Book my free AI audit
    We use cookies to analyse site usage and improve your experience. No tracking occurs until you accept.

    Is Your AI High-Risk? The New 2 Dec 2027 Deadline

    (Updated )
    Regulation
    Is Your AI High-Risk? The New 2 Dec 2027 Deadline

    Quick answer: An AI system is high-risk under Annex III of the EU AI Act if it materially shapes decisions in recruitment, credit scoring, life and health insurance pricing, biometrics, education access, essential public services or critical infrastructure. The deadline is no longer 2 August 2026. Regulation (EU) 2026/1744 — the Digital Omnibus on AI, in force since 27 July 2026 — moved stand-alone Annex III obligations to 2 December 2027 and product-embedded AI to 2 August 2028. For each in-scope system you still need the same seven-pillar file: risk management, data governance, technical documentation, logging, transparency, human oversight and accuracy/robustness evidence. Sixteen months is the right amount of time for that work, not a reprieve from it.

    Last verified 7 August 2026.

    The date changed. Read this before you re-plan

    Most of the content published about high-risk AI in the first half of 2026 — including earlier versions of this article — was written against 2 August 2026. That date has passed, and the high-risk regime did not start with it.

    The Digital Omnibus on AI was proposed on 19 November 2025, agreed politically on 7 May 2026, voted by Parliament on 16 June 2026, approved by the Council on 29 June 2026, published in the Official Journal as Regulation (EU) 2026/1744 on 24 July 2026, and entered into force on 27 July 2026. It rewrote Article 113:

    • Stand-alone Annex III high-risk systems (Article 6(2)): 2 December 2027. Was 2 August 2026.
    • AI as a safety component of Annex I Section A products (Article 6(1)): 2 August 2028. Was 2 August 2027.

    What did start on 2 August 2026 is the Article 50 transparency regime and the Commission's power to fine general-purpose AI model providers. If your high-risk system also talks to people or generates content, those duties are live now even though the high-risk file is not yet due — see what actually applies today.

    Two honest consequences:

    1. You are not late. If you have not started the high-risk file, you are on schedule rather than in breach — provided you start.
    2. You are not early either. A complete high-risk file for one non-trivial system takes twelve to eighteen months of elapsed time in an organisation that also runs a business. Sixteen months is the duration of the job, not a buffer on top of it. The companies that reset to "we'll start in 2027" will run the identical fire drill, a year later, with a harder market for compliance help.

    If you are using AI in Luxembourg in any capacity touching the Annex III categories, this post is the sequencing we walk clients through: an intensive 84-day front end that produces the classification and the two hardest pillars, then a paced programme to December 2027.

    First: confirm whether your system actually is high-risk

    Most of the urgent questions land on systems that aren't high-risk and don't realise it, or are and don't realise it.

    Almost certainly high-risk under Annex III if your system:

    • Filters, scores, ranks or recommends candidates in recruitment, or makes decisions on promotion, termination or task allocation
    • Monitors and evaluates worker performance and behaviour
    • Makes or materially supports decisions on creditworthiness or credit scoring of natural persons
    • Sets risk-based pricing or performs risk assessment for life or health insurance
    • Identifies, categorises or verifies natural persons via biometrics
    • Determines access to, or assigns persons to, educational institutions or programmes, or evaluates learning outcomes
    • Is used by public authorities to evaluate eligibility for essential public services or benefits
    • Manages or operates critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity

    Almost certainly not high-risk:

    • Marketing copy generation
    • Internal RAG over your own documents
    • Code completion, summarisation, translation
    • Customer-service chatbots that route to a human on any consequential decision (note: still fully inside Article 50 disclosure, which is due now)
    • Document processing where a human signs off the outcome

    Three carve-outs worth knowing precisely — they save real money:

    • Fraud detection is expressly excluded from Annex III 5(b). AI used to detect financial fraud is not high-risk on that ground. Internal AML and capital-adequacy models are governed by sectoral law, not Annex III.
    • Annex III 5(c) covers life and health insurance only. Motor, property and liability pricing is outside that heading. Do not scope your whole insurance book into the programme.
    • Article 6(3) is a genuine filter. A listed system can be treated as not high-risk where it does not pose a significant risk of harm — because it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task. The filter never applies where the system profiles natural persons. Rely on it and you must document the assessment and register it; the omnibus streamlined that registration after the Commission's proposal to remove it was rejected by both co-legislators.

    Genuine grey zones we see weekly in Luxembourg:

    • HR systems that "just suggest" candidates — probably high-risk if they materially shape hiring outcomes; the Article 6(3) carve-out is narrow and never survives profiling
    • Insurance underwriting copilots recommending pricing to a human underwriter — high-risk if the human is rubber-stamping, arguably filtered if the human genuinely reviews and can be shown to override
    • AI-assisted credit decisioning at fintechs — almost always high-risk regardless of framing
    • Hybrid fraud-and-credit pipelines where the scoring logic is not architecturally separable from the anomaly detection — assume in scope
    • Educational assessment AI used by Luxembourg lycées and Université du Luxembourg admissions teams — high-risk under Annex III paragraph 3

    If you are in a grey zone, resolve it on paper now. Have a lawyer or compliance officer write a one-page determination memo, dated, with reasoning. The worst outcome is having to defend "we didn't know". The second-worst is ten people in the company holding ten different mental models of whether a system is in scope.

    The seven-pillar high-risk readiness file

    For every system classified as high-risk, you need a file. Providers owe all seven pillars plus a quality management system, conformity assessment, the EU declaration of conformity, CE marking, and registration in the EU database under Article 49 (registration is in the EU database — there is no Luxembourg national registry for this).

    1. Risk management documentation. Iterative, system-lifetime risk assessment. Not the GDPR DPIA; this is wider. If you are a financial entity, Article 9(10) explicitly permits integrating this into your DORA ICT risk management procedures — use that.
    2. Data and data-governance documentation. What trained the model, what feeds it in production, provenance, bias examination, how quality is maintained. The omnibus added a GDPR legal basis for processing special categories of data specifically for bias detection and correction, subject to a strict-necessity test and safeguards (non-sensitive or synthetic data considered first, pseudonymisation, access controls, limits on onward sharing, timely deletion).
    3. Technical documentation. Minimum content in Annex IV. The omnibus introduced a simplified technical documentation form for SMEs and small mid-caps — check your eligibility before you build the full version.
    4. Logging. Automatic event logging across the lifecycle, retained appropriately. Deployers must retain the automatically generated logs for at least six months.
    5. Transparency and instructions for use. What deployers and end-users need in order to operate it safely — FR / DE / EN for a Luxembourg user base.
    6. Human oversight. How a human interprets, overrides and intervenes — by a person with the competence, training and authority to do it.
    7. Accuracy, robustness and cybersecurity. Documented performance benchmarks and resilience to adversarial input, manipulation and drift — increasingly overlapping with NIS2 security duties.

    Plus, for a specific set of deployers: Article 27, the Fundamental Rights Impact Assessment. Required from public bodies, from private operators providing public services, and from any deployer of an Annex III point 5(b) or 5(c) system. In this market that means every lender doing creditworthiness assessment and every life or health insurer — private or not.

    The 84-day front end, week by week

    The full programme runs to December 2027. The first 84 days are what determine whether the rest of it is cheap or expensive, because they catch the scope mistakes that cost months.

    Weeks 1–2 (days 1–14): Inventory and classification

    • List every AI system in production and every AI feature in tools you procured (Microsoft 365 Copilot, Salesforce Einstein, your ATS's "AI matching", your finance platform's "AI insights")
    • For each: deployer? provider? both? Use the five-minute test
    • For each: Annex III high-risk? Article 6(3) filter? clearly out of scope?
    • In parallel, and this one is due now: which Article 50 disclosure duties attach, and are they live on the product?
    • Output: a one-page register signed by the responsible executive

    Weeks 3–4 (days 15–28): Pillars 1 and 2 — risk management and data governance

    • Risk register per high-risk system
    • Data lineage diagram per high-risk system
    • Bias / fairness baseline established, with the legal basis for any special-category processing documented
    • Output: pillars 1 and 2 complete

    Weeks 5–6 (days 29–42): Pillar 3 — technical documentation

    • Annex IV-aligned documentation per high-risk system, or the simplified SME form where eligible
    • If you procured the system, this is mostly the vendor's documentation plus your deployment-specific addendum — request it now, contractually, because it will take them longer than you expect
    • Output: pillar 3 skeleton complete

    Weeks 7–8 (days 43–56): Pillars 4 and 5 — logging and transparency

    • Logging architecture audited; retention policy set at six months minimum for deployer-held logs
    • User-facing transparency notices reviewed in FR / DE / EN — and reconciled against the Article 50 duties that already apply
    • Output: pillars 4 and 5 complete

    Weeks 9–10 (days 57–70): Pillar 6 — human oversight

    • Documented oversight role, training and intervention path per system
    • Tied to your Article 4 literacy programme
    • Tabletop exercise: walk an "override" scenario end to end, and start measuring override rates in production
    • Output: pillar 6 complete

    Weeks 11–12 (days 71–84): Pillar 7, FRIA scoping, and review

    • Accuracy / robustness / cybersecurity testing documented
    • Article 27 FRIA scoped for any 5(b) or 5(c) system
    • Independent internal review of the file, separate from the team that built it
    • Output: a complete first-pass file and a costed plan for the remaining thirteen months

    The order matters. Do it backwards — start with technical docs, end with classification — and you produce three files for systems that turn out not to be in scope while missing two that are.

    The CSSF / DORA wrinkle

    If you are CSSF-supervised, the high-risk work overlaps materially with DORA + EU AI Act compliance and with Circular CSSF 22/806 on outsourcing, as amended by Circular CSSF 25/883. The CSSF realigned its rulebook around DORA in 2025 through Circulars 25/880 and 25/882, separating DORA from non-DORA obligations — establish which side your arrangement falls on before you build the vendor file.

    Real consolidation is available: the same supplier due-diligence file, exit strategy and incident-response playbook can serve all three regimes if you architect it that way, and Article 9(10) of the AI Act gives you explicit permission to fold AI risk management into your DORA procedures. Firms that duplicate this across functions typically spend 30–40% more compliance hours than firms that consolidate.

    There is no dedicated CSSF circular on AI. The supervisory expectations come through the two joint CSSF/BCL thematic reviews on AI in the Luxembourg financial sector — May 2023 (credit institutions, e-money and payment institutions) and the substantially broader May 2025 edition (adding investment firms and authorised AIFMs). The consistent message across both: governance, human oversight and explainability must be demonstrable for any AI solution a supervised entity relies on.

    Running a Luxembourg SME?

    Book a free 30-minute AI audit — we’ll tell you honestly where AI pays off for your business, and where it doesn’t.

    Book a free AI audit

    What good looks like on 2 December 2027

    • A one-page system register, signed and dated, with classification per system
    • A complete seven-pillar file for each high-risk system
    • Article 27 FRIAs where 5(b) or 5(c) applies
    • A literacy-training register covering everyone who interacts with these systems
    • A named human-oversight officer per system with a one-page role description — and override-rate data proving the oversight is real
    • Tabletop exercise records
    • Vendor agreements updated where the Act has shifted obligations to the provider
    • EU database registration completed for stand-alone Annex III systems
    • An incident-response playbook integrated with what you already run for GDPR, DORA and NIS2

    If you have all of that, you are not just compliant — you are auditable, which is the standard regulators actually care about.

    Who will ask for it in Luxembourg

    Luxembourg has not completed its national designation. Bill of law n°8476, deposited on 23 December 2024, would make the CNPD the national competent authority, single point of contact and default market surveillance authority, with the CSSF for financial-sector AI, the CAA for insurance, the ILR for high-risk AI at NIS2 essential and important entities, and ILNAS as notifying authority for conformity assessment bodies. The CNPD would also operate Luxembourg's Article 57 regulatory sandbox — to which the omnibus gives SMEs and small mid-caps priority access.

    The bill was still in the parliamentary process at the time of writing. The obligations bind you directly regardless: the AI Act is a regulation, and the evidence file is the same file whichever authority eventually asks.


    Turn sixteen months into a plan you can defend

    The commonest failure mode right now is neither panic nor negligence. It is a company that has read that the deadline moved, quietly deprioritised the work, and will rediscover it in mid-2027 with four months left and no register.

    The 20 More AI Act Readiness Assessment is the front end of that programme, delivered in ten working days:

    1. The AI system register — every system and every AI feature, including procured tools nobody classified, with the provider-or-deployer determination made and evidenced per system.
    2. The Article 50 gap report — the disclosures you owe today, mapped to the specific chatbots, voice agents, screens and published content that are missing them, with the 2 December 2026 machine-readable-marking work scheduled as engineering.
    3. The Annex III exposure list — which systems are high-risk on 2 December 2027, which qualify for the Article 6(3) filter and on what documented reasoning, which trigger an Article 27 FRIA, and a costed pillar-by-pillar work programme with dates.
    4. A one-page board memo — signed and dated, written to be handed to the CNPD, the CSSF or a client's procurement team unedited.

    From there we run the seven-pillar build alongside your DPO, internal counsel or external compliance support. We do not replace them; we produce and sequence the operational work they sign.

    See the AI Act readiness service, or book the 30-minute scoping call. Bring the systems you are least sure about — those are the ones worth the thirty minutes.


    Related reading:

    Is your AI project eligible for up to 70% Luxembourg funding?

    Max €17,500 per project. Instant estimate — 4 quick questions, no email required.

    Check my eligibility (2 min)

    Ready to put this into practice?

    Two ways to start — pick whichever fits your timing.

    Tags:
    Luxembourg
    EU AI Act
    Compliance
    High-Risk Systems
    Regulation

    Related Resources

    AI Implementation in Luxembourg

    Explore our comprehensive guide to AI adoption, implementation, and governance in Luxembourg.

    Read the Guide

    Work with an AI consultant in Luxembourg

    See what we build, what it costs, and how projects qualify for up to 70% SME co-funding.

    AI Consultant in Luxembourg