The classic trap
Recital 117 clarifies a frequently misunderstood point: codes of practice, harmonised standards and 'alternative adequate means' are not equivalent before the regulator. Many general-purpose AI model providers believe that a simple internal charter will suffice to demonstrate compliance with Chapter V obligations. In reality, only adherence to a code approved by the Commission via implementing act, or to a harmonised standard deemed adequate by the EU AI Office (Brussels), triggers the presumption of conformity. Any other route puts the burden of proof entirely on the provider, obligation by obligation, before the AI Office.
The hierarchy of compliance evidence to master
- Published harmonised standard + deemed adequate by the AI Office: automatic presumption of conformity, strongest level of proof.
- Code of practice approved by Commission implementing act: general validity across the Union, enforceable against the AI Office.
- Signed but non-approved code of practice: strong indicator but no automatic presumption.
- 'Alternative adequate means' (internal policy, external audit, proprietary methodology): admissible but the burden of proof falls entirely on the provider, with article-by-article demonstration required.
- Practical risk: choosing the 'alternative means' route without enforceable documentation exposes the provider to requalification as non-compliant during an AI Office investigation, with fines up to EUR 15M or 3% of global turnover (Article 101).
The specific trap for Luxembourg-based providers
Luxembourg AI startups and US group subsidiaries developing or fine-tuning GPAI models from the country often underestimate that they fall directly under the AI Office, without national intermediary. The CNPD remains competent on the personal training data aspect, but it is Brussels that will assess the adequacy of your compliance methodology. Building a credible alternative compliance proof requires cryptographic traceability of training, mapping of systemic risks and versioned, enforceable documentation.
How Luxgap automates this risk
Our Luxgap GPAI Compliance Compass eliminates uncertainty about which compliance route to follow by mapping in real time the status of codes of practice, CEN-CENELEC JTC 21 harmonised standards and published EU AI Office positions, then projecting your AI model onto the strongest available evidence route. The tool ingests your model card, training logs (Weights & Biases, MLflow, Hugging Face Hub) and internal policies to produce an article-by-article adequacy matrix for Chapter V.
- Continuously monitors the EU Official Journal and AI Office publications to detect each new code approval or harmonised standard impacting your model.
- Automatically maps your current practices (technical documentation, copyright policy, training data summary) onto Articles 53 and 55 requirements, and identifies gaps.
- Generates a versioned and timestamped compliance dossier that materialises the chosen route (approved code, harmonised standard or alternative means) with enforceable justification.
- Alerts as soon as a status change (code approved by implementing act, standard published) modifies your regulatory exposure and recommends switching to the presumption route.
- Produces a cryptographically sealed PDF report, enforceable before the AI Office in case of an Article 91 information request, demonstrating provider diligence.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your actual model, with a free blank audit within 48h to measure your exposure before any engagement.