Luxembourg Bill 8476 Would Name CNPD Default AI Authority
By Anthony Guerriero, Founder and AI Training Lead, The Leveraged Years. Filed 23 December 2024. Last recorded committee update 10 July 2026 (a logged dossier date, not an effective date). Last verified: 2026-07-25.
Most of the coverage of Europe's AI Act stops at the big five member states. Luxembourg rarely makes the list, which is exactly why its choice of national regulator is worth reading closely. The Grand Duchy has put the question in writing. A pending bill, Projet de loi 8476, would hand the country's data protection authority the lead role over artificial intelligence, and it would name that authority in plain statutory language rather than leaving it to a later decree. For now it is a proposal, not law.
The wedge here is specific. Where some governments are still debating whether to build a fresh AI agency, Luxembourg's draft would answer the question by defaulting to the regulator it already trusts with personal data. If you want to cite how a small, finance heavy EU state is wiring up the AI Act, this is the document, and it is public on the Chambre des Deputes site.
What Projet de loi 8476 proposes
Bill 8476 is the proposed national implementing measure for Regulation (EU) 2024/1689, the AI Act. Its full title states that it would implement certain provisions of the regulation and amend three existing laws: the law of 1 August 2018 organising the Commission nationale pour la protection des donnees, the 1998 law that created the financial sector supervisor, and the 2015 insurance sector law.
The bill was tabled by government minister Elisabeth Margue and sent to the Commission des Medias et des Communications, with Felix Eischen as rapporteur. The dossier records the date of filing as 23 December 2024. As of the last recorded update on 10 July 2026, the status is en commission, meaning it sits with the parliamentary committee and has drawn twelve formal opinions from bodies including the financial supervisor, the audiovisual regulator, and the standards institute. None of that makes it law yet.
The operative choice is structural. Rather than inventing a standalone AI regulator, the draft slots AI supervision into the country's existing institutional map, with one authority sitting at the center and a set of sector regulators keeping their own turf.
The CNPD's designated role, in the bill's own words
The center of the draft is the CNPD. Article 7(1) of the bill states, in French, "La Commission nationale pour la protection des donnees est designee autorite de surveillance du marche," designating it as the market surveillance authority under Article 70(1) of the AI Act. The explanatory memorandum calls this the default horizontal role: "La CNPD est designee comme autorite de surveillance du marche horizontale par defaut," which in English reads that the CNPD is designated as the default horizontal market surveillance authority.
The bill then adds a coordinating function. It would make the CNPD the country's single contact point:
"La Commission nationale pour la protection des donnees est designee point de contact unique conformement a l'article 70, paragraphe 2, troisieme phrase, du reglement (UE) 2024/1689."
The National Commission for Data Protection is designated as the single point of contact in accordance with Article 70(2), third sentence, of Regulation (EU) 2024/1689. Projet de loi 8476, Article 13.
That single point of contact is not a mailbox. Article 14 of the draft would charge it with organising coordination between the national competent authorities, and the memorandum spells out the logic: as the default horizontal authority, the CNPD is "chargee de la coordination des autorites de surveillance du marche et designee comme point de contact unique," responsible for coordinating the market surveillance authorities and acting as the single point of contact for the market.
The drafters give a reason for leaning on the data protection regulator instead of building something new. They point to Article 16 of the Treaty on the Functioning of the EU, to the reality that a large share of AI systems process personal data and therefore already fall under the GDPR, and to Article 74(8) of the AI Act, which recommends designating the national data protection authority for much of Annex III high risk AI. They also note the choice lines up with a recommendation from the European Data Protection Board.
Who is covered, and who is carved out
Under the bill, the CNPD would be the default, not the only, authority. The draft would keep sector regulators in charge where they already supervise the underlying activity. That matters for anyone trying to work out which desk to call.
| Domain | Authority the bill would designate |
|---|---|
| General or horizontal AI systems (default) | CNPD (data protection authority) |
| AI used by courts and the public prosecutor in judicial functions | Judicial control authority (autorite de controle judiciaire) |
| AI placed on the market or used by supervised financial entities | CSSF (financial sector supervisor) |
| AI in the insurance sector | Commissariat aux Assurances |
| Products and services within its remit | ILNAS (standards, accreditation and safety institute) |
| Audiovisual media content under its watch | ALIA (independent audiovisual authority) |
The draft is careful to say supervision runs on an ad hoc basis. The memorandum states that the authorities named in the law will not have to run a systematic review of every AI system before it reaches the market. Enforcement is meant to be triggered, not blanket. That is a meaningful scope limit for firms worried about a pre approval bottleneck.
How Luxembourg's model compares with peer member states
The AI Act, at Article 70, tells each member state to designate at least one notifying authority and at least one market surveillance authority. It does not prescribe the institutional shape, so states have diverged. The archetypes are worth setting side by side.
| Jurisdiction | Lead authority | Model archetype | Status |
|---|---|---|---|
| Luxembourg | CNPD (data protection authority) | DPA as default horizontal authority, plus sector carve-outs | Bill 8476, in committee |
| Spain | AESIA (Agencia Espanola de Supervision de la IA) | Purpose built, standalone AI agency | Established by Royal Decree 729/2023 |
| Ireland | Existing sector regulators, coordinated | Distributed model across multiple bodies | Announced by government |
| EU baseline | At least one per state | Framework requirement, shape left to states | Article 70, AI Act |
Read against that spread, Luxembourg's choice is the low friction one. It would reuse an authority with GDPR muscle memory rather than standing up a new agency, and it would concentrate coordination in a single office. The trade off, which the committee opinions probe, is capacity: a data protection regulator now carries a much wider brief. Source note: the Luxembourg row is drawn from Bill 8476 itself; the other rows summarise publicly stated national approaches and the AI Act text.
What Bill 8476 does NOT do
It helps to be precise about the limits, because the headline can be read too broadly.
- It is not law. The dossier lists the status as en commission. Until the Chambre des Deputes votes it through, nothing here is binding, and the text can change in committee.
- It does not create a new AI agency. There is no fresh regulator. The bill assigns roles to bodies that already exist.
- It does not give the CNPD every AI file. Courts, the financial supervisor, the insurance commissioner, the standards institute, and the audiovisual authority keep AI within their own domains.
- It does not impose pre market approval. The memorandum states supervision is ad hoc, with no systematic review of all systems before they reach the market.
- It does not set new fines by itself. The penalty architecture flows from the AI Act; this bill wires up who supervises, not a separate national fine schedule for AI.
Key Facts
- Instrument
- Projet de loi 8476, a pending bill that would implement Regulation (EU) 2024/1689 (the AI Act) and amend three national laws.
- Issuer
- Chambre des Deputes du Grand-Duche de Luxembourg. Tabled by minister Elisabeth Margue; rapporteur Felix Eischen; Commission des Medias et des Communications.
- Date filed
- 23 December 2024. Last recorded dossier update 10 July 2026 (a logged committee date, not an effective date).
- Who would be covered
- The bill would make the CNPD the default horizontal market surveillance authority and single point of contact, with sector carve-outs for courts, CSSF, insurance, ILNAS, and ALIA.
- Consequence
- If enacted, enforcement would be triggered ad hoc under the AI Act framework, with no systematic pre market review of all systems.
- Status
- Pending bill, in committee (en commission). Not yet law.
FAQ
Is Bill 8476 already law in Luxembourg?
No. It is a bill filed on 23 December 2024 and, as of 10 July 2026, still in committee before the Commission des Medias et des Communications. It has not been voted into law.
Which authority would Bill 8476 put in charge of AI?
The CNPD, Luxembourg's data protection authority, as the default horizontal market surveillance authority and the single point of contact, with several sector regulators keeping their own domains.
Why the data protection authority rather than a new AI agency?
The explanatory memorandum points to Article 16 TFEU, the overlap between AI and personal data under the GDPR, Article 74(8) of the AI Act, and an EDPB recommendation.
Primary sources and related tracking
- Primary: Chambre des Deputes, Dossier parlementaire 8476
- Primary: Compiled dossier 8476 (PDF, includes the deposited bill text and explanatory memorandum)
- Related: Romania's AI Act competent authorities
- Related: Hungary's AI Act implementation law
- Related: Slovenia's AI Act implementation law
- Hub: AI Regulation News, by jurisdiction