Chapter III · High-risk AI systems
Article 27 — Fundamental rights impact assessment for high-risk AI systems
Official text
Each paragraph records where its wording comes from. Only text reproduced unchanged from the Official Journal is authentic; consolidated text is editorial and has no legal value. Paragraphs, subparagraphs and points each have their own link.
Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:
- (a)
a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;
- (b)
a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;
- (c)
the categories of natural persons and groups likely to be affected by its use in the specific context;
- (d)
the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;
- (e)
a description of the implementation of human oversight measures, according to the instructions for use;
- (f)
the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.
Authentic — as published in the Official Journal
The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.
Authentic — as published in the Official Journal
Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.
Authentic — as published in the Official Journal
If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment.
Consolidated text — no legal value · amended by Regulation (EU) 2026/1744
The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner. This template shall, where relevant, give deployers the possibility to include cross-references to the relevant sections of the data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment pursuant to paragraph 4.
Consolidated text — no legal value · amended by Regulation (EU) 2026/1744
The formal analysis of Article 27
Article 6 is formalised first. The remaining articles follow.
Article 27 is formalised node by node: each rule as a deontic position with its operator, each exception with its rank, each predicate resolved against the definitions in Article 3.
What members get, per article
- the rule logic: every norm as a formal position, with the defeater chain that decides which exception wins
- the competency questions and their answers, every unanswered one marked as a gap and named
- the ontology: predicates bound to AISV (AI Standardisation Vocabulary) and to the definitions they depend on, exportable as JSON-LD and OWL
- the documentation: the Article 6(4) assessment record generated from a fact set, with its derivation and the version of the law it was decided against
Built for providers claiming the 6(3) derogation, for the counsel who has to defend that claim, and for the auditor who reads it afterwards.
Access is invite-only and opening in stages. Article 6 is formalised first; the remaining articles follow.
No mail client? Write to hello@signatu.com
Already a member? Sign in
Commentary in preparation
The official text above is complete. The editorial layer for this article — duties, the roles bound by them, the AISV concepts that model them, and the European standards written to support them — is in preparation, in the same form as the articles already published.
See the published articles