Article 50(2) machine-readable marking is a provider obligation,
not a deployer obligation. Deployers have 50(1) chatbot disclosure
and 50(4) deepfake disclosure. Revised to distinguish roles.
Address Greptile P1: guide conflated provider and deployer obligations.
- Added section explaining Article 3(3) provider vs Article 3(4) deployer
- Most LiteLLM users building custom apps are providers (heavier obligations)
- Clarified that system-level compliance is the user's responsibility,
separate from foundation model providers' own obligations
Address Greptile P1: 'your_logging_backend' is not a valid callback.
Show both built-in integration (langfuse/s3/datadog) and CustomLogger
class pattern with actual Article 12 field references.
Address Greptile review:
- P1: Article 14 table incorrectly mapped automated controls as human
oversight. Rewritten to clarify that guardrails are Art 9/15 controls,
not Art 14 human oversight. New table shows actual Art 14 requirements.
- P2: Consistent stadium/pill shapes for all provider nodes in diagram.
Address Greptile review feedback:
- 'less likely to apply' → 'do not apply via the Annex III pathway'
- Add full scope check section (Is your system in scope?)
- Align provider list with data flow diagram examples
- Add "Is your system in scope?" section with Annex III checklist
- Fix retention: Article 18 requires 10 years for providers, Article 26(6)
requires minimum 6 months for deployers (was incorrectly "6+ months")
- Qualify GDPR processor role as provider-dependent
Maps LiteLLM's existing logging, callbacks, and guardrails to
EU AI Act Articles 12, 13, and 14. Includes data flow diagram
showing gateway architecture with GDPR role classifications.
Scanner analysis: 4,861 files, 7 AI providers, 112 model identifiers,
12 external services.
Address review feedback from greptile — use new_callable=AsyncMock
on the concurrent test's patch.object to ensure the mock is properly
typed as async, even though side_effect already handles the coroutine.
The release job was failing with "Resource not accessible by integration"
because other jobs explicitly set permissions, causing GitHub to scope the
default token down for all jobs. The release job needs contents:write to
create GitHub releases.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Add WARNING docstring to _get_shared_session_lock() about not resetting
the lock to None while coroutines may be in the recovery path
- Remove redundant proxy_server_module.shared_aiohttp_session assignment
in mock_init (add_shared_session_to_data overwrites it synchronously)
- Add try/except around _initialize_shared_aiohttp_session call to catch
and log exceptions (instead of letting them bubble to outer handler)
- Fix warning message when re-checked session is None (was incorrectly
logging closed session ID on a None session)
- Add debug logging to outer except handler instead of bare pass
- Add test for _initialize_shared_aiohttp_session raising exception
Address Greptile P1 review: tests that exercise the closed-session code
path need to reset the module-level lock to avoid RuntimeError on
Python < 3.10 when asyncio.Lock is reused across different event loops.