The EU AI Act — in Dutch, the AI-verordening — is the first comprehensive law on artificial intelligence, and it applies directly in the Netherlands. Because it is a European regulation (a verordening), it needs no separate Dutch implementation law: the rules apply here automatically, in phases. If your business uses AI, here is what that means in practice.
(This is general information, not legal advice.)
Does it apply to you, and how risky is your AI?
The law mainly separates two roles. Providers build or sell AI systems; deployers use them in their operations. Most Dutch companies are deployers — you use AI tools rather than build them — and that already brings duties. The heaviest obligations fall on providers of high-risk systems, but deployers have their share too, especially around transparency, oversight and staff training. Note that the roles are not fixed labels for a company: the same organisation can be a deployer of a standard chatbot and a provider of a model it has substantially adapted and put on the market under its own name.
Beyond the roles, the AI Act sorts systems into four risk levels, with heavier rules as the risk rises:
- Unacceptable risk (verboden praktijken) — banned outright, such as social scoring or systems that manipulate behaviour.
- High risk (hoog-risico) — allowed, but with strict obligations. Think AI used in recruitment, credit scoring, or access to essential services.
- Limited risk — mainly transparency duties, like telling people they are dealing with AI.
- Minimal risk — the vast majority of AI, with no specific obligations.
For most Dutch companies, everyday tools — writing assistants, chatbots, analytics — sit in the minimal or limited categories. The rules get serious once AI starts to affect people’s rights or safety. A system counts as hoog-risico when it can materially affect people’s rights, health or safety, and the common business examples are exactly the ones you might not think of as “AI projects”: software that screens job applicants, scores creditworthiness, or decides access to essential services. For these systems the law expects risk management, high-quality training data, logging, human oversight and clear documentation. If you deploy such a system rather than build it, your duties are lighter but real: use it as intended, keep a competent human in the loop, monitor how it performs in practice, and keep the logs. The practical takeaway is that classification comes first — you cannot know which obligations apply until you know where each tool sits.
What the law asks of you in practice
Even outside high-risk, transparency is often required. If customers chat with an AI bot, they should know it. AI-generated or manipulated content — text, images, so-called deepfakes — must be recognisable as such. A short, honest disclosure is usually enough to meet the transparantieverplichting; it does not need legal language, and in most cases a line in the interface beats a paragraph in your terms and conditions.
The second duty is a quieter one, and it is already in force. Since February 2025, organisations must ensure the people who work with AI have enough AI literacy (AI-geletterdheid) to use it responsibly. Nobody needs a data-science degree, but staff should understand what your AI can and cannot do, where it can go wrong, and when to involve a human. In practice this means short training, some internal guidance, and clear ownership — someone who can answer the question “are we allowed to use this for that?” before a team finds out the hard way.
Put together, a workable starting point for most Dutch businesses looks like this:
- Inventory every AI tool in use — including ones your teams adopted on their own.
- Classify each use by risk; flag anything touching hiring, credit, safety or personal data.
- Disclose AI clearly wherever customers interact with it.
- Check suppliers on AVG (GDPR) compliance, EU data storage, and no reuse of your data to train their models.
- Assign ownership and train your team (AI-geletterdheid).
- Document briefly what you use and why.
The timeline, the supervisors and the fines
The AI Act does not land all at once. It phases in over several years, which is why some duties already bind you today while others are still on the horizon:
- August 2024 — the regulation entered into force.
- February 2025 — the bans on unacceptable-risk AI took effect, and the AI literacy duty began.
- August 2025 — rules for general-purpose AI models and the supervisory structure started; member states had to name their supervisors.
- August 2026 — transparency obligations and the requirements for many high-risk systems apply.
- 2027 and beyond — the remaining high-risk rules phase in.
Enforcement in the Netherlands is decentralised. The country appointed ten market-surveillance authorities (markttoezichthouders), each covering its own domain — among them the Autoriteit Persoonsgegevens (AP), the Rijksinspectie Digitale Infrastructuur (RDI), the AFM, DNB, the NVWA and the Nederlandse Arbeidsinspectie. Coordination sits with two of them: the AP leads on fundamental rights (privacy, non-discrimination, transparency), while the RDI takes the technical and product side (safety, conformity, market surveillance). At European level, the AI Office (AI-bureau) oversees the largest general-purpose models. Which supervisor you would deal with therefore depends on your sector, not on the technology itself. To work out which rules apply to a specific use, the Dutch government offers a practical decision aid, the beslishulp AI-verordening.
And if you ignore all of it? Supervisors can require changes, order a product to be withdrawn from the market, and impose fines. The regulation sets steep ceilings — up to €35 million or 7% of worldwide annual turnover for the most serious (prohibited) breaches, with lower ceilings for other violations. Because it is an EU regulation, these powers apply directly in the Netherlands, without waiting for a Dutch law to switch them on.
Where to start, and who can help
You do not have to figure this out alone. A good AI provider can explain how their system is classified, what documentation exists, and how they handle your data under the AVG. Make compliance part of the conversation from the start rather than a question you raise after the contract is signed — a supplier who cannot answer it clearly is telling you something useful. See also our guide on how to choose the right AI provider.
The AI-verordening is not a reason to avoid AI — it is a framework for using it with confidence. Start with an inventory, train your people, and work with providers who take compliance seriously. Most companies discover that the work is smaller than feared, and that the inventory alone is worth doing. See how Baionic connects you to the right AI experts.