Back to KISYN

The AI Act in Norway

Does the EU AI Act apply in Norway? Status as of August 2026

The short answer: the AI Act — KI-forordningen in Norwegian — does not yet apply directly in Norway. As a regulation it applies in the EU, but for Norway it must first be incorporated into the EEA Agreement and then implemented in Norwegian law. That work is not finished. Many Norwegian organisations are still covered in practice, because the rules follow the EU market rather than the company's address.

By Yassin BahriPublished and reviewed 1 August 20268 min read

Where the process stands

The AI Act entered into force in the EU on 1 August 2024 and applies in stages. In Norway it is not yet in force. Because Norway is in the EEA and not in the EU, the regulation has to be incorporated into the EEA Agreement first, which requires negotiations between Norway, Iceland, Liechtenstein and the EU about possible EEA adaptations. Those negotiations are not concluded.

The original ambition was a Norwegian AI act adopted during 2026. That timeline has slipped, and the Government now aims to put a bill before the Storting in spring 2027. Until then there is no Norwegian AI act in force, and no national deadline that mirrors the EU dates.

  • The AI Act is in force in the EU, in stages, from 1 August 2024.
  • It is not yet incorporated into the EEA Agreement, so it is not yet Norwegian law.
  • EEA negotiations on adaptations are still ongoing.
  • A bill is expected to go to the Storting in spring 2027.

Why many Norwegian organisations are covered anyway

The AI Act follows the EU market, not the supplier's postal address. A Norwegian organisation is covered when it places an AI system on the EU market, puts one into service in the EU, or when the output of its AI system is used in the EU. A Norwegian company selling software to customers in the EU can therefore be a provider under the regulation long before any Norwegian act is passed.

Customer requirements arrive earlier than the law does. European buyers, and Norwegian buyers who answer to European owners or partners, increasingly ask suppliers to document which AI systems they use, what those systems are used for, and which risk class the use falls into. That documentation request does not wait for the EEA process to finish.

  • Placing an AI system on the EU market makes you a provider.
  • Using AI whose output is used in the EU can also bring you into scope.
  • Group companies with EU parents often apply the requirements internally.
  • Procurement and tender documents already ask for AI inventories.

What already applies in Norway today

The absence of a Norwegian AI act does not mean AI use is unregulated. The Personal Data Act and the GDPR apply in full whenever an AI tool processes personal data, and that covers most everyday workplace use. The duties to have a lawful basis, to inform data subjects, to enter into data processor agreements and to assess risk are already in force.

Sector rules apply on top of that. Public bodies must observe the rules on case handling and transparency, employers must respect the rules on monitoring in working life, and regulated sectors such as health and finance have their own requirements. In practice these obligations, not the AI Act, are what an organisation is most likely to breach today.

  • The GDPR and the Personal Data Act apply to all AI use involving personal data.
  • A lawful basis and a data processor agreement are required before use.
  • Rules on monitoring in working life limit what may be logged about employees.
  • Sector legislation in health, finance and the public sector applies unchanged.

What the Digital Omnibus changed

In June 2026 the EU adopted the Digital Omnibus on AI, which moved several of the AI Act's deadlines. The European Parliament endorsed the package on 16 June 2026 and the Council gave final approval on 29 June 2026.

The obligations for standalone high-risk systems under Annex III were deferred to 2 December 2027, and those for AI embedded in regulated products under Annex I to 2 August 2028. The transparency duties in Article 50 were not deferred: they applied from 2 August 2026. Those are the rules requiring that people are told when they are interacting with an AI system and that AI-generated content is labelled.

  • Annex III standalone high-risk obligations move to 2 December 2027.
  • Annex I embedded high-risk obligations move to 2 August 2028.
  • Article 50 transparency duties still applied from 2 August 2026.
  • The prohibitions from February 2025 and the GPAI rules from August 2025 are unchanged.

Who will supervise the rules in Norway

The Norwegian Communications Authority (Nkom) is set to be the coordinating market surveillance authority and the national contact point, with responsibility for consistent supervision across sectors. Sector authorities keep their own areas, and the Data Protection Authority retains its role wherever personal data is involved.

A regulatory sandbox for AI is being built through cooperation between the Norwegian Digitalisation Agency, the Data Protection Authority and Nkom, organised under KI Norge. It is intended to give developers guidance on meeting the requirements before the rules bite.

  • Nkom is set to coordinate market surveillance and act as national contact point.
  • Sector authorities keep supervision within their own fields.
  • The Data Protection Authority continues to supervise processing of personal data.
  • A regulatory sandbox is being established under KI Norge.

What to do while the rules are pending

The work that the AI Act will eventually require is the same work that answers customer questionnaires and data protection obligations today, so it is rarely wasted. Start with an overview of actual use, because every later obligation depends on knowing what AI is used for and by whom.

Classify by use rather than by tool. The same assistant can be minimal risk when it corrects spelling and high risk when it screens job applicants. A list of tool names says nothing about the obligations that will apply.

  • Build an inventory of AI use, with a named owner for each use case.
  • Record the purpose, the data involved and the decisions the output affects.
  • Give employees an approved route for proposing new tools.
  • Reassess when a tool gains new AI features or a new purpose.

Frequently asked questions

Does the AI Act apply in Norway right now?

Not directly. The regulation is in force in the EU but has not yet been incorporated into the EEA Agreement or implemented in Norwegian law. A bill is expected to go to the Storting in spring 2027. Norwegian organisations that place AI systems on the EU market, or whose AI output is used in the EU, can still be covered by the EU rules.

When will the Norwegian AI act enter into force?

No date is fixed. The original ambition was during 2026, but the EEA negotiations have taken longer than expected and the Government now aims to present a bill in spring 2027. Entry into force will follow the Storting's treatment of that bill.

What is the difference between the AI Act, KI-forordningen and KI-loven?

The AI Act and KI-forordningen are two names for the same EU rules: Regulation (EU) 2024/1689. KI-loven is the name used for the Norwegian act that will implement those rules once the regulation is incorporated into the EEA Agreement. The EU rules apply in the EU today; the Norwegian act has not been adopted.

Were the high-risk requirements postponed?

Yes. Through the Digital Omnibus on AI, adopted in June 2026, the obligations for standalone high-risk systems under Annex III were deferred to 2 December 2027 and those for AI embedded in regulated products under Annex I to 2 August 2028. The transparency duties in Article 50 were not postponed and applied from 2 August 2026.

Does anything regulate AI use in Norway today?

Yes. The GDPR and the Personal Data Act apply whenever an AI tool processes personal data, which covers most workplace use. Rules on monitoring in working life, case handling in the public sector and sector legislation in areas such as health and finance also apply unchanged.

Who will supervise the AI Act in Norway?

Nkom is set to be the coordinating market surveillance authority and national contact point, while sector authorities keep supervision in their own fields and the Data Protection Authority continues to supervise the processing of personal data. A regulatory sandbox is being established under KI Norge together with the Norwegian Digitalisation Agency.

Free orientation tool

Understand how the EU AI Act may apply

Answer plain-language questions, get explanations as you go, and see the official legal basis behind your result.

Start the AI Act assessment