Topic
High-risk AI
The heaviest obligations in the AI Act apply to high-risk systems. The first question is not what you must do, but whether you fall under the category at all: a system can sit in an Annex III domain and still fall outside high risk. Below is what has been officially published, plus the route to the classification itself.
Official guidance on this topic
29- Regulation (EU) 2026/1744, Digital Omnibus on AIBinding amending regulation published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It amends the AI Act and several rules for regulated products. For the AI Act, it sets fixed application dates of 2 December 2027 for Article 6(2) and Annex III and 2 August 2028 for Article 6(1) and Annex I. It also retains registration after relying on Article 6(3), while simplifying the information in Annex VIII, expressly allows cross-references between a FRIA and DPIA, and adjusts the penalty regime for small mid-caps.PublishedRegulationEuropean Parliament and Council of the European Union24 Jul 2026
- AIB 2025-1 / MDCG 2025-6 Interplay between the Medical Devices Regulation (MDR) and In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA)Question-and-answer document with 36 questions on the joint application of the AI Regulation and the regulations on medical devices and in vitro diagnostics. The document introduces the term Medical Device Artificial Intelligence and explains that manufacturers may integrate their AI testing, documentation and reporting procedures into existing Medical Devices Regulation and in vitro Diagnostic Medical Devices Regulation procedures. It is not formally a Commission document and not legally binding, but is endorsed by the AI Board and the Medical Device Coordination Group. The document is dated June 2025, without a specific day.PublishedGuidelinesAI Board (AIB) and Medical Device Coordination Group (MDCG), European Commission
- NEN webinar slides: European AI standards under the AI Act (JTC 21 work programme and timelines)Official NEN presentation with the complete work programme of CEN-CENELEC JTC 21 and the timeline per standard. The slides explicitly link the requested standards to Articles: risk management under Article 9, data and data governance under Article 10, registration under Article 12, transparency under Article 13, human oversight under Article 14, accuracy, robustness and cybersecurity under Article 15, quality management under Article 17 and conformity assessment under Article 43. The deck identifies the work items prEN 18228 risk management, prEN 18229-1 and 18229-2 AI reliability framework, prEN 18282 cybersecurity, prEN 18283 bias, prEN 18284 datasets, prEN 18285 conformity assessment, prEN 18286 quality management and prEN 18281 computer vision, and explicitly cautions that publication by CEN-CENELEC is different from citation in the Official Journal, which can take weeks to months longer. The precise date of this presentation cannot be unambiguously determined from the source and has therefore been left blank.PublishedGuidelinesNEN, Artificial Intelligence and Big Data standards committee
- AI PactVoluntary initiative of the AI Office that helps organisations to keep ahead of the application of the AI Act. It consists of two pillars: a knowledge network with webinars and exchange of practical experience, and a set of voluntary commitments in which companies commit to concrete steps such as establishing an AI governance strategy, mapping possible high-risk systems and promoting AI literacy amongst staff. More than 230 organisations have signed the non-binding commitments. The initiative began in September 2024. The date 7 August 2026 is the last updated date on the page.PublishedCode of practiceEuropean Commission / AI Office7 Aug 2026
- Commission Implementing Decision C(2025) 3871 of 23.6.2025 on a standardisation request to CEN and CENELEC as regards high-risk AI systems in support of Regulation (EU) 2024/1689 and repealing Implementing Decision C(2023) 3215The updated standardisation request (M/613, successor to M/593 from Decision C(2023) 3215). It covers ten areas: risk management, data governance, registration, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and conformity assessment. CEN and CENELEC were to deliver the requested standards by 31 August 2025, the final report by 31 August 2026, and the decision expires on 28 February 2027. The delivery deadline was not met, which explains why the standards are only available in 2026 and 2027.PublishedImplementing actEuropean Commission23 Jun 2025
- Navigating the AI Act (Questions and Answers)The broad official Q&A on the AI Act as a whole, structured around scope and objectives, high-risk AI, general-purpose AI models, governance and enforcement, and innovation and sustainability. The page covers, among other things, who the regulation applies to, how high-risk systems are identified, what obligations providers and deployers have, how supervision and the penalty structure work, and what role the AI Pact and the Service Desk play. The date 7 August 2026 is the last updated date on the page itself.PublishedQ&AEuropean Commission, DG CONNECT7 Aug 2026
- AI Literacy - Questions & AnswersOfficial Q&A with approximately forty questions on Article 4, originally published in May 2025 and last updated on 27 July 2026, the day the Digital Omnibus on AI entered into force. The Commission confirms that providers and deployers must take measures to promote the AI literacy of their personnel and of others who work with AI on their behalf, tailored to knowledge, experience, training and use context. The requirement for a 'sufficient' level has been removed: it has become a duty to take measures, without obligation to measure or guarantee knowledge levels, and the provision has not expired. Merely referring to the user manual is generally not sufficient. For deployers of high-risk AI systems, the requirement for training in human oversight remains. The page also describes the strengthened role of the Commission and Member States and mentions supervision and enforcement from 3 August 2026.PublishedQ&AEuropean Commission, DG CONNECT27 Jul 2026
- Draft Commission Guidelines on the classification of high-risk AI systems under the AI ActThree related draft documents: general principles, the Annex I route and the Annex III route. The Annex I route covers AI that is a safety component of or itself a product under EU harmonisation legislation with third-party conformity assessment. The Annex III route goes through the eight use cases with non-exhaustive examples of systems that are and are not high-risk, plus the exceptions in Article 6, paragraph 3. Not yet adopted; the targeted consultation has closed and the final version follows later. Each timeline in the draft must be tested against the Digital Omnibus: Annex III standalone applies from 2 December 2027, Annex I embedded from 2 August 2028.ConsultationGuidelinesEuropean Commission (AI Office)19 May 2026
- EU AI Act Compliance CheckerInteractive questionnaire that helps determine which rules of Regulation (EU) 2024/1689 may apply to an AI system, and what obligations apply for providers, deployers and other operators. The tool is explicitly presented as a beta version on the website and is presented as an ongoing project, with a call for feedback to be sent to CNECT-AIOFFICE@ec.europa.eu. The outcome is therefore indicative and not a formal determination of the system's status.DraftQ&AEuropean Commission (AI Act Service Desk)
- Generative AI and the EUDPR. Orientations for ensuring data protection compliance when using Generative AI systems (Version 2)Revised version of the EDPS orientations on generative AI and personal data, primarily aimed at EU institutions under Regulation (EU) 2018/1725 but practically usable for any organisation. Covered are, amongst other things, determining roles and responsibilities in the chain, when use of a generative system processes personal data, the role of the data protection officer, when a DPIA is required, purpose limitation, data minimisation, accuracy, bias and automated decision-making. The EDPS provides these orientations explicitly in its role as data protection supervisor and not as market supervisor under the AI Act, and states that they leave the AI Act unaffected.PublishedGuidelinesEDPS (European Data Protection Supervisor)28 Oct 2025
- EDPB-EDPS Joint Opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)Joint opinion (adopted 20 January 2026, published 21 January 2026) on the Commission proposal that later became Regulation (EU) 2026/1744. The supervisors support simplification but state that this must not come at the expense of fundamental rights and effective supervision. They address, among other things, the postponement of the high-risk rules, which stems from the lack of harmonised standards and delay in designating national competent authorities and conformity assessment bodies, and warn of a protection gap. It is an opinion on the legislative process, not an explanation of existing law.PublishedOpinionEDPB and EDPS jointly21 Jan 2026
- Statement 3/2024 on data protection authorities' role in the Artificial Intelligence Act frameworkThe EDPB states that the AI Act and EU data protection law complement each other and must be interpreted in a coordinated manner, referring explicitly to Article 2(7) and recitals 9 and 10. It advises Member States to designate national data protection authorities as market surveillance authorities, mandatory for high-risk systems in Annex III points 1, 6, 7 and 8 and preferably also more broadly. The EDPB also points to the close link between the data protection impact assessment (DPIA) and the fundamental rights impact assessment, and to the absence of structured coordination between the AI Office and data protection authorities on general-purpose AI models.PublishedOpinionEDPB (European Data Protection Board)16 Jul 2024
- EDPB Work Programme 2026-2027 (announcing joint guidelines on the interplay between the AI Act and the GDPR)The European Data Protection Board work programme 2026-2027, adopted on 11 February 2026, announces joint guidelines on the interplay between the AI Act and the GDPR. These guidelines do not yet exist; the Commission confirms in its Article 50 guidelines of 20 July 2026 that they are being prepared together with the European Data Protection Board. They are expected to address transparency, risk assessments, bias detection and accountability, with concrete examples.AnnouncedGuidelinesEDPB (European Data Protection Board)11 Feb 2026
- EN ISO/IEC 42001:2026 Information technology - Artificial intelligence - Management systemThe international standard for an AI management system has now also been adopted as a European standard: NEN-EN-ISO/IEC 42001:2026 is final and has a publication date of 1 March 2026, and replaces NEN-ISO/IEC 42001:2025. The standard sets requirements for establishing, implementing, maintaining and improving an AI management system and is certifiable. Important distinction: this standard was not developed under standardisation request M/593 or M/613 and is therefore not a harmonised standard under the AI Act. It therefore gives no presumption of conformity; that role is for EN 18286 once it is cited in the Official Journal.PublishedStandardISO/IEC JTC 1/SC 42, European adoption through CEN-CENELEC, Dutch adoption by NEN1 Mar 2026
- EN 18286:2026 Artificial intelligence - Quality management system for EU AI Act regulatory purposesThis is the first European standard specifically written for regulatory purposes under the AI Act. The standard describes requirements and guidelines for establishing, implementing and maintaining a quality management system at organisations that supply AI systems, in particular providers who place high-risk AI systems on the market or put them into use. CEN and CENELEC announced publication on 31 July 2026; NEN published the Dutch adoption NEN-EN 18286:2026 (51 pages) with publication date 1 July 2026. Note: published by CEN-CENELEC is not the same as cited in the EU Official Journal, and on the official sources consulted that citation cannot yet be found.PublishedStandardCEN-CENELEC (JTC 21), Dutch adoption by NEN31 Jul 2026
- ISO/IEC 42005:2025 Information technology - Artificial intelligence (AI) - AI system impact assessmentGuideline standard (39 pages) for carrying out impact assessments of AI systems on individuals and society: when and at which lifecycle phase, how to document, and how to link to AI risk management and the AI management system. Direct ISO adoption by NEN; not a European standard and does not fulfil the fundamental rights assessment of Article 27, which obligation only comes into effect from 2 December 2027 and has its own legal scope. At most an aid, not a conformity route.PublishedStandardISO/IEC JTC 1/SC 42, Dutch adoption by NEN1 Jun 2025
- EN ISO/IEC 23894:2024 Information technology - Artificial intelligence - Guidance on risk managementGuideline standard for risk management of AI, based on the ISO 31000 approach. The standard helps organisations developing, producing, supplying or using AI to identify AI-specific risk sources and embed risk management in their existing processes. The European adoption NEN-EN-ISO/IEC 23894:2024 was published on 1 February 2024 and superseded NEN-ISO/IEC 23894:2023. It is a guideline, not a prescriptive standard, and is not a harmonised standard under the AI Act; that role is foreseen for prEN 18228.PublishedStandardISO/IEC JTC 1/SC 42, European adoption through CEN-CENELEC, Dutch adoption by NEN1 Feb 2024
- AI Regulation timeline (Algoritmekader)Dutch timeline from BZK showing which requirements apply on each effective date, linked to numbered requirements in the Algorithm Framework. Living document, last updated 3 August 2026, incorporating the postponement: new standalone high-risk systems from 2 December 2027, high-risk in products from 2 August 2028, with an exception until 2030 for systems already in use in government organisations on 2 December 2027. Warning: the timeline is incomplete, as 2 August 2026 is missing as a milestone for the transparency obligations of Article 50. Do not use as a complete timeline source.PublishedNational guidanceMinistry of the Interior and Kingdom Relations (Algorithm Framework)17 Jul 2025
- About the Dutch Algorithm RegisterExplanation of the Dutch Algorithm Register, in which public sector organisations publish information about their algorithms. Publication is not currently a legal requirement, but that requirement has been announced. The register is linked to the Algorithm Framework of the Ministry of Interior and Kingdom Relations and to the coordinating supervisory role of the Data Protection Authority. The Algorithm Framework additionally sets as requirement bzk-01 that administrative bodies publish impactful algorithms and high-risk AI systems in this register, unless there are exemption grounds.PublishedNational guidanceMinistry of the Interior and Kingdom Relations (Algorithm Register, Overheid.nl)
- prEN 18281:2026 Evaluation methods for computer vision systems (draft European standard, public enquiry)Draft standard setting out methods and measurement criteria for evaluating computer vision systems: selecting, applying and interpreting evaluation methods for AI that analyses visual data. NEN opened the Dutch public enquiry on 7 April 2026; it closed on 11 May 2026. In the JTC 21 work programme, the work item is entitled 'Evaluation methods for accurate computer vision systems'. Domain-specific supplement, not yet an adopted standard.DraftStandardCEN-CENELEC JTC 21, national consultation through NEN7 Apr 2026
- prEN 18283 Managing bias in AI systems (draft European standard)Draft standard that establishes concepts, measures and requirements for assessing and mitigating bias in AI systems, formally requested by the Commission in support of requirements on data and data governance. The source used here is a CEN-CENELEC newsletter item of 27 May 2026 on input from the European Trade Union Confederation, not a standard document; that date therefore indicates nothing about the phase of the standard itself. The work item is independently confirmed in the JTC 21 work programme. Still under development.DraftStandardCEN-CENELEC JTC 2127 May 2026
- prEN 18282 Cybersecurity specifications for AI systems (draft European standard, public enquiry)Draft standard with organisational and technical measures to protect AI systems against cyber threats. The standard explicitly addresses AI-specific attack forms such as data poisoning, attacks on the model itself and malicious input. NEN published the call for comment on 19 May 2026, closing on 30 June 2026. The standard is being developed in working group 5 of JTC 21 and has not yet been adopted.DraftStandardCEN-CENELEC JTC 21, national consultation through NEN19 May 2026
- prEN 18228 Artificial intelligence - Risk management (draft European standard, public enquiry)Draft standard for risk management of AI systems. The standard describes terminology, principles and a process for identifying, assessing and treating risks to health, safety and fundamental rights. NEN opened the Dutch consultation period on 18 May 2026, closing on 30 June 2026; the CEN-CENELEC newsletter of 27 May 2026 confirms that the European enquiry ran until end July 2026 and that the standard supports Article 9. This remains emphatically a draft and therefore provides no presumption of conformity.DraftStandardCEN-CENELEC JTC 21, national consultation through NEN18 May 2026
- Supervision of AI takes shape: key role for the AP and the RDIResponse by the AP to the draft bill. The AP makes explicit which parts it will itself enforce: prohibited AI practices, transparency obligations such as the detectability of chatbots and deepfakes, and a large part of high-risk applications in work, education and government. The AP and RDI jointly provide coordination, knowledge-building and harmonisation, and will establish an AI regulatory sandbox from 2026 onwards. The AP stresses that parts of the Regulation already apply while the implementing legislation is not yet in force.PublishedNational guidanceDutch Data Protection Authority (AP), Algorithm Coordination Directorate20 Apr 2026
- Report AI & Algorithms Netherlands (RAN) - March 2026Sixth edition of the half-yearly report in which the AP analyses the risks and effects of AI and algorithms in the Netherlands via the AI Impact Barometer. Four of the nine indicators are now red, compared with two in the previous edition. The three main points are that AI in recruitment and selection is growing rapidly with significant risks, that transparency and explainability are falling short, and that preparation for the AI Regulation is lagging. The AP also signals that organisations are attempting to circumvent the rules or failing to comply with them.PublishedNational guidanceDutch Data Protection Authority (AP)5 Mar 2026
- AI-verordening (Rijksinspectie Digitale Infrastructuur)Fixed Digital Infrastructure Inspectorate page on its role under the AI Act and on the structure of Dutch supervision. The principle is that supervision is placed with existing sectoral supervisors as much as possible rather than with a new authority, with the Digital Infrastructure Inspectorate and Personal Data Authority together providing a coordinating expert role. Supervision of AI in CE-marked products such as machinery, lifts and toys remains with the existing product authority. The page refers to the final opinion of 7 November 2024 and the two interim opinions. Not substantively refreshed since 30 October 2025: no current position after the April 2026 consultation and nothing on the Digital Omnibus.PublishedNational guidanceDutch Authority for Digital Infrastructure (RDI)
- Response of the President of the Administrative Jurisdiction Division to the draft AI Regulation Implementation ActLetter of 8 July 2026 from the President of the Administrative Jurisdiction Division to the Ministry of Justice and Security, with response and implementing assessment to the draft bill. The Division endorses that market supervision of courts by courts takes place, but advises that the sandbox task and the agreements on uniform interpretation of terms should not apply to its President because this conflicts with judicial independence. It advises expanding its own supervision to AI systems that fall only under the transparency obligations, and signals a question of competence when it is unclear whether a system is prohibited or high-risk. The implementing assessment estimates approximately 1 full-time equivalent additional.PublishedOpinionCouncil of State, Administrative Jurisdiction Division8 Jul 2026
- Final advice on the design of AI supervision in the NetherlandsJoint final advice from RDI and AP (34 pages) on the design of Dutch supervision of the AI Act. Core: AI supervision aligns as closely as possible with regular sectoral supervision, products with CE marking remain with their existing supervisor, and cross-sectoral applications such as recruitment and selection, assessment in education and risk-based selection by public authorities require close cooperation. RDI and AP assume the coordinating expert role. The cabinet adopted this advice substantially in full in the draft legislative proposal of April 2026. An English version is also available.PublishedOpinionDutch Authority for Digital Infrastructure (RDI) and Dutch Data Protection Authority (AP)7 Nov 2024
- Public consultation on the Dutch AI Regulation Implementation Act (Uitvoeringswet AI-verordening)The Dutch legislative proposal that makes the AI Act implementable and enforceable nationally. The consultation ran from 20 April to 1 June 2026 and is closed. The proposal designates ten market supervisory authorities: the Personal Data Authority, the Digital Infrastructure Inspectorate, the Transport and Infrastructure Inspectorate, the Inspectorate for the Judiciary, the Food and Consumer Product Safety Authority, the Dutch Labour Inspectorate, the Financial Markets Authority, the Dutch Central Bank, the Advocate General at the Supreme Court and the chair of the Administrative Law Division of the Council of State. Additionally, it provides for powers, cooperation between these authorities and the establishment of an AI testing environment. Annexes include the legislative proposal, draft explanatory memorandum, visual representation of the supervisory system, policy compass and impact assessment.ConsultationNational guidanceMinistry of Justice and Security / Government of the Netherlands (through internetconsultatie.nl)20 Apr 2026