Act on Supplementary Provisions to the Regulation on Artificial Intelligence (Lov om supplerende bestemmelser til forordningen om kunstig intelligens)
in_forceact · Effective Jan 1, 2025
DK regulates AI through Act on Supplementary Provisions to the Regulation on Artificial Intelligence (Lov om supplerende bestemmelser til forordningen om kunstig intelligens).
Act on Supplementary Provisions to the Regulation on Artificial Intelligence (Lov om supplerende bestemmelser til forordningen om kunstig intelligens) · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Denmark's approach to Artificial Intelligence (AI) regulation is marked by a forward-looking and comprehensive strategy that carefully balances the imperative for technological innovation with a steadfast commitment to ethical principles, fundamental rights, and robust legal safeguards. The nation's regulatory philosophy is deeply rooted in a human-centric perspective, aiming to harness the transformative potential of AI for societal benefit while meticulously mitigating associated risks, particularly concerning data protection, transparency, and accountability. This dual focus is evident across its legislative, policy, and guidance instruments, which collectively form a mature and evolving regulatory landscape. Denmark's position as an EU member state means its AI governance is intrinsically linked to and significantly shaped by the broader European Union framework, with national efforts primarily focused on implementing and supplementing these overarching EU regulations, most notably the forthcoming EU AI Act. The country has demonstrated a proactive stance, not only in preparing for and transposing EU directives but also in developing its own national strategies and practical guidance to address the immediate challenges and opportunities presented by AI, including the rapid advancements in generative AI technologies.The maturity of Denmark's AI regulatory ecosystem is reflected in its multi-layered approach, which encompasses binding national legislation, advisory guidelines, and strategic policy initiatives. This framework is designed to provide clarity for both public authorities and private enterprises, guiding them towards responsible AI development and deployment. The emphasis is on fostering an environment where AI solutions can thrive securely and ethically, ensuring public trust and upholding democratic values. Through instruments like the Act on Supplementary Provisions to the Regulation on Artificial Intelligence, Denmark has established the necessary national infrastructure for market surveillance and enforcement, thereby operationalizing the EU AI Act within its borders. Concurrently, agencies such as Digitaliseringsstyrelsen and Datatilsynet issue practical, non-binding guidance, and establish innovative mechanisms like regulatory sandboxes, to assist organizations in navigating the complexities of AI, particularly concerning data protection and risk management. This integrated strategy underscores Denmark's commitment to being a digital frontrunner, where technological progress is inextricably linked with responsible governance and citizen welfare.
Regulatory approach
Denmark employs a hybrid regulatory approach that strategically combines horizontal, risk-based frameworks with targeted soft law instruments and policy initiatives, all underpinned by its commitment to EU-level harmonization. The foundational element of this approach is the EU Artificial Intelligence Regulation (EU AI Act), which is directly applicable in member states and establishes a comprehensive, risk-based regulatory framework for AI systems across various sectors. Denmark's national legislation, such as the Act on Supplementary Provisions to the Regulation on Artificial Intelligence, serves as the critical implementing framework, clarifying national arrangements, designating competent authorities, and conferring necessary market surveillance and enforcement powers to operationalize the EU rules. This horizontal application ensures a consistent baseline of AI governance across diverse applications, moving away from a purely sectoral approach unless specifically mandated by EU law or identified national needs. The risk-based methodology of the EU AI Act, which classifies AI systems based on their potential to cause harm, directly informs Denmark's national oversight, focusing regulatory scrutiny and compliance burdens on high-risk applications.Complementing this binding legislative framework, Denmark extensively utilizes soft law instruments, including guidelines, policy strategies, and advisory bodies, to foster responsible AI adoption and address emerging challenges. Digitaliseringsstyrelsen, for instance, publishes practical guides for the responsible use of generative AI, offering non-binding but authoritative recommendations for public authorities and private companies. Similarly, Datatilsynet provides detailed guidance for public authorities on integrating data protection principles into AI projects from the outset. These guidelines serve to translate complex legal obligations into actionable advice, promoting best practices in areas such as risk management, data privacy, and ethical considerations. The establishment of initiatives like the Regulatory Sandbox for Artificial Intelligence further exemplifies this pragmatic approach, offering hands-on regulatory guidance and fostering a learning environment for both innovators and regulators. While these soft law instruments are not legally binding, they play a crucial role in shaping organizational practices, building capacity, and preparing entities for compliance with evolving statutory obligations, thereby creating a robust and adaptive regulatory ecosystem. Denmark's AI governance and enforcement landscape is characterized by a distributed yet coordinated approach, leveraging the expertise of existing national agencies and establishing new collaborative frameworks. At the forefront of this structure is the Digitaliseringsstyrelsen (Danish Agency for Digital Government), which has been designated as the national authorising authority and central contact point for Denmark under the EU AI Regulation. In this pivotal role, Digitaliseringsstyrelsen acts as Denmark’s official interlocutor with the European Commission and other Member States on AI Regulation matters, and is responsible for coordinating national enforcement efforts, especially where multiple authorities are involved. Beyond its central contact point function, Digitaliseringsstyrelsen is also designated as a market surveillance authority for specific prohibited AI practices, granting it broad investigative and enforcement powers. These powers include the right to request information, obtain documents and technical material, and conduct on-site inspections and technical examinations of AI systems without prior judicial authorization in business premises, subject to due process. The agency can issue binding remedial directions, corrective measures, withdrawal or recall orders, and temporary prohibitions on placing AI systems on the market or making them available.Further strengthening the enforcement framework, the Datatilsynet (Danish Data Protection Agency) and Domstolsstyrelsen (Danish Court Administration) are designated as additional market surveillance authorities with specified remits. Datatilsynet, already the independent authority supervising compliance with personal data protection rules (GDPR), is now also responsible for market surveillance concerning other specified prohibited uses of AI systems. Its existing expertise in data protection and its powers to provide guidance, handle complaints, and conduct inspections make it a natural fit for overseeing AI systems that process personal data. Domstolsstyrelsen is specifically designated as a market surveillance authority responsible for the courts’ non-judicial usages of AI systems, ensuring oversight within the judicial domain. The Act on Supplementary Provisions ensures the functional independence of these market surveillance authorities in the exercise of their statutory duties and facilitates cooperation with other sectoral regulators, such as financial supervisory authorities, where the EU Regulation anticipates sectoral allocation. The Digital Taskforce for Artificial Intelligence also plays a significant governance role, albeit as a cross-public-sector framework rather than a direct regulatory body. Established under the Digitalisation Ministry, it aims to accelerate the responsible deployment of AI in public services by identifying and removing legal, organizational, and technical barriers, coordinating pilots, and recommending necessary legal or regulatory adjustments.An important advisory body in the Danish AI ecosystem is the Data Ethics Council (Dataetisk Råd). While not an enforcement authority, the Council provides independent advice and recommendations on data ethical questions arising from the use of data and new technologies. It aims to support a culture of responsible data use in both the public and private sectors and contributes to the broader ethical discourse surrounding AI. Although a parliamentary proposal (B 149) to formally establish the Data Ethics Council as a hearing body for all legislative initiatives involving personal data processing and to transfer Datatilsynet's accountability to Parliament was not enacted, it highlighted the ongoing emphasis on independent ethical review and strengthened oversight. The Regulatory Sandbox for Artificial Intelligence, a joint initiative by Datatilsynet and Digitaliseringsstyrelsen, further exemplifies the collaborative governance model, providing hands-on regulatory guidance to organizations and fostering a learning environment for both innovators and regulators. This comprehensive institutional setup, combining legislative mandates, designated enforcement powers, strategic policy initiatives, and advisory functions, underscores Denmark's commitment to a robust and adaptive AI governance framework.
Enforcement & penalties
The enforcement mechanisms and penalties for AI regulation in Denmark are primarily established through the Act on Supplementary Provisions to the Regulation on Artificial Intelligence, which operationalizes the EU AI Act at a national level. This Act grants market surveillance authorities, including Digitaliseringsstyrelsen, Datatilsynet, and Domstolsstyrelsen, broad investigative and enforcement powers. These powers are crucial for ensuring compliance with the EU AI Regulation's substantive duties, such as technical documentation, risk management, transparency, human oversight, incident reporting, and conformity assessment where applicable. Authorities are empowered to issue binding remedial directions, requiring organizations to implement corrective measures, withdraw or recall non-compliant AI systems, or temporarily prohibit their placement on the market or making them available. They can also publish enforcement decisions, increasing transparency and accountability. The Act specifically provides for the possibility of on-the-spot fines (bødeforelæg) in certain cases, offering an administrative enforcement tool for quicker resolution of less severe infringements.For more serious breaches, the Act establishes the legal basis for administrative orders and interim measures to address risks posed by AI systems and references coordination with the Justice Ministry where fines and criminal sanctions are considered. This indicates that while administrative penalties are the primary tool, the framework allows for the escalation to criminal proceedings for severe violations, aligning with the EU AI Act's provisions for national criminal sanctions. The law also contemplates appeal routes and time limits for judicial review of administrative decisions, particularly concerning courts' own use of AI and other determinations, ensuring due process and the right to challenge enforcement actions. Beyond the specific provisions of the AI Act implementation, non-compliance with the General Data Protection Regulation (GDPR), supervised by Datatilsynet, continues to expose organizations to significant corrective measures and substantial fines. The GDPR allows for fines up to €20 million or 4% of annual global turnover, whichever is higher, for serious infringements. This dual enforcement capability, covering both AI-specific regulations and broader data protection laws, provides a comprehensive and robust system for ensuring accountability and deterring non-compliance in the Danish AI landscape.
Data protection
Denmark's data protection framework is robust and primarily governed by the General Data Protection Regulation (GDPR), a directly applicable EU regulation, supplemented by national legislation such as the Danish Data Protection Act. This framework forms the bedrock for regulating any AI system that processes personal data, ensuring that fundamental rights to privacy and data protection are upheld. The Datatilsynet (Danish Data Protection Agency) serves as the independent supervisory authority responsible for overseeing compliance with these rules. Its mandate includes providing guidance, handling complaints, conducting inspections, and imposing corrective measures and fines for infringements. The GDPR's principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality are central to Denmark's approach to AI development and deployment. Any AI project involving personal data must identify a valid lawful basis for processing, conduct thorough Data Protection Impact Assessments (DPIAs) for high-risk processing, and implement privacy-by-design and default principles.The interplay between AI regulation and data protection is a critical focus in Denmark. Datatilsynet's guidance, such as "Public authorities' use of artificial intelligence: Before you start," explicitly situates AI projects within the existing data protection framework, emphasizing that GDPR obligations apply irrespective of the technology used. This guidance provides practical advice on determining lawful bases, handling special categories of sensitive data, managing profiling and automated decision-making (including Article 22 GDPR constraints), and fulfilling information duties to data subjects. It also stresses proportionality in data collection and training set design, recommending anonymization or pseudonymization where feasible, and fewer personal data in testing environments. There are no specific data localization requirements beyond those stipulated by the GDPR for international data transfers, which require adequate safeguards such as Standard Contractual Clauses or Binding Corporate Rules. The Regulatory Sandbox for Artificial Intelligence, a joint initiative by Datatilsynet and Digitaliseringsstyrelsen, further supports organizations in navigating these complexities, offering hands-on advice on GDPR compliance and risk classification under the EU AI Act, demonstrating a proactive effort to ensure data protection is integrated into AI innovation.
Sector-specific rules
While Denmark's primary AI regulatory approach is horizontal, largely driven by the EU AI Act's risk-based framework, its national strategies and policy initiatives acknowledge and address the specific implications of AI across various sectors. The EU AI Act itself categorizes high-risk AI systems, many of which are sector-specific, including those used in critical infrastructure, education, employment, essential private and public services (e.g., healthcare, credit scoring), law enforcement, migration, and the administration of justice. Consequently, Denmark's implementing legislation and the mandates of its designated market surveillance authorities will inherently apply to these sectors. For instance, Datatilsynet, as a market surveillance authority, will oversee specific prohibited AI uses, which could have implications across various sectors where personal data is processed. Domstolsstyrelsen's designation specifically for the courts' non-judicial usages of AI systems highlights a tailored approach within the justice sector.Beyond the direct application of the EU AI Act, Denmark's broader AI strategies and taskforces indicate a focus on certain sectors for accelerated AI deployment and responsible innovation. The 2019 National Strategy for Artificial Intelligence identified priority sectors such as health, energy and utilities, agriculture, and transport for AI initiatives. The more recent Digital Taskforce for Artificial Intelligence, established in 2024, is specifically charged with accelerating the deployment of AI in public services, with a strong emphasis on welfare services. This taskforce aims to identify and address legal and organizational barriers within the public sector, including those related to GDPR and the EU AI Act, and coordinates pilots in areas like healthcare and social services. The Medical Device Regulation (MDR) is also referenced in relation to the Digital Taskforce, indicating an awareness of existing sectoral regulations that AI systems, particularly in healthcare, must comply with. While Denmark has not introduced separate federal/national sector-specific AI regulations beyond the general implementation of the EU AI Act, its policy documents and initiatives clearly demonstrate a strategic focus on leveraging and governing AI in key societal and economic sectors, ensuring that ethical and data protection considerations are paramount in these applications.
International alignment
Denmark's AI regulatory framework is deeply intertwined with and strongly aligned to international and, particularly, European Union standards and initiatives. As a member state of the EU, Denmark's approach to AI governance is fundamentally shaped by EU law, with the EU Artificial Intelligence Regulation (EU AI Act) serving as the cornerstone of its regulatory structure. The Act on Supplementary Provisions to the Regulation on Artificial Intelligence is a direct national implementing framework for the EU AI Act, demonstrating Denmark's commitment to transposing and operationalizing this landmark European legislation. This ensures a high degree of harmonization with other EU member states, fostering a single market for AI systems while upholding common standards for safety, fundamental rights, and ethical use. Denmark's national authorities are explicitly tasked with notifying the European Commission of their designated market surveillance roles, further solidifying this alignment.Beyond the EU AI Act, Denmark's regulatory landscape is also heavily influenced by the General Data Protection Regulation (GDPR), another directly applicable EU law that forms the bedrock of data protection for all AI systems processing personal data. The Danish Data Protection Agency (Datatilsynet) plays a crucial role in enforcing GDPR and actively participates in European data protection bodies, such as the European Data Protection Board (EDPB), ensuring consistent application of data protection principles across the EU. Furthermore, Denmark's national AI strategies, including the 2019 National Strategy for Artificial Intelligence and the 2024 Strategic Approach for Artificial Intelligence, consistently emphasize alignment with broader international standards and ethical principles, such as those promoted by the OECD. These strategies underscore Denmark's commitment to a human-centric approach to AI, mirroring global efforts to ensure responsible innovation. The country's active participation in EU-level discussions and its proactive national measures demonstrate a strong dedication to contributing to and benefiting from a harmonized international AI governance landscape, reflecting a belief that cross-border cooperation is essential for effectively managing the global implications of AI.
What's next
Denmark's AI regulatory landscape is poised for continued evolution, primarily driven by the phased implementation of the EU AI Act and ongoing national policy initiatives. The Act on Supplementary Provisions to the Regulation on Artificial Intelligence, which entered into force for most provisions on August 2, 2025, provides a national timetable consistent with the EU Regulation's staged entry into force. This means that as different parts of the EU AI Act become applicable, Denmark's national authorities will progressively assume their full oversight and enforcement responsibilities regarding high-risk AI systems, prohibited practices, and transparency requirements. Digitaliseringsstyrelsen's guides for responsible use of generative AI are explicitly designed to be updated as the technology and legal landscape evolves, indicating a commitment to adaptive guidance that keeps pace with rapid AI advancements. This continuous review and updating process will be crucial for addressing emerging challenges and ensuring that national guidance remains relevant and effective.Furthermore, the policy debates surrounding several withdrawn or rejected parliamentary proposals offer insights into potential future legislative or administrative actions. Proposals concerning algorithmic transparency in public administration (B 136), the establishment of an independent AI supervisory authority under Datatilsynet (B 90), and the development of formal guidelines and risk assessments for AI (B 42) highlight areas of ongoing parliamentary concern. While these specific proposals did not become law, the underlying policy goals—such as enhancing citizen insight into algorithmic decisions, strengthening independent oversight, and embedding ethical considerations more formally into AI development—are likely to remain prominent in future discussions. The Digital Taskforce for Artificial Intelligence, currently provisional until the end of 2027 with a review point in mid-2027, represents a significant ongoing initiative for scaling AI in the public sector. Its mandate to identify and address legal and organizational barriers, and to recommend legislative or administrative amendments, suggests that further regulatory adjustments may emerge from its work. These combined factors indicate a dynamic regulatory environment in Denmark, characterized by ongoing adaptation to EU law, continuous refinement of national guidance, and a persistent focus on ethical and rights-based AI governance.
act · Effective Jan 1, 2025
policy · Effective May 30, 2024
central_coordinator
National authorising authority and central contact point for Denmark under the EU AI Regulation; market surveillance authority for specified prohibited AI practices. Leads digital development and solutions for public sector.
data_protection
Market surveillance authority for other specified prohibited uses of AI systems; independent authority supervising compliance with personal data protection rules (GDPR).
enforcement
Market surveillance authority responsible for the courts’ non-judicial usages of AI systems. Oversees the administrative and financial affairs of the Danish courts, including IT.
Feb 2, 2026 · law_amended
European Commission issues opinion on Danish Bill amending Copyright Act, introducing performance protection and protection against digitally generated imitations
Open source →Jun 25, 2025 · law_amended
Ministry of Culture proposes to amend Copyright Act prohibiting unauthorised sharing of digitally generated imitations of personal characteristics
Open source →Jun 17, 2025 · news
Nordic Council of Ministers approve funding for a Nordic-Baltic AI Center
Open source →Mar 3, 2025 · news
Danish Parliament bans DeepSeek
Open source →May 30, 2024 · international_agreement
Nordic data protection authorities issue declaration on children's data protection in gaming, AI, and administrative fines
guideline · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
guideline · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2019
policy · Effective Jan 1, 2018
advisory
Independent advisory council providing recommendations and ethical analyses of data use and new technologies. Supports a culture of responsible data use.
May 21, 2024 · law_amended
Danish DPA releases AI impact assessment templates
Open source →Apr 9, 2024 · news
Danish Agency for Digitisation designated as Denmark's AI regulator
Open source →Mar 4, 2024 · news
Denmark announces regulatory sandbox for AI
Open source →