Our Expert in Finland
No results available
Finland became one of the first EU Member States to activate national supervision powers under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) when the laws granting enforcement authority were approved on 22 December 2025 and took effect on 1 January 2026. For technology lawyers in Finland, and for every in-house counsel, CTO or product legal team whose AI systems touch the Finnish market, that date marks the start of concrete, enforceable obligations covering risk management, technical documentation, transparency and post-market monitoring.
This guide maps those obligations to the contract clauses, IP provisions and enforcement playbooks that SaaS and software providers need right now, filling the gap between high-level government announcements and the granular drafting work that commercial teams must complete in 2026.
Before diving into detail, here is the essential checklist for teams operating AI systems in or into Finland.
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies directly across all Member States. It establishes a risk-based classification system for AI, imposes graduated obligations on providers, deployers and distributors, and sets EU-wide deadlines for compliance. Finland implemented the national enforcement layer (The Act on on the Supervision of Certain Artificial Intelligence Systems) through Government Proposal HE 46/2025, which the President approved on 22 December 2025. The resulting laws, granting supervisory, investigatory and sanctioning powers to designated authorities, became effective on 1 January 2026.
Understanding the EU AI Act Finland timeline is essential for compliance planning. The Regulation phases in obligations across multiple deadlines, and Finland’s national measures run in parallel.
| Date | Measure | Practical effect |
|---|---|---|
| 1 Aug 2024 | AI Act enters into force (EU-wide) | Clock starts on all transitional periods; definitions and scope apply immediately for planning purposes. |
| 2 Feb 2025 | Prohibited AI practices ban applies | Systems using subliminal manipulation, social scoring or real-time biometric identification (with limited exceptions) must be withdrawn. |
| 2 Aug 2025 | GPAI obligations and governance provisions apply | Providers of general-purpose AI models must comply with transparency, documentation and systemic-risk rules. |
| 22 Dec 2025 | Finland approves HE 46/2025 (Stage 1) | National supervisory powers, authority designations and sanction mechanisms confirmed. |
| 1 Jan 2026 | Finnish enforcement powers effective | Traficom and sectoral authorities can investigate, request information, issue orders and impose fines. |
| 2 Aug 2026 | High-risk AI obligations apply (EU-wide) | Full conformity assessment, risk-management system and post-market monitoring requirements for high-risk AI systems. |
| By Aug 2027 | Stage 2 national measures (sandbox / register) | Finland’s AI sandbox operational rules and national AI system register expected to be finalised. |
Finland’s enforcement architecture distributes responsibilities across several bodies. Technology lawyers in Finland need to know which authority has jurisdiction over their client’s specific AI system.
The EU AI Act imposes distinct duties on providers (those who develop or place an AI system on the market) and deployers (those who use the system under their authority). For AI compliance in Finland, these regulatory obligations must be translated into enforceable contract terms. Failure to do so leaves both parties exposed: providers risk non-compliance fines, and deployers risk liability for misuse without contractual recourse.
The core obligations that reshape commercial agreements include:
The following ten actions should be embedded in every SaaS AI contract touching the Finnish market:
The following sample AI contract clause addresses core provider duties. It should be adapted to each transaction’s risk profile.
“Provider shall maintain a risk-management system in accordance with Article 9 of Regulation (EU) 2024/1689 throughout the term of this Agreement. Provider shall, upon reasonable request and no more than once per calendar year, make available to Deployer the technical documentation required under Article 11 and evidence of completed conformity assessment under Articles 40–49. Provider shall report any serious incident involving the System to the competent market surveillance authority and to Deployer within the timeframes prescribed by Article 73.”
Negotiation note: Deployers should push for the right to conduct independent audits rather than relying solely on provider self-certification. Providers should negotiate reasonable caps on audit frequency and require advance notice.
“Deployer shall use the System strictly in accordance with the instructions for use provided by the Provider and shall not modify, retrain or repurpose the System in a manner that alters its risk classification without Provider’s prior written consent. Deployer shall implement and maintain human-oversight measures as specified in the instructions for use. Deployer shall indemnify Provider against any claims, fines or losses arising from Deployer’s use of the System in breach of this clause or in breach of Regulation (EU) 2024/1689.”
Negotiation note: Deployers should carve out indemnity obligations for losses caused by defects in the system that exist prior to delivery or by provider’s own non-compliance with the AI Act.
AI liability and IP ownership present some of the most complex drafting challenges for technology lawyers in Finland. The AI Act does not directly harmonise intellectual property rules, but its transparency, documentation and data-governance requirements interact heavily with IP and data-protection obligations. Contracts must address several distinct risk areas.
| Clause area | Key risk | Drafting tip |
|---|---|---|
| Input ownership | Data fed into the AI system may include proprietary or personal data; unclear rights create infringement exposure. | Require the data-supplying party to warrant that it holds all necessary rights, licences and consents for the data used. |
| Output ownership | AI-generated outputs may not qualify for copyright protection under Finnish law, leaving ownership ambiguous. | Assign all rights in outputs contractually; include a licence-back for provider analytics if needed. |
| Derivative works / fine-tuning | Fine-tuning a model with deployer data creates new IP that both parties may claim. | Define ownership of fine-tuned model weights and derivatives expressly; consider joint-ownership or exclusive-licence structures. |
| Training-data provenance | Training data sourced without proper licences creates downstream infringement risk for all parties. | Include a training-data warranty and require the provider to maintain a provenance register accessible to the deployer. |
| Third-party IP indemnity | If the AI system’s outputs infringe a third party’s IP, both provider and deployer may face claims. | Allocate indemnity obligations clearly, typically provider indemnifies for system-level infringement; deployer indemnifies for use-level infringement. |
| Limitation of liability | Standard liability caps may be inadequate for AI Act fines (up to €35 million or 7% of global turnover). | Carve AI Act fines out of general liability caps, or set a separate, higher cap for regulatory liabilities. |
Insurance is an increasingly important element in AI liability allocation. Industry observers expect cyber-liability and professional-indemnity policies to evolve rapidly through 2026–2027 as insurers adjust to the AI Act’s penalty framework. Contracts should require minimum coverage levels and mandate that the provider names the deployer as an additional insured where feasible.
The intersection of GDPR and AI creates overlapping obligations for any AI system that processes personal data. The European AI Office’s Service Desk guidance confirms that the AI Act does not replace or modify GDPR obligations, it adds to them. In practice, this means technology lawyers in Finland must ensure contracts address both regulatory frameworks simultaneously.
With AI enforcement powers now active, Finnish authorities can conduct investigations, request access to source code and training data, order modifications or withdrawals of non-compliant systems, and impose administrative fines. The AI Act sets maximum penalties at the EU level: up to €35 million or 7% of total worldwide annual turnover for prohibited-practice violations, and up to €15 million or 3% of turnover for other infringements.
Finland’s implementing law establishes the procedural framework for how these powers are exercised nationally. Key tactical considerations for legal teams responding to an investigation include:
When a market surveillance authority opens an inquiry, or when an internal audit reveals a potential compliance gap, the following evidence-preservation steps should be executed immediately:
Sample preservation clause: “Each party shall retain all automatically generated logs, training-data provenance records and output samples relating to the System for a minimum period of [five] years following termination of this Agreement, or such longer period as required by applicable law. Upon receipt of a preservation notice from the other party or any competent authority, the receiving party shall immediately suspend all routine deletion processes affecting such records.”
Finland’s AI sandbox programme, coordinated by Traficom, is designed to allow providers to test AI systems under regulatory supervision before full market deployment. Stage 2 national legislation governing sandbox operations is expected by August 2027, but early indications suggest Traficom is already developing operational frameworks and accepting expressions of interest from potential participants.
Sandbox participation offers several advantages relevant to AI compliance in Finland: direct regulator feedback on classification and conformity questions, a controlled environment for testing high-risk systems, and documented evidence of good-faith compliance efforts that can mitigate enforcement risk. Contracts involving AI systems that may enter a sandbox should include:
The following ten-step plan provides a structured approach for product legal teams to achieve baseline AI compliance in Finland within 90 days.
| Entity type | Key reporting / surveillance obligations under AI Act | Practical contractual / operational implication |
|---|---|---|
| Provider (developer, placer on market) | Conformity assessment, technical documentation, post-market monitoring, incident reporting, EU-wide obligations for GPAI | Include compliance warranties, access to technical docs, audit and remediation obligations, allocation of costs for recalls |
| Deployer (customer / operator) | Deployment-level obligations (use restrictions, user info, logging), cooperation with supervisors | Use/deploy warranties, indemnities for misuse, obligations to notify provider and authorities on incidents |
| Distributor / reseller | Ensure product placed meets obligations, cooperate with market surveillance | Right to require provider assurances, pass-through compliance clauses |
Finland’s activation of national AI Act enforcement powers on 1 January 2026 is not a future event, it is the present operating reality. Every SaaS licence, software supply agreement and AI deployment contract touching the Finnish market must now reflect the obligations set out in Regulation (EU) 2024/1689 and the national implementing law. The practical steps are clear: classify systems, update contracts with the compliance warranties and model clauses outlined in this guide, preserve evidence from day one, and prepare for market surveillance engagement with Traficom and the relevant sectoral authorities.
The likely practical effect of Finland’s early enforcement posture will be to set precedents that influence AI compliance standards across the broader Nordic and EU market. Organisations that invest in robust contract drafting and compliance infrastructure now will be better positioned to manage enforcement risk, participate in sandbox programmes and maintain competitive advantage as the regulatory framework matures through 2027 and beyond.
For specialist advice on this topic, contact Mikko Junno at Hedman Partners, a member of the Global Law Experts network.
posted 2 hours ago
posted 6 hours ago
posted 7 hours ago
posted 8 hours ago
posted 8 hours ago
posted 8 hours ago
posted 9 hours ago
posted 9 hours ago
posted 10 hours ago
posted 10 hours ago
posted 10 hours ago
posted 11 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message