AI Compliance and Risk Management: How Dutch Businesses Navigate the EU AI Act
The EU AI Act is in force. Dutch companies using AI must comply with strict requirements for transparency, risk management, and human oversight.
Gepubliceerd door NordX Consulting — AI bureau voor enterprise bedrijven in Nederland.
AI governance is the set of arrangements by which your organisation decides who may deploy which AI, for what, and who checks the output. Under the AI Act that is no longer optional. This is how to set it up without building a compliance department — including where it meets AI cybersecurity and AI privacy under the GDPR.
The EU AI Act: What Every Dutch Entrepreneur Needs to Know
The EU AI Act is the world's first comprehensive AI legislation and applies to all companies that develop, deploy, or use AI systems in the European Union. For Dutch businesses, this means that virtually every AI application falls under the regulation.
The law uses a risk-based approach: the higher the risk of an AI system, the stricter the requirements.
The Risk Categories
Unacceptable Risk (Prohibited): Social scoring systems, real-time biometric identification in public spaces, and systems that manipulate unconscious behavior.
High Risk (Strict Requirements): CV screening and HR decisions, credit assessment, medical diagnosis support, safety systems in machinery, and biometric identification all require documented risk management, data governance, technical documentation, and human oversight mechanisms.
Limited Risk (Transparency Requirements): Chatbots must clearly indicate the user is communicating with an AI.
Minimal Risk (No Extra Requirements): Spam filters, recommendation systems, AI in video games.
The Compliance Timeline
Prohibited AI systems have been banned since August 2024. High-risk systems were due to be compliant by August 2026, but in June 2026 that deadline moved to 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in regulated products. The Article 50 transparency obligation and the Article 4 AI literacy duty were not postponed and continue to apply. See exactly what was and was not deferred. For most Dutch companies, there is urgency to act now.
Compliance is not a constraint but a competitive advantage. Companies that demonstrably handle AI responsibly build more trust with customers and partners and avoid costly fines and reputational damage.
Further Reading
- AI Implementation Costs Netherlands
- AI Consultant Netherlands: What Does He Do?
- Digital Transformation SME Step-by-Step Plan 2026
Sources
- Dutch Data Protection Authority: AI and privacy
- European Commission: EU AI Act
- ENISA: AI Cybersecurity Challenges
Frequently asked questions
What is AI governance?
The set of arrangements by which an organisation decides who may deploy which AI, for what, which risks are acceptable, and who checks the output. It is the organisational side of using AI, where compliance is the legal side.
Is AI governance mandatory?
Not as a separately prescribed document, but the AI Act imposes obligations you cannot demonstrate without governance: knowing which systems you use, transparency where AI communicates with people, demonstrable AI literacy, and for high-risk uses risk management and human oversight. Governance is how you organise that.
Who is responsible for AI governance in a company?
Ultimate accountability sits with the board, because it concerns acceptable risk. In practice it works when one owner is named per AI application, with someone keeping the overview. Shared responsibility without names does not work.
How do you start with AI governance?
With an inventory of what you already use, including the AI embedded in existing software. Then classify per application, name an owner per application, and record where a human must check. That is achievable without building a compliance department.
Related articles
Meer weten? Bekijk onze andere artikelen op het NordX blog of neem contact op via nordx.ai.