InsightsAI Governance & Compliance

AI Impact Assessments: What They Are and When You Need One

Idrak Insights TeamAugust 8, 202613 min read

FRIA · AIA · DPIA

Key takeaways

  • "AI impact assessment" is an umbrella term covering at least three legally distinct instruments: the EU AI Act's Fundamental Rights Impact Assessment (FRIA), Canada's Algorithmic Impact Assessment (AIA), and GDPR's Data Protection Impact Assessment (DPIA), each with different triggers, scope, and consequences.
  • The EU AI Act's high-risk compliance deadline, originally August 2, 2026, was pushed back to December 2, 2027 following final approval of the Digital Omnibus on AI on June 29, 2026, a 16-month extension many compliance timelines were built around the old date.
  • A FRIA covers all fundamental rights under the EU Charter and applies regardless of whether personal data is involved; a DPIA is narrower, focused specifically on data protection risk.
  • Canada's AIA, in effect since 2019, uses a scored questionnaire to assign one of four impact levels, with governance requirements scaling proportionally at each level.
  • Even organizations without a specific legal mandate benefit from conducting AI impact assessments voluntarily, using frameworks like NIST's AI Risk Management Framework or ISO 42001 as a structure.

Introduction

"We already do a DPIA, so we're covered" is one of the more common, and increasingly incorrect, assumptions organizations make about AI compliance. AI impact assessments aren't a single, interchangeable requirement, they're a family of related but legally distinct instruments, each triggered by different circumstances and each assessing a different kind of risk. Getting the terminology right matters, because assuming one type of assessment covers the requirements of another is exactly how compliance gaps happen. This guide breaks down the major frameworks, what each actually requires, and how to figure out which one, if any, applies to your organization.

What Is an AI Impact Assessment, Actually?

At its core, an AI impact assessment is a structured process for identifying, evaluating, and mitigating the potential effects of an AI system before or during its deployment. Depending on the specific framework, "effects" can mean data protection risk, fundamental rights impact, discriminatory outcomes, or broader societal harm. The shared goal across all versions is the same: force a deliberate evaluation before deployment, rather than discovering problems after the system is already affecting real people.

The Three (Main) Flavors, Compared

Three types of AI impact assessment

01

FRIA

EU AI Act, Art. 27

Triggered by
Deploying a high-risk AI system
Scope
All fundamental rights in the EU Charter
Applies to
Certain deployers (public bodies, public service providers, some credit and insurance uses)
Binding?
Yes, with regulatory notification required
Penalties
Significant financial penalties under the AI Act
02

AIA

Canada

Triggered by
Deploying an automated decision system in the federal government
Scope
Impact to rights, health, and economic interests
Applies to
Government of Canada institutions
Binding?
Yes, internal government policy
Penalties
None; internal governance consequences only
03

DPIA

GDPR, Art. 35

Triggered by
High-risk processing of personal data
Scope
Data protection and privacy specifically
Applies to
Any organization subject to GDPR
Binding?
Yes, legally binding under GDPR
Penalties
GDPR fines apply

Deep Dive: The EU's Fundamental Rights Impact Assessment

Article 27 of the EU AI Act requires certain deployers, public sector bodies, private entities providing public services, and deployers using high-risk AI for credit scoring or life and health insurance risk assessment, to complete a FRIA before putting a high-risk AI system into use.

What a FRIA actually covers

01

Descriptive section

The system's intended purpose, the processes it will be used in, timeframes and frequency of use, and the individuals or groups it may affect.

02

Assessment section

The specific risks of harm likely to affect identified individuals or groups, considering the provider's instructions for use.

03

Mitigation section

Human oversight measures, governance structures, and mechanisms for affected individuals to raise complaints or seek remedy.

A critical, very recent update: many compliance timelines were built around an August 2, 2026 deadline for standalone high-risk AI systems under Annex III. That date has moved. The EU's Digital Omnibus on AI, first proposed by the European Commission in November 2025 to address delays in implementation infrastructure, received European Parliament endorsement on June 16, 2026, and final Council approval on June 29, 2026. The result: standalone high-risk AI systems now have until December 2, 2027, a 16-month deferral, while AI embedded in regulated products under Annex I has until August 2, 2028. The FRIA obligation under Article 27 itself is unchanged in substance, only the timeline moved.

Deep Dive: Canada's Algorithmic Impact Assessment

Canada's AIA, in effect since April 2019 under the Directive on Automated Decision-Making, is one of the earliest formal government AI governance frameworks in the world. It's a mandatory, publicly available questionnaire, 65 risk questions and 41 mitigation questions, that Government of Canada institutions must complete before deploying an automated decision system.

Canada's AIA impact levels

I0-25%

Little to no impact

Not required

II26-50%

Moderate impact

Not required

III51-75%

High impact

Specific human intervention points required

IV76-100%

Very high impact

Final decision must be made by a human

Unlike the EU's FRIA, there's no way to "fail" Canada's AIA outright, and no financial or criminal penalties attach to it, since it's an internal government policy instrument rather than binding legislation with enforcement teeth. Level IV requirements are deliberately demanding, though, specifically designed to discourage deploying very high-risk automated systems without serious justification and oversight.

How These Relate to DPIAs

Where a FRIA and Canada's AIA both look broadly at rights and societal impact, a Data Protection Impact Assessment under GDPR Article 35 stays narrower: it evaluates specifically whether personal data processing is lawful, proportionate, and adequately protected. An AI system that doesn't process personal data at all, a purely industrial optimization model, for example, may still require a FRIA under the EU AI Act if it's high-risk, but wouldn't trigger a DPIA at all. The two aren't substitutes for each other, and the EU AI Act explicitly allows combining both where an AI system processes personal data, rather than duplicating the work twice. Where the data itself sits matters too, which is the separate question of data sovereignty.

When Does Your Organization Actually Need One?

Do you need an AI impact assessment?

  • 01Are you deploying, not just building, an AI system that falls into a high-risk category under a relevant regulation (EU AI Act Annex III, sector-specific rules, etc.)?
  • 02Is your organization a public sector body, or providing services on behalf of one?
  • 03Does the AI system make or materially influence decisions affecting individuals (credit, employment, benefits, insurance, legal outcomes)?
  • 04Does the system process personal data in a way that would independently trigger a DPIA requirement?
  • 05Even without a legal trigger, would a structured pre-deployment review meaningfully reduce your organization's risk exposure?

If the answer to any of the regulatory questions is yes, a specific, named assessment likely applies, and getting the right one matters more than doing "an assessment" generically. The same discipline applies to tools nobody formally approved, which is the governance problem behind shadow AI.

Building an AI Impact Assessment Practice

Building the practice

  • 01Don't assume one assessment type covers another; map which specific instrument (FRIA, DPIA, sector-specific requirement, or none legally required) actually applies before starting.
  • 02Build assessments into the deployment process itself, not as an afterthought once a system is already in production.
  • 03Where no legal mandate exists, consider adopting a voluntary framework such as NIST's AI Risk Management Framework or ISO 42001 as a structured starting point.
  • 04Assign clear ownership. Under most frameworks, responsibility sits with whoever is deploying the system, not necessarily whoever built it.
  • 05Treat assessments as living documents. Both the FRIA and Canada's AIA require updates when the system's use, scope, or functionality changes materially.

Regionally, the same logic is already visible in Qatar's National AI Strategy and the ethics and public policy pillar underpinning it.

Sources

  • European Union, EU AI Act, Article 27, Fundamental Rights Impact Assessment (eur-lex.europa.eu)
  • Freshfields, Gibson Dunn, DLA Piper, legal coverage of the Digital Omnibus on AI final adoption, June 2026
  • Government of Canada, Treasury Board of Canada Secretariat, Directive on Automated Decision-Making and Algorithmic Impact Assessment tool (canada.ca)
  • GDPR, Article 35, Data Protection Impact Assessment

This article reflects publicly available regulatory information as of July 2026. AI regulation is changing quickly, as this article's own central example shows, verify current deadlines and requirements with qualified legal counsel before making compliance decisions.

Frequently Asked Questions

What is an AI impact assessment?+

A structured process for identifying, evaluating, and mitigating the potential effects of an AI system before or during deployment. The term covers several legally distinct instruments, including the FRIA, AIA, and DPIA, each with different triggers and scope.

What's the difference between a FRIA and a DPIA?+

A DPIA focuses specifically on data protection risk triggered by high-risk personal data processing. A FRIA covers the full range of fundamental rights, is triggered by high-risk AI deployment, and applies regardless of whether personal data is involved.

Does the EU AI Act's high-risk deadline still apply in 2026?+

The original August 2, 2026 deadline was deferred. Following final approval of the Digital Omnibus on AI on June 29, 2026, standalone high-risk AI systems now have until December 2, 2027.

What is Canada's Algorithmic Impact Assessment?+

A mandatory questionnaire, in effect since 2019, that Government of Canada institutions must complete before deploying an automated decision system, scoring it into one of four impact levels with proportionally scaled requirements.

Does my organization need an AI impact assessment if we're not in the EU or Canada?+

Legal requirements vary by jurisdiction and sector. Even without a legal mandate, a voluntary assessment using frameworks like NIST's AI RMF or ISO 42001 is considered good governance practice.

Who is responsible for conducting an AI impact assessment?+

Under the EU AI Act, the deployer is responsible for the FRIA. Under GDPR, the data controller is responsible for the DPIA. Responsibility generally follows whoever is putting the system into use.

Advisory

Preparing an AI impact assessment? Idrak advises on AI governance and builds the systems behind it.

Explore our AI Solutions practice