The classic trap
The EU declaration of conformity looks like an administrative formality. It is actually the act by which the provider takes full and sole responsibility for the conformity of the high-risk AI system. During a market surveillance check or an EU AI Office investigation on a general-purpose model, missing any of the eight elements of Annex V, or worse a generic declaration copy-pasted from a CE machinery template, is enough to qualify the placing on the market as non-compliant. The biggest trap is point 5: forgetting the GDPR/EUDPR/LED reference when the system processes personal data, which opens a second front with the CNPD.
The 8 mandatory elements to lock down before signature
- Traceable identification of the AI system: commercial name, version, model hash, logical serial. Not just the marketing name.
- Provider identity (or EU authorised representative under Art. 22 if the provider is established outside the EU) with an enforceable address.
- Sole responsibility statement of the provider: imperative wording, not a soft good-faith attestation.
- Conformity with the AI Act plus any other applicable Union law (Machinery Regulation 2023/1230, Medical Devices 2017/745, etc.).
- GDPR/EUDPR/LED clause mandatory as soon as the system processes personal data, which covers almost all biometric, HR, credit scoring or educational systems.
- Harmonised standards used (ISO/IEC 42001, upcoming CEN-CENELEC JTC 21 standards) or common specifications adopted by the Commission.
- Notified body with identification number where third-party assessment is required (Annex VII).
- Place, date and signatory identified by name, function, and mandate to sign.
The declaration must be kept for ten years from the placing on the market (Art. 47(2)) and made available to the national competent authorities. It must be translated into a language easily understood by the authorities of the Member State where the system is made available, which is a real operational challenge for a Luxembourg provider distributing across 27 countries.
How Luxgap automates this risk
Our Luxgap AI Conformity Declarant turns the drafting of the EU declaration of conformity into an automatic output of your AI development cycle. Instead of filling a Word template at each release, the tool plugs a specialised LLM agent into your MLOps stack (MLflow, Weights & Biases, Azure ML, Vertex AI, Hugging Face Hub, GitLab) and extracts the eight Annex V elements directly from existing artefacts: model tags, version registry, conformity assessment reports, notified body certificates stored in SharePoint.
- Automatically generates the draft EU declaration of conformity at every major version of the AI system, including model identification, hash, version and training lineage.
- Detects whether the system processes personal data by parsing the feature schema and automatically inserts the GDPR/EUDPR/LED clause required under point 5.
- Maintains a living library of harmonised standards published in the OJEU and alerts when a new CEN-CENELEC JTC 21 standard makes your declaration obsolete.
- Translates the declaration into the 24 official EU languages through a lawyer-supervised pipeline, with Git versioning of each translation.
- Cryptographically seals each signed declaration (qualified eIDAS timestamping via LuxTrust) and stores it in a vault aligned with the ten-year retention required by Article 47(2).
- Produces an audit-ready bundle for the market surveillance authority or the EU AI Office, linking the declaration to the technical documentation of Annex IV.
Available as part of a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will run a demonstration on one of your real AI systems, with a free 48-hour gap analysis to measure the distance between your current declaration and the eight Annex V requirements.