With the entry into force of the European AI Act, a new, fundamental legal framework has been created for the development and use of artificial intelligence. However, a European law is just paper without strong national enforcement. For many Dutch AI developers, implementation partners, and end users, this raises an urgent question: which authority should I turn to?
In the Netherlands, the supervision of algorithms and AI is not assigned to a single, all-powerful 'AI police force'. The landscape is divided among various inspectorates and authorities, each looking at AI systems from their own area of expertise. In this article, we dissect the Dutch supervisory landscape, clarify the powers of the key players, and provide guidance for organizations that need to get started with compliance.
The Decentralized Structure of Dutch Supervision
The AI Act adopts a risk-based approach. The higher the risk of an AI system to the safety or fundamental rights of citizens, the stricter the rules. Because AI has a wide range of applications—from medical diagnostics to fraud detection at insurers and autonomous vehicles—the Dutch government has opted for an ecosystem of supervisory authorities instead of a single central authority.
In practice, this means that supervision under the AI Act will lie with existing market surveillance authorities, with two authorities clearly taking a leading role: the Dutch Data Protection Authority (AP) and the Dutch Authority for Digital Infrastructure (RDI). For developers, it is crucial to understand who supervises which aspect of their system.
The Key Players in the Landscape
1. Dutch Data Protection Authority (AP) & DCA
The Dutch Data Protection Authority (AP) is traditionally the privacy watchdog, but its mandate has expanded significantly in recent years. Within the AP, the Algorithm Coordination Directorate (DCA) has been established. This directorate currently has an important signaling function and promotes cooperation between different regulators.
Under the AI Act, it is expected (with an important caveat: the final, formal designation in the national Implementing Act is still partly pending) that the AP will lead the supervision of AI systems that affect fundamental rights. Examples include biometric identification systems, AI in the workplace, law enforcement systems, and AI used for migration and asylum. As soon as personal data and AI intersect, the AP is undisputedly the competent authority. The AP also manages the Dutch government's algorithm register.
2. Dutch Authority for Digital Infrastructure (RDI)
While the AP primarily focuses on fundamental rights and the human dimension, the Dutch Authority for Digital Infrastructure (RDI, formerly the Radiocommunications Agency) is the authority for the technical and infrastructural side of AI. The RDI is the designated regulator for cybersecurity and product safety of digital systems in the broadest sense.
It is generally expected that the RDI will take on the role of market surveillance authority for AI systems, particularly for systems falling under technical product safety legislation. This includes the robustness of machine learning models, the quality of training data from a technical perspective (error-free), and protection against data manipulation or cyberattacks. The RDI tests algorithms for robustness and safety in its own AI test laboratories.
3. Netherlands Authority for Consumers and Markets (ACM)
The Netherlands Authority for Consumers and Markets (ACM) focuses on economic market power and consumer protection. AI systems can be used for anti-competitive behavior, price-fixing via algorithms (so-called collusion by algorithm), or misleading practices such as dark patterns driven by personalized recommendation systems.
Under the AI Act, the ACM will be the regulator when AI is used to cause economic harm to consumers or to manipulate markets. The ACM has already made it clear in previous guidelines that the use of AI in commercial systems must be transparent to consumers.
Sectoral Regulators: Tailored Oversight per Industry
In addition to the broad regulators, there are specific inspectorates that integrate the AI Act into their existing sectoral supervision. The AI Act explicitly states that AI systems used as safety components in regulated products fall under the relevant product-specific legislation.
- Dutch Authority for the Financial Markets (AFM) / De Nederlandsche Bank (DNB): Supervision of AI for credit scoring, algorithmic trading, and risk models within the financial sector.
- Health and Youth Care Inspectorate (IGJ): Responsible for medical devices (Medical Device Regulation). If AI is used for diagnostics, such as image recognition in X-rays, the IGJ supervises clinical validity.
- Inspectorate of Education: Supervision of high-risk AI systems in education, such as algorithms that determine whether a student is admitted to a program or systems for grading exams.
- Netherlands Institute for Human Rights: Although not a formal enforcement body with fining powers like the AP, the Institute rules on individual complaints regarding algorithmic discrimination and bias.
Overview: Which Regulator for Which Domain?
To clarify the division of responsibilities, a brief overview of the main domains is provided below. Please note: due to the aforementioned caveat regarding the final national AI Act Implementing Act, the exact boundaries may still shift slightly.
| Regulator | Primary AI Supervision Domain (Expected / Current) | Example Case |
|---|---|---|
| AP (DCA) | Fundamental rights, privacy, biometrics, government systems | Facial recognition in public spaces |
| RDI | Technical robustness, cybersecurity, market surveillance | Generative AI models with security vulnerabilities |
| ACM | Consumer protection, fair competition | AI-driven dynamic pricing in webshops |
| IGJ | Healthcare and medical devices | A diagnostic AI model for skin cancer |
| AFM | Financial services | Credit scoring algorithm for mortgages |
Timeline of Enforcement in the Netherlands
Compliance is not a goal that must be fully achieved by tomorrow; the European legislator has provided for transitional periods. Supervision will be phased in according to the following stages, the details of which you can also read in our AI Act timeline:
- February 2025: Ban on systems with unacceptable risk (such as social scoring and manipulative AI). Regulators can intervene from this point onward.
- August 2025: Rules for providers of General-Purpose AI (GPAI), such as the large language models behind well-known chatbots, come into effect.
- August 2026: Rules for most high-risk AI systems come into force. Developers must, among other things, apply CE markings.
- August 2027: Rules for high-risk AI systems that are part of products (such as machinery or medical devices) come into effect.
What Does This Mean for AI Developers and Businesses?
For organizations developing or placing AI on the market in the Netherlands, the fragmented supervisory structure means they must carefully document which regulator their system falls under. Experience shows that systems often overlap. An AI system in healthcare that processes patient data will have to deal with both the IGJ (medical safety) and the AP (medical personal data).
What can you do today to be prepared?
- Inventory your systems: Create a register of all AI models you deploy or develop.
- Determine the risk class: Validate whether your system falls into the 'high risk' category according to the annexes of the AI Act.
- Quality management: Set up a conformity assessment procedure (for high-risk systems). This requires technical documentation, logging, and human oversight.
- Documentation guideline: As a rule of thumb, companies developing high-risk AI will need to allocate at least 5% to 10% of their resource time and budget to compliance documentation, quality management, and risk assessments. Note: explicitly mark this as a rough estimate for resource planning, not as a hard legal standard or exact measurement.
The One-Stop-Shop Principle and the Future
To prevent businesses and SMEs from getting lost in the regulatory maze, the Dutch government is striving for a coordinated approach. In practice, there will need to be a single central contact point or coordinating authority ('Single Point of Contact') where companies can go with questions about their obligations, compliance, and reporting incidents. Read more about this in the frequently asked questions about supervision.
Currently, the AP (via the DCA) already largely fulfills this coordinating bridge function for the government itself, but whether this portal for businesses will ultimately be physically housed at the AP, the RDI, or an interdepartmental body will be definitively determined by the upcoming AI Act Implementing Act.
In short: Dutch AI supervision is being set up. There is no more time for a wait-and-see attitude. Developers would be wise to build in transparency, data minimization, and technical security as standard today (compliance by design) instead of waiting for the inspector to knock on the door.