Netherlands AI Act Implementation Draft

AI Regulation Implementation Act

Uitvoeringswet AI-verordening

Netherlands

RAI-NL-NA-IMPLEME-2026
Proposed(Officially filed for action)
BillGovernance and OversightRisk ManagementEnforcement and Penalties
Export PDF

The Netherlands' draft AI Regulation Implementation Act aims to integrate and enforce the EU AI Act, establishing national oversight and compliance for safe and trustworthy AI.

Overview

The Uitvoeringswet AI-verordening, or AI Regulation Implementation Act, represents the Netherlands' national legislative effort to integrate and enforce the comprehensive European AI Regulation (AI Act) within its legal framework. This crucial piece of legislation aims to establish a robust regulatory environment for artificial intelligence systems, ensuring their safe, trustworthy, and human-centric development and deployment across various sectors. The draft act, currently undergoing public consultation, is a direct response to the European Union's pioneering AI Act, which sets harmonized rules for AI systems throughout the EU. By transposing the provisions of the EU AI Act into national law, the Netherlands seeks to uphold fundamental rights, promote innovation, and mitigate the risks associated with AI technologies, thereby fostering public trust in AI. The initiative underscores the Dutch government's commitment to creating a balanced regulatory landscape that supports technological advancement while safeguarding societal values and individual well-being.

The core objective of the Uitvoeringswet AI-verordening is to provide the necessary legal infrastructure for the effective implementation and enforcement of the EU AI Act. This includes defining the roles and responsibilities of national supervisory authorities, establishing mechanisms for compliance, and outlining the penalties for non-compliance. The act adopts a risk-based approach, mirroring the EU AI Act, which categorizes AI systems based on their potential to cause harm. This tiered approach ensures that regulatory burdens are proportionate to the risks posed by different AI applications, ranging from minimal to unacceptable. The consultation process, which commenced on April 20, 2026, and concluded on June 1, 2026, allowed stakeholders, including businesses, civil society organizations, and citizens, to provide feedback on the proposed legislation, contributing to a more comprehensive and effective regulatory framework.

Definitions

The Uitvoeringswet AI-verordening largely relies on the definitions established within the overarching European AI Regulation, ensuring consistency and harmonization across the European Union. Key terms central to the regulation, such as 'AI system,' 'provider,' 'deployer,' and 'high-risk AI system,' are adopted directly from the EU framework. An 'AI system' is generally understood as a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This broad definition captures a wide array of AI technologies and applications, ensuring comprehensive coverage under the new regulatory regime. The act also clarifies the roles of 'providers' (those who develop or place an AI system on the market) and 'deployers' (those who use an AI system), assigning specific obligations to each party to ensure accountability throughout the AI lifecycle.

Crucially, the concept of 'high-risk AI systems' forms a cornerstone of the regulatory approach, necessitating stringent requirements due to their potential to significantly impact safety, health, and fundamental rights. These systems are explicitly listed in Annex III of the EU AI Act and include AI applications used in critical infrastructure, education, employment, law enforcement, migration, and the administration of justice. The Dutch implementation act will detail how these classifications are applied nationally and which specific AI systems fall under the high-risk category within the Dutch context. Furthermore, the act addresses 'prohibited AI practices,' which are deemed to pose an unacceptable risk to fundamental rights and are therefore banned outright. These include manipulative AI practices, indiscriminate social scoring, and real-time biometric identification in publicly accessible spaces for law enforcement purposes, with limited exceptions. The consistent application of these definitions is vital for legal certainty and effective enforcement.

Governance and Institutional Framework

The Netherlands has opted for a hybrid supervisory model for the enforcement of the AI Act, leveraging existing regulatory bodies rather than creating a single new overarching authority. This approach aims to ensure that market participants primarily interact with supervisory authorities they are already familiar with, thereby streamlining compliance and minimizing administrative burden. The proposed framework designates a total of ten market surveillance authorities, each responsible for overseeing AI systems within their specific domain of expertise. This sector-based supervision model acknowledges the pervasive nature of AI across various industries and seeks to capitalize on the specialized knowledge of existing regulators. For instance, an AI system used in the financial sector would fall under the purview of financial regulators, while AI in healthcare would be supervised by health authorities.

Central to this multi-stakeholder governance structure are two coordinating authorities: the Autoriteit Persoonsgegevens (AP), the Dutch Data Protection Authority, and the Rijksinspectie Digitale Infrastructuur (RDI), the Digital Infrastructure Inspectorate. The AP is assigned a broad coordinating role and will also be responsible for supervising prohibited AI applications, transparency obligations, and a significant portion of high-risk AI systems, especially those not clearly falling under an existing sectoral regulator. This includes AI systems used in recruitment, education, benefits, and law enforcement. The RDI will specifically oversee AI systems within the Radio Equipment Directive (RED) and those integrated into digital critical infrastructure, such as telecommunications and internet systems. The Minister of Economic Affairs and Climate will serve as the central contact point for the AI Regulation, facilitating coordination among the various supervisory bodies. This collaborative model is designed to ensure comprehensive oversight while maintaining a balance between safety and fostering innovation.

Key Focus Areas

The Uitvoeringswet AI-verordening, in alignment with the EU AI Act, places significant emphasis on several key areas to ensure the responsible development and deployment of AI systems. A primary focus is on the stringent requirements for high-risk AI systems, which are subject to extensive obligations regarding data governance, risk management, human oversight, and transparency. Providers of such systems must implement robust risk management systems throughout the AI system's lifecycle, from design to decommissioning, to identify, analyze, and mitigate potential risks. This includes ensuring high-quality training, validation, and testing data, as well as maintaining comprehensive technical documentation and logging capabilities. Human oversight is mandated to ensure that natural persons can effectively oversee and intervene in the operation of high-risk AI systems, preventing or minimizing risks to health, safety, and fundamental rights.

Another critical area addressed by the act is the prohibition of certain AI practices deemed to pose an unacceptable risk to fundamental rights. These include AI systems that deploy manipulative subliminal techniques, exploit vulnerabilities of specific groups, or are used for social scoring by public authorities. Real-time biometric identification systems in publicly accessible spaces for law enforcement purposes are also generally prohibited, with very limited and specific exceptions. Furthermore, the act introduces transparency obligations for certain AI systems, such as those intended to interact with natural persons (e.g., chatbots) or those that generate or manipulate image, audio, or video content (deepfakes), requiring users to be informed that they are interacting with or viewing AI-generated content. These provisions are designed to enhance public trust and ensure that individuals are aware when they are engaging with AI, promoting accountability and informed decision-making.

Implementation Framework

The implementation framework outlined in the Uitvoeringswet AI-verordening details the practical mechanisms through which the EU AI Act will be enforced in the Netherlands. This includes establishing the legal basis for the designated national competent authorities to carry out their supervisory tasks, granting them the necessary powers for market surveillance, investigations, and imposing corrective measures. The act will specify procedures for conformity assessments, which are mandatory for high-risk AI systems before they can be placed on the market or put into service. These assessments ensure that AI systems comply with the essential requirements set forth in the AI Act, covering aspects such as risk management, data quality, technical robustness, cybersecurity, and human oversight. The framework also anticipates the establishment of regulatory sandboxes, which will provide a controlled environment for the development and testing of innovative AI systems under regulatory supervision, fostering innovation while ensuring compliance with future regulations.

A key aspect of the implementation framework is the emphasis on cooperation and information sharing among the various national supervisory authorities. Given the hybrid model with multiple regulators, effective coordination is paramount to prevent fragmentation and ensure a consistent application of the rules. The act will outline mechanisms for these authorities to collaborate, share expertise, and jointly address complex cases involving AI systems that span multiple sectors. Furthermore, the framework addresses the need for adequate resources, capacity, and data-sharing protocols for the designated authorities to effectively perform their duties, as highlighted by feedback from bodies like the Autoriteit Financiële Markten (AFM). The goal is to create a coherent and efficient enforcement ecosystem that can adapt to the rapid pace of AI development while ensuring a high level of protection for citizens and businesses.

Monitoring and Evaluation

Monitoring and evaluation are integral components of the Uitvoeringswet AI-verordening, designed to ensure the ongoing effectiveness and adaptability of the AI regulatory framework. The designated national supervisory authorities will be responsible for continuously monitoring the compliance of AI systems with the requirements of the EU AI Act and the national implementation law. This includes conducting market surveillance activities, investigating complaints, and performing audits of AI systems, particularly those classified as high-risk. The monitoring process will involve assessing whether AI systems continue to meet the standards for data quality, risk management, human oversight, and transparency throughout their lifecycle. Regular reporting mechanisms will be established to collect data on AI incidents, compliance rates, and the overall impact of the regulation, providing valuable insights for future policy adjustments.

The evaluation aspect of the framework will involve periodic reviews of the Uitvoeringswet AI-verordening to assess its effectiveness in achieving its objectives, such as fostering trustworthy AI, protecting fundamental rights, and promoting innovation. These evaluations will consider feedback from stakeholders, insights gained from enforcement activities, and developments in AI technology. The aim is to identify any gaps or challenges in the current regulatory approach and propose necessary amendments to ensure the law remains relevant and fit for purpose in a rapidly evolving technological landscape. The coordinating roles of the AP and RDI will be crucial in synthesizing monitoring data and facilitating comprehensive evaluations across different sectors, contributing to a unified understanding of AI's impact and the regulatory response. This continuous cycle of monitoring and evaluation is essential for maintaining a dynamic and responsive AI governance system in the Netherlands.

Penalties, Liability, and Appeals

The Uitvoeringswet AI-verordening will establish a robust framework for penalties, liability, and appeals, aligning with the enforcement mechanisms stipulated in the European AI Regulation. The national act will define the specific administrative fines and other corrective measures that can be imposed on providers and deployers of AI systems for non-compliance with the established requirements. These penalties are expected to be effective, proportionate, and dissuasive, reflecting the severity of the infringement and the potential harm caused. Non-compliance with the prohibitions on certain AI practices or with the requirements for high-risk AI systems could lead to substantial financial penalties, mirroring the significant fines outlined in the EU AI Act to ensure a strong deterrent effect. The precise amounts and criteria for imposing these fines will be detailed within the national legislation, providing clarity for all stakeholders.

Furthermore, the act will address aspects of liability and redress, ensuring that individuals who suffer harm due to non-compliant or faulty AI systems have avenues for seeking compensation. While the EU AI Act primarily focuses on regulatory compliance, national implementation acts like the Uitvoeringswet AI-verordening are crucial for laying down the procedural rules for civil liability claims. The legislation will also establish clear procedures for appeals against decisions made by supervisory authorities, guaranteeing due process and the right to a fair hearing for affected parties. This includes mechanisms for administrative appeals and judicial review, allowing businesses and individuals to challenge enforcement actions. The goal is to create a comprehensive system that not only enforces compliance but also provides effective remedies for those adversely affected by AI systems, thereby reinforcing trust and accountability in the AI ecosystem.

Relationship to Other Instruments

The Uitvoeringswet AI-verordening is designed to operate in conjunction with, and complement, existing national and European legal instruments, rather than replacing them. Its primary relationship is, of course, with the European AI Regulation, which it directly implements and enforces. This means that the national act will interpret and apply the broad principles and specific requirements of the EU AI Act within the Dutch legal context. Crucially, the act will also interact closely with the General Data Protection Regulation (GDPR), given the significant overlap between AI systems and personal data processing. Where AI systems process personal data, both the AI Act and the GDPR will apply concurrently, with the GDPR governing the lawfulness of data processing and the AI Act setting requirements for the AI system itself, such as data governance and quality for high-risk AI. The Autoriteit Persoonsgegevens (AP) will play a key role in navigating this intersection, given its mandate under both regulations.

Beyond data protection, the Uitvoeringswet AI-verordening will also interface with sector-specific legislation and product safety laws. For instance, AI systems integrated into medical devices will still need to comply with existing medical device regulations, in addition to the AI Act's requirements for high-risk AI. The hybrid supervisory model, which assigns oversight to existing sectoral regulators, inherently facilitates this integration by leveraging their established expertise in specific domains. The act will clarify how these various legal frameworks interact, aiming to avoid regulatory conflicts and ensure a coherent legal landscape for AI. This layered approach ensures that AI systems are not only safe and trustworthy from an AI-specific perspective but also comply with all other relevant legal obligations, contributing to a comprehensive and robust regulatory environment.

International Alignment

The Uitvoeringswet AI-verordening is fundamentally rooted in the principle of international alignment, specifically with the European Union's overarching regulatory framework for artificial intelligence. As an implementation act, its core purpose is to transpose the provisions of the EU AI Act into national Dutch law, thereby ensuring a harmonized approach to AI regulation across all EU Member States. This alignment is crucial for fostering a single market for trustworthy AI within the EU, preventing fragmentation, and enabling businesses to operate seamlessly across borders. The Netherlands has consistently expressed its support for a strong European approach to AI, emphasizing the importance of common standards for safety, ethics, and fundamental rights in AI development and deployment.

By adopting the EU AI Act's risk-based classification system, its definitions, and its core requirements, the Dutch implementation act contributes to Europe's ambition to be a global leader in responsible AI. This international alignment extends beyond mere legislative conformity; it also involves active participation in European-level discussions and cooperation mechanisms, such as the European Artificial Intelligence Board. The Dutch government's stance underscores a commitment to ensuring that AI systems developed and used in the Netherlands adhere to the highest ethical and safety standards, consistent with European values. This not only benefits Dutch citizens and businesses by providing a clear and predictable regulatory environment but also strengthens the EU's collective voice and influence in shaping global AI governance norms and standards.

Implementation Timeline

MilestoneDateNotes
Internet Consultation Period2026-04-20 to 2026-06-01Public feedback collected on the draft Uitvoeringswet AI-verordening.
Advisory Opinion from Council of StatePost 2026-06-01The draft bill will be submitted to the Raad van State for legal advice.
Submission to Tweede KamerTo be determinedFormal legislative treatment in the Dutch House of Representatives.
Enactment and PublicationTo be determinedFollowing parliamentary approval and royal assent.
Entry into Force (Phased)Anticipated 2027-08-02 (full effect)The EU AI Act itself has phased entry into force, with some prohibitions already in effect (e.g., 2025-02-02). The national act will align with these dates.

Compliance Checklist

CheckRequired Action
Identify AI System Risk CategoryDetermine if your AI system falls under unacceptable, high-risk, limited, or minimal risk categories as per the EU AI Act.
Prohibited AI Practices ReviewEnsure no AI systems are deployed that engage in prohibited practices (e.g., manipulative AI, social scoring, real-time biometric identification in public spaces).
High-Risk AI System ComplianceFor high-risk systems, implement robust risk management systems, ensure data governance and quality, establish human oversight, and maintain technical documentation.
Transparency ObligationsFor AI systems interacting with humans or generating content, ensure users are informed of AI interaction/generation.
Conformity AssessmentConduct mandatory conformity assessments for high-risk AI systems before market placement.
Post-Market MonitoringEstablish systems for continuous monitoring of AI systems once in use, including incident reporting.
Designated Authority EngagementUnderstand which national supervisory authority is responsible for your sector and engage with them as required.
Data Protection AlignmentEnsure AI system operations comply with GDPR requirements, especially concerning personal data processing.

Sources and References

SourceType
Consultatie Uitvoeringswet AI-verordening van start - Digitale Overheidgovernment
Kabinet zet stap met toezicht op Europese AI-regels | Rijksoverheid.nlgovernment
Toezicht op AI: balans tussen veiligheid en innovatie | Rijksinspectie Digitale Infrastructuur (RDI)government
AI-verordening AI (Artificiële Intelligentie) - Digitale Overheidgovernment
Plain English

The Netherlands' proposed AI Regulation Implementation Act translates the EU AI Act into national law, setting clear rules for anyone developing or using Artificial Intelligence (AI) systems in the country. This bill aims to ensure AI is safe, trustworthy, and human-centric, applying to all AI systems based on their potential risk, from minimal to unacceptable.

The law covers "providers" who develop or put AI systems on the market, and "deployers" who use them. It introduces several key obligations and prohibitions. Most importantly, it bans certain AI practices outright, such as: - Manipulative AI techniques that exploit vulnerabilities. - Indiscriminate social scoring by public authorities. - Real-time biometric identification in public spaces for law enforcement, with very limited exceptions. For "high-risk AI systems"—those with significant potential impact on safety, health, or fundamental rights (e.g., in critical infrastructure, education, employment, law enforcement)—the requirements are stringent. Providers must implement robust risk management, ensure high-quality data, maintain human oversight, provide detailed technical documentation, and undergo mandatory conformity assessments before market entry. Additionally, certain AI systems, like chatbots or those generating "deepfake" content, must clearly inform users they are interacting with or viewing AI-generated material.

The law is anticipated to fully take effect on August 2, 2027, though some prohibitions from the EU AI Act may apply earlier. Non-compliance can lead to substantial administrative fines and other corrective measures, designed to be effective and dissuasive. Individuals harmed by non-compliant AI systems will also have avenues for seeking compensation.

A practical point to note is the Netherlands' hybrid supervisory model. Instead of one central authority, ten existing market surveillance authorities will oversee AI in their specific sectors. The Dutch Data Protection Authority (AP) will play a broad coordinating role and supervise many high-risk AI systems not covered by other sectoral regulators, which could make navigating compliance complex for some businesses.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Netherlands AI Act Implementation Draft. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalFeb 2, 2025

    Applies to: Providers and deployers of AI systems

    The act addresses 'prohibited AI practices,' which are deemed to pose an unacceptable risk to fundamental rights and are therefore banned outright.
  2. #2CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems

    The act will specify procedures for conformity assessments, which are mandatory for high-risk AI systems before they can be placed on the market or put into service.
  3. #3CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems

    Providers of such systems must implement robust risk management systems throughout the AI system's lifecycle.
  4. #4CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems

    This includes ensuring high-quality training, validation, and testing data.
  5. #5CriticalBefore placing on market

    Applies to: Providers and deployers of high-risk AI systems

    Human oversight is mandated to ensure that natural persons can effectively oversee and intervene in the operation of high-risk AI systems.
  6. #6CriticalAug 2, 2027

    Applies to: Providers and deployers of AI systems processing personal data

    Where AI systems process personal data, both the AI Act and the GDPR will apply concurrently.
  7. #7CriticalAug 2, 2027

    Applies to: Providers and deployers of AI systems in regulated sectors

    AI systems integrated into medical devices will still need to comply with existing medical device regulations, in addition to the AI Act's requirements for high-risk AI.
  8. #8ImportantBefore placing on market

    Applies to: Providers of high-risk AI systems

    as well as maintaining comprehensive technical documentation and logging capabilities.
  9. #9ImportantAug 2, 2027

    Applies to: Providers and deployers of certain AI systems (e.g., chatbots, deepfakes)

    requiring users to be informed that they are interacting with or viewing AI-generated content.
  10. #10ImportantUpon incident / As required

    Applies to: Providers and deployers of AI systems

    Regular reporting mechanisms will be established to collect data on AI incidents, compliance rates.

© Regulations.AI — created on 12-Jun-2026 using Gemini 2.5 Flash