Preparing your organization for the AI Act starts with three concrete steps: identify your AI systems, determine which risk category they fall into, and ensure that your documentation and governance are in order. The AI Act is the first comprehensive European law regulating the use of AI, and its requirements apply to every organization that uses or develops AI, regardless of sector. In this article, we answer the most frequently asked questions about what the law specifically requires of you and how to get started in practice.
Specifically, what does the AI Act require of organizations?
The AI Act requires organizations to classify their AI systems by risk, document how those systems work, and demonstrate that they are used safely and transparently. The scope of these obligations depends directly on the risk level of your AI applications. For most organizations, the two most important obligations are: ensuring AI literacy among employees and maintaining a clear overview of which AI systems you use.
Specifically, this means the following for organizations that use AI as users (deployers):
- Ensure that employees have a sufficient understanding of how the AI systems they use work and what risks are associated with them (AI literacy, Article 4).
- For high-risk AI: Ensure human oversight so that an employee can always intervene or override a decision.
- For high-risk AI: Conduct a fundamental rights impact assessment before putting the system into use.
- Transparency toward users when they interact with an AI system, such as a chatbot.
- Maintaining logs and documentation regarding the use of high-risk systems.
Organizations that develop or market AI systems themselves face significantly stricter obligations, including comprehensive technical documentation, conformity assessments, and registration in the EU database. But even if you only purchase and use existing AI tools, you still have an active responsibility.
Which AI systems fall into the high-risk category?
High-risk AI systems are defined in Article 6 of the AI Act and include two categories: systems incorporated as safety components in regulated products, and systems that fall under one of the eight domains listed in Annex III. These are applications in which errors or misuse can have direct consequences for fundamental rights, safety, or access to essential services.
The eight areas listed in Annex III are:
- Biometrics (facial recognition, emotion recognition)
- Critical infrastructure (energy, water, transportation)
- Education and Vocational Training (Admission, Student Evaluation)
- Employment and Human Resources Management (Recruitment, Performance Evaluation)
- Access to essential services (creditworthiness, insurance, emergency calls)
- Law Enforcement
- Migration and Border Control
- The Administration of Justice and Democratic Processes
Important: Any system that performs profiling of natural persons always falls into the high-risk category, regardless of the domain. A system that performs only a narrow procedural or preparatory task and does not pose a significant risk to fundamental rights may fall outside the high-risk category, but the provider must document this with supporting evidence. If you’re unsure whether your system is high-risk, always document your reasoning in writing.
When do the requirements of the AI Act take effect?
The AI Act will take effect in phases. As of February 2, 2025, the prohibitions on unacceptable AI practices and the requirement for AI literacy will take effect. As of August 2, 2026, most of the obligations for high-risk systems listed in Annex III will take effect. This means that organizations must already comply with part of the law, while other obligations are still to come.
The complete timeline at a glance:
- February 2, 2025: Prohibited practices (Article 5) and the AI literacy requirement (Article 4) take effect.
- August 2, 2025: Requirements for GPAI models, governance, penalty provisions, and designation of national supervisory authorities.
- August 2, 2026: Most of the requirements for high-risk Annex III systems take effect.
- August 2, 2027: Requirements for high-risk AI used as a safety component in regulated products (Annex I).
So by 2026, it will already be urgent to take action if you’re using high-risk AI. In January 2026, Finland became the first member state to formally grant enforcement powers to its national authority. Other EU countries are following suit. Waiting is no longer an option.
How do you assess the AI systems in your organization?
You can map out AI systems by conducting a structured AI inventory: go through all departments, ask targeted questions of team leaders and IT, and document every system that supports decision-making, automates processes, or makes predictions. In doing so, many organizations discover that they are using more AI than they realized, because AI is increasingly built into standard software.
A practical four-step approach:
- For each department, take stock of the following: What software, tools, or services are used that incorporate AI? Examples include HR software with recruitment algorithms, customer service platforms that use AI to handle customer inquiries, or financial tools that perform risk assessments.
- Describe the purpose and functionality: What does the system do, based on what data, and what decisions does it support or make?
- Classify the risk level: Use the four categories from the AI Act: unacceptable risk (prohibited), high risk, limited risk, minimal risk.
- Determine your role: Are you a provider (you develop or market the system) or a deployer (you use a system from another provider)? This determines which obligations apply to you.
Record the results in a central registry. This document serves as the basis for your compliance approach and is also useful in the event of audits by regulatory authorities.
What is the difference between an AI provider and an AI user?
An AI provider is the party that develops and markets an AI system. An AI user (deployer) is the organization that deploys an existing AI system within its own context. This distinction is crucial because providers have significantly greater obligations than users, but users are not exempt from responsibility either.
As a provider, you are responsible for technical documentation, conformity assessments, CE marking (for high-risk AI), registration in the EU database, and actively monitoring your system after it is placed on the market. As a deployer, you are responsible for ensuring correct use in accordance with the provider’s instructions, human oversight, AI literacy among your employees, and a fundamental rights impact assessment for high-risk applications.
Please note: the line between provider and user can shift. If you modify a system, put your own name on it, or use it for a purpose for which it was not intended, you become the provider yourself from a legal standpoint. This also applies to importers and distributors who make substantial modifications. Review your contracts with your software vendors to understand who bears which responsibilities.
What are the first steps you should take to become AI Act-compliant?
The first step toward AI Act compliance is a comprehensive inventory of your AI systems, followed by risk classification and the establishment of an internal governance structure. Don’t start with the most onerous requirements, but rather with the actions that are already legally required: avoiding prohibited practices and promoting AI literacy.
A concrete list of priorities for 2026:
- Right now: Check whether your organization uses AI applications that fall under the prohibited practices listed in Article 5. Examples include emotion recognition in the workplace or social scoring. Stop using these applications immediately.
- Short term: Conduct an AI inventory as described in the previous section and classify each system.
- Within a few months: Ensure that employees who use AI systems are AI-literate. This does not have to be extensive training, but employees must understand what the system does, what its limitations are, and when they need to intervene.
- Establishing Governance: Appoint a person responsible for AI compliance, develop an internal policy, and define how to handle reports of incidents or deviations.
- Review contracts with suppliers: Make sure you know, for each AI supplier, which obligations fall to them and which fall to you as the deployer.
The fines for non-compliance are substantial: violations of prohibited practices can result in fines of up to 35 million euros or 7% of global annual revenue. Non-compliance with other obligations can result in fines of up to 15 million euros or 3%. So starting early is not only wise—it’s necessary.
How Pegamento Helps with AI Act Compliance
We understand that the AI Act is a complex issue for many organizations, especially if you’re already using AI in your customer interactions or business processes. At Pegamento, we help organizations gain control over their use of AI and implement it in a responsible manner. Specifically, we do this by:
- To provide insight into which of our AI-driven solutions fall under which risk category and what documentation is associated with them.
- To provide transparent technical documentation so that you, as the deployer, can meet your obligations.
- Build customized solutions using standard building blocks, so you don’t need a costly development process but still get a system that fits your situation and is set up to be compliant.
- We offer everything under one roof: from implementation to management and support, without you having to coordinate multiple vendors.
- Using Agentic AI for customer service: self-thinking assistants that don’t just follow instructions, but take the initiative on their own. This marks the evolution from traditional RPA to Agentic AI, in which bots have evolved into autonomous assistants capable of assessing and handling complex tasks.
Would you like to know where your organization currently stands in terms of AI Act compliance, or would you like to discuss how to use AI responsibly? Please contact us, and we’d be happy to help you find a solution.
Frequently Asked Questions
Wat gebeurt er als mijn organisatie nu nog niets heeft gedaan aan AI Act-compliance?
Als je nog geen stappen hebt gezet, is het belangrijk om direct te beginnen met de verplichtingen die al van kracht zijn: controleer of je verboden AI-praktijken gebruikt en zorg voor AI-geletterdheid bij medewerkers. Voor hoog-risico systemen uit Annex III heb je tot augustus 2026, maar gezien de benodigde voorbereidingstijd is uitstel riskant. Nationale toezichthouders in de EU worden actief en de boetes voor niet-naleving kunnen oplopen tot 35 miljoen euro of 7% van de wereldwijde jaaromzet.
Hoe weet ik of de AI-tools die ik inkoop bij een leverancier compliant zijn?
Vraag je leverancier expliciet om technische documentatie en vraag wie de aanbieder is in de zin van de AI Act. Als deployer ben jij verantwoordelijk voor correct gebruik, maar de aanbieder is verantwoordelijk voor conformiteitsbeoordelingen en CE-markering bij hoog-risico systemen. Controleer contracten op wie welke verantwoordelijkheid draagt en zorg dat je toegang hebt tot de informatie die je nodig hebt om je eigen verplichtingen na te komen, zoals instructies voor menselijk toezicht en logboeken.
Wat houdt AI-geletterdheid precies in en hoe organiseer ik dit praktisch?
AI-geletterdheid (Artikel 4) betekent dat medewerkers die met AI-systemen werken voldoende moeten begrijpen wat het systeem doet, wat de beperkingen zijn en wanneer ze moeten ingrijpen of een beslissing moeten overschrijven. Dit hoeft geen uitgebreide opleiding te zijn: een gerichte instructie per tool, afgestemd op de rol van de medewerker, is vaak voldoende. Leg vast welke trainingen zijn gegeven, aan wie en wanneer, zodat je dit bij een eventuele controle kunt aantonen.
Geldt de AI Act ook voor kleine organisaties en het mkb?
Ja, de AI Act geldt voor elke organisatie die AI-systemen inzet of ontwikkelt binnen de EU, ongeacht de bedrijfsgrootte of sector. Wel zijn er lichtere verplichtingen voor micro-ondernemingen bij bepaalde specifieke eisen, zoals de kosten van conformiteitsbeoordelingen. Voor de kernverplichtingen, zoals het vermijden van verboden praktijken en AI-geletterdheid, maakt de omvang van je organisatie geen verschil. Juist voor het mkb is een gestructureerde aanpak waardevol, omdat de beschikbare capaciteit voor compliance vaak beperkt is.
Wat is een grondrechteneffectbeoordeling en wanneer moet ik die uitvoeren?
Een grondrechteneffectbeoordeling (Fundamental Rights Impact Assessment, FRIA) is een analyse van de mogelijke impact van een hoog-risico AI-systeem op grondrechten zoals privacy, non-discriminatie en toegang tot diensten. Als deployer van een hoog-risico AI-systeem ben je verplicht deze beoordeling uit te voeren vóórdat je het systeem in gebruik neemt. De beoordeling documenteert welke risico’s je hebt geïdentificeerd, welke maatregelen je neemt om die te mitigeren en hoe je menselijk toezicht hebt ingericht.
Wat zijn veelgemaakte fouten bij het opzetten van een AI-inventarisatie?
Een veelgemaakte fout is dat organisaties alleen kijken naar zelfstandige AI-tools en vergeten dat AI ook ingebouwd zit in bestaande software zoals HR-systemen, CRM-platformen of financiële applicaties. Een andere valkuil is het onderschatten van het risiconiveau: systemen die profielen aanmaken van medewerkers of klanten vallen altijd in de hoog-risico categorie, ook als ze op het eerste gezicht onschuldig lijken. Documenteer bij twijfel altijd je redenering schriftelijk, zodat je bij een controle kunt aantonen hoe je tot je classificatie bent gekomen.
Hoe moet ik omgaan met AI-systemen die we intern hebben ontwikkeld of sterk hebben aangepast?
Als je een AI-systeem intern hebt ontwikkeld, er je eigen naam op hebt gezet, of het hebt ingezet voor een doel waarvoor het oorspronkelijk niet bedoeld was, word je juridisch gezien aanbieder in plaats van deployer. Dit betekent dat de zwaardere verplichtingen voor aanbieders op jou van toepassing zijn, waaronder technische documentatie, conformiteitsbeoordelingen en registratie in de EU-databank bij hoog-risico systemen. Beoordeel dit per systeem zorgvuldig en leg de redenering vast.


