The rise of AI changes the legal responsibility of organisations, with you as General Counsel at the helm.
The technological acceleration in which we find ourselves puts great pressure on the legal playing field. Artificial intelligence, automated decision-making and data-driven processes come with unprecedented opportunities as well as risks. New laws and regulations, such as the AI Act of the European Commission, call not only for compliance, but also for a reconsideration of the way in which fundamental risks are identified and controlled.
Pressure on legal departments increases
As General Counsel or Head of Legal Affairs, you are confronted with a multitude of forces:
- Technological: AI is being integrated into business processes, from HR to customer service, without always having a clear picture of the risks to the organisation and the persons concerned.
- Political: Governments are intensifying their supervision. The AI Regulation requires that organisations proactively identify and mitigate risks attached to high-risk AI systems for fundamental rights.
- Macro-economic: There is growing pressure to work more efficiently and to (keep) innovating, while the regulatory framework that must be fulfilled is becoming bigger.
- Ethical: Stakeholders, from supervisors to customers and staff members, expect organisations not only to act in the legally correct way, but also to show moral leadership.
What is a Fundamental Rights Impact Assessment?
A Fundamental Rights Impact Assessment or “FRIA”) is an instrument for organisations to map out specific risks to the rights of (groups of) persons who are likely to be affected by the use of a high-risk AI system and to determine which mitigating measures are needed in case such risks occur.
The reason for this is that AI systems may have considerable consequences for the fundamental rights of individuals, such as the right to protection of privacy (including the right to data protection, but also the right to autonomy and self-determination), the right to equal treatment, the right to a fair trial, and the right to protection of (intellectual) property.
High-risk AI systems are often used in sensitive domains, such as law enforcement, migration, health care and education, where errors, prejudice or a lack of transparency may immediately lead to unjust treatment, exclusion or damage. The FRIA helps organisations identify, assess and limit in advance any risks their systems may generate, and ensures that the use of AI systems is in line with the values and fundamental rights that are subject to statutory protection within the EU.
Under the AI Regulation, organisations that use an AI system may in some cases be obliged to perform a FRIA. This will be the case in particular if the AI system qualifies as ‘high-risk’ and is used to evaluate creditworthiness, credit scores or risk assessments or if the organisation is a public-law body or a private entity that renders public services. Also beyond that context, a FRIA is a powerful legal tool to identify and control ethical risks at an early stage.
By performing a FRIA:
- You systematically identify risks early;
- You get concrete tools to take mitigating measures;
- You enhance transparency towards supervisors and stakeholders;
- You reinforce the trust of customers, staff members and society;
- You fulfil your compliance obligation from the AI Regulation.
Why you should deal with this now
The EU AI Regulation has already taken effect and will become applicable in phases. Starting from 2 August 2026, organisations are expected to comply with all rules in the AI Regulation. Organisations that are preparing now have a clear head start, legally, ethically and strategically. At the same time, the social sensitivity around AI is big: discrimination by algorithms, bias in recruitment processes or privacy infringements may end in damage to reputation or even legal claims.
By performing a FRIA in good time, you will show that your organisation is not just compliant, but also deals with AI and the fundamental rights of those involved consciously and responsibly.
Email laura.poolman@kvdl.com to request a free FRIA template developed by Kennedy Van der Laan, based on the AI Regulation and standards of international (human rights) organisations, and obtain a practical tool at once to identify and control risks in the field of fundamental rights in the use of AI systems.
Laura Poolman is a member of the AI team at Kennedy Van der Laan. The team offers broad advice to General Counsels on AI-related topics, ranging from strategic and compliance-oriented advice to product liability and disputes. Read more about the expertise and the team on the AI theme page.
Prepare your organisation for the future. Responsibly. Transparently. Legally sound.