Regulation (EU) 2024/1689 has been in force since August 2024, and it lands on organisations in stages. Which duties reach you depends on two questions: what your systems do, and whether you build them or use them.
The Act sorts systems by what they are used for. Nothing here depends on your sector, your size or your turnover.
Social scoring, manipulative techniques that exploit vulnerability, untargeted scraping of facial images, and emotion recognition at work and in education. Eight categories in Article 5, in force since February 2025. Two more, covering nudifiers and AI-generated child sexual abuse material, were added by the Digital Omnibus.
Two routes in. Annex III lists standalone use cases: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Annex I covers AI embedded in products that already carry a CE mark, such as medical devices and machinery.
Chatbots must disclose they are AI. Deepfakes and AI-generated content must be labelled. That is Article 50, and it has applied since August 2026. Most companies meet the AI Act here first, not in the high-risk tier.
Spam filters, recommendation engines, most productivity tooling. The AI literacy duty in Article 4 still applies, because it attaches to the organisation rather than to a system.
Every obligation in the Act hangs on a role. Build a system, or have one built, and put it on the market under your own name, and you are a provider (Article 3(3)). Payment is irrelevant: giving it away counts, and so does using something you built purely internally.
Use a system under your own responsibility in your operations and you are a deployer (Article 3(4)). That is where nearly every company sits. The duties are lighter but real: AI literacy, transparency where Article 50 applies, and for high-risk use the diligence requirements of Article 26.
The line matters more than it looks, because it moves. Put an AI feature into the product you sell and you become a provider for that feature, with technical documentation and a conformity assessment attached.
The Act is a regulation, so its substance is identical in every member state. What differs is who enforces it and how the national implementing law is written, and the Netherlands has not finished that yet.
The draft Dutch implementing act proposes the Dutch Data Protection Authority and the Radiocommunications Agency as joint coordinating supervisors, with sectoral roles for the financial, healthcare and transport regulators. That act has not been adopted. Any English source presenting a settled list of Dutch supervisors is ahead of the facts.
One thing is already settled: general-purpose AI models are supervised by the European Commission and the AI Office under Article 88, not by national authorities.
A deployer, almost certainly. You are a deployer when you use an AI system under your own authority in your operations (Article 3(4)), which covers nearly every business using ChatGPT, Copilot or AI features inside other software. You become a provider when you develop a system, or have one developed, and put it on the market under your own name (Article 3(3)). Building an AI feature into your own product makes you a provider, and so does purely internal use of something you built yourself.
No, and this is the most common misreading. The AI Act classifies on what a system does, not on the industry it sits in. Annex III is organised by use case. A hospital using AI to schedule cleaning rotas is not in scope; the same hospital using AI to triage emergency patients is. Sector tells you where high-risk uses tend to cluster, nothing more.
No. Article 6(3) carves out systems that perform a narrow procedural task, improve the result of prior human work, detect patterns or deviations without replacing a human assessment, or do preparatory work. The carve-out falls away the moment the system profiles natural persons. Human oversight on its own is not an exemption: the Commission's draft guidelines are clear that a formal review does not save a system once its output effectively drives the outcome.
Up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher, for breaching the Article 5 prohibitions. Lower ceilings apply to other infringements and to SMEs, for which the lower of the two amounts applies rather than the higher.
Not settled yet. The draft Dutch implementing act proposes the Dutch Data Protection Authority and the Radiocommunications Agency as joint coordinating supervisors, with sectoral roles for the financial, healthcare and transport regulators. That act has not been adopted, so treat any list of Dutch supervisors as provisional. General-purpose AI models are a separate matter: those sit with the European Commission and the AI Office under Article 88, not with any national authority.
The rest of this site is in Dutch. These two pages are not.
Reading Dutch? The full guide is at /eu-ai-act.