The classic trap
Recital 88 sheds light on a major blind spot in AI compliance: the value chain. In practice, the provider of a high-risk AI system assembles building blocks (pre-trained models, training datasets, inference APIs, evaluation libraries, software integration components) supplied by third parties. Without a written agreement requiring those third parties to share the necessary information, capabilities and technical access, the final provider cannot demonstrate compliance with articles 9 to 15 (risk management, data governance, technical documentation, transparency, human oversight, robustness). The EU AI Office and, for the personal data dimension, the CNPD will demand this contractual traceability during any inspection.
What this recital concretely requires in your AI supplier contracts
- A technical information clause requiring the upstream supplier to document training datasets, evaluation metrics and known model limitations.
- A technical access right allowing the final provider to test, audit and re-evaluate the integrated component, without disclosing trade secrets (via isolated environments, detailed model cards, evaluation sheets).
- An obligation to notify material changes (retraining, fine-tuning, model drift) likely to affect the compliance of the integrated system.
- Alignment with the generally acknowledged state of the art: ISO/IEC 42001, ISO/IEC 23894, NIST AI Risk Management Framework, EU AI Office codes of conduct.
- Articulation with GDPR article 28 obligations when the component processes personal data, and with DORA for critical ICT providers in the financial sector.
How Luxgap automates this risk
Our Luxgap AI Supply Chain Mapper automatically reconstructs your organisation's AI value chain and identifies every missing contractual link before the EU AI Office does it for you. The tool scans your development environments (GitHub, GitLab, Azure ML, AWS SageMaker, Hugging Face, Vertex AI) to map imported pre-trained models, consumed LLM APIs, external datasets and evaluation libraries, then cross-references this map with your supplier contracts stored in Odoo, M365 or DocuWare.
- Automatically detects every third-party model (OpenAI, Anthropic, Mistral, Hugging Face) integrated into your AI pipelines and qualifies its role in the AI Act value chain.
- Verifies the presence of a written agreement compliant with recital 88 and article 25, and flags missing clauses (technical access, model card, retraining notification, state of the art).
- Generates a preloaded AI supplier agreement template, tailored to each supplier type (foundation model provider, dataset provider, software integrator, evaluation service).
- Tracks public supplier updates (Hugging Face changelog, OpenAI release notes, Anthropic model cards) and alerts on any change likely to invalidate your article 11 technical documentation.
- Produces a timestamped PDF report, enforceable before the EU AI Office and the CNPD, demonstrating contractual control of your AI value chain.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI pipelines, with a free 48h blank audit to map your contractual exposure before any engagement.