In September 2020 Amsterdam and Helsinki launched the world’s first public registers of municipal algorithms. Six years on, Amsterdam’s is being folded into the Dutch national register, while the EU’s registration duty for high-risk systems has slipped to 2 December 2027. A practical guide to what a register entry contains, what it leaves out, and what to do with the extra time.
Open algoritmeregister.amsterdam.nl today and the first thing you see is not a list of the city’s algorithms. It is a notice: the municipality now publishes its systems on the Dutch national register, and the city register will be archived at the end of the year. Everything that was there has already been transferred to the national database, where the City of Amsterdam is the single largest contributor — 50 entries according to a 2024 count by the Dutch specialist outlet iBestuur, 57 according to the national register page as more recently consulted.
That is the end of a six-year experiment, and it is worth understanding what it leaves behind. Those entries are not generic paperwork: they describe machine learning systems running on the street. The best-known case is automated parking enforcement: camera-equipped cars drive the city, a computer vision model reads licence plates from the images and matches them against the permit database, across a stock of more than 150,000 parking spaces. The other documented example is an algorithm that ranks reports of illegal tourist rentals by priority, designed to decide which ones deserve a human inspection. That one was described as a six-month pilot started on 1 July 2020 — wording from that era, which would need rechecking on the national register before being treated as current.
What an entry actually says
On 28 September 2020, at the Next Generation Internet Policy Summit co-organised by the European Commission and the city of Amsterdam, the two administrations presented their registers in beta. They were the first in the world. The white paper setting out the design, Public AI Registers, carries three signatures: City of Amsterdam, City of Helsinki and Saidot, the Finnish company that worked on the platform.
The structure of an entry, then and now, has four blocks — and they are worth remembering because they are exactly the questions a non-technical citizen can ask:
- Training data: what material the model was built on. This is what lets you guess where systematic distortions might sit.
- Description of use: what the system does inside the administrative process, not in the abstract.
- The human operator’s role in relation to the prediction: who looks at the output, with how much room to deviate, at which point in the chain. The most underrated field, and the most revealing.
- Bias and risk assessment: what the administration states it has checked.
Pasi Rautio, project manager at Helsinki City Data, framed the exercise simply: building public trust through the greatest possible openness. It sounded broad at the time. It is now the standard by which the outcome should be judged.
The hole: nobody knows who reads them
Here is something the enthusiastic literature on public registers tends to skip. There are no verifiable figures on how many people have consulted Amsterdam’s register or Helsinki’s, who they were, which entries they opened, how much feedback came back. This is not a detail: a transparency instrument that does not measure its own readership is a tool whose effectiveness nobody knows, including the people running it.
An indirect signal comes from Amsterdam’s metropolitan court of audit, the Rekenkamer, which examined the question: the public registers are not complete, citizens are poorly informed about algorithm use and almost never involved. In September 2023 the city register held 29 algorithms, against an evidently larger number of systems in actual use. On the risk management framework, the same analysis counted 49 risks covered out of 61 identified. At launch in 2020 the numbers were thinner still: five services in Helsinki, three in Amsterdam.
An incomplete register is not a partial version of a complete one. It is a document that implies to the reader a perimeter that does not exist.
That is the line anyone designing a register — a city, a region, an agency, in any EU member state — should write on the whiteboard before starting. Completeness is not a maturity milestone to reach later: it is the condition that makes the document legible at all.
Why the national register changes the geometry
Amsterdam’s move to the Dutch national register (algoritmes.overheid.nl) is not a surrender, it is a change of scale. The national database held 268 algorithms on 1 January 2024 and passed 600 during that same year. Participation, however, is voluntary: no public body is required to appear. Which explains why a city that invested early in transparency ends up as the main contributor, and why the national total should be read as a sum of good intentions rather than a census.
Helsinki’s situation is different: ai.hel.fi is still online and the city’s institutional page appears to have been updated recently, but how many systems it holds today, and how often it is maintained, is not as easily verifiable from the outside.
The AI Act deadline most people think has arrived has not
Now the part where confusion is thickest. Article 71 of the EU AI Act requires the Commission to set up and maintain a public, searchable EU database of the high-risk systems listed in Annex III. Article 49(3) requires deployers that are public authorities to register in the database and select the system before putting it into use. The public-facing section is free, navigable and machine-readable.
Except that obligation is not in force today. The Digital Omnibus on AI — proposed by the Commission on 19 November 2025, provisionally agreed on 7 May 2026, voted by Parliament on 16 June 2026 and adopted by the Council on 29 June 2026 — moved the obligations for stand-alone Annex III high-risk systems from 2 August 2026 to 2 December 2027. Annex I systems slip to 2 August 2028. What does still apply from 2 August 2026 are the Article 50 transparency duties, which are a different thing: telling users they are interacting with an AI system, or that content is artificially generated, not registering in a database.
Nor is it established whether and when the Article 71 database will be technically operational for public deployers. Translated for anyone working inside an administration: the preparation window is wide, and spending it waiting would be the most predictable waste available.
What to do with it
Three things the Dutch and Finnish experience suggests to anyone who will be registering systems over the next two years.
First: the inventory comes before the register. The Rekenkamer did not fault the quality of Amsterdam’s entries, it faulted the fact that not all of them were there. An administration that does not know how many automated systems it runs cannot publish the list: it can only publish the ones someone remembered.
Second: the human-oversight field deserves the most care. “An operator validates the output” can mean someone reads every case, or that someone clicks through a batch of four hundred. Those are two different systems and two different levels of accountability.
Third: measure the reading. It is the gap that makes it hard, six years on, to say whether the two pioneer registers worked. No sophisticated analytics needed: knowing how many entries get opened, which ones, and whether anyone writes in, is what separates a transparency device from a compliance task.
One last detail says a lot about how fragile these archives are. Sources disagree on the exact 2020 launch date: Amsterdam’s own municipal site says 24 September, specialist press and academic literature say the 28th, a regulatory database says the 29th. Four days of drift on a documented public event, six years later, in a project created to make automated decisions traceable. If a register is to be worth anything, the first thing that has to survive is its own chronology.