logo

Do I need an Impact Assessment before implementing an AI tool in my company?

LetsLaw / Digital Law  / Do I need an Impact Assessment before implementing an AI tool in my company?
Abogados evaluación de impacto IA en la empresa

Do I need an Impact Assessment before implementing an AI tool in my company?

It is one of the questions we are hearing most often lately. The company has already chosen the tool (an assistant for Human Resources, a system that scores customers, a chatbot connected to the CRM) and, almost at the end of the meeting, someone asks whether any “paperwork” is needed before putting it into use. The short answer is: it depends. The longer answer is worth knowing before signing with the provider.

Impact assessments and AI: we are not talking about a single obligation

When discussing impact assessments in the field of artificial intelligence, there are actually two different mechanisms that are often confused.

The first is the Data Protection Impact Assessment (DPIA), provided for in Article 35 of the GDPR. It has been with us for years and is required where the processing of personal data is likely to result in a high risk to the rights and freedoms of individuals.

The second is more recent. Article 27 of Regulation (EU) 2024/1689 on Artificial Intelligence (the AI Act) introduces a fundamental rights impact assessment for certain uses of high-risk AI systems. Here, the analysis goes beyond privacy and also covers issues such as potential discrimination, access to certain services or available complaint mechanisms.

Although these are different assessments, they are based on a fairly similar idea: before using a system, it is important to understand what it does, who it may affect, what risks it creates and what measures will be adopted to control those risks.

When is each assessment mandatory?

This is the point that raises the most questions.

The assessment provided for in Article 27 of the AI Act does not apply to every company that uses artificial intelligence. It applies to certain deployers of high-risk AI systems listed in Annex III, including public bodies, certain private entities providing public services, and entities using certain systems to assess the creditworthiness of natural persons or to assess risks and determine pricing in life and health insurance.

That said, the timetable for the application of the Regulation must be kept in mind: following the latest amendments to the AI Act, these obligations relating to high-risk systems listed in Annex III will apply from 2 December 2027.

Therefore, a company that merely uses an AI assistant to draft commercial proposals will not, for that reason alone, be required to carry out the assessment under Article 27. The position would be very different for an entity using a high-risk system to assess the creditworthiness of natural persons.

The DPIA has a different and potentially much broader scope. The obligation arises where the processing of personal data is likely to result in a high risk to the rights and freedoms of individuals.

The use of new technologies is one of the criteria that must be taken into account, but it does not automatically mean that every use of AI requires a DPIA. The AEPD notes that, as a general rule, the presence of several risk factors may make an assessment necessary.

For this reason, certain uses of AI involving individuals (for example, candidate screening, employee performance assessment, customer profiling or automated decision-making with significant effects) may require particularly careful analysis.

In practice, a company may not be required to carry out the assessment under Article 27 of the AI Act and may nevertheless need a DPIA under the GDPR.

And it should not be overlooked: failure to carry out a DPIA where one is required may result in fines of up to EUR 10 million or, in the case of an undertaking, up to 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher.

What should an impact assessment analyse?

An assessment that merely consists of filling in a template is of little value, either before an authority or within the company itself. Although the specific content will depend on which assessment applies, there are some questions that should always be addressed:

  • The system and the process: what it is used for, how it is integrated into the activity and how often it is used.
  • The people affected: which groups may be affected and whether particularly vulnerable individuals are involved.
  • Necessity and proportionality: why that processing or system is necessary and whether less intrusive alternatives exist.
  • The specific risks: bias, errors, incorrect decisions, lack of transparency or misuse of data. No generic risks.
  • Human oversight: who reviews the outputs and, above all, whether that person has a genuine ability to correct them.
  • Mitigation measures: which technical, organisational or legal controls will be applied to reduce the identified risks.
  • The response plan: what will happen if the risk materialises and what channels affected individuals will have to lodge a complaint.

 

Two further practical recommendations.

  1. Ask the provider for sufficient documentation on how the system works and its instructions for use. Assessing a tool without really understanding how it works turns the exercise into little more than a formality.
  2. If the company already has a DPIA, there is no point in duplicating work. The AI Act itself allows, where certain issues are already covered by that assessment, references to be incorporated to the relevant sections or the relevant information to be reused when carrying out the fundamental rights impact assessment.

Where Article 27 applies, the outcome of the assessment must also be notified to the competent market surveillance authority.

Finally, an impact assessment should not be filed away once it has been completed. If the use of the tool changes, new functionalities are added or the provider makes material changes to the system, it will be necessary to check whether the assessment remains valid and update it where necessary.

Spending time on these questions before implementing a tool is usually much easier than trying to correct its risks once it is already in operation.

At Letslaw, we specialise in this area and can advise you.

Contact Us

    By clicking on "Send" you accept our Privacy Policy - + Info

    I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our Privacy Policy - + Info