# EU AI Act in the Netherlands: Which authorities supervise what > The Netherlands has not yet finalised how it will supervise the EU AI Act. A draft implementation law, published for consultation in April 2026, splits oversight across eight sector-specific authorities rather than one dedicated AI regulator, coordinated by the Dutch Data Protection Authority and the Authority for Digital Infrastructure. **Author:** Maarten Stolk **Last reviewed:** 31 July 2026 **Source:** https://deeploy.ai/eu-ai-act-hub/articles/eu-ai-act-in-the-netherlands-which-authorities-supervise-what/ ## **No new substantive law, but a missing piece** The EU AI Act is a directly applicable regulation, so the Netherlands does not need its own law to make the Act's obligations binding. What it does need is a national law that designates which Dutch authorities can actually supervise those obligations and issue fines under Article 99. That law, the ‘Uitvoeringswet AI-verordening’, went out for public consultation on 20 April 2026 and had not been finalised as of July 2026.  Its central choice is a decentralised model: rather than creating one new AI regulator, supervision is spread across eight existing sector-specific authorities, each overseeing AI within the domain it already regulates. Two of those authorities, the Dutch Data Protection Authority and the Dutch Authority for Digital Infrastructure, take on a coordinating role across the whole system, and the latter is designated as the country's single point of contact under Article 70(2).  For organisations operating in the Netherlands, the practical result is that the regulator they already deal with for their sector is likely to become their AI Act regulator too, rather than a single new authority appearing on top of the existing ones. ## **Who supervises what under the draft law** There are different authorities enforcing the draft law in the Netherlands. Find the corresponding domains below: | Authority | Domain | | --- | --- | | **Dutch Data Protection Authority (AP)** | Prohibited AI practices, Article 50 transparency obligations, and most Annex III high-risk categories: biometrics, education, employment, essential services outside finance, law enforcement, and migration | | **Dutch Authority for Digital Infrastructure (RDI)** | Coordinates the overall system together with the AP; designated single point of contact under Article 70(2); critical infrastructure oversight alongside the ILT | | **Authority for the Financial Markets (AFM) and Dutch Central Bank (DNB)** | High-risk AI, prohibited practices, and transparency obligations in financial services, including creditworthiness assessment | | **RDI, ILT, IGJ, NLA, and NVWA** | Annex I product-related high-risk systems, split by existing product category: digital infrastructure and telecom equipment (RDI), transport (ILT), healthcare (IGJ), labour equipment (NLA), and food and consumer products (NVWA) | | **Procurator General at the Supreme Court and the President of the Administrative Jurisdiction Division of the Council of State** | High-risk AI systems used within the judiciary, in the administration of justice | **What this means in practice:** Nobody in the Netherlands gets a brand-new regulator knocking on their door. A bank already answering to the AFM keeps answering to the AFM, just with an AI Act question added to the list. A hospital already dealing with the IGJ over medical devices deals with the same inspectorate if an AI system is involved. The organising principle is simple: whoever already regulates your sector now also regulates your AI. ## **Coordination and the sandbox** - The AP and the RDI jointly coordinate the overall supervisory system, aligning approaches and sharing information across the eight designated authorities. - The RDI is the Article 70(2) single point of contact for the Netherlands. - All eight designated authorities are set to jointly operate a single, multi-sectoral AI regulatory sandbox with a shared digital application portal, coordinated by the AP and RDI, ahead of the national sandbox deadline, now 2 August 2027 under the Digital Omnibus. **In Short:** AP and RDI are the two authorities holding the map for the other six. They are not taking over anyone else's supervisory turf, but are making sure all eight pieces move as one system rather than eight unrelated ones. ## **Timeline in accordance with the EU AI Act** The AP has coordinated algorithm and AI oversight in the Netherlands since 2023, and had begun preparing to supervise the Article 5 prohibitions before they took effect on 2 February 2025. In November 2025, the AP and RDI jointly advised the Minister of Economic Affairs on how national supervision should be organised. Later on, the draft  for ‘Uitvoeringswet AI-verordening’ went out for public consultation on 20 April 2026, and closed on 1 June 2026. As of early July 2026, the bill had moved into the Council of State's advisory phase, the standard step before a bill is sent to the House of Representatives for debate. Until the law is adopted, the legal basis for which Dutch authority issues a national Article 99 fine is not yet finalised, even though the underlying EU AI Act obligations already apply directly. ## **How the draft manages fines** The draft does not create separate Dutch fine amounts. It applies the EU-wide Article 99 tiers directly, and gives the designated market surveillance authorities the power to impose those fines, order corrective measures, suspend or prohibit use of a system, mandate withdrawal from the market, or issue public warnings. ## Deeploy's role in the adoption of the EU AI Act in the Netherlands Whichever Dutch authority ends up reviewing a system, the AP, the RDI, or a sector regulator like the AFM or DNB, they are asking the same underlying question every market surveillance authority asks: what has the system actually been doing in production, and is it safe? Deeploy keeps that evidence ready regardless of which of the eight authorities ends up asking for it. The AI governance platform ensures the deployment, monitoring and organisation of data, contributing to responsible AI practices in the Netherlands and all of Europe.  ## Frequently asked questions ## Frequently asked questions ### What is a conformity assessment and who needs one? A conformity assessment is the process by which a provider of a high-risk AI system demonstrates that the system meets the Act's requirements before placing it on the market. For most Annex III systems, providers can conduct a self-assessment based on internal documentation. Third-party assessment by a notified body is required for biometric identification systems and AI systems used as safety components of Annex I regulated products. ### What is the difference between Annex VI and Annex VII? Annex VI is the internal control, or self-assessment, procedure: the provider checks its own quality management system and technical documentation against the Act's requirements. Annex VII is the notified body procedure: an accredited third party reviews the same material and issues a certificate. ### When is a notified body mandatory for a biometric AI system? Under Article 43(1), a provider of a biometric system listed in Annex III, point 1, can choose self-assessment only if it has fully applied the relevant harmonised standards or common specifications. If those standards do not yet exist, have not been fully applied, or only partially cover the requirements, notified body assessment under Annex VII is mandatory. ### Do all high-risk AI systems under the EU AI Act need a notified body? No. Under Article 43(2), high-risk systems listed in Annex III, points 2 to 8, which cover employment, education, essential services, law enforcement, migration, and justice, use self-assessment only. A notified body is required only for certain biometric systems under Annex III, point 1, and for AI embedded in products already regulated under Annex I. ### Does a completed conformity assessment last indefinitely? No. Under Article 43(4), a substantial modification to a high-risk system after assessment triggers a new conformity assessment, regardless of which route was originally used. ### What happens if my AI system will be used by law enforcement or an EU institution? For biometric systems under Annex III, point 1, that are intended for use by law enforcement, immigration, or asylum authorities, or by EU institutions, bodies, or agencies, the relevant market surveillance authority performs the notified body role itself, rather than a private notified body. ### Has the Digital Omnibus changed the conformity assessment deadlines? Yes. Stand-alone Annex III obligations now move to 2 December 2027, and Annex I embedded high-risk systems move to 2 August 2028. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026, so these are now the legally binding dates.