Skip to main content

    Denmark met the deadline. Sweden is late. Norway is outside the regime.

    A model classified Critical for cyber capability shipped this month and no Nordic AI authority has issued operational guidance in response. What policymakers, businesses and citizens should do — and what the region is getting right.

    Javad Mushtaq · Founder and Executive Director · 5 September 2026

    Reading time 12 min · Published by ImpactLab

    Issue 02 of this publication argued that the Nordic model is a strength when treated as craft and a liability when treated as a brand, and that the region's real comparative advantage is the operational business of running AI well inside ordinary public institutions under EU law.

    I still believe that. It is worth checking, this month, how the craft is doing.

    On 3 September a frontier laboratory shipped the first model it classifies as Critical for cyber capability, and disclosed that its ability to monitor that model has gone backwards. In June the European Systemic Risk Board raised systemic cyber risk from elevated to severe. [1] In July ENISA published an assessment finding that frontier models compress the window from vulnerability discovery to exploitation to "hours or even minutes," enable weaponisation "within 15 minutes of disclosure," and can "orchestrate entire autonomous attack campaigns" — and named the resulting problem an "Authority Gap," because human authorisation cannot operate at machine speed. [2] In July the European Supervisory Authorities issued concrete control expectations to financial entities. [3]

    Against that: no Nordic AI authority has published anything operational on deploying models of this class. Not one. The single piece of new, dated, practical Nordic AI Act guidance issued in 2026 came from Finland's transport and communications agency on 20 August, and it concerns transparency labelling. [4]

    That is the honest position. It is not a reason for despair, and this issue is not a lament — the Nordics are executing very well on one dimension and there are specific, cheap things available on the others. But the gap between the region's self-description and its current output is real, and pretending otherwise is exactly the brand-over-craft failure Issue 02 warned about.

    Where each country actually stands

    The AI Act required Member States to designate market surveillance and notifying authorities by 2 August 2025. Nine of twenty-seven met it. [5]

    Denmark met it. Law No. 467 entered into force on the day, with the Agency for Digital Government as national coordinating supervisory authority under a sector-based model. Sector supervisors are still incompletely specified and the agency's published material does not yet state that enforcement is operational — but Denmark is the only Nordic country that had a law in force on the deadline.

    Finland was five months late but is now furthest ahead in practice. Act 1377/2025 entered into force on 1 January 2026, with supervision decentralised across existing regulators and Traficom as single point of contact. Finland is also the only Nordic country to have published new practical AI Act guidance this year.

    Sweden is thirteen months late and still legislating. PTS holds an interim assignment as national competent authority that runs only to 31 December 2026. IMY received a permanent market surveillance designation on 15 June 2026. The enabling statute, SOU 2025:101, went out for consultation on 11 November 2025 and has not been enacted. PTS's own page notes that the AI Act applies as Swedish law but presupposes complementary national provisions that do not yet exist. Sweden's national AI strategy, published in February 2026, does not mention the AI Act.

    Norway and Iceland are outside the regime. The AI Act has not been incorporated into the EEA Agreement. EFTA's own record lists it as under scrutiny with a draft Joint Committee Decision under consideration and no date. [6] Incorporation requires Storting consent under Article 103. Norway and Iceland attend AI Board meetings as observers.

    And Norway's position is worse than that, because it compounds. Its AI law is not in force; the second consultation announced on 4 August had not launched as of publication; the minister's stated ambition is to put the bill to the Storting in spring 2027. [7] Its AI Act regulatory sandbox, per its own published page, "will open when the AI law comes into force in Norway. This is likely to happen during 2027." [8]

    And Norway has not implemented NIS2. Its digital security act implements the original NIS Directive. NSM's own page states NIS2 will be introduced into Norwegian law "eventually," together with the CER Directive, with no date. [9] Denmark, Finland and Sweden all have NIS2 regimes in force.

    So at the moment a Critical-cyber-capability model reaches market, Norway has neither the AI Act nor NIS2 — its critical-infrastructure regime is one directive generation behind its neighbours, and its AI regime is not law at all.

    For completeness: Norway's most recent national threat assessment, published in February 2026, does address AI. [10] It notes that Chinese threat actors are reported to have conducted the first cyber operation almost entirely orchestrated by AI, that less capable actors are gaining the ability to run operations that previously required higher technical competence, and that NSM and PST expect Norwegian entities to face AI-assisted cyber operations during 2026. That is a serious document. It also frames AI as an attacker's support tool, which was the right frame in February and is six months behind where the capability now is.

    What the Nordics are getting right

    The compute story is the one place the region is executing, and it deserves saying plainly because it is genuinely good work.

    Norway's KI-fabrikken opened in November 2025. Its Olivia system expanded from 304 to 448 accelerator chips in March 2026. On 31 August the LUMI-AI contract was signed — €387.8 million, sited at Kajaani, roughly ten times LUMI's current AI capacity, operational in 2027 — and on 1 September Norway joined the consortium, paying €20.4 million for just over three percent of the machine, which nonetheless gives it more compute than all of Olivia. [11] Denmark committed up to DKK 750 million over five years to European AI gigafactory capacity on 31 July, explicitly framed by its research and digitalisation minister around dependence on non-EU providers. [12] Denmark's Gefion is operational. Finland is bidding to host an EU gigafactory.

    Adoption is also strong. On Eurostat's 2025 figures, Denmark leads the European Union on enterprise AI use at 42 percent, with Finland at 38 and Sweden at 35, against an EU average near 20. [13] Norway is outside the Eurostat series, but Statistics Norway records 30 percent of enterprises with ten or more employees using AI in 2025, up from 20 the previous year, and 58 percent among those with more than 100 employees. [14]

    That is a region with compute, adoption and public trust. The missing layer is the one Issue 02 said was the comparative advantage: the operational craft.

    The two Nordic vehicles that were supposed to produce it

    Both exist. Neither has produced output.

    KI Norge was announced by Digdir in September 2025 with NOK 30 million for establishment, sandbox and AI oversight. Hans Christian Holte was named director in June 2026. Its website was published on 20 August 2026, self-described as a first version still under development. Its sandbox opens with the AI Act, likely in 2027. [8]

    The Nordic-Baltic AI Center received DKK 30 million over three years from the Nordic Council of Ministers in June 2025 and launched in October 2025 with a secretariat in Stockholm. One of its three active projects is an AI Act Implementation Network — precisely the vehicle that would produce cross-Nordic AI Act guidance. Its own page describes intent: clear, user-friendly pathways to compliance, mapping existing tools. It has published nothing. No deliverables, no timeline. [15]

    I do not raise these to score points. Both are the right idea and both are recently established. But an organisation whose stated purpose is implementation guidance, funded for over a year, is measured by guidance published — and the moment at which that guidance would have been most useful is now.

    For policymakers

    Publish the interim rule. Norway's most valuable available document is one page stating which existing Norwegian instruments govern AI deployment while the KI-loven is absent, and what a public body should do in the meantime. Not a strategy. A page. The same applies to Sweden during PTS's interim mandate, which expires on 31 December 2026 with no successor statute enacted.

    Do NIS2 before the AI Act. For Norway specifically, this is the sequencing argument I would make hardest. The AI Act is blocked on an EEA process Norway does not control. NIS2 is blocked on nothing. A Critical-cyber-capability model raises the risk to critical infrastructure now, and NIS2 is the instrument that addresses it. Norway is choosing to wait on the file it cannot move while not moving the file it can.

    Adopt ENISA's operational recommendations directly. They are written for national authorities and they are specific: run AI-powered threat-hunting operations and publish anonymised datasets; require critical infrastructure operators to attest zero-trust baselines; develop evaluation capacity for products with AI functionality; proactively scan critical infrastructure components. [2] A Nordic authority could adopt these as supervisory expectations this quarter without any legislative change.

    Give the Nordic AI Act Implementation Network a deadline and a deliverable. It is funded, staffed and mandated. The Nordic Council of Ministers should ask it for one published artefact — a common Nordic reading of deployer obligations under Articles 4, 26 and 50 — with a date.

    And publish the grid allocation methodology. Norwegian data centres now hold 3,841 MW of 7,837 MW of reserved new consumption — just under half, on Statnett data as at 10 August 2026 reported by Filter Nyheter. [17] There is still no published methodology for evaluating or prioritising that allocation; the only instrument added in 2026 was a national-security override in force from 1 July. Issue 12 argued this before the numbers grew. They have grown.

    For businesses

    The obligations that bind you today are not the ones being discussed. Article 50 transparency became enforceable on 2 August 2026 and was not deferred by the Omnibus: disclose AI interaction, mark synthetic content, label deepfakes. Article 4 literacy has applied since February 2025, though the Omnibus weakened it from an obligation of result to an obligation of means. The high-risk obligations everyone is preparing for are deferred to December 2027 and August 2028. Most organisations have this exactly backwards.

    Know whether you are a deployer or a provider. Nkom flags the trap directly: integrate a general-purpose model into your own system and place it on the market, and you may become a provider with the full obligation set rather than a deployer. [16] For any company building on Astra or its competitors, this is the single most expensive determination to get wrong.

    Use the financial-sector documents even if you are not a financial entity. The European Supervisory Authorities' statement of 31 July is the most operational guidance published anywhere on frontier-model cyber risk. [3] Its controls are sector-neutral in substance: maintain a continuously updated inventory of IT assets including AI components and APIs; protect source-code confidentiality specifically to prevent AI-driven vulnerability analysis; move from periodic to continuous vulnerability scanning; enforce standards across supply chains; run resilience tests simulating AI-enhanced threat scenarios. If you are looking for something to put in front of a board this quarter, that is the document.

    Take ENISA's detection benchmark seriously. Its recommendation is to target single-digit-minute mean-time-to-detect. Against a median data-exfiltration time of 72 minutes and exploitation windows measured in minutes, quarterly penetration testing is not a control. [2]

    Write the clauses now. Procurement does not wait for transposition. Every AI contract signed between now and December 2027 either carries documentation, oversight and literacy obligations or it does not. In Norway and Iceland, where none of this is legally binding, the contract is the only instrument you have.

    For civil society, and for citizens

    The accountability question has moved and almost nobody has noticed. The debate most people are having is about bias, employment and misinformation. Those matter. But the disclosure that should concern a democratic public most this month is that a model's developer has said its ability to monitor that model has decreased, and has not published the level at which it would stop. That is a question about who gets to make an unobserved judgement on everyone's behalf, and it belongs in public debate rather than in a system card appendix.

    Ask the concrete question, not the abstract one. For any Nordic public body deploying AI, the useful questions are: which instruments govern this deployment today, given that the AI Act is not in force here; who supervises it; what happens if it fails; and where is that written down. In Norway those questions currently have no good answers, and the fact that they have no good answers is itself the finding.

    Watch the register, not the strategy. Strategies are cheap. The test of a state's AI governance is whether it can enumerate the AI systems its own institutions run. Norway's only public overview of AI in the public sector was abandoned in September 2024, and its replacement was published as a first version last month with a sandbox that opens in 2027.

    And note what is not a Nordic problem. Enterprise adoption in Denmark, Finland and Sweden leads Europe. Public trust is high. Compute is being bought at scale, in Europe, on European terms. The deficit is narrow and specific — supervisory guidance and implementation craft — which is the most fixable category of deficit there is, and the one the Nordics have historically been best at.

    The objection worth taking seriously

    The strongest objection is that this criticises the Nordics for the pace of a European process they do not control, and for failing to regulate a capability that shipped days ago. Regulators do not move in a week and should not. Denmark, Finland and Sweden are implementing a regulation on the timetable available; Norway is bound by an EEA process requiring parliamentary consent. Demanding that a national AI authority respond to a model release is demanding something no authority anywhere has done.

    That is fair on the AI Act and on Astra specifically, and it is why the concrete asks above are mostly not about the AI Act at all. They are about NIS2, which Norway could have done and has not; about ENISA's recommendations, which require no legislation; about a one-page interim rule; and about a funded Nordic body publishing the guidance it was funded to publish. None of those is blocked in Brussels.

    The deeper answer is that the region has spent two years describing itself as the place that would do implementation well. That claim now has evidence available against it, and the honest response is to fix the implementation rather than adjust the claim.

    The bear case

    If, by the end of 2027, the Nordic AI Act Implementation Network has published a common Nordic reading of deployer obligations, and Norway has either introduced the KI-loven or published interim supervisory expectations, then the gap described here was a transitional lag competently closed, and this issue was written at the low point of a curve. That is the outcome we want and we will report it.

    If neither has happened by then — if the Network has still published nothing and Norway is still waiting on an EEA decision with no date — then the craft claim in Issue 02 will have been a brand claim after all, and this publication will have to say so about a region it is based in.

    What ImpactLab is doing

    The Nordic AI Blueprint, publishing in the fourth quarter of 2026, is an open, versioned clause library for ministries and agencies operating under the AI Act and EEA-equivalent frameworks. It is built for exactly the interim described above: the procurement instrument is available whether or not the transposition is.

    The governance track of the Nordic Responsible AI Summit's second edition, in autumn 2026, produces the procurement clause library as its working-session output. Its literacy track produces the AI for Norway curriculum framework.

    The AI Policy Radar tracks incorporation and implementation status jurisdiction by jurisdiction, with Nordic maturity scores added this quarter.

    AI for Norway adapts Harvard and MIT executive AI curriculum into a six-module Norwegian-language framework built around the decisions public servants actually make, with a pilot in Østfold and a pilot cohort opening this autumn.

    Bear case · Open · Resolves Q4 2027

    If the Nordic AI Act Implementation Network publishes a common Nordic reading of deployer obligations and Norway either introduces the KI-loven or publishes interim supervisory expectations before the end of 2027, the gap described here was a transitional lag competently closed. If neither happens, the craft claim in Issue 02 was a brand claim.

    All tracked bear cases

    Footnotes

    1. [1] European Systemic Risk Board, Warning ESRB/2026/3, adopted 25 June 2026, published 7 July 2026. https://www.esrb.europa.eu/news/pr/date/2026/html/esrb.pr260707~4e1b68241a.en.html
    2. [2] ENISA, "ENISA’s view on Cybersecurity in the Frontier AI Era", 7 July 2026. https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era
    3. [3] European Supervisory Authorities, "Statement on frontier AI models", JC 2026 25, 31 July 2026 (PDF). https://www.esma.europa.eu/sites/default/files/2026-07/JC_2026_25_ESA_statement_on_frontier_AI_models.pdf
    4. [4] Traficom, guidance on AI transparency obligations, 20 August 2026. https://www.traficom.fi/fi/uutiset/tekoalyn-kaytosta-nyt-kerrottava-aiempaa-avoimemmin-traficom-julkaisi-ohjeet-uusiin-velvoitteisiin (Published in Finnish.)
    5. [5] AI Act national implementation status tracker, covering Denmark (Law No. 467), Finland (Act 1377/2025) and Sweden (PTS interim assignment, IMY designation of 15 June 2026). https://artificialintelligenceact.eu/national-implementation-plans/ Primary source: Danish Agency for Digital Government, AI Act supervision pages. https://digst.dk/tilsyn/ai-forordningen/
    6. [6] EFTA, EEA-Lex record for Regulation (EU) 2024/1689: under scrutiny for incorporation, draft Joint Committee Decision under consideration. https://www.efta.int/eea-lex/32024r1689
    7. [7] Government of Norway, announcement of a second consultation on the KI-loven, 4 August 2026. https://www.regjeringen.no/no/aktuelt/tung-vil-sende-ki-loven-med-endringer-pa-horing/id3169693/ (Published in Norwegian. The consultation had not appeared on the government consultation index at the time of publication.)
    8. [8] KI Norge, regulatory sandbox page, and the Digdir establishment announcement of 18 September 2025. https://ki.norge.no/sandkasse Primary source: Digdir, "Digdir etablerer KI Norge". https://www.digdir.no/kunstig-intelligens/digdir-etablerer-ki-norge/7412
    9. [9] NSM, "Ny digitalsikkerhetslov i Norge", confirming that the Norwegian act implements the original NIS Directive and that NIS2 will follow "eventually". https://nsm.no/aktuelt/ny-digitalsikkerhetslov-i-norge (Published in Norwegian.)
    10. [10] NSM, Risiko 2026, 6 February 2026. https://nsm.no/regelverk-og-hjelp/rapporter/risiko-2026
    11. [11] Sigma2, "Norway joins LUMI-AI, Europe’s new AI supercomputer", 1 September 2026. https://www.sigma2.no/news/2026/norway-joins-lumi-ai-europes-new-ai-supercomputer Primary source: EuroHPC JU, contract signature for the LUMI-AI supercomputer, 31 August 2026. https://www.eurohpc-ju.europa.eu/eurohpc-ju-signs-contract-deploy-lumi-ai-supercomputer-2026-08-31_en
    12. [12] Danish Ministry of Higher Education and Science, commitment to procure AI gigafactory capacity, 31 July 2026. https://ufm.dk/aktuelt/pressemeddelelser/2026/juli/danmark-melder-sig-paa-banen-i-projekt-med-ai-gigafabrikker/ (Published in Danish.)
    13. [13] Eurostat, "Use of artificial intelligence in enterprises", reference year 2025. https://ec.europa.eu/eurostat/statistics-explained/index.php?title=Use_of_artificial_intelligence_in_enterprises
    14. [14] Statistics Norway, "Bruken av KI har skutt fart det siste året", 24 September 2025. https://www.ssb.no/teknologi-og-innovasjon/informasjons-og-kommunikasjonsteknologi-ikt/statistikk/bruk-av-ikt-i-naeringslivet/artikler/bruken-av-ki-har-skutt-fart-det-siste-aret (Published in Norwegian.)
    15. [15] New Nordics AI, AI Act Implementation Network project page; funding approved by the Nordic Council of Ministers, 18 June 2025. https://www.newnordics.ai/ai-act-implementation-network Primary source: Nordic Council of Ministers, funding approval for the Nordic-Baltic AI Center. https://www.norden.org/en/news/nordic-council-ministers-approve-funding-nordic-baltic-ai-center
    16. [16] Nkom, "De kraftigste KI-modellene – hvilke regler gjelder?" https://nkom.no/ki/regulering/kraftige-modeller (Published in Norwegian.)
    17. [17] Filter Nyheter, analysis of Statnett reserved-capacity data as at 10 August 2026, published 4 September 2026. https://filternyheter.no/datasenter-legg-beslag-pa-halvparten-av-kraftreservasjonane-i-noreg-og-fire-andre-grafar-om-utviklinga/ Primary source: Statnett, requests and reservations in the grid. https://www.statnett.no/for-aktorer-i-kraftbransjen/nettkapasitet-til-produksjon-og-forbruk/foresporsler-og-reservasjon-i-nettet/ (Statnett publishes the underlying reservation data through a dashboard rather than a citable document; the figures here are as reported.)

    Cite this issue as: ImpactLab, The Dispatch, Issue 17, 5 September 2026.

    Author

    Javad Mushtaq

    Founder and Executive Director, ImpactLab. The byline is set inside the publication; ImpactLab is the publisher of record.