The classic trap
Recital 175 announces that the European Commission will hold implementing powers to refine the AI Act over time: implementing acts on codes of practice, GPAI provider obligations, technical documentation templates, compute thresholds. The practical trap is freezing your compliance on the 2024 text and discovering 18 months later that the Commission has adopted an implementing act changing the assessment grid. The EU AI Office publishes these acts regularly, and the CNPD watches the personal data layer embedded in AI systems.
Why a procedural recital is strategic for your compliance
Regulation 182/2011 organises comitology: each implementing act goes through a Member State committee, is published in the OJEU and typically enters into force within 20 days. Concretely, your AI Act compliance is not a fixed-deadline project (August 2026), it is a continuous flow of obligations being refined. Key vigilance points:
- GPAI codes of practice published by the EU AI Office are living documents that translate into implementing acts.
- Technical notice templates (annex IV) will be specified by implementing act, your current documentation will need to align.
- Compute thresholds (10^25 FLOPs for systemic risk) can be revised by delegated or implementing act.
- Serious incident reporting templates (article 73) will be harmonised by implementing act.
- Manual EUR-Lex monitoring averages 4 hours per month and misses comitology committees where decisions are actually shaped.
How Luxgap automates this risk
Our Luxgap Regulatory Radar AI turns AI Act regulatory monitoring into a real-time, audit-defensible flow. The tool continuously monitors EUR-Lex, the Commission's comitology register, EU AI Office publications, EDPB AI guidelines and CNPD communications, then correlates each new text with your AI system inventory to tell you exactly what changes for you.
- Detects within 24h every new implementing or delegated act published in the OJEU and qualifies it by impact (high-risk, GPAI, transparency, governance).
- Automatically correlates the text with your AI system register to produce a concrete action list per impacted system.
- Tracks preparatory work in comitology via the Commission register, giving 3 to 6 months of anticipation before official publication.
- Generates a timestamped PDF impact note, defensible during an EU AI Office or CNPD audit, demonstrating active monitoring.
- Sends Teams or Slack alerts on critical publications, with a 200-word synthetic brief and link to the source text.
- Archives the full monitoring history (5 years) with cryptographic sealing for audit purposes.
Available as part of a Luxgap DPO or CISO mandate or as a standalone SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI system portfolio, with a free 48h white audit to measure your exposure to expected implementing acts.