Short answer: probably yes, and sooner than you think. The Norwegian AI Act, the national implementation of the EU AI Act, has not yet entered into force. But two other bodies of law already apply in full, and they cover most of what you actually do with AI today.
The question usually surfaces the same way. Someone on the leadership team discovers that a colleague pasted a client document into ChatGPT to get help with a summary. At that point it stops being theoretical.
The long answer is about why, and that is where most people get stuck. The regulatory position is in an interim phase right now, and it is unusually hard to navigate.
Two bodies of law, not one
The commonest misunderstanding is to treat this as a single law that either applies or does not.
The Norwegian AI Act, meaning the national implementation of the EU AI Act, is delayed. The Minister of Digitalisation and Public Governance, Karianne Tung, has confirmed that proposed legislative amendments will not go out for consultation until autumn 2026, with a bill targeted for spring 2027. The Norwegian Communications Authority (Nkom), appointed as coordinating supervisory body, states itself that the timing of incorporation into the EEA Agreement remains unclear.
So much for the argument to wait. Here are the two that already apply.
The Norwegian Working Environment Act. Tools that monitor or direct how employees work can trigger the rules on monitoring measures in Chapter 9. They must be discussed with employee representatives before introduction, whatever the size of the organisation. The Act also requires employers to provide the necessary training in new systems under section 4-2, and to watch for discrimination under Chapter 13 if the tool has been trained on skewed data. NHO (the Confederation of Norwegian Enterprise) works through this in its own guide for member companies.
The Norwegian Personal Data Act and the GDPR. These apply the moment an AI tool processes personal data. That happens when a language model is given access to documents containing client data, and it happens when a system logs employee usage. The legal basis then has to be in place, and often you need to be able to point to a data protection impact assessment.
On top of that, Article 4 of the EU AI Act itself already applies in the EU. It requires that employees who develop or use AI systems have sufficient competence to do so responsibly. Norwegian organisations with customers or supply chains in the EU market have to deal with it whatever happens to the Norwegian law.
The single unifying AI Act is not here. Two of the three rule sets that govern how you use AI are.
Why it is more urgent than the law would suggest
More than half of Norwegian businesses use artificial intelligence today, more than a doubling in two years according to NHO. Governance has not kept the same pace. Industry surveys through 2025 and 2026 estimate that between 12 and 22 per cent of Norwegian organisations have a concrete plan for complying with the EU AI Act.
The gap between use and governance has a name: shadow AI. It is not an edge case. It is the norm. Employees paste customer lists into Gemini for help with segmentation, or emails into the free version of a chatbot to polish the wording, without anyone in management having taken a position on whether that is acceptable.
The Samsung case from 2023 has become the reference point. Three engineers uploaded source code and internal meeting notes to ChatGPT within twenty days of the tool being approved internally, and the information became part of the vendor's training data. The security firm Harmonic Security has since estimated that around 8.5 per cent of all queries to AI chatbots contain sensitive business information, and that more than half go through free versions that explicitly train on what they receive.
For organisations that process personal data, which is most of them, this is more than a security question. The Norwegian Data Protection Authority (Datatilsynet) has shown that it uses its sanction powers. Grindr was fined 65 million kroner (roughly 5.6 million euros) for unlawful sharing of data in a profiling-driven advertising model. NAV received 20 million kroner (roughly 1.7 million euros) for breaches of data protection rules. Neither case concerned generative AI, but they say something about the level of penalty the authority is willing to apply when controls fail. In spring 2026 Datatilsynet announced new inspections of municipalities' use of digital tools, among them Hustadvika, Bardu, Målselv, Stavanger and Sola.
An AI policy does not solve this on its own. It is the cheapest measure that actually moves something, because it forces a conversation about what is approved and who is responsible, before someone makes that call alone.
What a policy has to cover
An AI policy is not one document that solves everything. It is a set of concrete answers to questions employees are already asking themselves, whether or not they say so out loud.
Which tools are approved, and for what. Not a general yes to AI, but a list. ChatGPT is fine for first drafts of internal notes, not for client data. Copilot is integrated and approved for email and meeting notes. Anything not on the list has not been assessed yet, and must be cleared before use.
What must never be pasted in. Personal data, source code, trade secrets, unpublished board papers. This single point captures most of the risk from shadow AI, and it is also the easiest thing to communicate to people who have neither the time nor the interest for the regulation.
Who approves new tools. Without a defined point of responsibility, the decision lands with the individual employee, who has neither the grounding nor the mandate to make it.
What you do when the AI gets it wrong. Hallucinations are not an exceptional state. They are a known property of language models. A policy with nothing about human oversight and verification is missing the most important point.
How employee representatives are involved. For organisations with more than 50 employees this is not optional under the Working Environment Act, and Supplementary Agreement IV to the Norwegian Basic Agreement governs the introduction of new technology specifically. Several NHO members report good experience with bringing representatives in during the pilot phase.
How training is documented. This is the core of the Article 4 requirement. It is also the point that is easiest to postpone, right up until someone asks for the documentation.
None of these points requires a consultancy or a six-month project. They require someone in management to set aside a morning, work through them for the tools you actually use, and write down the answers.
Where to start
Step one is not writing the policy. It is finding out what is already happening.
Most are surprised by how many AI tools are in use once they ask. Not because employees have done anything wrong, but because nobody asked before.
Build a simple inventory: which tools, who uses them, for which tasks, and what data could end up there. Then assess each use against risk. A tool that drafts internal notes is something quite different from one involved in hiring or credit assessment, which falls under what the EU AI Act defines as high risk. Then assign responsibility: who approves new tools, and who owns the policy once it is written.
This is not a one-off project. The tools change faster than internal routines can follow, and a policy that is not updated quickly becomes a document nobody trusts.
Frequently asked questions
Do we need an AI policy when the Norwegian AI Act has not yet entered into force?
Yes, in practice. The Norwegian Working Environment Act and the Norwegian Personal Data Act already apply in full, and they govern most of how AI can be used in a workplace. Article 4 of the EU AI Act also applies in the EU, and reaches Norwegian organisations with customers or supply chains there.
Does this apply to small organisations too?
Yes. The requirements in the Norwegian Personal Data Act have no lower size threshold, and the duty to discuss monitoring measures with employee representatives applies regardless of headcount. The requirement for formal co-determination machinery grows with size, but the basic requirements do not.
How long should an AI policy be?
Shorter than people expect. Two to four pages is enough for most organisations, provided it is specific. A list of approved tools, a list of what must never be pasted in, a named point of responsibility and a routine for training covers most of the risk.
Do we have to involve employee representatives?
If the tool can monitor or direct how work is performed, yes. It then counts as a monitoring measure under Chapter 9 of the Norwegian Working Environment Act and must be discussed before introduction. Supplementary Agreement IV to the Norwegian Basic Agreement governs the introduction of new technology specifically.
Sources: NHO, "KI på jobben: hva må arbeidsgiver gjøre?" (2026) · Nkom, "Hvem må følge KI-loven?" and "Ofte stilte spørsmål om KI-loven" · Datatilsynet, "Bruk og håndheving av kunstig intelligens" and notice of municipal inspections 2026 · Regulation (EU) 2024/1689 (AI Act), Article 4 · Tek.no, on the delay to the Norwegian AI Act (August 2026) · Harmonic Security, analysis of sensitive data in AI chatbot queries.
Last updated 6 August 2026. This is a general account, not legal advice. The status of Norwegian implementation may change.