Through the EEA Agreement, Norway is directly tied to the EU's regulatory framework, and the EU AI Act will in all likelihood be incorporated into Norwegian law. This means that the deadlines, obligations, and sanctions in the revised legislation are just as relevant to a Norwegian startup in Bergen as to a technology company in Berlin.
The Digital Omnibus Changes the Rules of the Game
The official designation is the Digital Omnibus amendments, but in tech-policy circles they are commonly referred to as the "omnibus deal." According to Tech Policy Press, the core of the changes is to simplify implementation of the AI Act, clarify supervisory responsibilities, and adjust a number of transitional deadlines — without altering the law's fundamental objectives.
The AI Act formally entered into force on 1 August 2024. Obligations relating to so-called general-purpose AI models (GPAI models, also known as foundation models) became applicable from 2 August 2025.

Two Tracks: Standard GPAI Models and High-Risk Models
The regulatory framework distinguishes between generic GPAI models and those with systemic risk. Standard models are subject to requirements covering technical documentation, user instructions, compliance with the copyright directive, and publication of a summary of training data.
Models classified as posing systemic risk face far stricter requirements — including risk assessments, testing against adversarial attack scenarios, and an obligation to report serious incidents. Open-source models are in principle exempt from most obligations, with the exception of copyright requirements and the training data summary requirement — unless they are classified as posing systemic risk.
Revised Deadlines — But Not for Everything
The Omnibus package introduces several postponements that Norwegian organisations should take note of:
Providers of GPAI models that were already on the market before 2 August 2025 have a transitional period until 2 August 2027. New models launched after that date must, however, comply with the requirements immediately.
The AI Office Gains Expanded Authority
A significant structural change is that the EU's AI Office — the central supervisory body — now has exclusive authority over AI systems built on GPAI models from the same provider or corporate group, and over models integrated into very large online platforms and search engines as defined under the Digital Services Act.
National authorities retain supervisory responsibility within specific sectors, such as law enforcement and financial institutions. For Norwegian businesses, this means in practice that the line of accountability may run directly to EU level for many of the most relevant AI services.
Guidance and Voluntary Code of Conduct
To assist stakeholders with compliance, the European Commission published guidelines on GPAI obligations in July 2025, along with a voluntary code of conduct for GPAI models, according to source material from Tech Policy Press. The code is formally voluntary, but experts describe it as a "quasi-mandatory governance framework" — a regime in which compliance in practice provides a clearer path through the regulatory landscape and potentially lower regulatory risk.
What Does This Mean in Practice for Norwegian Stakeholders?
For Norwegian developers and tech leaders, there are three things that are immediately actionable:
Transparency requirements apply now. From 2 August 2026, AI systems that interact with users — chatbots, generative tools, deepfakes — must be clearly labelled and disclosed. There is no postponement here.
Check whether your system falls under high-risk. If your organisation develops or uses AI in healthcare, critical infrastructure, education, employment, or law enforcement, Annex III or Annex I applies — with deadlines in 2027 and 2028.
Consider the code of conduct. For those developing or building products on GPAI models, early adoption of the voluntary code can provide predictability and reduce the risk of conflicts with supervisory authorities.
The source material emphasises that ambiguities in the regulatory framework remain, and that experts caution against interpreting the postponements as a general relaxation of requirements. The fundamental regulatory framework remains unchanged.
