The classic trap
Recital 119 creates a dangerous grey zone: your AI chatbot, augmented search engine or conversational assistant may be simultaneously subject to the AI Act AND the Digital Services Act (Regulation 2022/2065) as an intermediary service. Companies focus on one and forget the other, ending up non-compliant with DSA transparency obligations (illegal content reporting, redress mechanisms, transparency reports) while believing they are compliant because they did their AI Act homework. In Luxembourg, the EU AI Office will supervise the general AI side, but the DSA applies independently, and CNPD retains jurisdiction over personal data indexed by your chatbot.
The qualification test: are you an intermediary service under the DSA?
Your AI system falls within recital 119 if at least one of these situations applies:
- Your chatbot queries third-party websites live (live search, web RAG) and returns results to the end user.
- Your AI assistant aggregates content from third parties (forums, social networks, press) to generate a single answer.
- You offer an LLM-augmented search engine, even internal for B2B clients, that combines multiple external sources.
- Your platform hosts AI outputs generated by other users (prompt marketplaces, AI image galleries, etc.).
In these cases, you cumulate AI Act obligations (article 50 transparency, synthetic content marking, technical documentation) AND DSA obligations (contact points, clear terms of service, notice and action, annual transparency reports if platform).
How Luxgap automates this risk
Our Luxgap AI-DSA Crossover Mapper eliminates the regulatory blind spot between AI Act and DSA by automatically mapping, for each AI system in your catalogue, its dual legal qualification and the exhaustive list of cumulated obligations. The tool queries your Azure OpenAI, AWS Bedrock, Vertex AI environments, your production logs and functional specifications to detect whether your AI makes outbound calls to third-party sources, aggregates external content or hosts user outputs, then flips the qualification in real time.
- Scans your RAG pipelines, LangChain agents and function calls to identify systems that query third-party websites and trigger DSA scope.
- Classifies each AI system against a crossed matrix AI Act (minimal, limited, high risk, GPAI) and DSA (intermediary service, hosting, online platform, very large platform).
- Generates the cumulated list of applicable obligations: article 50 AI Act transparency, DSA contact point, terms of service, notice mechanism, annual report.
- Detects synthetic content produced and automatically applies the C2PA watermark required by article 50 AI Act.
- Produces a timestamped crossed compliance file, opposable to the EU AI Office and the European Commission (DSA authority for VLOPs).
Available as an add-on to a Luxgap DPO or CISO mandate or as a standalone SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual AI systems, with a free 48-hour blank audit to measure your crossed AI Act / DSA exposure before any commitment.