Legal requirement Impact assessment European Union Partially applicable

Carry out a fundamental rights impact assessment before deployment

Under EU AI Act, Article 27

Source-linked Open official source

What does it require?

Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.

Practical action

Reuse GDPR DPIA workflows and extend them with the Article 27 elements; the AI Office is to provide a template.

Who does it apply to?

Public bodies, private providers of public services, and deployers in credit and insurance use cases.

Applies from:

Evidence examples

  • Fundamental rights impact assessment report (report)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 6.1.4 AI system impact assessment; Annex A control on impact assessmentOriginal editorial mapping.high
NIST AI RMF 1.0MAP 5.1, MAP 5.2Impacts on individuals, groups and society.medium

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.