Fundamental Rights Impact Assessment (FRIA)
A Fundamental Rights Impact Assessment (FRIA) is the structured analysis required by Article 27 of the EU AI Act for certain deployers of high-risk AI systems — bodies governed by public law, private operators of public services, and deployers of credit-scoring or insurance-pricing AI.
Full definition
Required content includes: (1) processes in which the system will be used; (2) period and frequency of use; (3) categories of natural persons likely affected; (4) specific risks of harm; (5) human-oversight measures; (6) mitigations if risks materialize. The assessment must be notified to the relevant market-surveillance authority. FRIA is distinct from — and complementary to — GDPR Data Protection Impact Assessment (DPIA); the AI Act allows the two to be combined.
Why it matters
FRIA puts deployers (not just providers) on the hook for high-risk AI governance. For public-sector buyers and regulated industries, FRIA is now a mandatory step in any procurement of high-risk AI — and a recurring compliance cost.
Example
A municipality deploys an AI tool to triage social-benefits applications (Annex III §5); before go-live it runs a FRIA covering language access, appeal rights, and disparate-impact monitoring, and registers the assessment with the national authority.
Related terms
- EU AI ActThe EU AI Act (Regulation (EU) 2024/1689) is the European Union's comprehensive, risk-tiered regulation of AI systems, the world's first horizontal AI law, with obligations phasing in from February 2025 and full general-purpose AI rules applying from August 2025.
- EU AI Act Risk TierEU AI Act risk tiers are the four-level classification — unacceptable, high, limited, and minimal/no risk — that determines which obligations apply to an AI system placed on the EU market under Regulation (EU) 2024/1689.
- AI Act Conformity AssessmentA conformity assessment under the EU AI Act is the procedure by which a high-risk AI system is verified to meet the regulation's requirements (Articles 8-15) before being placed on the EU market or put into service.
- AI Risk AssessmentAn AI risk assessment is a structured review of an AI system's potential harms — to individuals, groups, the organization, and society — covering likelihood, severity, affected populations, and mitigation controls across safety, fairness, security, privacy, and compliance dimensions.
Source & further reading
Primary source: European Union — Regulation (EU) 2024/1689, Article 27 (2024).
Citation policy: this entry is part of the AIDOLS AI Implementation Glossary and may be quoted for research, journalism, and education with attribution to aidolsgroup.com/es/glossary/fundamental-rights-impact-assessment/.