"Substantial modification": the EU AI Act clause that breaks grandfathering for improving systems
July 12, 2026 · the looptail team
Buried in the EU AI Act is a clause that quietly determines whether your system stays exempt from the high-risk regime: grandfathered systems lose protection when they undergo a "substantial modification." If your AI improves every month — and whose doesn't? — this clause is aimed at you.
The setup: high-risk obligations for standalone Annex III systems apply from 2 December 2027, but systems already on the market before that date are exempt. Reading that, plenty of teams conclude they should ship now and coast on grandfathering. The clause is why that plan fails.
Death by a hundred hotfixes
A substantial modification isn't one big rewrite. It's a functional test: has the system changed, beyond what was planned, in ways that affect compliance or purpose? Model swaps are obvious candidates. But so is the accumulation of small things — the prompt hotfix in March, the routing change in April, the new tool in May. None substantial alone; together, a system that behaves materially differently from the one that earned the exemption. Without records, you can't even argue the question — you don't know what changed.
The clause is really a mandate for change control
Look at what the defense requires and you'll notice it's the same artifact regardless of how the legal question resolves: a complete, credible record of every change — what changed, why, what the evaluation said, who approved it. If your changes were planned and controlled, the record proves it. If a modification does cross the line, the record is also exactly what the ensuing conformity assessment needs. Either way you needthe record-keeping stack; the only losing move is improvising it after the question is asked.
What to do this quarter
Write down your change-management plan — what kinds of changes you make, how they're evaluated, who approves them. Then make the record automatic: every change tied to the evidence that motivated it and the evaluation that cleared it, in an append-only,signed trail nobody can quietly rewrite. Experimentation platforms like Braintrust help you decide what to change; the trail is what proves how change is governed. A first one takes ten minutes.
A builder's summary, not legal advice.
FAQ
What counts as a substantial modification under the EU AI Act?
A change to an AI system after it reaches the market that was not planned in the provider’s initial conformity assessment and that affects the system’s compliance or its intended purpose. The definition is functional, not quantitative — there is no “under 10% of weights” safe harbor.
Does every prompt change trigger it?
No. Changes anticipated and documented in your change-management plan at assessment time are part of the assessed system. The trap is unplanned, accumulated change: a hundred small hotfixes that were never in any plan can amount to a system materially different from the one assessed.
Why does it matter for grandfathered systems?
Systems already on the market before the high-risk obligations apply are exempt — until substantially modified. For a system that improves continuously, the exemption is therefore temporary by construction. The clause effectively converts “we ship weekly” into “we will be regulated.”
What is the practical defense?
A documented change-management process, in place before you need it: every change recorded with its motivation, its evaluation, and its approval. That gives you both the argument that changes were planned and controlled, and the evidence to support it.