Chapter III · Section 3 · Obligations of providers and deployers of high-risk AI systems and other parties
Article 27 — Fundamental rights impact assessment for high-risk AI systems
▼ Primary text, verbatim. Our annotations appear below, visibly separated.
1. Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:
(a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;
(b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;
(c) the categories of natural persons and groups likely to be affected by its use in the specific context;
(d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;
(e) a description of the implementation of human oversight measures, according to the instructions for use;
(f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.
2. The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.
3. Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.
4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment.
5. The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment pursuant to paragraph 4.
This text is meant purely as a documentation tool and has no legal effect. The Union's institutions do not assume any liability for its contents. The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union and available in EUR-Lex.
Passages marked with the accent edge in the primary text were inserted or replaced by the amendment.
Show the text as adopted, before the amendment
The authentic 2024 text of this provision, shown for comparison. It no longer states the law.
1. Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:
(a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;
(b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;
(c) the categories of natural persons and groups likely to be affected by its use in the specific context;
(d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;
(e) a description of the implementation of human oversight measures, according to the instructions for use;
(f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.
2. The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.
3. Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.
4. If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment.
5. The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.
What this means for you
In your terms · Fundamental rights impact assessment
The assessment describes your actual process: which decisions the system feeds, who is affected, what can go wrong for them and what you will do about it.
- Fundamental rights impact assessment
Failure smells likeThe system goes live to the public and the first assessment of what it does to people is the complaint that follows.
In your terms · Fundamental rights impact assessment
Whether your organization is in scope is the first question; the answer decides real pre-deployment work.
- Scope determination on record
Obligations derived from this article
Scenarios that touch this provision
A credit-decision feature
Illustrative
A model scores applicants for a lending product and the score drives the decision, with a human able to override it.
- Your role
- ProviderDeployer
- Where it lands
- High risk 2 Dec 2027
- Decided by
- Annex III, point 5(b): systems intended to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of systems used to detect financial fraud.
What applies
- Risk management system
- Data and data governance
- Technical documentation
- Automatic recording of events
- Human oversight
- Accuracy, robustness and cybersecurity
- Deployer obligations
- Fundamental rights impact assessment
- Conformity assessment
- Registration in the EU database
- Right to explanation of individual decisions
What you have to be able to produce
- Adversarial and injection test suite
- Annex IV technical file
- Bias examination report
- Conformity route decision per system
- Dataset cards with provenance
- Decision factors captured per output
- Decision-correlation IDs across services
- Declared accuracy levels and metrics
- Deployer-side log retention
- Deployment instructions record per system
- Doc generation wired into CI
- Documentation format decision on record
- Escalation path for emergent risk
- Explanation request process
- Field-risk signal feed into the register
- Foreseeable-misuse analysis per release
- Fundamental rights impact assessment
- Inference event schema
- Kill switch and override, with tests
- Living risk register with review cadence
- Model performance SLOs with alerts
- Named oversight roles
- Oversight runbook
- Oversight UX with override path
- Per-run lineage records
- Registration entries per system
- Replay runbook
- Representativeness note for the target population
- Risk-to-control mapping in the design docs
- Scope determination on record
- Stated assumptions per data set
- Tamper-evident log storage
- Worker information notice
What would change the answer
- Unlike the hiring case, this one carries a fundamental rights impact assessment: Article 27(1) names Annex III point 5(b) explicitly.
- Restricting the system to fraud detection takes it out of point 5(b). Scoring the same people for a lending decision puts it back.
- An affected person can ask for an explanation of the individual decision under Article 86, and that explanation comes from the same records Article 12 asked you to keep.
If you would rather not read the law
The basics page explains the Regulation's own categories in order: scope, role, tier, date. The engineering view groups the obligations by the platform capability they demand.