# FRIA AI Act: obligations, scope, methodology, and deadlines to know

> The FRIA, provided for by Article 27 of the AI Act, requires public bodies, operators of essential services, and educational institutions using high-risk AI to assess the impact on fundamental rights before August 2, 2026. It differs from the GDPR DPIA.

- Tags: fria ai act, fria déployeur, article 27 ai act, évaluation d'impact IA, conformité AI Act, droits fondamentaux IA, obligations déployeur IA
- Main keyword: fria ai act

## Key points

- The FRIA (Fundamental Rights Impact Assessment) is imposed by Article 27 of the AI Act regulation on deployers of high-risk AI systems in certain sectors (public, essential services, education).
- Distinct from the GDPR DPIA, the FRIA assesses the impact on all fundamental rights, far beyond just the protection of personal data.
- The obligation to conduct the FRIA must be met imperatively before the commissioning of the high-risk AI system, not after.
- The FRIA must include at least 15 structured fields, covering the system description, rights concerned, mitigation measures, and monitoring.
- The results of the FRIA must be recorded in the dedicated European database for high-risk AI systems.
- The FRIA must be finalized before August 2, 2026, for concerned entities, subject to any potential postponement related to the Digital Omnibus.

## Introduction

Compliance with the AI Act regulation often focuses on the technical documentation of providers, but deployers of high-risk AI systems are subject to specific requirements, among which is the FRIA (Fundamental Rights Impact Assessment). This fundamental rights impact assessment, imposed by **Article 27 of Regulation (EU) 2024/1689**, must be conducted by certain deployers before any commissioning of a high-risk AI system.

Still little known and regularly confused with the GDPR DPIA, the FRIA nevertheless concerns a wide range of public and private organizations. This guide explains who is concerned, how to proceed, and what deadlines to prepare for.

## Content

## Definition and origin of the FRIA

The FRIA is a structured assessment process that every deployer of a high-risk AI system must carry out to anticipate and measure the potential effects of this system on the fundamental rights of the individuals concerned. Inspired by existing practices in the European Union (notably the GDPR DPIA), the FRIA differs due to its much broader scope.

While the DPIA targets risks related to the processing of personal data, the FRIA encompasses all rights guaranteed by the **Charter of Fundamental Rights of the European Union**:

- Human dignity and integrity of the person
- Right to non-discrimination (Article 21)
- Data protection and respect for private life
- Freedom of expression and information
- Right to an effective remedy and a fair trial
- Rights of the child and vulnerable persons
- Equality between women and men
- Workers' rights, particularly regarding working conditions

The central objective: to anticipate whether the use of the AI system risks infringing upon one or more of these fundamental rights.

## Who must conduct a FRIA?

The FRIA is not required for all deployers of high-risk systems. **Article 27** makes it mandatory for specific categories:

### Public law bodies

This includes:
- Central administrations and local authorities
- Public institutions (hospitals, public universities, employment agencies, etc.)
- Social security organizations
- Judicial, police, or border control authorities

### Operators of essential services

Private companies that manage critical infrastructure or provide vital services (energy, transport, water, digital health, systemic banking systems) must conduct a FRIA if they deploy a high-risk AI system.

### Educational and vocational training institutions

Schools, universities, and training organizations using AI systems for evaluation, admission management, or orientation—when these systems fall under Annex III—are also subject to the FRIA.

> Traditional private companies that use AI HR software or commercial scoring tools are generally not concerned by the FRIA. However, they must comply with the obligations of Article 26 (human oversight, log retention, informing individuals), but not the formal assessment of Article 27.

## FRIA and DPIA: what are the differences?

Confusion between FRIA and DPIA is common. Here is how to distinguish them:

- **Legal basis**: The DPIA is based on Article 35 of the GDPR, the FRIA on Article 27 of the AI Act regulation.
- **Scope**: The DPIA targets only risks related to personal data protection. The FRIA covers all fundamental rights, including those without a direct link to private life (non-discrimination, equality, access to justice, social rights, etc.).
- **Trigger**: The DPIA is required for certain high-risk data processing. The FRIA is mandatory when a high-risk AI system is deployed by a deployer falling under the targeted categories.
- **Coordination**: It is possible—and recommended—to coordinate both assessments, particularly on aspects related to data protection and non-discrimination, to avoid redundancies.

## How to conduct a FRIA: steps and content

Article 27 does not provide a single template but imposes structured content. Here are the main recommended steps:

### 1. Presentation of the system and context of use

Precisely describe the AI system: purpose, general operation, automated or assisted decisions, organizational context, users concerned, and impacted populations.

### 2. Identification of affected persons

Identify the individuals directly or indirectly affected by the system. Pay particular attention to vulnerable groups (minors, the elderly, persons with disabilities, minorities).

### 3. Analysis of potentially affected fundamental rights

For each fundamental right in the Charter, determine:
- If the system can affect it in the context of use
- The level of probability and severity of the impact
- If the infringement would be direct or indirect

### 4. Assessment of concrete risks

Transform potential impacts into concrete risks. For example, a scoring system can generate indirect discrimination if its training data is biased. A school assessment tool can infringe upon the right to education if its results are erroneous and cannot be challenged.

### 5. Planned mitigation measures

For each identified risk, detail the risk reduction measures:
- Human oversight of critical decisions
- Accessible appeal and challenge procedures
- Bias detection and correction procedures
- Usage restrictions or scope limitations
- User training on system limits and biases

### 6. Monitoring and review of the FRIA

The FRIA is not static. Define a review schedule, indicators to monitor, and circumstances that would justify a new assessment (major system evolution, context change, reported incident, etc.).

### 7. Registration and publication of results

The results of the FRIA must be recorded in the **EU database for high-risk AI systems** (Article 71). Some data may be exempted from publication for confidentiality reasons, but the summary of the assessment must be accessible.

## Pitfalls to avoid during the FRIA

- **Conducting the FRIA after deployment**: the assessment must imperatively precede commissioning. A post-hoc FRIA does not meet the legal obligation and exposes the entity to sanctions.
- **Limiting the analysis to personal data**: the FRIA is not just an extension of the DPIA. Social rights, equality, and access to justice must be taken into account even without personal data processing.
- **Forgetting to involve stakeholders**: consulting representatives of affected populations improves the quality and robustness of the assessment.
- **Neglecting indirect risks**: some systems affect people without direct contact (e.g., social housing allocation algorithms).
- **Omitting periodic reviews**: a FRIA done in 2025 for a system evolved in 2026 is no longer valid. Plan for regular updates.

To facilitate the process, the [compaia Deployer module](https://compaia.eu/diagnostic) offers step-by-step support, covering all requirements of Article 27 and generating an exportable document ready for registration.

## Calendar: FRIA deadline and sanctions

Concerned deployers must have completed their FRIA before **August 2, 2026** (subject to any potential postponement related to the Digital Omnibus). Failure to comply with this obligation exposes the entity to sanctions of up to **15 million euros** or **3%** of the total annual worldwide turnover. National authorities will have investigative and sanctioning powers starting from **August 2026**.

To plan your compliance, consult the [AI Act timeline](https://compaia.eu/echeancier-ai-act).

## To go further

- [FRIA compliance diagnostic – compaia](https://compaia.eu/diagnostic)
- [AI Act timeline – compaia](https://compaia.eu/echeancier-ai-act)

The FRIA, although less publicized than other obligations of the AI Act regulation, constitutes an essential foundation for the responsible governance of high-risk AI systems in the public, critical, and educational sectors. Its serious and anticipated execution is a guarantee of both compliance and the effective respect of fundamental rights.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/fria-ai-act-evaluation-impact-droits-fondamentaux)
