Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · EU AI Act: high-risk AI

Fundamental rights impact assessment (AI Act)

Also known as: FRIA, fundamental rights impact assessment

Under the EU AI Act, a fundamental rights impact assessment (FRIA) is an assessment that certain deployers of high-risk AI systems must carry out before first use, describing how the system will be used, who may be affected, the specific risks of harm and the measures taken to mitigate them.

  • AI regulation
  • EU

In one sentence

A FRIA (Art. 27 AI Act) is the assessment public bodies and certain deployers must carry out before first using a high-risk AI system.

Example

A city administration using an AI system to assess eligibility for social benefits documents the affected groups, risks of wrongful denial and the human review process before going live.

How it applies

  • Who: Bodies governed by public law, private entities providing public services, and deployers of AI systems for credit scoring and for risk assessment and pricing in life and health insurance.
  • Contents: The deployer's processes in which the system is used, period and frequency of use, categories of people affected, specific risks of harm, human oversight measures, and measures to take if risks materialize — including internal governance and complaint mechanisms.
  • Notification: The results are notified to the market surveillance authority, using a template from the AI Office. Where a data protection impact assessment under the GDPR already covers some points, the two complement each other.
  • Technical documentation: The deployer relies on the provider's instructions for use for much of the input — another reason to state limitations and performance for different groups clearly.

Compared with the USA, Canada and China

Canada's Algorithmic Impact Assessment is the closest counterpart: federal institutions must complete it before deploying an automated decision system, and publish the results. Colorado's original AI Act required impact assessments from deployers, but its replacement dropped them. China requires a self-assessment of security as part of the algorithm filing, focused on content and public-opinion risks.