Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Dutch Privacy Regulator Establishes New AI Oversight Directorate Ahead of Enforcement Role

Dutch Privacy Regulator Establishes New AI Oversight Directorate Ahead of Enforcement Role

By
Key Takeaways
  • New AI Oversight Directorate Established: The Dutch Data Protection Authority (AP) has created a dedicated directorate to coordinate algorithmic oversight and prepare for future AI Act enforcement responsibilities.
  • Enforcement Powers Still Pending: The AP has not yet been formally designated as an AI market surveillance authority and must await the necessary Dutch implementing legislation.
  • Two Departments to Lead Oversight: One department will examine algorithmic risks, discrimination, and fundamental rights, while another develops the technical expertise needed to investigate and test AI systems.
  • Regulatory Sandbox in Development: The AP and the National Inspectorate for Digital Infrastructure (RDI) are working together to establish an AI regulatory sandbox and a joint AI Coordination Centre.
  • Growing Concern Over Autonomous AI: The authority cited incidents involving AI agents gaining unauthorized access to online environments as evidence of the need for early and effective supervision.
Deep Dive

The Dutch Data Protection Authority (AP) has established a new directorate to oversee its work on artificial intelligence and prepare for enforcement responsibilities under the European Union's AI Act, even as the legislation needed to grant it those powers remains unfinished.

Announced October 9, the Directorate for Supervision and Coordination AI/Algorithms (TCA) brings together the authority's existing work on algorithmic oversight with preparations for AI market surveillance. It will also work with the Netherlands' National Inspectorate for Digital Infrastructure (RDI) to establish a regulatory sandbox and a joint AI Coordination Centre.

The Dutch government intends to give the AP and RDI central roles in supervising compliance with the AI Act. The AP, however, has not yet been formally designated as an AI market surveillance authority. Its powers in that area will take effect only after the relevant Dutch implementing legislation enters into force.

The authority has continued preparing in the meantime, drawing on its experience enforcing the General Data Protection Regulation (GDPR) and coordinating oversight of AI and algorithms since 2023. Katja Mur, a member of the AP's board, said the pace of AI development made those preparations necessary before the regulatory framework was fully in place.

"The 'traffic rules' for AI are becoming increasingly concrete, and traffic is getting busier and faster every day," Mur said. "We therefore cannot wait until the last traffic sign has been placed."

Mur said the authority had spent the past three years developing its approach to AI oversight and would continue building the expertise needed to supervise increasingly sophisticated systems. The new directorate will have two departments with separate but closely related responsibilities.

The AI/Algorithms Risk Analysis & Coordination department (ARC) will examine the effects of AI and algorithmic systems on individuals, fundamental rights, and society. Its work will include identifying emerging risks, conducting research, and coordinating with other regulators and technical experts.

The department will pay particular attention to algorithmic systems with significant consequences for individuals, including those used to assess or select people according to risk. It will also examine algorithm registers and auditing frameworks, with an emphasis on testing risk selection instruments for discrimination and accuracy.

The AI Market Surveillance department (MTA) will prepare for the AP's anticipated enforcement responsibilities under the AI Act. Its work will include developing the technical expertise needed to investigate and test AI systems, providing information to organizations, and supporting responsible innovation. The department will also participate in cooperation between national regulators and the European AI Office, including work involving the testing and evaluation of advanced AI models and systems.

The AP expects findings from the two departments to inform one another. Research into the societal consequences of AI will help identify supervisory priorities, while technical investigations will contribute to the authority's understanding of how AI systems operate and what risks they present. The announcement comes amid growing concern at the authority about AI systems capable of making decisions about individuals or performing tasks with increasing autonomy.

The AP specifically cited recent incidents involving AI agents gaining unauthorized access to private and public online environments. Although it did not identify the incidents, the authority said they demonstrated the importance of establishing effective supervision at an early stage. It also warned that manipulative or misleading AI applications could have particularly serious consequences for children and other vulnerable groups.

The authority has experience addressing some of these concerns through its existing privacy responsibilities. Under the GDPR, it already supervises the processing of personal information, including its use in algorithmic decision-making and AI applications. Its anticipated responsibilities under the AI Act will require additional technical knowledge, particularly in examining system safety and assessing whether AI applications meet the regulation's requirements.

Regulatory Sandbox to Support Compliance

Alongside its preparations for market surveillance, the AP is working with the RDI to establish an AI regulatory sandbox. The planned facility will allow organizations to work with supervisors in a controlled environment while developing innovative AI systems and bringing them into compliance with the AI Act.

The AP said its approach to supervision would include providing organizations with clarity about their obligations and supporting responsible innovation, rather than concentrating exclusively on enforcement after violations occur.

The two authorities are also developing a joint AI Coordination Centre, although the AP did not provide a launch date or detailed operating arrangements for either initiative.

The preparations are taking place while provisions of the European AI Act are already applicable. Certain AI practices are prohibited, and the regulation contains transparency requirements concerning specified AI applications and AI-generated content.

The AP's anticipated market surveillance responsibilities remain subject to the Dutch legislative process. Until the implementing legislation takes effect and the authority receives its formal designation, it will continue its existing GDPR supervision and coordination of algorithmic oversight.

The establishment of TCA gives those activities a dedicated organizational structure while the authority prepares for its proposed additional responsibilities. The AP has not indicated when it expects to receive its formal AI market surveillance powers.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong