The EU AI Act timeline, read from a Luxembourg desk
The Act entered into force on 1 August 2024 and applies in stages. Most document-search and drafting uses are not high-risk — but the obligations that do apply are easier to meet when the system sits under your roof.
The dates that matter
2 February 2025: prohibited practices are banned, and the duty of AI literacy for staff (Article 4) applies to every organisation deploying AI. 2 August 2025: obligations for providers of general-purpose AI models. 2 August 2026: the bulk of the Act, including the high-risk regime — technical documentation, logging, human oversight, accuracy and robustness. Rules for AI embedded in regulated products follow in 2027.
For supervised financial entities, expect the CSSF to take a close interest in how the Act interacts with existing prudential and conduct rules.
Is document AI high-risk?
Annex III lists the high-risk uses: creditworthiness scoring of natural persons, recruitment and employment decisions, access to essential services, administration of justice by judicial authorities, among others. Searching your own contracts, summarising a file, drafting from a template or flagging anomalies for a human to review are not on that list.
The line is crossed when the system’s output decides something about a person — a loan, a hire, a benefit. Scope your use cases with that test in mind, and document the scoping.
What every deployer must do regardless
AI literacy for the people who use the system; transparency where users interact with AI-generated content; and, for any high-risk use, the full documentation and logging regime. A system you run yourself makes the last of these tractable: the logs are yours, the model version is pinned, and there is no provider whose documentation you have to chase.
Engineering guidance, not legal advice. We work alongside your DPO and counsel.
Official sources
Relevant sectors
See it on your own documents.
Thirty minutes on your use case, against a sample of your kind of files. We come to you.