NL·EU AI Act series·Netherlands implementation·EU timeline checked August 2026
The EU AI Act in the Netherlands: hybrid supervision, ten authorities deep.
The Dutch government has proposed a hybrid model in which ten market-surveillance authorities share competences across sectors, with Autoriteit Persoonsgegevens (AP) and the Rijksinspectie Digitale Infrastructuur (RDI) co-coordinating. Public consultation on the proposed Dutch AI Implementation Act ran from 20 April through 1 June 2026 and is now closed; the structure remains proposed pending legislation.
The public consultation on the Dutch AI Implementation Act ran from 20 April to 1 June 2026. That was the window in which Dutch deployers, providers, and trade associations could influence how the ten-authority hybrid is operationalised. AP and RDI continue to co-coordinate the network in the meantime.
The separate 2 August 2026 registration requirement for public-body deployers of high-risk systems was not converted into a general high-risk compliance date. The AI Omnibus entered into force on 27 July 2026: relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028. Other provisions retain their own dates; Dutch operators should confirm the provisions applicable to each system.
Who supervises what in the Netherlands
The Netherlands has proposed a hybrid supervisory model. AP would hold horizontal competences over prohibited practices, transparency obligations, and many high-risk applications; RDI would handle infrastructure-adjacent supervision and co-coordinate the network, with sectoral authorities holding roles in their domains. The consultation closed June 1, 2026, and the final allocation may change through the legislative process.
| Authority | Mandate | Proposed EU AI Act role (reviewed August 2026) |
|---|---|---|
| AP | Autoriteit Persoonsgegevens (data protection authority) | Co-coordinator. Prohibited practices, transparency obligations, large share of high-risk applications, GDPR and AI Act overlap. Primary point of contact for cross-sector deployers. |
| RDI | Rijksinspectie Digitale Infrastructuur | Co-coordinator. Infrastructure, telecommunications, radio equipment; technical-conformance supervision in adjacent product law. |
| AFM, DNB | Financial-conduct and prudential supervisors | Sector-specific high-risk AI in financial services: credit scoring, insurance underwriting, anti-fraud, algorithmic trading. Market-conduct conformity overlap. |
| IGJ | Inspectie Gezondheidszorg en Jeugd (health and youth-care inspectorate) | Healthcare AI: clinical decision support, diagnostic AI, ambient documentation; MDR/IVDR overlap with the AI Act conformity route. |
| NLA | Nederlandse Arbeidsinspectie (labour inspectorate) | Workplace AI: emotion recognition prohibition, worker monitoring, automated employment decisions. |
| ACM | Autoriteit Consument en Markt (competition and consumer authority) | Consumer-facing AI, dark-pattern overlap with the Digital Services Act, recommender systems. |
| CvdM | Commissariaat voor de Media | Media, AI-generated content, transparency obligations under Article 50. |
| College voor de Rechten van de Mens | Netherlands Institute for Human Rights | Article 77 fundamental-rights body; non-discrimination supervision on AI-affected decisions. |
| Onderwijsinspectie | Inspectorate of Education | Education-sector AI; admissions and assessment systems, prohibited emotion-recognition use cases in classrooms. |
| ILT | Inspectie Leefomgeving en Transport | Transport, environment, critical infrastructure AI; Annex III overlap. |
Rijksoverheid opened public consultation on the Dutch AI Implementation Act (Uitvoeringswet AI-verordening) on 20 April 2026 and closed it on 1 June 2026. The Act will codify authority designations, fine ceilings, sandbox arrangements, and procedural rules for cooperation between AP, RDI and the eight sectoral authorities. Until adoption, the network operates on a Memorandum of Cooperation rather than statute.
Dutch sector overlays
The substantive obligations in Articles 9 to 15 apply EU-wide. What differs in the Netherlands is the supervisory stack on top. The most common combinations:
| Sector | Dutch regulators on top of the AI Act |
|---|---|
| Healthcare AI | IGJ for clinical AI inspections; CIBG for medical-device registry; AP on patient-data overlap; College ter Beoordeling van Geneesmiddelen on AI-aided drug decisions. MDR/IVDR conformity where the AI is a medical device. |
| Financial services | AFM on conduct (algorithmic trading, recommendation, treating customers fairly); DNB on prudential and AML; AP on customer-data lawful basis. |
| Public administration | From 2 August 2026, public bodies must register high-risk AI in the EU database. The Adviescollege ICT-toetsing reviews algorithmic-decision systems in central government. AP holds horizontal supervision. |
| Workplace AI | NLA on the prohibited-practice line (emotion recognition, biometric categorization in workplaces). Works-council co-determination under the Wet op de ondernemingsraden often applies in parallel. |
| Logistics and ports | ILT and Havenbedrijven supervise transport-system AI. Critical infrastructure under Annex III(2) where safety components are involved. |
| Media and content | CvdM on Article 50 disclosure for media providers; ACM on platform-side recommender systems and dark patterns. |
Data-protection overlay: UAVG
Dutch AI deployments rarely sit on AI Act obligations alone. The UAVG (Uitvoeringswet Algemene verordening gegevensbescherming) and GDPR remain the operative data-protection regime, and AP supervises both. Common overlaps:
- Article 10 (data governance) and GDPR Articles 5 and 6. Lawful basis for training data, purpose limitation, accuracy.
- Article 13 (transparency) and GDPR Articles 13 and 14. Information to data subjects on automated decision-making.
- Article 14 (human oversight) and GDPR Article 22. Meaningful human review of consequential decisions.
- Article 26 (deployer obligations) and AP-required impact assessments. A single artefact often covers both with care.
AP’s SyRI ruling (in the District Court of The Hague, 2020) and its subsequent guidance on algorithmic governance remain the practical reference for high-risk public-sector deployments.
Regulatory sandbox
Article 57 sandbox provisions are addressed in the proposed Dutch AI Implementation Act. Confirm the final administrators, operational date, eligibility, and application route from the enacted law and current AP/RDI notices. Existing sector innovation or advice programs should not be described as AI Act sandboxes without a current primary source establishing that status.
References
- European Union. Regulation (EU) 2024/1689 (EU AI Act). EUR-Lex 32024R1689.
- Stibbe. Dutch proposal for AI supervision: hybrid cooperation between market surveillance authorities. stibbe.com.
- Government of the Netherlands. “Kabinet zet stap met toezicht op Europese AI-regels.” 20 April 2026. rijksoverheid.nl.
- Overheid.nl. “Consultatie Uitvoeringswet AI-verordening.” Consultation ran 20 April to 1 June 2026; status closed. internetconsultatie.nl.
- Autoriteit Persoonsgegevens. “Toezicht op AI wordt concreet: sleutelrol voor de AP en de RDI.” autoriteitpersoonsgegevens.nl.
- Technology’s Legal Edge. State of the Act: EU AI Act implementation in key Member States, November 2025. technologyslegaledge.com.
- European Parliament. AI Act: deal on simplification measures, ban on nudifier apps, 27 April 2026. europarl.europa.eu.
Build the evidence trail
Dutch operators: selected control records for the wider evidence trail.
For configured paths, GLACIS can add signed, scoped records of selected control decisions to the provider or deployer’s wider documentation and Article 12 logging design. The records do not replace technical documentation, establish compliance, or imply acceptance by the AP, a notified body, or a public register.
Start where your AI already acts. We’ll map the intended controls, operational decision points, and evidence gaps.