Denmark AI Regulation Overview
Denmark AI Regulation Overview
Denmark
RAI-DK-NA-SUMMARY-2026Tracked instruments in Denmark
12 instruments tracked — 5 In Force, 3 Withdrawn, 2 Superseded, 1 Adopted, 1 Under Review. Built directly from our records, so — unlike the article below — it cannot go stale.
| Instrument | Type | Status | Year | Effective |
|---|---|---|---|---|
| Denmark - AI Regulation Supplement (Law No. 467/2025) | Act | In Force | 2025 | 2 Aug 2025 |
| Denmark - AI Regulatory Sandbox | Guideline | In Force | 2024 | 5 Mar 2024 |
| Denmark - AI Strategic Approach | Policy | Adopted | 2024 | 2 Dec 2024 |
| Denmark - Algorithm Transparency Proposal (B 136) | Policy | Withdrawn | 2024 | — |
| Denmark - National AI Taskforce | Policy | In Force | 2024 | 2 Dec 2024 |
| Denmark - Responsible Generative AI Guidelines | Guideline | In Force | 2024 | 9 Jan 2024 |
| Denmark - AI Guidelines and Risk Assessments (B 42) | Policy | Withdrawn | 2023 | — |
| Denmark - AI Use by Public Authorities | Guideline | In Force | 2023 | — |
| Denmark - Independent AI Supervisory Authority (B 90) | Policy | Withdrawn | 2023 | — |
| Denmark - Data Security and Ethics (B 149) | Policy | Under Review | 2022 | — |
| Denmark - National AI Strategy | Policy | Superseded | 2019 | 14 Mar 2019 |
| Denmark - Digital Growth Strategy | Policy | Superseded | 2018 | 30 Jan 2018 |
Denmark regulates AI primarily through EU AI Act implementation under Law No. 467 of 14 May 2025, supported by designated market surveillance authorities (Digitaliseringsstyrelsen, Datatilsynet, Domstolsstyrelsen), national AI strategies, and practical regulatory sandbox guidance.
Full article
Overview
Denmark's overall framework for artificial intelligence governance centers on operationalising European Union legislation alongside national strategic policy and administrative guidance. Rather than enacting an independent substantive AI code, Denmark relies on the direct applicability of Regulation (EU) 2024/1689 (EU AI Act). To operationalise these EU-level rules domestically, Denmark enacted the Act on Supplementary Provisions to the Regulation on Artificial Intelligence (Law No. 467 of 14 May 2025), which entered into force on 2 August 2025. This Act establishes the national institutional, supervisory, and enforcement architecture required under the EU framework.
Complementing its binding statutory implementation, Denmark has built a strong ecosystem of non-binding policy instruments, practical guidelines, and joint regulatory initiatives. National policy is spearheaded by the Ministry of Digitalisation through the Strategisk indsats for kunstig intelligens (published December 2, 2024), which updated and superseded the earlier 2019 National Strategy for AI. Regulatory guidance and oversight are coordinated closely between Digitaliseringsstyrelsen (Danish Agency for Digital Government) and Datatilsynet (Danish Data Protection Authority), notably through a joint AI Regulatory Sandbox and practical manuals on GDPR compliance and responsible generative AI adoption.
Regulatory Approach
Denmark employs a hybrid, risk-aligned regulatory approach that distinguishes between binding statutory enforcement and soft-law administrative support. Substantive compliance obligations, system risk classifications, and prohibitions are dictated directly by the EU AI Act. The domestic supplementary Act focuses strictly on procedural, institutional, and market surveillance powers within Denmark, leaving core definitions and classification thresholds to European law. The territorial scope of the national supplementary law explicitly excludes the Faroe Islands and Greenland.
To support public authorities and private entities in navigating these requirements, Danish authorities make extensive use of advisory soft-law mechanisms. Digitaliseringsstyrelsen maintains practical guidance for generative AI deployment based on a three-step managerial workflow, while Datatilsynet offers structured lifecycle compliance guidance for public entities processing personal data. Furthermore, the cross-governmental Digital Taskforce for AI drives public sector adoption by addressing legal and organizational barriers, running testbeds, and developing target deployment visions (målbillede).
Key AI Legislation
- Act on Supplementary Provisions to the Regulation on Artificial Intelligence (Lov om supplerende bestemmelser til forordningen om kunstig intelligens; Law No. 467 of 14 May 2025; ID: RAI-DK-NA-SPAILXX-2025): National implementing Act that designates market surveillance authorities, establishes inspection and information-gathering powers, and creates the framework for administrative fines (bødeforelæg) under the EU AI Act.
- Strategic Approach for Artificial Intelligence (Strategisk indsats for kunstig intelligens, 2024; ID: RAI-DK-NA-SAAISXX-2024): National strategy allocating DKK 62.5 million (2024–2027) across four key initiatives: the Digital Taskforce for AI, the Center for AI in Society, a secure platform for Danish language models, and expanded access to Danish text data.
- Digitaliseringsstyrelsen Guides for Responsible Use of Generative AI (Guides til ansvarlig anvendelse af generativ kunstig intelligens, 2024; ID: RAI-DK-NA-DGRUGXX-2024): Practical, non-binding guidelines setting out a three-step management approach for strategy, internal rules, and organizational readiness when deploying generative AI.
- Datatilsynet Guidance: Public Authorities' Use of AI – 'Before You Start' (Offentlige myndigheders brug af kunstig intelligens: Inden I går i gang, 2023; ID: RAI-DK-NA-DGPAUXX-2023): Lifecycle compliance manual for public bodies addressing GDPR lawful bases, DPIAs, data minimisation, and Article 22 automated decision-making constraints.
- Regulatory Sandbox for Artificial Intelligence (Regulatorisk sandkasse for AI, 2024; ID: RAI-DK-NA-RSAIRXX-2024): Collaborative advisory framework run by Datatilsynet and Digitaliseringsstyrelsen providing four-month tailored guidance engagements on GDPR and EU AI Act risk classification.
- Digital Taskforce for Artificial Intelligence (Digital Taskforce for kunstig intelligens, 2024; ID: RAI-DK-NA-DTAIDXX-2024): Public-sector framework governed by a political steering committee to accelerate ethical, large-scale public AI deployment and resolve regulatory barriers.
- Superseded Policies: National Strategy for Artificial Intelligence (2019; ID: RAI-DK-NA-NSAINXX-2019) and Strategy for Denmark's Digital Growth (2018; ID: RAI-DK-NA-SDDGSXX-2018), both replaced by subsequent strategic initiatives.
- Withdrawn/Rejected Parliamentary Proposals: Proposal B 136 (2024; algorithmic transparency in casework), Proposal B 90 (2023; dedicated AI unit in Datatilsynet), Proposal B 42 (2023; national risk assessments and fairness declaration), and Proposal B 149 (2022; data security and ethics oversight).
Governance & Enforcement Bodies
Governance of AI in Denmark is distributed among three designated national competent market surveillance authorities under Article 5 of the EU AI Regulation: Digitaliseringsstyrelsen, Datatilsynet, and Domstolsstyrelsen. Digitaliseringsstyrelsen serves as the primary authorising authority and central national contact point, coordinating Denmark's engagement with the European Commission and other EU Member States while handling central market surveillance.
Datatilsynet acts as both a designated market surveillance authority for AI systems within its supervisory remit and the lead supervisory body for GDPR and data protection compliance. Domstolsstyrelsen is appointed with a specific market surveillance remit within judicial administration. Strategic and operational support bodies include the Digital Taskforce for AI (anchored in the Digitalisation Ministry), the planned Center for AI in Society, and the Data Ethics Council (Dataetisk Råd).
Penalties & Enforcement
Enforcement mechanisms under the Act on Supplementary Provisions confer direct powers on designated market surveillance authorities to request operational and technical documentation, gain access to business premises without prior judicial authorization in specified circumstances, and execute technical examinations of AI systems. Authorities are empowered to issue binding remedial orders, command system recalls or withdrawals, impose temporary prohibitions, and publish enforcement decisions in the public interest.
For monetary sanctions, the Act establishes an administrative basis for issuing bødeforelæg (administrative fines settled without full judicial trial) in coordination with the Ministry of Justice, while foreseeing coordination on criminal enforcement where contemplated by EU law. Enforcement of data protection non-compliance linked to AI processing remains under Datatilsynet's established powers to issue corrective orders and administrative fines under the GDPR.
Data Protection Framework
Data protection rules applicable to AI development and operation in Denmark are grounded in the General Data Protection Regulation (GDPR) and the Danish Data Protection Act. Datatilsynet enforces these rules strictly across the AI lifecycle, treating model development and operational deployment as distinct processing activities that each require an identified lawful basis, explicit purpose limitation, and rigorous data minimisation.
Public authorities and private deployers using AI must perform Data Protection Impact Assessments (DPIAs) when processing presents high risks. Datatilsynet's published guidance highlights constraints on profiling and fully automated decision-making under Article 22 GDPR, requiring human-in-the-loop controls where decisions affect citizens' legal status or fundamental rights. The joint regulatory sandbox directly assists entities in integrating privacy-by-design and conducting DPIAs alongside EU AI Act risk classification.
Sector-Specific Rules
Where the corpus holds no record of unified sector-specific AI statutes, AI systems operating within targeted fields are governed by existing sectoral rules and administrative principles. In public administration, AI deployment must conform with general administrative law duties under forvaltningsloven, including obligations regarding confidentiality, procedural fairness, and explainability in citizen casework. In healthcare settings, software and AI tools are subject to intersecting framework regulations such as the European Medical Device Regulation (MDR).
In terms of territorial execution, national AI legislation explicitly defines its geographical boundaries: the Act on Supplementary Provisions to the Regulation on Artificial Intelligence explicitly excludes the Faroe Islands and Greenland from its scope of application.
International Alignment
Denmark's AI regulatory architecture is fully aligned with the European Union framework. As a Member State, Denmark directly applies the EU AI Regulation (EU 2024/1689), GDPR, and the Digital Services framework. The domestic supplementary legislation explicitly operationalises Member State obligations mandated by the EU AI Act, including statutory notifications to the European Commission.
Through Digitaliseringsstyrelsen's designated role as Denmark's central contact point, the country participates in European cross-border coordination, market surveillance networks, and joint policy development with the European Commission and other Member States.
Future Developments
Future developments in Danish AI policy are guided by the implementation roadmap of the December 2024 Strategisk indsats for kunstig intelligens. Key deliverables spanning the 2024–2027 funding period include establishing the Center for AI in Society, launching a secure technical platform for transparent Danish language models, and opening curated Danish text corpora for domestic developer use.
Concurrently, the Digital Taskforce for Artificial Intelligence will continue executing its mandate through at least mid-2027—with a formal extension review point scheduled for mid-2027—focusing on scaling public-sector pilots and publishing updated target visions (målbillede). Although several opposition proposals (B 136, B 90, B 42, B 149) regarding mandatory algorithmic transparency, independent AI oversight, and data ethics were rejected or left under review, they continue to inform policy discussions around administrative law reform and supervisory resource allocation.
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| Digitaliseringsstyrelsen (Danish Agency for Digital Government) | Central national contact point, authorising authority, and market surveillance authority under the EU AI Regulation; leads digital policy. | Request information, inspect premises without prior judicial authorization, conduct technical examinations, issue remedial orders/prohibitions, impose administrative fines (bødeforelæg) with Ministry of Justice. | |
| Datatilsynet (Danish Data Protection Agency) | Designated market surveillance authority under Article 5 of EU AI Act; lead supervisory authority for GDPR compliance. | Conduct inspections, issue corrective orders and administrative fines under GDPR, co-operate regulatory sandbox, issue binding enforcement decisions. | |
| Domstolsstyrelsen (Danish Court Administration) | Designated market surveillance authority with specific remit under Article 5 of the EU AI Regulation. | Market surveillance within designated judicial administration remit, request information, inspect premises, issue remedial orders. | |
| Digital Taskforce for kunstig intelligens | Cross-public-sector framework under Digitalisation Ministry, KL, and Danske Regioner to accelerate public AI adoption. | Publish strategic target visions (målbillede), coordinate pilots/testbeds, evaluate legal barriers, issue implementation recommendations. | |
| Dataetisk Råd (Data Ethics Council) | Independent advisory body providing recommendations and data-ethical analyses. | Advise government and parliament on data ethics, technological developments, and societal impacts of data processing. |
Real enforcement actions
4 entries recordedPublic enforcement actions where regulators cited Denmark AI Regulation Overview. Helps you see how the law is actually applied in practice.
- OtherAug 20, 2024
Datatilsynet (Denmark) vs Sporting Health Club
Datatilsynet held a fitness centre could obtain valid consent for facial-recognition access control because alternatives existed, but criticised the specific consent obtained from a complainant wrongly told no alternative existed.
Source ↗ - Enforcement orderJun 27, 2024
Datatilsynet (Denmark) vs IDA Forsikring
Datatilsynet held that IDA Forsikring could analyse recorded customer phone calls with AI within data-protection rules, but found its process for obtaining callers' consent did not meet GDPR requirements.
Source ↗ - OtherMar 17, 2022
Datatilsynet (Denmark) vs FysioDanmark Hilleroed
Datatilsynet warned a fitness centre that its planned facial-recognition access-control system would breach GDPR Article 9, as scanning non-consenting individuals and using biometric data for analytics lacked explicit consent.
Source ↗ - Enforcement orderMay 24, 2019
Datatilsynet (Denmark) vs Broendby IF
Datatilsynet authorised Broendby IF to use automatic facial recognition at stadium entrances to identify banned individuals, under the substantial-public-interest basis and nine conditions including encryption and limited storage.
Source ↗
Related Regulations
More AI regulation in Denmark
- Denmark - AI Use by Public Authorities
- Denmark - Responsible Generative AI Guidelines
- Denmark - National AI Taskforce
- Denmark - Data Security and Ethics (B 149)
- Denmark - Independent AI Supervisory Authority (B 90)
- Denmark - Algorithm Transparency Proposal (B 136)
- Denmark - AI Guidelines and Risk Assessments (B 42)
- Denmark - AI Regulatory Sandbox
© Regulations.AI using Gemini 3.6 Flash · updated on 12 Sep 2026