How Dutch & German regulators are approaching enforcement
11 June 2026 · 7 min read

If you run a small studio, agency or SaaS team in the Netherlands or Germany, the EU AI Act can feel like a distant piece of Brussels machinery. In practice, though, the Act is enforced at home, by national authorities in your own country. That means the tone, the priorities and the early signals coming from Dutch and German regulators matter more to you than any headline from the European Commission. This is a grounded look at where those two countries stand today, what their enforcement posture looks like for a small deployer, and what you can reasonably do about it now.
A quick reminder on where you sit. The EU AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024 and applies in phases. Almost every small business is a deployer, meaning you use an AI system under your own authority in a professional context, rather than a provider who builds and places systems on the market. The enforcement posture below is written with deployers in mind.
The Act does not switch on all at once, and that phasing directly shapes what regulators can and will act on right now.
The practical takeaway is that in 2026 we are in an in-between period. The banned uses are already off the table, the literacy duty is already expected, and the machinery of penalties and designated authorities is coming into place. But the heavy high-risk obligations that will define day-to-day compliance for many deployers were moved by the 2026 Digital Omnibus and now land on 2 December 2027, while 2 August 2026 brings the lighter transparency duties. Regulators know this, and their current posture reflects a system that is standing up its people and processes rather than one running at full enforcement speed.
The Netherlands has moved relatively early to give algorithm and AI supervision a recognisable home. The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, has taken a coordinating role for algorithm and AI supervision through its algorithm-coordination directorate. It does not do this alone. It works alongside sector regulators and the RDI (Rijksinspectie Digitale Infrastructuur), so oversight is shared across bodies that already understand their own domains.
What matters for a small deployer is the signalled focus. The AP has published guidance and pointed to two priorities in particular: transparency and prohibited uses. That is a coherent and, frankly, predictable emphasis. Transparency obligations, such as telling people they are interacting with a chatbot or disclosing AI-generated and manipulated content, are relatively easy to check and easy to get wrong. Prohibited uses under Article 5 are already banned and carry the highest penalty exposure. A regulator building its capacity will naturally start where the rules are clearest and the harm is most obvious.
For a Dutch SME, the reading is straightforward. You are unlikely to be the first target of a complex, contested case. You are, however, operating in a country where the supervisor has said out loud what it cares about. If your business uses AI in ways that touch transparency, or anywhere near the prohibited list, those are the areas to get clean first.
Germany presents a different picture, shaped by its federal structure. There is no single federal AI authority yet. The most widely held expectation is that the Bundesnetzagentur (BNetzA), the federal network agency, will take a central market-surveillance and coordination role. Alongside it, the data protection authorities and various sector bodies are expected to be involved. The final division of responsibilities is set by national implementing legislation, so the precise map is not yet fixed.
In the meantime, German supervisors have emphasised something you already have to deal with: existing data-protection duties. This is an important signal. It tells you that in the interim, before the full AI Act enforcement structure is bedded in, regulators are leaning on the rules that are already firmly in force. If your AI use involves personal data, and for most small businesses it does, the near-term scrutiny is at least as likely to come through a data-protection lens as through a brand-new AI Act one.
For a German SME, the uncertainty about who does what is not an excuse to wait. The obligations themselves are set by EU law and by the same phased timeline as everywhere else. Only the enforcing body is still being decided. Building good practice against the substance of the Act is the safe path, regardless of which authority eventually knocks.
Despite the structural differences, the Dutch and German postures rhyme in ways that are useful for a smaller deployer to notice.
Read together, these signals are calmer than the headlines suggest, but they are not an invitation to do nothing. A few honest observations.
First, the areas regulators have named are the areas you can act on today without waiting for 2 August 2026. Transparency, prohibited uses and data protection are all either already in force or already expected. None of them requires you to wait for the high-risk regime to fully arrive.
Second, the fact that authorities are still building capacity is a window, not a reprieve. The obligations are fixed and the timeline is public. Using this period to get organised is far cheaper than scrambling once the full regime and its penalties are being actively applied. As a reminder of the stakes, penalties are capped at up to 35 million euro or 7% of worldwide annual turnover for prohibited practices, and up to 15 million euro or 3% for most other obligations, including high-risk and transparency duties. For SMEs and startups, the fine is the lower of the fixed sum or the percentage, but the direction of travel is clear.
Third, whichever country you are in, the same modest groundwork answers the questions a regulator, or for that matter a client or insurer, is most likely to ask: what AI are you using, do the people using it understand it, and can you show that any of this happened.
What this means for you. You do not need to predict exactly which Dutch or German authority will supervise you, or wait for the full high-risk regime, which the 2026 Digital Omnibus moved to 2 December 2027. The signals from both countries point at the same practical starting points. Make a short list of the AI tools your team uses and note where each one sits against the risk tiers. Fix anything that touches transparency or the prohibited list first. Make sure your people have a basic, role-appropriate understanding of the tools they use, which is the Article 4 literacy duty that already applies. And keep a dated record of what you did, so that "we tried" becomes "we can show it".
If you want a concrete plan that works in both jurisdictions, keep it simple and dated.
This is the model Klaar is built around: a risk-classified tool inventory, role-based training with dated certificates, a clear AI usage policy, and a dated compliance record you can actually produce on request. None of it depends on knowing in advance which authority in the Netherlands or Germany will eventually supervise you. It simply makes you ready.
The honest summary is that Dutch and German regulators are, for now, coordinating, publishing guidance, and leaning on the duties that already apply rather than launching an enforcement blitz. That posture will harden as 2 August 2026 approaches. The small businesses that come through this comfortably will be the ones that treated the quiet period as time to get their house in order, not time to look away.
Klaar walks you through inventory, training, policy and the dated evidence.