Written by a human

How can Nordic firms prepare for the EU AI Act?

With the EU AI Act about to enter its next phase, how can Nordic firms gain operational value from their AI investment while ensuring responsible, compliant implementation?

5 mins read 31 July 2026
Written by humans

Written by a human

In brief:

  • Businesses across the Nordics are increasingly embedding AI across a range of use cases
  • However, Nordic firms are still weighing factors including how best to implement AI to achieve meaningful returns while maintaining privacy and transparency
  • With regulations like the EU AI Act continuing to develop, how can Nordic firms realize the benefits of AI while remaining compliant?

The artificial intelligence (AI) adoption curve continues to climb – 27% of financial services firms in EMEA are already using AI for compliance or surveillance, with 40% of those not yet using AI intending to implement it over the next year.

In the Nordics specifically, three quarters of businesses are embracing AI adoption. While regulators have been slower off the mark in establishing their AI outlook, they are catching up. The European Union (EU) AI Act has been gathering momentum, intending to maintain oversight of how AI is used while supporting responsible implementation.

Despite a rapid increase in use across the Nordics during the initial wave of “AI hype,” financial firms are now determining how to obtain meaningful results from AI technologies long term while meeting growing compliance expectations. How can Nordics firms evaluate their compliance processes to meet the demands of developing regulations while maximizing AI opportunities and achieving meaningful value from their investments?

What to expect from the EU AI Act’s next implementation phase

Described as a risk-based framework aimed at managing the challenges and risks that evolving technologies introduce, the EU AI Act is meant to set clear guardrails for how firms can responsibly build compliance frameworks to deploy novel technologies without threatening market integrity or consumer protections. 

While two phases of the EU AI Act have passed already, including its initial entry into force in August 2024application of rules around general prohibitions and provisions in February 2025, and rules for general-purpose use and governance requirements in August 2025, the remainder of the rule is set to come into effect in August 2026.

One of the key elements of the act firms should be aware of is Article 50 on transparency rules, which will “affect more organizations than another other provision.” The rule enforces transparency expectations in several scenarios where organizations are required to make note of AI involvement, such as:

  1. When AI interacts directly with people, such as when chatbots or virtual assistants are used to conduct client interactions
  2. When AI generates synthetic content, such as text, images, audio, or video
  3. When AI publishes text on matters of public interest (unless the text has been subject to human review)

This aspect of the Act is particularly relevant because it broadly applies to “any AI system,” whether seen as high-risk or not. The Act defines high-risk as “applications that could cause significant harm if used inappropriately,” which encompasses models that assist with decision-making and risk analysis. As GenAI use cases continue to emerge, firms must be especially mindful of these uses in their business operations.

Additionally, firms must prepare to comply with Article 12 on recordkeeping requirements related to high-risk AI systems. These rules mandate that firms ensure high-risk AI systems automatically record events over their lifespan, have logging capabilities in place to record events that could present risk, and identify persons involved in verifying generated results.

What do these rules mean for Nordic firms? 

So, where should Nordic firms pay particular attention as the next phase of the Act moves forward – and could this next phase help enable innovation?

One of the most foundational elements to achieving AI success is maintaining  transparency, accountability, and security. In its 2026 State of AI report in the Nordics, Deloitte found that governance and security have become core to AI strategies for Nordic organizations, with 84% of respondents listing data privacy and security as a top concern. Clearly, privacy and security are a key concern for Nordics based organizations, as comparatively 37% of EMEA firms see security and privacy as a considerable barrier to AI adoption.

Consequently, 67% have made investments in security and compliance a priority, and efforts to strengthen these areas have led to a 27% increase in AI trust from 2022 to 2026, proving the essentiality of governance and risk frameworks to appropriately support successful adoption.

The future of AI in the Nordics

Nordic firms are substantially investing in AI – with 25% allocating more than 20% of budget toward related efforts – but, according to the Deloitte survey, are seeing slower returns on that investment compared to other firms across Europe.

While firms navigate the push and pull of growing regulatory expectations and their own around realizing ROI, being able to answer these foundational questions will be vital to ensure that AI is compliant, as well as performant:

  1. Is my data easily accessible, unified, complete, and accurate enough to support AI our business goals and use?
  2. What are the top AI initiatives and high-impact use cases based on my business objectives?
  3. Has my firm refined frameworks to reflect AI implementation and established training around responsible AI use?
  4. Are we using AI in line with regulations like the EU AI Act, and are we consistently staying up to date with developing regulations and auditing our processes and compliance posture?

Executives in the Nordics expect AI to help drive revenue growth by almost a third by 2029. Realizing this potential will require firms to build the right frameworks to adopt and scale AI compliantly.

To fully realize the potential of AI, it’s imperative that Nordic firms not only build comprehensive governance to support AI integration, but invest in secure and scalable data consolidation tools that enable them to implement new technologies at scale.

5 mins read 31 July 2026