Map AI use
List every tool involving AI, including hidden AI in HR tools, marketing, and customer service. Note purpose, supplier, data sources, and who is affected.
The EU regulation on artificial intelligence already applies in the EU, and Norway is implementing it through a dedicated Norwegian AI Act. For small and medium-sized businesses using AI tools or commissioning AI solutions, it comes down to three things: some uses are prohibited, some require systematic work, and everyone must understand what the tools do. This is a practical overview, not legal advice.
Last updated: September 26, 2026. Last fact-checked September 26, 2026.
The AI Act is EU Regulation 2024/1689 laying down harmonised rules on artificial intelligence. It entered into force in the EU on 1 August 2024. Its purpose is to protect health, safety, and fundamental rights, and to create a single market for safe AI systems. The framework is risk-based: it prohibits a small number of uses, places strict duties on high-risk systems, requires transparency where people should know AI is involved, and leaves low-risk use largely unregulated. The regulation is EEA-relevant and will be implemented in Norway through a dedicated AI Act.
Prohibited AI practices are listed in Article 5 and include manipulative systems, exploitation of vulnerable groups, social scoring, and real-time remote biometric identification. In December 2026 a ninth prohibition arrives, targeting non-consensual intimate images and child sexual abuse material. High-risk systems are either safety components in regulated products (Annex I) or use cases in Annex III, such as recruitment, credit, and insurance. Chatbots and AI-generated content carry transparency duties, while spellchecking and spam filters count as minimal risk. Article numbers refer to the original numbering; check them against the consolidated legal text, since the Omnibus amendments may have moved numbers.
Whoever develops or places an AI system on the market is the provider and carries the heaviest duties: risk management, documentation, logging, human oversight, conformity assessment, and CE marking. Whoever puts the system into use in their own organisation is the deployer and must follow the instructions for use, exercise oversight, monitor operations, report serious incidents, and inform those affected. Substantial modifications, a new purpose, or your own trademark on the system can turn the deployer into the provider. Light configuration normally does not move the role, but where the line falls in practice is not finally settled.
An SMB using AI tools without selling AI systems still faces duties. The prohibitions apply to everyone, including pure users. Article 4 requires sufficient AI literacy among staff operating and using the systems, with no demand for formal certification. Chatbots and AI-generated content must be disclosed, and the deployer carries independent responsibility that the information reaches those affected. Using AI for recruitment, staff appraisal, credit, or insurance triggers the high-risk duties: oversight, monitoring, logging, and a fundamental rights impact assessment.
Prohibitions and AI literacy have applied in the EU since 2 February 2025. Rules for general-purpose AI models, governance, and penalties followed on 2 August 2025. General application arrives on 2 August 2026, while the Omnibus amendments push the high-risk deadlines to 2 December 2027 for Annex III and 2 August 2028 for Annex I products. For SMB planning this means prohibitions, literacy, and transparency apply now, while the heaviest high-risk deadlines sit further out. In Norway the real deadlines depend on EEA incorporation and Norwegian entry into force.
The Ministry of Digitalisation and Public Governance sent a proposal for a new AI Act for consultation on 30 June 2025, with a deadline of 30 September 2025. The consultation paper proposes Nkom as coordinating market surveillance authority, the Financial Supervisory Authority for finance, and the Data Protection Authority in the complaints role, with KI Norge in Digdir and regulatory sandboxes as support. The stated plan has been entry into force during 2026, but as of 26 September 2026 we have not found public confirmation of a proposition, adoption, EEA Committee decision, or final date. Verify the status against regjeringen.no and Lovdata before relying on it. Do not wait to prepare: mapping, training, and supplier documentation are useful whatever the final timeline turns out to be.
Ten practical steps before adopting or expanding AI. These are general pointers, not legal advice.
List every tool involving AI, including hidden AI in HR tools, marketing, and customer service. Note purpose, supplier, data sources, and who is affected.
Go through Article 5 and discontinue any use resembling prohibited practices. Document the assessment.
Are you provider or deployer for each system? Have you made changes that could move the role? Get the answer in writing where in doubt.
Do any use cases appear in Annex III? Start work on oversight, logging, monitoring, and impact assessment well before the deadlines.
Train staff for the tools they use: capabilities, limitations, checking routines, and escalation. Repeat for new tools and major updates.
Label chatbots, AI-generated content, and automated assessments. Agree with suppliers who does what.
Instructions for use, limitations, test results, and an incident contact should exist in writing before purchase.
Define what counts as a serious AI incident in your business, who is notified, and how it is logged and reported onward.
Check regjeringen.no, the Data Protection Authority, and Lovdata regularly for proposition, adoption, and entry into force.
For innovative AI uses with regulatory uncertainty, the Data Protection Authority sandbox or KI Norge may be relevant sparring partners.
This article builds on primary sources, last checked 26 September 2026. Check them again before important decisions.
Aprex builds AI solutions for Norwegian businesses with open eyes: know what you use, make sure people understand it, be open about it, and keep high-risk uses away without a proper foundation. This article is a practical overview based on primary sources, not legal advice. When in doubt about duties or high-risk uses, consult a lawyer.
Send which AI tools you use, what they are used for, and who is affected. Aprex helps with mapping and safe next steps.
Contact Aprex about AI mapping →