Human oversight (Art. 14): not a fig leaf
Deployers of high-risk systems must ensure real human oversight, exercised by qualified, trained personnel. “Real” specifically means: the overseeing person must understand the system's capabilities and limits, be able to recognise signs of malfunction, correctly interpret the output, be able to deliberately decide against the system's recommendation in justified cases – and have the ability to interrupt or stop the system. A person who merely rubber-stamps decisions without those abilities doesn't satisfy this requirement.
The fundamental rights impact assessment (Art. 27): when it's mandatory
A fundamental rights impact assessment (FRIA) isn't mandatory for every deployer of a high-risk system – it mainly applies to public bodies and to private deployers providing certain public services, or those using systems for creditworthiness assessment or risk assessment in life and health insurance. Important in practice: the duty arises upon the FIRST use of a specific high-risk system, not for every individual use – and a deployer can rely on its own earlier assessments in comparable cases, or on an assessment already provided by the provider, instead of starting from scratch.
The six mandatory elements in detail
- Process description: exactly what the system is used for, and which process it's embedded in.
- Period and frequency of use: how often and over what period the system is actually used.
- Affected groups of people: who is concretely affected by the system's decisions.
- Specific risks of harm: what concrete fundamental-rights risks exist for those groups.
- Human oversight measures: how the oversight from Art. 14 is organised in this specific case.
- Risk mitigation concepts: what measures concretely reduce the identified risks.
Practice section: building a first FRIA
In practice, it's worth not treating the FRIA as a completely new exercise: anyone who has already carried out a GDPR data protection impact assessment (DPIA) for a similar system can reuse large parts of the structure – affected groups, risks, safeguards – and add the AI-Act-specific elements. Responsibility usually sits with the same function that already owns data protection impact assessments (a data protection officer or a comparable compliance function), supplemented with technical expertise on the specific system. Important: document once at first use, not freshly for every individual case – but revise it once the purpose or the affected groups change substantially. This classification doesn't replace case-by-case legal advice.