Skip to main content

The EU AI regulation: what is happening now, and does it concern your business?

New AI rules took effect in the EU on 2 August. But they do not yet apply in Norway. Here is what that actually means for a Norwegian business today.

By Lars Henrik Netland

Produced with AI tools, edited and fact-checked by the author

Last updated: 5 August 2026

The EU's AI regulation, the AI Act, has been discussed for years as something that is "coming". Last week a piece of it arrived. On 2 August the European Commission gained the authority to actually use its powers against the providers of the large AI models: demand documentation, carry out evaluations, and impose fines. At the same time new transparency requirements took effect.

So the big question for a Norwegian business: do we have to do anything now? The short answer is no, not yet, and the reason is worth understanding. Because although the headlines are about EU rules applying from 2 August, the situation in Norway is different.

Briefly, what the AI Act is

The AI Act is the EU's attempt to regulate artificial intelligence according to risk. The greater the harm an AI use can do, the stricter the requirements. The rules divide usage into levels: some things are prohibited, some count as high risk with heavy requirements, and the large majority of ordinary use falls into a lighter category with simpler requirements, mainly about transparency.

Norway is not in the EU, and here is the most important thing for Norwegian readers: the AI Act does not currently apply as Norwegian law. The regulation has not yet been incorporated into the EEA Agreement, and the Norwegian AI act is delayed. A bill was out for consultation in the autumn of 2025, but negotiations about EEA adaptations take time, and the government is now aiming to present a legislative proposition in the spring of 2027.

That means the transparency requirements that took effect in the EU on 2 August have no direct legal effect in Norway today. But before you breathe a sigh of relief: there are two reasons why this concerns you anyway.

What actually applies right now

Here it is important to separate the timeline, because a lot was recently moved. In June 2026 the European Parliament adopted changes that pushed the heaviest requirements for high-risk AI further out, to 2027 and 2028. So much of the most demanding material is not relevant yet.

But two things did land on 2 August 2026, and they were deliberately not postponed:

First, the Commission gained enforcement power over the large, general-purpose AI models, meaning the models that ChatGPT, Claude and Gemini are built on. The requirements for these providers have formally applied since August 2025, but now the Commission can actually demand access and issue fines.

Second, and this is what may concern you: the transparency requirements. They say, among other things, that people should be told when they are talking to a chatbot and not a human, and that AI-generated content, such as deepfakes and synthetic images, should be labelled.

The part that can reach an ordinary business

Even though Norwegian rules are taking their time, there are two reasons why this is worth knowing about.

If you sell into the EU, the rules already apply. If your business offers AI systems or AI-based services to customers in the EU market, you are covered by the regulation now, regardless of how far Norway has come. The same applies if the output from your system is used in the EU.

And the rules are coming anyway. When the Norwegian AI act takes effect, the requirements will in practice be the same. Businesses that have this in order in advance avoid a rushed clean-up project later.

What the transparency requirements are about in practice is quite simple: if you have a chatbot on your website answering customers, they should understand that they are talking to a machine and not a human. If you use AI to produce content that could be mistaken for something real, there may be labelling requirements.

For most people it boils down to honesty: do not pretend a machine is a human, and do not put out AI-generated material as if it were genuine. That is good craft whatever the law eventually says, and there is no reason to wait for a section number to do it.

This is not the same as data protection

A common confusion is mixing up the AI Act with GDPR. They are two different sets of rules that apply at the same time. GDPR is about personal data, regardless of whether AI is involved. The AI Act is about AI systems, regardless of whether personal data is involved. If you use AI to process customer data, you have to deal with both. We have written more thoroughly about data protection in the article on GDPR for Norwegian businesses, and the principles there still apply in full.

This is also the main reason why the delay of the Norwegian AI act does not mean a free-for-all. Data protection rules, copyright law and other existing legislation apply just as much when you use AI. If you use an AI tool to process customer information, you are subject to GDPR today, regardless of how far the AI Act has come in the EEA process.

What you should do now

No reason to panic, but a couple of healthy habits:

  • Know where you use AI. Do you have an overview of which AI tools are in use in the business, and what they do with data? Most do not, and that is the first step.
  • Be open about it. Where customers meet AI, say so. It builds trust and covers the transparency requirement at the same time.
  • Do not lock yourself to one provider. The rules are in motion, and an AI provider may have to change or withdraw services to comply. A solution that can switch model without being rebuilt stands safer. We wrote about precisely this in the snapshot of the AI landscape.

The rules will develop over the coming years, and the details will become clearer over time. But the direction is clear: transparency about where AI is used, and responsibility for what it does. That is not a bad guiding principle, whatever the law eventually lands on.

Related