AI Assistants in the Workplace – A Practical Guide
Last peer-reviewed July 16, 2026
Brief overview
Publisher: Ministry of Digitalisation and Public Administration.
The current published edition is dated June 16, 2025. Neither the official website nor the PDF edition specifies a version number. The edition should therefore be referred to as «the edition dated June 16, 2025 – without a specified version number».
The guide was prepared by an expert group appointed by the Ministry of Digitalisation and Public Administration. The secretariat was led by Digital Norway – Toppindustrisenteret, with participation from the Norwegian Digitalisation Agency. It is published as official guidance, but is not binding regulations.
The guide provides a practical approach to planning, implementing, and operating AI assistants in public and private organizations. It covers, among other things, purpose and benefit goals, organizational buy-in, involvement of employees and union representatives, competence, legal assessments, selection of technical solutions, data management, logging, quality assurance, information security, and ongoing operations.
The guide describes various levels of AI assistants, from the use of open platforms to solutions that are integrated or specifically tailored to the enterprise. The closer the solution is integrated with internal systems and data, the greater the need for governance, documentation, testing, and control.
The legal section must be read as a snapshot from the publication date. As of July 18, 2026, the AI Act is still not incorporated into the EEA Agreement or implemented as Norwegian law. Current Norwegian regulations, including privacy, labor, administrative, and sector-specific regulations, nevertheless apply in full when businesses use AI.
What regulates this
The guide does not regulate the business and establishes no new legal obligations. It provides practical recommendations on how public and private entities can implement and use AI assistants in a responsible, secure, and useful manner.
The content follows a process from clarifying needs and desired benefits to organizational preparation, legal assessments, technical setup, quality assurance, and operations. A concluding checklist gathers key questions that the organization should clarify before putting an AI assistant into use.
The guide discusses, among other things, the AI Act, the General Data Protection Regulation (GDPR), labor market issues, information security, the Public Administration Act, the Security Act, the Archives Act, and the Copyright Act. The discussion is high-level and does not replace the verification of the regulations that apply to the specific area of use.
Who is affected
Public sector
Private sector
Why it has practical significance
Many businesses start with a specific AI tool before they have clarified their needs, responsibilities, data usage, and expected return. The guide reverses this order and recommends that the business first define the problem to be solved, who the solution is for, and how results and risk are to be measured.
It is particularly useful as a shared working framework for management, professional communities, IT, privacy, security, HR, and employee representatives. The checklists can be used to uncover unresolved issues before a solution is procured, integrated, or opened up to employees.
For language-based AI assistants, advice on data quality, hallucinations, logging, human oversight, and ongoing evaluation is central. A linguistically well-formulated response is not necessarily professionally correct, complete, or suitable as a basis for a decision.
Key Requirements and Obligations
- The guideline does not establish binding requirements; legal obligations follow from the legislation applicable to the specific area of use.
- Clarify needs, purpose, target audience, and expected benefits before the organization chooses an AI tool or technical solution.
- Secure management buy-in for the implementation and assign responsibility for decisions, risk, operations, quality, and follow-up.
- Involve employees, union representatives, and relevant professional environments early when the solution affects work tasks, roles, or monitoring of employees.
- Determine whether the business operates as a user, commissioner, supplier, or in another role under relevant regulations.
- Map what information the AI assistant is given access to, where data is processed, whether data is used for training, and which vendors and subcontractors are involved.
- Assess the lawful basis for processing, purpose limitation, data minimization, information to data subjects, and the need for a data protection impact assessment.
- Establish guidelines for what information employees can enter into open or external AI services.
- Evaluate the need for logging and traceability against privacy, information security, and control requirements.
- Test quality, robustness, security, and the risk of hallucinations or undesired model behavior before the solution is deployed widely.
- Determine when human control is necessary and who is responsible for controlling and approving results.
- Follow up on the solution throughout its entire lifecycle with monitoring, user feedback, incident management, updates, and regular evaluation.
What the business may consider documenting
- Use the supervisor's final checklist as a starting point for an internal onboarding program.
- Describe the concrete problem to be solved, and assess whether an AI assistant is actually a suitable and proportionate tool.
- Start with a defined use case where risk, data access, and quality can be controlled.
- Establish a cross-functional team with representatives from management, subject matter experts, IT, security, privacy, HR, and employees.
- Create an overview of approved AI tools, permitted use cases, and information that must not be shared with the solutions.
- Document supplier, model, version, configuration, data sources, integrations, and enabled add-on features.
- Define test criteria for professional quality, language, bias, security, stability, and user experience.
- Determine which results must always be checked by a qualified person before they are used or published.
- Provide role-based training in safe usage, source criticism, instructions for the model, and error handling.
- Measure both benefits and unintended consequences, and have a clear process for modifying, limiting, or stopping the solution.
- Check the legal references in the guide against updated regulations and newer official guidance before relying on them.
Sources and Further Reading
- Primary official source
- The PDF edition of the guide
- Ministry of Digitalisation and Public Administration: Launch of the guide
- Mandate, expert group and secretariat
- EFTA EEA-Lex: Status of the AI Act in the EEA
- Regjeringen.no: EEA note on the AI Act
The links point to external sources. Check the current text and status before using them in your own work.
