The EU AI Act in Netherlands

How Regulation (EU) 2024/1689 applies in Netherlands, and the 22 AI instruments Netherlands has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Netherlands’s own AI instruments

22 records tracked for Netherlands, beyond the EU-level Act above.

Netherlands AI Act Implementation Draft

BillProposed

Netherlands · 2026 · 2 Aug 2027

Netherlands International AI Strategy

PolicyIn Force

Netherlands · 2026 · 3 Jul 2026

Netherlands - AI Supervision Guidelines

GuidelineAdopted

Netherlands · 2024 · 7 Nov 2024

Netherlands - Generative AI Vision

PolicyAdopted

Netherlands · 2024 · 18 Jan 2024

Netherlands - Algorithm Regulation (Kamerstuk 26 643, nr. 1056)

PolicyAdopted

Netherlands · 2023 · 7 Jul 2023

Netherlands - Responsible Algorithm Use

GuidelineAdopted

Netherlands · 2023 · 30 Jun 2023

Netherlands - Algorithm Transparency Register

PolicyIn Force

Netherlands · 2022 · 21 Dec 2022

Netherlands - Digitalisation Strategy (2022)

PolicyAdopted

Netherlands · 2022 · 4 Nov 2022

Netherlands - AI Investment Programme

PolicyIn Force

Netherlands · 2021 · 9 Apr 2021

Netherlands - AI Non-Discrimination Handbook

GuidelineIn Force

Netherlands · 2021

Netherlands - Algorithm Application Guidelines

GuidelineIn Force

Netherlands · 2021

Netherlands - Digital Public Administration Guidelines

GuidelineAdopted

Netherlands · 2021 · 30 Apr 2021

Netherlands - Human Rights Impact Assessment

GuidelineIn Force

Netherlands · 2021 · 25 Feb 2021

Netherlands - AI Oversight Guidelines

GuidelineIn Force

Netherlands · 2020 · 16 Feb 2020

Netherlands - Amsterdam - Algorithm Transparency (2020)

PolicyIn Force

Netherlands · 2020 · 21 Sep 2020

Netherlands - Response to AI White Paper

PolicyAdopted

Netherlands · 2020 · 20 Apr 2020

Netherlands - AI and Human Rights (2019)

PolicyAdopted

Netherlands · 2019 · 8 Oct 2019

Netherlands - AI Development Coalition

PolicySuperseded

Netherlands · 2019 · 8 Oct 2019

Netherlands - AI Strategic Action Plan

PolicyIn Force

Netherlands · 2019 · 8 Oct 2019

Netherlands - Data Analysis Safeguards

GuidelineIn Force

Netherlands · 2019 · 8 Oct 2019

Netherlands - AI Innovation Center

GuidelineIn Force

Netherlands · 2018 · 26 Apr 2018

Amsterdam AI Regulation Summary

SummarySummary

Netherlands

National authority in Netherlands

Named in Netherlands’s own records, not inferred.

Per Netherlands - AI Supervision Guidelines

Per Netherlands - Generative AI Vision

Per Netherlands - Algorithm Regulation (Kamerstuk 26 643, nr. 1056)

Per Netherlands - Responsible Algorithm Use

Per Netherlands - Algorithm Transparency Register

Per Netherlands - Digitalisation Strategy (2022)

Per Netherlands - AI Investment Programme

Per Netherlands - AI Non-Discrimination Handbook

Per Netherlands - Algorithm Application Guidelines

Per Netherlands - Digital Public Administration Guidelines

Per Netherlands - Human Rights Impact Assessment

Per Netherlands - AI Oversight Guidelines

Per Netherlands - Response to AI White Paper

Per Netherlands - AI and Human Rights (2019)

Per Netherlands - AI Development Coalition

Per Netherlands - AI Strategic Action Plan

Per Netherlands - Data Analysis Safeguards

Per Netherlands - AI Innovation Center

Penalties in Netherlands

As stated in Netherlands’s own records.

Per Netherlands - AI Supervision Guidelines

  • The advice notes enforcement will be carried out by designated authorities using the sanctioning powers available under national law and the EU AI Regulation; this may include corrective orders, temporary or permanent market restrictions, and administrative fines where national law provides. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))
  • Coordination of enforcement is recommended to ensure consistent application of penalties across authorities and to protect fundamental‑rights enforcement priorities. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))
  • The document recommends clear procedural safeguards for appeals and judicial review of enforcement measures. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Per Netherlands - Generative AI Vision

  • Existing enforcement under GDPR by the Autoriteit Persoonsgegevens (administrative fines, corrective orders) for privacy breaches involving generative AI.
  • Sectoral sanctions enforceable by domain regulators (e.g., healthcare regulators, financial supervisors) for breaches of sector‑specific rules.
  • Procurement-related remedies including contract termination, damages and exclusion from future tenders for contractual non-compliance.
  • Administrative measures such as orders to suspend or modify public deployments where unlawful risks or harms are identified.
  • Potential criminal liability under existing laws (for example where offenses arise from misuse or negligent conduct) where applicable.
  • Commitment to propose additional enforcement mechanisms where legislative gaps are identified in line with EU AI Act developments.

Per Netherlands - Algorithm Regulation (Kamerstuk 26 643, nr. 1056)

  • The Verzamelbrief itself does not establish a bespoke penalty regime; enforcement flows through existing statutory channels.
  • For data-protection breaches related to algorithmic processing, the Autoriteit Persoonsgegevens may apply fines and corrective measures under the AVG/GDPR.
  • Audits or adverse findings by the Auditdienst Rijk or Algemene Rekenkamer may lead to parliamentary scrutiny and administrative corrective mandates.
  • Non-compliance with administrative law requirements can result in judicial review, annulment of decisions, and potential liability under the Algemene wet bestuursrecht.
  • Contractual remedies or procurement sanctions may be applied where suppliers fail to meet IKA-derived contractual obligations.

Per Netherlands - Responsible Algorithm Use

  • The framework itself does not set out direct statutory penalties.
  • Non-compliance with legal obligations referenced in the framework (e.g., GDPR) may trigger fines and administrative enforcement by supervisory authorities.
  • Audit findings by Auditdienst Rijk or Algemene Rekenkamer can result in remedial orders and reputational consequences.
  • Contractual remedies (damages, termination, indemnities) may apply where procurement or vendor contracts are breached.
  • Civil liability and judicial review may ensue in case of unlawful algorithmic decision-making.

Per Netherlands - Algorithm Transparency Register

  • Absent a formal statutory publication obligation at launch, the register itself did not immediately impose fines; future non-compliance when mandatory publication is enacted may result in administrative measures.
  • Privacy or data-protection violations discovered through registry disclosures may trigger enforcement by the Autoriteit Persoonsgegevens, including fines and binding corrective orders under the GDPR and related national law.
  • Under the EU AI Regulation, providers or deployers of high-risk AI systems may be subject to administrative fines and corrective measures imposed by designated national authorities.
  • Sectoral regulators and audit bodies may pursue administrative, contractual or reputational sanctions for non-compliance with sector rules or procurement obligations.

Per Netherlands - Digitalisation Strategy (2022)

  • The Werkagenda itself does not create new criminal penalties; enforcement relies on existing sectoral laws (e.g., GDPR enforcement by the Autoriteit Persoonsgegevens).
  • Administrative consequences (parliamentary scrutiny, budgetary actions or corrective directives) for non-compliant public bodies.
  • Regulatory sanctions or fines may apply where sectoral or statutory obligations (privacy, safety, consumer protection) are breached.

Per Netherlands - AI Investment Programme

  • Withholding or suspension of tranche payments for missed milestones.
  • Requirement to repay (clawback) funds if grant conditions are breached or funds are misapplied.
  • Termination of grant agreements and discontinuation of project support for major non-compliance.
  • Exclusion or reduced eligibility for future AiNed calls or related public funding opportunities.
  • Contractual remedies and administrative measures under applicable Dutch administrative law for disputes and breaches.

Per Netherlands - AI Non-Discrimination Handbook

  • Administrative fines under GDPR/AVG enforced by the Autoriteit Persoonsgegevens for unlawful processing leading to discriminatory outcomes (e.g., AP decision against Belastingdienst).
  • Judicial remedies under Dutch equality and administrative law for affected individuals, including annulment of decisions and compensation.
  • Contractual and procurement sanctions, including termination, damages and supplier debarment where vendor failures cause discriminatory outcomes.

Per Netherlands - Algorithm Application Guidelines

  • No penalties are created by the Guidelines themselves; enforcement is through existing statutes (e.g., GDPR/AVG fines, corrective measures by the Autoriteit Persoonsgegevens).
  • Sectoral administrative sanctions or enforcement measures may apply where algorithmic use breaches sector-specific law or regulatory obligations.
  • Judicial remedies, damages claims and administrative appeals remain available to individuals affected by unlawful automated decisions.
  • Contractual or procurement sanctions may be applied by public bodies against vendors who fail to meet contractual disclosure or audit obligations.

Per Netherlands - Digital Public Administration Guidelines

  • CODIO itself imposes no statutory penalties; it is a guidance instrument.
  • Failure to follow CODIO recommendations may increase exposure to legal enforcement under existing laws (e.g., GDPR sanctions by the <a href="https://autoriteitpersoonsgegevens.nl">Autoriteit Persoonsgegevens</a>), judicial remedies and administrative consequences.
  • Reputational and political accountability (parliamentary scrutiny, public criticism) for public bodies not demonstrating adherence to good-practice guidance.
  • Sectoral or contractual remedies where procurement contracts require adherence to equivalent standards.

Per Netherlands - Human Rights Impact Assessment

  • IAMA itself does not prescribe fines, but failure to perform adequate impact assessment can give rise to GDPR enforcement by the <a href="https://autoriteitpersoonsgegevens.nl">Autoriteit Persoonsgegevens</a> (administrative fines, orders) where personal data protection obligations are breached.
  • Administrative corrective measures, suspensions or cancellation of deployments by responsible ministries or agencies following audits (e.g., by the <a href="https://www.rekenkamer.nl">Algemene Rekenkamer</a> or internal audit).
  • Civil litigation or compensation claims by individuals affected by rights violations caused or enabled by inadequate assessment or mitigation.
  • Political, reputational and organisational consequences including parliamentary inquiries, policy restrictions and procurement bans.

Per Netherlands - AI Oversight Guidelines

  • Corrective orders requiring cessation or alteration of processing activities.
  • Administrative fines under the GDPR (up to EUR 20 million or 4% of global annual turnover, whichever is higher) where applicable.
  • Orders to delete or anonymise unlawfully processed personal data.
  • Publication of enforcement decisions and reputational measures.
  • Possible referral to sectoral regulators for non-data protection harms where relevant.

Per Netherlands - Response to AI White Paper

  • The appreciation does not itself create new penalties; it recommends that enforcement measures and sanctions be proportionate and specified in any future EU or national legislation.
  • Existing enforcement mechanisms under the GDPR (fines and corrective measures) remain applicable where personal data processing is involved.
  • Civil liability remedies remain available under national law for harms caused by AI; any new liability rules should clarify interactions with current frameworks.

Per Netherlands - AI and Human Rights (2019)

  • The Kamerbrief itself does not create new penalties; enforcement relies on existing legal frameworks.
  • Privacy violations or unlawful processing remain subject to GDPR enforcement and fines administered by the Autoriteit Persoonsgegevens (<a href="https://autoriteitpersoonsgegevens.nl">Autoriteit Persoonsgegevens</a>).
  • Administrative law remedies under the Algemene wet bestuursrecht (Awb) and sectoral statutes remain available to challenge adverse administrative decisions.
  • Civil liability claims may be brought under general tort or contract law where harm results from negligent or unlawful AI deployment.
  • Possible future statutory obligations (if enacted) could carry new administrative sanctions or penalties as determined by implementing legislation.

Per Netherlands - AI Development Coalition

  • None imposed by the Dutch AI Coalition itself (the NL AIC is a voluntary coordination framework).
  • Where public funding is involved, standard grant conditions and administrative remedies apply as set out by the relevant funding body.
  • Legal penalties or enforcement for_AI systems remain subject to statutory regulators and applicable legislation (e.g., data protection authorities, sector regulators, and forthcoming national implementing measures of EU rules).

Per Netherlands - AI Strategic Action Plan

  • No new penalties introduced by SAPAI itself; existing enforcement regimes (e.g., GDPR fines by the Autoriteit Persoonsgegevens) remain applicable for breaches of law
  • Potential procurement sanctions under public procurement rules where contractual obligations (including ethics/technical requirements) are breached

Per Netherlands - Data Analysis Safeguards

  • Enforcement under the GDPR/AVG by the Autoriteit Persoonsgegevens, including administrative fines where unlawful processing of personal data is found.
  • Administrative corrective measures under existing administrative law (orders to cease or modify processing; suspension of systems).
  • Judicial review and remedies through courts and administrative tribunals for breaches of legal obligations and procedural errors.
  • Sectoral sanctions or disciplinary measures where sectoral law or employment rules are breached.
  • Reputational and political consequences, including parliamentary scrutiny and ministerial inquiries, for failure to comply with guidelines or statutory safeguards.

Per Netherlands - AI Innovation Center

  • ICAI itself does not impose statutory penalties; remedies are contractual and funder-based
  • Possible penalties include suspension or withdrawal of funding for breaches of grant terms
  • Contracts may provide for dispute resolution, damages or termination in case of material breach
  • Institutional disciplinary procedures may apply for breaches of academic integrity or law

Netherlands overview

The full picture of AI regulation in Netherlands, beyond just the EU AI Act.

Netherlands AI regulation overview →