The EU AI Act in Denmark

How Regulation (EU) 2024/1689 applies in Denmark, and the 12 AI instruments Denmark has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Denmark’s own AI instruments

12 records tracked for Denmark, beyond the EU-level Act above.

National authority in Denmark

Named in Denmark’s own records, not inferred.

Per Denmark - AI Regulation Supplement (Law No. 467/2025)

Per Denmark - AI Regulatory Sandbox

Per Denmark - AI Strategic Approach

Per Denmark - Algorithm Transparency Proposal (B 136)

Per Denmark - National AI Taskforce

Per Denmark - Responsible Generative AI Guidelines

Per Denmark - AI Guidelines and Risk Assessments (B 42)

Per Denmark - AI Use by Public Authorities

Per Denmark - Independent AI Supervisory Authority (B 90)

  • Datatilsynet (Danish Data Protection Authority)Primary proposed host and executing supervisory authority for AI oversight; responsible for guidance, investigations and enforcement in relation to data protection aspects of AI.
  • Folketinget (Parliament of Denmark)Proposed institutional overseer to which Datatilsynet would be moved to secure political independence; legislative sponsor and accountability forum.

Per Denmark - Data Security and Ethics (B 149)

Per Denmark - National AI Strategy

Per Denmark - Digital Growth Strategy

Penalties in Denmark

As stated in Denmark’s own records.

Per Denmark - AI Regulation Supplement (Law No. 467/2025)

  • Administrative corrective orders (injunctions) requiring remedial action, user warnings, or cessation of marketing activities.
  • Temporary prohibition orders blocking placing on the market or availability of AI systems while investigations proceed.
  • Orders to recall or withdraw AI systems from the market or from end‑users.
  • Bødeforelæg (administrative fine settlements) where the accused admits liability and accepts the proposed fine.
  • Administrative fines and other penalties in accordance with the EU AI Regulation and national law where applicable.
  • Potential criminal sanctions under national law for serious or repeated offences where the EU Regulation permits criminal measures.
  • Publication of enforcement decisions and naming of the responsible entities in public interest cases.
  • Coordination with sectoral regulators that may bring additional sectoral penalties (e.g., for breaches affecting financial or health sector rules).

Per Denmark - AI Regulatory Sandbox

  • Participation does not create immunity; standard enforcement remedies under GDPR remain applicable (warnings, corrective orders, fines)
  • If non-compliance is found, Datatilsynet may impose administrative measures, corrective orders or fines consistent with GDPR
  • Digitaliseringsstyrelsen may take actions under national procedures related to AI Act enforcement where applicable
  • Public naming/criticism under transparency rules or publication of enforcement decisions where legally permitted

Per Denmark - AI Strategic Approach

  • The strategy itself does not create new statutory penalties; enforcement of obligations continues under existing laws (e.g., GDPR, sectoral law).
  • Non‑compliance with procurement contract terms may lead to contractual remedies, including termination, damages or exclusion from future procurements.
  • Where deployments violate existing legal obligations, responsible parties remain subject to administrative fines or legal remedies under applicable legislation (for example data protection enforcement by the Danish Data Protection Agency).
  • Future enforcement mechanisms for AI-specific obligations may arise from the EU AI Act once applicable, and Denmark will align enforcement accordingly.

Per Denmark - Algorithm Transparency Proposal (B 136)

  • Administrative orders to suspend or modify the use of non‑compliant algorithmic systems.
  • Mandatory remediation plans with deadlines and mandatory reporting to oversight bodies.
  • Public disclosure of significant compliance failures (naming and shaming) in official reports.
  • Financial administrative penalties at the authority level (to be specified in implementing legislation).
  • Loss of procurement eligibility for third‑party providers that fail to meet transparency/audit requirements.
  • Potential civil liability and strengthened individual redress routes where algorithmic decisions cause harm.

Per Denmark - National AI Taskforce

  • The taskforce itself does not impose sanctions; enforcement of breaches of law (e.g., GDPR) remains with the competent authorities such as <a href="https://www.datatilsynet.dk">Datatilsynet</a>.
  • Non-compliance with procurement or sectoral safety rules by an implementing authority may trigger administrative or financial consequences under existing Danish law and procurement rules.
  • Where the taskforce's recommendations lead to new statutory obligations, penalties would be defined in subsequent legislation and enforced by the designated regulator.

Per Denmark - Responsible Generative AI Guidelines

  • The Digitaliseringsstyrelsen guides themselves do not create new statutory penalties; they are advisory.
  • However, failure to implement appropriate data protection measures may result in enforcement under the GDPR (including administrative fines and corrective measures by Datatilsynet where applicable).
  • Sector- or contract-specific liability and penalties may apply if AI use breaches sector regulation or contractual obligations (e.g., healthcare, finance).
  • Organisational consequences include reputational harm, contractual termination, and remedial costs following incidents.

Per Denmark - AI Guidelines and Risk Assessments (B 42)

  • The proposal itself did not specify new penalties; it requested legal review to determine whether amendments to the Product Liability Act and administrative law should include enforceable remedies and sanctions.
  • Existing enforcement regimes (e.g., Datatilsynet fines under GDPR where personal data is mishandled) would continue to apply to relevant data-protection breaches.
  • Potential civil liability under general tort and product liability regimes if future legislative proposals implement new liability standards for AI systems.

Per Denmark - AI Use by Public Authorities

  • Corrective orders and binding remedies issued by Datatilsynet for GDPR infringements.
  • Administrative fines and penalties pursuant to Regulation (EU) 2016/679 (GDPR) and national implementing law.
  • Temporary suspension or prohibition of processing or AI system operation where risks are not mitigated.
  • Procurement remedies, contractual liability, and potential civil liability for harms caused by unlawful processing.
  • Public enforcement measures such as reprimands, published decisions and follow-up audits.

Per Denmark - Independent AI Supervisory Authority (B 90)

  • Administrative corrective orders issued by the supervisory authority (e.g., cessation orders, mandated remediation).
  • Public reprimands and publication of enforcement actions to ensure transparency and deterrence.
  • Monetary fines or sanctions where statutory powers are conferred (subject to enabling legislation and coordination with GDPR fines where applicable).
  • Referral to judicial or prosecutorial authorities for criminal or civil enforcement where statutory thresholds are met.
  • Restrictions on market access or temporary suspension of high-risk AI systems pending remediation.

Per Denmark - Data Security and Ethics (B 149)

  • The resolution itself does not introduce new statutory fines; existing GDPR-based administrative fines and corrective powers remain applicable.
  • Failure by ministries to produce required consequence assessments would be addressed through parliamentary oversight, public accountability and committee follow-up rather than direct fines.
  • If statutory changes are enacted later to implement institutional transfer, non-compliance with new statutory duties could trigger administrative consequences under the relevant statutory framework.
  • Reputational and political consequences: agencies and ministries failing to consult the Data Ethics Council or to provide transparency may face formal parliamentary inquiries and public reports.
  • Datatilsynet retains the authority to investigate unlawful processing and to impose corrective orders and fines under existing law.

Per Denmark - National AI Strategy

  • The strategy does not create new statutory penalties; enforcement for data protection and privacy violations remains under existing legislation (e.g., GDPR) and Danish administrative and sectoral law
  • Non-compliance with ethical guidance in the strategy is addressed through programme governance, reporting requirements and funding conditions rather than fines in the document itself

Per Denmark - Digital Growth Strategy

  • The strategy itself does not create new criminal or administrative penalties; existing statutory enforcement mechanisms remain in force for breaches of sectoral law (e.g., data protection infringements under GDPR enforced by the Danish Data Protection Agency).
  • Failure to comply with grant or funding terms may result in repayment obligations, administrative sanctions or exclusion from future funding.
  • Where regulatory conditions apply (e.g., consumer protection, industry supervision), existing sanctions, corrective orders and enforcement processes implemented by the relevant authority apply.

Denmark overview

The full picture of AI regulation in Denmark, beyond just the EU AI Act.

Denmark AI regulation overview →