The EU AI Act After 2 August 2026: What Luxembourg Boards Should Check Now
In short: From 2 August 2026, the EU AI Act’s transparency obligations under Article 50 apply, and the European Commission’s AI Office and national authorities can enforce them. The high-risk rules have moved to December 2027 and August 2028. For Luxembourg boards, the immediate question is whether the organisation knows where AI is being used — including at its delegates — and can show that the controls are working. 2 August 2026 was an important date for Luxembourg boards and for every organisation caught by the EU AI Act. New transparency obligations became applicable, and the European Commission’s AI Office and national authorities moved into the enforcement phase. For organisations, this is no longer only a matter of preparing for legislation that will apply at some point in the future. Certain requirements are now in force. For boards, the immediate question is practical: do we know where AI is being used in our organisation, and can we demonstrate that the appropriate controls are actually working? What changed on 2 August 2026? Article 50 of the EU AI Act now requires greater transparency around certain AI systems and AI-generated content. People should know when they are interacting with an AI system, when content has been generated or materially manipulated by AI, and when technologies such as emotion recognition or biometric categorisation are being used. The rules apply differently depending on whether an organisation is acting as a provider of an AI system or as a deployer using a system supplied by someone else. This distinction is important because most Luxembourg organisations will be deployers rather than developers of AI. Using a third-party tool does not remove the need for oversight. The Commission published its guidelines on the transparency of AI-generated content under Article 50 on 20 July 2026. Boards should expect management to be working from those guidelines rather than from a general understanding of the Act. When people interact with AI Providers of interactive AI systems must ensure that individuals are informed when they are dealing with AI rather than a human, unless this is already obvious. The most familiar example is a chatbot. But the obligation may also be relevant to virtual assistants used in customer service, employee support, client onboarding, complaints handling, recruitment, website enquiries and internal help desks — the places where an AI layer is often added to an existing process without anyone treating it as an AI deployment. For a board, the question should not simply be whether the organisation uses a chatbot. It should be whether all AI-enabled interactions have been identified and whether the disclosure is clear enough for the person using the service. A vague reference hidden in general terms and conditions may not provide the level of transparency expected in practice. AI-generated content must be identifiable Providers of generative AI systems must enable certain AI-generated or manipulated content to be detected in a machine-readable format. This applies to synthetic text, images, audio and video, subject to specific exceptions — for example, where AI is performing a standard editing function or does not substantially change the input or its meaning. There is a timing point here that is easy to miss. For generative systems that were already on the market before 2 August 2026, the machine-readable marking obligation in Article 50(2) applies from 2 December 2026. Since most organisations are using tools that were in service well before August, this transition will often be the date that actually matters. It is a short reprieve, not an exemption, and it does not delay the disclosure obligations that fall on deployers. Most Luxembourg boards will not need to supervise the technical design of generative AI models. They should, however, understand whether the tools used by their organisation support the required marking and whether procurement teams are checking this before entering into or renewing contracts. This is particularly relevant where AI is used to produce marketing materials, client communications, training content, research publications, public reports, voice recordings, images, video and social-media content. The fact that content looks professional does not answer the regulatory question of whether its AI origin must be detectable or disclosed. Deepfakes must be disclosed The EU AI Act requires deployers to disclose when image, audio or video content constituting a deepfake has been artificially generated or manipulated. The term “deepfake” may suggest fraud or political misinformation. In business, however, the issue can arise in entirely legitimate settings. An organisation might use AI to create: These applications are not prohibited. But the audience may need to be told that what they are seeing or hearing has been generated or altered by AI. This is an area in which marketing teams can move faster than internal governance. Boards should therefore be satisfied that approval processes cover synthetic media and not only traditional advertising or communications risks. Public-interest content may also require disclosure Where AI is used to generate or manipulate text published to inform the public on matters of public interest, the content must generally be disclosed as AI-generated. There is an important exception where the content has undergone human review or editorial control and a person or organisation assumes editorial responsibility for it. That exception carries more weight than it is often given. Asking someone to glance at AI-generated text before publication is not meaningful editorial review. The reviewer should understand the subject, verify material statements and be prepared to take responsibility for the final content. For regulated firms, asset managers and fund service providers, this may be relevant to publications concerning financial markets, investment products, sustainability, governance or regulatory matters. It may also be relevant to board-approved statements and reports. I would add one item that sits closer to home than most directors expect: board minutes. AI-assisted drafting and transcription tools are now routinely used in and around the boardroom, and I co-authored the ILA’s guidance on new technologies for board minutes precisely because the governance questions are not obvious. Who reviewed the output. Whether the reviewer had the standing


