The EU AI Act in Luxembourg

How Regulation (EU) 2024/1689 applies in Luxembourg, and the 5 AI instruments Luxembourg has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Luxembourg’s own AI instruments

5 records tracked for Luxembourg, beyond the EU-level Act above.

National authority in Luxembourg

Named in Luxembourg’s own records, not inferred.

Per Luxembourg - AI in Schools Guidelines

Per Luxembourg - National AI Strategy (2025)

Per Luxembourg - National Data Strategy

Per Luxembourg - AI Act Implementation (Bill No. 8476)

Per Luxembourg - AI Strategic Vision

Penalties in Luxembourg

As stated in Luxembourg’s own records.

Per Luxembourg - AI in Schools Guidelines

  • Internal disciplinary measures for breaches of school academic-integrity policies (e.g., warnings, grade sanctions) as specified in local guidance.
  • Administrative referral to national authorities for statutory breaches (data protection violations to CNPD; possible sanctions under the AI Act / RIA where applicable).
  • Potential delisting of non-compliant tools from the KI Kompass validation registry and removal from the national platform.
  • Contractual remedies against third-party providers in procurement (penalties, termination, liability claims) for breaches of SLAs or data-handling obligations.

Per Luxembourg - National AI Strategy (2025)

  • The strategy itself does not create new criminal sanctions; enforcement will use existing national laws and EU measures (notably the GDPR and the EU AI Act when applicable).
  • Administrative sanctions and orders (e.g., remediation requirements) applied by competent authorities such as the CNPD for data protection breaches.
  • Exclusion from public procurement opportunities and suspension of contracts for non-compliant AI suppliers.
  • Mandatory withdrawal or suspension of non-compliant high-risk systems pending remediation where legal frameworks permit.
  • Reputational and market measures including public disclosure of compliance failures where permitted by law.

Per Luxembourg - National Data Strategy

  • GDPR administrative fines for personal data breaches (applied by CNPD where applicable)
  • Administrative sanctions to be defined in implementing regulations for breaches of access protocols or misuse of secure processing environments
  • Contractual remedies and liquidated damages for failure to comply with Data Factory participation agreements
  • Removal or suspension of access to national data services in case of non-compliance or security incidents

Per Luxembourg - AI Act Implementation (Bill No. 8476)

  • Fines up to EUR 35,000,000 or 7% of total worldwide annual turnover for infringements relating to prohibited AI practices.
  • Fines up to EUR 15,000,000 or 3% of total worldwide annual turnover for breaches of high-risk obligations.
  • Fines up to EUR 7,500,000 or 1% of total worldwide annual turnover for providing incorrect or misleading information to authorities.
  • Proportionality safeguards and special caps/exemptions for SMEs and start-ups as foreseen in national implementing measures.
  • Publication of sanctions decisions and remedial orders; powers to issue warnings, corrective measures, and temporary market restrictions.
  • Sanctions do not exclude civil liability or other national criminal sanctions where applicable.

Per Luxembourg - AI Strategic Vision

  • The strategy itself contains no statutory penalties; it is non-binding guidance.
  • Compliance expectations are enforced via existing sectoral laws (e.g., GDPR) which carry statutory penalties for data protection breaches.
  • Future sectoral regulation (including anticipated EU-level rules such as the EU AI Act) may introduce mandatory obligations, conformity assessment requirements and penalties.

Luxembourg overview

The full picture of AI regulation in Luxembourg, beyond just the EU AI Act.

Luxembourg AI regulation overview →