---
authoritative: false
representation: annotated-page
publisher: AstroKube
methodology: https://ai-act.astrokube.com/about/
source_verified_on: '2026-09-15'
site_content_updated_on: '2026-09-15'
title: 'Article 27: Fundamental rights impact assessment for high-risk AI systems | EU AI Act | AstroKube'
description: 'Article 27, EU AI Act: 1. Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be…'
language: en
source: https://ai-act.astrokube.com/law/art-27/
---

1.  [Start](https://ai-act.astrokube.com/)
2.  [The law](https://ai-act.astrokube.com/law/)
3.  Article 27

Chapter III · Section 3 · Obligations of providers and deployers of high-risk AI systems and other parties

# Article 27 — Fundamental rights impact assessment for high-risk AI systems

⟲ Amended · Regulation (EU) 2026/1744

▼ Primary text, verbatim. Our annotations appear below, visibly separated.

[1\.](https://ai-act.astrokube.com/law/art-27/#p-1) Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:

(a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;

(b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;

(c) the categories of natural persons and groups likely to be affected by its use in the specific context;

(d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;

(e) a description of the implementation of human oversight measures, according to the instructions for use;

(f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.

[2\.](https://ai-act.astrokube.com/law/art-27/#p-2) The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.

[3\.](https://ai-act.astrokube.com/law/art-27/#p-3) Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.

[4\.](https://ai-act.astrokube.com/law/art-27/#p-4) If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment.

[5\.](https://ai-act.astrokube.com/law/art-27/#p-5) The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment pursuant to paragraph 4.

This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex.

**Amended**

— Regulation (EU) 2026/1744

Passages marked with the accent edge in the primary text were inserted or replaced by the amendment.

Show the text as adopted, before the amendment

The authentic 2024 text of this provision, shown for comparison. It no longer states the law.

1\. Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:

(a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;

(b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;

(c) the categories of natural persons and groups likely to be affected by its use in the specific context;

(d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;

(e) a description of the implementation of human oversight measures, according to the instructions for use;

(f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.

2\. The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.

3\. Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.

4\. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment.

5\. The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.

[

Recital 96 — interpretive context

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important…

](https://ai-act.astrokube.com/law/recital-96/)

## What this means for you

In your terms · Fundamental rights impact assessment

The assessment describes your actual process: which decisions the system feeds, who is affected, what can go wrong for them and what you will do about it.

-   Fundamental rights impact assessment

Failure smells likeThe system goes live to the public and the first assessment of what it does to people is the complaint that follows.

## Obligations derived from this article

[Fundamental rights impact assessmentArt. 27](https://ai-act.astrokube.com/explorer/?art=art-27)

## Scenarios that touch this provision

### A credit-decision feature

Illustrative

A model scores applicants for a lending product and the score drives the decision, with a human able to override it.

### Your role

ProviderDeployer

### Where it lands

High risk Deferred 2 Dec 2027

### Decided by

Annex III, point 5(b): systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of systems used to detect financial fraud.

What applies

-   [Risk management system](https://ai-act.astrokube.com/explorer/?q=art-9-risk-management)
-   [Data and data governance](https://ai-act.astrokube.com/explorer/?q=art-10-data-governance)
-   [Technical documentation](https://ai-act.astrokube.com/explorer/?q=art-11-technical-documentation)
-   [Automatic recording of events](https://ai-act.astrokube.com/explorer/?q=art-12-logging)
-   [Human oversight](https://ai-act.astrokube.com/explorer/?q=art-14-human-oversight)
-   [Accuracy, robustness and cybersecurity](https://ai-act.astrokube.com/explorer/?q=art-15-accuracy-robustness)
-   [Deployer obligations](https://ai-act.astrokube.com/explorer/?q=art-26-deployer-obligations)
-   [Fundamental rights impact assessment](https://ai-act.astrokube.com/explorer/?q=art-27-fria)
-   [Conformity assessment](https://ai-act.astrokube.com/explorer/?q=art-43-conformity-assessment)
-   [Registration in the EU database](https://ai-act.astrokube.com/explorer/?q=art-49-registration)
-   [Right to explanation of individual decisions](https://ai-act.astrokube.com/explorer/?q=art-86-right-to-explanation)

What you have to be able to produce

-   Adversarial and injection test suite
-   Annex IV technical file
-   Bias examination report
-   Conformity route decision per system
-   Dataset cards with provenance
-   Decision factors captured per output
-   Decision-correlation IDs across services
-   Declared accuracy levels and metrics
-   Deployer-side log retention
-   Deployment instructions record per system
-   Doc generation wired into CI
-   Documentation format decision on record
-   Escalation path for emergent risk
-   Explanation request process
-   Field-risk signal feed into the register
-   Foreseeable-misuse analysis per release
-   Fundamental rights impact assessment
-   Inference event schema
-   Kill switch and override, with tests
-   Living risk register with review cadence
-   Model performance SLOs with alerts
-   Named oversight roles
-   Oversight runbook
-   Oversight UX with override path
-   Per-run lineage records
-   Registration entries per system
-   Replay runbook
-   Representativeness note for the target population
-   Risk-to-control mapping in the design docs
-   Scope determination on record
-   Stated assumptions per data set
-   Tamper-evident log storage
-   Worker information notice

What would change the answer

-   Unlike the hiring case, this one carries a fundamental rights impact assessment: Article 27(1) names Annex III point 5(b) explicitly.
-   Restricting the system to fraud detection takes it out of point 5(b). Scoring the same people for a lending decision puts it back.
-   An affected person can ask for an explanation of the individual decision under Article 86, and that explanation comes from the same records Article 12 asked you to keep.

[EU Annex III, point 5(b)](https://ai-act.astrokube.com/law/annex-iii/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 27(1)](https://ai-act.astrokube.com/law/art-27/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 86](https://ai-act.astrokube.com/law/art-86/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)") [EU Art. 12](https://ai-act.astrokube.com/law/art-12/ "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)")

A scenario describes a system we made up, not yours. It is not a classification of your system and not legal advice. Pending review by a named legal reviewer.

## If you would rather not read the law

The basics page explains the Regulation's own categories in order: scope, role, tier, date. The engineering view groups the obligations by the platform capability they demand.

[Start with the basics →](https://ai-act.astrokube.com/basics/) [Open the engineering view →](https://ai-act.astrokube.com/engineering/)

## About this provision

### Status

Upcoming 2 Dec 2027

Moved from ~2 Aug 2026~

### Regime

High-risk

### Binds

Deployer

### Type

Article · Chapter III · Section 3

### Amended by

[Regulation (EU) 2026/1744](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727)

### Recitals

[96](https://ai-act.astrokube.com/law/recital-96/)

### Related

[Article 26](https://ai-act.astrokube.com/law/art-26/) [Article 49](https://ai-act.astrokube.com/law/art-49/)

### Cited capture

regulation-2024-1689/en-2026-08-18.html sha256 8f0b656302f9864c…

[Authentic text (EUR-Lex) →](http://data.europa.eu/eli/reg/2024/1689/oj) [This version (EUR-Lex) →](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727)

### Machine readable

[/law/art-27.md](https://ai-act.astrokube.com/law/art-27.md) [/api/law.json](https://ai-act.astrokube.com/api/law.json)

### Found an error?

[Write to us →](https://astrokube.com/contact)
