Back to blog

AI

The AI Act has been postponed in Norway. Does that mean you can wait?

Per Andre Rønsen
Per Andre Rønsen·8 October 2026·7 min read
The AI Act has been postponed in Norway. Does that mean you can wait?

The EU has postponed the strictest parts of the AI Act, and Norway's own AI law will arrive later than the government first said. It is tempting to read that as permission to park the topic. That would be a mistake. Large parts of the regulation already apply in the EU, the bans have been in force for more than eighteen months, and the transparency rules for AI-generated content took effect this August. Here is the timeline, and what it means for a Norwegian business that uses or builds AI solutions.

The EU AI Act timeline

  • 1 August 2024: The AI Act (Regulation (EU) 2024/1689) enters into force in the EU. The rules are phased in.
  • 2 February 2025: The bans on certain AI practices apply, such as social scoring and manipulative systems. The AI literacy requirement for people using the systems applies from the same date.
  • 30 June 2025: The Norwegian government sends a draft AI law out for public consultation. The plan at that point is for the law to apply from late summer 2026.
  • 2 August 2025: The rules for general-purpose AI models (GPAI) apply, together with the rules on governance and penalties.
  • 19 November 2025: The European Commission proposes a "digital omnibus" on AI, a simplification package that among other things postpones the high-risk rules.
  • 8 July 2026: The EU adopts the changes as Regulation (EU) 2026/1744. They enter into force on 27 July 2026.
  • 2 August 2026: Most of the regulation applies, including the transparency obligations in Article 50. Chatbots must tell users they are talking to a machine, and deepfakes must be labelled.
  • 4 August 2026: Norway's Minister of Digitalisation, Karianne Tung, announces a new consultation on the AI law in autumn 2026.
  • 2 December 2026: Deadline for machine-readable marking of AI-generated content (Article 50(2)) for systems already on the market before 2 August 2026. The omnibus gave them four extra months.
  • Spring 2027: The government's target for presenting the AI law to the Storting, Norway's parliament.
  • 2 December 2027: The high-risk rules apply to stand-alone systems listed in Annex III, such as AI used in recruitment, education, credit scoring and critical infrastructure. The original date was 2 August 2026.
  • 2 August 2028: The high-risk rules apply to AI built into products already regulated by the EU (Annex I), such as medical devices and machinery. The original date was 2 August 2027.

What has been postponed?

The postponement covers the requirements for high-risk systems: risk management, data quality, documentation, human oversight and conformity assessment before a system goes into use. The Commission's reasoning was that the standards and guidance companies need in order to comply were not ready. Regulation (EU) 2026/1744 moved the deadlines to 2 December 2027 and 2 August 2028.

The omnibus changed a few other things too. The AI literacy requirement in Article 4 has been softened: instead of ensuring staff have a "sufficient" level of AI literacy, organisations must now support the development of it. A new ban was also added on AI systems that generate non-consensual sexual content of real people and child sexual abuse material. According to the European Commission, it applies from December 2026.

So the delay covers one category, albeit the most demanding one. Most of what a typical Norwegian business uses AI for (content production, customer service, analytics, internal efficiency) falls outside the high-risk category anyway.

What already applies?

Three parts of the regulation apply in the EU today.

The bans. Since February 2025 it has been prohibited to use AI for, among other things, social scoring, manipulation that exploits vulnerabilities, and emotion recognition in workplaces and schools (with some exceptions). Few Norwegian businesses do any of this, but it is worth knowing where the line is.

The rules for general-purpose AI models. Providers of large language models have had obligations since August 2025. This mainly affects companies such as OpenAI, Google and Anthropic. As a user of the models, you will notice it mostly through the documentation providers now have to publish.

The transparency obligations in Article 50. This part has not been postponed, apart from the four extra months for machine-readable marking. Since 2 August 2026, the following applies in the EU:

  • A chatbot or AI assistant must make it clear to users that they are dealing with an AI system, unless that is obvious.
  • Images, audio and video generated or manipulated to resemble real people or events (deepfakes) must be labelled.
  • AI-generated text published to inform the public on matters of public interest must be labelled, unless a human has reviewed it and holds editorial responsibility.
  • Providers of generative systems must mark the output in a machine-readable way.

For many businesses, this is the part with the first practical consequences. If you have a chatbot on your website or use AI-generated images in your marketing, start here.

What does this mean for Norway?

The AI Act is relevant to the EEA, but it does not apply in Norway until it has been incorporated into the EEA Agreement and implemented in Norwegian law. The government sent a draft AI law out for consultation in June 2025, aiming for it to apply from late summer 2026. That plan did not hold. The consultation drew just under 150 responses, and once the EU adopted the omnibus changes, the bill had to be updated. In a press release on 4 August 2026 (in Norwegian), the ministry says the proposal will go out for a new consultation in autumn 2026. The minister aims to present it to the Storting in spring 2027.

Supervision has been settled. Nkom has been designated as the coordinating market surveillance authority and national point of contact, while sector regulators keep responsibility in their own areas. Norwegian Accreditation will oversee the bodies that carry out conformity assessments.

Two things mean you cannot rely on the Norwegian delay:

  1. You may be covered by the EU rules directly. The regulation applies to anyone who places AI systems on the EU market or uses them there, wherever the business is established. If you sell to customers in Sweden, Denmark or Germany, or run a website with a chatbot aimed at EU users, the requirements may already apply to you.
  2. Other legislation applies regardless. The government itself points out that data protection law, the Penal Code and copyright law also apply when you develop and use AI. A privacy breach in an AI solution is a GDPR breach today.

Frontkom has offices in Poland and Portugal, where the regulation applies directly as EU law. For us this is not a future scenario. We follow the same rules as our clients in the EU.

What you should do now

The postponement gives you more time on the high-risk part. The rest is worth going through now, while things are still quiet.

  1. Map your AI use. Write down which AI tools and features you use, who supplies them and what they are used for. Include features built into systems you already have, such as your CRM, CMS and customer service platform.
  2. Place each use in a risk category. Most will land in the low-risk or transparency category. If you use AI to screen job applicants, assess students or make credit decisions, you are probably in the high-risk category, and you have until December 2027.
  3. Check your transparency. Is it clear that the chatbot is a machine? Are AI-generated images and videos that could be mistaken for reality labelled? This already applies in the EU and will apply in Norway.
  4. Set requirements for your suppliers. Ask for documentation on which models are used, where data is processed and how the supplier approaches the AI Act. It is easier to get this into the contract now than to renegotiate later.
  5. Train your staff. The AI literacy requirement has been softened, but the need is the same. People who use AI at work should know what the tools do well, where they fail and what they should never feed them.
  6. Follow the new consultation. When the ministry publishes the updated proposal this autumn, read how Norway plans to handle supervision and penalties.
The postponement covers high-risk systems. The bans, the transparency rules and the rules for AI models already apply in the EU, and Norwegian businesses operating there are covered.

At Frontkom I help organisations map their AI use and choose solutions that will hold up under both today's rules and the ones coming next. We are following the new consultation closely.

Sources

Transparency note: This article is based on the author's own analysis and experience. AI has been used as an editorial aid for language and structure.