Article 27 of the EU AI Act (Regulation (EU) 2024/1689) catches only two categories of deployer: bodies governed by public law, or private entities providing public services, and deployers of the Annex III point 5(b) creditworthiness and point 5(c) life and health insurance systems. A private employer running an Annex III recruitment tool owes no fundamental rights impact assessment at all. Critical infrastructure — Annex III point 2 — is carved out of Article 27 by name, in the operative text itself. Most compliance content treats the FRIA as a blanket high-risk deployer duty. It isn’t one.
The date matters as much as the scope, and it moved. The FRIA obligation tracks the Annex III application date, which the Digital Omnibus deferred from 2 August 2026 to 2 December 2027 — and that deferral almost didn’t include the FRIA. During trilogue, the Parliament’s IMCO and LIBE committees specifically pushed to carve Article 27 out of the general delay and keep it on the original 2026 date, on the reasoning that a fundamental-rights safeguard deserved different treatment from the rest of the high-risk package. That carve-out didn’t survive the final agreement: the FRIA moved with everything else, to 2 December 2027, once the Parliament adopted the deal on 16 June 2026. As with the rest of the Omnibus, that date only binds once the amending regulation is published in the Official Journal — until then, 2 August 2026 is still the legally operative date.
Do you owe a FRIA?
Four questions settle it:
- Are you a body governed by public law, or a private entity providing public services?
- Are you deploying an Annex III 5(b) creditworthiness system, or a 5(c) life and health insurance risk-assessment or pricing system? (This limb catches you regardless of whether you’re a public or private organisation — a bank running credit scoring owes a FRIA through this route alone, without needing to argue over whether banking counts as a public service.)
- Is the system critical infrastructure under Annex III point 2? If so, you’re excluded from Article 27 by name, full stop.
- Is this your first use of the system? The obligation attaches at first use, not every use afterward.
What goes in it
Article 27(1) specifies six elements, and they’re worth naming precisely rather than paraphrasing loosely:
- A description of the deployer’s own processes in which the system will be used, in line with its intended purpose.
- The period and frequency over which each high-risk system will be used.
- The categories of natural persons and groups likely to be affected by the specific context of use.
- The specific risks of harm likely to affect those categories, taking into account the information the provider supplied under Article 13.
- A description of the human oversight measures implemented, in line with the instructions for use.
- The measures to take if those risks materialise, including internal governance arrangements and complaints mechanisms.
The filing nobody mentions
Once the assessment is done, the deployer notifies the market surveillance authority of the results and submits the completed template as part of that notification. That’s what turns Article 27 from an internal document into a reporting obligation, and it’s the part most summaries skip entirely.
There is one specific, named exemption from the notification duty: the Article 46(1) case, where a market surveillance authority has authorised a system in exceptional circumstances of public security, life and health, environmental protection, or protection of key infrastructure. Outside that specific case, notification is owed.
The template itself is still missing. Article 27(5) requires the AI Office to develop a questionnaire template — potentially through an automated tool, not just a form — to help deployers comply, but as of this writing that template hasn’t been published, and there’s no fixed deadline forcing its release. Its absence doesn’t suspend the obligation. In the meantime, the ECNL and the Danish Institute for Human Rights published a practitioner guide to fundamental rights impact assessments in December 2025 that’s worth building against while the official template is still pending.
How to not do it twice
The obligation applies to first use only. For similar later cases, a deployer can rely on a fundamental rights impact assessment it already carried out, or on one the provider carried out for similar cases — you’re not starting from a blank page every time you deploy a comparable system.
There’s a second overlap most summaries also skip: if any obligation under Article 27 is already satisfied by a data protection impact assessment carried out under Article 35 GDPR, or under Article 27 of the Law Enforcement Directive, the fundamental rights impact assessment becomes a supplement to that existing DPIA rather than a separate document duplicating it. Build the FRIA as an addition to the DPIA you likely already have, not a second filing cabinet.
The reuse right isn’t unconditional, though. If, during use, any of the six elements changes or stops being current — the affected population shifts, the frequency of use changes, a new risk emerges — the deployer has to update the assessment. Retraining a model, or a material change in how it’s actually used, is exactly the kind of event that should trigger this update duty; there’s no fixed retraining cadence that automatically resets the clock, but a change substantial enough to touch any of the six elements is substantial enough to require revisiting them.
The GDPR Article 22 trap next door
A related but separate question sits beside all of this. Deployers using these systems without meaningful human review of individual decisions still have to separately consider whether the GDPR’s Article 22 restriction on solely automated decision-making applies. That’s a different instrument, with a different test, frequently triggered by the same use case — passing your Article 27 analysis doesn’t answer the Article 22 question, and the two shouldn’t be run as if one substitutes for the other.
Frequently asked questions
Is a bank a “public service” deployer?
You don’t need to resolve that argument for credit scoring specifically — Annex III 5(b) already catches a bank running creditworthiness assessment directly, regardless of whether banking counts as a public service in your Member State. The public-service question only matters for deployers who aren’t independently caught by the 5(b) or 5(c) limb.
Does a private hospital count?
This is a genuine grey area rather than a settled answer. Private hospitals aren’t covered by the credit or insurance limb, so the question turns entirely on whether they count as providing a public service — and that can depend on how a given Member State’s healthcare system blends public and private provision, including whether the hospital operates under a public health insurance scheme. Don’t assume either answer without checking the national position.
What if the provider gives us their own FRIA?
Article 27(2) explicitly allows this — you can rely on an impact assessment the provider already carried out for similar cases instead of starting your own from scratch. Confirm it actually covers your specific context of use, since the six elements are context-dependent by design, and update it if your deployment differs from what the provider assessed.
Do we redo it when the model is retrained?
There’s no fixed rule tying a FRIA refresh to every retraining cycle, but Article 27(2) requires an update whenever any of the six elements changes or becomes outdated during use. A retraining that changes who’s affected, what risks arise, or how the system behaves in practice is exactly the kind of change that obligation is aimed at — treat significant retraining as a trigger to check the assessment, not as an automatic all-clear.
What’s the penalty for not filing?
Violations of the high-risk operator obligations, including Article 27, sit in the tier of fines up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99 — with the lower of the two figures applying to SMEs and start-ups instead of the higher one.
