Who is affected by Art. 27?
Art. 27 AI Act does not apply to all operators of high-risk AI systems. According to Art. 27(1), the obligation to carry out a fundamental rights impact assessment (FRIA) specifically applies to:
- bodies governed by public law,
- private entities providing public services, and
- operators of high-risk AI systems referred to in Annex III, point 5(b) and (c) (this concerns certain systems used for creditworthiness assessment and risk assessment/pricing in relation to insurance).
High-risk AI systems under Annex III, point 2 (critical infrastructure) are excluded. So if you are a public authority, a company entrusted with a public service mandate, or an operator in the financial or insurance sector, you should check whether your system falls within scope – regardless of whether you are a provider or purely an operator. The obligation is expressly addressed to operators, not providers.
What the impact assessment must contain
Art. 27(1) sets out six mandatory elements that the assessment must contain:
- a description of the processes in which the system will be used in line with its intended purpose (point (a)),
- the period of time and frequency in which the system is intended to be used (point (b)),
- the categories of natural persons and groups likely to be affected by its use (point (c)),
- the specific risks of harm likely to affect those groups, taking into account the information provided by the provider pursuant to Art. 13 (point (d)),
- the implementation of human oversight measures, in accordance with the instructions for use (point (e)), and
- the measures to be taken in the event of the materialisation of those risks, including internal governance arrangements and complaint mechanisms (point (f)).
In practice, this means a FRIA is not a free-form document but must demonstrably cover these six elements. Point (d) in particular requires drawing on the information provided by the provider under Art. 13 – without robust technical documentation from the provider, this requirement can hardly be met in a credible way. This is often the first gap: operators do not hold the relevant provider documentation in sufficient depth.
Timing, updates and notification
Under Art. 27(2), the obligation arises upon the first use of a high-risk AI system – not on each individual use. The operator may rely on previously conducted assessments carried out by it in similar cases, or on existing impact assessments carried out by the provider. This particularly eases the burden for organisations deploying several comparable systems from the same provider.
The update obligation is important: if, in the course of using the high-risk AI system, the operator considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, it must take the necessary steps to update the information (Art. 27(2), third sentence). This is not a one-off document but a living process, linked to changes in the deployment context, the number of users or the intended purpose.
Once the assessment has been carried out, the operator notifies the market surveillance authority of its results, using a template to be developed by the AI Office pursuant to Art. 27(5) (Art. 27(3)). In the case referred to in Art. 46(1), an exemption from this notification obligation may apply.
Relationship with the GDPR impact assessment
Art. 27(4) clarifies: if a data protection impact assessment has already been carried out under Art. 35 GDPR or Art. 27 of Directive (EU) 2016/680, and that assessment covers any of the obligations under Art. 27 AI Act, the FRIA merely complements that data protection impact assessment. No duplicate document needs to be produced from scratch – only a supplement is required.
In practice, this means that anyone who already has a data protection impact assessment for an AI-supported process should check which of the six FRIA elements are already covered there – typically the categories of data subjects and risk descriptions – and specifically close the remaining gaps, for example on human oversight or complaint mechanisms. Producing a new assessment without reflection leads to unnecessary effort and inconsistencies between the two documents.
Common gaps in practice
Three recurring patterns emerge. First, the reliance on the provider’s Art. 13 information is missing, simply because it was never requested. Second, the FRIA is treated as a one-off project, without any trigger process for updates when use or the target group changes. Third, there is no integration with existing data protection impact assessment documents, meaning complaint mechanisms and governance measures end up either duplicated or not documented at all.
If you are unsure whether your organisation falls within the scope of Art. 27 and which documentation obligations specifically apply, our free risk check at /einstufung can help you clarify your classification under the AI Act in a structured way.