Norway - AI Coordination Plan

Common plan for artificial intelligence 2020

Felles plan for kunstig intelligens 2020

Norway

RAI-NO-NA-FPKI2XX-2019
Effective: November 29, 2019
In Force(In Force)
PolicyGovernance and OversightSafety, Testing, and EvaluationData Protection and Privacy
Export PDF

A sectoral joint plan prepared by Norwegian health authorities (Helsedirektoratet, Directorate for e-Health, and others) setting out a coordinated program for further study, piloting and safe adoption of AI in the health and specialist health services. The plan (published November 29, 2019) outlines priorities, proposed studies, organizational roles, data access considerations, and recommended actions for regulation, procurement, validation and competence-building.

Overview

The "Felles plan for kunstig intelligens 2020" is a short, cross-agency plan led by the Norwegian Directorate of Health that sets out a coordinated programme of follow-up work to enable safe and effective use of AI in the specialist health services. It was prepared after an assignment from the Ministry of Health and Care Services dated 28 June 2019, delivered in autumn 2019, and published 29 November 2019. The plan documents stakeholder workshops, establishes priority themes (mapping readiness, piloting, validation, access to data, procurement, competence and governance), and proposes concrete studies and operational support activities. The official PDF is available from the Directorate of Health: Felles plan for kunstig intelligens 2020 (PDF). The plan is a sectoral coordination framework rather than a statute, intended to steer agencies, regional health authorities and other stakeholders toward common priorities and actions.

Definitions

The document adopts a working approach to AI in line with EU/Norwegian public sector usage: AI systems are treated as software (often with machine learning) that interpret and process structured or unstructured data to achieve specific goals and which may adapt over time. The plan distinguishes AI systems that may fall under health-care or medical device regulation (i.e., systems used for diagnosis, treatment support or other direct patient care) from non-clinical uses (e.g., logistics), which it largely excludes. It also clarifies terms like "forprosjekt" (pre-project), "RHF-ene" (Regional Health Authorities), validation, and operational deployment phases (pilot, clinical evaluation, production).

Governance and Institutional Framework

The plan sets out a cooperative governance model where Helsedirektoratet holds coordinating responsibility for the forprosjekt and works closely with Direktoratet for e-helse and Statens legemiddelverk, alongside the four RHFs. Organisationally, the plan recommends continued multi-agency steering groups, regular workshops with service providers, and clear assignment of responsibilities for follow-up tasks (surveys, pilot support, guidance development and financing). It prescribes coordination with national oversight bodies (e.g. Helsedirektoratet, Direktoratet for e-helse, Statens legemiddelverk) and involvement of specialist stakeholders (universities, research centres such as SINTEF, BigMed and regional ICT actors). The plan emphasises collaborative governance mechanisms, clear accountability for pilots and workflows for escalation where regulatory clarification is needed.

Key Focus Areas

The plan organises follow-up activity into three main strands: (1) "Map" — evaluate sector readiness by surveying primary and specialist care, clinicians, patients and private actors to identify high-value use cases and risks; (2) "Support" — provide concrete support for adoption, including guidance for procurement, clinical validation frameworks, pilot facilitation and short-term financing options; and (3) "Collaborate" — continue cross-agency collaboration and regular stakeholder engagement. Within these strands are detailed topics: simplifying controlled access to data for development/validation while maintaining privacy safeguards; drafting guidance on quality assurance and validation of ML models; clarifying when AI constitutes medical device functionality under existing law; addressing competence gaps among health personnel; and proposing targeted regulatory clarifications where necessary. The plan also identifies out-of-scope items (e.g., national security, certain research ethics processes, and generic search engines) to keep focus on clinical care use cases.

Implementation Framework

Implementation is proposed via a series of discrete studies and operational activities with named responsible agencies and RHF involvement. Short-term measures include workshops, readiness surveys, pilot support for clinical AI deployments, and procurement guidance. Medium-term tasks include work to improve access to curated data sets for model training and validation under strict privacy and security controls, development of health-sector specific validation and quality assurance processes (including metrics for model performance and monitoring), and competence-building programmes for clinical staff and procurement officers. The plan recommends evaluating whether regulatory changes are needed and, if so, developing proposals in coordination with the Ministry and existing regulatory frameworks for medical devices and health data protection.

Monitoring and Evaluation

The plan recommends establishing monitoring via regular reporting to the steering group and use of staged milestones for each recommended activity (mapping, pilots, guidance production). Measures include tracking numbers of pilots supported, completed validations, guidance publications, data-access authorisations, and competence activities delivered. The plan suggests periodic stakeholder workshops to surface issues and adapt priorities. Outcomes are to be evaluated against safety, clinical benefit, interoperability, and compliance with existing legal requirements including data protection and medical device rules.

Penalties, Liability, and Appeals

The 2020 plan is a coordination and action plan and does not itself create new penalties. It clarifies that liability, enforcement and sanctions for AI systems used in health care remain governed by existing legislation (e.g., patient safety rules, medical device regulation, and general civil liability). Where the plan recommends regulatory clarification or change, any future enforcement mechanisms would be defined in those legislative instruments. The document therefore places emphasis on risk management, validation and governance to reduce liability exposure rather than prescribing penalties.

Relationship to Other Instruments

The plan explicitly situates itself alongside Norway's National AI Strategy ("Nasjonal strategi for kunstig intelligens", Jan 2020) and other national guidance, and it cross-references medical device regulation and health privacy and information-security norms. It is complementary to sectoral guidance produced later by Helsedirektoratet and other agencies (for example, quality assurance guidance and follow-up joint AI plans published in subsequent years). Links to related documents and subsequent workstreams are provided by the Directorate: Helsedirektoratet AI resource page and the national strategy repository on Regjeringen.no.

International Alignment

Although nationally focused, the plan aligns with broader European and international AI policy themes: trustworthy AI, ethics, human oversight, data protection and safety. The plan adopts concepts consistent with EU expert-group thinking and Norway's subsequent national AI strategy (2020), positioning Norwegian health-sector actions to be compatible with EU developments such as the EU's White Paper on AI and later legislative initiatives. It encourages participation in standards and international cooperation to ensure interoperability and alignment with evolving conformity and assessment frameworks.

Implementation Timeline

ActivityResponsibleTarget date
Assignment from MinistryHelsedirektoratet / Direktoratet for e-helse / Statens legemiddelverk2019-06-28
Delivery / Publication of forprosjekt planHelsedirektoratet et al.2019-11-29
Presisering og ansvarsavklaring noteHelsedirektoratet2020-03-16
Workshops and stakeholder mappingHelsedirektoratet / RHFs2020 (rolling)
Follow-up guidance and validation frameworksRelevant agencies2020-2022 (recommended)

Compliance Checklist

RequirementChecklist
Map readinessConducted stakeholder survey / workshop
Data accessDefine controlled access path with privacy and security controls
ValidationAdopt clinical validation metrics and procedures
ProcurementApply recommended procurement guidance and contractual clauses
GovernanceAssign agency/regional responsibilities and reporting lines

Sources and References

SourceType
Felles plan for kunstig intelligens 2020 (Helsedirektoratet PDF)Primary Source
Felles plan for kunstig intelligens 2020 - Presisering og ansvar (Helsedirektoratet PDF)Primary Source
Helsedirektoratet - Kunstig intelligens (webpage)Primary Source / Official guidance
Nasjonal strategi for kunstig intelligens (Regjeringen.no, Jan 2020)Primary Source
Plain English

This Norwegian policy guides health authorities and related stakeholders in safely adopting Artificial Intelligence (AI) across health and specialist health services. Published on November 29, 2019, it sets out a coordinated program for studying, piloting, and integrating AI.

The plan primarily applies to Norwegian health authorities, including the Directorate of Health (Helsedirektoratet), Directorate for e-Health, and the Norwegian Medicines Agency (Statens legemiddelverk), alongside regional health authorities and other partners like universities and private companies developing AI for healthcare. Its focus is on AI systems used for direct patient care, such as diagnosis or treatment support, largely excluding non-clinical uses like hospital logistics.

Key actions outlined in the plan include: - Mapping the sector's readiness for AI by identifying high-value uses and risks. - Providing concrete support for AI adoption, including guidance for procurement and clinical validation frameworks. - Improving controlled access to health data for AI development and validation, while strictly maintaining privacy safeguards. - Addressing competence gaps among health personnel to ensure safe and effective AI use.

It's crucial to understand that this document is a coordination framework, not a new law. It does not introduce new penalties or enforcement mechanisms. Instead, liability and sanctions for AI systems in healthcare continue to be governed by existing legislation, such as patient safety rules and medical device regulations. The plan emphasizes robust risk management, thorough validation, and strong governance to minimize legal exposure. A practical pitfall for product teams is that while this plan doesn't create new legal obligations, it strongly signals the need for rigorous clinical validation and adherence to existing medical device and data protection laws for any AI solution deployed in Norwegian health services.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 8 marked complete

Plain-English obligations under Norway - AI Coordination Plan. Not legal advice — verify against the official text before relying on it.

  1. #1Critical

    Applies to: Providers and operators of AI systems used for diagnosis or treatment support.

    liability, enforcement and sanctions for AI systems used in health care remain governed by existing legislation (e.g., patient safety rules, medical device regulation, and general civil liability).
  2. #2Critical

    Applies to: Providers and operators of AI systems handling health data.

    Outcomes are to be evaluated against safety, clinical benefit, interoperability, and compliance with existing legal requirements including data protection and medical device rules.
  3. #3Important

    Applies to: Providers and operators of AI systems in health services.

    The document therefore places emphasis on risk management, validation and governance to reduce liability exposure rather than prescribing penalties.
  4. #4Important

    Applies to: Providers and operators of AI systems in health services.

    development of health-sector specific validation and quality assurance processes (including metrics for model performance and monitoring)
  5. #5Important

    Applies to: Developers and researchers using health data for AI.

    simplifying controlled access to data for development/validation while maintaining privacy safeguards
  6. #6Important

    Applies to: Entities conducting AI pilot projects in health services.

    The plan emphasises collaborative governance mechanisms, clear accountability for pilots and workflows for escalation where regulatory clarification is needed.
  7. #7Recommended

    Applies to: Procurers of AI systems in health services.

    provide concrete support for adoption, including guidance for procurement
  8. #8Recommended

    Applies to: Health personnel and procurement officers.

    addressing competence gaps among health personnel

© Regulations.AI — created on 13-Jun-2026