Fundamental Rights Impact Assessment (FRIA) Template
Purpose: Template for assessing the impact of high-risk AI agent systems on fundamental rights, as required by EU AI Act Article 27. Must be completed before deploying high-risk AI systems that affect individuals in the EU.
Deadline: EU AI Act high-risk provisions apply from August 2, 2026.
Who completes this: Deployers of high-risk AI systems. This template helps structure the assessment; organizations should engage legal counsel and rights experts for production deployments.
1. System Identification
| Field | Value |
| AI System Name | |
| Agent DID | did:agentmesh:... |
| Provider | |
| Deployer Organization | |
| EU AI Act Risk Classification | โ High-risk (Annex III) โ Other |
| Annex III Category | โ Biometrics โ Critical infrastructure โ Education โ Employment โ Essential services โ Law enforcement โ Migration โ Justice |
| Assessment Date | |
| Assessor(s) | |
| Data Protection Officer consulted | โ Yes โ No |
2. Purpose and Intended Use
2.1 Description of Purpose
What is the AI system designed to do? What decisions does it make or support?
2.2 Intended Use Context
In what context will the system be deployed? What processes does it integrate with?
2.3 Groups of Persons Affected
Who is directly or indirectly affected by the system's output?
| Group | How Affected | Estimated Scale |
| | |
3. Fundamental Rights Assessment
For each applicable right, assess the potential impact of the AI agent system.
3.1 Right to Human Dignity (EU Charter Art. 1)
| Question | Assessment |
| Can the system make decisions that affect a person's dignity? | โ Yes โ No |
| Is there a risk of dehumanizing or objectifying individuals? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
3.2 Right to Non-Discrimination (EU Charter Art. 21)
| Question | Assessment |
| Does the system process data related to protected characteristics? | โ Yes โ No |
| Has bias testing been performed? | โ Yes โ No |
| Has disparate impact analysis been conducted? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
3.3 Right to Privacy and Data Protection (EU Charter Art. 7-8)
| Question | Assessment |
| Does the system process personal data? | โ Yes โ No |
| Is a Data Protection Impact Assessment (DPIA) required? | โ Yes โ No |
| What is the legal basis for processing? | โ Consent โ Contract โ Legal obligation โ Legitimate interest |
| Are data minimization principles applied? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
3.4 Right to an Effective Remedy (EU Charter Art. 47)
| Question | Assessment |
| Can affected persons contest decisions made by the system? | โ Yes โ No |
| Is there a human review mechanism for automated decisions? | โ Yes โ No |
| Is there a complaint procedure? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
3.5 Freedom of Expression (EU Charter Art. 11)
| Question | Assessment |
| Does the system filter, moderate, or restrict content? | โ Yes โ No |
| Could the system have a chilling effect on expression? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
3.6 Right to Education (EU Charter Art. 14)
| Question | Assessment |
| Does the system affect access to education? | โ Yes โ No |
| Are admissions, grading, or assessment decisions involved? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
3.7 Workers' Rights (EU Charter Art. 31)
| Question | Assessment |
| Does the system monitor or evaluate workers? | โ Yes โ No |
| Does it affect hiring, promotion, or termination decisions? | โ Yes โ No |
| Were workers' representatives consulted? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
3.8 Rights of the Child (EU Charter Art. 24)
| Question | Assessment |
| Could the system affect persons under 18? | โ Yes โ No |
| Are age-appropriate safeguards in place? | โ Yes โ No |
| Impact level | โ None โ Low โ Medium โ High |
| Mitigation measures | |
4. AGT Governance Controls Mapping
| Fundamental Right | AGT Control | Configuration |
| Non-discrimination | Advisory classifier (bias detection) | PatternAdvisory or CallbackAdvisory with fairness model |
| Privacy/Data protection | Attribute ratchets (sensitivity monotonic) | SessionState with monotonic: true |
| Effective remedy | Approval workflows (human-in-the-loop) | CallbackApproval or WebhookApproval |
| All rights | Tamper-evident audit trail | AuditLog with hash-chaining |
| All rights | Multi-stage policy pipeline | Pre-input โ pre-tool โ post-tool โ pre-output |
| All rights | OTel observability | enable_otel() for monitoring and accountability |
5. Overall Risk Assessment
| Dimension | Rating | Justification |
| Severity of potential impact | โ Low โ Medium โ High โ Very High | |
| Probability of impact | โ Low โ Medium โ High โ Very High | |
| Number of persons affected | โ Small โ Medium โ Large โ Very Large | |
| Reversibility of impact | โ Fully reversible โ Partially โ Irreversible | |
| Overall risk level | โ Acceptable โ Acceptable with mitigations โ Unacceptable | |
6. Mitigation Plan
| Risk Identified | Mitigation Measure | Implementation Status | Owner | Due Date |
| | โ Planned โ In progress โ Complete | | |
7. Consultation Record
| Stakeholder | Date | Key Findings | Actions Taken |
| Data Protection Officer | | | |
| Workers' representatives | | | |
| Affected communities | | | |
| Legal counsel | | | |
8. Sign-Off
| Role | Name | Date | Signature |
| Assessment Lead | | | |
| Data Protection Officer | | | |
| Legal/Compliance | | | |
| Senior Management | | | |
9. Review and Update
- This assessment must be updated when:
- The AI system is significantly modified
- New risks are identified
- The intended use changes
- Relevant regulations change
- Minimum review frequency: Annually
- Retention: Lifetime of the AI system + 5 years (per retention policy)
Legal Note: This template provides a structured framework for FRIA. It does not constitute legal advice. Organizations should consult qualified legal counsel to ensure compliance with the EU AI Act and applicable national implementing laws.
Related: EU AI Act Checklist ยท Impact Assessment Template ยท NIST AI RMF Alignment ยท Record Retention Policy