In this article
- 01Introduction
- 02What Is an AI Impact Assessment, Actually?
- 03The Three (Main) Flavors, Compared
- 04Deep Dive: The EU's Fundamental Rights Impact Assessment
- 05Deep Dive: Canada's Algorithmic Impact Assessment
- 06How These Relate to DPIAs
- 07When Does Your Organization Actually Need One?
- 08Building an AI Impact Assessment Practice
Introduction
"We already do a DPIA, so we're covered" is one of the more common, and increasingly incorrect, assumptions organizations make about AI compliance. AI impact assessments aren't a single, interchangeable requirement, they're a family of related but legally distinct instruments, each triggered by different circumstances and each assessing a different kind of risk. Getting the terminology right matters, because assuming one type of assessment covers the requirements of another is exactly how compliance gaps happen. This guide breaks down the major frameworks, what each actually requires, and how to figure out which one, if any, applies to your organization.
What Is an AI Impact Assessment, Actually?
At its core, an AI impact assessment is a structured process for identifying, evaluating, and mitigating the potential effects of an AI system before or during its deployment. Depending on the specific framework, "effects" can mean data protection risk, fundamental rights impact, discriminatory outcomes, or broader societal harm. The shared goal across all versions is the same: force a deliberate evaluation before deployment, rather than discovering problems after the system is already affecting real people.
The Three (Main) Flavors, Compared
Three types of AI impact assessment
FRIA
EU AI Act, Art. 27
- Triggered by
- Deploying a high-risk AI system
- Scope
- All fundamental rights in the EU Charter
- Applies to
- Certain deployers (public bodies, public service providers, some credit and insurance uses)
- Binding?
- Yes, with regulatory notification required
- Penalties
- Significant financial penalties under the AI Act
AIA
Canada
- Triggered by
- Deploying an automated decision system in the federal government
- Scope
- Impact to rights, health, and economic interests
- Applies to
- Government of Canada institutions
- Binding?
- Yes, internal government policy
- Penalties
- None; internal governance consequences only
DPIA
GDPR, Art. 35
- Triggered by
- High-risk processing of personal data
- Scope
- Data protection and privacy specifically
- Applies to
- Any organization subject to GDPR
- Binding?
- Yes, legally binding under GDPR
- Penalties
- GDPR fines apply
Deep Dive: The EU's Fundamental Rights Impact Assessment
Article 27 of the EU AI Act requires certain deployers, public sector bodies, private entities providing public services, and deployers using high-risk AI for credit scoring or life and health insurance risk assessment, to complete a FRIA before putting a high-risk AI system into use.
What a FRIA actually covers
Descriptive section
The system's intended purpose, the processes it will be used in, timeframes and frequency of use, and the individuals or groups it may affect.
Assessment section
The specific risks of harm likely to affect identified individuals or groups, considering the provider's instructions for use.
Mitigation section
Human oversight measures, governance structures, and mechanisms for affected individuals to raise complaints or seek remedy.
A critical, very recent update: many compliance timelines were built around an August 2, 2026 deadline for standalone high-risk AI systems under Annex III. That date has moved. The EU's Digital Omnibus on AI, first proposed by the European Commission in November 2025 to address delays in implementation infrastructure, received European Parliament endorsement on June 16, 2026, and final Council approval on June 29, 2026. The result: standalone high-risk AI systems now have until December 2, 2027, a 16-month deferral, while AI embedded in regulated products under Annex I has until August 2, 2028. The FRIA obligation under Article 27 itself is unchanged in substance, only the timeline moved.
Deep Dive: Canada's Algorithmic Impact Assessment
Canada's AIA, in effect since April 2019 under the Directive on Automated Decision-Making, is one of the earliest formal government AI governance frameworks in the world. It's a mandatory, publicly available questionnaire, 65 risk questions and 41 mitigation questions, that Government of Canada institutions must complete before deploying an automated decision system.
Canada's AIA impact levels
Little to no impact
Not required
Moderate impact
Not required
High impact
Specific human intervention points required
Very high impact
Final decision must be made by a human
Unlike the EU's FRIA, there's no way to "fail" Canada's AIA outright, and no financial or criminal penalties attach to it, since it's an internal government policy instrument rather than binding legislation with enforcement teeth. Level IV requirements are deliberately demanding, though, specifically designed to discourage deploying very high-risk automated systems without serious justification and oversight.
How These Relate to DPIAs
Where a FRIA and Canada's AIA both look broadly at rights and societal impact, a Data Protection Impact Assessment under GDPR Article 35 stays narrower: it evaluates specifically whether personal data processing is lawful, proportionate, and adequately protected. An AI system that doesn't process personal data at all, a purely industrial optimization model, for example, may still require a FRIA under the EU AI Act if it's high-risk, but wouldn't trigger a DPIA at all. The two aren't substitutes for each other, and the EU AI Act explicitly allows combining both where an AI system processes personal data, rather than duplicating the work twice. Where the data itself sits matters too, which is the separate question of data sovereignty.
When Does Your Organization Actually Need One?
Do you need an AI impact assessment?
- 01Are you deploying, not just building, an AI system that falls into a high-risk category under a relevant regulation (EU AI Act Annex III, sector-specific rules, etc.)?
- 02Is your organization a public sector body, or providing services on behalf of one?
- 03Does the AI system make or materially influence decisions affecting individuals (credit, employment, benefits, insurance, legal outcomes)?
- 04Does the system process personal data in a way that would independently trigger a DPIA requirement?
- 05Even without a legal trigger, would a structured pre-deployment review meaningfully reduce your organization's risk exposure?
If the answer to any of the regulatory questions is yes, a specific, named assessment likely applies, and getting the right one matters more than doing "an assessment" generically. The same discipline applies to tools nobody formally approved, which is the governance problem behind shadow AI.
Building an AI Impact Assessment Practice
Building the practice
- 01Don't assume one assessment type covers another; map which specific instrument (FRIA, DPIA, sector-specific requirement, or none legally required) actually applies before starting.
- 02Build assessments into the deployment process itself, not as an afterthought once a system is already in production.
- 03Where no legal mandate exists, consider adopting a voluntary framework such as NIST's AI Risk Management Framework or ISO 42001 as a structured starting point.
- 04Assign clear ownership. Under most frameworks, responsibility sits with whoever is deploying the system, not necessarily whoever built it.
- 05Treat assessments as living documents. Both the FRIA and Canada's AIA require updates when the system's use, scope, or functionality changes materially.
Regionally, the same logic is already visible in Qatar's National AI Strategy and the ethics and public policy pillar underpinning it.
Sources
- European Union, EU AI Act, Article 27, Fundamental Rights Impact Assessment (eur-lex.europa.eu)
- Freshfields, Gibson Dunn, DLA Piper, legal coverage of the Digital Omnibus on AI final adoption, June 2026
- Government of Canada, Treasury Board of Canada Secretariat, Directive on Automated Decision-Making and Algorithmic Impact Assessment tool (canada.ca)
- GDPR, Article 35, Data Protection Impact Assessment
This article reflects publicly available regulatory information as of July 2026. AI regulation is changing quickly, as this article's own central example shows, verify current deadlines and requirements with qualified legal counsel before making compliance decisions.
Frequently Asked Questions
What is an AI impact assessment?+
A structured process for identifying, evaluating, and mitigating the potential effects of an AI system before or during deployment. The term covers several legally distinct instruments, including the FRIA, AIA, and DPIA, each with different triggers and scope.
What's the difference between a FRIA and a DPIA?+
A DPIA focuses specifically on data protection risk triggered by high-risk personal data processing. A FRIA covers the full range of fundamental rights, is triggered by high-risk AI deployment, and applies regardless of whether personal data is involved.
Does the EU AI Act's high-risk deadline still apply in 2026?+
The original August 2, 2026 deadline was deferred. Following final approval of the Digital Omnibus on AI on June 29, 2026, standalone high-risk AI systems now have until December 2, 2027.
What is Canada's Algorithmic Impact Assessment?+
A mandatory questionnaire, in effect since 2019, that Government of Canada institutions must complete before deploying an automated decision system, scoring it into one of four impact levels with proportionally scaled requirements.
Does my organization need an AI impact assessment if we're not in the EU or Canada?+
Legal requirements vary by jurisdiction and sector. Even without a legal mandate, a voluntary assessment using frameworks like NIST's AI RMF or ISO 42001 is considered good governance practice.
Who is responsible for conducting an AI impact assessment?+
Under the EU AI Act, the deployer is responsible for the FRIA. Under GDPR, the data controller is responsible for the DPIA. Responsibility generally follows whoever is putting the system into use.
