Denmark - Responsible Generative AI Guidelines
Digitaliseringsstyrelsen Guides for Responsible Use of Generative AI
Digitaliseringsstyrelsen Guides til ansvarlig anvendelse af generativ kunstig intelligens
Denmark
RAI-DK-NA-DGRUGXX-2024In January 2024 Digitaliseringsstyrelsen (the Danish Agency for Digital Government) published short, practical guides for public authorities and private companies on responsible use of generative AI. The documents set out management responsibilities, three-step implementation advice (approach, rules, organisational arrangements), data- and security-related cautions, and recommendations for ongoing updates and risk-based oversight. (digst.dk)
Summary
Read full text ↗Plain English
Overview
The Digitaliseringsstyrelsen guides published in January 2024 provide short, practical, organisational guidance for responsible adoption of generative AI by public authorities and private businesses in Denmark. They present clear, managerial-first advice: senior management should own the policy choices, organisations should classify how AI will be used (general vs. specialised), create tailored rules for staff, and set up the organisational capacity to test, validate and monitor AI use. The guides are explicitly designed to be updated as the technology and the legal framework evolve and to serve as an accessible starting point for internal governance rather than as technical standards or legally binding regulation. For the official announcement and to download the guides, see Digitaliseringsstyrelsen news release (09.01.2024). ([digst.dk](https://digst.dk/nyheder/nyhedsarkiv/2024/januar/nye-guides-til-ansvarlig-anvendelse-af-generativ-kunstig-intelligens/?utm_source=openai))
Definitions
The guides define key terminology with concise descriptions to help non-technical leaders: "generative AI" (models that produce text, images, audio, video or code from prompts), "foundation models" (large models trained on broad data that can be adapted to many tasks), "prompts" (user inputs to generate outputs), and distinctions between "open source" and "closed source" models and between cloud services and locally deployed models. The documents emphasize that generative AI is statistical in nature — it predicts likely outputs rather than reveals facts — which underlies risks such as hallucinations and outdated or incorrect outputs. These definitions are aligned with the explanatory sections on the guides' web pages and downloadable PDFs. ([digst.dk](https://digst.dk/kunstig-intelligens/guides-til-brug-af-kunstig-intelligens/guide-til-virksomheder/))
Governance and Institutional Framework
Digitaliseringsstyrelsen places governance responsibility at the level of senior management: organisations should treat responsible AI as a leadership task, ensuring allocation of resources and clear roles for policy, procurement, cybersecurity, legal review and operational rollout. The guides recommend a three-step governance workflow: 1) decide on an approach to AI use (scope and modality), 2) draft and publish organisational rules and guidelines adapted to that approach, and 3) build organisational capacity (training, designated owners, processes for testing and validation). For public authorities, the guides underline additional administrative obligations such as confidentiality and procedural fairness; for private companies they highlight contractual and IP considerations. The guidance also points readers to Digitaliseringsstyrelsen's other materials and preparatory resources as Denmark aligns with the EU AI Act and national oversight planning (guides index). ([digst.dk](https://digst.dk/kunstig-intelligens/guides-til-brug-af-kunstig-intelligens/guide-til-virksomheder/))
Key Focus Areas
The guides concentrate on risk-aware decision-making across multiple domains: (a) Accuracy & reliability — recognising hallucinations and designing human validation and fact-checking processes; (b) Bias & fairness — screening for discriminatory outputs and ensuring oversight where decisions affect people; (c) Data protection & confidentiality — avoiding input of personal data or trade secrets to third-party, free cloud models and carrying out DPIA-like considerations; (d) Security — preventing leakage of sensitive data and ensuring secure integration with enterprise systems; (e) Vendor & contract risk — obtaining contractual assurances about data use, retention and model training rights; and (f) Organisational readiness — staff training, logging and documentation. Practical mitigations are provided for each focus area — e.g. human in the loop, limited prompt scopes, using paid/enterprise services with stricter contracts, running models locally for sensitive use-cases, and maintaining audit trails of outputs and decisions. The approach is intentionally pragmatic: short guidance items and checklists that managers can adapt to their organisational context. ([digst.dk](https://digst.dk/media/kz3dgblm/guide-til-virksomheder-om-generativ-kunstig-intelligens.pdf))
Implementation Framework
The guides give a stepwise implementation path: start with an inventory and classification of use-cases (who, what, sensitivity), select an approach (general availability for staff or project-specific deployments), draft retningslinjer (internal rules) addressing permitted uses and prohibitions (e.g., do not enter personal data into public free services), and create organisational arrangements (designated owners, resources for testing, training and monitoring). They recommend concrete contractual checks when procuring cloud or SaaS AI services, including clauses on provider rights to use prompts and outputs, data retention, and model training. For high-sensitivity or regulated contexts the guides point to the option of local deployment or use of enterprise-grade offerings with stronger data protections. Implementation includes templates for communication to staff, training content, and a cadence for rule reviews. ([digst.dk](https://digst.dk/media/kz3dgblm/guide-til-virksomheder-om-generativ-kunstig-intelligens.pdf))
Monitoring and Evaluation
Monitoring focuses on tracking both technical performance (error rates, drift, hallucination incidents) and governance metrics (policy adherence, incident reports, vendor contract compliance). The guides recommend logging usage where feasible, maintaining records of decisions to rely on AI outputs, periodic review of model outputs for bias or inaccuracy, and mechanisms for users to report problems. For public bodies, continued review is also recommended to ensure compliance with administrative law obligations. Digitaliseringsstyrelsen indicates the guides will be updated based on experience and changes in legal requirements, and organisations are advised to treat monitoring as a continuous learning process rather than a one-off activity. ([digst.dk](https://digst.dk/media/0x5ptreb/guide-til-offentlige-myndigheder-om-ansvarlig-anvendelse-af-generativ-kunstig-intelligens.pdf))
Penalties, Liability, and Appeals
As non-binding guidance, the Digitaliseringsstyrelsen documents do not themselves introduce penalties. However the guides stress that failure to follow recommended practices can increase legal and regulatory exposure under existing frameworks — for example, GDPR obligations on personal data handling, procurement and contract law risks, sector-specific regulation (healthcare, finance), and administrative law for public authorities. Digitaliseringsstyrelsen therefore frames the guidance as risk mitigation: following the practices reduces the likelihood of regulatory enforcement, contractual liability and reputational harm. Organisations should therefore link their AI governance to their legal/compliance functions and maintain records that can support defence or remediation in case of complaints or audits. ([digst.dk](https://digst.dk/media/kz3dgblm/guide-til-virksomheder-om-generativ-kunstig-intelligens.pdf))
Relationship to Other Instruments
The guides are explicitly positioned as complementary to other Danish and EU instruments: they reference Denmark's national AI strategy and preparatory work for the EU AI Act, and should be used together with sector-specific rules, the GDPR, and national data protection guidance (Datatilsynet). Digitaliseringsstyrelsen signals that its guides are intended to help organisations prepare for future binding obligations under the EU AI Act and to operationalise existing obligations under privacy and administrative law. Where technical standards, conformity assessment or registration obligations appear under EU law, organisations will need to move beyond these guides to formal assessments and documentation. For more on related instruments see Digitaliseringsstyrelsen's AI pages and EU resources. ([digst.dk](https://digst.dk/kunstig-intelligens/guides-til-brug-af-kunstig-intelligens/guide-til-virksomheder/))
International Alignment
The approach in the guides follows commonly emphasised principles across EU and OECD guidance: risk-based oversight, human oversight for critical uses, protection of fundamental rights, data protection compliance and contractual due diligence with vendors. Digitaliseringsstyrelsen expressly notes alignment with the expected requirements of the EU AI Act and positions the guides as preparatory and pragmatic steps to help organisations comply with future binding rules. Organisations with international operations are advised to map these recommendations to other jurisdictions' rules and to use contractual and technical measures to harmonise compliance across borders. See Digitaliseringsstyrelsen's guidance index and the EU AI Act preparatory materials for further crosswalks. ([digst.dk](https://digst.dk/kunstig-intelligens/guides-til-brug-af-kunstig-intelligens/guide-til-virksomheder/))
Implementation Timeline
| Milestone | Suggested timeframe | Notes |
|---|---|---|
| Initial awareness and inventory | 0-3 months | Map existing uses and informal staff activity; quick wins: communications and immediate prohibitions (e.g., no personal data in public tools) |
| Draft internal rules & procurement checks | 1-4 months | Establish permitted tools, vendor clause templates and human validation requirements |
| Pilot projects & security testing | 2-6 months | Run supervised pilots, security / privacy tests and user training |
| Full organisational roll-out | 6-12 months | Scale solutions where risk-mitigations are demonstrated; keep sensitive uses restricted |
| Ongoing monitoring & review | Continuous, quarterly reviews | Adapt to model updates, legal changes (notably EU AI Act timelines) and operational experience |
Compliance Checklist
| Item | Yes/No | Notes |
|---|---|---|
| Senior management assigned responsibility | Make role and owner explicit | |
| Inventory of use-cases and sensitivity classification | Record: who, what, data types used | |
| Internal rules for permitted/prohibited use | Include explicit ban on entering personal/confidential data to public tools | |
| Vendor due diligence and contract clauses | Data retention, usage rights, training rights | |
| Human-in-the-loop / validation for critical outputs | Define thresholds for manual review | |
| Logging, documentation and record-keeping | Retention policy aligned with legal obligations | |
| Training plan for staff | Regular sessions and update materials |
Sources and References
The Danish Agency for Digital Government (Digitaliseringsstyrelsen) has published practical guides to help public authorities and private companies in Denmark use generative artificial intelligence (AI) responsibly. These guides, effective from January 2024, apply to any Danish public authority or private business considering or already using generative AI. They emphasize that senior management must take ownership of AI policy, allocating resources and defining clear roles for its safe adoption.
Organisations are expected to develop internal rules for staff, specifying permitted uses and strict prohibitions, such as never inputting personal data or confidential information into free, public generative AI tools. Furthermore, companies must establish robust processes for testing, validating, and continuously monitoring AI use and its outputs to ensure accuracy, fairness, and data security. This includes maintaining audit trails and ensuring human oversight for critical decisions.
While these guides are not legally binding in themselves, Digitaliseringsstyrelsen stresses that failing to follow their recommendations significantly increases an organisation's exposure to existing laws, such as the General Data Protection Regulation (GDPR), contract law, and sector-specific regulations. This means that ignoring the guidance could lead to regulatory enforcement, contractual liability, or reputational damage. A key takeaway is that generative AI is statistical, predicting likely outputs rather than stating facts, which means human oversight and validation are crucial to mitigate risks like "hallucinations" or incorrect information. The guides are designed to be updated regularly, helping organisations prepare for future binding obligations, like those expected under the EU AI Act.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under Denmark - Responsible Generative AI Guidelines. Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: All organisations using generative AI.
“avoiding input of personal data or trade secrets to third-party, free cloud models”
- #2Critical
Applies to: Public authorities using generative AI.
“For public authorities, the guides underline additional administrative obligations such as confidentiality and procedural fairness”
- #3Important
Applies to: All organisations using generative AI.
“Digitaliseringsstyrelsen places governance responsibility at the level of senior management: organisations should treat responsible AI as a leadership task”
- #4Important
Applies to: All organisations using generative AI.
“start with an inventory and classification of use-cases (who, what, sensitivity)”
- #5Important
Applies to: All organisations using generative AI.
“draft retningslinjer (internal rules) addressing permitted uses and prohibitions”
- #6Important⏰ Before procuring AI services
Applies to: Organisations procuring cloud or SaaS AI services.
“recommend concrete contractual checks when procuring cloud or SaaS AI services, including clauses on provider rights to use prompts and outputs, data retention, and model training.”
- #7Important
Applies to: All organisations using generative AI.
“Accuracy & reliability — recognising hallucinations and designing human validation and fact-checking processes”
- #8Important
Applies to: All organisations using generative AI.
“Bias & fairness — screening for discriminatory outputs and ensuring oversight where decisions affect people”
- #9Important
Applies to: All organisations using generative AI.
“Security — preventing leakage of sensitive data and ensuring secure integration with enterprise systems”
- #10Important
Applies to: All organisations using generative AI.
“logging usage where feasible, maintaining records of decisions to rely on AI outputs”
- #11Important
Applies to: All organisations using generative AI.
“Organisational readiness — staff training”
Related Regulations
Datatilsynet Guidance: Public Authorities' Use of Artificial Intelligence – 'Before You Start' (Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang)
Denmark94% similar
National Strategy for Artificial Intelligence (National strategi for kunstig intelligens)
Denmark92% similar
Responsible AI Guidance for the Public Service: GenAI
New Zealand92% similar
Strategic Approach for Artificial Intelligence (Strategisk indsats for kunstig intelligens)
Denmark92% similar
Regulatory Sandbox for Artificial Intelligence (Regulatorisk sandkasse for AI) – Datatilsynet & Digitaliseringsstyrelsen
Denmark91% similar
© Regulations.AI — created on 13-Jun-2026