All questions

Does the EU AI Act apply to my company and what must I do?

Freelance & BusinessLegislation verified on Ook in het Nederlands

The EU AI Act is an EU regulation (Regulation (EU) 2024/1689), not a Dutch national statute, so it is not in the BWB database searched by the legal-research tools available to me in this session. The web-search tool likewise returned no usable hits when I queried the AI Act's scope, timeline, GPAI rules and high-risk obligations. The article below is therefore written from the publicly available text of the regulation; the article numbers cited are accurate to that public text, but I could not obtain source URLs from the tools to attach to each citation.


Short answer. Yes, in most cases the EU AI Act (Regulation (EU) 2024/1689) applies to your company if it develops, places on the market, imports, distributes or professionally uses an AI system whose effect is felt in the EU — including the Netherlands. Your concrete obligations depend on (i) your role — provider, deployer, importer or distributor — and (ii) the risk class of the AI system or model you handle. Several core obligations (the AI-literacy duty and the prohibitions) already apply from 2 February 2025; GPAI-model rules apply from 2 August 2025; the bulk of the obligations, including the high-risk regime, apply from 2 August 2026.

1. Does the AI Act reach your company at all?

Under article 2 AI Act the regulation applies to:

  1. Providers that place an AI system on the EU market or put it into service in the EU, regardless of where the provider is established;
  2. Deployers of AI systems located in the EU;
  3. Providers and deployers in third countries when the output of the AI system is used in the EU;
  4. Importers and distributors of AI systems on the EU market.

This means:

  • A Dutch BV that buys a third-party AI HR tool and uses it on staff → in scope as a deployer.
  • A US startup selling a CV-screening AI to Dutch employers → in scope as a provider.
  • A Dutch retailer that only uses a free consumer chatbot for personal reasons outside work → out of scope.

The AI Act does not apply (art. 2(2)-(3)) to:

  • AI systems developed or used exclusively for scientific R&D before any market release;
  • AI systems for military, defence or national-security purposes;
  • Free and open-source AI components, except GPAI models with systemic risk (art. 2(4)-(5));
  • Public authorities in a third-country law-enforcement or judicial-cooperation context with an EU member state.

2. What role do you play?

Article 3 defines the four roles and is the first thing to determine, because obligations differ:

RoleDefinition (art. 3 AI Act)
ProviderDevelops (or has developed) an AI system and places it on the market or puts it into service under its own name/brand. A product manufacturer that embeds an AI system in a product is also a provider.
DeployerNatural or legal person using an AI system under its authority in a professional capacity (e.g. an employer using AI in recruitment).
ImporterPlaces on the EU market an AI system bearing the name or trademark of a third-country person.
DistributorMakes an AI system available on the EU market, other than as provider or importer.

If you only use AI, you are a deployer (lighter obligations). If you build, substantially modify, or rebrand AI and put it on the market, you are a provider (heaviest obligations). Substantial modification that changes the system's purpose or risk profile can turn a deployer into a provider (art. 25).

3. The four risk tiers

The AI Act works as a risk pyramid (art. 5, 6, 50; Annexes I and III):

a. Unacceptable risk — PROHIBITED (art. 5). Already in force from 2 February 2025. You may not place on the market, put into service, or use AI systems that:

  • use subliminal techniques or manipulative/deceptive methods materially distorting behaviour and causing significant harm;
  • exploit vulnerabilities of persons (age, disability, social/economic situation);
  • are used by public authorities for social scoring leading to detrimental treatment;
  • perform real-time remote biometric identification in publicly accessible spaces for law enforcement (narrow exceptions for victims, imminent threats, etc.);
  • predict criminal recidivism solely on profiling or personality traits;
  • scrape facial images from the internet or CCTV to build untargeted facial-recognition databases;
  • infer emotions in workplaces or educational institutions (with medical/safety exceptions);
  • biometrically categorise individuals to deduce race, political opinions, etc. (limited exceptions).

b. High risk (art. 6 + Annex I & III). Two routes into high-risk:

  1. The AI is a safety component of — or itself is — a product covered by EU product-safety legislation listed in Annex I (toys, machinery, medical devices, in-vitro diagnostics, vehicles, aviation, etc.).
  2. The AI is used in one of the Annex III areas: biometric identification; critical infrastructure; education and vocational training; employment, workers' management and self-employment; access to essential private and public services (credit scoring, insurance pricing, emergency dispatch, public-benefit eligibility); law enforcement; migration, asylum and border control; administration of justice and democratic processes.

Provider obligations (high-risk): art. 8-17 and 43-49 — risk-management system (art. 9); data governance (art. 10); technical documentation per Annex IV (art. 11); automatic logging (art. 12); transparency and instructions to deployers (art. 13); human oversight (art. 14); accuracy, robustness and cybersecurity (art. 15); conformity assessment (art. 43); CE marking and EU declaration of conformity (art. 48); registration in the EU database (art. 49 + art. 71).

Deployer obligations (high-risk): art. 26-27 — use the system in line with the provider's instructions; assign human oversight to competent staff; ensure input data is relevant and representative; monitor operation and inform provider and competent authority of serious incidents or risk of harm. Article 27 imposes a fundamental-rights impact assessment (FRIA) on deployers of certain Annex III systems (public authorities, banks, insurers, employers, etc.) before first use. Under art. 26(11), deployers of high-risk systems that take decisions affecting individuals must inform those individuals.

c. Limited risk — transparency (art. 50). From 2 August 2026 you must:

  • Inform users that they are interacting with an AI system (chatbots, virtual assistants);
  • Inform individuals exposed to emotion-recognition or biometric-categorisation systems;
  • Label AI-generated content as such (deepfakes, art. 50(4));
  • Mark machine-readable AI-generated text.

d. Minimal risk. Spam filters, AI in video games, basic inventory optimisers, etc. No AI Act-specific obligations. But the AI-literacy obligation in art. 4 — already in force from 2 February 2025 — applies to all providers and deployers: ensure your staff and other persons handling the operation and use of AI have a sufficient level of AI literacy, taking into account their role and the system's risk.

4. General-purpose AI (GPAI) models — a parallel regime

From 2 August 2025, providers of GPAI models must (art. 53):

  • Maintain technical documentation per Annex XI;
  • Provide a publicly available summary of the training data per Annex XII;
  • Put in place a copyright-compliance policy, in particular respecting text-and-data-mining opt-outs (art. 53(1)(c)).

GPAI models classified as posing systemic risk — either by exceeding the 10²⁵ FLOPs training-compute threshold or by being so designated by the European Commission (art. 51) — face additional obligations (art. 55): state-of-the-art model evaluations and adversarial testing; systemic-risk assessment and mitigation; serious-incident reporting; cybersecurity protection.

If you fine-tune, modify or integrate a GPAI model into your own AI system in a way that changes its purpose or risk profile, you may become a provider of that new AI system.

5. When does each obligation kick in? (art. 113)

DateProvisions that apply
2 February 2025Chapter I (art. 1-5), art. 4 (AI literacy), prohibitions in art. 5, designated national competent authorities
2 August 2025Chapter V GPAI rules (art. 51-56), governance (Chapter VII Section 1 — AI Office, AI Board), confidentiality (art. 78), penalties (art. 99)
2 August 2026Most remaining provisions, including high-risk AI in Annex III, transparency (art. 50), full applicability of the regulation
2 August 2027High-risk AI systems covered by Annex I product-safety legislation

6. Penalties (art. 99)

EU-level fines of up to:

  • €35 million or 7 % of worldwide annual turnover (whichever is higher) — breach of prohibited AI (art. 5);
  • €15 million or 3 % — breach of other obligations (e.g. high-risk requirements, GPAI rules, transparency);
  • €7.5 million or 1 % — supplying incorrect, incomplete or misleading information to authorities.

For SMEs and start-ups, the lower of the two amounts applies (art. 99(6)). Member states may add national penalties for misuse of AI to the detriment of natural persons.

7. What you should do now — a checklist

  1. Identify your role (provider / deployer / importer / distributor) — art. 3.
  2. Map your AI inventory. Which systems do you develop, buy, integrate, fine-tune, or use? Classify each as prohibited, high-risk, GPAI, transparency-sensitive, or minimal-risk.
  3. Check exemptions under art. 2(2)-(3).
  4. If you have any art. 5 use-case: stop it. The prohibition is already binding.
  5. Train your staff. The art. 4 AI-literacy duty is already binding.
  6. For high-risk systems: prepare technical documentation (Annex IV), the conformity assessment (art. 43), CE marking (art. 48) and EU database registration (art. 49); if you are an Annex III deployer, prepare the FRIA (art. 27) and the individual information duty (art. 26(11)).
  7. For GPAI models: prepare technical documentation (Annex XI), training-data summary (Annex XII), and copyright policy (art. 53(1)(c)).
  8. For transparency-sensitive AI (chatbots, deepfakes, etc.): prepare user-facing disclosures for 2 August 2026.
  9. Watch the Dutch national layer. The Netherlands is preparing an Implementatiewet EU AI Act to designate national competent authorities and to set any additional national rules. Monitor the Autoriteit Persoonsgegevens (AP), which has been designated as the Dutch AI Act coordinating authority, and sector supervisors such as the AFM (financial services) and IGJ (medical devices).
  10. Mind the overlap with other law. The AI Act sits alongside the GDPR (AVG in Dutch), the Product Liability Directive (EU) 2024/2853, the Digital Services Act, sector regulation (medical devices, financial services) and the Dutch implementing law. Where they overlap — for example profiling and automated decisions (art. 22 AVG) — both regimes apply.

8. Typical cases and main exceptions

  • Typical in-scope case: a Dutch employer (deployer) using a vendor-provided AI CV-screening tool for recruitment → Annex III high-risk → provider obligations and deployer obligations (art. 26-27), plus FRIA.
  • Typical in-scope case: a Dutch software BV (provider) placing its own chatbot on the market → transparency obligation (art. 50) from August 2026.
  • Typical in-scope case: a Dutch foundation that fine-tunes an open-source LLM and exposes it via API → likely a GPAI provider, possibly systemic-risk GPAI depending on compute.
  • Main exception: purely scientific R&D before market release (art. 2(2)).
  • Main exception: free and open-source non-systemic-risk GPAI components, except where used in a high-risk system (art. 2(4)-(5)).
  • Main exception: national-security use (art. 2(3)).
  • Main SME relief: art. 11 and recital 77 — documentation proportionate to size, priority access to regulatory sandboxes, fee reductions — but obligations are not waived.

Disclaimer. This is general information, not legal advice. Whether the AI Act applies to a specific AI system and which obligations it triggers depends on facts that only you can determine. For a binding assessment, consult a qualified EU/Dutch lawyer and the relevant competent authority.

Sources relied on. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 12 July 2024 — articles 1-5, 8-17, 25-27, 43-49, 50, 51-56, 71, 78, 99, 113, and Annexes I, III, IV, XI, XII. (As noted above, the EU AI Act is not part of the Dutch BWB database searched by the tools in this session, and the web searches returned no usable hits, so the citations are to the public regulation text rather than to a tool-returned source URL.)