Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Organisations planning to deploy high risk artificial intelligence systems in the Netherlands must apply to the

21 September 2026

Organisations planning to deploy high risk artificial intelligence systems in the Netherlands must apply to the Autoriteit Persoonsgegevens for its FRIA pilot by 21 September 2026. This initiative offers early experience with the fundamental rights impact assessment requirements of the EU AI Act. Participation is crucial for entities seeking to understand and prepare for future compliance obligations.

The pilot programme, launched by the Dutch data protection authority, provides a structured opportunity for both public and private sector organisations to engage with the practical application of fundamental rights impact assessments (FRIAs). These assessments are a cornerstone of the EU AI Act, designed to identify and mitigate risks to individuals' rights posed by high risk artificial intelligence systems. Organisations participating in the pilot will gain invaluable insights into the methodology and documentation required for FRIAs, allowing them to refine their internal processes before the Act's full implementation.

This proactive engagement is particularly beneficial for controllers developing or procuring high risk AI, as it allows for iterative learning and adjustment of their governance frameworks. Evidence of participation and the lessons learned will be vital for demonstrating due diligence and a commitment to responsible artificial intelligence deployment. The Autoriteit Persoonsgegevens expects applicants to be actively developing or planning to deploy a high risk artificial intelligence system, ensuring the pilot addresses real world scenarios.

EU AI Act sets 21 September 2026 as the point of effect, and the preparation it requires sits with teams who are measured on other work, which is why this date slips rather than the obligation being misread.

EU AI Act

Who this binds
Public and private organisations in the Netherlands planning to use high risk AI systems
What changed
What is fixed is the date: 21 September 2026, when organisations can apply to participate in a pilot programme to gain experience with Fundamental Rights Impact Assessments (FRIAs) required by the EU AI Act.
What to check
Organisations should review the pilot invitation and apply if they wish to gain early experience with FRIA reporting.
What this does not mean
This is a date in the diary, not a new obligation published today. Nothing in force changed this morning.

Send this to your team

Organisations in the Netherlands planning to use high risk artificial intelligence systems should consider applying for the Autoriteit Persoonsgegevens FRIA pilot by 21 September 2026 to gain early experience with EU AI Act compliance.

Today's question

A controller experiences a data breach involving 25 million records, including IBANs. The breach is due to inadequate security measures. The controller notifies the supervisory authority but delays notifying data subjects for several weeks, citing internal investigations. Under GDPR, which articles are most likely to be violated?

  1. Article 6 (Lawfulness of processing) and Article 7 (Conditions for consent)
  2. Article 32 (Security of processing) and Article 34 (Communication of a personal data breach to the data subject)
  3. Article 15 (Right of access) and Article 17 (Right to erasure)
  4. Article 28 (Processor) and Article 30 (Records of processing activities)

Answer this question on the site

Worth knowing

  1. New York Attorney General halts Trump Administration's attempt to seize commercial drivers' personal information

    New York Attorney General James's successful intervention demonstrates how state legal action can protect commercial drivers' personal information from federal government data seizure attempts.

  2. EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition

    Privacy advocates are challenging the use of live facial recognition by Nottinghamshire Police, highlighting ongoing concerns about surveillance technology and its impact on public liberties.

  3. DAP Health Settles Data Breach Lawsuit for $1,300,000

    Healthcare providers facing data breaches should note the significant financial liability, as demonstrated by DAP Health's $1.3 million settlement for compromised protected health information.

  4. ChatGPT, Grok and Google IA fazem ranking de melhores candidatos, e descumprem norma do TSE

    Developers and deployers of AI systems must understand and comply with electoral regulations, as demonstrated by AI models violating TSE norms by ranking political candidates.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.