Who enforces the AI Act in Sweden? PTS and the new map
Sweden's AI Act enforcement map is now set: the SOU 2025:101 inquiry designates Post- och telestyrelsen (PTS) as coordinating market surveillance authority, with eleven surveillance bodies, two notifying authorities, and a PTS-run regulatory sandbox. The supplementary law was written to take effect on 2 August 2026 but awaits formal adoption, so PTS and its peers operate on interim government assignments while EU transparency rules already apply.
The AI Act's high-risk deadline moved to December 2027
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moves the AI Act deadline for Annex III high-risk systems from August 2026 to 2 December 2027, with Annex I embedded systems following in August 2028. Article 50 transparency still applies from 2 August 2026, a new prohibition arrives with a December 2026 marking deadline, and a phased 16-month plan turns the reprieve into a workable compliance programme.
AI Act deadlines moved: what still lands August 2, 2026
On 16 June 2026 the European Parliament approved the Digital Omnibus amendments 423-57, moving Annex III high-risk AI Act obligations to 2 December 2027 and product-embedded obligations to 2 August 2028. Article 50 transparency duties and the Commission's GPAI enforcement powers were not delayed, which leaves Swedish enterprises six weeks to ship chatbot disclosure, content marking and a documented GPAI position before 2 August 2026.
Who will knock on your door about AI in Sweden? IMY, mostly
On 15 June 2026 IMY confirmed its role as market surveillance authority for the EU AI Act, with responsibility covering AI systems in areas such as law enforcement and credit assessment, alongside PTS and Finansinspektionen. For Swedish enterprises this puts GDPR and AI Act supervision under one regulator, and IMY's sandbox role offers a way to get data protection guidance before enforcement reaches full strength in 2027.
CADA explained for Azure customers: EU cloud sovereignty
On 3 June 2026 the European Commission proposed the Cloud and AI Development Act, a regulation that introduces four Union assurance levels for cloud sovereignty and aims to at least triple EU data centre capacity within five to seven years. For Swedish public-sector and regulated teams on Azure, the framework will decide which workloads can stay on a US hyperscaler and which need an EU-controlled alternative, so the classification work should start now.
Sweden's cloud policy: digital sovereignty for Azure teams
Sweden's first national cloud policy (Fi2026/01233) bans no provider but makes jurisdictional exposure, portability and exit capability the questions every public-sector cloud decision must now answer in writing. For Azure estates, a defensible position means classified workloads, enforced Swedish and EU residency, customer-managed keys for sensitive data and a tested export path.
Demystifying the EU AI Act: The Engineering Reality
A working-engineer walk-through of the EU AI Act beyond the risk-tier summary. Covers legal structure, Annex III classification decisions, GPAI rules, the full timeline to 2027, Article 12 logging, Article 50 transparency, conformity assessment artifacts, CE marking, penalties, and the Swedish implementation.
EU AI Act High-Risk Deadline: Swedish Prep List for August 2026
A 4-month practical preparation checklist for the EU AI Act August 2026 high-risk deadline, tailored to Swedish B2B teams — classification, Annex IV documentation, Article 12 logging, human oversight, and CE marking.
NIS2 in Sweden: The Practical Engineer's Checklist
A practical engineering checklist for NIS2 compliance in Sweden — the ten risk-management measures, the 24-hour and 72-hour incident reporting timelines, supply-chain controls, and what board accountability looks like on the ground.
Swish Handel 2026: Integration Patterns for Node Applications
A practical integration guide for Swish Handel in modern Node and Next.js applications in 2026 — certificate management, callback handling, idempotency, reconciliation, and the failure modes every integrator should design for.
DORA One Year In: Swedish Fintech Engineering Lessons
One year after the Digital Operational Resilience Act entered into force for financial-sector firms on 17 January 2025, this is what Swedish fintech engineering teams actually learned about ICT risk, incident reporting, TLPT, and the third-party register.
EU AI Act One Year On: Lessons for Swedish B2B Teams
A practical review, one year after the EU AI Act Article 5 prohibitions entered into force on 2 February 2025 — where Swedish B2B teams over-reacted, where they under-reacted, and what must ship before the August 2026 high-risk deadline.
IT Budget 2026: Where Swedish CTOs Should Invest First
A practical allocation framework for Swedish CTOs planning 2026 IT spend — from EU AI Act governance infrastructure and Entra Agent ID, to Azure Sweden Central residency work, NIS2 gap closure, and the investments worth deferring.