EU AI Act August 2026: What Actually Applies Now
Quick answer: The 2 August 2026 deadline did not land the way it was originally written. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — moved the high-risk obligations for stand-alone Annex III systems to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. What did start on 2 August 2026 is the Article 50 transparency regime (you must tell people they are talking to an AI, and label AI-generated content) and the Commission's power to fine general-purpose AI model providers. Two further hard dates now sit in front of Luxembourg companies: 2 December 2026 for machine-readable marking of generative outputs on systems already in the market, and 2 December 2027 for the full high-risk file.
Last verified 7 August 2026, against Regulation (EU) 2026/1744 as published in the Official Journal on 24 July 2026.
This is the canonical 20 More guide to EU AI Act compliance for Luxembourg businesses, consolidating our previous articles on the August 2026 deadline, risk classification, and SME checklists.
First: the deadline you were told about has moved. Here is the accurate picture
If you planned your AI Act programme against "2 August 2026 = high-risk day," that plan is now out of date — and a great deal of the content still circulating online is wrong.
On 19 November 2025 the European Commission proposed the Digital Omnibus package. The Parliament and the Council reached political agreement on 7 May 2026, Parliament voted it through on 16 June 2026 (423 for, 57 against, 174 abstentions), the Council gave final approval on 29 June 2026, and the resulting Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
It rewrote Article 113 of the AI Act. The new application dates:
| Obligation | Original date | Date now in force |
|---|---|---|
| Article 5 prohibited practices, Article 4 AI literacy | 2 Feb 2025 | 2 Feb 2025 (unchanged) |
| GPAI model obligations (Chapter V), governance, penalties regime (Article 99) | 2 Aug 2025 | 2 Aug 2025 (unchanged) |
| Article 50 transparency obligations | 2 Aug 2026 | 2 Aug 2026 (unchanged — this one landed) |
| Commission fining powers over GPAI providers | 2 Aug 2026 | 2 Aug 2026 (unchanged) |
| Machine-readable marking (Art. 50(2)) for generative systems already on the market | 2 Aug 2026 | 2 Dec 2026 |
| New prohibitions: non-consensual intimate imagery, CSAM generation | — | 2 Dec 2026 (new) |
| Legacy GPAI models placed on the market before 2 Aug 2025 | 2 Aug 2027 | 2 Aug 2027 (unchanged) |
| High-risk: stand-alone Annex III systems (Art. 6(2)) | 2 Aug 2026 | 2 Dec 2027 |
| High-risk: AI embedded in Annex I Section A products (Art. 6(1)) | 2 Aug 2027 | 2 Aug 2028 |
Read that table twice before you brief your board. The two conclusions that matter:
- Something real did bite this month. Article 50 is now enforceable, it applies to almost every business with a chatbot or a content pipeline, and it carries the €15 million / 3% penalty band.
- The high-risk work did not go away — it got a realistic runway. 2 December 2027 is roughly sixteen months out. A complete high-risk file for a single system takes twelve to eighteen months of elapsed time in a company that also has a day job. The deferral is not slack; it is the amount of time the work actually needs.
We would rather tell you this than sell you a panic. If a vendor is still telling you that high-risk conformity assessment is due this month, they have not read Regulation (EU) 2026/1744.
This guide covers what a Luxembourg business owes today, what it owes in December, and what it owes by December 2027 — and where compliance fits into your wider AI implementation in Luxembourg.
What actually started on 2 August 2026: Article 50 transparency
Article 50 is the sleeper provision of the AI Act. It is short, it applies horizontally regardless of risk class, and it reaches more Luxembourg organisations than any other article in the regulation — because it is triggered by interaction and content, not by sector.
Four duties, split between providers and deployers:
50(1) — Provider duty: disclose the AI. If you place an AI system on the market that interacts directly with people — a website chatbot, a voice agent, an in-app assistant — it must be designed so the person is informed they are dealing with an AI. The exemption is narrow: it applies only where this is obvious to a reasonably well-informed person in the circumstances.
50(2) — Provider duty: mark generative output. Providers of AI systems that generate synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This is the watermarking and provenance-metadata layer. For systems already placed on the market before 2 August 2026, the omnibus gives until 2 December 2026 — the tooling standards were not ready in time.
50(3) — Deployer duty: emotion recognition and biometric categorisation. If you operate one, you must inform the people exposed to it. (Note that emotion recognition in the workplace and in education is separately prohibited outright under Article 5 — see below.)
50(4) — Deployer duty: deepfakes and public-interest text. If you deploy a system that generates or manipulates image, audio or video constituting a deep fake, you must disclose that the content is artificially generated or manipulated. The same applies to AI-generated text published to inform the public on matters of public interest, unless the content underwent human review and a person or organisation holds editorial responsibility.
50(5) requires the information to be given clearly and distinguishably, at the latest at the first interaction or exposure.
What that means concretely for a Luxembourg SME this month
- Your customer-service chatbot needs an unambiguous disclosure at the start of the conversation. "Hi, I'm Ana!" is not a disclosure. "Hi, I'm Ana, an AI assistant — I'll pass you to a colleague any time you ask" is.
- Your voice agent needs the same, spoken, in the first few seconds — in the language of the call. In Luxembourg that means the disclosure has to exist in FR, DE and EN, not only in English.
- Marketing content generated with AI and published as editorial to inform the public needs either a disclosure or a documented human editorial review. Pick one and write down which.
- If you build and ship a generative feature to customers, the machine-readable marking work has a real deadline of 2 December 2026. That one is engineering work, not policy work — start it now.
- Every one of these decisions belongs in a written record. The record is what turns a supervisory question into a short conversation.
Penalty band for Article 50 breaches: up to €15 million or 3% of total worldwide annual turnover, whichever is higher — with the important SME reversal described below. Enforcement sits with national market surveillance authorities from 2 August 2026.
What also started on 2 August 2026: GPAI enforcement
Obligations on providers of general-purpose AI models have applied since 2 August 2025. What changed this month is that the Commission can now actually fine them — up to 3% of worldwide annual turnover or €15 million, whichever is higher. Providers whose models were placed on the market before 2 August 2025 have until 2 August 2027 to bring them into line.
For almost every Luxembourg company this is somebody else's obligation: it falls on OpenAI, Anthropic, Google, Mistral, Meta and their peers, not on you for using their APIs. It matters to you in one specific way — as a downstream builder you are entitled to receive technical documentation and integration information from the model provider, and that documentation is part of your evidence file. Collect it and version it. The detail is in our GPAI obligations breakdown.
The exception is the company that fine-tunes or substantially modifies a model and puts it out under its own name. That can make you a provider. Which brings us to the classification question.
The classification that decides everything: provider or deployer
The AI Act assigns obligations by role, not by industry. Most Luxembourg SMEs are deployers — they use AI systems supplied by someone else, under their own authority, in the course of a professional activity. Deployer obligations are materially lighter than provider obligations, but they are real and they are not transferable to the vendor by contract.
You become a provider if you place an AI system on the market or put it into service under your own name or trademark, or if you substantially modify a system, or change its intended purpose. A fintech shipping a customer-facing AI feature inside its own product is a provider of that system even if the underlying engine is a thin wrapper over a foundation model.
Same company, different systems, different roles. Work it out per system, write down the reasoning, date it. Our provider vs. deployer quick reference is the five-minute version of that test.
What lands on 2 December 2026
Two things, and both are easy to miss because they sit between the two headline dates:
- Machine-readable marking under Article 50(2) for generative systems that were already on the market on 2 August 2026. Watermarking, provenance metadata, detectability. Engineering lead time applies.
- Two new prohibited practices added by the omnibus: AI systems used to generate non-consensual intimate imagery ("nudification" applications) and child sexual abuse material. These join the Article 5 list and carry the top penalty band. Very few Luxembourg businesses are anywhere near this, but if you provide general image-generation capability to third parties, your abuse controls are now a legal matter and not only a trust-and-safety matter.
What lands on 2 December 2027: the high-risk regime
This is the big body of work, and sixteen months is the right amount of time for it — not a comfortable margin.
Which AI systems are high-risk
Two routes into the classification.
Annex I (Section A): AI as a safety component of a regulated product. Machinery, medical devices, in-vitro diagnostics, lifts, toys, radio equipment, pressure equipment and the rest. These are absorbed into the existing sectoral CE-marking regime, and their AI Act date is 2 August 2028.
Annex III: listed high-risk use cases. These are the stand-alone systems, and their date is 2 December 2027:
- Biometrics — remote biometric identification; biometric categorisation by sensitive attributes; emotion recognition (outside the contexts where it is prohibited entirely).
- Critical infrastructure — safety components in the management and operation of digital infrastructure, road traffic, and the supply of water, gas, heating and electricity.
- Education and vocational training — admission or assignment to institutions, evaluating learning outcomes, assessing the appropriate level of education, monitoring prohibited behaviour during tests.
- Employment and worker management — recruitment, CV filtering, candidate evaluation; decisions on promotion, termination, task allocation; monitoring and evaluating performance and behaviour.
- Access to essential services — evaluating eligibility for public benefits; evaluating creditworthiness or establishing credit scores of natural persons; risk assessment and pricing in life and health insurance; emergency-call triage and dispatch.
- Law enforcement, migration, asylum, border control, and administration of justice — largely public-sector.
Two precision points that Luxembourg financial firms get wrong constantly:
- Fraud detection is expressly carved out of Annex III 5(b). AI used to detect financial fraud is not high-risk on that basis. Neither is an internal AML or capital-adequacy model — those are governed by sectoral law. Where firms get into trouble is the hybrid pipeline that fuses fraud anomaly detection with credit-scoring logic in a single model. If the scoring component is not architecturally separable, assume the whole thing is in scope and design accordingly.
- Annex III 5(c) covers life and health insurance only. Risk assessment and pricing for motor, property or liability lines is not high-risk under that heading. Do not over-scope your programme by treating the whole insurance book as Annex III; do not under-scope it by forgetting that health and life products are squarely in.
There is also a filter. Article 6(3) allows a system listed in Annex III to be treated as not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights — because it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task. The filter never applies where the system performs profiling of natural persons. If you rely on it, you must document the assessment and register it. The omnibus streamlined that registration; the Commission had proposed removing it entirely and both co-legislators refused.
What a high-risk file contains
For each in-scope system: a risk management system across the lifecycle; data and data-governance documentation covering training, validation and testing sets including bias examination; technical documentation to Annex IV; automatic logging with retention; transparency and instructions for use; human oversight design; and evidence on accuracy, robustness and cybersecurity. Providers add a quality management system, conformity assessment, the EU declaration of conformity, CE marking and registration in the EU database.
Deployers of Annex III systems carry a shorter but non-trivial list under Article 26: use the system per the provider's instructions; assign human oversight to people with the competence, training and authority to exercise it; ensure input data is relevant and sufficiently representative for the intended purpose; monitor operation and report risks and serious incidents; keep the automatically generated logs for at least six months; and inform workers and their representatives before putting a system into service in the workplace.
And Article 27: a Fundamental Rights Impact Assessment is required from public bodies, from private operators providing public services, and — importantly for this market — from any deployer of an Annex III 5(b) or 5(c) system. If you assess creditworthiness or price life and health insurance, the FRIA is yours regardless of whether you are public or private. It falls due with the rest of the high-risk regime on 2 December 2027.
The full seven-pillar breakdown is in our high-risk systems guide.
Stop guessing where you stand. Get it in writing.
Right now most Luxembourg companies are in one of two wrong positions: they think a deadline passed that did not, or they think nothing applies because a deadline moved. Both are expensive.
The 20 More AI Act Readiness Assessment is a fixed-scope engagement that ends the guessing. Ten working days. You get four artefacts:
- The AI system register — every AI system and AI feature in the business, including the ones procurement never saw, with the provider-or-deployer determination made and evidenced per system.
- The Article 50 gap report — the disclosures you legally owe today, mapped to the specific chatbots, voice agents, screens, templates and published content that are missing them, with the 2 December 2026 machine-readable-marking items scheduled separately as engineering work.
- The Annex III exposure list — which systems will be high-risk on 2 December 2027, which qualify for the Article 6(3) filter and on what documented reasoning, whether Article 27 FRIA applies to you, and a costed work programme against that date.
- A one-page board memo — signed and dated, written to be handed to the CNPD, the CSSF or a client's procurement team without further translation.
→ See the AI Act readiness service, or book the 30-minute scoping call and we will tell you on the call which of the three dates actually applies to you.
Luxembourg specifics: who supervises, and where you register
Two corrections to claims that circulate widely in this market, including in earlier versions of this article.
There is no Luxembourg national registry of high-risk AI systems, and no "Luxembourg Digital Authority". Registration of stand-alone Annex III high-risk systems happens in the EU database established under Article 71, with the registration obligation in Article 49. Only high-risk systems in the critical-infrastructure area are registered at national level. If you have been told to register with a Luxembourg AI authority by a given date, ask for the legal basis.
Luxembourg has not yet completed its national designation. Bill of law n°8476, deposited with the Chamber of Deputies on 23 December 2024, is the instrument that will designate the national competent authorities and set national penalty rules. It was still in the parliamentary process at the time of writing. Its architecture:
| Role | Body |
|---|---|
| National competent authority, single point of contact, default market surveillance authority | CNPD (Commission nationale pour la protection des données) |
| Regulatory sandbox operator (Article 57) | CNPD |
| Financial sector AI systems | CSSF |
| Insurance sector AI systems | CAA (Commissariat aux Assurances) |
| High-risk AI deployed by NIS2 essential/important entities | ILR (Institut Luxembourgeois de Régulation) |
| Notifying authority for conformity assessment bodies | ILNAS |
The CNPD has been visibly preparing for the role — it convened the "AI Act in Action" conference in Luxembourg in January 2026 to work through exactly this governance question with industry.
Practical consequence: until 8476 is voted, the enforcement route for a Luxembourg company is less certain than the substantive obligations are. That is not a reason to wait. The obligations bind directly — the AI Act is a regulation, not a directive — and the evidence file you build now is the same file whichever authority eventually asks for it.
Article 57 sandbox. Member States must have at least one AI regulatory sandbox operational by 2 August 2026, individually or jointly with other Member States. Under bill 8476 the CNPD would run Luxembourg's. The omnibus gives SMEs and small mid-caps priority access — a genuine, underused benefit for a small-market company with a novel system.
Sector notes for Luxembourg
Financial services — CSSF, DORA and Circular 22/806
Luxembourg's financial sector is the one where AI Act obligations land on top of an already dense regulatory stack, and where consolidation saves the most money.
- DORA has applied since 17 January 2025 and is the ICT risk regime for financial entities. Article 9(10) of the AI Act explicitly permits integrating the AI risk management system into the ICT risk management procedures a financial entity already runs under DORA. That is a licence to build once and evidence twice — take it.
- Circular CSSF 22/806 on outsourcing arrangements, as amended by Circular CSSF 25/883, governs your ICT outsourcing file. Your model provider, your orchestration platform and your hosting environment sit in it. The CSSF reworked the rulebook around DORA in 2025 (Circulars 25/880 and 25/882) to separate DORA and non-DORA obligations — check which side your arrangement falls on before you build the file.
- CSSF expectations on AI are set out through supervisory practice, not a dedicated AI circular. The CSSF and the BCL have published two joint thematic reviews on AI use in the Luxembourg financial sector — the first in May 2023 covering credit institutions, e-money and payment institutions, and a second, substantially broader edition in May 2025 adding investment firms and authorised AIFMs. The consistent supervisory message across both: governance, human oversight and explainability must be demonstrable for any AI solution a supervised entity relies on. Read them; they are the closest thing to a CSSF AI rulebook that exists.
- Classification discipline matters most here. Credit scoring of natural persons: Annex III 5(b), high-risk, and FRIA applies. Life and health insurance pricing: Annex III 5(c), high-risk, FRIA applies. Fraud detection: carved out. AML: sectoral law. Customer-service chatbots: not high-risk, but squarely inside Article 50 — which is due now.
Depth on the combined regime is in our DORA + EU AI Act playbook.
Employment and HR
Recruitment screening, CV filtering, candidate ranking, promotion and termination decisions, task allocation and performance monitoring are all Annex III — high-risk from 2 December 2027. Two things already apply, though: emotion recognition in the workplace is prohibited outright under Article 5 and has been since 2 February 2025, and Article 26 will require you to inform workers and their representatives before putting a system into service. In a Luxembourg context that means engaging the delegation du personnel — start that conversation before the system is bought, not after.
Professional services, healthcare, logistics
- Legal research, contract review and document analysis: generally not Annex III where a professional retains judgement; the risk rises sharply where the AI output substitutes for that judgement.
- Diagnostic support: high-risk as a safety component of a medical device, dual-regulated under the MDR, and on the 2 August 2028 track.
- Route optimisation and demand forecasting: minimal risk. Workforce management, scheduling and productivity monitoring: employment-category high-risk. Separate the two systems architecturally and the compliance boundary follows the architecture.
The penalty framework, precisely
The penalty regime in Article 99 has applied since 2 August 2025. It was not waiting for August 2026, and it was not deferred by the omnibus.
| Tier | Trigger | Maximum |
|---|---|---|
| 1 | Article 5 prohibited practices | €35 million or 7% of total worldwide annual turnover, whichever is higher |
| 2 | Most other obligations — high-risk duties, Article 50 transparency, GPAI, and (added by the omnibus) certain Article 25 duties | €15 million or 3%, whichever is higher |
| 3 | Incorrect, incomplete or misleading information to a notified body or competent authority | €7.5 million or 1%, whichever is higher |
The SME reversal matters more than the headline numbers. Article 99(6) inverts the rule for SMEs and start-ups: they face the lower of the fixed amount and the percentage, not the higher. A Luxembourg SME with €30 million turnover faces up to €2.1 million on tier 1, not €35 million. The omnibus extended a comparable lower cap to small mid-cap enterprises for the tier 2 and tier 3 bands, and wrote the SME and small mid-cap definitions into the AI Act itself along with a simplified technical documentation form for high-risk systems and proportionate quality-management requirements.
Article 99(7) additionally requires authorities to take the size and interests of an SME into account when setting an amount. "Up to" means up to.
Our fines and penalties breakdown works the arithmetic through on Luxembourg turnover figures.
What already applied, and still catches people out
Article 5 prohibitions — since 2 February 2025
Eight practices banned outright, with two more joining on 2 December 2026. The ones that catch ordinary Luxembourg businesses: emotion recognition in the workplace or in education (engagement scoring, sentiment dashboards over sales calls, AI proctoring in training platforms), manipulative techniques that materially distort behaviour, and exploitation of vulnerability by age, disability or socio-economic situation. Top penalty band. Full sweep in our Article 5 guide.
Article 4 AI literacy — since 2 February 2025, and amended
Providers and deployers must take measures relating to the AI literacy of staff and of others operating AI systems on their behalf. The omnibus softened the wording: the duty is now to take measures to support the development of AI literacy, rather than to ensure, to their best extent, a sufficient level of it. That is a genuine reduction in the standard — and it does not remove the obligation, it removes the argument that you were required to guarantee an outcome you cannot control. A documented, role-proportionate programme with attendance records remains the right answer, and it is cheap. See the Article 4 implementation guide.
Running a Luxembourg SME?
Book a free 30-minute AI audit — we’ll tell you honestly where AI pays off for your business, and where it doesn’t.
Book a free AI auditCommon mistakes, updated for the post-omnibus timeline
Treating the deferral as a reprieve. Sixteen months is the honest duration of a high-risk programme for a first system, not a buffer on top of it. Companies that reset their plan to "start in 2027" will run the same fire drill, twelve months later.
Assuming the vendor's compliance is your compliance. As a deployer you carry Article 26 duties in your own name. A contract can allocate cost and indemnity; it cannot allocate the obligation.
Missing Article 50 because it is not called "high-risk". The single most likely enforcement contact for an ordinary Luxembourg SME in the next twelve months is an unlabelled chatbot, not a conformity assessment failure.
Misclassifying by technical sophistication. Classification follows purpose and impact. A simple rules engine making employment decisions is high-risk; a large neural network optimising delivery routes is minimal risk. Ask what decisions the system influences and who is affected, not how clever it is.
Illusory human oversight. Article 26 requires oversight by people with the competence, training and authority to exercise it. If a credit officer reviewing a hundred AI decisions a day is measured on throughput, the oversight is decorative. Measure override rates. If nobody ever overrides, you do not have oversight — you have a rubber stamp, and a supervisor will see it as one.
Building the file twice. GDPR, DORA, NIS2 and the AI Act converge on the same artefacts: an inventory, a risk register, a vendor file, an incident taxonomy, a training record. Build one system of record with multiple regulatory views. See the NIS2 overlap analysis.
Luxembourg funding
Compliance-adjacent work is partly fundable here. Luxinnovation's Fit 4 Digital and Fit 4 AI routes can support assessment work, SME package schemes cover regulatory consulting, and AI implementation support can reach substantial co-funding for qualifying Luxembourg SMEs. Eligibility rules and rates change — confirm current terms with Luxinnovation before you budget against a number you read in a blog post, including this one. Our Fit 4 AI programme guide has the current shape of it.
Frequently asked questions
Did the EU AI Act deadline of 2 August 2026 actually pass?
Partly. Article 50 transparency obligations and the Commission's GPAI fining powers took effect on 2 August 2026 as originally scheduled. The high-risk obligations that were also due that day were deferred by Regulation (EU) 2026/1744 — to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products.
What does my Luxembourg business have to do right now, in August 2026?
Disclose AI interaction wherever a person talks to your AI system; disclose or take documented editorial responsibility for AI-generated content published to inform the public; inform people exposed to emotion recognition or biometric categorisation systems; and confirm you are not operating any Article 5 prohibited practice. Then build the register that lets you prove all of the above.
What happens if my Luxembourg business is not compliant with Article 50?
Article 50 breaches fall in the €15 million or 3% of worldwide turnover band — with SMEs facing the lower of the two figures rather than the higher, under Article 99(6). Market surveillance authorities can also require corrective action or withdrawal of the system.
How do I know if my AI system is high-risk?
It is high-risk if it falls under Annex I Section A (a safety component of a product already covered by EU harmonisation legislation) or Annex III (the listed use cases — recruitment, credit scoring, life and health insurance pricing, biometrics, education access, essential services, critical infrastructure, law enforcement). The Article 6(3) filter can take a listed system out of scope where it poses no significant risk of harm, but never where it profiles natural persons.
Is AI-based fraud detection a high-risk system?
No, not on the creditworthiness ground. Annex III point 5(b) expressly excludes AI systems used to detect financial fraud. The complication is the hybrid model: if fraud anomaly detection and credit scoring share one inseparable pipeline, treat the system as in scope.
Do I need to comply if I only use third-party AI tools?
Yes. Using an AI system under your own authority in a professional activity makes you a deployer, and deployer obligations bind you directly. Article 50 disclosure duties for deepfakes, emotion recognition and biometric categorisation fall on deployers today. Article 26 duties follow on 2 December 2027 for high-risk systems.
Where do I register a high-risk AI system in Luxembourg?
In the EU database established by Article 71, under the Article 49 registration obligation — not in a Luxembourg national registry, which does not exist. Only critical-infrastructure high-risk systems are registered nationally.
Does the deferral to December 2027 mean we can stop work?
No — but you can re-sequence it. The high-risk file for a single complex system realistically takes twelve to eighteen months. Sixteen months is a working timetable, not a pause. And the classification and inventory work at the front of that programme is the same work Article 50 compliance needs today, so it pays for itself twice.
How does the EU AI Act interact with GDPR?
They apply simultaneously and were designed to. The omnibus added a specific legal basis for processing special categories of personal data for bias detection and correction in AI models and systems, under a strict-necessity standard with mandatory safeguards — considering non-sensitive or synthetic data first, pseudonymisation, access controls, limits on onward sharing and timely deletion. Run AI Act and GDPR assessments as one workstream. See GDPR-compliant AI for Luxembourg SMEs.
Next steps
- Inventory. Every AI system and every AI feature inside tools you already bought. Include the shadow ones.
- Classify by role. Provider or deployer, per system, with written reasoning and a date.
- Close the Article 50 gaps. This is live. It is also the cheapest work in the programme.
- Schedule the 2 December 2026 marking work if you ship generative features.
- Map Annex III exposure and set a plan against 2 December 2027 — starting from the systems where a FRIA will be required.
- Consolidate. One register, one incident taxonomy, one vendor file, serving AI Act, GDPR, DORA and NIS2.
Companion guides: Article 5 prohibited practices, Article 4 AI literacy, provider vs. deployer, high-risk systems, conformity assessment and notified bodies, and AI legal and compliance automation.
Ready to stop reading and start with a register? The AI Act readiness service delivers the four artefacts above in ten working days, or book a 30-minute scoping call.
Is your AI project eligible for up to 70% Luxembourg funding?
Max €17,500 per project. Instant estimate — 4 quick questions, no email required.
Ready to put this into practice?
Two ways to start — pick whichever fits your timing.
Related Resources
AI Implementation in Luxembourg
Explore our comprehensive guide to AI adoption, implementation, and governance in Luxembourg.
Read the GuideWork with an AI consultant in Luxembourg
See what we build, what it costs, and how projects qualify for up to 70% SME co-funding.
AI Consultant in LuxembourgRelated Posts
GDPR-Compliant AI in Luxembourg: 2026 CNPD Guide
CNPD audits intensified in 2026. The vendor checklist Luxembourg SMEs use to pick GDPR-compliant AI — DPAs, data transfers, AI Act overlap, plain English.
AI Legal & Compliance Automation: Luxembourg 2026
Cut contract review time 70% at Luxembourg law firms with AI: due diligence, compliance monitoring, GDPR-safe tools, 50% Fit 4 AI funded. Inside.
NIS2 + EU AI Act: One Compliance Program, Not Two
NIS2 and the EU AI Act share five duty areas — risk, incidents, vendors, training, logging. One programme, not two, mapped to the revised 2027 AI Act dates.
