The EU AI Act in Finland

How Regulation (EU) 2024/1689 applies in Finland, and the 11 AI instruments Finland has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Finland’s own AI instruments

11 records tracked for Finland, beyond the EU-level Act above.

National authority in Finland

Named in Finland’s own records, not inferred.

Per Finland - AI Regulation Implementation (HE 46/2025)

  • Liikenne- ja viestintävirasto (Traficom)Central contact point and sectoral supervisor for transport/telecom safety components; national coordinator for market-surveillance authorities under the AI Act.
  • Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman)Market-surveillance authority for specified Annex III domains (biometrics; education; employment; law enforcement-support; migration and border-control related uses; credit scoring in certain cases).

Per Finland - AI Deployment Strategy

Per Finland - AI in Health Sector

Per Finland - Helsinki - AI Register

Per Finland - Human-Centric AI Programme

Per Finland - AI Business Programme (2018)

Per Finland - AI Impact on Work (21/2018)

Per Finland - National AI Programme

Per Finland - National AI Strategy (2017)

Penalties in Finland

As stated in Finland’s own records.

Per Finland - AI Deployment Strategy

  • The AI 4.0 Programme is primarily a strategy and does not impose statutory penalties.
  • Non-compliance with programme recommendations may affect eligibility for public funding or participation in public pilots and procurement.
  • Sectoral statutory penalties and liabilities continue to apply under existing law (e.g., product safety, data protection).
  • Reputational and commercial consequences for organisations that ignore recommended ethical and governance practices.

Per Finland - AI in Health Sector

  • Hyteairo itself is a strategic programme and does not impose direct statutory penalties; instead, non‑compliance with binding laws (e.g., GDPR, MDR, national health and patient safety regulations) may trigger enforcement by the competent authorities under those laws.
  • Potential penalties for breaches of GDPR (fines and corrective measures) remain applicable to data controllers/processors involved in AiRo projects.
  • Medical Devices Regulation non‑compliance (where applicable) can lead to market withdrawal, corrective action and sanctions under EU and national frameworks.
  • Professional or administrative sanctions may apply under Finnish healthcare regulations where clinical governance or patient safety requirements are breached.
  • Civil and product liability claims remain available to injured parties under Finnish law and EU product liability regimes.

Per Finland - Helsinki - AI Register

  • The AI Register is a municipal transparency policy and does not itself prescribe statutory fines; non-compliance is addressed through internal administrative and procurement remedies.
  • Failure to observe data protection requirements in systems documented in the register may trigger investigations and sanctions under GDPR enforced by national data-protection authorities. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2016/679/art_26/oj/eng?utm_source=openai))
  • Contractual or procurement breaches identified via register documentation may result in supplier-level contractual remedies or procurement sanctions in accordance with City procurement rules.

Per Finland - Human-Centric AI Programme

  • No new statutory penalties were established by AuroraAI itself (it is a strategy/programme).
  • Existing sanctions under GDPR and Finnish administrative law apply to implementers that breach data protection or legal obligations.
  • Non‑compliance with procurement rules or misuse of public funds could trigger administrative or financial consequences under existing public sector oversight regimes.

Per Finland - AI Business Programme (2018)

  • Repayment (clawback) of disbursed funds where misuse or material misrepresentation is proven.
  • Suspension of payments and project activities pending remediation or audit.
  • Termination of funding contract and immediate cessation of programme support.
  • Exclusion from future Business Finland funding opportunities for a defined period.
  • Administrative audit and potential reporting to other competent authorities if legal breaches (e.g., GDPR violations) are discovered.

Per Finland - AI Impact on Work (21/2018)

  • The strategy itself does not establish statutory penalties; it recommends follow-on regulatory review where legal gaps emerge (e.g., data protection or discrimination), which would be enforced under existing legislation.
  • Administrative or contractual remedies may apply in later instrument-specific regulations or procurement rules implementing the strategy.
  • If subsequent binding measures are developed (e.g., procurement rules), non-compliance would be subject to the penalties specified in those instruments.

Per Finland - National AI Programme

  • The Strategy is non-legislative and does not itself prescribe penalties. Existing sectoral laws (data protection, health, safety, procurement) govern enforcement and penalties where applicable.

Per Finland - National AI Strategy (2017)

  • The 2017 strategy itself imposes no new statutory penalties — it is a non-binding policy roadmap.
  • Enforcement of legal obligations (e.g., GDPR breaches) remains subject to existing regulatory sanctions under Finnish and EU law.
  • Potential indirect consequences for non-compliance with programme funding terms (e.g., withdrawal of public funding or contractual remedies).
  • Sectoral regulators may apply sector-specific enforcement for breaches of existing sector laws (healthcare, finance, safety).

Finland overview

The full picture of AI regulation in Finland, beyond just the EU AI Act.

Finland AI regulation overview →