The EU AI Act, Regulation (EU) 2024/1689, has applied in stages since it entered into force on 1 August 2024: the bans, the rules for general-purpose AI models and the transparency duties for chatbots and AI-generated content already apply. The strictest regime, for high-risk AI, has been postponed by the AI Omnibus to 2 December 2027 for the systems listed in Annex III and to 2 August 2028 for AI in regulated products.
The AI Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal in July 2026 and is now in force. The postponed dates are therefore settled law, not a planning assumption. Below we explain what the AI Act requires, whom it binds, what applies today and how you can prepare.
What is the EU AI Act?
The AI Act is a risk-based EU regulation: the higher the risk an AI system poses, the heavier the obligations. It applies directly in the Netherlands, without the need for Dutch implementing legislation for the core rules.
The aim is twofold. The Act protects health, safety and fundamental rights, and it gives businesses legal certainty so that trustworthy AI can be developed and used across the single market.
The Act defines an AI system broadly, in line with the OECD approach. It is a machine-based system that operates with some degree of autonomy, may adapt after it is deployed and, from the input it receives, infers how to generate output such as predictions, content, recommendations or decisions that can influence physical or virtual environments. This wide definition captures modern machine-learning models, including generative and general-purpose AI. Simple rule-based software that only follows instructions written by people generally falls outside it.
Does the AI Act apply to your organisation?
Probably, if you develop, sell or use AI systems in a professional context in the EU. The Act also reaches companies outside the EU when their system is placed on the EU market or its output is used in the EU.
A US or UK company serving European customers can therefore fall within scope. The Act distinguishes several roles, each with its own duties:
- Providers develop an AI system or a general-purpose AI model and place it on the market or put it into service under their own name or trademark. They carry the heaviest obligations.
- Deployers use an AI system under their authority in a professional context, for example an employer using an AI tool to screen job applicants. Purely personal, non-professional use falls outside these duties.
- Importers and distributors bring a third-party system onto the EU market or make it available further down the supply chain, and must check that the provider has met its obligations.
- Product manufacturers and, in some cases, authorised representatives of non-EU providers may take on provider obligations.
Your role can change. A deployer that substantially modifies a high-risk system, or markets it under its own name, becomes a provider and takes on the stricter duties. Check this before you customise a system bought from a vendor.
How does the AI Act classify risk?
The Act works with four levels of risk: prohibited practices, high risk, limited risk with transparency duties, and minimal risk. The level depends on the purpose for which you use the system, not on the technology behind it.
Prohibited practices
Some uses are banned outright under Article 5, and those bans have applied since 2 February 2025. They include manipulative or deceptive techniques that materially distort behaviour and cause significant harm, and exploiting vulnerabilities related to age, disability or socio-economic situation. Also banned are social scoring, untargeted scraping of facial images to build recognition databases, emotion recognition in the workplace and in education (except for medical or safety reasons), and biometric categorisation that infers sensitive characteristics such as religion or sexual orientation.
Real-time remote biometric identification in public spaces for law enforcement is prohibited, subject to narrow exceptions with safeguards. The AI Omnibus adds a new prohibition on AI systems that generate child sexual abuse material or non-consensual intimate images of identifiable people.
High risk
High-risk systems are permitted but strictly regulated. There are two groups. Annex I covers AI that is a safety component of, or is itself, a product already regulated by EU product legislation, such as medical devices, machinery, lifts and toys. Annex III lists standalone uses in sensitive areas: biometrics, critical infrastructure, education, employment and worker management, access to essential public and private services such as credit and insurance, law enforcement, migration and border control, and the administration of justice and democratic processes.
A system listed in Annex III is not high-risk if it performs only a narrow procedural or preparatory task and does not materially influence the outcome of a decision. That exception is drawn tightly, and a provider that relies on it must document its assessment.
Limited risk: transparency
Some systems are not high-risk but can mislead people. They carry transparency duties under Article 50. People must be told when they are interacting with a chatbot, AI-generated or manipulated content must be disclosed and marked, and people must be informed when they are exposed to permitted emotion recognition or biometric categorisation.
Minimal risk
Most AI, such as spam filters, recommendation engines and AI in video games, falls into this category. The Act imposes no specific obligations here, although voluntary codes of conduct are encouraged, and the general AI literacy duty in Article 4 still applies.
When do the obligations apply?
The Act applies in phases. The bans, the AI literacy duty, the rules for general-purpose AI and the transparency duties already apply; the high-risk rules follow in December 2027 and August 2028.
| Milestone | Applies from |
|---|---|
| Regulation enters into force | 1 August 2024 |
| Prohibited practices (Article 5) and AI literacy (Article 4) | 2 February 2025 |
| General-purpose AI obligations, governance and penalties | 2 August 2025 |
| Transparency obligations (Article 50) | 2 August 2026 |
| Marking of output from generative AI systems already on the market before 2 August 2026 | 2 December 2026 |
| High-risk systems listed in Annex III | 2 December 2027 |
| High-risk AI in products covered by Annex I | 2 August 2028 |
Two practical points follow. First, the transparency duties are not a future concern: they have applied since 2 August 2026. Only providers of generative AI systems that were already on the market before that date have until 2 December 2026 to meet the machine-readable marking requirement. Systems placed on the market from 2 August 2026 onwards have no grace period.
Second, the extra time for high-risk AI is a deferral, not an exemption. The substantive obligations have not changed, and building a technical file, a risk management system and human oversight takes months. It makes sense to start now.
What must providers, deployers and importers do?
Providers of high-risk systems carry the main burden and must prove conformity before the system reaches the market. Deployers must use the system properly, supervise it and inform the people affected.
Providers of high-risk systems must set up a risk management system covering the whole life cycle, apply data governance to training, validation and test data, and draw up and maintain technical documentation. They must design the system for automatic logging, give clear instructions for use, enable effective human oversight and achieve appropriate accuracy, robustness and cybersecurity. Before placing the system on the market, they carry out the conformity assessment, draw up an EU declaration of conformity, affix the CE marking and register the system in the EU database. After that, they monitor the system on the market and report serious incidents.
Deployers of high-risk systems must use the system in line with the provider’s instructions, assign human oversight to competent staff, make sure the input data is relevant, monitor operation and keep the logs. Where required, they must inform the people affected. Public bodies and certain private deployers, for example in credit scoring and insurance pricing, must carry out a fundamental rights impact assessment. Employers must inform workers and their representatives before they put a high-risk system into use in the workplace.
Importers and distributors must check that the provider has completed the conformity assessment, the documentation and the CE marking before they make a system available. If they believe a system does not comply, they must not supply it and must inform the provider and, where relevant, the authorities.
The AI literacy duty in Article 4 applies to all providers and deployers. The AI Omnibus has softened the wording: organisations must now take measures to support a sufficient level of AI literacy among their staff. The expectation that people who work with AI understand what it does and where it can go wrong remains.
Which technical requirements apply to high-risk AI?
A provider must be able to show seven things: risk management, data quality, technical documentation, logging, transparency, human oversight, and accuracy, robustness and cybersecurity. Together they form the evidence for the conformity assessment.
Risk management must be a documented and repeated process, not a one-off exercise. The data used must be suitable for the intended purpose, with attention to bias and representativeness. The technical documentation must be detailed enough for an authority to assess compliance. Events must be logged automatically so that the system’s operation can be traced.
The instructions for use must allow the deployer to understand and use the system correctly. Human oversight must be designed into the system so that a person can understand the output, intervene and stop the system. Finally, the provider must demonstrate an appropriate level of accuracy, robustness and cybersecurity. In practice, this is the material a regulator will ask to see first.
What applies to general-purpose AI models?
Providers of general-purpose AI (GPAI) models have had their own obligations since 2 August 2025. Models with systemic risk face additional duties.
Under Articles 53 to 55, all GPAI providers must maintain technical documentation, publish a sufficiently detailed summary of the content used for training, have a policy to comply with EU copyright law and give information to the companies that build on the model. Providers of models with systemic risk must also evaluate their models, including adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and ensure strong cybersecurity. Following the official General-Purpose AI Code of Practice is a recognised way to show compliance. The AI Office of the European Commission supervises these providers directly.
Which transparency duties apply now?
Since 2 August 2026, Article 50 requires that people know when they are dealing with AI. This applies to chatbots, AI-generated content and deepfakes, and to emotion recognition and biometric categorisation.
Providers of chatbots and conversational agents must make clear that the user is interacting with a machine, unless that is obvious. Providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable format so that it can be detected as artificial. Deployers who publish deepfakes must disclose that the content was artificially generated or manipulated, and deployers who publish AI-generated text on matters of public interest must disclose this unless a person has reviewed it and bears editorial responsibility. Deployers of permitted emotion recognition or biometric categorisation must inform the people exposed to it.
If you already offer generative AI features, treat 2 December 2026 as a hard deadline for marking output from systems that were on the market before 2 August 2026.
What are the fines under the AI Act?
Under Article 99, fines go up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices. For small and medium-sized enterprises, the lower of the two amounts applies.
- Prohibited practices (Article 5): up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher.
- Breaches of most other obligations, including the high-risk requirements and the transparency duties: up to EUR 15 million or 3% of worldwide annual turnover.
- Supplying incorrect, incomplete or misleading information to notified bodies or authorities: up to EUR 7.5 million or 1% of worldwide annual turnover.
For SMEs and start-ups, the fine is capped at the lower of the fixed amount and the percentage. The AI Omnibus extends a number of these reliefs to small mid-cap companies. Fines are not the only instrument: market surveillance authorities can require corrective action, restrict or prohibit the making available of a system, and order its withdrawal or recall.
How does the AI Act relate to the GDPR and the Cyberbeveiligingswet?
The AI Act comes on top of existing law. If your AI system processes personal data, the GDPR applies in full, and if you provide essential or important services, Dutch cybersecurity law applies as well.
Under the GDPR you need a lawful basis, you must respect purpose limitation and data subject rights, and you often have to carry out a data protection impact assessment (DPIA). The fundamental rights impact assessment under the AI Act and the DPIA overlap, so it is efficient to carry them out together.
The Cybersecurity Act (Cyberbeveiligingswet), which implements the EU NIS2 Directive, has applied in the Netherlands since 15 August 2026. It adds duties on risk management and incident reporting for essential and important entities, which reinforce the AI Act’s requirements on robustness and security. Treat these regimes as one compliance programme rather than three separate projects: that saves effort and avoids contradictory controls.
Who enforces the AI Act in the Netherlands?
General-purpose AI models are supervised by the AI Office in Brussels; everything else is enforced by national market surveillance authorities. In the Netherlands, the law designating those authorities is still going through the legislative process.
At EU level, the AI Office within the European Commission supervises general-purpose AI models directly and develops guidance and codes of practice. It works with the European Artificial Intelligence Board, in which the member states are represented, and with an independent scientific panel. The AI Omnibus has extended the AI Office’s powers to AI systems based on a provider’s own GPAI model and to AI integrated into very large online platforms and search engines. Notified bodies carry out third-party conformity assessments where the Act requires them.
The AI Act applies directly, so businesses are already bound by the parts that apply. The Dutch act that designates the supervisors and their powers, however, has not yet entered into force, and the final allocation can still change. The model proposed so far is a hybrid one. Existing sector regulators become market surveillance authorities in their own fields, so healthcare AI falls to the healthcare inspectorate and AI in the workplace to the labour inspectorate. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) and the Dutch Authority for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur, RDI) have coordinating roles, with the AP acting as the residual supervisor for high-risk systems that have no obvious sector regulator.
For businesses, the practical question is therefore not only whether a system is high-risk, but also which regulator will look at it.
Which misconceptions should you avoid?
Five misunderstandings come up in almost every first conversation about the AI Act. Each of them leads organisations to spend effort in the wrong place.
The first is that the Act bans or licenses AI in general. It does neither. What triggers the heavy regime is the purpose the system serves, not the technology behind it.
The second is that a human signature removes the high-risk label. It does not. The exception for narrow procedural or preparatory tasks is drawn tightly. A tool that ranks job applicants or selects files for closer review influences the decision even if a person signs off. A rubber stamp is not human oversight and does not take a system out of Annex III.
The third is that only developers are regulated. Deployer obligations are real and enforceable against the organisation that uses the system. Several of them, such as informing workers and their representatives, assigning competent oversight and keeping logs, cannot be passed on to the vendor.
The fourth is that everything already in use is exempt. Under Article 111, high-risk systems placed on the market before the high-risk rules apply are in principle only caught if their design changes significantly afterwards. That exception is narrower than it sounds: updates, retraining and new uses are exactly the kind of change that brings a system back into scope. Systems used by public authorities must comply by 2 August 2030 regardless. If you plan to rely on the transitional rule, document the current configuration now.
The fifth is that the AI Act replaces existing law. It sits on top of it. Data protection, equal treatment law, consumer law, sector regulation, employment law and the rights of the works council (ondernemingsraad) continue to apply in full. In the Netherlands, it is usually one of those, not the AI Act itself, that produces the first concrete complaint. Under Article 27(1)(l) of the Works Councils Act (Wet op de ondernemingsraden), for example, the introduction of a system for monitoring staff requires the works council’s consent.
How do you prepare for the AI Act?
Start with an inventory of the AI you provide or use, and determine per system the risk level and your role. Then deal with prohibited uses and transparency first, because those rules already apply.
- List every AI system you provide or use, including AI built into third-party software.
- Classify each system: prohibited, high risk, transparency duty or minimal risk.
- Determine your role for each system: provider, deployer, importer or distributor.
- Stop any use that falls under the Article 5 bans.
- Apply the transparency measures for chatbots, deepfakes and AI-generated content, and plan output marking before 2 December 2026.
- For high-risk systems, build the technical file, risk management and human oversight ahead of December 2027.
- Check the GPAI obligations if you develop or substantially modify general-purpose models.
- Take measures to support AI literacy among the staff concerned.
- Align your DPIAs, fundamental rights impact assessments and security measures with the GDPR and the Cyberbeveiligingswet.
- Assign ownership, documentation and monitoring, and keep your records ready for an audit.
Involve the works council at an early stage if AI affects employees. Its consent may be required, and a late request for consent can delay the introduction of a system by months.
In summary
- The EU AI Act (Regulation (EU) 2024/1689) has been in force since 1 August 2024 and applies in phases.
- The bans, AI literacy, GPAI rules and transparency duties already apply; marking of output from older generative systems is due by 2 December 2026.
- The AI Omnibus (Regulation (EU) 2026/1744) has postponed the high-risk rules to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- Fines go up to EUR 35 million or 7% of worldwide turnover; for SMEs, the lower amount applies.
- The AI Act comes on top of the GDPR, the Cyberbeveiligingswet and employment law; plan compliance as one programme.
Frequently asked questions
Is the EU AI Act in force yet?
Yes. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages. The bans and AI literacy duty have applied since 2 February 2025, the GPAI rules since 2 August 2025 and the transparency duties since 2 August 2026.
When do the high-risk rules start?
The AI Omnibus, now in force, has set the dates at 2 December 2027 for high-risk systems listed in Annex III and 2 August 2028 for AI in products covered by Annex I. The substantive requirements are unchanged.
Do the transparency rules apply to my chatbot today?
Yes. Since 2 August 2026, users must be told they are interacting with AI, unless that is obvious. Output from generative AI systems on the market before that date must be marked in a machine-readable way by 2 December 2026.
What are the maximum fines?
Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for most other breaches, and up to EUR 7.5 million or 1% for incorrect information. For SMEs, the lower of the two amounts applies.
Does the AI Act apply to non-EU companies?
Yes, if the AI system is placed on the EU market or its output is used in the EU, even when the provider or deployer is established outside the EU.
The technology and privacy lawyers at Law & More help providers and deployers classify their systems, adjust prohibited or non-compliant uses, meet the transparency duties and prepare for the high-risk rules, in line with the GDPR. You can read the full text of the AI Act on EUR-Lex, and our index of Dutch IT and privacy law guides lists everything we have written on this subject. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.


