AI regulation in Denmark is shaped primarily by the EU AI Act, which applies directly across all EU member states, including Denmark. Businesses deploying or developing artificial intelligence systems in Denmark must now navigate a layered framework: EU-level rules, Danish national implementation measures, and sector-specific requirements enforced by Danish authorities. This guide covers the current regulatory landscape, the obligations that apply to different types of AI systems, the competent authorities, enforcement mechanisms, and the practical steps companies must take to remain compliant.
What the EU AI Act means for businesses operating in Denmark
The EU AI Act is the world';s first comprehensive horizontal legal framework for artificial intelligence. It entered into force in recent years and applies directly in Denmark without the need for national transposition into Danish law. The Act establishes a risk-based classification system that determines the obligations placed on providers, deployers, importers and distributors of AI systems.
The Act divides AI systems into four categories. Prohibited AI practices are banned outright - these include systems that use subliminal manipulation, exploit vulnerabilities of specific groups, or enable real-time remote biometric identification in public spaces by law enforcement, subject to narrow exceptions. High-risk AI systems face the most demanding compliance requirements. Limited-risk systems are subject to transparency obligations. Minimal-risk systems carry no specific obligations under the Act, though general product safety and data protection rules still apply.
For businesses in Denmark, the practical starting point is determining which category their AI system falls into. High-risk systems include AI used in critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice. If a Danish company deploys an AI-powered recruitment tool, for example, it is operating a high-risk system and must comply with the full suite of obligations under the Act.
A common mistake among foreign companies entering the Danish market is assuming that because the AI Act is an EU regulation, compliance is handled at the EU level and requires no local action. In practice, Denmark has designated national competent authorities, and enforcement is conducted domestically. Ignoring the Danish enforcement layer creates real compliance risk.
Danish national authorities and their roles in AI oversight
Denmark has taken a structured approach to designating the national competent authorities required by the EU AI Act. The Danish Business Authority (Erhvervsstyrelsen) serves as the primary market surveillance authority for AI systems in most sectors. It is responsible for monitoring compliance, investigating complaints, and imposing administrative measures against non-compliant providers and deployers.
The Danish Data Protection Authority (Datatilsynet) retains its role as the supervisory authority under the General Data Protection Regulation and plays a significant role in AI oversight where AI systems process personal data. Given that most commercially deployed AI systems involve some form of personal data processing, Datatilsynet is frequently a relevant authority alongside the Danish Business Authority.
Sector-specific regulators also have a role. The Danish Financial Supervisory Authority (Finanstilsynet) oversees AI systems used in financial services, including credit scoring, fraud detection, and algorithmic trading. The Danish Health Authority (Sundhedsstyrelsen) is involved in the oversight of AI used in medical devices and healthcare settings. This multi-authority structure means that a single AI deployment may fall under the concurrent jurisdiction of two or more regulators.
A non-obvious requirement is that Denmark has also established a national AI coordination body to facilitate cooperation between these authorities and to provide guidance to businesses. This body issues non-binding guidance and best-practice recommendations, which in practice carry significant weight in enforcement proceedings. Businesses that can demonstrate they followed published guidance are in a stronger position when regulators investigate.
Compliance obligations for high-risk AI systems in Denmark
High-risk AI systems are subject to the most detailed obligations under the EU AI Act, and these obligations apply fully to providers and deployers operating in Denmark. The core requirements cover technical documentation, data governance, transparency, human oversight, accuracy and robustness, and conformity assessment.
Providers of high-risk AI systems must prepare and maintain comprehensive technical documentation before placing the system on the market or putting it into service. This documentation must describe the system';s intended purpose, the data used for training and testing, the performance metrics, the risk management process, and the measures taken to ensure accuracy and robustness. The documentation must be kept up to date throughout the system';s lifecycle.
Deployers - companies that use a high-risk AI system in a professional context - have their own distinct obligations. They must implement appropriate technical and organisational measures to ensure they use the system in accordance with the provider';s instructions. They must monitor the system';s operation, report serious incidents to the relevant authority, and conduct a fundamental rights impact assessment where the system poses risks to individuals'; rights.
In practice, founders and compliance officers should consider the following key obligations:
- Register high-risk AI systems in the EU database maintained by the European Commission before deployment.
- Establish a post-market monitoring system to track performance and detect issues after deployment.
- Ensure human oversight mechanisms are in place, meaning a qualified person can intervene, override or shut down the system.
- Maintain logs of the system';s operation for the period specified in the Act, which varies by system type.
- Provide clear information to individuals interacting with the AI system where transparency obligations apply.
Many companies underestimate the documentation burden. Preparing adequate technical documentation for a high-risk system typically requires input from legal, technical and compliance teams, and the process takes several weeks at minimum. Starting this process after deployment is a common and costly mistake.
If your business is deploying or developing AI systems in Denmark and you are uncertain about your classification or compliance obligations, contact info@vlolawfirm.com. We can help structure the compliance framework correctly from the outset.
General-purpose AI models and foundation models under Danish and EU rules
The EU AI Act introduced specific obligations for general-purpose AI (GPAI) models - large AI models trained on broad data that can be adapted to a wide range of tasks. This category is particularly relevant for technology companies and research institutions operating in Denmark.
Providers of GPAI models must prepare and maintain technical documentation, make available information to downstream providers who integrate the model into their own systems, and comply with EU copyright law in relation to training data. The Act imposes additional obligations on providers of GPAI models that are deemed to pose systemic risk, based on the computational power used for training. These providers must conduct adversarial testing, report serious incidents to the European Commission, and implement cybersecurity measures.
Denmark has a growing AI and technology sector, with significant activity in Copenhagen and Aarhus. Several Danish companies and research institutions develop or deploy GPAI-adjacent systems. For these entities, the GPAI provisions of the Act are directly relevant, and the Danish Business Authority is the point of contact for national-level queries.
A practical scenario: a Danish software company builds a customer service chatbot using a third-party GPAI model. The company is acting as a deployer of the GPAI model and as a provider of the downstream AI system. It must comply with the transparency obligations applicable to AI systems that interact with humans - users must be informed they are interacting with an AI - and must ensure the system does not generate prohibited content. The company must also review the documentation provided by the GPAI model provider and assess whether the downstream system qualifies as high-risk.
A second scenario: a Danish financial institution uses an AI model to assess creditworthiness. This is a high-risk use case under the Act. The institution must conduct a conformity assessment, register the system, implement human oversight, and report to both the Danish Business Authority and Finanstilsynet. The dual reporting obligation is a local nuance that foreign companies entering the Danish market frequently overlook.
Data protection, GDPR and AI in Denmark
AI regulation in Denmark cannot be understood in isolation from data protection law. The General Data Protection Regulation applies to virtually all AI systems that process personal data, and in Denmark, Datatilsynet enforces the GDPR with increasing focus on AI-related processing activities.
The GDPR imposes several obligations that interact directly with AI deployment. Automated decision-making that produces legal or similarly significant effects on individuals is restricted under Article 22 of the GDPR. Individuals have the right not to be subject to solely automated decisions of this kind unless specific conditions are met - including explicit consent, contractual necessity, or a basis in EU or member state law. Danish law has implemented the member state derogations available under Article 22, and Datatilsynet has issued guidance on when these derogations apply.
Data protection impact assessments (DPIAs) are required before deploying AI systems that are likely to result in high risk to individuals'; rights and freedoms. Datatilsynet has published a list of processing activities that always require a DPIA in Denmark, and several AI use cases appear on this list, including large-scale profiling, systematic monitoring of publicly accessible areas, and processing of special categories of data using new technologies.
The intersection of the EU AI Act and the GDPR creates a dual compliance burden. A high-risk AI system that also processes personal data must comply with both the Act';s technical documentation and conformity assessment requirements and the GDPR';s data minimisation, purpose limitation and security obligations. In practice, companies should integrate their AI Act compliance work with their existing GDPR compliance programme rather than treating them as separate workstreams.
Recent guidance from Datatilsynet has emphasised that AI systems used for profiling or behavioural analysis must have a clear and documented legal basis under the GDPR. Relying on legitimate interests as the legal basis for high-risk AI processing is increasingly scrutinised, and companies should consider whether consent or another basis is more appropriate.
Sector-specific AI rules and upcoming developments in Denmark
Beyond the EU AI Act and the GDPR, several sector-specific frameworks affect AI deployment in Denmark. These rules apply in addition to, not instead of, the horizontal AI Act obligations.
In financial services, Finanstilsynet has issued guidance on the use of AI in credit decisions, fraud detection and customer-facing applications. The guidance draws on the European Banking Authority';s and European Securities and Markets Authority';s frameworks and emphasises explainability, fairness and auditability. Financial institutions must be able to explain AI-driven decisions to customers and to the regulator.
In healthcare, AI systems used as medical devices are subject to the EU Medical Device Regulation and the In Vitro Diagnostic Regulation, in addition to the AI Act. The Danish Health Authority oversees compliance in this sector. AI-powered diagnostic tools, clinical decision support systems and patient monitoring applications all require careful regulatory mapping before deployment.
In the public sector, Danish government agencies are significant users of AI. The Danish Agency for Digital Government (Digitaliseringsstyrelsen) has published principles for responsible use of AI in public administration, covering transparency, accountability and non-discrimination. Public sector bodies must also comply with the AI Act where they act as deployers of high-risk systems.
Upcoming developments to monitor include the full application of the EU AI Act';s high-risk provisions, which are being phased in over a multi-year period. The prohibited practices provisions and the GPAI obligations are already in effect. The high-risk system obligations apply to new systems placed on the market from the relevant application date, with a longer transition period for existing systems already in service. Businesses should map their AI portfolio now and build compliance timelines accordingly.
The European Commission is also developing implementing acts, delegated acts and harmonised standards under the AI Act. These technical standards will define in detail what constitutes adequate technical documentation, acceptable conformity assessment procedures, and appropriate risk management systems. Monitoring the development of these standards is essential for companies building long-term compliance programmes.
For guidance on navigating the intersection of EU and Danish AI rules for your specific business, contact info@vlolawfirm.com. We can assist with regulatory mapping, documentation and authority interactions.
Frequently asked questions about AI regulation in Denmark
Does the EU AI Act apply directly in Denmark, or does Denmark have separate national AI legislation?
The EU AI Act is an EU regulation, which means it applies directly and uniformly in all EU member states, including Denmark, without requiring national transposition into Danish law. Denmark does not have a separate standalone AI law that replaces or duplicates the Act. However, Denmark has designated national competent authorities to enforce the Act domestically, and Danish law supplements the Act in specific areas - for example, through GDPR implementation measures and sector-specific rules in finance and healthcare. Businesses operating in Denmark must therefore comply with the EU AI Act as enforced by Danish authorities, alongside any applicable sector-specific Danish rules.
How long does it take to prepare a high-risk AI system for compliant deployment in Denmark, and what does it cost?
The timeline for bringing a high-risk AI system into compliance depends heavily on the system';s complexity, the maturity of the provider';s existing documentation, and whether a third-party conformity assessment is required. In practice, companies with no existing compliance infrastructure should allow several months for the full process, covering risk classification, technical documentation, conformity assessment, registration in the EU database, and internal governance setup. Professional fees for legal and technical compliance support typically start from the low thousands of EUR for straightforward systems and rise significantly for complex deployments requiring external audits. State registration and conformity assessment costs vary by system type and the conformity assessment route chosen.
What happens if a company deploys an AI system in Denmark without complying with the EU AI Act?
Non-compliance with the EU AI Act can result in significant administrative fines. The Act sets out a tiered penalty structure: violations involving prohibited AI practices carry the highest fines, followed by violations of high-risk system obligations, with lower fines for providing incorrect information to authorities. The Danish Business Authority has the power to require corrective action, withdraw systems from the market, and impose fines. In addition, non-compliant AI systems that also violate the GDPR may face separate enforcement action from Datatilsynet. Reputational damage and loss of customer trust are practical consequences that often exceed the direct financial penalties.
Conclusion
AI regulation in Denmark is a live and evolving area of law, shaped by the EU AI Act, the GDPR, and a growing body of sector-specific rules enforced by Danish authorities. Businesses that invest in compliance now - through proper risk classification, documentation, and governance - are better positioned to deploy AI systems confidently and avoid enforcement action.
VLO Law Firms advises international clients on AI regulation in Denmark. We can assist with AI system classification, EU AI Act compliance documentation, GDPR impact assessments, authority interactions, and sector-specific regulatory mapping. To request a consultation, contact: info@vlolawfirm.com