The FRIA in EU AI Act: Governance, Rights, and Global Jurisdiction

The Chair AI Regulation is pleased to share information about a new paper titled ‘The FRIA in EU AI Act: Governance, Rights, and Global Jurisdiction’ by its research fellow, Dr. Theodoros Karathanasis, and published at the Journal Law, Innovation and Technology.

Abstract

The Fundamental Right Impact Assessment (FRIA) under the EU AI Act presents a critical yet problematic mechanism for mitigating AI’s harms on fundamental rights. This article conducts an in-depth analysis of FRIA’s multifaceted components and its relationship with existing assessments like the Data Protection Impact Assessment (DPIA), highlighting its broader scope covering non-personal data scenarios and focusing on ‘interferences’ rather than solely ‘damages’. The most significant result is the EU’s expansive jurisdictional assertion, rooted in ‘territorializing’ extraterritorial obligations and the ‘effects doctrine,’ wherein FRIA functions as a direct manifestation of internal due diligence to protect human rights globally. This signifies a normative shift from traditional physical territory to a framework, aiming to diffuse EU rights-based standards universally despite challenges like sovereignty conflicts and AI’s black box nature.

Brief:

The EU AI Act’s Fundamental Rights Impact Assessment (FRIA) is meant to be one of the Act’s most important safeguards — a mechanism requiring certain deployers to assess how high-risk AI systems could affect fundamental rights before those systems go live. But as my recently published article explores, turning that ambition into practice is far from straightforward.

At its core, FRIA asks deployers to map out who might be affected by an AI system, identify specific risks to their rights, and put oversight and mitigation measures in place. What sets it apart from the GDPR’s more familiar Data Protection Impact Assessment is its scope: FRIA is concerned with “interferences” with rights, not just quantifiable “damages,” which means it applies even in cases involving no personal data at all — think AI-driven surveillance affecting freedom of assembly, or systems shaping societal trust more broadly.

The article is candid about the obstacles ahead. Many organisations still lack the expertise to assess rights beyond data protection and non-discrimination, there’s no agreed methodology for measuring impact across the full spectrum of fundamental rights, stakeholder participation remains weakly required, and enforcement is left to a patchwork of national penalty regimes — a recipe for uneven protection across the EU.

The most striking argument, though, is about reach. I make the case that FRIA reflects a broader EU strategy of “territorializing” its extraterritorial human rights obligations — using the effects doctrine to project rights-based standards onto AI systems well beyond its borders, regardless of where they’re built or hosted. It’s part of a larger story about how digital regulation is reshaping what “territory” even means for jurisdiction.

Since the article was accepted, the landscape has kept moving: the Digital Omnibus has pushed back the FRIA’s application date to December 2027 (and August 2028 for embedded systems), introduced mandatory cross-referencing between FRIA and DPIA, and — notably — FRIA survived industry pressure to have it scrapped entirely. That survival, I argue, says something about how much normative weight the mechanism has already acquired.

The article closes by setting out a research agenda: testing emerging assessment methodologies, tracking the FRIA/DPIA relationship in practice, comparing enforcement across Member States, and testing empirically whether FRIA becomes a genuine global standard for AI governance or remains a distinctly European experiment.

CiteKarathanasis, T. (2026). The FRIA in EU AI Act: governance, rights, and global jurisdiction. Law, Innovation and Technology, 1–24. https://doi.org/10.1080/17579961.2026.2710952

An earlier and accessible version of this article can be found here.

These statements are attributable only to the author, and their publication here does not necessarily reflect the view of the other members of the AI-Regulation Chair or any partner organizations.

This work has been partially supported by MIAI @ Grenoble Alpes, (ANR-19-P3IA-0003) and by the Interdisciplinary Project on Privacy (IPoP) commissioned by the Cybersecurity PEPR (ANR 22-PECY-0002 IPOP).

Like this article?
Share on Facebook
Share on Twitter
Share on Linkdin
Share by Email