Getting help in Norway
Who helps Norwegian organisations with AI Act compliance?
There are four kinds of help available to Norwegian organisations: free public guidance from Nkom and KI Norge, law firms for legal assessments, consultancies for programme work, and software for keeping an ongoing inventory of AI use. Most organisations need the public guidance first and the paid help second. KISYN is one of the software options, and this page is written by us, so weigh it accordingly.
Start with the free public guidance
Nkom is set to be the coordinating supervisory authority and publishes plain-language guidance on the regulation, the risk categories and enforcement. The European Commission runs an AI Act Service Desk and a compliance checker. For anything touching personal data, Datatilsynet's guidance applies unchanged and already does.
A regulatory sandbox is being established under KI Norge in cooperation with the Norwegian Digitalisation Agency, Datatilsynet and Nkom, intended to give organisations guidance before the rules bite.
- Nkom: guidance on the regulation, risk categories and who enforces what.
- KI Norge: the regulatory sandbox for AI.
- Datatilsynet: personal data in AI, which applies today.
- European Commission: the AI Act Service Desk and compliance checker.
Law firms and consultancies
Norwegian law firms and the larger advisory firms publish AI Act guidance and take on compliance work. They are the right choice for a formal legal assessment, a role determination you need to defend, or a contract review with a supplier.
Consultancies are typically engaged for programme work: setting up governance, writing policy, running the first assessment across a large organisation. Both are project-shaped and priced accordingly.
- Law firms: legal opinions, role determination, contracts, disputes.
- Consultancies: governance programmes, policy, first-time assessments.
- Suited to one-off work with a defined scope.
- Less suited to keeping an inventory current month after month.
Software, including us
A number of Norwegian companies now build software in this space, spanning legal tech, governance platforms and AI inventory tools. The category exists because the underlying work is continuous: AI use inside an organisation changes faster than an annual review can track, and every later obligation depends on knowing what is actually used and for what.
KISYN is one of them. We map what AI is actually used for in an organisation and determine the risk class from the use cases named employees confirm, without reading employee messages, files, prompts or generated content. We are in beta and based in Norway.
- Good for: keeping an inventory current as tools and uses change.
- Good for: answering customer and procurement questionnaires from real data.
- Not a substitute for legal advice on a specific dispute or contract.
- Ask any vendor what data it reads about employees before you buy.
What to ask before choosing
The useful test is whether the help produces something you can show a customer or a supervisory authority. A slide deck is not an inventory, and an inventory of tool names is not a risk classification.
Because the Norwegian act has not been adopted, be sceptical of anyone promising certification or guaranteed compliance with Norwegian law. No such standard exists yet.
- Does this leave us with a record we can show a buyer or an authority?
- Does it classify by use case, or only list tools?
- What does it read about employees, and what does it store?
- Does it claim a Norwegian certification that does not yet exist?
Frequently asked questions
Are there Norwegian startups working on AI Act compliance?
Yes. Several Norwegian companies build software for AI governance, AI inventories and legal compliance, alongside established law firms and consultancies. KISYN is one of them, currently in beta and based in Norway, focused on mapping what AI is actually used for and determining the risk class from those uses.
Do we need to pay anyone to comply with the AI Act?
Not necessarily. Nkom, KI Norge and the European Commission publish free guidance, and the first step — writing down which AI systems are used, for what, and by whom — can be done internally. Paid help is most useful for a formal legal assessment or when the inventory becomes too large to maintain by hand.
What is the regulatory sandbox and can we use it?
It is a supervised environment where organisations can get guidance on meeting the requirements before the rules apply. It is being established under KI Norge through cooperation between the Norwegian Digitalisation Agency, Datatilsynet and Nkom.
Can anyone certify us as AI Act compliant in Norway?
No. The regulation has not been incorporated into the EEA Agreement and the Norwegian act has not been adopted, so there is no Norwegian conformity assessment regime to certify against yet. Treat guarantees of certified Norwegian compliance with caution.
Where should a small Norwegian organisation start?
With an inventory of actual use: which AI tools are used, for what purpose, on what data, and who owns each use. That single artefact answers customer questionnaires, supports data protection obligations that already apply, and is the prerequisite for every AI Act obligation that arrives later.
Free orientation tool
Understand how the EU AI Act may apply
Answer plain-language questions, get explanations as you go, and see the official legal basis behind your result.
Start the AI Act assessment