FRIA Notification to National Supervisory Authority
Acme Insurance finished the FRIA for its credit-scoring AI on May 11, 2026. Eight weeks of work: seven sections of Article 27(1)(a)-(f) drafted, three sets of stakeholder consultations completed, the affected-persons appendix walked past works councils in five Member States. The draft sits on the General Counsel's desk with the FRIA owner's signature. The next sentence of Article 27, paragraph 3, reads: "Once the assessment referred to in paragraph 1 has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 as part of the notification." That sentence triggers a workstream most programs underestimate: per-Member-State notification design, template adaptation, submission-channel mapping, trade-secret redaction, proof-of-submission evidence, and a 10-year retention discipline tied to Article 18. This lesson is the L3 playbook for that workstream: the Article 27(3) notification template adapted from the AI Office's expected guidance, the per-Member-State authority directory as of mid-2026, the record-retention schedule under Article 18, and the worked example of Acme notifying France CNIL and Germany BfDI simultaneously for a multi-country credit-scoring deployment.
Article 27(3) Text and Trigger Conditions - When Notification Attaches
Article 27(3) reads, in operational paraphrase: once the FRIA referred to in Article 27(1) has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in Article 27(5). The text is unconditional: the obligation is not optional, not contingent on regulator request, not subject to a materiality threshold. Every completed FRIA generates a corresponding notification. Programs that treat Article 27(3) as voluntary or as triggered-only-on-inquiry have not completed the Article 27 obligation set, regardless of FRIA artifact quality.
Three trigger conditions for notification activate in the L3 program:
- Trigger 1 - Initial FRIA completion before first use. Article 27(1) requires the FRIA performed "prior to deploying a high-risk AI system." Sequence: FRIA completed → Article 27(3) notification filed → system placed into service. Notification is not a precondition for deployment (the authority does not approve or reject) but the record establishes the deployer's compliance posture. Pragmatic timing: file on or within five business days of FRIA completion and ahead of go-live; document submission timestamp and authority acknowledgment in the FRIA file.
- Trigger 2 - Substantial modification under Article 43(4). Article 43(4) treats a substantial modification of a high-risk AI system as triggering a new conformity assessment. "Substantial modification" is defined in Article 3(23), a change not foreseen in the provider's initial conformity assessment that affects compliance with the high-risk requirements or modifies the intended purpose. In practice: vendor model upgrades that materially shift scoring distributions; deployer fine-tune retraining on new data; addition of profiling not in the initial intended purpose; deployment-jurisdiction expansion adding a new Member State; integration of a new upstream data source; change of the human-oversight architecture. Each substantial modification triggers FRIA refresh and Article 27(3) re-notification scoped to the change.
- Trigger 3 - Periodic refresh required by national law or by the deployer's governance cycle. Some Member States are signaling expectations for periodic FRIA refresh notifications under Article 70 designations. Mature programs build an annual FRIA refresh cadence aligned to the artifact's anniversary and re-notify on each refresh, regardless of whether the underlying system changed materially. The annual notification creates audit-defensible cadence aligned with ISO 42001 Clause 9.3 management-review discipline.
Two non-trigger clarifications. Article 27(3) does not require notification of every FRIA-adjacent activity: quarterly bias-monitoring reports, stakeholder consultation minutes, internal governance briefings remain internal unless the program elects to share. And Article 27(3) is distinct from Article 73 incident reporting, which triggers on a serious incident affecting fundamental rights and follows a faster 15-day clock. Programs occasionally confuse the two and over-report routine FRIA refreshes through the incident channel.
Article 70 National Supervisory Authority Directory - Mid-2026 State of Play
Article 70 requires each Member State to designate at least one notifying authority and at least one market surveillance authority for the EU AI Act, and to communicate the designations to the Commission. The designations have been rolling through 2025-2026 with material variation by Member State on (a) whether a single authority handles both notifying and market-surveillance roles, (b) whether existing data-protection authorities (DPAs) are augmented or whether new AI-specific authorities are constituted, and (c) whether the FRIA notification under Article 27(3) goes to the market-surveillance authority, to the DPA, or to a joint single-point-of-contact under Article 75. As of mid-2026, the practitioner-facing directory is approximately:
- France. CNIL (Commission nationale de l'informatique et des libertés) is the Article 75 single-point-of-contact and handles Article 27(3) notifications for most Annex III categories. CNIL operates a dedicated AI Act portal with French-language template; sworn translation accepted for cross-border deployers. Acknowledgment target: 7 business days per CNIL's January 2026 practice note.
- Germany. Federal Network Agency (Bundesnetzagentur, BNetzA) designated as primary market-surveillance authority; BfDI (Bundesbeauftragte für den Datenschutz und die Informationsfreiheit) coordinates on personal-data overlap; BSI supports the Article 15 cybersecurity dimension. Article 27(3) notification routes through BNetzA with copies to BfDI where personal data processing is in scope. German-language template required; English summary as appendix. Länder DPAs handle subsidiary inquiries but the federal channel is the notification of record.
- Spain. AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), the first Member State stand-alone AI agency; AEPD coordinates on personal-data overlap. Article 27(3) through AESIA's online portal. Spanish-language template; co-official-language acceptance (Catalan, Basque, Galician) at AESIA's discretion. Acknowledgment target: 10 business days.
- Italy. Garante per la protezione dei dati personali handles AI Act intersections with personal data; AGID covers technical and sector-specific dimensions. Joint notification routes through Garante's portal with AGID coordination flagged. Italian-language template required.
- Netherlands. AP (Autoriteit Persoonsgegevens) leads with sector regulators (DNB financial, ACM consumer, RDI technical) coordinating. AP portal with sector-coordination flag where applicable. Dutch-language template; English accepted as practical matter for cross-border deployers.
- Ireland. DPC (Data Protection Commission) is the designated single-point-of-contact under Article 75; given Ireland's role as EU HQ for many US tech vendors, the DPC's Article 27(3) workload is disproportionately high. Online portal in English. Acknowledgment 10 business days; deeper review on complex cross-border deployments extends to 60-90 days.
- Belgium, Poland, Sweden. Belgium APD/GBA with trilingual requirement (NL/FR/DE) + English summary; Poland UODO with Polish template and sworn translation for English source FRIAs; Sweden IMY portal since Q4 2025 with Swedish template and English accepted in practice.
- Other Member States. Denmark / Finland / Austria / Portugal / Czech Republic / Hungary / Romania / Bulgaria / Greece / Slovakia / Slovenia / Croatia / Lithuania / Latvia / Estonia / Luxembourg / Malta / Cyprus and EEA Norway, designations rolling through 2025-2026; most have appointed the national DPA as lead with sector coordination. The European AI Board (Article 65) publishes a quarterly directory through 2026-2027.
Maintain an internal per-Member-State authority registry that the FRIA program references for each Article 27(3) notification. The registry tracks: designated authority name and contact; notification channel (portal URL, email, paper); template language and translation requirements; acknowledgment SLA; escalation contact; recent practice-note publication. The registry updates quarterly aligned to the European AI Board's directory refresh.
Notification Template Structure - Article 27(5) Adapted from AI Office Expected Guidance
Article 27(5) provides that the AI Office shall develop a template for the notification referred to in Article 27(3). The template is being progressively published through 2026. The structure that has emerged in pre-publication consultations covers ten sections; programs should adopt the ten-section structure now and refresh as the AI Office finalizes the template.
- Section 1 - Deployer identification. Legal name; registered office; LEI where applicable; national tax/registration ID; Article 5 of Directive (EU) 2015/849 ultimate beneficial owner where required by national law; named compliance contact (FRIA owner, position, email, phone); for non-EU deployers, the Article 25 EU-based authorized representative.
- Section 2 - System identification. System name and version; vendor/provider name and Article 25 EU representative; Article 71 EU database registration ID (cross-referenced where the provider has completed it); deployment instance ID; brief functional description (3-5 sentences); intended purpose per the provider's Article 13 instructions for use; deployment scope (Member States, locations, volume).
- Section 3 - Annex III category and sub-category. Citation to the specific Annex III paragraph and sub-paragraph triggering high-risk classification; rationale where multiple sub-categories arguably apply; cross-reference to the deployer's Article 6 high-risk classification artifact.
- Section 4 - FRIA summary. Condensed version of the FRIA artifact: (a) deployment process and intended purpose; (b) period and frequency of use; (c) categories of natural persons and groups likely to be affected; (d) specific risks of harm to fundamental rights; (e) human oversight measures (Article 14 integration); (f) measures if risks materialize, including governance and complaint-handling. Typically 5-15 pages depending on system complexity; the full FRIA artifact is referenced and made available on regulator request.
- Section 5 - Confidentiality and trade-secret claims. Explicit identification of sections containing commercially sensitive information, trade secrets, or other confidential data that the deployer requests be withheld from public disclosure under Article 78 confidentiality obligations. Each redaction is itemized with a redaction code, the rationale (trade secret / personal data / security-sensitive), and the cross-reference to the corresponding section of the full FRIA artifact. The supervisory authority retains discretion on the public-interest balance.
- Section 6 - Linked obligations. Cross-references to related compliance artifacts: Article 71 EU database registration ID; Annex IV technical file reference; ISO 42001 certification status and certificate ID if applicable; GDPR Article 35 DPIA where personal data processing in scope; Article 86 right-to-explanation design where applicable; Article 26(7) worker-representative consultation evidence; Member State implementing-law overlay artifacts.
- Section 7 - Date of notification. Timestamp of submission; deployer's internal FRIA artifact completion date; intended deployment date (initial go-live) or substantial-modification effective date.
- Section 8 - Multi-jurisdiction scope. Where the deployment spans multiple Member States, the list of Member States in scope; whether parallel notifications have been or will be filed in each Member State; the deployer's nomination of a coordinating authority under Article 75 single-point-of-contact framework where applicable.
- Section 9 - Contact for follow-up. Named individual responsible for responding to authority inquiries (typically the FRIA owner or AI Risk Manager); secondary contact (typically General Counsel or DPO); legal-representative contact for litigation or formal regulatory inquiry; preferred working language for follow-up.
- Section 10 - Signatures and approvals. FRIA owner signature; General Counsel sign-off; Chief AI Officer or equivalent senior accountable executive signature; deployer's authorized signatory under company governance rules. Where the notification is filed electronically via portal, the e-signature framework of the supervisory authority's portal applies; some authorities also require a signed PDF cover letter as backup.
The notification submission typically runs 15-30 pages. The full FRIA artifact (30-100+ pages) is retained internally and made available to the authority on request via secure transfer or controlled access.
Submission Channels, Multi-Jurisdiction Coordination, and Authority Response Expectations
Submission channels vary by Member State. Most authorities (CNIL, AESIA, DPC, AP, IMY) operate online portals with structured intake forms, e-signature support, and automated acknowledgment. Some (BNetzA, Garante) accept portal submission and email-with-PDF as transitional channel. A small number still require a signed paper original as backup within 30 days of electronic submission. File electronically through the portal where available and track per-Member-State channel requirements in the authority registry.
Multi-jurisdiction notification, for deployments spanning multiple Member States, is the most operationally complex element of Article 27(3) compliance. Two notification models are emerging in 2026 practice:
- Model A - Parallel per-Member-State notification. The deployer files a separate Article 27(3) notification in each Member State where the system is deployed. Each notification uses that Member State's template and language. The deployer cross-references the parallel notifications in Section 8 of each. This is the conservative default and is the recommended pattern where the Member States have not formally coordinated under Article 75 or Article 76. Operational burden: high (n Member States × full template adaptation), but legally robust and resilient to subsequent Member-State-specific inquiries.
- Model B - Coordinated single-point-of-contact notification under Article 75 with cascading notifications. The deployer files the primary notification with the Member State of its EU establishment or main place of business (analogous to GDPR Article 56 one-stop-shop), with the receiving authority undertaking to coordinate with the other affected Member States under Article 75 single-point-of-contact and Article 76 mutual-assistance provisions. The deployer's filing burden is lower (one primary notification + summary cross-notifications to other Member States) but the legal robustness depends on the receiving authority's actual coordination capacity. As of mid-2026, formal one-stop-shop is not yet established across all 27 Member States; Model B works where it works (e.g., Ireland DPC for US-headquartered deployers with EU subsidiary in Dublin; CNIL for France-headquartered) but breaks down in cross-border cases without clear primary establishment.
The pragmatic 2026 default is Model A with Model B aspirational. Multinational deployers with operations across 5-10 Member States file 5-10 parallel notifications and coordinate across receiving authorities; investment in the per-Member-State authority registry pays off across filings. Engage each receiving authority in advance of the first filing to confirm template, channel, language, and acknowledgment expectations; bilateral engagement also positions the deployer for cooperative inquiry handling later.
Authority response follows a two-stage pattern. Stage 1 - Initial acknowledgment. Per Commission draft guidance circulated Q1 2026, the authority acknowledges receipt within 7 business days (portal) or 14 business days (paper). Acknowledgment is procedural confirmation, not substantive approval or rejection. Stage 2 - Deeper review. Typical ranges: 30-60 days for routine notifications; 60-90 days for complex multi-jurisdiction or sector-sensitive cases; longer where supplementary information is requested. Stage 2 posture is cooperative engagement: respond to information requests promptly (10-20 business days), make the FRIA available through controlled-access, designate the named follow-up contact as single point of authority interaction, document each interaction. Most Stage 2 reviews in 2026 conclude with no further action or informal feedback; formal Article 79 corrective action or Article 99 penalty escalation remain rare and are driven by clear FRIA inadequacies or non-cooperation rather than technical disagreement.
Record Retention - Article 18 Discipline and the 10-Year Schedule
Article 18 requires providers of high-risk AI systems to keep specified documentation at the disposal of national competent authorities for 10 years after the system has been placed on the market or put into service. The deployer-side analog under Article 26 and the integrated record-keeping discipline that Article 27 FRIA work generates extends the same 10-year retention period to FRIA artifacts, Article 27(3) notification records, and supporting evidence. The retention schedule:
- FRIA artifact and all annexes, 10 years from system end-of-life. The FRIA artifact itself, including all appendices (stakeholder consultation minutes, bias-monitoring reports, vendor documentation references, GDPR Article 35 DPIA where combined, NIST AI RMF Map 5 cross-walk where applicable). End-of-life is the later of (a) system decommissioning or (b) last use of any FRIA-generated decision (e.g., a credit decision based on the system may remain consequential for the data subject for years after the system is decommissioned). The conservative read is to anchor end-of-life to the later date.
- Article 27(3) notification submission record, 10 years from submission. The notification PDF as submitted; the portal-submission timestamp; the authority's acknowledgment with reference number; any subsequent correspondence with the authority; the deployer's responses to authority inquiries. Each Member State's notification record is retained separately for multi-jurisdiction deployers, with cross-references.
- Proof-of-submission evidence, 10 years from submission. Portal-submission screenshots; email send-receipts; certified-mail receipts for paper backup; portal-acknowledgment IDs; any authority-issued reference numbers. The evidence chain establishes that the notification was filed and received, which becomes critical if a subsequent dispute arises about whether the deployer met the Article 27(3) obligation.
- FRIA refresh history, 10 years from each refresh. Each refresh creates a new FRIA version (v1.0, v1.1, v2.0 on substantial modification, etc.); each version is retained with the rationale for the refresh, the changes from the prior version, and the corresponding Article 27(3) re-notification record where applicable. The refresh history demonstrates living-document discipline and aligns with ISO 42001 Clause 9.3 management-review evidence.
- Stakeholder-consultation evidence, 10 years from each consultation. Works-council consultation minutes; affected-stakeholder engagement records (where the FRIA included direct affected-stakeholder input); legal-counsel sign-off records; General Counsel signature pages. These records substantiate the FRIA's Article 27(1)(c)-(d) affected-persons and risk analysis and become important in disputes about FRIA adequacy.
- Authority-interaction records, 10 years from interaction. Any authority inquiries, requests for supplementary information, in-person briefings, informal feedback, or formal supervisory measures, with the deployer's responses. The record establishes the cooperative-engagement posture and is referenced in subsequent inquiries.
The retention discipline cross-walks to three complementary frameworks. ISO 42001 Annex A.7 (records and documentation) controls cover documented information lifecycle: creation, identification, format, review, approval, distribution, access, retrieval, storage, retention, disposition. The FRIA retention schedule evidences A.7 control implementation. GDPR Article 5(1)(e) storage-limitation principle requires personal data kept "no longer than is necessary"; the 10-year FRIA retention is justified by GDPR Article 6(1)(c) legal-obligation lawful basis (AI Act Article 18 record-keeping) and Article 9(2)(g) substantial-public-interest basis for special-category data. Note the AI Act Article 10(5) explicit carve-out: special-category data may be processed for the strictly necessary purpose of bias detection and correction in high-risk systems with corresponding security and access controls. Article 78 confidentiality requires storage location and access controls implementing confidentiality obligations on deployers handling regulator-shared information, aligned with affected-persons sensitivity and trade-secret protection.
Confidentiality, Trade Secrets, Multi-Deployment, and Substantial Modification
Four operational topics merit dedicated treatment because programs commonly underweight or misread them.
Confidentiality and trade-secret protection. Article 78 imposes confidentiality obligations on national competent authorities, market surveillance authorities, notified bodies, the European AI Board, the Commission, and any other natural or legal persons involved in the application of the Regulation. Authorities receiving Article 27(3) notifications are bound by these obligations. The deployer's complementary right is to claim trade-secret or commercially-sensitive-information protection on specific sections (typically: vendor model architecture; deployer fine-tune training data; deployment-instance scoring thresholds; proprietary bias-mitigation methodology; vendor-supplied confidential information). Claim process: itemize each redaction in Section 5 with a code, rationale, and cross-reference; submit a public version and a confidential version; the authority balances the claim against public-interest disclosure expectations. CJEU and national courts have jurisprudence on the analogous trade-secret balance under GDPR Article 15 DSAR contexts; AI Act jurisprudence is emerging through 2026-2027.
Multi-deployment notification design for cross-border systems. Where a single system is deployed across multiple Member States, parallel notification (Model A) is the conservative default. Operational discipline: (1) maintain a single master FRIA artifact covering the multi-jurisdiction footprint with consolidated affected-persons analysis, risk analysis, mitigation, monitoring, and Article 14 human-oversight design; (2) generate per-Member-State notification packages from the master by adapting Section 4 to local language and context (e.g., German Betriebsrat evidence for Germany; CNIL-specific scope description for France); (3) cross-reference all parallel notifications in Section 8 with Member-State list and submission timestamps; (4) coordinate inquiry handling: share supplementary responses across parallel authorities to maintain consistency; (5) maintain a multi-jurisdiction notification tracker rolling up submission timestamps, acknowledgment IDs, inquiry status, and resolution for the quarterly AI Governance Committee briefing.
Substantial-modification re-notification. Article 43(4) substantial-modification triggers FRIA refresh and Article 27(3) re-notification. The scope of re-notification depends on the modification's scope:
- Update-only re-notification (delta scope). Where the modification is bounded and the rest of the FRIA remains unchanged (e.g., vendor model upgrade with new bias-monitoring baseline but unchanged intended purpose, affected persons, and mitigation), a delta re-notification covering only the changed sections plus the cross-reference to the prior notification is acceptable. The supervisory authority's portal often supports incremental updates; the deployer's record retains both the original and the delta as a series.
- Full re-notification (complete refresh scope). Where the modification is fundamental (e.g., expansion of intended purpose to a new use case; addition of profiling not in initial scope; change of deployer-type from private-sector to private-operator-providing-public-services; entry into a new sub-category of Annex III), a full re-notification is required. The full re-notification is a fresh template submission with the new FRIA artifact attached; the prior notification is closed with a cross-reference to the new submission.
- Timing. Re-notification should ideally precede the substantial modification taking effect; in practice, the re-notification timeline should be planned with the modification rollout schedule and should not lag behind the operational change. The pragmatic discipline: file the re-notification on or within 5 business days of the FRIA refresh completion and ahead of the modification effective date.
Article 70 + Article 74 + Article 75 + Article 76 interplay. Article 70 designates national authorities; Article 74 elaborates market-surveillance powers; Article 75 establishes single-point-of-contact for cross-border cases; Article 76 covers mutual assistance between Member-State authorities. The Article 27(3) notification is filed with the market-surveillance authority (Article 74 power to receive); the deployer may nominate a single-point-of-contact under Article 75; receiving authorities may invoke Article 76 mutual assistance for cross-border review. Map the per-Member-State Article 70 designation and the operational practice on Article 75/76 coordination as part of the authority registry.
Worked Example - Acme Insurance Credit-Scoring FRIA Notification to France CNIL and Germany BNetzA
Acme Insurance deploys a §5(b) creditworthiness scoring AI for life-insurance-policy underwriting decisions across its EU operations. The system is hosted on Acme's EU-hosted infrastructure in Dublin and serves the Acme operating entities in France (Paris office, ~25,000 underwriting decisions per year) and Germany (Frankfurt office, ~40,000 underwriting decisions per year), with smaller volumes in Spain, Italy, Belgium, Netherlands (treated as separate parallel notifications). The FRIA was completed May 11, 2026; Article 27(3) notification is being prepared for filing ahead of the May 25, 2026 go-live.
The notification workstream:
- Master FRIA artifact. 78-page consolidated artifact covering Article 27(1)(a)-(f), with French- and German-specific appendices on national consumer-credit regulator overlays (ACPR for France; BaFin for Germany), Solvency II model-risk overlay across both, and Article 86 right-to-explanation design integrated into the customer-facing underwriting flow.
- France CNIL notification. 22-page submission via CNIL's AI Act notification portal. French-language Section 4 FRIA summary (14 pages) drafted by Acme's Paris legal team with sworn translation review; English appendix for internal use. Section 5 confidentiality claims itemize 4 redactions: vendor model architecture, Acme fine-tune training data composition, scoring thresholds, internal bias-mitigation methodology. Section 8 lists Germany, Spain, Italy, Belgium, Netherlands as parallel notifications. Submission May 20, 2026; CNIL acknowledgment May 27, 2026 (5 business days, within 7-day SLA).
- Germany BNetzA notification. 24-page submission via BNetzA's online portal with copy to BfDI flagged. German-language Section 4 FRIA summary (16 pages) by Acme's Frankfurt legal team with sworn translation review; English summary as appendix. Section 5 mirrors the CNIL confidentiality claims. Section 6 additionally cross-references the German Betriebsrat consultation completed April 2026 and the BaFin coordination on Solvency II model-risk-validation alignment. Submission May 21, 2026; BNetzA acknowledgment May 30, 2026.
- Stage 2 inquiry handling. CNIL Stage 2 on July 14, 2026 requesting the full bias-monitoring report and four-fifths-rule selection-rate analysis across protected categories; Acme response July 28, 2026 (10 business days). BNetzA Stage 2 on August 4, 2026 requesting Article 14 human-oversight design detail and Article 86 customer-facing explanation language; Acme response August 20, 2026. Both reviews concluded September-October 2026 with no formal supervisory measure and with informal feedback on bias-monitoring methodology that Acme voluntarily incorporated in the Q4 2026 refresh.
- Record retention. Full FRIA, both notification packages, portal timestamps and acknowledgments, Stage 2 inquiries and responses, Q4 2026 delta re-notifications, and the 2027 anniversary refresh, all retained in Acme's FRIA record system with 10-year retention from system end-of-life. Access controls limit access to Acme legal, compliance, audit; copies available to external auditors (Schellman for ISO 42001, KPMG for Big-4 advisory) under NDA and to regulators on request via secure transfer.
The worked example illustrates the operational pattern: master FRIA + parallel per-Member-State notifications + bilateral authority engagement + Stage 2 inquiry handling + refresh-and-re-notify cadence + 10-year retention. The pattern scales across multinational and single-jurisdiction deployers; the discipline is the same.
Cross-Walks and Six Common Mistakes
The Article 27(3) notification cross-walks across the EU AI Act articles and the broader governance-framework landscape:
- EU AI Act Article 27(3) + Article 27(1) + Article 27(5). Article 27(3) attaches once Article 27(1) FRIA is performed; Article 27(5) provides the AI Office template. The three paragraphs are read together as a single obligation set.
- Article 70 + Article 74 + Article 75 + Article 76 + Article 78. Article 70 designates national authorities; Article 74 elaborates market-surveillance powers; Article 75 establishes single-point-of-contact; Article 76 provides mutual assistance; Article 78 imposes confidentiality. The Article 27(3) notification flows through this institutional framework.
- Article 18 + Article 26 record-keeping discipline. Article 18's 10-year retention for high-risk-system documentation extends to FRIA artifacts and notification records by integrated read.
- Article 43(4) substantial-modification + Article 73 incident reporting. Substantial modification triggers FRIA refresh and Article 27(3) re-notification (Article 43(4)); serious-incident events trigger separate Article 73 reporting (15-day clock). The two pathways are distinct.
- Article 71 EU database registration. The provider's Article 71 registration generates a system-level identifier that the deployer's Article 27(3) notification cross-references in Section 2.
- GDPR Article 5(1)(e) storage limitation + Article 10(5) bias-monitoring carve-out. The 10-year FRIA retention is justified under GDPR Article 6(1)(c) legal-obligation lawful basis (AI Act Article 18); Article 10(5) explicitly permits special-category data processing for bias-monitoring purposes.
- ISO 42001 Annex A.7 records and documentation. A.7 controls cross-walk to the FRIA retention schedule and to the Article 27(3) notification record management.
- Charter of Fundamental Rights Article 41 right to good administration. Article 41 informs the deployer's expectation of authority responsiveness during Stage 1 acknowledgment and Stage 2 review and supports the deployer's right to be heard if formal supervisory measures are considered.
Mistake 1 - Treating Article 27(3) as Voluntary or Triggered-Only-on-Inquiry
Article 27(3) is unconditional. Every completed FRIA generates a notification. Programs that complete the FRIA artifact and skip the notification face Article 99(3) penalty exposure (€15M / 3% global turnover tier). The trigger memo discipline tracks per-row notification-readiness and prevents the omission.
Mistake 2 - Single-Member-State Notification for Multi-Member-State Deployment
Where the system is deployed across multiple Member States, the conservative default is Model A parallel per-Member-State notification. Single-Member-State notification (e.g., filing only with Ireland DPC on the theory that the deployer is Ireland-headquartered) is risky absent clear establishment of a single-point-of-contact arrangement under Article 75 with all affected Member-State authorities. The multi-jurisdiction notification tracker prevents this error.
Mistake 3 - Missing the Substantial-Modification Re-Notification
Article 43(4) substantial modification triggers FRIA refresh and Article 27(3) re-notification. Programs that refresh the FRIA internally on substantial modification but do not file the re-notification have not completed the obligation. The FRIA refresh runbook should include the re-notification step as a mandatory checklist item with named accountability.
Mistake 4 - Weak Retention Discipline
The 10-year retention under Article 18 (extended to FRIA and notification records by integrated read) requires deliberate record-management discipline: storage location, access controls, version history, refresh records, authority-interaction records. Programs that store FRIA artifacts on individual SharePoint folders without retention-policy enforcement risk evidence loss at the 5-7 year mark when corporate IT migrates or when individuals leave. Centralized FRIA record system with policy-enforced retention is the discipline.
Mistake 5 - Missing the Trade-Secret Confidentiality Claim Where Appropriate
Article 78 confidentiality obligations on authorities protect deployer trade secrets and commercially sensitive information, but the deployer must affirmatively claim the protection by itemizing redactions in Section 5 of the notification. Programs that file the full FRIA artifact without confidentiality claims expose vendor and deployer trade secrets to potential subsequent disclosure (e.g., under access-to-information requests). The Section 5 confidentiality claim is the protective mechanism and should be actively used where appropriate.
Mistake 6 - No Proof-of-Submission Evidence
Portal submissions generate acknowledgment IDs; paper submissions should be sent certified-mail with return receipt; email submissions should retain send-receipts and authority acknowledgment emails. The proof-of-submission evidence chain establishes that the notification was filed and received. Programs that file Article 27(3) notifications without retained proof-of-submission evidence face exposure if the authority later disputes receipt or if the deployer needs to demonstrate timely compliance in a subsequent inquiry. Each notification's proof-of-submission evidence is retained for 10 years alongside the notification record itself.
Key Takeaways
- Article 27(3) is unconditional. Every completed FRIA triggers a notification to the national supervisory authority. Three triggers: initial FRIA completion before first use; substantial modification under Article 43(4); periodic refresh required by national law or by the deployer's governance cycle.
- Article 70 national-authority designations vary by Member State. Maintain an internal per-Member-State authority registry tracking designated authority, notification channel, template language, acknowledgment SLA, escalation contact, recent practice notes. Refresh quarterly aligned to European AI Board directory updates.
- The Article 27(3) notification template covers ten sections. Deployer identification; system identification (with Article 71 EU database registration cross-reference); Annex III category and sub-category; FRIA summary (5-15 pages); confidentiality and trade-secret claims under Article 78; linked obligations cross-references; date of notification; multi-jurisdiction scope; contact for follow-up; signatures and approvals.
- Submission channels vary by Member State. Most authorities (CNIL, AESIA, DPC, AP, IMY) operate online portals; some (BNetzA, Garante) support portal + email transitional; a few still require paper backup within 30 days. File electronically through the portal where available; track per-Member-State channel requirements in the authority registry.
- Multi-jurisdiction notification, Model A (parallel per-Member-State) is the 2026 default. Multinational deployers file n parallel notifications across n Member States with cross-references in Section 8. Model B (single-point-of-contact under Article 75) works where it works but breaks down in cross-border cases without clear primary establishment.
- Authority response, two-stage pattern. Stage 1 initial acknowledgment within 7 business days (portal) or 14 business days (paper) per Commission draft guidance. Stage 2 deeper review ranges 30-90 days depending on complexity; most Stage 2 reviews in 2026 conclude with no further action or informal feedback rather than formal supervisory measures.
- Substantial-modification re-notification under Article 43(4). Delta re-notification for bounded changes; full re-notification for fundamental changes (new intended purpose, profiling addition, deployer-type change, Annex III sub-category change). File on or within 5 business days of FRIA refresh completion, ahead of modification effective date.
- Record retention, 10 years from system end-of-life per Article 18 integrated read. FRIA artifact and annexes; Article 27(3) notification submission record; proof-of-submission evidence; FRIA refresh history; stakeholder-consultation evidence; authority-interaction records. Cross-walk to ISO 42001 Annex A.7 and to GDPR Article 5(1)(e) with Article 10(5) bias-monitoring carve-out.
- Confidentiality and trade-secret protection under Article 78. Authorities are bound by confidentiality obligations; deployers must affirmatively claim trade-secret protection by itemizing redactions in Section 5 of the notification. Vendor model architecture, deployer fine-tune training data, scoring thresholds, proprietary bias-mitigation methodology are typical redaction categories.
- Six common mistakes, treating Article 27(3) as voluntary; single-Member-State notification for multi-deployment; missing substantial-modification re-notification; weak retention discipline; missing trade-secret confidentiality claim; no proof-of-submission evidence. Each mistake is recoverable when caught in the notification workstream design; each is materially harder to recover at the audit or regulator inquiry.
Skill.re