evidoria

← Back to browse

Good practice Imported

Norway's National AI Regulatory Sandbox — Testing High-Risk and Generative AI Before Deployment

Norway · Oslo · See the Norway profile · See the Oslo profile

Evidence: Observational / pre–post Top 6% 87/100 · Ask Evidence Copilot about this practice

Since 2021, Norway's data protection authority has run about 20 time-boxed AI sandbox projects with public bodies — from NAV's sick-leave models to NTNU's Copilot trial — publishing exit reports and prompting a 2023 evaluation that found real competence gains.

~20
AI sandbox projects run since programme launch (2021-2026)
Norway's National AI Regulatory Sandbox — Testing High-Risk and Generative AI Before Deployment Norway's National AI Regulatory Sandbox — Testing High-Risk and Generative AI Before Deployment

Details

Maturity
Established
Promoter
Datatilsynet (Norwegian Data Protection Authority)
Period
2021–2026
Keywords
data protection, AI governance, regulatory sandbox, public administration

Context

Datatilsynet, Norway's data protection authority, pairs public and private organisations with the regulator in time-boxed 3-6 month dialogues that test whether a planned or in-use AI system complies with data protection law before deployment at scale. Since launching in 2021, roughly 20 such projects have run through the programme.

Activities

Public-sector examples include NAV's 2022 project on predicting sick-leave duration with machine learning; Ruter's 2023 work on transparency in its transit app; Helse Bergen's 2023 hospital-readmission prediction model; Ahus and the Equality and Anti-Discrimination Ombud's 2023 investigation of bias in a cardiac-risk algorithm; NTNU's June 2024 exit report on using Microsoft 365 Copilot under data protection law; and Ahus's 2025 project on remote monitoring of elderly patients.

Results

An independent 2023 evaluation by consultancy Agenda Kaupang, based on interviews and a participant survey, found Datatilsynet's organisation of admissions, projects and communication 'very satisfactory', and participants and observers credited the sandbox with building real AI and data-protection competence.

Conclusions

The same evaluation flagged honest limits: the sandbox struggles to attract academic participants and to reach organisations that do not naturally think of a data regulator as an AI actor, and the guidance produced is advisory, not a legal safe harbour. The model has since drawn academic study (Cambridge Forum on AI: Law and Governance) and is echoed in the EU AI Act's Article 57, which requires every member state to establish a national AI regulatory sandbox by August 2026.

Implementation

Indicative cost
Medium (€50k–€500k)
Time to results
Long (> 3 years)
Staffing & skills
Datatilsynet regulatory/legal staff running sandbox dialogues, Participating public-body project teams (e.g. NAV, Ruter, Helse Bergen, NTNU, Ahus)

Conditions for success

  • Time-boxed 3-6 month structured dialogue between regulator and organisation before deployment at scale
  • Publishing a public exit report for every completed project
  • Commissioning an independent third-party evaluation of the programme itself

Common failure modes

  • Struggles to attract academic participants
  • Struggles to reach organisations that do not naturally think of a data regulator as an AI actor
  • Guidance produced is advisory only, not a legal safe harbour

Commonly funded by

National / regional programmes Digital Europe Programme

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful