Blog

AP launches TCA directorate for AI oversight, but still lacks market surveillance powers

The Dutch Data Protection Authority has launched its TCA directorate for AI oversight. What changes, what does not, and what should directors and lawyers record now?

· By

A meeting table with a stack of dossiers and a whiteboard organisational chart on one side, and an empty chair with a blank nameplate holder on the other.
The Dutch Data Protection Authority has launched its TCA directorate for AI oversight but does not yet hold formal market surveillance powers.Image: IamVera.ai — original editorial illustration

On 9 October 2026 the Dutch Data Protection Authority launched the Supervision and Coordination of AI/Algorithms directorate (TCA), which continues coordinating AI oversight and prepares market surveillance. It is not yet designated as market surveillance authority and would obtain those proposed powers only after the national AI Regulation Implementing Act takes effect, so start documenting your AI use, risks and human controls now.

The step shifts AI oversight from preparatory coordination to a firmer organisational framework, but leaves one crucial question open: when the AP will actually be able to enforce as a market surveillance authority. In our analysis this means that, for directors, lawyers and CISOs, oversight pressure is mounting before the formal powers are definitively established.

What has the Dutch Data Protection Authority announced with the TCA directorate?

The Dutch Data Protection Authority announced that it has launched the new Supervision and Coordination of AI/Algorithms directorate (TCA). According to the AP, this directorate continues the coordinating oversight of AI and algorithms that has been carried out since 2023, prepares AI market surveillance, and together with the Dutch Radiocommunications Agency (RDI) shapes the AI sandbox and a joint AI Coordination Centre.

TCA builds on the earlier Algorithm Coordination Directorate (DCA). The AP explains that its coordinating oversight focuses on fundamental values and fundamental rights, and that it also remains the supervisory authority for the processing of personal data by algorithms and AI. The AP's announcement about the next step in AI oversight presents this as a scaling up of capacity, not as a completed oversight structure.

Why does the AP not yet have market surveillance powers over AI?

The AP is the intended market surveillance authority under the European AI Regulation, but it has not yet been formally designated and does not yet have the associated enforcement powers. In the proposed oversight system, the AP would take on a market surveillance role for certain oversight areas. The definitive allocation of powers is therefore proposed but not yet definitively established; under the current proposal, the allocation would depend on adoption of the national AI Regulation Implementing Act and the relevant formal designations and provisions taking effect.

In the proposal for that implementing act, the government proposed a national oversight structure in which several supervisory authorities cooperate and in which the AP and RDI take on a coordinating role. The government's explanation on the oversight of European AI rules moreover describes that, for oversight areas not yet clearly assigned, the AP is proposed as the supervisory authority with a special AI director. The RDI describes the same model, in which the AP and RDI jointly fulfil a coordinating role and regulatory sandboxes are intended to support innovation. In our assessment the Dutch model is therefore multi-layered and still being built, and not a fully operational single-desk oversight.

What does the launch of TCA mean for directors, lawyers and CISOs?

Our analysis: because the AP is organisationally anchoring AI oversight in a permanent directorate, this is expected to provide a clearer point of contact and reinforce the expectation that organisations can account for their AI use; therefore directors should now appoint an owner who records, per AI system, which supervisory or coordinating role is relevant. Because the AP remains the supervisory authority for the processing of personal data by AI, your organisation already faces existing enforcement risk with AI involving personal data, in our assessment; therefore lawyers should record, before deployment, which personal data and fundamental rights are at stake and which legal basis applies. Our analysis: because TCA shapes the AI sandbox together with the RDI, that sandbox may offer a route to test applications within a supervised oversight framework once its set-up and access have been established; therefore teams working on high-risk AI should now assess whether participating in that sandbox could accelerate their validation and documentation. Because the formal market surveillance power has not yet been definitively established, it is tempting to postpone preparation; therefore we advise CISOs to set up incident and escalation logging for AI systems now, so that you are not left behind when the implementing act takes effect.

As a summary of that analysis, this is the course that we assess to be sensible:

  • Appoint a responsible person per AI system and record the intended supervisory or coordinating role.
  • Map which personal data and fundamental rights the system affects and on what legal basis.
  • Assess whether participation in the AP and RDI AI sandbox supports your validation of high-risk applications.
  • Set up incident and escalation logging before the formal powers take effect.

See also our topic hub on AI governance and oversight structures for the broader context and the earlier AP fine for automated decisions without human intervention, which connects with the broader distinction between the AP's existing oversight of the processing of personal data by algorithms and AI and the still-proposed market surveillance under the AI Regulation.

What evidence about AI systems should my organisation record now?

Record evidence with which you can later demonstrate to a supervisory or coordinating body what the system does, who controls it and which risks have been weighed. That is useful regardless of which supervisory authority ultimately becomes competent, because the AP takes on a coordinating role in the intended Dutch model and is proposed as market surveillance authority for certain oversight areas not yet assigned.

We advise a file that, per AI system, contains at least the following:

  1. A description of the system, its purpose and the deployment context.
  2. The personal data processed, the legal basis and the fundamental rights affected.
  3. The risk analyses carried out and the built-in human controls.
  4. The incident and escalation data, with who can intervene and how.

This documentation connects with the broader trend that testable evidence about purpose, data and validation of AI is increasingly becoming the norm, and with the discussion about AI logging and retention periods under the EU AI Act and GDPR. The AP itself emphasises in its explanation of the predecessor DCA that oversight is based on fundamental rights; an evidence-focused approach makes that weighing demonstrable afterwards.

Sources and references

  1. AP zet volgende stap in toezicht op AIAutoriteit Persoonsgegevens · 2026-10-09
  2. Directie Coördinatie Algoritmes (DCA)Autoriteit Persoonsgegevens · 2025-04-03
  3. Toezicht op AI: balans tussen veiligheid en innovatieRijksinspectie Digitale Infrastructuur · 2026-04-20
  4. Kabinet zet stap met toezicht op Europese AI-regelsRijksoverheid · 2026-04-20

Sources: The article relies on the Dutch Data Protection Authority's announcement about the TCA directorate, its earlier explanation of the DCA, and official explanations from the RDI and the Dutch government about the Dutch AI-oversight model.

← All articles in this topic ← All articles