
AI Act explained: what EU rules mean for your organization (and when)
20 September 2026
The AI Act is the world's first comprehensive AI legislation — and since this year no longer theory but practice: the first rules already apply, supervisors are active, and via the Digital Omnibus amendment proposal the toughest deadlines for high-risk AI have been postponed to 2027 and 2028. For many organisations, this is precisely the challenge right now: no panic, but definitely an agenda. In this blog we explain what the AI Act is, what already applies, what changes and which steps an organisation logically takes in 2026.
What is the AI Act?
The AI Act (officially: AI Regulation) is the European law that regulates AI systems based on risk. The principle: the greater the risk to safety and fundamental rights, the stricter the requirements. The law applies throughout the EU — also for companies outside the EU that offer or use AI in Europe. For Dutch organisations this means: no separate Dutch AI law, but one European framework law with Dutch supervisors (including the Data Protection Authority).
The risk ladder shows the system at a glance:
Risk level | Examples | Regime |
|---|---|---|
Prohibited practices | social scoring by governments, manipulative AI | already prohibited since Feb 2025 |
High-risk (Annex III) | AI in recruitment & selection, credit assessment, education, healthcare | strictest requirements: risk analysis, human oversight, documentation — deadline postponed to Dec 2027 |
Limited risk | chatbots, AI-generated content (deepfakes) | transparency: make clear that you're interacting with AI — applies since Aug 2026 |
Minimal risk | spam filters, recommendation algorithms | no obligations; code of conduct suffices |
The AI Act deadlines: what applies when?
The AI Act was phased in — and the Digital Omnibus proposal has adjusted the key date:
2 February 2025 — prohibited practices + AI literacy. The prohibitions are in force and organisations that professionally deploy AI must ensure staff has sufficient AI knowledge.
2 August 2025 — GPAI. Rules for general-purpose AI models (such as large language models) and the European code of conduct.
2 August 2026 — transparency and oversight. Transparency duties (you see/hear when you're interacting with AI; deepfakes must be marked) and national oversight and sanctioning powers are active.
2 December 2027 — high-risk (Annex III). Was 2 August 2026; extended through the Digital Omnibus proposal. Then full requirements for AI in recruitment, credit, education, healthcare and more apply.
2 August 2028 — high-risk in regulated products (Annex I). AI in machinery, medical devices and similar products gets an extra year.
2030 — legacy systems. High-risk systems already on the market before the law have until 2030 to comply.
What is the Digital Omnibus proposal?
In May 2026, the European Commission presented the Digital Omnibus: a clean-up package intended to simplify the AI Act. The essence:
Extension of high-risk: the Annex III deadline moves from 2 August 2026 to 2 December 2027 (Annex I to 2028) — extra time because European standards for these systems are not yet ready.
Less overlap: rules are trimmed where they duplicate existing legislation (including privacy).
New prohibitions: the package adds some new prohibited practices.
Important to remember: this is a simplification, not a rollback. The risk approach, transparency requirements and oversight remain intact. For organisations it mainly means: more time to do it right.
What does the AI Act mean in practice for your organisation?
Four questions that should be on the table in 2026:
Which AI are we already using? From recruitment software to the chatbot on the website: without an overview no risk analysis. This is the step almost every organisation skips.
Does anything fall under high-risk? AI in recruitment, performance assessment, credit or access to services quickly becomes high-risk. If so: start with documentation and human oversight — that takes time.
Who is responsible? Provider (builds or markets AI) or deployer (deploys AI)? The roles determine which obligations fall on your shoulders — and who is liable for errors.
Is transparency correct? Customers, employees and candidates must know when they're dealing with AI. That is the requirement organisations most easily overlook — and which has applied since August.
The three misconceptions companies have about the AI Act
1. "The AI Act is postponed"
No: only the high-risk requirements are extended. The prohibitions, the AI literacy requirement, the transparency rules and oversight apply now. Organisations waiting until 2027 are still obligated.
2. "We don't build AI ourselves, so it doesn't apply to us"
If you buy and deploy AI tools — a recruitment tool, a credit model, a customer service bot — you are a deployer and part of the obligations fall on you. For SMEs in particular, this is the misconception that is most costly.
3. "This is an IT issue"
The AI Act affects HR, customer contact, compliance and management. The risk analysis alone is a collaborative task. Companies that leave it to IT discover too late that the real questions lie elsewhere.
Why now is the moment to start the conversation
The transparency rules already apply — anyone deploying AI without making it clear is already operating in the risk zone.
The high-risk requirements are coming into view (Dec 2027): a risk analysis and governance setup take months, not weeks. Start in October and you'll be on time.
October is AI month: World Summit AI (7-8 Oct), AI & Big Data Expo Europe (19-20 Oct, RAI), AI010 Congress Rotterdam (15 Oct), AI & Real Estate (7 Oct) and AI & Government (12 Nov) — the agenda where the country discusses its AI questions.
The specialist media proves the interest: "AI Act explained" content ranks via consulting firms and law firms; clear summaries are scarcer than the demand.
Speakers who make the AI Act understandable
Want to bring this topic into a conference or team programme? The voices that understand both AI and the rules of practice — all speakers on technology & AI:
Dr Irina Mirkina — AI ethics and responsible AI: the STEM door to the conversation about regulation → Profile Irina Mirkina
Vincent Roders — AI in organisational practice: what works, what doesn't, what's mandatory → Profile Vincent Roders
Robbert van Empel — AI and the future of work: the high-risk zone (recruitment, assessment) on the workplace → Profile Robbert van Empel
Kim Pot — behaviour and communication around tech: the door of adoption, not of law → Profile Kim Pot
Bianca Best — performance and performance pressure in the AI era: the human side of automation → Profile Bianca Best
FAQ
When does the AI Act come fully into force?
Phase by phase: prohibitions and AI literacy since February 2025, transparency and oversight since August 2026, high-risk systems on 2 December 2027 (Annex I: August 2028). Some legacy systems have until 2030.
Is my AI system high-risk?
Quick check: if the system falls in a sensitive sector — recruitment, performance assessment, credit, education, healthcare, access to services — there's a good chance it is. Full classification is in Annex III of the law; advice is always a risk analysis.
What does the AI Act mean for SMEs?
Usually as a procuring party (deployer): an overview of AI in use, transparency to customers and employees, and for sensitive applications oversight and documentation. The law also includes SME relief: higher thresholds and free support via the European Digital Innovation Hubs system.
What is the Digital Omnibus proposal?
The Commission's simplification package (May 2026): extension of high-risk deadlines to Dec 2027/2028, less overlap with other EU legislation and some new prohibitions. Not a rollback of the law.
Put the AI question sharply on the agenda
For a conference, a board day or a team moment where AI is discussed not as hype but as reality: a custom proposal within 2 hours — filling halls is our craft.
Illustration risk ladder / scale — alt: "AI Act explained risk levels prohibited high-risk transparency"
Conference hall photo — alt: "AI Act keynote conference speaker hall"
Office image team meeting — alt: "AI Act for organisations risk analysis team meeting"
Timeline (Feb 2025 prohibitions+literacy, Aug 2025 GPAI, Aug 2026 transparency+oversight, Dec 2027 Annex III, Aug 2028 Annex I, 2030 legacy): EU digital-strategy + multiple independent updates (confirmed in both search result sets)
Digital Omnibus: Commission proposal May 2026 — extension of high-risk to 2 Dec 2027 (Annex I 2028), less overlap, new prohibitions (Latham & Watkins, ICL, MEP-support-news, digital-strategy)
"AI literacy requirement already applies + enforcement since 2 Aug 2026": letter analysis (AI Act Deadlines Reset)
High-risk examples (recruitment, credit, education, healthcare): Annex III; DPA as NL supervisor
AI month October: Events NL-BE database (WSAI 7-8 Oct Zaandam, AI & Big Data Expo 19-20 Oct RAI, AI010 15 Oct South Wing, AI & Real Estate 7 Oct The Hague, AI & Government 12 Nov)
SERP-check: "AI Act explained" is dominated by consulting firms/law firms (Deloitte, ICTRecht, DPA) — understandable NL knowledge base entry point is open; "AI speaker" SERP = bureaus + independent AI speakers, Smidswater absent (opportunity for later transactional variant)
Speakers from /themas/technologie-ai (20-09 scraped): Mirkina, Roders, van Empel, Pot, Best — descriptions deliberately kept light and non-claiming (no speaker claims about AI Act itself)
Noah's choice: purely informational theme block; speakers below as "voices that make it understandable" — not central



