The classic trap
Recital 93 shifts part of the responsibility to the deployer of the high-risk AI system, not only to the provider. In practice, many Luxembourg organisations assume that buying an HR AI tool, a credit scoring engine or a CV-screening solution discharges them of any obligation: it does not. The EU AI Office and the CNPD (for the personal data dimension) expect the deployer to document the actual context of use, inform affected natural persons and explain the decisions made. Failure to inform the data subjects is the easiest supervisory finding to establish.
What this recital concretely imposes on the deployer
- Identify risks specific to the actual context of use (not only those foreseen by the provider), particularly for vulnerable groups (minors, persons with disabilities, jobseekers, welfare recipients).
- Inform every natural person that they are subject to a high-risk AI system, stating the intended purpose and the type of decisions it produces or assists.
- Inform the person of their right to an explanation under the AI Act (Article 86).
- For law enforcement uses, align this information with Article 13 of Directive (EU) 2016/680 (already transposed in Luxembourg).
- Trace these information acts in an opposable manner: notice screenshot, model version, display date, channel used.
The 'best placed to understand' test: the key argument
The recital establishes an information asymmetry principle: the deployer is presumed better placed than the provider to anticipate the effects on natural persons. This means that in case of supervision, the argument 'the provider designed the algorithm' will not hold. The deployer must demonstrate that it assessed the specific context (affected population, decisions assisted, remedies available) and informed the persons accordingly.
How Luxgap automates this risk
Our Luxgap Deployer Disclosure Engine turns the information obligation of Recital 93 into an opposable software layer, triggered automatically whenever a high-risk AI system produces or assists a decision affecting a natural person. The tool sits between your business applications (Workday, SAP SuccessFactors, Sage BOB 50, Salesforce, Odoo, credit scoring platforms) and the end user, injecting a contextualised, time-stamped and versioned notice, without modifying your business code.
- Detects decision-making flows routed through a high-risk AI system via native connectors to Microsoft Purview, Azure AI Foundry and AWS Bedrock.
- Generates the notice for the natural person with the intended purpose, the type of decision, the Article 86 right to explanation, translated into FR / EN / DE / LU.
- Identifies exposed vulnerable groups (minors, welfare recipients, jobseekers) by cross-referencing population attributes with the EDPB grid and EU AI Office guidelines.
- Archives every notice display with cryptographic sealing (hash + eIDAS qualified timestamp) to produce opposable evidence in case of supervision.
- Produces a register of AI-assisted decisions, exportable in the format expected by the EU AI Office and compatible with the CNPD records of processing activities.
- Sends real-time alerts via Teams or Slack when a new undeclared use case appears in your IT landscape (shadow AI deployment).
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual scope, with a free 48-hour gap assessment to map your high-risk AI systems before any engagement.