Hopp til hovedinnhold

Law Radar

Which AI and security deadlines apply to Norwegian businesses — right now?

The Digital Security Act has been in force since 1 October 2025, the EU AI Act has several deadlines between 2025 and 2028, and a Norwegian AI Act is expected no earlier than H2 2027. This is a source-verified map of what actually applies — preparation for a dated regime, not fear-mongering.

Last verified 2026-09-03

Norway

1 October 2025

Confirmed

Digital Security Act enters into force (NIS1-level)

Applies to operators of critical digital infrastructure and services in covered sectors. Registration duty and incident-notification duty are already in force.

Source

2 October 2025

Expected

Registration with NSM — via PDF form

Entities covered by the Digital Security Act must register "as quickly as possible". No digital registration portal is confirmed live — registration currently happens via a PDF form emailed to NSM.

Source

1 July 2026

Expected

Digital Services Act (DSA) national implementation planned in force

Hearing closed 1 October 2025. Nkom is proposed as coordinating authority, with Medietilsynet, Forbrukertilsynet and Datatilsynet as competent authorities for different parts. EEA incorporation is still pending.

Source

1 September 2026

Expected

Hearing on AI Act adjustments following the EU Digital Omnibus

The government has signalled an updated hearing round on the Norwegian AI Act following the EU's Digital Omnibus deferral. Nkom is proposed as coordinating authority and Norwegian EU contact point.

Source

1 January 2027

Expected

NSM regular supervision begins (not autumn 2026)

NSM is fixing supervision intervals during 2026; regular supervision is stated to begin in 2027, per NSM's own guidance. Often incorrectly reported as "supervision starting autumn 2026" — that is not accurate.

Source

1 March 2027

Expected

AI Act: bill submitted to the Norwegian parliament

A bill is expected spring 2027, with entry into force likely H2 2027. EEA negotiations are the main bottleneck. No enacted law or fixed date exists yet.

Source

EU

2 February 2025

Confirmed

AI Act: prohibited practices (art. 5) + AI literacy (art. 4)

Applies to anyone offering or using AI systems in the EU/EEA market, regardless of where the company is established. Prohibited practices and literacy requirements are already in force.

Source

2 August 2025

Confirmed

AI Act: general-purpose AI (GPAI) model obligations

Applies to providers of general-purpose AI models placed on the EU/EEA market.

Source

2 August 2026

Confirmed

AI Act art. 50: transparency duties (AI-content labelling, chatbot disclosure)

Applies to anyone offering chatbots, deepfakes or AI-generated content to EU/EEA users — including Norwegian companies without a European establishment. Transitional period for existing systems until roughly 2 December 2026.

Source

2 December 2027

Confirmed

AI Act Annex III: high-risk obligations (deferred by the Digital Omnibus)

Applies to high-risk AI systems (e.g. employment, credit, judiciary). The deadline was deferred from 2026 to December 2027 by the Digital Omnibus regulation.

Source

2 August 2028

Confirmed

AI Act Annex I: high-risk AI in regulated products

Applies to AI systems embedded in products covered by existing EU product-safety legislation (machinery, medical devices, etc.).

Source

Sweden & Denmark

15 January 2026

Confirmed

Sweden: Cybersecurity Act (2025:1506) enters into force — NIS2 implemented

Roughly 8,000 organizations across 18 sectors are covered, including registration duties, management liability and incident reporting. Directly affects Norwegian parent companies with Swedish subsidiaries.

Source

2 August 2026

Expected

Sweden: national adaptation to the AI Act (PTS/IMY)

A government inquiry (SOU 2025:101) proposes PTS as lead supervisor with IMY/Finansinspektionen as co-supervisors for high-risk AI. Still at the inquiry stage — not enacted law.

Source

1 July 2025

Confirmed

Denmark: NIS2 Act enters into force

Registration on Virk.dk had a deadline of 1 October 2025 (already passed). Directly affects Norwegian parent companies with Danish subsidiaries, and Norwegian suppliers to Danish NIS2-covered customers.

Source

2 August 2025

Confirmed

Denmark: supervision of prohibited AI practices (interim act)

Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen supervise the AI Act's prohibited practices under an interim act, pending the full Danish AI Act.

Source

2 August 2026

Confirmed

Denmark: Danish AI Act (L 111) enters into force

Replaces the interim act. Digitaliseringsstyrelsen becomes lead supervisor with inspection and sanction powers; the regulatory sandbox is run jointly with Datatilsynet.

Source

16 deadlines tracked across Norway, the EU, Sweden and Denmark. Every row carries a primary source and a confidence marker. This page is information, not legal advice.

Frequently asked questions

Is my company covered by the Digital Security Act?

The Digital Security Act applies to operators of critical digital infrastructure and services in covered sectors. It entered into force on 1 October 2025. If you are unsure, the safest step is to clarify scope with NSM in writing before assuming anything.

When does the Norwegian AI Act apply?

No Norwegian AI Act has been enacted yet. A bill is expected spring 2027, with possible entry into force in H2 2027 — depending on EEA negotiations. Until then, the EU AI Act applies to Norwegian companies only via their activity in the EU/EEA market.

What does NIS2 require from suppliers?

NIS2 is not yet EEA-incorporated or implemented in Norway — the Digital Security Act is at NIS1 level. But Norwegian suppliers to Swedish or Danish customers already face NIS2-grade requirements today, via supply-chain obligations passed down from those NIS2-covered customers.

Does the AI Act apply to Norwegian businesses today?

Partially. Prohibited practices and AI-literacy requirements have been in force since February 2025, and from 2 August 2026 transparency duties (art. 50) apply to chatbots and AI-generated content aimed at EU/EEA users — including Norwegian companies without a European establishment.

What do "Confirmed" and "Expected" mean on this page?

"Confirmed" means the date is in force or fixed in an enacted law, regulation or EU act. "Expected" means a government or authority has signalled intent, but no enacted law or fixed date exists yet. We never change a category without a new source.

What should I do now if I am unsure whether I am covered?

Start by documenting which laws and regulations could actually apply to your business — including through EU sales, Swedish/Danish subsidiaries, or supply chains. A verification audit can reveal whether your AI systems and documentation hold up against the requirements that already apply.

Is this page legal advice?

No. This is information based on publicly available primary sources, not legal advice. Consult a lawyer for your specific situation.

How often is this overview updated?

Last verified 2026-09-03. The overview is updated whenever sources change, with a full review at least quarterly.

Want to know if your AI holds up to the requirements?

A verification audit shows exactly where your AI system and documentation actually stand — with evidence, not assumptions.

Book a verification audit

Information, not legal advice. Consult a lawyer for your specific situation.