← Back to the regulatory map
Official guidance portal Norway

KI Norway: Guidelines for the Responsible Development and Use of Artificial Intelligence in the Public Sector

Official guidance

Last peer-reviewed July 16, 2026

Brief overview

AI Norway is the active, official main gateway for guidance on the responsible and innovative development and use of artificial intelligence. Digdir states that the content regarding artificial intelligence has been moved to ki.norge.no. AI Norway is organized under the Norwegian Digitalisation Agency and collaborates with, among others, the Norwegian Data Protection Authority and the Norwegian Communications Authority.

The former Digdir guide has been carried over into a broader and continuously updated collection of web guides. The central process guide, «How to succeed with AI,» follows the work from needs and risk assessment through procurement, development, and testing to implementation, operation, and management.

The guidance provides practical advice, but is not binding regulation and does not establish a separate legal basis for the use of AI. The organization must itself identify and comply with relevant requirements, including within privacy, information security, administrative law, archiving, procurement, and sector regulations.

When using AI for text drafting, summarization, or translation, verification of content, sources, language, and professional precision is still necessary. Generative AI should not be used alone as a basis for facts, legal assessments, or decisions with significant consequences.

What regulates this

The guideline does not regulate businesses and does not establish independent legal obligations. It provides recommendations on how businesses can work systematically with AI throughout its entire lifecycle – from the clarification of needs and framework conditions to procurement, testing, implementation, operation, and subsequent follow-up.

The content includes risk assessment, data quality, privacy, information security, responsibilities and roles, vendor management, human oversight, testing, and documentation, among other things. Which binding requirements apply must be assessed based on the area of use, the data being processed, and the role of the enterprise.

Who is affected

Public sector

Why it has practical significance

The guide translates overarching requirements for responsible AI use into concrete tasks and control points. It can help public sector entities identify legal, technical, and organizational risks before a solution is procured or put into operation.

This is particularly relevant when AI is used in case processing, communication, summarization, or translation. Such tools can produce convincing, yet incorrect or misleading content. The organization must therefore test the solution in its own context, ensure sufficient human oversight, and maintain necessary professional and linguistic expertise.

Key Requirements and Obligations

  • The guidance is not binding; legal obligations follow from the laws and regulations that apply to the relevant area of use.
  • Clarify needs, expected utility, and whether AI is a suitable solution before procurement or development
  • Map out which data is to be used, and assess data quality, privacy, security, and usage rights
  • Identify relevant general and sector-specific regulations early in the process
  • Assess legal, ethical, technical, and societal risk and document relevant risk-mitigating measures
  • Involve relevant professional communities and clarify responsibilities between management, professionals, technologists, and suppliers
  • Test the solution with relevant data, users, languages, work processes, and edge cases before it is put into operation
  • Monitor the model's quality, safety, and suitability throughout its entire lifecycle

What the business may consider documenting

  • Use «How to succeed with AI» as an internal control model from idea to operation
  • Designate a responsible owner and document roles and involvement, for example in a responsibility matrix
  • Establish internal rules for approved AI tools, use cases, data types, and necessary human oversight
  • Testing AI-generated text, summarization, and translation with qualified subject matter and language resources
  • Verify that employees do not enter confidential, sensitive, or other protected information into solutions that are not approved for this purpose
  • Document tests, known limitations, supplier assumptions, deviations, and the decision to deploy the solution
  • Plan a new assessment for significant changes in model, supplier, data basis, use, or regulations

Sources and Further Reading

The links point to external sources. Check the current text and status before using them in your own work.

The information is general information and not legal advice. The applicable requirements must be assessed based on the enterprise's sector, role, information, and specific use of technology.

Next step with ClearNord

Hvordan styrer dere KI- og språkverktøy?

ClearNords egenvurdering hjelper dere å reflektere over hvordan virksomheten styrer KI- og språkverktøy. Bruk den som et utgangspunkt for intern diskusjon om hva dere bør undersøke nærmere.

Ta ClearNords egenvurdering