Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Dutch regulator pilot lets organisations shape AI Act fundamental rights reporting

21 September 2026

Organisations interested in piloting fundamental rights impact assessment (FRIA) reporting under the AI Act must submit their applications by 21 September 2026. This deadline is for participation in a programme designed to test the reporting mechanisms for high risk artificial intelligence systems. Successful applicants will contribute to shaping the practical implementation of future regulatory requirements.

The application window for the pilot FRIA reporting programme closes on 21 September 2026, offering a crucial opportunity for organisations to engage directly with the implementation of the AI Act. This initiative targets entities developing or deploying high risk artificial intelligence systems. Participation requires a commitment to testing the reporting framework for these systems, providing invaluable feedback to regulators.

Organisations should prepare to demonstrate their capacity to conduct comprehensive impact assessments and report on their findings, anticipating the detailed requirements that will eventually become mandatory. The work preceding this deadline involves understanding the scope of high risk AI systems as defined by the AI Act and assessing internal readiness for compliance. Evidence an authority would expect to see includes a clear methodology for impact assessment, resource allocation for reporting, and a commitment to transparency.

This pilot programme is a proactive step for controllers and processors to influence the practical application of the AI Act, ensuring their systems meet future regulatory expectations. It is not a formal compliance obligation yet, but a preparatory exercise for those who will eventually be bound by the full force of the regulation.

AI Act sets 21 September 2026 as the point of effect, and the preparation it requires sits with teams who are measured on other work, which is why this date slips rather than the obligation being misread.

AI Act

Who this binds
Organisations interested in piloting FRIA reporting
What changed
What is fixed is the date: 21 September 2026, when deadline for organisations to sign up for the Autoriteit Persoonsgegevens' pilot programme to gain experience with Fundamental Rights Impact Assessment (FRIA) reporting.
What to check
Submit an application to participate in the pilot FRIA reporting programme.
What this does not mean
This is a date in the diary, not a new obligation published today. Nothing in force changed this morning.

Send this to your team

Organisations interested in piloting fundamental rights impact assessment (FRIA) reporting under the AI Act must submit applications by 21 September 2026 to participate in this programme.

Today's question

A social media platform operating in New York provides algorithmically personalised feeds to all users. Following the New York SAFE Act, what is the platform's primary obligation regarding users under 18?

  1. Cease all data collection from users under 18.
  2. Obtain verifiable parental consent to provide algorithmically personalised feeds to users under 18.
  3. Implement a complete ban on users under 18 accessing the platform.
  4. Provide an opt out option for personalised feeds to all users, regardless of age.

Answer this question on the site

Worth knowing

  1. FTC seeks comment on enforcement policy statement regarding personalised pricing

    Organisations employing personalised pricing models should monitor the FTC's policy development to understand potential future enforcement priorities and adjust their practices accordingly.

  2. OAIC review highlights opportunities to strengthen transparency

    Australian organisations should review the OAIC's findings to identify opportunities for improving their transparency practices, particularly regarding privacy policies and data use disclosures.

  3. New Jersey enacts Kids Code Act with privacy by default and safety by design obligations

    Online service providers with users in New Jersey must begin assessing their services for compliance with privacy by default and safety by design requirements for minors, with an effective date in late 2027.

  4. French tax authority says break in exposed data of 600K, including some private messages

    Organisations handling sensitive personal data, especially in the public sector, should review their incident response plans following the French tax authority's data breach affecting 600,000 individuals.

  5. Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.

    Technology companies should consider strengthening their legal strategies for resisting government data requests, as the EFF advocates for more robust pushback against ICE subpoenas for user information.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.