{"id":145464,"date":"2026-08-12T09:19:40","date_gmt":"2026-08-12T09:19:40","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=145464"},"modified":"2026-08-12T09:26:51","modified_gmt":"2026-08-12T09:26:51","slug":"sweden-artificial-intelligence","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/sweden-artificial-intelligence\/","title":{"rendered":"Sweden: Artificial Intelligence"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-145464","comparative_guide","type-comparative_guide","status-publish","hentry","guides-artificial-intelligence","jurisdictions-sweden"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Glimstedt<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2021\/03\/GLIM_horizontal_RGB.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Glimstedt<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2021\/03\/GLIM_horizontal_RGB.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of Artificial Intelligence laws and regulations applicable in Sweden<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What is the legal definition of \u201cartificial intelligence\u201d in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The definition of an AI system under Swedish law originates from the EU AI Regulation ((EU) 2024\/1689), which is an EU regulation and is therefore directly applicable as law in all member states, including Sweden.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Government Offices of Sweden presented a national strategy for AI in 2026 titled \u201cSveriges AI-strategi\u201d, translated into English as \u201cSweden\u2019s AI-strategy\u201d. The primary aim of the strategy is to ensure that Sweden becomes a leader in harnessing the opportunities of AI for Swedish welfare and competitiveness. To achieve this ambitious goal, the key elements of Sweden\u2019s national AI strategy include:<\/p>\n<p><strong>&#8211; Top-10 ambition.<\/strong> Sweden aims to become one of the ten leading AI nations in the world, leveraging its strong starting position with high digital maturity, world-leading research in machine learning and language models, and access to fossil-free energy and competitive digital infrastructure.<\/p>\n<p><strong>&#8211; AI for public benefit.<\/strong> AI should be used across both the private and public sectors to drive societal benefit, sustainable development, competitiveness, and innovation, while data, information, and AI are managed efficiently, responsibly, and securely.<\/p>\n<p><strong>&#8211; World-leading public sector.<\/strong> The government&#8217;s ambition is for Sweden to be the best in the world at using AI in public administration \u2014 improving cost-efficiency, quality, and service while freeing up time for healthcare professionals, social workers, and teachers to focus on human interactions.<\/p>\n<p><strong>&#8211; Regulatory simplification and legal certainty.<\/strong> Rules governing AI shall be simple, predictable, technology-neutral, and fit for purpose. The government supports regulatory sandboxes and advocates at EU level for regulation that does not hamper innovation, including realistic implementation timelines and less burdensome guidelines.<\/p>\n<p><strong>&#8211; Data access and sharing.<\/strong> Access to high-quality, relevant data is recognized as critical. The strategy calls for improved data sharing within and between public authorities, secure and interoperable data environments, and active Swedish engagement in EU data initiatives such as the European Health Data Space (EHDS).<\/p>\n<p><strong>&#8211; Security and defence.<\/strong> AI is identified as a strategic resource for Sweden&#8217;s total defence, encompassing autonomous systems, AI-driven intelligence processing, and sensor analysis. The government also takes seriously the threats from AI-generated disinformation and the use of AI as a criminal tool.<\/p>\n<p><strong>&#8211; Human-centred and responsible AI.<\/strong> AI must be developed and used to strengthen democratic values, the rule of law, and personal integrity. Transparency, accountability, and active management of bias and discrimination risks are fundamental requirements, with EU and international ethical frameworks serving as guides.<\/p>\n<p><strong>&#8211; Digital infrastructure and computing capacity.<\/strong> Sweden aims to be Europe&#8217;s leader in climate-efficient and competitive computing capacity, including the establishment of an \u201cAI workshop\u201d (AI-verkstad) for the public sector by 2030 and participation in EU AI factory initiatives such as Mimer in Link\u00f6ping.<\/p>\n<p><strong>&#8211; Research, education, and competence.<\/strong> The strategy includes the establishment of AI excellence clusters at Swedish universities, national doctoral schools for AI, and integration of AI across all levels of education \u2014 from primary school to higher education and lifelong learning \u2014 to build both broad and specialised competence.<\/p>\n<p><strong>&#8211; Implementation and follow-up.<\/strong> The strategy is operationalised through a dedicated action plan with government assignments, legislative changes, cooperation forums, and targeted budget allocations. DIGG (Myndigheten f\u00f6r digital f\u00f6rvaltning) and PTS (Post- och telestyrelsen) are tasked with supporting implementation, and annual follow-up is conducted in conjunction with Sweden&#8217;s broader digitalisation strategy and OECD reviews.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be\/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sweden has not adopted a general national AI statute governing all use or development of AI. The main AI-specific framework is Regulation (EU) 2024\/1689 (the \u201cAI Act\u201d), which applies directly in Sweden according to its phased timetable. Sweden has also adopted specific legislation, not yet in force as of 15 June 2026, on the use of AI systems for real-time facial recognition and other real-time remote biometric identification in public places for law-enforcement purposes. The European Commission\u2019s independent High-Level Expert Group on Artificial Intelligence has issued Ethical Guidelines for Trustworthy AI that can be applied in Sweden, but those guidelines are voluntary and not legally binding.<\/p>\n<p>Several existing laws in Sweden may also apply to AI and the use of AI, for example the General Data Protection Regulation (the \u201cGDPR\u201d), the Tort Liability Act (SFS 1972:207, the \u201cTLA\u201d), the Product Liability Act (SFS 1992:18, the \u201cPLA\u201d), the Act on Copyright in Literary and Artistic Works (SFS 1960:729, the \u201cCA\u201d), the Discrimination Act (SFS 2008:567), the Security Protection Act (SFS 2018:585), sector-specific financial regulation and consumer protection legislation. The Swedish Parliament and Government have long aimed for technology-neutral laws. Nonetheless, there remains room for uncertainty when applying existing laws to AI and the use of AI, particularly in relation to liability, transparency, IP ownership and governance of autonomous systems.<\/p>\n<p>As in most other EU countries, difficulties arise in interpreting existing laws. For example, ensuring GDPR compliance while leveraging large datasets for AI can be challenging. Existing intellectual property laws do not clearly address the ownership of AI-generated works or inventions. Whether AI can be an inventor or creator, and how liability should be allocated for harm caused by AI systems, remains uncertain. Traditional concepts of liability may not be directly applicable to autonomous systems that make decisions without human intervention. There are also ethical and fairness aspects to consider. Ensuring that AI systems are fair, non-discriminatory and ethical is difficult within the current legal framework.<\/p>\n<p>In some cases, there is a statutory duty to supervise or control automated technology. For example, Chapter 8, section 23 of the Securities Market Act (2007:528) requires a securities institution that engages in algorithmic trading to have effective systems and risk controls, to ensure that its trading systems are resilient and have sufficient capacity, and to have arrangements that prevent erroneous orders or disorderly markets. Breaches may lead to supervisory intervention and, depending on the circumstances, issues under market abuse rules, but the requirement does not mean that the offence of market manipulation is automatically committed whenever the provision is breached.<\/p>\n<p>While not a law or binding legislative initiative, various sectors and authorities in Sweden are developing specific guidelines and standards for AI applications.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers\/clients?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are currently no Swedish rules of general application that impose AI-specific transparency, explainability or audit obligations outside the EU framework. The main requirements arise from the AI Act and, where personal data is processed, GDPR. Under the AI Act, deployers and providers will need to comply with transparency obligations for certain AI systems, including systems that interact directly with natural persons, generate or manipulate content, or constitute high-risk AI systems. High-risk systems will also be subject to documentation, logging, record-keeping and conformity assessment requirements. These obligations will apply directly in Sweden according to the AI Act\u2019s phased timetable.<\/p>\n<p>Under the GDPR, transparency obligations may also require controllers to inform data subjects about the use of personal data in AI systems, the purposes and legal basis for the processing, and, in the case of automated individual decision-making with legal or similarly significant effects, meaningful information about the logic involved and the significance and envisaged consequences of the processing. IMY\u2019s guidance emphasises that using an AI model merely as decision support will not normally amount to automated individual decision-making if a natural person makes the actual decision. However, the human review must be genuine and not a purely formal step.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no general Swedish statutory requirement that all AI systems must include human oversight or a human-in-the-loop function. However, the AI Act will require high-risk AI systems to be designed and developed so that they can be effectively overseen by natural persons during use. The purpose is to prevent or minimise risks to health, safety and fundamental rights, including risks arising from automation bias or over-reliance on system outputs.<\/p>\n<p>Under Swedish law, similar expectations may arise indirectly from sector-specific and general duties of care. For example, securities institutions conducting algorithmic trading must have effective systems and risk controls, ensure that trading systems are tested and properly monitored, and document the measures taken so that Finansinspektionen can supervise compliance. In employment, credit, healthcare and public-sector contexts, human oversight may also be necessary to comply with GDPR, administrative-law principles, discrimination law, professional duties and internal governance requirements. As a matter of best practice, organisations deploying AI should define when human intervention is required, ensure that human reviewers have adequate competence and authority, and document the review process.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no Swedish AI-specific rules that comprehensively regulate algorithmic bias, discrimination or fairness. These issues are instead addressed through the AI Act, GDPR, the Swedish Discrimination Act (SFS 2008:567), sector-specific regulation and general principles of equal treatment and objectivity in public administration. The AI Act is particularly relevant for high-risk AI systems, including certain systems used in employment, education, access to essential services, law enforcement and migration. Such systems will be subject to requirements concerning risk management, data governance, technical documentation, transparency, human oversight, accuracy, robustness and cybersecurity.<\/p>\n<p>Where AI systems process personal data, GDPR principles such as lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy and accountability are central. Bias may also arise if training data contains personal data that is inaccurate, unrepresentative or unlawfully processed, or if special category data is used without a valid exception. In employment and recruitment, AI tools must also comply with the Discrimination Act, which prohibits direct and indirect discrimination on protected grounds such as sex, ethnicity, disability, age and religion or other belief. An employer or service provider may therefore be exposed to liability if an AI system produces discriminatory effects, even where the discriminatory outcome was not intended.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no specific rules that apply to defective AI. For liability to be imposed according to TLA, it is required that the natural or legal persons behind the AI have been negligent and that there is adequate causation between the negligent act and the damage. It remains uncertain how high the standards for negligence and adequate causation are, and whether liability can be imposed in cases where AI causes personal or property damage. Determining adequate causation in incidents involving AI is particularly challenging, given the complexity and autonomous decision-making capabilities of these systems.<\/p>\n<p>Defective AI systems could be subject to claims under the PLA, the CA, the Product Safety Act (SFS 2022:1254) and the Swedish Consumer Sales Act (SFS 2022:260), depending on the nature of the system, the claimant and the damage suffered.<\/p>\n<p>When AI has caused damage, it can be hard to identify if it is the developer, the deployer or the user who should or could be held responsible for the damage. The starting point is that the TLA requires the liable party to have acted intentionally or negligently for damages to be awarded. If AI is considered a part of a product, in accordance with PLA, and there is a fault in the AI that causes harm, the product manufacturer may be held liable for the damage, under the PLA.<\/p>\n<p>If an AI system is sold to consumers, the Swedish Consumer Sales Act (SFS 2022:260) could be applicable. Goods, including digital content, digital services and goods with digital elements, sold to consumers must meet expected standards of safety and functionality. Determining who ultimately bears responsibility may be difficult; however, the Consumer Sales Act entitles the consumer to claim damages from the retailer that supplied the goods, and the retailer may in turn seek recourse from the manufacturer or other responsible party.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What cybersecurity obligations apply to AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Cybersecurity obligations for AI systems depend on the sector, the type of AI system and the data processed. Under GDPR, controllers and processors must implement appropriate technical and organisational security measures where AI systems process personal data. This may include access controls, logging, encryption, testing, incident management, data minimisation, resilience measures and procedures for restoring availability and access to personal data after an incident. If an AI system is used to process sensitive or confidential information, security requirements should also be addressed contractually with suppliers and integrated into internal governance, risk management and procurement processes.<\/p>\n<p>The AI Act will also impose cybersecurity, robustness and accuracy requirements for high-risk AI systems. In addition, Swedish organisations may be subject to sector-specific cybersecurity rules, including the Security Protection Act (SFS 2018:585) for security-sensitive activities, financial-sector rules such as DORA, the Cybersecurity Act (SFS 2025:1506) implementing the NIS2 framework and the EU Cybersecurity Act. For financial markets, the Securities Market Act requires firms engaged in algorithmic trading to maintain effective systems and risk controls, ensure resilience and sufficient capacity, prevent erroneous orders or disorderly markets, and keep the systems appropriately tested and monitored.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Is the use of artificial intelligence insured and\/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Considering the technology-neutral approach generally taken in Swedish legislation and regulation, and provided no specific exclusions apply, risks associated with the use of AI should in principle be insurable. For example, risks related to data breaches, cyberattacks and other digital threats may be covered by cyber insurance, although coverage will depend on the policy wording, exclusions and underwriting assessment. As AI systems often handle sensitive or confidential data, cyber insurance may be relevant. For companies that develop and sell AI products, product liability insurance may cover damages caused by AI systems, such as malfunctioning autonomous machines or defective AI software, subject to the terms of the policy.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No. Since AI is not a natural person and is not recognised as a legal inventor in Sweden, AI cannot be named as an inventor in a patent application.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Do images or works generated by and\/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>If an image has been generated entirely by AI, no one benefits from copyright protection in the AI-generated output as such according to the Swedish Intellectual Property Office. The right to use images generated by AI may, however, be regulated in the AI system\u2019s terms of use.<\/p>\n<p>The fundamental principle of copyright in Sweden is that it can only be attributed to a human being. Copyright is based on the premise that the creator has contributed to the work through free and creative choices. Even though AI-generated images are produced based on human instructions, the outcome is unpredictable. Under current legislation, AI-generated images would in most cases not be eligible for copyright protection. For AI-generated material to be protected, the human creator must use the generative AI system as a tool or aid as part of a larger creative process. If it is possible to process AI-generated material to create a predictable result based on free and creative choices by the creator such material may be protected by copyright.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The AI Act constitutes a series of binding rules and guidelines for AI-driven hiring, performance assessment, and employee monitoring. The formal classification of AI systems for recruitment, work management, and monitoring as high-risk systems is a central regulation. This includes, for instance, systems used to monitor and evaluate the performance and behavior of individuals in work-related relationships. This classification activates the entire set of strict requirements and obligations in the regulation regarding high-risk AI systems, which shall most probably be implemented by 2 December 2027 (stand-alone AI-systems) and 2 August 2028 (integrated AI-systems) in accordance with Omnibus VII.<\/p>\n<p>Key issues may differ from business to business. Generally, however, organizations should consider GDPR compliance, including whether personal data is processed on a valid legal basis, whether employees have received sufficient information, and whether confidential information is adequately protected. AI systems may also raise ethical issues concerning fairness and bias. Algorithms may discriminate against certain groups if they are not properly designed, trained, tested and monitored. Ensuring fairness and transparency in AI-supported decision-making is therefore crucial.<\/p>\n<p>AI systems must also be accurate and reliable, according to the GDPR. Ensuring that AI models are properly trained, validated, and tested is critical to avoid errors that could potentially impact business operations or decision-making.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main privacy\/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The main privacy and data protection issues arise from the fact that AI development and use often involve large volumes of data, including training data, prompts, user inputs, logs and model outputs. If personal data is processed, GDPR applies in parallel with the AI Act. Key issues include identifying a valid legal basis, defining and limiting purposes, ensuring transparency towards data subjects, complying with the principles of data minimisation and storage limitation, managing data subject rights, preventing unauthorised use of special category data, and ensuring appropriate security. Particular attention is required where data is scraped from public sources, reused for model training or fine-tuning, or processed for purposes that differ from the original collection purpose.<\/p>\n<p>IMY has issued guidance on GDPR and AI, including guidance on generative AI, automated decision-making and responsibility roles when AI applications are fine-tuned or used. The main takeaways are that organisations must determine whether they act as controllers, processors or joint controllers; carry out data protection impact assessments where processing is likely to result in high risk; implement privacy by design and by default; document the reasoning behind legal bases and risk assessments; and ensure that individuals receive understandable information about AI-related processing. In cases involving automated individual decision-making with legal or similarly significant effects, additional safeguards apply, including the right to obtain human intervention, express a view and contest the decision.<\/p>\n<p>On January 21, 2025, the Swedish Digital Governance Agency (Digg) and the Swedish Privacy Protection Agency (IMY) launched guidelines to promote the use of generative AI in public administration. The aim is to increase the security and ability to use generative AI in a safe, ethical and effective way.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>On 1 January 2023, changes were introduced to the CA to implement the text and data mining exceptions in Directive (EU) 2019\/790, including Article 4 and the separate exception for scientific research in Article 3. Training an AI tool may involve text and data mining, as it typically uses automated techniques to analyse text and data in digital form in order to generate information. However, the legality of AI training based on scraped data has not yet been tested by Swedish courts. The relevant Swedish provisions are set out in Chapter 2, sections 15a-15c of the CA. A person with lawful access to a work may make copies of the work for text and data mining purposes, but the exception permits copying only and does not permit making the copies available to the public. Copies produced under the exception may not be retained for longer than necessary for the purpose, and may not be used for other purposes. Importantly, the exception does not apply where the rightsholder has appropriately reserved the right to prohibit text and data mining, for example through machine-readable opt-out mechanisms or explicit notices on a website.<\/p>\n<p>Data scraping is a violation of the CA if the website is protected by copyright and the scraped work is copied or made available to the public. The overall appearance of a website can be protected by copyright according to the CA. Since copyright arises automatically and does not require prior registration, it is difficult to know in advance if certain content on a website is protected by copyright or not. The scraping itself often constitutes unauthorized copying if the scraped material is protected by copyright.<\/p>\n<p>The exception in Chapter 2 Section 15a-15c of the CA will have implications for competition, and could potentially be interpreted restrictively, placing Sweden and the EU at a competitive disadvantage in relation to other countries&#8217; legislation on scraping.<\/p>\n<p>Personal data processing occurs when a website is scraped and the entity initiating the scraping becomes responsible for that processing, typically as a controller. Data scraping that involves personal data must comply with GDPR principles, such as lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. In addition to identifying a legal basis for the processing, the controller must observe the rights of the data subject, including the rights of access, rectification, erasure and objection.<\/p>\n<p>There are no major Swedish court precedents specifically on AI training and scraping, but the legal framework is strict, especially regarding personal data and copyrighted content.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">To what extent is the prohibition of data scraping in the terms of use of a website enforceable?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>By using a website, the visitor may be obliged to accept the terms and conditions that apply to the website. For the terms and conditions to be legally binding, they must be clearly visible to the visitor. It is advisable that some form of documentation that the visitor has had access to the terms and conditions is available, for example by clearly requiring acceptance of the terms and conditions. If the terms and conditions include a provision prohibiting data scraping, the data scraping is unauthorized, even if the scraped data is not protected by copyright. Data scraping in violation of the terms and conditions thus constitutes a breach of contract that may entitle the website owner to claim damages.<\/p>\n<p>If the prohibition is only in a link in the footer or in a text file (or similar), it is unlikely to be enforceable unless the website can prove the user had clear notice and accepted the terms.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is currently no single Swedish authority with general responsibility for supervising all use and development of AI. Sectoral authorities supervise AI-related issues within their existing mandates, for example IMY for data protection, Finansinspektionen for regulated financial activities and the Swedish Medical Products Agency for medical devices. In June 2026, the Government designated IMY (the Swedish Authority for Privacy Protection) as the market surveillance authority for the AI Act for several categories of AI systems. IMY\u2019s mandate as market surveillance authority covers, among other things, high-risk AI systems used in law enforcement, border management, administration of justice, democratic processes, creditworthiness assessment and credit scoring. Post- och telestyrelsen (PTS) and Finansinspektionen have also been designated as competent authorities for AI systems within their respective sectors. IMY has also been given a specific market surveillance role, from 1 July 2026, for the use of AI systems for real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes. IMY will also participate in the regulatory sandbox for AI, providing guidance on data protection.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Many businesses use AI to some extent, and adoption is likely to continue increasing as comprehensive AI tools are integrated into commonly used office suites, such as Microsoft 365 Copilot and Gemini for Google Workspace. As AI systems are increasingly customised for specific industries and individual companies, wider adoption is likely to accelerate further.<\/p>\n<p>It is hard to determine which sectors have seen the most rapid adoption of AI technologies, but adoption can be seen in several sectors, such as healthcare, automotive, manufacturing, telecommunications, energy, public administration, financial services and legal services.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is artificial intelligence used in the legal sector, by lawyers and\/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Examples include M&amp;A processes, where AI can assist with processing large volumes of data; legal research, where AI can help sift through legal documents and case law; and document review, where AI can identify key information, omissions and potential drafting revisions. In addition, agentic workflows are becoming more common.<\/p>\n<p>Companies offering legal services in the form of search engines are developing AI tools to facilitate this type of investigative work.<\/p>\n<p>The main regulatory concerns revolve around data protection and privacy, as well as ethical and professional standards under the Swedish Bar Association.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p><strong>Challenges:<\/strong><\/p>\n<ol>\n<li>Regulatory compliance. Ensuring that AI applications comply with existing legal and ethical standards is a significant challenge. Lawyers must navigate the complexities of integrating AI into their practices while adhering to regulatory requirements and ethical considerations.<\/li>\n<li>Liability and accountability. There will be legal questions concerning liability for AI-driven decisions.<\/li>\n<li>Privacy and security. It is imperative to safeguard client and company information in connection with the use of AI.<\/li>\n<li>Changing landscape for lawyers. Over time, certain questions and matters may not be referred to lawyers, but instead in many cases be handled with the use of AI services.<\/li>\n<li>Understanding the technology. The lack of transparency in many AI systems can, in combination with the increasing complexity of the technology, make it difficult for lawyers to understand or challenge AI-driven decisions or outcomes.<\/li>\n<\/ol>\n<p><strong>Opportunities:<\/strong><\/p>\n<ol>\n<li>AI offers unparalleled opportunities for efficiency and innovation in the provision of legal services.<\/li>\n<li>Risk management. AI can be used to evaluate and manage risks associated with different legal strategies or client portfolios.<\/li>\n<li>Regulatory compliance. Although a challenge, AI can also help to improve regulatory compliance in many fields by ensuring compliance with complex regulatory frameworks, reducing the risk of non-compliance and associated penalties.<\/li>\n<li>New markets. The adoption of AI can create new opportunities for lawyers to offer innovative services, access new markets, and meet the evolving needs of clients in the digital age.<\/li>\n<li>Technology-enabled service delivery. AI can support new ways of delivering legal services, including scalable knowledge management, faster contract analysis and more tailored client-facing tools. Lawyers must nevertheless balance the use of AI with the need to maintain core legal skills and professional judgment.<\/li>\n<\/ol>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The most significant legal developments in the next 12 months are expected to relate to the continued implementation of the AI Act, including the operationalisation of the national supervisory framework. In June 2026, the Government designated IMY as the market surveillance authority for several categories of AI systems under the AI Act, including high-risk AI systems used in law enforcement, border management, administration of justice, democratic processes, creditworthiness assessment and credit scoring. Post- och telestyrelsen (PTS) and Finansinspektionen have also been designated as competent authorities within their respective sectors. These authorities will need to build capacity, issue guidance and establish enforcement practices. Sweden has also adopted legislation on real-time remote biometric identification for law-enforcement purposes, which entered into force on 1 July 2026. As AI use continues to increase, more case law and regulatory guidance can also be expected in areas such as liability, data protection, copyright infringement, employment and public-sector decision-making.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">4844<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/145464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=145464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}