Direct comparison
HUDERIA vs EU AI Act Article 27 FRIA
One is voluntary Council of Europe guidance, the other a binding deployer duty. Compare scope, timing, content and who ever sees the assessment.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about HUDERIA vs EU AI Act Article 27 FRIA
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do HUDERIA (Council of Europe, Methodology and Model), FRIA — Article 27, EU AI Act (Regulation (EU) 2024/1689) compare side by side?
The table below compares HUDERIA (Council of Europe, Methodology and Model), FRIA — Article 27, EU AI Act (Regulation (EU) 2024/1689) across 12 procurement-relevant dimensions, from legal force through what happens if you skip it.
Side-by-side comparison
| Dimension | HUDERIA (Council of Europe, Methodology and Model) | FRIA — Article 27, EU AI Act (Regulation (EU) 2024/1689) |
|---|---|---|
| Legal force | None, and the text says so itself: HUDERIA is "a stand-alone, non-legally binding guidance that does not have legal effect", "not mandatory, nor intended as an interpretative aid" for the Framework Convention, and "while HUDERIA has a facilitative role, it is not a means for implementing the Framework Convention". Parties to CETS 225 may use it, adapt it in whole or in part, or use a different approach, so long as they meet the Chapter V baseline for risk and impact management. | A binding obligation in directly applicable EU law. Article 27(1) opens "Prior to deploying a high-risk AI system referred to in Article 6(2) … deployers … shall perform an assessment of the impact on fundamental rights". Enforcement runs through national market surveillance authorities under the AI Act’s enforcement chapter. |
| Who must do it | Nobody must. HUDERIA "can be used by both public and private actors" to identify and address risks and impacts to human rights, democracy and the rule of law throughout the life cycle of AI systems. There is no covered-entity test because there is no duty — the question is only whether an organisation, or a Party writing its own domestic framework, chooses to pick it up. | A narrow, enumerated set of deployers: those that are "bodies governed by public law, or are private entities providing public services", plus deployers of the Annex III point 5(b) and (c) systems — creditworthiness assessment and credit scoring of natural persons, and risk assessment and pricing in relation to natural persons for life and health insurance. Providers are not covered by Article 27; this is a deployer duty. Annex III point 2 (safety components in critical infrastructure) is carved out. |
| Trigger and timing | Whenever the user chooses, at any life-cycle stage. The methodology is explicitly front-loadable — the COBRA context-based risk analysis begins with preliminary scoping that can draw on "the project business case, proof of concept or project charter", i.e. before anything is built. Its triage step exists so that the methodology "is not onerous for minimal or low-risk AI systems", letting low-risk systems exit early rather than carrying the whole process. | Before first use. Article 27(2): "The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system." A deployer "may, in similar cases, rely on previously conducted fundamental rights impact assessments", and there is a standing update duty — if the deployer considers any paragraph 1 element "has changed or is no longer up to date", it "shall take the necessary steps to update the information". No triage: if you are a covered deployer of a covered system, you do the assessment. |
| Protected interest | Human rights, democracy and the rule of law — all three, in the instrument’s own name. That third limb is not decoration: the methodology asks about "the high scope and long-lasting effects on persons, institutions and society in general", and expressly directs attention to "cumulative or aggregate impacts of the system on present and future potentially affected persons and groups of persons". | Fundamental rights, as they bear on people. Article 27(1)(c) asks for "the categories of natural persons and groups likely to be affected by its use" and (d) for "the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified". There is no separate democracy or rule-of-law limb, and no instruction to aggregate societal effect across deployments. |
| Required content | Four elements, applied proportionately: (1) the context-based risk analysis (COBRA), itself four steps — preliminary scoping, analysis of risk factors, mapping of potential impacts, triage; (2) the stakeholder engagement process (SEP); (3) the risk and impact assessment; (4) the mitigation plan, "including access to remedies and iterative review". The sequence is adaptable — "one may choose to change the sequence of the elements and/or apply or otherwise use only certain parts of the methodology". | Six enumerated items in Article 27(1): (a) the deployer’s processes in which the system will be used in line with its intended purpose; (b) the period of time within which, and frequency with which, it is intended to be used; (c) the categories of natural persons and groups likely to be affected; (d) the specific risks of harm to them; (e) the implementation of human oversight measures, according to the instructions for use; and (f) the measures to be taken if those risks materialise, "including the arrangements for internal governance and complaint mechanisms". A closed list, not a methodology. |
| How severity and probability are expressed | Explicitly, through four named variables. HUDERIA "takes as a basis well-known variables … scale, scope, probability and reversibility of potential adverse impacts", grouping scale, scope and reversibility as severity, with probability alongside. It footnotes that reversibility "may sometimes be referred to as remediability" and probability "as likelihood", and leaves the qualitative/quantitative choice to the assessing authority or project team. | Not specified. Article 27 asks for "the specific risks of harm" without prescribing a severity scale, a probability scale, or any grading vocabulary at all. Whatever ladder a deployer uses is its own, and two deployers filing to the same market surveillance authority can use incommensurable scales without either being non-compliant. |
| Stakeholder engagement | A full, structured process. The SEP has five key steps — stakeholder analysis, positionality reflection, establishment of engagement objectives, determination of an engagement method, and implementation — and the stakeholder analysis specifically directs attention to those "disproportionately at risk", those "particularly vulnerable to potential harms", and those with "particularly limited ability to influence how the system is designed and used". | Nothing equivalent. Article 27 requires the deployer to identify affected categories of persons and groups; it does not require the deployer to talk to any of them, and no consultation, participation or positionality step appears anywhere in the article. |
| The build/don’t-build question | Asked directly, twice. The COBRA triage exists partly "to make an initial determination of whether the AI system should be developed or deployed", including "whether the use of the AI system is incompatible with respect for human rights, democracy and the rule of law". The "zero questions" push the same way, asking whether existing technologies "are better placed" to solve the problem, with "particular focus … on any marginal risk added by introducing AI into the current context". | Not asked. Article 27 is framed around a deployment that is going ahead: the deployer describes its processes, the period of use, the affected groups, the risks, the oversight and the response if risks materialise. There is no step at which the answer "then do not deploy it" is one of the outputs the article contemplates. |
| Output, and who ever sees it | Internal documentation by default. Publication is a value, not a duty: transparency appears as one of five principles for stakeholder engagement, which asks users to "make available information about the understanding of potential implications and human rights impacts, where appropriate, and publicly communicate HUDERIA findings and impact management plans (action plans)". No regulator receives anything. | A regulator receives it. Article 27(3): once the assessment has been performed "the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 … as part of the notification", with an exemption available in the Article 46(1) case. Article 27(5) tasks the AI Office with developing that template questionnaire, "including through an automated tool". |
| Handling overlap with other assessments | Interoperability is a stated design objective. HUDERIA aims "to promote compatibility and interoperability with existing and future guidance, standards and frameworks" developed by ISO, IEC, ITU, CEN, CENELEC, IEEE, the OECD and NIST, naming "the NIST AI Risk Management Framework and risk management and fundamental rights impact assessment under the European Union AI Act" — so the Article 27 FRIA is, by name, one of the things HUDERIA was built to sit alongside. | One explicit carve-out. Article 27(4) allows a deployer that has already carried out a data protection impact assessment under Article 35 GDPR, or Article 27 of Directive (EU) 2016/680, to complement it rather than duplicate it — the fundamental rights impact assessment "shall complement" that DPIA. Nothing in the article gives credit for a HUDERIA, a NIST AI RMF profile, or an ISO/IEC 42001 management system. |
| When it starts to matter | Already available, and already being pointed at. The Methodology was adopted by the Committee on Artificial Intelligence in November 2024, with the Methodology and Model published subsequently; the model text notes further components — the roles and responsibilities section and the SEP Resources — as still to be developed and adopted in 2026. Nothing about it is contingent on a compliance date, because nothing about it is a deadline. | Deferred with the rest of the Annex III high-risk regime. Multiple law-firm and practitioner sources report that the Digital Omnibus on AI, cited as Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, moving the standalone Annex III high-risk application date from 2 August 2026 to 2 December 2027, with Annex I embedded systems at 2 August 2028. CASRAI has not read the Official Journal text and states this as reported, not verified at source. |
| What happens if you skip it | Nothing, legally. Skipping HUDERIA breaches no obligation, because HUDERIA imposes none. What is lost is evidential: an organisation that never did the early triage has no record of having asked whether the system should exist, which is exactly the record that is hardest to reconstruct later. | A breach of a directly applicable regulation, enforced by the national market surveillance authority, plus a missing notification the authority can see is missing. CASRAI has not verified which penalty tier of Article 99 a bare Article 27 failure falls into and does not state one here. |
Common questions
Common questions about HUDERIA (Council of Europe, Methodology and Model) vs FRIA — Article 27, EU AI Act (Regulation (EU) 2024/1689)
If we complete a HUDERIA, have we satisfied Article 27?
+
No, and HUDERIA does not claim you have. The methodology describes itself as non-legally binding guidance that does not have legal effect and is "not a means for implementing the Framework Convention" — it makes no claim to discharge any EU obligation either. Article 27 requires six specific items, a trigger at first use, and a notification to the market surveillance authority on the AI Office template; a HUDERIA produces a different set of artefacts on a different schedule for a different audience. The practical relationship runs the other way: a completed HUDERIA gives you most of the raw material for items (c), (d) and (f) — affected categories, specific risks of harm, and mitigation with access to remedies — but you still have to write the Article 27 assessment and file it.
Our university deploys an AI tool for admissions screening. Does Article 27 apply to us?
+
Quite possibly, and this is the case most research institutions miss. Annex III point 3(a) covers AI systems intended to determine access or admission, or to assign people to educational and vocational training institutions at all levels; point 3(b) covers evaluating learning outcomes; 3(c) assessing the appropriate level of education a person will receive; and 3(d) monitoring and detecting prohibited behaviour of students during tests. Article 27 reaches deployers that are bodies governed by public law or private entities providing public services, with only Annex III point 2 carved out — so a public university deploying any of those systems is a covered deployer, not merely a covered provider’s customer. Whether a particular institution is a "body governed by public law" is a question of national law and legal form, not of whether it receives public funding, so that determination belongs with institutional counsel.
Does the EU ratifying CETS 225 make HUDERIA mandatory in the EU?
+
No. The European Union deposited its instrument of ratification of the Framework Convention on 15 May 2026, and CASRAI has been unable to fetch the Council of Europe Treaty Office chart directly to confirm the date the Convention takes effect in respect of the EU, so no entry-into-force date for the EU is stated here. What is clear from the HUDERIA text itself is that ratification would not make it binding in any event: Parties "have the flexibility to use or adapt the guidance, in whole or in part, to develop new approaches to risk assessment or to use or adapt existing approaches in keeping with their applicable laws", provided they meet their Convention obligations including the Chapter V baseline. HUDERIA is one available way to meet that baseline, not the required way.
Can we reuse our GDPR data protection impact assessment?
+
Partly, and only for the Article 27 side. Article 27(4) provides that where a deployer has already carried out a data protection impact assessment under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment complements it rather than repeating it. That is a genuine efficiency, but it is narrower than it sounds: a DPIA asks about processing of personal data and risks to data subjects, while Article 27 asks about the deployer’s processes, period and frequency of use, human oversight implementation, and internal governance and complaint mechanisms — none of which a DPIA necessarily covers. HUDERIA gives no such credit and asks for none, since it imposes no duty to discharge.
Which one should we start with if we are doing both?
+
Start with the HUDERIA-shaped work, because of what it asks and when. Its COBRA triage and "zero questions" are designed to run while the build decision is still open — whether existing technologies already in place "are better placed" to solve the problem, whether impacts will be equitable across affected groups, whether available data is sufficient, and what marginal risk introducing AI adds to the current context. Article 27 cannot ask those questions, because it starts from a deployment that is going ahead and must be completed before first use. Running the open-ended assessment early and the compliance assessment late uses each instrument for what it can actually do, and the stakeholder engagement process produces exactly the evidence about affected groups that Article 27(1)(c) and (d) then need.
How does NIKOLAI relate to either instrument?
+
It sits beside them and neither has endorsed it. NIKOLAI is CASRAI’s own independent frontier-AI-safety dictionary, and the element that bears on this comparison is Likelihood Term on the N4 "Claims and argument" track, which proposes a controlled ladder of ordinal likelihood terms with a required likelihood.scheme reference naming which scale a source is using. The gap it describes is visible in exactly this pairing: HUDERIA names probability as a risk variable and notes it "may sometimes be referred to as likelihood", while Article 27 asks for specific risks of harm and prescribes no probability vocabulary at all — so two assessments of the same system can grade the same risk in terms that do not compare. Every crosswalk row on that element is a shadow mapping: CASRAI’s own reading of a published document, which no institution named on it has declared, endorsed or been consulted on. That changes only when an organisation files a Mapping Declaration.
Is there a research-administration angle here beyond admissions systems?
+
Yes, in two places that sit with different offices. The first is deployment: a European university or research institute that is a body governed by public law and deploys an Annex III high-risk system — admissions and placement, evaluation of learning outcomes, exam proctoring under point 3, or an essential-services eligibility system under point 5(a) — is a covered deployer under Article 27 in its own right, which makes this a research-computing and institutional-counsel question rather than a vendor question. The second is procurement: because Article 27(1)(e) requires a description of how human oversight measures will be implemented "according to the instructions for use", the assessment depends on documentation the provider supplies, so the time to secure it is in the contract, not after go-live. HUDERIA has no compliance role for institutions on either point, but its stakeholder engagement process maps unusually well onto the consultation practices research ethics and IRB offices already run.
Going deeper








