Will you also need to demonstrate compliance soon? On applatenmaken.com you'll find an overview of risk and compliance software.
The EU AI Act: what does this law mean for your business?
The EU AI Act is the European regulation that classifies AI systems by risk and attaches requirements to each level. For most businesses building or deploying AI, it currently comes down mainly to transparency: users need to know when they are dealing with AI. The stricter requirements for high-risk AI have recently been postponed to December 2027. This page explains what applies to you and when. This is not legal advice.
What is the EU AI Act?
The EU AI Act is the European regulation on artificial intelligence, formally Regulation (EU) 2024/1689, which entered into force on 1 August 2024. It is the first comprehensive law worldwide to regulate AI systems based on the risk they pose to people's health, safety and fundamental rights. The higher the risk of an application, the stricter the requirements it must meet.
The regulation is directly applicable law in all EU Member States. No national transposition law is needed as with a directive, but the Netherlands does set out, through an implementing act, who supervises compliance and how infringements are enforced. That bill is currently still going through the legislative process.
For businesses building their own AI or deploying AI services, the core question is always the same: which risk category does our application fall into, and what obligations come with it?
The four risk categories
Unacceptable risk: prohibited
This category covers AI practices that are incompatible with fundamental rights and are therefore simply banned. Examples include social scoring of citizens, manipulating behaviour through subliminal techniques, untargeted scraping of facial images from camera footage to build facial recognition databases, and emotion recognition in the workplace or at school. This ban has applied since 2 February 2025.
High risk: strict obligations
High-risk systems are explicitly listed in the regulation's annexes: among others, recruitment and employee evaluation, creditworthiness assessment, certain applications in critical infrastructure, access to education, and risk assessments in law enforcement and migration. These systems must meet strict requirements for risk management, data quality, technical documentation, logging and human oversight before they may be placed on the market.
Limited risk: transparency obligation
This category centres on Article 50 of the regulation: users must be told that they are interacting with AI. Examples include chatbots that must identify themselves as AI, AI-generated images, audio, video and text that must be marked in a machine-readable way, and deepfakes that must be clearly recognisable as artificially generated or manipulated.
Minimal risk: no obligations
The vast majority of AI applications currently on the European market, such as spam filters or AI in video games, remain unregulated. The regulation does, however, encourage providers to voluntarily follow codes of conduct here too.
Provider or deployer: who has which obligations?
The regulation distinguishes two main roles. A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system under its own responsibility within a professional context.
If you have AI functionality built for internal use only, you are generally a deployer. If you also offer that functionality to customers or third parties, you may also qualify as a provider, with the additional obligations that come with it.
Obligations for providers of high-risk systems
A risk management system covering the entire lifecycle, careful data governance for training, validation and testing data, technical documentation, automatic logging for traceability, clear instructions for use, a design that enables human oversight, and demonstrable accuracy, robustness and cybersecurity.
Obligations for deployers
Deployers have fewer, but still concrete, obligations: actually exercising the human oversight the system was designed for, following the provider's instructions, and monitoring how the system performs in your own practice.
The phased timeline (with an important postponement)
The regulation does not take full effect all at once, but in stages. This is especially relevant for businesses right now, as part of the timeline has recently been amended.
2 February 2025
The prohibition on unacceptable AI practices takes effect, together with the obligation for organisations to ensure sufficient AI literacy among staff who work with AI systems (Article 4).
2 August 2025
The obligations for providers of general-purpose AI models take effect, together with the governance structure and the provisions on penalties.
2 August 2026
The transparency obligations of Article 50 come into force: disclosing AI interaction, labelling AI-generated content, and informing individuals when emotion recognition or biometric categorisation is used.
2 December 2027 (was: 2 August 2026)
The obligations for standalone high-risk AI systems (Annex III) were originally due to take effect on 2 August 2026. Following a political agreement between the Council and the European Parliament on the Digital Omnibus on 7 May 2026, with final approval by the Council on 29 June 2026, this date has been moved to 2 December 2027. This change still needs to be formally published in the Official Journal of the EU before it becomes legally effective.
2 August 2028
For high-risk AI embedded in products already covered by European product safety legislation (Annex I), the extended transitional period applies until this date.
What does this mean in practice for software you commission?
For most companies building AI now, two things are most urgent. First, the transparency obligation of 2 August 2026: if your software uses a chatbot, generates content or recognises emotions, users must be made aware of it. Second, AI literacy: employees who work with AI systems must sufficiently understand what the system does and where its limits lie.
If you are building or considering an application that falls closer to a high-risk category, such as a recruitment screening tool or a credit assessment tool, it is wise to account for the requirements of Annex III in the design now, even though the hard deadline has moved to December 2027. Documentation, logging and human oversight are things you are better off building in from the architecture onwards rather than adding afterwards.
We do not determine for you whether, and in which category, your application falls. That is a legal classification for which we refer you to specialist advice and to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). What we do ensure is that the technology is built so that the required transparency, documentation and oversight are possible.
Penalties for non-compliance
Article 99 of the regulation sets out three tiers of penalties. Breaching the prohibition on unacceptable AI practices can result in a fine of up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Most other obligations, including the requirements for high-risk systems and the transparency obligations, can be fined up to €15 million or 3% of turnover. Providing incorrect, incomplete or misleading information to supervisory authorities can result in a fine of up to €7.5 million or 1% of turnover.
For SMEs and start-ups, the lower of the two amounts applies at each tier, rather than the higher.
Supervision in the Netherlands
The Netherlands is working on an implementing act that sets out which supervisory authorities are responsible for the AI Act. The government has opted for a hybrid model: several existing sector regulators will assess AI within their own domains. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has been the coordinating supervisor for algorithms and AI since 2023 and will play a key role, including in overseeing the transparency obligations and high-risk applications for which no specific sector regulator has yet been designated.
This bill is still going through the legislative process, so the precise allocation of supervision may still change. We are following these developments, but we do not provide legal advice on this matter.
How we build with the AI Act in mind
When we build AI functionality for you, we document what the AI component does and which data it uses, we put logging in place where relevant, and we make sure users can see when they are interacting with AI. Where human oversight plays a role, we design for it explicitly from the outset rather than adding it afterwards.
This ties in with our broader work on AI agents for businesses and with the way we build software with the Cyber Security Act (NIS2) in mind: regulation as a starting point for design, not a checklist afterwards. If you're considering a broader AI strategy for your organisation, we can also help you think it through at a strategic level through AI strategy development.
Frequently asked questions about the EU AI Act
The EU AI Act is the European regulation on artificial intelligence (Regulation (EU) 2024/1689), in force since 1 August 2024. It is the first comprehensive legislation in the world to regulate AI systems based on the risk they pose to people: the higher the risk of an application, the stricter the requirements. The regulation applies directly across all EU Member States, including the Netherlands, without the need for a separate national law. The Netherlands does, however, set out through an implementing act which authorities are responsible for supervision. We base our information on the official text of the regulation, and for your legal classification we refer you to that source and to specialist legal advice.
The law distinguishes four categories. Unacceptable risk is prohibited, for example social scoring and untargeted facial recognition from public camera footage; this ban has applied since 2 February 2025. High risk covers applications such as recruitment selection, credit assessment and certain uses in critical infrastructure, education and law enforcement, with heavy obligations around risk management, data, documentation and human oversight. Limited risk concerns transparency obligations, such as making clear that a user is talking to a chatbot or that content is AI-generated. Minimal risk remains unregulated, such as a spam filter.
Yes. The obligations for high-risk AI systems (Annex III) were originally due to apply from 2 August 2026. Following a political agreement between the Council and the European Parliament on 7 May 2026 on the Digital Omnibus, with final approval by the Council on 29 June 2026, that date has been moved to 2 December 2027. For high-risk AI embedded in products already covered by European product safety legislation (Annex I), the date is 2 August 2028. Important: this change still needs to be formally published in the Official Journal of the EU before it takes legal effect. The transparency obligations under Article 50 and the AI literacy duty under Article 4 have not been postponed and remain on their original dates.
A provider develops an AI system, or has one developed, and places it on the market under its own name. A deployer uses an AI system under its own responsibility in a professional context. If you commission an AI solution purely for internal use, you are usually a deployer; if you also offer that solution to others, you may (jointly) count as a provider. Providers of high-risk systems carry the heaviest obligations: risk management, data governance, technical documentation, logging, instructions for use, and a design that allows human oversight. Deployers must actually exercise that oversight and follow the provider's instructions.
Article 99 sets out three tiers. Breaching the prohibition on unacceptable AI practices can result in a fine of up to €35 million or 7 per cent of worldwide annual turnover, whichever is higher. Most other obligations, including the requirements for high-risk systems and the transparency obligations, can be fined up to €15 million or 3 per cent of turnover. Supplying incorrect or misleading information to supervisory authorities can lead to a fine of up to €7.5 million or 1 per cent of turnover. For SMEs and start-ups, the lower of the two amounts applies at each tier instead of the higher.
The Netherlands is working on an implementing act that will set out which supervisory authorities are responsible. The cabinet has opted for a hybrid model, with several existing sector regulators assessing AI within their own domains. Since 2023, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has been the coordinating supervisor for algorithms and AI, and it will play a key role, including for the transparency obligations and for high-risk applications for which no sector regulator has yet been designated. The bill is still going through the legislative process, so the final structure of supervision may still change.
We build AI functionality with the regulation as the starting point: clear documentation of what an AI component does and which data it uses, logging and human oversight where relevant, and clear labelling when users are interacting with an AI system or viewing AI-generated content. We do not provide legal advice and do not determine which risk category your application falls under; for that, we refer you to specialist legal advice and the Autoriteit Persoonsgegevens. We do, however, ensure that the technology supports the required transparency and oversight.
Building AI functionality with the AI Act as a starting point?
Tell us what you want to use AI for and who the users are. We will build the transparency, documentation and oversight in from the design stage, so your software aligns with the regulation. For your legal classification, we refer you to specialist advice and the Autoriteit Persoonsgegevens.