Public bodies and public-service deployers
The obligation reaches bodies governed by public law and private operators providing public services, which catches a wider set of organisations than the phrase suggests.

Dynamic FRIA™ · EU AI Act Art. 27
Article 27 requires certain deployers to assess the impact on fundamental rights before putting a high-risk system into use. The AI Office template contemplated by Art. 27(5) is not out. We build from the statutory requirements themselves and say so on the cover.
The honest position
That is an awkward thing to put on a product page and the alternative is worse. Any vendor implying otherwise is either mistaken or hoping you will not check.
What Art. 27 actually asks for
A description of the deployer's processes, the period and frequency of use, the categories of people affected, the specific risks of harm to them, human-oversight measures, and what happens if those risks materialise. Those requirements are in the text now, whatever form eventually carries them.
What we build against
Those requirements, structured, with the obligation set for your deployment cited to provision. When the AI Office form publishes, the substance transfers — because it was written against the statute rather than against a guess at the layout.
The ECNL / DIHR workbook, filled exactly
A civil-society template with real standing, and the most credible published structure available today. We fill it precisely. It is not the Art. 27(5) form, and the document says that in the first paragraph rather than the last footnote.
What happens when the form arrives
Documents built on the interim structure are flagged for re-check. You are told which of yours are affected; you decide what to do about them.
We bring the regulatory intelligence and the intake. You bring the privacy and legal judgment for your use case and organization. The document is built to hold both.
The division of labour, stated onceWho this is for
Most published writing on the AI Act addresses the people building systems. Article 27 lands on the people using them, and it lands earlier in practice than most teams expect.
The obligation reaches bodies governed by public law and private operators providing public services, which catches a wider set of organisations than the phrase suggests.
Including systems used in creditworthiness evaluation and in risk assessment and pricing for life and health insurance.
Even where the obligation does not attach, the exercise produces the dated record of consideration that is otherwise missing.
What this is not. LegisGate produces regulatory intelligence and assessment-preparation materials. Nothing we produce is legal advice, a legal opinion, a certification, or a determination of compliance, and no document we deliver satisfies a legal obligation on its own. Sufficiency is determined by your counsel. Whether Art. 27 attaches to a particular deployment is a determination, and whether a completed assessment is sufficient is your counsel's judgement.

Sequence
Article 27 attaches to deployers of high-risk systems. So the first question is not how do I write a FRIA — it is whether this deployment is high-risk at all, which is a determination with a right answer.
A Compass report classifies the system deterministically and tells you whether the obligation reaches you. If it does not, you have the record showing why.

Built on the statute, not on a guess
That is the whole reason to build against the requirements rather than against somebody's mock-up of a template — the work transfers instead of being redone.