Norway - AI Regulation (2026)
Artificial Intelligence Act
Kunstig intelligens-loven
Norway
RAI-NO-NA-ARTIINT-2026The proposed Norwegian Artificial Intelligence Act (KI-loven) is a draft law to implement the EU AI Regulation (AI Act) into Norwegian law. The proposal adopts a risk-based approach (ban on unacceptable-risk systems, strict rules for high-risk systems, transparency for limited-risk systems) and designates national authorities and implementation measures including a regulatory sandbox and national coordination by Nkom.
Summary
Read full text ↗Plain English
Overview
The Digitaliserings- og forvaltningsdepartementet published a consultation package on 30 June 2025 proposing a new Norwegian law to implement the EU Artificial Intelligence Regulation (AI Act) into national law. The proposal ("KI-loven") would incorporate the EU regulation into Norwegian law and add national provisions where the regulation allows discretion – for example on national competent authorities, enforcement tools and geographic application. The consultation material and draft law are published on the ministry website and include an explanatory consultation page and a full høringsnotat and draft law (PDF) that explain the risk‑based architecture, planned institutional responsibilities, and practical measures such as a national regulatory sandbox hosted in "KI Norge" at Digdir.
Definitions
The draft law adopts the EU AI Act terminology. Central definitions include "AI system" (machine‑based system which may exhibit adaptiveness and infer outputs from inputs), "provider" (entity placing an AI system on the market or putting it into service), "deployer/idriftsetter" (entity operating the system within Norway), "high‑risk AI system" (as defined by sectoral lists in the regulation), "foundation models" and "models for general purpose". The consultation document discusses terminological clarifications and recommends aligned Norwegian translations of the EU text to reduce legal uncertainty.
Governance and Institutional Framework
The department proposes a multi‑agency model: Nasjonal kommunikasjonsmyndighet (Nkom) as the national coordinating market surveillance authority and contact point to EU, sectoral market surveillance authorities for domain-specific high‑risk systems, and Datatilsynet among the market surveillance/competent authorities for certain uses (e.g., law‑enforcement purposes). Digitaliseringsdirektoratet (Digdir) will host "KI Norge", a national arena to provide guidance, capacity building, and a regulatory sandbox for controlled testing. The consultation notes the need for clear allocation of responsibilities, information sharing mechanisms between authorities, and adequate resourcing (the government proposed funding increases and staffing to support the new responsibilities).
Key Focus Areas
The draft law and explanatory note emphasize the following substantive policy pillars: prohibitions of AI practices that present unacceptable risk (such as covert manipulative systems directed at vulnerable groups, certain social scoring or mass biometric remote identification uses), stringent requirements for high‑risk AI systems (data governance, technical documentation, human oversight, transparency, robustness and cybersecurity), transparency obligations for systems with limited risk (e.g., notifying users of AI-generated content), specific measures for foundation models and general-purpose models (including model‑level obligations when system risk arises), and strong post‑market monitoring and incident reporting obligations. The consultation also addresses conformity assessment routes, harmonised standards, CE‑type marking and registry requirements for certain high‑risk systems. The package explicitly highlights data protection, fundamental rights safeguards, and sectoral interfaces (health, finance, employment, law enforcement) as priority areas.
Implementation Framework
The ministry proposes incorporation of the EU regulation into Norwegian law and complementary national provisions where the regulation leaves margin. The consultation describes practical implementation measures: designation of competent and market surveillance authorities (Nkom and sectoral regulators), rules on jurisdictional scope (including discussion on continental shelf application), options for allowing testing in regulatory sandboxes, accreditation of conformity assessment bodies, and the creation of national registers. The draft sets out enforcement tools (overtredelsesgebyr, tvangsmulkt) and contemplates administrative procedures for imposing corrective measures. The consultation seeks feedback on enforcement design choices and on whether to include criminal sanctions.
Monitoring and Evaluation
The draft law foresees post‑market monitoring obligations for providers and deployers of high‑risk systems, reporting of serious incidents and cataloguing of non‑compliances to the responsible market surveillance authorities. National oversight will be coordinated by Nkom and supported by sectoral supervisors; the consultation document stresses inter‑agency information sharing, common reporting formats, and public transparency about enforcement outcomes. The text also anticipates periodic reviews and alignment with EU implementing acts and guidance developed at the EU level.
Penalties, Liability, and Appeals
The proposal relies primarily on administrative enforcement: provision for overtredelsesgebyr (administrative pecuniary penalties), orders to cease or remediate non‑compliant systems, and tvangsmulkt (coercive fines) to secure compliance. The ministry proposes not to introduce new criminal offences in the KI‑law itself and seeks input on limitation periods and the possibility to impose fines on public sector entities. The consultation material addresses procedural safeguards, rights to administrative appeal, and potential judicial review mechanisms.
Relationship to Other Instruments
The draft explicitly aligns with existing Norwegian and EEA instruments: it cross‑references the GDPR (and national data protection rules enforced by Datatilsynet), sectoral health and financial regulation, product safety frameworks, and national procurement rules. It also discusses interplay with proposals for a Digital Services Act (digitaltjenesteloven) and with national rules on law‑enforcement use of AI – including possible targeted adjustments to police legislation to address biometrics and remote identification.
International Alignment
Norge aims to implement the AI Regulation in step with the EU to secure EEA alignment and equal market conditions for Norwegian actors. The consultation invites input on ratification of the Council of Europe’s framework convention on AI and human rights. The ministry highlights coordination with EU bodies (AI Office) and the need to follow EU implementing acts, standards, and guidance to maintain regulatory coherence for cross‑border services, conformity assessment, and TEFs/ sandboxes.
Implementation Timeline
| Event | Date |
|---|---|
| Consultation published (høringsnotat and draft law) | 2025-06-30 |
| Consultation deadline (høringsfrist) | 2025-09-30 |
| Government indicated target for entry into force (main parts) | Planned summer 2026 (EU alignment, August 2026) |
| Nkom designated as coordinating authority (announcement) | 2025-03-21 |
| Funding and establishment of KI Norge announced | 2025-10-15 |
Compliance Checklist
| Requirement | Action for Entities |
|---|---|
| Risk assessment | Map AI systems; classify risk level; document risk management |
| Conformity assessment (high‑risk) | Prepare technical documentation; engage notified/conformity body; obtain certificate |
| Data governance | Adopt data quality and training data provenance policies; maintain logs |
| Transparency | Inform users when interacting with AI; disclose system purpose and limitations |
| Post‑market monitoring | Establish monitoring plan; report incidents to authorities |
| Human oversight | Define human‑in‑the‑loop controls and training for operators |
Sources and References
| Source | Type |
|---|---|
| Høring – utkast til ny lov om kunstig intelligens (regjeringen.no) | Primary Source |
| Høringsnotat - Gjennomføring av forordningen om kunstig intelligens (PDF) | Primary Source |
| Nkom – Information about KI and responsibilities (Nkom) | Primary Source |
| Datatilsynet – Høringssvar om KI-forordningen | Primary Source |
| Digdir – Digdir establishes KI Norge | Primary Source |
Norway's proposed Artificial Intelligence Act (KI-loven) aims to bring the EU's comprehensive AI Regulation into Norwegian law, establishing a risk-based framework for anyone developing, selling, or using AI systems within the country.
This draft legislation applies to "providers" who place AI systems on the market or put them into service, and "deployers" who operate these systems within Norway. It adopts the EU's terminology, defining an AI system as a machine-based system that can exhibit adaptiveness and infer outputs from inputs. The core of the law is its risk-based approach, categorizing AI systems into different risk levels with corresponding obligations.
Key requirements include: - **Outright bans** on AI practices deemed to pose an unacceptable risk, such as covert manipulative systems targeting vulnerable groups, certain social scoring applications, or mass biometric remote identification. - **Strict rules** for "high-risk" AI systems, which must adhere to stringent requirements for data governance, technical documentation, human oversight, transparency, robustness, and cybersecurity. - **Transparency obligations** for "limited-risk" systems, requiring users to be informed when they are interacting with AI-generated content. - **Specific measures** for "foundation models" and general-purpose AI, addressing risks at the model level.
The law is expected to take effect around August 1, 2026, aligning with the EU's implementation timeline. Enforcement will primarily involve administrative measures, including pecuniary penalties (overtredelsesgebyr), orders to cease or remediate non-compliant systems, and coercive fines (tvangsmulkt). The current proposal does not introduce new criminal offenses.
A practical pitfall for businesses is navigating the multi-agency enforcement model. While Nkom (Nasjonal kommunikasjonsmyndighet) will serve as the national coordinating authority, various sectoral bodies and Datatilsynet (the data protection authority) will also have oversight for specific AI uses. This complex structure, coupled with the detailed EU definitions, means companies must carefully classify their AI systems and understand which specific authority oversees their particular use case to ensure compliance.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Norway - AI Regulation (2026). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before placing on market or putting into service
Applies to: All providers and deployers of AI systems.
“prohibitions of AI practices that present unacceptable risk”
- #2Critical⏰ Before placing on market or putting into service
Applies to: All providers and deployers of AI systems.
“Risk assessment: Map AI systems; classify risk level; document risk management”
- #3Critical⏰ Before placing on market or putting into service
Applies to: Providers of high-risk AI systems.
“conformity assessment routes... for certain high‑risk systems.”
- #4Critical⏰ Before placing on market
Applies to: Providers of high-risk AI systems.
“CE‑type marking... for certain high‑risk systems.”
- #5Critical⏰ Before placing on market or putting into service
Applies to: Providers of certain high-risk AI systems.
“registry requirements for certain high‑risk systems.”
- #6Critical⏰ Before placing on market or putting into service
Applies to: Providers of high-risk AI systems.
“stringent requirements for high‑risk AI systems (data governance...)”
- #7Critical⏰ Before putting into service
Applies to: Providers and deployers of high-risk AI systems.
“stringent requirements for high‑risk AI systems (...human oversight...)”
- #8Critical⏰ Before placing on market or putting into service
Applies to: Providers of high-risk AI systems.
“stringent requirements for high‑risk AI systems (...robustness and cybersecurity)”
- #9Critical⏰ Ongoing
Applies to: Providers and deployers of high-risk AI systems.
“strong post‑market monitoring and incident reporting obligations.”
- #10Critical⏰ Ongoing
Applies to: All providers and deployers of AI systems.
“cross‑references the GDPR... sectoral health and financial regulation, product safety frameworks”
- #11Important⏰ Before putting into service
Applies to: Providers and deployers of limited-risk AI systems.
“transparency obligations for systems with limited risk (e.g., notifying users of AI-generated content)”
- #12Important⏰ Before placing on market or putting into service
Applies to: Providers of foundation models and general-purpose models.
“specific measures for foundation models and general-purpose models (including model‑level obligations when system risk arises)”
Related Regulations
National Strategy for Artificial Intelligence (Nasjonal strategi for kunstig intelligens)
Norway93% similar
Joint AI plan for the safe and effective use of AI in the Norwegian health and care services 2024–2025
Norway91% similar
Norway AI Regulation Overview
Norway91% similar
Status and proposals for further work with artificial intelligence (KI) in the health and care services (Status og forslag til videre arbeid med kunstig intelligens i helse- og omsorgstjenesten)
Norway91% similar
Hallituksen esitys eduskunnalle EU:n tekoälyasetusta täydentäväksi lainsäädännöksi (Government Proposal HE 46/2025) — Proposal for national implementing legislation for the EU Artificial Intelligence Act
Finland90% similar
© Regulations.AI — created on 13-Jun-2026