AI Act Compliance for Dutch Businesses: Where to Start

AI Act compliance for Dutch businesses: which rules already apply, what was deferred, and a practical step-by-step plan to get started.

Gepubliceerd door NordX Consulting — AI bureau voor enterprise bedrijven in Nederland.

The AI Act sounds like a heavy compliance project with risk assessments, documentation, and audits. For a small share of businesses, it is. For most Dutch businesses, it is not. If you use AI without, say, selecting people or scoring credit with a model, it comes down to a few concrete duties you can handle in days. This article lays out the order.

The AI Act in brief

The EU AI Act entered into force on 1 August 2024 and applies in phases:

The trap is thinking "the AI Act" is a single deadline. It is not: some duties have applied for over a year, others are just arriving.

What already applies to most businesses

Set the words "high-risk" aside for a moment. Most businesses are not high-risk users. What does apply broadly is two things:

AI literacy (Article 4). Every business that uses AI must ensure the people working with it understand it well enough — appropriate to their role. This has applied since February 2025. Read how to handle it in AI literacy: what Article 4 requires.

Transparency (Article 50). If you use a chatbot or other AI that interacts directly with people, you must disclose it visibly. This takes effect on 2 August 2026. What counts as valid disclosure is covered in AI Act transparency: must your chatbot say it's AI?.

What was deferred, and what was not

In June 2026 the news was that "the AI Act has been delayed." That is partly true: the heavy high-risk obligations were proposed to move to December 2027. But the transparency and literacy duties stayed put. Those are exactly the two that touch most businesses. The full explanation is in EU AI Act delayed to December 2027: what still applies.

Are you a high-risk user?

This decides whether you are on the heavy track or the light one. High-risk concerns specific uses, including:

If you use AI for text, customer service, marketing, or internal process automation, you generally do not fall under this. You then deal with the transparency and literacy duties, not the full high-risk track.

Where to start: the step-by-step plan

1. Inventory your AI use. List every place AI sits in your organisation — standalone tools and AI buried inside existing software (CRM, accounting, customer service).

2. Determine your risk class. Run through the high-risk categories. If you are not in them, your track is light. If a use is borderline, have it assessed.

3. Handle transparency. Add a visible disclosure to every AI that interacts with people. Usually a matter of copy, not a rebuild.

4. Handle literacy. Give your team basic knowledge about the AI tools they use: what they do, where the risks are, and the house rules.

5. Record it. Document your AI inventory, your risk assessment, and the measures you took. This is your evidence in an inspection.

6. Make it repeatable. AI changes fast. Build these steps into your standing processes rather than ticking them off once.

Need help?

Most businesses can handle the currently applicable duties themselves with this plan. Where it gets harder is the risk-class assessment for borderline cases and building transparency and governance into AI systems you already use. NordX helps Dutch businesses map their AI use, determine the right duties, and arrange them in practice — without turning it into a bigger project than it is.

In short

For most businesses the AI Act is not a high-risk project but two duties that apply now or soon: AI literacy and transparency. First decide whether you are high-risk (usually not), then handle transparency and literacy, and record what you did. Start now and you will not be caught out.

Sources

Frequently asked questions

Does the AI Act apply to my business?

Most likely yes, but usually in a limited form. As soon as you use AI — a chatbot, ChatGPT, or AI inside existing software — the AI literacy duty (Article 4) applies, and where AI interacts with customers, the transparency duty (Article 50). The heavy high-risk obligations only touch a small share of businesses.

Which AI Act obligations already apply?

Since 2 February 2025 the prohibited practices (Article 5) and the AI literacy duty (Article 4) apply. The transparency duty (Article 50) takes effect on 2 August 2026. The high-risk obligations have been proposed for deferral to December 2027 via the Digital Omnibus.

Is my business a 'high-risk' AI user?

Usually not. High-risk concerns specific uses such as AI in recruitment, credit scoring, or critical infrastructure. A chatbot, text generation, or internal process automation generally does not fall under it. The transparency and literacy duties, however, apply broadly.

What does AI Act compliance cost?

For most businesses the currently applicable duties are mainly a matter of taking inventory, adding a few visible disclosures, and giving your team basic knowledge — that takes days, not months. NordX helps map your AI use and arrange the duties that actually apply to you.

Meer weten? Bekijk onze andere artikelen op het NordX blog of neem contact op via nordx.ai.