The classic trap
This recital opens an emergency door: a market surveillance authority may authorise the placing on the market of a high-risk AI system without a prior conformity assessment, for exceptional reasons (public security, protection of life and health, environment, key industrial or infrastructural assets). The classic trap is to believe this derogation is broadly available: only law enforcement or civil protection authorities may act without prior authorisation, and only with a regularisation request submitted without undue delay. A private operator, even a critical infrastructure provider under NIS 2, cannot invoke this mechanism unilaterally; it must obtain an explicit, reasoned and traceable authorisation from the competent AI market surveillance authority (at EU level, the EU AI Office in Brussels supervises general-purpose AI; the Luxembourg national authority has not yet been formally designated to date).
How this recital shapes the operational articles
This recital informs Article 46 (derogation procedure) and imposes three cumulative requirements in practice before invoking emergency:
- Characterise the exceptional reason in writing: public security, life/health, environment, or major industrial/infrastructural asset. A commercial urgency or project delay never qualifies.
- Demonstrate proportionality and the absence of any compliant alternative available within the required timeframe, with a written benefit-risk analysis.
- Establish a regularisation plan: parallel filing of the conformity assessment dossier, reinforced monitoring, incident logs, and immediate withdrawal capability if the authority refuses.
For private operators (hospitals, energy or telecom infrastructure managers, industrial operators), the derogation is never automatic: it is built through a dossier presented to the authority, not by self-declaration. The most frequent misinterpretation will be to confuse this regime with the regulatory sandboxes (Articles 57 et seq.) which follow a completely different logic.
How Luxgap automates this risk
Our Luxgap Emergency AI Dossier turns a crisis situation (airport radar failure, health alert, cyberattack on the power grid) into an Article 46 derogation file enforceable in under 4 hours. The tool pre-assembles automatically, from your connected sources (ServiceNow, Jira, Splunk, internal AI Act register, ISO 27001 ISMS), the pieces the market surveillance authority requires: qualification of the exceptional reason, benefit-risk analysis, compensating measures, regularisation plan. You don't write the dossier in panic at 3am, you validate a dossier already built.
- Detects potential emergency triggers by correlating your SOC alerts (Sentinel, Defender, Wazuh), your ServiceNow priority-1 tickets and your critical business indicators to prepare the dossier before the crisis hits.
- Automatically generates the notification letter to the competent AI market surveillance authority, with cryptographic timestamp and filing receipt, in French, English and German for the Luxembourg context.
- Computes an admissibility score for the request based on the recital 130 criteria (reason, proportionality, urgency, scope) to avoid a humiliating refusal that would expose the organisation to Article 99 sanctions.
- Tracks the post-use regularisation countdown and alerts the DPO/CISO if the deadline drifts, with automatic escalation to senior management.
- Produces a cryptographically sealed PDF report, enforceable during a subsequent authority audit, demonstrating that the exceptional use respected the letter of recital 130 and Article 46.
Available as part of a Luxgap CISO or DPO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on a crisis scenario inspired by your sector, with a free 48h blank audit to map your AI systems eligible for an emergency derogation before any engagement.