that is the relevant application date. Public-authority systems already on the market or in service have a separate Article 111 deadline of 2 August 2030, while other legacy systems depend on whether their design changes significantly after the applicable date.

Citations
Question 2

What must the FRIA contain?

Article 27 gives a concrete assessment list. The record should describe the deployer's process in which the high-risk AI system will be used, the intended period and frequency of use, the categories of natural persons and groups likely to be affected, and the specific risks of harm for those groups.

The also needs the human oversight implementation described according to the instructions for use, plus the measures to take if the risks materialise. Those measures include internal governance and complaint mechanisms, so the evidence should reach beyond legal sign-off into operating procedures.

  • Process evidence: workflow map, intended purpose, provider instructions for use, and the deployer's use case.
  • Use evidence: expected start, duration or period of use, frequency, countries or operating units, and whether this is a first use or a similar case relying on an earlier assessment.
  • Affected-person evidence: natural-person categories, affected groups, dependency or vulnerability factors, and the decision or service the AI output influences.
  • Risk evidence: specific fundamental-rights harms, provider Article 13 information considered, residual risks, and escalation criteria.
  • Control evidence: human oversight procedure, complaint route, internal governance owner, operational playbook for risk materialisation, and approval record.

Can a deployer reuse an earlier ?

Yes, but only in similar cases. Article 27 says the obligation applies to the first use of the high-risk AI system and that a deployer may rely on previous FRIAs or existing impact assessments in similar cases. The record should explain why the earlier assessment is similar enough for the current process, affected groups, risks, oversight, and complaint arrangements.

When must the be updated?

Article 27 requires an update when, during use, the deployer considers that any assessment element has changed or is no longer up to date. Practical update triggers include a changed deployment process, materially different use frequency, a new affected group, changed provider instructions, new risk evidence, or changed oversight, governance, or complaint mechanisms.

What practical proof should an Article 27 file contain?

Keep the classification decision, the deployer-category check, the Annex III point check, provider instructions used for the risk analysis, the Article 27 assessment answers, evidence of human oversight and complaint routing, the market-surveillance notification record, and, where applicable, the link and EU database or national registration evidence.

Citations
Question 3

How does FRIA connect to DPIA, notification, and registration?

A does not replace a GDPR or law-enforcement data protection impact assessment. From 27 July 2026, amended Article 27(4) lets a deployer cross-reference the relevant parts of a under GDPR Article 35 or Directive (EU) 2016/680 Article 27, or include those parts in the FRIA, when they already meet an Article 27 obligation. The deployer must still complete every Article 27 element that the DPIA does not cover.

After performing the , the deployer must notify the of the results by submitting the filled-out template referred to in Article 27. Separately, Article 49 requires public authorities, Union bodies, agencies, offices, or persons acting on their behalf to register their use of Annex III high-risk systems in the EU database, except Annex III point 2 systems, which are registered nationally.

  • Map the and where personal-data risk and fundamental-rights risk overlap. Cross-reference or include the DPIA sections that meet Article 27 elements, then complete the remaining FRIA fields.
  • Keep the market-surveillance authority notification proof with the completed Article 27 template once the is performed.
  • For public-authority deployers, confirm Article 49 registration before putting the Annex III high-risk system into service or use.
  • For law enforcement, migration, asylum, and border-control Annex III systems, expect restricted EU database registration rules under Article 49(4).
  • For Annex III point 2 critical-infrastructure systems, route registration evidence to the national-level process described in Article 49(5).

Does completing a satisfy Article 27?

Not by itself. Under Article 27(4), as replaced by Regulation (EU) 2026/1744 from 27 July 2026, the deployer may cross-reference relevant sections or include them in the when they already meet an Article 27 obligation. The deployer must still add any missing process, affected-group, fundamental-rights risk, human-oversight, governance, complaint, notification, and AI Act registration evidence.

Who receives the results?

Article 27 says the deployer must notify the of the results after the assessment is performed, using the filled-out template referred to in Article 27. The page should not assume a single authority name for every Member State; route the notification to the applicable market surveillance authority once identified for the deployment.

What should a reviewer check before approving first use?

Check that the system is an Article 6(2) Annex III high-risk system, the Annex III point 2 exclusion has been considered, the deployer category is documented, the Article 27 assessment fields are complete, the relationship is mapped where applicable, notification evidence is ready, and Article 49 registration evidence is present where the deployer is a public authority or acting on one.

Citations
Recommended next step

This EU AI Act FRIA FAQ is a cited implementation checklist

Sorena can help map Article 27 scope, DPIA overlap, authority notification, registration evidence, and update triggers into reusable review steps for high-risk AI deployments.

Primary sources

References and citations

ai-act-service-desk.ec.europa.eu
Referenced sections
  • Commission-hosted AI Act Explorer page for Article 27 used to cross-check the FRIA article citation and official article title.
"Article 27: Fundamental rights impact assessment for high-risk AI systems"
eur-lex.europa.eu
Referenced sections
  • Supports the required FRIA contents, the provider information needed to assess deployer-side risk, and the FRIA and DPIA summary fields required for applicable deployer registration.
"a description of the deployer’s processes"
eur-lex.europa.eu
Referenced sections
  • Supports the Article 27 trigger, covered deployer categories, critical-infrastructure carve-out, first-use rule, notification duty, DPIA complement rule, FRIA content list, and the related deployer registration requirements.
"Fundamental rights impact assessment for high-risk AI systems"
eur-lex.europa.eu
Referenced sections
  • Supports the FRIA notification, first-use, update, and DPIA complement rules; the registration obligations; and the distinction between product-safety and Annex III high-risk systems.
"the deployer shall notify the market surveillance authority of its results"
eur-lex.europa.eu
Referenced sections
  • Binding amendment published on 24 July 2026, entering into force on 27 July 2026, which replaces Article 27(4) and (5), permits DPIA cross-references or incorporation, and moves the Annex III Chapter III duties to 2 December 2027.
"include cross-references to the relevant sections"
Related guides

Explore more topics

Are industry AI use cases high-risk under EU AI Act Annex III?
FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
EU AI Act AI System Classification Edge Cases FAQ
Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence
Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
EU AI Act applicability test: scope, role, and risk classification
Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
EU AI Act Article 5 Prohibited AI Practices Screening Guide
Screen AI systems against EU AI Act Article 5, including manipulation, social scoring, biometrics, law enforcement, and the new prohibited-content category.
EU AI Act Article 50 transparency disclosures FAQ
Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
EU AI Act Article 50 transparency, labeling, and user disclosures
Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
EU AI Act Article 73 serious incident FAQ
FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
EU AI Act Compliance Checklist by Risk Class
A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents
Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
EU AI Act conformity assessment and notified bodies for high-risk AI
Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
EU AI Act deadlines and compliance calendar | Article 113 dates
EU AI Act compliance calendar for Regulation (EU) 2026/1744, Article 113 dates, Article 111 transitions, GPAI enforcement, Article 50, and high-risk systems.
EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates
Source-backed EU AI Act FAQ covering scope, roles, risk classification, GPAI, transparency, AI literacy, rights and complaints, sandboxes, authorities, SME provisions, and current legal status.
EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence
Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ
FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
EU AI Act GPAI evidence pack checklist for Article 53 and 55
Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
EU AI Act GPAI Provider Obligations: Articles 53 and 55
Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
EU AI Act High-Risk AI Requirements: Articles 8-16 and 26
Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide
Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
EU AI Act high-risk conformity assessment route selector
Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
EU AI Act high-risk requirements checklist: Articles 8-15
Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
EU AI Act penalties and fines: Article 99 tiers and GPAI exposure
EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
EU AI Act post-market monitoring and serious incident reporting
Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
EU AI Act post-market monitoring FAQ for high-risk AI systems
Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ
FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
EU AI Act risk classification intake workflow
A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
EU AI Act serious incident reporting triage workflow: Article 73 and Article 55
Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
EU AI Act Technical Documentation and Provider Evidence Templates
Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
EU AI Act technical documentation FAQ | Article 11 and Annex IV
What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
EU AI Act Timeline Roadmap: Dates, Legal Status, Owners, and Evidence
Turn EU AI Act milestones into an implementation roadmap by separating enacted dates, political agreements, draft guidance, consultations, and voluntary codes, then assigning actions and evidence.
EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits
Compare the EU AI Act and ISO/IEC 42001:2023, including legal status, Article 17 quality management, high-risk duties, GPAI, evidence reuse, and assurance limits.
EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries
Compare the EU AI Act with NIST AI RMF 1.0 across legal status, GOVERN-MAP-MEASURE-MANAGE, high-risk duties, GPAI, evidence reuse, and revision limits.
FAQ: EU AI Act conformity assessment procedures and notified body selection
cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.