Skip to content
Questa e una traduzione di cortesia. La versione inglese e la versione ufficiale e giuridicamente vincolante. Visualizza versione inglese
BEMEDIUM coverage1 enforcement action

Belgium — APD/GBA + EU AI Act + Belgian AI Strategy: AI Compliance Requirements

Belgium's Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit — APD/GBA) has been particularly active in AI enforcement, issuing significant fines for AI profiling and unlawful automated decisions. Belgium hosts multiple EU institutions and AI labs. The Belgian AI Strategy 2021-2025 created a national AI governance framework. Belgium's AI Act implementation is led by the AI Centre within the Belgian Digital Administration (BOSA). All EU AI Act obligations apply.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

June 1, 2022

Enforcement Begins

August 2, 2026

Maximum Penalty

GDPR (APD/GBA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover. APD has issued fines of up to €200,000 in AI-related investigations.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

EU AI Act Compliance (Mandatory)

Critical

Belgium is subject to the EU AI Act. Full risk classification required. High-risk AI systems (recruitment, education, law enforcement, migration, administration of justice) need conformity assessment, technical documentation, and registration. Belgium's BOSA AI Centre coordinates national implementation. NOTE: the EU AI Act high-risk (Annex III) conformity-assessment deadline was deferred EU-wide from 2026-08-02 to 2027-12-02 by the "Digital Omnibus" amendment, Regulation (EU) 2026/1744 (in force 2026-07-27) -- Article 50 transparency obligations still apply from 2026-08-02, but conformity assessment/technical documentation/registration for stand-alone high-risk systems is not due until 2027-12-02 (2028-08-02 for Annex I product-embedded high-risk systems).

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

APD/GBA Proactive AI Enforcement

High Priority

Belgium's APD/GBA actively investigates AI profiling, targeted advertising, and automated scoring systems. Notable enforcement actions include investigations of social media AI algorithms, insurance AI scoring, and political ad targeting. Conduct DPIA for all AI profiling, document the legal basis (legitimate interest alone is generally insufficient for AI profiling under APD guidance).

GDPR Art. 22 (automated decisions); Art. 35 (DPIA); Art. 6(1)(f)/Recital 47 (legitimate interest balancing test)

Belgian AI Strategy 2021-2025 Compliance

Medium Priority

Belgium's national AI strategy established trustworthy AI principles with specific public procurement requirements. Organizations contracting with Belgian federal or regional government must demonstrate AI transparency, non-discrimination, and human oversight. Voluntary BENAI certification available for Belgian market credibility.

Who Does This Apply To?

Applies to: any organisation established in Belgium, and any organisation outside Belgium processing the personal data of Belgian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Belgium is fully subject to the EU AI Act, with national implementation coordinated by the BOSA AI Centre: full risk classification is required, and high-risk systems (recruitment, education, law enforcement, migration, administration of justice) need conformity assessment, technical documentation and registration. The Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit — APD/GBA) actively investigates AI profiling, targeted advertising and automated scoring; it requires a DPIA for AI profiling and treats legitimate interest alone as generally insufficient as a basis for AI profiling. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Enforcement Actions

2022-02-02Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024

APD/GBA — AI and Profiling under GDPR — Proactive Enforcement Priorities

APD enforcement priorities include: (1) AI-driven insurance risk scoring without adequate individual explanation mechanisms; (2) employee behavioral monitoring AI without DPIA; (3) social media algorithm profiling of Belgian minors without parental consent. Organizations in these sectors should conduct DPIAs and document Art. 22 human review procedures.

Frequently Asked Questions

Does Belgium — APD/GBA + EU AI Act + Belgian AI Strategy apply to my business?

Belgium's Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit — APD/GBA) has been particularly active in AI enforcement, issuing significant fines for AI profiling and unlawful automated decisions. Belgium… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Belgium — APD/GBA + EU AI Act + Belgian AI Strategy is: GDPR (APD/GBA): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover. APD has issued fines of up to €200,000 in AI-related investigations.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Belgium — APD/GBA + EU AI Act + Belgian AI Strategy?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.dataprotectionauthority.be/citizen/themes/artificial-intelligence

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan