The classic trap
Recital 25 creates an attractive scientific R&D exclusion, but it is also where most data science teams fall. Many organisations wrongly label as research projects that are in fact product-oriented: an internal POC meant to be deployed in production, a client pilot, a technical beta on a real perimeter. As soon as the system is put into service or placed on the market, the AI Act applies fully and retroactively to the documentation. The EU AI Office and, for the data dimension, the CNPD in Luxembourg, will look at the actual purpose of the project, not the internal label.
The 'scientific research' test: 5 cumulative criteria to document
- Exclusive purpose: the system is developed for the sole purpose of research, not to prepare short-term commercialisation.
- Scientific methodology: formal research protocol, hypotheses, peer review, planned publication.
- No putting into service: no real end users, no paying customers, no business production deployment.
- Recognised ethical standards: ethics committee, research charter, GDPR compliance for training data.
- Documented transition: as soon as an R&D project becomes a product, immediate triggering of the AI Act compliance cycle (risk classification, Annex IV technical documentation, FRIA if high-risk, etc.).
The research-to-product transition trap
Recital 25 explicitly states that the exclusion is without prejudice to the obligation of compliance as soon as a system resulting from R&D is placed on the market. Concretely: the day your POC becomes a commercialised MVP, you must have retroactively built up all the technical documentation, test sets, bias analyses, and cybersecurity measures. Failing to trace the development history during the research phase makes this compliance retrofit nearly impossible.
How Luxgap automates this risk
Our Luxgap Research Boundary Tracker eliminates the grey zone between excluded scientific research and AI Act-bound product by continuously materialising the actual boundary of each AI project. The tool connects to your GitLab/GitHub repositories, your MLflow and Weights & Biases environments, your Azure ML or AWS SageMaker pipelines, and your project management tools (Jira, Linear, Notion) to automatically detect research-to-product transition signals, without waiting for a lawyer to ask the question six months too late.
- Automatically detects putting-into-service signals (first external user, first production API endpoint exposed, first customer invoice, first commercial agreement) that move a project out of the recital 25 exclusion.
- Classifies each AI project according to the 5 cumulative criteria of the scientific research test and computes a robustness score for the invoked exclusion.
- Builds in the background, from the research phase, the skeleton of Annex IV technical documentation (training data, architecture choices, performance metrics, bias tests) to avoid the impossible retroactive reconstruction on market-launch day.
- Alerts the DPO and the AI lead as soon as a project labelled research shows objective signs of product orientation (pilot customers, commercial KPIs, integration into the product backlog).
- Generates a timestamped research protocol file, compliant with recognised ethical standards, enforceable during an EU AI Office audit or a CNPD inquiry on the data dimension.
- Produces an automatic transition report on the D-day of the switch, listing the AI Act obligations immediately applicable according to the system's risk level.
Available as part of a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI projects, with a free 48-hour blind audit to map your projects at risk of reclassification before any commitment.