EU AI Act: Everything You Need to Know About the AI Regulation
The EU AI Act is the world's first horizontal law on artificial intelligence. Discover what the legal framework and phased timeline mean for the use of AI within your organization.
Regulation (EU) 2024/1689, better known as the EU AI Act or AI Regulation, establishes a historic framework. As the first in the world, the European Union introduces horizontal AI legislation. The law was officially adopted by the Council and the European Parliament, signed on 13 June 2024, and finally published in the Official Journal of the EU on 12 July 2024.
With its entry into force on 1 August 2024, a phased rollout has started. This means that organizations will gradually face new rules in the coming years. Because this law is extraterritorial, providers from outside the EU also fall under this legislation when their AI output is used within the borders of the EU, similar to the scope of the GDPR.
For Dutch institutions, it is crucial to comply with these requirements in time to avoid hefty sanctions. Curious about what this means for your implementation strategy? Discover the possibilities via AI Consultancy on ai.nl.
What is the EU AI Act (Regulation 2024/1689)?
The EU AI Act, officially Regulation (EU) 2024/1689, is the first horizontal legislation in the world specifically designed to ensure safe, transparent and accountable development and deployment of AI systems. After approval by the Council and the EP, the document was signed on 13 June 2024 and published in the Official Journal of the EU on 12 July 2024.
Update July 2026: what the Digital Omnibus changes
On 24 July 2026, the Digital Omnibus on AI was published in the Official Journal of the EU: Regulation (EU) 2026/1744, in force since 27 July 2026. This regulation amends the AI Act itself and moves a number of deadlines that were originally set for 2 August 2026.
The essence in three points:
- High-risk AI has been postponed. The obligations for stand-alone high-risk systems under Annex III will only apply on 2 December 2027 instead of 2 August 2026. For high-risk AI that is a safety component in regulated products (Annex I), the date moves from 2 August 2027 to 2 August 2028.
- Transparency has not been postponed. The obligations of Article 50 apply from 2 August 2026. For labelling synthetic content (Art. 50(2)), a transition period until 2 December 2026 applies to systems placed on the market before 2 August 2026; anything placed on the market after that must comply immediately.
- New prohibitions are added. Article 5 is extended with a prohibition on AI systems that generate non-consensual intimate images (NCII) or child sexual abuse material (CSAM), with a transition period until 2 December 2026. Providers of image and video generators must assess the risk of foreseeable misuse.
In addition, the AI literacy obligation of Article 4 has been relaxed: providers and deployers must support the development of AI literacy among their staff, instead of guaranteeing a certain level. The deadline for setting up national AI regulatory sandboxes moves from 2 August 2026 to 2 August 2027.
What does this mean in practice? Postponement is not cancellation. The substantive requirements for high-risk AI remain in place; you simply get more time for them. What you must arrange now is transparency — do your users know they are communicating with AI, and is AI-generated content recognisable? — plus ruling out prohibited practices.
Timeline with exact dates (updated after the Digital Omnibus)
The law formally entered into force on 1 August 2024 (20 days after publication). Since then a phased timeline has been running, which has been amended in parts by Regulation (EU) 2026/1744:
- 2 February 2025: the general provisions, definitions, the AI literacy obligation (Art. 4, since relaxed) and the prohibition of prohibited AI practices (Art. 5) apply.
- 2 August 2025: the rules for general-purpose AI (GPAI) models, the governance structures and the sanction rules apply from this date.
- 2 August 2026: the transparency obligations of Article 50 apply. This was originally also the date for high-risk AI under Annex III — that date has moved.
- 2 December 2026: end of the transition period for labelling synthetic content (Art. 50(2)) by existing systems, and for the new prohibitions on NCII and CSAM.
- 2 August 2027: final date for member states to have AI regulatory sandboxes operational.
- 2 December 2027: the obligations for high-risk AI systems under Annex III take effect (was 2 August 2026).
- 2 August 2028: the obligations for high-risk AI in products already covered by existing EU product legislation (Annex I) take effect (was 2 August 2027).
The 4 risk categories
The AI Regulation opts for a risk-based approach. AI systems are classified into four categories:
- Unacceptable risk: These systems pose a clear threat and are strictly prohibited (Art. 5).
- High risk: Systems with far-reaching impact on fundamental rights or (product) safety. Think of AI in critical infrastructure.
- Limited risk: AI applications where interaction can be misleading, for which transparency (Art. 50) is required.
- Minimal risk: The bulk of AI in society falls under this (such as spam filters or in-game AI). There are no obligations for this, but Member States encourage the use of voluntary codes.
Prohibited AI practices (Art. 5)
According to the AI Act, it is strictly prohibited to design, develop or deploy systems with an unacceptable risk in Europe. Think of:
- Manipulative techniques to cause harm.
- Social scoring by governments.
- Untargeted scraping of facial images from the internet for recognition databases.
- Emotion recognition in the workplace and in education (exceptions apply only around the medical domain or safety).
- Biometric categorization based on protected or sensitive characteristics.
- Real-time biometric identification at a distance in public spaces for law enforcement, except for very specific exceptional cases.
High-risk systems, obligations
For the High Risk category, there are roughly two legal paths. Option (A): The AI functions as a safety component in a product (Annex I legislation), such as in medical devices, toys, lifts or motor vehicles. Option (B): The AI is deployed within Annex III sectors. Annex III mentions the deployment areas of biometrics, critical infrastructure, education, employment and HR, access to essential (private/public) services, law enforcement, migration/asylum/borders, justice and democratic processes.
Providers of such high-risk AI must meet robust requirements. They must ensure risk management and correct data quality, keep logs and technical documentation, guarantee human oversight and ensure robustness and cybersecurity. Furthermore, the process includes a formal 'conformity assessment', CE marking and registration in a new EU database. Want more insight into these documentation requirements? See our services at AI Consultancy.
Note the changed dates: under Regulation (EU) 2026/1744 these obligations only apply to Annex III systems from 2 December 2027 and to Annex I systems from 2 August 2028. The requirements themselves are unchanged — you have more time for them, not an exemption.
Transparency obligation (Art. 50)
For AI under the 'Limited risk' category, a transparency obligation is included via Art. 50. Users must know that they are communicating with AI (such as with chatbots). AI-generated content or AI-manipulated pieces such as deepfakes must also be made recognizable. For text generated by AI on matters of general or public interest, the labeling obligation is also mandatory.
Since the Digital Omnibus, the following rhythm applies here: the information obligation — the user knows they are communicating with AI — applies from 2 August 2026. For labelling AI-generated or AI-edited content (Art. 50(2)), systems already placed on the market before 2 August 2026 have until 2 December 2026; systems placed on the market after that must comply immediately.
General-purpose AI (GPAI) and systemic risk
To monitor broad language models (LLMs) or generative systems, a special regime has been set up in Chapter V for General-purpose AI (GPAI).
All GPAI providers must at least:
- Keep technical documentation in order.
- Share specifications with downstream providers and customers.
- Apply a copyright policy focused on opt-out requests.
- Provide a public summary of where which training data came from.
In addition, there may be a so-called "systemic risk". In the law, the threshold for systemic risk is set at models trained with compute greater than 10^25 FLOPs. These models must also conduct model evaluations, adequately mitigate systemic risk, handle incident reporting and implement heavy cybersecurity measures. Through good AI training, those involved in your company learn to deal with these regulations efficiently.
Sanctions (Art. 99)
Article 99 sets explicit, high maximums for fines when standards are violated:
- For violations of prohibited AI practices (Art. 5) the fine can amount to a maximum of €35 million or 7% of global annual turnover (whichever is higher).
- In case of non-compliance with other obligations, for example the rules for high-risk providers and deployers, sanctions of up to €15 million or 3% global turnover are conceivable.
- If you provide incorrect or misleading information to supervisors through your company, you face fines of up to €7.5 million or 1% turnover.
Important in these amounts: for both SMEs and start-ups, the lowest of the two amounts applies by default instead of the regular highest option.
Supervision in the Netherlands (AP, RDI, implementation act)
Governance for regulation is placed at the European level with the new European AI Office. This falls directly under the Commission (DG CNECT). In addition, the AI Board functions, supported by a European scientific panel and advisory forum.
At national level, each EU member state must have designated a national market surveillance authority and so-called 'notifying authority' by 2 August 2025 at the latest.
In the Netherlands, the situation currently stands as follows:
- The Dutch Data Protection Authority (AP) and the National Digital Infrastructure Inspectorate (RDI) have been designated for central supervision. The AP supervises the prohibited AI practices, most of the high-risk systems under Annex III and the transparency obligations. Together, the AP and RDI fulfil the coordinating role, with the RDI acting as the central point of contact towards Europe.
- The online consultation for the Implementation Act for the AI Regulation ran until 1 June 2026. The act is expected to enter into force later than 2 August 2026; in the meantime the AI Regulation itself applies directly, regardless of the national implementation act.
- The AP and RDI are setting up an AI regulatory sandbox in which organisations can test their AI systems under the guidance of the supervisory authorities. Member states have until 2 August 2027 to do so.
Practical step-by-step plan for organizations
Ensure that AI compliance is systematically examined based on the following steps derived from the regulation:
- Start with AI literacy (Art. 4): Begin by creating knowledge among your employees; according to the Commission's timeline, this is already required on 2 February 2025.
- Check for prohibited practices (Art. 5): Check and avoid tools that, for example, build up facial images through untargeted scraping or real-time measurement via vulnerable emotion recognition in the office.
- Identify your risk categories: Determine whether systems within your company fall under high risk (Annexes I or III) and check your CE marking in the future, or label your chatbot for the transparency requirement.
- Integrate the Transparency obligation (Art. 50): Ensure that every AI-generated deepfake or chatbot is clearly and recognizably presented to end users.
- Manage your General-Purpose AI requests: If you build or offer broadly trained language models, pay attention to documentation and check the copyright opt-out preferences of content owners. Also check whether the computing power for model training exceeds the 10^25 FLOPs threshold in connection with additional cybersecurity legislation.
- Plan around the new deadlines: use the postponement to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) to calmly set up risk management, technical documentation, conformity assessment and human oversight. But arrange transparency (Art. 50) and the exclusion of prohibited practices (Art. 5) now — those dates are fixed.
Veelgestelde vragen
When does the EU AI Act actually apply?+
The regulation entered into force on 1 August 2024 and applies in phases. Since 2 February 2025 the definitions, the AI literacy obligation and the prohibited practices apply; since 2 August 2025 the GPAI and sanction rules; from 2 August 2026 the transparency obligations of Article 50. The obligations for high-risk AI have been postponed by the Digital Omnibus (Regulation (EU) 2026/1744) to 2 December 2027 for Annex III and 2 August 2028 for Annex I.
Has the EU AI Act been postponed?+
Partly. With the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), the EU has postponed the obligations for high-risk AI: Annex III from 2 August 2026 to 2 December 2027, and Annex I from 2 August 2027 to 2 August 2028. What has been postponed is therefore the heavy conformity requirements, not the law as a whole. The prohibited practices (Art. 5), the GPAI rules and the transparency obligation (Art. 50) apply in full.
What must my organisation have in place on 2 August 2026?+
Three things. One: your users must know when they are communicating with an AI system (Art. 50). Two: AI-generated or AI-edited content must be recognisable — for systems already placed on the market before 2 August 2026 this may take until 2 December 2026. Three: no prohibited AI practices in use (Art. 5). The high-risk requirements only apply later, but preparing for them starts with an inventory of your AI systems.
Who does the AI Regulation apply to in business?+
The law covers every developer or professional user of AI systems on the European market. Moreover, the regulation has a so-called extraterritorial effect, meaning that providers from outside the EU must also comply when their AI output ends up in the EU.
What are the fines and sanctions under this regulation?+
Article 99 stipulates that fines vary depending on the violation. For violations related to prohibited AI practices, the limit reaches up to €35 million, or 7% of global commercial turnover (whichever is higher). For SMEs or start-ups, the lowest threshold applies.
Which practices are classified as prohibited AI applications?+
Under Article 5, a number of unacceptable risks fall. Social scoring by governments, biometric classification based on sensitive characteristics, emotion recognition in the classroom or workplace (without specific requirements), or untargeted scraping of facial images from the internet is prohibited.
Does the Act apply if our supplier is not based in the EU?+
Absolutely. Just like the GDPR data protection law, the EU AI Act applies an extraterritorial principle. As long as the results (outputs) generated by the model are deployed or have impact within the thirty countries of the EU/EEA, Regulation 2024/1689 is mandatory to pursue.
What has been agreed regarding large language models and general-purpose AI (GPAI)?+
Developers of GPAI (as set out in Chapter V) must openly declare their copyright policy, be transparent about the source of data with a public summary, and exchange technical documentation. If a model has exceeded the large compute threshold of 10^25 FLOPs, there is also incident reporting and legally required model evaluation due to systemic risk factor.
Blijf scherp op AI
Stay compliant with your AI initiatives
Ensure that your organization meets the AI Regulation in time within the set deadlines and avoid hefty sanctions.
Volgende stap
Bekijk AI Consultancy


