Skip to content

Fundamental Rights Impact Assessment (FRIA) Template

Purpose: Template for assessing the impact of high-risk AI agent systems on fundamental rights, as required by EU AI Act Article 27. Must be completed before deploying high-risk AI systems that affect individuals in the EU.

Deadline: EU AI Act high-risk provisions apply from August 2, 2026.

Who completes this: Deployers of high-risk AI systems. This template helps structure the assessment; organizations should engage legal counsel and rights experts for production deployments.


1. System Identification

Field Value
AI System Name
Agent DID did:agentmesh:...
Provider
Deployer Organization
EU AI Act Risk Classification โ˜ High-risk (Annex III) โ˜ Other
Annex III Category โ˜ Biometrics โ˜ Critical infrastructure โ˜ Education โ˜ Employment โ˜ Essential services โ˜ Law enforcement โ˜ Migration โ˜ Justice
Assessment Date
Assessor(s)
Data Protection Officer consulted โ˜ Yes โ˜ No

2. Purpose and Intended Use

2.1 Description of Purpose

What is the AI system designed to do? What decisions does it make or support?

2.2 Intended Use Context

In what context will the system be deployed? What processes does it integrate with?

2.3 Groups of Persons Affected

Who is directly or indirectly affected by the system's output?

Group How Affected Estimated Scale

3. Fundamental Rights Assessment

For each applicable right, assess the potential impact of the AI agent system.

3.1 Right to Human Dignity (EU Charter Art. 1)

Question Assessment
Can the system make decisions that affect a person's dignity? โ˜ Yes โ˜ No
Is there a risk of dehumanizing or objectifying individuals? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

3.2 Right to Non-Discrimination (EU Charter Art. 21)

Question Assessment
Does the system process data related to protected characteristics? โ˜ Yes โ˜ No
Has bias testing been performed? โ˜ Yes โ˜ No
Has disparate impact analysis been conducted? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

3.3 Right to Privacy and Data Protection (EU Charter Art. 7-8)

Question Assessment
Does the system process personal data? โ˜ Yes โ˜ No
Is a Data Protection Impact Assessment (DPIA) required? โ˜ Yes โ˜ No
What is the legal basis for processing? โ˜ Consent โ˜ Contract โ˜ Legal obligation โ˜ Legitimate interest
Are data minimization principles applied? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

3.4 Right to an Effective Remedy (EU Charter Art. 47)

Question Assessment
Can affected persons contest decisions made by the system? โ˜ Yes โ˜ No
Is there a human review mechanism for automated decisions? โ˜ Yes โ˜ No
Is there a complaint procedure? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

3.5 Freedom of Expression (EU Charter Art. 11)

Question Assessment
Does the system filter, moderate, or restrict content? โ˜ Yes โ˜ No
Could the system have a chilling effect on expression? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

3.6 Right to Education (EU Charter Art. 14)

Question Assessment
Does the system affect access to education? โ˜ Yes โ˜ No
Are admissions, grading, or assessment decisions involved? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

3.7 Workers' Rights (EU Charter Art. 31)

Question Assessment
Does the system monitor or evaluate workers? โ˜ Yes โ˜ No
Does it affect hiring, promotion, or termination decisions? โ˜ Yes โ˜ No
Were workers' representatives consulted? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

3.8 Rights of the Child (EU Charter Art. 24)

Question Assessment
Could the system affect persons under 18? โ˜ Yes โ˜ No
Are age-appropriate safeguards in place? โ˜ Yes โ˜ No
Impact level โ˜ None โ˜ Low โ˜ Medium โ˜ High
Mitigation measures

4. AGT Governance Controls Mapping

Fundamental Right AGT Control Configuration
Non-discrimination Advisory classifier (bias detection) PatternAdvisory or CallbackAdvisory with fairness model
Privacy/Data protection Attribute ratchets (sensitivity monotonic) SessionState with monotonic: true
Effective remedy Approval workflows (human-in-the-loop) CallbackApproval or WebhookApproval
All rights Tamper-evident audit trail AuditLog with hash-chaining
All rights Multi-stage policy pipeline Pre-input โ†’ pre-tool โ†’ post-tool โ†’ pre-output
All rights OTel observability enable_otel() for monitoring and accountability

5. Overall Risk Assessment

Dimension Rating Justification
Severity of potential impact โ˜ Low โ˜ Medium โ˜ High โ˜ Very High
Probability of impact โ˜ Low โ˜ Medium โ˜ High โ˜ Very High
Number of persons affected โ˜ Small โ˜ Medium โ˜ Large โ˜ Very Large
Reversibility of impact โ˜ Fully reversible โ˜ Partially โ˜ Irreversible
Overall risk level โ˜ Acceptable โ˜ Acceptable with mitigations โ˜ Unacceptable

6. Mitigation Plan

Risk Identified Mitigation Measure Implementation Status Owner Due Date
โ˜ Planned โ˜ In progress โ˜ Complete

7. Consultation Record

Stakeholder Date Key Findings Actions Taken
Data Protection Officer
Workers' representatives
Affected communities
Legal counsel

8. Sign-Off

Role Name Date Signature
Assessment Lead
Data Protection Officer
Legal/Compliance
Senior Management

9. Review and Update

  • This assessment must be updated when:
  • The AI system is significantly modified
  • New risks are identified
  • The intended use changes
  • Relevant regulations change
  • Minimum review frequency: Annually
  • Retention: Lifetime of the AI system + 5 years (per retention policy)

Legal Note: This template provides a structured framework for FRIA. It does not constitute legal advice. Organizations should consult qualified legal counsel to ensure compliance with the EU AI Act and applicable national implementing laws.

Related: EU AI Act Checklist ยท Impact Assessment Template ยท NIST AI RMF Alignment ยท Record Retention Policy