Netherlands - AI Supervision Guidelines

Final Advice on the Organisation of AI Supervision

Eindadvies inrichting AI-toezicht

Netherlands

RAI-NL-NA-FAOASXX-2024
Adopted(Adopted)
GuidelineGovernance and OversightMarket SurveillanceConformity Assessment and Registration
Export PDF

A joint final advice published on 7 November 2024 by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) and the Rijksinspectie Digitale Infrastructuur (RDI) sets out a coordinated, sector-based approach to national supervision of AI under the EU AI Regulation. The document proposes roles, cooperation mechanisms, designation of market surveillance and fundamental-rights authorities, a national sandbox model, information-sharing safeguards and preparatory steps to implement the AI Regulation in the Netherlands. (rdi.nl)

Overview

The "Final Advice on the Organisation of AI Supervision" (Eindadvies inrichting AI-toezicht Nederland), published jointly by the Autoriteit Persoonsgegevens (AP) and the Rijksinspectie Digitale Infrastructuur (RDI) on 7 November 2024, recommends a coordinated, sectorally‑anchored national supervision model to implement the EU AI Regulation. The advice argues that effective protection of public interests (notably health, safety and fundamental rights) is best achieved by leveraging existing sectoral supervisory mandates while appointing a limited set of market surveillance authorities to oversee product‑style AI systems and Annex I/III categories. The document sets out governance principles, proposed authority designations, information‑sharing arrangements, and preparatory measures for a national regulatory sandbox intended to support compliance and innovation. For the primary text and annexes see the full official report and the AP and RDI webpages. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Definitions

The advice uses key terms drawn from the EU AI Regulation and domestic supervisory practice: "market surveillance authority" (as used in Regulation (EU) 2019/1020 and the AI Regulation), "sectoral or domain‑specific supervisory authorities" (national agencies with existing mandates over particular sectors), "fundamental‑rights supervisors" (authorities charged with oversight of Charter rights, equal‑treatment bodies and data protection authorities), and "conformity assessment bodies" (notified bodies that perform assessments under the AI Regulation). The document clarifies that the recommended model should not weaken existing sectoral mandates and that the assignment of new AI supervision duties must be accompanied by resources and legal authority. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Governance and Institutional Framework

The advice proposes a layered governance structure: a Core Team of coordinating authorities (led operationally by AP and RDI) that performs day‑to‑day coordination and knowledge management; a broader cooperating network of sectoral supervisors and fundamental‑rights authorities participating via the same platform that already supports algorithmic oversight; and formal designation of a limited number of market surveillance authorities for Annex I/III product groups (notably AP, RDI/ILT, DNB, AFM). It emphasizes the need for statutory legal bases for information exchange, memoranda of understanding to set practical cooperation rules, shared technical expertise (cybersecurity, conformity assessment, forensic investigation), and an annual public report. The governance model is deliberately pragmatic and modular to allow the national implementing law to set roles while preserving sectoral proximity to supervised entities. The advice further outlines roles for a national regulatory sandbox and joint training and staff‑sharing measures to build capacity across authorities. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Key Focus Areas

The document highlights a set of priority areas for Dutch AI supervision: (1) systems listed in Annex I (product‑style, safety‑critical AI) and Annex III (other high‑risk sectors), where a small number of market surveillance authorities should be designated; (2) transparency obligations (Article 50 of the AI Regulation), with AP proposed as coordinator for transparency enforcement in cooperation with other authorities; (3) the registration and monitoring of notified conformity assessment bodies and oversight of the conformity assessment process; (4) prohibited AI systems and rapid incident response; (5) cross‑authority information‑sharing and legal safeguards for exchanging evidence and intelligence; (6) regulatory sandboxes and compliance support mechanisms; and (7) capacity building and resourcing to enable effective enforcement without degrading existing sector supervision. The advice also flags oversight of general purpose AI (GPAI) and the need to determine which authorities will lead on those novel systems depending on risk and use cases. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Implementation Framework

The final advice proposes concrete implementation steps for national legislators and supervisors: (a) formally designate market surveillance and fundamental‑rights authorities in national implementing legislation; (b) set up the Core Team and joint governance bodies (with terms of reference and reporting lines); (c) provide legal bases and data‑sharing protocols that respect the GDPR and national confidentiality rules; (d) create a register and onboarding process for conformity assessment bodies and ensure adequate oversight capacity; (e) operationalize a national regulatory sandbox consistent with forthcoming EU implementing acts; (f) prepare sectoral supervisors with resourcing, guidance documents, and technical training; and (g) adopt standard operating procedures for incident coordination, investigations and cross‑authority enforcement. The advice stresses that designation of roles must be paired with clear funding and workforce commitments to be feasible. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Monitoring and Evaluation

The advice calls for a continuous monitoring and evaluation regime: annual public reporting on supervisory activities and outcomes, periodic joint reviews of the supervisory architecture, feedback loops from sandbox participants to inform guidance, and metrics to measure responsiveness to incidents, enforcement actions taken, and progress on capacity building. It recommends that monitoring focus both on compliance outcomes and on systemically identifying blind spots (e.g., cross‑sector uses of high‑risk AI, supply‑chain vulnerabilities, and emergent GPAI risks). The Core Team is assigned a role in collating and publishing an annual supervisory assessment to maintain transparency and public trust. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Penalties, Liability, and Appeals

While the advice itself does not create new sanctions, it explains how enforcement under the AI Regulation should be carried out by the designated market surveillance and fundamental‑rights authorities, consistent with the sanctioning powers available under national law and the AI Regulation. It stresses coordination on enforcement strategy to ensure coherent application of corrective measures, administrative fines, ordering of compliance steps, and referral to criminal or administrative procedures where applicable. The document also recommends clear procedural rules for rights of appeal, inter‑authority dispute resolution mechanisms, and the preservation of judicial redress for affected persons. These mechanisms should be spelled out in national implementing legislation and supporting procedural rules. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

Relationship to Other Instruments

The advice situates the national supervisory design within the broader EU legal landscape: it links directly to the EU AI Regulation (including Annex I and III), relevant product safety regulation (including Regulation (EU) 2019/1020), and the GDPR. It recommends aligning national implementing legislation with the AI Regulation and with sectoral rules (healthcare, transport, financial services), ensuring that AI supervision complements existing product and sectoral oversight rather than duplicating or undermining it. The advice also calls for coordination with EU bodies and the AI Board to ensure consistent interpretation and cross‑border enforcement. ([rdi.nl](https://www.rdi.nl/binaries/rdi/documenten/publicaties/2024/11/7/eindadvies-inrichting-ai-toezicht-nederland/2024-11-07_Eindadvies_Inrichting_AI-toezicht_Nederland.pdf))

International Alignment

The report emphasises that national arrangements should be compatible with EU‑level structures and with international cooperation on AI oversight. It recommends active engagement in the AI Board and cooperation with other Member States on designation practices, sandbox best practices, conformity assessment procedures and cross‑border incident handling, while preserving national sector expertise. The proposed sandbox model is intended to reflect forthcoming EU implementing acts and to allow the Netherlands to both comply with and influence EU‑wide sandbox criteria and selection processes. International alignment is recommended on technical standards, conformity assessment equivalence and information sharing while maintaining data protection guarantees. ([rdi.nl](https://www.rdi.nl/documenten/publicaties/2025/03/25/vormvoorstel-regulatory-sandbox-ai-verordening?utm_source=openai))

Implementation Timeline

MilestoneDate / Deadline
Publication of final advice (AP & RDI)2024-11-07
Stakeholder technical briefing2024-11-18
National implementing legislation & formal designations (recommended target start of process)2024 Q4 onwards (process to be initiated immediately)
Operational readiness, capacity building and onboarding of notified bodies2025–2026
Start of at least one national regulatory sandbox (aligned with EU implementing acts)By 2026-08-01 (EU AI Regulation requirement: by August 2026)

Compliance Checklist

Action for Regulated PartiesNotes
Identify if your AI system falls under Annex I / Annex III or high‑risk categoryFollow guidance from sectoral supervisor and designated market surveillance authority
Prepare documentation required by the AI Regulation (risk assessment, technical documentation, logs)Be ready for conformity assessment and market surveillance requests
Consider joining or consulting the national sandbox for guidanceSandbox participation is voluntary but strongly recommended for complex systems
Ensure transparency obligations are met (Article 50 and other disclosure rules)AP coordinates transparency enforcement; maintain records to demonstrate compliance

Sources and References

SourceType
Eindadvies Inrichting AI-toezicht Nederland (PDF) — RDI & AP, 07-11-2024Primary Source
Eindadvies inrichting AI-toezicht AP & RDI — Autoriteit PersoonsgegevensPrimary Source
Proposal for Dutch regulatory sandbox under the AI Regulation — RDI (March 2025)Primary Source
Plain English

The Netherlands is setting up a comprehensive system to supervise Artificial Intelligence (AI) under the upcoming European Union AI Regulation, affecting companies and public bodies that develop or use AI in the country. This framework, outlined in a final advice from the Dutch Data Protection Authority (AP) and the Rijksinspectie Digitale Infrastructuur (RDI), aims to protect public interests like health, safety, and fundamental rights.

The advice primarily guides Dutch national supervisory authorities, but its implications extend to any organisation developing or deploying AI systems in the Netherlands, particularly those categorised as "high-risk" under the EU AI Regulation (e.g., AI in critical infrastructure, medical devices, or employment). Companies operating in these areas must prepare for increased scrutiny.

Key obligations for businesses, once national laws are in place, will include: - Identifying if your AI system falls into a high-risk category (Annex I or III of the EU AI Regulation). - Preparing extensive documentation, such as risk assessments, technical specifications, and activity logs, to demonstrate compliance. - Ensuring your AI systems meet transparency requirements, like those in Article 50 of the EU AI Regulation. - Avoiding the development or deployment of AI systems explicitly prohibited by the EU AI Regulation.

This supervisory framework will be rolled out gradually. While the advice was published in November 2024, national implementing legislation is expected from late 2024 onwards, with full operational readiness and capacity building continuing through 2025-2026. A national regulatory sandbox, designed to help companies test and ensure compliance, is targeted to be operational by August 2026.

Enforcement will be handled by designated market surveillance and fundamental-rights authorities, who will have powers to issue corrective measures, impose administrative fines, and order compliance steps, as defined by national law and the EU AI Regulation.

A practical pitfall for businesses is the proposed "sector-based" approach. This means that in addition to new AI-specific oversight, companies might still be supervised by their existing sectoral regulators (e.g., in finance or healthcare), potentially leading to a complex, multi-layered compliance landscape. The advice stresses that new AI duties must come with adequate resources and legal authority for supervisors.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 6 marked complete

Plain-English obligations under Netherlands - AI Supervision Guidelines. Not legal advice — verify against the official text before relying on it.

  1. #1Critical

    Applies to: Providers of AI systems

    Identify if your AI system falls under Annex I / Annex III or high‑risk category
  2. #2CriticalBefore placing on market

    Applies to: Providers of AI systems

    prohibited AI systems
  3. #3CriticalBefore placing on market

    Applies to: Providers of AI systems

    Prepare documentation required by the AI Regulation (risk assessment, technical documentation, logs)
  4. #4CriticalArticle 50Before placing on market

    Applies to: Providers of AI systems

    Ensure transparency obligations are met (Article 50 and other disclosure rules)
  5. #5CriticalImmediately upon incident detection

    Applies to: Providers of AI systems

    rapid incident response
  6. #6Recommended

    Applies to: Providers of complex AI systems

    Consider joining or consulting the national sandbox for guidance

© Regulations.AI — created on 13-Jun-2026