European Authorities to Vet Fundamental Rights Before Deploying High‐Risk AI

News
Tuesday, 18 August 2026 at 07:00
Nederlandse overheden moeten straks grondrechten toetsen vóór inzet van risicovolle AI
Dutch public authorities and certain public service providers will soon have to assess how a high‑risk AI system could affect people’s fundamental rights before rolling it out. To prepare, the Dutch Data Protection Authority is launching a pilot for the new Fundamental Rights Impact Assessment, better known as the FRIA.
FRIA stands for Fundamental Rights Impact Assessment. It’s required under Article 27 of the European AI Act and must be completed before an organization uses an applicable high‑risk AI system for the first time.
According to the Dutch Data Protection Authority, the obligation will apply from December 2027. Organizations can already sign up for a voluntary pilot to test the European reporting model.
Registration is open until 21 September 2026. The pilot starts in early October.

Not every company needs a FRIA

A FRIA is not a blanket requirement for anyone using ChatGPT, Copilot, or another AI tool.
Article 27 mainly targets:
  • public bodies, such as governments and executive agencies;
  • private organizations delivering a public service;
  • organizations that deploy AI to assess risk or set prices for life and health insurance.
Even within these groups, it must involve a high‑risk AI system as defined in the relevant sections of the AI Act.
For example, a municipality using AI to evaluate welfare benefits may be covered. The same could apply to a lender using an AI system to decide whether someone gets a loan.
A marketing agency using ChatGPT to draft a newsletter does not need to perform a FRIA for that use.

What must the assessment include?

Beforehand, the organization must describe where and how the AI system will be used. This should capture, among other things:
  • the business process and purpose the system serves;
  • how long and how often it is used;
  • which individuals and groups are affected;
  • which fundamental rights may be at risk;
  • what human oversight is in place;
  • what measures will be taken if risks materialize;
  • how people can challenge a decision or file a complaint.
Fundamental rights go beyond privacy alone. An AI system can affect equal treatment, access to public services, freedom of expression, social security, or the right to a fair decision.
A benefits scoring model can work technically well yet still systematically disadvantage certain groups. The FRIA is meant to surface such risks before the system impacts people.
Once completed, results must be submitted to the competent market regulator using the European reporting model. If the system or its use changes materially, the assessment must be updated.

FRIA is not the same as a DPIA

Many organizations already know the Data Protection Impact Assessment under the GDPR. A DPIA examines privacy risks in personal data processing.
A FRIA looks broader. It covers the potential impact of an AI system on all relevant fundamental rights.
The two assessments can overlap and may be conducted together. However, having a DPIA does not automatically mean a FRIA is unnecessary. Any gaps not covered by the DPIA must be filled.

Regulator seeks pilot participants

With the pilot, the authority wants to test whether the European reporting model is clear and usable in practice. Participants will perform a trial assessment and provide feedback on the model and its documentation.
Participation in the pilot is voluntary. The future legal FRIA for organizations covered by Article 27 is not.
Organizations using AI to serve the public can use the pilot to identify now:
  • which AI systems they actually use;
  • which applications may count as high risk;
  • who is responsible internally;
  • which groups are affected by the system;
  • what information must be requested from vendors;
  • how to organize human oversight and a complaints process.

Start with an AI registry

A smart first step is to create a registry of all AI systems in use. That includes not only standalone tools, but also AI features quietly added by vendors to existing software.
Then, for each system, determine its purpose, what data it uses, and whether its decisions affect people.
The FRIA aligns with other obligations under the European AI Act. Organizations must provide risk management, documentation, human oversight, and sufficient AI literacy among staff.
December 2027 may seem far off. But for large organizations, simply mapping systems, processes, vendors, and responsibilities can take months. The regulator’s message is clear: don’t wait until the last minute to prepare.
loading

Loading