act · Effective May 30, 2024
IS regulates AI through Act No. 77/2018 on Data Protection.
Act No. 77/2018 on Data Protection · effective 2024-05-30
Updated 60 days ago · 2 sources · confidence: medium
Overview
Iceland’s regulatory landscape for artificial intelligence (AI) is characterized by a proactive, human-centric approach that seeks to balance rapid technological adoption with the preservation of its unique cultural and linguistic heritage. As a technologically advanced nation with a small population, Iceland views AI as a critical tool for maintaining economic competitiveness and enhancing public services. The government’s philosophy is rooted in the "Nordic model," which emphasizes high levels of social trust, transparency, and the protection of fundamental rights. Rather than viewing AI as a disruptive threat, Icelandic policy frames it as an opportunity to address labor shortages and automate routine tasks, particularly within the public sector. This vision is further supported by the "Digital Iceland" (Stafrænt Ísland) initiative, which aims to make all public services digital and accessible, with AI serving as the underlying engine for personalization and efficiency. The maturity level of Iceland's AI governance has advanced significantly since the adoption of its first formal policy in 2021. The current framework is guided by the "Iceland AI Action Plan 2024-2026," which provides a roadmap for integrating AI across five strategic pillars: society, the workforce, education, the public sector, and healthcare. This plan reflects a shift from abstract ethical principles to concrete implementation measures. Iceland’s approach is also defined by its membership in the European Economic Area (EEA), which necessitates close alignment with European Union standards. Consequently, Iceland is not developing a standalone, isolated regulatory regime but is instead weaving international best practices into its national strategy to ensure seamless cross-border data flows and technological interoperability. The overarching goal is to create an environment where AI is used responsibly to improve quality of life while safeguarding the democratic values that define Icelandic society.
Regulatory approach
Iceland employs a hybrid regulatory approach that combines horizontal policy frameworks with sector-specific initiatives. Historically, the country relied on "soft law" instruments, such as the 2021 Policy on Artificial Intelligence, which established ethical guidelines without imposing strict legal penalties. However, the introduction of the 2024-2026 Action Plan marks a transition toward more structured governance. This plan introduces 25 targeted measures designed to operationalize AI ethics and safety. While these measures are primarily policy-driven, they set the stage for the "hard law" requirements that will follow the incorporation of the EU AI Act into the EEA Agreement. This risk-based approach ensures that regulatory burdens are proportionate to the potential harm posed by specific AI applications. A distinctive feature of Iceland's regulatory approach is its focus on "Responsible AI," which encompasses transparency, accountability, and the mitigation of bias. The government actively promotes the use of AI for the public good while maintaining a technology-neutral stance. This means that regulations focus on the outcomes and impacts of AI systems rather than the specific underlying algorithms. Furthermore, the regulatory environment is designed to be flexible, allowing for the rapid evolution of technology while providing a stable legal foundation for businesses and researchers. The emphasis on language technology is also a regulatory priority, with specific funding and guidelines aimed at ensuring that AI systems can function effectively in the Icelandic language, thereby preventing "digital extinction." The approach also emphasizes public-private partnerships, encouraging the tech sector to adopt self-regulatory standards that align with national ethical goals before formal legislation is fully enacted. The governance of AI in Iceland is a multi-agency effort coordinated primarily by the Ministry of Culture, Innovation and Higher Education. This ministry is responsible for the overarching AI strategy and the implementation of the 2024-2026 Action Plan. It works in tandem with the Icelandic Centre for Research (Rannís), which manages funding for AI-related research and innovation projects. These bodies focus on the promotional and developmental aspects of AI, ensuring that Iceland remains competitive in the global digital economy. They also facilitate international cooperation through the Nordic Council of Ministers and the OECD. Enforcement and oversight are distributed among existing regulators based on their specific domains. Persónuvernd (the Icelandic Data Protection Authority) is the most prominent enforcement body in the AI space, tasked with ensuring that AI systems comply with privacy laws and data processing requirements. It has the power to audit algorithms and investigate complaints from citizens regarding automated decisions. Additionally, the Consumer Agency (Neytendastofa) monitors AI-driven commercial practices to prevent fraud, deceptive advertising, or unfair competition in the digital marketplace. The Electronic Communications Office (Fjarskiptastofa) also plays a role in regulating the underlying infrastructure and ensuring the security of networks used by AI systems. As the EU AI Act is implemented, Iceland is expected to designate a national supervisory authority—or expand the mandate of an existing one—to serve as the central market surveillance authority for high-risk AI systems. This body will be responsible for auditing high-risk algorithms, maintaining a national registry of AI systems, and ensuring compliance with safety standards across all sectors of the economy.
Enforcement & penalties
Current enforcement mechanisms for AI-related infractions in Iceland are primarily derived from the Data Protection Act (No. 77/2018). Persónuvernd has the authority to impose significant administrative fines for violations related to the processing of personal data by AI systems. These fines can reach up to 2,400,000,000 ISK or 4% of a company's total global annual turnover, whichever is higher. Beyond financial penalties, the authority can issue bans on specific data processing activities, effectively shutting down non-compliant AI systems until they are brought into alignment with the law. The enforcement process includes a right to appeal, where decisions made by administrative agencies can be challenged in the Icelandic court system. With the forthcoming full implementation of the EU AI Act, the penalty framework will become even more stringent and tiered. The Act specifies fines for different levels of non-compliance: up to €35 million or 7% of global turnover for prohibited AI practices (such as manipulative AI or unauthorized biometric surveillance); up to €15 million or 3% for general non-compliance with requirements for high-risk systems; and up to €7.5 million or 1.5% for providing incorrect information to regulators. Iceland’s enforcement bodies will also have the power to demand the withdrawal of dangerous AI products from the market and require developers to provide detailed technical documentation during audits. This transition from policy-based oversight to a high-stakes enforcement regime represents a significant hardening of Iceland's regulatory stance, aimed at ensuring that the benefits of AI do not come at the cost of public safety or individual rights. The principle of proportionality remains central, ensuring that small and medium-sized enterprises are not unfairly burdened by the maximum penalty levels unless their violations are severe.
Data protection
Data protection is the cornerstone of AI regulation in Iceland. The country’s framework is governed by Act No. 77/2018 on Data Protection and the Processing of Personal Information, which mirrors the European Union’s General Data Protection Regulation (GDPR). This law applies to any AI system that processes the personal data of individuals in Iceland, regardless of where the AI provider is located. Key requirements include the principles of data minimization, purpose limitation, and the necessity of a legal basis (such as consent or legitimate interest) for processing data. AI developers must also conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities to identify and mitigate potential harms to individuals. Iceland does not currently impose strict data localization requirements that would prevent the transfer of data to other EEA countries; however, transfers to "third countries" outside the EEA are subject to rigorous adequacy decisions or standard contractual clauses. Persónuvernd has been active in providing guidance on the use of AI in the workplace and the public sector, emphasizing that automated decision-making must be transparent and allow for human intervention. The framework also grants individuals the right not to be subject to a decision based solely on automated processing if it produces legal effects or significantly affects them, a provision that is central to the ethical deployment of AI in Iceland. Furthermore, the Data Protection Authority emphasizes the "right to explanation," meaning that individuals have the right to understand the logic behind an AI-driven decision that affects them. This framework ensures that as AI becomes more integrated into daily life, the privacy and autonomy of Icelandic citizens remain protected by a robust and enforceable legal structure.
Sector-specific rules
While Iceland pursues a horizontal strategy, several sectors have developed specific rules and guidelines for AI application. In the healthcare sector, the AI Action Plan 2024-2026 outlines pilot projects for AI in diagnostics and patient care, which must comply with both the Data Protection Act and the Act on Medical Devices. These systems are subject to strict clinical validation and oversight by the Directorate of Health to ensure patient safety. In the financial sector, the Central Bank of Iceland and the Financial Supervisory Authority (FME) monitor the use of AI in algorithmic trading and credit scoring to ensure financial stability and prevent discriminatory practices in lending. The public sector is a major focus of recent regulation, with the government aiming for a 30% increase in efficiency through AI automation. Guidelines for public agencies emphasize that AI must not compromise the principle of administrative transparency or the right to a fair hearing. Additionally, the language technology sector is governed by specific state-funded programs, such as the Language Technology Program for Icelandic (Máltækniáætlun), aimed at developing an open-source infrastructure for the Icelandic language. This ensures that AI tools used in education and media do not lead to linguistic erosion. In the realm of employment, the 2021 Policy and 2024 Action Plan emphasize the need for reskilling programs, though specific labor laws regarding AI-driven hiring are currently being updated to align with European standards on workplace surveillance. Finally, the energy sector is exploring "Green AI" initiatives, where AI is used to optimize the distribution of renewable energy from Iceland's geothermal and hydroelectric plants, subject to environmental regulations and infrastructure security standards.
International alignment
Iceland’s AI strategy is fundamentally defined by its international alignment, particularly with the European Union and the Nordic region. As an EEA member, Iceland participates in the Single Market, which requires it to adopt EU regulations that have "EEA relevance." The EU AI Act is the most significant example of this, and Iceland is actively participating in the EEA Joint Committee process to incorporate the Act into its national law. This alignment ensures that Icelandic AI startups have access to the broader European market while providing Icelandic citizens with the same level of protection as those in EU member states. Beyond the EU, Iceland is a committed member of the OECD and has formally endorsed the OECD Principles on Artificial Intelligence. These principles, which advocate for trustworthy AI that respects human rights and democratic values, serve as the ethical backbone for Iceland’s domestic policies. Iceland also collaborates closely with its neighbors through the Nordic-Baltic AI Cooperation, focusing on shared challenges such as AI in small-language communities and the development of ethical AI for the public sector. This multi-layered international engagement allows Iceland to influence global AI standards while ensuring its domestic regulations remain at the forefront of technological governance. Iceland also participates in the Council of Europe’s work on the Framework Convention on Artificial Intelligence, further solidifying its commitment to a rights-based approach to technology. This international synergy is crucial for a small nation like Iceland, as it allows for the pooling of resources and expertise in the face of rapidly evolving global technological trends.
What's next
The next two years will be a period of intense regulatory activity in Iceland as the 2024-2026 AI Action Plan reaches its full implementation phase. One of the most anticipated developments is the formal designation of a National AI Authority, which will be tasked with the market surveillance and enforcement duties mandated by the EU AI Act. This will likely involve a significant expansion of the technical capabilities of existing regulators or the creation of a new specialized unit within the Ministry of Culture, Innovation and Higher Education. Public consultations are expected to continue regarding the ethical use of facial recognition and biometric surveillance in public spaces, with a potential for stricter domestic bans than those found in the baseline EU legislation. Furthermore, the government is expected to introduce new legislation or amendments to the Public Administration Act to specifically address the use of generative AI in government decision-making and the drafting of official documents. As the 2024-2026 Action Plan concludes, a subsequent strategy for 2027 and beyond is likely to be drafted, with a projected focus on the "AI economy" and the potential for Iceland to become a hub for green AI data centers, leveraging its renewable energy resources. The evolution of the Icelandic Language Technology Program will also remain a priority, with future developments focusing on the integration of Icelandic into global Large Language Models (LLMs) through partnerships with major international technology firms. There is also discussion regarding the creation of an "AI Regulatory Sandbox" to allow Icelandic startups to test innovative AI solutions in a controlled environment under the supervision of regulators, fostering innovation while ensuring safety.
act · Effective May 30, 2024
policy · Effective Jan 1, 2024
central_coordinator
Oversees national AI strategy and policy implementation.
data_protection
Enforces data privacy laws and monitors AI data processing.
sectoral
Regulates digital infrastructure and electronic communications.
enforcement
Protects consumer rights in the digital marketplace.
Oct 10, 2025 · law_amended
Iceland releases AI Action Plan
Open source →Jun 17, 2025 · news
Nordic Council of Ministers approve funding for a Nordic-Baltic AI Center
Open source →Nov 6, 2024 · law_amended
Iceland releases AI Action Plan 2024-2026
Open source →May 30, 2024 · international_agreement
Nordic data protection authorities issue declaration on children's data protection in gaming, AI, and administrative fines
Open source →policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2021