What applies, when, and to whom

EU AI Act: what applies, when it starts and what to do now

The EU AI Act works with risk classes and came into force in phases. Part of it has applied since 2025; the heaviest obligations shifted to 2027 and 2028. Below: the timeline, the four categories, the sanctions, and what is worth doing now regardless of any deadline.

Plan an introduction

In short

What the EU AI Act is

The EU AI Act, formally Regulation (EU) 2024/1689, is the world's first broad law setting rules for developing and using artificial intelligence. It works with risk classes: the greater an application's risk to people, the heavier the requirements. It applies directly across all EU member states and affects not only those building AI but also organisations deploying it. In late July 2026 the regulation was amended on several points by the Digital Omnibus, Regulation (EU) 2026/1744. For most Dutch organisations their use falls into the lighter categories, where transparency and AI literacy are what matter.

This page describes the main lines and the dates, and was updated on 19 August 2026 with the changes from the Digital Omnibus. It does not replace legal advice, and the timeline has been adjusted several times in recent years.

What's actually changing

What already applies

The prohibited practices and the AI literacy requirements in Article 4 have applied since February 2025. The Article 50 transparency duty has applied since 2 August 2026: people must know when they are dealing with AI. That part was not postponed.

What was postponed

The strictest obligations, for so-called high-risk systems, were shifted in late July 2026 by the Digital Omnibus (Regulation (EU) 2026/1744): to 2 December 2027 for stand-alone systems, and 2 August 2028 for systems embedded in other products. High-risk systems already in use before August 2026 keep their original deadline of end-2030.

Why a postponement isn't an exemption

A later legal deadline doesn't change the risk of unclear AI use. That problem exists now, regardless of the law.

Why the date matters less each time

This is already the latest in a series of shifts. A policy built around a deadline has to be rebuilt every time it moves. A policy built on principles doesn't.

The timeline

What applied when

The law came into force in phases. These are the moments that matter for organisations using AI.

02.2025

Prohibited practices and AI literacy

Since February 2025 a number of applications are banned outright, including social scoring and certain forms of emotion recognition in the workplace. From that same moment Article 4 applies: organisations must ensure employees working with AI understand enough about what they use. In late July 2026 the Digital Omnibus softened that wording into an obligation of effort: you take measures that support AI literacy, but you need not guarantee a specific level of knowledge per person.

08.2025

Rules for general-purpose AI models

From August 2025 obligations apply to providers of general-purpose AI models, the models behind tools like ChatGPT and Claude. The supervisory framework also took effect: member states designate their authorities and the sanctions framework becomes applicable.

08.2026

The transparency duty starts

Since 2 August 2026 the Article 50 transparency duty applies: people must know when they are talking to an AI system, and artificially generated images, video, audio and text must be marked in a machine-readable way. This is the part most concrete for most organisations. Anyone who already offered systems generating synthetic content before August 2026 has until 2 December 2026 to meet that marking requirement.

12.2026

Two new bans, and the marking deadline

From 2 December 2026 two further practices are prohibited: AI generating realistic intimate imagery of identifiable people without explicit consent, and AI generating child sexual abuse material. That ban applies to providers and users alike. The same date ends the transition period for marking synthetic content produced by systems that already existed before August 2026.

2027-2028

High-risk obligations

The heaviest requirements, for high-risk systems, were shifted by the Digital Omnibus (Regulation (EU) 2026/1744) to 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in other products. Systems already in use before August 2026 keep their original deadline of end-2030.

The risk classes

Four categories, increasing in weight

Unacceptable

Prohibited

Applications seen as too great a risk to fundamental rights, such as social scoring and certain forms of biometric categorisation. The social scoring ban is aimed primarily at public authorities, but private parties are not exempt: they too may not use scoring systems that lead to unjustified detrimental treatment in a context unrelated to the original data. These bans have applied since February 2025. Two more arrive on 2 December 2026: AI generating realistic intimate imagery of identifiable people without consent, and AI generating child sexual abuse material.

High risk

Heavy requirements on documentation and oversight

AI in areas like recruitment, credit scoring, education or critical infrastructure. Requirements cover risk management, data quality, human oversight and logging. This is the category whose deadline shifted to 2027 and 2028.

Limited risk

Transparency required

Chatbots, AI-generated images and text. The requirement is that it is clear AI is involved, and that generated content is marked in a machine-readable way. Most everyday business use sits here, and it has applied since 2 August 2026. For systems that were already producing synthetic content before that date, the marking deadline runs to 2 December 2026.

Minimal risk

No additional requirements

Spam filters, webshop recommendations, AI in a planning tool. By far the largest share of applications sits here, and the law adds no requirements beyond what already applied.

When this isn't your first priority yet

  • Barely using AI yet, or is a legal department already leading this? Then this isn't what we'd tackle first.

We don't ask organisations to do anything we don't do ourselves.

Our own AI policy is public on this site

Curious what such a policy looks like in practice? Read our AI policy

Frequently asked questions

01 Does the postponement mean we can wait? +

No. The part that already applies — transparency, AI literacy — wasn't postponed, and the deadline for the rest has already shifted once. Build the policy now, independent of the date.

02 Is an AI policy mandatory? +

The EU AI Act sets requirements for how organisations use AI, depending on the application. A clear policy is the basis for meeting that, and more importantly: it gives your people clarity on what's allowed.

03 What's the difference with an AI strategy? +

Strategy determines what you focus on and in what order; policy determines within which boundaries that happens safely. They reinforce each other and are often picked up together.

04 Does the AI Act apply if we only use American tools? +

Yes. The law looks not at where the supplier sits but at where the system is used and who the outcome affects. Deploy an American tool for people in the EU and the obligations apply to you as the deploying organisation. The supplier has its own obligations on top, but those do not remove yours.

05 What's the difference between provider and deployer? +

The provider develops an AI system or places it on the market under its own name. The deployer uses it inside their own organisation. Most Dutch organisations are the latter, with lighter obligations. Note: build something on top of an existing model and put it out under your own name, and you may be classed as a provider.

06 How do we know if our system is high risk? +

The law works with a list of application areas, not a case-by-case judgement. Think recruitment, access to education, credit scoring, and AI as a safety component in products. If your application is not on that list, high risk is unlikely to apply. If you are unsure, that is exactly the moment to have it reviewed legally.

07 Do we have to label AI-generated content? +

For content that could be taken as genuine, such as generated images and video, a transparency obligation applies. It must also be clear when someone is talking to a chatbot rather than a person. For text an employee drafted with AI and then edited themselves, it is more nuanced. An internal agreement on this prevents most of the debate.

08 Does software we have used for years fall under it too? +

That depends on what is inside it. Many existing packages have gained AI features in recent years without much announcement. When taking stock it is worth looking not only at new tools but also at what has been added to existing systems.

09 What are the fines for non-compliance? +

The law has a tiered sanctions regime (Article 99). For prohibited practices fines run up to 35 million euro or 7 percent of global annual turnover, for most other breaches up to 15 million or 3 percent, and for supplying incorrect information up to 7.5 million or 1 percent. One detail that matters for smaller companies: for large undertakings the higher of the two applies, but for small and medium-sized businesses and start-ups it is the lower. For most organisations this is not the most urgent point anyway, because their use falls in the lighter categories.

10 Who supervises this in the Netherlands? +

The Dutch government has opted for a model in which existing regulators each supervise AI within their own domain, with a coordinating role for the Data Protection Authority and the Digital Infrastructure Inspectorate. The DPA also gets its own AI directorate for areas without a clear regulator. Note: this is set out in the AI Regulation Implementation Act, which is still a bill. Public consultation ran until June 2026; at the time of writing the act is not yet in force.

11 What is best to do right now? +

Three things, none of which depends on a deadline. Map which AI is used in the organisation, including what people started using on their own. Set out which tools are allowed and what data may go into them. And make sure people working with AI understand what they use, which has been an obligation since February 2025.

More on AI literacy and Article 4

Policy your people will actually use?

We'll look together at what's already there and what's needed.

See how we build an AI policy