Regulation · AI

The hard deadline moved. The hard part did not.

High-risk obligations now start in December 2027, and the relief is real. But almost none of the work that gets an organisation there depends on that date, and the transparency rules did not move at all.

Where this stands

The state of play

The regulation
Regulation (EU) 2024/1689, applying in stages, as amended by regulation (EU) 2026/1744 — the digital omnibus on AI, in force since 27 July 2026
Already applicable
Prohibited practices and AI literacy since 2 February 2025; general-purpose AI obligations since 2 August 2025, with models placed on the market before that date having until 2 August 2027
Transparency (art. 50)
Applicable since 2 August 2026 and not deferred. The only transitional is narrow: machine-readable marking of outputs, for generative systems already on the market, until 2 December 2026
Further prohibitions
From 2 December 2026, covering AI systems generating non-consensual intimate imagery and child sexual abuse material
High-risk, Annex III
Moved from 2 August 2026 to 2 December 2027
High-risk in regulated products
Moved from 2 August 2027 to 2 August 2028

Deferred is not cancelled. Only the application dates moved; the substantive obligations are unchanged. Note also that the Commission's public AI Act pages still display pre-omnibus dates in places, so a colleague checking the original text may reach a different answer than you — the amending instrument is regulation (EU) 2026/1744, and citing it settles the argument.

Luxembourg

There is still no designated authority here

The AI Act required member states to designate national competent authorities. Luxembourg has not yet adopted the law that does it. Bill n° 8476, deposited in December 2024, remains before the Chamber of Deputies; the Conseil d'État delivered its opinion in July 2026 with formal oppositions, and nothing has been published in the Mémorial.

If adopted in its current shape, the bill would make the CNPD the principal market surveillance authority and single point of contact, alongside sectoral regulators — the CSSF for the financial sector, the CAA for insurance, ILNAS, the ILR for critical infrastructure, and ALIA for audiovisual and synthetic media transparency. Until it passes, none of that is law, and anyone telling you the CNPD is your AI Act regulator is ahead of the legislature.

The practical consequence is not comfort. The obligations that apply, apply — the regulation binds you directly whether or not a national authority has been named. What is missing is the local guidance and the sandbox, which means the burden of interpretation sits with you for now.

The common case

You are probably not building models. You are buying them.

In the organisations we work with, the AI that matters arrived inside something else: a document tool, a screening service, a recruitment platform, a support assistant, a feature that appeared in a software update nobody read. It was not procured as artificial intelligence, and frequently it was not procured by IT at all.

That makes the first problem an inventory problem and a supplier problem before it is a technical one. You cannot govern what you have not found, and the systems hardest to find are exactly the ones bought outside IT on a departmental card.

Regardless of the deferral

Four things worth doing now

Find every use, including the invisible ones

An inventory of where AI touches your processes and which suppliers embed it. This has no deadline attached and is the prerequisite for everything else.

Separate the consequential from the routine

Classify each use by what happens when it is wrong. Steps that carry consequence get a human decision point; the rest are allowed to run.

Make oversight leave a record

The review has to produce a trace naming who reviewed what, when, and what they changed — otherwise there is nothing to show and nothing to improve.

Fix transparency wording

Where people interact with an AI system or see generated content, they must be told. That obligation is live now, and it is usually a matter of interface text and supplier documentation rather than engineering.

Human oversight that leaves no record is indistinguishable from none.

Not to a supervisor, not to an auditor, and not to the person who has to explain a decision eighteen months after whoever made it has left. This is why we treat oversight as an evidence problem rather than a policy one.

The next problem

Agents change the question from output to action

A model that drafts a recommendation is reviewable before anything happens. An agent that opens tickets, moves money, changes configuration or contacts customers has already acted by the time anyone reads the output. The governance question moves from “was the answer good?” to “what was this allowed to do without asking?”

The answer is not to forbid agents. It is to draw the line explicitly: which actions may be taken unattended, which require approval, what the agent can reach, and what it writes down. An agent with no recorded boundary is an uncontrolled change process wearing a friendlier interface.

Our part

What we do on AI, and what we do not

We map where AI already touches your processes and suppliers, classify uses by consequence, implement guardrails and oversight points that produce evidence, and assess the supplier documentation you are relying on. That work is AI governance and secure adoption, and it overlaps with DevSecOps as soon as agents get near a pipeline.

This page is a practitioner summary, not legal advice. We do not classify your systems for you as a legal matter, we do not issue conformity assessments, and we do not represent you before any authority. Whether a given system is high-risk in law belongs with counsel, and we will say so.

Regulation notes

Or start from what is on your desk.

The practitioner pages — dated, sourced, and written for engineers and risk officers rather than for search engines.