Denmark is repeatedly recognised as one of the most digitalised countries in Europe. Accordingly, Denmark has been at the forefront of implementing artificial intelligence (AI) in both the private and public sector. In a statistic from EUROSTAT (2025), Denmark ranked the highest among EU countries on the number of enterprises with 10 or more employees that utilised AI (42.03%). The Danish Government has — in collaboration with Local Government Denmark (Kommunernes Landsforening) and Danish Regions (Danske Regioner) — established the Taskforce for Artificial Intelligence (“Taskforce for Kunstig Intelligens”) whose purpose is to promote AI-driven strategies in the public sector. From the taskforce’s report in June 2025, one of the goals is to free up to 50 million hours in the public sector equivalent to at least 30,000 full-time equivalents by 2035 at the latest but ideally having realised a great deal of this objective by 2030.
AI is no doubt becoming an integral part of Danish enterprises and public authorities. The development and deployment of AI models and systems is, however, subject to key legal considerations which enterprises and public authorities must keep in mind when developing and deploying AI.
In a legal context, Danish law is, in general, technology-neutral, unless otherwise stated.
In the following, AI will be referred to as “AI models” and “AI systems” in line with how EU legislation has approached the concept of AI. In essence, AI models refer to the underlying software that enables a system to qualify as an AI system, including enabling the system to be capable of varying degrees of autonomy and inference. AI models themselves cannot, however, be deployed directly; they require additional components — for example, a user interface.
Although the Danish Constitution (Grundloven) does not contain AI-specific provisions, the constitution still holds prevalence in certain contexts. The doctrine of legality which is derived from the Danish Constitution states inter alia that public authorities’ exercise of authority must have a basis in law. It is generally recognised that for public authorities to deploy AI systems to issue decisions, a legal basis in law must be identified for the deployment of the AI system itself.
Although specific rulings on AI in the context of human rights in, for example, the Charter of Fundamental Rights of the EU or the European Convention on Human Rights (ECHR) have yet to be issued, domestic/international courts and supervisory authorities are slowly seeing an increase in AI-specific decisions. These cases concern legal questions concerning:
- the interpretation of AI under existing legislation; or
- the interpretation of AI under AI-specific legislation.
Additionally, the existing framework for human rights must be interpreted in the context of AI. For example, Article 8 of the Charter of Fundamental Rights of the EU on the right to protection of personal data must be read in light of the capacity of the AI models and systems to process personal data.
Under the Danish Patents Act (Patentloven), patent protection may apply to AI systems or models where they form part of a technical invention. Inventorship remains reserved for natural persons, which is a position consistent with international jurisprudence. However, AI involvement in the inventive process does not itself preclude protection. Where a natural person conceives the underlying inventive concept and exercises genuine creative direction and discretion constituting the significant contribution, patent protection may apply to the resulting invention. However, the point at which AI involvement becomes determinative remains legally uncertain and must be assessed on a case-by-case basis.
In Denmark, copyright protection for AI-related works requires human originality. Fully autonomous AI-generated outputs fall outside the scope of protection, while AI-assisted works may qualify where a natural person exercises genuine creative direction, such as by selecting, curating or editing outputs. Ownership vests in the human author or, in the context of an employer–employee relation, the employer. However, the point at which AI involvement becomes determinative remains legally uncertain and must be assessed on a case-by-case basis.
Training AI models on copyrighted works raises infringement risks both in relation to the use of protected works in the training itself and the outputs generated by the AI model that may reproduce or closely resemble protected works. The Directive on Copyright in the Digital Single Market’s (“DSM Directive”) text and data mining exceptions offer some safe harbours, and licensing frameworks are still evolving.
Under the Danish Trade Secrets Act (Lov om forretningshemmeligheder), AI systems may generate data qualifying as trade secrets, provided reasonable protective measures are in place to maintain confidentiality. Training methodologies and related know-how may similarly be safeguarded as trade secrets. However, AI also poses infringement risks: outputs generated by AI systems may inadvertently reproduce or expose third-party trade secrets, and users and providers should remain alert to this exposure. In the absence of explicit AI legislation in Denmark, contractual arrangements remain a primary tool for managing these risks alongside statutory protections.
A recent Danish decision has been among the first to address what may constitute a “machine-readable” format in the context of permissible text and data mining reservations under the DSM Directive. Furthermore, KODA, the collective management organisation (CMO) for composers and songwriters, has initiated proceedings against Suno, the AI music generation platform, alleging training on protected musical works without authorisation or remuneration. The Danish Publishers’ CMO (DPCMO) has similarly filed claims against OpenAI and LinkedIn regarding the use of Danish publishers’ content in AI training datasets. These proceedings are among the first Danish cases to directly address copyright infringement in the context of AI training data and are anticipated to yield significant guidance once resolved.
In Denmark, the primary framework for processing data in the context of AI is the General Data Protection Regulation No. 2016/679 (GDPR) and the Danish Data Protection Act (Databeskyttelsesloven) which supplements the GDPR.
Developing AI in relation to personal data
Developing AI models with personal data constitutes a separate purpose under the GDPR which requires the data controller to identify a legal basis in GDPR Article 6(1)(a)–(f). Although the data controller is free to choose whichever legal basis in GDPR Article 6(1)(a)–(f), some legal bases are more appropriate than others.
Private data controllers will often find Article 6(1)(f) most fitting: that is where data processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
For development to be based on Article 6(1)(f), three steps must be followed and adhered to by the controller:
- identification of a legitimate interest (i.e. an interest that is inter alia sufficiently clear, specific, real and present);
- processing personal data on the basis of the legitimate interest that makes attaining the purpose for the processing possible, including an assessment of whether other less intrusive means of processing exist; and
- application of a balancing test, in which the interests pursued by the controller (i.e. developing an AI model) must be weighed against the data subject’s interests and rights (e.g. categories of data of the data subject to be processed, the data subjects’ reasonable expectations and mitigating measures, such as pseudonymisation/anonymisation).
If the balancing test concludes that the interests or rights of the data subject do not take precedence over the controller’s legitimate interest, only then can processing based on legitimate interests be pursued, and vice versa.
Public data controllers will often find Article 6(1)(e) most fitting: that is where data processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. For data processing to be based on Article 6(1)(e), the basis for the processing must be laid down in EU or Member State law as a supplementary legal basis (cf. Article 6(3)). Depending on the intrusiveness of the processing (i.e. the consequences for the data subjects as a result of the processing), this supplementary legal basis must be more or less clear.
The Danish Data Protection Agency (DDPA) has stated that AI development in general does not constitute intrusive processing. As such, this tips the scales in favour of controllers wishing to develop AI models with reference to Article 6(1)(e) and (f).
Deploying AI in relation to personal data
In general, deploying AI in the context of personal data will not be considered a standalone purpose under the GDPR.
However, if the AI system is used for a new, separate purpose (which is pursued via the deployment of an AI system), this can require the identification of a legal basis in GDPR Article 6. Private data controllers will often find Article 6(1)(f) most fitting and public data controllers will find Article 6(1)(e) most fitting, subject to the same considerations as development (i.e. the balancing test and identifying a sufficiently clear supplementary legal basis).
The DDPA’s practice and guidelines emphasise that deployment of AI systems can constitute intrusive processing in certain use cases; for example, partial automation in case processing for public authorities or initial screenings of applications for benefits. This triggers a higher level of clarity of the supplementary legal basis in the context of Article 6(1)(e), and the interests and rights of the data subject will accordingly tilt the balancing test in favour of the data subject in the context of Article 6(1)(f).
Data Protection Impact Assessment (DPIA)
Controllers must carry out a DPIA pursuant to GDPR Article 35 where data processing is likely to result in a high risk to the rights and freedoms of natural persons, in particular where new technologies are applied. The DDPA has stated that the development and/or deployment of AI models and systems will almost always trigger the requirement to carry out a DPIA, as AI is perceived as a “new technology” and the development and deployment of AI models and systems often includes:
- processing sensitive personal data pursuant to GDPR Article 9;
- processing of personal data pertaining to vulnerable persons; or
- processing of personal data at a large scale.
To aid controllers in carrying out their DPIAs, the DDPA has on its website published a template for DPIAs specifically tailored to the development and deployment of AI models and systems.
In recent years, access to and sharing of data has become a focal point on both the political and legislative agenda. This has amounted to new legislation, such as EU Regulation No. 2023/2854 on fair access to and use of data, more commonly known as the “Data Act”.
The Data Act’s purpose is to ensure fair access to and use of data generated by connected products (e.g. Internet-of-Things (IoT) products) and related services across the EU. The Data Act regulates this by establishing rights for users to access data they generate, imposing obligations on data holders to share that data upon request, including, if relevant, to third parties if requested by the user.
The majority of the Data Act’s rules on data access and sharing have been applicable since 12 September 2025. The Data Act mandates that connected products and related services must be designed in a way that users can directly access data free of charge, but these design requirements apply to connected products and related services placed on the market after 12 September 2026.
The GDPR considers biometric data, including voice data, facial images and dactyloscopic data, for the purpose of uniquely identifying a natural person to be sensitive personal data. This triggers an obligation for the data controller to identify an exemption in GDPR Article 9(2)(a)–(j) alongside a legal basis in Article 6(1)(a)–(f). Some exemptions in Article 9(2) are directly applicable while others must be “activated” via Member State law, potentially subject to further conditions than ascribed in GDPR Article 9(2). One such example is Article 9(2)(g), concerning processing of sensitive categories of data for reasons of substantial interest, which for private data controllers requires the DDPA’s approval prior to the processing.
Although “bias” is not legally defined, bias in the context of AI refers to prejudices in the output of an AI system as a result of the AI model’s training data, either via selective input data, data poisoning and so on.
Existing anti-discrimination and equality legislation applies in the context of recruitment processes where AI systems are used, such as screening tools for job applications. Such AI systems must adhere to the Danish Employment Non-discrimination Act (Lov om forbud mod forskelsbehandling på arbejdsmarkedet) which prohibits discrimination based on unlawful criteria in, for example, recruitment processes.
The Danish cybersecurity and resilience legal framework is primarily based on the following EU legislation: the EU Artificial Intelligence Regulation (AI Act), the Digital Operational Resilience Act (DORA), the Cyber Resilience Act (CRA) and the Network and Information Systems Directive 2 (NIS 2). While the AI Act is AI-specific, other legislation does not explicitly mention AI but refers to general terms for IT-services where AI systems are included, such as “network and information systems” under NIS 2 and DORA.
AI Act Article 15 mandates that providers of high-risk AI systems (i.e. AI systems listed in AI Act Annex I or III) must mitigate AI-specific cybersecurity and resilience risks, including data poisoning, model poisoning and adversarial examples. Article 15 also mandates the implementation of appropriate cybersecurity measures.
Other than the AI Act, other cybersecurity legislation applies in parallel (e.g. NIS 2, DORA and the CRA, where relevant).
Several areas of competition law are highly relevant in the context of AI, such as merger control, exclusivity, collaborations and algorithmic collusions.
On merger control, novel arrangements such as acqui-hiring or post-investment board representation may trigger notification obligations. On exclusivity and collaborations, agreements between major players and AI developers, whether exclusive deals or strategic partnerships, are assessed under Danish rules prohibiting anti-competitive agreements and abuse of dominance. On algorithmic collusion, that is price coordination via algorithms, Danish competition law treats price coordination via shared pricing AI systems in the same way as non-AI price collusion.
The Danish Competition Act (Konkurrenceloven) sets out general antitrust and competition rules which, by virtue of their general scope, apply to conduct in AI markets in the same way as they apply to any other sector. Please see Section 6.1, above.
AI as a technology has undergone and is still undergoing rapid development. In recent years, the notion of “AI agents” or “agentic AI” has surfaced, referring to AI systems that autonomously and independently reason, plan and take concrete actions and decisions.
At the time of writing, AI agents do not have any independent legal status in Denmark. Any action taken by an AI agent is therefore deemed the action of the legal person or natural person deploying the AI agent with corresponding legal consequences, such as liability for damages.
Interestingly, in 2017, the European Parliament called for the European Commission to explore, analyse and consider the notion of establishing the concept of an “electronic person”, which would attribute legal status to “the most sophisticated robots”. The European Parliament’s call for attention to the matter did not, however, amount to any legal changes on attributing legal status to “the most sophisticated robots”.
Agentic AI is not specifically addressed in Danish sector-specific regulation.
The Product Liability Directive, which is transposed into Danish law via the Danish Product Liability Act (Produktansvarsloven), imposes a no-fault liability scheme for “producers” of “products”. A “product” is defined in the directive as “movables even if incorporated into another movable or into an immovable”. AI systems are not considered to be “movables”, unless the AI system is integrated into a “movable” itself, such as machines, toys, etc. Standalone AI systems as such do not constitute “products” and will therefore be subject to Danish liability law (i.e. an assessment of negligence and culpa).
For reference, the Product Liability Directive has been replaced with a new Product Liability Directive (Directive No. 2024/2853) which explicitly includes software, including AI, as a “product”. This will, for damages and harms caused by AI systems, impose a no-fault liability scheme for “manufacturers” of AI systems. The revised Product Liability Directive must be transposed into Member State law by 9 December 2026 at the latest. Until then, the current Product Liability Directive applies.
Currently, no specific strict liability schemes (e.g. no-fault liability) apply in an AI context but will apply from 9 December 2026. See Section 8.1, above, for more on this.
Under the General Product Safety Regulation No. 2023/988 (GPSR), recall obligations apply to “manufacturers” of “products”, but this definition does not encompass standalone AI systems. No recall obligations apply to standalone AI systems. An exception arises where the AI system is embedded in a physical “product” in which case the product as a whole may be subject to recall measures. In this regard, the GPSR does cover products where the product’s safety is affected by inter alia cybersecurity and the evolving, learning and predictive functionalities of the product.
The Danish Sale of Goods Act (Købeloven) regulates updates to digital services, including AI systems, in B2C relations. The seller is obliged to ensure that the consumer is informed of and receives updates, including safety updates, necessary to ensure the service remains free from defects during the period of the agreement. Where the AI system is provided by way of a single delivery, the obligation to provide updates, including safety updates, applies for the period that the consumer may reasonably expect, having regard to the type and purpose of the service and the circumstances of the agreement.
No AI specific liability cases have been presented to Danish authorities or courts yet.
Danish legislation is increasingly being amended to provide a sufficiently clear, supplementary basis for the processing of personal data by public authorities pursuant to GDPR Article 6(1)(e) (see Section 3.1, above).
The current Danish supplementary legislation for the AI Act (AI-loven) only enables inter alia the Agency for Digital Government (ADG) to enforce the AI Act’s rules that have been applicable since 2 February 2025 (i.e. the AI Act’s rules on prohibited AI practices). As the remainder of the AI Act’s rules apply on 2 August 2026, save for rules on high-risk AI systems covered in AI Act Annex I which apply from 2 August 2027, the ADG had proposed new supplementary legislation that enables the enforcement of inter alia high-risk AI systems covered by AI Act Annex III and AI systems subject to transparency requirements. On an EU level, the dates in the AI Act concerning the application of high-risk AI system rules; that is 2 August 2026 for Annex III high-risk AI systems and 2 August 2027 for Annex I high-risk AI systems, are currently undergoing the EU legislative procedure with the purpose of postponing these dates. At the time of writing, these changes have not yet been legally adopted.
In 2018, the Danish Government adopted the agreement on digitalised-ready legislation which sets clear goals to adopt and amend existing legislation to better accommodate technological developments for the public sector.
The current Joint Public Sector Digitalisation Strategy, which spans the years 2026–2029, encompasses a goal of responsible and value-adding new technologies, including AI. This includes bolstering the public sector with better tools, means and know-how about AI as well as the necessary legal frameworks for developing and deploying AI.
As mentioned in the introduction, the Danish Taskforce for Artificial Intelligence has set concrete goals for implementing AI in the public sector.
Can my organisation outsource regulatory compliance, including any responsibility under the AI Act?
While organisations as a rule are free to outsource specific tasks to bolster their compliance under the AI Act, the organisation that has been mandated a role by law (such as providers or deployers under the AI Act) cannot outsource the regulatory responsibility itself. In other words, the responsibility and regulatory compliance is ultimately vested in the hands of the organisation irrespective of whether specific tasks have been outsourced to a third party.
Is agentic AI subject to any specific regulatory requirements?
Agentic AI is not directly addressed as a sub-set of AI in current Danish or EU legislation. Agentic AI does, however, raise concerns; for example, determining the legal basis for deploying the agentic AI, as deploying agentic AI can constitute intrusive processing of personal data (see Section 3.1, above).
We use generative AI to assist us in coding software for clients, what should we be aware of?
In the context of copyright protection, the software’s (source) code will as a rule, and open-source considerations aside, only be commercially valuable under the condition it can be legally protected (e.g. via copyright). As mentioned in Section 2.2, above, AI-assisted code (i.e. code subject to a certain degree of human direction, such as being subject to further editing and control) can be copyright protected. Be wary and consistent in the human review and control applied to code generated by AI systems to ensure a sufficient level of human originality.
Does AI disrupt the legal sector?
Broadly speaking, AI has the potential to fundamentally change — and already has changed — the way legal professionals approach their work. For example, legal research is easier, initial drafts for reviewing documents save legal professionals hours and AI workflows often contribute to a better finished product. However, common issues with AI are still prevalent, such as hallucinations, as well as a lack of traceability for AI systems based on AI models utilising neural networks, also known as the “black box” problem. The core task for lawyers and attorneys remains the same: to advise and represent. AI systems prove themselves best when used as a tool in the hands of a legal professional with the right AI know-how in these contexts, and not as a replacement for legal advice or representation.
We use generative AI in our business operations — who remains liable for damages caused by the AI system, our organisation or the provider of the generative AI system?
Broadly speaking, organisations remain liable if the damage is, for example, linked to how they have selected, set up, or relied on the AI system (i.e. an assessment of negligence and culpa). The provider may instead prove liable if the harm stems from defects in the AI system itself. Any assessment of liability for damages incurred will therefore be determined on a case-by-case basis.