Guide · Roles · Article 27

Who must do a fundamental rights impact assessment under Article 27 of the EU AI Act?

Three kinds of deployer must do one before they first use a high-risk AI system listed in Annex III: bodies governed by public law, private entities providing public services and deployers of the creditworthiness and life and health insurance systems in points 5(b) and (c) of Annex III (Article 27(1)). Systems intended to be used in the area listed in point 2 of Annex III, critical infrastructure, are excepted. The duty applies from 2 December 2027 (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744).

Written and last checked 9 October 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Article 27(4) and (5) were replaced; Article 27(1) to (3) were not amended.

The short answer

  • Who: bodies governed by public law, private entities providing public services and deployers of point 5(b) or (c) systems, before using a high-risk system referred to in Article 6(2) outside point 2 of Annex III (Article 27(1)).
  • What: six points, from the processes the system is used in to the measures if its risks materialise (Article 27(1)).
  • When: before first use, updated when you consider any point has changed or is no longer up to date (Article 27(2)); from 2 December 2027 (Article 113, third paragraph, point (c), as replaced).
  • Then: notify the market surveillance authority of the results with the filled-out template; in the case referred to in Article 46(1), deployers may be exempt (Article 27(3)).
  • The DPIA: where it already meets an obligation, you may cross-refer to it or include relevant parts of it in the assessment (Article 27(4), as replaced).

Who has to do one?

Article 27(1) names three kinds of deployer. Two are defined by what the deployer is, bodies governed by public law and private entities providing public services, and they owe it for every high-risk system referred to in Article 6(2), less the exception below. The third is defined by the system, whoever deploys it: point 5(b) of Annex III, "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud", and point 5(c), "AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance". The fintech guide sorts lending and insurance tools against those points.

In every case the system must be high-risk. An Annex III system that Article 6(3) takes out is not, and Article 6(3) never takes out one that performs profiling of natural persons. A system that is high-risk only under Article 6(1), the Annex I route, is outside Article 27, which refers to Article 6(2).

None of the three owes one for a system intended to be used in the area listed in point 2 of Annex III, "AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity".

The Regulation defines neither "bodies governed by public law" nor "private entities providing public services". Recital 96, an aid to reading and not an operative provision, links the second to "tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice".

What must the assessment contain?

Article 27(1) lists six points, each with its qualifier:

Points (d) and (e) draw on what the provider hands over: point (d) from the information given under Article 13, point (e) from the instructions for use, which Article 13(3), point (d) requires to contain the human oversight measures referred to in Article 14.

When is it done, and how often?

Before deploying: the obligation "applies to the first use of the high-risk AI system" (Article 27(2)). The deployer "may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider". If, during use, it "considers that any of the elements listed in paragraph 1 has changed or is no longer up to date", it takes the necessary steps to update the information.

Who receives the results?

The market surveillance authority. Once the assessment is performed, the deployer notifies it of the results, "submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification" (Article 27(3)). The same paragraph adds: "In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify." Under Article 46(1), by way of derogation from Article 43 and upon a duly justified request, a market surveillance authority "may authorise the placing on the market or the putting into service of specific high-risk AI systems within the territory of the Member State concerned, for exceptional reasons of public security or the protection of life and health of persons, environmental protection or the protection of key industrial and infrastructural assets", for "a limited period while the necessary conformity assessment procedures are being carried out". The exemption reaches the notification and not the assessment; Article 27(3) does not say who decides it.

The AI Office develops the template, "including through an automated tool" (Article 27(5)), and the replacement added: "This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment pursuant to paragraph 4." Article 27(5) sets no date for it, and this guide has not checked whether it has been published.

How does it fit with the data protection impact assessment?

Article 27(4) handles the overlap, and Regulation (EU) 2026/1744 replaced it. The condition is unchanged: an obligation in Article 27 "is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680". The consequence changed. The 2024 text said the fundamental rights impact assessment "shall complement that data protection impact assessment"; the replacement says the deployer "may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment". The DPIA can feed the assessment, and Article 27(1) still requires the assessment; the GDPR comparison covers the rest of the overlap.

When does Article 27 apply?

Article 27 is in Chapter III, Section 3, which Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744, applies from 2 December 2027 for systems classified as high-risk pursuant to Article 6(2) and Annex III. Its other date, 2 August 2028 for systems classified pursuant to Article 6(1) and Annex I, does not reach Article 27, which covers Article 6(2) systems only.

For a system placed on the market or put into service before the date of application of Chapter III, Article 111(2), as replaced, applies the Regulation to its operators "only if, as from that date, those systems are subject to significant changes in their designs", leaving aside the components of large-scale IT systems that Article 111(1) covers. In any case, under Article 111(2), "the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030". Two points stay open: Article 111(2) refers to "the date of application of Chapter III referred to in Article 113" in the singular, while Article 113 applies parts of Chapter III on different dates, and "public authorities" is not the phrase Article 27(1) uses.

What does Complipath do here, and what does it not?

The AI inventory records each system with its classification and the article behind it. Each duty that follows carries an owner, a status and a date, and evidence is linked with the passage and its page. The fundamental rights impact assessment is not supported. The step-by-step plan lists Article 27 as a step only for systems classified under points 5(b) and (c) of Annex III. Article 27(1) also binds deployers that are bodies governed by public law or private entities providing public services, and the product does not ask whether you are one. Nothing carries the assessment itself. What Complipath is has the full table.

What this means for you

If you're a provider: Article 27 binds deployers, but points (d) and (e) draw on your Article 13 information and instructions for use, and Article 27(2) lets a deployer rely, in similar cases, on your existing impact assessments. Use your own point 5(b) or (c) system under your own authority and you are its deployer too (Article 3, point (4)).

If you're a deployer: ask two questions per system before 2 December 2027. Is it high-risk under Article 6(2) and outside point 2 of Annex III? Are you a body governed by public law, a private entity providing public services or the deployer of a point 5(b) or (c) system? Two yeses put the assessment before first use, so ask the provider for the instructions for use now. Article 26 applies alongside it.

FAQ

Does a private company ever have to do a fundamental rights impact assessment? Yes. A private entity providing public services owes one for any Article 6(2) high-risk system outside point 2 of Annex III. So does any deployer of a point 5(b) system, creditworthiness or credit scores of natural persons except financial fraud detection, or a point 5(c) system, risk assessment and pricing for natural persons in life and health insurance (Article 27(1)).

Can our data protection impact assessment replace it? No: Article 27(1) still requires the assessment. Where an Article 27 obligation is already met through your DPIA under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, Article 27(4), as replaced by Regulation (EU) 2026/1744, lets you cross-refer to the relevant sections of that DPIA or include relevant parts of it in the assessment.

Can the provider do the assessment for us? No: Article 27(1) puts it on the deployer. Article 27(2) lets you rely, in similar cases, on previously conducted fundamental rights impact assessments or existing impact assessments carried out by the provider, and Article 27(1), point (d) takes account of the information the provider gives under Article 13. Notifying the market surveillance authority stays with you (Article 27(3)).

Do we have to send the assessment to anyone? Yes. You notify the market surveillance authority of its results, with the filled-out template the AI Office develops (Article 27(3) and (5)). In the case referred to in Article 46(1), a time-limited authorisation of a specific high-risk system by a market surveillance authority, by derogation from Article 43, for exceptional reasons that paragraph lists, deployers may be exempt from notifying.

Sources: Regulation (EU) 2024/1689 (EUR-Lex), Article 3, point (4), Article 6, Article 13(3), Article 14, Article 26, Article 27, Article 43, Article 46(1), Article 111, Article 113, Annex III and recital 96; as amended by Regulation (EU) 2026/1744 (EUR-Lex), which replaced Article 27(4) and (5), Article 111(2) and Article 113, third paragraph, point (c). Article 27(1) to (3) were not amended.

Where this question meets the product: EU AI Act compliance for SaaS companies and deployers. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextEU AI Act database registration (Article 49)Article 49 and Annex VIIIAm I a provider or a deployer?Article 3, points (3) and (4)What are the importer and distributor obligations under the EU AI Act?Articles 23 and 24

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free