The classic trap
Recital 5 sets out the fundamental duality of the AI Act: AI is useful, but it may cause material or immaterial harm (physical, psychological, societal, economic). Organisations deploying an AI system without mapping these four harm categories find themselves unable to justify their risk analysis before the EU AI Office or the CNPD during a joint AI/GDPR audit. The typical trap: focusing on physical harm (product safety) and neglecting societal harm (algorithmic discrimination) or psychological harm (behavioural manipulation), which are nonetheless the main triggers for high-risk classification in subsequent articles.
The four harm categories to document for every AI use case
- Material or physical harm: bodily injury (medical AI, autonomous vehicle), direct financial loss (faulty credit scoring), damage to property.
- Psychological harm: manipulation, exploitation of vulnerabilities, anxiety from algorithmic surveillance, targeted deepfakes.
- Societal harm: systemic discrimination, undermining democratic pluralism, gender or ethnic bias amplified at population scale.
- Economic harm: exclusion from access to an essential service (insurance, housing, employment), market distortion, loss of professional opportunity.
- For each category: identify the application circumstance (who is exposed?), the intended use (automated decision? decision support?) and the technological maturity level (stable model or rapidly evolving foundation model?).
- Document all this in an enforceable matrix, updated at every model or context change.
The 'specific circumstances' test: the key to interpreting the AI Act
Recital 5 states that risk depends on circumstances, application, use and technological development level. In practice: the same image classification model can be low-risk in one context (industrial part sorting) and high-risk in another (CV screening with photo). Your internal documentation must therefore treat each use case as a distinct analytical unit, not the technical model itself. This is the strongest defence baseline in case of audit.
How Luxgap automates this risk
Our Luxgap AI Harm Mapper turns the fuzzy intent of Recital 5 into an enforceable harm map, use case by use case. The tool connects to your existing repositories (Azure ML, AWS SageMaker, Vertex AI, Hugging Face Spaces, MLflow, GitHub Actions) and automatically detects every deployed or in-development model, then a specialised LLM agent interviews your business teams to qualify the four harm categories in under 15 minutes per use case.
- Continuously scans your MLOps environments and inventories every model, training dataset and inference API, with no manual declaration.
- Classifies each use case against the four harm categories from Recital 5 (material, psychological, societal, economic) via an AI agent trained on the EU AI Office grid.
- Detects context shifts: instant alert when a low-risk model is reused in a new application that flips it to high-risk.
- Generates a time-stamped, cryptographically signed risk matrix, enforceable before the EU AI Office and CNPD in case of joint AI/GDPR audit.
- Computes a regulatory evolution probability score per use case, based on AI Office guidelines and European authority decisions.
- Produces pre-filled risk analysis sheets that directly feed your compliance with Articles 9 and 27 of the AI Act.
Available as part of a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real models, with a free 48h white audit to map your exposure before any commitment.