evidoria

← Back to browse

Good practice

Norway's National AI Regulatory Sandbox — Testing High-Risk and Generative AI Before Deployment

Norway · Oslo · See the Norway profile

Since 2021, Norway's data protection authority has run about 20 time-boxed AI sandbox projects with public bodies — from NAV's sick-leave models to NTNU's Copilot trial — publishing exit reports and prompting a 2023 evaluation that found real competence gains.

Norway's National AI Regulatory Sandbox — Testing High-Risk and Generative AI Before Deployment

Details

Promoter
Datatilsynet (Norwegian Data Protection Authority)
Period
2021–2026
Keywords
data protection, AI governance, regulatory sandbox, public administration

Description

Datatilsynet's regulatory sandbox pairs Norway's data protection authority with public and private organisations for time-boxed, 3–6 month dialogues that test whether a planned or in-use AI system complies with data protection law before it is deployed at scale. Since launching in 2021, roughly 20 such projects have run through the programme.

Public-sector examples include NAV's 2022 project on predicting sick-leave duration with machine learning, Ruter's 2023 work on transparency in its transit app, Helse Bergen's 2023 hospital-readmission prediction model, Ahus and the Equality and Anti-Discrimination Ombud's 2023 investigation of bias in a cardiac-risk algorithm, NTNU's June 2024 exit report on using Microsoft 365 Copilot under data protection law, and Ahus's 2025 project on remote monitoring of elderly patients.

An independent 2023 evaluation by consultancy Agenda Kaupang, based on interviews and a participant survey, found Datatilsynet's organisation of admissions, projects and communication "very satisfactory" and said participants and observers credited the sandbox with building real AI and data-protection competence. The same evaluation flagged honest limits: the sandbox struggles to attract academic participants and to reach organisations that do not naturally think of a data regulator as an AI actor. The guidance produced is advisory, not a legal safe harbour. The model has since drawn academic study (Cambridge Forum on AI: Law and Governance) and is echoed in the EU AI Act's Article 57, which requires every member state to establish a national AI regulatory sandbox by August 2026.

Read the full analysis: https://www.datatilsynet.no/en/regulations-and-tools/sandbox-for-artificial-intelligence/

Implementation

Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful