AI ACt

Get a handle on the AI Act and establish a solid foundation for the use of artificial intelligence in your organization.
We offer everything from comprehensive programs to ongoing consulting on an hourly basis. 
Purchase a preliminary analysis starting at 10,000 DKK
Guidelines for Ensuring Compliance with the AI Act

The AI Act sets requirements for how artificial intelligence is developed, used, and documented. For companies, this means gaining an overview of AI solutions, assessing risks, and ensuring that AI is used responsibly and in accordance with applicable requirements.

We help you translate these requirements into concrete actions so that you can use AI in a secure, well-documented, and trustworthy manner. The result is a stronger foundation for capitalizing on the opportunities offered by AI while reducing legal, organizational, and technical risks.

Implementation of the AI Act: From Start to Finish

Step 1

Preliminary Analysis  

The preliminary analysis provides a clear overview of how the AI Act affects your use of artificial intelligence.

We map out where and how AI is used within your organization, which systems are involved, and which requirements are relevant to you. Based on this, we identify specific measures in areas such as risk assessment, the allocation of roles and responsibilities, documentation, governance, and oversight of AI systems. The result is a clear foundation for working in a targeted and effective manner to ensure compliance with the AI Act.

Guide to a Preliminary Analysis of an Organization's Use of AI

Step 2

AI readiness and risk assessment 

To comply with the AI Act, the organization must have an overview of where AI is used, the risks associated with its use, and the requirements that apply to individual AI systems.

We assess your current use of AI and identify areas where there may be legal, organizational, or technical risks. Based on this assessment, you will receive specific recommendations on how to manage these risks, what measures to put in place, and how to work with AI in a secure, responsible, and well-documented manner.

Illustration of the various risks and their severity associated with the use of AI

Step 3

Documentation 

To comply with the AI Act, the organization must be able to document how artificial intelligence is used and how risks are identified and managed.

We help you establish the necessary policies, processes, and procedures in areas such as AI governance, risk assessment, the allocation of roles and responsibilities, transparency, and the responsible use of AI. The result is a documented framework for using AI safely, in a controlled manner, and in compliance with applicable requirements.

Example of Documentation of AI Act Compliance

Step 4

Education and skills development  

Training and skills development ensure that employees and relevant key personnel understand their responsibilities when using AI.

We provide the organization with concrete knowledge about the safe, responsible, and documented use of AI, including relevant requirements under the AI Act, risks associated with AI systems, and internal guidelines for use. This creates a stronger foundation for using AI safely in practice and reduces the risk of errors, misuse, and non-compliance.

Illustration of awareness training for employees in organizations seeking ISO 27001 certification

Step 5

Full Compliance 

Once the necessary processes, competencies, and guidelines are in place, the organization will have a solid foundation for using AI safely and in compliance with the AI Act.

Compliance requires ongoing monitoring, documentation, and responsible use in practice. This gives you better control over AI usage, reduces legal and organizational risks, and builds greater trust among customers, employees, and business partners.

Guidelines for Ensuring Compliance with the AI Act

AI Act - Process

Contact us for ad hoc consulting at
or start with our preliminary analysis.

Example of documentation demonstrating an organization's compliance with the AI Act

Consulting

Practical and effective—on the organization’s terms

Duration and Scope

Tailored to the company's use of AI systems, risk level, and regulatory requirements

Contents

Mapping and Classification of AI Systems

Governance Structure and Division of Responsibilities

Evidence of Responsible and Ethical Use of AI

Human oversight and control mechanisms

IT Security Policies and Procedures

Prepares documentation for the company

Awareness training and workshops

Internal and External Compliance Checks

Expected output

AI “know-how”

Increased transparency and traceability

Increased trust among customers and business partners

Responsible Use of AI

Start with a no-obligation consultation with one of our experts, or purchase a preliminary analysis starting at 10,000 DKK

The First Step Toward AI Act Compliance

Send us an email to schedule a free 15-minute review of your AI Act requirements with one of our cybersecurity experts. 

By submitting your email address, you agree to our privacy policy and consent to being contacted by nesp.ONE.

View upcoming courses and webinars

Learn how your company can strengthen cybersecurity and achieve compliance with standards such as ISO 27001, NIS2, and CRA.

NIS2 for management 

Copenhagen / August 26, 26

ISO 27001: Certificate Course

Copenhagen / September 2–3, 2026

NIS 2 in Practice

Odense / September 10–11, 2026

ISO 27001: Certificate Course

Copenhagen / Oct. 7–8, 2025

Guides and articles about the AI Act

View all blog posts

AI Act: Mærkning af AI-indhold

1 september, 2026

AI Act: Nye krav til mærkning af AI-genereret indhold er trådt i kraft

AI Act kræver gennemsigtighed om chatbots, deepfakes og visse AI-tekster. Se hvad danske virksomheder skal mærke, kontrollere og dokumentere.

AI Act efter AI Omnibus

27 august, 2026

AI Act efter AI Omnibus: Nye frister for højrisiko-AI

AI Omnibus ændrer fristerne for højrisiko-AI. Se, hvad der gælder nu, og hvordan virksomheden bør prioritere den ekstra tid.

AI Security

March 16, 2026

AI Security

An analytical review of AI-specific security risks, differences from traditional IT security, and security requirements under the EU AI Act. 

Frequently Asked Questions About the AI Act

Do you still have questions that weren't answered? Schedule a free 15-minute consultation with a cybersecurity expert.

Book a free consultation

The AI Act, also known as the AI Regulation or the AI Law, is the EU’s regulation on artificial intelligence (Read more here). Its purpose is to ensure that AI systems are developed, marketed, and used responsibly, safely, and in accordance with fundamental rights.

The AI Regulation is based on a risk-based approach. This means that the requirements depend on how the AI system is used and the risks it may pose to individuals, organizations, and society. Certain AI practices are prohibited, while high-risk AI is subject to more comprehensive requirements regarding, among other things, risk management, documentation, data quality, transparency, human oversight, and security.

For businesses and public organizations, the AI Act means that the use of AI must be managed and documented more systematically. This applies not only to organizations that develop AI systems, but also to those that use AI tools in processes, decision support, customer service, HR, case management, or other business-critical areas.

Nesp.ONE helps organizations gain a clear understanding of the requirements of the AI Regulation, assess risks, and establish specific processes, guidelines, and documentation for the safe, responsible, and compliant use of AI.

The AI Act, also known as the AI Regulation, entered into force in the EU on August 1, 2024, and is directly applicable in Denmark. However, the rules will be phased in over several years.

The most important dates are:

    1. February 2025: General provisions, AI literacy, and prohibited AI practices take effect

    1. August 2025: Regulations governing general-purpose AI models, including generative AI models, will take effect

    1. August 2026: Most provisions of the AI Act take effect, including requirements for many high-risk AI systems

    1. August 2027: Requirements for high-risk AI systems incorporated into certain regulated products take effect (Read more here)

Danish organizations should therefore begin now to gain an overview of where AI is used, which systems may be affected, and what requirements apply. Nesp.ONE helps structure efforts related to AI governance, risk assessment, documentation, and the responsible use of AI.

The AI Regulation may apply to all Danish companies and organizations that develop, market, distribute, or use AI systems as part of their activities.

This applies, among other things, to companies that:

  • Develops AI systems or AI-based products (providers)

  • Use AI systems in their operations or business processes (users/deployers)

  • Imports AI systems from countries outside the EU

  • Distributing AI systems on the European market

  • Integrates AI functionality into its own products or services

For many organizations, it is particularly important to note that the AI Regulation does not apply only to companies that develop AI. Companies that use AI solutions—such as Microsoft Copilot, ChatGPT, Gemini, or other AI-based tools—may also have obligations regarding governance, risk assessment, competencies, transparency, and responsible use.

This means that the AI Regulation applies to both small and large businesses across all industries, including private companies, public organizations, and organizations subject to regulatory requirements.

Nesp.ONE helps clarify how the AI Regulation affects your organization, which requirements are relevant, and how these requirements can be translated into specific processes, guidelines, and documentation.

Yes, Danish companies may have obligations under the AI Regulation when they use AI tools such as ChatGPT, Microsoft Copilot, or Gemini in a business context. The requirements depend on how the tools are used, what data is processed, and whether AI output is used as the basis for decisions or processes that affect individuals, customers, or the business.

For most companies, it will be particularly important to establish clear guidelines for the use of AI, assess risks, ensure that employees have the necessary AI skills, and document its use where necessary. This is especially important if AI is used for customer service, HR, case management, document management, consulting, or decision support.

If a company develops its own AI solutions on top of these platforms or integrates AI into its own products and services, additional obligations may arise. Nesp.ONE helps clarify roles, risks, and requirements so that AI can be used safely, responsibly, and in compliance with the AI Regulation.

In Denmark, the AI Regulation is enforced through a coordinated effort by government agencies, with the Agency for Digitization playing a central role. The Danish Data Protection Agency and the Danish Court Administration also have responsibilities in selected areas, depending on how AI is used and which rules apply.

The Danish Agency for Digitization
The Danish Agency for Digitization is the national coordinating supervisory authority for the AI Regulation in Denmark. The Agency is responsible for coordination and overall supervision and serves as the point of contact with other EU countries and the European Commission. The Danish Agency for Digitization has also been designated as the notifying authority and central market surveillance authority under Danish law.

The Danish Data Protection Agency
The Danish Data Protection Agency has been designated as the market surveillance authority for selected parts of the AI Regulation, particularly where the rules overlap with data protection, personal data, and fundamental rights.

The Danish Court Administration
The Danish Court Administration plays a more limited role with regard to the use of AI within the judicial system.

For businesses, this means that appropriate oversight may depend on the AI system’s use, data processing, risk level, and organizational context.

Foranalyse – AI Act

Formålet med en AI Act-foranalyse er at skabe overblik over, hvordan organisationen udvikler, leverer eller anvender AI-systemer, og hvilke krav der gælder for de enkelte systemer. Analysen identificerer forskellen mellem organisationens nuværende praksis og de relevante krav i AI Act.
Kravene afhænger blandt andet af organisationens rolle, AI-systemernes anvendelse og deres risikoklassifikation. Foranalysen tilpasses derfor organisationens konkrete AI-anvendelse og tager udgangspunkt i følgende områder:

1. Kortlægning af AI-systemer

Der foretages en kortlægning af, hvor og hvordan AI anvendes i organisationen. Dette omfatter blandt andet AI-systemernes formål, anvendelsesområder, leverandører, datagrundlag, integrationer og betydning for organisationens processer, produkter og beslutninger.
Kortlægningen danner grundlag for at vurdere, hvilke AI-systemer der er omfattet af AI Act, og hvilke systemer der kræver særlig opmærksomhed.

2. Roller og ansvar efter AI Act

Der foretages en vurdering af organisationens rolle i relation til de enkelte AI-systemer. Organisationen kan blandt andet være udbyder, idriftsætter, importør eller distributør.
Rollen har betydning for, hvilke forpligtelser organisationen er underlagt. Analysen omfatter derfor også ansvarsfordeling mellem organisationen, leverandører og øvrige samarbejdspartnere.

3. Risikoklassifikation

AI-systemerne vurderes i forhold til AI Acts risikobaserede tilgang. Dette omfatter identifikation af eventuelle forbudte AI-praksisser, højrisiko-AI-systemer og systemer, der er omfattet af særlige transparenskrav.

4. AI-governance og ansvarsfordeling

Der vurderes, om organisationen har etableret en klar struktur for styring af AI. Analysen omfatter blandt andet politikker, godkendelsesprocesser, roller, ansvar, ledelsesrapportering og løbende kontrol med AI-systemer.

5. Risikostyring og kontrolforanstaltninger

Der foretages en vurdering af organisationens processer for identifikation, vurdering og håndtering af risici ved AI-systemer. Dette omfatter blandt andet kontrol med utilsigtede resultater, bias, fejl, misbrug, informationssikkerhed og afhængighed af eksterne leverandører.
For højrisiko-AI vurderes det desuden, om risikostyringen er systematisk, dokumenteret og dækkende gennem hele AI-systemets livscyklus.

6. Datastyring og datakvalitet

Der vurderes, hvordan organisationen styrer de data, der anvendes til udvikling, tilpasning, test og drift af AI-systemer. Analysen omfatter blandt andet datakvalitet, datakilder, relevans, repræsentativitet, adgangsstyring og behandling af personoplysninger.
Der vurderes også, om organisationen har tilstrækkeligt overblik over, hvilke oplysninger medarbejdere må dele med generative AI-løsninger.

7. Transparens og information til brugere

Der foretages en vurdering af, om organisationens anvendelse af AI lever op til relevante krav om transparens. Dette kan blandt andet omfatte information om, at en person interagerer med et AI-system, mærkning af AI-genereret eller manipuleret indhold samt information om systemets formål og begrænsninger.

8. Menneskeligt tilsyn og kontrol

Der vurderes, om organisationen har etableret passende menneskeligt tilsyn med AI-systemer, særligt hvor AI indgår i beslutninger med betydning for personer, kunder, medarbejdere eller andre interessenter.

9. Dokumentation, logning og sporbarhed

Der foretages en vurdering af, om organisationen har den nødvendige dokumentation for sine AI-systemer og deres anvendelse. Dette kan blandt andet omfatte systemoversigter, risikovurderinger, leverandørdokumentation, instruktioner, beslutningsgrundlag, logs og dokumentation for gennemførte kontroller.
Formålet er at vurdere, om organisationen kan dokumentere sin ansvarlige anvendelse af AI og efterlevelse af relevante krav.

10. AI-kompetencer og interne retningslinjer

Der vurderes, om medarbejdere og relevante nøglepersoner har tilstrækkelige kompetencer til at anvende og føre kontrol med AI-systemer. Analysen omfatter blandt andet awareness-træning, instruktioner og retningslinjer for sikker og ansvarlig brug af AI.

AI Act foranalyserapport

På baggrund af foranalysen modtager organisationen en rapport med en kortlægning af AI-systemer, relevante roller og krav samt identificerede risici og mangler.
Rapporten indeholder en prioriteret handlingsplan med anbefalinger til governance, risikostyring, dokumentation, kontrolforanstaltninger og kompetenceudvikling. Den giver dermed et klart beslutningsgrundlag for det videre arbejde med sikker, ansvarlig og dokumenteret anvendelse af AI.
Preliminary analysis starting at 10,000 DKK. Contact us