Law Radar
Which AI and security deadlines apply to Norwegian businesses — right now?
The Digital Security Act has been in force since 1 October 2025, the EU AI Act has several deadlines between 2025 and 2028, and a Norwegian AI Act is expected no earlier than H2 2027. This is a source-verified map of what actually applies — preparation for a dated regime, not fear-mongering.
Last verified 2026-09-03
Norway
1 October 2025
ConfirmedDigital Security Act enters into force (NIS1-level)
Applies to operators of critical digital infrastructure and services in covered sectors. Registration duty and incident-notification duty are already in force.
Source2 October 2025
ExpectedRegistration with NSM — via PDF form
Entities covered by the Digital Security Act must register "as quickly as possible". No digital registration portal is confirmed live — registration currently happens via a PDF form emailed to NSM.
Source1 July 2026
ExpectedDigital Services Act (DSA) national implementation planned in force
Hearing closed 1 October 2025. Nkom is proposed as coordinating authority, with Medietilsynet, Forbrukertilsynet and Datatilsynet as competent authorities for different parts. EEA incorporation is still pending.
Source1 September 2026
ExpectedHearing on AI Act adjustments following the EU Digital Omnibus
The government has signalled an updated hearing round on the Norwegian AI Act following the EU's Digital Omnibus deferral. Nkom is proposed as coordinating authority and Norwegian EU contact point.
Source1 January 2027
ExpectedNSM regular supervision begins (not autumn 2026)
NSM is fixing supervision intervals during 2026; regular supervision is stated to begin in 2027, per NSM's own guidance. Often incorrectly reported as "supervision starting autumn 2026" — that is not accurate.
Source1 March 2027
ExpectedAI Act: bill submitted to the Norwegian parliament
A bill is expected spring 2027, with entry into force likely H2 2027. EEA negotiations are the main bottleneck. No enacted law or fixed date exists yet.
SourceEU
2 February 2025
ConfirmedAI Act: prohibited practices (art. 5) + AI literacy (art. 4)
Applies to anyone offering or using AI systems in the EU/EEA market, regardless of where the company is established. Prohibited practices and literacy requirements are already in force.
Source2 August 2025
ConfirmedAI Act: general-purpose AI (GPAI) model obligations
Applies to providers of general-purpose AI models placed on the EU/EEA market.
Source2 August 2026
ConfirmedAI Act art. 50: transparency duties (AI-content labelling, chatbot disclosure)
Applies to anyone offering chatbots, deepfakes or AI-generated content to EU/EEA users — including Norwegian companies without a European establishment. Transitional period for existing systems until roughly 2 December 2026.
Source2 December 2027
ConfirmedAI Act Annex III: high-risk obligations (deferred by the Digital Omnibus)
Applies to high-risk AI systems (e.g. employment, credit, judiciary). The deadline was deferred from 2026 to December 2027 by the Digital Omnibus regulation.
Source2 August 2028
ConfirmedAI Act Annex I: high-risk AI in regulated products
Applies to AI systems embedded in products covered by existing EU product-safety legislation (machinery, medical devices, etc.).
SourceSweden & Denmark
15 January 2026
ConfirmedSweden: Cybersecurity Act (2025:1506) enters into force — NIS2 implemented
Roughly 8,000 organizations across 18 sectors are covered, including registration duties, management liability and incident reporting. Directly affects Norwegian parent companies with Swedish subsidiaries.
Source2 August 2026
ExpectedSweden: national adaptation to the AI Act (PTS/IMY)
A government inquiry (SOU 2025:101) proposes PTS as lead supervisor with IMY/Finansinspektionen as co-supervisors for high-risk AI. Still at the inquiry stage — not enacted law.
Source1 July 2025
ConfirmedDenmark: NIS2 Act enters into force
Registration on Virk.dk had a deadline of 1 October 2025 (already passed). Directly affects Norwegian parent companies with Danish subsidiaries, and Norwegian suppliers to Danish NIS2-covered customers.
Source2 August 2025
ConfirmedDenmark: supervision of prohibited AI practices (interim act)
Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen supervise the AI Act's prohibited practices under an interim act, pending the full Danish AI Act.
Source2 August 2026
ConfirmedDenmark: Danish AI Act (L 111) enters into force
Replaces the interim act. Digitaliseringsstyrelsen becomes lead supervisor with inspection and sanction powers; the regulatory sandbox is run jointly with Datatilsynet.
Source16 deadlines tracked across Norway, the EU, Sweden and Denmark. Every row carries a primary source and a confidence marker. This page is information, not legal advice.
Frequently asked questions
Is my company covered by the Digital Security Act?
The Digital Security Act applies to operators of critical digital infrastructure and services in covered sectors. It entered into force on 1 October 2025. If you are unsure, the safest step is to clarify scope with NSM in writing before assuming anything.
When does the Norwegian AI Act apply?
No Norwegian AI Act has been enacted yet. A bill is expected spring 2027, with possible entry into force in H2 2027 — depending on EEA negotiations. Until then, the EU AI Act applies to Norwegian companies only via their activity in the EU/EEA market.
What does NIS2 require from suppliers?
NIS2 is not yet EEA-incorporated or implemented in Norway — the Digital Security Act is at NIS1 level. But Norwegian suppliers to Swedish or Danish customers already face NIS2-grade requirements today, via supply-chain obligations passed down from those NIS2-covered customers.
Does the AI Act apply to Norwegian businesses today?
Partially. Prohibited practices and AI-literacy requirements have been in force since February 2025, and from 2 August 2026 transparency duties (art. 50) apply to chatbots and AI-generated content aimed at EU/EEA users — including Norwegian companies without a European establishment.
What do "Confirmed" and "Expected" mean on this page?
"Confirmed" means the date is in force or fixed in an enacted law, regulation or EU act. "Expected" means a government or authority has signalled intent, but no enacted law or fixed date exists yet. We never change a category without a new source.
What should I do now if I am unsure whether I am covered?
Start by documenting which laws and regulations could actually apply to your business — including through EU sales, Swedish/Danish subsidiaries, or supply chains. A verification audit can reveal whether your AI systems and documentation hold up against the requirements that already apply.
Is this page legal advice?
No. This is information based on publicly available primary sources, not legal advice. Consult a lawyer for your specific situation.
How often is this overview updated?
Last verified 2026-09-03. The overview is updated whenever sources change, with a full review at least quarterly.
Want to know if your AI holds up to the requirements?
A verification audit shows exactly where your AI system and documentation actually stand — with evidence, not assumptions.
Book a verification auditInformation, not legal advice. Consult a lawyer for your specific situation.