The classic trap
Recital 23 closes a door many EU bodies would have liked to keep half-open: Union institutions themselves (Commission, agencies, ECB, Court of Auditors, EU AI Office, EUIPO, eu-LISA...) are subject to the AI Act whenever they develop or use an AI system. For Luxembourg private operators, this has a direct and often overlooked consequence: when your company integrates an AI tool provided by an EU institution (a DG TAXUD customs classification module, an EUDAMED connector, an EUIPO service) or when you respond to a European public procurement involving AI, you inherit Article 16 and Article 26 obligations that you must document toward the EU AI Office.
What this recital concretely changes in your contracts
Recital 23 establishes a public-private symmetry that must be reflected in your AI mapping. Operational points to verify:
- Identify in your IS all AI systems provided by an EU institution (Commission APIs, JRC services, EUIPO tools, Eurostat AI platforms) and qualify your role: deployer or end user.
- For every European public tender involving AI, require from the contracting authority the Article 11 technical documentation and the Article 47 declaration of conformity, just as you would from a private provider.
- Acknowledge that the CJEU and the European Data Protection Supervisor (EDPS) can be seized if an EU institution deploys a non-compliant AI system that impacts you.
- Verify that liability clauses in public-private contracts with EU entities do not unduly transfer to you the provider obligations that rest on the institution.
- Anticipate that future national AI regulatory sandboxes may associate EU institutions as co-deployers, with a responsibility split to clarify.
How Luxgap automates this risk
Our Luxgap AI Supply Chain Mapper automatically traces the AI supply chain crossing your organization, including AI building blocks provided by EU institutions and public bodies that your teams often integrate without realizing it. The tool cross-references your outbound API flows (via M365 Defender, Crowdstrike, Fortinet or Palo Alto firewall inspection), your Odoo or SAP supplier contracts, and your responses to TED Europe tenders to reconstruct the complete map of AI systems you deploy and who supplies them.
- Detects API calls to AI services from EU institutions (JRC, EUIPO, Commission, Frontex, EMA) and automatically qualifies your deployer role under Article 3(4).
- Cross-references your TED public contracts and European tenders with your internal AI mapping to reveal inherited obligations from the public provider.
- Generates request letters for Article 11 technical documentation to be sent to EU institutional providers, with a pre-drafted legal template.
- Alerts in real time when a new institutional EU AI service is integrated by a business team without prior compliance validation.
- Produces a timestamped, cryptographically sealed register opposable to the EU AI Office and the CNPD, demonstrating your control of the mixed public-private AI supply chain.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalized quote and our teams prepare a demonstration on your real perimeter, with a free 48h white audit to map your institutional AI dependencies before any engagement.