The classic trap
Recital 99 confirms that large generative models (LLMs like GPT, Claude, Mistral, Llama, but also image, audio and video models) fall within the general-purpose AI model category under Article 3(63) and Chapter V of the AI Act. The practical consequence is significant: any organisation that integrates such a model into a product, even via API (OpenAI, Anthropic, Mistral La Plateforme, Azure OpenAI, AWS Bedrock), becomes a downstream provider or deployer and inherits transparency obligations, content marking duties for generated outputs (Article 50) and technical documentation requirements. The EU AI Office has already signalled it will prioritise oversight of systemic-risk models, while the Luxembourg CNPD remains competent for the personal-data dimension (training, output, profiling).
Why this recital changes your project's qualification
Many companies believe they are mere users of a third-party AI. Recital 99 invalidates that comfortable stance the moment you adapt the model: fine-tuning, RAG over your business data, specialised system prompt, or packaging into a resold product. Concrete pitfalls:
- A customer chatbot built on GPT-4 with a 3000-token system prompt makes you a deployer within the meaning of Article 3(4), triggering Article 50 transparency duties.
- An internal legal assistant based on Claude plus a RAG document base triggers Annex IV obligations if the use case falls into high risk (Annex III).
- Fine-tuning a Mistral 7B on HR data may turn you into a provider of the derived model, with Chapter V obligations.
- An image generator embedded in your website must mark outputs as AI-generated content in a machine-readable way (Article 50(2)).
- Deepfakes or AI-generated texts of public interest require explicit disclosure to the end reader.
How Luxgap automates this risk
Our Luxgap GenAI Footprint Mapper turns the fuzzy question "are we in scope of the AI Act?" into an enforceable map of all your generative AI usage in less than 72 hours. The tool connects to your M365 Copilot, Azure OpenAI, AWS Bedrock, Google Vertex AI and Mistral La Plateforme environments, as well as your network gateways (Zscaler, Defender for Cloud Apps, Netskope) to detect actual shadow GenAI, without relying on voluntary declarations from business teams.
- Automatically detects every API call to a generative model (OpenAI, Anthropic, Mistral, Cohere, Hugging Face Inference) from your cloud and endpoint environments, with reconstructed volume and purpose.
- Classifies each use case against the AI Act grid: end user, Article 3(4) deployer, downstream provider after fine-tuning, or provider of a derived model.
- Generates ready-to-use Article 50 transparency notices per use case (chatbot, image generator, internal assistant, classifier), ready to embed in your terms and interfaces.
- Alerts in real time via Teams or Slack as soon as a new GenAI service appears in the IT estate, with automatic AI Act risk scoring (minimal, transparency, high-risk, prohibited).
- Produces a time-stamped AI model register, enforceable before the EU AI Office and the CNPD, demonstrating Article 26 deployer governance and Article 5(2) GDPR accountability.
- Cross-checks generated outputs against your marking policies (C2PA watermark, metadata) to verify Article 50(2) compliance on synthetic content.
Available as a complement to a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free 48-hour blind audit to map your GenAI exposure before any engagement.