policy · Effective Jan 1, 2025
FI regulates AI through Hallituksen esitys EU:n tekoälyasetusta täydentäväksi lainsäädännöksi (HE 46/2025).
Hallituksen esitys EU:n tekoälyasetusta täydentäväksi lainsäädännöksi (HE 46/2025) · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Finland’s journey into artificial intelligence regulation is deeply rooted in its national identity as a high-tech, digitally advanced society. The Finnish government recognized early on that AI would be a transformative force across all sectors of the economy and society. In 2017, Finland was among the first countries in the world to publish a dedicated National AI Strategy, titled 'Finland’s Age of Artificial Intelligence.' This strategy was not merely a technical roadmap but a holistic vision that integrated economic policy, educational reform, and ethical considerations. It emphasized the importance of 'trustworthy AI' as a competitive advantage for Finnish companies in the global market. The strategy was further refined through subsequent reports, including the 2019 'Leading the Way into the Age of Artificial Intelligence' and the 2020 'AI 4.0' program, which focused on the digitalization of the manufacturing industry. These strategic initiatives laid the groundwork for a regulatory environment that prioritizes human-centricity, transparency, and the 'twin transition'—the idea that digital transformation must go hand-in-hand with the green transition to achieve climate goals. Today, Finland's regulatory landscape is transitioning from these strategy-led 'soft law' approaches to a formal, binding framework centered on the European Union’s Artificial Intelligence Act. This transition is managed by the Ministry of Economic Affairs and Employment, which coordinates the national implementation to ensure that Finland remains a frontrunner in the ethical and efficient use of AI. The maturity level of Finland's AI ecosystem is high, supported by significant public investment in research through the Finnish Center for Artificial Intelligence (FCAI) and industrial programs like AI 4.0. The government views AI not merely as a technical tool but as a general-purpose technology that necessitates broad societal preparedness, including labor market reforms and lifelong learning initiatives. Currently, the national regulatory focus is on the operationalization of the EU AI Act through the Government Proposal HE 46/2025, which establishes the institutional machinery required for market surveillance, enforcement, and the protection of fundamental rights in the age of automation.
Regulatory approach
Finland employs a hybrid regulatory approach that combines horizontal EU-level mandates with sectoral national implementation. The primary binding instrument is the EU AI Act, which provides a risk-based horizontal framework for all AI systems placed on the market or used within the Union. Nationally, Finland has opted for a decentralized market surveillance model rather than creating a single, monolithic AI regulator. This approach leverages the existing expertise of sectoral authorities—such as the Data Protection Ombudsman for privacy-sensitive AI and the Financial Supervisory Authority for banking applications—ensuring that AI oversight is integrated into established regulatory workflows. While the core of the framework is now binding law, Finland continues to utilize 'soft law' and strategic guidance to steer innovation. Programs like Hyteairo (health sector) and AuroraAI (public services) have produced ethical guidelines, assessment frameworks like Digi-HTA, and technical standards that influence public procurement and organizational behavior without imposing statutory penalties. This dual-track approach allows the Finnish government to maintain a flexible environment for innovation in low-risk sectors while ensuring strict, prescriptive compliance for high-risk AI systems that impact safety, health, or fundamental rights. Finland’s regulatory approach to AI is characterized by a preference for decentralized oversight and the integration of AI governance into existing institutional structures. Rather than establishing a new, centralized 'AI Authority,' the Finnish government has opted to distribute market surveillance responsibilities among several existing sectoral regulators. This model is based on the principle that the risks associated with AI are best understood and managed by the authorities already familiar with the specific domains where AI is applied. For instance, the Financial Supervisory Authority is best equipped to handle AI in banking, while the Data Protection Ombudsman is best suited for AI involving personal data. To ensure consistency and coordination across this decentralized landscape, the Finnish Transport and Communications Agency (Traficom) has been designated as the national Central Contact Point. Traficom’s role is to facilitate information exchange between authorities, provide technical expertise, and represent Finland in the European AI Board. The Finnish governance framework for AI is coordinated by the Finnish Transport and Communications Agency (Traficom), which serves as the national Central Contact Point under the EU AI Act implementation. Traficom’s mandate includes coordinating market surveillance activities among various sectoral authorities, providing expertise to other regulators, and acting as the primary interface with the European AI Board. This role ensures that despite the decentralized nature of Finnish supervision, there is a unified national voice and a single point of entry for international cooperation and citizen inquiries. Supervision of specific AI use cases is distributed to existing authorities based on their domain expertise. The Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) is designated to supervise AI systems involving the processing of sensitive personal data or those categorized under certain high-risk Annex III domains. Other key players include the Financial Supervisory Authority (Finanssivalvonta) for AI in financial services, the Energy Authority (Energiavirasto) for critical infrastructure, and the Finnish Institute for Health and Welfare (THL) for health-related AI. This model ensures that regulators who understand the specific risks of a sector are the ones evaluating the AI systems deployed within it. The governance of AI in Finland is a collaborative effort involving multiple state agencies, each with a specific mandate. The Finnish Transport and Communications Agency (Traficom) stands at the center of this framework as the designated Central Contact Point. Traficom is responsible for the overall coordination of market surveillance, ensuring that different authorities do not duplicate efforts and that there is a unified national approach to AI oversight. The Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) plays a vital role, particularly concerning AI systems that process personal data or impact fundamental rights. It is designated as a market surveillance authority for several high-risk AI categories listed in the EU AI Act. The Financial Supervisory Authority (Finanssivalvonta) oversees the use of AI in the financial and insurance sectors, focusing on algorithmic trading, credit scoring, and risk management. Other important bodies include the Finnish Institute for Health and Welfare (THL) and the Finnish Medicines Agency (Fimea), which oversee AI in the healthcare and medical device sectors. The Ministry of Economic Affairs and Employment (TEM) provides the strategic and political leadership, drafting the national legislation and representing Finland in EU-level policy discussions.
Enforcement & penalties
Enforcement of AI regulations in Finland follows the tiered penalty structure established by the EU AI Act. For the most severe violations—such as the use of prohibited AI practices or non-compliance with data governance requirements for high-risk systems—administrative fines can reach up to €35,000,000 or 7% of a company's total worldwide annual turnover. Less severe non-compliance, such as failing to meet transparency obligations or technical documentation requirements, can result in fines of up to €15,000,000 or 3% of turnover. For SMEs and startups, the fines are capped at the lower of the two amounts to prevent stifling innovation. To manage these penalties, Government Proposal HE 46/2025 proposes the creation of a multi-member National Sanctions Board (seuraamusmaksulautakunta). This board is responsible for determining the final amount of administrative fines above certain thresholds, ensuring a consistent and fair application of the law. Decisions made by the Sanctions Board or individual market surveillance authorities are subject to appeal through the Finnish administrative court system. This judicial oversight ensures that enforcement actions remain proportionate and comply with the principles of Finnish administrative law. Enforcement of AI regulations in Finland is designed to be both effective and proportionate, following the penalty framework established by the EU AI Act. The most significant innovation in the Finnish enforcement model is the proposed creation of a National Sanctions Board (seuraamusmaksulautakunta) under Government Proposal HE 46/2025. This board will be a multi-member body responsible for imposing administrative fines for violations of the AI Act. The fines are categorized into three tiers: the highest tier, for using prohibited AI practices or violating data governance requirements for high-risk systems, can reach up to €35 million or 7% of global annual turnover. The second tier, for non-compliance with other requirements such as transparency or technical documentation, can reach up to €15 million or 3% of turnover. The third tier, for providing misleading information to authorities, can reach up to €7.5 million or 1.5% of turnover. For small and medium-sized enterprises (SMEs) and startups, the fines are capped at the lower of the absolute amount or the percentage, ensuring that penalties do not lead to insolvency for smaller innovators. Beyond financial penalties, market surveillance authorities have the power to order the withdrawal of non-compliant AI systems from the market or to require corrective actions. All enforcement decisions are subject to judicial review by the administrative courts, ensuring that the principles of due process and legal certainty are upheld.
Data protection
Data protection is a cornerstone of the Finnish AI regulatory landscape. As an EU member state, Finland is subject to the General Data Protection Regulation (GDPR), which is supplemented by the national Data Protection Act (1050/2018). The Finnish framework emphasizes the principles of data minimization, purpose limitation, and 'privacy by design,' which are directly applicable to the training and deployment of AI models. The Data Protection Ombudsman (Tietosuojavaltuutettu) plays a dual role as both a GDPR enforcer and a market surveillance authority for AI systems that impact fundamental rights and privacy. Finland has also established specialized frameworks for data sharing, such as the 'MyData' model, which advocates for individual control over personal data. In the public sector, the AuroraAI program explored decentralized data architectures to enable human-centric services while maintaining strict privacy safeguards. Furthermore, the Act on the Secondary Use of Health and Social Data provides a unique legal pathway for the use of sensitive health data in AI training, managed by the data permit authority Findata. This ensures that Finland can leverage its high-quality health registries for AI innovation while adhering to the highest standards of data security and ethical oversight. Data protection is a fundamental pillar of the Finnish approach to AI, reflecting the high value placed on privacy and societal trust in the Nordic model. The General Data Protection Regulation (GDPR) provides the overarching framework for all AI systems that process personal data. In Finland, this is supplemented by the national Data Protection Act, which provides specific rules for certain types of data processing. The Data Protection Ombudsman is the primary authority responsible for ensuring that AI developers and users comply with these rules. A key focus of the Finnish framework is the principle of 'privacy by design,' which requires that data protection measures are integrated into the AI development process from the very beginning. Finland has also been a leader in developing the 'MyData' concept, which aims to give individuals more control over their personal data and how it is used by AI systems. In the realm of health data, the Act on the Secondary Use of Health and Social Data has established a secure and transparent system for using sensitive data in AI research. This system is managed by Findata, the health and social data permit authority, which ensures that data is only used for legitimate purposes and that the privacy of individuals is protected through anonymization and secure processing environments.
Sector-specific rules
In the healthcare sector, AI and robotics are guided by the Hyteairo program and the Digi-HTA framework. Digi-HTA provides a standardized method for assessing the safety, effectiveness, and data security of digital health technologies, including AI-driven diagnostic tools. This framework is increasingly integrated into public procurement processes by Finland’s regional wellbeing service counties. Additionally, AI systems classified as medical devices must comply with the EU Medical Devices Regulation (MDR) and are supervised by the Finnish Medicines Agency (Fimea). In the industrial and manufacturing sectors, the AI 4.0 program steers the adoption of AI to support the 'twin transition.' While not a binding regulation, AI 4.0 sets the criteria for public funding and R&D grants, favoring projects that demonstrate green efficiency and ethical data use. In the financial sector, the Financial Supervisory Authority (Finanssivalvonta) monitors the use of algorithmic trading and AI-driven credit scoring, ensuring these systems do not introduce systemic risk or discriminatory outcomes. These sectoral rules are designed to complement the horizontal requirements of the EU AI Act, providing a granular layer of oversight for specialized applications. Finland has developed several sector-specific frameworks to address the unique challenges and opportunities of AI in different fields. In the healthcare sector, the 'Hyteairo' program has been instrumental in promoting the use of AI and robotics to improve wellbeing and health services. A key component of this is the 'Digi-HTA' framework, developed by the University of Oulu and FinCCHTA, which provides a standardized method for evaluating the safety, effectiveness, and cost-benefit of digital health technologies, including AI-based diagnostic tools. This framework is used by wellbeing service counties to inform their procurement decisions. In the industrial sector, the 'AI 4.0' program, led by the Ministry of Economic Affairs and Employment, focuses on the application of AI in manufacturing and logistics to support the 'twin transition.' This program provides guidance and funding for projects that use AI to improve energy efficiency and reduce environmental impact. In the financial sector, the Financial Supervisory Authority (Finanssivalvonta) has issued guidelines on the use of algorithms and AI in financial services, emphasizing the need for human oversight and the prevention of discriminatory outcomes in credit scoring. These sector-specific rules complement the horizontal requirements of the EU AI Act, providing a more granular and context-aware approach to AI regulation.
International alignment
Finland’s AI policy is deeply integrated with international standards and European Union frameworks. As a proactive participant in the development of the EU AI Act, Finland has aligned its national implementation (HE 46/2025) to mirror the Union's risk-based approach. Finland also adheres to the OECD Council Recommendation on Artificial Intelligence, promoting the principles of transparency, explainability, and accountability. The Finnish government frequently collaborates with other Nordic and Baltic countries to harmonize digital policies and create a unified regional market for ethical AI solutions. Beyond the EU, Finland participates in international standardization efforts through organizations like ISO and CEN/CENELEC. The Finnish Standards Association (SFS) coordinates national input into global AI standards, particularly regarding technical robustness and interoperability. This international alignment is a strategic priority for Finland, as it enables Finnish AI companies to scale their solutions globally while ensuring that foreign AI systems entering the Finnish market meet the high safety and ethical standards expected by Finnish citizens and regulators. Finland is a staunch advocate for international cooperation and the harmonization of AI standards. As a member of the European Union, Finland’s AI policy is primarily shaped by and aligned with EU-level initiatives. Finland was an active participant in the negotiations for the EU AI Act, pushing for a risk-based approach that balances safety with innovation. Beyond the EU, Finland is a member of the OECD and has fully endorsed the OECD Council Recommendation on Artificial Intelligence, which promotes the principles of inclusive growth, human-centered values, and transparency. Finland also participates in the Global Partnership on Artificial Intelligence (GPAI), an international initiative to support the responsible and human-centric development of AI. Regionally, Finland collaborates closely with other Nordic and Baltic countries through the Nordic Council of Ministers and the 'Digital North' program. This cooperation aims to create a unified regional market for digital services and to share best practices in AI governance. Finland also contributes to international standardization efforts through the Finnish Standards Association (SFS), which works with ISO and IEC to develop technical standards for AI robustness, safety, and interoperability. This commitment to international alignment ensures that Finnish AI companies can compete globally and that the AI systems used in Finland meet the high safety and ethical standards expected by Finnish citizens and regulators.
What's next
The immediate future of AI regulation in Finland will be dominated by the finalization and entry into force of Government Proposal HE 46/2025. The proposed entry-into-force date of August 2, 2025, is intended to align with the EU AI Act’s transitional timeline. During this period, the government will focus on the practical setup of the National Sanctions Board and the formalization of Traficom’s role as the Central Contact Point. Sectoral authorities are also expected to release updated guidance on how existing laws (such as consumer protection and labor law) will interact with the new AI-specific mandates. Looking further ahead, Finland is likely to explore more specific regulations regarding generative AI and its impact on the labor market and information integrity. The lessons learned from the AuroraAI program and the AI 4.0 strategy will likely inform new public-sector procurement rules that mandate 'green AI' criteria. Additionally, as the EU AI Act's requirements for high-risk systems become fully applicable by 2026, there will be an increased focus on developing national 'regulatory sandboxes' to allow Finnish SMEs to test innovative AI applications in a controlled environment before full-scale commercialization. The future of AI regulation in Finland will be characterized by the practical implementation and refinement of the EU AI Act and national legislation. The immediate priority is the finalization of Government Proposal HE 46/2025 and the formal establishment of the National Sanctions Board and the Central Contact Point at Traficom. This process is expected to be completed by mid-2025. Following this, there will be a significant focus on providing guidance and support to businesses, particularly SMEs, to help them comply with the new requirements. The Finnish government is also exploring the creation of national 'regulatory sandboxes' where companies can test innovative AI applications in a controlled environment with the support of regulators. These sandboxes will be crucial for fostering innovation in high-risk sectors like healthcare and transport. Another area of future development is the regulation of generative AI. While the EU AI Act includes provisions for general-purpose AI models, Finland may develop additional national guidelines or codes of conduct to address specific issues such as the impact of generative AI on the labor market, education, and the spread of disinformation. Furthermore, the 'AI 4.0' program will continue to evolve, with an increasing emphasis on the role of AI in achieving Finland’s ambitious climate goals. As the AI landscape continues to change rapidly, the Finnish government remains committed to a flexible and proactive regulatory approach that can adapt to new technological developments while protecting the fundamental rights and values of its citizens.
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2020
central_coordinator
National Central Contact Point and coordinator for AI market surveillance.
data_protection
Supervision of AI systems involving personal data and high-risk Annex III uses.
enforcement
Supervision of AI use within the financial, insurance, and banking sectors.
central_coordinator
Strategic lead for national AI policy and industrial digital transformation.
Jan 6, 2026 · law_amended
New powers for Finnish data watchdog as EU’s AI Act takes effect
Open source →Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
Open source →Jun 17, 2025 · news
Nordic Council of Ministers approve funding for a Nordic-Baltic AI Center
Open source →May 19, 2025 · news
Finland DPO releases guidance on privacy and AI
Open source →policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2019
policy · Effective Jan 1, 2018
policy · Effective Jan 1, 2018
policy · Effective Jan 1, 2017
Feb 10, 2025 · news
Paris Charter on AI signed
May 30, 2024 · international_agreement
Nordic data protection authorities issue declaration on children's data protection in gaming, AI, and administrative fines
Open source →