Who supervises the AI Act in Luxembourg: CNPD, CSSF, CAA and draft law No. 8476
Draft law No. 8476 makes the CNPD Luxembourg's default AI Act authority, with the CSSF and CAA for their sectors. It was still not adopted in October 2026.
Key takeaways
- Under draft law No. 8476, filed on 23 December 2024, the CNPD would be Luxembourg's default AI Act market surveillance authority, single point of contact and operator of the national AI regulatory sandbox.
- The CSSF and the Commissariat aux assurances (CAA) would supervise AI used by the entities they already oversee; ILNAS, the ILR, ALIA, the Autorité de contrôle judiciaire and a future medicines agency cover specific products and uses.
- The Conseil d'État issued its opinion on 10 July 2026 with several formal oppositions, including on the CSSF's scope and on how competing authorities coordinate complaints.
- As of 6 October 2026 the bill had not been voted; the parliamentary file showed no government amendments after the Conseil d'État opinion.
- The EU rules apply regardless of the national law: prohibited practices since 2 February 2025 and transparency obligations under Article 50 since 2 August 2026.
In Luxembourg, the Commission nationale pour la protection des données (CNPD) is set to be the default authority for the EU AI Act: market surveillance authority, single point of contact and operator of the national AI regulatory sandbox. The CSSF and the Commissariat aux assurances (CAA) would supervise AI used by the financial and insurance entities they already oversee. As of 6 October 2026, however, draft law No. 8476, which makes these designations, had not been voted; its latest step was the Conseil d’État opinion of 10 July 2026.
Why Luxembourg needs a national law
The AI Act (Regulation (EU) 2024/1689) applies directly in every Member State, but it leaves enforcement to national authorities. Article 70 requires each country to designate at least one notifying authority and one market surveillance authority, Article 57 requires at least one national AI regulatory sandbox, and Article 99 requires national rules on penalties.
The government filed draft law No. 8476 with the Chambre des Députés on 23 December 2024. Rather than create a new agency, the bill spreads supervision across existing regulators and gives the CNPD the coordinating role.
Who does what under draft law No. 8476
| Authority | Role in the bill (as filed) |
|---|---|
| CNPD | Default market surveillance authority (Art. 7(1)); single point of contact (Art. 13); notified body for high-risk AI put into service by law-enforcement, immigration or asylum authorities (Art. 6); must set up at least one AI regulatory sandbox (Art. 12) |
| CSSF | Market surveillance for AI placed on the market, put into service or used by entities it supervises; passes relevant information to the ECB for banks under the Single Supervisory Mechanism |
| Commissariat aux assurances (CAA) | Market surveillance for AI placed on the market, put into service or used by entities it supervises |
| ILNAS | Market surveillance for high-risk AI in products under points 1 to 10 of Annex I and for critical infrastructure (Annex III, point 2); notifying authority together with the government data commissioner |
| Institut luxembourgeois de régulation (ILR) | Deployers of critical-infrastructure AI that are essential or important entities under the national cybersecurity (NIS2) law |
| Agence luxembourgeoise des médicaments et produits de santé (to be created) | Medical devices and in vitro diagnostics (Annex I, points 11 and 12), as market surveillance and notifying authority |
| Autorité luxembourgeoise indépendante de l’audiovisuel (ALIA) | Transparency duties for AI-generated content and deepfakes (Article 50(2) and (4)) |
| Autorité de contrôle judiciaire | AI used by the courts in their judicial functions |
Sanctions follow the AI Act: warnings, reprimands and fines of up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches.
The CNPD at the centre
Any AI system not assigned to a sector regulator falls to the CNPD by default. As single point of contact it coordinates the other authorities and relays notifications to the European Commission and other Member States.
The CNPD already runs a sandbox. It launched Sandkëscht on 21 May 2024 to let innovators test AI processing of personal data under the GDPR. Its submission page, last updated on 15 January 2026, states that the pilot call is closed and that submissions for the AI Act regulatory sandbox would open in August 2026. No public confirmation that this call has opened could be found as of 6 October 2026.
The bill sets 2 August 2026 as the CNPD’s deadline for the sandbox, mirroring the original AI Act. The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, moved the EU deadline for national sandboxes to 2 August 2027.
Financial sector: CSSF and CAA
As filed, the bill makes the CSSF and the CAA competent whenever an AI system is placed on the market, put into service or used by an entity they supervise. Article 74(6) of the AI Act is narrower: financial supervisors are market surveillance authorities for high-risk AI only “in direct connection with the provision of those financial services”. The Conseil d’État raised a formal opposition on this point. If the text is aligned with Article 74(6), AI used by a bank or insurer for purposes unrelated to its financial services would fall to the default authority.
What the Conseil d’État objected to
The Conseil d’État opinion of 10 July 2026 contains formal oppositions on:
- the lack of a division of tasks between ILNAS and the government data commissioner as notifying authorities;
- the CSSF’s scope, which goes beyond Article 74(6);
- powers to adopt regulations given to authorities that are not public establishments;
- the absence of rules for complaints about the same AI system or operator filed with different authorities, which it found legally uncertain.
It also said it will not waive the second constitutional vote until the law creating the medicines agency (draft law No. 8491) is in force.
Status in October 2026
The parliamentary file shows opinions from bodies including the CSSF, the CNPD, ILNAS, the ILR and the Chamber of Commerce, a rapporteur appointed on 3 June 2025, and the Conseil d’État opinion of 10 July 2026 as the latest step. As of 6 October 2026, no government amendments, committee report or vote had been published. Until the law is adopted, the allocation of roles above remains a proposal.
The EU obligations do not wait for it. Prohibited practices and AI literacy have applied since 2 February 2025, general-purpose AI rules since 2 August 2025 and Article 50 transparency duties since 2 August 2026.
What to do now
- List your AI systems and note which authority would supervise each under the bill: CSSF or CAA for regulated financial activities, the CNPD for most other uses.
- Check for prohibited practices under Article 5, including the two new bans on non-consensual intimate content and child sexual abuse material that apply from 2 December 2026.
- Apply Article 50 transparency for chatbots, synthetic content and deepfakes. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 for machine-readable marking.
- Document AI literacy measures for staff who operate or use AI.
- Classify high-risk use cases such as credit scoring, life and health insurance pricing or recruitment, and plan for 2 December 2027. Organisations that want an outside view of their priorities can start with a short AI-governance diagnostic.
- Follow draft law No. 8476 on chd.lu, in particular any government amendments responding to the Conseil d’État.
Questions & answers
Who is the AI Act authority in Luxembourg?
Draft law No. 8476 designates the CNPD as the default market surveillance authority and single point of contact. As of 6 October 2026 the bill had not been adopted, so the designation was not yet law.
Does the CSSF supervise AI used by banks and investment firms?
The bill makes the CSSF the market surveillance authority for AI systems placed on the market, put into service or used by entities it supervises. The Conseil d'État asked for this to be limited to AI directly connected with the provision of financial services, as Article 74(6) of the AI Act requires.
Does Luxembourg have an AI regulatory sandbox?
The CNPD has run a GDPR-based sandbox, Sandkëscht, since May 2024 and announced that AI Act sandbox submissions would open in August 2026. The bill gives the CNPD the task of setting up the national AI Act sandbox; the EU deadline is now 2 August 2027.
Can companies ignore the AI Act until the Luxembourg law is voted?
No. The AI Act is an EU regulation that applies directly. Prohibited practices, AI literacy, general-purpose AI rules and Article 50 transparency obligations already apply, whatever the status of the national law.
Sources
- Regulation (EU) 2024/1689 (AI Act) · EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) · EUR-Lex
- Projet de loi 8476 – dossier parlementaire · Chambre des Députés
- Projet de loi No 8476 – document de dépôt (23 December 2024) · Chambre des Députés
- Avis du Conseil d'État No 62.024 (10 July 2026) · Conseil d'État / Chambre des Députés
- Soumettre un projet – Sandkëscht · CNPD
- La CNPD lance un bac à sable réglementaire sur l'IA (May 2024) · CNPD
- L'AI Act en action (20 January 2026) · CNPD
- L'Irlande crée son AI Office, le Luxembourg cherche son gendarme · Paperjam
Written and fact-checked against primary sources.