What the AI Act is, who it applies to, what you must do and by when. A practical, plain-language overview for organisations in Denmark and across the EU, kept up to date.
The AI Act is the EU's regulation on artificial intelligence. It applies directly in every member state, including Denmark, with no separate national law needed to take effect.
Rather than regulating the technology as such, the AI Act regulates the risk an AI system poses to people's safety and fundamental rights. The higher the risk, the stricter the requirements. It reaches organisations that build AI systems (providers) and organisations that use them (deployers), as well as importers and distributors, and it applies regardless of company size.
A common shortcut is to picture a simple "risk pyramid". In practice the Act runs four independent sets of obligations, and a single system can fall under more than one. Understanding which ones apply to you is the first real step.
These are assessed independently, not as a single ladder. Screen your systems against all four.
A defined list of uses that are banned outright, such as social scoring and certain manipulative or exploitative systems. No compliance path exists; they are simply not allowed.
Systems in sensitive areas (for example hiring, credit, education, critical infrastructure or regulated products). Strict duties: risk management, data quality, documentation, human oversight, accuracy and logging.
Lighter duties for systems that interact with people or generate content. Users must be told they are dealing with AI, and AI-generated or manipulated content must be marked.
Providers of general-purpose AI models (the large foundation models) have their own transparency, documentation and, for the most capable models, systemic-risk obligations.
AI literacy (Article 4) applies to everyone using AI at work: organisations must ensure staff have a basic understanding of how their AI systems work and the risks involved. This duty is already in effect.
The Act entered into force on 1 August 2024 and applies in phases. The 2026 Digital Omnibus deferred the high-risk deadlines; the dates below reflect that change.
Dates can change through further EU amendments. Always confirm against the official consolidated text on EUR-Lex before acting.
The regulation applies directly, and a Danish act (LOV nr. 467 of 14 May 2025) adds the supplementary national rules and names the competent authorities.
Coordinating national authority and market surveillance for most areas.
Authority for areas involving law enforcement and fundamental rights.
Authority for AI used in the administration of justice.
The Danish supplementary act also sets out penalties and entry into force. You can read it in full, in a readable format, on danskret.dk.
You do not need to solve everything at once, but you do need to know where you stand.
Part of the same family of plain-language overviews of laws and regulations, maintained by CisScan.
The General Data Protection Regulation explained: the seven principles, data subject rights, security and supervision (in Danish).
Denmark's ban on discrimination in the labour market: protected grounds and employer obligations (in Danish).
Documentation of a data processor's GDPR compliance, ready to hand to the data controller (in Danish).
CisScan turns the AI Act from a document exercise into continuously maintained evidence. It helps you inventory and classify your AI systems, close the gaps, and keep audit-ready documentation, alongside GDPR, ISO 27001, NIS2 and more, from one place.
The free check shows which EU regulations apply to your company, based on public data.