DPIA & FRIA: Mandatory Assessments for AI Tools in Patent Practice
From August 2026, AI tools require both DPIA and FRIA assessments. A step-by-step guide for patent practitioners on dual compliance.
The Dual Assessment Mandate: DPIA and FRIA for Every AI Tool in Your Patent Practice
On August 2, 2026, the EU AI Act's enforcement provisions for high-risk AI systems take effect. For patent law firms using AI-powered software, this creates a new compliance reality: alongside the Data Protection Impact Assessment (DPIA under GDPR Article 35), which has been mandatory since 2018, a Fundamental Rights Impact Assessment (FRIA under AI Act Article 27) is now required for any high-risk AI system deployed in professional practice.
Failing to conduct either assessment exposes firms to penalties under two separate regulatory regimes - simultaneously. This article explains when each assessment is triggered, how to conduct both efficiently, and what penalty stacking actually means in practice.
When Is a DPIA Triggered - and When Is a FRIA Required?
The DPIA under GDPR Article 35 is required whenever data processing is likely to result in a high risk to the rights and freedoms of natural persons. For AI tools in patent practice, this is regularly the case when the system processes inventor personal data, engages in profiling, or makes automated decisions that affect individuals.
The FRIA under AI Act Article 27 applies to deployers of high-risk AI systems. The critical difference: the FRIA does not focus solely on data protection but covers the full spectrum of fundamental rights - non-discrimination, access to justice, freedom of expression, protection of property. An AI system that evaluates patent claims and influences decisions about patentability can absolutely be fundamental-rights-relevant.
In practice, both assessments are triggered simultaneously in almost every case: any high-risk AI system processing personal data requires both DPIA and FRIA. The European Data Protection Board (EDPB) clarified in its Guidelines 01/2026 that both assessments may be conducted in parallel - but must not simply be merged into a single document.
Step-by-Step: DPIA for AI-Powered Patent Software
The DPIA follows an established methodology, but AI deployment adds specific requirements that go beyond traditional data processing assessments.
First, systematically describe the processing activity. What data enters the system - invention disclosures, technical drawings, inventor details, client correspondence? What data does the AI system generate? Are training data or prompts stored? Does the system retain or learn from user inputs?
Second, assess necessity and proportionality. Is there a less intrusive means that achieves the same purpose? For AI-powered prior art search, the answer will typically support the deployment - but you must document the analysis.
Third, identify risks specific to AI processing. Typical risks for patent AI tools include: erroneous attribution of inventor data, unintended disclosure of confidential client information to the software provider, profiling of inventors based on their invention patterns, and lack of transparency about how the system processes inputs.
Fourth, define mitigation measures. Encryption, pseudonymization, access controls, contractual binding of the provider, regular review of data processing activities. Document each measure concretely - not as general statements of intent but as specific, verifiable commitments.
Step-by-Step: FRIA Under AI Act Article 27
The FRIA will be new territory for most firms. Article 27(1) requires deployers of high-risk AI systems to conduct a fundamental rights impact assessment before putting the system into service.
The first step is context analysis: In what environment is the AI system deployed? Which groups of people are affected - inventors, clients, firm employees? Which fundamental rights could be impacted?
The second step is the substantive risk assessment: Is there a risk that the system operates in a discriminatory manner - for example, through bias in training data that systematically disadvantages certain technical fields or inventor groups? Could the system influence access to patent protection by rating certain inventions as less patentable?
The third step covers mitigation planning: What technical and organizational measures reduce the identified risks? Human-in-the-loop processes, regular bias audits, transparency reports to clients, and clear escalation procedures for contested AI outputs.
The fourth step is documentation and reporting: The FRIA must be available to the competent market surveillance authority on request. Unlike the DPIA, there is no explicit prior consultation requirement for the FRIA - but the documentation obligation is strict and must be maintained throughout the system's deployment lifecycle.
Templates and Practical Tips for Implementation
The European Commission published a FRIA template in March 2026, covering 47 checkpoints across six categories. Not all are relevant to patent practice - but you must document why you classified specific points as not applicable. Skipping without justification is itself a compliance failure.
Practical recommendation: Conduct the DPIA and FRIA as a coordinated process. Use a shared master document with clearly separated sections for data protection and fundamental rights assessment. This saves significant time while ensuring insights from one assessment flow into the other.
For ongoing documentation of AI usage, implement an AI register: a structured inventory of all deployed AI systems including purpose, risk category, date of last assessment, and responsible contact person. Article 49 of the AI Act requires such a register for high-risk systems regardless, so building it into your compliance workflow from the start eliminates redundant effort later.
Budget approximately 40 to 80 working hours for the initial assessment of a complex AI system. Subsequent annual reviews typically require 15 to 25 hours, assuming no major system changes.
Penalty Stacking: The Compound Risk of Dual Non-Compliance
This is where the financial reality becomes stark. When an AI tool simultaneously violates GDPR and AI Act requirements, penalties from both regimes can be imposed. The GDPR provides for fines up to EUR 20 million or 4% of global annual turnover. The AI Act adds up to EUR 35 million or 7% of global annual turnover for certain violations.
Article 99(4) of the AI Act does contain a credit provision: if a GDPR fine has already been imposed for the same infringement, the AI Act fine should not be applied cumulatively. But this rule only applies to identical violations. A missing DPIA concerns the GDPR; a missing FRIA concerns the AI Act - these are two separate obligations that can lead to two separate fines.
In practice, a firm operating a high-risk AI system without either DPIA or FRIA can face parallel enforcement from the data protection authority and the market surveillance authority. The cost of properly conducting both assessments stands in no reasonable proportion to this risk.
Documenting AI Usage in Daily Practice
Beyond the formal assessments, the regulatory landscape from August 2026 demands continuous documentation of AI usage across three levels.
At the system level: Which AI systems are deployed? Which version? Which configuration? Who authorized deployment? When was the last update applied? What changes were made?
At the process level: How is the AI system embedded in the firm's workflow? What review steps are prescribed before and after AI usage? Who bears responsibility for quality control of AI outputs?
At the individual case level: For client-matter-related AI usage, document when and for what purpose the system was used, what results it produced, and how those results informed the attorney's decision. This serves not only compliance but also liability protection - creating a clear record that professional judgment, not algorithmic output, drove the final work product.
Conclusion
The dual obligation of DPIA and FRIA is not bureaucratic excess but the logical consequence of two regulatory regimes addressing different protected interests. The GDPR protects personal data; the AI Act protects fundamental rights in a broader sense. Firms deploying AI tools in patent practice must cover both perspectives - and demonstrably so.
The good news: firms that approach both assessments in a structured, coordinated manner create not just compliance documentation but a robust foundation for responsible AI deployment. The effort is manageable. The risk of ignoring it is not.