Official sources
Guidance and official explanation for the AI Act
The legal text states what is required, the guidance explains how. Below are the official documents from the European Commission, the AI Office, standards bodies and Dutch supervisory authorities, each linked to the articles and annexes they belong to.
Looking for a topic instead of a document?
Regulation
1Guidelines
13- Guidance on generative AI and the GDPRThe first Dutch interpretation of the GDPR for the development and deployment of generative AI models, intended for organisations that build such models or are responsible for their use. The guidance addresses the legal basis for processing in detail and also works out further GDPR requirements for development and deployment. It builds on the earlier opinion from the Dutch Data Protection Authority on generative AI and refers to the obligations that the AI Act imposes on general-purpose AI model providers. The document is dated June 2026 internally and was published on 13 July 2026.PublishedDutch Data Protection Authority (AP)13 Jul 2026
- Repository of AI literacy practicesContinuously updated collection of more than forty examples of AI literacy practices submitted by organisations themselves: formal training, workshops, awareness-raising events, guidelines and peer learning. Filterable by type of organisation (provider or deployer), size, sector, country, format and status. Collected through two surveys of AI Pact participants and other organisations. The Commission explicitly states that copying a practice does not give rise to a presumption of compliance with Article 4; it is learning material, not a standard. Living page, last updated 27 July 2026.PublishedEuropean Commission / AI Office27 Jul 2026
- Guidelines on the scope of obligations for providers of general-purpose AI models under the AI ActNon-binding guidelines explaining when a model constitutes a general-purpose AI model, with an indicative threshold of more than 10^23 floating point operations training compute in combination with the capacity to generate language, image or video. They determine who qualifies as a provider, when a party that fine-tunes becomes a provider itself, when a provider outside the Union must appoint an authorised representative, and under what conditions open source is exempted. Available in all 24 EU languages and linked to the application of the general-purpose AI rules from 2 August 2025.PublishedEuropean Commission18 Jul 2025
- Guidelines on transparency obligations for providers and deployers of certain AI systems under Article 50 of the AI ActFinal guidelines (C(2026) 5054 final), adopted following consultation on the draft version of 8 May 2026. They clarify the scope, definitions and content of obligations for providers and deployers: designing systems so that people know they are communicating with AI, marking AI-generated or manipulated content in machine-readable form, informing people about deepfakes, about AI-generated text on matters of public concern without human editorial oversight, and about emotion recognition and biometric categorisation. Exceptions such as standard processing operations and artistic or satirical context are addressed. Separate paragraphs address the interplay with data protection law and refer to joint guidelines to be drawn up by the Commission and EDPB. Non-binding, but directive for how supervisors interpret Article 50. The obligations apply from 2 August 2026.PublishedEuropean Commission20 Jul 2026
- Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act)For each prohibition, the Commission explains which AI practices are unacceptable and where the boundary lies, with legal explanation and practical examples: harmful manipulation, exploitation of vulnerabilities, social scoring, predictive policing based on profiling, indiscriminate scraping of facial images, emotion recognition at work and in education, biometric categorisation and real-time biometric identification at a distance. A separate chapter addresses the interplay with the GDPR, LED and EUDPR: by virtue of Article 2, paragraph 7, those remain unaffected, so a practice that just falls outside Article 5 can still be unlawful. The guidelines are not binding; only the Court of Justice provides binding interpretation. The formally adopted communication version bears the reference C(2025) 5052 final.PublishedEuropean Commission (DG CONNECT / AI Office)4 Feb 2025
- AIB 2025-1 / MDCG 2025-6 Interplay between the Medical Devices Regulation (MDR) and In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA)Question-and-answer document with 36 questions on the joint application of the AI Regulation and the regulations on medical devices and in vitro diagnostics. The document introduces the term Medical Device Artificial Intelligence and explains that manufacturers may integrate their AI testing, documentation and reporting procedures into existing Medical Devices Regulation and in vitro Diagnostic Medical Devices Regulation procedures. It is not formally a Commission document and not legally binding, but is endorsed by the AI Board and the Medical Device Coordination Group. The document is dated June 2025, without a specific day.PublishedAI Board (AIB) and Medical Device Coordination Group (MDCG), European Commission
- Building further on AI literacySecond guidance note by the Dutch Data Protection Authority on AI literacy, supplementary to 'Getting started with AI literacy'. Goes deeper into the legal obligation and, with practical examples, sets out a multi-year action plan by which organisations can approach AI literacy strategically and sustainably. The Authority states that the law does not prescribe what specific measures are necessary and that the required level of knowledge depends on context and risk. Note: this document predates the Digital Omnibus on AI and describes Article 4 still in its previous formulation; since 27 July 2026 it is an obligation to take measures without a guaranteed individual level.PublishedDutch Data Protection Authority (AP)23 Oct 2025
- EDPB Work Programme 2026-2027 (announcing joint guidelines on the interplay between the AI Act and the GDPR)The European Data Protection Board work programme 2026-2027, adopted on 11 February 2026, announces joint guidelines on the interplay between the AI Act and the GDPR. These guidelines do not yet exist; the Commission confirms in its Article 50 guidelines of 20 July 2026 that they are being prepared together with the European Data Protection Board. They are expected to address transparency, risk assessments, bias detection and accountability, with concrete examples.AnnouncedEDPB (European Data Protection Board)11 Feb 2026
- Generative AI and the EUDPR. Orientations for ensuring data protection compliance when using Generative AI systems (Version 2)Revised version of the EDPS orientations on generative AI and personal data, primarily aimed at EU institutions under Regulation (EU) 2018/1725 but practically usable for any organisation. Covered are, amongst other things, determining roles and responsibilities in the chain, when use of a generative system processes personal data, the role of the data protection officer, when a DPIA is required, purpose limitation, data minimisation, accuracy, bias and automated decision-making. The EDPS provides these orientations explicitly in its role as data protection supervisor and not as market supervisor under the AI Act, and states that they leave the AI Act unaffected.PublishedEDPS (European Data Protection Supervisor)28 Oct 2025
- NEN webinar slides: European AI standards under the AI Act (JTC 21 work programme and timelines)Official NEN presentation with the complete work programme of CEN-CENELEC JTC 21 and the timeline per standard. The slides explicitly link the requested standards to Articles: risk management under Article 9, data and data governance under Article 10, registration under Article 12, transparency under Article 13, human oversight under Article 14, accuracy, robustness and cybersecurity under Article 15, quality management under Article 17 and conformity assessment under Article 43. The deck identifies the work items prEN 18228 risk management, prEN 18229-1 and 18229-2 AI reliability framework, prEN 18282 cybersecurity, prEN 18283 bias, prEN 18284 datasets, prEN 18285 conformity assessment, prEN 18286 quality management and prEN 18281 computer vision, and explicitly cautions that publication by CEN-CENELEC is different from citation in the Official Journal, which can take weeks to months longer. The precise date of this presentation cannot be unambiguously determined from the source and has therefore been left blank.PublishedNEN, Artificial Intelligence and Big Data standards committee
- Draft Commission Guidelines on the classification of high-risk AI systems under the AI ActThree related draft documents: general principles, the Annex I route and the Annex III route. The Annex I route covers AI that is a safety component of or itself a product under EU harmonisation legislation with third-party conformity assessment. The Annex III route goes through the eight use cases with non-exhaustive examples of systems that are and are not high-risk, plus the exceptions in Article 6, paragraph 3. Not yet adopted; the targeted consultation has closed and the final version follows later. Each timeline in the draft must be tested against the Digital Omnibus: Annex III standalone applies from 2 December 2027, Annex I embedded from 2 August 2028.ConsultationEuropean Commission (AI Office)19 May 2026
- Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act)These guidelines set out the seven building blocks of the definition of an artificial intelligence system, such as machine-based nature, autonomy, adaptability, objectives, derivation of output and impact on the environment. The Commission indicates that classical calculation rules, optimisation methods and simple statistical models generally fall outside the definition. This enables an organisation to determine whether a system falls within the scope of the Regulation at all.PublishedEuropean Commission (DG CONNECT / AI Office)6 Feb 2025
- Standardisation of the AI Act (policy page)Policy page on the standardisation process, last updated 3 August 2026. Describes the process, the ten requested areas and the procedure by which harmonised standards are included in the Official Journal after assessment by the Commission. Note: the page still describes prEN 18286 as in public enquiry and is out of date on that point, as the standard has since been published as EN 18286:2026. Use the page for the process, not for the current status of individual standards.PublishedEuropean Commission, DG CONNECT (Shaping Europe's Digital Future)3 Aug 2026
Code of practice
3- AI PactVoluntary initiative of the AI Office that helps organisations to keep ahead of the application of the AI Act. It consists of two pillars: a knowledge network with webinars and exchange of practical experience, and a set of voluntary commitments in which companies commit to concrete steps such as establishing an AI governance strategy, mapping possible high-risk systems and promoting AI literacy amongst staff. More than 230 organisations have signed the non-binding commitments. The initiative began in September 2024. The date 7 August 2026 is the last updated date on the page.PublishedEuropean Commission / AI Office7 Aug 2026
- Code of Practice on Transparency of AI-generated ContentVoluntary code of practice in two sections: section 1 on marking and detectability of AI-generated or manipulated content by providers, section 2 on labelling deepfakes and AI-generated text by deployers. The code describes watermarks, metadata and provenance information and contains the EU icons for visible labels. Signature can be per section; the deadline for initial signatories was 27 July 2026 and as of end of July 2026 approximately 190 organisations were listed. Process: consultation September 2025, first draft 17 December 2025, second draft 3 March 2026, final 10 June 2026. The code helps demonstrate compliance with Article 50 but does not replace statutory obligations.PublishedEuropean Commission / AI Office10 Jun 2026
- The General-Purpose AI Code of PracticeThe General-Purpose AI code of practice was delivered on 10 July 2025 by thirteen independent experts following input from more than one thousand stakeholders. The code consists of three chapters: Transparency and Copyright for all providers of general-purpose AI models, and Safety and Security only for providers of models with systemic risk. Signature is voluntary, but the Commission and the AI Board confirmed the code on 1 August 2025 as an adequate instrument, allowing signatories to demonstrate their obligations with less administrative burden. Those who do not sign must substantiate compliance in another, equally adequate manner.PublishedEuropean Commission / AI Office10 Jul 2025
Q&A
11- AI Literacy - Questions & AnswersOfficial Q&A with approximately forty questions on Article 4, originally published in May 2025 and last updated on 27 July 2026, the day the Digital Omnibus on AI entered into force. The Commission confirms that providers and deployers must take measures to promote the AI literacy of their personnel and of others who work with AI on their behalf, tailored to knowledge, experience, training and use context. The requirement for a 'sufficient' level has been removed: it has become a duty to take measures, without obligation to measure or guarantee knowledge levels, and the provision has not expired. Merely referring to the user manual is generally not sufficient. For deployers of high-risk AI systems, the requirement for training in human oversight remains. The page also describes the strengthened role of the Commission and Member States and mentions supervision and enforcement from 3 August 2026.PublishedEuropean Commission, DG CONNECT27 Jul 2026
- General-Purpose AI Models in the AI Act - Questions & AnswersOfficial Q&A on general-purpose AI models. The page explains what a general-purpose AI model is, when a model is classified as a model with systemic risk, what obligations providers have regarding technical documentation, information to users, copyright policy and a summary of training data, and what applies in the case of open-source release or fine-tuning. The role and powers of the AI Office are also covered. The obligations apply from 2 August 2025, with a transitional period until 2 August 2027 for models already on the market before that date. The date 9 September 2025 is the last updated date on the page.PublishedEuropean Commission, DG CONNECT9 Sept 2025
- Guidelines on obligations for General-Purpose AI providers - Questions & AnswersQ&A on the guidelines for providers of general-purpose AI models. The document makes concrete the indicative computational threshold of 10^23 FLOP as a starting point for the question of whether something is a general-purpose AI model, with the nuance that a model above that threshold might nevertheless fall outside the definition if it lacks genuine generality. It further explains when a party that adapts an existing model itself becomes a provider, with the rule of thumb that more than one third of the original training computational capacity is used. The scope of the open-source exception is also defined. The date 11 November 2025 appears as last updated at the bottom of the page.PublishedEuropean Commission, DG CONNECT11 Nov 2025
- Navigating the AI Act (Questions and Answers)The broad official Q&A on the AI Act as a whole, structured around scope and objectives, high-risk AI, general-purpose AI models, governance and enforcement, and innovation and sustainability. The page covers, among other things, who the regulation applies to, how high-risk systems are identified, what obligations providers and deployers have, how supervision and the penalty structure work, and what role the AI Pact and the Service Desk play. The date 7 August 2026 is the last updated date on the page itself.PublishedEuropean Commission, DG CONNECT7 Aug 2026
- Questions and answers on the Code of Practice for General-Purpose AIQ&A on the code of practice for general-purpose AI models. The Commission emphasises that the code is voluntary and creates no new obligations, but serves as a tool to comply with the existing obligations in the regulation. The code has three chapters: transparency and copyright for all general-purpose AI providers, and safety and security only for providers of the most advanced models with systemic risk. It also clarifies how the transparency rules for general-purpose AI models relate to the transparency obligations of Article 50 for AI systems. The date 20 July 2026 is the last updated date on the page.PublishedEuropean Commission, DG CONNECT20 Jul 2026
- Transparency requirements for AI: what does this mean for you?Public explanation by the Dutch Data Protection Authority of the transparency rules that have applied since 2 August 2026, with a downloadable infographic. Four situations: AI systems such as chatbots must be recognisable, AI-generated content receives a digital marking, people are informed about emotion recognition and biometric categorisation, and deepfakes and unedited AI articles on matters of public concern receive a visible label. The Authority confirms that systems placed on the market before 2 August 2026 have four additional months for the marking obligation, namely until 2 December 2026. Living topic page, updated on 31 July 2026.PublishedDutch Data Protection Authority (AP)31 Jul 2026
- Transparency obligations under Article 50 of the AI Act - Questions and AnswersOfficial questions and answers on the guidelines to Article 50. The page addresses who is provider and who is deployer, when a system must disclose that the user is communicating with AI, what requirements apply to machine-readable marking of synthetic content, and how the discoverability of deepfakes and AI-generated text on matters of public concern must be handled. The exception for human editorial oversight, the way compliance can be demonstrated and enforcement are also covered. The page confirms that a limited transition period applies to systems placed on the market before 2 August 2026, exclusively for the marking and detection obligation of Article 50, paragraph 2, to which they are only required to comply from 2 December 2026. The date 24 July 2026 is the last-updated date.PublishedEuropean Commission, DG CONNECT24 Jul 2026
- EU AI Act Compliance CheckerInteractive questionnaire that helps determine which rules of Regulation (EU) 2024/1689 may apply to an AI system, and what obligations apply for providers, deployers and other operators. The tool is explicitly presented as a beta version on the website and is presented as an ongoing project, with a call for feedback to be sent to CNECT-AIOFFICE@ec.europa.eu. The outcome is therefore indicative and not a formal determination of the system's status.DraftEuropean Commission (AI Act Service Desk)
- AI Act Service DeskOfficial helpdesk where organisations can submit a concrete question about the AI Act and receive an email reply from an expert team working with the AI Office. Submission is possible in any official EU language via a form that requires an EU Login account. You receive an acknowledgement first, then the substantive response and any follow-up by email. The page specifies no guaranteed response timeframe and no definition of which questions fall outside scope.PublishedEuropean Commission (DG CONNECT) and the AI Office
- AI Act Service Desk: ResourcesSearchable overview of all official documents on the AI Act, arranged by type: legislation, guidelines, policy documents, factsheets and webinars. This includes guidelines on transparency obligations, the code of conduct on transparency of AI-generated content with accompanying factsheet on signatories, the serious incident reporting template, and the whistleblowing facility that opened in November 2025. The AI Act Explorer, Compliance Checker and AI literacy repository are also accessible here.PublishedEuropean Commission (AI Act Service Desk)
- Understanding the standardisation of the AI Act (FAQ)Official question-and-answer page from the Commission on how standardisation under the AI Act works. The page explains that a product or system is only presumed to comply with legal requirements if it complies with harmonised standards whose reference has been published in the EU Official Journal. The Commission names ten requested areas, including risk management, data governance, logging, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and conformity assessment, and states that the first harmonised standards will be published by CEN and CENELEC in 2026. Last updated: 10 March 2026.PublishedEuropean Commission, DG CONNECT (Shaping Europe's Digital Future)10 Mar 2026
Template
4- EU icons for labelling AI-generated contentFreely available set of EU icons in SVG and PNG format that creators and deployers use to make AI involvement in content visible, in three variants: AI involvement, fully AI-generated and partially AI-modified. The icons form part of Section 2 of the Code of Practice on the transparency of AI-generated content and became available on 10 June 2026; the page was last updated on 6 August 2026. User research by the Commission shows that the basic icon performs better when displayed together with a text label. Use of the icons is voluntary; the labelling obligation under Article 50 is not.PublishedEuropean Commission / AI Office6 Aug 2026
- Report for Serious Incidents under the AI Act (General-Purpose AI Models with Systemic Risk)Standard form (DOCX and PDF) by which providers of general-purpose AI models with systemic risk report serious incidents to the AI Office and, where necessary, to national competent authorities. It operationalises commitment 9 from the safety chapter of the general-purpose AI Code of Practice and shows what level of detail the AI Office expects on cause, impact and measures taken. Not to be confused with the draft document for Article 73 (high-risk systems): different legal basis, different status.PublishedEuropean Commission / AI Office4 Nov 2025
- Explanatory Notice and Template for the Public Summary of Training Content for general-purpose AI modelsThe model prescribed by the Commission by which providers of general-purpose AI models publicly summarise what data they used for training. Use of this format is mandatory under Article 53, paragraph 1, point d. The summary has three parts: general information about provider and model, a list of data sources (public and private datasets, scraped data, user data, synthetic data) including top-level domain names, and processing aspects including the removal of illegal content. Updates occur every six months or earlier on material changes. Note: the downloadable version was revised after 24 July 2025, so always cite the version date.PublishedEuropean Commission / AI Office24 Jul 2025
- Draft guidance and reporting template on serious AI incidents (Article 73)Draft guidance plus reporting form for serious incidents with high-risk AI systems: when there is a serious incident, who is subject to the reporting obligation, within what timeframes, and how this reporting obligation relates to other EU reporting regimes. The public consultation ran from 26 September to 7 November 2025 and is closed; a final version has not yet been adopted. The entry date of August 2026 mentioned on the page is outdated because the high-risk obligations for Annex III standalone systems have been deferred to 2 December 2027.ConsultationEuropean Commission26 Sept 2025
Standard
8- EN ISO/IEC 42001:2026 Information technology - Artificial intelligence - Management systemThe international standard for an AI management system has now also been adopted as a European standard: NEN-EN-ISO/IEC 42001:2026 is final and has a publication date of 1 March 2026, and replaces NEN-ISO/IEC 42001:2025. The standard sets requirements for establishing, implementing, maintaining and improving an AI management system and is certifiable. Important distinction: this standard was not developed under standardisation request M/593 or M/613 and is therefore not a harmonised standard under the AI Act. It therefore gives no presumption of conformity; that role is for EN 18286 once it is cited in the Official Journal.PublishedISO/IEC JTC 1/SC 42, European adoption through CEN-CENELEC, Dutch adoption by NEN1 Mar 2026
- prEN 18281:2026 Evaluation methods for computer vision systems (draft European standard, public enquiry)Draft standard setting out methods and measurement criteria for evaluating computer vision systems: selecting, applying and interpreting evaluation methods for AI that analyses visual data. NEN opened the Dutch public enquiry on 7 April 2026; it closed on 11 May 2026. In the JTC 21 work programme, the work item is entitled 'Evaluation methods for accurate computer vision systems'. Domain-specific supplement, not yet an adopted standard.DraftCEN-CENELEC JTC 21, national consultation through NEN7 Apr 2026
- EN 18286:2026 Artificial intelligence - Quality management system for EU AI Act regulatory purposesThis is the first European standard specifically written for regulatory purposes under the AI Act. The standard describes requirements and guidelines for establishing, implementing and maintaining a quality management system at organisations that supply AI systems, in particular providers who place high-risk AI systems on the market or put them into use. CEN and CENELEC announced publication on 31 July 2026; NEN published the Dutch adoption NEN-EN 18286:2026 (51 pages) with publication date 1 July 2026. Note: published by CEN-CENELEC is not the same as cited in the EU Official Journal, and on the official sources consulted that citation cannot yet be found.PublishedCEN-CENELEC (JTC 21), Dutch adoption by NEN31 Jul 2026
- EN ISO/IEC 23894:2024 Information technology - Artificial intelligence - Guidance on risk managementGuideline standard for risk management of AI, based on the ISO 31000 approach. The standard helps organisations developing, producing, supplying or using AI to identify AI-specific risk sources and embed risk management in their existing processes. The European adoption NEN-EN-ISO/IEC 23894:2024 was published on 1 February 2024 and superseded NEN-ISO/IEC 23894:2023. It is a guideline, not a prescriptive standard, and is not a harmonised standard under the AI Act; that role is foreseen for prEN 18228.PublishedISO/IEC JTC 1/SC 42, European adoption through CEN-CENELEC, Dutch adoption by NEN1 Feb 2024
- ISO/IEC 42005:2025 Information technology - Artificial intelligence (AI) - AI system impact assessmentGuideline standard (39 pages) for carrying out impact assessments of AI systems on individuals and society: when and at which lifecycle phase, how to document, and how to link to AI risk management and the AI management system. Direct ISO adoption by NEN; not a European standard and does not fulfil the fundamental rights assessment of Article 27, which obligation only comes into effect from 2 December 2027 and has its own legal scope. At most an aid, not a conformity route.PublishedISO/IEC JTC 1/SC 42, Dutch adoption by NEN1 Jun 2025
- prEN 18228 Artificial intelligence - Risk management (draft European standard, public enquiry)Draft standard for risk management of AI systems. The standard describes terminology, principles and a process for identifying, assessing and treating risks to health, safety and fundamental rights. NEN opened the Dutch consultation period on 18 May 2026, closing on 30 June 2026; the CEN-CENELEC newsletter of 27 May 2026 confirms that the European enquiry ran until end July 2026 and that the standard supports Article 9. This remains emphatically a draft and therefore provides no presumption of conformity.DraftCEN-CENELEC JTC 21, national consultation through NEN18 May 2026
- prEN 18282 Cybersecurity specifications for AI systems (draft European standard, public enquiry)Draft standard with organisational and technical measures to protect AI systems against cyber threats. The standard explicitly addresses AI-specific attack forms such as data poisoning, attacks on the model itself and malicious input. NEN published the call for comment on 19 May 2026, closing on 30 June 2026. The standard is being developed in working group 5 of JTC 21 and has not yet been adopted.DraftCEN-CENELEC JTC 21, national consultation through NEN19 May 2026
- prEN 18283 Managing bias in AI systems (draft European standard)Draft standard that establishes concepts, measures and requirements for assessing and mitigating bias in AI systems, formally requested by the Commission in support of requirements on data and data governance. The source used here is a CEN-CENELEC newsletter item of 27 May 2026 on input from the European Trade Union Confederation, not a standard document; that date therefore indicates nothing about the phase of the standard itself. The work item is independently confirmed in the JTC 21 work programme. Still under development.DraftCEN-CENELEC JTC 2127 May 2026
National guidance
9- About the Dutch Algorithm RegisterExplanation of the Dutch Algorithm Register, in which public sector organisations publish information about their algorithms. Publication is not currently a legal requirement, but that requirement has been announced. The register is linked to the Algorithm Framework of the Ministry of Interior and Kingdom Relations and to the coordinating supervisory role of the Data Protection Authority. The Algorithm Framework additionally sets as requirement bzk-01 that administrative bodies publish impactful algorithms and high-risk AI systems in this register, unless there are exemption grounds.PublishedMinistry of the Interior and Kingdom Relations (Algorithm Register, Overheid.nl)
- Report AI & Algorithms Netherlands (RAN) - March 2026Sixth edition of the half-yearly report in which the AP analyses the risks and effects of AI and algorithms in the Netherlands via the AI Impact Barometer. Four of the nine indicators are now red, compared with two in the previous edition. The three main points are that AI in recruitment and selection is growing rapidly with significant risks, that transparency and explainability are falling short, and that preparation for the AI Regulation is lagging. The AP also signals that organisations are attempting to circumvent the rules or failing to comply with them.PublishedDutch Data Protection Authority (AP)5 Mar 2026
- AI Regulation timeline (Algoritmekader)Dutch timeline from BZK showing which requirements apply on each effective date, linked to numbered requirements in the Algorithm Framework. Living document, last updated 3 August 2026, incorporating the postponement: new standalone high-risk systems from 2 December 2027, high-risk in products from 2 August 2028, with an exception until 2030 for systems already in use in government organisations on 2 December 2027. Warning: the timeline is incomplete, as 2 August 2026 is missing as a milestone for the transparency obligations of Article 50. Do not use as a complete timeline source.PublishedMinistry of the Interior and Kingdom Relations (Algorithm Framework)17 Jul 2025
- Supervision of AI takes shape: key role for the AP and the RDIResponse by the AP to the draft bill. The AP makes explicit which parts it will itself enforce: prohibited AI practices, transparency obligations such as the detectability of chatbots and deepfakes, and a large part of high-risk applications in work, education and government. The AP and RDI jointly provide coordination, knowledge-building and harmonisation, and will establish an AI regulatory sandbox from 2026 onwards. The AP stresses that parts of the Regulation already apply while the implementing legislation is not yet in force.PublishedDutch Data Protection Authority (AP), Algorithm Coordination Directorate20 Apr 2026
- AI transparency requirements apply from 2 August: AP advises signing the code of practiceThe AP sets out the four transparency obligations with precise reference to Article 50, paragraphs 1 to 4, and advises providers and deployers of generative AI to sign the European code of practice on the transparency of AI-generated content. This code of practice was published by the European Commission on 10 June 2026 and contains freely usable EU icons with the labels AI, AI generated and AI modified. Those who signed by 22 July 2026 at 18:00 appeared on the list of first signatories. The DCA announces it will publish further guidance in the coming months.PublishedDutch Data Protection Authority (AP), Algorithm Coordination Directorate9 Jul 2026
- Work agenda for coordinating AI and algorithm supervision 2026The work agenda in which the AP as coordinating algorithm supervisory authority sets out its activities for 2026, divided across five pillars: mapping risks, systemic supervision, cooperation, shared knowledge base and preparation for the AI Regulation. In substance, the AP focuses in 2026 on transparency and explainability, clear frameworks and standards, bias and fairness testing against discrimination, and AI literacy. On the same date, the AP published its 2025 review.PublishedDutch Data Protection Authority (AP), Algorithm Coordination Directorate26 Mar 2026
- AI-verordening (Rijksinspectie Digitale Infrastructuur)Fixed Digital Infrastructure Inspectorate page on its role under the AI Act and on the structure of Dutch supervision. The principle is that supervision is placed with existing sectoral supervisors as much as possible rather than with a new authority, with the Digital Infrastructure Inspectorate and Personal Data Authority together providing a coordinating expert role. Supervision of AI in CE-marked products such as machinery, lifts and toys remains with the existing product authority. The page refers to the final opinion of 7 November 2024 and the two interim opinions. Not substantively refreshed since 30 October 2025: no current position after the April 2026 consultation and nothing on the Digital Omnibus.PublishedDutch Authority for Digital Infrastructure (RDI)
- Public consultation on the Dutch AI Regulation Implementation Act (Uitvoeringswet AI-verordening)The Dutch legislative proposal that makes the AI Act implementable and enforceable nationally. The consultation ran from 20 April to 1 June 2026 and is closed. The proposal designates ten market supervisory authorities: the Personal Data Authority, the Digital Infrastructure Inspectorate, the Transport and Infrastructure Inspectorate, the Inspectorate for the Judiciary, the Food and Consumer Product Safety Authority, the Dutch Labour Inspectorate, the Financial Markets Authority, the Dutch Central Bank, the Advocate General at the Supreme Court and the chair of the Administrative Law Division of the Council of State. Additionally, it provides for powers, cooperation between these authorities and the establishment of an AI testing environment. Annexes include the legislative proposal, draft explanatory memorandum, visual representation of the supervisory system, policy compass and impact assessment.ConsultationMinistry of Justice and Security / Government of the Netherlands (through internetconsultatie.nl)20 Apr 2026
- Cabinet takes step towards supervision of European AI rulesOfficial government announcement at the start of the public consultation on the Dutch AI Regulation Implementation Act. The government chooses a hybrid model in which existing sectoral supervisors exercise supervision of AI within their own domain. Where no clear supervisor yet exists, the Personal Data Authority is designated with a separate AI directorate. The Personal Data Authority and Digital Infrastructure Inspectorate together take the coordinating role in the system.PublishedGovernment of the Netherlands (State Secretary for Digital Economy and Sovereignty)20 Apr 2026
Opinion
9- Commission Opinion on the assessment of the General-Purpose AI Code of PracticeOn 1 August 2025, the Commission and the AI Board formally confirmed that the general-purpose AI code of practice is an adequate voluntary instrument to demonstrate compliance with the AI Regulation. This decision is the legal link that converts the voluntary code into a usable means of proof towards the AI Office. Without this adequacy confirmation, signature would not carry the same supervisory weight.PublishedEuropean Commission1 Aug 2025
- EDPB-EDPS Joint Opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)Joint opinion (adopted 20 January 2026, published 21 January 2026) on the Commission proposal that later became Regulation (EU) 2026/1744. The supervisors support simplification but state that this must not come at the expense of fundamental rights and effective supervision. They address, among other things, the postponement of the high-risk rules, which stems from the lack of harmonised standards and delay in designating national competent authorities and conformity assessment bodies, and warn of a protection gap. It is an opinion on the legislative process, not an explanation of existing law.PublishedEDPB and EDPS jointly21 Jan 2026
- Final advice on the design of AI supervision in the NetherlandsJoint final advice from RDI and AP (34 pages) on the design of Dutch supervision of the AI Act. Core: AI supervision aligns as closely as possible with regular sectoral supervision, products with CE marking remain with their existing supervisor, and cross-sectoral applications such as recruitment and selection, assessment in education and risk-based selection by public authorities require close cooperation. RDI and AP assume the coordinating expert role. The cabinet adopted this advice substantially in full in the draft legislative proposal of April 2026. An English version is also available.PublishedDutch Authority for Digital Infrastructure (RDI) and Dutch Data Protection Authority (AP)7 Nov 2024
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI modelsAt the request of the Irish supervisor, the EDPB answers four questions on data protection law and AI models. A model trained on personal data is not automatically anonymous: supervisors test case-by-case whether direct or probabilistic extraction and obtaining personal data via prompts are negligible. The Opinion elaborates the three-step test for legitimate interest for the development and deployment phases, including reasonable expectations in web scraping and mitigating measures, and describes three scenarios in which unlawful processing during development carries through into subsequent use. Adopted 17 December 2024, published 18 December 2024.PublishedEDPB (European Data Protection Board)17 Dec 2024
- Response of the President of the Administrative Jurisdiction Division to the draft AI Regulation Implementation ActLetter of 8 July 2026 from the President of the Administrative Jurisdiction Division to the Ministry of Justice and Security, with response and implementing assessment to the draft bill. The Division endorses that market supervision of courts by courts takes place, but advises that the sandbox task and the agreements on uniform interpretation of terms should not apply to its President because this conflicts with judicial independence. It advises expanding its own supervision to AI systems that fall only under the transparency obligations, and signals a question of competence when it is unclear whether a system is prohibited or high-risk. The implementing assessment estimates approximately 1 full-time equivalent additional.PublishedCouncil of State, Administrative Jurisdiction Division8 Jul 2026
- EDPB-EDPS Joint Opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus)This second joint opinion concerns the broader Digital Omnibus (COM(2025) 837) and thus the GDPR dimension of the same simplification exercise. It addresses, among other things, proposed changes regarding AI development, automated decision-making, the division of roles between controller and processor, legal bases for processing and coordination between digital regulatory frameworks. The supervisors emphasise that simplification must not lead to weakening the protection of data subjects.PublishedEDPB and EDPS jointly11 Feb 2026
- Interplay between the AI Act and the EU digital legislative frameworkStudy for the European Parliament that analyses how the AI Act relates to other pillars of the EU digital framework, particularly the GDPR, the Data Act and the Cyber Resilience Act, and also the Digital Services Act, the Digital Markets Act and NIS 2. The study maps overlaps and gaps between these instruments and concludes that the layered obligations create substantial regulatory burden. It contains recommendations for amendments. It is a study commissioned by a parliamentary committee and not a binding interpretation by the legislature or the Commission. There is also a short summary version (At a Glance, ECTI_ATA(2025)778577).PublishedEuropean Parliament (Policy Department, at the request of the ITRE Committee)30 Oct 2025
- Statement 3/2024 on data protection authorities' role in the Artificial Intelligence Act frameworkThe EDPB states that the AI Act and EU data protection law complement each other and must be interpreted in a coordinated manner, referring explicitly to Article 2(7) and recitals 9 and 10. It advises Member States to designate national data protection authorities as market surveillance authorities, mandatory for high-risk systems in Annex III points 1, 6, 7 and 8 and preferably also more broadly. The EDPB also points to the close link between the data protection impact assessment (DPIA) and the fundamental rights impact assessment, and to the absence of structured coordination between the AI Office and data protection authorities on general-purpose AI models.PublishedEDPB (European Data Protection Board)16 Jul 2024
- Proposal for the design of a Dutch AI regulatory sandboxProposal from RDI and AP, under coordination of the Ministry of Economic Affairs, for the design of a Dutch AI regulatory sandbox for the regulatory framework. It advocates for a single multisectoral sandbox in which all relevant authorities participate, built from a core team, an expert pool and concrete sandbox trajectories, with a process of six phases from pre-registration to publication of results. The document points to the deadline of 2 August 2026 by which the sandbox must be operational. It is a proposal, not established policy.PublishedDutch Authority for Digital Infrastructure (RDI) and Dutch Data Protection Authority (AP)25 Mar 2025
Implementing act
1Source overview updated on 8 Aug 2026. Missing an official document? Let us know via the contact page.