{"id":33177,"date":"2026-07-29T08:00:00","date_gmt":"2026-07-29T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/when-will-the-eu-ai-act-take-effect-and-what-are-the-key-deadlines\/"},"modified":"2026-07-29T10:01:10","modified_gmt":"2026-07-29T08:01:10","slug":"when-will-the-eu-ai-act-take-effect-and-what-are-the-key-deadlines","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/when-will-the-eu-ai-act-take-effect-and-what-are-the-key-deadlines\/","title":{"rendered":"When will the EU AI Act take effect, and what are the key deadlines?"},"content":{"rendered":"<p>The EU AI Act has entered into force in phases: the regulation officially took effect on August 1, 2024, but not all of its requirements apply at the same time. Depending on the type of AI system, different deadlines apply, spread out over a two-year period. If you\u2019re a Dutch organization working with AI, it\u2019s important to know which rules are already in effect and which ones are still to come. In this article, we answer the most frequently asked questions about the <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">EU AI Act<\/a> and its timeline.   <\/p>\n<h2>What are the phases involved in the implementation of the EU AI Act?<\/h2>\n<p>The EU AI Act follows a phased implementation schedule with four key milestones. The law took effect on August 1, 2024, but the specific obligations will come into force gradually over a 24-month period. This gives organizations time to prepare, but the clock is definitely ticking.  <\/p>\n<p>The four phases are as follows:<\/p>\n<ul>\n<li><strong>August 1, 2024:<\/strong> The EU AI Act formally enters into force. The text is binding, but most of the obligations do not yet apply. <\/li>\n<li><strong>February 2, 2025:<\/strong> The ban on AI applications that pose an unacceptable risk takes effect. These are the so-called prohibited practices listed in Article 5. <\/li>\n<li><strong>August 2, 2025:<\/strong> The requirements for providers of General-Purpose AI (GPAI) models take effect. These include large language models and other versatile AI systems. <\/li>\n<li><strong>August 2, 2026:<\/strong> The full set of regulations for high-risk AI systems takes effect. This is the strictest and most comprehensive category of requirements. <\/li>\n<\/ul>\n<p>For Dutch organizations, this means that by 2026, you will have already gone through the first two phases and will now be entering the third phase. The time to take action is now, not after the deadline. <\/p>\n<h2>What are the first requirements that will take effect as early as 2025?<\/h2>\n<p>Effective February 2, 2025, certain AI applications will be completely banned throughout the European Union. These are practices considered to pose an unacceptable risk and may no longer be used, developed, or marketed, effective immediately. <\/p>\n<p>Prohibited practices include, among others:<\/p>\n<ul>\n<li>Subliminal or manipulative techniques that influence behavior and cause harm without a person&#8217;s awareness<\/li>\n<li>Exploiting vulnerabilities based on age, disability, or socioeconomic status<\/li>\n<li>Social scoring by governments based on personal behavior<\/li>\n<li>Predictive policing based solely on profiling, without concrete evidence<\/li>\n<li>The creation of facial recognition databases through undirected scraping of the internet or security cameras<\/li>\n<li>Emotion recognition in the workplace or in educational institutions, excluding medical or safety applications<\/li>\n<li>Biometric categorization to infer sensitive characteristics such as race, political beliefs, or sexual orientation<\/li>\n<li>Real-time remote biometric identification in public spaces for law enforcement, except in strict cases<\/li>\n<\/ul>\n<p>Effective August 2, 2025, additional requirements will apply to providers of GPAI models. They must prepare technical documentation, inform downstream providers about the capabilities and limitations of their models, implement a policy to ensure compliance with copyright laws, and make a summary of the training data used publicly available. <\/p>\n<h2>Which AI systems fall into the high-risk category?<\/h2>\n<p>High-risk AI is defined in Article 6 of the EU AI Act and encompasses two types of systems. First: AI used as a safety component in products that are already subject to existing European harmonization legislation and for which a third-party conformity assessment is required. Second: AI systems deployed in one of the eight specific domains listed in Annex III of the Act.  <\/p>\n<p>Those eight areas are:<\/p>\n<ol>\n<li><strong>Biometrics<\/strong> (including emotion recognition and biometric categorization)<\/li>\n<li><strong>Critical infrastructure<\/strong> (energy, water, transportation, digital infrastructure)<\/li>\n<li><strong>Education and Vocational Training<\/strong> (Admission, Student Evaluation)<\/li>\n<li><strong>Employment and Human Resources Management<\/strong> (recruitment, performance evaluation, promotion)<\/li>\n<li><strong>Access to essential services<\/strong> (creditworthiness, insurance, emergency calls)<\/li>\n<li><strong>Law enforcement<\/strong> (risk assessments, evidence, investigations)<\/li>\n<li><strong>Migration and Border Control<\/strong><\/li>\n<li><strong>The Administration of Justice and Democratic Processes<\/strong><\/li>\n<\/ol>\n<p>Important to know: A system that performs only a limited procedural or preparatory task in one of these areas and does not pose a significant risk to fundamental rights may fall outside the high-risk category. However, the provider must provide substantiated documentation to support this. AI systems that profile natural persons are always high-risk, without exception.  <\/p>\n<h2>What is the deadline for high-risk AI systems?<\/h2>\n<p>The full requirements for high-risk AI systems will take effect on August 2, 2026. That is the deadline by which providers and users of high-risk AI must be in full compliance with all requirements of the EU AI Act. For organizations that are already working with these types of systems, preparation is therefore urgent.  <\/p>\n<p>The obligations for providers of high-risk AI are extensive:<\/p>\n<ul>\n<li>Establish a continuous risk management system throughout the system&#8217;s entire lifecycle<\/li>\n<li>Working with training, validation, and test data that are representative and as free of errors as possible<\/li>\n<li>Systematically investigate and mitigate potential bias<\/li>\n<li>Prepare technical documentation in accordance with Annex IV<\/li>\n<li>Enable automatic event logging<\/li>\n<li>Provide clear instructions to deployers<\/li>\n<li>Adopt a design that effectively enables human oversight<\/li>\n<li>Ensuring accuracy, robustness, and cybersecurity<\/li>\n<li>Arrange for a quality management system, a declaration of conformity, CE marking, and registration in the EU database<\/li>\n<\/ul>\n<p>Deployers\u2014the organizations that use high-risk AI under their own authority\u2014also have obligations. They must use the system in accordance with the user manual, assign human oversight to qualified individuals, retain logs for at least six months, inform employees before the system is put into use, and, where necessary, conduct a data protection impact assessment (DPIA). <\/p>\n<h2>What are the consequences of non-compliance with the EU AI Act?<\/h2>\n<p>Failure to comply with the EU AI Act may result in significant financial penalties. The fines are similar to those under the GDPR: they depend on the severity of the violation and the size of the organization. For the most serious violations, such as the use of prohibited AI practices, the maximum fines are set at the highest level.  <\/p>\n<p>In addition to financial penalties, there are also operational and reputational risks. A system that does not meet the requirements may be withdrawn from the market or prohibited from use. Furthermore, under Article 86, individuals affected by decisions made by high-risk AI systems may request an explanation of the factors that determined those decisions. This increases the legal vulnerability of organizations that do not operate transparently.   <\/p>\n<p>For Dutch organizations, regulators will also begin actively enforcing the law. The Dutch Data Protection Authority and other relevant agencies will play a role in overseeing compliance with the AI Act, in addition to the European AI Office, which oversees GPAI models. <\/p>\n<h2>How are Dutch organizations preparing for the AI Act?<\/h2>\n<p>Preparing for the EU AI Act begins with a clear inventory of all AI systems that your organization uses or offers. Next, for each system, you identify which risk category it falls into and what obligations result from that. This sounds straightforward, but in practice, it\u2019s a complex process for many organizations.  <\/p>\n<p>A practical approach consists of the following steps:<\/p>\n<ol>\n<li><strong>Identify<\/strong> all AI applications within your organization, including purchased software that contains AI components<\/li>\n<li><strong>Classify<\/strong> each system based on the risk categories specified in the AI Act<\/li>\n<li><strong>Determine your role<\/strong>: Are you a provider or a deployer? The obligations differ significantly <\/li>\n<li><strong>Prepare documentation in<\/strong> accordance with the requirements, including technical documentation and risk analyses<\/li>\n<li><strong>Set up processes<\/strong> for human oversight, logging, and incident reporting<\/li>\n<li><strong>Train employees<\/strong> who work with high-risk AI so that they understand their responsibilities<\/li>\n<li><strong>Stay up to date on the latest developments<\/strong>, as codes of conduct and harmonized standards are still being further developed<\/li>\n<\/ol>\n<p>For organizations that use AI in customer interactions or business processes, it\u2019s also wise to consider the broader governance framework surrounding AI. This includes aligning AI compliance with existing frameworks for information security and quality management. <\/p>\n<h2>How Pegamento Helps with AI Act Compliance<\/h2>\n<p>We understand that the EU AI Act raises many questions, especially if you\u2019re already using AI solutions for customer engagement or process automation. At Pegamento, we help Dutch organizations get started with AI in a responsible and compliant manner. Our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI for customer service<\/a> is built on a foundation of transparency, human oversight, and reliability. Agentic AI represents the evolution from traditional RPA bots to self-thinking assistants that not only follow instructions but also take the initiative and act independently within predefined parameters.   <\/p>\n<p>What we offer in the context of responsible AI use:<\/p>\n<ul>\n<li>A smart combination of proven modules that meet the requirements for transparency and human oversight<\/li>\n<li>Everything under one roof: from consulting and implementation to management and support, without complex supplier structures<\/li>\n<li>Solutions that align with our ISO 27001-certified approach to information security, supplemented by ISO 9001 and ISO 26000<\/li>\n<li>Guidance on setting up logging, user manuals, and human oversight in accordance with the requirements of the AI Act<\/li>\n<\/ul>\n<p>Would you like to know where your organization stands right now in light of the EU AI Act? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Please contact us<\/a>, and we\u2019d be happy to help you figure out the next step.<\/p>\n<div class=\"wp-block-seoaic-faq-block\">\n    <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n            <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Geldt de EU AI Act ook voor kleine en middelgrote ondernemingen (mkb)?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, de EU AI Act is van toepassing op alle organisaties die AI-systemen aanbieden of gebruiken binnen de EU, ongeacht hun omvang. Wel biedt de wet enkele verlichtingen voor mkb-bedrijven en startups, zoals verminderde kosten voor conformiteitsbeoordelingen en toegang tot regulatoire sandboxen om te experimenteren met AI onder begeleiding van toezichthouders. Dit neemt niet weg dat ook kleinere organisaties verplicht zijn om verboden AI-praktijken te vermijden en bij gebruik van hoog-risico AI te voldoen aan de relevante eisen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat als ik als organisatie gebruik maak van AI-software van een externe leverancier? Ben ik dan ook verantwoordelijk?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, als deployer \u2014 de partij die een AI-systeem onder eigen gezag inzet \u2014 draag je eigen verantwoordelijkheden onder de EU AI Act, ook als je de software niet zelf hebt ontwikkeld. Dit betekent dat je het systeem conform de gebruiksaanwijzing van de aanbieder moet inzetten, menselijk toezicht moet borgen en logs minimaal zes maanden moet bewaren. Het is daarom verstandig om bij inkoop van AI-software contractueel vast te leggen welke documentatie en ondersteuning de leverancier levert om jouw compliance te faciliteren.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe weet ik of mijn AI-systeem \u00e9cht buiten de hoog-risico categorie valt?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Dit is een van de meest praktische uitdagingen bij de implementatie van de AI Act. Een systeem valt buiten de hoog-risico categorie als het weliswaar in een van de acht Annex III-domeinen wordt ingezet, maar uitsluitend een beperkte procedurele of voorbereidende taak vervult zonder significant risico voor grondrechten. Cruciaal is dat je dit oordeel schriftelijk onderbouwt en documenteert \u2014 zonder die onderbouwing is de uitsluiting juridisch kwetsbaar. Bij twijfel is het raadzaam om juridisch of technisch advies in te winnen voordat je concludeert dat een systeem niet hoog-risico is.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat zijn de meest voorkomende fouten die organisaties maken bij de voorbereiding op de AI Act?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Een veelgemaakte fout is het onderschatten van de scope: veel organisaties realiseren zich niet hoeveel AI-componenten er al verwerkt zitten in standaardsoftware zoals HR-tools, CRM-systemen of klantenserviceplatformen. Daarnaast wachten veel organisaties te lang met de inventarisatie, waardoor er onvoldoende tijd overblijft voor het opstellen van de vereiste documentatie en het inrichten van processen v\u00f3\u00f3r de deadlines van 2025 en 2026. Een derde veelvoorkomende fout is het niet duidelijk vastleggen van rollen: wie is aanbieder en wie is deployer, en wat zijn de bijbehorende verantwoordelijkheden?            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe verhoudt de EU AI Act zich tot de AVG (GDPR) die we al kennen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De EU AI Act en de AVG vullen elkaar aan maar overlappen op bepaalde punten, met name rondom de verwerking van persoonsgegevens door AI-systemen. Zo is de verplichting voor deployers om een DPIA uit te voeren bij hoog-risico AI direct gekoppeld aan de AVG-verplichtingen. In de praktijk betekent dit dat AI-compliance en privacycompliance niet los van elkaar kunnen worden gezien en bij voorkeur ge\u00efntegreerd worden aangepakt binnen \u00e9\u00e9n governance-framework. Organisaties die al een volwassen AVG-proces hebben, kunnen dit als fundament gebruiken voor hun AI Act-voorbereiding.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Zijn er al offici\u00eble richtlijnen of normen beschikbaar om te helpen bij de implementatie?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De EU AI Act verwijst naar geharmoniseerde normen die nog worden ontwikkeld door Europese normalisatie-instellingen zoals CEN en CENELEC. Daarnaast werkt het Europese AI Office aan gedragscodes, met name voor aanbieders van GPAI-modellen. Op dit moment zijn er al wel praktische hulpmiddelen beschikbaar, zoals de AI Act Compliance Checker van de Europese Commissie en sectorspecifieke guidance vanuit toezichthouders. Het is belangrijk om deze ontwikkelingen actief bij te houden, omdat de nadere uitwerking van normen directe impact heeft op hoe je aan de verplichtingen kunt voldoen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat betekent &#039;menselijk toezicht&#039; concreet in de context van de AI Act, en hoe richt ik dit in?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Menselijk toezicht houdt in dat een bekwaam persoon de mogelijkheid heeft om het AI-systeem te begrijpen, te monitoren, te corrigeren of te stoppen wanneer dat nodig is \u2014 en dat dit ook daadwerkelijk in de praktijk wordt uitgeoefend, niet alleen op papier. Concreet betekent dit dat je medewerkers aanwijst die verantwoordelijk zijn voor het toezicht, hen traint zodat ze de werking en beperkingen van het systeem begrijpen, en procedures inricht voor het escaleren of ingrijpen bij afwijkende uitkomsten. Voor AI-systemen in klantcontact of besluitvorming is het ook belangrijk dat de toezichthouder niet alleen bevoegd is om in te grijpen, maar ook de tijd en middelen heeft om dit effectief te doen.            <\/p>\n        <\/div>\n        <\/div>\n","protected":false},"excerpt":{"rendered":"<p>The EU AI Act has four key deadlines\u2014do you know which requirements already apply to your organization?<\/p>\n","protected":false},"author":2,"featured_media":33178,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-33177","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=33177"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33177\/revisions"}],"predecessor-version":[{"id":33180,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33177\/revisions\/33180"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/33178"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=33177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=33177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=33177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}