In 2026 the Netherlands governs artificial intelligence mainly through the directly applicable EU AI Act and existing law such as the GDPR, with a national supervisory architecture that is still being built around the data protection authority as coordinator. This page sets out who supervises AI, the status of the government algorithm register, and the specific expectations for financial services, with links to the primary sources for each.
Last reviewed: 21 July 2026 · A factual snapshot; AI policy is evolving, so confirm against the primary sources linked below
The Netherlands does not have a standalone national AI Act. The binding backbone is the EU AI Act, which as an EU regulation applies directly in the Netherlands and phases in on the EU-wide timeline, alongside existing law such as the GDPR. What is still being organised nationally is supervision: which Dutch authorities enforce which parts of the Act.
Since 2023 the Autoriteit Persoonsgegevens (AP, the Dutch data protection authority) has been the coordinating supervisor for algorithms and AI, a role it runs through a dedicated unit, the Department for the Coordination of Algorithmic Oversight (DCA). The AP has said that multiple authorities are expected to be designated for different parts of the AI Act depending on how an AI system is used, and that the distribution of those roles will be set out in Dutch legislation. Until that legislation is in place, the national supervisory picture is coordinated rather than fully settled.
De Nederlandsche Bank (DNB), with the Authority for the Financial Markets (AFM), set out six general principles for responsible use of AI by financial institutions, captured in the acronym SAFEST: soundness, accountability, fairness, ethics, skills and transparency. They are guidance rather than binding rules, and DNB still weighs them in supervision.
The Autoriteit Persoonsgegevens (AP, the Dutch data protection authority) took on a national role coordinating oversight of algorithms and AI, and created a dedicated unit to carry it out: the Department for the Coordination of Algorithmic Oversight (DCA, Directie Coordinatie Algoritmes).
The Dutch government published a government-wide vision on generative AI, one of the first EU member states to set out a national position on the technology.
The two financial regulators jointly published a report on the impact of AI on the financial sector and supervision, mapping where institutions use AI (fraud and money-laundering detection, creditworthiness, identity verification), the risks (data quality, data protection, explainability, discrimination, dependence on a few large providers), and their supervisory attention points. Existing financial rules continue to apply in full.
The EU AI Act is a directly applicable EU regulation, so it takes effect across the Netherlands on the EU-wide timeline rather than through a separate national statute. The first tranche of obligations (governance and general-purpose AI) applied from August 2025, and member states were to designate their national supervisory authorities.
The AP set out its 2026 work agenda for coordinating AI and algorithm supervision, and, together with the Rijksinspectie Digitale Infrastructuur (RDI, the State Inspectorate for Digital Infrastructure), will open an AI regulatory sandbox from 2026 where organisations can test AI systems and receive guidance from supervisors.
The distinction that matters most for compliance is whether an instrument carries legal force, is supervisory guidance, or is still to be enacted. The table below sorts the main instruments accordingly.
| Instrument | Status | Applies to / owner |
|---|---|---|
| EU AI Act (Regulation (EU) 2024/1689) | Binding | Providers and deployers of AI systems in the EU; phased in on the EU timeline |
| GDPR and the Dutch implementing act (UAVG) | Binding | Any organisation processing personal data; enforced by the AP |
| AP coordinating supervision of algorithms and AI (via the DCA) | In force | The AP coordinates; it is not the only supervisor |
| National AI Act implementing legislation (supervisor designations) | Proposed, not in force | The distribution of supervisory roles is to be set in future Dutch legislation |
| Publication in the Algoritmeregister by government bodies | Policy commitment | Government organisations; as of September 2025 there is no statutory duty to publish |
| DNB SAFEST principles for AI in financial institutions (2019) | Non-binding guidance | Financial institutions; considered by DNB in supervision |
| AFM and DNB report on AI in the financial sector (2024) | Supervisory expectations | Financial institutions; existing rules apply in full |
| AP and RDI AI regulatory sandbox (from 2026) | Support mechanism | A voluntary way for organisations to test AI systems, not an obligation |
For the roles the AI Act itself allocates between providers and deployers, see our guide to EU AI Act roles, and for the phasing dates, the EU AI Act timeline.
Three practical points follow. First, the AI Act already sets the binding baseline, so the question for most organisations is not whether AI is regulated but which of their systems fall in scope and in what role. Second, because the Dutch supervisory designations are not yet settled in law, an organisation may deal with more than one authority depending on the context of use, with the AP coordinating and the RDI closely involved. Third, in financial services the sector regulators have been explicit that existing rules apply to AI in full, and that DNB weighs its SAFEST principles when it supervises how institutions use AI.
Where the national architecture is still forming, the weight of day-to-day AI governance sits with each organisation’s own framework and controls. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model.
There is no standalone Dutch AI Act. AI is governed principally by the EU AI Act, which is a directly applicable EU regulation, together with existing law such as the GDPR. The Netherlands is preparing national implementing legislation to designate which authorities supervise the AI Act, but as of mid-2026 those designations are not yet finalised in law.
The Autoriteit Persoonsgegevens (AP) is the coordinating supervisor for algorithms and AI, a role it has held since 2023 and carries out through its Department for the Coordination of Algorithmic Oversight (DCA). The AP expects multiple authorities to be designated for different parts of the AI Act depending on the context of use, and it is preparing for AI Act compliance monitoring jointly with the RDI. The precise allocation of roles will be set in Dutch legislation.
Government bodies are expected to publish the algorithms they use in the national Algoritmeregister, but this rests on policy rather than statute. In a letter to parliament dated 9 September 2025 the government took the position that a legal obligation to publish is not (yet) considered appropriate. For now, publication is a policy commitment, not a legal mandate.
Existing financial regulation continues to apply in full to AI use. On top of that, DNB set out its SAFEST principles for AI in 2019 (soundness, accountability, fairness, ethics, skills, transparency) as supervisory guidance, and in 2024 the AFM and DNB jointly published a report setting out their attention points for AI in the sector. The EU AI Act then adds further obligations where a financial institution provides or deploys AI that the Act covers.
Because the AI Act is an EU regulation, its obligations phase in across the Netherlands on the same EU-wide schedule rather than on a separate national one. See our EU AI Act timeline for the current phasing. Separately, the Dutch national supervisory architecture for the Act is still being organised.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, useful precisely because the national supervisory picture is still being organised.
This page is general information describing the state of Netherlands AI policy as at 21 July 2026, not legal or compliance advice. Policy and regulatory positions change; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.