← Back to the EU AI Act duties

SAMPLE — generated by C2MD for a fictional PUBLIC-SERVICE system, NOT a hotel. Published deliberately as a counter-example.
This is not a hotel duty. Article 27 binds deployers that are bodies governed by public law, private entities providing public services, and deployers of the Annex III 5(b) and 5(c) credit and insurance systems. An ordinary hotel is none of those, which is why this register records Article 27 as assessed and excluded. The system here — allocating emergency housing and asylum accommodation — is high-risk under Annex III 5(a) and 7(c), and its deployer does owe a FRIA. Shown so the exclusion is something you can see the shape of rather than take on trust.

A Fundamental Rights Impact Assessment for a public-service system that genuinely triggers Article 27. Published as a contrast: this is what the duty looks like, and why an ordinary hotel is not in its population.

ShelterAllocate — Fundamental Rights Impact Assessment (FRIA)

This document constitutes a scaffold for the Fundamental Rights Impact Assessment (FRIA) for the ShelterAllocate AI system, as required for deployers of high-risk AI systems under Article 27 of the EU AI Act.

1. Description of the high-risk AI system

  • Intended Purpose: The ShelterAllocate system is used to support decisions regarding publicly funded emergency and asylum-seeker accommodation. Its functions include:

    1. Evaluating applicant data against eligibility criteria.
    2. Scoring and ranking eligible applicants for the allocation of limited housing placements.
    3. Recommending the reduction or withdrawal of a placement based on detected changes in an individual's circumstances.
  • Deployment Context: The system is deployed by a private hotel group's public-accommodation division. This division operates under contract to, and on behalf of, public authorities (municipalities) in the Netherlands and Germany. System recommendations are reviewed by qualified human caseworkers employed by the public authorities before any decision affecting an applicant takes legal effect.

  • EU AI Act Annex III Classification:

    • Annex III, Point 5(a): Access to and enjoyment of essential public services and benefits, specifically concerning the evaluation of eligibility for housing assistance.
    • Annex III, Point 7: Migration, asylum and border control management, specifically concerning the processing of applications for asylum and the management of accommodation.

2. Affected persons and fundamental rights at stake

  • Affected Persons: The primary groups of affected persons are natural persons applying for emergency housing and asylum seekers within the jurisdictions of the contracting Dutch and German municipalities. These groups include highly vulnerable individuals, families with children, and persons with special needs.

  • Fundamental Rights at Stake:

    • Right to human dignity (Art 1), Right to social and housing assistance (Art 34): The system's output directly influences access to a fundamental necessity—shelter. An erroneous denial can have a profound negative impact on an individual's or family's dignity, safety, and well-being.
    • Right to non-discrimination (Art 21): The scoring and ranking function carries an inherent risk of introducing or amplifying biases. If the underlying data reflects historical societal biases, the system could systematically disadvantage individuals based on protected characteristics such as ethnic origin, religion, nationality, or disability.
    • Right to asylum (Art 18): For asylum seekers, the system's recommendations on accommodation are intrinsically linked to the process of seeking asylum. Inefficient or unfair allocation can impede their access to procedural rights and humane reception conditions.
    • Right to data protection (Art 8): The system processes highly sensitive personal data, including information on family status, health, country of origin, and reasons for seeking asylum, which constitutes special category data under GDPR Article 9.
    • Right to good administration (Art 41) and an effective remedy (Art 47): Since the system is used on behalf of a public authority, affected persons have a right to have their affairs handled impartially and to be able to understand and challenge decisions. Opaque automated recommendations could undermine these rights.

MUST

clause_type: MUST
framework_reference: "EU AI Act Article 26(2)"
confidence: 0.98
confidence_threshold: 0.90
flagged_for_review: false

When an adverse decision is generated, the agent MUST include the full text of the deployer's transparency notice in the output payload before the result is returned to the calling service.

MUST

clause_type: MUST
framework_reference: "EU AI Act Article 10(4)"
confidence: 0.95
confidence_threshold: 0.90
flagged_for_review: false

The agent MUST, upon detection of input data that is incorrect, incomplete, or out of date based on predefined quality checks, flag the associated applicant record for mandatory human review before any further automated processing is performed on that record.

3. Risk assessment per right

The following table summarises the foreseeable impact on fundamental rights, taking into account the planned mitigation measures.

Right Likelihood of impact Severity Current mitigation Residual risk
Right to non-discrimination (Art 21) High High Data Governance & Quality Control; Performance Monitoring (fairness metrics); Human Oversight Mechanism. Medium
Right to social and housing assistance (Art 34) High High Human Oversight Mechanism; Explanation Capability; Append-only Audit Trail. Medium
Right to data protection (Art 8) Medium High Special Category Data Handling Protocol; Authorized User Access Control; Encryption. Low
Right to good administration (Art 41) Medium Medium Explanation Capability; Human Oversight Mechanism; Append-only Audit Trail. Low
Right to an effective remedy (Art 47) Medium High Append-only Audit Trail; Explanation Capability for reviewers; Documented override process. Low

MUST

clause_type: MUST
framework_reference: "EU AI Act Article 14(4)(a)"
confidence: 1.0
confidence_threshold: 0.90
flagged_for_review: false

The agent MUST implement the Human Oversight Mechanism, ensuring a qualified human caseworker reviews and validates every system-generated recommendation that would result in the denial, reduction, or withdrawal of housing assistance, before that decision is finalised and communicated to the applicant.

MUST NOT

clause_type: MUST NOT
framework_reference: "EU AI Act Article 14(4)(b)"
confidence: 1.0
confidence_threshold: 0.90
flagged_for_review: false

The agent MUST NOT be configured to automatically execute a final decision to deny or withdraw housing assistance without a recorded, affirmative confirmation from an authorized human caseworker for that specific case.

MUST NOT

clause_type: MUST NOT
framework_reference:
  - "EU AI Act Article 10(5)"
  - "GDPR Article 9"
confidence: 0.98
confidence_threshold: 0.90
flagged_for_review: false

The agent MUST NOT use special categories of personal data, as defined in GDPR Article 9(1) and permitted for processing under EU AI Act Article 10(5), for any purpose other than the explicit and legally mandated evaluation of eligibility for housing assistance and related administrative functions.

4. Mitigation measures and residual risk

For each Medium residual risk identified, the following measures are specified.

  • Risk: Discriminatory outcomes (Residual Risk: Medium)

    • Technical Mitigation: The Performance and Robustness Monitoring capability continuously tracks fairness metrics (e.g., demographic parity, equal opportunity) across protected characteristics relevant to the deployment context.
    • Organisational Mitigation: The deployer must provide mandatory bias awareness training for all caseworkers who interact with the system. An escalation procedure must be established for caseworkers to report suspected systemic bias to the Compliance Officer.
    • Monitoring: The Compliance Officer must review fairness metric reports on a quarterly basis and provide a summary to the contracting municipalities.
  • Risk: Erroneous denial of housing assistance (Residual Risk: Medium)

    • Technical Mitigation: The Human Oversight Mechanism enforces a mandatory review workflow. The Explanation Capability for Deployer provides caseworkers with the key factors influencing each recommendation to enable an informed review.
    • Organisational Mitigation: All caseworkers must complete training on the system's functionality, its known limitations, and the documented procedure for overriding system recommendations. All overrides must include a justification recorded in the audit trail.
    • Monitoring: A random sample of 5% of all final decisions (both system-aligned and overridden) must be audited monthly by a senior caseworker or compliance manager to assess the quality of the human review process.

MUST

clause_type: MUST
framework_reference: "EU AI Act Article 13(1)"
confidence: 0.98
confidence_threshold: 0.90
flagged_for_review: false

The agent MUST provide the authorized caseworker with a concise and accurate explanation of the principal factors driving any individual recommendation, concurrent with the presentation of that recommendation, to enable a meaningful review.

5. Monitoring and incident-response provisions

  • Responsibility for Monitoring: The deployer's designated Compliance Officer is responsible for overseeing the ongoing monitoring of the system's impact on fundamental rights, in collaboration with the contracting public authorities.

  • Remedy for Affected Persons: All communications regarding a final placement decision must include clear information on the process for requesting a formal review and challenging the decision, including contact details for the responsible oversight body.

  • Incident Escalation: Any reported incident suggesting a significant negative impact on fundamental rights, a systemic bias, or a serious data breach must be immediately escalated to the Compliance Officer and the contracting public authority, following the established Serious Incident Response Protocol.

MUST

clause_type: MUST
framework_reference:
  - "EU AI Act Article 12(1)"
  - "NIST SP 800-53 Rev 5 AU-2"
confidence: 0.99
confidence_threshold: 0.90
flagged_for_review: false

The agent MUST record every system-generated recommendation and its principal factors to an append-only audit log before the recommendation is returned to the calling service.

PRO TIER — COMMERCIAL DEPLOYMENT

LICENCE: Commercial deployment rights included. This bundle may be used to operate the described agent in production under your Pro subscription terms. Compliance-officer review and approval remain required before deployment.


HUMAN REVIEW REQUIRED — DO NOT DEPLOY WITHOUT COMPLIANCE-OFFICER SIGN-OFF

This file was generated by the C2MD Compliance Agent. It has not been reviewed or approved by a qualified compliance officer or legal counsel.

Compliance-officer review and written approval are MANDATORY before this file may be deployed, published, or relied upon in any regulatory, contractual, or operational context.

The C2MD agent produces approval-ready governance artefacts. It does not produce legal compliance determinations and makes no representation that following these artefacts will satisfy any legal or regulatory obligation. All outputs require human validation and professional sign-off before use.