The classic trap
Recital 84 enshrines a rule that surprises most integrators and resellers: you can become the provider of a high-risk AI system without knowing it, simply by putting your trademark on it, making a substantial modification, or repurposing a general-purpose AI toward a high-risk use case (HR, credit scoring, education...). The EU AI Office and national AI market surveillance authorities will prioritise this requalification check on SaaS resellers, IT integrators and deployers who think they are mere users. The trap is huge: you then inherit all Article 16 obligations (quality management system, technical documentation, CE marking, EU declaration of conformity, EUDAMED-AI registration), often without access to the underlying model's source code.
The 4 triggers that flip you into provider status
- Trademark affixing (white-label): you resell a third-party LLM under your commercial brand, even with a simple UI wrapper. Absent an explicit contractual clause to the contrary, you become the provider.
- Substantial modification: heavy fine-tuning, addition of decisional modules, integration into a workflow that changes the risk profile. The "substantial" threshold is yet to be clarified by the EU AI Office.
- Purpose repurposing: you take a general-purpose AI (GPT-4, Mistral Large, Claude) and deploy it to screen CVs, score students or assess creditworthiness. The system flips to high-risk (Annex III) and YOU become the provider.
- Medical device integration: via the Article 16(2) MDR 2017/745 exception, certain modifications do not requalify. But outside the MDR scope, the general rule applies.
The contractual test: the key argumentation lever
The recital specifies "without prejudice to contractual arrangements stipulating that the obligations are allocated otherwise". Concretely, your contracts with OpenAI, Anthropic, Mistral, Microsoft and Google must contain an AI Act obligation allocation clause. Without it, the distributor is presumed to be the provider as soon as one of the 4 triggers fires.
How Luxgap automates this risk
Our Luxgap AI Provider Flip Detector continuously monitors your deployed AI stack and triggers a critical alert as soon as one of your use cases flips from deployer status to provider status under the AI Act. The tool cross-references your SaaS contracts (Microsoft 365 Copilot, OpenAI Enterprise, Anthropic, Mistral, Hugging Face), your Git repositories (fine-tuning detection, custom RAG, LLM agents), your business workflows (Odoo HR, Sage payroll, Salesforce scoring) and your marketing communications to detect the 4 requalification triggers before the EU AI Office detects them for you.
- Scans your public pages and commercial contracts to detect any trademark affixing on a third-party LLM ("powered by our AI", "our smart assistant") and flags the requalifying white-label risk.
- Analyses your code repositories (GitHub, GitLab, Azure DevOps) and detects fine-tuning operations, the addition of decisional layers or RAG pipelines that may constitute a substantial modification.
- Maps your real general-purpose AI usage against Annex III (HR, education, credit scoring, justice, migration, critical infrastructure) and identifies purpose repurposing flipping to high-risk.
- Audits your AI vendor contracts and detects the absence of an AI Act obligation allocation clause, then generates a standard addendum compliant with Recital 84.
- Produces a timestamped AI Act register, enforceable before the AI market surveillance authority, classifying each deployed system by your real status (provider, deployer, importer, distributor).
- Alerts via Teams or email as soon as a new AI project detected in your systems presents a flip risk, before go-live.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will run a demo on your real AI usage, with a free 48-hour blind audit to map your requalification exposure before any commitment.