The Five Records Behind an AI Act Article 27 FRIA
Separate an EU AI Act Article 27 fundamental-rights impact assessment from a generic AI risk review with five records covering scope, use, affected people, safeguards and notification.

Signals to watch
- A named AI deployment is approaching a steering, procurement or go-live decision and the group says a FRIA is incomplete
- The discussion identifies an affected public service, credit decision or insurance use but leaves the deployer and Article 6(2) classification unresolved
- A provider risk register exists, while affected-person categories, human oversight, complaint handling or market-surveillance notification remain unowned
An EU AI Act fundamental-rights impact assessment (FRIA) is a deployer-side assessment of how a specified high-risk AI system may affect people in its actual context of use before deployment. Article 27 requires the covered deployer to document the process, use period and frequency, affected categories of people, risks of harm, human oversight and measures for realised risks, then notify the market surveillance authority where required. It is not a generic AI risk register or a provider conformity report.
That distinction matters to an AI-governance consultancy practice lead following authorised AI implementation, public-service digitalisation and regulated-sector Telegram groups. A post saying “FRIA still open” can point to assessment, governance, complaints, oversight or notification work—but only after the legal role, system classification and deployment context are verified. Seeing it after the deployment meeting can mean the evidence owners and external adviser scope have already been fixed.
The deployment meeting needs five records, not one “AI risk review”
The official AI Act text calls Article 27 an assessment of the impact on fundamental rights that use of the system may produce.
First, it is tied to the deployer’s real process. The file must say where the system will be used in line with its intended purpose, for how long and how often. A provider’s general risk catalogue can inform that work, but it cannot describe every deployer’s service, affected population or complaint route.
Second, it is tied to people and safeguards, not merely model performance. The record identifies categories of natural persons and groups likely to be affected, specific risks of harm, implementation of human oversight, and measures if those risks materialise, including internal governance and complaint mechanisms.
This also marks the boundary with adjacent evidence. Article 12 logging evidence concerns automatic event recording and deployer log control. Article 4 literacy evidence concerns the knowledge and competence of people dealing with AI systems. Both may support a deployment file; neither is the FRIA itself.
Start with the scope gate
Article 27 does not impose one FRIA rule on every AI use. It applies before deploying a high-risk system referred to in Article 6(2), subject to the provision’s stated boundaries. The covered deployers include bodies governed by public law, private entities providing public services, and deployers of the Annex III point 5(b) and 5(c) systems used for natural-person creditworthiness or credit scoring and for risk assessment and pricing in life and health insurance. Article 27 excludes systems intended for the critical-infrastructure area in point 2 of Annex III from this specific obligation.
The scope record should therefore answer four questions before anyone prices “FRIA support”:
- What exact AI system and intended purpose are being deployed?
- What evidence supports or challenges an Article 6(2) high-risk classification?
- Which legal entity is the deployer, and why does it fall within a named Article 27 category?
- Is this the first use, a similar case relying on an earlier assessment, or a changed use that makes old information outdated?
Article 113 sets 2 August 2026 as the Regulation’s general application date and separately defers Article 6(1) and its corresponding obligations to 2 August 2027. Article 27 refers to Article 6(2), not Article 6(1). That is a useful date check, not a substitute for transition, classification or local competent-authority analysis.
One incomplete thread can expose five different gaps
Consider this illustrative composite thread. It is not a customer conversation, legal conclusion or record of commercial results:
“Housing intake model goes live next month. FRIA deck is still open.”
“Vendor sent their risk register. Not sure who owns appeals on our side.”
“Can the DPIA cover it? Steering call tomorrow.”
The fragments contain a deployment event, a possible public-service context, provider material and an unowned complaint question. They do not establish the legal entity, Article 6(2) status, whether the service is public, the people affected, the decision the model influences, human-oversight design, the contents of the data protection impact assessment (DPIA), or the responsible market surveillance authority.
The commercial Signal is therefore “a bounded Article 27 evidence-discovery need may exist,” not “this organisation must buy a FRIA.” The practice lead can route the thread to a qualified reviewer while the deployment meeting is still open.
The five-record FRIA evidence map
This evidence map turns Article 27’s requirements into five handoff records without pretending that a checklist makes the legal decision.
| Record | What it must preserve | Stop condition |
|---|---|---|
| 1. Deployer and scope | Legal deployer, system, intended purpose, Article 6(2) basis, Article 27 deployer category, first-use or reuse position | “Public sector” or “high risk” appears only as an unsupported label |
| 2. Process and use | Named business process, decisions supported, use period, frequency, deployment boundary and accountable owner | A product description replaces the actual context of use |
| 3. Affected people and harm | Categories of natural persons and groups, likely harms to fundamental rights, provider information used and unresolved evidence | The file lists abstract rights but cannot connect them to a person, process or decision |
| 4. Oversight and response | Human-oversight implementation, authority to intervene, internal governance, complaint route and measures if risk materialises | “Human in the loop” has no named role, action or escalation route |
| 5. Update and notification | Assessment version, change triggers, DPIA cross-reference, completed questionnaire, authority, submission status and receipt where required | “FRIA complete” exists only in a slide or project-status field |
Article 27(2) applies the obligation to first use and permits reliance on previous FRIAs or provider assessments in similar cases. Reuse still needs a comparison record; changed or outdated elements must be updated.
Article 27(3) requires notification to the market surveillance authority using the filled template in paragraph 5, subject to the stated Article 46(1) exception. Under Article 27(4), overlapping GDPR or law-enforcement DPIA work is complemented by the FRIA. “We have a DPIA” is a cross-reference question, not an automatic exemption.
What to ask before scoping the work
A useful first reply asks for evidence that can change the route:
- the system name, version, intended purpose and deployment date;
- the entity that will use it and the service or decision it supports;
- the documented Article 6(2) classification position and any exception analysis;
- affected-person categories and the provider information already available;
- the human-oversight role, complaint owner and response measures;
- any prior FRIA, provider impact assessment or DPIA proposed for reuse;
- the market surveillance authority and notification status, if already identified.
Those questions separate classification discovery, first-FRIA preparation, an assessment update and notification repair, and show which specialists the work needs.
TOP Prospect can surface, merge, deduplicate and rank fragments from Telegram groups the user deliberately connects and is authorised to access, retaining original messages, source, time, AI summary and reasons for human review. It cannot classify a system, determine Article 27 scope, inspect the deployment, perform the FRIA, notify an authority, contact the poster or read private or unauthorised sources. The Telegram business-signal workflow explains how candidate discussions reach a human review queue.
Key facts
- Article 27 is a deployer obligation for specified Article 6(2) high-risk systems and specified deployer categories; it is not universal to every AI system.
- The assessment occurs before deployment and covers the real process, duration and frequency of use.
- It identifies affected categories of people, specific risks of harm, human oversight and measures for materialised risks.
- The first-use rule allows reliance on earlier assessments in similar cases, but outdated or changed elements must be updated.
- Where DPIA obligations already cover part of the work, the FRIA complements the DPIA.
- After assessment, notification uses the filled questionnaire template where required; the Regulation states a limited exception linked to Article 46(1).
- Article 113 sets the Regulation’s general application date at 2 August 2026 while separately deferring Article 6(1) obligations.
Questions practice leads usually get
Is an AI Act FRIA the same as a data protection impact assessment?
No. Article 27(4) says that, where obligations are already met through a GDPR or law-enforcement data protection impact assessment, the FRIA complements that assessment. The two records may share evidence, but one does not automatically replace the other.
Does every high-risk AI system require an Article 27 FRIA?
No. Article 27 names particular deployers and Article 6(2) systems, excludes systems intended for the critical-infrastructure area in point 2 of Annex III, and specifically includes deployers of the creditworthiness and life or health insurance systems in points 5(b) and 5(c). Scope needs case-specific legal review.
Can a deployer reuse an earlier FRIA?
Article 27(2) allows a deployer in similar cases to rely on a previously conducted FRIA or an existing impact assessment carried out by the provider. If a listed element changes or is no longer current, the deployer must update the information.
When does Article 27 apply?
Article 113 sets 2 August 2026 as the Regulation’s general application date and separately delays Article 6(1) and corresponding obligations until 2 August 2027. Article 27 refers to Article 6(2) systems, but transition and system-specific facts still need qualified review.
What evidence shows that the Article 27 workflow reached notification?
The record should preserve the completed assessment, its version and owners, the filled template used to notify the market surveillance authority, and a submission receipt where notification is required. A slide saying “FRIA done” is not equivalent to those records.
Return to the composite thread: the steering call should not receive a promise that the DPIA “covers it.” It should receive five records with named owners and visible unknowns. That is enough to scope the next expert review without mistaking discovery evidence for an Article 27 conclusion.
Reviewed by TOP Prospect Editorial Team on 18 August 2026. Legal facts were checked against the official text of Regulation (EU) 2024/1689 listed above. Classification, transition, fundamental-rights and notification questions require qualified review for the actual deployment.
Frequently asked questions
Is an AI Act FRIA the same as a data protection impact assessment?
No. Article 27(4) says that, where obligations are already met through a GDPR or law-enforcement data protection impact assessment, the FRIA complements that assessment. The two records may share evidence, but one does not automatically replace the other.
Does every high-risk AI system require an Article 27 FRIA?
No. Article 27 names particular deployers and Article 6(2) systems, excludes systems intended for the critical-infrastructure area in point 2 of Annex III, and specifically includes deployers of the creditworthiness and life or health insurance systems in points 5(b) and 5(c). Scope needs case-specific legal review.
Can a deployer reuse an earlier FRIA?
Article 27(2) allows a deployer in similar cases to rely on a previously conducted FRIA or an existing impact assessment carried out by the provider. If a listed element changes or is no longer current, the deployer must update the information.
When does Article 27 apply?
Article 113 sets 2 August 2026 as the Regulation’s general application date and separately delays Article 6(1) and corresponding obligations until 2 August 2027. Article 27 refers to Article 6(2) systems, but transition and system-specific facts still need qualified review.
What evidence shows that the Article 27 workflow reached notification?
The record should preserve the completed assessment, its version and owners, the filled template used to notify the market surveillance authority, and a submission receipt where notification is required. A slide saying “FRIA done” is not equivalent to those records.
Sources and further reading
How a Signal worth attention is found
See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

