
Artificial intelligence has crossed the line from pilot to production in Luxembourg's regulated sector. The 2025 joint thematic review by the CSSF and the Banque centrale du Luxembourg surveyed 461 institutions with an 86% response rate, including investment firms, authorised IFMs and AIFMs, credit institutions, e-money. Most of the identified use cases were already in production, albeit primarily for internal use, while generative AI has moved from curiosity to a standing agenda item in barely two years.
For boards and conducting officers, that shift changes the nature of the conversation. The question is no longer whether to engage with AI, but whether the entity can pursue its AI objectives at the standard of governance, resilience and explainability that supervision now demands, and whether, critically, it has the people to do so.
What are regulated entities currently developing with AI?
The main goal always has been to finally automate routine tasks that were previously not worth developing specialized software for. This new operational leverage is consolidated around 3 axes.
The first is KYC: turning weeks of manual document analysis, transaction monitoring, and regulatory reporting into hours while freeing scarce senior staff from routine synthesis. The second is risk detection: AML and fraud analytics remain the single most valuable and mature category across the sector, particularly for payment and e-money firms. The third is client and portfolio insight: from next-generation assistants that route complex cases to humans to analytical support in asset and portfolio management. Increasingly, there is a fourth: internal productivity through assisted content and code generation, where generative tools are quietly reshaping how compliance memos, board materials, and even software are produced.
These are sound, defensible objectives. The difficulty is never ambition. It is everything required to make the ambition survive in a supervised environment.
- The obstacles are structural, not technological
Data before models
The most consistent finding across regulator and industry surveys alike is that the binding constraint is data, not models. Data quality, lineage and governance are repeatedly flagged as the top obstacle to scaling AI further. An agent is only as trustworthy as the data it has access to; in a regulated entity, "trustworthy" is not a marketing adjective but a supervisory expectation. Fragmented data, weak documentation of sources, and the absence of a clean separation between training and production datasets turn every promising pilot into an audit liability. Firms that skip this foundation do not fail slowly; they fail at the first serious model review.
New technologies, new dependencies
Generative AI has accelerated adoption but also concentrated risk. A large share of operational use now relies on third-party GenAI tools, which means the entity's control environment increasingly extends into vendors it does not own. Model drift, opaque updates, hallucination in client-facing outputs, and the difficulty of auditing complex systems are no longer theoretical concerns; they are live operational risks in systems already in production. The sector's governance maturity has not kept pace: relatively few institutions have AI-specific ethical policies in place, fewer still have established AI ethics or oversight committees, and a meaningful proportion had provided no AI-related staff training at all. Capability has outrun control.
Cybersecurity and operational resilience
AI does not sit outside the resilience perimeter; it enlarges it. With DORA directly applicable since January 2025, the CSSF has reworked its rulebook accordingly, drawing a sharper line around ICT third-party oversight and tightening expectations on the register of information, exit planning, concentration risk and notification timelines. Every externally sourced AI capability is, in DORA terms, an ICT arrangement to be mapped, contracted and monitored. Layer on the demands of data protection, DPIAs and fundamental-rights impact assessments for high-risk systems under CNPD oversight, and the security question becomes inseparable from the deployment question. The CSSF's own move to a sovereign, air-gapped environment for its internal AI is a signal worth reading: sensitive data and frontier tools can coexist, but only inside a deliberately engineered control envelope.
A tightening regulatory perimeter
The EU AI Act, in force since August 2024, applies horizontally and on a phased timeline: prohibited practices and AI-literacy obligations from early 2025, general-purpose AI and governance rules from mid-2025, and the heavier high-risk obligations landing across 2026 and 2027. Misclassifying a use case, or failing to demonstrate governance, human oversight and explainability where required, carries penalties that reach into the tens of millions of euros or a percentage of global turnover. For a supervised entity, AI-Act classification is not a compliance afterthought; it is a design input that belongs at the start of every project, not the end.
The obstacle beneath every other obstacle: people
Read the surveys carefully and one constraint underwrites all the others. The scarcity of AI and machine-learning talent, profiles fluent in data science, model governance and the regulated context they operate in, is the quiet bottleneck. Where data-science teams exist in Luxembourg at all, they are typically small and often sit at group level, far from the local entity that carries the regulatory responsibility. The result is a structural mismatch: the accountability is local and specific; the expertise is remote, generic, or simply absent.
This is not a problem that permanent recruitment solves quickly. Hiring a senior AI specialist with genuine regulatory literacy in the Luxembourg market is slow, expensive and competitive, and for a scoped initiative a permanent headcount is the wrong instrument entirely. Entities need capability calibrated to the task: enough, for exactly as long as the task requires, delivered by people who already understand a CSSF-supervised environment.
There is a cost dimension boards feel acutely, and it is not the one they expect. With AI, the difficulty is rarely that the spend is large; it is that it refuses to be forecast. A model that fails its supervisory review triggers unbudgeted remediation. A third-party GenAI tool re-prices, drifts, or forces a fresh validation cycle. An internal pilot quietly widens its scope with every stakeholder who joins it. A permanent hire made for one initiative becomes a fixed cost long after that initiative has changed shape. The result is a workstream whose final bill nobody can commit to at the outset, which is precisely the kind of open-ended exposure a supervised entity is least equipped to carry.
Where SableRock fits: specialist AI talent, on your terms
SableRock maintains a pool of AI and data specialists selected for a specific combination that the market rarely offers together: genuine technical depth and fluency in the governance, resilience and supervisory expectations that shape every regulated deployment. We make that capability available in two complementary models.
On-premises secondment. An embedded specialist works inside your entity, alongside your teams, under your operational direction, building data foundations, standing up or reviewing models, drafting AI governance frameworks, or preparing AI-Act classifications and the evidence trail behind them. This is the right model where continuity, context and proximity to your control functions matter. Every placement is structured to be clean under Luxembourg labour-law characterisation, so you gain the capability without inheriting the entanglement. You hold that capability for exactly as long as the mandate runs and carry no fixed cost beyond it.
Feature-package delivery. Where the need is a defined outcome rather than an ongoing presence, we scope and deliver a discrete package (a KYC-automation workflow, a monitoring model with its validation dossier, a DORA-aligned assessment of an AI vendor, a board-ready AI governance policy) against agreed specifications, timelines, acceptance criteria and a fixed price. You buy a defined outcome for a known cost, not open-ended headcount. The initiative that would otherwise carry an unforecastable bill becomes a line item you can commit to before the work begins, with the delivery risk sitting on our side of the contract, not yours.
Both models share the same premise, and it is the premise SableRock was built on: in a supervised entity, technology and governance are not two projects. They are one. A model that cannot be explained, documented, secured and defended in front of a regulator is not an asset; it is exposure. Our specialists build for the review from day one, because in this market the review always comes.
The practical next step
The institutions that will lead the next phase are not the ones with the boldest AI ambitions. They are the ones that pair ambition with the capacity to execute it responsibly: clean data, governed models, resilient architecture, and people who understand both the technology and the supervisory lens it will be judged through.
If you wish to go ahead with AI and you need support to deliver to supervisory standard, that is precisely how we can help you closing the gap.