EU AI Act Art. 27: Fundamental Rights Impact Assessment (FRIA)
Fundamental Rights Impact Assessment (FRIA) for deployers of Annex III systems
AIGE-OBL-EUAIA-ART27. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 27.
- Duty holder: Deployer.
- Applies from: 2027-12-02, Deferred.
- Artefact: FRIA-as-code from a template.
- Layers: Layer 01, Layer 02.
- Evidence record: Impact assessment, +2 more.
- Record schemas: Impact assessment , Deployment decision record , Use-case record .
- The same topic in 12 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART27- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 27
- Duty holder
- Deployer
- Authority
- National MSA
- Applies from
- Deferred · Annex III
- Later dates
-
- Deadline for legacy high-risk systems intended for use by public authorities (Art. 111(2))
- System class
- High-risk (Annex III)
The artefact that evidences it
FRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA.
Patterns that build it
- FRIA-as-Code (layer 1 and 2)
- Vendor / Model Due-Diligence Gate (layer 2 and 5)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Impact assessment
- ISO 42001 6.1.4 AI system impact assessment (core)
- ISO 42001 8.4 AI system impact assessment (operation) (core)
- ISO 42001 A.5 Assessing impacts of AI systems (core)
- NIST AI RMF MAP 3 MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs are understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- TC260 Framework 3.0 TC260 Appendix 1 Grading principles (core)
- China GenAI Measures GenAI Art. 17 Security assessment (core)
- GDPR Art. 35 Data protection impact assessment (core)
- ISO 42005 42005 5.8 Performing the AI system impact assessment (core) (clause not verified)
- ISO 42005 42005 6.8 Actual and reasonably foreseeable impacts (core) (clause not verified)
- CSA AICM GRC-10 AI Impact Assessment (core)
- Korea AI Act Art. 35 Impact assessment (best-effort duty) (core)
- UK ATRS ATRS 2.5.1 Impact assessments (core)
- EU AI Act Art. 9 Risk management system
- TC260 Framework 3.0 TC260 2.2 Safety risks in the application of AI
- GDPR Art. 36 Prior consultation
- ISO 42005 42005 5.12 Monitoring and review (clause not verified)
- CSA AICM DSP-09 Data Protection Impact Assessment
- CoE Convention CoE Art. 16 Risk and impact management framework
- GAO AI Accountability 1.5 Stakeholder involvement: include diverse perspectives from a community of stakeholders throughout the AI life cycle
Cases that cite this article
- Dutch childcare benefits: nationality as a risk indicator (2021)
- SyRI: a fraud risk model no court could verify (2020)
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art27.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 27: Fundamental Rights Impact Assessment (FRIA) (AIGE-OBL-EUAIA-ART27). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art27. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 27: Fundamental Rights Impact Assessment (FRIA) (AIGE-OBL-EUAIA-ART27)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art27},
note = {Version 0.5.0}
}