Denmark Launches Official AI Regulatory Sandbox
Denmark officially launched its new artificial intelligence regulatory sandbox on September 9, 2026. This makes Denmark one of only eight European Union countries with an operational testing framework where the General Data Protection Regulation and the European Union AI Act apply simultaneously for businesses processing personal data with artificial intelligence. The Danish Data Protection Agency and the Danish Agency for Digital Government lead the initiative.
Regulatory responsibilities are divided among different authorities. The Data Protection Agency oversees prohibited practices involving the exploitation of vulnerabilities and biometric categorization, while the Courts Administration handles AI oversight within law enforcement and the judicial system. Because of this division, a company developing systems like facial recognition or behavioral profiling may interact with up to three different Danish authorities depending on which part of the system is under review.
For software companies and developers working with AI products in Denmark, compliance is no longer just a data protection project. Development teams must simultaneously determine whether a system is lawful under data protection law and identify its risk classification under the AI regulation. These two frameworks do not always yield the same answers, which creates complex regulatory overlaps that the new sandbox aims to help navigate.