evidoria

← Back to browse

Good practice Imported

Denmark's AI Regulatory Sandbox — Testing AI Projects for GDPR and AI Act Compliance

Denmark · Copenhagen · See the Denmark profile · See the Copenhagen profile

Evidence: Descriptive / self-reported Top 32% 67/100 · Ask Evidence Copilot about this practice

Denmark's data-protection and digitalisation agencies jointly run a regulatory sandbox giving organisations free, project-specific guidance on GDPR and EU AI Act risk classification. Two cohorts published final reports; a third (3 projects) was selected in July 2026.

2
Sandbox cohorts completed with published final reports (2024-2026)
3
Projects selected in third sandbox round (July 2026)

Details

Maturity
Scaling
Promoter
Datatilsynet (Danish Data Protection Agency) & Digitaliseringsstyrelsen (Danish Agency for Digital Government)
Period
2024–2027 (ongoing)
Keywords
AI regulation, data protection, digital government, EU AI Act

Context

Datatilsynet and Digitaliseringsstyrelsen jointly established Denmark's AI regulatory sandbox in 2024, running under a mandate through 2027, to give organisations developing or deploying AI systems free, project-specific guidance on GDPR compliance and EU AI Act risk classification.

Activities

Two cohorts have completed the sandbox with published final reports -- Børns Vilkår, a children's-welfare NGO, and BrainCapture ApS, a medical-technology company -- and in July 2026 a third round selected three further projects spanning a Danish-language encyclopedia chatbot, a healthcare-communication AI tool, and an on-premises sovereign-AI platform.

Results

The scheme offers non-binding guidance rather than certification, and the evidence so far is procedural: published cohort reports document which projects passed through, but neither agency has released aggregate figures on applications received, rejection rates, or measured public-value outcomes.

Conclusions

The sandbox has grown from a single cohort to a third round, and is logged in the OECD.AI international policy registry as an early EU regulatory-sandbox model, but its case so far rests on continuity and published process transparency rather than demonstrated compliance or efficiency gains.

Implementation

Indicative cost
Low (< €50k) — Two national regulatory agencies co-staff the scheme within existing case-officer capacity; no dedicated budget figure is published, consistent with a free advisory service rather than a funded grant programme.
Time to results
Medium (1–3 years) — Running since 2024 under a mandate through 2027, with cohorts admitted roughly annually -- a bounded multi-year programme rather than permanent standing infrastructure.
Staffing & skills
Datatilsynet (Danish Data Protection Agency) case officers, Digitaliseringsstyrelsen (Danish Agency for Digital Government) staff

Conditions for success

  • joint mandate spanning data-protection and digital-government agencies so applicants get one coherent GDPR/AI Act opinion
  • free access for public and private organisations to lower the barrier to seeking guidance early in development
  • willingness of participating agencies to publish cohort final reports for transparency

Common failure modes

  • no published aggregate application or rejection data makes it hard to judge selection fairness or programme capacity
  • guidance is non-binding, so participants can accept the risk classification without changing their systems

Commonly funded by

National / regional programmes Digital Europe Programme

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Similar practices you may find useful