The classic trap
Recital 48 is not decorative: it is the interpretive grid that the EU AI Office (and eventually the Luxembourg AI market surveillance authority) will use to assess whether your system tips into high-risk territory, and to measure the severity of an incident. Organisations that limit themselves to a classic GDPR analysis (focus on personal data) miss the other fundamental rights at stake: non-discrimination, workers' rights, children's rights, environmental protection. This multi-rights analysis is also the foundation of the Fundamental Rights Impact Assessment required by Article 27 for certain deployers.
The 14 fundamental rights to map systematically
Recital 48 explicitly enumerates the rights to consider. For each AI system, your assessment must cover:
- Human dignity, private and family life, protection of personal data (already covered by CNPD via GDPR)
- Freedom of expression, information, assembly and association
- Non-discrimination (algorithmic bias on gender, origin, age, disability)
- Right to education and consumer protection
- Workers' rights (HR AI, productivity scoring, surveillance)
- Rights of persons with disabilities and gender equality
- Intellectual property (training data, generative outputs)
- Effective remedy, fair trial, rights of defence, presumption of innocence
- Right to good administration (AI in the public sector)
- Children's specific rights (Article 24 Charter + UNCRC General Comment No 25)
- Environmental protection (training carbon footprint, health impact)
The 'severity' test: the key argumentation lever before the EU AI Office
When you classify a system as not high-risk under Article 6(3), you must document why the impact on these rights is minor. Conversely, a robust Article 27 FRIA anticipates audits and drastically reduces the risk of retroactive reclassification. Severity is measured on three axes: severity of individual harm, scale of affected persons, reversibility of damage.
How Luxgap automates this risk
Our Luxgap Fundamental Rights Radar transforms the mapping of the 14 fundamental rights in Recital 48 into a continuous exposure score, opposable to the EU AI Office. A specialised LLM agent reads your technical specifications, training datasets and production logs (Azure ML, Vertex AI, AWS SageMaker, HuggingFace Spaces) to automatically detect which fundamental rights are affected by each model in service.
- Classifies each AI system against the 14 rights enumerated in Recital 48, with severity, scale and reversibility scores computed on your real data.
- Detects algorithmic bias by protected group (gender, age, origin, disability) by cross-referencing model outputs with the demographic distributions of your user base.
- Specifically alerts when minors are likely to interact with the system and applies the UNCRC General Comment No 25 grid (consent, advertising profiling, inappropriate content).
- Computes the carbon footprint of training and inference, mapped to the environmental criterion of Recital 48.
- Generates an Article 27 Fundamental Rights Impact Assessment ready to sign, structured according to the official EU AI Office template.
- Produces a timestamped, cryptographically sealed PDF report, opposable during an audit by the surveillance authority.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real models, with a free 48-hour blank audit to measure your exposure to the 14 fundamental rights before any engagement.