The classic trap
Recital 118 creates a very useful but treacherous presumption of conformity: if your AI system is embedded into a designated Very Large Online Platform (VLOP) or Very Large Online Search Engine (VLOSE) already subject to the DSA, the corresponding AI Act obligations are presumed fulfilled. In practice, downstream providers (you, who integrate AI into your Meta Ads, Google, TikTok, X or LinkedIn services) confuse this presumption with a blanket exemption. The EU AI Office and the European Commission (DSA unit) expect you to document precisely which systemic risks are covered by the platform's DSA assessment and which are not. The CNPD remains competent on the personal data dimension, regardless of this articulation.
Questions to settle before invoking the presumption
- Is your AI system embedded in a VLOP/VLOSE designated by the Commission, or merely distributed through that platform? The presumption only applies to the former.
- Does the platform's DSA systemic risk assessment (Article 34 DSA) explicitly cover the specific risks of your AI model (bias, hallucinations, deepfakes, cognitive manipulation)?
- Are there systemic risks not covered by the DSA that push your system back into the full AI Act regime (notably Chapter V for general-purpose AI models with systemic risk)?
- Do you hold documentary evidence of this articulation, defensible during a joint EU AI Office / DSA Commission audit?
- Do your contractual clauses with the third-party platform grant you access to its DSA risk assessment report, or are you blind to what is presumed covered?
How Luxgap automates this risk
Our Luxgap AI-DSA Coverage Mapper eliminates the grey zone between the AI Act and Regulation (EU) 2022/2065 by automatically mapping, for each AI system in your catalogue, what is presumed covered by the host platform's DSA assessment and what remains your direct responsibility. The tool ingests your API integrations (Meta Marketing API, Google Ads API, TikTok Business, LinkedIn Marketing, Microsoft Advertising), retrieves the transparency reports published bi-annually by designated VLOPs/VLOSEs, and cross-references their systemic risk scope with the AI Act taxonomy (Articles 9, 10, 13, 15 and Chapter V).
- Detects every third-party AI system embedded in your services by scanning your advertising pixels, mobile SDKs and GTM tags, and identifies whether it is hosted by a designated VLOP/VLOSE.
- Parses the DSA systemic risk reports published by platforms and extracts via NLP the risks explicitly covered by their Article 34 DSA assessment.
- Computes a coverage delta: what is presumed compliant via DSA versus what requires your own AI Act measures (impact assessment, logging, human oversight).
- Triggers a real-time alert when the Commission designates a new VLOP/VLOSE or withdraws a designation, instantly reshaping your presumption perimeter.
- Generates a time-stamped legal memo, defensible before the EU AI Office, documenting why you invoke the Recital 118 presumption and on which exact scope.
- Produces the residual risk register, pre-filled to feed your AI Act conformity assessment.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will run a demonstration on your real AI integrations, with a free 48-hour blind audit to map your exposure before any commitment.