Security & Compliance

Who will knock on your door about AI in Sweden? IMY, mostly

By Technspire TeamJune 15, 202610 views

Sweden now has an answer to the question every compliance officer has been asking since August 2024: which authority will actually supervise the EU AI Act here? On 12 June 2026 the government formally assigned five authorities to act as national competent authorities under the AI-förordningen, and today, 15 June, Integritetsskyddsmyndigheten (IMY) confirmed its own piece of the puzzle. IMY becomes a market surveillance authority for the AI Act, with responsibility that covers, among other areas, AI systems used in law enforcement and credit assessment. If you run AI workloads on Azure for a Swedish organisation, the abstract "someone in Brussels will regulate this" era just ended. Your regulator has a name, an address in Stockholm, and a track record of GDPR enforcement.

What the government actually decided

The government assignment, published on 12 June 2026, designates five authorities as national competent authorities under the AI Act: Post- och telestyrelsen (PTS), Integritetsskyddsmyndigheten (IMY), Finansinspektionen, Läkemedelsverket, and Styrelsen för ackreditering och teknisk kontroll (Swedac). The line-up follows the blueprint laid out by the government inquiry that delivered its report, SOU 2025:101 "Anpassningar till AI-förordningen", in October 2025. That inquiry proposed PTS as the authority with primary responsibility, with IMY and Finansinspektionen sharing supervision of high-risk AI, and a regulatory sandbox operated with PTS at the centre.

IMY's announcement today fills in its slice. Three things stand out from the authority's own description of the mandate:

  • Market surveillance for sensitive domains. IMY states that its responsibility covers, among other things, AI systems in brottsbekämpning (law enforcement) and kreditvärdering (credit assessment). These are two of the most rights-sensitive categories in the entire regulation.
  • A seat in the regulatory sandbox. IMY will participate in Sweden's regulatory sandbox for AI, contributing guidance on data protection while companies and public authorities test AI solutions under controlled conditions.
  • Preparation in concert. IMY says it will now begin preparing, above all in cooperation with the other designated authorities PTS and Finansinspektionen.

Director general Eric Leijonram framed the assignment as part of building trust in AI in Sweden: supervision that promotes innovation while protecting citizens' rights. Read past the ceremonial language and the operational signal is clear. The authority that has spent seven years enforcing GDPR against Swedish organisations will now also inspect their AI systems.

Where this lands in the AI Act timeline

A quick orientation, because two clocks are running and they are easy to confuse. The EU-level clock is fixed in the regulation itself:

  • 1 August 2024: the AI Act entered into force.
  • 2 February 2025: the prohibitions on unacceptable-risk practices and the AI literacy requirement began to apply.
  • 2 August 2025: obligations for general-purpose AI models took effect, and member states were required to designate national competent authorities.
  • 2 August 2026: the bulk of the regulation starts to apply, including the high-risk regime for Annex III systems. Member states must also have at least one operational AI regulatory sandbox by this date.
  • 2 August 2027: Article 6(1) and the rules for high-risk AI embedded in regulated products follow.

The Swedish clock is the second one. The 2025 inquiry proposed that the national rules, including sanction powers for the supervisory authorities, should apply from 2 August 2026, in step with the EU date. IMY's own announcement today describes the regulation as mainly entering into force during 2027, which reflects how the national enforcement machinery is expected to phase in. The practical reading for planning purposes: EU-level obligations for most high-risk systems bite from 2 August 2026, seven weeks from now, while the Swedish authorities spend the coming year standing up their supervision practice, guidance, and the sandbox before enforcement reaches full strength in 2027.

That gap is not a grace period. It is a window. Obligations exist from August whether or not an inspector is scheduled to visit, and the documentation you generate (or fail to generate) during 2026 is exactly what a 2027 inspection will ask for.

Why IMY specifically, and why it matters that it is IMY

The choice is not arbitrary. The AI Act itself, in Article 74(8), points member states toward their data protection authorities as market surveillance authorities for high-risk AI used in areas such as law enforcement, migration and the administration of justice. Sweden is following the grain of the regulation: the authority that already supervises how personal data is processed in policing under the Criminal Data Act is the natural supervisor for AI systems in the same domain. Credit assessment sits in the same logic. Creditworthiness evaluation of natural persons is an explicit high-risk category in Annex III of the AI Act, and it is an area where IMY already has enforcement history under GDPR.

For Swedish enterprises the consequence is structural, and it is the single most important thing to internalise from today's news: GDPR supervision and AI Act market surveillance now live in the same building.

Joined-up scrutiny, in practice. When one authority holds both mandates, an investigation that starts as a data protection complaint about an AI-driven decision can surface AI Act questions, and vice versa. A credit-scoring model that draws a GDPR question about automated decision-making under Article 22 is also a high-risk AI system whose technical documentation, logging, and human-oversight arrangements fall under the AI Act. Treating the two frameworks as separate compliance projects, owned by separate teams with separate document sets, was always inefficient. As of today it is also strategically unwise. Build one evidence base that serves both.

There is a friendlier flip side. One regulator for both regimes means one place to ask, and IMY's sandbox role is explicitly about giving data protection guidance while AI solutions are tested. Organisations that engage early get coherent answers about GDPR and the AI Act together, rather than two authorities' partially overlapping opinions.

A decision guide: is your system in IMY's lane?

Supervision responsibilities in Sweden are shared across the five designated authorities, and detailed boundary-drawing will continue over the coming months. But you can already sort your AI portfolio with a few questions:

  • 1. Does the system evaluate the creditworthiness of natural persons? Credit scoring of individuals is Annex III high-risk, and IMY has named credit assessment as part of its supervision area. If you build or deploy such a model, assume IMY is your market surveillance authority and Finansinspektionen has an adjacent interest if you are a regulated financial firm.
  • 2. Does the system support law enforcement, or do you sell into that sector? AI used in brottsbekämpning is squarely in IMY's stated remit. Vendors matter here as much as authorities: if your product is deployed by police or prosecution bodies, provider obligations under the AI Act apply to you, and the supervising authority is the one that also enforces data protection in that sector.
  • 3. Is the system high-risk under Annex III for another reason? Employment screening, access to essential services, education. The inquiry proposed that IMY and Finansinspektionen share high-risk supervision under PTS's primary responsibility, so expect the precise allocation to be clarified. Prepare the same documentation regardless: the obligations do not change with the inspector's letterhead.
  • 4. Does the system touch a regulated product domain? Läkemedelsverket and Swedac on the list signal that product-safety-adjacent AI (medical devices, conformity assessment) follows its sectoral track, mostly on the 2027 clock.
  • 5. Is the system none of the above? Then your near-term AI Act exposure is mostly transparency obligations and AI literacy, plus GDPR as always. Do not over-rotate; put your effort where the risk classification says it belongs.

The sandbox: use it before enforcement starts

Every member state must have at least one operational AI regulatory sandbox by 2 August 2026, and Sweden's design, per the inquiry, centres on PTS with IMY contributing data protection guidance. IMY describes the sandbox as a way for companies and public authorities to test AI solutions under controlled conditions.

Why should a pragmatic engineering organisation care about a regulatory sandbox? Three reasons, all of them concrete:

  • You get the regulator's reading before you commit architecture. Ambiguities in the high-risk requirements (what counts as sufficient human oversight for your use case, how detailed the logging must be, how to handle training data governance for a fine-tuned model) are cheaper to resolve in a sandbox dialogue than in a post-deployment inspection.
  • Participation produces evidence. A documented sandbox engagement, with the supervisory guidance you received and how you implemented it, is a strong exhibit in any later review, and equally useful in enterprise procurement where buyers increasingly ask how AI Act compliance was validated.
  • The data protection question comes bundled. For most Swedish AI projects the hard legal questions are GDPR questions wearing an AI costume: legal basis for training data, automated decision-making, data minimisation in feature pipelines. IMY sitting inside the sandbox means those questions get answered in the same conversation.

If you have a high-risk system on your 2026-2027 roadmap, decide now whether it is a sandbox candidate. Good candidates are systems with genuine regulatory ambiguity and enough internal priority that you can staff the engagement. A half-hearted sandbox application wastes the one early-mover window this timeline offers.

What Azure-first teams should do before 2 August

None of today's news changes your technical obligations, but it sharpens who will check them and how a Swedish inspection will think. A regulator with a GDPR reflex will reach for familiar instruments: records of processing, DPIAs, logging, and demonstrable human oversight. On Azure, the preparation maps to work you can start this quarter:

  • Inventory first. You cannot classify what you have not listed. Enumerate every AI system in production or late development, including the Copilot-style features embedded in SaaS you deploy, and record its Annex III status and your role (provider or deployer) for each.
  • Make logging an architectural requirement, not an afterthought. High-risk systems must support automatic event logging. Route model inputs, outputs and override events through your standard telemetry (Application Insights, Log Analytics) with retention that matches your documented policy, and keep the logs inside your EU data residency arrangement.
  • Unify the GDPR and AI Act evidence base. Extend your existing DPIA process to capture the AI Act's risk-management and human-oversight questions in the same workflow. One system, one dossier, both regimes. This is the direct answer to joined-up IMY scrutiny.
  • Pin down your provider/deployer boundary with vendors. For each third-party model or AI feature, get the vendor's technical documentation and instructions for use, and record what you rely on them for. Deployers inherit obligations they cannot outsource, but they should not re-document what the provider must supply.
  • Assign the regulator relationship. Someone in your organisation should own the IMY relationship for AI, the same way someone owns it for data protection today. In many Swedish organisations that will sensibly be the same person or team.

Takeaways

  • Sweden designated its AI Act authorities on 12 June 2026: PTS, IMY, Finansinspektionen, Läkemedelsverket and Swedac, following the structure proposed in SOU 2025:101.
  • IMY is a market surveillance authority with stated responsibility including AI in law enforcement and credit assessment, and a guidance role in the regulatory sandbox.
  • GDPR and AI Act supervision now sit with the same authority for the most rights-sensitive AI categories. Build one combined evidence base, not two parallel compliance tracks.
  • EU obligations for most high-risk systems apply from 2 August 2026. Swedish enforcement ramps toward 2027. Use the gap to inventory, classify, and instrument, not to wait.
  • If a high-risk system is on your roadmap, evaluate the sandbox seriously. Early guidance from IMY on the data protection questions is worth more than any amount of internal legal speculation.

Sources