The Netherlands runs the only national, publicly searchable catalogue of government algorithms in the European Union. The algoritmeregister, published at algoritmes.overheid.nl, lets any citizen look up which automated and AI systems a ministry, municipality, or regulator uses, what the system does, what data feeds it, and who to contact if something goes wrong. It predates the EU AI Act by more than two years, it covers far more than the Act's high-risk category, and it grew out of a domestic political crisis rather than a Brussels mandate. Understanding it purely as an AI Act compliance tool undersells what it is: a distinctly Dutch experiment in making algorithmic government legible to the people it governs.

Where the register came from

The idea did not start in The Hague. In September 2020 the cities of Amsterdam and Helsinki each launched a public algorithm register, publishing plain-language descriptions of the automated systems their municipal services relied on, an initiative later catalogued by the OECD's AI policy observatory among its collection of national and municipal algorithmic transparency tools. The municipal experiments landed against the backdrop of the toeslagenaffaire, the childcare benefits scandal in which a Dutch tax administration risk-scoring algorithm wrongly flagged tens of thousands of families, disproportionately those with dual nationality, as suspected fraudsters, a failure documented in detail in the parliamentary and judicial record of the affair and one that brought down the sitting cabinet in January 2021. The scandal turned algorithmic transparency from a municipal curiosity into a national political demand, and government policy in the years that followed increasingly pointed toward making algorithm transparency a binding legal obligation rather than a voluntary practice.

The national register went live on 21 December 2022, described by the government at launch as a central place where public bodies publish the algorithms they use. The register's own About page states that it "helps to make algorithms discoverable, to explain them better and to make their application and impact understandable." Its scope, notably, was never limited to artificial intelligence. From the outset it targeted any "impactful algorithm," a category that includes simple deterministic scoring rules used to award or reclaim benefits just as much as it includes machine learning models, a design choice that reflects the toeslagenaffaire's core lesson: harm to citizens does not require a neural network, only an opaque decision rule applied at scale.

Who operates it and who must register

The register is coordinated by the Ministry of the Interior and Kingdom Relations, with the Autoriteit Persoonsgegevens, the Dutch data protection authority, acting as the country's designated "Algorithm Supervisor" overseeing compliance, as confirmed on the AP's own site describing algorithm registration in the Netherlands. In practice, oversight of AI systems specifically is now split: the AP handles prohibited practices, most Annex III high-risk systems, and general transparency duties, while the Rijksinspectie Digitale Infrastructuur acts as the Article 70(2) single point of contact and coordinator. Product-embedded, Annex I high-risk AI systems instead fall to five existing sectoral market surveillance authorities acting jointly, the RDI itself, the ILT, the human environment and transport inspectorate, the IGJ, the Health and Youth Care Inspectorate, the NVWA, the food and consumer product safety authority, and the NLA, the labour authority, an arrangement laid out in the Netherlands' draft AI Act implementation law described by Bird and Bird's analysis of the Uitvoeringswet AI-verordening, published for public consultation on 20 April 2026 and open for comment until 1 June 2026. Inside the AP, a dedicated Directie Coördinatie Algoritmes, established in 2023, runs cross-sector risk analysis and publishes a half-yearly AI and algorithm risk report, a structure documented in an overview of the AI Act's institutional landscape in the Netherlands.

Registration itself remains, as a matter of hard law, voluntary. What has hardened over time is political and administrative pressure rather than statute: government policy has repeatedly signalled an intent to make publication compulsory, and the pending implementation law is the vehicle through which that obligation is expected to finally take legal form, aligned with national legislation and with the EU AI Regulation, as reporting on the National Algorithm Register's regulatory status notes. Central government ministries have registered relatively consistently, but coverage elsewhere is uneven. The AP's own assessment found that since the start of 2023, roughly a thousand algorithms had been entered into the register, yet more than half of Dutch municipalities had not registered a single one, and more than three-quarters of independent administrative bodies, the zelfstandige bestuursorganen that run large parts of the Dutch welfare and licensing state, had registered nothing at all, findings summarised in DataGuidance's coverage of the AP's call for improvement. The same assessment found that only around five percent of registered algorithms had undergone a fundamental rights impact assessment, despite that assessment being the register's own recommended safeguard for anything genuinely impactful.

What gets disclosed for each algorithm

Each entry follows a common publication standard, maintained collaboratively through the Algoritmes community, whose specification is published at standaard.algoritmeregister.org. The standard groups required fields into six categories. Basic information covers the algorithm's name, the responsible organisation and department, its geographic scope, its policy domain, a short plain-language summary, and an assigned risk category. A use case section requires the organisation to explain the underlying decision-making process, the policy goal being served, the assessed impact on individuals and on society, the mitigation measures attached to any identified risk, and the specific legal basis for processing. A data section covers the source and training data involved, known or suspected biases, and a link to the underlying data protection impact assessment. An algorithm section requires a substantive explanation, up to ten thousand characters, of how the system actually works, including its type, whether descriptive, diagnostic, predictive, or prescriptive, the methods used, alternatives that were considered, and, where available, a link to the source code. An oversight section covers how performance is monitored, how and by whom human intervention is exercised, what objection routes exist for affected individuals, and whether a decision can be rolled back. A metadata section carries the standard version, a unique identifier, a named contact, and revision history.

A representative entry, published by the Autoriteit Consument en Markt for its detection algorithm for unreasonable energy tariffs, illustrates how this plays out in practice. The entry explains that the tool flags electricity and gas tariffs that sit as statistical outliers against comparable products, states plainly that the results are checked manually by an investigation team before the regulator contacts a supplier, and lists the entry under the register's "Other algorithms" publication category, with the risk classification field left blank, rather than treating every flagged case as an automated enforcement action. That level of specificity, tied to a named regulator and a named process, is what distinguishes the register from a generic AI inventory.

Companion tools: the Algoritmekader and the IAMA

The register does not stand alone. The Ministry of the Interior also maintains the Algoritmekader, an open-source framework, published at minbzk.github.io/Algoritmekader, that walks public bodies through the laws, standards, and practical tools relevant to responsible algorithm use, functioning as the compliance roadmap that sits behind the register's public-facing entries. Alongside it sits the Impact Assessment Mensenrechten en Algoritmes, a human rights impact assessment tool originally developed in 2021 by Utrecht University for the ministry. An AI Act related update to the IAMA is expected in 2026, according to the glossary entry maintained by AI Act Blog, though the details of that update, including how closely it will track Article 27's fundamental rights impact assessment requirement for high-risk systems, have not yet been published. Together, the register, the Algoritmekader, and the IAMA form a three-part domestic architecture that predates, and may in time be drawn more closely into, the EU's own compliance apparatus.

How this relates to the EU AI Act

The relationship between the Dutch register and the AI Act's transparency machinery is one of overlap without equivalence. Article 50 of the AI Act imposes general transparency duties, disclosure that a person is interacting with an AI system, labelling of synthetic content, and similar obligations, and these were not delayed by the Digital Omnibus: they still apply from 2 August 2026. Separately, Article 71 establishes an EU-wide public database for high-risk AI systems listed in Annex III, populated by providers under Article 49 and, where the deployer is a public authority, by that authority itself under Article 49(3) and (4), as detailed in the official explanatory text for Article 71. Under the Digital Omnibus timetable, those standalone Annex III high-risk obligations are deferred to 2 December 2027, and embedded Annex I obligations to 2 August 2028.

The Dutch register and the EU database are not the same instrument wearing different names. The EU database is narrower in scope, limited to systems that meet the Act's high-risk definition, and it is narrower still in practice: registrations touching law enforcement, migration, and border control, three of the Annex III categories, are visible only to the European Commission and national supervisors, not to the public. The Dutch register, by contrast, was built around the broader idea of the "impactful algorithm," reaches deterministic scoring rules that never touch a machine learning model, and treats public visibility as the default rather than the exception. It also simply existed years before the Act's high-risk provisions were drafted, arising from a domestic accountability failure rather than from a directive to harmonise the internal market. The AI Act gives the Netherlands a reason to eventually make registration compulsory and, through Article 27's impact assessment duty, a possible template that the IAMA's expected 2026 update may draw on. It does not explain why the register exists in the first place.

Why the mechanism matters on its own terms

The register's real significance lies less in any single legal duty than in the governance culture it expresses: that a government's algorithmic decisions belong, by default, in front of the people affected by them, described and explained in language a non-specialist can follow, with a named person to contact and a stated route to challenge a result. That is a materially different premise from the AI Act's, which is organised around product risk classification and market surveillance rather than around a citizen's standing right to look up what automated system decided their case. The municipal registers that preceded it in Amsterdam and Helsinki demonstrated that a city government could publish this kind of disclosure on its own initiative, without waiting for a national or EU mandate, and the Netherlands' willingness to publish compliance gaps candidly, including its own regulator's finding that half of municipalities and three-quarters of independent administrative bodies have registered nothing, is itself a form of transparency that a purely compliance-driven register would have less incentive to surface.

The unresolved question is whether the register's voluntary status can survive contact with the accountability it was designed to deliver. A catalogue that omits most of the country's independent administrative bodies, and in which only one in twenty registered systems has been checked against fundamental rights, is a meaningful start rather than a finished mechanism. The draft Uitvoeringswet AI-verordening, moving through consultation in 2026, is the clearest sign yet that the Netherlands intends to close that gap by statute rather than by continued exhortation. Whatever form that law takes, the register itself, an idea born in two city halls and hardened by a national scandal, will likely remain a reference point for public-sector AI transparency well beyond whatever the EU AI Act eventually requires.

Primary sources

Related articles