
Since 2 August, Brussels finally has teeth: the European Commission's AI Office has gained real enforcement powers over general-purpose AI models. It can request information, demand access to models for technical evaluations, require risk-mitigation measures and impose fines of up to €15 million or 3% of global annual turnover, whichever is higher.
The Commission says it will initially favour technical compliance dialogues with the major AI providers, but the enforcement tools are now there.
That raises a bigger question than whether Brussels can fine OpenAI, Google or Anthropic...
Europe has become very good at regulation. It is much less powerful when it comes to the infrastructure underneath AI: frontier models, computing capacity, chips and cloud services. Most of the companies developing the most powerful models are American, as is much of the technology on which they depend.
That creates an uncomfortable asymmetry. A regulator with strong domestic alternatives can afford a confrontation with a foreign company. A regulator that depends on foreign technology has fewer options if the confrontation becomes political.
And Washington has already shown that it is willing to treat European digital regulation as a trade issue. AI enforcement could become the next, much larger, version of that dispute.
But Europe does have one enormous asset: its market.
The EU represents roughly 450 million consumers under a single regulatory framework. A major AI company can complain about European rules, but simply abandoning the European market is a very different proposition.
That is Europe's real leverage. The objective should therefore not be regulation for its own sake. The point of enforcement is to make access to the European market conditional on meaningful compliance: transparency, evaluation rights, risk management and fair treatment of European businesses and creators.
A fine can eventually become a cost of doing business. Losing access to a major market is harder to put into a spreadsheet.
Luxembourg may not be able to build a European Silicon Valley. But that does not mean Luxembourg has no strategic role. In fact, the country's strengths point towards a different opportunity: becoming exceptionally good at implementing AI regulation in practice.
Luxembourg already has something many countries struggle to build: an economy accustomed to operating across borders under complex European rules. Its financial sector has spent decades turning regulation into operational processes, compliance systems and internationally accepted standards.
That experience could be valuable in AI.
The National Commission for Data Protection (CNPD) is playing a central role in Luxembourg's implementation of the AI Act, including the development of a national AI regulatory sandbox. Luxembourg has also been developing initiatives such as Regulation Meets Innovation and the AI Experience Center at the Luxembourg House of Financial Technology (LHoFT), bringing regulators, companies and innovators together to work through practical compliance questions.
This is where a small country can sometimes move faster than a large one.
If Luxembourg can demonstrate, for example, how an AI system used in banking can be deployed while meeting the requirements of the AI Act, GDPR, human oversight and auditability, that experience can become a European template. The country does not need to invent the world's best AI model. It can become very good at showing the rest of Europe how powerful AI systems can actually be governed.
There is another Luxembourg advantage: capital.
Europe’s AI ambitions will require enormous investment in computing, data centres, cloud infrastructure and energy. Luxembourg cannot finance that transformation itself, but it is exceptionally well positioned to help channel international and institutional capital towards it. Luxembourg is the EU's leading investment-fund domicile, with trillions of euros in assets under management.
That gives Luxembourg a potentially useful role in Europe's AI strategy: not necessarily building the infrastructure, but helping finance it. This is a more realistic form of technological sovereignty for a small state.
Europe therefore has two tasks ahead. It must use the leverage it already possesses – its market – while simultaneously building the technological capacity it currently lacks. If it does only the first, it risks becoming a regulator dependent on foreign technology.
If it does both, something much more interesting becomes possible: a Europe that not only writes the rules for AI, but has enough economic and technological weight to make those rules matter.
Luxembourg will not determine whether Europe becomes an AI superpower. But it can help determine whether European AI governance actually works. And in the next phase of the AI race, that may turn out to be a surprisingly valuable thing to be good at.
Daniel Kaderjak is a lawyer living in Luxembourg