AI governance

EU AI Act — European Union flag stars over a circuit-board background
AI governance

The EU AI Act After 2 August 2026: What Luxembourg Boards Should Check Now

In short: From 2 August 2026, the EU AI Act’s transparency obligations under Article 50 apply, and the European Commission’s AI Office and national authorities can enforce them. The high-risk rules have moved to December 2027 and August 2028. For Luxembourg boards, the immediate question is whether the organisation knows where AI is being used — including at its delegates — and can show that the controls are working. 2 August 2026 was an important date for Luxembourg boards and for every organisation caught by the EU AI Act. New transparency obligations became applicable, and the European Commission’s AI Office and national authorities moved into the enforcement phase. For organisations, this is no longer only a matter of preparing for legislation that will apply at some point in the future. Certain requirements are now in force. For boards, the immediate question is practical: do we know where AI is being used in our organisation, and can we demonstrate that the appropriate controls are actually working? What changed on 2 August 2026? Article 50 of the EU AI Act now requires greater transparency around certain AI systems and AI-generated content. People should know when they are interacting with an AI system, when content has been generated or materially manipulated by AI, and when technologies such as emotion recognition or biometric categorisation are being used. The rules apply differently depending on whether an organisation is acting as a provider of an AI system or as a deployer using a system supplied by someone else. This distinction is important because most Luxembourg organisations will be deployers rather than developers of AI. Using a third-party tool does not remove the need for oversight. The Commission published its guidelines on the transparency of AI-generated content under Article 50 on 20 July 2026. Boards should expect management to be working from those guidelines rather than from a general understanding of the Act. When people interact with AI Providers of interactive AI systems must ensure that individuals are informed when they are dealing with AI rather than a human, unless this is already obvious. The most familiar example is a chatbot. But the obligation may also be relevant to virtual assistants used in customer service, employee support, client onboarding, complaints handling, recruitment, website enquiries and internal help desks — the places where an AI layer is often added to an existing process without anyone treating it as an AI deployment. For a board, the question should not simply be whether the organisation uses a chatbot. It should be whether all AI-enabled interactions have been identified and whether the disclosure is clear enough for the person using the service. A vague reference hidden in general terms and conditions may not provide the level of transparency expected in practice. AI-generated content must be identifiable Providers of generative AI systems must enable certain AI-generated or manipulated content to be detected in a machine-readable format. This applies to synthetic text, images, audio and video, subject to specific exceptions — for example, where AI is performing a standard editing function or does not substantially change the input or its meaning. There is a timing point here that is easy to miss. For generative systems that were already on the market before 2 August 2026, the machine-readable marking obligation in Article 50(2) applies from 2 December 2026. Since most organisations are using tools that were in service well before August, this transition will often be the date that actually matters. It is a short reprieve, not an exemption, and it does not delay the disclosure obligations that fall on deployers. Most Luxembourg boards will not need to supervise the technical design of generative AI models. They should, however, understand whether the tools used by their organisation support the required marking and whether procurement teams are checking this before entering into or renewing contracts. This is particularly relevant where AI is used to produce marketing materials, client communications, training content, research publications, public reports, voice recordings, images, video and social-media content. The fact that content looks professional does not answer the regulatory question of whether its AI origin must be detectable or disclosed. Deepfakes must be disclosed The EU AI Act requires deployers to disclose when image, audio or video content constituting a deepfake has been artificially generated or manipulated. The term “deepfake” may suggest fraud or political misinformation. In business, however, the issue can arise in entirely legitimate settings. An organisation might use AI to create: These applications are not prohibited. But the audience may need to be told that what they are seeing or hearing has been generated or altered by AI. This is an area in which marketing teams can move faster than internal governance. Boards should therefore be satisfied that approval processes cover synthetic media and not only traditional advertising or communications risks. Public-interest content may also require disclosure Where AI is used to generate or manipulate text published to inform the public on matters of public interest, the content must generally be disclosed as AI-generated. There is an important exception where the content has undergone human review or editorial control and a person or organisation assumes editorial responsibility for it. That exception carries more weight than it is often given. Asking someone to glance at AI-generated text before publication is not meaningful editorial review. The reviewer should understand the subject, verify material statements and be prepared to take responsibility for the final content. For regulated firms, asset managers and fund service providers, this may be relevant to publications concerning financial markets, investment products, sustainability, governance or regulatory matters. It may also be relevant to board-approved statements and reports. I would add one item that sits closer to home than most directors expect: board minutes. AI-assisted drafting and transcription tools are now routinely used in and around the boardroom, and I co-authored the ILA’s guidance on new technologies for board minutes precisely because the governance questions are not obvious. Who reviewed the output. Whether the reviewer had the standing

AI governance

The EU AI Act in the Boardroom: 180 Days to Full Applicability

Katia Ciesielska The era of AI curiosity is over; the era of AI accountability has begun for Luxembourg boards using high‑risk AI systems. As we move through 2026, the countdown toward 2 August 2026 has become critical for governance professionals across Luxembourg, when key obligations of the EU AI Act become fully applicable for high‑risk AI systems used in financial services and other regulated sectors. What was once a technology discussion is now a core board responsibility. In a jurisdiction where the CSSF continues to emphasise robust internal governance, digital operational resilience and documented oversight, boards must now move from awareness to structured action on AI governance. This article outlines what Luxembourg independent directors and board members should prioritise during the final months before August 2026. What the EU AI Act Requires from Luxembourg Boards Using High‑Risk AI Systems The EU AI Act introduces a risk‑based framework governing the development, placement and use of artificial intelligence systems within the European Union, with particularly strict requirements for high‑risk AI systems. In financial services, many commonly used tools fall within this high‑risk category, including systems used for creditworthiness assessments, AML transaction monitoring, fraud detection, insurance pricing, algorithmic portfolio allocation and automated decision‑making. Boards must understand one central point: the Act assigns responsibility along the AI value chain, including to deployers and, in some cases, those who substantially modify AI systems. It is not enough to say, “We bought the tool from a reputable vendor”; legal responsibility does not disappear through outsourcing. Oversight must be deliberate, documented and embedded in the governance framework. Deployer vs Provider: Why Classification Matters for Luxembourg Funds and Banks One of the first questions every Luxembourg board should address is its legal role under the EU AI Act. Most investment funds, management companies (ManCos), AIFMs and credit institutions will qualify as “deployers”, meaning they use an AI system under their authority in the course of a professional activity and must ensure proper use, monitoring and logging of the system. However, the distinction between deployer and provider can become blurred. A provider is the entity that develops an AI system, or has it developed, and places it on the market under its own name, carrying heavier obligations such as conformity assessments and extensive technical documentation. The concept of “substantial modification” is where boards are most frequently caught off guard: if a Luxembourg fund or institution modifies a high‑risk AI system beyond its original intended purpose or significantly alters its performance parameters, it may legally assume the role of provider, with materially increased regulatory exposure. This is not theoretical. Customising a vendor’s risk‑scoring model, adjusting core algorithmic thresholds without vendor supervision, or repurposing an AI tool for a new function can potentially trigger this reclassification. Boards should ensure that contracts with AI vendors clearly define responsibilities and that any system modifications are reviewed through a formal governance lens. AI Literacy Obligations for Board Members under Article 4 of the EU AI Act Article 4 of the EU AI Act introduces a concept that is highly relevant for directors: AI literacy. For the first time, EU legislation explicitly requires organisations to ensure that those involved in the operation and oversight of AI systems possess sufficient knowledge to understand their functioning and associated risks. For Luxembourg boards, this requirement cannot be delegated entirely to management. Supervisory authorities increasingly expect that AI literacy starts at the top; directors who are unable to understand how AI systems generate outputs, what data they rely on, or where bias risks may arise cannot effectively discharge their oversight duties. AI literacy does not require directors to become engineers, but it does require them to ask informed questions. Boards should ensure that training programmes are specifically tailored to governance needs rather than generic technology introductions. Directors should understand risk classifications under the Act, the concept of high‑risk systems, documentation obligations, bias and discrimination concerns, and the legal consequences of non‑compliance. Given the pace of technological development, AI training should become part of the annual board education calendar, similar to updates on AML, sanctions or regulatory changes, and the training itself should be documented as evidence of literacy. High‑Risk AI Systems, Human Oversight and Traceability Many AI applications used in Luxembourg’s financial sector will fall into the high‑risk category and are therefore subject to strict requirements around risk management, data governance, transparency, traceability and human oversight. The principle of human oversight is central: high‑risk systems must be designed to allow natural persons to oversee their operation and intervene where necessary, addressing the risk of automation bias – the tendency to accept algorithmic outputs without sufficient challenge. From a board perspective, oversight must translate into operational reality. Human overseers must have both technical competence and formal authority to override or disregard AI outputs, with clearly defined escalation procedures and, for critical systems, safe‑halt mechanisms or “kill switches”. Boards should ask: if the system produces an anomalous output tomorrow, who has the authority to stop it, how quickly can that intervention occur, and is that authority documented? These are fundamentally governance questions, not purely technical ones. Traceability is another cornerstone of the EU AI Act. High‑risk systems must automatically generate logs throughout their period of use to enable post‑incident analysis and supervisory review, and in Luxembourg such logs are typically expected to be retained for a period sufficient to support regulatory audit and investigation. Traceability is not merely an IT control; it is a governance safeguard. Documented policies on AI usage, risk assessments, monitoring reports and board minutes reflecting discussion of AI oversight will become increasingly important in demonstrating compliance. Aligning AI Governance with CSSF Expectations in Luxembourg In Luxembourg, AI governance cannot be viewed in isolation from existing supervisory expectations. The CSSF has consistently emphasised that new technological risks must be embedded within the broader internal governance framework, including risk management, compliance, internal control and ICT/digital resilience requirements. For credit institutions, this aligns with Circular 12/552 on internal governance, while for AIFMs and UCITS management companies, AI risk must

AI governance

Artificial Intelligence in the Boardroom: Governance Frameworks for Luxembourg Directors

Artificial Intelligence in the Boardroom: Governance Frameworks for Luxembourg Directors Boards in 2026 must prioritise agility amid economic volatility, tech disruption and regulatory shifts. Directors face growing pressure to evolve from compliance monitors into strategic partners who drive resilience and growth. Here’s how they can rise to the challenge: Katia Ciesielska Artificial intelligence has moved from boardroom speculation to boardroom imperative. For Luxembourg directors overseeing fund management companies, financial services firms, and international corporate structures, AI governance is no longer optional – it’s a fiduciary duty.The gap between AI’s potential and board readiness remains alarmingly wide. Deloitte research reveals that 66% of board members have limited to no knowledge of AI, and 31% say AI doesn’t even appear on their board agendas. Meanwhile, McKinsey data shows organizations with AI-savvy boards outperform peers by 10.9 percentage points in return on equity.For Luxembourg directors navigating the EU AI Act, sophisticated investors, and cross-border regulations, establishing robust AI governance frameworks is essential. This guide provides practical frameworks for overseeing AI effectively in 2026. Why AI Governance Matters for Luxembourg Boards Luxembourg’s position as Europe’s leading fund domicile creates unique AI governance challenges. Boards oversee organizations deploying AI across portfolio management, risk analytics, compliance automation, and operations often across multiple jurisdictions simultaneously.Directors face converging pressures that make AI governance a top priority:Regulatory Obligations: The EU AI Act entered force in August 2024, with full compliance requirements taking effect in August 2026. The CSSF expects Luxembourg financial sector boards to provide evidence of AI oversight in their governance frameworks. Boards must demonstrate they understand where AI is used, how systems are classified, and whether controls meet regulatory standards.Investor Scrutiny: Institutional investors increasingly examine board AI competence as an investment criterion. Research shows disclosure of board AI oversight increased by 84% year-over-year in 2024, with shareholder proposals related to AI quadrupling compared to 2023.Liability Exposure: The EU AI Act’s liability framework makes it easier for claimants to prove causation for AI-related harms, increasing potential director exposure. Directors bear fiduciary responsibility for AI governance failures.Competitive Imperative: AI fundamentally reshapes competitive dynamics. Organizations deploying AI effectively gain substantial advantages in efficiency and decision quality. Boards that fail to oversee AI strategy risk positioning their organizations at a decisive disadvantage.As explored in my analysis of  What High-Performing Boards Will Focus on in 2026, AI oversight represents a defining characteristic of board excellence. The EU AI Act: What Directors Must Know The EU AI Act establishes the world’s first comprehensive regulatory framework for artificial intelligence, imposing direct obligations on AI system providers and deployers.Risk Classification System: The Act categorizes AI systems into four tiers – prohibited, high-risk, limited-risk, and minimal-risk – with obligations scaling to risk levels. High-risk AI includes systems used in employment decisions, creditworthiness assessment, and certain operational contexts in regulated industries like financial services.Board Obligations: Directors cannot delegate AI Act compliance exclusively to management. Boards must approve risk frameworks, direct resources to compliance, and maintain audit-ready evidence of AI governance. Directors should demand a current inventory of AI use cases, the risk category for each system, and proof of controls for high-risk AI.Enforcement Reality: Non-compliance can trigger substantial fines (up to €35 million or 7% of global annual turnover for the most serious violations). More significantly, investors and regulators treat weak AI controls as a signal of broader governance gaps. A Governance Framework for Luxembourg Boards Effective AI governance requires boards to establish clear frameworks defining oversight responsibilities, reporting mechanisms, and decision rights. 1. Define Your AI Governance Posture Not all boards should approach AI governance identically. The appropriate posture depends on AI’s strategic importance and the risks it creates. Assess how central AI is to your organization’s competitive position. For some Luxembourg entities, AI may be core to fund performance. For others, it’s a supporting tool. This assessment should inform governance intensity. McKinsey research suggests boards should explicitly define which AI topics warrant full board discussion (such as material investments or strategic partnerships), which belong in committees (risk frameworks, vendor reviews), and which are operational matters. Only 39% of Fortune 100 companies currently have disclosed board AI oversight, suggesting most need to formalize these structures. 2. Build Board AI Literacy Directors cannot govern what they don’t understand. Developing baseline AI literacy across the full board is foundational, though directors don’t need to become technical experts. Essential Knowledge Areas: Luxembourg directors should understand core AI concepts (machine learning, generative AI, large language models), AI’s strategic implications for their industry, the EU AI Act’s risk framework and compliance obligations, common AI risks (bias, privacy violations, security vulnerabilities), and basic AI governance principles. Practical Learning: Effective board education combines management presentations on AI initiatives, participation in director education programs (such as those offered by the Luxembourg Institute of Directors), and hands-on experimentation with AI tools in low-stakes contexts. Given AI’s rapid evolution, high-performing boards establish rhythms of continuous learning through quarterly deep-dives on AI developments and regular management updates. 3. Demand Strategic Clarity on AI Boards should require management to articulate clear AI strategy aligned with overall business objectives. Vague aspirations to “leverage AI” are inadequate. Critical Strategic Questions: Where specifically will AI create competitive advantage? What capabilities must we build versus buy? How does AI strategy align with our strategic priorities and resource allocation? What are we NOT doing with AI, and why? How do our initiatives compare to competitors? Investment Oversight: Gartner projects AI spending will reach $644 billion globally in 2025, up 76% from 2024. Directors should ensure investments align with strategy and deliver measurable returns. 4. Establish Robust Risk Oversight AI introduces distinctive risks requiring board-level attention. While management handles day-to-day risk management, boards must define risk appetite, ensure appropriate controls exist, and monitor emerging risks. Risk Appetite: Boards should explicitly define the organization’s AI risk appetite. This includes clarifying which AI applications are off-limits, establishing thresholds for acceptable error rates or bias levels, and determining which risks require board approval. Key Risk Categories: Luxembourg boards should ensure management has frameworks to identify and mitigate algorithmic bias and fairness issues, data privacy violations under GDPR, cybersecurity vulnerabilities

Scroll to Top