Skip to content
Stratalytic

DATA DRIVEN DECISIONS

AI & Legislation

EU AI Act 2025: Complete Compliance Checklist for Dutch Businesses

Published:

European Union flag with digital AI network overlay

Key Takeaways: Since February 2, 2025, certain AI systems are prohibited and AI literacy is mandatory. Fines can reach €35 million or 7% of global annual turnover. Most Dutch businesses use low-risk AI and only need to meet basic requirements, but proactive compliance can deliver significant competitive advantage.

What is the EU AI Act and Why Does It Matter Now?

The EU AI Act is the world's first comprehensive AI legislation, establishing rules for the development, sale, and use of AI within the EU. The first obligations have been in effect since February 2025, and the Dutch Data Protection Authority is actively preparing enforcement, waiting is no longer an option.

The regulation officially entered into force on August 1, 2024, and is being implemented in phases, meaning different obligations apply at different times. For Dutch businesses, this isn't something for the future, the first obligations have been in effect since February 2025, and the Dutch government has indicated that the AI Act is a priority.

The Dutch Data Protection Authority serves as the coordinating supervisory authority and is actively preparing for enforcement. In a vision document, the government indicated that the AI Act is already being treated as applicable law in the Netherlands, meaning supervisory authorities are preparing to enforce even before all European deadlines have passed. Waiting is simply no longer an option.

The Four Risk Categories Explained

The AI Act classifies AI systems into four risk categories: unacceptable (prohibited), high risk (strict requirements from August 2026), limited risk (transparency obligations) and minimal risk (AI literacy only). Requirement stringency increases with the risk level.

Unacceptable Risk: What's Prohibited?

Certain AI applications are simply prohibited because they violate fundamental rights. This includes AI systems that manipulate human behavior in ways that can cause harm, social scoring systems by governments, real-time biometric identification in public spaces (with limited exceptions for law enforcement), AI for emotion recognition in the workplace or education, and predictive policing systems based on profiling.

It's essential to understand that these systems have been prohibited since February 2, 2025. Using or offering them can lead directly to enforcement, with fines that can reach €35 million or 7% of global annual turnover, whichever amount is higher.

High Risk: Strict Requirements, But Not Impossible

AI systems that can significantly impact safety or fundamental rights are subject to strict requirements. Think of AI for HR and recruitment (CV screening, job interviews, promotion decisions), credit assessment (mortgages, loans, credit cards), education (admission or performance assessment), essential services (access to healthcare or social benefits), and critical infrastructure (transport, energy, water supply).

These systems will be subject to extensive obligations regarding risk management, documentation, human oversight, and conformity assessment from August 2, 2026. This sounds overwhelming, but most Dutch businesses, especially SMEs, don't use these types of AI. However, it's crucial to verify this within your own organization.

Limited Risk: Transparency as Core Obligation

AI systems that people interact with directly, such as chatbots or generative AI, are subject to transparency obligations. Users must know they're dealing with AI, AI-generated content must be recognizable as such, and deepfakes must be clearly marked.

These obligations are less extensive than for high-risk systems, but non-compliance can still lead to sanctions. Moreover, transparency contributes to customer trust in your organization, an aspect that's becoming increasingly important in a market where AI scandals regularly make the news.

Minimal Risk: The Baseline

AI applications without specific risks, think spam filters, AI in video games, or logistics optimization, are subject to minimal or no specific obligations. However, the AI literacy requirement applies to all AI users, regardless of risk category.

AI Literacy: Mandatory Since February 2, 2025

Since February 2, 2025, all organizations that develop or use AI must ensure their employees have basic knowledge of AI operation, risk awareness, ethical considerations, practical skills, and rights and obligations under the AI Act. The required depth depends on the role and type of AI system.

According to the Dutch Data Protection Authority and the European Commission, an effective AI literacy program should include basic knowledge of what AI is and how it works, risk awareness about the potential dangers of AI systems, ethical considerations for fair and responsible deployment, practical skills for correct use in daily work, and insight into rights and obligations under the AI Act.

The required depth depends on the role and type of AI system. Employees who only use simple AI tools, such as a customer service chatbot, need basic training. Employees working with high-risk AI systems, such as HR selection tools, need more extensive training. Executives and decision-makers about AI implementation need strategic insight into both possibilities and risks.

The good news is that AI literacy doesn't necessarily require expensive external training. The Dutch Data Protection Authority has published an action plan with concrete steps organizations can take, and much knowledge can be built internally by employees who already have experience with AI tools.

Concrete Step-by-Step Plan for Compliance

AI Act compliance follows five steps: AI inventory (map all applications), risk categorization per system, gap analysis against requirements, implementation plan with deadlines and responsibilities, and structural embedding via an AI compliance officer and periodic reviews.

The second step is risk categorization. Determine which category each AI system falls into. If it's a prohibited application, stop immediately. If it's high risk, prepare for extensive compliance. For transparency obligations, implement the required notifications. If it's minimal risk, focus on AI literacy.

Next, conduct a gap analysis by comparing your current situation with the requirements. Do you have documentation about your AI systems? Is human oversight arranged? Are employees sufficiently trained? Have you designated a responsible person? The answers to these questions determine where your priorities lie.

Based on this analysis, create an implementation plan with concrete deadlines and responsibilities. In the short term, address AI literacy and check for prohibited systems. In the medium term, arrange documentation and risk management for any high-risk systems. In the long term, build a governance structure for continuous monitoring.

Finally, ensure structural embedding by designating an AI compliance responsible person, integrating AI compliance into existing governance (think of your GDPR structure), and planning periodic reviews.

Fines and Enforcement: The Risks Made Concrete

Fines under the AI Act can reach 35 million euros or 7% of global turnover for prohibited AI systems, 15 million euros or 3% for non-compliance with high-risk obligations, and 7.5 million euros or 1% for providing incorrect information. SMEs and startups are treated proportionally. For using prohibited AI systems, the maximum is €35 million or 7% of global turnover. Non-compliance with high-risk AI obligations can lead to fines of €15 million or 3% of turnover. The same maximum applies to non-compliance with transparency requirements. Providing incorrect information to supervisory authorities can result in fines up to €7.5 million or 1% of turnover.

The fine is calculated as the highest of both amounts. For a medium-sized company with €50 million turnover, the highest fine category means a potential fine of €3.5 million, an amount that would be existential for many organizations.

In the Netherlands, the Dutch Data Protection Authority has been designated as the coordinating supervisory authority, in cooperation with the National Digital Infrastructure Inspectorate and sector-specific supervisory authorities such as the AFM, DNB, and IGJ. At the European level, the AI Office supervises large AI models like ChatGPT and other general-purpose AI.

It's relevant to know that supervisory authorities take mitigating factors into account when determining fines: the severity and duration of the violation, previous violations, the size and market share of the organization, and the degree of cooperation with supervisory authorities. Specifically, SMEs and startups are treated proportionally, a violation by a small company won't automatically lead to the same fine as for a multinational.

Checklist: Is Your Organization AI Act-Compliant?

The basic obligations that already apply include five checks: AI inventory completed, no prohibited systems in use, basic training for AI users, demonstrable AI literacy, and transparency notifications for chatbots and generative AI. For these basic obligations, verify whether you have inventoried which AI systems you use, whether you're certain you don't use prohibited AI systems, whether employees working with AI have received basic training, whether you can demonstrate you're working on AI literacy, and whether you inform users with chatbots and generative AI that they're dealing with AI.

Organizations using high-risk AI must additionally verify before August 2026 whether they have a risk management system, technical documentation is available, logging and traceability are arranged, human oversight is secured, a conformity assessment has been conducted or planned, and registration in the EU database is prepared.

At the governance level, it's essential that a responsible person has been designated for AI compliance, AI policy is documented, there's a process for periodic review, and vendors have been informed of your compliance requirements.

The Timeline: When Must What Be Arranged?

Four crucial deadlines define your compliance planning: February 2025 (prohibited systems + AI literacy), August 2025 (general-purpose AI rules + fines possible), August 2026 (all high-risk obligations), and August 2027 (high-risk AI in products). On February 2, 2025, prohibited AI systems were no longer allowed and AI literacy became mandatory. On August 2, 2025, rules for general-purpose AI take effect, national supervisory authorities become fully operational, and fines can be imposed. On August 2, 2026, all obligations for high-risk AI systems take effect. And on August 2, 2027, high-risk AI systems as part of products, such as machines and medical devices, must comply with all requirements.

Compliance as Competitive Advantage

Early AI Act compliance strengthens customer trust, improves AI implementation quality through mandatory documentation and risk management, and opens doors to the entire EU market of 450 million consumers. Demonstrably responsible AI use strengthens the trust of customers and partners, especially in a market where AI scandals regularly make the news. Compliance thus becomes a differentiating factor.

The mandatory documentation, risk management, and human oversight also lead to better-controlled AI implementations. This reduces operational risks and improves the quality of AI-driven decisions, value that extends beyond compliance alone.

Moreover, the AI Act applies to the entire EU market. Compliance thereby opens doors to 450 million consumers and millions of businesses. And the regulatory sandbox provisions offer opportunities to develop and test innovative AI solutions under the guidance of supervisory authorities, which can be especially valuable for organizations wanting to be at the forefront of AI innovation.

Practical Resources

Three free government tools help you get started: the AI Regulation Decision Aid (determines applicability), the AI Literacy Action Plan from the Dutch DPA (step-by-step guide), and the AI Act Compliance Checker from the European Commission (initial compliance check). The AI Regulation Decision Aid from Digital Government determines through questions whether the regulation applies to your application. The AI Literacy Action Plan from the Dutch Data Protection Authority provides a step-by-step plan for setting up AI literacy within your organization. And the AI Act Compliance Checker from the European Commission is an online tool for an initial compliance check.

Next Steps

The AI Act is a reality, and waiting is no longer a strategy. The three most important actions you can take today are starting with an inventory of which AI systems are used within your organization, planning AI literacy so employees receive the right training, and determining your risk profile by identifying whether you use high-risk AI systems.

Do you need support with your AI Act compliance? Stratalytic helps organizations map AI usage, set up governance structures, and implement responsible AI. Get in touch for a no-obligation conversation.

Get the AI-subsidy radar

1 email per month. New subsidies, deadlines, and what changed for SMEs. 5-minute read.

Unsubscribe with one click. No spam, ever.

Let's talk business

Do you want to know how we can help you grow your business? Schedule free consultation with one of our experts and discover the possibilities.

Rutger Geerlings, founder of Stratalytic

Rutger Geerlings

Solution Architect

Discover what data and AI can concretely deliver

Latest cases

All cases