EU AI Act in Finland: Public-Sector AI, Authorities, and Deadlines
How the EU AI Act applies in Finland: directly applicable, EU-wide deadlines, Article 70 authorities, and why public-sector AI widens the high-risk frame.
Wider, not lighter. Finland's long public-sector AI and population-scale AI-literacy track record does not earn it an easier ride under the EU AI Act — it widens the high-risk frame, because the more an administration leans on AI in benefits, justice, and public services, the larger its Annex III surface. The Act applies in Finland directly, with no Finnish statute needed to create the obligations; the Finnish-specific questions are which obligations are already live and which national authority will operationalise them. This guide answers both for providers, deployers, importers, and distributors operating in Finland.
How the EU AI Act Applies in Finland — Directly, With No Finnish Transposition
Regulation (EU) 2024/1689 is a Regulation, not a Directive. Under Article 288 TFEU a Regulation applies directly in every Member State, so it creates obligations in Finland with no Finnish implementing statute needed to make the substantive rules binding. There is no waiting for a national "adoption" step.
What Finland must supply is narrower than re-legislating. Under the Regulation, Finland designates national competent authorities and confers domestic enforcement powers — that is machinery, not substantive rules. Whether you build, deploy, import, or distribute AI, the substance comes from the Regulation; the national measure decides who investigates and fines.
The obligations are already in force, regardless of national steps. Article 5 prohibited practices and Article 4 AI literacy have applied since 2 February 2025. General-purpose AI model duties under Chapter V (Articles 51–55) have applied since 2 August 2025. A Finnish firm waiting for a national law before acting on those is already exposed.
Finland's distinctive position is its public-sector AI leadership and its national AI-literacy efforts at population scale. That is the backdrop — not a different rulebook. The deadlines, the penalty tiers, and the designation mechanism are identical to every other Member State.
The Article 70 Designation Mechanism in Finland — and What to Verify
Article 70 requires each Member State to designate at least one notifying authority and at least one market surveillance authority (MSA) as national competent authorities, and to communicate them to the Commission. The milestone was 2 August 2025. The mechanism is uniform across the Union; what differs between states is only which national body each nominates.
Finland has established market-surveillance, data-protection, and digital-government bodies that could host the mandate. Describe it that way — in mechanism terms — and verify the rest.
Verify before you rely on it. This guide does not name a specific Finnish competent authority or a specific Finnish implementing act, because the exact designation should be confirmed against Finland's official notification to the Commission before you treat it as your enforcement contact. Treat any single named authority you read elsewhere as something to check, not a settled fact.
Once Finnish enforcement powers are in force, Article 74 governs market surveillance: the designated MSA can audit Annex IV technical documentation, review conformity and Article 72 post-market monitoring, order corrective action, and impose Article 99 fines. Until those domestic powers exist, the national fining route is incomplete — but the Article 5 prohibition applies regardless.
GPAI is carved out of national supervision. General-purpose AI model providers are supervised directly by the EU AI Office in Brussels, with Commission fines under Article 101. A Finnish single point of contact only coordinates; it does not supervise the model itself.
Finland's Public-AI Track Record and Why It Raises the Stakes
Finland has been an early mover on public-sector AI and on AI literacy at population scale. That is the factual backdrop, stated without attributing specific live deployments to named Finnish agencies.
A mature public-AI posture means more public-sector systems are candidates for the high-risk frame, not fewer. Annex III point 5(a) covers AI evaluating eligibility for essential public benefits and services; Annex III point 8 covers administration of justice and democratic processes. The more an administration leans on AI in those areas, the larger its high-risk surface.
That exposure connects to Article 27: the Fundamental Rights Impact Assessment (FRIA) is mandatory for public bodies and bodies governed by public law deploying Annex III high-risk systems, and for private deployers in the creditworthiness (Annex III point 5(b)) and life-and-health-insurance (Annex III point 5(c)) categories. A public body cannot skip the FRIA.
Finland's strong AI-literacy culture maps directly onto Article 4 AI literacy, in force since 2 February 2025 — a head start on one obligation, not the whole stack. It does not satisfy high-risk documentation, conformity, or logging duties.
Roles follow use. A Finnish agency or municipality running an eligibility-scoring tool is a deployer under Article 26; building or substantially modifying it can convert that body into a provider under Article 25, with the full provider stack attached.
How the EU AI Act Stacks With the GDPR in Finland
The GDPR and the EU AI Act run in parallel for any AI system processing personal data — which covers most Annex III high-risk systems. The Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) continues to enforce the GDPR, unchanged by the AI Act. The obligations stack; neither displaces the other.
The most practical overlap is between the GDPR Article 35 DPIA and the EU AI Act Article 27 FRIA. Both are mandatory pre-deployment assessments of fundamental-rights risk, and Article 27(4) expressly allows the FRIA to build on an existing DPIA where their scope overlaps. You do the fundamental-rights analysis once, then extend it.
Record-keeping interacts too. Article 12 automatic logging duties for high-risk systems sit alongside GDPR Article 22 transparency and human-review duties on automated decision-making. A Finnish deployer of an eligibility tool carries both at once.
The practical sequencing for Finnish deployers: build the factual base once — system description, data sources, categories of affected persons — and reuse it across DPIA and FRIA. Expect both the data-protection authority and the designated AI Act authority to take an interest wherever high-risk and personal data coincide.
The EU AI Act Timeline as It Applies in Finland
The dates are EU-wide and identical in every Member State. There are no Finland-specific deadlines.
| Date | What applies |
|---|---|
| 2 February 2025 | Article 5 prohibitions and Article 4 AI literacy — in force now |
| 2 August 2025 | GPAI duties (Chapter V, Articles 51–55), governance / AI Office, Article 99 penalties, and the Article 70 authority-communication milestone |
| 2 August 2026 | General application, including Article 50 transparency |
| 2 December 2026 | Article 50 content-marking duties for synthetic / AI-generated content, for generative systems already on the market (Digital Omnibus) |
| 2 December 2027 | Stand-alone high-risk Annex III systems under Article 6(2) (Digital Omnibus) |
| 2 August 2028 | High-risk AI as a safety component of Annex I regulated products — Article 6(1) (Digital Omnibus) |
The two caveats that matter for Finnish planning
Caveat one — the high-risk dates are settled. The Digital Omnibus, adopted in June 2026 (European Parliament 16 June, Council 29 June), moves stand-alone Annex III high-risk to 2 December 2027 and Annex I product-embedded (Article 6(1)) systems to 2 August 2028, and adds a content-marking duty plus a CSAM/nudifier prohibition. It enters into force on Official Journal publication, expected July 2026. Plan against 2 December 2027.
Caveat two — not everything is delayed. Article 5 prohibitions, Article 4 literacy, GPAI duties, and Article 50 transparency are unaffected by the deferral. The "stop the clock" framing was rejected. Treating the Omnibus as a blanket reprieve is a trap.
Penalties Finnish Companies Face Under Article 99
Article 99 sets three tiers, each the higher of a fixed sum or a percentage of total worldwide annual turnover:
- €35 million or 7% of total worldwide annual turnover, whichever is higher — Article 99(3), for breaches of the Article 5 prohibited practices.
- €15 million or 3% — Article 99(4), for non-compliance with most other obligations: high-risk requirements (Articles 9–15), provider duties (Article 16), deployer duties (Article 26), and Article 50 transparency.
- €7.5 million or 1% — Article 99(5), for supplying incorrect, incomplete, or misleading information to notified bodies or competent authorities.
The third tier is 1%, not 1.5%. There is no 1.5% tier in the Regulation. For SMEs and start-ups, Article 99(6) caps the fine at the lower of the fixed amount or the percentage — the reverse of the general "whichever is higher" rule.
National enforcement depends on the designated Finnish authority having domestic powers in force; the Article 5 prohibition applies regardless. GPAI fines are a separate instrument: up to €15 million or 3%, imposed by the Commission under Article 101.
Worked Example: A 200-Person Finnish AI Company
Meet Suomenpilvi — an illustrative, fictional Helsinki-based public-sector software vendor, roughly 200 employees and about €30 million turnover. It is invented to show the analysis, not a real company.
Product line one is a stand-alone AI tool that scores citizen eligibility for a public benefit on behalf of a municipal client — Annex III point 5(a), essential public services. It takes the full high-risk stack directly: Articles 9–15, provider duties under Article 16 (or deployer duties under Article 26 for the municipality), and conformity assessment under Article 43 — unless the Article 6(3) procedural-task filter removes it because it poses no significant risk to health, safety, or fundamental rights.
Product line two is an AI recruitment-screening feature for Suomenpilvi's own hiring — Annex III point 4(a), employment. Same outcome: the full high-risk stack directly, unless Article 6(3) applies.
Role analysis. As the builder of both, Suomenpilvi is a provider under Article 16. Had it merely licensed and operated a third-party tool, it would be a deployer under Article 26 — but fine-tuning, rebranding, or changing the intended purpose to a high-risk use could trigger Article 25 provider status, including re-running conformity assessment.
Public-sector angle. Because the eligibility tool is deployed by a public body, the municipal client must complete an Article 27 FRIA before deployment, and Suomenpilvi's documentation feeds it. Article 27(4) lets that FRIA build on the client's GDPR Article 35 DPIA.
Timeline for Suomenpilvi. Prohibitions and literacy already apply; GPAI is irrelevant unless it trains a general-purpose model. Its high-risk obligations target the 2 August 2026 statute — plan against it while tracking the proposed 2 December 2027 deferral. Action set: AI inventory, Article 6(3) filter, FRIA support, DPIA/FRIA coordination, and an Annex IV documentation pack.
Finland-Specific Compliance Considerations
Public-sector FRIA weight. Given Finland's public-AI maturity, Article 27 FRIAs for Annex III point 5(a) eligibility tools and point 8 justice-and-democracy systems are a likely early focus. Public-sector compliance is high-visibility and sets the standard others follow.
Prohibited practices to screen now. Article 5(1)(f) bans emotion recognition in workplace and education; Article 5(1)(g) bans biometric categorisation inferring sensitive attributes; Article 5(1)(a) covers subliminal and manipulative techniques. All have been enforceable since 2 February 2025 and are directly relevant to Finnish edtech and HR-tech.
Cross-border reach. Finland is an EU Member State, so the Act applies directly with no EEA-incorporation step. Separately, Article 2 extraterritorial reach catches any provider or deployer placing AI on the EU market regardless of establishment — so a non-EU vendor selling into Finland is caught.
Article 25 role-shift risk for Finnish customisers. Substantially modifying a high-risk system, changing its intended purpose to a high-risk use, or placing it under your own name makes you a provider with the full Article 16 stack, including re-running conformity assessment. Finnish firms that heavily customise vendor AI should run the Article 25 analysis before assuming the lighter deployer role.
Regulatory sandbox. Articles 57–59 require at least one AI regulatory sandbox per Member State by 2 August 2026, with priority and fee-free access for SMEs and start-ups under Article 58. Finnish firms with hard-to-classify systems should track it once stood up.
Importer and distributor duties. Article 23 (importer) and Article 24 (distributor) apply to Finnish firms importing or reselling third-party high-risk AI.
How Confir Helps Finnish Companies
Finnish compliance teams face a documentation-heavy obligation set: Article 9 risk management, Annex IV technical documentation, Article 27 FRIAs, Article 43 conformity preparation, and Article 72 post-market monitoring.
Confir is an EU-hosted compliance tool. Its classification engine is deterministic and rule-based — no model inference, no hallucination — encoding Articles 5 and 6 with Annex III logic in explicit rules, so the same intake always produces the same finding with a human-readable explanation of which rule fired. That makes the output audit-defensible.
Confir generates the Annex IV technical documentation pack, the Article 47 / Annex V Declaration of Conformity, and the Article 27 FRIA. The assessment spans four structured areas: risk classification (AIRC), data and technical robustness (AITR), transparency and human oversight (AITO), and governance and post-market monitoring (AIGM). GPAI workflow support is partial and on the roadmap, stated plainly — not a completed capability.
What Finnish Companies Should Do Now
Immediately. Audit for Article 5 prohibited practices — emotion recognition in work or education, sensitive-attribute biometric categorisation, manipulative techniques, untargeted facial-image scraping, social scoring. These have been in force since 2 February 2025. Restructure or stop non-compliant systems.
Before 2 August 2026. Meet Article 50 transparency — chatbots disclose they are AI, deepfakes and synthetic media are disclosed as artificially generated, and generative outputs are marked machine-readably. Content-marking duties for generative systems already on the market land 2 December 2026 under the Omnibus.
2026–2027 high-risk preparation. Build the AI inventory, apply the Article 6(3) filter, assign provider / deployer / importer / distributor roles, and start Annex IV documentation and FRIAs — planning against the 2 December 2027 Annex III date, and 2 August 2028 for Annex I product-embedded systems.
Ongoing. Monitor Finland's official Article 70 authority designation and any Finnish implementing act; watch for the Digital Omnibus text in the Official Journal; follow EU AI Office GPAI guidance if you build or integrate foundation models. Verify the named authority against official sources before relying on this guide for enforcement contact.
Related guides
- EU AI Act in Sweden: proposed authority and obligations
- EU AI Act in Denmark: authorities and deadlines
- EU AI Act deadlines and application dates
- market surveillance authority — glossary
- EU AI Act compliance: where to start
Manage your EU AI Act compliance in one place
Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.
Start free trial →