Advisory · AI Act + AI agents

AI Act and GDPR compliant. On-premise or public GPAI, you choose.

Our edge: we deploy enterprise AI that's actually compliant. For regulated sectors, public bodies and anyone who wants no external source: on-premise AI, disconnected from the Internet. For those who want the best tool right now: public GPAI (Claude, ChatGPT, Copilot) scoped on your internal policies. And behind every deployment, our three teams: lawyers, cyber engineers, developers.

Our edge

Two deployment modes, based on your level of criticality.

The right technical trade-off starts with the criticality of your data and the sector you operate in. We do both, fully.

On-premise AI, disconnected from the Internet

For regulated sectors and institutions

We install a production-grade open-source AI on a dedicated server at your site. No data leaves your infrastructure. No API calls to the outside. Suitable for banks under DORA, hospitals, defence, governments, municipalities, legal sector, and any client whose data cannot be sent to an external cloud provider.

  • Full data sovereignty
  • AI Act and GDPR compliant by design
  • Reproducible audit (versioned models)

Scoped public GPAI

For the best tool, right now

Public models (Claude, ChatGPT Enterprise, Copilot) are today the most powerful available. For organisations that can use them legally and technically, we deploy them in enterprise mode with solid governance: compliant DPA contracts, data classification, logging, team training. You get the cutting edge without the shadow IT risks.

  • Today's most powerful models
  • GDPR and AI Act framework respected
  • Faster and cheaper to roll out
Nobody else combines the three

Enterprise AI requires three skill sets, at the same time.

A law firm does the AI Act analysis but cannot deploy. A tech integrator installs the AI but ignores legal obligations. A cyber consultant secures it but does not touch code or law. Luxgap mobilises all three teams in parallel on the same AI project. That's the difference between a compliant AI deployment and a marketing rollout that fails the first audit.

Lawyers, AI Act and GDPR

Inventory of AI systems, risk classification, transparency duties, DPIAs for high-risk processing. Drafting of vendor contracts, internal AI usage charter.

Cybersecurity engineers

Infrastructure hardening (dedicated on-premise server, segmentation, access), monitoring, model governance, AI incident response, ISO 27001 compliance of the deployment.

Developers, custom AI agents

Development of specialised AI agents (KYC, log analysis, security monitoring, file cleansing, quality control). Integration with your existing IT. Full POC on dedicated server before any commitment.

Our method

How we work, step by step.

01

AI Act scoping

We inventory the AI systems already in use in your organisation (officially or not), classify them by risk level under the AI Act, and build a realistic compliance plan. Driven by our legal team in coordination with your DPO.

02

Identifying automatable tasks

Workshops with your business teams to spot repetitive, time-consuming tasks where an AI agent can offload humans. Prioritisation by hours saved and technical feasibility.

03

POC on dedicated server

For the priority case, we install a high-performance dedicated server at your premises (or use a public GPAI based on your trade-off). We configure the agent on your real situation, show you results on actual data. You validate before any long-term commitment.

04

Training and governance

Once the agent is in production, we train your teams to oversee it: reading the outputs, escalation when an anomaly appears, documented governance for AI Act audits, performance tracking.

Sample agents

Specialised AI agents, not generic chatbots.

Automated KYC

Identity verification, document consistency checks, forged document detection, risk scoring. For banks, trustees, fund administrators.

Security monitoring

Alert correlation, anomalous behaviour detection, automatic incident classification. Runs continuously, feeds our SOC.

Log analysis

Reading millions of application or system log lines, weak signal identification, daily summary reports.

Legacy file cleansing

Automatic classification of legacy documents (GDPR, retention duration, sensitivity), compliant deletion and documented legal archiving.

For your employees, a ready-to-use AI assistant scoped on your internal policies: luxapps.lu (a Luxgap group company)

Run an AI POC at your site, with no long-term commitment.

We bring the server, configure the agent, show you the results. Tailored quote within one business day.

Build my quote →