Norway - AI Regulation (2026)

Artificial Intelligence Act

Kunstig intelligens-loven

Norway

RAI-NO-NA-ARTIINT-2026
Draft(Being written or scoped)
BillGovernance and OversightConformity Assessment and Registration
Export PDF

The proposed Norwegian Artificial Intelligence Act (KI-loven) is a draft law to implement the EU AI Regulation (AI Act) into Norwegian law. The proposal adopts a risk-based approach (ban on unacceptable-risk systems, strict rules for high-risk systems, transparency for limited-risk systems) and designates national authorities and implementation measures including a regulatory sandbox and national coordination by Nkom.

Overview

The Digitaliserings- og forvaltningsdepartementet published a consultation package on 30 June 2025 proposing a new Norwegian law to implement the EU Artificial Intelligence Regulation (AI Act) into national law. The proposal ("KI-loven") would incorporate the EU regulation into Norwegian law and add national provisions where the regulation allows discretion – for example on national competent authorities, enforcement tools and geographic application. The consultation material and draft law are published on the ministry website and include an explanatory consultation page and a full høringsnotat and draft law (PDF) that explain the risk‑based architecture, planned institutional responsibilities, and practical measures such as a national regulatory sandbox hosted in "KI Norge" at Digdir.

Definitions

The draft law adopts the EU AI Act terminology. Central definitions include "AI system" (machine‑based system which may exhibit adaptiveness and infer outputs from inputs), "provider" (entity placing an AI system on the market or putting it into service), "deployer/idriftsetter" (entity operating the system within Norway), "high‑risk AI system" (as defined by sectoral lists in the regulation), "foundation models" and "models for general purpose". The consultation document discusses terminological clarifications and recommends aligned Norwegian translations of the EU text to reduce legal uncertainty.

Governance and Institutional Framework

The department proposes a multi‑agency model: Nasjonal kommunikasjonsmyndighet (Nkom) as the national coordinating market surveillance authority and contact point to EU, sectoral market surveillance authorities for domain-specific high‑risk systems, and Datatilsynet among the market surveillance/competent authorities for certain uses (e.g., law‑enforcement purposes). Digitaliseringsdirektoratet (Digdir) will host "KI Norge", a national arena to provide guidance, capacity building, and a regulatory sandbox for controlled testing. The consultation notes the need for clear allocation of responsibilities, information sharing mechanisms between authorities, and adequate resourcing (the government proposed funding increases and staffing to support the new responsibilities).

Key Focus Areas

The draft law and explanatory note emphasize the following substantive policy pillars: prohibitions of AI practices that present unacceptable risk (such as covert manipulative systems directed at vulnerable groups, certain social scoring or mass biometric remote identification uses), stringent requirements for high‑risk AI systems (data governance, technical documentation, human oversight, transparency, robustness and cybersecurity), transparency obligations for systems with limited risk (e.g., notifying users of AI-generated content), specific measures for foundation models and general-purpose models (including model‑level obligations when system risk arises), and strong post‑market monitoring and incident reporting obligations. The consultation also addresses conformity assessment routes, harmonised standards, CE‑type marking and registry requirements for certain high‑risk systems. The package explicitly highlights data protection, fundamental rights safeguards, and sectoral interfaces (health, finance, employment, law enforcement) as priority areas.

Implementation Framework

The ministry proposes incorporation of the EU regulation into Norwegian law and complementary national provisions where the regulation leaves margin. The consultation describes practical implementation measures: designation of competent and market surveillance authorities (Nkom and sectoral regulators), rules on jurisdictional scope (including discussion on continental shelf application), options for allowing testing in regulatory sandboxes, accreditation of conformity assessment bodies, and the creation of national registers. The draft sets out enforcement tools (overtredelsesgebyr, tvangsmulkt) and contemplates administrative procedures for imposing corrective measures. The consultation seeks feedback on enforcement design choices and on whether to include criminal sanctions.

Monitoring and Evaluation

The draft law foresees post‑market monitoring obligations for providers and deployers of high‑risk systems, reporting of serious incidents and cataloguing of non‑compliances to the responsible market surveillance authorities. National oversight will be coordinated by Nkom and supported by sectoral supervisors; the consultation document stresses inter‑agency information sharing, common reporting formats, and public transparency about enforcement outcomes. The text also anticipates periodic reviews and alignment with EU implementing acts and guidance developed at the EU level.

Penalties, Liability, and Appeals

The proposal relies primarily on administrative enforcement: provision for overtredelsesgebyr (administrative pecuniary penalties), orders to cease or remediate non‑compliant systems, and tvangsmulkt (coercive fines) to secure compliance. The ministry proposes not to introduce new criminal offences in the KI‑law itself and seeks input on limitation periods and the possibility to impose fines on public sector entities. The consultation material addresses procedural safeguards, rights to administrative appeal, and potential judicial review mechanisms.

Relationship to Other Instruments

The draft explicitly aligns with existing Norwegian and EEA instruments: it cross‑references the GDPR (and national data protection rules enforced by Datatilsynet), sectoral health and financial regulation, product safety frameworks, and national procurement rules. It also discusses interplay with proposals for a Digital Services Act (digitaltjenesteloven) and with national rules on law‑enforcement use of AI – including possible targeted adjustments to police legislation to address biometrics and remote identification.

International Alignment

Norge aims to implement the AI Regulation in step with the EU to secure EEA alignment and equal market conditions for Norwegian actors. The consultation invites input on ratification of the Council of Europe’s framework convention on AI and human rights. The ministry highlights coordination with EU bodies (AI Office) and the need to follow EU implementing acts, standards, and guidance to maintain regulatory coherence for cross‑border services, conformity assessment, and TEFs/ sandboxes.

Implementation Timeline

EventDate
Consultation published (høringsnotat and draft law)2025-06-30
Consultation deadline (høringsfrist)2025-09-30
Government indicated target for entry into force (main parts)Planned summer 2026 (EU alignment, August 2026)
Nkom designated as coordinating authority (announcement)2025-03-21
Funding and establishment of KI Norge announced2025-10-15

Compliance Checklist

RequirementAction for Entities
Risk assessmentMap AI systems; classify risk level; document risk management
Conformity assessment (high‑risk)Prepare technical documentation; engage notified/conformity body; obtain certificate
Data governanceAdopt data quality and training data provenance policies; maintain logs
TransparencyInform users when interacting with AI; disclose system purpose and limitations
Post‑market monitoringEstablish monitoring plan; report incidents to authorities
Human oversightDefine human‑in‑the‑loop controls and training for operators

Sources and References

SourceType
Høring – utkast til ny lov om kunstig intelligens (regjeringen.no)Primary Source
Høringsnotat - Gjennomføring av forordningen om kunstig intelligens (PDF)Primary Source
Nkom – Information about KI and responsibilities (Nkom)Primary Source
Datatilsynet – Høringssvar om KI-forordningenPrimary Source
Digdir – Digdir establishes KI NorgePrimary Source
Plain English

Norway's proposed Artificial Intelligence Act (KI-loven) aims to bring the EU's comprehensive AI Regulation into Norwegian law, establishing a risk-based framework for anyone developing, selling, or using AI systems within the country.

This draft legislation applies to "providers" who place AI systems on the market or put them into service, and "deployers" who operate these systems within Norway. It adopts the EU's terminology, defining an AI system as a machine-based system that can exhibit adaptiveness and infer outputs from inputs. The core of the law is its risk-based approach, categorizing AI systems into different risk levels with corresponding obligations.

Key requirements include: - **Outright bans** on AI practices deemed to pose an unacceptable risk, such as covert manipulative systems targeting vulnerable groups, certain social scoring applications, or mass biometric remote identification. - **Strict rules** for "high-risk" AI systems, which must adhere to stringent requirements for data governance, technical documentation, human oversight, transparency, robustness, and cybersecurity. - **Transparency obligations** for "limited-risk" systems, requiring users to be informed when they are interacting with AI-generated content. - **Specific measures** for "foundation models" and general-purpose AI, addressing risks at the model level.

The law is expected to take effect around August 1, 2026, aligning with the EU's implementation timeline. Enforcement will primarily involve administrative measures, including pecuniary penalties (overtredelsesgebyr), orders to cease or remediate non-compliant systems, and coercive fines (tvangsmulkt). The current proposal does not introduce new criminal offenses.

A practical pitfall for businesses is navigating the multi-agency enforcement model. While Nkom (Nasjonal kommunikasjonsmyndighet) will serve as the national coordinating authority, various sectoral bodies and Datatilsynet (the data protection authority) will also have oversight for specific AI uses. This complex structure, coupled with the detailed EU definitions, means companies must carefully classify their AI systems and understand which specific authority oversees their particular use case to ensure compliance.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Norway - AI Regulation (2026). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market or putting into service

    Applies to: All providers and deployers of AI systems.

    prohibitions of AI practices that present unacceptable risk
  2. #2CriticalBefore placing on market or putting into service

    Applies to: All providers and deployers of AI systems.

    Risk assessment: Map AI systems; classify risk level; document risk management
  3. #3CriticalBefore placing on market or putting into service

    Applies to: Providers of high-risk AI systems.

    conformity assessment routes... for certain high‑risk systems.
  4. #4CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    CE‑type marking... for certain high‑risk systems.
  5. #5CriticalBefore placing on market or putting into service

    Applies to: Providers of certain high-risk AI systems.

    registry requirements for certain high‑risk systems.
  6. #6CriticalBefore placing on market or putting into service

    Applies to: Providers of high-risk AI systems.

    stringent requirements for high‑risk AI systems (data governance...)
  7. #7CriticalBefore putting into service

    Applies to: Providers and deployers of high-risk AI systems.

    stringent requirements for high‑risk AI systems (...human oversight...)
  8. #8CriticalBefore placing on market or putting into service

    Applies to: Providers of high-risk AI systems.

    stringent requirements for high‑risk AI systems (...robustness and cybersecurity)
  9. #9CriticalOngoing

    Applies to: Providers and deployers of high-risk AI systems.

    strong post‑market monitoring and incident reporting obligations.
  10. #10CriticalOngoing

    Applies to: All providers and deployers of AI systems.

    cross‑references the GDPR... sectoral health and financial regulation, product safety frameworks
  11. #11ImportantBefore putting into service

    Applies to: Providers and deployers of limited-risk AI systems.

    transparency obligations for systems with limited risk (e.g., notifying users of AI-generated content)
  12. #12ImportantBefore placing on market or putting into service

    Applies to: Providers of foundation models and general-purpose models.

    specific measures for foundation models and general-purpose models (including model‑level obligations when system risk arises)

© Regulations.AI — created on 13-Jun-2026