Nehos Groupe

L'essentiel en bref

Nehos is an AI agency operating from Luxembourg City's Kirchberg district, serving financial institutions and EU-regulated entities.

We build DORA-compliant AI agents for KYC, AML, fund administration, and regulatory reporting — hosted on OVH EU sovereign infrastructure.

Every deployment comes with an AI Act risk assessment and CSSF-ready compliance documentation.

Our team delivers in both French and English, matching Luxembourg's bilingual professional environment.

From POC to production in 8 to 12 weeks, with a dedicated project manager and on-site availability.

AI Agency in Luxembourg — DORA & AI Act Compliant

Nehos deploys sovereign AI agents and LLM platforms for Kirchberg fintech firms, private banks, and fund managers. EU-hosted infrastructure, bilingual FR/EN delivery.

Adapté à toute taille de structure

Artisan
Startup
PME / TPE
ETI
Grand Groupe
Questions & Réponses

Questions fréquentes

Every Nehos AI agent deployed in a Luxembourg financial institution is architected for DORA compliance: full audit trails (Art. 11), ICT incident classification (Art. 17), documented third-party risk management (Art. 28), and penetration-testing-ready infrastructure. We deliver a DORA ICT risk register addendum with each project.
Under the EU AI Act, AI systems used for credit scoring, AML screening, and automated financial decisions are classified as high-risk (Annex III). Nehos delivers the required conformity assessment, technical documentation (Annex IV), and registration support. We work with your legal and compliance team to complete the classification exercise before deployment.
Yes. All production AI workloads for Luxembourg-regulated clients run exclusively on OVH EU datacentres (Gravelines, Strasbourg, Roubaix). No data leaves the EU. We provide a DPA (Data Processing Agreement) compliant with LPD and GDPR, and a data residency attestation for your CSSF reporting.
Absolutely. Our core team operates in French and English. All deliverables — technical documentation, user interfaces, training materials, and compliance dossiers — are produced in both languages by default, at no additional cost. We also support German for clients with German-speaking stakeholders.
A focused AI agent project (one well-defined use case, such as KYC document extraction or regulatory reporting automation) typically runs 8 to 12 weeks from kickoff to production deployment. This includes discovery, architecture design, development, compliance review, UAT, and go-live support.

#AI Agency in Luxembourg — DORA & AI Act Compliant

Nehos AI agency in Luxembourg: DORA-compliant AI agents, LLM deployment & sovereign infrastructure for Kirchberg fintech and EU-regulated financial.

#In a fund centre, an AI decision is a governance decision first

Luxembourg's financial industry runs on delegation. A management company or AIFM authorised here typically delegates portfolio management, fund administration, transfer agency and distribution to several entities, sometimes in several countries, while remaining answerable to the CSSF for the oversight of everything it delegates. Insert an AI system anywhere in that chain and it becomes something the ManCo has to be able to describe, monitor, evidence and, if it goes wrong, unwind. That is why the opening conversation about artificial intelligence in Luxembourg is almost never about which model to use. It is about who owns the system, what it touches, and what happens the day a supervisor asks for the file.

The Digital Operational Resilience Act has applied to the sector since 17 January 2025 and it changed the mechanics of buying technology here. Financial entities maintain a register of information on their contractual arrangements with ICT third-party providers and report it to the supervisor. ICT-related incidents have to be classified and, above thresholds, notified within defined windows. Contracts covering critical or important functions need the provisions set out in Article 30: access, audit and inspection rights, defined service levels, conditions on subcontracting, and an exit strategy that works without disrupting the business. The practical consequence for an AI project is unglamorous but decisive — adding a model provider to your stack means adding a line to a register a regulator reads. A vendor who cannot support audit rights, name its sub-processors, state where inference physically runs and describe a credible exit will not survive legal review, and the discovery usually happens three months after the technical proof of concept everybody enjoyed.

Luxembourg then adds a layer of its own. CSSF Circular 22/806 governs outsourcing arrangements, including cloud, with its own notification and authorisation expectations for critical or important functions and its own register requirement, and it has to be read alongside DORA rather than instead of it. More constraining still for AI architecture is professional secrecy under Article 41 of the amended law of 5 April 1993 on the financial sector. Client-identifying data does not leave the perimeter of a credit institution or investment firm simply because a service is convenient; the arrangement has to sit inside the legal framework that binds the provider and its staff to confidentiality. In engineering terms this settles questions that generic AI vendors treat as configuration: what actually crosses the boundary, what is pseudonymised or tokenised before it does, whether inference runs in a tenant you control, and whether prompts and outputs are retained anywhere you have not documented.

The AI Act adds a third calendar. Annex III names creditworthiness assessment of natural persons and risk assessment and pricing in life and health insurance among the high-risk financial uses, which means a good deal of fund-sector automation sits outside that list — a fact worth establishing early, with evidence, rather than assuming either way. What does apply broadly is the literacy obligation in Article 4, in force since 2 February 2025 for providers and deployers alike, and the transparency duties in Article 50 where a system interacts directly with people. Most Luxembourg institutions will be deployers rather than providers, and the deployer's obligations — using the system as instructed, assigning human oversight with genuine authority to override, keeping logs, documenting the classification — are a different piece of work from a conformity assessment. Doing that analysis properly, once, is cheaper than a compliance function relitigating it at every steering committee.

Two local particularities shape delivery. The first is the European institutional cluster on Kirchberg — the Court of Justice, the Court of Auditors, the EIB and EIF, the ESM, the Publications Office — which procures under tender rules, language regimes and accessibility obligations that have nothing to do with how a private bank buys. The second is that sovereign compute is not an abstraction here: LuxConnect operates state-backed data centres, and the EuroHPC supercomputer MeluXina, operated by LuxProvide at Bissen, gives Luxembourg-based organisations a domestic option for heavy workloads. When a client tells us EU hosting is non-negotiable, we can answer that question locally instead of asking them to accept a vendor's assurance. Our office is at 19 rue de l'Industrie, 8069 Luxembourg, and we work in French and English throughout, with German where a DACH counterparty is involved.

#The work Luxembourg institutions actually commission

Oversight tooling for delegated activities. A ManCo's supervisory duty produces an enormous amount of reading: delegate reports, due diligence questionnaires, service level evidence, breach logs, complaint statistics, counterparty updates. We build systems that extract the substance from those documents, reconcile it against the commitments in the delegation agreements, and surface what moved since the last cycle — a service level trending toward its threshold, a control marked as remediated with no evidence attached, a new sub-delegate appearing in an appendix nobody read. The oversight judgement remains with the conducting officer. What changes is that the judgement is made on a structured picture rather than on the two files someone had time to open before the board meeting.

NAV error and investment-breach files. Since 1 January 2025 the CSSF framework on the protection of investors in the case of NAV calculation errors, non-compliance with investment rules and other errors at UCI level has governed how these incidents are detected, assessed against materiality thresholds, corrected, compensated and notified. The bottleneck we are asked to remove is almost never the arithmetic. It is the assembly of the file: establishing the period affected, identifying the impacted investors and their transactions across the register, computing compensation, documenting the root cause, and producing something a depositary, an auditor and the supervisor can all follow. That is a retrieval, reconciliation and evidence-chain problem, and it is well suited to automation precisely because the output is a documented file rather than an opaque decision.

Regulatory reporting assembly. AIFMD Annex IV filings, PRIIPs key information documents — which replaced the UCITS KIID for retail investors at the start of 2023 — SFDR periodic disclosures and principal adverse impact data, plus the transaction reporting obligations that apply depending on activity. The regime keeps moving: the AIFMD II amendments, whose transposition deadline fell in April 2026, touch delegation, liquidity management tools and loan-originating funds, and the ELTIF 2.0 regime has pulled a retail audience toward private-asset products with their own disclosure consequences. Language models are genuinely useful for mapping data between source systems and report schemas, for cross-checking consistency between narrative and figures, and for drafting the same disclosure in French and English. Nothing gets filed without every field tracing back to its source, and that traceability is a design requirement, not a report.

Client-file work in private banking and cross-border insurance. Luxembourg is a major centre for cross-border life insurance written under freedom of services and supervised by the Commissariat aux Assurances, and for private banking serving clients whose affairs span several jurisdictions. The files are long, multilingual and evidentiary: identification documents, corporate structures, source of wealth, tax status under CRS and FATCA, suitability records. AI structures the file, reads what has been provided, states what is missing and prepares the reviewer's queue in priority order. Where a decision affects a person's access to a service, a qualified human decides — both because Article 14 of the AI Act requires oversight capable of overriding the system and because Article 22 of the GDPR constrains decisions taken solely by automated means.

Institutional memory made searchable. Prospectuses, board packs, delegation agreements, legal opinions, circulars, minutes and audit reports accumulated over decades, in French, English and German, mostly as PDFs produced by whatever tool was current at the time. The valuable deliverable is not a chatbot; it is the ability to ask what position the house took on a question in a previous fund launch and get the paragraph, the document and the date. Access rights are a first-class design constraint: the assistant answers with the permissions of the person asking, so a confidential board paper never surfaces because someone phrased a question cleverly.

AI literacy, the AI register and third-party assessments. A substantial share of our Luxembourg work involves no model development at all. It begins with an honest inventory of the AI already operating in the organisation, including the assistant features that arrived inside your fund administration platform, your CRM or your office suite through a release note. From there: role-specific training that satisfies Article 4 with something more useful than a slide deck, a usage policy staff can actually follow, a maintained register answering the first question any auditor asks — which systems do we operate and who is accountable for each — and structured assessments of vendor AI features so that your DORA register and your outsourcing notifications reflect reality.

#How an engagement runs

It starts with a free 30-minute audit whose only purpose is to establish whether there is a real use case and who inside the organisation would own it. If the answer is no, we say so, because a project without an internal owner in a supervised entity fails at the governance stage regardless of engineering quality.

Framing follows, and we insist that compliance, the business line and IT sit in the same room from the first workshop rather than reviewing sequentially. The output is a written scope: the process to be automated, the data that has to move and the data that must not, the classification position under the AI Act, the hosting decision, the human decision points, and the acceptance criteria the operations team will actually test against.

Build runs as one narrow slice taken to production quality rather than a broad prototype. In parallel, a compliance track produces the artefacts your governance needs before go-live and not after: the register entry and, where relevant, the outsourcing notification, a data protection impact assessment if the processing warrants it, the contractual annex covering DORA Article 30 provisions, the exit plan, model and data documentation, and the logging specification that makes a decision replayable months later. Deliverables come in French and English by default, because your steering committee and your delegate in another country do not read the same one.

User acceptance is run by the people who do the work today, on their own documents and their own edge cases, not on a curated sample. Go-live falls inside a production window of 8 to 12 weeks for a well-scoped use case, followed by hypercare and a review cadence aligned with your internal control cycle rather than with our invoicing.

#Five questions worth putting to any AI vendor pitching a Luxembourg institution

Ask where inference physically runs and request the sub-processor list in writing — you need it for your register of information, and a vendor who improvises the answer has not been through this before. Ask whether they will support audit and inspection rights, including on site, and what their exit plan looks like in practice: what you get back, in what format, and how long it takes. Ask how client-identifying data is handled given professional secrecy, and expect an architectural answer rather than a reassurance. Ask them to replay a single decision from six months ago and show you the inputs, the model version, the prompt and the output. Finally, ask who signs the AI Act classification and on what evidence, because in a deployer organisation that signature has an owner and it is usually not the vendor.

#Three ways these projects fail here

The proof of concept built on synthetic or curated data proves the technology works, which nobody doubted, and tells you nothing about your actual documents, your permissions model or your exceptions. A narrow slice built to production standards is worth more than a broad demonstration that cannot be promoted.

Buying a model instead of designing a process produces an impressive tool that quietly goes unused. The value sits in where the system stands in a workflow, who checks its output, what happens when it declines to answer, and how corrections feed back.

Treating compliance as a deliverable written at the end produces a dossier describing a system that does not exist. Traceability, logging, reversibility and human oversight are architectural properties. Retrofitting them costs more than building them, and in a supervised entity the retrofit happens under time pressure.

#What you should be able to measure

Across our engagements, clients target a 340% average ROI over twelve months, 40% lower operating costs on the processes actually automated and a 55% productivity gain on high-value work, against KPIs fixed during framing rather than chosen afterwards to flatter the result. Operationally, production platforms run to 99.5% availability. The measures that matter most to a Luxembourg governance committee, though, are rarely the headline ones: the proportion of files that pass first-line review without rework, the time between an exception occurring and its being noticed, and how long it takes to produce a complete evidence file when someone asks for one.

#Why Nehos in Luxembourg

  • On the ground — 19 rue de l'Industrie, 8069 Luxembourg, with senior people available for on-site workshops rather than a remote delivery team on a different clock.
  • 47 specialists in AI, data and cloud, and 200+ projects in production since 2014.
  • Regulatory architecture from the first line of code — logging, reversibility, exit plans and documentation designed in, because in this market they cannot be added at acceptance testing.
  • European sovereign hosting — production workloads in EU data centres, with the residency and traceability evidence your DORA register and your outsourcing file require.
  • The financial centre's vocabulary — fund administration, depositary, transfer agency, KYC and AML, regulatory reporting: we are not a generalist team learning the regime at your expense.
  • Working bilingualism, FR/EN — documentation, interfaces and training in both working languages of the centre.
  • Free audit — 30 minutes to qualify your use case and tell you honestly whether it is worth starting.

Related areas we cover: artificial intelligence Luxembourg, DORA compliant AI Luxembourg, fintech AI agency Luxembourg, AI Act Luxembourg, LLM deployment Luxembourg.

The FAQ below answers the questions our Luxembourg clients ask most often on this topic.

Get in touch with our Luxembourg team for an initial conversation with no strings attached: we assess the potential of your project together and give you a costed estimate of the expected ROI.

Réserver un audit