The classic trap
Recital 100 closes a major loophole: integrating a general-purpose AI model (GPT-4, Llama, Mistral Large) into your application does not exempt you from the GPAI system regime. Organisations that think of themselves as mere 'integrators' discover they actually inherit provider obligations as soon as their product can serve a variety of purposes, something the EU AI Office monitors actively at European level. The CNPD remains competent in parallel on the personal data dimension of these systems.
The practical 'variety of purposes' test
To determine whether your integration falls into the GPAI system category, ask these concrete questions:
- Does your user interface allow free prompting, even partially (chat, semantic search, text generation)?
- Have you technically constrained the model to a single purpose (closed classification, predefined field extraction) or does it retain its native versatility?
- Do your terms of use formally prohibit out-of-scope uses, and do you have technical safeguards (locked system prompt, output filtering, out-of-domain rejection)?
- Is the underlying model called directly by the end user or orchestrated by your business layer which filters inputs and outputs?
- Do you document the responsibility chain with the upstream model provider (OpenAI, Anthropic, Mistral, Meta) via an Article 25 agreement on transferred obligations?
The cascade of obligations
If you qualify as a GPAI system provider, you inherit technical documentation (Annex XI), transparency obligations toward downstream deployers, and copyright compliance for training data passed through. If your integration also adds a high-risk purpose (Annex III), you cumulate Chapter III obligations. The classic mistake is believing that the contract with OpenAI or Anthropic is enough: it transfers certain guarantees but does not relieve you of your own obligations as provider of the integrated system.
How Luxgap automates this risk
Our Luxgap GPAI Integration Scanner eliminates the blind spot of LLM integrations by automatically mapping every call to a general-purpose AI model in your IT estate and qualifying the resulting legal status. The tool deploys a network probe and an agent that inspects your API gateways, Azure OpenAI containers, AWS Bedrock endpoints, Mistral and Anthropic keys, and reconstructs the actual integration chain without questioning your developers.
- Automatically detects every GPAI model called from your applications by inspecting outbound flows to OpenAI, Anthropic, Mistral, Cohere, Google Vertex and Hugging Face Inference APIs.
- Qualifies each integration against the Recital 100 test by analysing the prompt template, technical safeguards and openness of the end-user interface.
- Generates prefilled Annex XI technical documentation, broken down by integration, ready to submit to the EU AI Office on request.
- Alerts in real time as soon as a new GPAI model appears in your Azure, AWS or Datadog logs, preventing shadow AI from product teams.
- Verifies consistency between upstream model provider contractual commitments and your residual obligations as downstream system provider.
- Produces a timestamped PDF report demonstrating your complete GPAI mapping as of 2 August 2026, the date obligations apply.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real LLM integrations, with a free 48-hour scan to materialise your exposure before any engagement.