AI Regulation in the Netherlands
10 min read · updated August 4, 2026
The Netherlands has no national AI act. What applies is the EU AI Act, directly, plus the GDPR and its Dutch implementation, plus sectoral law. What the Netherlands has added is a supervisory structure: a coordinating pair of regulators, a set of sectoral market surveillance authorities, and a public algorithm register for government bodies.
The position in one paragraph
If you run an AI system from the Netherlands, the binding instrument is Regulation (EU) 2024/1689 and your obligations depend on whether you are its provider or its deployer and on which risk band it falls in. Nothing Dutch changes those obligations. What is Dutch is who comes to ask about them, what penalties national law attaches where the Regulation leaves that to Member States, and — for public bodies — a transparency duty that has no EU equivalent.
Who supervises what
The AI Act requires each Member State to designate at least one notifying authority and at least one market surveillance authority. The Dutch approach has been to keep sectoral supervision with the sectoral regulators and to add a coordinating layer rather than create a new single AI regulator.
| Authority | Description |
|---|---|
| Autoriteit Persoonsgegevens (AP) | The Dutch data protection authority, and the coordinating supervisor for algorithms and AI. It enforces the GDPR in the Netherlands and houses a directorate dedicated to the coordination of algorithmic oversight, set up in 2023. |
| Rijksinspectie Digitale Infrastructuur (RDI) | The digital infrastructure inspectorate, part of the Ministry of Economic Affairs and formerly Agentschap Telecom. Designated to coordinate market surveillance under the AI Act alongside the AP, and the natural home for product-side supervision given its existing role under EU product legislation. |
| Autoriteit Financiële Markten (AFM) and De Nederlandsche Bank (DNB) | Conduct and prudential supervision of the financial sector. Where a financial institution deploys a high-risk system, the financial supervisor is the natural market surveillance authority, and both have published their views on AI use in the sector. |
| Autoriteit Consument & Markt (ACM) | Consumer protection, competition and the Digital Services Act. Misleading AI claims to consumers are an ACM matter regardless of the AI Act. |
| Inspectie Gezondheidszorg en Jeugd (IGJ) and Nederlandse Zorgautoriteit (NZa) | Health and youth care inspection, and healthcare market regulation. Clinical software is regulated as a medical device under EU law first; the AI Act sits on top of that. |
| Nederlandse Arbeidsinspectie | The labour inspectorate. Relevant to workplace monitoring and to the AI Act's prohibition on emotion inference at work. |
| Commissariaat voor de Media | Media supervision, relevant to synthetic media disclosure duties in broadcast and on-demand services. |
The AP and the RDI have jointly advised the Dutch government on how AI Act supervision should be organised, in advice published during 2024. That advice, and the ministry’s response to it, is the document trail to follow if you need to know why a particular sector sits where it does. Both authorities publish their own material; read it at the source rather than through a summary, because this is an area where intermediaries paraphrase badly.
The Autoriteit Persoonsgegevens and algorithmic oversight
The AP established a directorate for the coordination of algorithmic oversight in January 2023, before the AI Act was adopted. Its remit is coordination and signalling rather than exclusive enforcement: it maps risks, works with other supervisors, and publishes.
Its most consistent published output is a periodic report on AI and algorithmic risks in the Netherlands, issued roughly twice a year since 2023. It is worth reading for two reasons that have nothing to do with compliance theatre. It signals which categories of system the supervisor is currently worried about, and it is written in plain Dutch about deployments in Dutch organisations rather than about frontier models.
Separately, the AP enforces the GDPR, and for most Dutch companies the GDPR is still the sharper instrument. An AI system processing personal data needs a lawful basis, a purpose, a retention period and, where the processing is high risk, a data protection impact assessment before it starts. Those duties are in force now, carry the GDPR’s own fine ceiling, and have an established enforcement history behind them, which the AI Act does not yet. If you are prioritising, the GDPR analysis comes first.
The implementing act, which is not finished
A regulation applies directly, but it leaves Member States to do three things in national law: designate the authorities formally, give them investigatory and enforcement powers, and set penalties where the Act does not set them itself. In the Netherlands that is the job of an implementing act for the AI Regulation.
At this page’s review date, that legislation was in preparation rather than in force. This page does not state a commencement date for it, because stating one that turned out to be wrong would be worse than leaving the gap. Check the status at wetten.overheid.nl and in the parliamentary papers before assuming a designation is legally effective.
What this means practically: the substantive obligations bind you already, on the EU timetable. The question the implementing act settles is who can fine you and under what procedure — not whether the duties exist.
The algorithm register for public bodies
The Netherlands runs a public algorithm register at algoritmes.overheid.nl, where government organisations publish descriptions of the algorithms they use: what the system does, the data it uses, how it is monitored, and who is responsible. It grew out of policy rather than statute and coverage is uneven, with central government further along than municipalities.
Two reasons it matters even if you are a private company. If you sell to Dutch government, your system may end up described in a public register, and your customer will need the information from you to write the entry — which is a procurement requirement to negotiate before signature rather than after. And the register is a genuinely useful corpus: several hundred real entries describing how public bodies document decision-support systems, which is a better model for your own documentation than most templates on sale.
Why Dutch supervision is shaped the way it is
Two episodes explain the Dutch appetite for algorithmic oversight better than any policy document.
In February 2020 the district court in The Hague held that SyRI, a system used to detect welfare fraud by linking government datasets, did not meet the requirements of Article 8 of the European Convention on Human Rights, and struck down the legislation authorising it. The judgment (ECLI:NL:RBDHA:2020:865) turned on the absence of transparency and verifiability about how the risk model worked — not on a finding that the model was inaccurate.
Then the childcare benefits affair, the toeslagenaffaire, in which risk classification at the tax administration contributed to tens of thousands of families being wrongly accused of fraud, with nationality-related indicators among the factors used. The government resigned in January 2021. The AP subsequently found the tax administration’s processing unlawful.
The relevance is not historical. Dutch supervisors approach automated decision-making with the assumption that opacity is itself a harm and that the burden of showing a system is explicable falls on the body using it. If you are preparing for a conversation with a Dutch regulator, prepare to explain the system to a non-specialist, not to defend its accuracy metric.
What a Dutch company should actually do
- Inventory, then classify. Same first step as anywhere in the EU. Nothing Dutch changes it.
- Do the GDPR work first. Lawful basis, purpose limitation, retention, DPIA where required, and a transfer mechanism if your model calls leave the EEA. The AP enforces this today.
- Decide where inference runs, and record it. Whether data leaves the EEA is a question you will be asked, and what residency actually guarantees is narrower than most vendor pages imply.
- Read the supervisors’ own publications, not summaries. The AP and RDI publish in Dutch and in English; sectoral supervisors publish in their own sector’s language of risk.
- Log the AI literacy work. In force since February 2025 and cheap. See the literacy duty.