Belgium — APD/GBA + EU AI Act + Belgian AI Strategy: AI Compliance Requirements
Belgium's Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit — APD/GBA) has been particularly active in AI enforcement, issuing significant fines for AI profiling and unlawful automated decisions. Belgium hosts multiple EU institutions and AI labs. The Belgian AI Strategy 2021-2025 created a national AI governance framework. Belgium's AI Act implementation is led by the AI Centre within the Belgian Digital Administration (BOSA). All EU AI Act obligations apply.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
June 1, 2022
August 2, 2026
GDPR (APD/GBA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover. APD has issued fines of up to €200,000 in AI-related investigations.
What Your Business Must Do
3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
EU AI Act Compliance (Mandatory)
CriticalBelgium is subject to the EU AI Act. Full risk classification required. High-risk AI systems (recruitment, education, law enforcement, migration, administration of justice) need conformity assessment, technical documentation, and registration. Belgium's BOSA AI Centre coordinates national implementation. NOTE: the EU AI Act high-risk (Annex III) conformity-assessment deadline was deferred EU-wide from 2026-08-02 to 2027-12-02 by the "Digital Omnibus" amendment, Regulation (EU) 2026/1744 (in force 2026-07-27) -- Article 50 transparency obligations still apply from 2026-08-02, but conformity assessment/technical documentation/registration for stand-alone high-risk systems is not due until 2027-12-02 (2028-08-02 for Annex I product-embedded high-risk systems).
Deadline: December 2, 2027
EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)APD/GBA Proactive AI Enforcement
High PriorityBelgium's APD/GBA actively investigates AI profiling, targeted advertising, and automated scoring systems. Notable enforcement actions include investigations of social media AI algorithms, insurance AI scoring, and political ad targeting. Conduct DPIA for all AI profiling, document the legal basis (legitimate interest alone is generally insufficient for AI profiling under APD guidance).
Belgian AI Strategy 2021-2025 Compliance
Medium PriorityBelgium's national AI strategy established trustworthy AI principles with specific public procurement requirements. Organizations contracting with Belgian federal or regional government must demonstrate AI transparency, non-discrimination, and human oversight. Voluntary BENAI certification available for Belgian market credibility.
Who Does This Apply To?
Applies to: any organisation established in Belgium, and any organisation outside Belgium processing the personal data of Belgian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Belgium is fully subject to the EU AI Act, with national implementation coordinated by the BOSA AI Centre: full risk classification is required, and high-risk systems (recruitment, education, law enforcement, migration, administration of justice) need conformity assessment, technical documentation and registration. The Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit — APD/GBA) actively investigates AI profiling, targeted advertising and automated scoring; it requires a DPIA for AI profiling and treats legitimate interest alone as generally insufficient as a basis for AI profiling. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.
Recent Enforcement Actions
Against:
Recent Regulatory Guidance
APD/GBA — AI and Profiling under GDPR — Proactive Enforcement Priorities
APD enforcement priorities include: (1) AI-driven insurance risk scoring without adequate individual explanation mechanisms; (2) employee behavioral monitoring AI without DPIA; (3) social media algorithm profiling of Belgian minors without parental consent. Organizations in these sectors should conduct DPIAs and document Art. 22 human review procedures.
Frequently Asked Questions
Does Belgium — APD/GBA + EU AI Act + Belgian AI Strategy apply to my business?
Belgium's Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit — APD/GBA) has been particularly active in AI enforcement, issuing significant fines for AI profiling and unlawful automated decisions. Belgium… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Belgium — APD/GBA + EU AI Act + Belgian AI Strategy is: GDPR (APD/GBA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover. APD has issued fines of up to €200,000 in AI-related investigations.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Belgium — APD/GBA + EU AI Act + Belgian AI Strategy?
The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.dataprotectionauthority.be/citizen/themes/artificial-intelligenceLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan