HƯỚNG DẪN xã hội

Fundamental Rights Impact Assessment Under Article 27

Article 27 requires specified deployers to assess fundamental-rights impacts before first use of covered high-risk AI systems.

  • Đọc trong 3 phút
  • Cập nhật lần cuối
Trên trang nàyĐọc trong 3 phút
  1. Tổng quan
  2. Lặn sâu
  3. Tác động chiến lược
  4. The Future of Fundamental Rights Impact Assessment Under Article 27
  5. Triển khai trong thế giới thực
  6. Rủi ro & lan can
  7. Lộ trình thực hiện
  8. Tiếp tục khám phá
  9. Câu hỏi thường gặp

Tổng quan

The duty has defined organisation and system scopes, permits reuse or cross-reference of certain existing assessments, and requires notice to the market-surveillance authority subject to a statutory exception.

Lặn sâu

Article 27 of Regulation (EU) 2024/1689 establishes a fundamental-rights impact assessment (FRIA) for specified deployers of certain high-risk systems classified under Article 6(2) and Annex III. Before deployment, the duty applies to bodies governed by public law and private entities providing public services, except for systems intended for the Annex III point 2 area. It also applies to deployers of high-risk systems in Annex III points 5(b) and 5(c), covering creditworthiness assessment of natural persons and risk assessment or pricing in life and health insurance. These system-specific categories are not restricted to public bodies. The assessment describes the use process, intended period and frequency, the people and groups likely to be affected, likely harms in that context using provider information, how human oversight will work, and measures if risks materialise, including internal governance and complaint mechanisms. The duty applies to first use. A deployer may rely on prior FRIAs or provider assessments in similar cases, but must update information when a listed element changes or becomes out of date. After assessment, the deployer notifies the market-surveillance authority with the prescribed template; Article 46(1) can provide an exception to notification. A FRIA is distinct from a data-protection impact assessment (DPIA). If a GDPR or law-enforcement DPIA already meets some Article 27 obligations, the deployer may cross-reference those parts or include them. This prevents needless duplication but does not erase the FRIA’s distinct scope and content. As amended, Article 27 also directs the AI Office’s template to support such cross-referencing. The high-risk rules containing Article 27’s operational obligation apply on the delayed timetable: for Annex III Article 6(2) systems, from 2 December 2027 under Regulation 2026/1744.

Tác động chiến lược

Rủi ro và an toàn

Những tác hại thảm khốc và thường ngày của AI đều phụ thuộc vào việc ai hiểu được rủi ro và ai có thể hành động.

Quyết định rõ ràng hơn

Kiến thức công cộng và chuyên môn định hình liệu chính sách an toàn mạnh mẽ có khả thi về mặt chính trị hay không.

Phá vỡ sự thổi phồng

Những lời giải thích rõ ràng làm giảm sự thu hút bởi sự cường điệu, PR trong phòng thí nghiệm và sân khấu đạo đức mơ hồ.

The Future of Fundamental Rights Impact Assessment Under Article 27

The AI Office is to develop a questionnaire template, potentially through an automated tool, to simplify Article 27 compliance and support cross-references to DPIAs. That template facilitates the statutory duty; it does not change which deployers are in scope or turn the assessment into a general requirement for every AI use. Monitor official template publication and local market-surveillance processes. Deployer teams should check the final questionnaire and local notification channel before first use. Official implementation materials can make the process easier, but they cannot widen or remove Article 27’s statutory scope.

Triển khai trong thế giới thực

A public authority deploying an Annex III high-risk system for a public service documents affected groups, harms, human oversight and complaint arrangements before first use.

A private credit provider using an Annex III creditworthiness system assesses impacts even though it is not itself a public-service body.

A deployer reuses a similar prior assessment but updates it because the new context affects a different group.

A team cross-references relevant GDPR data-protection impact-assessment sections while separately completing the Article 27 assessment.

Rủi ro & lan can

  • Xử lý rủi ro hiện hữu như khoa học viễn tưởng trong khi khả năng lại phức tạp.

  • Nhầm lẫn giữa an toàn sản phẩm bề mặt với sự liên kết dưới quyền tự chủ cao.

  • Chỉ để lại những khán giả không phải người Anh và không có chuyên môn với những nguồn chất lượng thấp.

Lộ trình thực hiện

  1. Tách biệt các tác hại của sản phẩm, sử dụng sai và rủi ro mất kiểm soát/sai lệch.

  2. Hỏi bằng chứng nào sẽ thay đổi quan điểm của bạn về thời gian và mức độ nghiêm trọng.

  3. Ưu tiên các nguồn chính và đánh giá cụ thể hơn các tuyên bố tiếp thị.

  4. Xác định một lộ trình hành động: sự nghiệp, chính sách, nguồn tài trợ hoặc kỹ năng - không chỉ là nhận thức.

Tiếp tục khám phá

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Fundamental Rights Impact Assessment Under Article 27 quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Bắt đầu bài kiểm tra

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Câu hỏi thường gặp

What is Fundamental Rights Impact Assessment Under Article 27?

Article 27 requires specified deployers to assess fundamental-rights impacts before first use of covered high-risk AI systems. The duty has defined organisation and system scopes, permits reuse or cross-reference of certain existing assessments, and requires notice to the market-surveillance authority subject to a statutory exception.

Which deployer is within Article 27’s public-service scope route?

Article 27 covers public-law bodies and private entities providing public services, with a stated exception for Annex III point 2 systems.

Which use categories can trigger Article 27 regardless of whether the deployer is a public-service body?

Article 27 separately covers Annex III points 5(b) and 5(c).

When must an in-scope deployer complete the assessment?

Article 27 requires assessment prior to deploying and says the obligation applies to first use.

Which item belongs in the Article 27 assessment?

The assessment identifies affected groups and likely harms in the specific use context.

What must the assessment say about mitigation and governance?

Article 27 lists response measures, governance arrangements and complaint mechanisms.