Between late June and mid-August, four developments landed in the Luxembourg financial sector. Not all of them were addressed to every entity — one went only to significant institutions — but all four will surface in the same quarterly board pack, as separate agenda items, probably owned by three different functions.

25 June. The European Systemic Risk Board adopted Warning ESRB/2026/3 on systemic cyber risks stemming from frontier AI models, published on 7 July. The General Board had moved its systemic cyber risk assessment to severe in June, up from elevated in March. Current evidence, the warning states, indicates these models can discover vulnerabilities, generate working exploits and autonomously execute full-scale cyber-attacks at a speed, scale and accuracy far exceeding earlier systems — a paradigm shift, in its own words. It also says something a systemic risk body rarely puts in writing: the concentration of leading AI providers outside the Union exposes the EU to strategic dependency and geopolitical risk.

7 July. On the day the warning was published, Claudia Buch wrote to the chief executives of the 110 significant institutions under ECB supervision. Letter SSM-2026-0301 asks each to assess the new threat environment without delay and submit a board-owned action plan to its Joint Supervisory Team by 31 October 2026, with named measures, resources, responsibilities and timelines. It creates no new rulebook — DORA remains the binding framework — and names six focus areas, one of which is AI-enabled defence. To make room for the work, the ECB extended the annual IT Risk Questionnaire collection from September 2026 to February 2027. It closes with a note that quantum computing will be the subject of a separate letter in due course.

24 to 27 July. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July and entered into force on 27 July — on the third day rather than the customary twentieth, because general application of the AI Act was imminent. It deferred the high-risk obligations most organisations were bracing for: Annex III standalone systems from 2 August 2026 to 2 December 2027, and Annex I embedded systems to 2 August 2028. It softened Article 4 from a duty to ensure AI literacy into a duty to support its development. And it left 2 August exactly where it was for everything else.

2 August. The AI Act became generally applicable, with Article 50 transparency obligations now binding deployers directly. In the following days, Anthropic began embedding invisible watermarks in text generated by models launched on or after 2 August, alongside signed provenance metadata on generated files — worldwide, no opt-out, explicitly to satisfy Article 50. OpenAI had joined the same provenance coalition in May and partnered with Google to mark generated images.

Read as four items, this is an unusually busy quarter. Read together, it is one instruction set, and the instructions do not conflict:

Frontier AI is a severe systemic threat, and depending on non-EU providers for it is a strategic vulnerability. Deploy AI in your own defence, and have the board own that plan by October. Here is how you must govern the AI you deploy — and the parts you were dreading have moved to 2027, while the parts you were not watching arrived on time. And the providers you depend on will decide, on their own schedule, what a piece of your compliance actually looks like.

Nothing in that set contradicts anything else. What it never acknowledges is the dependency it creates.

In the conversations I am having, the deferral is being taken as a general reprieve and the high-risk label is being stretched well past what the text supports. Both are worth correcting, and the second one first.

Annex III names exactly two financial use cases as high-risk: creditworthiness evaluation and credit scoring of natural persons, and risk assessment and pricing in life and health insurance. For a fund administrator, a management company or a depositary, none of the core activity touches either.

That does not make the high-risk regime irrelevant, and this is where a genuine trap sits. Annex III is not organised by sector. Its employment section catches AI used to screen job applicants or make decisions affecting workers. A firm with no high-risk financial use case at all may still be running one through HR, procured by a team that never saw it as a regulatory decision. Before concluding that the December 2027 deadline is beside the point, it is worth asking what recruitment is using.

What is not beside the point is Article 50, which applies from 2 August and is by some distance the most widely applicable part of the Act, because it reaches deployers and not only providers. The Commission published a voluntary Code of Practice on 10 June, and its final interpretive guidelines on 20 July — the reference document national market surveillance authorities, the CSSF included, will work from. Penalties for breach reach €15 million or 3% of worldwide turnover.

The allocation of duties is worth getting right, because it is routinely misstated. Informing people that they are interacting with an AI system is a provider duty under Article 50(1) — as is machine-readable marking of synthetic output under 50(2). What falls on deployers is narrower: informing people exposed to emotion recognition or biometric categorisation (50(3)), and disclosing deepfakes and AI-generated text published to inform the public on matters of public interest (50(4)).

That second one is narrower still than most summaries suggest. It does not require a label on every AI-assisted document. It targets text published to inform the public on a matter of public interest — and it falls away entirely where the content has undergone genuine human review or editorial control and a named person holds editorial responsibility for the publication. The Code of Practice pushes that exception towards a documented editorial workflow with identified responsible persons, rather than an assertion that someone glanced at it.

For most Luxembourg entities, then, the practical Article 50 exposure is a client-facing assistant and any published material that no identified human is prepared to own. Both are addressable this quarter. The elaborate high-risk programme most likely does not apply at all — and if it does, there is until December 2027.

One passage in the guidelines deserves attention from anyone building with agents. The Commission reads Article 50(1) as covering AI agents capable of interacting with people while carrying out their tasks — booking, correspondence, negotiating or concluding contracts, executing purchases — and requires them to disclose two things: that they are artificial, and on whose behalf they are acting. The justification given is transparency about the delegation of authority and accountability for the agent’s actions. The requirement extends to multi-agent architectures, and where a provider cannot rule out contact with a person, the disclosure has to be built in at architecture level rather than added at the interface.

Note what that leaves open. The guidelines require an agent to state whose authority it acts under. They do not resolve whether that act binds the organisation. Which is a reasonable moment to ask whether anyone in your organisation could currently answer the first question for every agent you are running.

Which makes the watermarking story more interesting than it first appears.

Article 50(2) puts the marking duty on providers, and they are meeting it — Anthropic from 10 August for models launched on or after 2 August, consistent with the grandfathering that gives earlier systems until 2 December.

It is tempting for a deployer to read that as the problem being handled upstream. It is not. A machine-readable mark is a signal a detection tool can read, not a notice a person sees, and the Commission is unambiguous that deployers cannot rely on the provider’s marking to satisfy their own disclosure obligation. The disclosure has to be perceivable by a human, without specialist tools.

The providers discharged their duty. A separate one sits with whoever puts the output in front of a person, and it does not travel back up the chain to the model maker.

Where the high-risk regime does apply, there is better news.

Article 9(10) allows providers of high-risk AI systems already subject to internal risk management requirements under other Union law to make the AI Act’s risk management elements part of, or combined with, those existing procedures. Article 26(5) goes further for deployers that are financial institutions: the monitoring obligation is deemed fulfilled by complying with the internal governance rules already required under financial services law. And Article 26(6) has the logs sit inside documentation that law already demands.

Two caveats, and they land differently. The first is the provider–deployer line, which is routinely blurred. Article 9(10) speaks to providers, and its “combined with” is a permission rather than a presumption — an entity relying on it still has to show its existing processes genuinely cover the Article 9 elements. Article 26(5), by contrast, is a deeming provision, and it does what it says.

The second is that the line moves. Under Article 25(1), putting your own name on a high-risk system already on the market makes you its provider, with the full Article 16 set — though contracts can allocate that differently, and Article 25 bites only on high-risk systems. More quietly, an institution that builds a high-risk system for internal use is a provider from the outset, without any rebadging at all. Neither transition tends to be flagged as a regulatory decision at the time it is made.

The AI Act is not asking most Luxembourg entities to build a new risk management system from scratch. It is asking them to show the one they already have, from an angle it was not designed for, and to fill what it never covered. The outsourcing framework under Circular CSSF 22/806 already covers the model provider, the orchestration platform and the hosting environment. The open question is whether anyone has revisited those entries to ask what has changed inside the services they describe.

This matters more here than elsewhere, because the CSSF has issued no dedicated AI circular yet. Its expectations live in supervisory practice and in the joint CSSF/BCL thematic reviews on artificial intelligence in the financial sector, from May 2023 and May 2025 — both returning to governance, human oversight, and explainability that can actually be demonstrated.

And for the substantial part of the Luxembourg market that is not a significant institution, and therefore not addressed by the ECB letter: the ESAs issued a joint statement on frontier AI models on 31 July setting out mitigating actions financial entities may implement. Supervisory expectations of this kind rarely stay confined to the institutions formally named.

Which brings me to what I keep finding inside these organisations, and it is the part that concerns me most.

Nearly every entity now has an inventory of AI initiatives. Owners, business cases, a governance workstream, a slide.

Very few have a register of the agents running in production. Which ones exist, under whose credentials, with what entitlements, touching which systems, taking which actions, and whether those actions can be reversed.

These are not the same object. An inventory of initiatives records what the organisation decided to do. A register of running agents records what is currently executing on its behalf. A file assembled from the first documents the wrong thing — convincingly enough that nobody notices until someone asks a question it cannot answer.

All four developments resolve to that same register. The AI Act asks which systems are in scope, what oversight exists, what is logged, what is disclosed. DORA asks which ICT dependencies you carry and what happens when one fails. The ESRB warning asks what your exposure to frontier model capability looks like, upstream and downstream. The ECB action plan asks what you are deploying in your own defence, who owns it, and whether the board can sign it.

Four questions, one underlying object. Answered as four documentation exercises, they produce four files that will not reconcile — and with an October deadline for significant institutions, that inconsistency surfaces in eleven weeks rather than at the next inspection.

The register is also the part that cannot be written once and filed. An agent’s entitlements change the moment someone grants it a new integration. That is an instrumentation problem before it is a documentation problem, and organisations that treat it the other way round tend to discover the difference during a supervisory dialogue.

Two things to watch, neither of them a prediction.

The deferral to December 2027 is real, and it is being read as breathing room. It may be exactly that — provided the sixteen months are used to fold AI risk into an existing framework and close the gaps DORA never covered, rather than to postpone the question. The ESRB’s threat assessment carries no deadline, and neither does the ECB’s.

And the dependency the ESRB named has reached the legislative agenda: the Cloud and AI Development Act, proposed on 3 June, would establish a sovereignty assurance framework for cloud and AI infrastructure. It is a proposal, aimed initially at public procurement, and it will be argued over for a long time. But it confirms the diagnosis is shared where law gets written — useful to know when deciding how much of an operating model to hang on a single provider.

Which returns to the plain question underneath all of it: what is running, on whose authority, and who would know if it changed?


Alexandre Castaing is Managing Director of Axon Advisory & Consulting, working with supervised financial entities in Luxembourg on digital resilience, AI governance and regulatory compliance.

#AIAct #DORA #AIGovernance #CSSF #Luxembourg #BoardLeadership #OperationalResilience #ESRB