
Blog Post
AI Governance for Public Bodies, and Who Shares the Obligation
September 24, 2026
A public body running a high-risk AI system owes a fundamental rights impact assessment under Article 27 before first use, with the results notified to a market surveillance authority. The obligation is real and it is not yet in force.
Regulation (EU) 2026/1744, in force since July 2026, deferred the section of the Act containing Article 27 to December 2027 for standalone high-risk systems and August 2028 for those embedded in regulated products. So the interesting question is no longer what the assessment requires. It is who will owe it, and that answer is wider than the phrase public sector suggests.
Who Owes the Assessment?
Four categories, and only the first is what people expect.
Public authorities and bodies deploying a high-risk system listed in the relevant annex. Private entities providing public services, which covers utilities, transport operators and healthcare providers regardless of ownership. Deployers evaluating creditworthiness or establishing a credit score for individuals, with fraud detection carved out. Deployers using AI for risk assessment and pricing in life and health insurance complete the set.
The Line Is Functional Rather Than Sectoral
A bank is a private commercial entity and owes the assessment for its credit scoring, because the obligation attaches to what the system decides rather than to who owns the organization. A public body owes it for what it is. Two different routes to the same requirement, and an organization checking whether it is in the public sector has asked the wrong question.
Why Isn't This Just a Stricter Version of a Privacy Assessment?
Because it asks a different question, and the relationship between the two is complementary rather than substitutive.

A data protection assessment examines processing and its effect on the individuals whose data is processed. The fundamental rights assessment examines the deployment and its effect on the people subject to the decisions, which is a wider population and a wider set of harms. Where an existing assessment already covers some elements, it can be built on rather than duplicated, and it does not discharge the obligation.
Which Element Has No Privacy Equivalent?
The complaint and redress mechanism. The assessment has to describe how a person affected by a decision can raise it and what happens next, which is an operational capability rather than a documentation exercise. A privacy assessment does not require establishing one, so an organization with a mature process on that side still has this to build.
What Has to Be in It?
Seven elements, and the balance of effort is uneven in a way worth planning around.
- Process and conditions of use: Where the system sits and how it is operated, which is straightforward where an inventory exists.
- Period and frequency of use: Also straightforward and frequently unrecorded.
- Categories of persons and groups affected: Harder, since it requires thinking about who is subject to the decision rather than who uses the system.
The remaining four carry the work. Specific risks of harm to fundamental rights, the human oversight measures in place, a mitigation plan, and the complaint and redress route. Those are assessments and commitments rather than descriptions, and they are where a thin assessment becomes visible.
What Happens After It Is Done?
It goes to a regulator, which is the structural difference from a privacy assessment and the part most likely to catch an organization out.

The deployer notifies the market surveillance authority of the results on completion. A privacy assessment is generally retained and produced on request, so a proactive notification is a different relationship. The receiving body is also not the data protection authority, so an organization with an established relationship on privacy is writing to a regulator it may never have contacted.
Which Authority Receives It?
The national market surveillance authority designated for AI purposes, and in sectors where a sectoral regulator already supervises, that regulator may hold the role. An organization deploying across several member states needs the answer per country, and the same mapping problem applies to the incident reporting route.
What About the Template?
Unsettled, and the deferral makes that less pressing than it was.
The notification is to be made using a template from the European AI Office, and its content and publication status remain unsettled. The deferral gives that machinery time to arrive, which was part of the stated reason for moving the dates, since harmonized standards and national supervisory capacity were not ready.
What Does That Argue For?
Conducting the assessment against the seven elements in the article rather than against a template. An assessment structured on the legal requirements can be transcribed into whatever form arrives, where one structured on a guessed format may need redoing, which storing observations rather than documents addresses as a general principle.
Is It a One-Time Exercise?
No, which matters more than it appears given how far out the date is.
The assessment covers first use and has to be updated where any of its elements change. A change in the process, the frequency of use, the population affected, the oversight arrangement or the mitigation plan triggers a revision, and several of those change without anybody framing it as a governance event. A system extended to a new population is the common case.
The Problem Is an Inventory Problem
Knowing that an element changed requires knowing what the elements were and noticing when the deployment moves. Organizations holding a current system inventory with recorded ownership find this a short exercise. Those without one find it a discovery project, and the assessment is where the absence of an inventory becomes expensive, which building the inventory is the prerequisite for.
What Does Notification Expose?
The assessment itself, on request, which changes how it should be written.
The notification tells the authority a completed assessment exists and the document has to be available for inspection. Several national authorities have indicated they expect these at volume and that the assessment will be an early item requested in any inquiry. So it functions as a document written for a supervisor rather than an internal record that happens to be disclosable.
Which Changes What Goes In It
An internal assessment can note an unresolved concern and leave it open. A supervisor-facing one listing a risk with no mitigation against it has documented an accepted exposure and dated the acceptance. Neither omitting the risk nor leaving it unmitigated is a good position, so the mitigation plan element carries more weight than its length suggests.
Does an Authority Respond?
It can, and planning for silence is unwise. Authorities may raise concerns after receiving a notification, which puts the deployer in a dialogue rather than at the end of a filing exercise. A deployment scheduled to begin on the assumption that notification closes the matter has assumed away the possibility of a question, and answering on somebody else's timeline is what that dialogue requires.
What Does the Deferral Change?
The date, and almost nothing else, which is the part organizations get wrong in both directions.
The requirements were not reduced, narrowed or made optional. The reason given for moving the dates was that harmonized standards, notified body capacity and national supervisory infrastructure were not ready, so the deferral addressed the machinery rather than the substance. An organization reading it as relief has read it as a reduction in what is owed rather than a change in when.
Which Argues for Using the Interval
The elements that take longest are the ones a deadline cannot compress. A complaint and redress route is an operational capability rather than a document. Identifying the categories of persons affected requires thinking nobody has done. A deployment record accurate enough to notice when an element changes also takes time to build, which maintaining that record sets out.
What Would Be Wasted Effort Now?
Anything shaped around the notification format, since the template does not exist and may look different when it arrives. Conducting the assessment against the elements in the article produces work that transcribes into whatever form appears, and building to a guessed layout produces work that may need redoing.
What Should Be Established First?
Three things, and the first frequently changes the answer to whether this applies at all.
Whether any deployed system falls into the four categories, checked against function rather than sector. For those that do, whether an existing privacy assessment covers part of the content and which elements it does not reach. Then which market surveillance authority receives the notification in each country of deployment. AI compliance readiness assessed per requirement is what shows how much of the seven elements existing records already answer.
Check the Function, Not the Sector
The fundamental rights assessment is described as a public sector obligation and reaches four categories, including private entities providing public services, credit scoring deployers and life and health insurance pricing. So a private commercial organization can owe it on the strength of what its system decides. It complements a privacy assessment rather than duplicating one, since it examines effects on the people subject to decisions rather than on the people whose data is processed, and the complaint and redress element has no privacy equivalent at all. It is notified proactively to a regulator that is not the data protection authority. It has to be updated whenever an element changes too, which makes it an inventory problem rather than a documentation one. Kovrr's AI Security and Governance Platform maintains the deployment record the assessment and its updates both draw on.
To see which of your AI deployments fall into the categories that owe an assessment, book a demo mapped to your own estate.
Fundamental Rights Assessment FAQs
Speak to an ExpertWho has to do a FRIA under the EU AI Act?
Four categories under Article 27. Public authorities and bodies deploying a high-risk system listed in Annex III. Private entities providing public services, covering utilities, transport operators and healthcare providers regardless of ownership. Deployers evaluating creditworthiness or establishing a credit score for individuals, with fraud detection carved out. And deployers using AI for risk assessment and pricing in life and health insurance. The line is functional rather than sectoral, so a private company can owe a FRIA.
Do banks and insurers need to do a FRIA?
Yes, where the deployment falls in scope, and this surprises organizations that read the fundamental rights impact assessment as a public sector requirement. Article 27 names deployers evaluating creditworthiness or establishing a credit score for individuals, excluding fraud detection, and deployers using AI for risk assessment and pricing in life and health insurance. A bank owes it because of what its system decides rather than because of what the bank is.
Is a FRIA the same as a GDPR DPIA?
No, and one does not discharge the other. A data protection impact assessment examines processing and its effect on the individuals whose data is processed, while a fundamental rights impact assessment examines the deployment and its effect on the people subject to the decisions, which is a wider population and a wider set of harms. Where a DPIA already covers some elements it can be built on rather than duplicated. The complaint and redress mechanism required by Article 27 has no DPIA equivalent at all.
When does Article 27 of the EU AI Act apply?
December 2027 for standalone high-risk systems under Annex III and August 2028 for high-risk AI embedded in regulated products under Annex I. Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferred Chapter III Sections 1 to 3 of the AI Act, which contains Article 27, from the original date of 2 August 2026. The requirements themselves were not changed, only the date on which they apply.
Does the Digital Omnibus remove the FRIA requirement?
No. Regulation (EU) 2026/1744 moved the date and left the substance intact, and the reason given was that harmonized standards, notified body capacity and national supervisory infrastructure were not ready rather than that the obligation was unnecessary. The elements that take longest are the ones a deadline cannot compress, including the complaint and redress route, which is an operational capability rather than a document.
Who do you submit a FRIA to?
The market surveillance authority in the member state, which is a different body from the data protection authority. Article 27 requires the deployer to notify the authority of the results on completion, using a template to be provided by the European AI Office, and that proactive notification is a structural difference from a DPIA that is generally retained and produced on request. An organization deploying across several member states needs the contact per country.




