KI Norway: Guidelines for the Responsible Development and Use of Artificial Intelligence in the Public Sector
Last peer-reviewed July 16, 2026
Brief overview
AI Norway is the active, official main gateway for guidance on the responsible and innovative development and use of artificial intelligence. Digdir states that the content regarding artificial intelligence has been moved to ki.norge.no. AI Norway is organized under the Norwegian Digitalisation Agency and collaborates with, among others, the Norwegian Data Protection Authority and the Norwegian Communications Authority.
The former Digdir guide has been carried over into a broader and continuously updated collection of web guides. The central process guide, «How to succeed with AI,» follows the work from needs and risk assessment through procurement, development, and testing to implementation, operation, and management.
The guidance provides practical advice, but is not binding regulation and does not establish a separate legal basis for the use of AI. The organization must itself identify and comply with relevant requirements, including within privacy, information security, administrative law, archiving, procurement, and sector regulations.
When using AI for text drafting, summarization, or translation, verification of content, sources, language, and professional precision is still necessary. Generative AI should not be used alone as a basis for facts, legal assessments, or decisions with significant consequences.
What regulates this
The guideline does not regulate businesses and does not establish independent legal obligations. It provides recommendations on how businesses can work systematically with AI throughout its entire lifecycle – from the clarification of needs and framework conditions to procurement, testing, implementation, operation, and subsequent follow-up.
The content includes risk assessment, data quality, privacy, information security, responsibilities and roles, vendor management, human oversight, testing, and documentation, among other things. Which binding requirements apply must be assessed based on the area of use, the data being processed, and the role of the enterprise.
Who is affected
Public sector
Why it has practical significance
The guide translates overarching requirements for responsible AI use into concrete tasks and control points. It can help public sector entities identify legal, technical, and organizational risks before a solution is procured or put into operation.
This is particularly relevant when AI is used in case processing, communication, summarization, or translation. Such tools can produce convincing, yet incorrect or misleading content. The organization must therefore test the solution in its own context, ensure sufficient human oversight, and maintain necessary professional and linguistic expertise.
Key Requirements and Obligations
- The guidance is not binding; legal obligations follow from the laws and regulations that apply to the relevant area of use.
- Clarify needs, expected utility, and whether AI is a suitable solution before procurement or development
- Map out which data is to be used, and assess data quality, privacy, security, and usage rights
- Identify relevant general and sector-specific regulations early in the process
- Assess legal, ethical, technical, and societal risk and document relevant risk-mitigating measures
- Involve relevant professional communities and clarify responsibilities between management, professionals, technologists, and suppliers
- Test the solution with relevant data, users, languages, work processes, and edge cases before it is put into operation
- Monitor the model's quality, safety, and suitability throughout its entire lifecycle
What the business may consider documenting
- Use «How to succeed with AI» as an internal control model from idea to operation
- Designate a responsible owner and document roles and involvement, for example in a responsibility matrix
- Establish internal rules for approved AI tools, use cases, data types, and necessary human oversight
- Testing AI-generated text, summarization, and translation with qualified subject matter and language resources
- Verify that employees do not enter confidential, sensitive, or other protected information into solutions that are not approved for this purpose
- Document tests, known limitations, supplier assumptions, deviations, and the decision to deploy the solution
- Plan a new assessment for significant changes in model, supplier, data basis, use, or regulations
Sources and Further Reading
- Primary official source
- AI Norway – How to succeed with AI
- AI Norway – What is AI and what can you use it for?
- AI Norway – About AI Norway
- Digdir – information that the AI content has been moved to AI Norway
- Digdir – launch of the former guide in open beta
- Ministry of Digitalisation and Public Governance – This is what AI Norway will look like
The links point to external sources. Check the current text and status before using them in your own work.
