BV Formation

EU AI Act deadlines for Dutch BVs: what Is already law

The EU AI Act already applies to Dutch BVs. See what is in force, what the Digital Omnibus deferred to 2027, and five steps to take before year-end.

•

14 mins

EU AI Act Deadlines for Dutch BVs

Intro

The EU AI Act is not a future regulation. Three of its major phases have already passed. As of September 2026, the prohibited AI practices have been banned for 18 months, the rules for large AI models have applied for over a year, and the Article 50 transparency duties that require a chatbot to identify itself as AI became enforceable last month. The Autoriteit Persoonsgegevens, the AP, has been operating as an AI Act supervisor since 2 August 2026 and can receive complaints and open investigations from that date.

The most important correction for anyone reading older material is this: many articles still present 2 August 2026 as the high-risk compliance deadline. That is no longer correct. The Digital Omnibus on AI, formally Regulation (EU) 2026/1744, was endorsed by the European Parliament on 16 June 2026, adopted by the Council on 29 June, published in the Official Journal on 24 July, and has been in force since 27 July. It moved the deadline for standalone high-risk systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products from 2 August 2027 to 2 August 2028. The obligations themselves did not change. Only the date by which they must be met did.

Key takeaway: Three things are already law. Prohibited AI practices have been banned since 2 February 2025. The AI literacy duty has applied since the same date. Chatbot and transparency disclosures have applied since 2 August 2026. The high-risk rules for hiring tools, credit scoring, and biometric systems are deferred to December 2027. That window is open, but it is not infinite.

Date

What applies

Who is affected

Status

1 August 2024

AI Act enters into force

All businesses in the EU

✅ Past

2 February 2025

Prohibited practices banned (Art. 5); AI literacy duty (Art. 4)

Every organisation using AI

✅ Already in force

2 August 2025

General purpose AI model obligations (Chapter V); AI Office operational

Providers of large AI models; businesses building on them

✅ Already in force

2 August 2026

Art. 50 transparency duties for chatbots and deepfakes; national enforcement powers; AP operational as supervisor

Any organisation deploying chatbots or publishing AI-generated content

✅ Just activated

2 December 2026

Two new prohibited practices (nudifier apps, AI-generated child abuse material); machine-readable marking for generative systems already on the market

Providers of generative AI; everyone for the new bans

🔜 Upcoming

2 December 2027

High-risk AI under Annex III (deferred by the Digital Omnibus)

Employment AI, credit scoring, biometric identification, education AI

🔜 Upcoming

2 August 2028

High-risk AI embedded in Annex I regulated products (deferred)

AI inside medical devices, machinery, toys, vehicles

🔜 Upcoming

This sits inside a much wider wave of EU rulemaking reaching Dutch businesses at the same time; AMLA EU AML authority Netherlands covers another new EU supervisory body whose rulebook is also being rewritten right now.

Four Tiers: Which One Is Your BV In?

The AI Act sorts AI systems into four risk tiers, and the tier determines the obligations. For most Dutch BVs, the relevant question is not whether they have built an AI system. It is whether the AI tools they buy and use fall into a tier that requires action.

The first tier is unacceptable risk, meaning prohibited outright. This covers a short list of practices: social scoring, subliminal manipulation that causes harm, exploiting the vulnerabilities of specific groups, real-time biometric identification in public spaces by law enforcement, biometric categorisation that infers protected characteristics, untargeted scraping of facial images, and emotion recognition in workplaces and schools. The one most likely to catch an ordinary Dutch business off guard is the last. An AI tool that reads employees' facial expressions or voice tone to assess mood or engagement, and then draws consequences from that, has been prohibited since 2 February 2025. The maximum penalty sits at 35 million euros or 7% of global annual turnover, whichever is higher.

The second tier is high risk, with heavy requirements now arriving in December 2027. These are AI systems in domains where errors seriously affect individuals: employment decisions such as CV screening, hiring, performance monitoring, and redundancy selection; access to essential services such as credit scoring and insurance underwriting; education and assessment; biometric identification; and critical infrastructure. Providers must run a risk management system, keep technical documentation and logs, ensure human oversight and accuracy testing, and register the system in an EU database. A Dutch BV that deploys a vendor's CV-screening tool carries its own, lighter, deployer obligations, though the vendor leads the heavy lifting. The maximum penalty here is 15 million euros or 3% of turnover.

The third tier is limited risk, where the issue is not what the AI does but whether people know they are dealing with it. A customer-facing chatbot must say at the start of the interaction that the user is talking to AI. Deepfakes and AI-generated text published on matters of public interest must be labelled. Emotion recognition used outside the workplace and schools must be disclosed to the people assessed. These duties have applied since 2 August 2026.

The fourth tier is minimal risk, and it is where most Dutch business AI use sits. A spam filter, a sales forecasting tool, a document summariser, a design assistant, or Microsoft Copilot used for drafting emails carries no mandatory obligations beyond the general AI literacy duty. The critical insight for a DGA is that most AI use is minimal-risk, the prohibited list is short and specific, and the high-risk rules are deferred. What needs attention now is the transparency duty for chatbots and the AI literacy duty that has been running since February 2025. Where AI touches payments and financial services specifically, stablecoins Dutch businesses shows how another strand of EU digital regulation applies to Dutch firms in practice.

What Is Already Required

Three obligations apply to Dutch businesses right now, not from 2027, and not only to businesses whose systems are high-risk.

The first is AI literacy, the obligation most Dutch businesses have missed entirely. Article 4 has applied since 2 February 2025 and covers every organisation that deploys or uses AI. Its wording changed in July 2026: the Digital Omnibus rewrote it from a duty to ensure a sufficient level of AI literacy into a duty to take measures to support the development of AI literacy among staff, with an express statement that no particular level of competence needs to be guaranteed. That makes it an obligation of effort rather than result, but it did not disappear, and it still binds every provider and deployer at every risk tier. It does not require a certificate or a formal training programme. In practice, a minimum viable approach is a short internal AI use policy, even one or two pages, listing which AI tools the business uses, for what purposes, and what staff should understand about their limits. If the AP investigates, evidence of that effort is what it is likely to ask for.

The second is the chatbot disclosure. Since 2 August 2026, any Dutch BV with a customer-facing chatbot or conversational AI must make clear at the start of each interaction that the user is dealing with AI. A line in the privacy policy does not do it. The disclosure has to appear in the interaction itself, and a simple opening message such as "you are talking to an AI assistant" satisfies the core requirement.

The third is labelling of AI-generated content, which depends on context. AI-generated images, video, and audio that look realistic, and AI-written text published to inform the public on matters of public interest, must be labelled. A separate duty, machine-readable marking of synthetic output, falls on providers of generative AI systems rather than on a business that merely uses them, and for systems already on the market before 2 August 2026 it applies from 2 December 2026 after a short grace period. For most Dutch BVs, AI-drafted marketing copy and illustrations create no mandatory labelling duty, though noting AI involvement is good practice.

Watch out: Emotion recognition systems used in the workplace have been prohibited since 2 February 2025. That includes AI tools that read facial expressions, voice tone, or physiological signals to assess mood, engagement, or productivity and then draw consequences from the result. If your BV has rolled out any productivity or engagement monitoring tool with an AI component, review it against this prohibition now.

Workplace monitoring sits alongside wider employer obligations that are worth checking at the same time; CAO Netherlands employer covers how collective labour terms interact with what an employer may and may not do with its staff. And because this is a regime where regulators examine documentation, boekenonderzoek Belastingdienst is a useful preview of how Dutch inspectors approach evidence in a compliance investigation.

What Is Coming, and Why the Deferral Matters

The most consequential change to the AI Act's calendar is the Digital Omnibus deferral. A Dutch HR software provider whose AI-powered CV screening tool was meant to be compliant by August 2026 now has until 2 December 2027. That is a genuine relief for many, but the deferral has a specific character. It does not change what high-risk systems must do. The conformity assessment, risk management system, technical documentation, human oversight arrangements, and EU registration are all still coming. The EU deferred the date because national authorities and harmonised technical standards were not ready, not because it abandoned the requirements. For a business that develops or deploys a high-risk system, the extra sixteen months is a preparation window, not a reprieve from the rules.

Two new prohibitions arrive on 2 December 2026: AI systems that generate or manipulate non-consensual intimate imagery, the so-called nudifier applications, and AI systems that generate child sexual abuse material. They carry the top fine tier, up to 35 million euros or 7% of turnover. Most Dutch businesses will never come near them, but any platform that offers image or video generation to its users should check now that effective safeguards are in place, because the ban reaches systems where such misuse is reasonably foreseeable and the provider has not taken adequate preventive measures.

For Dutch BVs, the Annex III categories that matter most are hiring and HR tools, credit and insurance assessment, and education. A company that uses an AI tool in any of these areas has until 2 December 2027 to have the full framework in place, and conformity work for complex systems takes months. Leaving it to November 2027 is not a viable plan. There is also some welcome news for smaller businesses: the Omnibus introduced relief for SMEs and small mid-caps, including simplified technical documentation, proportionate quality management requirements, and reduced fine caps.

On the Dutch side, the Autoriteit Persoonsgegevens coordinates algorithm and AI supervision together with sectoral regulators, including the Rijksinspectie Digitale Infrastructuur, the RDI, which serves as a central coordination point. The Dutch implementation act, the Uitvoeringswet AI-verordening, was in consultation until 1 June 2026 and is not expected to reach the Tweede Kamer before late 2026, but the EU regulation applies directly in the meantime. Early enforcement is likely to focus on clear, visible violations, prohibited practices and missing chatbot disclosures first, rather than technical documentation details. Regulation of this kind rarely waits for national paperwork, and both investigative powers and the ability to fine already exist.

Five Things a Dutch BV Should Do Before the End of 2026

The distance between "AI Act compliance is someone else's problem" and "our BV has done the minimum" is smaller than most DGAs assume. Five actions, all achievable before year-end, cover what is already in force and prepare for what is coming.

Start with an AI inventory, since everything else depends on it. List every AI tool in use: software that includes AI features, plugins inside productivity tools, APIs connected to internal systems, and any automated decision tool. For each one, note what it does and whether it touches personal data. This takes a few hours and produces the document from which every later decision flows. Without it, a business cannot know which tier its AI use falls into.

Then check for prohibited practices straight away. For each tool in the inventory, ask whether it could involve social scoring, subliminal manipulation, or emotion recognition at work. A standard productivity assistant almost certainly does not. A tool that monitors keystrokes, facial expressions, or voice tone for performance management might. If in doubt, stop using it for that purpose until advice confirms it is acceptable.

Next, put AI literacy on paper with a short internal policy. One or two pages is enough: which tools are used, for what, what their known limits are in your context, and basic guidance for staff on responsible use. It does not need to be a legal document. It needs to be a genuine effort that staff have seen, so date it and keep a record of who received it.

If a chatbot is deployed anywhere a customer interacts with it, whether on the website, in WhatsApp, or by email, add a disclosure at the very start of every interaction and name the business as the operator.

Finally, assess any high-risk use and start preparing. If the inventory shows a tool used for hiring, credit scoring, or insurance underwriting, note the December 2027 date and ask the vendor for its AI Act compliance roadmap now. In most cases the vendor leads on conformity, but the deployer has duties too, and asking is both reasonable and wise. The AI Act overlaps heavily with the AVG whenever personal data is involved, so a business with solid AVG compliance already has a head start. Article 22 of the AVG, which limits purely automated decisions with significant effects, already covers many high-risk use cases, though meeting it does not by itself satisfy the AI Act.

Neno's platform handles the full-year financial administration of a Dutch BV, and as AI tools become part of how financial data is processed and analysed, the AI Act is a natural extension of the compliance landscape a DGA already navigates. For guidance on where professional support fits into this kind of regulatory work, accountant or bookkeeper is a good place to start, and starting a company in the Netherlands covers the wider regulatory framework a new Dutch BV works within.

If you want your administration set up so compliance work like this has a clear home, book a demo and we will walk through how your current setup holds up. Our team can also help you incorporate your BV or get bookkeeping and payroll running correctly from the start.

FAQs

Does the EU AI Act apply to my Dutch BV?

Yes, if your BV uses or deploys any AI system. The AI Act is a regulation, so it applies directly in the Netherlands. Most business AI use is minimal-risk with few obligations, but the prohibited-practices ban and the AI literacy duty apply to every organisation using AI.

What AI practices are prohibited in the Netherlands right now?

Social scoring, subliminal manipulation that causes harm, exploiting vulnerable groups, emotion recognition in workplaces and schools, biometric categorisation inferring protected characteristics, untargeted facial image scraping, and real-time remote biometric identification in public spaces by law enforcement, with narrow exceptions. All have been banned since 2 February 2025.

What is the AI literacy obligation and what does it require?

Article 4 requires organisations that provide or deploy AI to take measures supporting the development of AI literacy among their staff. Since the July 2026 rewrite, it is a duty of effort rather than of guaranteeing a particular level. In practice, a short internal policy on which AI tools are used and how is a sensible minimum.

Does my chatbot need to disclose it is AI?

Yes. Since 2 August 2026, a customer-facing chatbot or conversational AI must make clear at the start of the interaction that the user is communicating with AI. The disclosure must appear in the interaction itself, not only in a privacy policy.

What is the deadline for high-risk AI compliance in the Netherlands?

2 December 2027 for standalone high-risk systems listed in Annex III, such as hiring, credit scoring, and biometric tools, and 2 August 2028 for AI embedded in regulated products listed in Annex I.

Did the high-risk AI deadline change in 2026?

Yes. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the Annex III deadline from 2 August 2026 to 2 December 2027 and the Annex I deadline from 2 August 2027 to 2 August 2028. It entered into force on 27 July 2026. The underlying obligations were not changed.

What is the penalty for violating the AI Act in the Netherlands?

Up to 35 million euros or 7% of global annual turnover for prohibited practices, and up to 15 million euros or 3% for most other violations, whichever is higher. The Omnibus also introduced reduced fine caps for SMEs and small mid-caps.

Who enforces the AI Act in the Netherlands?

The Autoriteit Persoonsgegevens coordinates supervision together with sector regulators, with the Rijksinspectie Digitale Infrastructuur acting as a central coordination point. The AP has been operational as an AI Act supervisor since 2 August 2026.

What is general purpose AI and does it affect my BV?

General purpose AI models are large models such as those behind ChatGPT, Claude, or Gemini. The heavy obligations fall on the providers who build them. A BV that merely uses such a tool carries minimal obligations, and one that integrates a model's API into its own product carries lighter deployer duties.

How does the AI Act interact with the AVG?

They overlap whenever AI processes personal data, as with CV screening or customer scoring tools. Both apply. Article 22 of the AVG, on solely automated decisions, already covers many high-risk use cases, which gives a strong foundation, but compliance with the AVG does not substitute for AI Act compliance.

Portrait of Nick
Portrait of Nick

Written by

Nick Knuppe

CEO & Founder

We take care of admin. You take care of business.

We take care of admin. You take care of business.

We take care of admin. You take care of business.