Article 27 of the EU AI Act requires a Fundamental Rights Impact Assessment before deploying any High-Risk AI system. Bridge 03 confirmed all four Halstead & Cole systems are Not High-Risk. So the FRIA obligation isn't triggered — yet. This module documents that determination, and gives you the full template for when it is.
Article 27 of Regulation (EU) 2024/1689 requires deployers of high-risk AI systems to conduct a Fundamental Rights Impact Assessment (FRIA) before deployment. The obligation is conditional: it applies only where REG-AIMS-CLASS-001 records a High-Risk classification. If all systems are Not High-Risk — as is the case for Halstead & Cole LLP — the FRIA is not currently required. FRIA-AIMS-001 records both positions: Part A confirms the non-trigger with COLP sign-off; Part B is the full Art. 27(1)(a)–(h) assessment template, pre-structured and ready to activate if any system is reclassified.
James Okafor, Partner, attends an AI governance briefing hosted by Pemberton Capital. The session covers the EU AI Act compliance programme. The presenter mentions that "deployers of high-risk AI systems must complete a Fundamental Rights Impact Assessment before using those systems." James returns to the office and asks Priya Anand: "Do we need to do one of these?"
Priya opens FRIA-AIMS-001. Part A: Non-Trigger Confirmation. Four systems assessed in REG-AIMS-CLASS-001. Zero High-Risk. Article 27 FRIA not currently required. COLP sign-off dated 25 July 2026. She forwards the document to James with a covering note: "No — our systems are Not High-Risk. This document confirms the assessment and the basis for it. If we ever add or change an AI system that turns out to be High-Risk, Part B of the same document is the FRIA template we'd complete."
James is satisfied. More importantly, the document exists. When the compliance deadline arrives (2 December 2027 for standalone systems) and Pemberton Capital asks for the firm's full EU AI Act documentation pack, the FRIA non-trigger confirmation is in it — alongside the classification register, the literacy register, the Article 50 statement, and the other bridge documents.
A compliance programme that only documents obligations it has met creates a structural gap: an auditor examining the programme will ask "did you assess whether Article 27 applied, and if not, why not?" A programme that documents both the trigger assessment and its outcome — including outcomes where the obligation is not triggered — is demonstrably more complete. FRIA-AIMS-001 Part A is the record of that assessment. It takes one session to sign and costs nothing to maintain.
"Prior to deploying a high-risk AI system referred to in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, deployers that are bodies governed by public law, or private operators providing public services, as well as deployers referred to in point (a) of Article 27(2), shall perform a fundamental rights impact assessment for the high-risk AI systems referred to in Annex III."
Three elements determine whether a law firm deploying an Annex III high-risk AI system must conduct a FRIA under Article 27(1).
First: the system must be High-Risk under Annex III. This is the Bridge 03 gateway. If REG-AIMS-CLASS-001 records Not High-Risk for every system, Article 27 does not apply in its basic form.
Second: the deployer category matters. Article 27(1) explicitly covers bodies governed by public law and private operators providing public services. Law firms are private entities providing legal services — not public services in the technical sense. However, Article 27(2) extends the obligation to private deployers in certain contexts, and the Commission may issue delegated acts expanding the scope. Firms should not rely on the private-entity carve-out as a permanent shield without legal advice.
Third: even where Article 27 doesn't strictly apply, the FRIA is best practice. A firm that voluntarily conducts or templates a FRIA demonstrates proactive governance — and if the scope expands, is already prepared.
Law firms using AI to assist in asylum or immigration applications (Area 7) or in legal aid eligibility assessments (Area 5) are the most likely candidates for a High-Risk classification in the legal sector. If REG-AIMS-CLASS-001 records a High-Risk outcome for any such system, Article 27 applies and Part B of FRIA-AIMS-001 shall be completed before the system is used in that specific context. Do not rely on the Halstead & Cole Not High-Risk outcome as a precedent for firms in different practice areas.
The EU AI Act Simplification Regulation (Omnibus VII, adopted 29 June 2026) postpones national AI regulatory sandboxes to 2 August 2027. For firms that activate Part B of FRIA-AIMS-001 for a high-risk system, regulatory sandboxes offer a supervised testing pathway under competent authority oversight — an option available before the 2 December 2027 compliance deadline for standalone high-risk systems. Firms planning to deploy high-risk AI tools should consider the sandbox option as a risk-mitigation pathway during the implementation period.
Under ITIL 4, the FRIA maps to two practices. As a Risk Management input, it identifies which fundamental rights are placed at risk by a high-risk AI system and what mitigations are required before the system enters service. As a Service Validation and Testing event, it is the pre-deployment sign-off gate for any high-risk AI system — analogous to the HITL sign-off in PROC-AIMS-HITL-001 but operating at the system level rather than the output level. The FRIA approval is the "system-level green light"; the HITL sign-off is the "output-level green light." Both are required for high-risk systems.
Documents the Bridge 03 outcome. All four Halstead & Cole systems are Not High-Risk. Article 27 is not currently triggered. COLP sign-off confirms the assessment is accurate and the trigger conditions are understood and being monitored. This part is immediately complete — it requires only COLP signature.
Pre-structured against all eight mandatory FRIA dimensions. Activated only if any AI system receives a High-Risk classification. All [BRACKETED PLACEHOLDERS] are populated for the specific system being assessed. Completion target: within 30 days of reclassification, before the system is used in the high-risk use case.
The commercial rationale for including Part B in the same document is operational efficiency. If a firm adds a new AI system in 2027 — a legal research tool, an automated matter management system, or an AI-assisted compliance checker — and that system receives a High-Risk classification from REG-AIMS-CLASS-001, the firm does not need to commission a new document framework. Part B is already structured, the approach is already approved by the COLP, and the assessment can begin immediately.
Article 27(1)(a)–(h) specifies eight mandatory dimensions. Every completed Part B shall address all eight. The template in FRIA-AIMS-001 pre-structures each dimension with guidance questions and an assessment field. Here is what each dimension requires in plain terms:
What the AI system does in the firm's workflow, who operates it, whose decisions it informs, and how many people are affected. This is the factual context from which all subsequent dimensions flow.
When the system will be deployed and how often. Relevant because more frequent use increases the volume of potential rights impacts — a system used once a year has a different risk profile than one used for every matter.
Who is affected by the AI system's outputs — not just the fee earner using it, but the clients, third parties, and other persons whose rights or interests may be influenced. Vulnerability factors shall be considered: financial vulnerability, limited literacy, minority status, age, or distress.
The core of the FRIA. For each fundamental right potentially at risk — referenced against the EU Charter of Fundamental Rights — assess likelihood, severity, and residual risk after mitigations. The rights most commonly implicated in legal AI contexts: non-discrimination (Art. 21), privacy and data protection (Arts. 7 & 8), right to effective remedy (Art. 47), human dignity (Art. 1).
What human oversight is in place to catch and correct AI errors that could harm fundamental rights. For law firms with PROC-AIMS-HITL-001 operative, this dimension points directly to the sign-off procedure — supplemented with any enhanced measures required for the specific high-risk use case.
What the firm will do if a fundamental rights harm actually occurs. References PROC-AIMS-EUINC-001 (Bridge 05) for the incident response pathway, plus any specific notification obligations to affected persons or the national competent authority.
Every Dimension D risk with a residual rating above LOW shall have a mitigation documented here with an implementation status. No high-risk AI system shall be deployed with open HIGH residual risks — these are blocking conditions on the Part B approval sign-off.
Does the system also require a Data Protection Impact Assessment under UK GDPR Article 35? If so, how do the DPIA and FRIA interact? Which risks are addressed by each? High-risk AI systems processing personal data will almost certainly require both.
The EU Charter of Fundamental Rights provides the rights framework for Dimension D. Four articles are most commonly implicated in legal sector AI use cases:
| Fundamental Right | Charter Reference | Why It Matters in Legal AI | Key Risk Scenario |
|---|---|---|---|
Human Dignity |
Art. 1 | AI system outputs that demean, dehumanise, or produce discriminatory characterisations of clients or opposing parties | AI-generated matter summaries that categorise individuals using stereotyped or reductive language |
Privacy and Family Life |
Art. 7 | Client confidential information processed through AI APIs; inference data potentially retained by providers | Client communications passed to AI system without adequate data processing controls |
Data Protection |
Art. 8 | Personal data of clients and third parties processed by AI system; lawful basis for AI-assisted processing; data subject rights over AI outputs | AI system processes special category data (health, legal proceedings) without explicit legal basis |
Non-Discrimination |
Art. 21 | AI system trained on biased data may produce systematically different quality outputs for clients of different protected characteristics | Legal research AI that surfaces less case law for matters involving ethnic minority clients due to training data bias |
Effective Remedy |
Art. 47 | Persons affected by AI-assisted legal decisions must have access to explanation and recourse; AI opacity cannot remove the right to challenge | AI-generated eligibility assessment communicated to client without disclosure or right of challenge |
FRIA-AIMS-001 Part A confirms that Bridge 04 is not triggered by classification for Halstead & Cole LLP in its current state. Bridges 05 and 06 are not gated by classification — they apply regardless of whether any system is High-Risk. Bridge 05 (Incident Notification) is a risk management measure for all AI deployments. Bridge 06 (GPAI Verification) applies specifically to firms using General-Purpose AI models such as GPT-4o under certain deployment configurations. Both proceed independently.
| Module | Gap | Trigger | Status |
|---|---|---|---|
| EU Bridge 01 | Art. 4 — AI Literacy | In force — all firms | Complete ✓ |
| EU Bridge 02 | Art. 50 — Transparency | 2 Dec 2026 — all firms | Complete ✓ |
| EU Bridge 03 | Annex III Classification | 2 Dec 2027 (standalone) / 2 Aug 2028 (embedded) | Complete ✓ |
| EU Bridge 04 | Art. 27 — FRIA | If High-Risk classification | This Module ✓ |
| EU Bridge 05 | Art. 26(5) — Incident Notification | Dec 2027 — all AI deployers | Next |
| EU Bridge 06 | Arts. 25 & 53 — GPAI | Dec 2027 — GPAI deployers | Planned |
The following gates were checked before publication. All 10 gates pass. This record satisfies ISO 9001:2015 Clause 7.5.3 for the EU AI Act Bridge Series.
Governance Academy members receive the complete FRIA-AIMS-001 Word document: Part A pre-populated for Halstead & Cole, Part B pre-structured against all eight Art. 27(1) dimensions with guidance questions. Adapt and sign in one session. £97/month. All documents owned permanently.
Join the Governance AcademyThis article is published for educational purposes only and does not constitute legal advice. The FRIA template in Part B of FRIA-AIMS-001 is a structured assessment framework — it is not a completed FRIA and does not substitute for qualified legal input on the specific fundamental rights implications of a given AI system in a given deployment context. Dimension D in particular requires expert judgement on EU Charter rights that goes beyond what a template can provide. Halstead & Cole LLP, Priya Anand, James Okafor, and Pemberton Capital LLP are fictional constructs. Any resemblance to real persons or firms is coincidental. · Document ref: ART-AIMS-EU-004 v1.1 · Published 25 July 2026 · Next review: 25 October 2026 · Retention: 7 years · UNUS London Ltd. · unuslondon.com/legal/eu-ai-act-bridge-04-fria-fundamental-rights-impact-assessment