Something curious is happening with AI in the Netherlands. Adoption doubled in two years. Objections to it grew faster.

Statistics Netherlands (CBS) asked companies that had seriously considered AI, but ultimately decided against it, why they had held back. Privacy stood at 34.1 percent in 2023. By 2025 it had climbed to 48.8 percent. Fear of legal consequences: 42.7 percent. Cost — the objection most subsidy schemes are designed to remove — came near the bottom at 20.3 percent.

That is a meaningful signal. Companies are not keeping AI outside the door because it is too expensive, or because they cannot see the value. They are doing it because they do not know where their data ends up, or who will be held responsible for it later.

The fear is not irrational

For legal professionals, that caution is entirely justified. Since 2 August 2026 the transparency obligations under Article 50 of the EU AI Act have applied. Anyone deploying a chatbot must make clear at first contact that no human is on the other end. AI-generated images and video must carry machine-readable markings — new content from 2 August, existing content by 2 December 2026 at the latest. In the Netherlands the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) supervises compliance. The penalty ceiling for this category is 15 million euros or 3 percent of worldwide turnover.

For the Dutch bar, a second layer arrived this year. In late 2025 the Netherlands Bar Association (NOvA) published its Recommendations on AI in legal practice, measured against the profession’s five core values: independence, partisanship, expertise, integrity and confidentiality. On 8 January 2026 the Dutch legal profession’s supervisory board (College van Toezicht Advocatuur) announced in its work plan that the use of legal AI tools now forms part of routine supervision — assessed through the local deans, during firm reviews, questionnaires and on-site visits.

In practice that means a firm must be able to show how it uses AI. What policy is in place. How staff have been trained. How output is checked by a human. And what clients are told about it.

A firm that could still get by in 2024 with “we don’t do anything with AI” now faces a different question in 2026: show us how you have arranged it.

Where the fear points in the wrong direction

This is where many firms go wrong. The objections get translated into a decision about AI as a whole — yes or no — when the real question is far narrower: where does the data land, and who is allowed to do what with it?

The NOvA is unambiguous here: do not enter confidential data into free, open tools, because those tools’ business models often run on user data in the first place. That is not a verdict on AI. It is a verdict on one specific way of using it — the way where, at five in the afternoon, an associate pastes a draft writ into a free chat window because nobody has given them an alternative.

Which is exactly what happens when a firm says “no” to AI without arranging anything else. The usage does not disappear; it disappears from view — the pattern we described in our piece on shadow AI. Six in ten Dutch legal professionals now say they have an AI tool somewhere in their workflow. The question is no longer whether it is happening at your firm, but whether you know where.

What to arrange instead

The NOvA recommendations and the AI Act requirements overlap heavily. In short, it comes down to six things:

  1. Know where the data sits. Record where data is stored, who processes it and which subprocessors sit in the chain. No data processing agreement, no confidential input.
  2. Rule out free, open tools for client data. Not as a ban on AI, but as part of a policy that points to a safe alternative.
  3. Put the AI policy in writing. Supervisors will ask for it. A two-page document is infinitely better than no document.
  4. Always verify output by hand. Citations, case law, facts. Favour tools that show their sources, so that verification is actually possible.
  5. Be transparent with clients. Ask for consent before using AI on a matter, and disclose it where it is relevant. Under the AI Act, disclosure of automated interaction is mandatory regardless.
  6. Invest in knowledge, not just licences. The most common objection in the CBS data was not privacy but lack of experience, at 71.6 percent. A tool without training does not solve that.

The gap this creates

The CBS research shows one more thing. Among large companies, AI usage stands at 66.2 percent; in mid-sized firms at 29.8 percent; among micro-enterprises at 13.8 percent. Together, the companies that do use AI account for roughly half of all revenue in the Dutch business sector.

That gap is not driven by budget. It is driven by the capacity to organise the preconditions — precisely what smaller firms have no department for. Large organisations have a privacy officer who reads the data processing agreement. A twelve-person firm does not, and so more often chooses to do nothing.

Until recently, doing nothing was a defensible position. Since August it is less so: the transparency rules apply regardless of company size, and supervision of the Dutch bar was not announced for large firms only.

The good news is that the requirements are now concrete. What is expected of you is written down. That is considerably more workable than the fog this sat in two years ago. Where to begin is a separate question — one we covered in AI in Law Firms: From Hype to a Firm Footing.

Ready to find your match?

Want to know how AI can be deployed safely within the boundaries of legal practice? Read our whitepaper for the legal sector.