Back to KISYN

Template

AI policy template for Norwegian organisations

A workable AI policy fits on two pages. It names what staff may use, what must never go into an AI tool, who decides on new tools, and who owns each use. This page gives the clauses to copy, in the order they belong, and explains which ones are required by law today rather than good practice. It is a starting point, not legal advice.

By Yassin BahriPublished and reviewed 1 August 20268 min read

What the policy has to achieve

A policy that only forbids things does not survive contact with a workplace. Staff adopt AI tools because they help, and a rule with no approved alternative pushes that use underground, which is precisely how shadow AI forms. The policy has to give a permitted path as clearly as it draws limits.

Two duties are already live regardless of the AI Act's status in Norway: the Personal Data Act and the GDPR govern any AI use touching personal data, and the AI literacy duty in Article 4 applies to organisations covered by the EU rules.

  • Name approved tools, not just prohibited ones.
  • Give a route for proposing something new, with a stated response time.
  • Assign an owner per use case, not one owner for all AI.
  • Keep it to two pages; a long policy is not read.

The clauses to include

Copy these headings in order. Each should be two or three sentences in your own wording; the aim is that someone reads the whole thing in five minutes.

  • Purpose and scope — who the policy applies to, including contractors.
  • Approved tools — the current list, and where it is maintained.
  • Data rules — what must never be entered: personal data of customers or colleagues, health data, unpublished financial data, credentials, source code where prohibited.
  • Human accountability — output is a draft; a named person owns the decision.
  • High-risk uses — recruitment, performance, access to services and benefits require approval before use.
  • Prohibited uses — emotion recognition on staff, social scoring, covert monitoring.
  • Proposing a new tool — who to ask, what to supply, expected response time.
  • Transparency — when customers or colleagues must be told AI was involved.
  • Training — the minimum AI literacy expected of anyone using these tools.
  • Review — the date this policy is next revisited, and who owns it.

What to leave out

Most weak AI policies fail because they try to enumerate technology. A list of named products is stale within a quarter, and it invites the argument that anything unlisted is permitted.

Equally, avoid promising compliance with a Norwegian AI act. None has been adopted, so the promise cannot be kept and it dates the document.

  • Do not enumerate every model or vendor; describe categories and the approval route.
  • Do not claim certification against Norwegian AI legislation that does not exist.
  • Do not copy an EU template unchanged; the Norwegian legal position differs.
  • Do not bury the rules in a handbook nobody opens.

Keeping it current

A policy is only as good as the inventory beneath it. If nobody knows which tools are in use for what, the policy is a statement of intent rather than a control. Pair it with an AI inventory and review both on the same cycle.

Set a review date in the document. The rules are moving: the Digital Omnibus changed the high-risk deadlines in June 2026, and the Norwegian act is expected to reach the Storting in spring 2027.

  • Review at least twice a year while the rules are changing.
  • Re-check when a familiar tool gains new AI features.
  • Re-check when a use case changes purpose.
  • Record who approved each exception and when.

Frequently asked questions

Is an AI policy required by law in Norway?

There is no standalone Norwegian legal requirement to have an AI policy, because the Norwegian act has not been adopted. However, the duties that already apply — the Personal Data Act, the GDPR and, for organisations covered by the EU rules, the AI literacy duty in Article 4 — are difficult to demonstrate without written internal rules.

How long should an AI policy be?

Two pages is usually enough. The purpose is that staff read it and follow it. Detail belongs in the inventory and in the approval process, not in the policy document.

Should the policy list approved AI tools by name?

List them somewhere maintained and linked, but not inside the policy itself. A named list inside the document goes stale quickly and implies that anything unlisted is allowed.

Who should own the AI policy?

One named person, usually in legal, compliance or security, with each individual use case owned by the team that runs it. A policy owned by everyone is owned by nobody.

Can we reuse an EU AI policy template in Norway?

Partly. The obligations it describes are the ones Norway is expected to adopt, but the AI Act is not yet Norwegian law and no national deadlines mirror the EU dates. Any statement about what is legally required in Norway today needs rewriting.

Free orientation tool

Understand how the EU AI Act may apply

Answer plain-language questions, get explanations as you go, and see the official legal basis behind your result.

Start the AI Act assessment