
De opkomst van kunstmatige intelligentie (AI) en data-analyse biedt enorme kansen voor bedrijven. Tegelijk ontstaan er nieuwe AI legislation om AI veilig en verantwoord te laten verlopen. The European AI Act and Data Act are recent laws that businesses in the Netherlands cannot ignore. These regulations require AI compliance – demonstrably meeting legislation for safe AI and careful data use. What do the AI Act and Data Act entail, and how can you ensure that AI for businesses stays within the rules? In this article, we answer these questions and provide practical tips for compliance and data governance.
Table of Contents
What is the AI Act?
The EU AI Act is the world’s first comprehensive law on artificial intelligence, which came into force on 1 August 2024. This AI Act (officially Regulation (EU) 2024/1689) establishes a risk-based framework for the use and development of AI systems. Put simply, the classifies AI applications into categories ranging from unacceptable risk (prohibited) to high, limited and minimal risk. Specific obligations apply to each level:
- High-risk AI: AI systems that can have a significant impact on a person’s safety or rights (such as AI in medical devices, recruitment or lending) are referred to as ‘high-risk’. Developers of such systems must meet strict requirements in the areas of risk management, data quality, technical documentation, transparency and human oversight. This includes conducting risk analyses, maintaining logs and ensuring human oversight before the AI is used. These AI systems must also obtain CE marking/certification before they are placed on the market.
- Prohibited AI: Some AI applications are banned outright because they pose an unacceptable risk, such as AI used for manipulation or social credit scoring.
- Low-risk AI: This refers to AI such as chatbots or generative AI that interacts with people. In this context, the AI Act primarily mandates transparency: users must be aware that they are dealing with a machine or that content has been generated by AI. For example, if your company uses an AI chatbot on its website, it must be clear that this is not a human.
The AI Act focuses on both “providers” (developers/suppliers of AI systems) and “users” (organisations that implement AI). This means that not only tech companies, but all organisations that use AI must comply with the rules. From February 2025, the first obligations will apply to certain AI systems. From then on, for example, organisations must stop using prohibited AI and ensure that staff have sufficient AI knowledge. Most other requirements (e.g. for high-risk AI) will follow gradually in 2025 and 2026. In short: the law is in place, and the rules will come into effect gradually over the coming years – so companies now have a transition period to prepare.

What is the Data Act?
The EU Data Act (officially Regulation (EU) 2023/2854) is a new European law that regulates the fair use of and access to data. Whereas the AI Act focuses on AI systems, the Data Act centres on data sharing and data rights. This law aims to make data exchange between businesses, consumers and public authorities smoother and fairer, whilst respecting confidentiality and competition. Some key points of the Data Act for businesses:
- Access to IoT and device data: Companies that provide ‘smart’ products or services (e.g. sensor-equipped devices, vehicles, smart machines) must give users access to the data generated by those devices. Consider a manufacturer of smart agricultural machinery that must share agricultural data with the farmer using the device. This gives customers greater control over their own data.
- Data sharing on request: At the request of a user or a third party, data controllers must make certain data accessible, subject to reasonable conditions. This is intended to stimulate innovation – for example, a car dealer may request data from a car manufacturer to provide better maintenance services, provided the customer consents. Contracts that unnecessarily restrict data sharing will be declared invalid.
- Cloud and switching services: The Data Act also includes rules to make it easier for customers to switch from one cloud service to another (portability) without excessive costs or technical barriers. Cloud and data service providers will have to adapt to this so that lock-in decreases.
Government requests in emergencies: In exceptional circumstances (such as public emergencies), the government may demand access to certain private data. Companies must then provide data under strict conditions, for example to manage disasters.
For Dutch companies, the Data Act primarily means that they must ensure their data governance is in order. You need to know what data your products and systems generate, who has access to it, and how you can share it securely. The Data Act was adopted on 13 December 2023 and will also come into force in phases. Companies are expected to comply with most provisions from September 2025. This allows some time to adapt data flows and contracts, but it is important to start identifying now where adjustments are needed.
Why are the AI Act and the Data Act important for businesses?
New obligations and the risk of fines: For businesses, the AI Act and Data Act mark a major shift. Whereas AI development and data use have been largely unregulated until now, a clear framework with strict requirements is now emerging. Failure to comply carries the risk of substantial penalties. Fines under the AI Act can amount to €30 million or 6% of global annual turnover – comparable to the highest fines under the GDPR (privacy legislation). The Data Act also imposes fines (to be determined by each EU country) on companies that cut corners. The financial and reputational risks of non-compliance are therefore considerable.
Protecting rights and trust: At the same time, these laws have been introduced to boost trust in AI and data. They complement the existing privacy regulations (GDPR). Whilst the GDPR protects personal data, the AI Act ensures that AI systems are secure, transparent and human-centred, and the Data Act ensures that data is shared fairly. Together, they form a basis for enabling innovation without compromising the rights of citizens and customers. For businesses, compliance can therefore also be an opportunity: it demonstrates that you handle AI and data responsibly, which instils confidence in customers and partners.
Impact on business operations: In practice, many departments within your organisation will be involved in this. Legal teams, IT departments, data analysts, HR – all will have to deal with new procedures. For example, HR must pay attention to AI tools used in recruitment (is this still permitted, does it meet non-discrimination requirements?), and IT must ensure that data from your products can be exported by customers. This is likely to involve additional administrative work, such as drawing up technical documentation for AI (for high-risk systems) and keeping track of where your data is stored and with whom it is shared. This requires investment in expertise and possibly new roles, such as an AI compliance officer or data steward.
The Netherlands is leading the way: It is worth noting that the Netherlands aims to take the lead with this AI legislation. The Dutch government has even announced that it will apply the core provisions of the AI Act with immediate effect even before the law comes fully into force across the EU. In a policy document dated January 2024, the government stated that the AI Act is already regarded as applicable law in the Netherlands. In other words: regulators and government bodies (such as the Dutch Data Protection Authority for AI) are already preparing to enforce it. Companies would therefore be wise not to wait, but to take action now.
How is your company preparing for this AI legislation?
As the AI Act and Data Act are due to come into force shortly, it is crucial to ensure your organisation is prepared in good time. Here are a few steps you can take now to ensure proper AI compliance and data compliance:
How does Your Tech Club ensure the safety of its AI?
At Your Tech Club , we believe in leading by example. As a tech company, we use AI innovatively, but always with an emphasis on safety and ethics. For example, we carry out internal AI audits on the tools and models we develop – we test for biases, privacy and reliability before deploying anything to clients.
We have also drawn up a clear AI code of conduct: AI must never make autonomous decisions that have a significant impact without human oversight. Our teams regularly receive training on the latest AI guidelines and risks, ensuring everyone is “AI-aware”. Furthermore, we work according to strictly certified processes (such as ISO 27001 for information security), which aligns seamlessly with AI compliance requirements. All of this ensures that we apply secure AI and can help our clients do the same – from advising on AI risks to building AI solutions that comply with the law.