What is the EU AI Act, and what does it mean for your organization?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

The EU AI Act is the first comprehensive European law to establish rules governing the development and use of artificial intelligence. The law applies to organizations that offer, import, distribute, or use AI systems within the EU, regardless of where they are based. In this article, we answer the most frequently asked questions about the EU AI Act and what it specifically means for your organization.

Which organizations are subject to the EU AI Act?

The EU AI Act applies to any organization that offers, deploys, imports, or distributes AI systems within the European Union. This includes both companies based in the EU and companies outside the EU whose AI systems are used by EU users or whose output affects people in the EU.

The law distinguishes between different roles:

  • Providers: organizations that develop and market AI systems. They bear the heaviest obligations.
  • Deployers (data controllers): organizations that deploy an AI system under their own authority, such as a company that uses an AI chatbot from a third-party provider in its customer service department.
  • Importers and distributors: entities that import or resell AI systems from outside the EU.

An important point to note: a deployer can automatically assume the role of provider as soon as they add their name to a system, make a substantial change to it, or alter its use in such a way that the system falls into the high-risk category. In practical terms, this means that virtually every organization currently using AI falls within the scope of the law and has at least the obligations of a deployer.

What are the four risk categories under the EU AI Act?

The EU AI Act classifies AI applications into four risk levels: unacceptable risk (prohibited), high risk (strictly regulated), limited risk (minimal transparency requirements), and minimal or no risk (unregulated). The category determines which obligations apply to your organization.

Here is an overview of the four levels:

  1. Unacceptable risk (prohibited): AI applications that seriously violate fundamental rights are completely prohibited. Examples include subliminal manipulation techniques, social scoring by governments, predictive policing based on profiling, emotion recognition in the workplace or in educational institutions, and the creation of facial recognition databases through indiscriminate scraping. These prohibitions have been in effect since February 2, 2025.
  2. High risk: Systems that could have a significant impact on fundamental rights or security. Examples include AI in biometrics, critical infrastructure, education, human resources management, access to essential services, law enforcement, and migration. Extensive obligations apply to this category (see the next section).
  3. Limited risk: Applications such as chatbots or deepfake generators. In these cases, the main requirement is transparency: users must know that they are interacting with AI.
  4. Minimal or no risk: The vast majority of current AI applications, such as spam filters or recommendation systems in non-sensitive contexts, fall outside the scope of regulation.

Please note: Systems that perform profiling of natural persons are always high-risk, regardless of the context.

What obligations apply to high-risk AI systems?

High-risk AI systems are subject to extensive obligations that affect both providers and deployers. Providers bear the greatest responsibility and must comply with a broad range of technical and organizational requirements throughout the system’s entire lifecycle.

Requirements for Providers of High-Risk AI

If your organization develops and markets a high-risk AI system, the following obligations, among others, apply:

  • Establish and maintain a continuous risk management system.
  • Working with training, validation, and test data that are representative and as free of errors as possible, including systematic investigation and mitigation of bias.
  • Prepare technical documentation in accordance with Annex IV of the law.
  • Enable automatic logging of events throughout the product lifecycle.
  • Adopt a design that effectively enables human oversight, including awareness of automation bias.
  • Implement a quality management system, conduct a conformity assessment, issue an EU declaration of conformity, apply the CE marking, and register the product in the EU database.

Requirements for Deployers of High-Risk AI

If your organization uses a high-risk system from an external provider, the obligations are less stringent but by no means optional:

  • Use the system in accordance with the provider’s instructions for use.
  • Assign human supervision to qualified and trained employees.
  • Keep logs for at least six months.
  • Inform employees before the equipment is put into service (Article 26(7)).
  • Where applicable, conduct a data protection impact assessment (DPIA).

Under Article 86, individuals who are subject to a decision made by a high-risk AI system have the right to request an explanation of the factors that determined that decision.

When does my organization need to comply with the EU AI Act?

The EU AI Act will take effect in phases. The first obligations are already in effect, but the most far-reaching requirements for high-risk systems will not apply until 2026 and 2027. The exact deadline depends on your role and the type of AI system you use.

The implementation timeline is as follows:

  • February 2, 2025: The prohibitions set forth in Article 5 (unacceptable risk) and the requirement for AI literacy (Article 4) are in effect.
  • August 2, 2025: Requirements for GPAI models (large language models and similar systems), the European governance structure, and penalty provisions take effect. National supervisory authorities must have been designated.
  • August 2, 2026: Most of the requirements for high-risk Annex III systems will take effect. For many organizations, this is the most important deadline.
  • August 2, 2027: Requirements for high-risk AI used as a safety component in regulated products (Annex I) take effect. GPAI models that were on the market before August 2025 must therefore also be compliant.

The law will be evaluated in 2028 and 2029, with a final report on enforcement in 2031. Don’t wait until the deadline: achieving compliance takes time, especially if you have to set up a quality management system and risk documentation from scratch.

What are the fines for noncompliance with the EU AI Act?

The EU AI Act establishes a tiered penalty system in which the amount of the penalty depends on the severity of the violation. The most severe penalties apply to prohibited AI practices, followed by violations of obligations regarding high-risk systems.

The fine structure is organized as follows:

  • Up to 35 million euros or 7% of global annual revenue (whichever is higher) for violations of the prohibitions set forth in Article 5, such as the use of prohibited manipulation techniques or real-time biometric identification in public spaces.
  • Up to 15 million euros or 3% of global annual revenue for failure to comply with obligations regarding high-risk systems or GPAI models.
  • Up to 7.5 million euros or 1.5% of global annual revenue for providing inaccurate information to regulatory authorities.

The penalty provisions will take effect on August 2, 2025. For small and medium-sized enterprises, there are revenue-based caps that are proportional to the size of the business. National regulators will monitor compliance and have the authority to conduct investigations and impose sanctions.

How can an organization prepare for the EU AI Act?

Proper preparation for the EU AI Act starts with understanding: which AI systems do you use or develop, which risk category do they fall into, and what obligations arise from that? Based on that understanding, you can build the necessary governance and documentation step by step.

A practical approach consists of the following steps:

  1. Create an AI inventory: Identify all AI applications that your organization uses or develops, including tools from third-party vendors.
  2. Classify the risk: Determine the risk level for each system based on the four categories. Keep in mind that systems that perform profiling are always high-risk.
  3. Determine your role: Are you a supplier, deployer, importer, or distributor? Your role determines what obligations you have.
  4. Establish governance: Implement a risk management system, prepare technical documentation, designate individuals responsible for human oversight, and develop a policy on AI literacy for employees.
  5. Review contracts with AI vendors: As a deployer, you rely on your vendor’s documentation and user guides. Ensure that contracts include the appropriate provisions regarding logging, explainability, and compliance.
  6. Plan for the deadlines: Start preparing now for the requirements that will apply to high-risk Annex III systems as of August 2, 2026.

Organizations that already comply with ISO 27001 (information security), ISO 9001, or ISO 26000 have a head start: the process-based approach of these standards aligns well with the governance requirements of the EU AI Act.

How Pegamento Helps with EU AI Act Compliance

We understand that the EU AI Act is a complex challenge for many organizations, especially if you’re also looking to use AI to improve your customer service. Pegamento helps you combine these two goals: using AI intelligently and responsibly, while ensuring compliance.

What we can do for your organization:

  • Responsible AI Implementation: Our Agentic AI for customer service is designed with human oversight as a core principle, which directly aligns with the requirements of the EU AI Act for high-risk applications.
  • Transparent technology: We use proven, documented modules that support the legal requirements for explainability and logging.
  • Everything under one roof: From implementation to management and support, you have a single point of contact and no complex supply chain to complicate compliance.
  • Certified Process: As an ISO 27001-, ISO 9001-, and ISO 26000-certified company, we already operate in accordance with the governance principles required by the EU AI Act.
  • No costly custom development, just a smart combination of proven modules: Our solutions are flexible and scalable, allowing you to act quickly without major investment risks.

Would you like to know where your organization stands right now and what steps you can take? Contact us, and we’d be happy to help you figure it out.

Frequently Asked Questions

Geldt de EU AI Act ook voor kleine en middelgrote ondernemingen (mkb)?

Ja, de EU AI Act geldt in principe voor alle organisaties die AI inzetten binnen de EU, ongeacht hun omvang. Voor het mkb zijn er wel enkele verzachtende maatregelen: boetes zijn geplafonneerd op basis van omzet, en de Europese Commissie werkt aan vereenvoudigde documentatievereisten. Toch is het verstandig om ook als mkb’er tijdig te starten met een AI-inventaris en risicoklassificatie, zodat je niet voor verrassingen komt te staan wanneer de deadlines naderen.

Wat als mijn organisatie gebruikmaakt van AI-tools van grote aanbieders zoals Microsoft, Google of OpenAI — ben ik dan ook verantwoordelijk?

Als deployer ben je verantwoordelijk voor de manier waarop je het AI-systeem inzet, ook als je gebruikmaakt van tools van grote externe aanbieders. Je bent verplicht het systeem in te zetten conform de gebruiksaanwijzing van de aanbieder, menselijk toezicht te borgen en logs minimaal zes maanden te bewaren. Controleer daarnaast je contracten met deze leveranciers: ze moeten voldoende informatie bieden over de werking, beperkingen en conformiteitsstatus van hun systemen om jou als deployer in staat te stellen aan je eigen verplichtingen te voldoen.

Hoe weet ik of mijn AI-systeem in de hoog-risicocategorie valt?

Een AI-systeem is hoog-risico als het valt binnen de toepassingsgebieden van Annex III van de wet, zoals biometrie, personeelsbeheer, onderwijs, toegang tot essentiële diensten of rechtshandhaving. Daarnaast zijn systemen die profilering van natuurlijke personen uitvoeren altijd hoog-risico, ongeacht de context. Twijfel je over de classificatie van een specifiek systeem? Raadpleeg dan een juridisch of compliance-adviseur met kennis van de EU AI Act, of gebruik de risicobeoordelingstools die de Europese Commissie beschikbaar stelt.

Wat houdt de verplichting rondom AI-geletterdheid (Artikel 4) precies in, en hoe pak ik dat aan?

Artikel 4 verplicht organisaties om te zorgen dat medewerkers die AI-systemen inzetten of beheren, over voldoende kennis en vaardigheden beschikken om dit verantwoord te doen. In de praktijk betekent dit dat je trainingen moet aanbieden die zijn afgestemd op de rol van de medewerker: een eindgebruiker heeft andere kennis nodig dan een systeembeheerder of een beslisser die vertrouwt op AI-output. Begin met een nulmeting van de huidige AI-kennis binnen je organisatie en bouw van daaruit een gericht opleidingsprogramma op — deze verplichting is al van kracht sinds 2 februari 2025.

Wat is het verschil tussen de EU AI Act en de AVG, en hoe verhouden ze zich tot elkaar?

De AVG (GDPR) regelt de bescherming van persoonsgegevens, terwijl de EU AI Act specifiek gericht is op de risico’s van AI-systemen als zodanig — ook als er geen persoonsgegevens in het spel zijn. In de praktijk overlappen de twee wetten elkaar echter sterk: veel hoog-risico AI-systemen verwerken persoonsgegevens, waardoor zowel AVG- als AI Act-verplichtingen gelden. Een DPIA (gegevensbeschermingseffectbeoordeling) die je al uitvoert in het kader van de AVG, kan ook input leveren voor de risicobeheersing die de EU AI Act vereist — de twee kaders versterken elkaar dus.

Kan mijn organisatie beboet worden voor AI-systemen die al in gebruik waren vóór de inwerkingtreding van de wet?

Bestaande hoog-risico AI-systemen die al op de markt waren vóór augustus 2026 krijgen in principe tot augustus 2027 de tijd om aan de eisen te voldoen, maar dit geldt alleen als er geen substantiële wijzigingen aan het systeem worden aangebracht. Voor verboden AI-toepassingen (Artikel 5) geldt echter geen overgangsperiode: die zijn verboden vanaf 2 februari 2025, ongeacht wanneer het systeem is geïmplementeerd. Het is dus verstandig om bestaande AI-toepassingen nu al te toetsen aan de verbodscategorieën.

Hoe documenteer ik mijn AI-systemen correct zonder een heel compliance-team in te zetten?

Start met een eenvoudige maar gestructureerde AI-inventaris: noteer per systeem wat het doet, welke data het gebruikt, wie er verantwoordelijk voor is en welk risiconiveau van toepassing is. Voor hoog-risico systemen schrijft de wet technische documentatie voor conform Annex IV, maar voor deployers is de drempel lager dan voor aanbieders. Maak gebruik van bestaande frameworks zoals ISO 27001 of ISO 9001 als je organisatie die al toepast — de procesmatige structuur daarvan sluit goed aan bij de documentatie-eisen van de EU AI Act en bespaart je dubbel werk.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.