EU AI Act · Luxembourg

Get AI Act–ready without the big-firm price tag

The EU AI Act is here, and most of the noise around it is aimed at large enterprises. If you run a small business, an NGO, or an independent practice using AI in Luxembourg, the obligations that actually apply to you are narrower than the headlines suggest — but some are live right now, and they are easy to miss. We help you find out exactly which rules touch your work, get compliant on the ones that do, and skip the ones that don't.

Take the 2-minute readiness check Or book a call

The honest version of the timeline

You may have read that "the EU delayed the AI Act." That is half true, and the half that is wrong could cost you.

In mid-2026 the EU agreed the Digital Omnibus on AI, which pushes back the heaviest obligations — the ones for so-called high-risk systems. Those are set to apply from December 2027 (standalone systems) and August 2028 (AI built into regulated products). For most small organisations, those rules were never the main concern anyway.

What did not move is the part most likely to apply to you:

  • Transparency obligations — telling people when they are dealing with an AI system (not only a chatbot, but any AI that interacts with them — a voice assistant, an automated reply tool), and when content is AI-generated — apply from 2 August 2026.
  • AI literacy — making sure the people using AI on your behalf actually understand it — has been an expectation since February 2025.

So the scary deadlines got breathing room. The everyday ones are already here. That is the gap we help you close. If you are still getting oriented on the bigger picture, start with the guide to AI in Luxembourg.

Who this is for

You run a small business, a non-profit, or an independent practice, and somewhere in your work there is AI: a chatbot on your website, AI-drafted content, an AI tool in your hiring, a team quietly using ChatGPT or Copilot. You don't have a legal department. You don't need one — you need someone who can tell you, plainly, what applies and what to do about it.

That is the whole job. No 60-page memo you can't act on. A clear picture, and the practical work to get you there.

The 2-minute readiness check

Answer a handful of questions about how you use AI. Each one tells you straight away — in plain language — whether that obligation touches you, how urgent it is, and where we can help. Nothing is stored or sent anywhere — it runs entirely in your browser.

1.Does a chatbot, voice assistant, or other AI system interact directly with your customers on your site or channels?
2.Do you publish AI-generated or AI-edited images, audio, or video that show real people, places, or events?
3.Do you use AI to screen, rank, recommend, evaluate, or decide about people — hiring, staff, eligibility, or access to a service?
4.Does anyone on your team use AI tools in their work?
5.Do you use AI that detects emotions or categorises people by biometric data?

What actually applies — by how you use AI

Rather than reciting the regulation, here is where the common cases land.

You run any AI that interacts with your customers — a chatbot, a voice assistant, an auto-reply tool

This rule is not limited to chatbots — it covers any AI that talks to people on your behalf. They must be told they are interacting with AI, not a human, from the first exchange. If you built the system yourself, that obligation is yours. Live from August 2026. Usually a small, quick fix — but it does have to be done.

You publish AI-generated or AI-edited images, audio, or video

If the content is a realistic depiction of real people, places, or events that could be mistaken for authentic (a "deepfake"), you have to disclose that it is AI-generated. Generic illustrations and clearly artistic images don't count. Live from August 2026.

You use AI to rank, recommend, or decide about people

Screening job applicants, ranking or recommending who to shortlist, evaluating staff, scoring eligibility, allocating access to a service — this is "high-risk" territory, and it catches recommendation and scoring engines, not just final decisions. The formal obligations don't bite until December 2027, but the hard part (documentation, oversight, knowing exactly what your tool does) takes real time to build. This is the one to start early rather than late.

Your team uses AI tools in their work

You are expected to make sure they have a basic, appropriate level of AI literacy for what they do. Low-cost to satisfy, and genuinely useful to your organisation regardless of the rule. A short internal policy and some training usually covers it.

None of the above sounds like you

Then you may have very little to do — and knowing that, with confidence, is worth something too. The readiness check above will tell you.

How we work with you

Three ways in, depending on where you are.

AI Inventory & Scoping

Fixed fee · the starting point

We find every place AI shows up in your work — the obvious tools and the quiet ones — classify each against the AI Act, and produce a clear register: what you use, what role you are in, which obligations apply, and by when. Many clients find this is most of what they needed.

Readiness Implementation

Scoped per engagement · the doing

Setting up the transparency notices and content labelling, drafting your AI-use policy and governance documentation, and running a short AI-literacy session for your team. Practical, done-with-you work that leaves you actually compliant, not just informed.

Ongoing Governance

Retainer · kept current

For organisations that want it kept current. We keep your AI register live as you adopt new tools, track the deadlines and standards as they land, and re-map your position onto Luxembourg's supervisory framework as it is finalised — so you are never scrambling before a deadline.

What this is — and what it isn't

We do AI implementation and governance, not law, and we keep that line clear because it protects you.

We do the practical, technical, and organisational work: scoping, classification, documentation, transparency setup, policy, training, architecture. For formal legal opinions — a contested high-risk classification, liability questions, anything that needs a lawyer's sign-off — we work alongside your legal adviser or refer you to one. You get hands-on readiness from us and proper legal cover where it is genuinely needed, without paying legal rates for work that isn't legal.

Based in Luxembourg. Working in English and French. Rooted in EU data sovereignty and GDPR-by-design — the same principles that run through everything else we do.

AI Act in Luxembourg — common questions

Does the EU AI Act apply to small businesses and NGOs in Luxembourg?

Yes, but far more narrowly than the headlines suggest. If you use any customer-facing AI (a chatbot, a voice assistant, an automated reply tool), use AI to rank or recommend decisions about people, publish AI-generated media, or your team uses AI tools, some obligations already apply — most large-enterprise rules do not.

The AI Act applies across the EU, including Luxembourg, regardless of your size. What changes with size is which obligations bite. For most small organisations the live concerns are the transparency rules (telling people they are talking to AI, labelling realistic AI-generated media) and AI literacy (making sure staff using AI understand it). The heavy "high-risk" obligations were deferred to December 2027 by the Digital Omnibus and, in any case, rarely apply to a small business or non-profit. The readiness check on this page tells you which of these touch your specific situation.

Who enforces the AI Act in Luxembourg?

The CNPD (Commission nationale pour la protection des données) is set to become Luxembourg's default national supervisory authority for the AI Act under a bill still before Parliament, with sectoral regulators overseeing AI within their existing remits.

Under draft Bill n°8476 — filed in December 2024 and still going through Parliament — Luxembourg would designate the CNPD, the same authority that supervises GDPR, as the primary market surveillance authority for the AI Act where no sectoral regulator already applies. Banking, insurance, and medicines regulators would keep oversight of AI used within their domains. The CNPD is also standing up an AI regulatory sandbox. This overlap with GDPR is one reason a data-protection-by-design approach carries directly into AI Act readiness.

Has the AI Act been delayed? What changed with the Digital Omnibus?

Partly. The Digital Omnibus, agreed in mid-2026, pushes high-risk obligations to December 2027 (and August 2028 for AI in regulated products). The transparency rules and AI literacy duty were not delayed.

It is a common and costly misreading to hear "the AI Act was delayed" and assume nothing applies yet. The deferral covers high-risk systems — the part least likely to affect a small organisation. The Article 50 transparency obligations remain live from 2 August 2026, and the Article 4 AI literacy expectation has applied since February 2025. So the scary deadlines got breathing room; the everyday ones are already here.

Do I need to label my website chatbot or AI-generated content?

If a chatbot talks to your customers, yes — people must be told they are interacting with AI from the first message, live from August 2026. Realistic AI-generated media of real people or events must also be labelled. Generic illustrations do not.

The chatbot disclosure (Article 50(1)) is usually a small, quick fix, and if you built or configured the assistant yourself the obligation sits with you, not just the vendor. The synthetic-media rule (Article 50(4)) applies to "deepfake"-style content — realistic depictions that could be mistaken for authentic. Clearly artistic or obviously generated illustrations are out of scope. Setting up compliant notices and a labelling approach is exactly the kind of practical work covered by a readiness engagement.

Are you a law firm? Is this legal advice?

No. We do AI implementation and governance, not law. We handle the practical scoping, classification, documentation, transparency setup, policy, and training — and work alongside your legal adviser for anything that needs a formal legal opinion.

Keeping that line clear protects you. You get hands-on readiness from us and proper legal cover where it is genuinely needed — a contested high-risk classification, liability questions, formal sign-off — without paying legal rates for work that is technical and organisational rather than legal. Based in Luxembourg, working in English and French, rooted in EU data sovereignty and GDPR-by-design.

Sources

The rules referenced here come from primary EU and Luxembourg sources:

  • AI ActRegulation (EU) 2024/1689 (EUR-Lex)
  • Digital Omnibus on AI — the simplification package deferring high-risk obligations, agreed by the Parliament (16 June 2026) and Council (29 June 2026), taking legal effect on publication in the Official Journal
  • Luxembourg implementationdraft Bill n°8476, which would designate the CNPD as the default national supervisory authority

Regulatory content last reviewed 9 July 2026. This page is practical guidance, not legal advice.

Not sure where you stand? Let's find out together.

A free 20-minute call — no commitment, no jargon, just an honest conversation about which AI Act obligations touch your work.

Book a call