{"id":33177,"date":"2026-07-29T08:00:00","date_gmt":"2026-07-29T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/when-will-the-eu-ai-act-take-effect-and-what-are-the-key-deadlines\/"},"modified":"2026-07-29T10:01:10","modified_gmt":"2026-07-29T08:01:10","slug":"when-will-the-eu-ai-act-take-effect-and-what-are-the-key-deadlines","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/when-will-the-eu-ai-act-take-effect-and-what-are-the-key-deadlines\/","title":{"rendered":"When will the EU AI Act take effect, and what are the key deadlines?"},"content":{"rendered":"<p>The EU AI Act has entered into force in phases: the regulation officially took effect on August 1, 2024, but not all of its requirements apply at the same time. Depending on the type of AI system, different deadlines apply, spread out over a two-year period. If you\u2019re a Dutch organization working with AI, it\u2019s important to know which rules are already in effect and which ones are still to come. In this article, we answer the most frequently asked questions about the <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">EU AI Act<\/a> and its timeline.   <\/p>\n<h2>What are the phases involved in the implementation of the EU AI Act?<\/h2>\n<p>The EU AI Act follows a phased implementation schedule with four key milestones. The law took effect on August 1, 2024, but the specific obligations will come into force gradually over a 24-month period. This gives organizations time to prepare, but the clock is definitely ticking.  <\/p>\n<p>The four phases are as follows:<\/p>\n<ul>\n<li><strong>August 1, 2024:<\/strong> The EU AI Act formally enters into force. The text is binding, but most of the obligations do not yet apply. <\/li>\n<li><strong>February 2, 2025:<\/strong> The ban on AI applications that pose an unacceptable risk takes effect. These are the so-called prohibited practices listed in Article 5. <\/li>\n<li><strong>August 2, 2025:<\/strong> The requirements for providers of General-Purpose AI (GPAI) models take effect. These include large language models and other versatile AI systems. <\/li>\n<li><strong>August 2, 2026:<\/strong> The full set of regulations for high-risk AI systems takes effect. This is the strictest and most comprehensive category of requirements. <\/li>\n<\/ul>\n<p>For Dutch organizations, this means that by 2026, you will have already gone through the first two phases and will now be entering the third phase. The time to take action is now, not after the deadline. <\/p>\n<h2>What are the first requirements that will take effect as early as 2025?<\/h2>\n<p>Effective February 2, 2025, certain AI applications will be completely banned throughout the European Union. These are practices considered to pose an unacceptable risk and may no longer be used, developed, or marketed, effective immediately. <\/p>\n<p>Prohibited practices include, among others:<\/p>\n<ul>\n<li>Subliminal or manipulative techniques that influence behavior and cause harm without a person&#8217;s awareness<\/li>\n<li>Exploiting vulnerabilities based on age, disability, or socioeconomic status<\/li>\n<li>Social scoring by governments based on personal behavior<\/li>\n<li>Predictive policing based solely on profiling, without concrete evidence<\/li>\n<li>The creation of facial recognition databases through undirected scraping of the internet or security cameras<\/li>\n<li>Emotion recognition in the workplace or in educational institutions, excluding medical or safety applications<\/li>\n<li>Biometric categorization to infer sensitive characteristics such as race, political beliefs, or sexual orientation<\/li>\n<li>Real-time remote biometric identification in public spaces for law enforcement, except in strict cases<\/li>\n<\/ul>\n<p>Effective August 2, 2025, additional requirements will apply to providers of GPAI models. They must prepare technical documentation, inform downstream providers about the capabilities and limitations of their models, implement a policy to ensure compliance with copyright laws, and make a summary of the training data used publicly available. <\/p>\n<h2>Which AI systems fall into the high-risk category?<\/h2>\n<p>High-risk AI is defined in Article 6 of the EU AI Act and encompasses two types of systems. First: AI used as a safety component in products that are already subject to existing European harmonization legislation and for which a third-party conformity assessment is required. Second: AI systems deployed in one of the eight specific domains listed in Annex III of the Act.  <\/p>\n<p>Those eight areas are:<\/p>\n<ol>\n<li><strong>Biometrics<\/strong> (including emotion recognition and biometric categorization)<\/li>\n<li><strong>Critical infrastructure<\/strong> (energy, water, transportation, digital infrastructure)<\/li>\n<li><strong>Education and Vocational Training<\/strong> (Admission, Student Evaluation)<\/li>\n<li><strong>Employment and Human Resources Management<\/strong> (recruitment, performance evaluation, promotion)<\/li>\n<li><strong>Access to essential services<\/strong> (creditworthiness, insurance, emergency calls)<\/li>\n<li><strong>Law enforcement<\/strong> (risk assessments, evidence, investigations)<\/li>\n<li><strong>Migration and Border Control<\/strong><\/li>\n<li><strong>The Administration of Justice and Democratic Processes<\/strong><\/li>\n<\/ol>\n<p>Important to know: A system that performs only a limited procedural or preparatory task in one of these areas and does not pose a significant risk to fundamental rights may fall outside the high-risk category. However, the provider must provide substantiated documentation to support this. AI systems that profile natural persons are always high-risk, without exception.  <\/p>\n<h2>What is the deadline for high-risk AI systems?<\/h2>\n<p>The full requirements for high-risk AI systems will take effect on August 2, 2026. That is the deadline by which providers and users of high-risk AI must be in full compliance with all requirements of the EU AI Act. For organizations that are already working with these types of systems, preparation is therefore urgent.  <\/p>\n<p>The obligations for providers of high-risk AI are extensive:<\/p>\n<ul>\n<li>Establish a continuous risk management system throughout the system&#8217;s entire lifecycle<\/li>\n<li>Working with training, validation, and test data that are representative and as free of errors as possible<\/li>\n<li>Systematically investigate and mitigate potential bias<\/li>\n<li>Prepare technical documentation in accordance with Annex IV<\/li>\n<li>Enable automatic event logging<\/li>\n<li>Provide clear instructions to deployers<\/li>\n<li>Adopt a design that effectively enables human oversight<\/li>\n<li>Ensuring accuracy, robustness, and cybersecurity<\/li>\n<li>Arrange for a quality management system, a declaration of conformity, CE marking, and registration in the EU database<\/li>\n<\/ul>\n<p>Deployers\u2014the organizations that use high-risk AI under their own authority\u2014also have obligations. They must use the system in accordance with the user manual, assign human oversight to qualified individuals, retain logs for at least six months, inform employees before the system is put into use, and, where necessary, conduct a data protection impact assessment (DPIA). <\/p>\n<h2>What are the consequences of non-compliance with the EU AI Act?<\/h2>\n<p>Failure to comply with the EU AI Act may result in significant financial penalties. The fines are similar to those under the GDPR: they depend on the severity of the violation and the size of the organization. For the most serious violations, such as the use of prohibited AI practices, the maximum fines are set at the highest level.  <\/p>\n<p>In addition to financial penalties, there are also operational and reputational risks. A system that does not meet the requirements may be withdrawn from the market or prohibited from use. Furthermore, under Article 86, individuals affected by decisions made by high-risk AI systems may request an explanation of the factors that determined those decisions. This increases the legal vulnerability of organizations that do not operate transparently.   <\/p>\n<p>For Dutch organizations, regulators will also begin actively enforcing the law. The Dutch Data Protection Authority and other relevant agencies will play a role in overseeing compliance with the AI Act, in addition to the European AI Office, which oversees GPAI models. <\/p>\n<h2>How are Dutch organizations preparing for the AI Act?<\/h2>\n<p>Preparing for the EU AI Act begins with a clear inventory of all AI systems that your organization uses or offers. Next, for each system, you identify which risk category it falls into and what obligations result from that. This sounds straightforward, but in practice, it\u2019s a complex process for many organizations.  <\/p>\n<p>A practical approach consists of the following steps:<\/p>\n<ol>\n<li><strong>Identify<\/strong> all AI applications within your organization, including purchased software that contains AI components<\/li>\n<li><strong>Classify<\/strong> each system based on the risk categories specified in the AI Act<\/li>\n<li><strong>Determine your role<\/strong>: Are you a provider or a deployer? The obligations differ significantly <\/li>\n<li><strong>Prepare documentation in<\/strong> accordance with the requirements, including technical documentation and risk analyses<\/li>\n<li><strong>Set up processes<\/strong> for human oversight, logging, and incident reporting<\/li>\n<li><strong>Train employees<\/strong> who work with high-risk AI so that they understand their responsibilities<\/li>\n<li><strong>Stay up to date on the latest developments<\/strong>, as codes of conduct and harmonized standards are still being further developed<\/li>\n<\/ol>\n<p>For organizations that use AI in customer interactions or business processes, it\u2019s also wise to consider the broader governance framework surrounding AI. This includes aligning AI compliance with existing frameworks for information security and quality management. <\/p>\n<h2>How Pegamento Helps with AI Act Compliance<\/h2>\n<p>We understand that the EU AI Act raises many questions, especially if you\u2019re already using AI solutions for customer engagement or process automation. At Pegamento, we help Dutch organizations get started with AI in a responsible and compliant manner. Our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI for customer service<\/a> is built on a foundation of transparency, human oversight, and reliability. Agentic AI represents the evolution from traditional RPA bots to self-thinking assistants that not only follow instructions but also take the initiative and act independently within predefined parameters.   <\/p>\n<p>What we offer in the context of responsible AI use:<\/p>\n<ul>\n<li>A smart combination of proven modules that meet the requirements for transparency and human oversight<\/li>\n<li>Everything under one roof: from consulting and implementation to management and support, without complex supplier structures<\/li>\n<li>Solutions that align with our ISO 27001-certified approach to information security, supplemented by ISO 9001 and ISO 26000<\/li>\n<li>Guidance on setting up logging, user manuals, and human oversight in accordance with the requirements of the AI Act<\/li>\n<\/ul>\n<p>Would you like to know where your organization stands right now in light of the EU AI Act? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Please contact us<\/a>, and we\u2019d be happy to help you figure out the next step.<\/p>\n        <div class=\"wp-block-seoaic-faq-block\">\n            <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n                            <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Does the EU AI Act also apply to small and medium-sized enterprises (SMEs)?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, the EU AI Act applies to all organizations that offer or use AI systems within the EU, regardless of their size. However, the law does provide some relief for SMEs and startups, such as reduced costs for compliance assessments and access to regulatory sandboxes to experiment with AI under the guidance of regulators. Nevertheless, even smaller organizations are required to avoid prohibited AI practices and, when using high-risk AI, to comply with the relevant requirements.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What if my organization uses AI software from a third-party vendor? Am I still responsible?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, as a deployer\u2014the party that deploys an AI system under its own authority\u2014you have your own responsibilities under the EU AI Act, even if you did not develop the software yourself. This means you must deploy the system in accordance with the provider\u2019s instructions, ensure human oversight, and retain logs for at least six months. It is therefore advisable to specify in the contract when purchasing AI software what documentation and support the supplier will provide to facilitate your compliance.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I know if my AI system truly falls outside the high-risk category?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        This is one of the most practical challenges in implementing the AI Act. A system falls outside the high-risk category if, although it is used in one of the eight Annex III domains, it performs only a limited procedural or preparatory task without posing a significant risk to fundamental rights. It is crucial that you substantiate and document this assessment in writing\u2014without that substantiation, the exclusion is legally vulnerable. When in doubt, it is advisable to seek legal or technical advice before concluding that a system is not high-risk.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What are the most common mistakes organizations make when preparing for the AI Act?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        A common mistake is underestimating the scope: many organizations do not realize how many AI components are already embedded in standard software such as HR tools, CRM systems, or customer service platforms. In addition, many organizations wait too long to conduct an inventory, leaving insufficient time to prepare the required documentation and set up processes before the 2025 and 2026 deadlines. A third common mistake is failing to clearly define roles: who is the provider and who is the deployer, and what are their respective responsibilities?                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How does the EU AI Act relate to the GDPR (General Data Protection Regulation) we are already familiar with?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The EU AI Act and the GDPR complement each other but overlap in certain areas, particularly regarding the processing of personal data by AI systems. For example, the requirement for deployers to conduct a DPIA for high-risk AI is directly linked to GDPR obligations. In practice, this means that AI compliance and privacy compliance cannot be viewed separately and should preferably be addressed in an integrated manner within a single governance framework. Organizations that already have a mature GDPR process in place can use this as a foundation for their AI Act preparations.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Are there any official guidelines or standards available to assist with implementation?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The EU AI Act refers to harmonized standards that are still being developed by European standardization bodies such as CEN and CENELEC. In addition, the European AI Office is working on codes of conduct, particularly for providers of GPAI models. However, practical tools are already available, such as the European Commission\u2019s AI Act Compliance Checker and sector-specific guidance from regulators. It\u2019s important to actively monitor these developments, as the further elaboration of standards will directly impact how you can comply with the requirements.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What does &#039;human oversight&#039; mean in concrete terms in the context of the AI Act, and how do I implement it?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Human oversight means that a qualified person has the ability to understand, monitor, correct, or stop the AI system when necessary\u2014and that this is actually carried out in practice, not just on paper. In practice, this means designating employees who are responsible for oversight, training them so they understand the system\u2019s operation and limitations, and establishing procedures for escalating or intervening in the event of unexpected outcomes. For AI systems used in customer interactions or decision-making, it is also important that the supervisor not only has the authority to intervene but also has the time and resources to do so effectively.                    <\/p>\n                <\/div>\n                        <\/div>\n        ","protected":false},"excerpt":{"rendered":"<p>The EU AI Act has four key deadlines\u2014do you know which requirements already apply to your organization?<\/p>\n","protected":false},"author":2,"featured_media":33178,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-33177","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=33177"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33177\/revisions"}],"predecessor-version":[{"id":33180,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/33177\/revisions\/33180"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/33178"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=33177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=33177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=33177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}