AIGO — EU AI Act Rights and Remedies Mapping
1. Document Purpose
This document provides the AIGO mapping for rights, fundamental-rights safeguards, complaints, explanations, access to information, human review, regulatory remedies, and related protections under Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. The mapping translates relevant EU AI Act requirements into the AIGO governance framework covering:- fundamental-rights protection;
- affected-person identification;
- fundamental-rights impact assessment;
- data protection interaction;
- transparency;
- human oversight;
- explanations and information;
- complaint mechanisms;
- regulatory complaints;
- affected-person communications;
- bias and discrimination;
- monitoring;
- incident management;
- corrective action;
- evidence;
- assurance;
- management review; and
- continual improvement.
2. Mapping Information
3. Rights Governance Principle
AIGO should treat fundamental-rights protection as a lifecycle governance responsibility. The preferred model is:4. Source Hierarchy
4.1 Binding Legal Sources
The primary legal source is: Regulation (EU) 2024/1689 as amended by: Regulation (EU) 2026/1744 The current EUR-Lex legal text is authoritative. Rights and remedies may also be governed by other EU and national law, including:- data protection law;
- equality and anti-discrimination law;
- consumer protection law;
- employment law;
- administrative law;
- sector-specific law;
- judicial remedies.
5. Fundamental-Rights Scope
Potential rights and interests affected by AI systems may include:- human dignity;
- privacy;
- personal data protection;
- non-discrimination;
- equality;
- freedom of expression;
- freedom of association;
- freedom of assembly;
- freedom of thought and conscience;
- right to an effective remedy;
- presumption of innocence;
- rights of the child;
- workers’ rights;
- access to essential services;
- democratic participation;
- human autonomy.
6. AIGO Fundamental-Rights Governance Control
Control Name: Fundamental-Rights AI Governance Control Objective: Identify, assess, mitigate, monitor, and remediate material fundamental-rights risks arising from applicable AI systems. Control Owner: AI Governance Owner / Fundamental-Rights or Compliance Owner. Frequency:- before deployment where applicable;
- before material change;
- after material incidents;
- after relevant regulatory change;
- periodically according to risk.
- rights assessment;
- affected-person analysis;
- safeguards;
- decisions;
- monitoring;
- complaints;
- remediation;
- assurance.
7. Affected-Person Model
AIGO should identify individuals and groups potentially affected by an AI system. Potential categories include:8. Affected-Group Analysis
The organization should consider whether a system may disproportionately affect:- protected groups;
- vulnerable people;
- children;
- persons with disabilities;
- economically vulnerable people;
- socially vulnerable people;
- employees;
- applicants;
- persons with limited access to alternative services.
9. Fundamental-Rights Impact Assessment
Article 27 requires certain deployers of high-risk AI systems to conduct a fundamental-rights impact assessment in the circumstances specified by the Regulation. The Commission explains that this requirement applies to certain public-law bodies and private operators providing public services, and to operators of high-risk AI systems used for certain creditworthiness or life/health-insurance pricing or risk assessments. The Commission also explains that where a data protection impact assessment is required, the fundamental-rights impact assessment should be conducted in conjunction with it.10. Article 27 AIGO Mapping
Relationship:DIRECT / CONDITIONAL / CRITICAL
AIGO Components:
- Assessment;
- Risk;
- Governance;
- Evidence;
- Human Oversight;
- Monitoring;
- Assurance.
11. Article 27 Applicability Record
The AIGO assessment should determine:12. Article 27 and Data Protection Impact Assessment
The amended Article 27 permits cross-reference to relevant sections of a GDPR Article 35 DPIA or Article 27 DPIA under Directive (EU) 2016/680 where those obligations already address the relevant matters. AIGO should therefore support:13. Combined Assessment Governance
Where a DPIA and Article 27 assessment overlap, AIGO should identify:- common issue;
- DPIA section;
- Article 27 section;
- remaining rights considerations;
- remaining privacy considerations;
- responsible owner;
- approval;
- evidence.
14. Fundamental-Rights Assessment Content
AIGO should assess, where relevant:- purpose;
- affected individuals;
- affected groups;
- decision context;
- power asymmetry;
- potential rights impacts;
- discrimination;
- privacy;
- autonomy;
- dignity;
- access to services;
- human oversight;
- transparency;
- remedies;
- safeguards;
- residual risk.
15. Bias and Discrimination
The amended AI Act explicitly recognizes bias detection and correction as an important protection of persons from adverse effects, including discrimination, and extends attention beyond providers of high-risk systems to potential bias arising from deployer activity and other AI systems. AIGO should therefore treat bias governance as potentially relevant beyond the strict high-risk-provider context.16. Bias Governance Control
Control Name: AI Bias Detection and Correction Control The control should cover:- bias identification;
- relevant protected characteristics;
- data and output analysis;
- testing;
- mitigation;
- residual impact;
- monitoring;
- correction.
17. Bias Evidence
Potential evidence:- bias assessment;
- demographic performance analysis where lawful;
- test results;
- mitigation records;
- model changes;
- complaints;
- monitoring;
- assurance.
18. Non-Discrimination
AIGO should evaluate whether AI use could:- create discriminatory outcomes;
- amplify existing disparities;
- unfairly restrict access;
- create differential treatment;
- produce indirect discrimination;
- obscure decision responsibility.
19. Human Oversight
Human oversight can provide an important rights safeguard. AIGO should define:- responsible person;
- authority;
- competence;
- intervention;
- override;
- escalation;
- review.
20. Human Decision Review
Where AI contributes to a consequential decision, AIGO should consider:- what the AI actually determined;
- what the human reviewed;
- whether the human had sufficient information;
- whether the human could challenge or override the output;
- whether reasons were documented;
- whether the person affected had a meaningful route to challenge.
21. Explanation and Information
The AI Act contains specific information and transparency requirements in particular contexts. AIGO should distinguish:22. Explanations for High-Risk Decisions
Where applicable law requires an explanation or information regarding an AI-assisted decision, AIGO should record:- decision;
- AI role;
- decision-maker;
- explanation provided;
- date;
- recipient;
- method;
- complaint route.
23. Complaints
AIGO should support internal complaints relating to:- AI decisions;
- transparency;
- bias;
- discrimination;
- inappropriate use;
- system errors;
- rights impact;
- inability to obtain information.
24. Regulatory Complaint Mechanisms
The amended AI Act includes complaint mechanisms relevant to AI Office supervision for AI systems under its competence. The amended Article 75 framework allows the AI Office to act following complaints concerning covered operators and AI systems. AIGO should maintain the ability to:- receive complaints;
- assess jurisdiction;
- preserve evidence;
- notify legal/compliance;
- cooperate with authorities where required;
- track regulatory responses.
25. Complaint Intake Control
Control Name: AI Rights Complaint Management The control should define:- intake;
- identity;
- affected AI system;
- issue;
- claimed right;
- urgency;
- safeguarding;
- investigation;
- response;
- escalation;
- remedy;
- evidence.
26. Complaint Triage
Complaints may be categorized as:27. Vulnerable Persons
Complaints involving:- children;
- persons with disabilities;
- vulnerable persons;
- serious rights impacts;
- urgent safety risks
28. Access to Information
AIGO should maintain procedures for determining what information affected persons are entitled to receive. Potential information may include:- AI use;
- purpose;
- decision context;
- relevant explanation;
- responsible organization;
- complaint route;
- correction process.
29. Transparency Relationship
Rights governance should link to the Article 50 transparency mapping. Recommended chain:30. Remedies
AIGO should support remediation mechanisms such as:- correction;
- reconsideration;
- human review;
- system restriction;
- decision reversal where appropriate;
- compensation where legally required;
- escalation to an authority;
- process improvement.
31. Human Reconsideration
Where an AI-assisted outcome can materially affect an individual, AIGO should consider whether an appropriate human reconsideration mechanism is needed. Potential process:32. Decision Auditability
For material AI-assisted decisions, AIGO should retain enough information to reconstruct:- system version;
- relevant input/context;
- output;
- human review;
- decision;
- reason;
- applicable policy;
- date;
- affected-person communication.
33. Right to Challenge
Where applicable, AIGO should provide a meaningful mechanism for a person to challenge an AI-assisted outcome. The mechanism should identify:- how to submit;
- responsible function;
- response timeframe;
- escalation;
- records;
- remediation.
34. Human Review and Automation Bias
AIGO should address the risk that humans may defer excessively to AI output. Controls may include:- review protocols;
- independent evidence checks;
- uncertainty display;
- challenge procedures;
- escalation;
- reviewer training;
- sampling.
35. Fundamental-Rights Risk
AIGO should support a dedicated risk category:FUNDAMENTAL_RIGHTS_RISK
Potential risk sources:
- discriminatory outputs;
- exclusion;
- surveillance;
- inaccurate classification;
- automated denial;
- profiling;
- opacity;
- lack of human review;
- inappropriate inference.
36. Rights Risk Treatment
Treatment may include:- human review;
- restrictions;
- additional testing;
- transparency;
- data improvement;
- controls;
- monitoring;
- alternative decision paths.
37. Children
AI systems involving children should receive enhanced consideration of:- rights;
- vulnerability;
- safety;
- privacy;
- manipulation;
- transparency;
- age-appropriate communication.
38. Persons with Disabilities
AIGO should consider:- accessibility;
- assistive technology;
- discrimination;
- communication;
- human review;
- alternative channels.
39. Employment Context
Where AI systems affect workers or employment decisions, AIGO should consider:- worker information;
- transparency;
- human review;
- discrimination;
- complaint routes;
- workplace governance;
- applicable employment law.
40. Essential Services
Where AI decisions affect access to essential services or benefits, AIGO should emphasize:- fairness;
- accuracy;
- human review;
- explanations;
- complaints;
- remediation;
- monitoring.
41. Creditworthiness
Where an applicable high-risk AI system performs creditworthiness assessment, AIGO should consider:- discrimination;
- explainability;
- human review;
- evidence;
- complaint mechanism;
- affected-person communication;
- fundamental-rights assessment.
42. Insurance
Where applicable high-risk AI is used for life or health insurance pricing or risk assessment, AIGO should consider:- discrimination;
- sensitive characteristics;
- transparency;
- human oversight;
- fundamental-rights impact;
- complaints;
- remediation.
43. Law Enforcement Context
AI systems used in law-enforcement contexts require heightened rights governance. Potential considerations:- proportionality;
- necessity;
- human oversight;
- accountability;
- evidence;
- affected-person rights;
- legal authorization.
44. Migration and Border Control
AI systems used in migration, asylum, or border-control contexts may have significant rights impacts. AIGO should consider:- vulnerability;
- dignity;
- access;
- human review;
- appeal or complaint;
- transparency;
- evidence.
45. Justice and Democratic Processes
AI used in judicial or democratic contexts may affect:- fairness;
- procedural rights;
- access to justice;
- democratic participation;
- public trust.
46. Rights and Privacy
The amended AI Act explicitly states that Union law on personal-data protection, privacy, and communications confidentiality continues to apply to personal data processed under the AI Act. AIGO should therefore maintain:47. Rights and Data Protection
The organization should avoid treating a DPIA as automatically covering every AI Act rights obligation. Instead:48. Rights and Security
Security incidents may become rights incidents. Example:49. Rights and AI Incidents
A serious incident affecting rights should trigger:- containment;
- investigation;
- affected-person analysis;
- legal review;
- remediation;
- communication;
- evidence preservation;
- assurance.
50. Rights Monitoring
Monitoring may include:- complaints;
- demographic disparities;
- decision reversals;
- false positives;
- false negatives;
- accessibility complaints;
- explanation requests;
- human-review outcomes;
- recurring rights issues.
51. Rights Assurance
Assurance may review:- rights assessments;
- affected-person identification;
- controls;
- human review;
- complaints;
- remediation;
- evidence;
- monitoring.
52. Rights Evidence
Potential evidence includes:53. Rights Evidence Quality
Evidence should be:- attributable;
- current;
- complete;
- relevant;
- traceable;
- protected.
54. Complaint Evidence
A complaint record should include enough information to demonstrate:- receipt;
- issue;
- investigation;
- decision;
- response;
- remediation;
- escalation where necessary.
55. Rights and Monitoring Evidence
Monitoring should retain enough evidence to reproduce material findings. For example:56. Rights and Change Management
A material change should trigger rights-impact review where it affects:- target population;
- decision context;
- data;
- model;
- capability;
- autonomy;
- intended purpose;
- deployment geography;
- human oversight;
- explanation mechanism.
57. Rights and Retirement
Retirement should preserve relevant rights-related records where required, including:- historical decisions;
- complaints;
- incidents;
- evidence;
- regulatory communications;
- retention obligations.
58. Rights and Governance
The Governance Schema should define:- accountability;
- rights oversight;
- escalation;
- decision authority;
- legal/compliance responsibilities.
59. Rights and Management Review
Management review should consider:- rights-impact findings;
- complaints;
- discrimination indicators;
- serious incidents;
- regulatory developments;
- remediation;
- assurance;
- affected-person trends.
60. Rights and Continual Improvement
Improvement activities may include:- redesign;
- additional human review;
- improved transparency;
- data improvement;
- new controls;
- complaint-process improvements;
- user support;
- training;
- monitoring enhancements.
61. Regulatory Rights and AI Office Complaints
For AI systems under AI Office supervision, the amended legal framework enables complaints to trigger AI Office supervisory action within its competence. AIGO should therefore maintain:- regulatory complaint intake;
- jurisdiction assessment;
- evidence preservation;
- legal review;
- response process;
- regulatory interaction record.
62. Rights of Defence in AI Office Proceedings
The amended Article 75 framework expressly provides rights of defence and access to the file for operators within the AI Office’s supervisory scope, subject to confidentiality and business-secret protections. AIGO should support:- legal representation;
- file-access coordination;
- confidentiality review;
- business-secret protection;
- evidence preservation;
- response tracking.
63. Access to Regulatory File
Where legally applicable, the organization should maintain a controlled process for:- access request;
- legal review;
- confidentiality review;
- negotiated disclosure;
- internal distribution;
- record keeping.
64. Judicial Review
Where the AI Act provides judicial remedies or review mechanisms, AIGO should preserve:- decision;
- legal basis;
- deadline;
- representation;
- evidence;
- submissions.
65. Rights and Transparency
The rights-and-remedies mapping should connect to:04-AIGO-EU-AI-Act-Transparency-Mapping-v0.1.md
The relationship is:
66. Rights and Prohibited AI Practices
Article 5 is relevant because the prohibited-practice framework protects fundamental rights. The relationship should be:67. Rights and High-Risk AI
The High-Risk mapping remains authoritative for:- Article 9 risk management;
- Article 13 transparency;
- Article 14 human oversight;
- Article 27 fundamental-rights impact assessment;
- related high-risk requirements.
68. Rights Control Matrix
69. Rights Traceability Chain
The minimum AIGO chain should be:70. Rights Findings
Potential findings include:71. Critical Rights Findings
Potential critical findings include:- applicable Article 27 assessment absent;
- material discriminatory impact not addressed;
- high-impact AI decision lacks required human oversight;
- statutory complaint mechanism not supported where applicable;
- material rights incident lacks remediation;
- affected persons cannot exercise an applicable legal right;
- evidence needed for a rights matter is improperly destroyed.
72. Rights Coverage
A future AIGO Rights Coverage Validator may measure:73. Rights Metrics
Potential management metrics include:
Metrics should not be treated as legal-compliance percentages.
74. Rights Evidence Coverage
Evidence requirements may include:- rights assessment;
- affected-person analysis;
- bias assessment;
- human-review evidence;
- complaints;
- explanations;
- remediation;
- monitoring;
- assurance.
75. Rights Assurance Coverage
Assurance should assess:- whether rights impacts were identified;
- whether controls exist;
- whether human oversight works;
- whether complaints are handled;
- whether remediation is effective;
- whether evidence is sufficient.
76. Rights and AI Literacy
Relevant personnel should receive contextual AI literacy on:- rights impacts;
- discrimination;
- human oversight;
- transparency;
- complaints;
- escalation.
06-AIGO-EU-AI-Act-AI-Literacy-Mapping-v0.1.md
77. Rights and Governance Enforcement
Rights-related concerns may lead to regulatory involvement. The Governance and Enforcement mapping remains authoritative for:- authorities;
- inspections;
- complaints to authorities;
- investigations;
- corrective measures;
- enforcement.
78. Rights and Conformity
For applicable high-risk systems, rights-related evidence may contribute to conformity assessment. However:79. Rights and Evidence Protection
Rights-related evidence may be highly sensitive. AIGO should apply:- access controls;
- minimization;
- retention rules;
- integrity;
- confidentiality;
- role-based access.
80. Rights and Legal Privilege
Legal advice concerning rights matters may be privileged depending on applicable law. AIGO should preserve operational traceability while limiting unnecessary distribution of privileged material.81. Rights and Regulatory Change
Changes in:- AI Act provisions;
- data protection law;
- equality law;
- consumer law;
- employment law;
- sectoral law;
- national implementation
82. Rights Regulatory Watch
The organization should monitor:- AI Act amendments;
- Commission guidance;
- AI Office material;
- AI Board outputs;
- national authority guidance;
- court decisions;
- data protection authority guidance;
- equality and human-rights developments.
83. Rights Review Frequency
Minimum:- annual;
- event-driven after material legal change;
- after material rights incident;
- after serious complaint;
- after relevant assurance finding;
- before major AIGO release.
84. Current Amendment Baseline
Regulation (EU) 2026/1744 is part of the current legal baseline and modifies several rights-related AI Act mechanisms. Notably, it:- retains the AI Act’s fundamental-rights protection objective;
- clarifies interaction with EU data-protection law;
- amends Article 27 to allow cross-references to applicable DPIAs;
- strengthens attention to bias detection and correction;
- modifies the supervisory and enforcement architecture relevant to complaints and rights of defence.
85. Current Enforcement and Complaints Baseline
The amended AI Office framework allows complaints to inform supervisory action for AI systems within AI Office competence, while preserving procedural rights including access to the file subject to confidentiality safeguards. AIGO should therefore maintain two distinct routes:86. Limitations
This mapping cannot independently determine:- whether a particular right has legally been infringed;
- whether discrimination exists under applicable law;
- whether a person has a specific statutory remedy;
- whether an explanation is legally sufficient;
- whether a complaint is admissible before an authority;
- whether a fundamental-rights impact assessment is legally required in a particular fact pattern;
- whether a particular remedy must be provided.
87. Validation Requirements
The mapping should satisfy:Legal Source Validation
Rights provisions trace to current law.Applicability Validation
Affected actor and affected persons are identified.Assessment Validation
Article 27 applicability is explicitly evaluated where relevant.Rights Validation
Potentially affected rights are identified.Control Validation
Rights safeguards are mapped to AIGO controls.Remedy Validation
Applicable complaint and remediation routes are identified.Evidence Validation
Rights decisions and safeguards have evidence requirements.Authority Validation
External complaint routes identify the appropriate authority where known.Privacy Validation
Rights evidence remains aligned with data-protection requirements.Consistency Validation
Rights terminology aligns with the master mapping and high-risk mapping.88. Relationship to Other EU AI Act Mappings
89. Relationship to AIGO Schemas
No separate Rights Schema is required at this stage.
90. Relationship to AIGO Templates
Relevant templates include:- AI System Registration;
- AI System Profile;
- AI Classification;
- AI Risk Assessment;
- AI Control Assessment;
- AI Approval;
- AI Monitoring;
- AI Incident;
- AI Change Management;
- AI Assurance;
- AI Management Review;
- AI Continuous Improvement;
- AI Evidence Record.
91. Relationship to AIGO Tools
The rights mapping should be supported by:- Schema Validator;
- Reference Validator;
- Traceability Validator;
- Control Coverage Validator;
- Evidence Coverage Validator;
- Framework Consistency Checker;
- Document Integrity Checker;
- Repository Health Checker.
92. Document Control
93. Document Status
Document: AIGO — EU AI Act Rights and Remedies Mapping Version: 0.1 Status: Draft Working Name: AIGO Full Name: AI Governance Operating Framework Document Identifier:AIGO-MAP-EUAI-009
Document Type: EU AI Act Mapping
This document maps fundamental-rights protections, affected-person governance, Article 27 impact assessment, complaints, explanations, human review, remediation, regulatory complaints, evidence, assurance, monitoring, and continual improvement into the AIGO AI Governance Operating Framework.
End of Document