The classic trap
Recital 66 locks in the legitimacy of the seven cumulative requirements of Chapter III Section 2 (Articles 9 to 15): risk management, data quality, technical documentation, record-keeping, transparency, human oversight, robustness and cybersecurity. In practice, providers of high-risk AI systems who plead disproportionate burden to escape one of these requirements consistently lose: the legislator already settled the proportionality test at the recital stage. The EU AI Office and future national market surveillance authorities will rely on this recital to dismiss any defense based on cost or technical complexity.
The seven inseparable requirements: the compliance checklist
Recital 66 lists an inseparable block. None of the seven bricks can be neglected on the grounds that the other six are in place. Here is the concrete mapping between the recital and the operational articles:
- Risk management (Article 9): documented, iterative system, across the entire lifecycle.
- Data quality and relevance (Article 10): training, validation, test, with bias governance.
- Technical documentation (Article 11 + Annex IV): ready before placing on the market, kept up to date.
- Record-keeping / logs (Article 12): automatic traceability of relevant events.
- Transparency and deployer information (Article 13): clear instructions for use, known limitations.
- Human oversight (Article 14): measures built in by design, not a mere contractual reminder.
- Robustness, accuracy, cybersecurity (Article 15): declared levels, resilience to adversarial attacks and data poisoning.
The most frequent mistake is to treat these requirements as an administrative checklist. Recital 66 frames them as a system: the failure of a single brick compromises the placing on the market of the entire system.
How Luxgap automates this risk
Our Luxgap AI System Compliance Twin creates a compliance digital twin for each high-risk AI system you develop or deploy, materializing in real time the status of the seven requirements of Recital 66 without ever asking the data science team to fill in a form. The tool natively connects to MLflow, Azure ML, AWS SageMaker, Databricks and GitHub Actions to automatically extract technical evidence (versioned datasets, evaluation metrics, inference logs, model cards) and transform it into an enforceable Annex IV file.
- Continuously scans your MLOps pipelines and automatically detects each new trained model that matches a high-risk use case listed in Annex III.
- Calculates a completeness score for each of the seven requirements of Recital 66, with drill-down article by article and identification of missing bricks.
- Generates the Annex IV technical documentation by automatically aggregating MLflow artifacts, data sheets, bias reports and versioning logs.
- Detects data quality drifts between training and production via continuous statistical comparison, and alerts on Teams or Slack in case of significant drift.
- Produces a time-stamped, cryptographically sealed PDF report, ready to be submitted to the EU AI Office or the national surveillance authority during an inspection.
- Simulates a mock audit by generating likely regulator questions based on the Article 9 to 15 grid, and identifies argumentative blind spots.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your AI scope. Request a personalized quote and our teams will prepare a demonstration on your real models, with a free mock audit within 48h to measure your exposure to the seven requirements before any engagement.