Norway - National AI Strategy
National Strategy for Artificial Intelligence
Nasjonal strategi for kunstig intelligens
Norway
RAI-NO-NA-NSAINXX-2020The Norwegian National Strategy for Artificial Intelligence (published 14 January 2020) sets out a national policy framework to promote research, innovation and trustworthy use of AI across public and private sectors. It emphasises ethical principles, data access, infrastructure, skills, and international cooperation while seeking regulatory sandboxes and supervisory oversight where needed.
Summary
Read full text ↗Plain English
Overview
The National Strategy for Artificial Intelligence (published 14 January 2020) sets out Norway's ambition to harness AI for public value, industry competitiveness and social welfare while safeguarding trust, human rights and privacy. The strategy is available in English and Norwegian; the English version is published on the Government of Norway website and the full text is downloadable as a PDF. The Government frames AI as both an economic opportunity and a governance challenge: it seeks to ensure that Norway develops world-class AI infrastructure, good language resources, adequate computing power and robust networks. At the same time the strategy emphasises that AI must be developed and applied responsibly, with Norway leveraging its high level of public trust and digital maturity to lead in 'human-friendly' AI. Key actions include facilitating access to data, supporting research and skills, piloting regulatory sandboxes, and coordinating oversight by relevant supervisory authorities. See the official strategy document: The National Strategy for Artificial Intelligence (Government of Norway) and the full PDF: English PDF: National Strategy for Artificial Intelligence (2020).
Definitions
The strategy provides working definitions and explanatory material for artificial intelligence and related concepts. It describes AI broadly to include data-driven machine learning and algorithmic systems used to perform tasks that would normally require human intelligence (pattern recognition, prediction, classification, decision support). The document clarifies distinctions between models, data, systems and services, and explains relevant technical concepts at a level intended for policymakers and public agencies. Definitions emphasise that governance must address systems (not only code): datasets, training methods, lifecycle deployment, monitoring and human oversight are all treated as part of the AI system. The strategy aligns with common EEA/EU terminology to facilitate international cooperation and regulatory interoperability.
Governance and Institutional Framework
The strategy designates the ministry responsible for digitalisation and public governance as the lead coordinating authority and calls for strengthened inter‑ministerial cooperation. It asks supervisory authorities (for example, the Norwegian Data Protection Authority (Datatilsynet)) to oversee AI systems within their sectoral remit and to provide guidance on privacy, fairness, and transparency. The document proposes the establishment of an advisory body and regulatory sandboxes — including a privacy-focused sandbox — to test novel AI applications under supervised conditions. The strategy stresses the role of public procurement, government research councils and university institutions in delivering centres of excellence and shared services (language datasets, HPC access). Coordination between national agencies is to be complemented by proactive engagement at EU and OECD levels to align standards and enforcement practices.
Key Focus Areas
The strategy organizes policy action around several mutually reinforcing focus areas:
- Data and data management: improving access to high-quality, interoperable datasets (open public data, registries, and language resources for Norwegian and Sami languages) while protecting privacy and confidentiality.
- Regulations and regulatory sandboxes: reviewing and refining rules that unintentionally hinder digital innovation, and piloting sandboxes in domains such as autonomous mobility and data-protection-sensitive AI.
- Infrastructure: securing high-speed networks (5G), national and international high-performance computing resources, and resilient data centre capacity.
- Research & higher education: boosting funding for basic and applied AI research and embedding AI topics across education to build interdisciplinary expertise.
- Skills & workforce: developing retraining, upskilling, and flexible further education programmes to manage labour market transitions.
- Innovation and public sector adoption: using procurement and public-private collaboration to stimulate AI development in priority sectors (health, maritime, energy, public services).
- Trustworthy AI: articulating and promoting ethical principles (transparency, human oversight, privacy protection, cautious testing, explainability) and insisting supervisory oversight in deployment.
Implementation Framework
The strategy outlines implementation mechanisms rather than binding legal obligations. Implementation levers include budgetary support for research (through the Research Council of Norway and grant programs), targeted competence-building initiatives (education curricula, short courses and workplace training), creation of shared public datasets and language resources, and investments in HPC and network infrastructure. The strategy also recommends clarifying sectoral regulation that intersects with AI (healthcare, transport, energy) and encourages the use of regulatory sandboxes where legal uncertainty or innovation risk justifies supervised experimentation. Ministries are asked to identify priority measures, oversee timetable and funding, and coordinate with supervisory agencies to ensure legal compliance. A central theme is that existing laws (e.g., the Personal Data Act/GDPR, Public Administration Act) remain applicable and supervisory authorities should exercise their oversight powers in AI matters.
Monitoring and Evaluation
Monitoring is framed around periodic assessment of progress against objectives (research capacity, infrastructure access, uptake across sectors, ethical adoption). The strategy envisages public reporting and an iterative approach: outcomes from sandboxes and advisory bodies should feed back into policy and regulatory clarification. It also calls on national audit and supervisory institutions to evaluate whether agencies and regulated entities implement the strategy’s principles in practice. Indicators suggested include the number of research projects, HPC capacity made available, uptake metrics in priority sectors, and qualitative assessments of transparency and ethical compliance in public deployments. The aim is to allow course-correction while maintaining oversight of rights and safety.
Penalties, Liability, and Appeals
The strategy itself is a policy/strategic document and does not create new penalties. Instead, it affirms that existing legal frameworks (notably the Personal Data Act and sectoral statutes) apply to AI systems and that supervisory authorities retain their enforcement powers under those laws. Where enforcement or liability issues arise in AI deployments, the strategy expects the relevant supervisory authority (for example, Datatilsynet for privacy matters) and sectoral regulators to use established enforcement tools, including investigations, orders, and administrative fines where permitted by law. The strategy also highlights the need for clear responsibility chains in procurement and deployment so that liability and redress can be established under existing civil or administrative law.
Relationship to Other Instruments
The strategy explicitly situates itself alongside existing Norwegian laws and international instruments. It references the Personal Data Act (implementing the GDPR), the Public Administration Act, the Archival Act, sectoral health and transport regulation, and international commitments (EEA cooperation). It anticipates the need to align national practice with the EU's AI regulatory framework and related OECD and Council of Europe instruments. The document promotes regulatory sandboxes as a way to reconcile innovation and legal compliance and advises ministries to review domestic rules that could unintentionally block beneficial AI uses while preserving fundamental rights.
International Alignment
Norway commits to active international cooperation. The strategy states that Norway will participate in EU, OECD and Council of Europe processes to influence standards and ensure interoperability. It highlights Norway's EEA relationship and the practical need to follow developments such as the EU's Artificial Intelligence Act and related guidance. The strategy also encourages collaboration on research and infrastructure with international partners (HPC, Horizon programmes) and notes that international alignment is critical for market access, procurement and cross-border data flows.
Implementation Timeline
| Phase | Actions | Indicative Timing |
|---|---|---|
| Immediate (2020) | Publish strategy, launch advisory body, begin regulatory review and open data initiatives, establish sandboxes. | 2020–2021 |
| Short term | Fund research centres, launch skills initiatives and language resource projects, secure HPC partnerships. | 2020–2022 |
| Medium term | Scale public procurement use of AI, evaluate sandboxes, strengthen supervisory guidance and cross‑agency coordination. | 2022–2024 |
| Ongoing | Monitor uptake, iterate policy, participate in EU/EEA rule-making and align domestic practice. | 2020 onward |
Compliance Checklist
| Checklist Item | Who | Notes |
|---|---|---|
| Assess data protection impact (DPIA) | Deployers/Controllers | Follow Datatilsynet guidance where personal data involved. |
| Ensure transparency and human oversight | Providers/Deployers | Document decision-making chains and provide user information. |
| Use privacy‑by‑design | Developers | Embed data minimisation and security early in design. |
| Engage with supervisory sandboxes | Innovators | Apply to Datatilsynet or sector sandboxes for regulated testing. |
| Record-keeping and documentation | Providers | Maintain technical documentation to support audits. |
Sources and References
| Source | Type |
|---|---|
| The National Strategy for Artificial Intelligence (Government of Norway – English page) | Primary Source |
| English PDF: National Strategy for Artificial Intelligence (2020) | Primary Source |
| Norwegian Data Protection Authority (Datatilsynet) – English | Primary Source (supervisory guidance) |
| European Commission – AI Act / EU developments | Context / International Alignment |
Norway's National Strategy for Artificial Intelligence, adopted in January 2020, outlines the country's vision for developing and using AI responsibly across both public and private sectors. It aims to harness artificial intelligence for economic growth and social welfare while upholding trust, human rights, and privacy.
This strategy applies to any organization, public or private, developing or deploying AI systems in Norway. While it doesn't introduce new laws, it sets clear expectations for how AI should be used. At its core, the strategy emphasizes building "trustworthy AI" by setting expectations for organisations. This includes prioritising data protection and privacy, often requiring Data Protection Impact Assessments (DPIAs) and privacy-by-design approaches. It also stresses the importance of maintaining transparency and human oversight in AI decision-making processes, alongside comprehensive record-keeping and documentation for AI systems to support audits.
The strategy took effect on January 14, 2020, and has been guiding Norway's approach to AI development since. Since it is a policy document, it doesn't create new penalties. Instead, it reinforces that existing laws, such as the Personal Data Act (which implements the General Data Protection Regulation, or GDPR) and other sectoral regulations, fully apply to AI systems. This means supervisory bodies like the Norwegian Data Protection Authority (Datatilsynet) will use their existing powers, including investigations and administrative fines, to enforce compliance where AI systems fall short.
A key practical takeaway for businesses is that the strategy views AI governance broadly, extending beyond just the code to include datasets, training methods, deployment, monitoring, and human oversight. This means a holistic approach to compliance is necessary. Furthermore, Norway actively participates in international efforts, particularly with the European Union, meaning future EU AI regulations will likely influence Norwegian practices and create a need for ongoing alignment. The strategy also encourages the use of regulatory sandboxes to test novel AI applications under supervised conditions, offering a pathway for innovation while ensuring adherence to ethical and legal standards.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under Norway - National AI Strategy. Not legal advice — verify against the official text before relying on it.
- #1ImportantCompliance Checklist⏰ Before deploying AI systems involving personal data
Applies to: Deployers and controllers of AI systems.
“Assess data protection impact (DPIA)”
- #2ImportantCompliance Checklist⏰ During the design phase of AI systems
Applies to: Developers of AI systems.
“Use privacy‑by‑design”
- #3ImportantCompliance Checklist⏰ Before placing AI systems on the market or deploying them
Applies to: Providers and deployers of AI systems.
“Ensure transparency and human oversight”
- #4ImportantTrustworthy AI⏰ Before placing AI systems on the market or deploying them
Applies to: Providers and deployers of AI systems.
“explainability”
- #5ImportantTrustworthy AI⏰ Before and during AI system deployment
Applies to: Providers and deployers of AI systems.
“cautious testing”
- #6ImportantCompliance Checklist⏰ Throughout the lifecycle of AI systems
Applies to: Providers of AI systems.
“Record-keeping and documentation”
- #7ImportantPenalties, Liability, and Appeals⏰ Before procuring or deploying AI systems
Applies to: Organizations procuring and deploying AI systems.
“clear responsibility chains in procurement and deployment so that liability and redress can be established”
- #8RecommendedCompliance Checklist⏰ Before full-scale deployment of novel AI applications
Applies to: Innovators developing novel AI applications.
“Engage with supervisory sandboxes”
Related Regulations
National Strategy for Artificial Intelligence (National strategi for kunstig intelligens)
Denmark94% similar
Artificial Intelligence Act
Norway93% similar
Status and proposals for further work with artificial intelligence (KI) in the health and care services (Status og forslag til videre arbeid med kunstig intelligens i helse- og omsorgstjenesten)
Norway92% similar
Felles plan for kunstig intelligens 2020 (Common plan for artificial intelligence 2020)
Norway92% similar
The Digital Norway of the Future – National digitalisation strategy 2024–2030
Norway92% similar
© Regulations.AI — created on 13-Jun-2026