The classic trap
Recital 79 locks in a point many Luxembourg AI integrators underestimate: regardless of who coded the model, the entity that places on the market or puts into service a high-risk AI system bears the regulatory responsibility. In practice, a CSSF-regulated fintech deploying a fine-tuned HuggingFace open-source model becomes a provider under the AI Act, with all the obligations of articles 16 to 21. The EU AI Office and the future Luxembourg surveillance authority will not go after Mistral or OpenAI: they will sanction the entity whose name is on the system.
The practical test: provider, deployer, or both?
Recital 79 read together with article 25 creates four tipping situations where a mere deployer legally becomes a provider, with all associated obligations:
- You put your brand or logo on a third-party AI system you redistribute to your clients.
- You substantially modify a high-risk AI system already on the market (heavy fine-tuning, change of intended purpose).
- You divert a general-purpose AI system (ChatGPT, Claude, Gemini) toward a use case classified as high-risk by annex III (recruitment, credit scoring, education).
- You integrate a third-party AI component into a finished product you market under your own responsibility.
The consequence is heavy: technical documentation article 11, risk management system article 9, post-market monitoring article 72, EU declaration of conformity article 47. Plus CNPD coordination for the personal data dimension.
How Luxgap automates this risk
Our Luxgap AI Role Classifier eliminates the most dangerous blind spot of the AI Act: believing you are a mere deployer when you are already legally a provider. The tool continuously maps your actual AI usage through native connectors to Microsoft Copilot, Azure OpenAI, AWS Bedrock, Google Vertex, HuggingFace Enterprise and your GitHub/GitLab repositories, then applies a decision tree aligned with articles 3, 25 and annex III to qualify each system.
- Automatically detects every new AI model deployed in your IT environment, including fine-tunes and in-house wrappers built on top of third-party APIs.
- Classifies each system across the four AI Act tiers (prohibited, high-risk, transparency, minimal) by cross-referencing the observed actual purpose with annex III.
- Alerts on Teams or Slack the moment a substantial modification (system prompt change, fine-tuning, new use case) shifts a deployer into a provider role under article 25.
- Generates the technical file required by article 11, pre-filled from metadata collected automatically (training data, metrics, logging).
- Produces a timestamped, cryptographically sealed PDF report, enforceable before the EU AI Office and the future Luxembourg authority during an inspection.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual AI footprint, with a free 48-hour blind audit to identify the systems where you are already a provider without knowing it.