← All guides

Deployers

The fundamental-rights impact assessment (Article 27)

Some deployers of high-risk systems must assess the impact on fundamental rights before deployment. Who is caught, and what the assessment must contain.

Updated 3 July 2026 · Reference material, not legal advice


Beyond the provider’s obligations, certain deployers of high-risk systems must complete a fundamental-rights impact assessment (FRIA) before putting the system to use. It is one of the more demanding deployer duties, and it is easy to miss.

Who must do it

Under Article 27, before deploying an Annex III high-risk system (except critical-infrastructure systems, point 2), the following must carry out a FRIA:

  • bodies governed by public law;
  • private entities providing public services; and
  • deployers of the creditworthiness / credit-scoring and life and health insurance systems (Annex III, points 5(b) and (c)).

What it must contain

The assessment sets out:

  1. the deployer’s processes in which the system will be used;
  2. the period and frequency of intended use;
  3. the categories of people and groups likely to be affected;
  4. the specific risks of harm to those groups, drawing on the provider’s information;
  5. the human-oversight measures to be applied;
  6. the measures if risks materialise, including internal governance and complaint mechanisms.

How it works in practice

The FRIA applies to the first use; for similar cases the deployer may rely on a previous assessment, updating it when circumstances change. The result is notified to the market-surveillance authority, using a template the AI Office provides (including an automated tool). Where a data-protection impact assessment already exists under the GDPR, the FRIA complements it rather than repeating it.

Why it matters

The FRIA is where the deployer confronts, in writing, who could be harmed and how — before anything goes live. Done well, it is a genuine governance artefact; done as an afterthought, it is a liability.

What this means in practice

Euridium surfaces the FRIA as a scoped obligation for the deployers who owe it, with the six required elements as a structured, evidenced workflow rather than a blank document.

See where your own AI systems stand.

Run a guided assessment and get the obligations that apply to your role.

Open the platform

This guide is a plain-language summary for orientation. The authoritative text is Regulation (EU) 2024/1689 as published in the Official Journal of the European Union (12 July 2024). It does not constitute legal advice.