AI Act · Regulation (EU) 2024/1689
Compliant AI in Luxembourg: governance and the AI Act.
The European AI Act entered into force on 1 August 2024 and applies in stages until 2027. Every Luxembourg company that uses ChatGPT, Claude, Copilot or a proprietary AI system is affected. Fines of up to €35 million or 7% of worldwide turnover for prohibited practices.
Why get AI-compliant now?
Beyond the fines, this is a matter of management liability. If an AI system makes a biased decision (recruitment, credit, claims), the liability falls on the company that commissioned it, not on the model vendor. In Luxembourg, the financial sector (PSF, banks, funds) is particularly exposed: the CSSF is aligning its AI requirements with the AI Act from 2025.
Anticipating also protects your brand: a customer or a journalist discovering that you run AI in production without governance is a serious reputational risk.
Anticipating also protects your brand: a customer or a journalist discovering that you run AI in production without governance is a serious reputational risk.
What does the AI Act require for your use case?
Prohibited practices (Article 5): social scoring, behavioural manipulation, real-time biometric identification in publicly accessible spaces. Maximum penalty.
High-risk systems (Annex III): recruitment, credit, insurance, identity checks, medical systems. Obligations: CE marking, technical documentation, human oversight, log records, declaration of conformity.
Limited-risk systems (chatbots, deepfakes, AI-generated content): transparency obligation (users must know they are interacting with an AI).
Minimal-risk systems (recommendation, games, spam filtering): no specific obligation, but a code of conduct is recommended.
High-risk systems (Annex III): recruitment, credit, insurance, identity checks, medical systems. Obligations: CE marking, technical documentation, human oversight, log records, declaration of conformity.
Limited-risk systems (chatbots, deepfakes, AI-generated content): transparency obligation (users must know they are interacting with an AI).
Minimal-risk systems (recommendation, games, spam filtering): no specific obligation, but a code of conduct is recommended.
How does Luxgap make your AI compliant?
Three pragmatic steps:
1. AI Act scoping: inventory of your AI systems (including SaaS tools), risk classification under Annex III, gap analysis against the AI Act, prioritised compliance plan.
2. AI governance: internal usage policy, monthly AI committee, assessment process for new use cases, user charter, staff training.
3. Secure roll-out: Claude/ChatGPT/Copilot integration with GDPR controls (anonymisation, sensitive data), enterprise APIs (no leakage to public models), usage monitoring.
We work with publicly available technologies (Anthropic's Claude API, OpenAI's ChatGPT Enterprise). No licence to buy from us, just the scoping expertise.
1. AI Act scoping: inventory of your AI systems (including SaaS tools), risk classification under Annex III, gap analysis against the AI Act, prioritised compliance plan.
2. AI governance: internal usage policy, monthly AI committee, assessment process for new use cases, user charter, staff training.
3. Secure roll-out: Claude/ChatGPT/Copilot integration with GDPR controls (anonymisation, sensitive data), enterprise APIs (no leakage to public models), usage monitoring.
We work with publicly available technologies (Anthropic's Claude API, OpenAI's ChatGPT Enterprise). No licence to buy from us, just the scoping expertise.
How is an AI compliance engagement structured?
One-off AI Act audit: mapping + classification + action plan, delivered within 3 weeks.
Annual AI governance mandate: AI committee, policy updates, ongoing training, regulatory watch.
Dedicated AI proof of concept on the client's infrastructure: 4 to 8 weeks depending on the use case. All our PoCs comply with the AI Act and the GDPR by design.
Quote-based pricing, calibrated to the number of AI systems to map and your regulatory exposure. Contact us →
Annual AI governance mandate: AI committee, policy updates, ongoing training, regulatory watch.
Dedicated AI proof of concept on the client's infrastructure: 4 to 8 weeks depending on the use case. All our PoCs comply with the AI Act and the GDPR by design.
Quote-based pricing, calibrated to the number of AI systems to map and your regulatory exposure. Contact us →
Let's talk about your situation.
Reply within 24 business hours. No commitment, no sales pressure.