Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement
Lov nr. 467 af 14. maj 2025 om supplerende bestemmelser til forordningen om kunstig intelligens (AI-loven) Folketingets sagsforlob 2024/1 LF 154
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 2 August 2025.
An AI prohibited practices rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not deploy an AI system in Denmark that engages in a practice the EU AI Act's Article 5 prohibits, including untargeted scraping of facial images from the internet or CCTV to build a facial-recognition database, biometric categorization that infers a protected characteristic, or individual predictive-policing profiling.
- Provide accurate, complete information to Digitaliseringsstyrelsen, Datatilsynet or Domstolsstyrelsen on request, and allow them to inspect your premises and technical systems, or risk a court-set fine with no statutory ceiling stated in Danish law.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Section 10(1): a fine, unless a higher penalty is warranted under other legislation, for violating Article 5(1)(a) to (g) of the EU AI Act, giving inaccurate, incomplete or misleading information to a competent authority, failing to comply with an information demand or inspection, or failing to comply with an order or temporary ban. No monetary ceiling is stated for this fine in the Danish text; a bodeforelag (administrative fine notice with the same effect as a judgment if accepted) is available under section 11. Section 10(4): the limitation period is 5 years.
Who enforces it
Enforcement body
Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen, Denmark's national competent authorities under the EU AI Act, with market-surveillance responsibility for the Article 5 prohibited practices divided between the first two and Domstolsstyrelsen covering the courts' own non-judicial use of AI systems.
What it reaches
Obligation class
Prohibition, Governance
Who checks it
Audit expectation
on_request
Who audits it
Regulator
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Denmark's supplementary AI Act law designates Digitaliseringsstyrelsen, Datatilsynet and Domstolsstyrelsen as the national competent authorities under Article 70(1) of the EU AI Act.
Digitaliseringsstyrelsen is the notifying authority and central contact point and is the market-surveillance authority for Article 5(1)(a) to (c), (e) and (f) of the prohibited-practices list, which includes the untargeted scraping of facial images from the internet or CCTV footage to build a facial-recognition database.
Datatilsynet is the market-surveillance authority for Article 5(1)(d) and (g), covering individual predictive-policing profiling and biometric categorization that infers a protected characteristic. Domstolsstyrelsen covers the courts' own use of AI systems outside their judicial capacity. The authorities may demand information, enter business premises without a court order, run technical inspections of an AI system, publish their decisions, and issue compliance orders or temporary bans.
An intentional or grossly negligent violation of Article 5's prohibited practices, a failure to give accurate information on request, obstruction of an inspection, or non-compliance with an order is punishable by a fine set by the courts, with no statutory ceiling stated in this law; the limitation period is 5 years.
When LexLint raises it
crawls_webprocesses_biometricshigh_risk_decisions