Regulation Tracker / EU AI Act / Chapter III · Section 3
Article 27
Fundamental rights impact assessment for high-risk AI systems
Chapter III — Classification rules for high-risk AI systems, Section 3 — Obligations of providers of high-risk AI systems. 6 distinct duties, powers or definitions are coded from this article, applying from 2027-12-02. 5 reach legal practice directly.
Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 2026-07-27 — about 61 words changed. The text below is the consolidated version of 27 July 2026; the 2024 text and the amending regulation are on EUR-Lex. 6 of the duties below now apply later than Article 113 originally provided; each shows both dates.
official text: EUR-Lex (consolidated 27 Jul 2026) · text © European Union (Decision 2011/833/EU) · coding CC BY 4.0 · data: obligations.json · Hugging Face · GitHub
The text
1. Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:
- (a)a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;
- (b)a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;
- (c)the categories of natural persons and groups likely to be affected by its use in the specific context;
- (d)the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;
- (e)a description of the implementation of human oversight measures, according to the instructions for use;
- (f)the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.
2. The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.
3. Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.
4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment.
5. The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment pursuant to paragraph 4.
What it requires, coded
SafeLegalAI's reading of each duty in this article: who, what, from when, under which fine tier, and whether it reaches a firm, chambers, court or legal-AI vendor. Descriptive, not advice; the quoted words are the Regulation's.
Art. 27(1)Risk managementHigh-risklegal practice
Before deploying specified Article 6(2) high-risk AI systems, covered public-law bodies, private public-service entities and certain credit and insurance deployers must perform a fundamental-rights impact assessment.
"Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b)"
- Who
- Deployer, Public-authority deployer
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2) gives public-authority high-risk systems until 2030-08-02; systems placed on the market or put into service before the Chapter III date are covered only if significantly changed from that date.
- Legal practice
- Reaches legal practice directly — Direct for courts, public bodies and some financial or insurance deployers; judicial AI under Annex III point 8 can be covered when deployed by public-law bodies.
- See
- Art. 6(2) · Annex III point 5(b) · Annex III point 5(c) · Annex III point 8
Art. 27(1) (a-f)DocumentationHigh-risklegal practice
The FRIA must describe deployer processes, duration and frequency of use, affected persons or groups, specific harm risks, human oversight implementation and measures for materialised risks.
"a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;"
- Who
- Deployer, Public-authority deployer
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2) gives public-authority high-risk systems until 2030-08-02; systems placed on the market or put into service before the Chapter III date are covered only if significantly changed from that date.
- Legal practice
- Reaches legal practice directly — FRIA contents are central to public-authority legal AI, including court or ADR contexts where natural persons may be affected.
- See
- Art. 13 · Art. 14 · Annex III point 8
Art. 27(2)Risk managementHigh-risklegal practice
The FRIA obligation applies to first use; deployers may rely on prior or provider assessments in similar cases but must update information when Article 27(1) elements change or become outdated.
"The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1"
- Who
- Deployer, Public-authority deployer
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2) gives public-authority high-risk systems until 2030-08-02; systems placed on the market or put into service before the Chapter III date are covered only if significantly changed from that date.
- Legal practice
- Reaches legal practice directly — Public legal deployers may reuse assessments for similar AI uses but must keep them current as system or context changes.
- See
- Art. 27(1)
Art. 27(4)DocumentationHigh-risklegal practice
Where Article 27 obligations are already met through a GDPR or law-enforcement DPIA, the deployer may include cross-references to relevant DPIA sections or include relevant parts in the FRIA.
"If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of"
- Who
- Deployer, Public-authority deployer
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2) gives public-authority high-risk systems until 2030-08-02; systems placed on the market or put into service before the Chapter III date are covered only if significantly changed from that date.
- Legal practice
- Reaches legal practice directly — Important for legal deployers aligning AI fundamental-rights assessment with data protection impact assessment work.
- See
- Regulation (EU) 2016/679 Art. 35 · Directive (EU) 2016/680 Art. 27
Art. 27(5)Support measureHigh-risk
The AI Office must develop a questionnaire template, including through an automated tool, to help deployers comply with Article 27 and include DPIA cross-references or relevant DPIA parts where appropriate.
"The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental"
- Who
- AI Office
- From
- (Art. 113(c)(i) as amended by Reg. (EU) 2026/1744)As enacted in 2024: (Art. 113 second subparagraph); deferred by Regulation (EU) 2026/1744 (Digital Omnibus on AI).Art. 111(2) gives public-authority high-risk systems until 2030-08-02; systems placed on the market or put into service before the Chapter III date are covered only if significantly changed from that date.
- Legal practice
- Reaches legal-AI vendors or public bodies — The template can shape FRIA practice for courts, public authorities and legal-sector deployers of covered high-risk AI.
- See
- Art. 27(4)
Cite
Regulation (EU) 2024/1689, Article 27 (Fundamental rights impact assessment for high-risk AI systems), as amended by Regulation (EU) 2026/1744, consolidated text of 27 July 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_27 — text © European Union; only the Official Journal is authentic. Coding: SafeLegalAI (published by Cognesio LLP), "EU AI Act, structured", safelegalai.com/regulation/eu-ai-act/article-27, accessed 2026-09-08, CC BY 4.0.