The classic trap
Recital 174 acknowledges an operational reality: the AI Act is a living text. The list of high-risk AI systems (Annex III) and the list of prohibited practices (Article 5) will be reassessed every year by the Commission. Concretely, an AI system today out of scope may flip to high-risk within 12 months, retroactively triggering heavy obligations (technical documentation, conformity assessment, EU database registration). Organisations that freeze their AI mapping in 2025 based on the initial text will find themselves non-compliant at the first update, with no visibility until the EU AI Office or the Luxembourg national authority (still to be designated) audits them.
Reviews to anticipate in your regulatory watch
- Annual review of the list of prohibited practices (Article 5) and the list of high-risk AI systems (Annex III): risk of sudden reclassification of your HR, customer scoring or biometrics use cases.
- Quadrennial review by 2 August 2028 on high-risk area headings, transparency obligations (Article 50) and energy efficiency of general-purpose AI models.
- Triennial review by 2 August 2028 on the impact of voluntary codes of conduct, which may become de facto mandatory if the Commission finds them ineffective.
- General review by 2 August 2029 and every four years: possible scope extension, tougher sanctions, modified GPAI thresholds (10^25 FLOPs today).
- Articulation with the CNPD on the personal data side, which evolves in parallel (EDPB AI guidelines, Schrems II decisions applied to models trained outside the EU).
The specific trap of recital 174
The fatal mistake is treating AI Act compliance as a one-off project (one-shot audit, frozen technical file, Excel registry). The text is designed to move faster than your annual budget cycles. Without a structured watch process plugged into the Official Journal, Commission delegated acts and EU AI Office implementing acts, your AI use cases silently drift into non-compliance.
How Luxgap automates this risk
Our Luxgap AI Act Drift Sentinel makes it impossible to miss a regulatory review that reclassifies your AI systems. The tool combines a specialised LLM agent that monitors in real time the EU Official Journal, EU AI Office publications, EDPB guidelines and Commission delegated acts, with continuous mapping against your real AI inventory extracted from your Azure ML, AWS SageMaker, Databricks, Hugging Face Enterprise environments and your LLM APIs (OpenAI, Anthropic, Mistral) via their usage logs.
- Scans daily the official EU publications and detects any modification of Annex III or Article 5 before OJEU publication thanks to draft delegated acts monitoring.
- Cross-references each AI use case mapped at your premises with the new classification and alerts within 24h via Teams or Slack if a system flips to high-risk.
- Automatically generates the compliance roadmap (technical documentation Article 11, conformity assessment Article 43, EU database registration Article 49) with legal deadlines.
- Tracks the progress of CEN-CENELEC JTC 21 standardisation work and alerts as soon as a harmonised standard covering your use case is published, triggering the presumption of conformity.
- Produces a quarterly timestamped PDF report, opposable to the EU AI Office and the Luxembourg authority during a control, demonstrating your continuous regulatory vigilance.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS brick depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your real AI inventory, with a free 48h white audit to measure your exposure to the next Annex III revisions.