Regulation (EU) 2024/1689 has been in force since August 2024, and it lands on organisations in stages. Which duties reach you depends on two questions: what your systems do, and whether you build them or use them.
The Act sorts systems by what they are used for. Nothing here depends on your sector, your size or your turnover.
Social scoring, manipulative techniques that exploit vulnerability, untargeted scraping of facial images, and emotion recognition at work and in education. Eight categories in Article 5, in force since February 2025. Two more, covering nudifiers and AI-generated child sexual abuse material, were added by the Digital Omnibus.
Two routes in. Annex III lists standalone use cases: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Annex I covers AI that is a safety component of a product covered by the Union harmonisation legislation listed there, such as medical devices or toys, or that is itself such a product, where that product is required to undergo a third-party conformity assessment (Article 6(1)).
Chatbots must disclose they are AI. Deployers must disclose deep fakes as artificially generated or manipulated, and the same applies to AI-generated text published to inform the public on matters of public interest, unless it has undergone human review or editorial control and someone holds editorial responsibility for publishing it (Article 50(4)). Providers of generative AI also mark outputs in a machine-readable format (Article 50(2)). That is Article 50, and it has applied since August 2026. Most companies meet the AI Act here first, not in the high-risk tier.
Spam filters, recommendation engines, most productivity tooling. The AI literacy duty in Article 4 still applies, because it attaches to the organisation rather than to a system.
Every obligation in the Act hangs on a role. Build a system, or have one built, and place it on the market or put it into service under your own name or trademark, and you are a provider (Article 3(3)). Payment is irrelevant: giving it away counts, and so does using something you built purely internally.
Use a system under your own responsibility in your operations and you are a deployer (Article 3(4)). That is where nearly every company sits. The duties are lighter but real: AI literacy, transparency where Article 50 applies, and for high-risk use the diligence requirements of Article 26.
A deployer can also turn into a provider through Article 25, but that route runs through high-risk systems only. It applies when you put your name or trademark on a high-risk system, when you substantially modify one so that it remains high-risk, or when you change the intended purpose of a system so that it becomes high-risk.
The line matters more than it looks, because it moves. Put an AI feature into the product you sell and you become a provider for that feature, with technical documentation and a conformity assessment attached.
The Act is a regulation, so its substance is identical in every member state. What differs is who enforces it and how the national implementing law is written, and the Netherlands has not finished that yet.
The draft Dutch implementing act proposes the Dutch Data Protection Authority (AP) and the Dutch Authority for Digital Infrastructure (RDI) as joint coordinating supervisors. Supervision follows the system, not the sector: the AP for most Annex III systems, the financial supervisors for credit scoring and life and health insurance pricing at financial institutions, and the existing product regulators for AI in products. That act has not been adopted. Any English source presenting a settled list of Dutch supervisors is ahead of the facts.
One thing is already settled: general-purpose AI models are supervised by the European Commission and the AI Office under Article 88, not by national authorities.
Click a question to see the answer. These are fixed answers; the AI Act assistant inside the platform answers your own questions.
A deployer, almost certainly. You are a deployer when you use an AI system under your own authority in your operations (Article 3(4)), which covers nearly every business using ChatGPT, Copilot or AI features inside other software. You become a provider when you develop a system, or have one developed, and place it on the market or put it into service under your own name or trademark (Article 3(3)). Building an AI feature into your own product makes you a provider, and so does purely internal use of something you built yourself.
No, and this is the most common misreading. The AI Act classifies on what a system does, not on the industry it sits in. Annex III is organised by use case. A hospital using AI to schedule cleaning rotas is not in scope; the same hospital using AI to triage emergency patients is. Sector tells you where high-risk uses tend to cluster, nothing more.
No. Article 6(3) carves out systems that perform a narrow procedural task, improve the result of prior human work, detect patterns or deviations without replacing a human assessment, or do preparatory work. The carve-out falls away the moment the system profiles natural persons. Human oversight on its own is not an exemption: the Commission's draft guidelines are clear that a formal review does not save a system once its output effectively drives the outcome.
Up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher, for breaching the Article 5 prohibitions. Lower ceilings apply to other infringements and to SMEs, for which the lower of the two amounts applies rather than the higher.
Not settled yet. The draft Dutch implementing act proposes the Dutch Data Protection Authority (AP) and the Dutch Authority for Digital Infrastructure (RDI) as joint coordinating supervisors. Which authority supervises a system depends on what the system does, not on the sector: the AP for most Annex III systems, such as recruitment and triage, AFM and DNB for credit scoring and life and health insurance pricing at financial institutions, and the existing product regulators for AI in products, such as the Health and Youth Care Inspectorate (IGJ) for medical devices. That act has not been adopted, so treat any list of Dutch supervisors as provisional. General-purpose AI models are a separate matter: those sit with the European Commission and the AI Office under Article 88, not with any national authority.
The rest of this site is in Dutch. These two pages are not.
Reading Dutch? The full guide is at /eu-ai-act.