The classic trap
Recital 85 addresses a very concrete situation: you integrate a general-purpose AI model (GPT-4, Claude, Mistral Large, Llama, Gemini) into your product, and that product becomes a high-risk AI system under Annex III (HR, credit scoring, education, critical infrastructure). Without documented cooperation from the upstream model provider, you cannot produce the technical documentation required by Article 11 and Annex IV. The EU AI Office will primarily sanction the downstream provider who failed to obtain, or failed to demand, the necessary information from its upstream provider. The 'the model provider gave us nothing' defence does not hold: it is your job to contractualise this information flow upstream.
Information you must demand from your GPAI model provider
- Description of the model's capabilities and limitations, training procedures and data used (Article 53 and Annex XI/XII).
- Policy on Union copyright compliance, particularly the TDM opt-out under Article 4 of Directive 2019/790.
- Sufficiently detailed summary of the training corpus, published using the EU AI Office template.
- Risk mitigation measures for general-purpose models presenting systemic risk (Article 55).
- Serious incident procedure and notification channel between upstream and downstream provider.
- Documentation of adversarial evaluations, red-teaming and safety benchmarks performed on the model.
- Feedback clauses: what you, the downstream provider, must report to the upstream provider when drift is observed in production.
The upstream cooperation clause: your contractual shield
Recital 85 is not self-executing: it materialises in your contracts with OpenAI, Anthropic, Mistral, Google or Microsoft Azure OpenAI. If your API licence contract does not contain an explicit AI Act cooperation clause, you are at risk. The standard terms of these providers are, to date, highly asymmetric and shift most of the compliance burden onto the client. Negotiation via addendum is possible for enterprise accounts and becomes indispensable as soon as your use case falls within Annex III.
How Luxgap automates this risk
Our Luxgap GPAI Supply Chain Mapper automatically charts your AI value chain and detects every general-purpose model consumed by your applications, including those your developers integrated without informing compliance. The tool connects to your API gateways (Azure OpenAI, AWS Bedrock, Vertex AI, Mistral La Plateforme), your GitHub and GitLab repositories, and your cloud invoices to reconstruct the real list of upstream models in use, version by version.
- Continuously detects every API call to a GPAI provider and tags the exact model version invoked, with timestamp and calling application.
- Verifies for each upstream provider the existence of public Article 53 documentation and supplements it with materials obtained under NDA.
- Analyses your API licence contracts (cooperation clauses, intellectual property, AI Act indemnification) via a specialised LLM agent and flags missing or unbalanced clauses.
- Automatically generates an upstream cooperation file per provider, ready to be presented to the EU AI Office or the competent AI market surveillance authority.
- Alerts on Teams or Slack as soon as a new GPAI model appears in your information system, before it reaches production without risk assessment.
- Produces a timestamped, legally opposable PDF report that evidences your due diligence on the AI value chain.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real integrations, with a free 48-hour blank audit to map your GPAI exposure before any commitment.