Decoding the world of cybersecurity

Dutch bill widens intelligence cyber powers

The Netherlands has opened consultation on legislation designed to let its intelligence services act faster against cyber and national-security threats while reshaping oversight of bulk data and AI use.

Dutch bill widens intelligence cyber powers
Summary
  • Proposed legislation would allow the AIVD and MIVD to deploy powers more quickly against clearly identified national-security threats.
  • The framework would expand intelligence cooperation with businesses and organisations and strengthen information exchange with the armed forces.
  • New safeguards cover bulk data, AI, and algorithms, alongside an independent oversight body able to stop unlawful investigations.

The Dutch General Intelligence and Security Service has opened consultation on legislation intended to give the Netherlands’ intelligence agencies greater freedom to act quickly against cyber, espionage, and other national-security threats.

The proposed Wet bescherming nationale veiligheid door de inlichtingen- en veiligheidsdiensten, or Wbnv, would apply to both the AIVD and the Military Intelligence and Security Service, the MIVD. The government describes it as a threat-led framework intended to remove delays when agencies are dealing with clearly identified adversaries.

Under the current system, the services can be required to obtain prior review for individual hacking operations. The proposed law would allow powers to be deployed more quickly where the opponent is clear, with the AIVD citing foreign intelligence services, hostile hackers, and terrorist organisations as examples.

The proposal comes as intelligence work becomes increasingly dependent on infrastructure and information that can change faster than conventional authorisation processes. Cyber operations can move between accounts, systems, providers, and jurisdictions rapidly, increasing pressure on agencies to make decisions before an opportunity to collect intelligence disappears.

Greater operational discretion also increases the importance of oversight. The bill would create a new independent College van Toetsing en Toezicht, or CTT, to examine whether intelligence powers are being used lawfully. The AIVD says the body would be able to stop investigations where it identifies unlawful activity, with a court resolving disagreements over binding decisions.

The proposal also addresses technologies that have become more important to modern intelligence collection and analysis. New safeguards would apply to bulk data, while the legislation would set rules governing the agencies’ use of artificial intelligence and algorithms.

That is a consequential part of the framework because automation can change both the scale at which data is processed and the speed with which intelligence conclusions are generated. Legal controls designed around individual searches or human-led analysis can become harder to apply when large datasets are combined and interrogated through automated systems.

The legislation would also broaden cooperation between the intelligence services and organisations outside government. The AIVD identifies banks, universities, and online platforms as examples of organisations that may hold information relevant to emerging threats. Information exchange between the MIVD and the armed forces would also be strengthened.

Those relationships put commercial organisations closer to national-security processes while leaving them responsible for their own legal and governance obligations. The basis on which information is requested or exchanged, the proportionality of those arrangements, and the safeguards surrounding data use will therefore become important features of the final law.

The government’s case for reform is built around a threat environment that includes Russian espionage, Chinese cyber operations seeking sensitive technology, sabotage risks, and terrorist recruitment. These are government threat assessments rather than findings about any particular operation being investigated under the proposed legislation.

The bill also reflects a broader European policy problem: intelligence services are expected to respond rapidly to hostile activity conducted through commercial digital infrastructure while remaining subject to legal safeguards designed to prevent excessive or arbitrary surveillance.

The effectiveness of the proposed CTT will consequently depend on more than its formal powers. Oversight will need to keep pace with operational activity, understand increasingly technical collection methods, and have enough visibility to challenge the way bulk datasets and AI systems are used.

The Wbnv has not yet become law. The consultation opened on 28 August and runs until 11 October, allowing citizens, businesses, and organisations to comment before the legislation advances further.

The final balance will depend on how the law defines identifiable opponents, when prior review can be replaced by faster authorisation, how information from private organisations can be used, and what constraints ultimately govern bulk data and AI-assisted intelligence work.

×