The classic trap
Recital 83 highlights a point many organisations underestimate: in an AI value chain, a single actor can wear several hats (provider, importer, distributor, deployer) and must then cumulatively meet all related obligations. In practice, the EU AI Office and market surveillance authorities will look at operational reality, not contractual labels: reselling a US model with added fine-tuning turns you into a provider under Article 25, with the Annex IV technical documentation that follows.
Role cumulations that catch Luxembourg organisations off guard
- SaaS integrator rebranding a US LLM: distributor AND provider when you substantially modify the system or affix your trademark (Art. 25(1)(a) and (b)).
- Consulting firm reselling an HR AI solution: importer (Art. 23) if the provider is outside the EU AND distributor (Art. 24) on the Luxembourg market.
- CSSF-regulated bank deploying a third-party scoring model: deployer (Art. 26) but flips to provider when retraining the model on its own data.
- Software vendor embedding an open-source model: provider of the final system, even if the base model comes from elsewhere.
- Distributor adding a post-processing module: substantial modification under Art. 25(1)(c), hence requalification as a provider.
The argumentation test before the surveillance authority
For each AI system, ask four questions: who developed it? who places it on the EU market first? who distributes it under which brand? who substantially modifies it? An honest answer determines your cumulative obligations. The classic mistake is to declare yourself a simple deployer when fine-tuning or rebranding has tipped you into provider status, triggering conformity assessment, CE marking and EU registration duties.
How Luxgap automates this risk
Our Luxgap AI Role Classifier eliminates the blind spot in your AI value chain by automatically mapping your organisation's real role for every AI system in production. The tool ingests your vendor contracts (Odoo, DocuSign, Ironclad), API flows (Azure OpenAI, AWS Bedrock, Hugging Face, Anthropic), code repositories (GitHub, GitLab) and MLOps pipelines to reconstruct who develops, modifies, distributes and deploys each model, without asking the CISO to fill in a single spreadsheet.
- Automatically detects every API call to a third-party AI model and identifies the provider's country of establishment to qualify importer status under Article 23.
- Analyses your Git commits and fine-tuning pipelines to flag substantial modifications that trigger requalification as a provider (Art. 25(1)(c)).
- Classifies each AI system in the provider / importer / distributor / deployer matrix and surfaces applicable role cumulations.
- Generates the list of cumulative obligations triggered (Annex IV, CE marking, EU register, FRIA, Art. 50 transparency) with a compliance roadmap.
- Alerts in real time via Teams or Slack as soon as a product team adds a new model or modifies an existing one, before requalification becomes a fait accompli.
- Produces a time-stamped PDF report, enforceable before the EU AI Office and the future Luxembourg market surveillance authority, demonstrating your control over the value chain.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual AI systems, with a free 48-hour blank audit to map your exposure before any engagement.