NL·EU AI Act series·Netherlands implementation·EU timeline checked August 2026

The EU AI Act in the Netherlands: hybrid supervision, ten authorities deep.

The Dutch government has proposed a hybrid model in which ten market-surveillance authorities share competences across sectors, with Autoriteit Persoonsgegevens (AP) and the Rijksinspectie Digitale Infrastructuur (RDI) co-coordinating. Public consultation on the proposed Dutch AI Implementation Act ran from 20 April through 1 June 2026 and is now closed; the structure remains proposed pending legislation.

Talk to us All-EU material in the main guide →
Compliance lead DPO General Counsel CISO
Feb 2025
Prohibited-practice provisions begin applying; confirm the current Dutch competent-authority route
20 Apr 2026
Public consultation on Dutch AI Implementation Act opened
1 Jun 2026
Implementation Act consultation closes
2 Aug 2026
Public bodies must register high-risk AI in the EU database
Status checked August 2026 · Netherlands

The public consultation on the Dutch AI Implementation Act ran from 20 April to 1 June 2026. That was the window in which Dutch deployers, providers, and trade associations could influence how the ten-authority hybrid is operationalised. AP and RDI continue to co-coordinate the network in the meantime.

The separate 2 August 2026 registration requirement for public-body deployers of high-risk systems was not converted into a general high-risk compliance date. The AI Omnibus entered into force on 27 July 2026: relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028. Other provisions retain their own dates; Dutch operators should confirm the provisions applicable to each system.

Who supervises what in the Netherlands

The Netherlands has proposed a hybrid supervisory model. AP would hold horizontal competences over prohibited practices, transparency obligations, and many high-risk applications; RDI would handle infrastructure-adjacent supervision and co-coordinate the network, with sectoral authorities holding roles in their domains. The consultation closed June 1, 2026, and the final allocation may change through the legislative process.

AuthorityMandateProposed EU AI Act role (reviewed August 2026)
AP Autoriteit Persoonsgegevens (data protection authority) Co-coordinator. Prohibited practices, transparency obligations, large share of high-risk applications, GDPR and AI Act overlap. Primary point of contact for cross-sector deployers.
RDI Rijksinspectie Digitale Infrastructuur Co-coordinator. Infrastructure, telecommunications, radio equipment; technical-conformance supervision in adjacent product law.
AFM, DNB Financial-conduct and prudential supervisors Sector-specific high-risk AI in financial services: credit scoring, insurance underwriting, anti-fraud, algorithmic trading. Market-conduct conformity overlap.
IGJ Inspectie Gezondheidszorg en Jeugd (health and youth-care inspectorate) Healthcare AI: clinical decision support, diagnostic AI, ambient documentation; MDR/IVDR overlap with the AI Act conformity route.
NLA Nederlandse Arbeidsinspectie (labour inspectorate) Workplace AI: emotion recognition prohibition, worker monitoring, automated employment decisions.
ACM Autoriteit Consument en Markt (competition and consumer authority) Consumer-facing AI, dark-pattern overlap with the Digital Services Act, recommender systems.
CvdM Commissariaat voor de Media Media, AI-generated content, transparency obligations under Article 50.
College voor de Rechten van de Mens Netherlands Institute for Human Rights Article 77 fundamental-rights body; non-discrimination supervision on AI-affected decisions.
Onderwijsinspectie Inspectorate of Education Education-sector AI; admissions and assessment systems, prohibited emotion-recognition use cases in classrooms.
ILT Inspectie Leefomgeving en Transport Transport, environment, critical infrastructure AI; Annex III overlap.
Implementation Act in flight

Rijksoverheid opened public consultation on the Dutch AI Implementation Act (Uitvoeringswet AI-verordening) on 20 April 2026 and closed it on 1 June 2026. The Act will codify authority designations, fine ceilings, sandbox arrangements, and procedural rules for cooperation between AP, RDI and the eight sectoral authorities. Until adoption, the network operates on a Memorandum of Cooperation rather than statute.

Dutch sector overlays

The substantive obligations in Articles 9 to 15 apply EU-wide. What differs in the Netherlands is the supervisory stack on top. The most common combinations:

SectorDutch regulators on top of the AI Act
Healthcare AIIGJ for clinical AI inspections; CIBG for medical-device registry; AP on patient-data overlap; College ter Beoordeling van Geneesmiddelen on AI-aided drug decisions. MDR/IVDR conformity where the AI is a medical device.
Financial servicesAFM on conduct (algorithmic trading, recommendation, treating customers fairly); DNB on prudential and AML; AP on customer-data lawful basis.
Public administrationFrom 2 August 2026, public bodies must register high-risk AI in the EU database. The Adviescollege ICT-toetsing reviews algorithmic-decision systems in central government. AP holds horizontal supervision.
Workplace AINLA on the prohibited-practice line (emotion recognition, biometric categorization in workplaces). Works-council co-determination under the Wet op de ondernemingsraden often applies in parallel.
Logistics and portsILT and Havenbedrijven supervise transport-system AI. Critical infrastructure under Annex III(2) where safety components are involved.
Media and contentCvdM on Article 50 disclosure for media providers; ACM on platform-side recommender systems and dark patterns.

Data-protection overlay: UAVG

Dutch AI deployments rarely sit on AI Act obligations alone. The UAVG (Uitvoeringswet Algemene verordening gegevensbescherming) and GDPR remain the operative data-protection regime, and AP supervises both. Common overlaps:

  • Article 10 (data governance) and GDPR Articles 5 and 6. Lawful basis for training data, purpose limitation, accuracy.
  • Article 13 (transparency) and GDPR Articles 13 and 14. Information to data subjects on automated decision-making.
  • Article 14 (human oversight) and GDPR Article 22. Meaningful human review of consequential decisions.
  • Article 26 (deployer obligations) and AP-required impact assessments. A single artefact often covers both with care.

AP’s SyRI ruling (in the District Court of The Hague, 2020) and its subsequent guidance on algorithmic governance remain the practical reference for high-risk public-sector deployments.

Regulatory sandbox

Article 57 sandbox provisions are addressed in the proposed Dutch AI Implementation Act. Confirm the final administrators, operational date, eligibility, and application route from the enacted law and current AP/RDI notices. Existing sector innovation or advice programs should not be described as AI Act sandboxes without a current primary source establishing that status.

Articles 9 to 15, conformity assessment, GPAI, penalties

These obligations apply EU-wide and are not Netherlands-specific. To keep this page focused on locality, the in-depth treatment of Articles 9 to 15, the conformity-assessment workflow, GPAI provider duties, and the Article 99 penalty structure is maintained on the main guide.

↑ For all-EU material, see the main guide

TopicAnchor on the main guide
Articles 9 to 15 explainerguide-eu-ai-act#requirements-by-category
Article 12 logging requirementsguide-eu-ai-act#requirements-by-category
Conformity-assessment workflowguide-eu-ai-act#compliance-roadmap
GPAI obligations and Code of Practiceguide-eu-ai-act#gpai-requirements
Article 99 penalty structureguide-eu-ai-act#penalties-enforcement
Member-state implementation tableguide-eu-ai-act#member-states

References

  1. European Union. Regulation (EU) 2024/1689 (EU AI Act). EUR-Lex 32024R1689.
  2. Stibbe. Dutch proposal for AI supervision: hybrid cooperation between market surveillance authorities. stibbe.com.
  3. Government of the Netherlands. “Kabinet zet stap met toezicht op Europese AI-regels.” 20 April 2026. rijksoverheid.nl.
  4. Overheid.nl. “Consultatie Uitvoeringswet AI-verordening.” Consultation ran 20 April to 1 June 2026; status closed. internetconsultatie.nl.
  5. Autoriteit Persoonsgegevens. “Toezicht op AI wordt concreet: sleutelrol voor de AP en de RDI.” autoriteitpersoonsgegevens.nl.
  6. Technology’s Legal Edge. State of the Act: EU AI Act implementation in key Member States, November 2025. technologyslegaledge.com.
  7. European Parliament. AI Act: deal on simplification measures, ban on nudifier apps, 27 April 2026. europarl.europa.eu.

Build the evidence trail

Dutch operators: selected control records for the wider evidence trail.

For configured paths, GLACIS can add signed, scoped records of selected control decisions to the provider or deployer’s wider documentation and Article 12 logging design. The records do not replace technical documentation, establish compliance, or imply acceptance by the AP, a notified body, or a public register.

Talk to us See an evidence pack →

Start where your AI already acts. We’ll map the intended controls, operational decision points, and evidence gaps.