Article 27 Fundamental Rights Impact Assessments for Public Bodies

Article 27 of the EU AI Act is the most demanding provision for deployers. It requires public authorities using high-risk AI systems to conduct a fundamental rights impact assessment (FRIA) before the system goes live and to update that assessment periodically. Unlike providers who must build technical conformity evidence, deployers, specifically public bodies, must evaluate whether the system respects fundamental human rights. This is not a compliance checkbox; it is a substantive examination of whether the AI system interferes with privacy, freedom of expression, equality or other protected rights.

A fundamental rights impact assessment for a public authority is an analytical document that identifies the AI system’s purpose, examines which fundamental rights could be affected, explains what mitigation measures are in place and concludes whether the deployment is justified. A local authority deploying an AI system to assign social housing prioritises, for example, must assess whether the system treats applicants fairly regardless of ethnic background or disability status. A police force deploying a facial recognition system must assess privacy impacts and the risk of misidentification. A benefits administration authority deploying an AI eligibility assessment must assess whether the system correctly understands rights and vulnerable people are not wrongly excluded.

Structure of a fundamental rights impact assessment

A well-structured fundamental rights impact assessment begins by clearly stating the scope: what AI system is being deployed, what decisions does it make, and who is affected. The assessment identifies relevant fundamental rights for the specific use case. For a housing allocation system, relevant rights include fair access to housing, non-discrimination and privacy. For a benefits system, relevant rights include social security entitlements and equal treatment.

The assessment then examines how the system could interfere with each identified right. If the system relies on historical data that reflects past discrimination, does the system perpetuate that discrimination? Could the system’s decisions suppress freedom of expression, deny fair employment, or violate privacy by collecting unnecessary personal data? These questions ground the assessment in specific harms rather than generic risk concerns.

Next, the assessment describes mitigation measures that would reduce or eliminate identified risks. For a housing system that might disadvantage certain ethnic groups, mitigations could include human review of all automatic denials, regular audit of outcomes by ethnicity, and adjustment of model features that encode proxy discrimination. The assessment then documents how those mitigations are implemented, who is responsible for them and how they are monitored. Clear governance with assigned accountability ensures mitigations actually work rather than remaining theoretical. Finally, the assessment reaches a conclusion about whether the deployment is justified given the risks and mitigations.

Evidence and documentation

A fundamental rights impact assessment is not speculative. It must be grounded in evidence about the system’s actual behaviour. A public authority should test the AI system on data reflecting the affected population, measure whether outcomes differ by protected characteristics and document the findings. If the system makes loan eligibility decisions, test it on applications from different demographic groups and compare approval rates. If the system makes asylum decisions, test it on applications reflecting different case profiles and measure consistency and fairness.

Testing can reveal bias, but bias alone does not mean the system is unusable. A system that shows lower accuracy for one group might still be more fair than the prior human process. The assessment must compare the system’s performance against the baseline of what would happen without the AI system. If the baseline is ad hoc, inconsistent human decision-making, even an imperfect AI system might be fairer.

Lesson concept diagram

Updating and review

A fundamental rights impact assessment is not a one-time exercise. Article 27 requires periodic updating, typically annually or whenever the system materially changes. Deployers must monitor how the system behaves in practice, whether unintended impacts emerge, and whether the mitigation measures remain effective. If the system is fed new data or retrained on new data, the assessment must be updated to examine impacts in the new context.

Remediation and rebalancing

If a fundamental rights impact assessment reveals that a proposed system poses unacceptable risks to fundamental rights, public authorities must not deploy the system as originally planned. Instead, they must redesign the system or its deployment to mitigate the risks. Examples of mitigations might include excluding high-risk decisions from the AI system’s scope, adding mandatory human review for all automated recommendations, implementing regular audits of outcomes by protected characteristics, or improving the quality of training data used to build the system.

Some jurisdictions have published guidance on impact assessment format and rigour. Public authorities should consult this guidance and, where available, engage with regulators or oversight bodies during the assessment process. Early engagement can prevent spending resources on designs that will not pass scrutiny.

Public authority accountability

Public bodies are accountable for their fundamental rights impact assessments both to their governing bodies and to affected members of the public. Some jurisdictions may require public authorities to publish impact assessments or summaries of them. Even where not required, transparency builds public trust. A housing authority that publishes its assessment of an AI allocation system and explains the safeguards demonstrates accountability and reduces the risk of later public backlash when the system is deployed.