Finland AI Act Implementation Law
Act on the Implementation of the Artificial Intelligence Act
Laki tekoälyasetuksen toimeenpanosta
Finland
RAI-FI-NA-HE10320-2024HE 103/2024 vp
Finland's national legislation implementing the EU AI Act and establishing domestic oversight authorities.
Summary
Read full text ↗Plain English
Overview
The Act on the Implementation of the Artificial Intelligence Act (Laki tekoälyasetuksen toimeenpanosta) represents Finland's primary legislative vehicle for integrating the European Union’s AI Act (Regulation (EU) 2024/1689) into its national legal framework. Enacted to ensure that the Finnish market remains both innovative and safe, the law establishes the necessary administrative structures to oversee the development, deployment, and use of artificial intelligence systems within the country. The Finnish government, primarily through the Ministry of Economic Affairs and Employment, designed this legislation to balance the stringent safety requirements of the EU mandate with Finland’s national interest in maintaining its position as a leading digital economy. By providing a clear legal basis for national competent authorities, the Act ensures that Finnish businesses and public sector entities have a predictable regulatory environment in which to operate, while simultaneously protecting the fundamental rights of citizens as enshrined in both the Finnish Constitution and the EU Charter of Fundamental Rights. Beyond mere compliance with Brussels, this Act serves as a cornerstone for Finland's broader digital strategy. It addresses the specificities of the Finnish administrative landscape, ensuring that existing regulators—such as the Finnish Transport and Communications Agency (Traficom) and the Office of the Data Protection Ombudsman—have the explicit legal mandates and budgetary authorizations required to perform market surveillance. The legislation also emphasizes the 'innovation-friendly' approach characteristic of Nordic governance, incorporating provisions for regulatory sandboxes that allow Finnish startups and research institutions to test high-risk AI systems under controlled conditions. This proactive stance is intended to mitigate the 'chilling effect' of regulation, ensuring that the high bars set for high-risk AI systems do not stifle the growth of the local tech ecosystem. Consequently, the Act is not just a restrictive document but a strategic framework for the ethical and competitive evolution of AI in Finland.
Definitions
The Act adopts the harmonized definitions provided by the EU AI Act but provides specific contextualization for the Finnish legal context. An 'AI system' is defined as a machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This definition is interpreted in alignment with the Finnish Administrative Procedure Act to ensure that when AI is used in public decision-making, the principles of good governance are maintained. The Act further distinguishes between 'providers' (those who develop AI systems or have them developed with a view to placing them on the market under their own name) and 'deployers' (those using an AI system under their authority, except where the system is used in the course of a personal non-professional activity). Crucially, the Finnish legislation provides specific clarity on 'high-risk AI systems,' particularly those used in critical infrastructure, education, employment, and law enforcement. The definitions section also clarifies the role of 'national competent authorities,' which in the Finnish context includes the Market Surveillance Authority and the Notifying Authority. By explicitly defining these roles, the Act prevents jurisdictional overlap and provides a clear point of contact for stakeholders. Furthermore, the Act defines 'substantial modification' in a way that aligns with Finnish product safety laws, ensuring that any significant change to an AI system’s purpose or risk profile triggers a new conformity assessment. These definitions serve as the bedrock for the enforcement mechanisms detailed later in the document, providing the legal certainty required for judicial review and administrative appeals.
Governance and Institutional Framework
The governance structure established by the Act is centralized yet collaborative, reflecting Finland’s efficient administrative tradition. The Finnish Transport and Communications Agency (Traficom) is designated as the primary Market Surveillance Authority (MSA) for AI. In this capacity, Traficom is responsible for monitoring the market, conducting inspections, and ensuring that AI systems placed on the Finnish market comply with the safety and transparency requirements of the EU AI Act. Traficom’s role is augmented by its existing expertise in digital infrastructure and cybersecurity, making it a natural fit for overseeing complex algorithmic systems. To support this, the Act grants Traficom the power to access the source code of high-risk AI systems when necessary to assess compliance, subject to strict confidentiality and intellectual property protections. In addition to Traficom, the Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) plays a pivotal role, particularly regarding AI systems that process personal data or impact fundamental rights. The Act establishes a formal cooperation mechanism between these two bodies to ensure that AI supervision does not conflict with GDPR enforcement. Furthermore, the Ministry of Economic Affairs and Employment acts as the 'Notifying Authority,' responsible for setting up and carrying out the necessary procedures for the assessment, designation, and notification of conformity assessment bodies. This multi-layered framework is designed to provide comprehensive oversight while avoiding the creation of entirely new, siloed bureaucracies. A national AI coordination group is also established to facilitate information sharing between various sector-specific regulators, ensuring a unified Finnish voice in the EU's European Artificial Intelligence Board.
Key Focus Areas
One of the primary focus areas of the Act is the regulation of high-risk AI systems and the absolute prohibition of certain AI practices deemed to pose an unacceptable risk. In accordance with EU standards, the Finnish Act prohibits AI systems that use subliminal techniques to distort behavior, exploit vulnerabilities of specific groups, or implement social scoring by public authorities. Finland has taken a particularly firm stance on the use of real-time remote biometric identification in publicly accessible spaces for law enforcement, strictly limiting its use to the narrow exceptions allowed under the EU framework and requiring prior judicial authorization from a Finnish court. This reflects the high value placed on privacy and civil liberties within Finnish society. Another key focus area is the support for innovation through regulatory sandboxes. The Act mandates the creation of at least one national AI regulatory sandbox, which is to be operational by mid-2025. These sandboxes provide a structured environment where providers can develop and test innovative AI systems for a limited period under the direct supervision of Traficom and other relevant authorities. This focus area is designed to assist small and medium-sized enterprises (SMEs) and startups in navigating the complex compliance requirements of high-risk AI. By providing guidance on technical documentation and risk management during the development phase, the Finnish government aims to reduce the time-to-market for safe and ethical AI solutions, thereby fostering a competitive advantage for the Finnish technology sector.
Implementation Framework
The implementation of the Act is phased to align with the transition periods established by the European Union. The Finnish government has adopted a 'digital-first' implementation strategy, utilizing existing electronic portals for the registration of high-risk AI systems and the reporting of incidents. The Act requires providers of high-risk AI systems to register themselves and their systems in a centralized EU database, but the Finnish authorities provide a national interface to assist with this process. Implementation also involves a significant training component; the Act authorizes the allocation of resources to train civil servants and judicial officers on the technical nuances of AI, ensuring that the 'human-in-the-loop' requirement is not just a legal formality but a practical reality in Finnish administration. Furthermore, the implementation framework emphasizes transparency and public engagement. The Act requires the Market Surveillance Authority to publish annual reports on its activities, including the number of inspections conducted and the types of non-compliance identified. This transparency is intended to build public trust in AI technologies. For public sector deployers, the Act introduces additional transparency obligations, such as the requirement to inform citizens when they are interacting with an AI system in an administrative process. This is integrated with the Finnish Act on the Openness of Government Activities, ensuring that the use of algorithms in the public sector remains accountable to the citizenry. The implementation is supported by a dedicated budget line within the national budget to ensure that the designated authorities have the technical tools and personnel required for effective oversight.
Monitoring and Evaluation
Monitoring under the Act is both proactive and reactive. Traficom is empowered to conduct market surveillance through random checks, targeted inspections, and the review of technical documentation. The Act establishes a 'Post-Market Monitoring' (PMM) system, where providers of high-risk AI systems must actively collect and analyze data on the performance of their systems throughout their lifetime. If a system is found to present a risk at the national level, the Act provides a clear procedure for the authority to require the provider to bring the system into compliance, withdraw it from the market, or recall it. This monitoring extends to 'general-purpose AI' (GPAI) models, where the Finnish authorities cooperate with the European AI Office to monitor systemic risks. Evaluation of the Act’s effectiveness is scheduled to occur at regular intervals. The Ministry of Economic Affairs and Employment is required to conduct a comprehensive review of the Act every two years. This evaluation focuses on whether the governance structure is functioning efficiently, whether the administrative burden on SMEs is proportionate, and how the Act has impacted the adoption of AI in Finland. These reviews will incorporate feedback from a permanent stakeholder advisory forum, which includes representatives from industry, academia, and civil society. The findings of these evaluations are presented to the Finnish Parliament (Eduskunta), ensuring that the legislative framework can be iteratively improved as AI technology continues to evolve at a rapid pace.
Penalties, Liability, and Appeals
The Act introduces a robust system of administrative fines for non-compliance, directly mirroring the ceilings set by the EU AI Act. For the use of prohibited AI practices, fines can reach up to €35 million or 7% of the total worldwide annual turnover of the preceding financial year, whichever is higher. Non-compliance with requirements for high-risk AI systems can result in fines of up to €15 million or 3% of turnover. The Finnish Act specifies that when determining the amount of the fine, the authorities must consider the nature, gravity, and duration of the infringement, as well as the size of the company, with specific leniency provisions for SMEs and startups to ensure that penalties are proportionate and not existential. Regarding liability, the Act complements existing Finnish tort law and the EU’s proposed AI Liability Directive. It clarifies that the use of AI does not absolve a provider or deployer of their legal responsibilities for damages caused to third parties. Furthermore, the Act ensures that any decision made by the Market Surveillance Authority—such as a fine or a market withdrawal order—is subject to judicial review. Affected parties have the right to appeal decisions to the Administrative Courts of Finland. This ensures that the enforcement of AI regulations adheres to the principles of legal certainty and the right to a fair trial. The Act also provides a mechanism for individuals to lodge complaints with the Market Surveillance Authority if they believe an AI system has infringed upon their rights or violated the provisions of the Act.
Relationship to Other Instruments
The Act on the Implementation of the AI Act does not operate in a vacuum; it is designed to be consistent with a suite of other national and international legal instruments. Most notably, it maintains a strict relationship with the General Data Protection Regulation (GDPR). In cases where AI systems process personal data, the requirements of both the AI Act and the GDPR must be met cumulatively. The Finnish Act explicitly states that the powers of the Data Protection Ombudsman remain unaffected and that the Ombudsman is the lead authority for any AI-related issues that primarily concern the processing of personal data. This prevents 'forum shopping' and ensures a high level of data protection. The Act also interacts with the Finnish Product Safety Act and various sector-specific regulations, such as those governing medical devices, aviation, and motor vehicles. Where AI is integrated into these products, the conformity assessment procedures are streamlined to avoid double-certification, though the specific AI safety requirements must still be verified. Furthermore, the Act is aligned with the Finnish Administrative Procedure Act, ensuring that when AI is used by Finnish authorities, it respects the constitutional requirements for transparency, the right to be heard, and the requirement for reasoned decisions. This holistic approach ensures that the AI Act strengthens, rather than complicates, the existing Finnish legal order.
International Alignment
Finland’s approach to AI regulation is deeply rooted in international cooperation. The Act mandates that Finnish authorities participate actively in the European Artificial Intelligence Board and collaborate with the European AI Office. This ensures that the interpretation of 'high-risk' and 'conformity' remains consistent across the EU Single Market, preventing internal trade barriers. Finland also views this Act as a tool for international standard-setting. By aligning its national standards with those developed by organizations like ISO/IEC and CEN/CENELEC, Finland ensures that its domestic AI industry can easily export products globally. Beyond the EU, Finland uses this legislative framework to engage in bilateral and multilateral dialogues on AI governance, particularly within the Nordic-Baltic region and the OECD. The Act encourages the exchange of best practices regarding market surveillance and regulatory sandboxes with other nations. This international alignment is crucial for addressing the cross-border nature of AI development and deployment. By adhering to high ethical standards and robust oversight, Finland aims to promote a 'European model' of AI—one that is trustworthy, human-centric, and competitive against models that may prioritize state control or pure commercial gain over individual rights.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Entry into Force of EU AI Act | 2024-08-01 | The base Regulation becomes effective across the EU. |
| Prohibition of Unacceptable Risk AI | 2025-02-02 | Deadline for phasing out prohibited AI systems (e.g., social scoring). |
| Designation of National Authorities | 2025-08-02 | Traficom and other bodies formally assume their AI mandates. |
| Operational National AI Sandbox | 2025-10-01 | Finland's first regulatory sandbox becomes open for applications. |
| Full Application for High-Risk AI | 2026-08-02 | Mandatory compliance for all high-risk systems listed in Annex III. |
| First National Review of the Act | 2027-12-31 | Ministry of Economic Affairs completes the first effectiveness report. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Risk Classification | Determine if the AI system falls under Prohibited, High-Risk, or Limited Risk categories. |
| Quality Management System | Establish a system for ensuring data quality and technical compliance for high-risk AI. |
| Technical Documentation | Draft and maintain detailed files as per Annex IV of the EU AI Act. |
| Human Oversight | Design the system to allow for effective intervention and oversight by natural persons. |
| Registration | Register high-risk AI systems in the EU database before placing them on the market. |
| Incident Reporting | Establish a protocol to report serious incidents to Traficom within 15 days. |
| Transparency Disclosure | Ensure users are informed when interacting with AI or viewing AI-generated content. |
Sources and References
| Source | Type |
|---|
Finland's new law implements the European Union's Artificial Intelligence Act, establishing national oversight for AI systems developed, deployed, or used by Finnish businesses and public sector entities.
This legislation applies to anyone providing or deploying AI systems in Finland, from developers creating AI for the market to organizations using AI under their authority. It particularly focuses on "high-risk" AI systems, such as those used in critical infrastructure, education, employment, and law enforcement. The law sets out several key obligations and prohibitions: - It strictly bans AI practices deemed to pose an unacceptable risk, including systems that use subliminal techniques to distort behavior, exploit vulnerabilities, or implement social scoring by public authorities. Real-time remote biometric identification in public spaces is also heavily restricted. - For high-risk AI, providers must conduct conformity assessments, maintain quality management systems, prepare detailed technical documentation, ensure human oversight, and register their systems in an EU database. They must also report serious incidents to the Finnish Transport and Communications Agency (Traficom) within 15 days. - Public sector entities deploying AI must inform citizens when they are interacting with an AI system in an administrative process.
The law takes effect on August 1, 2024, with a phased rollout for different provisions. Prohibitions on unacceptable risk AI begin on February 2, 2025, national authorities like Traficom will be fully designated by August 2, 2025, and full application for high-risk AI systems starts on August 2, 2026.
Non-compliance carries significant penalties. Using prohibited AI systems can result in fines up to €35 million or 7% of a company's global annual turnover, whichever is higher. For other high-risk AI violations, fines can reach €15 million or 3% of turnover. These fines are adjusted based on the severity of the breach and company size, with leniency for smaller businesses. All enforcement decisions can be appealed to Finnish Administrative Courts.
A key practical consideration is the cumulative application of this law with the General Data Protection Regulation (GDPR). If your AI system processes personal data, you must comply with both the AI Act and GDPR requirements, with the Data Protection Ombudsman remaining the lead authority for data privacy issues. Finland also offers regulatory sandboxes, operational by October 1, 2025, allowing companies to test innovative AI under supervision, aiming to foster innovation rather than stifle it.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Finland AI Act Implementation Law. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Feb 2, 2025
Applies to: Providers and deployers of AI systems.
“the Finnish Act prohibits AI systems that use subliminal techniques to distort behavior, exploit vulnerabilities of specific groups, or implement social scoring by public authorities.”
- #2Critical⏰ Feb 2, 2025
Applies to: Law enforcement deployers of real-time remote biometric identification systems.
“requiring prior judicial authorization from a Finnish court.”
- #3Critical⏰ Before placing on market
Applies to: Providers of high-risk AI systems.
“The Act requires providers of high-risk AI systems to register themselves and their systems in a centralized EU database”
- #4Critical
Applies to: Providers of high-risk AI systems.
“Establish a protocol to report serious incidents to Traficom within 15 days.”
- #5Critical
Applies to: Providers of high-risk AI systems.
“any significant change to an AI system’s purpose or risk profile triggers a new conformity assessment.”
- #6Critical⏰ Aug 1, 2024
Applies to: Providers and deployers of AI systems processing personal data.
“In cases where AI systems process personal data, the requirements of both the AI Act and the GDPR must be met cumulatively.”
- #7Important⏰ Aug 2, 2026
Applies to: Providers of high-risk AI systems.
“Establish a system for ensuring data quality and technical compliance for high-risk AI.”
- #8Important⏰ Aug 2, 2026
Applies to: Providers of high-risk AI systems.
“Draft and maintain detailed files as per Annex IV of the EU AI Act.”
- #9Important⏰ Aug 2, 2026
Applies to: Providers of high-risk AI systems.
“Design the system to allow for effective intervention and oversight by natural persons.”
- #10Important⏰ Aug 2, 2026
Applies to: Providers of high-risk AI systems.
“providers of high-risk AI systems must actively collect and analyze data on the performance of their systems throughout their lifetime.”
- #11Important⏰ Aug 2, 2026
Applies to: Deployers of AI systems.
“Ensure users are informed when interacting with AI or viewing AI-generated content.”
- #12Important⏰ Aug 2, 2026
Applies to: Public sector deployers of AI systems.
“the Act introduces additional transparency obligations, such as the requirement to inform citizens when they are interacting with an AI system in an administrative process.”
Related Regulations
Hallituksen esitys eduskunnalle EU:n tekoälyasetusta täydentäväksi lainsäädännöksi (Government Proposal HE 46/2025) — Proposal for national implementing legislation for the EU Artificial Intelligence Act
Finland96% similar
Finland AI Regulation Overview
Finland93% similar
Amendments implementing the EU Artificial Intelligence Act: Amendments to the Law on Technology and Innovation (XV-105) and the Law on Information Society Services (XV-106) to implement Regulation (EU) 2024/1689 (Lithuanian AI Act implementation amendments)
Lithuania90% similar
Artificial Intelligence Act
Norway90% similar
Ireland — National Implementation Roadmap for the EU Artificial Intelligence Act (Draft/Implementation Measures)
Ireland90% similar
© Regulations.AI — created on 05-Feb-2026 using Gemini 3 Flash Preview