AI developers should mitigate risks during internal testing as well as after release, the Dutch government says. State Secretary W.J.M. Aerdts set out that position in a parliamentary answer received on October 5 about unauthorized access by AI agents.

The government identifies instructions, test environments and infrastructure alongside model capabilities as risk factors. It calls the reported incidents concerning but says broader conclusions require further analysis.

The answer also identifies a limit to the AI Act’s scope: internal development and testing are exempt where models have not been placed on the market or put into service. It says the European AI Office is studying the cases and is in contact with the intended Dutch supervisory authorities, RDI and AP.

The government does not know whether Dutch organizations were affected. It favors international cooperation through existing structures. The answer introduces no new reporting duty and settles no specific liability case.