EU AI Act in Finland: Supervision, Sandboxes and Deadlines

This page explains who supervises the EU AI Act in Finland, how the Finnish authority structure splits across sectoral regulators, what the national regulatory sandbox offers, and which dates now bind a company shipping AI products from or into Finland. Enforcement powers have been live since 2 August 2026, so the questions below are operational, not preparatory.

What the Act requires of Member States

The Regulation is directly applicable in Finland. There is no Finnish transposition of the substantive obligations, and no Finnish version of Article 5, Article 50 or Article 53 that differs from the text applied in Germany or Spain. What Finland does control is the institutional layer.

Article 70 requires each Member State to establish or designate at least one notifying authority and at least one market surveillance authority as national competent authorities, and to identify a single point of contact for the Commission and for other Member States. Article 74 gives market surveillance authorities the powers of Regulation (EU) 2019/1020, which includes demanding documentation, requiring corrective action, restricting or withdrawing a system from the market, and, under Article 74, requesting access to the training and trained models of a high risk system where that is necessary to assess conformity. Article 77 requires Member States to identify the public bodies that supervise fundamental rights obligations and to give them the power to request documentation from providers and deployers.

Article 57 requires each Member State to ensure that at least one AI regulatory sandbox is established and operational at national level. Article 62 requires Member States to give SMEs and start-ups established in the Union priority access to those sandboxes, plus dedicated communication channels and awareness raising. Article 99 sets the penalty ceilings that national authorities apply: up to 35 million euros or 7 per cent of worldwide annual turnover for breaches of the Article 5 prohibitions, up to 15 million euros or 3 per cent for most other provider and deployer obligations, and up to 7.5 million euros or 1 per cent for supplying incorrect, incomplete or misleading information to authorities.

The Finnish authority structure

Finland has taken a distributed approach rather than creating a single new AI regulator. Preparation has been led by the Ministry of Economic Affairs and Employment, and the model is that existing sectoral supervisors take AI market surveillance inside the domains they already regulate, with one authority acting as coordinator and single point of contact.

In practice this means the following mapping, which you should confirm against the current designation before you rely on it in a filing:

  • Coordination and single point of contact. Traficom, the Finnish Transport and Communications Agency, which also hosts the National Cyber Security Centre.
  • Financial services, credit scoring and insurance pricing. Finanssivalvonta, the Financial Supervisory Authority.
  • Medical devices and health software. Fimea and Valvira within their existing product and service remits.
  • Consumer facing systems and unfair commercial practices. The Finnish Competition and Consumer Authority.
  • Biometrics, law enforcement and fundamental rights requests. The Office of the Data Protection Ombudsman, alongside its GDPR role.
  • Accreditation of conformity assessment bodies. FINAS, the Finnish accreditation service.

The practical consequence for a Finnish company is that your first contact may not be Traficom at all. A Helsinki insurtech running a risk pricing model will be looked at by Finanssivalvonta, using supervisory relationships and reporting channels that already exist. A recruitment platform selling into Finnish employers will be dealt with by the labour and consumer side. Do not build a compliance function that assumes one inbox.

Language matters too. Finland operates in Finnish and Swedish. Article 13 requires instructions for use to be provided in a language easily understood by deployers, and Member States set that language. Plan for Finnish and Swedish instructions for use and human oversight material for any high risk system placed on the Finnish market, and budget the translation and review time rather than treating it as a release day task.

Provider or deployer, and which one you are in Finland

The Act attaches obligations to roles, not to company size or nationality. You are a provider if you develop an AI system or a general purpose AI model and place it on the market or put it into service under your own name or trade mark. You are a deployer if you use an AI system under your own authority in a professional capacity. A Finnish SaaS company that fine tunes and ships a model is a provider. The same company using a third party CV screening tool internally is a deployer of that tool.

Two crossovers catch Finnish companies regularly. Article 25 turns a deployer into a provider if you put your own name or trade mark on a high risk system, make a substantial modification to it, or change its intended purpose so that it becomes high risk. Article 26 imposes standalone deployer duties: use the system in line with the instructions for use, assign human oversight to people with the competence, training and authority to exercise it, keep the automatically generated logs under your control for at least six months unless other law says otherwise, and inform workers' representatives and affected workers before putting a high risk system into use in the workplace. That last point interacts with Finnish co-determination practice, so involve HR and any shop steward early rather than at rollout.

Article 4 applies to everyone now. Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf, taking account of technical knowledge, context of use and the affected persons.

The Finnish sandbox

Article 57 sandboxes are supervised testing environments. They allow you to develop, train, validate and test an AI system under the supervision of the competent authority before it is placed on the market, on agreed terms and for a defined period. Finland has signalled that its national sandbox will be run through Traficom, drawing on its existing experience with regulatory testing and experimentation, with sectoral supervisors joining where the use case sits in their domain. Confirm the operating body and the current application window before you plan a release around it.

What a sandbox does and does not give you:

  • It gives you written guidance from the supervisor and an exit report describing the activities carried out and the results. That report is evidence you can present to other authorities and to notified bodies.
  • Under Article 57, participation does not affect the supervisory powers of the authority, and it does not exempt you from liability for harm caused to third parties.
  • Article 59 allows the processing of personal data lawfully collected for other purposes within a sandbox, but only for developing, training and testing specified AI systems in the public interest, and only under strict conditions.
  • Article 62 gives SMEs and start-ups established in the Union priority access, free of charge, without prejudice to exceptional costs that authorities may recover.

A sandbox is worth the effort if your product sits close to an Annex III category and you genuinely do not know which side of the line it falls on, or if your conformity assessment route is unclear. It is not worth the effort as a marketing exercise, and it will not compress the technical documentation work under Article 11.

The dates that bind

  • 2 February 2025. Article 5 prohibitions apply. Social scoring, untargeted facial image scraping, emotion inference in the workplace and in education outside safety and medical grounds, and the other listed practices are already unlawful.
  • 2 August 2026. Enforcement powers went live. Article 50 transparency duties and Article 53 general purpose AI model obligations have been enforceable since that date. Article 57 sandboxes were required to be operational.
  • 2 December 2027. Annex III standalone high risk obligations apply, following the Digital Omnibus provisional agreement of May 2026, which is still pending formal adoption. This is the next hard date, 454 days away.
  • 2 August 2028. Annex I embedded high risk obligations apply, covering AI that is a safety component of a product already subject to Union product legislation.

Five things to do

  1. Map every system to a sector, then to a Finnish supervisor. Produce a one page table listing each AI system you provide or deploy, its role classification, its risk classification, and the Finnish authority most likely to hold the file. Circulate it to engineering leadership and the board.
  2. Close the Article 50 and Article 53 gaps this quarter, not next year. These are already enforceable. Check that synthetic image, audio and video output is marked in a machine readable format, that chatbots disclose they are machines, that deepfakes are labelled, and that any general purpose model you publish carries the technical documentation, the copyright policy and the training data summary.
  3. Fix logging now. Article 12 requires high risk systems to log automatically over their lifetime. Article 26 requires deployers to retain logs for at least six months. Retrofitting event logging into a mature product is a multi sprint job, so start it while the December 2027 date still allows for slippage.
  4. Prepare Finnish and Swedish documentation. Instructions for use, human oversight guidance and the customer facing parts of your technical file will need to be available in the language your Finnish deployers understand. Treat translation as part of the release definition of done.
  5. Decide on the sandbox by a fixed date. If you are borderline Annex III, apply. If you are not, write down why in one paragraph and move on. Undecided is the expensive option.

If you are unsure whether your system falls inside Annex III or whether you are a provider or a deployer of it, the free screener at https://www.getactcomply.com/check walks through the classification questions and returns the obligations that attach to each answer.

Check your EU AI Act risk in 5 minutes

Free risk classifier. No signup required. Enforcement is already live.

Run the free screener