Recital 91
Artificial Intelligence Act · UE 2024/1689
| (91) | Given the nature of AI systems and the risks to safety and fundamental rights possibly associated with their use, including as regards the need to ensure proper monitoring of the performance of an AI system in a real-life setting, it is appropriate to set specific responsibilities for deployers. Deployers should in particular take appropriate technical and organisational measures to ensure they use high-risk AI systems in accordance with the instructions of use and certain other obligations should be provided for with regard to monitoring of the functioning of the AI systems and with regard to record-keeping, as appropriate. Furthermore, deployers should ensure that the persons assigned to implement the instructions for use and human oversight as set out in this Regulation have the necessary competence, in particular an adequate level of AI literacy, training and authority to properly fulfil those tasks. Those obligations should be without prejudice to other deployer obligations in relation to high-risk AI systems under Union or national law. |
In Luxembourg, the AI market surveillance authority is not yet formally designated, but the CNPD remains competent for the personal data dimension of AI systems, and the CSSF intervenes whenever a deployer is a regulated financial entity (stacking AI Act + DORA + CSSF circular 22/806 on ICT outsourcing). For health and public sectors, ILR and HCPN watch the AI Act + NIS 2 overlap closely.
Luxgap practice: we recommend formally appointing an AI deployer officer separate from the DPO, with a written mission letter explicitly mentioning the authority to override algorithmic recommendations, a document the CNPD has been systematically requesting during inspections since 2024.