Skip to content

Enterprise AI

The EU AI Act in Luxembourg: what companies must do before August 2026

The phased timeline of Regulation (EU) 2024/1689, what it means for Luxembourg companies — including CSSF-regulated firms — and the three practical steps to take before 2 August 2026.

Sid Ali Temkit, PhDAugust 22, 20266 minShare:

The EU AI Act — Regulation (EU) 2024/1689 — is the world's first comprehensive law on artificial intelligence. It entered into force on 1 August 2024 and applies in phases. The next major deadline, 2 August 2026, is the one that matters for most Luxembourg companies: from that date, the bulk of the Act's obligations — including most rules for high-risk AI systems — apply.

This guide explains the timeline, who is affected, and what a sensible first response looks like for a company in Luxembourg. It is general information, not legal advice — your obligations depend on how your specific AI uses are classified, and that classification deserves a proper review with your legal counsel.

The phased timeline, in plain terms

The AI Act does not arrive all at once. The European Commission's published implementation timeline works out as follows:

  • 2 February 2025 — prohibited practices and AI literacy. Certain AI practices are banned outright: social scoring by public authorities, AI that manipulates people to their detriment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools (with narrow exceptions), and more. Organisations must also ensure their staff have an adequate level of AI literacy.
  • 2 August 2025 — general-purpose AI (GPAI). Obligations for providers of general-purpose AI models apply: technical documentation, copyright policy, training-data summaries, and additional duties for models posing systemic risk. The EU AI Office and the governance framework also become operational, and member states must lay down penalty rules.
  • 2 August 2026 — the general application date. Most of the remaining Act applies, including the rules for high-risk AI systems listed in Annex III (areas such as employment and worker management, access to essential services, credit scoring, education, and law enforcement) and the transparency obligations for systems like chatbots and AI-generated content.
  • 2 August 2027 — high-risk AI embedded in regulated products. An extended transition applies for AI systems that are safety components of products already covered by EU product legislation (Annex I) — machinery, medical devices, vehicles and similar.

Penalties scale with the violation: up to €35 million or 7% of worldwide annual turnover for prohibited practices, with lower tiers for other infringements.

Who is affected — probably you, as a deployer

The Act distinguishes several roles. The two that matter most in practice:

  • Providers develop AI systems or models and place them on the EU market. They carry the heaviest obligations.
  • Deployers use AI systems under their own authority. This is where most Luxembourg companies will land — the moment your teams use an AI system in hiring, customer scoring, or customer-facing chat, you have deployer duties for it.

Deployer obligations for high-risk systems include using the system according to the provider's instructions, ensuring human oversight, monitoring operation, keeping logs, and — for employers — informing workers' representatives before putting a high-risk AI system into service at the workplace. Even outside the high-risk category, transparency duties apply: people must be told when they are interacting with an AI system, and AI-generated content must be identifiable as such in the situations the Act defines.

Importantly, the Act applies regardless of company size. SMEs get some proportionality relief — lighter documentation formats, sandbox access — but not an exemption.

The Luxembourg context

Luxembourg's economy concentrates exactly the sectors where the AI Act bites hardest. A few points worth knowing:

  • CSSF-regulated firms. Banks, insurers, fund managers and payment institutions already operate under an outsourcing, ICT-risk and governance framework (including DORA since January 2025). AI Act duties do not replace that framework — they stack on top of it. If you use AI for creditworthiness assessment of natural persons, that use case is explicitly listed as high-risk in Annex III. The CSSF has been publicly active on AI in the financial sector for years, including thematic work on machine learning use by supervised entities — supervisory attention should be expected.
  • The CNPD. Most corporate AI use cases process personal data, so the GDPR — enforced in Luxembourg by the Commission nationale pour la protection des données — applies in parallel with the AI Act. A DPIA and an AI Act risk assessment will often cover overlapping ground; doing them together saves work.
  • National implementation. Member states must designate national authorities to supervise the Act. Luxembourg's implementation has been going through the legislative process; check the current state of designation with your counsel rather than assuming — but do not wait for it to be final before starting, because the deadlines above come from the Regulation itself and apply directly.

What to do now: three practical first steps

You do not need a transformation programme to get started. You need three things most companies can begin this quarter:

1. Build an AI inventory. You cannot classify what you have not listed. Record every AI system in use or planned — including the ones inside SaaS tools your teams already use, and the unofficial ChatGPT usage nobody put in a register. For each: what it does, who provides it, what data it touches, who is affected by its outputs.

2. Classify by risk. Map each system against the Act's categories: prohibited (stop immediately), high-risk (Annex III or product-embedded — the heavy obligations), limited-risk (transparency duties), minimal-risk (no specific obligations, but good governance still pays). Most companies discover that the bulk of their AI use is minimal-risk — and that one or two use cases, usually in HR or credit, need real attention.

3. Stand up lightweight governance. Someone accountable for AI (not a committee of everyone), a short internal policy on acceptable AI use, a defined intake path for new AI tools, and basic staff AI-literacy training — which has been a legal duty since February 2025, not a nice-to-have.

If you want help with exactly this exercise, this is what our AI Act Readiness Audit does: inventory, risk classification, and a prioritised remediation plan your DPO and board can work with.

The honest closing note

Two things are true at once. First: for most Luxembourg companies, AI Act compliance is genuinely manageable — an inventory, a classification, some governance, and provider due diligence cover the majority of cases. Second: the high-risk category is demanding, and if you are in it, August 2026 is close for the work involved. The companies that will have a calm 2026 are the ones that find out which of those two situations they are in now — not the ones with the biggest compliance budget.

And once more, clearly: this article is general information, not legal advice. For decisions about your specific obligations, involve qualified legal counsel.

Topics

  • EU AI Act
  • AI compliance
  • Luxembourg regulation
  • AI governance
  • Risk classification