EU AI Act: Everything You Need to Know About the AI Regulation
The EU AI Act is the world's first horizontal law on artificial intelligence. Discover what the legal framework and phased timeline mean for the use of AI within your organization.
Regulation (EU) 2024/1689, better known as the EU AI Act or AI Regulation, establishes a historic framework. As the first in the world, the European Union introduces horizontal AI legislation. The law was officially adopted by the Council and the European Parliament, signed on 13 June 2024, and finally published in the Official Journal of the EU on 12 July 2024.
With its entry into force on 1 August 2024, a phased rollout has started. This means that organizations will gradually face new rules in the coming years. Because this law is extraterritorial, providers from outside the EU also fall under this legislation when their AI output is used within the borders of the EU, similar to the scope of the GDPR.
For Dutch institutions, it is crucial to comply with these requirements in time to avoid hefty sanctions. Curious about what this means for your implementation strategy? Discover the possibilities via AI Consultancy on ai.nl.
What is the EU AI Act (Regulation 2024/1689)?
The EU AI Act, officially Regulation (EU) 2024/1689, is the first horizontal legislation in the world specifically designed to ensure safe, transparent and accountable development and deployment of AI systems. After approval by the Council and the EP, the document was signed on 13 June 2024 and published in the Official Journal of the EU on 12 July 2024.
Timeline with exact dates
The law formally entered into force on 1 August 2024 (20 days after publication). From that moment, a strict, phased timeline from the European Commission runs until full applicability on 2 August 2027:
- 2 February 2025: The general provisions, definitions, AI literacy obligation (Art. 4) and the prohibition of prohibited AI practices (Art. 5) are directly applicable.
- 2 August 2025: Rules for general-purpose AI (GPAI) models, the new governance structures and sanction rules (fines) are effective from this date.
- 2 August 2026: Applicability of the vast majority of obligations. This also includes the requirements for high-risk systems listed in Annex III.
- 2 August 2027: Obligations enter into force for the remaining high-risk AI products already covered by existing EU product legislation (Annex I).
The 4 risk categories
The AI Regulation opts for a risk-based approach. AI systems are classified into four categories:
- Unacceptable risk: These systems pose a clear threat and are strictly prohibited (Art. 5).
- High risk: Systems with far-reaching impact on fundamental rights or (product) safety. Think of AI in critical infrastructure.
- Limited risk: AI applications where interaction can be misleading, for which transparency (Art. 50) is required.
- Minimal risk: The bulk of AI in society falls under this (such as spam filters or in-game AI). There are no obligations for this, but Member States encourage the use of voluntary codes.
Prohibited AI practices (Art. 5)
According to the AI Act, it is strictly prohibited to design, develop or deploy systems with an unacceptable risk in Europe. Think of:
- Manipulative techniques to cause harm.
- Social scoring by governments.
- Untargeted scraping of facial images from the internet for recognition databases.
- Emotion recognition in the workplace and in education (exceptions apply only around the medical domain or safety).
- Biometric categorization based on protected or sensitive characteristics.
- Real-time biometric identification at a distance in public spaces for law enforcement, except for very specific exceptional cases.
High-risk systems — obligations
For the High Risk category, there are roughly two legal paths. Option (A): The AI functions as a safety component in a product (Annex I legislation), such as in medical devices, toys, lifts or motor vehicles. Option (B): The AI is deployed within Annex III sectors. Annex III mentions the deployment areas of biometrics, critical infrastructure, education, employment and HR, access to essential (private/public) services, law enforcement, migration/asylum/borders, justice and democratic processes.
Providers of such high-risk AI must meet robust requirements. They must ensure risk management and correct data quality, keep logs and technical documentation, guarantee human oversight and ensure robustness and cybersecurity. Furthermore, the process includes a formal 'conformity assessment', CE marking and registration in a new EU database. Want more insight into these documentation requirements? See our services at AI Consultancy.
Transparency obligation (Art. 50)
For AI under the 'Limited risk' category, a transparency obligation is included via Art. 50. Users must know that they are communicating with AI (such as with chatbots). AI-generated content or AI-manipulated pieces such as deepfakes must also be made recognizable. For text generated by AI on matters of general or public interest, the labeling obligation is also mandatory.
General-purpose AI (GPAI) and systemic risk
To monitor broad language models (LLMs) or generative systems, a special regime has been set up in Chapter V for General-purpose AI (GPAI).
All GPAI providers must at least:
- Keep technical documentation in order.
- Share specifications with downstream providers and customers.
- Apply a copyright policy focused on opt-out requests.
- Provide a public summary of where which training data came from.
In addition, there may be a so-called "systemic risk". In the law, the threshold for systemic risk is set at models trained with compute greater than 10^25 FLOPs. These models must also conduct model evaluations, adequately mitigate systemic risk, handle incident reporting and implement heavy cybersecurity measures. Through good AI training, those involved in your company learn to deal with these regulations efficiently.
Sanctions (Art. 99)
Article 99 sets explicit, high maximums for fines when standards are violated:
- For violations of prohibited AI practices (Art. 5) the fine can amount to a maximum of €35 million or 7% of global annual turnover (whichever is higher).
- In case of non-compliance with other obligations – for example the rules for high-risk providers and deployers – sanctions of up to €15 million or 3% global turnover are conceivable.
- If you provide incorrect or misleading information to supervisors through your company, you face fines of up to €7.5 million or 1% turnover.
Important in these amounts: for both SMEs and start-ups, the lowest of the two amounts applies by default instead of the regular highest option.
Supervision in the Netherlands (AP, RDI, implementation act)
Governance for regulation is placed at the European level with the new European AI Office. This falls directly under the Commission (DG CNECT). In addition, the AI Board functions, supported by a European scientific panel and advisory forum.
At national level, each EU member state must have designated a national market surveillance authority and so-called 'notifying authority' by 2 August 2025 at the latest.
In the Dutch context (up to November 2024 / towards 2026) the situation is as follows:
- The Dutch Data Protection Authority (AP) and the National Digital Infrastructure Inspectorate (RDI) published their final advice on 7 November 2024 entitled "Supervision of AI". In it, they express a preference for sectoral supervision including central coordination.
- The formal Implementation Act for the AI Regulation was brought into online consultation in the Netherlands by State Secretary Aerdts (April 2026). This consultation period runs until 1 June 2026.
- Meanwhile, the AP has internally established the Coordination Algorithms Directorate (DCA), which is already focusing on general AI/algorithm coordination in the supervision field.
Practical step-by-step plan for organizations
Ensure that AI compliance is systematically examined based on the following steps derived from the regulation:
- Start with AI literacy (Art. 4): Begin by creating knowledge among your employees; according to the Commission's timeline, this is already required on 2 February 2025.
- Check for prohibited practices (Art. 5): Check and avoid tools that, for example, build up facial images through untargeted scraping or real-time measurement via vulnerable emotion recognition in the office.
- Identify your risk categories: Determine whether systems within your company fall under high risk (Annexes I or III) and check your CE marking in the future, or label your chatbot for the transparency requirement.
- Integrate the Transparency obligation (Art. 50): Ensure that every AI-generated deepfake or chatbot is clearly and recognizably presented to end users.
- Manage your General-Purpose AI requests: If you build or offer broadly trained language models, pay attention to documentation and check the copyright opt-out preferences of content owners. Also check whether the computing power for model training exceeds the 10^25 FLOPs threshold in connection with additional cybersecurity legislation.
- Keep an eye on national rollout: Closely monitor the online consultation for the Implementation Act for the AI Regulation (active until 1 June 2026) so that you know the designated Dutch competent authorities by 2 August 2025.
Veelgestelde vragen
When does the EU AI Act actually apply?+
The regulation entered into force on 1 August 2024. Full applicability of all articles will be enforced on 2 August 2027. Certain elements, such as definitions, AI literacy (Art. 4) and prohibited practices (Art. 5) already apply on 2 February 2025.
Who does the AI Regulation apply to in business?+
The law covers every developer or professional user of AI systems on the European market. Moreover, the regulation has a so-called extraterritorial effect, meaning that providers from outside the EU must also comply when their AI output ends up in the EU.
What are the fines and sanctions under this regulation?+
Article 99 stipulates that fines vary depending on the violation. For violations related to prohibited AI practices, the limit reaches up to €35 million, or 7% of global commercial turnover (whichever is higher). For SMEs or start-ups, the lowest threshold applies.
Which practices are classified as prohibited AI applications?+
Under Article 5, a number of unacceptable risks fall. Social scoring by governments, biometric classification based on sensitive characteristics, emotion recognition in the classroom or workplace (without specific requirements), or untargeted scraping of facial images from the internet is prohibited.
Does the Act apply if our supplier is not based in the EU?+
Absolutely. Just like the GDPR data protection law, the EU AI Act applies an extraterritorial principle. As long as the results (outputs) generated by the model are deployed or have impact within the thirty countries of the EU/EEA, Regulation 2024/1689 is mandatory to pursue.
What has been agreed regarding large language models and general-purpose AI (GPAI)?+
Developers of GPAI (as set out in Chapter V) must openly declare their copyright policy, be transparent about the source of data with a public summary, and exchange technical documentation. If a model has exceeded the large compute threshold of 10^25 FLOPs, there is also incident reporting and legally required model evaluation due to systemic risk factor.
Blijf scherp op AI
Stay compliant with your AI initiatives
Ensure that your organization meets the AI Regulation in time within the set deadlines and avoid hefty sanctions.
Volgende stap
Bekijk AI Consultancy