EU AI Act – Regulation (EU) 2024/1689
High-Risk AI Deployment Pack
Article 26 & Article 27 Fundamental Rights Impact Assessment — Regulation (EU) 2024/1689
The obligations that fall on you when you deploy a high-risk AI system — not the ones your vendor already met. Including the fundamental rights impact assessment you must complete, and notify to your regulator, before the system’s first use.
Drafted by a qualified lawyer, includes twelve months of updates.


4 documents, 48 pages




The Obligation Most Deployers Don’t Know They Have
Almost everything written about the AI Act is written for providers — the companies that build high-risk systems. Very little is done for the organisations that deploy them. That gap is where the risk sits.
If you use a high-risk AI system — to score credit, price insurance, screen candidates, allocate a public service, support a decision that affects someone’s rights — Article 26 places continuing obligations on you, arising from use.
Vendor conformity assessments don’t discharge these obligations.
And if you’re a public body, a private provider of a public service, or a deployer in credit or insurance, Article 27 requires you to complete a fundamental rights impact assessment before you first use the system, and to notify the market surveillance authority of the results.
There is no official template for it. The obligation is substantial, the assessment is yours alone to make. Most often, these obligations are carried by a bank, an insurer, or a public authority — you cannot absorb a misstep.
This pack is the instrument for avoiding costly mistakes.
Why a Generic Template Cannot Satisfy the Obligation
A fundamental rights impact assessment is not a form. The assessment subject is your deployment: your process, your affected population, and what happens to a real person when the system is wrong.
The same system, used by two organisations, produces two different assessments. Nothing your vendor supplies can substitute for it, because your vendor doesn’t know your process, the people it affects, or the consequence to them of an adverse outcome. A downloadable “FRIA template” that ignores this is worse than nothing: it produces a document that looks complete and assesses nothing.
What can be built — and what this is — is a rigorous structure that follows the six statutory elements of Article 27 in order, prompts the questions organisations habitually avoid, and records your reasoning so the assessment can be defended to a regulator, updated when your deployment changes, and notified with confidence.
What This Pack Does (That Others Don’t)
It follows the statute element by element. Article 27(1)(a)–(f) prescribes six mandatory contents. The assessment mirrors them exactly, so a regulator reviewing your notified results can trace each element to your analysis. No invented structure to argue with.
It forces the questions that matter and are easiest to skip. Are you a deployer — or have you quietly become a provider under Article 25 by fine-tuning or re-branding the system, and inherited a far heavier regime? Does your “human oversight” actually let the overseer depart from the system’s output — or does your override rate sit at zero because departing is professionally costly and no one is looking?
These are the questions that decide whether your compliance is real, and they are the ones a generic pack never asks.
It refuses the box-ticking version of oversight. Article 26(2) is trivially easy to satisfy on paper and routinely fails in practice. The pack requires the evidence that distinguishes genuine oversight from a rubber stamp: departure rates, time per case, automation-bias controls, and whether your overseer has the authority and the practical capacity to act.
It treats the assessment as a defensible legal position, not paperwork — because a bank or a public authority will be asked to defend it, and “we filled in the template” is not a defence.
What You Get in This Pack
Deployer Applicability and FRIA Trigger Assessment — Establishes whether you’re a deployer, whether the system is high-risk, whether you’ve become a provider under Article 25, and — decisively — whether the Article 27 duty is triggered for you. The trigger is narrower than “any high-risk deployer” and widely misread; this resolves it.
Fundamental Rights Impact Assessment — The flagship. Fourteen pages structured to the six statutory elements: your process, the affected population and its vulnerable sub-groups, the specific risks of harm expressed as harms to people rather than failures of the model, your oversight measures, and — the element regulators test hardest — what you will actually do when a risk materialises, including governance and complaints. With the notification and DPIA interface built in.
Deployer Obligations Record — The full set of Article 26 duties, paragraph by paragraph, as a maintained operational record: use within the instructions, competent oversight, input-data quality, monitoring and suspension, log retention, the duty to inform workers before deployment, and the duty to tell affected people a system was involved in a decision about them.
Human Oversight and Monitoring Evidence — The evidence layer that substantiates the oversight and monitoring you assert everywhere else: the metrics, the escalation path, the suspension capability, and the logging that lets an adverse decision be reconstructed when someone contests it.
Every document follows the structure of the European Commission’s own explanatory notices and templates.
43 pages across four documents. Word format, editable, plus a read-only PDF.
Who Is This For
- Banks and lenders deploying creditworthiness and credit-scoring systems.
- Life and health insurers using AI in risk assessment and pricing.
- Public authorities and the private companies that deliver public services — in education, healthcare, housing, employment, and social services — deploying high-risk AI that bears on people’s rights.
If an adverse output from your system could cost someone a loan, a job, a home, a place, or a benefit, this is the obligation that governs it.
Start With the Free Document
The Deployer Applicability & FRIA Trigger Assessment is free, complete, and requires no email address.
It answers the two questions that determine everything else: are you caught by Article 26, and is the Article 27 fundamental rights impact assessment triggered for you? Given how often the trigger is misread — in both directions — this is worth completing before you spend anything, and before you deploy.
Download the free Applicability Assessment
Who Wrote This
Written by a qualified lawyer working in EU AI regulation, not assembled from a template library.
A fundamental rights impact assessment commissioned from a law firm is a substantial engagement — commonly well beyond the fifteen-to-thirty-hour range of a straightforward compliance deliverable, given the analysis it requires.
This pack gives you that structure to work within, at a fraction of the cost, with the reasoning already built in.
What the Price Covers
€1,449 — the full pack, including twelve months of updates.
Priced for the deliverable it is. This is not a disclosure notice; it is the documentation a regulated institution or public body relies on to deploy a high-risk system lawfully, and to answer for it afterwards.
For most deployers I’d recommend the reviewed engagement below. A fundamental rights impact assessment is exactly the document where a second, independent legal read earns its cost — and where completing it alone is hardest.
After twelve months, updates continue for €500 a year (billed separately), or keep the version you have.
The Engagement Most Deployers Should Take
Pack with review — €7,500. You complete the assessment and the records; we review them with the scrutiny a regulator would bring — the Article 25 provider question, the reality of your oversight, whether your risk analysis would survive challenge — and write up what’s weak, what’s missing, and what to fix before you notify.
Full assessment — from €15,000. We perform the fundamental rights impact assessment and the deployer analysis with you, and deliver the completed, notification-ready pack.
Authorised representative and ongoing support. For providers established outside the EU, and for deployers needing continuing assurance. On enquiry.
Part of European AI Act Compliance Suite
A high-risk deployment rarely stands alone. The same system may also interact with people, generate content, or infer emotions — each a separate transparency obligation. Consider these:
Chatbot & Agent Disclosure (50(1))
Synthetic Content Marking (50(2))
Emotion Recognition & Biometric Categorisation (50(3))
What This Pack Is Not (Important)
It is documentation, not advice on your particular circumstances — and given what it governs, that line matters more here than anywhere else on this site.
It does not perform the assessment for you. The fundamental rights impact assessment turns on your process, your population, and your judgment about real harms. The pack gives you the structure and the questions; the analysis is yours, and for most regulated deployers it should be reviewed by counsel — which is what the reviewed engagement is for.
It does not make you compliant. If your oversight is nominal or your risk analysis thin, a rigorous assessment will show that — which is the point of doing it properly before a regulator does it for you.
