EU AI Act in the Netherlands: Which authorities supervise what

4 min readLast reviewed 4 August 2026
In short

The Netherlands has not yet finalised how it will supervise the EU AI Act. A draft implementation law, published for consultation in April 2026, splits oversight across eight sector-specific authorities rather than one dedicated AI regulator, coordinated by the Dutch Data Protection Authority and the Authority for Digital Infrastructure.

No new substantive law, but a missing piece

The EU AI Act is a directly applicable regulation, so the Netherlands does not need its own law to make the Act’s obligations binding. What it does need is a national law that designates which Dutch authorities can actually supervise those obligations and issue fines under Article 99. That law, the ‘Uitvoeringswet AI-verordening’, went out for public consultation on 20 April 2026 and had not been finalised as of July 2026. 

Its central choice is a decentralised model: rather than creating one new AI regulator, supervision is spread across eight existing sector-specific authorities, each overseeing AI within the domain it already regulates. Two of those authorities, the Dutch Data Protection Authority and the Dutch Authority for Digital Infrastructure, take on a coordinating role across the whole system, and the latter is designated as the country’s single point of contact under Article 70(2). 

For organisations operating in the Netherlands, the practical result is that the regulator they already deal with for their sector is likely to become their AI Act regulator too, rather than a single new authority appearing on top of the existing ones.

Who supervises what under the draft law

There are different authorities enforcing the draft law in the Netherlands. Find the corresponding domains below:

AuthorityDomain
Dutch Data Protection Authority (AP)Prohibited AI practices, Article 50 transparency obligations, and most Annex III high-risk categories: biometrics, education, employment, essential services outside finance, law enforcement, and migration
Dutch Authority for Digital Infrastructure (RDI)Coordinates the overall system together with the AP; designated single point of contact under Article 70(2); critical infrastructure oversight alongside the ILT
Authority for the Financial Markets (AFM) and Dutch Central Bank (DNB)High-risk AI, prohibited practices, and transparency obligations in financial services, including creditworthiness assessment
RDI, ILT, IGJ, NLA, and NVWAAnnex I product-related high-risk systems, split by existing product category: digital infrastructure and telecom equipment (RDI), transport (ILT), healthcare (IGJ), labour equipment (NLA), and food and consumer products (NVWA)
Procurator General at the Supreme Court and the President of the Administrative Jurisdiction Division of the Council of StateHigh-risk AI systems used within the judiciary, in the administration of justice

What this means in practice: Nobody in the Netherlands gets a brand-new regulator knocking on their door. A bank already answering to the AFM keeps answering to the AFM, just with an AI Act question added to the list. A hospital already dealing with the IGJ over medical devices deals with the same inspectorate if an AI system is involved. The organising principle is simple: whoever already regulates your sector now also regulates your AI.

Coordination and the sandbox

  • The AP and the RDI jointly coordinate the overall supervisory system, aligning approaches and sharing information across the eight designated authorities.
  • The RDI is the Article 70(2) single point of contact for the Netherlands.
  • All eight designated authorities are set to jointly operate a single, multi-sectoral AI regulatory sandbox with a shared digital application portal, coordinated by the AP and RDI, ahead of the national sandbox deadline, now 2 August 2027 under the Digital Omnibus.

In Short: AP and RDI are the two authorities holding the map for the other six. They are not taking over anyone else’s supervisory turf, but are making sure all eight pieces move as one system rather than eight unrelated ones.

Timeline in accordance with the EU AI Act

The AP has coordinated algorithm and AI oversight in the Netherlands since 2023, and had begun preparing to supervise the Article 5 prohibitions before they took effect on 2 February 2025. In November 2025, the AP and RDI jointly advised the Minister of Economic Affairs on how national supervision should be organised. Later on, the draft  for ‘Uitvoeringswet AI-verordening’ went out for public consultation on 20 April 2026, and closed on 1 June 2026. As of early July 2026, the bill had moved into the Council of State’s advisory phase, the standard step before a bill is sent to the House of Representatives for debate.

Until the law is adopted, the legal basis for which Dutch authority issues a national Article 99 fine is not yet finalised, even though the underlying EU AI Act obligations already apply directly.

How the draft manages fines

The draft does not create separate Dutch fine amounts. It applies the EU-wide Article 99 tiers directly, and gives the designated market surveillance authorities the power to impose those fines, order corrective measures, suspend or prohibit use of a system, mandate withdrawal from the market, or issue public warnings.

Deeploy’s role in the adoption of the EU AI Act in the Netherlands

Whichever Dutch authority ends up reviewing a system, the AP, the RDI, or a sector regulator like the AFM or DNB, they are asking the same underlying question every market surveillance authority asks: what has the system actually been doing in production, and is it safe? Deeploy keeps that evidence ready regardless of which of the eight authorities ends up asking for it. The AI governance platform ensures the deployment, monitoring and organisation of data, contributing to responsible AI practices in the Netherlands and all of Europe. 

Frequently asked questions

Disclaimer

This is general information, not legal advice. Please consult your legal/compliance team to confirm your organisation’s specific obligations. Deeploy supports your governance process; it does not constitute a guarantee of regulatory compliance.

Reading about compliance is step one. Operating it is Deeploy.See how teams use Deeploy to monitor, document and govern their AI against the EU AI Act.
Book a Demo

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one