Asset Management | The EU AI Act: a call and guide to implementation for Norwegian asset managers
Relevance of the EU AI Act for Norwegian asset managers
In Norway, implementation of the EU AI Act is still underway, and further behind than originally planned. The draft Norwegian AI Act (KI-loven) went out for public consultation on 30 June 2025, drawing close to 150 consultation responses. Formal EEA incorporation and Norwegian entry into force have not yet happened, and the Government’s original target of “late summer 2026” has been missed. The Ministry of Digitalisation and Public Governance has indicated the ambition of putting a bill on the Norwegian AI Act before the Storting in spring 2027 – but progress depends on the EEA negotiations on incorporating the AI Act into the EEA Agreement, so even that timeline is not fixed. In our view, Norwegian entry into force is therefore rather unlikely before mid 2027.
However, that gap does not remove Norwegian asset managers from scope. The EU AI Act applies not only to providers and deployers established in the EU, but also, critically, to those established in a third country – like Norway – where the output of the AI system is used in the Union. A Norwegian asset manager can fall within scope without any EU establishment once an AI system’s output – a recommendation, decision, prediction, or piece of content – is used in the EU. Practical examples can include an investment decision for an EU AIF, communication with EU investors, or a due-diligence assessment of an EU target.
Further scope of the EU AI Act
The EU AI Act separates the provider of an AI system – the entity that creates it and places it on the market or puts it into service under its own name – from the deployer – the person or entity that uses it under its own authority. The assessment is made for each AI system individually, so a company can be both a provider and a deployer at the same time. Providers generally face more, and stricter, requirements under the EU AI Act. Asset managers generally sit on the deployer side when using AI systems in their professional activities. However, an asset manager can easily become a provider in relation to an AI tool – for example, when it commissions a bespoke chatbot or content generator under its own name – and should confirm the allocation of responsibility with its vendor before go-live. The same question arises for EU target companies building AI-related products.
We have compiled a simplified overview of the main concepts to check when determining who falls within the further scope of the EU AI Act.
| Provider
= the company or person that creates an AI system and puts it out into the world under its own name or brand – whether they sell it or give it away for free. Examples: OpenAI as the provider of ChatGPT; Anthropic as the provider of Claude; Microsoft as provider of Copilot. |
Deployer
= the company or person that uses someone else’s AI system to run their own business or activities. Example: An asset manager or employee that uses Copilot or ChatGPT in the course of a professional activity. |
AND
| AI system
= a software that doesn’t just follow a fixed set of human-written rules, but works things out itself from data or knowledge, and its output can have a real effect. |
|
European Commission examples for AI systems:
|
European Commission examples for systems that do not qualify:
|
AND NO
General exclusions from the EU AI Act:
|
High risk system
High-risk systems face tougher obligations under the EU AI Act: risk management, data governance, technical documentation, human oversight, robustness and cybersecurity standards, formal conformity assessment, and registration in an EU database, on top of the provider/deployer duties covered elsewhere in this note. In plain terms, a system becomes “high-risk” in one of two ways.
| Product-safety systems: where it is a safety component of a product already regulated under EU product-safety rules (think machinery, medical devices, cars, lifts) that needs independent safety certification before sale. These are the product categories listed in Annex I of the EU AI Act, and are rarely directly relevant to asset managers. |
| Sensitive-use-case systems: where it is used for one of eight sensitive uses listed in Annex III – biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration/asylum/border control, and justice and democracy. Of these, only three are realistically relevant for asset managers, discussed below.
A system in one of those eight areas is not treated as high-risk if it only performs a narrow, procedural task, double-checks a human decision without replacing it, or otherwise does not create a meaningful risk of harm – unless it profiles individuals, in which case the carve-out never applies. For asset managers, only three of those eight areas are realistically relevant: (i) credit scoring under the “access to essential services” category (but not fraud detection, which is carved out); (ii) life and health insurance risk-pricing, also under “access to essential services”; and (iii) employment and workforce management tools, such as CV-screening software, recruitment tools, and systems deciding promotions, terminations, task allocation, or performance monitoring. |
These high-risk rules were originally due to apply from 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and defers them to 2 December 2027 for the sensitive-use-case systems and to 2 August 2028 for the product-safety systems. Only the timing has changed. Which activities count as high-risk has not.
Provisions relevant to Norwegian asset managers
| Generally applicable provisions for deployers | Article 4 (AI literacy), applicable since February 2025 but amended only recently on 27 July 2026, requires providers and deployers to take measures ensuring their staff and other persons dealing with AI systems on their behalf have sufficient AI literacy, taking into account their knowledge, experience, education and training, the context of use, and the persons or groups on whom the systems are used. The obligation does not require guaranteeing any specific level of AI literacy for any individual. AI literacy should provide all relevant actors in the AI value chain with the insights required to ensure appropriate compliance. AI literacy should cover the correct application of technical elements during development, the measures to apply during use, and how to interpret the AI system’s output; for staff facing clients or investors whose interests may be affected by AI-assisted decisions, it should also extend to understanding how those decisions can impact them. The European Artificial Intelligence Board is expected to promote specific AI literacy tools, and the Commission should facilitate the drawing up of voluntary codes of conduct to advance AI literacy. |
| Article 5 (prohibited AI practices), bans manipulative, exploitative, discriminatory or surveillance uses of AI that should fall well outside typical asset management use cases. | |
Article 50 (transparency obligations for certain AI systems) applies from 2 August 2026 for new systems placed on the market on or after that date.
|
|
| Deployers of high-risk systems (earliest from 2 December 2027) | Article 26 (obligations of deployers of high-risk AI systems): Deployers must use high-risk systems as instructed, assign competent human oversight, monitor performance and report risks or incidents, retain logs for at least six months, inform workers before workplace use, register public-sector use, support DPIAs, and follow strict rules for post-remote biometric identification. |
| Article 27 (Fundamental rights impact assessment): Certain deployers (public bodies, public-service providers, and specific Annex III cases) must assess fundamental rights impacts before first use and notify the market surveillance authority. |
Note that non-compliance with transparency obligations can attract fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.
AI in day-to-day practice: confidentiality and due diligence
For most Norwegian asset managers, the practical challenges with using AI in their operations lie less in the EU AI Act and more with related fields such as DORA and the GDPR. While the EU AI Act is governing the system itself (i.e. risk classification, documentation, disclosure), the GDPR governs the input and output data. Whenever an AI system processes personal data – i.e. training data, prompts, or data used to generate a decision – the GDPR’s core obligations apply in the ordinary way, including the requirement for a lawful basis for processing, data minimisation, purpose limitation, transparency to data subjects, and potentially a full data protection impact assessment (DPIA) for high-risk processing. Two practical issues are worth highlighting:
- Confidential information. Employees should not input insider information, fund or portfolio data, investor personal data, or other confidential information into AI tools that have not been specifically approved for that purpose. Asset managers should have a clear policy on AI use, and ideally give employees access to approved AI tools, to discourage unauthorised “shadow AI” use – an emerging problem Finanstilsynet has already started looking at. Enterprise deployments such as Microsoft Copilot, configured so that data stays within the firm’s own tenant and is not used to train the provider’s underlying models, carry a materially different risk profile from public consumer AI tools (such as a free chatbot), where inputs may be used for model training and confidentiality cannot be assured. This is particularly important for confidential information received from a counterparty under an NDA: sharing it with an AI tool may qualify as disclosure to the AI provider. Most NDAs permit disclosure to “representatives” or “advisers” who need the information for the permitted purpose and require that those representatives are bound by confidentiality obligations at least as strict as the NDA itself – but most NDA templates predate the use of AI tools and may not adequately address this.
- Use of AI in due diligence. AI is increasingly used in due diligence: summarising data-room documents and deal papers, extracting and structuring financial and ownership data from PDF reports into valuation models, and providing a first-pass overview of a target’s contracts or disclosures. Used this way, AI supports rather than replaces the deal team’s own analysis. Human review before reliance remains essential – generative AI can produce convincing but inaccurate output (“hallucinations” and biases), including misclassifying figures or conflating similar documents, and should never be treated as authoritative without independent verification.
Implementation checklist
- Map your AI systems and screen your third-party provider, note that this exercise overlaps with existing obligations under DORA, since a provider of an AI system typically also qualifies as an ICT third-party provider under DORA. For new AI vendors, run DORA-aligned due diligence: check the vendor’s critical/important ICT third-party classification, review the contractual framework for must-have clauses and provisions and document the review.
- Confirm your role as provider or deployer for each system, and revisit vendor contracts for bespoke tools built under the firm’s own name to avoid unintentionally qualifying as a provider.
- Check the EU link: which systems’ output reaches an EU AIF or an EU investor relationship.
- Address AI in your internal policies, whether through updates to existing policies or a stand-alone AI policy, covering permitted use and disclosure.
- Keep AI literacy training current for relevant team members, covering how the firm’s AI tools work, permitted and prohibited uses, how to identify and handle hallucinations and bias, how to interpret AI output, and, for client-facing staff, how AI-assisted decisions can affect clients and investors.
BAHR’s comment
Norwegian asset managers should not treat the EU AI Act as an issue that can wait for EEA incorporation. That is because the Act’s own scope already reaches a Norwegian asset manager as soon as an AI system’s output is used in the EU – a threshold that is particularly relevant to AIFMs managing an EU AIF or investing in an EU target, and one that does not depend on Norwegian transposition of the Act.
Even so, meeting those obligations should not fundamentally affect the typical business of a Norwegian asset manager. For most firms operating as deployers of non-high-risk systems, bringing existing practices into line with the AI literacy and transparency requirements should be a manageable, largely process-driven exercise rather than a fundamental overhaul. That said, firms should act now rather than wait: AI use is only set to grow, and supervisory authorities across Europe – including Finanstilsynet – are watching developments closely. Moreover, while the high-risk deadline has moved to December 2027, the underlying classification test has not, so it remains worth monitoring whether a firm’s use of AI is drifting from deployer into provider, or into one of the high-risk categories – particularly when dealing with EU target companies.
Alongside the EU AI Act itself, firms should keep DORA in view: its requirements apply in addition to, not instead of, the AI Act. In practice, the provider of an AI system under the EU AI Act should typically also qualify as an ICT third-party provider under DORA and must therefore be checked against DORA compliance as well, including rules on incidents handling, the register of information and contractual due diligence.