The classic trap
Recital 128 sets a silent but ruthless rule: any modification of your high-risk AI system (change of OS, architectural overhaul, new intended purpose) triggers a brand new conformity assessment. In practice, product teams ship major updates without realising they have just legally created a new AI system. The EU AI Office and future market surveillance authorities will rely on this recital to reclassify continuous deployments as non-compliant placing on the market. In parallel, the CNPD will sanction any personal data processing relying on a system whose conformity baseline is no longer valid.
What triggers (or not) a new conformity assessment
Recital 128 distinguishes two categories of changes. Understanding the boundary is the key to neither freezing your release cycles nor, conversely, deploying in breach of the AI Act.
- Triggers a new assessment: change of operating system, software architecture overhaul, change of intended purpose (HR use shifting to credit scoring), addition of new training data not foreseen, integration of a new underlying foundation model.
- Does NOT trigger a new assessment: continuous learning and automatic adaptation of functions, strictly provided that these evolutions were pre-determined and assessed in the initial conformity file (article 43(4) and annex IV).
- The dangerous grey zone: additional fine-tuning, significant hyperparameter change, expansion of geographical scope of use. Doctrine leans towards reclassification as substantial modification.
- The classic mistake: failing to document the initial change envelope, which makes every later update potentially reclassifiable.
How Luxgap automates this risk
Our Luxgap AI Change Sentinel makes silent deployment of an undeclared substantial modification impossible. The tool plugs directly into your MLOps pipelines (MLflow, Azure ML, AWS SageMaker, Vertex AI, GitHub Actions, GitLab CI) and continuously compares every release candidate with the initial article 43 conformity file to determine, before the merge to production, whether the change crosses the recital 128 threshold.
- Automatically detects every change to host OS, container architecture, underlying foundation model or critical hyperparameters through Git hooks and Docker image scanning.
- Compares the proposed change envelope against the pre-determined scope declared in your annex IV file and alerts on Teams or Slack as soon as a drift exceeds the assessed bounds.
- Classifies each change against the recital 128 grid (substantial, pre-assessed, grey zone) with regulatory justification enforceable before the EU AI Office.
- Automatically blocks the CI/CD pipeline if the modification is qualified as substantial and no new conformity assessment has been launched.
- Generates the pre-filled re-assessment file, including technical diffs, impact on article 9 risk management and adjustments to article 13 transparency.
- Produces a time-stamped, cryptographically sealed PDF report, demonstrating that each release underwent a qualification analysis, enforceable during inspection.
Available alongside a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real pipelines, with a free 48-hour blank audit to measure how many of your recent releases should have triggered a new conformity assessment.