Skip to content
NLEN
Illustration: The algorithm register examined: what governments report

The algorithm register examined: what governments are reporting in 2026

By Ivo Donker — compiled with AI assistance (Claude & Gemini)

In AI in Dutch government we covered government use in general terms; here we measure what is actually being reported in the algorithm register. The national algorithm register acts as the central shop window in which public organizations disclose their use of automation systems and artificial intelligence.

To understand how this practice is developing, we run a repeatable measurement on the register's public dataset, checked on 2026-08-07. Where the discussion around algorithms was long theoretical in nature, practice now offers a wealth of concrete data on the organizations actually implementing and publishing systems.

What has changed since last time

Methodology of the measurement

This analysis is based on the public dataset as made available via the Algorithm register public dataset (CSV). Interested readers and researchers can download this file themselves and verify the counts against the accompanying date. The check date used for this specific count is 2026-08-07.

It is important to note that these figures change with each publication by the participating bodies and agencies; consult the source for the current state. The breakdown by government layer in this article was produced through our own classification based on the organization names in the CSV export. This yields an objective and repeatable picture of the actual status within the Dutch public sector.

Live count and size of the register

The dataset of 2026-08-07 shows that the register now forms a lively database. The live count on the website's home page reads "Find one of the 1530 algorithms", which corresponds exactly to the sum in the downloaded CSV. These registrations come from 336 unique organizations that voluntarily offer insight into their digital toolkit.

Zooming in on the operational status of these 1,530 systems, we see that by far the majority of algorithms are genuinely running in production. A full 1,392 registrations have the status "in use". A further 73 systems are in the design phase or under development, while 65 registrations have since been decommissioned but are retained for historical transparency and accountability.

What the register records exactly

A registration in the national algorithm register is more than a simple mention of a software package; it is a structured profile offering insight into the background and operation of an automated system. Anyone diving into the public dataset will see that each entry is built from a fixed set of metadata safeguarding accountability toward citizens. Every registration first states the responsible government organization and the specific department, linked to the exact name of the information system or model.

The register also describes at length the system's operational purpose, which decisions it supports or automates, and the legal basis on which its use rests. Technical characteristics, such as the data sources used and the degree of human intervention, are named explicitly as well. To make it immediately clear which systems have the greatest impact on citizens' lives, the register distinguishes between impact categories. Within the total dataset of 1,530 systems, 694 are registered as impactful algorithms, while 795 systems fall under the heading of other algorithms. Within this group sits the specific category of the 41 high-risk AI systems, which face stricter scrutiny because of their far-reaching nature.

Municipalities as the largest group

A striking finding in this measurement is the dominance of municipalities. Where central government stood at the cradle of the initiative, it is now local authorities that dominate the list. The classification of organizations from the dataset shows that municipalities account for 955 of the 1,530 registrations, which amounts to over 60 percent of the total. This broad local enthusiasm contrasts sharply with the earlier situation, in which decentralization and sluggishness set the tone. By way of comparison: central government, independent administrative bodies (zbo's), agencies and inspectorates together account for 411 registrations (27 percent), while provinces contribute 62 registrations (4 percent), regional partnerships and foundations 80 registrations (5 percent) and water authorities 22 registrations (2 percent).

Within these local layers, specific front-runners stand out. The Municipality of Amsterdam leads the list with 70 registered systems, closely followed by the Tax Administration with 69 and Customs with 48. Other large municipalities such as Utrecht (45), The Hague (44) and Rotterdam (29) likewise make a substantial and recognizable contribution to openness within the network. These figures stand in stark contrast to the historical context that emerged from the regulator's investigations: in July 2025, the Dutch Data Protection Authority reported that more than half of all Dutch municipalities had at that point registered nothing at all. The catching up that has taken place since ties in closely with the broader analyses of the state of play around AI in Dutch government, which sets out the transition from local experiment to structural accountability in detail.

Government layer Number of registrations Percentage
Municipalities 955 62%
Central government, zbo's, agencies and inspectorates 411 27%
Provinces 62 4%
Regional, joint arrangements & foundations 80 5%
Water authorities 22 2%

Supervision and the role of the DPA

The rapid growth of the algorithm register does not stand on its own, but is closely connected to increasing pressure from the regulatory field. The Dutch Data Protection Authority (AP) plays a central, coordinating role here as guardian of citizens' fundamental rights and privacy in the digital domain. Because voluntary transparency in the register's early years led to large blank spots and reticence among government organizations, the AP called as early as 11 July 2025 for the algorithm register to be made a hard legal requirement across the entire public sector.

To help governments set up their digital systems correctly and report them in good time, the regulator has drawn up concrete guidance. This guidance forms the thread running through the fifth AI & Algorithms Report Netherlands, which also appeared in July 2025. It stated in no uncertain terms that the non-committal phase of algorithmic transparency had to end and that organizations had to account proactively for risky applications. Anyone wishing to explore further how these enforcement frameworks are embedded in national governance can turn to the background information on AI supervision in the Netherlands, where the division of tasks between the various inspectorates and the AP is set out clearly.

Alignment with the AI Act

The national algorithm register does not operate in a vacuum, but seeks explicit alignment with broader European legislation, and with the EU AI Regulation (AI Act) in particular. This European law applies a risk-based approach in which artificial intelligence is divided into categories ranging from minimal risk to unacceptable risk. Systems designated by the law as a "high-risk AI system" — such as applications for biometric identification, critical infrastructure or selection processes within the social domain — must meet strict requirements on data quality, human oversight and transparency.

On the check date of this measurement, registering algorithms in the central register remains largely voluntary at national level, although central government announced as early as December 2022, through an official letter to parliament, that it was working toward a legal obligation for impactful systems. Close attention is being paid to the AI Regulation Implementation Act, whose public internet consultation ran from 20 April to 1 June 2026 inclusive. Because the definitive status and entry into force as of 7 August 2026 have not been formally verified, no assumptions may be made about this law's eventual legal force. The register does already function as a practical trial run for meeting European standards. Anyone wanting to understand the technical and legal depth of these European rules can read the main outlines in the article on the EU AI Act, and for the technical and qualitative frameworks, further documentation is available on AI standards and ISO norms.

Categorization and high-risk systems

Not every registered system has the same impact on citizens. Within the dataset, registrations are divided into different categories. A total of 694 systems are recorded as "impactful algorithms", while 795 registrations are classified as "other algorithms". This distinction helps citizens and regulators see immediately where the greatest societal risks lie.

Particular attention goes to the 41 systems explicitly designated as "high-risk AI system". These can be found at the National Police, the Netherlands Forensic Institute, implementing organizations around asylum and migration, and at several large municipalities. To understand how such systems are framed legally and socially, it is worth consulting the in-depth analysis on the EU AI Act in outline , which sets out the European rules of the game for this type of technology.

Publication growth over the years

Willingness among governments to share information has increased sharply in recent years. Analysis of the publication dates in the dataset shows a clear acceleration in the adoption of transparency about digitalization:

For historical context, the Dutch Data Protection Authority (AP) reported on 11 July 2025 that the register had passed the threshold of 1,000 registrations since its launch in early 2023. The growth since then shows that openness about algorithms has become an established part of government operations, although considerable differences still exist between the various government organizations.

The role of impact assessments and fundamental rights

Transparency goes further than merely noting that an algorithm exists; it also requires insight into the risks and the protection of citizens. The measurement of the dataset shows that 439 of the 1,530 registrations (roughly 28.7 percent) mention a DPIA (Data Protection Impact Assessment). A further 47 registrations have had an IAMA (human rights impact assessment) carried out. For 1,050 registrations (68.6 percent), however, a formal mention of an impact assessment is absent.

This aligns with earlier findings by the Dutch Data Protection Authority. In July 2025 the AP established that at that point only 5 percent of registrations had undergone a fundamental rights review, and that more than half of municipalities and three-quarters of independent administrative bodies had registered nothing at all. Anyone wanting to know more about how such risks are mapped systematically can turn to the manual on carrying out an AI risk analysis and DPIA, which describes the methodology behind these impact assessments.

Legal basis and supervision

On the check date of 7 August 2026, registering algorithms in the central register remains largely voluntary at national level. Central government is, however, working on a legal obligation to register impactful algorithms, a course announced in a letter to parliament in December 2022. In doing so, the register seeks explicit alignment with the definitions from European legislation.

Broader oversight of these developments lies with coordinating bodies. The AP called in July 2025 for a hard legal requirement and published guidance on responsible deployment. Anyone wishing to explore the specific role of enforcers can read more in the article on AI supervision in the Netherlands: which regulators do what, which delineates the powers of the various inspectorates and regulators clearly.

A practical example: the rise of AI assistants

The content of the register is shifting increasingly from traditional calculations and risk calculators toward modern generative applications. Decentralized authorities and regional environmental agencies are integrating generative AI tools into their daily work processes more and more, and these systems are now finding their way into the public register too. A concrete example is the registration of "Microsoft 365 Copilot" by the Midden-Holland Environmental Agency, which received a recent status change in the database on 3 August 2026. In similar fashion, the Municipality of Oss entered "Microsoft CoPilot" into the register on 30 July 2026.

The inclusion of generative assistants of this kind raises fundamental questions about operational autonomy, the degree of human control and the transparency of AI-generated output. Civil servants and policymakers experimenting with such technologies who want to understand how they relate to the broader market can read the technical implications in the article on Agentic AI: the shift to autonomous AI systems, which goes deeper into the transition toward independently acting software.

Conclusion of the measurement

As of August 2026, the Dutch government's algorithm register shows a maturing practice. With 1,530 registrations and strong representation from municipalities, the foundation for public accountability has been laid. At the same time, the figures show that major steps remain to be taken on qualitative impact assessments and full coverage across all layers of government.

The period ahead will have to show whether the anticipated legal obligations and the tightening of European standards bring about a definitive shift toward one hundred percent transparency. The published dataset remains the instrument of choice for following this development critically and factually.