Introduction: four languages, three countries, one question
AI customer service in a Luxembourg SME comes down to six requests that a private agent handles end to end: recurring questions, documents, complaints, case tracking, appointments, handover to an advisor with the full history. That is the job of custom AI agents built for your business processes, on one condition: the data stays in the European Union, from the entry channel to the model that answers. Since August 2, 2026, Article 50 of the AI Act adds a simple requirement: the person on the other end must know they are talking to an AI.
Tuesday morning, in a real estate agency in Luxembourg City, a tenant from Brussels writes in Dutch for a duplicate rent receipt. A cross-border landlord calls in German about a leak. An applicant asks in English where her file stands. The manager is considering AI for customer service, but every request touches personal data.
Automation is not the problem for the customer service of a regulated SME. The path the data takes is. Here are the six requests, and for each one the data involved, where it stays and the rule that applies.
1. What customer service covers in a Luxembourg SME
A mailbox, a switchboard, a form, a chat window, all run by the same people on top of their actual job. Three constraints weigh on it.
Language comes first. As of January 1, 2026, 46.6% of Luxembourg residents are foreign nationals (Statec, Luxembourg's national statistics institute, STATNEWS No. 15/2026). An accounting firm or a broker answers in French, German and English on the same day, and in Dutch as soon as it serves customers in Belgium or the Netherlands.
A large share of requests repeat (opening hours, status, duplicates); the rest needs a human (dispute, negotiation). And every request carries personal data: customer service is, by construction, data processing within the meaning of the GDPR.
2. Six requests a private AI agent handles end to end
A business AI agent does more than answer. It reads a file, produces a document, triggers an action in an internal tool and knows when to hand over.
2.1 Recurring questions
Opening hours, procedures, documents to provide, usual lead times: the customer service AI agent answers these questions from your internal knowledge base, not from the memory of a general-purpose model that invents a plausible procedure. A question without a validated answer goes to an advisor instead of an approximation. No personal data is needed at this stage, and the knowledge base stays hosted within your perimeter, in the EU.
2.2 Document requests
Certificate, duplicate invoice, customer account statement: the agent verifies the requester's identity, reads the file, generates the document and sends it in the language of the request. Document processing by a private AI takes place within your perimeter, with no third-party generation or storage service. Identity, contract and amounts never leave the customer file; the data processing agreement sets out what the provider may do with them.
2.3 Complaints
The agent acknowledges receipt of a complaint, qualifies it (delay, billing error, non-compliant service), gathers the relevant documents and routes it to the right person with a file already assembled. It never decides on the merits of a complaint: granting or refusing is an advisor's call. The customer's statements and history stay in your internal ticketing tool, with no copy sent to an external service.
2.4 Case or order tracking
Knowing where a case or an order stands is a tracking request that an AI agent handles without human intervention. The agent reads your internal tools (CRM, case management, order tracking), retrieves the exact status and states it in the customer's language. Its access is read-only: it modifies neither a status nor a data item. It looks up the identifier and the state of the case, nothing beyond what the question requires.
2.5 Booking and rescheduling appointments
Offering a slot, moving it, cancelling it, sending the confirmation: the AI agent manages the appointment end to end, by phone as well as by chat or email. It writes to the calendar you open to it, and only that one, with no access to the company's other calendars. Identity, contact details and reason for the appointment stay in that calendar, with a defined retention period, as for any personal data.
2.6 Handover to a human, with summary and history
This is the criterion that separates an agent from an answering machine. When a request falls outside its scope, the agent passes the advisor a summary, the history and the documents already collected. The customer repeats nothing.
For each of the six requests, the data involved, where it stays and the rule that applies:
| Request | Data involved | Where it stays | Applicable rule |
|---|---|---|---|
| Recurring questions | None, then identity if follow-up | Internal knowledge base, in the EU | Information that an AI is used (AI Act, Article 50) |
| Document requests | Identity, contract, amounts | Customer file, generation within your perimeter | GDPR, data processing agreement (Article 28) |
| Complaints | Identity, history, customer's statements | Internal ticketing tool | GDPR, minimisation; decision reserved to a human |
| Case tracking | Identifier, case status | Read-only in your tools | GDPR, access limited to what is needed |
| Appointments | Identity, contact details, reason | Your calendar, a single one | GDPR, retention period |
| Handover to a human | Summary and history | Internal transfer, no external copy | GDPR, internal traceability |
2.7 Three entry channels for the same agent
The customer service chatbot, the phone and email are three doors to the same agent and the same rules. On your website, the AI assistant embedded in your site detects the visitor's language. On the phone, the AI phone agent takes calls outside opening hours.
3. Where the data of an AI customer service goes, step by step
A request follows a path: entry channel, call to the model, lookup in the file, archiving. The question to put to the provider concerns each step.
3.1 Hosted in Europe does not mean processed in Europe
A server in Frankfurt that sends every question to a model operated from the United States is not a European deployment. Inference, the moment the model produces its answer, is the most sensitive step. We have detailed why hosted in Europe does not mean processed in Europe. Ask where the model runs, not only where the files sleep.
3.2 What the provider must document
Four written documents: the data processing agreement provided for in Article 28 of the GDPR; the data path including sub-processors; the commitment not to train any model on your conversations; the location of inference.
3.3 Why the provider's head office matters
The Cloud Act, a US federal law enacted on March 23, 2018, allows US authorities to demand, on a judicial order, data held by a provider subject to their law, even when stored in Europe.
Your teams' reflex, meanwhile, goes to the consumer tool, whose provider falls precisely under that law. On August 31, 2026, the European Commission designated ChatGPT a very large online search engine under the DSA, on the basis of around 159.1 million monthly active users in the EU. A consumer assistant is not a channel for customer files.
4. What the AI Act changes for an AI customer service agent
The AI Act, Regulation (EU) 2024/1689, has applied generally since August 2, 2026. Two articles matter here, and one category does not apply.
Transparency (Article 50): since August 2, 2026, a person interacting with an AI system must be informed of it, unless this is obvious from the context. Your agent therefore introduces itself as an AI from the first message or the first seconds of a call.
AI literacy (Article 4): since February 2, 2025, companies that deploy an AI system take measures to foster the development of their staff's AI literacy. Your advisors know what the agent does, what it does not do, and how to take back control.
No high risk for everyday customer service. High-risk classification works by use case listed in Annex III of the regulation, whose obligations will only apply from December 2, 2027; answering customers is not one of them.
💡 Worth knowing: the AI Act does not replace the GDPR, it adds to it. An agent that correctly introduces itself as an AI but sends questions to a model outside the EU without a data processing agreement remains non-compliant with the GDPR.
5. Customers in Belgium and the Netherlands: same rules, same EU perimeter
The GDPR applies in the same way in all 27 Member States. The Luxembourg provider remains under the authority of the CNPD (Luxembourg's data protection authority), and no transfer outside the EU is needed to serve a Belgian or Dutch customer. Dutch is a setting of the agent, not an architecture.
The tasks delegated to a private agent at a broker's (claims, certificates, reminders) are the same whether the policyholder lives in Luxembourg or in Arlon. Only the language changes.
6. What a customer service agent must not handle alone
A well-designed agent is recognised by what it refuses. Of the six requests in the table, only one, the complaint, calls for a decision on the merits, and that decision belongs to an advisor.
Disputes and any decision with legal effect. Terminating a contract, refusing a refund, granting a goodwill gesture. Article 22 of the GDPR protects every person against a decision based solely on automated processing that produces legal effects. The agent prepares, an advisor decides.
Health data and sensitive financial data. A sick note attached to a complaint, a bank statement sent by mistake. The agent detects them, does not summarise them and forwards them to the authorised advisor.
What it does not need. The principle of data minimisation, set out in Article 5 of the GDPR, applies to the agent as it does to an employee: it looks up the fields it needs, not the whole file. And when the customer asks for a human, the handover happens without justification.
A Luxembourg para-public organisation has deployed a setup of this kind, chat and phone agent on a private LLM, with these limits set from day one. See how to protect your company's data with a private AI.
7. Where to start an AI project for customer service
One channel, not three: the one where repetition is highest and the data least sensitive, often email or chat. Then a clean knowledge base: up-to-date procedures, validated answers. Finally, metrics from day one: requests resolved without a human, time to first response, reason for each handover to an advisor.
The SME Packages AI scheme reimburses 70% of the eligible costs of a project between €3,000 and €25,000 excl. VAT, i.e. up to €17,500 in aid (guichet.public.lu, Luxembourg's official administrative portal). The process starts with a pre-analysis with the House of Entrepreneurship or the eHandwierk service of the Chambre des Métiers (Luxembourg's Chamber of Skilled Trades and Crafts).
If the question is still "which solution to choose", see our guide on choosing an AI solution for customer service.
FAQ: your questions about AI in the customer service of a Luxembourg SME
1. Does a customer service AI agent have to say it is an AI?
Yes. Since August 2, 2026, Article 50 of the AI Act provides that any person interacting with an AI system must be informed of it. Your agent therefore introduces itself as an AI from the first message or the first seconds of a call.
2. Are my customers' conversations used to train the model?
Not on a private deployment, and it is a clause to demand in writing. The no-training commitment is one of the four written documents to ask the provider for, together with the data processing agreement provided for in Article 28 of the GDPR, the data path and the location of inference. Without that clause, assume the answer is yes.
3. What happens when the agent does not know the answer?
It hands over to an advisor with three elements: a summary, the history of the exchange and the documents already collected. This handover is also triggered on simple request. An agent that cannot say "I don't know" is a risk.
4. Are my Belgian or Dutch customers covered by the same rules?
Yes. The GDPR has applied identically across the European Union since May 25, 2018, in Belgium and the Netherlands as in Luxembourg. Your provider remains under the authority of the CNPD (Luxembourg's data protection authority) and no transfer outside the EU is required.
5. Is a customer service agent a "high-risk" system under the AI Act?
Not in the usual case. High risk is defined by use case listed in Annex III, whose obligations will only apply from December 2, 2027; answering customers is not one of them. A customer service agent falls under Article 50, applicable since August 2, 2026.
The data path decides, not the tool
A private AI agent handles six customer service requests end to end, provided the data stays in the EU from the entry channel to inference. The GDPR sets the framework, the AI Act adds the duty to inform the person you are talking to.
A list of recurring requests and a doubt about the data path? Bring both: we test them against your organisation.



