Frequently asked
What is the EU AI Act?
The EU AI Act is the European law that sorts AI systems by risk: prohibited, high-risk, limited-risk and minimal-risk. The higher the risk, the heavier the obligations. The law applies to anyone offering or using AI in the EU, so SMEs are covered too.
Which deadlines apply right now?
Prohibited AI practices have applied since 2 February 2025, GPAI obligations since 2 August 2025. Since 2 August 2026, the transparency duties in Article 50, the fining powers and market surveillance apply as well. The high-risk rules in Annex III moved via the Digital Omnibus to 2 December 2027.
What changed on 2 August 2026?
Article 50 took effect: a chatbot must say you are talking to AI unless that is already obvious. Deepfakes and certain AI-generated texts on public matters need labels. National authorities can enforce the rules and Article 101 GPAI fines are active. Existing generative systems have until 2 December 2026 for machine-readable marking.
Is the high-risk deadline final?
Yes. Parliament approved the Digital Omnibus on 16 June 2026 and the Council on 29 June. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July and has applied since 27 July. Annex III systems follow on 2 December 2027; high-risk AI in regulated products on 2 August 2028.
What does the AI Act mean for SMEs?
Most AI use in SMEs falls under limited or minimal risk. Article 50 then mainly asks three things: disclose direct AI interaction when it is not obvious, label deepfakes, and label AI-generated text on public matters that nobody has reviewed. For each application, determine the risk tier and whether you are its provider or its user.
What fines does the AI Act set?
The AI Act has three fine levels. Prohibited practices: up to 35 million euro or 7% of global annual turnover. Most other breaches, such as the transparency duties: up to 15 million euro or 3%. Incorrect information to regulators: up to 7.5 million euro or 1%. Large companies face the higher of the two amounts, SMEs and start-ups the lower.
Who supervises this in the Netherlands?
The Netherlands appoints 10 market surveillance authorities, each in its own domain (AFM and DNB for financial services). For areas without an existing supervisor, such as prohibited practices and transparency duties, the Dutch Data Protection Authority (AP) gets a central role, alongside the Rijksinspectie Digitale Infrastructuur. Consultation on the implementation law closed 1 June 2026; parliamentary debate is to come.
How do you make AI AI-Act-proof in production?
Start per application: the law classifies use cases, not "AI" as a whole. Many pilots stall on the production gap sooner than on the law, because ownership, compliance and maintenance get sorted out too late. In my Scan I review your AI work on ROI, risk and what the law asks.
The four risk tiers
Prohibited
AI the EU deems too harmful, such as social scoring or manipulating vulnerable groups.
Banned since 2 February 2025.
High-risk
AI in sensitive domains (Annex III), such as hiring, credit or critical infrastructure.
Strict requirements. Date moved to 2 December 2027 (Digital Omnibus, finally approved June 2026).
Limited-risk
Direct AI interaction, emotion recognition, deepfakes and certain AI-generated texts.
Transparency by type from 2 August 2026. One transition period applies to existing generative systems.
Minimal-risk
Most AI: spam filters, recommendations, tools with no direct risk.
No specific obligations under the law.
What should an SME do now?
- List every AI application you use or offer, from chatbot to hiring tool.
- For each one, determine the risk tier from the table above, and whether you are its provider or its user.
- Check whether anything counts as a prohibited practice. That ban has applied since 2 February 2025; stop it straight away.
- Comply with Article 50, in force since 2 August 2026: disclose that a chatbot is AI when that is not obvious, and label deepfakes and unreviewed AI-generated text on public matters.
- Do you offer an existing generative system? Put machine-readable marking in place before 2 December 2026.
- Does an application count as high-risk, such as hiring or credit? Plan for the requirements by 2 December 2027, or 2 August 2028 for AI in regulated products.
This is not legal advice. The EU AI Act is still getting implementing rules and guidance; details can shift. For your own situation, have a lawyer look at it.
Want to check your AI work against the AI Act?
In the Scan I review your AI work on ROI, risk and what the law asks, and tell you which projects I would put into production. Fixed fee from €1,995 ex VAT, about one week.
30 minutes · free, no obligation