The classic trap
Many Luxembourg companies integrating a general-purpose AI model (GPT-4, Claude, Mistral Large, Gemini) assume that AI Act compliance is fully carried by the upstream provider. Wrong: recital 116 sets the stage for codes of practice steered by the EU AI Office, which become the de facto standard for demonstrating compliance with the obligations of articles 53 and 55. A downstream deployer that does not verify whether its provider adheres to the GPAI Code of Practice published in July 2025 exposes itself to a broken documentary chain, particularly scrutinised by the CNPD on the personal data side and by the EU AI Office on the systemic risks side.
Why this recital changes your AI procurement practice
Recital 116 turns codes of practice into the reference for interpreting GPAI obligations. Concretely, your provider due diligence must verify:
- The public adherence of the model provider to the EU AI Office GPAI Code (signature, version, date).
- The systemic risk taxonomy used by the provider (cyber-offensive, CBRN, loss of control, cognitive manipulation) and its alignment with the AI Office taxonomy.
- Specific mitigation measures documented by the provider (red teaming, evaluations, model cards, incident reporting).
- The chain traceability: upstream provider -> integrator -> your deployment, with proof that each link honours the Code.
- Consistency with other international frameworks (NIST AI RMF, ISO/IEC 42001, Hiroshima Process) referenced by the recital.
How Luxgap automates this risk
Our Luxgap GPAI Code Tracker turns the monitoring of GPAI codes of practice into a continuous, court-proof radar. The tool ingests in real time the publications of the EU AI Office, the Scientific Panel and major providers (OpenAI, Anthropic, Google DeepMind, Mistral, Meta, Cohere), cross-references those signals with your actual AI inventory (extracted from M365 Copilot, Azure OpenAI, AWS Bedrock, your API integrations), and instantly materialises the gaps between upstream commitments and your downstream usage.
- Automatically detects every GPAI model used across your IT estate via Azure logs, AWS CloudTrail, Google Cloud Audit and connected SaaS invoices.
- Tracks the version of the GPAI Code signed by each provider and alerts on withdrawal, non-renewal or divergence with the version in force published by the AI Office.
- Classifies each model according to the AI Office systemic risk taxonomy and flags models exceeding the 10^25 cumulative FLOPs threshold.
- Automatically generates the specific risk assessment and mitigation measures sheet, ready to be appended to your article 53 compliance file.
- Produces a timestamped, cryptographically sealed PDF report, opposable to the EU AI Office and the CNPD during an audit, demonstrating that your GPAI chain respects the Code of Practice in force.
- Sends Teams or Slack alerts whenever a provider publishes a new model card, an incident report or an update to its commitments under the Code.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI estate, with a free 48-hour blind audit to measure your GPAI exposure before any engagement.