The classic trap
Recital 109 sets out a deceptive proportionality principle: many actors conclude they are exempt because they are an SME, because they do research, or because they only fine-tune an open source model. This reading is dangerous. The EU AI Office considers that as soon as a fine-tuned model is placed on the market or put into service for professional purposes, the fine-tuner becomes a provider for the scope of its modification, with up-to-date technical documentation, copyright policy and training data summary. The CNPD, on its side, remains competent on personal data used for training, with no SME proportionality benefit.
The qualification test: am I truly exempt or simply lightened ?
- Non-professional or pure scientific research use: full exemption, but must be documented (academic publication, no market placement, no direct or indirect monetisation).
- SME or start-up placing a model on the market: no exemption, but simplified compliance routes (documentation templates, narrative training data summary, lighter copyright policy).
- Fine-tuning of a third-party model: obligations limited to the scope of the modification (new training data, new risks introduced, new target uses), without restating the upstream model documentation.
- Substantial modification of an open source model: if the modification changes capabilities or risk profile, you become a full provider for the modified scope.
- Research funded by an industrial partner with a commercialisation clause: automatic exit from the research regime, return to the provider regime from first availability.
The operational trap: a Luxembourg start-up that fine-tunes Llama or Mistral on its own customer data cannot simply point to Meta's or Mistral's documentation. It must produce a documentation addendum on its fine-tuning, its data sources and the risks introduced.
How Luxgap automates this risk
Our Luxgap GPAI Proportionality Navigator determines in under 5 minutes your exact regime under the AI Act (exempt, lightened SME, full provider, scoped fine-tuner) and automatically generates the minimal documentation file matching your situation, without imposing on you the documentation burden of an OpenAI or an Anthropic. The tool queries your Hugging Face registry, your MLflow or Weights and Biases pipelines, your GitLab repositories and your customer contracts to reconstitute the real value chain of every model you deploy or modify.
- Automatically qualifies every model in your stack (foundation, fine-tune, RAG, distillation) and determines whether you are a provider, scoped fine-tuner, deployer or research-exempt.
- Generates a lightened technical documentation compliant with Annex XI Part 1, calibrated to the SME or start-up status declared at the Luxembourg trade register.
- Produces the fine-tuning addendum that complements the upstream model documentation (Llama, Mistral, Falcon) with your new training sources, without duplicating what already exists upstream.
- Detects loss of research exemption eligibility as soon as a commercialisation contract or licence clause appears in Odoo or DocuSign.
- Publishes the narrative training data summary in the EU AI Office template format, ready to transmit upon information request.
- Tracks SME threshold evolution (headcount, turnover, balance sheet) and alerts when you cross the threshold triggering full compliance.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS brick depending on your perimeter. Request your demonstration and our teams prepare a proof of value within 48h on your real models, with free qualification of your AI Act regime before any engagement.