07 Aug '26
The Artificial Intelligence Regulation 2024/1689 (AI Act) aims to make the use and development of AI systems safer, so that people and businesses in the EU can gain and maintain confidence in this technology. New obligations came into force on 2 August 2026. From that same date, the European Commission’s AI Office, together with the national authorities, will also begin enforcing the AI Act.
The new obligations primarily entail more extensive transparency requirements for providers of AI systems. The measures are designed to ensure that users know when they are interacting with AI and that artificially generated content is labelled as such. Under these transparency rules, certain AI systems must make it clear when users are interacting with AI and when content has been generated or modified by it. For example, chatbots and other interactive AI systems must inform users that they are interacting with AI and not with humans. In addition, from 2 August 2026, so-called deepfakes (images, videos or audio edited or generated using AI) must be labelled. Furthermore, content generated or modified by AI must contain a machine-readable marker, making it easier to detect such content. The aim is to reduce deception and manipulation and to help people make informed choices.
From 2 August 2026, the European Commission’s AI Office, together with national authorities, will begin enforcing the AI Act. The European Commission can now enforce compliance with the rules of the AI Act for General Purpose AI (GPAI) models. GPAI models are those that offer a wide range of functions and services; examples include ChatGPT and Copilot. For instance, all providers of GPAI must keep records of certain information and provide this to the competent authorities. Enforcement will also focus on the aforementioned transparency obligations and on so-called prohibited AI practices. How effective the enforcement of the AI Act will be will also depend on the Member States. It is up to them to ensure that the competent authorities are correctly designated and have sufficient resources.
In the Netherlands, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (Dutch DPA) and the Dutch Authority for Digital Infrastructure share responsibility for coordinating the supervision of AI. The Dutch DPA is responsible for supervising the obligations discussed in this blog. In 2023, the Dutch DPA established a separate organisational unit for the supervision of AI, called the Algorithm Coordination Directorate (DCA).
On 2 August 2026 other obligations were also to come into force; however, this entry into force has been deferred. These obligations relate to the so-called high-risk AI systems. These are AI systems whose use could pose a serious risk of harm to health, safety or the protection of fundamental rights. High-risk AI systems are listed in Annex 1 and Annex 3 of the AI Act. Annex 1 covers AI systems as products or as safety components in already strictly regulated physical products, such as toys or medical devices. Annex 3 provides a list of specific sensitive areas of application and sectors. Examples include AI systems used in critical infrastructure, educational institutions or the provision of consumer credit.
These obligations, which are yet to come into force, concern strict requirements for high-risk AI systems. For example, high-risk AI systems must be subject to adequate risk assessments and mitigation measures. Providers of high-risk AI systems must also keep a record of their activities so that the results can be traced. The new obligations are also intended to ensure that the risk of harm that high-risk AI systems may cause is limited through the incorporation of systematic control mechanisms. These obligations for the high-risk AI systems listed in Annex 3 of the AI Act are now scheduled to come into force on 2 December 2027. The entry into force of these obligations for the AI systems listed in Annex 1 of the AI Act is scheduled for 2 August 2028.
With these newly enacted rules relating to the AI Act, a further step has been taken towards establishing an effective set of tools to ensure the safety of AI systems. Ploum is closely monitoring the latest developments regarding the AI Act. Would you like to know more? Please contact Matthijs Gardien, Bine Schoenmaker and/or Daan Augustijn.
Contact
07 Aug 26
30 Jul 26
15 Jul 26
13 Jul 26
07 May 26
07 May 26
28 Apr 26
20 Apr 26
25 Mar 26
25 Mar 26
19 Mar 26
19 Mar 26
Met uw inschrijving blijft u op de hoogte van de laatste juridische ontwikkelingen op dit gebied. Vul hieronder uw gegevens in om per e-mail op te hoogte te blijven.
Stay up to date with the latest legal developments in your sector. Fill in your personal details below to receive invitations to events and legal updates that matches your interest.
Follow what you find interesting
Receive recommendations based on your interests
{phrase:advantage_3}
{phrase:advantage_4}
We ask for your first name and last name so we can use this information when you register for a Ploum event or a Ploum academy.
A password will automatically be created for you. As soon as your account has been created you will receive this password in a welcome e-mail. You can use it to log in immediately. If you wish, you can also change this password yourself via the password forgotten function.