EU AI Act for Dutch organizations: what you really need to know and do

May 8, 2026 · Joos Luteijn · 8-minute read

A practical guide, not a legal text

On May 7, 2026, Europe decided that some parts of the AI Act would take effect later than planned. Organizations that use AI to assess people—such as CV screening, loan applications, municipal benefits, and school results—have until December 2027 instead of August 2026. It sounds like a relief, and for some, it is.

However, nothing changes for the most important part of the law. AI literacy among your employees has already been required since February 2025. Unacceptable AI applications remain prohibited. And if someone in your organization misuses AI, the bill lies with you as the employer, regardless of which date is stated in the law.

This guide explains what the AI Act means for your organization. What is mandatory, what is not, and what to do if you haven't arranged anything yet. With practical examples and without having to hire a battery of lawyers first.

Does this law actually apply to my organization?

Almost certainly, yes. The law distinguishes between those who make AI and those who use AI. The makers are a handful of large companies (OpenAI, Microsoft, Google). The users are virtually everyone. If your people use Copilot in Word, ChatGPT in the browser, or an AI chatbot on the website, then you fall under the law.

Three common misconceptions:

  • “We do not develop AI, so this does not affect us.” That is incorrect. Anyone who deploys AI bears independent obligations, even if the tool belongs to someone else.
  • “We are too small for this law.” That is incorrect. The size of your company does not matter. However, there are lighter obligations and proportional supervision for SMEs.
  • “Our AI is for internal use only, so no problem.” That is incorrect. Internal use is covered by the law just as much as external use.

The four risk levels, with examples from practice

The law does not look at which AI you use, but at what you do with it. The same model can be low risk in one context and high in another. Four levels, increasing in severity.

1. Forbidden

AI that you are simply not allowed to deploy. For example, systems that monitor employees' emotions during their work (think of call center software that measures “stress”), AI that manipulates vulnerable groups, or social scoring where people receive a general “score” based on their behavior. Since May 7, one application has been added: AI that generates non-consensual sexual images or abusive material. That ban takes effect on December 2, 2026.

2. High risk

AI used to make decisions that directly affect people. This is the category receiving the most attention, and rightly so. Examples:

  • A recruiter who uses AI to screen resumes or rank candidates.
  • A bank or leasing company that uses AI for loan applications.
  • A municipality that uses AI to assess benefit applications or detect fraud.
  • An educational institution that uses AI for admissions or for assessing exam work.
  • A healthcare institution with AI in medical equipment that supports diagnoses.

For these applications, the law requires that you know what the system does, can demonstrate that it operates fairly, that a human can intervene, and that you document its use. Not impossible, but certainly work. Last week, the deadline was pushed back to December 2027, or August 2028 if the AI is embedded in a physical product (medical equipment, machinery).

3. Limited risk

AI about which you must be transparent, but for which few rules apply otherwise. A chatbot on your website must make it clear that it is not human. AI-generated content (images, video, audio) must be provided with a digital watermark as of December 2, 2026. Customer service using AI to formulate answers must mention this in their communication.

4. Minimal risk

Virtually everything you use daily. Spam filters in Outlook, grammar check in Word, Netflix recommendations, translations via Google Translate, autocomplete on your phone. No obligations under the AI Act, although the GDPR and other legislation remain applicable.

The practical question is: in which category does AI usage fall within my organization? For most companies, the answer is: primarily minimal and limited, sometimes high risk. Those who do not engage in recruitment, credit assessment, or make government decisions are rarely in a high-risk category.

Which deadlines take effect when

Due to the Omnibus deal of May 7, some dates have been shifted. Below is the current status.

WhatWhen
Prohibited AI applications (Article 5)Already in effect since February 2, 2025
AI literacy among employees (Article 4)Already in effect since February 2, 2025
Obligations for large AI models (GPAI)Already in effect since August 2, 2025
Enforcement begins, transparency and governance rulesAugust 2, 2026
Ban on non-consensual sexual AI content + watermarksDecember 2, 2026
High-risk AI (CV screening, loans, benefits, education)December 2, 2027
High-risk AI embedded in products (medical equipment, machines)August 2, 2028

What stands out: the top three rules are already in effect. Companies that have not yet taken any action have therefore been in violation regarding AI literacy for more than a year. Serious enforcement of this will begin in August 2026. The postponement of high-risk AI to 2027 changes nothing in this regard.

What AI literacy actually is

The AI Act does not require specific training or a certificate. It requires that the people in your organization who work with AI know what they are doing. The law calls this an “adequate level of AI literacy.” What that entails depends on the role.

In concrete terms, this means that:

  • A recruiter who uses an AI screening tool knows how the system arrives at a ranking and can argue why he or she deviates from it.
  • A marketing employee which uses ChatGPT for customer emails, checks the output for factual errors and knows when things might go wrong.
  • A HR Business Partner can explain to an applicant why AI was used in the selection process, how the decision was made, and what the applicant can do if he or she disagrees with it.
  • A customer service representative knows when a conversation becomes too complex for the AI chatbot and needs to be taken over.
  • A Director who approves AI tools for his department knows which questions to ask before signing.

A single general two-hour training session for the entire company is rarely sufficient, because different roles require different knowledge. A receptionist who uses ChatGPT for a birthday card needs less than a recruiter who assesses career paths.

The good news: for most roles, literacy at the level of “I know what I can and cannot ask AI, I recognize when something goes wrong, I know who to call” is sufficient. That is achievable in a few hours per role, provided the content is correct.

Five steps to get a grip

Compliance works best as a project plan, not as a knee-jerk reaction. Five steps that will take you to a workable foundation in 8 to 12 weeks.

Step 1. Make a list of all AI used in your organization.

Not only the tools IT has purchased, but also what employees have found themselves. Research shows that organizations have visibility into less than 11 percent of actual AI usage. The rest is “shadow AI”: ChatGPT accounts under personal email addresses, browser plugins, and AI features in tools you have been using for years without realizing it.

Ask in every team: which AI are you using? Guarantee that the answer will have no consequences. The first time you do this, you will be shocked. The second time, your life will be much easier.

Step 2. Sort into which risk category each AI falls

For most tools, this is straightforward. ChatGPT for writing internal memos is minimal or limited risk. ChatGPT for selecting applicants is high risk, regardless of whether the tool is the same. Usage determines the category, not the brand.

Step 3. Measure what your people know about AI

Before you invest in training, you need to know where you stand. A short questionnaire distributed to each team provides insight into three things: what individuals know, how the team stands as a whole, and how your organization's policies align. Without a baseline assessment, you are training haphazardly.

Step 4. Train specifically for what is needed per role.

Based on the baseline assessment, you know who needs to learn what. The recruiter receives something different from the marketer. The L&D manager receives something different from the IT architect. Document what people have taken and what they know about it afterwards. That is your evidence for supervisory authorities as well as for potential lawsuits.

Step 5. Keep it alive

AI changes faster than any learning program. A new tool this month can be everywhere in your organization a week later. A quarterly check on new tools, new roles, and new risks prevents you from being back at step 1 in a year. Compliance is not a project with an end date; it is a habit.

What if things go wrong: fines and liability

The fine amounts in the news are shocking (up to 35 million euros), but unrealistic for most organizations. Regulators have announced that enforcement will be proportionate. In the first months of enforcement, the focus will be on clear offenders, not on companies that are visibly at work.

What is underestimated are two other risks:

  • Civil liability. If a job applicant or customer suffers damage because your employee misused AI, they can sue your organization. This bypasses the regulator and can end up being more expensive than a fine.
  • Reputational damage. Whoever is the first to make the news with a discriminated job applicant or a data leak caused by careless AI usage carries that burden for years. Fines are written off, headlines are not.

The simple advice: if you can demonstrate that you are taking AI literacy and risk management seriously, you stand strong. Not only against the regulator, but also in any potential lawsuit.

Compliance is not an afterthought, it is a good foundation.

At Transforming the Dots, we see that the organizations navigating the AI Act most smoothly are not the ones that have allocated the most budget. They are the organizations using compliance to finally get a grip on something that has been creeping in for a long time.

The law effectively enforces what is best for the organization itself: knowing which AI you use, knowing the associated risks, and ensuring that your people can handle it responsibly. That is not a cost; it is the foundation upon which AI usage can grow safely.

The question, therefore, is not whether you comply with the law. The question is whether you have a grip on what AI is doing in your organization. The former follows automatically from the latter.

Where does your organization stand?

The AI Maturity Scan It maps where you currently stand across six dimensions: strategy, governance, data, technology, people, and culture. You receive a concrete roadmap towards compliance as well as broader AI adoption. The scan combines a short questionnaire with expert interviews and delivers a dashboard plus a report with recommendations.

For organizations that do not want to use the Omnibus Deal as an excuse to postpone, but want to utilize the extra time strategically, this is the fastest way to get a grip.

Frequently Asked Questions

Yes. Almost all organizations are “users” of AI, even if they purchase the tools from others. An HR team working with an AI screening tool, a marketing team deploying ChatGPT, customer service with a chatbot: all users, all with their own obligations.

Usually not. It depends on what you do with it. ChatGPT for writing internal memos is limited or minimal risk. ChatGPT for assessing job applicants or loan applications is high risk, not because of ChatGPT itself, but because of what you have done with it.

For most organizations, little. The deadlines for strictly regulated AI (CV screening, loans, education, municipal decisions) are being pushed back to December 2027. However, the obligation to make your employees AI-literate has been on the agenda since February 2025 and has not been moved. For those working on literacy, nothing actually changes.

Then you remain responsible. If an external agency screens your applicants using AI, you remain liable for anything that goes wrong. Establish in advance what the partner does, how you can monitor it, and what happens if things go wrong.

For AI literacy: an overview of who learned what, at what level, and when. For high-risk AI: a description of the system, how to mitigate risks, how people can intervene, and usage logs. It does not need to be extensive, but it must be current and verifiable.

Step 1: taking stock. Without insight into what is actually happening in your organization, all subsequent choices are guesswork. This can be done in two to four weeks through a short survey and targeted conversations. It often turns out that the real priority is much lower than the rumors suggest.

Sources and further reading

Official sources

Market research and context

  • Awareways Trend Report 2025 (published 2026), shadow AI usage among 33,690 respondents.
  • KPMG Algorithm Trust Monitor, Microsoft Work Trend Index 2025-2026, and BlackFog research on shadow AI in work environments.

About the author

Joos Luteijn has worked in strategy, technology, and organizational development for over 20 years. For the past two years, he has guided change processes related to AI adoption at Essent, was previously Digital Manager at Eneco, Toon, and Oxxio, and is a guest expert on the Studio Beeckestijn podcast about AI adoption. Through Transforming the Dots, he helps organizations get a grip on AI adoption via research, advice, and coaching.