Direct answer
Do we need to perform a FRIA and how do we approach it?
You describe: A fundamental rights impact assessment (Article 27) for deploying a high-risk AI system. Likely role: public body, public service provider or credit/insurance deployer.
This applies now
- For this situation, the preparation phase matters most right now.
Coming up
- Article 27: FRIAfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
The FRIA duty applies only to specific deployers and follows the high-risk timeline to 2 December 2027. A FRIA is not a DPIA: they overlap, but the FRIA assesses more than data protection.
Your first actions
- Perform a FRIA before deployment. Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.
- Classify the use case and document the outcome. Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
Record this
- FRIA report and notification
- Article 6 and Annex III classification record
General interpretation, not legal advice. The official source remains authoritative.
Full map for your situationExecution
Carry out the FRIA in a structured way
A FRIA touches DPIA, register and human oversight. Embed AI runs the assessment together with your team and delivers the evidence file.
See the Embed AI approach