Denmark - AI Regulatory Sandbox
Regulatory Sandbox for Artificial Intelligence
Regulatorisk sandkasse for AI
Denmark
RAI-DK-NA-RSAIRXX-2024The Regulatory Sandbox for AI is a joint initiative by the Danish Data Protection Authority (Datatilsynet) and the Danish Agency for Digitisation (Digitaliseringsstyrelsen) to provide project-specific, practice-oriented guidance on GDPR and AI Act risk classification. It offers eligible public and private organisations tailored advice, an iterative four-month engagement model, and publication of lessons learned to support lawful and responsible AI development.
Summary
Read full text ↗Plain English
Overview
The Regulatory Sandbox for AI ("Regulatorisk sandkasse for AI") is a joint initiative by the Danish Data Protection Authority and the Danish Agency for Digitisation to provide hands-on, project-level guidance for organisations developing or using AI systems that process personal data or fall within the scope of the EU AI Act. Announced on 5 March 2024, the sandbox aims to reduce uncertainty, shorten time-to-market for compliant solutions, and produce case-based learning shared with the wider ecosystem. Participants receive free, tailored advice on GDPR compliance, risk classification under the AI-forordningen and practical mitigations. The sandbox offers a structured advisory engagement (typically ~4 months) with a start-up meeting, up to four targeted sessions, follow-up work between meetings, and a joint closing report that balances transparency with protection of confidential business information. Final summaries and anonymised reports are published to ensure that other actors can benefit from the lessons learned. The sandbox is open to public authorities, private companies and other organisations; applicants are selected based on potential public value and replicability of lessons. Details and application materials are published on both agencies' websites: Datatilsynet - Regulatory Sandbox and Digitaliseringsstyrelsen - Regulatory Sandbox.
Definitions
Key terms used by the sandbox align with national and EU definitions. "AI" follows the operational framing used in national guidance and the EU AI Act for systems that perform tasks by processing data to achieve goals. "Participant" means any applying organisation (private company, public authority, NGO). "Sandbox engagement" denotes the structured advisory process (intake, advisory sessions, reporting). "Risikoklassifikation" refers to determining whether a system is unacceptable, high-risk, limited risk, or minimal risk under the AI-forordningen. "DPIA" (Data Protection Impact Assessment) and "technical/organisational measures" are used per GDPR. Confidentiality and publication rules are governed by public access legislation but generally allow anonymisation of sensitive information in final reports. These definitions and the sandbox’s scope are available in the agencies’ public guidance pages referenced above.
Governance and Institutional Framework
The sandbox is jointly administered by Datatilsynet (the Danish Data Protection Authority) and Digitaliseringsstyrelsen (the Danish Agency for Digitisation). Datatilsynet leads on GDPR and data-protection oversight and contributes supervisory expertise; Digitaliseringsstyrelsen brings AI policy, public-sector digitalisation and AI-forordningen coordination experience, and it has been designated as Denmark’s national coordinating authority for the EU AI Act. Operational governance includes an intake and selection committee drawn from both agencies and, when relevant, invitations to sectoral ministries or supervisory bodies to contribute their sectoral expertise (e.g., health, social services). The sandbox’s outputs include bespoke participant guidance and anonymised public reports intended to inform future supervisory guidance and legislative development. Both agencies are subject to Denmark’s Freedom of Information rules and statutory confidentiality obligations; the sandbox’s communication policy explains which parts of a dossier can be withheld or redacted for public disclosure. The institutional set-up explicitly positions the sandbox as a non-binding advisory process — it does not suspend or replace statutory obligations or enforcement powers under GDPR or sectoral law (Datatilsynet Sandbox Page).
Key Focus Areas
The sandbox concentrates on practical regulatory intersections encountered in real projects. Primary focus areas include: (1) personal data protections under GDPR — lawfulness, purpose limitation, data minimisation, storage limitation and DPIAs; (2) classification under the EU AI Act — identifying whether a system is high-risk, limited-risk or prohibited for certain uses; (3) transparency obligations and user information requirements, including human oversight and opt-outs; (4) documentation and accountability — development of documentation packages, model cards and records of processing; (5) security and model robustness including measures to mitigate adversarial risks, supply-chain risks and data breaches; (6) fairness and fundamental rights impact, including bias mitigation and monitoring; and (7) sectoral interface issues (health, social services, employment, finance) where sector laws may impose additional constraints or reporting obligations. In practice, sandbox engagements deliver pragmatic recommendations: e.g., scope and content of DPIAs, tailored logging and monitoring regimes, approaches to user and data subject notices, contractual clauses with vendors, techniques for differential access to training data, and deployment-stage checks. The sandbox also supports early-stage risk classification while the AI Act’s detailed implementing rules are still being phased in, offering a bridge between current GDPR obligations and the forthcoming AI Act requirements. The agencies emphasise that their findings will be used to improve guidance and supervisory readiness at national level.
Implementation Framework
Application is through a published application form; Datatilsynet and Digitaliseringsstyrelsen run selection rounds with explicit deadlines (for example, application rounds were open in 2024 and 2025). The typical engagement lasts approximately four months but may be adapted to project complexity. The process follows these steps: (1) submission of an application and baseline documentation (project description, data flows, intended processing, risk assessments); (2) intake meeting to set objectives and a project plan; (3) up to four structured advisory sessions with assigned case officers and technical experts; (4) iterative work between sessions where participants implement agreed actions or provide additional materials; and (5) a closing session and a joint final report capturing findings, mitigations and anonymised lessons for publication. Participants must allocate sufficient internal resources, agree to co-produce the final report content, and comply with reasonable requests for information. Confidential business information can be protected where permitted under public access rules, and the agencies provide guidance on publication and redaction. The sandbox may draw on external experts or invite sectoral regulators as needed. Engagements are non-binding: formal regulatory compliance and enforcement remain available under existing law.
Monitoring and Evaluation
The sandbox includes internal monitoring and iterative evaluation to ensure outcomes are documented and actionable. Each engagement produces a project plan with measurable deliverables and milestones. Datatilsynet and Digitaliseringsstyrelsen compile anonymised lessons and prepare post-engagement reports summarising technical and legal findings, common pitfalls and recommended mitigations. These outputs feed into agency workstreams for guidance updates, supervisory practice development and public outreach. The agencies also track participation metrics (number of applications, sectors represented, proportion of public/private participants) and qualitative indicators (transferability of recommendations, number of published reports). Where valuable, the sandbox will solicit participant feedback and incorporate it into process improvements. Published final reports and summaries serve as an external evaluation mechanism, enabling stakeholders to assess the sandbox’s value and effectiveness over time.
Penalties, Liability, and Appeals
The sandbox is an advisory and collaborative mechanism and does not create new penalty regimes. Participants remain fully subject to statutory obligations under GDPR, sectoral laws and — when applicable — provisions of the EU AI Act. Where sandbox engagements reveal non-compliance, Datatilsynet retains its full investigative and enforcement powers (corrective orders, warnings, requirements to bring processing into compliance, and administrative fines under GDPR). The Digitaliseringsstyrelsen, as the national coordinating authority for the AI Act, will apply applicable enforcement measures for AI Act infringements in accordance with national procedures. Participants are informed that sandbox participation does not shield against enforcement, and any formal supervisory action follows standard decision-making and appeal routes under Danish administrative law. The agencies’ public statements make this clear and emphasise that the sandbox’s principal value is proactive compliance assistance rather than legal immunity.
Relationship to Other Instruments
The sandbox is positioned at the intersection of multiple legal instruments: the GDPR, Danish data protection law, sector-specific statutes (health, social, employment, financial regulation), and the EU AI Act (AI-forordningen). It complements existing guidance and templates such as DPIA templates and public-sector AI guidance published by Datatilsynet and Digitaliseringsstyrelsen. The sandbox seeks to operationalise these instruments in concrete projects and to provide consistent interpretation where rules overlap. Outputs are intended to inform future guidance documents and supervisory methodologies. Where the sandbox identifies legislative or regulatory gaps, the agencies may feed that evidence into policy discussions with ministries and the parliament to improve legal clarity. The initiative also coordinates with European supervisory developments to maintain alignment with EDPB and EU-level AI guidance work.
International Alignment
Denmark’s sandbox is explicitly designed to align with EU-level instruments and evolving international practice. It references and operationalises the EU AI Act's risk categories (prohibited uses, high-risk systems, transparency obligations) insofar as they are already applicable, and it prepares participants for upcoming AI Act requirements. The sandbox also monitors trends in other national sandboxes and international guidance (e.g., EDPB, European Commission, and other national data protection authorities) to harmonise approaches and share lessons. By publishing anonymised final reports and lessons learned, the sandbox contributes to cross-border learning and provides inputs to pan-European supervisory dialogues. The Danish approach emphasises coordination with the European supervisory community to support predictability for developers and deployers of AI across jurisdictions.
Implementation Timeline
| Event | Date |
|---|---|
| Government digitalisation strategy announces measures leading to sandbox | 2023-11-16 |
| Public announcement of sandbox by Datatilsynet and Digitaliseringsstyrelsen | 2024-03-05 |
| First application round deadline (2024 round) | 2024-05-21 |
| First round project selections announced | 2024-07-08 |
| Second round opened for applications | 2025-03-03 |
| Second round selection announced | 2025-06-18 |
Compliance Checklist
| Requirement | Yes/No |
|---|---|
| Submit completed application and project description | Yes |
| Provide data flow diagrams and DPIA (if applicable) | Yes |
| Participate in intake meeting and planning | Yes |
| Allocate internal resources for follow-up work | Yes |
| Cooperate with reasonable requests from agencies | Yes |
| Agree on publication / redaction of final report | Yes |
| Implement agreed mitigations where feasible | Yes |
Sources and References
| Source | Type |
|---|---|
| Datatilsynet - Regulatorisk sandkasse for AI | Primary Source |
| Datatilsynet - Press release 5 March 2024 | Primary Source |
| Digitaliseringsstyrelsen - Regulatorisk sandkasse for AI | Primary Source |
| Datatilsynet - First round selections (8 July 2024) | Primary Source |
| Datatilsynet - Second round open (3 March 2025) | Primary Source |
Denmark's Regulatory Sandbox for AI provides project-specific, practical guidance to public and private organisations developing or using AI systems that process personal data or fall under the EU AI Act. Launched in March 2024 by the Danish Data Protection Authority (Datatilsynet) and the Danish Agency for Digitisation (Digitaliseringsstyrelsen), this initiative aims to clarify complex regulations, reduce uncertainty, and accelerate the development of lawful and responsible AI solutions.
Any public authority, private company, or other organisation can apply to participate in the sandbox. If selected, you'll receive free, tailored advice over an approximately four-month engagement. The focus areas include ensuring compliance with the General Data Protection Regulation (GDPR), correctly classifying AI system risks under the EU AI Act, meeting transparency obligations, and developing robust documentation. Your organisation's main "obligations" as a participant are to: - Submit a detailed application and project description. - Actively participate in intake and advisory sessions. - Allocate internal resources to implement agreed actions and provide necessary information. - Co-produce a final report with the agencies.
A critical point for participants is that the sandbox is an advisory service, not a shield from legal responsibility. It does not suspend or replace your existing statutory obligations under GDPR or the EU AI Act. Both Datatilsynet and Digitaliseringsstyrelsen retain their full investigative and enforcement powers, meaning participation offers no immunity from potential penalties if non-compliance is discovered. A practical surprise for some might be that while confidential business information is protected, anonymised summaries of lessons learned from each project are published. This ensures the wider AI community benefits from the insights gained, fostering a more compliant ecosystem. Application rounds are held periodically, with the first projects selected in July 2024 and a second round opening in March 2025.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 7 marked completePlain-English obligations under Denmark - AI Regulatory Sandbox. Not legal advice — verify against the official text before relying on it.
- #1ImportantImplementation Framework⏰ Before application deadline
Applies to: Organizations applying to the AI Regulatory Sandbox.
“submission of an application and baseline documentation (project description, data flows, intended processing, risk assessments)”
- #2ImportantImplementation Framework⏰ Before application deadline
Applies to: Organizations applying to the AI Regulatory Sandbox.
“submission of an application and baseline documentation (project description, data flows, intended processing, risk assessments)”
- #3ImportantImplementation Framework
Applies to: Organizations selected for the AI Regulatory Sandbox.
“intake meeting to set objectives and a project plan”
- #4ImportantImplementation Framework
Applies to: Organizations participating in the AI Regulatory Sandbox.
“Participants must allocate sufficient internal resources, agree to co-produce the final report content, and comply with reasonable requests for information.”
- #5ImportantImplementation Framework
Applies to: Organizations participating in the AI Regulatory Sandbox.
“comply with reasonable requests for information”
- #6ImportantImplementation Framework⏰ Before closing session
Applies to: Organizations participating in the AI Regulatory Sandbox.
“agree to co-produce the final report content”
- #7ImportantImplementation Framework
Applies to: Organizations participating in the AI Regulatory Sandbox.
“iterative work between sessions where participants implement agreed actions or provide additional materials”
Related Regulations
Datatilsynet Regulatory Sandbox for privacy-friendly innovation and AI (Sandbox for Responsible AI)
Norway96% similar
AI Regulatory Sandbox Policy
Lithuania92% similar
Digitaliseringsstyrelsen Guides for Responsible Use of Generative AI (Guides til ansvarlig anvendelse af generativ kunstig intelligens)
Denmark91% similar
National AI Sandbox (first Spanish EU AI sandbox / Entorno de pruebas de Inteligencia Artificial)
Spain91% similar
Datatilsynet Guidance: Public Authorities' Use of Artificial Intelligence – 'Before You Start' (Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang)
Denmark91% similar
© Regulations.AI — created on 13-Jun-2026