Artificial Intelligence Act
proposedpolicy · Effective Jan 1, 2026
NO regulates AI through Artificial Intelligence Act.
Artificial Intelligence Act · effective 2026
Updated 60 days ago · 2 sources · confidence: medium
Overview
Norway's overarching approach to Artificial Intelligence (AI) regulation is characterized by a proactive and comprehensive strategy, deeply rooted in principles of trustworthiness, ethics, and human-centric development. The nation aims to harness the transformative potential of AI across its public services, research, and industry, while simultaneously establishing robust safeguards to protect fundamental rights, privacy, and public trust. This philosophy is evident in its foundational National Strategy for Artificial Intelligence from 2020, which articulated a multi-dimensional program combining investment in research, infrastructure, and skills development with a strong emphasis on legal compliance and ethical considerations. The regulatory landscape is rapidly evolving, with a significant move towards harmonizing with broader European frameworks. The proposed Artificial Intelligence Act (KI-loven), currently in draft form, is a cornerstone of this development, directly implementing the EU AI Act into Norwegian law. This bill signifies Norway's commitment to a comprehensive, risk-based regulatory approach that addresses the full lifecycle of AI systems. Beyond legislative measures, Norway leverages policy documents, national digitalization strategies, and regulatory sandboxes to guide responsible AI adoption and foster innovation, particularly in key sectors like health and public administration.
Regulatory approach
Norway's regulatory approach to AI is predominantly horizontal, with the forthcoming Artificial Intelligence Act (KI-loven) designed to establish a comprehensive, cross-sectoral framework for AI systems. This draft legislation explicitly adopts the EU AI Act's risk-based methodology, categorizing AI applications based on their potential to cause harm. This includes prohibitions for AI systems posing unacceptable risks, stringent obligations for high-risk systems (covering areas like conformity assessment, data governance, human oversight, and cybersecurity), and transparency requirements for limited-risk systems. This horizontal approach ensures a consistent regulatory baseline across diverse applications and industries. While the AI Act will introduce binding legal obligations, Norway also employs a significant amount of 'soft law' in the form of national strategies, policies, and guidelines. These documents, such as the National Strategy for Artificial Intelligence and the Digital Norway of the Future strategy, provide overarching policy direction, promote ethical principles, and guide public sector adoption. Additionally, sector-specific policies, notably in the health and care services, complement the horizontal framework by addressing unique challenges and opportunities within particular domains. The Datatilsynet Regulatory Sandbox also serves as a facilitative and advisory environment, helping organizations navigate legal and ethical complexities without immediately imposing new binding rules, thereby fostering innovation under supervised conditions. The governance and enforcement of AI regulations in Norway are designed as a multi-agency model, leveraging existing sectoral expertise while establishing new coordinating roles. Under the proposed Artificial Intelligence Act, the Nasjonal kommunikasjonsmyndighet (Nkom) is nominated as the national coordinating market surveillance authority and the primary contact point towards EU structures. Nkom's mandate will extend beyond its traditional role in electronic communications to encompass the broader oversight of AI systems, ensuring compliance with the new national AI law. This central coordination is crucial for a consistent application of the risk-based framework across different sectors. Alongside Nkom, several other key authorities play significant roles. The Datatilsynet (Norwegian Data Protection Authority) is proposed as a market surveillance or competent authority for specific AI uses, particularly those involving law enforcement, and continues to be the primary enforcer of data protection laws, including the GDPR. The Digitaliseringsdirektoratet (Digdir) will host "KI Norge," a national arena providing guidance, capacity building, and a regulatory sandbox to assist testing and safe experimentation of AI systems. Sectoral supervisors, including the Helsedirektoratet (Norwegian Directorate of Health), Direktoratet for medisinske produkter (DMP, formerly Statens legemiddelverk), and Helsetilsynet (Norwegian Board of Health Supervision), are designated as market surveillance or reporting authorities for their respective domains, ensuring specialized oversight in areas like health and medical devices. The Nasjonal sikkerhetsmyndighet (NSM) also contributes expertise in cybersecurity and national resilience, which is critical for the secure deployment of AI systems.
Enforcement & penalties
The draft Artificial Intelligence Act (KI-loven) outlines a robust administrative enforcement regime for non-compliance. Key enforcement tools include administrative sanctions such as overtredelsesgebyr (administrative fines) and tvangsmulkt (coercive fines). These measures are designed to ensure that providers and deployers of AI systems adhere to the obligations set forth in the Act. Beyond financial penalties, authorities will have the power to issue obligations to cease or modify non-compliant systems, to order their removal from the market, and to publicize enforcement actions. The emphasis is on administrative enforcement to ensure swift and effective corrective action. While the department proposes not to include new criminal offenses directly within the KI-loven, it seeks input on the use of coercive fines, the statute of limitations for penalty imposition, and whether administrative fines should apply to public bodies. This indicates a deliberate focus on administrative remedies, aligning with the EU AI Act's approach. For matters related to data protection, the Datatilsynet, under the Personal Data Act (which incorporates the GDPR), can impose significant administrative fines for breaches of personal data processing rules, which would apply to AI systems handling personal data. The existing enforcement powers of sectoral supervisors also remain relevant for AI applications within their respective remits, ensuring that a comprehensive array of sanctions can be applied depending on the nature and severity of the non-compliance.
Data protection
Norway's data protection framework is robust and deeply integrated with European standards, primarily through its adherence to the General Data Protection Regulation (GDPR). As a member of the European Economic Area (EEA), Norway has incorporated the GDPR into its national law via the Personal Data Act (personopplysningsloven). This means that all AI systems operating in Norway that process personal data must comply with the stringent requirements of the GDPR, including principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. The Norwegian Data Protection Authority (Datatilsynet) is the independent supervisory authority responsible for enforcing these rules, providing guidance, and handling complaints. The importance of privacy-by-design and data protection impact assessments (DPIAs) is consistently emphasized across Norway's AI policies and guidelines. The Datatilsynet's Regulatory Sandbox, for instance, is specifically designed to assist organizations in developing AI-driven services that are compliant with data protection laws from the outset. This initiative helps innovators navigate complex legal requirements, identify and mitigate risks, and implement robust safeguards for personal data. The national digitalization strategies also underscore the need for secure data access and interoperability while safeguarding privacy and confidentiality, ensuring that data protection remains a central consideration in the development and deployment of AI across both public and private sectors.
Sector-specific rules
While Norway is developing a horizontal AI regulatory framework, significant attention has been given to sector-specific applications, particularly within the health and care services. The "Joint AI plan for the safe and effective use of AI in the Norwegian health and care services 2024–2025" and the earlier "Status and proposals for further work with artificial intelligence (KI) in the health and care services" are prime examples. These policy documents outline coordinated measures for the safe, ethical, and effective introduction of AI in healthcare, focusing on patient safety, quality assurance, competence building, and regulatory guidance. They address the unique challenges of AI in clinical settings, including its intersection with medical device regulations and existing health legislation, and clarify roles for agencies like the Norwegian Directorate of Health, the Norwegian Medical Products Agency (DMP), and the Norwegian Board of Health Supervision. Beyond health, Norway's National Strategy for Artificial Intelligence identifies other sectors where the country has comparative advantages, such as maritime industries, energy, aquaculture, and public administration, as priority areas for AI development and adoption. While explicit sector-specific AI regulations for these areas are not detailed in the provided information, the general principles of the forthcoming AI Act, coupled with existing sectoral laws and regulatory oversight by relevant authorities (e.g., Nkom for communications infrastructure or NSM for cybersecurity), would apply. The national digitalization strategies also promote the responsible use of AI across the public sector, ensuring that digital services integrate cybersecurity, privacy, and universal design principles.
International alignment
Norway's approach to AI regulation is heavily influenced by and aligned with international and, in particular, European frameworks. The most significant development in this regard is the proposed Artificial Intelligence Act (KI-loven), which directly implements the EU Regulation on Artificial Intelligence (AI Act / KI-forordningen) into Norwegian law. This incorporation ensures that Norway's legal framework for AI will largely mirror that of the European Union, adopting the same risk-based architecture, definitions, and obligations. The government has explicitly stated its ambition to align Norway’s entry-into-force with the EU timing, with main parts expected to apply in summer/August 2026. This commitment to EU alignment is a cornerstone of Norway's international strategy for AI. Furthermore, Norway actively participates in broader international cooperation efforts to shape global norms and standards for AI. The National Strategy for Artificial Intelligence explicitly mentions engagement with organizations such as the OECD and the Council of Europe. This engagement reflects Norway's commitment to promoting trustworthy AI principles on a global scale, influencing discussions on data flows, ethical guidelines, and secure infrastructures. The national digitalization strategies also position Norway's digital policy within European frameworks, emphasizing collaboration on interoperability initiatives and adherence to international standards. This multi-faceted international alignment ensures that Norway's AI regulatory landscape is not only robust nationally but also harmonized with leading global practices.
What's next
The most significant future development in Norway's AI regulatory landscape is the planned implementation of the Artificial Intelligence Act (KI-loven). This draft bill, which aims to incorporate the EU AI Act, was published for public consultation with a deadline of 30 September 2025. The government has indicated an ambition to align Norway’s entry-into-force with the EU timing, with the main parts expected to apply in summer/August 2026. This will introduce comprehensive, legally binding obligations for AI systems across various risk categories, fundamentally reshaping the regulatory environment. The ongoing process includes securing adequate resources for designated authorities like Nkom, Digdir, and Datatilsynet to effectively carry out their new responsibilities. Beyond this foundational legislation, Norway anticipates continued evolution in its AI governance. The "Joint AI plan for the safe and effective use of AI in the Norwegian health and care services 2024–2025" outlines further work on developing quality assurance frameworks, producing cross-agency regulatory guidance, and building competence among health personnel. The "Digital Norway of the Future – National digitalisation strategy 2024–2030" also foresees annual status reporting and a planned mid-term review to assess progress and adapt measures related to AI and digitalization. Datatilsynet's Regulatory Sandbox will continue to provide insights that inform future policy and supervisory practices, ensuring that the regulatory framework remains adaptive to technological advancements and societal needs. These ongoing initiatives highlight a dynamic and iterative approach to AI governance in Norway.
policy · Effective Jan 1, 2026
policy · Effective Jan 1, 2025
guideline · Effective Mar 21, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2019
policy · Effective Jan 1, 2019
strategy · Effective Jan 1, 2019
strategy · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
Sources:
policy · Effective Jan 1, 2023
sectoral
National coordinating market surveillance authority and national contact point towards EU structures for AI, and regulation of telecommunication and postal sector.
data_protection
Market surveillance/competent authority for certain AI uses (e.g., law enforcement), enforces GDPR/Personal Data Act, operates regulatory sandbox.
advisory
Hosts "KI Norge" (national arena for guidance, capacity building, regulatory sandbox), operational coordination for digitalization strategies across the public sector.
advisory
Lead coordinating body for AI in health and care services, develops joint AI plans and guidance, implements government health policies.
advisory
Responsible for ensuring access to safe medicines and safe medical devices, including AI as a medical device.
enforcement
Oversees social, child welfare, health and care services, including patient safety aspects of AI in healthcare.
enforcement
Norway's agency for national protective security, responsible for preventive national security and ICT security matters.
Mar 13, 2026 · international_agreement
Canada and Norway issue joint statement on sovereign technology and AI
Open source →Sep 28, 2025 · law_amended
Norwegian Data Protection Authority submits consultation statement on proposed implementing act of EU AI Act
Open source →Jun 29, 2025 · law_amended
Norway releases draft AI Act implementing EU AI Act in Norwegian law
Open source →Jun 17, 2025 · news
Nordic Council of Ministers approve funding for a Nordic-Baltic AI Center
Open source →Nov 7, 2024 · news
Norway launches 2024-2030 national digital strategy, covering AI
Open source →Oct 27, 2024 · news
Global data protection authorities issue statement on data scraping, covering AI
Open source →Jun 3, 2024 · news
Norway DPA issues note regarding Meta’s use of user content for AI training
Open source →May 30, 2024 · international_agreement
Nordic data protection authorities issue declaration on children's data protection in gaming, AI, and administrative fines
Open source →Mar 21, 2024 · news
Norway Data Protection Authority publishes strategy on the use of AI
Open source →Jun 19, 2023 · news
Forbrukerrådet releases generative AI risks report
Open source →