Glossary · AI Act

FRIA (Fundamental Rights Impact Assessment)

An assessment of the impact on fundamental rights that certain deployers must complete before using a high-risk AI system.

Explained in depth: AI Act overview

Article 27 of the AI Act requires certain deployers, bodies governed by public law, private entities providing public services, and deployers using high-risk AI for creditworthiness assessment or life and health insurance pricing, to assess the fundamental-rights impact of a high-risk system before first use. The FRIA describes the deployment context and period, the categories of persons affected, the specific risks of harm to them, the human oversight measures, and the arrangements if risks materialise, and the market surveillance authority is notified of the outcome. The FRIA complements, and can build on, a GDPR data protection impact assessment: where a DPIA already covers parts of the analysis, the FRIA adds to it rather than duplicating it.

Why it matters

For banks, insurers, and public-sector bodies, the FRIA is a concrete, dated deliverable an authority can ask to see. It is also a governance forcing function: it makes the deploying organisation articulate, in writing, who could be harmed and what happens then.

Used in

See also

← All glossary terms