The EU AI Act has entered into force in phases: the regulation officially took effect on August 1, 2024, but not all of its requirements apply at the same time. Depending on the type of AI system, different deadlines apply, spread out over a two-year period. If you’re a Dutch organization working with AI, it’s important to know which rules are already in effect and which ones are still to come. In this article, we answer the most frequently asked questions about the EU AI Act and its timeline.
What are the phases involved in the implementation of the EU AI Act?
The EU AI Act follows a phased implementation schedule with four key milestones. The law took effect on August 1, 2024, but the specific obligations will come into force gradually over a 24-month period. This gives organizations time to prepare, but the clock is definitely ticking.
The four phases are as follows:
- August 1, 2024: The EU AI Act formally enters into force. The text is binding, but most of the obligations do not yet apply.
- February 2, 2025: The ban on AI applications that pose an unacceptable risk takes effect. These are the so-called prohibited practices listed in Article 5.
- August 2, 2025: The requirements for providers of General-Purpose AI (GPAI) models take effect. These include large language models and other versatile AI systems.
- August 2, 2026: The full set of regulations for high-risk AI systems takes effect. This is the strictest and most comprehensive category of requirements.
For Dutch organizations, this means that by 2026, you will have already gone through the first two phases and will now be entering the third phase. The time to take action is now, not after the deadline.
What are the first requirements that will take effect as early as 2025?
Effective February 2, 2025, certain AI applications will be completely banned throughout the European Union. These are practices considered to pose an unacceptable risk and may no longer be used, developed, or marketed, effective immediately.
Prohibited practices include, among others:
- Subliminal or manipulative techniques that influence behavior and cause harm without a person’s awareness
- Exploiting vulnerabilities based on age, disability, or socioeconomic status
- Social scoring by governments based on personal behavior
- Predictive policing based solely on profiling, without concrete evidence
- The creation of facial recognition databases through undirected scraping of the internet or security cameras
- Emotion recognition in the workplace or in educational institutions, excluding medical or safety applications
- Biometric categorization to infer sensitive characteristics such as race, political beliefs, or sexual orientation
- Real-time remote biometric identification in public spaces for law enforcement, except in strict cases
Effective August 2, 2025, additional requirements will apply to providers of GPAI models. They must prepare technical documentation, inform downstream providers about the capabilities and limitations of their models, implement a policy to ensure compliance with copyright laws, and make a summary of the training data used publicly available.
Which AI systems fall into the high-risk category?
High-risk AI is defined in Article 6 of the EU AI Act and encompasses two types of systems. First: AI used as a safety component in products that are already subject to existing European harmonization legislation and for which a third-party conformity assessment is required. Second: AI systems deployed in one of the eight specific domains listed in Annex III of the Act.
Those eight areas are:
- Biometrics (including emotion recognition and biometric categorization)
- Critical infrastructure (energy, water, transportation, digital infrastructure)
- Education and Vocational Training (Admission, Student Evaluation)
- Employment and Human Resources Management (recruitment, performance evaluation, promotion)
- Access to essential services (creditworthiness, insurance, emergency calls)
- Law enforcement (risk assessments, evidence, investigations)
- Migration and Border Control
- The Administration of Justice and Democratic Processes
Important to know: A system that performs only a limited procedural or preparatory task in one of these areas and does not pose a significant risk to fundamental rights may fall outside the high-risk category. However, the provider must provide substantiated documentation to support this. AI systems that profile natural persons are always high-risk, without exception.
What is the deadline for high-risk AI systems?
The full requirements for high-risk AI systems will take effect on August 2, 2026. That is the deadline by which providers and users of high-risk AI must be in full compliance with all requirements of the EU AI Act. For organizations that are already working with these types of systems, preparation is therefore urgent.
The obligations for providers of high-risk AI are extensive:
- Establish a continuous risk management system throughout the system’s entire lifecycle
- Working with training, validation, and test data that are representative and as free of errors as possible
- Systematically investigate and mitigate potential bias
- Prepare technical documentation in accordance with Annex IV
- Enable automatic event logging
- Provide clear instructions to deployers
- Adopt a design that effectively enables human oversight
- Ensuring accuracy, robustness, and cybersecurity
- Arrange for a quality management system, a declaration of conformity, CE marking, and registration in the EU database
Deployers—the organizations that use high-risk AI under their own authority—also have obligations. They must use the system in accordance with the user manual, assign human oversight to qualified individuals, retain logs for at least six months, inform employees before the system is put into use, and, where necessary, conduct a data protection impact assessment (DPIA).
What are the consequences of non-compliance with the EU AI Act?
Failure to comply with the EU AI Act may result in significant financial penalties. The fines are similar to those under the GDPR: they depend on the severity of the violation and the size of the organization. For the most serious violations, such as the use of prohibited AI practices, the maximum fines are set at the highest level.
In addition to financial penalties, there are also operational and reputational risks. A system that does not meet the requirements may be withdrawn from the market or prohibited from use. Furthermore, under Article 86, individuals affected by decisions made by high-risk AI systems may request an explanation of the factors that determined those decisions. This increases the legal vulnerability of organizations that do not operate transparently.
For Dutch organizations, regulators will also begin actively enforcing the law. The Dutch Data Protection Authority and other relevant agencies will play a role in overseeing compliance with the AI Act, in addition to the European AI Office, which oversees GPAI models.
How are Dutch organizations preparing for the AI Act?
Preparing for the EU AI Act begins with a clear inventory of all AI systems that your organization uses or offers. Next, for each system, you identify which risk category it falls into and what obligations result from that. This sounds straightforward, but in practice, it’s a complex process for many organizations.
A practical approach consists of the following steps:
- Identify all AI applications within your organization, including purchased software that contains AI components
- Classify each system based on the risk categories specified in the AI Act
- Determine your role: Are you a provider or a deployer? The obligations differ significantly
- Prepare documentation in accordance with the requirements, including technical documentation and risk analyses
- Set up processes for human oversight, logging, and incident reporting
- Train employees who work with high-risk AI so that they understand their responsibilities
- Stay up to date on the latest developments, as codes of conduct and harmonized standards are still being further developed
For organizations that use AI in customer interactions or business processes, it’s also wise to consider the broader governance framework surrounding AI. This includes aligning AI compliance with existing frameworks for information security and quality management.
How Pegamento Helps with AI Act Compliance
We understand that the EU AI Act raises many questions, especially if you’re already using AI solutions for customer engagement or process automation. At Pegamento, we help Dutch organizations get started with AI in a responsible and compliant manner. Our Agentic AI for customer service is built on a foundation of transparency, human oversight, and reliability. Agentic AI represents the evolution from traditional RPA bots to self-thinking assistants that not only follow instructions but also take the initiative and act independently within predefined parameters.
What we offer in the context of responsible AI use:
- A smart combination of proven modules that meet the requirements for transparency and human oversight
- Everything under one roof: from consulting and implementation to management and support, without complex supplier structures
- Solutions that align with our ISO 27001-certified approach to information security, supplemented by ISO 9001 and ISO 26000
- Guidance on setting up logging, user manuals, and human oversight in accordance with the requirements of the AI Act
Would you like to know where your organization stands right now in light of the EU AI Act? Please contact us, and we’d be happy to help you figure out the next step.
Frequently Asked Questions
Geldt de EU AI Act ook voor kleine en middelgrote ondernemingen (mkb)?
Ja, de EU AI Act is van toepassing op alle organisaties die AI-systemen aanbieden of gebruiken binnen de EU, ongeacht hun omvang. Wel biedt de wet enkele verlichtingen voor mkb-bedrijven en startups, zoals verminderde kosten voor conformiteitsbeoordelingen en toegang tot regulatoire sandboxen om te experimenteren met AI onder begeleiding van toezichthouders. Dit neemt niet weg dat ook kleinere organisaties verplicht zijn om verboden AI-praktijken te vermijden en bij gebruik van hoog-risico AI te voldoen aan de relevante eisen.
Wat als ik als organisatie gebruik maak van AI-software van een externe leverancier? Ben ik dan ook verantwoordelijk?
Ja, als deployer — de partij die een AI-systeem onder eigen gezag inzet — draag je eigen verantwoordelijkheden onder de EU AI Act, ook als je de software niet zelf hebt ontwikkeld. Dit betekent dat je het systeem conform de gebruiksaanwijzing van de aanbieder moet inzetten, menselijk toezicht moet borgen en logs minimaal zes maanden moet bewaren. Het is daarom verstandig om bij inkoop van AI-software contractueel vast te leggen welke documentatie en ondersteuning de leverancier levert om jouw compliance te faciliteren.
Hoe weet ik of mijn AI-systeem écht buiten de hoog-risico categorie valt?
Dit is een van de meest praktische uitdagingen bij de implementatie van de AI Act. Een systeem valt buiten de hoog-risico categorie als het weliswaar in een van de acht Annex III-domeinen wordt ingezet, maar uitsluitend een beperkte procedurele of voorbereidende taak vervult zonder significant risico voor grondrechten. Cruciaal is dat je dit oordeel schriftelijk onderbouwt en documenteert — zonder die onderbouwing is de uitsluiting juridisch kwetsbaar. Bij twijfel is het raadzaam om juridisch of technisch advies in te winnen voordat je concludeert dat een systeem niet hoog-risico is.
Wat zijn de meest voorkomende fouten die organisaties maken bij de voorbereiding op de AI Act?
Een veelgemaakte fout is het onderschatten van de scope: veel organisaties realiseren zich niet hoeveel AI-componenten er al verwerkt zitten in standaardsoftware zoals HR-tools, CRM-systemen of klantenserviceplatformen. Daarnaast wachten veel organisaties te lang met de inventarisatie, waardoor er onvoldoende tijd overblijft voor het opstellen van de vereiste documentatie en het inrichten van processen vóór de deadlines van 2025 en 2026. Een derde veelvoorkomende fout is het niet duidelijk vastleggen van rollen: wie is aanbieder en wie is deployer, en wat zijn de bijbehorende verantwoordelijkheden?
Hoe verhoudt de EU AI Act zich tot de AVG (GDPR) die we al kennen?
De EU AI Act en de AVG vullen elkaar aan maar overlappen op bepaalde punten, met name rondom de verwerking van persoonsgegevens door AI-systemen. Zo is de verplichting voor deployers om een DPIA uit te voeren bij hoog-risico AI direct gekoppeld aan de AVG-verplichtingen. In de praktijk betekent dit dat AI-compliance en privacycompliance niet los van elkaar kunnen worden gezien en bij voorkeur geïntegreerd worden aangepakt binnen één governance-framework. Organisaties die al een volwassen AVG-proces hebben, kunnen dit als fundament gebruiken voor hun AI Act-voorbereiding.
Zijn er al officiële richtlijnen of normen beschikbaar om te helpen bij de implementatie?
De EU AI Act verwijst naar geharmoniseerde normen die nog worden ontwikkeld door Europese normalisatie-instellingen zoals CEN en CENELEC. Daarnaast werkt het Europese AI Office aan gedragscodes, met name voor aanbieders van GPAI-modellen. Op dit moment zijn er al wel praktische hulpmiddelen beschikbaar, zoals de AI Act Compliance Checker van de Europese Commissie en sectorspecifieke guidance vanuit toezichthouders. Het is belangrijk om deze ontwikkelingen actief bij te houden, omdat de nadere uitwerking van normen directe impact heeft op hoe je aan de verplichtingen kunt voldoen.
Wat betekent 'menselijk toezicht' concreet in de context van de AI Act, en hoe richt ik dit in?
Menselijk toezicht houdt in dat een bekwaam persoon de mogelijkheid heeft om het AI-systeem te begrijpen, te monitoren, te corrigeren of te stoppen wanneer dat nodig is — en dat dit ook daadwerkelijk in de praktijk wordt uitgeoefend, niet alleen op papier. Concreet betekent dit dat je medewerkers aanwijst die verantwoordelijk zijn voor het toezicht, hen traint zodat ze de werking en beperkingen van het systeem begrijpen, en procedures inricht voor het escaleren of ingrijpen bij afwijkende uitkomsten. Voor AI-systemen in klantcontact of besluitvorming is het ook belangrijk dat de toezichthouder niet alleen bevoegd is om in te grijpen, maar ook de tijd en middelen heeft om dit effectief te doen.


