Luxembourg - AI Act Implementation (Bill No. 8476)

Law of 20 December 2024 on implementing rules and penalties related to the EU Artificial Intelligence Act

Loi du 20 décembre 2024 sur les règles d'exécution et les sanctions liées au règlement européen sur l'intelligence artificielle

Luxembourg

RAI-LU-NA-2D2IRXX-2024
Effective: December 20, 2024
In Force(In Force)
ActGovernance and OversightConformity Assessment and RegistrationEnforcement and Penalties
Export PDF

This entry documents Luxembourg's national implementing measures referenced to the EU "AI Act" (Regulation (EU) 2024/1689). It is based on the government project (Bill No. 8476) submitted in December 2024 and related official materials; the Chamber dossier and national regulator pages set out designations, governance choices and the administrative sanctioning framework aligning with the EU Regulation.

Overview

Luxembourg's national implementing measures for the EU "AI Act" were packaged by government in a project of law (Bill No. 8476) submitted in late December 2024 to the Chamber of Deputies. The project completes the EU Regulation (Regulation (EU) 2024/1689) at national level by designating national competent authorities (market surveillance and notifying authorities), establishing a single point of contact and setting an administrative sanction regime consistent with the EU ceilings. The EU text itself is available at Regulation (EU) 2024/1689 (AI Act). The Luxembourg parliamentary dossier summarising the project is published on the Chamber's website at Chamber dossier on AI Act implementation (Bill 8476). National regulator guidance and thematic pages (notably from the CNPD) underpin the practical enforcement emphasis of the draft.

Definitions

Terminology in Luxembourg's implementing project follows the AI Act's definitions: "AI system", "provider", "deployers/operat ors", "high-risk AI system", "general-purpose AI model", "notifying authority", "market surveillance authority" and "notified body". The project clarifies that national legal terms (e.g., "authority protecting fundamental rights") shall be read consistently with the EU Regulation and relevant national statutes (e.g., law organizing the CNPD). Definitions for sectoral oversight are mapped to existing national supervisory functions (financial supervision, insurance supervision, health products agency, audiovisual regulator and accreditation bodies) to avoid normative gaps and fragmentation of enforcement.

Governance and Institutional Framework

Bill 8476 positions the Commission nationale pour la protection des données (CNPD) as the central coordinating authority and single point of contact for the AI Act in Luxembourg while stipulating sectoral market surveillance responsibilities for specialist regulators (e.g., CSSF for supervised financial firms, the CAA for insurance, the national medicines/health products agency for medical AI, and OLAS/ILNAS for accreditation and notified-body oversight). The draft establishes rules on cooperation, information exchange and shared investigations; it also gives the CNPD coordinating competence to notify the Commission under Article 70(2) of the AI Act. External coordination mechanisms with the EU AI Office and the European Artificial Intelligence Board are foreseen, and national regulatory sandboxes are mandated to foster innovation within safe, supervised experimental environments. Legal counsel and commentary from Luxembourg law firms summarise these designations and the cross-sector allocation of responsibilities in practice (see analyses cited below).

Key Focus Areas

The implementing project emphasises the following focal areas: (1) prohibition and enforcement for unacceptable-risk AI uses (per Article 5 AI Act), (2) robust governance and risk-management for high-risk AI systems (quality of training data, documentation and logs, human oversight, accuracy and robustness requirements), (3) conformity assessment and notification regimes for high-risk systems and the role of notified bodies, (4) registration obligations for high-risk systems to the EU database, (5) transparency obligations for certain AI systems and for general-purpose models, (6) rules on safety testing and adversarial evaluation where applicable, (7) obligations for incident reporting and post-market monitoring, (8) special rules for AI uses in fundamental-rights-sensitive domains (law enforcement, migration, employment, credit scoring, health), and (9) creation of administrative sanctions and remedial pathways. The draft maps many of these obligations onto existing Luxembourg supervisory frameworks so sectoral experience (for example, in financial supervision) is leveraged while avoiding duplication.

Implementation Framework

Implementation is planned in stages aligning with the AI Act calendar: early application of prohibition rules and basic transparency obligations; designation of authorities by 2 August 2025; progressive application of high-risk obligations and conformity assessment timelines by 2026–2027 as per the EU timetable. The draft requires designated notifying authorities to authorize and supervise conformity assessment bodies (notified bodies) and tasks market surveillance authorities with investigative powers — including sample testing, on-site inspections and (where necessary) access to model artefacts under safeguards. The framework includes obligations to establish sectorspecific sandboxes, guidance for SMEs, and measures to protect trade secrets while allowing effective supervision. Operators and providers must maintain technical documentation, risk assessments, logs and records to enable verifications by market surveillance authorities.

Monitoring and Evaluation

The draft law creates an administrative monitoring regime: market surveillance authorities will run proactive monitoring, reactive investigations (complaints, incidents) and publish periodic enforcement reports. It mandates inter-authority cooperation, reporting to the CNPD-coordinated single contact point, and data exchange with the EU AI Office and the European Artificial Intelligence Board. The CNPD pages provide thematic guidance on core topics (prohibited systems, data protection interactions and AI literacy obligations) and will be a public information channel for Luxembourg-regulated entities. Oversight includes publication of decisions (subject to confidentiality limits), and a statistical monitoring obligation designed to inform legislative and policy adjustments.

Penalties, Liability, and Appeals

Administrative penalties in the draft mirror the AI Act ceilings: (i) up to EUR 35 million or 7% of global annual turnover for prohibited AI practices; (ii) up to EUR 15 million or 3% for breaches of high-risk system obligations; (iii) up to EUR 7.5 million or 1% for providing incorrect or misleading information to authorities. The draft explicitly requires proportionality and special consideration for SMEs and startups. Affected parties can appeal administrative decisions to the Luxembourg administrative courts; the draft affirms judicial review and sets internal administrative reconsideration steps. The draft clarifies that sector-specific civil liability regimes (e.g., product liability for safety components) remain applicable and that the administrative fines do not exclude other legal remedies or criminal sanctions where national criminal law is engaged.

Relationship to Other Instruments

The Luxembourg implementing project is drafted to be complementary to: the EU AI Act (Regulation 2024/1689), the GDPR and national data protection law (the CNPD's enabling law), consumer protection rules, product safety laws, sectoral supervisory frameworks (financial supervision by the CSSF, insurance oversight by the CAA), medical device and medicines legislation (national medicines agency and EU MDR/IVDR intersection), and national administrative law governing sanctions and appeals. The project proposes targeted amendments to existing national statutes to align procedural powers, confidentiality rules, and notification requirements with the enforcement needs of the AI Act.

International Alignment

Luxembourg's approach is explicitly designed for consistency with EU-wide governance: designation of national authorities, coordination through the CNPD single point of contact, and cooperation with the EU AI Office and the European Artificial Intelligence Board are emphasised. The draft mirrors EU penalty ceilings and procedural safeguards to reduce regulatory fragmentation across the single market. It also signals cooperation with accreditation and standardisation bodies (ILNAS/OLAS) to ensure that conformity assessments and notified-body functions meet EU harmonised standards. Internationally, Luxembourg commits to reciprocal information exchange and participation in EU-level code-making for general-purpose AI models, aligning national enforcement with EU and EEA partners to prevent market fragmentation.

Implementation Timeline

EventDate/Deadline
EU AI Act - Signature (Council/EP)2024-06-13
EU AI Act - OJ Publication2024-07-12
EU AI Act - Entry into force2024-08-01
Unacceptable-risk prohibitions apply (EU)2025-02-02
Member States designate authorities (deadline)2025-08-02
Draft Bill 8476 submitted to Chamber (Luxembourg)2024-12-23 (Bill No. 8476)
Full application milestones (EU timetable)2026–2029 (phased)

Compliance Checklist

Operator / Provider ActionYes/No / Notes
Map AI systems and classify risk levelRequired
Implement governance & risk-management systemRequired for high-risk systems
Maintain technical documentation & logsRequired
Conformity assessment / notified body engagementRequired for many high-risk systems
Register high-risk systems in EU databaseRequired
Designate a person responsible for regulatory contactBest practice / often required
Prepare incident reporting & post-market monitoringRequired
Use national regulatory sandboxes where applicableEncouraged / mandated by draft

Sources and References

SourceType
Regulation (EU) 2024/1689 (Artificial Intelligence Act)Primary Source
Chamber of Deputies dossier — Project of law No. 8476 (Luxembourg)Primary Source
CNPD — AI thematic pages and guidancePrimary Source
Arendt – analysis of Luxembourg Bill No. 8476Secondary analysis
Plain English

Luxembourg's new national law establishes how the EU Artificial Intelligence Act will be enforced within the country, affecting any entity developing, deploying, or operating AI systems here. It designates national authorities, sets up a single point of contact, and defines administrative penalties, aligning with the broader EU framework.

The law applies to a wide range of AI system providers and deployers, including those creating "high-risk" AI systems or "general-purpose AI models." This includes companies in sectors already under specific supervision, such as financial services, insurance, and healthcare, where existing regulators like the Commission de Surveillance du Secteur Financier (CSSF) and the Commissariat aux Assurances (CAA) will also have AI Act oversight.

Key obligations under this law include: - A strict prohibition on AI systems deemed to pose an "unacceptable risk" to fundamental rights. - For "high-risk" AI systems, mandatory robust governance, risk management, data quality, human oversight, and accuracy requirements. - The need to perform conformity assessments, register high-risk systems in an EU database, and maintain detailed technical documentation and logs. - Transparency rules for certain AI systems and general-purpose AI models, alongside obligations for incident reporting and post-market monitoring.

While the Luxembourg law itself took effect on December 20, 2024, its core obligations will roll out in phases. Prohibitions on unacceptable-risk AI systems apply from February 2, 2025, with most high-risk system requirements, including conformity assessments, taking effect progressively from 2026-2027.

Non-compliance carries significant administrative penalties, mirroring EU ceilings. These can reach up to EUR 35 million or 7% of a company's global annual turnover for prohibited AI practices, and up to EUR 15 million or 3% for breaches related to high-risk systems. Authorities have broad investigative powers, including on-site inspections. A practical pitfall for businesses is navigating the enforcement landscape: while the Commission nationale pour la protection des données (CNPD) acts as the central coordinator, specific market surveillance responsibilities are split across various sectoral regulators, meaning companies might need to engage with multiple authorities depending on their AI system's application.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Luxembourg - AI Act Implementation (Bill No. 8476). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalArticle 5 AI ActFeb 2, 2025

    Applies to: Providers and deployers of AI systems.

    prohibition and enforcement for unacceptable-risk AI uses (per Article 5 AI Act)
  2. #2Critical

    Applies to: Providers and deployers of high-risk AI systems.

    robust governance and risk-management for high-risk AI systems
  3. #3Critical

    Applies to: Providers of high-risk AI systems.

    quality of training data
  4. #4Critical

    Applies to: Providers and deployers of high-risk AI systems.

    Operators and providers must maintain technical documentation, risk assessments, logs and records to enable verifications.
  5. #5Critical

    Applies to: Providers and deployers of high-risk AI systems.

    human oversight
  6. #6Critical

    Applies to: Providers of high-risk AI systems.

    accuracy and robustness requirements
  7. #7Critical

    Applies to: Providers of high-risk AI systems.

    Conformity assessment and notification regimes for high-risk systems
  8. #8Critical

    Applies to: Providers of high-risk AI systems.

    Registration obligations for high-risk systems to the EU database
  9. #9Critical

    Applies to: Providers of high-risk AI systems.

    obligations for incident reporting and post-market monitoring
  10. #10Important

    Applies to: Providers and deployers of certain AI systems and general-purpose models.

    Transparency obligations for certain AI systems and for general-purpose models
  11. #11Important

    Applies to: Providers of AI systems where applicable.

    rules on safety testing and adversarial evaluation where applicable
  12. #12Recommended

    Applies to: Luxembourg-regulated entities.

    The CNPD pages provide thematic guidance on core topics... and will be a public information channel for Luxembourg-regulated entities.
  13. #13Recommended

    Applies to: Providers and deployers of AI systems.

    national regulatory sandboxes are mandated to foster innovation within safe, supervised experimental environments.

© Regulations.AI — created on 13-Jun-2026