Parts of the AI Act have applied since February 2025. Who enforces them in the Netherlands still isn't written into law.
AI Act enforcement in the Netherlands is set to be split across ten existing regulators under the draft implementation bill, with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) covering everything that doesn't fit a sector regulator, and the AP and the Dutch Authority for Digital Infrastructure (RDI) jointly coordinating. As of 9 October 2026, none of those ten has the power to enforce the AI Act, because the Dutch implementation act (Uitvoeringswet AI-verordening) hasn't reached parliament yet.
That isn't a reason to relax. It means you can already see where you'll end up, and you can use the time before the law lands to get your files in order.
Who can enforce the AI Act in the Netherlands today?
Nobody, in the sense of the AI Act itself. The Dutch DPA said so plainly on 9 October 2026: "De AP is beoogd markttoezichthouder op AI, maar nog niet aangewezen." In English: the AP is the intended market surveillance authority for AI but hasn't been designated, and it only gets AI market surveillance powers once the Dutch implementation act is in force.
The EU asked member states to designate their authorities by 2 August 2025. The Netherlands missed that. The bill went to public consultation on 20 April 2026, which closed on 1 June. It still has to pass the Council of Ministers and the Council of State before it can be sent to parliament, and the bill's entry-into-force date currently reads "PM".
The government accepted that delay knowingly. Its letter to parliament of 20 April 2026 says the implementation act is expected to take effect later than the AI Act requires, and adds straight away that the obligations still apply, because the regulation is directly applicable in every member state.
For a business, that's an odd position. The ban on emotion recognition in the workplace has applied since February 2025 and the transparency duty since August 2026. Break those rules and you're doing something prohibited, but you can't yet be fined for it under the AI Act. Regulators can still act under the laws they already have: the AP enforces the GDPR, and the consumer authority ACM can step in when an algorithm misleads consumers. The explanatory memorandum names those routes as the tools for the interim period.
Which regulator covers your AI use case?
The regulator for your AI system depends on what it does and which sector you're in. The explanatory memorandum to the consultation bill contains the full split. These are the use cases we see most at Dutch companies with 50 to 500 staff:
| Your use case | AI Act category | Proposed regulator |
|---|---|---|
| Customer chatbot or voicebot | transparency (Article 50) | AP; AFM for financial institutions |
| Publishing AI-generated images or text | transparency (Article 50) | AP; AFM for financial institutions |
| CV screening, assessments, rostering, staff evaluation | high-risk, Annex III point 4 | AP |
| Assessing customer creditworthiness | high-risk, Annex III point 5b | AP; AFM and DNB for financial services |
| AI in managing critical infrastructure | high-risk, Annex III point 2 | RDI or ILT, depending on the domain |
| AI in a machine you place on the market | Annex I, product legislation | NVWA (consumer) or Labour Inspectorate (professional) |
| AI in a medical device | Annex I, product legislation | IGJ (health inspectorate) |
| Prohibited practices, such as manipulation or workplace emotion recognition | Article 5 | AP; AFM and DNB for financial institutions |
Two things stand out. The AP becomes the regulator for most AI an ordinary company runs, including everything HR-related. And it takes that role on top of its GDPR supervision, so an AI system that processes personal data will in practice be tested against two laws by one regulator.
The split is still a proposal. The financial markets authority AFM has raised concerns about how tasks are divided with the central bank DNB, and the AP has asked for transparency supervision of emotion recognition and biometric categorisation to sit with the AP alone. Expect details to shift.
Time saved
Save 12 hours per week on working out which AI use cases fall under which risk category and regulator
What powers will an AI regulator have over your company?
An AI regulator in the Netherlands will get more tools than most companies expect. According to the implementation assessment the AP sent to parliament on 31 August 2026, in a prohibited-practice investigation the AP can require information, request samples and run digital or physical inspections, and then impose corrective measures, pull an AI system from the market or order a recall.
The bill adds a few powers you don't see in every regime:
- Mystery shopping. Inspectors may obtain or use an AI system under a different identity, to see how it treats an ordinary customer.
- Administrative enforcement orders, with or without penalty payments, to stop an infringement, alongside the fine.
- Cost recovery. The regulator may recover supervision costs from the company concerned.
- Documentation in Dutch or English. A technical file only in German or Chinese from your vendor won't do.
One exception is worth knowing. AI literacy (Article 4) carries no fine. The memorandum calls it a best-efforts obligation with a very open character. If a regulator finds the level too low, it issues an order with a deadline to improve. The Digital Omnibus also softened Article 4 into supporting AI literacy, without a guaranteed level. How to set that up is covered in the AI literacy requirement for staff.
How high can a fine get for a company with 50 to 500 staff?
The maximum fine for a company with 50 to 500 staff is lower than the headline 35 and 15 million euros, and the Digital Omnibus lowered it further for a big part of that group. Article 99 of the AI Act has three tiers:
| Infringement | Large company | SME | Small mid-cap |
|---|---|---|---|
| Prohibited practice (Article 5) | €35m or 7% of turnover, whichever is higher | whichever is lower | whichever is higher |
| High-risk and transparency duties | €15m or 3% of turnover, whichever is higher | whichever is lower | whichever is lower |
| Incorrect information to the regulator | €7.5m or 1% of turnover, whichever is higher | whichever is lower | whichever is lower |
A small mid-cap is a new category from the Digital Omnibus (Regulation (EU) 2026/1744): a company that's no longer an SME but has fewer than 750 staff and turnover up to €150 million or a balance sheet up to €129 million. Under the EU definition an SME has fewer than 250 staff and turnover up to €50 million or a balance sheet up to €43 million.
Two worked examples, assuming the maximum fine:
- Wholesaler, 300 staff, €80 million turnover. Not an SME, but a small mid-cap. A chatbot with no AI disclosure breaches the transparency duty: at most the lower of €15 million and 3% of €80 million, so €2.4 million. A prohibited practice falls outside the mid-cap rule: at most the higher of €35 million and 7% of €80 million (€5.6 million), so €35 million.
- Installation company, 120 staff, €20 million turnover. An SME. Transparency: the lower of €15 million and €0.6 million, so €0.6 million. Prohibited practice: the lower of €35 million and €1.4 million, so €1.4 million.
The gap between those two prohibited-practice lines is the point. A mid-cap gets no discount on the heaviest tier. A tool that infers employees' emotions from camera footage or calls could, in the worst case, cost a 300-person company the full amount rather than a percentage of turnover. A maximum isn't a tariff, of course. Regulators weigh seriousness, duration and cooperation, and the Omnibus requires member states to consider the interests of SMEs and mid-caps and to use warnings and non-monetary measures too.
How does a complaint or investigation work?
An investigation into your AI system will often start with a complaint. Anyone who believes the AI Act is being breached may report it to a regulator under Article 85. The Dutch memorandum treats such a complaint as an enforcement request under the General Administrative Law Act (Awb, Article 1:3). That gives the regulator a principled duty to enforce with corrective sanctions, such as an order with penalty payments. There's no such duty for fines.
The decision on that request is a formal decision, open to objection and appeal by both the complainant and you. A rejected applicant who suspects a CV filter screened them out can therefore start proceedings that may end up before the administrative courts, separately from any GDPR complaint.
Because ten regulators can touch the same system, the bill requires a cooperation protocol published in the Government Gazette. The AP and RDI have already set up a joint AI Coordination Centre for this. The AP's own examples: a toy with a chatbot, or an AI triage system in an emergency department, where product law and the AI Act meet. The RDI will be the central point of contact towards the EU.
What to expect until the law is in place
The AP is building the organisation in the meantime. In early October 2026 it launched a new directorate for AI and algorithm supervision, including a department preparing market surveillance. In its assessment the AP asks for €9.7 million for 2027, rising to €28.2 million in 2031. What's secured right now is €1.7 million in one-off funding for 2027. That gap tells you something about how fast enforcement will ramp up.
Where the AP is already looking is set out in its AI and algorithm risk report of March 2026: AI in recruitment is growing fast and carries big risks, transparency and explainability fall short, and organisations try to dodge the AI Act by classifying their systems as "ordinary algorithms". That last point signals that the classification itself will be investigated. Record why a system does or doesn't fall under the regulation, and who assessed it.
There's no official help desk yet. The RDI and AP will run a digital desk for general questions and applications to the regulatory sandbox, the test environment the Netherlands should have opened by 2 August 2026 under the AI Act. The sandbox is still being prepared.
In practice, for the coming months:
- Map each AI system to its category and regulator. The table above is a starting point.
- Treat HR systems as a priority. They sit with the AP, the risk report flags them, and the high-risk requirements apply from 2 December 2027 (see the Digital Omnibus and the AI Act delay). What changes for hiring is covered in AI in recruitment: rules and risks.
- Sort out transparency now. It has applied since August and is easy to test with mystery shopping. Details in AI transparency requirements for businesses.
- Work out whether you're an SME, a small mid-cap or a large company. That sets your maximum exposure more than any headline figure.
The full legal framework, including the risk categories, is in our overview of the EU AI Act and AI legislation in the Netherlands. If you'd like someone to go through it system by system, we do that as part of AI consulting.