KC
Katia Ciesielska
INDEPENDENT DIRECTOR & CONSULTANT
DISCUSS A MANDATE

BOARDROOM INSIGHT

The EU AI Act After 2 August 2026: What Luxembourg Boards Should Check Now

In short: From 2 August 2026, the EU AI Act’s transparency obligations under Article 50 apply, and the European Commission’s AI Office and national authorities can enforce them. The high-risk rules have moved to December 2027 and August 2028. For Luxembourg boards, the immediate question is whether the organisation knows where AI is being used — including at its delegates — and can show that the controls are working.

2 August 2026 was an important date for Luxembourg boards and for every organisation caught by the EU AI Act. New transparency obligations became applicable, and the European Commission’s AI Office and national authorities moved into the enforcement phase.

For organisations, this is no longer only a matter of preparing for legislation that will apply at some point in the future. Certain requirements are now in force.

For boards, the immediate question is practical: do we know where AI is being used in our organisation, and can we demonstrate that the appropriate controls are actually working?

What changed on 2 August 2026?

Article 50 of the EU AI Act now requires greater transparency around certain AI systems and AI-generated content. People should know when they are interacting with an AI system, when content has been generated or materially manipulated by AI, and when technologies such as emotion recognition or biometric categorisation are being used.

The rules apply differently depending on whether an organisation is acting as a provider of an AI system or as a deployer using a system supplied by someone else. This distinction is important because most Luxembourg organisations will be deployers rather than developers of AI.

Using a third-party tool does not remove the need for oversight.

The Commission published its guidelines on the transparency of AI-generated content under Article 50 on 20 July 2026. Boards should expect management to be working from those guidelines rather than from a general understanding of the Act.

When people interact with AI

Providers of interactive AI systems must ensure that individuals are informed when they are dealing with AI rather than a human, unless this is already obvious.

The most familiar example is a chatbot. But the obligation may also be relevant to virtual assistants used in customer service, employee support, client onboarding, complaints handling, recruitment, website enquiries and internal help desks — the places where an AI layer is often added to an existing process without anyone treating it as an AI deployment.

For a board, the question should not simply be whether the organisation uses a chatbot. It should be whether all AI-enabled interactions have been identified and whether the disclosure is clear enough for the person using the service.

A vague reference hidden in general terms and conditions may not provide the level of transparency expected in practice.

AI-generated content must be identifiable

Providers of generative AI systems must enable certain AI-generated or manipulated content to be detected in a machine-readable format. This applies to synthetic text, images, audio and video, subject to specific exceptions — for example, where AI is performing a standard editing function or does not substantially change the input or its meaning.

There is a timing point here that is easy to miss. For generative systems that were already on the market before 2 August 2026, the machine-readable marking obligation in Article 50(2) applies from 2 December 2026. Since most organisations are using tools that were in service well before August, this transition will often be the date that actually matters. It is a short reprieve, not an exemption, and it does not delay the disclosure obligations that fall on deployers.

Most Luxembourg boards will not need to supervise the technical design of generative AI models. They should, however, understand whether the tools used by their organisation support the required marking and whether procurement teams are checking this before entering into or renewing contracts.

This is particularly relevant where AI is used to produce marketing materials, client communications, training content, research publications, public reports, voice recordings, images, video and social-media content.

The fact that content looks professional does not answer the regulatory question of whether its AI origin must be detectable or disclosed.

Deepfakes must be disclosed

The EU AI Act requires deployers to disclose when image, audio or video content constituting a deepfake has been artificially generated or manipulated.

The term “deepfake” may suggest fraud or political misinformation. In business, however, the issue can arise in entirely legitimate settings. An organisation might use AI to create:

  • an avatar delivering an internal training session;
  • a translated video in which a speaker’s voice or lip movements are altered;
  • a synthetic voice-over;
  • a digitally recreated person;
  • a realistic promotional image; or
  • a video that materially changes an actual event.

These applications are not prohibited. But the audience may need to be told that what they are seeing or hearing has been generated or altered by AI.

This is an area in which marketing teams can move faster than internal governance. Boards should therefore be satisfied that approval processes cover synthetic media and not only traditional advertising or communications risks.

Public-interest content may also require disclosure

Where AI is used to generate or manipulate text published to inform the public on matters of public interest, the content must generally be disclosed as AI-generated.

There is an important exception where the content has undergone human review or editorial control and a person or organisation assumes editorial responsibility for it. That exception carries more weight than it is often given. Asking someone to glance at AI-generated text before publication is not meaningful editorial review. The reviewer should understand the subject, verify material statements and be prepared to take responsibility for the final content.

For regulated firms, asset managers and fund service providers, this may be relevant to publications concerning financial markets, investment products, sustainability, governance or regulatory matters. It may also be relevant to board-approved statements and reports.

I would add one item that sits closer to home than most directors expect: board minutes. AI-assisted drafting and transcription tools are now routinely used in and around the boardroom, and I co-authored the ILA’s guidance on new technologies for board minutes precisely because the governance questions are not obvious. Who reviewed the output. Whether the reviewer had the standing to correct it. Whether the record the board approves is genuinely the board’s own. The transparency rules give those questions a regulatory edge they did not previously have.

Emotion recognition and biometric categorisation

Organisations deploying certain emotion-recognition or biometric-categorisation systems must inform the individuals exposed to them.

These tools are not yet common in many Luxembourg boardrooms, but they turn up in ordinary products — in recruitment interviews, employee monitoring, customer behaviour analysis, security and fraud detection, access control, and the assessment of participants during online meetings or training.

A director may be told that a system merely measures engagement or improves security. That description is not sufficient. The organisation needs to understand what the system is actually analysing and how the AI Act, data-protection rules and employment law may apply.

The Luxembourg question: where does the AI actually sit?

For a Luxembourg fund board, the most important point about the AI Act is that most of the AI in scope is not in your organisation at all. It is at your delegates.

The AIFM or management company, the central administrator, the transfer agent, the depositary, the AML screening and transaction-monitoring vendor, the data provider — this is where AI is being introduced, usually as a feature of an existing service rather than as a new one. The fund itself may have no employees and no systems, and still be exposed through every one of those relationships.

That places AI squarely inside frameworks Luxembourg boards already run. Delegation and ongoing oversight of delegates. The outsourcing requirements the CSSF already expects boards to supervise. The ICT third-party arrangements captured under DORA. AML/CFT effectiveness, where a screening tool’s behaviour is the RC’s and the RR’s problem long before it is an AI Act problem.

In my experience, this is the practical gap. AI appears in board packs as an innovation topic or an efficiency story, and rarely in the section where the board reviews its service providers — which is where the exposure actually is. A board that asks its administrator and its AIFM directly what AI is embedded in the services being delivered, and how the AI Act obligations are being allocated between the parties, will learn more in one meeting than from any internal AI policy.

Enforcement has started

From 2 August 2026, the European Commission’s AI Office and competent national authorities began exercising enforcement powers under the AI Act.

Breaches of the transparency obligations can result in fines of up to EUR 15 million or 3% of total worldwide annual turnover, with proportionality considerations applying to smaller organisations.

The fine should not be the board’s only concern. Poor AI governance can also expose an organisation to misleading communications, client complaints, data-protection breaches, intellectual-property disputes, discrimination claims, cybersecurity incidents, unreliable decisions and reputational damage.

In my view, the main risk for many organisations is not the deliberate misuse of sophisticated AI. It is the uncontrolled use of ordinary tools across the business without a reliable inventory, clear ownership or consistent review.

What about high-risk AI systems?

Not all AI Act requirements became applicable on 2 August 2026.

The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July — extended the application dates for high-risk AI systems.

The rules for stand-alone high-risk systems listed in Annex III now apply from 2 December 2027. Requirements for high-risk AI embedded in certain regulated products under Annex I apply from 2 August 2028.

These extensions provide additional preparation time. They are not permission to do nothing until 2027 or 2028.

An organisation first needs to determine whether any of its use cases could fall within a high-risk category. It may then need to obtain documentation from vendors, change procurement arrangements, introduce human-oversight procedures, establish logging and monitoring, train staff and allocate responsibility. That work is unlikely to be completed effectively at the last minute.

A board checklist for August 2026

By now, I would expect a well-governed organisation to have moved beyond a general statement that it is “looking into AI.” The level of detail will depend on the organisation’s size, activities and risk exposure. At a minimum, the board should be able to obtain clear answers to the following.

1. Do we know which AI systems we use?

The inventory should include not only major systems purchased by the organisation but also AI functions embedded in existing software, and AI embedded in services delivered by delegates and outsourced providers.

It should cover approved tools, pilot projects and material employee use of publicly available generative AI.

Without an inventory, it is difficult to classify the systems, assess the risks or determine which obligations apply.

2. Do we understand our legal role?

The organisation should know whether it acts as a provider, deployer, importer or distributor in relation to each material AI system.

An organisation that modifies a system significantly or makes it available under its own name may assume responsibilities it did not initially expect.

3. Have we identified the Article 50 use cases?

The inventory should flag systems involving:

  • direct interaction with individuals;
  • synthetic content;
  • deepfakes;
  • public-interest publications;
  • emotion recognition; and
  • biometric categorisation.

The relevant disclosures and technical measures should then be tested, not merely described in a policy.

4. Is someone clearly accountable?

AI governance often sits across IT, legal, compliance, risk, data protection, procurement, human resources and the business. That is understandable, but shared involvement should not result in unclear ownership.

The board should know who maintains the AI inventory, who approves higher-risk use cases, who monitors regulatory developments and who reports incidents or exceptions.

5. Are vendor assurances being checked?

Many organisations depend heavily on third-party AI providers. Contracts and due-diligence processes should address, where relevant:

  • the provider’s role under the AI Act;
  • system documentation;
  • transparency functionality;
  • data use;
  • intellectual property;
  • information security;
  • audit and access rights;
  • incident notification;
  • subcontractors; and
  • support with regulatory enquiries.

Relying on the reputation of a large technology company is not a governance control.

6. Is human review genuine?

Human oversight should be designed around the particular use case. A person reviewing an AI-generated output must have the knowledge, authority and time to challenge it, and should understand that automation can create a false sense of accuracy.

This matters most where AI supports recruitment, client decisions, risk assessments, compliance reviews or public communications.

A practical agenda item for the next board meeting

AI governance does not require a lengthy technical presentation. A useful board update could begin with five items:

  • the organisation’s principal AI use cases, including those at its delegates;
  • the systems caught by the new transparency obligations;
  • the controls already implemented;
  • any gaps, incidents or unapproved use; and
  • the work planned before the next AI Act deadlines.

The board does not need to operate the technology. It should, however, be able to challenge whether management understands the organisation’s exposure and whether there is evidence behind the assurances being given.

The real change after 2 August 2026

The significance of 2 August is not that every provision of the EU AI Act now applies. It does not.

The real change is that the implementation debate has moved into a more concrete phase. Transparency requirements are applicable, enforcement has begun, and organisations should be able to show what they have done.

For Luxembourg boards, particularly in regulated financial services, AI should now form part of normal governance discussions. It belongs alongside data protection, outsourcing, cybersecurity, conduct risk and operational resilience, and not in a separate innovation project with no clear connection to the organisation’s risk framework.

The objective is not to slow down responsible use of AI. It is to ensure that the organisation knows where AI is being used, understands the consequences and can stand behind the way it is deployed.

That is increasingly the standard boards will be expected to meet.

Frequently asked questions

Does the EU AI Act apply to Luxembourg fund boards?

Yes. The AI Act applies across the EU, and a Luxembourg fund or management company will usually be a deployer of AI systems rather than a provider. Even where a fund has no employees and no systems of its own, it can be exposed through its AIFM, central administrator, transfer agent and AML screening providers, which brings AI within the board’s existing delegation and outsourcing oversight.

What changed on 2 August 2026?

The transparency obligations in Article 50 of the EU AI Act became applicable, covering disclosure when people interact with AI, marking of AI-generated content, disclosure of deepfakes, disclosure of AI-generated public-interest text, and notification where emotion-recognition or biometric-categorisation systems are used. The Commission’s AI Office and national authorities also began exercising enforcement powers.

Have the high-risk AI rules been delayed?

Yes, in part. Under the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force from 27 July 2026, obligations for stand-alone high-risk systems listed in Annex III apply from 2 December 2027, and obligations for high-risk AI embedded in regulated products under Annex I apply from 2 August 2028. The Article 50 transparency obligations were not postponed.

When does the AI content-marking obligation apply?

Article 50 applies from 2 August 2026. For generative AI systems that were already on the market before that date, the machine-readable marking obligation in Article 50(2) applies from 2 December 2026.

What are the penalties for breaching the AI Act transparency rules?

Breaches of the transparency obligations can attract fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher, with proportionality considerations applying to smaller organisations.

What should a Luxembourg board have in place now?

An inventory of AI systems used directly and by delegates, clarity on whether the organisation is a provider or a deployer of each system, identification of Article 50 use cases, a named owner for AI governance, vendor due diligence that addresses AI Act allocation of responsibility, and human review arrangements that are genuine rather than nominal.

This article is provided for general information and does not constitute legal advice.

Katia Ciesielska is a Luxembourg independent non-executive director serving on the boards of regulated funds and corporate structures across approximately 15 sponsor and family-office groups. She is a board member of the Luxembourg Institute of Governance (ILA) and co-author of the ILA’s “AI in the Boardroom: Opportunities, Risk and Board Oversight” and “New Technologies for Board Minutes.”

Scroll to Top