The classic trap
Annex XII lists the technical documentation that a general-purpose AI (GPAI) model provider must hand over to downstream providers integrating its model. The trap: most Luxembourg integrators (CSSF-regulated fintechs, SaaS vendors, consulting firms) NEVER receive this documentation from OpenAI, Anthropic, Mistral or Google, and don't even know they can contractually demand it. As a result, they cannot fulfil their own Article 13 (transparency), Article 14 (human oversight) or Article 11 (technical documentation) obligations on their downstream AI system. The EU AI Office directly supervises GPAI providers, but it is the downstream integrator who will be hit by the CNPD if its HR chatbot hallucinates without traceable documentation.
The 11 elements GPAI documentation must contain, and that you must demand
- Intended tasks and target AI system types (point 1.a): verify your use case fits the declared scope.
- Acceptable use policies (point 1.b): the key to knowing whether you breach OpenAI/Anthropic terms by integrating into a medical or HR workflow.
- Release date and distribution methods (point 1.c): allows tracing the exact version in production.
- External hardware/software interactions (point 1.d): critical for AI agents calling third-party tools.
- Related software versions (point 1.e): essential for reproducibility and incident handling.
- Architecture and parameter count (point 1.f): supports carbon and sovereignty assessment.
- Modality and format of inputs/outputs (point 1.g): text, image, audio, video.
- Model licence (point 1.h): open weight, proprietary, commercial restrictions.
- Technical integration means (point 2.a): API, SDK, required infrastructure.
- Maximum input/output size including context window (point 2.b).
- Training data: type, provenance, curation methodologies (point 2.c): the most sensitive point, often missing or vague.
The contractual reflex to embed in YOUR AI supplier contracts
If you are a downstream integrator (you plug GPT-4o, Claude, Mistral Large, Gemini into your product), your contracts with these providers MUST require delivery of this Annex XII documentation on every major model update. Without that, you are structurally unable to meet your own AI Act duties and you simply transfer the risk to your end clients.
How Luxgap automates this risk
Our Luxgap GPAI Documentation Vault turns the chaotic collection of supplier technical PDFs into a living, versioned, audit-grade vault. The tool continuously monitors the public documentation portals of OpenAI, Anthropic, Mistral, Google DeepMind, Meta AI and Cohere, automatically downloads published Annex XII fact sheets, and matches them line by line against the 11 mandatory points to surface contractually exploitable gaps.
- Scrapes daily the model cards, system cards and technical reports of the main GPAI providers and detects any version update.
- Automatically maps each published element to the 11 Annex XII requirements and produces a completeness score per model (GPT-4o: 8/11, Claude 3.5 Sonnet: 9/11, Mistral Large 2: 7/11).
- Detects which GPAI models are actually used in your IT estate by analysing Azure OpenAI, AWS Bedrock, Google Vertex AI logs and outbound API keys via your proxy or Defender for Cloud Apps.
- Generates the contractual clause to insert in your AI supplier agreements to demand the missing documentation, in French, English and German.
- Sends Teams or email alerts as soon as a provider releases a new model version you run in production, with a diff of the documentary elements.
- Produces a timestamped PDF report, opposable to the EU AI Office and the CNPD, evidencing your downstream-provider due diligence under Article 53.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a demonstration and our teams run a free 48h scan of your API calls to GPAI models to measure your documentary exposure before any engagement.