Procurement is the underrated frontier of European AI policy
The most important AI decisions in Europe over the next thirty-six months will not be made in legislatures. They will be made in tenders.
Javad Mushtaq · Founder and Executive Director · 2 April 2026
Reading time 4 min · Published by ImpactLab
Editor's note
- Clarification · 13 August 2026The five clauses set out here and the five contract conditions in Issue 03 are the same instrument, developed across both essays rather than two separate proposals. Read Issue 03
A useful test of any AI-policy ecosystem is to ask which document its officials reach for first when they have a real decision to make. In most Nordic public-sector institutions in 2026, the answer is no longer the AI Act, the national AI strategy, or even the deployer's internal AI policy. It is the tender document.
The EU AI Act sets the legal frame. The Norwegian AI Act, expected in summer 2026, transposes it into Norwegian law with Nkom as the proposed coordinating supervisory body [1]. National strategies set the political frame. But the actual decisions about which AI gets deployed in Norwegian municipalities, hospitals, agencies, and education systems — what data flows are accepted, what oversight is meaningful, what risk thresholds are tolerable, who is liable for what — are decided in procurement.
This is the gap. It is also the leverage point.
Why procurement is where the policy actually happens
Three structural features make procurement the operative layer.
First, AI Act compliance is enforced on deployers as well as providers. Article 4 has applied since 2 February 2025, and applies to deployers and the persons acting on their behalf, calibrated to the persons on whom the AI is used [2]. The deployer therefore needs to know what it is buying, in detail, before it buys.
Second, the Norwegian AI Act will explicitly require organisations to map AI usage including indirect use via third-party systems, to determine their role for each AI system (provider or deployer), and to assess risks based on use and purpose [1]. None of those determinations are possible without contractual artefacts created in procurement.
Third, the cost of getting compliance wrong is asymmetrically high for public bodies. Reputational risk, audit risk, parliamentary risk, and citizen-trust risk all converge on the moment a public-sector body has to explain why it bought a system that produced a discriminatory or opaque outcome.
Procurement is the place where deployer obligations under both regimes are operationalised, in writing, with money attached.
What good Nordic AI procurement looks like in practice
Five clauses define a defensible Nordic public-sector AI procurement in 2026.
One. A vendor representation that the system is or is not a high-risk AI system under Annex III of the EU AI Act, with the reasoning, and an obligation to update if the classification changes.
Two. A model and data documentation appendix — at minimum a model card, training-data summary, evaluation summary, and known-limitations statement — refreshed at agreed intervals, in a form that survives staff turnover on both sides.
Three. A human-oversight specification consistent with Article 14 of the AI Act: who exactly performs oversight, what they are trained on, what they can override, what they cannot override, and how the oversight log is preserved.
Four. An AI literacy obligation flowed down from Article 4: the vendor identifies the staff and persons acting on its behalf who interact with the system, and certifies, with documentation, that their literacy has been calibrated to context.
Five. An exit and portability clause: at termination, the deployer receives the inputs it provided, a portable record of decisions made, and the documentation needed to defend prior decisions in a regulator-led review.
These five clauses are not exotic. They are within reach of every Nordic municipality, hospital trust, and public agency that has a competent legal and IT function. They are not yet standard.
The geopolitical layer
There is a second reason procurement matters more than commonly recognised, and it is geopolitical. The Microsoft–G42 Intergovernmental Assurance Agreement, signed in April 2024, has set a template for how state-to-state assurance is built into commercial AI deployments [3]. Nordic ministries are now operating in a world where, alongside their domestic procurement standards, an allied-assurance overlay sits behind the largest vendors. That overlay is mostly invisible at procurement-officer level. It should not stay invisible.
Practically, this means that Nordic procurement officers buying AI from a US-headquartered hyperscaler in 2026 are buying into a stack that has commitments — on cybersecurity, export controls, technology transfer, data protection, responsible AI, and KYC — to a third government. Those commitments are, on balance, in Nordic interests. They should still be understood and documented.
The Nordic export opportunity
If Norway and its Nordic peers do this work seriously between mid-2026 and late 2027, they will accumulate something rare and exportable: a body of public-sector AI procurement craft tested under the EU AI Act, harmonised with national transpositions, robust against allied-assurance overlays, and reusable across the rest of Europe.
This is exactly the export Norway should be building. Not frontier models. Not sovereign-scale chip stacks. The unglamorous, durable craft of buying AI well, in the public interest, and being able to defend the buy in front of a parliament, a press corps, and a citizen.
Procurement is also the place where AI literacy, diversity, climate cost, and oversight stop being values statements and become contract clauses. The next thirty-six months will reward the institutions that take this layer seriously.
Bear case · Open · Resolves Q4 2028
If, by the end of 2028, no national procurement authority in the EU or EEA has published AI-specific contract clauses covering literacy, evaluation and exit, then the tender is not where these decisions are being made.
Footnotes
- [1] Schjødt, Line Krydsby, "Norway's new AI Act — what it will mean for your business", 15 January 2026. https://svw.no/en/norways-new-ai-act-what-it-will-mean-for-your-business/ ↩
- [2] European Commission, Directorate-General for Communications Networks, Content and Technology, "AI literacy — questions & answers", 2025. https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers ↩
- [3] Microsoft, Brad Smith, "Microsoft's $15.2 billion USD investment in the UAE", 3 November 2025. https://blogs.microsoft.com/on-the-issues/2025/11/03/microsofts-15-2-billion-usd-investment-in-the-uae/ ↩
Cite this issue as: ImpactLab, The Dispatch, Issue 07, 2 April 2026.
Author
Javad Mushtaq
Founder and Executive Director, ImpactLab. The byline is set inside the publication; ImpactLab is the publisher of record.