Asset Management | The EU AI Act: a call and guide to implementation for Norwegian asset managers

As of 2 August 2026, the EU AI Act’s (Regulation (EU) 2024/1689) transparency obligations apply across the EU, and they already affect Norwegian asset managers whose AI systems produce output used in the EU, even ahead of the AI Act’s implementation in Norway. This is a call and guide to implementation tailored to the requirements for Norwegian asset managers.

Relevance of the EU AI Act for Norwegian asset managers

In Norway, implementation of the EU AI Act is still underway, and further behind than originally planned. The draft Norwegian AI Act (KI-loven) went out for public consultation on 30 June 2025, drawing close to 150 consultation responses. Formal EEA incorporation and Norwegian entry into force have not yet happened, and the Government’s original target of “late summer 2026” has been missed. The Ministry of Digitalisation and Public Governance has indicated the ambition of putting a bill on the Norwegian AI Act before the Storting in spring 2027 – but progress depends on the EEA negotiations on incorporating the AI Act into the EEA Agreement, so even that timeline is not fixed. In our view, Norwegian entry into force is therefore rather unlikely before mid 2027.

However, that gap does not remove Norwegian asset managers from scope. The EU AI Act applies not only to providers and deployers established in the EU, but also, critically, to those established in a third country – like Norway – where the output of the AI system is used in the Union. A Norwegian asset manager can fall within scope without any EU establishment once an AI system’s output – a recommendation, decision, prediction, or piece of content – is used in the EU. Practical examples can include an investment decision for an EU AIF, communication with EU investors, or a due-diligence assessment of an EU target.

Further scope of the EU AI Act

The EU AI Act separates the provider of an AI system – the entity that creates it and places it on the market or puts it into service under its own name – from the deployer – the person or entity that uses it under its own authority. The assessment is made for each AI system individually, so a company can be both a provider and a deployer at the same time. Providers generally face more, and stricter, requirements under the EU AI Act. Asset managers generally sit on the deployer side when using AI systems in their professional activities.   However, an asset manager can easily become a provider in relation to an AI tool – for example, when it commissions a bespoke chatbot or content generator under its own name – and should confirm the allocation of responsibility with its vendor before go-live. The same question arises for EU target companies building AI-related products.

We have compiled a simplified overview of the main concepts to check when determining who falls within the further scope of the EU AI Act.

Provider

= the company or person that creates an AI system and puts it out into the world under its own name or brand – whether they sell it or give it away for free.

Examples: OpenAI as the provider of ChatGPT; Anthropic as the provider of Claude; Microsoft as provider of Copilot.

Deployer

= the company or person that uses someone else’s AI system to run their own business or activities.

Example: An asset manager or employee that uses Copilot or ChatGPT in the course of a professional activity.

AND

AI system

= a software that doesn’t just follow a fixed set of human-written rules, but works things out itself from data or knowledge, and its output can have a real effect.

European Commission examples for AI systems:

  • A spam filter that learns from emails people have labelled “spam” or “not spam” and then sorts new emails accordingly.
  • Image classification tools, medical imaging diagnostic tools, and fraud detection systems trained on labelled examples.
  • Language models that essentially predict the next word in a sentence.
  • Tools that predict household or building energy use by combining data from smart meters, weather forecasts, and people’s usage habits.
European Commission examples for systems that do not qualify:

  • Basic database or spreadsheet tools that just sort or filter data using fixed rules.
  • Software that only displays or visualises data, like a sales dashboard showing totals and trends, without recommending what to do next.

AND NO

General exclusions from the EU AI Act:

  • Use of AI systems for purely personal, non-professional purposes.
  • AI systems developed and put into service for the sole purpose of scientific research and development, and pre-market research, testing and development activity.
  • AI systems released under free and open-source licences, unless they qualify as high-risk, are prohibited under Article 5, or fall under the Article 50 transparency rules.
  • AI systems used exclusively for military/defence or national security purposes.

 

High risk system

High-risk systems face tougher obligations under the EU AI Act: risk management, data governance, technical documentation, human oversight, robustness and cybersecurity standards, formal conformity assessment, and registration in an EU database, on top of the provider/deployer duties covered elsewhere in this note. In plain terms, a system becomes “high-risk” in one of two ways.

Product-safety systems: where it is a safety component of a product already regulated under EU product-safety rules (think machinery, medical devices, cars, lifts) that needs independent safety certification before sale. These are the product categories listed in Annex I of the EU AI Act, and are rarely directly relevant to asset managers.
Sensitive-use-case systems: where it is used for one of eight sensitive uses listed in Annex III – biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration/asylum/border control, and justice and democracy. Of these, only three are realistically relevant for asset managers, discussed below.

A system in one of those eight areas is not treated as high-risk if it only performs a narrow, procedural task, double-checks a human decision without replacing it, or otherwise does not create a meaningful risk of harm – unless it profiles individuals, in which case the carve-out never applies.

For asset managers, only three of those eight areas are realistically relevant: (i) credit scoring under the “access to essential services” category (but not fraud detection, which is carved out); (ii) life and health insurance risk-pricing, also under “access to essential services”; and (iii) employment and workforce management tools, such as CV-screening software, recruitment tools, and systems deciding promotions, terminations, task allocation, or performance monitoring.

These high-risk rules were originally due to apply from 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and defers them to 2 December 2027 for the sensitive-use-case systems and to 2 August 2028 for the product-safety systems. Only the timing has changed. Which activities count as high-risk has not.

Provisions relevant to Norwegian asset managers

Generally applicable provisions for deployers Article 4 (AI literacy), applicable since February 2025 but amended only recently on 27 July 2026, requires providers and deployers to take measures ensuring their staff and other persons dealing with AI systems on their behalf have sufficient AI literacy, taking into account their knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are used. The obligation does not require guaranteeing any specific level of AI literacy for any individual. AI literacy should provide all relevant actors in the AI value chain with the insights required to ensure appropriate compliance. AI literacy should cover the correct application of technical elements during development, the measures to apply during use, and how to interpret the AI system’s output; for staff facing clients or investors whose interests may be affected by AI-assisted decisions, it should also extend to understanding how those decisions can impact them. The European Artificial Intelligence Board is expected to promote specific AI literacy tools, and the Commission should facilitate the drawing up of voluntary codes of conduct to advance AI literacy.
Article 5 (prohibited AI practices), bans manipulative, exploitative, discriminatory or surveillance uses of AI that should fall well outside typical asset management use cases.
Article 50 (transparency obligations for certain AI systems) applies from 2 August 2026 for new systems placed on the market on or after that date.

  • Emotion recognition or biometric categorisation systems: Deployer must inform the people exposed to the system about its operation and process any personal data in line with the GDPR, Regulation (EU) 2018/1725 and the Law Enforcement Directive. Exempt for systems lawfully used to detect, prevent or investigate crime, subject to safeguards.
  • Deep fake systems (image, audio or video content): Deployer must disclose that the content is artificially generated or manipulated. Exempt for lawful law-enforcement use; for evidently artistic, creative, satirical or fictional works, disclosure only needs to flag the existence of the generated/manipulated content in a way that doesn’t disrupt the work.
  • AI-generated or manipulated text published on matters of public interest: Must disclose that the text is artificially generated or manipulated. Exempt for lawful law-enforcement use, or where the content has undergone human review/editorial control and an accountable natural or legal person holds editorial responsibility for publishing it.
Deployers of high-risk systems (earliest from 2 December 2027) Article 26 (obligations of deployers of high-risk AI systems): Deployers must use high-risk systems as instructed, assign competent human oversight, monitor performance and report risks or incidents, retain logs for at least six months, inform workers before workplace use, register public-sector use, support DPIAs, and follow strict rules for post-remote biometric identification.
Article 27 (Fundamental rights impact assessment): Certain deployers (public bodies, public-service providers, and specific Annex III cases) must assess fundamental rights impacts before first use and notify the market surveillance authority.

Note that non-compliance with transparency obligations can attract fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.

AI in day-to-day practice: confidentiality and due diligence

For most Norwegian asset managers, the practical challenges with using AI in their operations lie less in the EU AI Act and more with related fields such as DORA and the GDPR. While the EU AI Act is governing the system itself (i.e. risk classification, documentation, disclosure), the GDPR governs the input and output data. Whenever an AI system processes personal data – i.e. training data, prompts, or data used to generate a decision – the GDPR’s core obligations apply in the ordinary way, including the requirement for a lawful basis for processing, data minimisation, purpose limitation, transparency to data subjects, and potentially a full data protection impact assessment (DPIA) for high-risk processing. Two practical issues are worth highlighting:

  • Confidential information. Employees should not input insider information, fund or portfolio data, investor personal data, or other confidential information into AI tools that have not been specifically approved for that purpose. Asset managers should have a clear policy on AI use, and ideally give employees access to approved AI tools, to discourage unauthorised “shadow AI” use – an emerging problem Finanstilsynet has already started looking at. Enterprise deployments such as Microsoft Copilot, configured so that data stays within the firm’s own tenant and is not used to train the provider’s underlying models, carry a materially different risk profile from public consumer AI tools (such as a free chatbot), where inputs may be used for model training and confidentiality cannot be assured. This is particularly important for confidential information received from a counterparty under an NDA: sharing it with an AI tool may qualify as disclosure to the AI provider. Most NDAs permit disclosure to “representatives” or “advisers” who need the information for the permitted purpose and require that those representatives are bound by confidentiality obligations at least as strict as the NDA itself – but most NDA templates predate the use of AI tools and may not adequately address this.
  • Use of AI in due diligence. AI is increasingly used in due diligence: summarising data-room documents and deal papers, extracting and structuring financial and ownership data from PDF reports into valuation models, and providing a first-pass overview of a target’s contracts or disclosures. Used this way, AI supports rather than replaces the deal team’s own analysis. Human review before reliance remains essential – generative AI can produce convincing but inaccurate output (“hallucinations” and biases), including misclassifying figures or conflating similar documents, and should never be treated as authoritative without independent verification.

Implementation checklist

  • Map your AI systems and screen your third-party provider, note that this exercise overlaps with existing obligations under DORA, since a provider of an AI system typically also qualifies as an ICT third-party provider under DORA. For new AI vendors, run DORA-aligned due diligence: check the vendor’s critical/important ICT third-party classification, review the contractual framework for must-have clauses and provisions and document the review.
  • Confirm your role as provider or deployer for each system, and revisit vendor contracts for bespoke tools built under the firm’s own name to avoid unintentionally qualifying as a provider.
  • Check the EU link: which systems’ output reaches an EU AIF or an EU investor relationship.
  • Address AI in your internal policies, whether through updates to existing policies or a stand-alone AI policy, covering permitted use and disclosure.
  • Keep AI literacy training current for relevant team members, covering how the firm’s AI tools work, permitted and prohibited uses, how to identify and handle hallucinations and bias, how to interpret AI output, and, for client-facing staff, how AI-assisted decisions can affect clients and investors.

BAHR’s comment

Norwegian asset managers should not treat the EU AI Act as an issue that can wait for EEA incorporation. That is because the Act’s own scope already reaches a Norwegian asset manager as soon as an AI system’s output is used in the EU – a threshold that is particularly relevant to AIFMs managing an EU AIF or investing in an EU target, and one that does not depend on Norwegian transposition of the Act.

Even so, meeting those obligations should not fundamentally affect the typical business of a Norwegian asset manager. For most firms operating as deployers of non-high-risk systems, bringing existing practices into line with the AI literacy and transparency requirements should be a manageable, largely process-driven exercise rather than a fundamental overhaul. That said, firms should act now rather than wait: AI use is only set to grow, and supervisory authorities across Europe – including Finanstilsynet – are watching developments closely. Moreover, while the high-risk deadline has moved to December 2027, the underlying classification test has not, so it remains worth monitoring whether a firm’s use of AI is drifting from deployer into provider, or into one of the high-risk categories – particularly when dealing with EU target companies.

Alongside the EU AI Act itself, firms should keep DORA in view: its requirements apply in addition to, not instead of, the AI Act. In practice, the provider of an AI system under the EU AI Act should typically also qualify as an ICT third-party provider under DORA and must therefore be checked against DORA compliance as well, including rules on incidents handling, the register of information and contractual due diligence.

Share aticle to
Loading video ...
close