5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Denmark

AI Act supervision in Denmark: who supervises what, and where the gap is

Denmark has designated national authorities for the AI Act prohibitions in Article 5, and for almost nothing else. No market surveillance authority has been designated for high-risk systems, and no national penalty provisions have been enacted, because the framework bill L 111 lapsed at the general election of 24 March 2026. The gap is in the Danish designation and enforcement machinery — not in your obligations. A regulation applies directly. That distinction is the whole point of this page, and it is the one most group briefings get wrong in one direction or the other.

Also available in Dansk

How Barzel applies here Start free with BarzelVault

What has Denmark actually designated, and what has it not?

The Danish supplementary act is called lov om supplerende bestemmelser til forordningen om kunstig intelligens (act on supplementary provisions to the Regulation on artificial intelligence), LOV nr 467 af 14/05/2025. It came into force on 2 August 2025. It is short, and it is deliberately narrow: it deals with the prohibitions, not with the Regulation as a whole.

Role under the RegulationDanish authorityStatus
Competent authority — prohibited AI practices (Article 5) Digitaliseringsstyrelsen, Datatilsynet, Domstolsstyrelsen Designated by LOV nr 467
Notifying authority (bemyndigende myndighed) Digitaliseringsstyrelsen Designated
Single point of contact Digitaliseringsstyrelsen Designated
Market surveillance — high-risk systems — Not designated
National penalty provisions — Not enacted

Three Danish institutions are worth knowing by name, because English-language material tends to render them inconsistently. Digitaliseringsstyrelsen is the Danish Agency for Digital Government. Datatilsynet is the Danish Data Protection Agency, and it has been an operational supervisory authority for years, which matters below. Domstolsstyrelsen is the Danish Court Administration, and its presence in the list reflects the Article 5 prohibitions that bear on the administration of justice.

Why is the rest of it missing?

Because the bill reached its first reading and no further. The complete framework bill — L 111, forslag til lov om supplerende bestemmelser til forordningen om kunstig intelligens (AI-loven) — was tabled on 18 February 2026 with a proposed commencement of 2 August 2026. It reached first reading on 17 March 2026 and lapsed at the general election of 24 March 2026. As at 3 September 2026 it had not been reintroduced.

This is an entirely ordinary parliamentary outcome — a Danish bill that has not completed its readings when an election is called falls, and has to be tabled afresh in the new session. It is not a political decision to abstain from regulating. The effect, though, is the same: the designations and the penalties that were to have been in place on 2 August 2026 are not.

For a group compliance function the practical instruction is narrow and specific. Do not repeat the claim that Denmark has a national AI framework law. It appears in advisory material, in vendor decks and in group policy annexes drafted in early 2026 while L 111 was live, and it was superseded by an election. Where a decision turns on Danish designation or Danish sanctions, check the status of L 111 on ft.dk on the day, not the memo from last quarter.

Does the gap suspend your obligations?

No. This is the most important sentence on the page. A regulation applies directly in the Member States and does not require national implementation in order to bind undertakings. What Denmark lacks is the designation of authorities and the national penalty provisions — the apparatus that enforces. The duties themselves sit in the Regulation and apply on its own dates.

Two consequences follow, and they point in opposite directions, which is why this is so often mis-stated. The obligations are real now, and the absence of a Danish supervisor is not a dispensation. But in practice you will meet them first by another route: procurement conditions, group requirements and supplier agreements that ask about the Regulation long before any Danish authority does. The Article 5 prohibitions are the exception, because there is a live Danish supervisor for them today.

Which entity in a group structure is actually caught?

Start by separating two questions that English-language summaries habitually merge: who is obliged and who supervises. The Danish gap is entirely in the second. Nothing about it changes the first.

That has three implications for a group with a Danish entity.

The obligation attaches to the operator, not to the country that has designated a supervisor. A Danish subsidiary that puts an AI system into use is subject to the Regulation on its own account, whether or not a Danish authority is ready to inspect it. Conversely, a group parent in London, New York or Frankfurt does not acquire Danish obligations merely because its subsidiary is Danish; it acquires them through its own role in relation to the system.

There is no forum to shop for. A Danish gap does not relocate supervision to a Member State that has completed its designations, and it does not create a Danish safe harbour either. Groups occasionally reason that a system deployed through the Danish entity is, for now, out of anyone's reach. That is a misreading of what has not happened in Denmark. If the same system is also placed on the market or put into service elsewhere in the Union, the designations in those Member States are unaffected by Denmark's.

You have exactly one Danish addressee, and it is the single point of contact. Digitaliseringsstyrelsen holds that role and the notifying-authority role. For an Article 5 question about a Danish deployment there is a competent authority to answer to today. For anything about high-risk systems there is currently no Danish counterpart to correspond with at all, which is itself a fact worth recording in a group risk register rather than leaving as a blank.

One more point for a vendor selling into Denmark. Because the national penalty provisions are not enacted, the commercial pressure in Danish procurement is running ahead of the statute. Danish buyers — particularly public-sector and regulated ones — are asking for conformity evidence on the Regulation's timetable, not on Denmark's. A vendor that answers Denmark has not designated an authority to a Danish tender question is answering a question nobody asked.

Which dates actually bind, and where is the trap?

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moved the high-risk requirements. It did not move the transparency obligations.

ObligationApplies from
Prohibited AI practices (Article 5)Applying — and with a designated Danish supervisor
Transparency obligations2 August 2026 — not deferred
High-risk: standalone systems (Annex III)2 December 2027
High-risk: safety components of regulated products (Annex I)2 August 2028

The trap is the choice of source. Digitaliseringsstyrelsen's FAQ still shows the dates that applied before the omnibus, and the agency states itself that the site is being updated. So take the dates from the Regulation and the institutional picture from the agency's material. Anyone reading the dates off the official Danish guidance at present is planning against a timetable that no longer holds — and a group that has standardised on citing the national regulator as its authoritative source is exposed to precisely that error.

Is Denmark an outlier?

No. Several markets have either partial designations or none, which matters if your entity map covers more than one of them.

CountryNational AI lawAuthority
Denmark Article 5 only (LOV nr 467). Framework bill lapsed March 2026 Digitaliseringsstyrelsen, Datatilsynet, Domstolsstyrelsen — Article 5 alone
Slovakia Draft approved by the government on 26 August 2026; intended commencement 1 January 2027 MIRRI SR as coordinating authority and single point of contact. A planned standalone authority was abandoned on budgetary grounds — 2025 sources naming a different body are out of date
Belgium No dedicated AI law, and none planned BIPT has been announced as lead market surveillance authority, but sources disagree on whether the designation has formally been completed. The federal and regional division of competence is part of the delay
Estonia No national implementing act TTJA states that it intends to take the role — an intention, not a completed designation
Switzerland No AI law. Sector-specific approach decided on 12 February 2025; consultation draft expected by the end of 2026 —
Norway The AI Regulation has not been incorporated into the EEA Agreement and does not apply. A draft Norwegian AI act is expected to be put to the Storting in spring 2027 —

If you operate in several of these, you cannot use a local supervisor as your bearing. The Regulation is common; the apparatus is not yet. The Norwegian position is the one that most often surprises a group compliance lead: an entity in Norway is not in the same regime as an entity in Denmark, however similar the two markets look on an org chart.

What actually binds a Danish entity today?

The regimes that are genuinely in operation. The contrast is sharp. The NIS 2-loven, LOV nr 434 af 06/05/2025, came into force on 1 July 2025, has a functioning authority in Styrelsen for Samfundssikkerhed (the Danish Emergency Management and Societal Security Agency), sector-based supervision, a duty under § 7 on the ledelsesorgan (management body) to approve the measures and attend training, reporting deadlines under § 13 of 24 hours, 72 hours and one month, and sanctions under § 32 — including, for væsentlige enheder (essential entities), the power temporarily to prohibit an individual from exercising management functions.

So the cyber regime is operational while the AI regime is half built. Add to that the data protection rules, where Datatilsynet has been an active authority for years.

The conclusion is not to ignore the AI Regulation but to build against the requirements that are already enforced: documented management approval, controls that run before an automated action executes, and a record that can reconstruct a single action months later. Build that, and the high-risk obligations arriving in December 2027 become, in large part, the documentation of controls you needed anyway. The general treatment of those controls is in approving AI actions and human in the loop; the Danish evidentiary detail is in building an AI audit trail a Danish auditor will accept.

What should a group compliance function do now?

  1. Establish whether any of your systems fall under the Article 5 prohibitions. That is the part with a live Danish supervisor today.
  2. Review the transparency obligations against your customer-facing AI. They have applied since 2 August 2026 and were not deferred.
  3. Map which systems will be high-risk and which date they meet — 2 December 2027 or 2 August 2028.
  4. Take dates from the Regulation. Do not mark official Danish guidance as current without checking it.
  5. Build against the NIS 2-loven and the data protection rules, where the duties are concrete and enforced today.
  6. Put a standing check of L 111's status on ft.dk before any decision that depends on Danish designation or sanction.
  7. Correct the group entity register: record Denmark as Article 5 designated, high-risk not designated, rather than as compliant or non-compliant.

In practice

BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts covering the input data and the model and policy version in force. That is the evidence the high-risk obligations ask for in 2027 and the NIS 2-loven deadlines already require today.

How Barzel applies here

Frequently asked questions

Does Denmark have a complete national AI framework law?

Not as at 3 September 2026. LOV nr 467 af 14/05/2025 covers the Article 5 prohibitions alone. The framework bill L 111 was tabled on 18 February 2026, reached first reading on 17 March 2026 and lapsed at the general election of 24 March 2026. It had not been reintroduced at the date of this article.

Who supervises high-risk AI systems in Denmark?

No authority has been designated. Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen are competent authorities for Article 5, and Digitaliseringsstyrelsen is also the notifying authority and single point of contact. Market surveillance for high-risk systems is not designated, and penalty provisions are not enacted.

Is a foreign parent off the hook because Denmark has not designated an authority?

No. A regulation applies directly and does not need national implementation to bind. What is missing is the national designation and the national penalties, not the duties. In practice the requirements arrive through procurement, group requirements and supplier contracts first.

Did the digital omnibus defer the transparency obligations?

No. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and deferred only the high-risk requirements. The transparency obligations have applied since 2 August 2026.

When do the high-risk requirements apply?

Standalone systems under Annex III from 2 December 2027. High-risk systems that are safety components of regulated products under Annex I from 2 August 2028.

Which Danish authority should we contact?

Digitaliseringsstyrelsen, as single point of contact and notifying authority. For high-risk matters there is currently no designated Danish counterpart at all.

Where this goes next

This is the least stable point in Danish AI compliance at present. A reintroduced bill could change the picture within a single parliamentary session, and an article carrying this date should not be relied on alone. Check the status of L 111 on ft.dk. That is the check that keeps working when the dates in the text no longer do. Errors we have found and corrected in published material are listed under corrections.

Related reading

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

429 days leftEU AI Act high-risk obligations (Annex III) apply from 2 December 2027

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel Central Gateway

The AI governance control plane: one inventory and one policy layer across every MCP server and agent.

  • Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
  • Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
  • Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.

Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Lov om supplerende bestemmelser til forordningen om kunstig intelligens, LOV nr 467 af 14/05/2025 — retsinformation.dk. In force 2 August 2025.
  2. Folketinget, bill L 111 (2025/1), forslag til lov om supplerende bestemmelser til forordningen om kunstig intelligens (AI-loven) — ft.dk. Tabled 18 February 2026, lapsed at the general election of 24 March 2026.
  3. Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) — in force 27 July 2026.
  4. Digitaliseringsstyrelsen, material on the AI Regulation — note that at the date of this article the FAQ still showed dates from before the digital omnibus, and the agency states the site is being updated.
  5. Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven), LOV nr 434 af 06/05/2025 — retsinformation.dk.

This article is for information and does not constitute legal advice. The Danish text of the instruments cited is the binding one. Position as at 3 September 2026.