{"id":934,"date":"2025-09-09T07:36:35","date_gmt":"2025-09-09T07:36:35","guid":{"rendered":"https:\/\/adriangrigoras.com\/blog\/?p=934"},"modified":"2025-09-09T17:29:50","modified_gmt":"2025-09-09T17:29:50","slug":"prompt-trigger-assessment-reporting-eu-ai-act","status":"publish","type":"post","link":"https:\/\/adriangrigoras.com\/blog\/prompt-trigger-assessment-reporting-eu-ai-act\/","title":{"rendered":"When Do Prompt Changes Trigger Assessment and Reporting under the EU AI Act?"},"content":{"rendered":"<h3 data-start=\"225\" data-end=\"275\">A New Era of AI Governance<\/h3>\n<p data-start=\"276\" data-end=\"472\">The EU AI Act is the world\u2019s first comprehensive regulatory framework for artificial intelligence. It introduces a <strong data-start=\"391\" data-end=\"414\">risk-based approach<\/strong>, imposing strict obligations on <em data-start=\"447\" data-end=\"469\">high-risk AI systems<\/em>.<\/p>\n<p data-start=\"474\" data-end=\"580\">As enterprises adopt generative AI and experiment with prompt engineering, a practical question emerges:<\/p>\n<p data-start=\"582\" data-end=\"767\">\ud83d\udc49 <em data-start=\"585\" data-end=\"765\">When does a \u201cprompt change\u201d remain just normal use, and when does it become a substantial modification that triggers new assessment and reporting obligations under the EU AI Act?<\/em><\/p>\n<h3 data-start=\"774\" data-end=\"827\">The Core Principle: Substantial Modification<\/h3>\n<p data-start=\"828\" data-end=\"1008\">According to the Act, once an AI system is <strong data-start=\"871\" data-end=\"899\">\u201csubstantially modified\u201d<\/strong>, it is treated as a <em data-start=\"920\" data-end=\"932\">new system<\/em> and must undergo a new conformity assessment (European Parliament, 2024).<\/p>\n<p data-start=\"1010\" data-end=\"1059\">A substantial modification includes changes to:<\/p>\n<ul data-start=\"1060\" data-end=\"1257\">\n<li data-start=\"1060\" data-end=\"1097\">\n<p data-start=\"1062\" data-end=\"1097\">The system\u2019s <strong data-start=\"1075\" data-end=\"1095\">intended purpose<\/strong><\/p>\n<\/li>\n<li data-start=\"1098\" data-end=\"1147\">\n<p data-start=\"1100\" data-end=\"1147\">Its <strong data-start=\"1104\" data-end=\"1145\">architecture, model, or training data<\/strong><\/p>\n<\/li>\n<li data-start=\"1148\" data-end=\"1190\">\n<p data-start=\"1150\" data-end=\"1190\">Its <strong data-start=\"1154\" data-end=\"1188\">rules or decision-making logic<\/strong><\/p>\n<\/li>\n<li data-start=\"1191\" data-end=\"1257\">\n<p data-start=\"1193\" data-end=\"1257\">Its <strong data-start=\"1197\" data-end=\"1213\">risk profile<\/strong> in terms of safety, rights, or compliance<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1259\" data-end=\"1369\">This makes it critical for organizations to understand when a prompt crosses from <em data-start=\"1341\" data-end=\"1346\">use<\/em> into <em data-start=\"1352\" data-end=\"1366\">modification<\/em>.<\/p>\n<h3 data-start=\"1376\" data-end=\"1418\">Prompt Changes vs. System Changes<\/h3>\n<p data-start=\"1419\" data-end=\"1510\">Not all prompts are created equal. The Act distinguishes between usage and modifications:<\/p>\n<ul data-start=\"1512\" data-end=\"2532\">\n<li data-start=\"1512\" data-end=\"1614\">\n<p data-start=\"1514\" data-end=\"1614\"><strong data-start=\"1514\" data-end=\"1539\">Minor Prompt Changes:<\/strong> Adjusting wording to refine an answer is normal use, not a modification.<\/p>\n<\/li>\n<li data-start=\"1615\" data-end=\"1871\">\n<p data-start=\"1617\" data-end=\"1871\"><strong data-start=\"1617\" data-end=\"1650\">Operational Prompt Libraries:<\/strong> When standardized prompts systematically shape outputs (e.g., enforcing compliance checks), they effectively create <em data-start=\"1767\" data-end=\"1778\">new rules<\/em>. If those rules impact outcomes, regulators may see this as altering the system\u2019s purpose.<\/p>\n<\/li>\n<li data-start=\"1872\" data-end=\"2109\">\n<p data-start=\"1874\" data-end=\"2109\"><strong data-start=\"1874\" data-end=\"1917\">Prompts Driving New Rules or Decisions:<\/strong> Directing an AI to change how it evaluates risks, applies scoring, or gives regulated advice alters its <strong data-start=\"2022\" data-end=\"2051\">decision-making framework<\/strong>. That shift can classify as a substantial modification.<\/p>\n<\/li>\n<li data-start=\"2110\" data-end=\"2330\">\n<p data-start=\"2112\" data-end=\"2330\"><strong data-start=\"2112\" data-end=\"2130\">Domain Shifts:<\/strong> Using the same AI chatbot with different prompts to give HR hiring advice one day and financial credit scoring the next repurposes the system. Each domain carries new risks, requiring reassessment.<\/p>\n<\/li>\n<li data-start=\"2331\" data-end=\"2532\">\n<p data-start=\"2333\" data-end=\"2532\"><strong data-start=\"2333\" data-end=\"2369\">Continuous Learning via Prompts:<\/strong> If prompts are fed back into training loops (fine-tuning or reinforcement learning), they <strong data-start=\"2460\" data-end=\"2487\">modify the model itself<\/strong>, making conformity reassessment necessary.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"2534\" data-end=\"2689\">\ud83d\udc49 The key test: <em data-start=\"2551\" data-end=\"2645\">Do the prompts alter the system\u2019s rules or decisions in ways that affect compliance or risk?<\/em> If yes, it is no longer \u201cjust prompting&#8221;.<\/p>\n<h3 data-start=\"2696\" data-end=\"2741\">Reporting and Assessment Obligations<\/h3>\n<p data-start=\"2742\" data-end=\"2810\">If prompts amount to a substantial modification, enterprises must:<\/p>\n<ul data-start=\"2811\" data-end=\"3104\">\n<li data-start=\"2811\" data-end=\"2869\">\n<p data-start=\"2813\" data-end=\"2869\">Carry out a new <strong data-start=\"2829\" data-end=\"2854\">conformity assessment<\/strong> (Annex VII).<\/p>\n<\/li>\n<li data-start=\"2870\" data-end=\"2943\">\n<p data-start=\"2872\" data-end=\"2943\">Update their <strong data-start=\"2885\" data-end=\"2912\">risk management systems<\/strong> and technical documentation.<\/p>\n<\/li>\n<li data-start=\"2944\" data-end=\"3022\">\n<p data-start=\"2946\" data-end=\"3022\"><strong data-start=\"2946\" data-end=\"2968\">Notify authorities<\/strong> (such as the designated national supervisory body).<\/p>\n<\/li>\n<li data-start=\"3023\" data-end=\"3104\">\n<p data-start=\"3025\" data-end=\"3104\">Extend <strong data-start=\"3032\" data-end=\"3058\">post-market monitoring<\/strong> to reflect the AI\u2019s new scope and behavior.<\/p>\n<\/li>\n<\/ul>\n<h3 data-start=\"3111\" data-end=\"3159\">When Does a Deployer Become a Provider?<\/h3>\n<p data-start=\"3160\" data-end=\"3461\">Under the EU AI Act, the role of a <strong data-start=\"3195\" data-end=\"3207\">Deployer<\/strong> typically applies to organizations that <strong data-start=\"3248\" data-end=\"3255\">use<\/strong> AI systems developed by others. In this role, you are responsible for safe use, human oversight, and compliance with applicable obligations \u2014 but you are not responsible for the underlying system itself.<\/p>\n<p data-start=\"3463\" data-end=\"3755\">However, a Deployer may become a <strong data-start=\"3496\" data-end=\"3508\">Provider<\/strong> if they <strong data-start=\"3517\" data-end=\"3541\">substantially modify<\/strong> the AI system or repurpose it beyond its intended use. This happens when you alter the default behavior of a Large Language Model (LLM) through technical or functional changes that affect how the model operates.<\/p>\n<p data-start=\"3757\" data-end=\"3811\"><strong data-start=\"3757\" data-end=\"3809\">Examples where a Deployer may become a Provider:<\/strong><\/p>\n<ul data-start=\"3812\" data-end=\"4840\">\n<li data-start=\"3812\" data-end=\"3929\">\n<p data-start=\"3814\" data-end=\"3929\"><strong data-start=\"3814\" data-end=\"3836\">Model Fine-Tuning:<\/strong> Training the LLM further with your own datasets to change its knowledge base or responses.<\/p>\n<\/li>\n<li data-start=\"3930\" data-end=\"4107\">\n<p data-start=\"3932\" data-end=\"4107\"><strong data-start=\"3932\" data-end=\"3955\">Domain Repurposing:<\/strong> Modifying outputs so that the model acts as a <strong data-start=\"4002\" data-end=\"4019\">legal advisor<\/strong>, financial consultant, or healthcare professional \u2014 i.e., providing regulated advice.<\/p>\n<\/li>\n<li data-start=\"4108\" data-end=\"4501\">\n<p data-start=\"4110\" data-end=\"4220\"><strong data-start=\"4110\" data-end=\"4140\">Automated Decision-Making:<\/strong> Using the LLM to take <strong data-start=\"4163\" data-end=\"4183\">direct decisions<\/strong> without human validation, such as:<\/p>\n<ul data-start=\"4223\" data-end=\"4501\">\n<li data-start=\"4223\" data-end=\"4267\">\n<p data-start=\"4225\" data-end=\"4267\">Approving or rejecting loan applications<\/p>\n<\/li>\n<li data-start=\"4270\" data-end=\"4325\">\n<p data-start=\"4272\" data-end=\"4325\">Screening CVs and matching them to job descriptions<\/p>\n<\/li>\n<li data-start=\"4328\" data-end=\"4403\">\n<p data-start=\"4330\" data-end=\"4403\">Prioritizing patients in a hospital or customers in a call center queue<\/p>\n<\/li>\n<li data-start=\"4406\" data-end=\"4450\">\n<p data-start=\"4408\" data-end=\"4450\">Assessing insurance claims automatically<\/p>\n<\/li>\n<li data-start=\"4453\" data-end=\"4501\">\n<p data-start=\"4455\" data-end=\"4501\">Assigning credit scores or fraud risk levels<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li data-start=\"4502\" data-end=\"4677\">\n<p data-start=\"4504\" data-end=\"4677\"><strong data-start=\"4504\" data-end=\"4538\">Embedding into Core Processes:<\/strong> Integrating an LLM into ERP or CRM systems so it autonomously executes tasks (e.g., negotiating supplier contracts, approving invoices).<\/p>\n<\/li>\n<li data-start=\"4678\" data-end=\"4840\">\n<p data-start=\"4680\" data-end=\"4840\"><strong data-start=\"4680\" data-end=\"4707\">High-Risk Environments:<\/strong> Deploying LLMs in education, justice, or critical infrastructure contexts where outputs directly impact people\u2019s rights or safety.<\/p>\n<\/li>\n<\/ul>\n<h3 data-start=\"4847\" data-end=\"4894\">Deployer vs. Provider \u2013 Visual Summary<\/h3>\n<p data-start=\"4896\" data-end=\"5217\"><strong data-start=\"4896\" data-end=\"4989\">Not every organization that uses AI automatically becomes a Provider under the EU AI Act.<\/strong> The distinction depends on whether you simply <em data-start=\"5036\" data-end=\"5061\">use the system as it is<\/em> (Deployer) or whether you <em data-start=\"5088\" data-end=\"5134\">substantially modify its behavior or purpose<\/em> (Provider). The table below illustrates this difference with practical examples.<\/p>\n<table>\n<thead>\n<tr>\n<th><strong>Role<\/strong><\/th>\n<th><strong>Definition<\/strong><\/th>\n<th><strong>Examples<\/strong><\/th>\n<th><strong>Key Responsibility<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Deployer<\/strong><\/td>\n<td>Uses an AI system <em>as provided<\/em> by a third party, without substantially modifying its behavior or intended purpose.<\/td>\n<td>&#8211; Using LLMs for drafting documents with <strong>human review<\/strong> before publication.<\/p>\n<p>&#8211; Chatbot answers FAQs, but <strong>humans handle escalations<\/strong>.<\/p>\n<p>&#8211; AI suggests CV matches, but <strong>recruiters decide final selection<\/strong>.<\/td>\n<td>Ensure <strong>safe use<\/strong>, human oversight, data protection, and compliance with usage obligations.<\/td>\n<\/tr>\n<tr>\n<td><strong>Provider<\/strong><\/td>\n<td>Develops or <em>substantially modifies<\/em> an AI system, making it effectively a <strong>new system<\/strong> under the Act.<\/td>\n<td>&#8211; Fine-tuning a model with your own datasets. &#8211; Modifying outputs so LLM provides <strong>legal, medical, or financial advice<\/strong>.<\/p>\n<p>&#8211; Letting LLM <strong>approve loans, reject insurance claims, or prioritize hospital patients<\/strong> automatically.<\/p>\n<p>&#8211; Embedding LLM into ERP\/CRM systems to <strong>autonomously approve invoices or contracts<\/strong>.<\/td>\n<td>Must perform <strong>conformity assessment<\/strong>, register the system, maintain risk management, technical documentation, and post-market monitoring.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong data-start=\"6413\" data-end=\"6426\">Takeaway:<\/strong> <em data-start=\"6427\" data-end=\"6469\">When in doubt, keep a human in the loop.<\/em> By ensuring oversight and final decision-making remain with people, organizations can avoid unintentionally becoming Providers and stay compliant as Deployers under the EU AI Act.<\/p>\n<h3 data-start=\"6658\" data-end=\"6701\">Practical Guidance for Enterprises<\/h3>\n<p data-start=\"6702\" data-end=\"6755\">To stay compliant while experimenting with prompts:<\/p>\n<ul data-start=\"6756\" data-end=\"7302\">\n<li data-start=\"6756\" data-end=\"6863\">\n<p data-start=\"6758\" data-end=\"6863\"><strong data-start=\"6758\" data-end=\"6787\">Define Prompt Boundaries:<\/strong> Document which prompts are \u201csafe\u201d vs. which could alter purpose or rules.<\/p>\n<\/li>\n<li data-start=\"6864\" data-end=\"6961\">\n<p data-start=\"6866\" data-end=\"6961\"><strong data-start=\"6866\" data-end=\"6894\">Govern Prompt Libraries:<\/strong> Treat shared prompts as code \u2014 versioned, reviewed, and audited.<\/p>\n<\/li>\n<li data-start=\"6962\" data-end=\"7089\">\n<p data-start=\"6964\" data-end=\"7089\"><strong data-start=\"6964\" data-end=\"6998\">Assess Rule &amp; Decision Impact:<\/strong> If a prompt changes how the system makes decisions, treat it as a possible modification.<\/p>\n<\/li>\n<li data-start=\"7090\" data-end=\"7183\">\n<p data-start=\"7092\" data-end=\"7183\"><strong data-start=\"7092\" data-end=\"7118\">Monitor Domain Shifts:<\/strong> Repurposing into new sectors should trigger risk reassessment.<\/p>\n<\/li>\n<li data-start=\"7184\" data-end=\"7302\">\n<p data-start=\"7186\" data-end=\"7302\"><strong data-start=\"7186\" data-end=\"7215\">Stay Close to Regulators:<\/strong> The EU AI Office and national authorities will issue further guidance. Stay aligned.<\/p>\n<\/li>\n<\/ul>\n<h3 data-start=\"7309\" data-end=\"7367\">Conclusion \u2013 Rules and Decisions Are the Red Line<\/h3>\n<p data-start=\"7368\" data-end=\"7629\">Prompts may appear harmless, but under the EU AI Act they can, in some cases, <strong data-start=\"7446\" data-end=\"7501\">reshape the rules or decisions an AI system applies<\/strong>. When this happens, the AI may be considered <strong data-start=\"7547\" data-end=\"7573\">substantially modified<\/strong>, triggering new assessment and reporting obligations.<\/p>\n<p data-start=\"7631\" data-end=\"7770\">Enterprises need to treat prompt engineering with the same discipline as software engineering: governed, version-controlled, and audited.<\/p>\n<p data-start=\"7772\" data-end=\"7783\">In short:<\/p>\n<ul data-start=\"7784\" data-end=\"7901\">\n<li data-start=\"7784\" data-end=\"7831\">\n<p data-start=\"7786\" data-end=\"7831\"><strong data-start=\"7786\" data-end=\"7829\">If prompts only refine answers \u2192 usage.<\/strong><\/p>\n<\/li>\n<li data-start=\"7832\" data-end=\"7901\">\n<p data-start=\"7834\" data-end=\"7901\"><strong data-start=\"7834\" data-end=\"7899\">If prompts alter rules, decisions, or purpose \u2192 modification.<\/strong><\/p>\n<\/li>\n<\/ul>\n<p data-start=\"7903\" data-end=\"7983\">Trust, compliance, and accountability depend on making this distinction clear.<\/p>\n<p data-start=\"7985\" data-end=\"8094\">\ud83d\udc49 Do you agree? Should <strong data-start=\"8009\" data-end=\"8029\">prompt libraries<\/strong> be treated like \u201ccode\u201d and fully governed under the EU AI Act?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A New Era of AI Governance The EU AI Act is the world\u2019s first comprehensive regulatory framework for artificial intelligence. It introduces a risk-based approach, imposing strict obligations on high-risk AI systems. As enterprises adopt generative AI and experiment with prompt engineering, a practical question emerges: \ud83d\udc49 When does a \u201cprompt change\u201d remain just normal\u2026 <span class=\"read-more\"><a href=\"https:\/\/adriangrigoras.com\/blog\/prompt-trigger-assessment-reporting-eu-ai-act\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":937,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[30,32],"tags":[],"class_list":["post-934","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-architecture","category-leadership"],"_links":{"self":[{"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/posts\/934","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/comments?post=934"}],"version-history":[{"count":3,"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/posts\/934\/revisions"}],"predecessor-version":[{"id":938,"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/posts\/934\/revisions\/938"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/media\/937"}],"wp:attachment":[{"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/media?parent=934"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/categories?post=934"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/adriangrigoras.com\/blog\/wp-json\/wp\/v2\/tags?post=934"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}