Sweden - AI Regulation Adjustments (SOU 2025:101)

Adjustments to the AI Regulation — Report of the Inquiry on the AI Regulation (SOU 2025:101)

Anpassningar till AI-förordningen — Betänkande av Utredningen om AI-förordningen (SOU 2025:101)

Sweden

RAI-SE-NA-ATABAXX-2025
Draft(Being written or scoped)
PolicyGovernance and OversightConformity Assessment and RegistrationMarket Surveillance
Export PDF

SOU 2025:101 ("Anpassningar till AI-förordningen") is a government inquiry report proposing Swedish implementing legislation and regulations to complement the EU AI Regulation. It recommends a new national law and complementary ordinance establishing market surveillance authorities, sanctions, registry and sandbox arrangements to enable safe AI use while promoting innovation.

Overview

SOU 2025:101, "Anpassningar till AI-förordningen — Säker användning, effektiv kontroll och stöd för innovation," is the final report from the national inquiry charged with identifying and drafting the Swedish legal measures necessary to implement and complement the EU AI Regulation. The inquiry recommends that Sweden adopt a targeted set of national rules assembled in a new law and a complementary ordinance to operationalize market surveillance, designate competent national authorities, clarify secrecy and documentation rules, and introduce innovation-enabling measures such as regulatory sandboxes. The full official report is published by the Government Offices: SOU 2025:101 (Regeringen) and the complete PDF report is available here: Anpassningar till AI-förordningen (PDF, SOU 2025:101). The inquiry frames its recommendations to be consistent with the EU AI Regulation while tailoring operational arrangements to Swedish institutional structures.

Definitions

The report adopts and clarifies key definitions from the EU AI Regulation (AI-system; high-risk AI; AI models for general purposes; provider; user; placing on the market) and maps these to Swedish legal categories (e.g. product, service, public sector deployment). It further defines "market control authority", "anmälande myndighet" (notifying authority), "regulatory sandbox" and "testing under real-world conditions" to ensure consistent application across agencies and sectors. The definitional section aims to avoid duplication and ensures terms operate coherently with the AI Regulation and with Swedish laws such as the Public Access to Information and Secrecy Act (2009:400).

Governance and Institutional Framework

The inquiry proposes a structured governance model that designates Post- och telestyrelsen (PTS) as the primary coordinating market control authority with overall responsibility for national market surveillance, the role of common contact point under Article 70(2) of the AI Regulation, and a leading role in public guidance and the national sandbox. The report specifies eleven market-control authorities, each with sector-specific responsibilities, and two notifying/accreditation-related authorities (Swedac and Läkemedelsverket for specific medical-device-related matters). Agencies highlighted for concrete roles include Post- och telestyrelsen (PTS), Integritetsskyddsmyndigheten (IMY), Finansinspektionen, Styrelsen för ackreditering och teknisk kontroll (Swedac), Läkemedelsverket, Myndigheten för digital förvaltning (DIGG) and Kammarkollegiet. The governance chapter describes coordination, reporting channels, data-exchange requirements and the mechanisms for resolving jurisdictional overlaps.

Key Focus Areas

SOU 2025:101 concentrates on several interlocking areas: market surveillance and enforcement capacity; registration and documentation for high-risk AI systems; confidentiality and limited secrecy-breaching rules to allow effective supervision; accreditation and designation mechanisms for conformity assessment bodies (leveraging Swedac and existing accreditation law); incident reporting and risk management requirements aligned with Article 73 of the AI Regulation; the structure and authorisation of regulatory sandboxes and approvals for testing under real-world conditions (both inside and outside sandboxes); penalties and fee structures (including sanction fees collected by Kammarkollegiet); and safeguards for fundamental rights and data protection (coordinated with IMY and GDPR obligations). The report also addresses practical tooling — templates, guidance, and registries — to facilitate compliance and cross-agency oversight. It emphasises proportionality and legal certainty, seeking to reduce unnecessary regulatory burden while ensuring enforceability and the protection of fundamental rights and safety.

Implementation Framework

The proposed implementation framework includes concrete legislative text: a new national law containing complementary provisions to the EU AI Regulation (covering designation of national authorities, national registrations, national enforcement powers, secrecy exceptions and sanctioning procedures) together with an implementing ordinance detailing sectoral responsibilities, procedural rules, and provisions on regulatory sandboxes. The report prescribes that PTS will prepare implementing regulations and guidance for the national register of certain high-risk AI systems under Article 49(5) and set rules for incident reporting, document preservation and exchange. The framework leverages existing Swedish administrative law practices (administrative decisions, inspections, and administrative fines) and aligns conformity assessment procedures with Swedac accreditation practices and existing conformity assessment law (2011:791).

Monitoring and Evaluation

The inquiry recommends establishing clear monitoring and evaluation mechanisms, including annual reporting from market control authorities to PTS, joint annual overviews presented to the Finansdepartementet and the Riksdag, and routine reviews of sandboxes and testing approvals. It suggests metrics for monitoring effectiveness (number of inspections, incident reports, sanction decisions, time to market for sandboxed projects) and a formal review clause requiring re-evaluation of the national implementing legislation within a defined period after the AI Regulation’s full applicability. It also foresees coordinated engagement with the EU AI Office (the AI-byrån) for information exchange and harmonised implementation.

Penalties, Liability, and Appeals

The report proposes a coherent enforcement model that follows the AI Regulation’s risk-based approach: administrative sanction fees and corrective measures for infringements, delegated penalty enforcement (fees to be paid to Kammarkollegiet), injunctive powers (orders to suspend or withdraw AI systems), and coordination rules for cross-sector or multi-authority cases. It clarifies avenues for judicial and administrative appeal and recommends procedural safeguards for rights of defence. The report also analyses civil liability and encourages that liability and redress mechanisms be clarified through parallel updates to existing Swedish fault- and product-liability rules to ensure effective compensation for harm caused by AI systems.

Relationship to Other Instruments

SOU 2025:101 explicitly maps the proposed national measures to existing EU and Swedish laws: the EU AI Regulation (2024/1689), the General Data Protection Regulation (GDPR), the Public Access to Information and Secrecy Act (2009:400), the Accreditation and Conformity Assessment Act (2011:791), and sectoral EU product regulations (e.g. medical devices). The report recommends limited, targeted amendments to national secrecy law and to accreditation legislation to avoid legal gaps and to harmonise authorities’ powers. Where sectoral EU product law (e.g. medical devices) already governs safety and conformity, the proposed national rules avoid duplication and focus on coordination between Swedac, Läkemedelsverket and PTS.

International Alignment

The inquiry stresses that national measures must be aligned with the EU AI Regulation and the broader EU framework. It proposes active Swedish participation in EU-level implementation bodies and the AI Office (AI-byrån), and recommends technical and procedural alignment (data exchange, templates, standards) to reduce fragmentation across Member States. The report emphasises use of international standards and EU harmonised standards for conformity assessment and welcomes participation in joint testing and research initiatives to promote interoperability and cross-border market access for Swedish AI developers.

Implementation Timeline

MilestoneDate
Report published (SOU 2025:101)2025-10-06
Remittance (remiss) to stakeholders opens2025-11-11
Consultation/Remiss deadline2026-02-23
Most provisions of EU AI Regulation applicable at EU level2026-08-02
Target for national implementing legislation (drafting & consultation)2026 (following remiss)

Compliance Checklist

RequirementWhoAction
Determine if AI system is in-scope / high-riskProvider / DistributorConduct risk classification per AI Regulation
Register specified high-risk systemsProvider / PTSSubmit entries to national register where required
Maintain technical documentationProviderRetain and make available to market-control authorities on request
Incident reportingProvider / UserReport serious incidents per Article 73 and national rules
Conformity assessmentProvider / Notified body (Swedac-accredited)Undergo assessment and obtain required documentation

Sources and References

SourceType
Anpassningar till AI-förordningen — Säker användning, effektiv kontroll och stöd för innovation (SOU 2025:101) — full report (PDF)Primary Source
SOU 2025:101 — Regeringen (summary page)Primary Source
Remiss av SOU 2025:101 — Regeringen (remiss notice)Primary Source
Plain English

Sweden is preparing a new national legal framework to implement and enforce the European Union's landmark AI Act, affecting all entities in Sweden that develop, provide, or use artificial intelligence systems. A recent government inquiry proposes a new national law and complementary regulations to ensure safe AI use while fostering innovation.

This framework applies to Swedish companies, public sector bodies, and any organisation operating within Sweden that develops or deploys AI, particularly those dealing with "high-risk" AI systems as defined by the EU AI Act. Key obligations for these entities will include: - Registering certain high-risk AI systems in a national database. - Maintaining detailed technical documentation for their AI systems. - Reporting serious incidents or malfunctions to designated authorities. - Undergoing conformity assessments to ensure their AI systems meet safety and ethical standards.

The Post and Telecom Authority (PTS) is set to become the primary coordinating market surveillance authority, working alongside ten other sector-specific agencies like the Swedish Authority for Privacy Protection (IMY) and the Financial Supervisory Authority (Finansinspektionen). This national legislation is targeted to be in force by August 2, 2026, aligning with the EU AI Act's major applicability date.

Failure to comply can result in administrative sanction fees, corrective measures, and orders to suspend or withdraw non-compliant AI systems from the market. These fees will be collected by Kammarkollegiet. A practical pitfall for businesses and public bodies is the need to navigate a multi-layered regulatory landscape, involving both the overarching EU AI Act and these new, specific Swedish rules. Furthermore, the proposed framework includes limited exceptions to existing secrecy rules, allowing supervisory authorities to access necessary information to effectively monitor and enforce AI compliance, which might be a surprise for some organisations.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 9 marked complete

Plain-English obligations under Sweden - AI Regulation Adjustments (SOU 2025:101). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Providers and distributors of AI systems.

    Determine if AI system is in-scope / high-risk
  2. #2CriticalBefore placing on market

    Applies to: Providers of specified high-risk AI systems.

    registration and documentation for high-risk AI systems
  3. #3CriticalFor the lifetime of the AI system

    Applies to: Providers of AI systems.

    Retain and make available to market-control authorities on request
  4. #4CriticalWithout undue delay

    Applies to: Providers and users of AI systems.

    incident reporting and risk management requirements aligned with Article 73 of the AI Regulation
  5. #5CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    Undergo assessment and obtain required documentation
  6. #6CriticalOngoing from 2026-08-02

    Applies to: Providers and users of AI systems.

    safeguards for fundamental rights and data protection (coordinated with IMY and GDPR obligations)
  7. #7CriticalUpon decision by authority

    Applies to: Duty-bearers found in infringement.

    administrative sanction fees and corrective measures for infringements
  8. #8ImportantBefore entering a sandbox

    Applies to: AI developers and providers using regulatory sandboxes.

    the structure and authorisation of regulatory sandboxes
  9. #9ImportantBefore commencing real-world testing

    Applies to: AI developers and providers testing AI systems in real-world conditions.

    approvals for testing under real-world conditions

© Regulations.AI — created on 13-Jun-2026