The Netherlands operates a twin peaks model of financial supervision, and that structure carries directly into how the country oversees artificial intelligence in banking, insurance, pensions and investment services. De Nederlandsche Bank (DNB) supervises the prudential soundness of financial institutions, while the Autoriteit Financiele Markten (AFM) supervises conduct of business and market integrity. Both regulators have been examining AI in financial services since well before the EU AI Act existed, and both now have to fit their sector-specific expectations underneath the AI Act, which took direct effect across the EU as Regulation (EU) 2024/1689 and was subsequently amended by the Digital Omnibus.
DNB's 2019 starting point: the SAFEST principles
The foundational Dutch text on AI in finance is not the AI Act at all. On 25 July 2019, DNB published a discussion paper titled General principles for the use of Artificial Intelligence in the financial sector, setting out six principles that have become known by the acronym SAFEST: soundness, accountability, fairness, ethics, skills and transparency. Under soundness, DNB expects AI applications to be reliable, accurate and predictable, and to operate within existing regulatory boundaries. Under accountability, firms remain responsible for AI outcomes even where a model behaves unexpectedly and causes harm to the institution, its customers or wider stakeholders. The remaining principles, fairness, ethics, skills and transparency, extend the same logic of responsible use across non-discrimination, ethical deployment, staff competence and explainability of outputs. DNB framed SAFEST explicitly as an interpretation of the existing statutory requirement that financial undertakings maintain controlled and sound business operations, applied with proportionality to the scale, complexity and materiality of the AI application in question, rather than as a new freestanding rulebook.
The 2024 joint AFM-DNB report on AI and supervision
Almost five years later, on 9 April 2024, AFM and DNB published a joint report, The impact of AI on the financial sector and supervision, available in full from the AFM website. The report acknowledged that Dutch financial institutions had already been using AI for years in areas such as identity verification during customer onboarding, transaction analysis, fraud detection in claims handling, bond pricing, automated review of legal documents and credit and insurance risk management, and that firms were increasingly experimenting with more advanced and general-purpose models. Alongside the efficiency and fraud-detection benefits, the regulators flagged a consistent set of risks: data quality problems, privacy exposure, algorithmic bias and discrimination, weak explainability of model outputs, incorrect or unreliable outputs, and growing dependence on external technology vendors for critical AI infrastructure.
On supervision, the two regulators were explicit that no separate AI-specific regulatory regime exists in the Netherlands outside the EU AI Act itself: existing sectoral rules, whether prudential requirements enforced by DNB or conduct and market rules enforced by AFM, already apply regardless of the technology used to meet them. What changes is supervisory practice. AFM and DNB said supervision would need to focus more closely on institutions' risk management around AI, the way AI is applied in practice, and the outcomes AI systems produce for customers and markets, and that both regulators would need to build deeper technical expertise and adapt supervisory methods accordingly. The report also anticipated that the EU AI Act would formally classify certain financial AI use cases as high-risk, which would layer additional, more prescriptive compliance obligations on top of existing sectoral supervision.
Where the AI Act intersects financial services specifically
The AI Act's Annex III list of high-risk use cases directly names two financial applications. Point 5(b) classifies AI systems used to evaluate the creditworthiness of natural persons or to establish their credit score as high-risk, with an exception for AI used solely to detect financial fraud. Point 5(c) classifies AI systems used for risk assessment and pricing in relation to natural persons in life and health insurance as high-risk, a category that does not extend to property, casualty, motor or commercial insurance pricing. Institutions running these specific use cases face the fuller high-risk regime under the AI Act, including risk management systems, data governance, technical documentation, human oversight, and conformity assessment, once those obligations take effect.
That timeline has itself shifted. The Digital Omnibus was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, and it deferred the high-risk obligations for standalone Annex III systems, including the credit-scoring and insurance-pricing categories relevant to finance, to 2 December 2027. High-risk obligations for AI embedded in products already covered by Annex I are deferred further, to 2 August 2028. The deferral does not touch the AI Act's general transparency duties under Article 50, which still apply from 2 August 2026 regardless of whether a given AI system is separately classified as high-risk, so Dutch financial institutions deploying customer-facing AI, such as chatbots or AI-generated content in customer communications, still need to meet those disclosure obligations on the original schedule even as the deeper high-risk compliance work is phased in later.
Who actually supervises AI Act compliance in Dutch finance
The Netherlands did not create a new standalone AI regulator. Instead it built its AI Act supervisory architecture around existing authorities. The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, acts as the coordinating algorithm and AI regulator, covering prohibited AI practices and any domain that lacks its own sector regulator, and has established an internal directorate dedicated to coordinating algorithm oversight, though the exact scope and establishment date of that unit should be confirmed against the AP's own publications rather than assumed. The Rijksinspectie Digitale Infrastructuur (RDI) acts as the technical market-surveillance coordinator for product-related AI and conformity assessment bodies. Financial services, however, keep their existing sectoral regulators: AFM and DNB continue to supervise AI used in banking, insurance and investment activity, including creditworthiness assessment and risk-modelling systems, rather than that oversight shifting to the AP.
The Dutch government's implementation bill for the AI Act, the Uitvoeringswet AI-verordening, went out for public consultation on 20 April 2026, and it is this bill that is expected to formally confirm AFM and DNB's designation as market surveillance authorities for financial-sector AI under the Act, alongside the AP's coordinating role and the RDI's technical function, as described in contemporaneous legal analysis of the Dutch AI Act supervision structure. As of the middle of 2026, the domestic legal basis for imposing national administrative fines under that implementation act had not yet been finalised, even though the underlying EU-level obligations in the AI Act were already directly applicable and enforceable in their own right.
The EU-level financial guidance layered on top
Dutch financial institutions do not read the AI Act in isolation. Three EU-level financial supervisory authorities have each issued their own interpretive guidance on AI within their existing sectoral legislation, and DNB and AFM apply these as part of the same supervisory conversation.
The European Securities and Markets Authority (ESMA) issued a public statement on 30 May 2024 giving initial guidance to investment firms using AI in the provision of retail investment services under MiFID II. ESMA identified customer service, investment advice and portfolio management support, compliance, risk management and fraud detection as common AI use cases, and said firms remain bound by MiFID II's organisational and conduct-of-business requirements, including the obligation to act in clients' best interests, and should present information about how AI is used in a clear, fair and not misleading way. ESMA flagged algorithmic bias, opaque staff-level decision-making, overreliance on AI outputs by firms and clients alike, and data privacy and security as the principal risks warranting supervisory attention.
The European Insurance and Occupational Pensions Authority (EIOPA) published its Opinion on Artificial Intelligence governance and risk management in August 2025, addressed to national insurance supervisors. Rather than creating new rules, the Opinion clarifies how existing Solvency II, Insurance Distribution Directive and DORA requirements already apply to AI systems that fall outside the AI Act's own prohibited-practice and high-risk categories, and sets out a risk-based, proportionate expectation that insurers address fairness and ethics, data governance, documentation and record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity in their AI governance frameworks.
Underpinning both is the Digital Operational Resilience Act (DORA), which has applied across EU financial services since 17 January 2025 and imposes harmonised requirements on ICT risk management, incident reporting, and oversight of third-party technology providers, a category that increasingly includes external AI model and infrastructure vendors. The European Banking Authority has been working to align its own outsourcing and ICT guidelines with DORA and has consulted on extending third-party risk management requirements beyond ICT services generally, reflecting how much AI-related risk in finance now runs through vendor and outsourcing arrangements rather than through in-house model development alone.
Supporting innovation alongside supervision
DNB and AFM have paired this supervisory posture with structured channels for firms experimenting with AI. The two regulators, together with the Authority for Consumers and Markets (ACM), jointly run an InnovationHub where financial firms can raise questions about how existing rules apply to new technology, including AI-driven tools. Separately, under Article 57 of the AI Act, every member state must stand up a regulatory sandbox for supervised AI testing, and the AP and RDI published a joint proposal for the Dutch regulatory sandbox design, describing a single, multi-sectoral sandbox with one shared entry point for participating organisations and involvement from the AP itself whenever a tested AI system processes personal data. The sandbox was originally targeted for operation by the AI Act's original 2 August 2026 deadline for Article 57 sandboxes, but the Digital Omnibus pushed that deadline back by one year, to 2 August 2027, and the Dutch proposal's operational target should move with it.
What this means in practice
For a bank, insurer, pension provider or investment firm operating in the Netherlands, AI governance now sits at the intersection of several distinct but overlapping expectations. DNB's SAFEST principles remain the durable reference point for how the regulator reads AI risk into the existing statutory duty of controlled and sound operations. The 2024 joint AFM-DNB report signals that supervisory attention will keep concentrating on risk management practice, real-world application and outcomes rather than the technology label itself. The AI Act adds a harder-edged compliance layer specifically for credit-scoring and life and health insurance pricing systems, on a timeline now pushed to December 2027 for those high-risk obligations, while transparency duties for AI-driven customer interactions already apply from August 2026. ESMA and EIOPA guidance fills in sector-specific detail for investment firms and insurers respectively, and DORA's third-party risk regime increasingly governs how institutions must manage AI vendors and infrastructure providers. None of these layers replaces the others, and Dutch institutions building AI governance programmes need to map their AI use cases against all of them rather than treating any single publication as a complete compliance answer.
Primary sources
- DNB, General principles for the use of Artificial Intelligence in the financial sector (25 July 2019)
- AFM and DNB publish report on the impact of AI on the financial sector and supervision (9 April 2024)
- AFM/DNB, The impact of AI on the financial sector and supervision (full report, April 2024)
- ESMA, guidance to firms using artificial intelligence in investment services (30 May 2024)
- EIOPA, Opinion on Artificial Intelligence governance and risk management (August 2025)
- Analysis of AI Act supervision structure in the Netherlands, including AP, RDI, AFM and DNB roles
- Autoriteit Persoonsgegevens and RDI, proposal for the Dutch AI Act regulatory sandbox
- European Banking Authority, amendments to ICT and security risk management guidelines under DORA