Topic
Supervision and enforcement
Supervision of the AI Act is split between European and national bodies: the AI Office for general-purpose models, and in the Netherlands the Dutch Data Protection Authority and the RDI among others. Below is what has been officially set out on roles, powers and penalties.
Official guidance on this topic
11- Regulation (EU) 2026/1744, Digital Omnibus on AIBinding amending regulation published in the Official Journal on 24 July 2026 and in force since 27 July 2026. It amends the AI Act and several rules for regulated products. For the AI Act, it sets fixed application dates of 2 December 2027 for Article 6(2) and Annex III and 2 August 2028 for Article 6(1) and Annex I. It also retains registration after relying on Article 6(3), while simplifying the information in Annex VIII, expressly allows cross-references between a FRIA and DPIA, and adjusts the penalty regime for small mid-caps.PublishedRegulationEuropean Parliament and Council of the European Union24 Jul 2026
- Guidelines on transparency obligations for providers and deployers of certain AI systems under Article 50 of the AI ActFinal guidelines (C(2026) 5054 final), adopted following consultation on the draft version of 8 May 2026. They clarify the scope, definitions and content of obligations for providers and deployers: designing systems so that people know they are communicating with AI, marking AI-generated or manipulated content in machine-readable form, informing people about deepfakes, about AI-generated text on matters of public concern without human editorial oversight, and about emotion recognition and biometric categorisation. Exceptions such as standard processing operations and artistic or satirical context are addressed. Separate paragraphs address the interplay with data protection law and refer to joint guidelines to be drawn up by the Commission and EDPB. Non-binding, but directive for how supervisors interpret Article 50. The obligations apply from 2 August 2026.PublishedGuidelinesEuropean Commission20 Jul 2026
- Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act)For each prohibition, the Commission explains which AI practices are unacceptable and where the boundary lies, with legal explanation and practical examples: harmful manipulation, exploitation of vulnerabilities, social scoring, predictive policing based on profiling, indiscriminate scraping of facial images, emotion recognition at work and in education, biometric categorisation and real-time biometric identification at a distance. A separate chapter addresses the interplay with the GDPR, LED and EUDPR: by virtue of Article 2, paragraph 7, those remain unaffected, so a practice that just falls outside Article 5 can still be unlawful. The guidelines are not binding; only the Court of Justice provides binding interpretation. The formally adopted communication version bears the reference C(2025) 5052 final.PublishedGuidelinesEuropean Commission (DG CONNECT / AI Office)4 Feb 2025
- Navigating the AI Act (Questions and Answers)The broad official Q&A on the AI Act as a whole, structured around scope and objectives, high-risk AI, general-purpose AI models, governance and enforcement, and innovation and sustainability. The page covers, among other things, who the regulation applies to, how high-risk systems are identified, what obligations providers and deployers have, how supervision and the penalty structure work, and what role the AI Pact and the Service Desk play. The date 7 August 2026 is the last updated date on the page itself.PublishedQ&AEuropean Commission, DG CONNECT7 Aug 2026
- Generative AI and the EUDPR. Orientations for ensuring data protection compliance when using Generative AI systems (Version 2)Revised version of the EDPS orientations on generative AI and personal data, primarily aimed at EU institutions under Regulation (EU) 2018/1725 but practically usable for any organisation. Covered are, amongst other things, determining roles and responsibilities in the chain, when use of a generative system processes personal data, the role of the data protection officer, when a DPIA is required, purpose limitation, data minimisation, accuracy, bias and automated decision-making. The EDPS provides these orientations explicitly in its role as data protection supervisor and not as market supervisor under the AI Act, and states that they leave the AI Act unaffected.PublishedGuidelinesEDPS (European Data Protection Supervisor)28 Oct 2025
- Statement 3/2024 on data protection authorities' role in the Artificial Intelligence Act frameworkThe EDPB states that the AI Act and EU data protection law complement each other and must be interpreted in a coordinated manner, referring explicitly to Article 2(7) and recitals 9 and 10. It advises Member States to designate national data protection authorities as market surveillance authorities, mandatory for high-risk systems in Annex III points 1, 6, 7 and 8 and preferably also more broadly. The EDPB also points to the close link between the data protection impact assessment (DPIA) and the fundamental rights impact assessment, and to the absence of structured coordination between the AI Office and data protection authorities on general-purpose AI models.PublishedOpinionEDPB (European Data Protection Board)16 Jul 2024
- Cabinet takes step towards supervision of European AI rulesOfficial government announcement at the start of the public consultation on the Dutch AI Regulation Implementation Act. The government chooses a hybrid model in which existing sectoral supervisors exercise supervision of AI within their own domain. Where no clear supervisor yet exists, the Personal Data Authority is designated with a separate AI directorate. The Personal Data Authority and Digital Infrastructure Inspectorate together take the coordinating role in the system.PublishedNational guidanceGovernment of the Netherlands (State Secretary for Digital Economy and Sovereignty)20 Apr 2026
- AI-verordening (Rijksinspectie Digitale Infrastructuur)Fixed Digital Infrastructure Inspectorate page on its role under the AI Act and on the structure of Dutch supervision. The principle is that supervision is placed with existing sectoral supervisors as much as possible rather than with a new authority, with the Digital Infrastructure Inspectorate and Personal Data Authority together providing a coordinating expert role. Supervision of AI in CE-marked products such as machinery, lifts and toys remains with the existing product authority. The page refers to the final opinion of 7 November 2024 and the two interim opinions. Not substantively refreshed since 30 October 2025: no current position after the April 2026 consultation and nothing on the Digital Omnibus.PublishedNational guidanceDutch Authority for Digital Infrastructure (RDI)
- Response of the President of the Administrative Jurisdiction Division to the draft AI Regulation Implementation ActLetter of 8 July 2026 from the President of the Administrative Jurisdiction Division to the Ministry of Justice and Security, with response and implementing assessment to the draft bill. The Division endorses that market supervision of courts by courts takes place, but advises that the sandbox task and the agreements on uniform interpretation of terms should not apply to its President because this conflicts with judicial independence. It advises expanding its own supervision to AI systems that fall only under the transparency obligations, and signals a question of competence when it is unclear whether a system is prohibited or high-risk. The implementing assessment estimates approximately 1 full-time equivalent additional.PublishedOpinionCouncil of State, Administrative Jurisdiction Division8 Jul 2026
- Final advice on the design of AI supervision in the NetherlandsJoint final advice from RDI and AP (34 pages) on the design of Dutch supervision of the AI Act. Core: AI supervision aligns as closely as possible with regular sectoral supervision, products with CE marking remain with their existing supervisor, and cross-sectoral applications such as recruitment and selection, assessment in education and risk-based selection by public authorities require close cooperation. RDI and AP assume the coordinating expert role. The cabinet adopted this advice substantially in full in the draft legislative proposal of April 2026. An English version is also available.PublishedOpinionDutch Authority for Digital Infrastructure (RDI) and Dutch Data Protection Authority (AP)7 Nov 2024
- Public consultation on the Dutch AI Regulation Implementation Act (Uitvoeringswet AI-verordening)The Dutch legislative proposal that makes the AI Act implementable and enforceable nationally. The consultation ran from 20 April to 1 June 2026 and is closed. The proposal designates ten market supervisory authorities: the Personal Data Authority, the Digital Infrastructure Inspectorate, the Transport and Infrastructure Inspectorate, the Inspectorate for the Judiciary, the Food and Consumer Product Safety Authority, the Dutch Labour Inspectorate, the Financial Markets Authority, the Dutch Central Bank, the Advocate General at the Supreme Court and the chair of the Administrative Law Division of the Council of State. Additionally, it provides for powers, cooperation between these authorities and the establishment of an AI testing environment. Annexes include the legislative proposal, draft explanatory memorandum, visual representation of the supervisory system, policy compass and impact assessment.ConsultationNational guidanceMinistry of Justice and Security / Government of the Netherlands (through internetconsultatie.nl)20 Apr 2026