Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
NOMEDIUM coverage1 enforcement action

Norway — EU AI Act (EEA, Pending) + Datatilsynet AI Guidance: AI Compliance Requirements

Norway is an EEA member that has committed to incorporating the EU AI Act through the EEA Agreement, but as of this cycle the Act is confirmed NOT YET LAW in Norway and no firm incorporation date exists. Norway's own national implementing bill (the KI-loven, consultation package published June 2025, originally targeting summer 2026) has itself slipped — both because the EU AI Act/EEA adaptation negotiations remain unresolved and because the EU's own July 2026 "Digital Omnibus" amendment changed the underlying text being negotiated. Norway's Datatilsynet (Data Protection Authority) has been proactive in AI regulation regardless, publishing detailed AI and GDPR guidance and conducting investigations into AI profiling systems, and has issued large AI-related GDPR fines. Norway's National AI Strategy emphasizes ethical AI and strong public sector governance. Norwegian companies selling into the EU, or with EU-based subsidiaries, are directly reached by the EU AI Act today regardless of Norway's own incorporation timeline.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

August 1, 2024

Maximum Penalty

GDPR (via EEA): up to NOK 200M (approx. EUR 17.5M). EU AI Act penalty ceiling (€35M / 7% global turnover) will apply via the EEA Agreement once incorporated — no confirmed incorporation date as of this cycle.

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Prepare for EU AI Act (EEA Incorporation Pending, No Firm Date)

High Priority

Norway will incorporate the EU AI Act through the EEA Agreement, but as of this cycle it is not yet in force in Norway and Norway's own KI-loven implementing bill has slipped past its original summer-2026 target with no new firm date published. Begin preparing now regardless: classify AI systems by risk, identify likely high-risk AI obligations, implement transparency notices for limited-risk AI, prepare documentation. Norwegian companies selling into the EU or operating EU subsidiaries are already directly bound by the EU AI Act today. See the EU AI Act entry for detailed requirements.

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16/26/43 (provider/deployer/conformity obligations) — NOT yet incorporated into the EEA Agreement as of this cycle (see entry summary), cited for preparation purposes only.

Norwegian Datatilsynet AI and GDPR Compliance

High Priority

Datatilsynet requires: explicit consent for most AI profiling under GDPR Art. 22, AI bias audits for consequential decisions, transparency for AI-driven decisions, and data minimization for AI training. Review guidance at datatilsynet.no/en. Datatilsynet has been actively investigating and fining AI-related GDPR violations.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA) — incorporated via the EEA Agreement, enforced by Datatilsynet

Who Does This Apply To?

Applies to any organisation processing the personal data of Norwegian residents through AI — Norway's Datatilsynet enforces GDPR today (incorporated via the EEA Agreement); the EU AI Act itself is NOT yet incorporated into the EEA Agreement and is not yet law in Norway, with Norway's own KI-loven implementing bill delayed past its original summer-2026 target and no new firm date published as of this cycle. In scope today: any business making AI-driven decisions about Norwegian residents (explicit consent generally required for AI profiling under GDPR Art. 22, with bias audits for consequential decisions), and adtech/profiling deployers (the Grindr NOK 65M / €6.6M fine, upheld by the Borgarting Court of Appeal in 2025, set the Nordic lawful-basis standard for sharing data with AI-driven adtech) — plus, separately, any Norwegian company selling into the EU or operating an EU-based subsidiary, which is already directly bound by the EU AI Act regardless of Norway's own incorporation timeline. Datatilsynet's AI sandbox (regulatorisk sandkasse) supports Norwegian deployers preparing for eventual conformity. Maximum exposure: up to NOK 200M (~€17.5M) under GDPR today; the €35M / 7%-of-turnover AI Act ceiling will apply via the EEA Agreement once incorporated, with no confirmed date yet.

Recent Enforcement Actions

2025-10-21Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2025-06

Datatilsynet — Sandbox for Responsible AI exit reports and AI-and-GDPR guidance (2022-2025)

Datatilsynet's AI sandbox published exit reports for participating Norwegian AI projects (Helse Bergen, Norwegian Labour and Welfare Administration, Ruter, Doffin) operationalizing GDPR + AI compliance: (1) lawful basis selection for AI training; (2) data-minimization in fine-tuning; (3) DPIA scoping for high-risk AI; (4) algorithmic-transparency requirements under Article 22 GDPR. Datatilsynet's published AI-and-GDPR guidance is treated as a regional reference framework across the Nordics.

Key Case Law & Precedent

Datatilsynet v. Grindr LLC (December 2021)

Norway Datatilsynet · 2021

Norway's own leading enforcement precedent — NOK 65M (€6.6M) fine against Grindr for unlawful sharing of personal data with advertising partners. Datatilsynet's reasoning on the lawful-basis requirement for sharing data with AI-driven adtech systems established the Nordic enforcement standard. The decision is directly cited by Datatilsynet when applying GDPR to AI-profiling deployments today, and is expected to inform the DPA's interpretation once EU AI Act high-risk obligations eventually apply via EEA incorporation.

Outcome: NOK 65M (€6.6M) fine, cease-and-desist order on unlawful data sharing

Case reference

Industry Playbooks covering Norway — EU AI Act (EEA, Pending) + Datatilsynet AI Guidance

These industry playbooks include jurisdiction-specific checklist items and guidance for Norway — EU AI Act (EEA, Pending) + Datatilsynet AI Guidance.

Frequently Asked Questions

Does Norway — EU AI Act (EEA, Pending) + Datatilsynet AI Guidance apply to my business?

Norway is an EEA member that has committed to incorporating the EU AI Act through the EEA Agreement, but as of this cycle the Act is confirmed NOT YET LAW in Norway and no firm incorporation date exists. Norway's own national implementing bill (the… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Norway — EU AI Act (EEA, Pending) + Datatilsynet AI Guidance is: GDPR (via EEA): up to NOK 200M (approx. EUR 17.5M). EU AI Act penalty ceiling (€35M / 7% global turnover) will apply via the EEA Agreement once incorporated — no confirmed incorporation date as of this cycle.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Norway — EU AI Act (EEA, Pending) + Datatilsynet AI Guidance?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.datatilsynet.no/en/artificial-intelligence/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan