
Sweden's AI Rank Climbs. Its Government Sits Dead Last.
The most Swedish problem in tech right now
Here is today's headline, distilled: Sweden is climbing in global AI competitiveness rankings. The private sector is building. Companies are shipping. And the Swedish public sector ranks dead last among comparable nations in AI adoption. Dead. Last. Let that sit for a second.
I run a tech company in Jönköping. We build AI agents, blockchain systems, and SaaS products. We work with clients across Europe. And from where I sit, this split between private capability and public paralysis is not a surprise. It is the most predictable failure in Nordic tech policy. Every founder I know in Sweden has the same experience: the private side moves fast, the state side moves in committee cycles. The gap is now so wide it shows up in international rankings.
Dagens Industri reports today that Sweden's overall AI competitiveness is on the rise. Good. But dig into the numbers and you see a country running on one leg. The companies do the running. The government does the limping. And the new Digitaliseringsstrategi 2025–2030 is supposed to fix this. It will not.
The Digitaliseringsstrategi is a PowerPoint deck cosplaying as policy
I have read the strategy document. I suspect most kommun directors have too, and they are not sleeping better because of it. Dagens Samhälle reports that municipal directors across Sweden are losing sleep over digitalization gaps. They know they are behind. They lack mandate, budget, and technical literacy to act. The strategy gives them none of these things.
What does the Digitaliseringsstrategi actually contain? Vision statements. Framework language. Coordination ambitions. What it does not contain: concrete technical requirements, binding timelines, budget allocations tied to outcomes, or any serious engagement with the threats that are already here. It reads like it was written by people who understand governance but do not understand software. That is a problem when your strategy is about software.
The worst part is the quantum blind spot. Dagens Medicin flags a new report today warning that quantum computers pose a growing threat to Swedish health data. This is not theoretical. Post-quantum cryptography migration is already underway at serious organizations globally. NIST finalized its post-quantum standards. The US federal government has deadlines. Sweden's digitalization strategy barely addresses this. The infrastructure it is supposed to modernize is the same infrastructure that quantum computing will break. If you are a software development company in Sweden and you are not thinking about post-quantum readiness for your clients, you are already late.
Private sector carries the weight. As usual.
Sweden's AI ranking improvement comes from companies. Full stop. The Wallenberg foundations fund AI research. Startups in Stockholm, Gothenburg, and yes, Jönköping ship real products. Sweden's deep engineering culture, the one that built Ericsson and Spotify, is alive and building. But it builds despite the state, not because of it.
At HEIMLANDR, we see this every week. Companies come to us because they need to move. They need AI agents that actually work in production. They need rapid MVPs to test ideas before the market moves on. They do not come to us because a government strategy told them to digitalize. They come because their competitors are already doing it.
The Swedish private sector understands urgency. The Swedish public sector understands process. These are not the same thing. And when you are competing against companies in the US and China who face zero equivalent of the EU AI Act compliance burden, process becomes a tax on your survival.
The EU AI Act: compliance costs without strategic air cover
Let me be direct about something that I think the European tech community talks around but rarely states clearly: the EU AI Act is a competitive handicap unless member states provide real support to their companies.
The Act enters enforcement phases in 2025 and 2026. Swedish companies face compliance costs, documentation requirements, risk assessments, and operational constraints that US and Chinese competitors simply do not carry. This is a fact. You can argue the Act is morally correct. You can argue it protects citizens. Fine. But if you impose costs on your own companies and then provide zero strategic air cover, zero fast-track AI procurement from the state, zero public sector demand signal, zero infrastructure investment to help companies build compliant systems efficiently, then you are not regulating responsibly. You are handicapping your own team.
The Swedish state cannot even deploy AI in its own procurement workflows. How is it supposed to be a sophisticated buyer of AI systems? How is it supposed to create the demand that helps Swedish AI companies scale domestically before competing internationally? It cannot. So the private sector does what it always does in Sweden: figures it out alone, exports early, and treats the domestic public sector as a lost cause.
This is not healthy. A functioning AI ecosystem needs government as a smart customer, not just a slow regulator.
How this looks from Jönköping vs. San Francisco
I get asked this sometimes. Why Jönköping? Why not Stockholm, or Berlin, or Austin? The answer is simple: location matters less than it ever has, and the cost structure in a mid-size Swedish city lets you build with discipline.
But here is what looks different from Jönköping than from San Francisco. In SF, the government is a customer. The DoD, intelligence agencies, federal health systems. They buy AI. They deploy it. They create massive demand that funds entire ecosystems. In Sweden, the government is a bystander. The kommun IT director wants to adopt AI but has a budget built for maintaining a 2014 server room and a mandate that requires three layers of approval before changing a font on a website.
In China, the state is a co-builder. In the US, the state is a buyer. In Sweden, the state is a PDF. This has consequences.
The Nordic advantage is still real: high trust, educated workforce, strong infrastructure, low corruption, sensible labor laws. If you want to hire an AI developer in Sweden, the talent pool is excellent. The engineering culture is collaborative and pragmatic. But talent without institutional support eventually leaves or builds for someone else's market. We are already seeing this. Swedish AI talent goes to US companies. Swedish startups target US customers first because the domestic public sector is not a viable early adopter.
Where this goes: 2027 and beyond
Let me project forward honestly.
Quantum risk is not a 2035 problem. Harvest-now-decrypt-later attacks are happening today. Health data, citizen records, infrastructure systems. All of it is being collected by adversaries who will decrypt it when quantum hardware matures. Sweden's health data infrastructure, the stuff Dagens Medicin is warning about today, needs post-quantum cryptography migration starting now. Not in the next strategy cycle. Now.
AGI changes the compliance math entirely. The EU AI Act was written for today's AI. Narrow systems. Classifiers. Language models. When capable general systems arrive, and the trajectory points to the late 2020s for meaningful progress, the entire regulatory framework becomes obsolete overnight. European regulators are building a dam for last year's river. The water is about to change direction. Swedish companies need to build with adaptability in mind, not just compliance.
The bifurcation accelerates. Countries that treat AI as strategic infrastructure, the US, China, UAE, Singapore, will pull further ahead. Countries that treat AI as a regulatory problem will fall behind. Sweden sits in a strange middle ground: strong private capability, weak public adoption, heavy regulatory burden. Without a course correction, Sweden becomes an exporter of talent and a consumer of other nations' AI platforms.
The kommun layer breaks first. Swedish municipalities are the operational layer of the welfare state. Healthcare, education, social services, elder care. These are the services that need AI most urgently. They are also the institutions least equipped to adopt it. Within two years, the gap between what these services need and what they can deploy will become a political crisis. Some kommun will have a preventable failure, a data breach, a service collapse, a patient harm event, and the lack of modernization will be the cause. The strategy document will not be a defense.
What to look at
If you are a CTO or technical leader in Sweden right now, here are concrete things worth your attention this week:
Prowler (13.7k stars on GitHub). Open-source cloud security and compliance automation. If you are running workloads in AWS, Azure, or GCP and you are not continuously auditing your security posture, this is where to start. Especially relevant as EU compliance requirements ratchet up. Run it. See what it finds. You will not like the results, but you need them.
CISO Assistant (4k stars). A GRC platform that maps across 130+ frameworks including NIS2, DORA, GDPR, and ISO 27001. If you are a Swedish company trying to manage the compliance matrix without a dedicated GRC team, this is genuinely useful. Open-source. Self-hostable. Covers the frameworks that actually matter in a European context.
immudb (9k stars). An immutable database built on zero-trust principles. Tamperproof data storage with change history. As quantum threats to data integrity grow and regulatory requirements for audit trails intensify, the concept of an immutable data layer becomes less optional. Worth evaluating for health data, financial records, and any system where you need to prove data has not been altered.
Post-quantum cryptography standards. NIST's FIPS 203, 204, and 205 are finalized. If you are building blockchain systems or handling sensitive data, start your migration planning. This is not a drill. The algorithms are ready. The question is whether your organization will migrate proactively or reactively after an incident.
What you should actually do
If you are a CEO or CTO reading this, here is my honest advice:
Do not wait for Swedish public sector to catch up. It will not catch up in time for your business cycle. Build for European compliance but target global markets. The EU AI Act is a cost, so make it a competitive feature. "EU-compliant AI" is a selling point in markets that value data protection.
Start your post-quantum audit this quarter. Identify which systems hold data that will still be sensitive in ten years. Those systems need migration plans now.
If you are a kommun director reading this at 2 AM because you cannot sleep: you are right to be worried. The strategy will not save you. Find a technical partner who speaks plainly. Start with one project. Get a win. Build from there.
And if you are building AI products in Sweden, remember: the talent is here. The engineering culture is strong. The infrastructure works. The government is not going to help you, but it is not going to stop you either. That is the Swedish deal. It has always been the Swedish deal.
I write this from Jönköping on Valborg. Outside, people are lighting bonfires and singing about spring. Inside, the servers are running. The gap between Sweden's potential and Sweden's policy is the bonfire I am most interested in. It is getting bigger. And unlike the one in the park, nobody in government seems to notice the smoke.
Fredrik Brunnberg is the CEO of HEIMLANDR.IO, building AI and software solutions from Jönköping, Sweden. This is the daily HEIMLANDR briefing. If you found this valuable, share it with someone who builds things.
CEO & Writer
CEO of HEIMLANDR.IO. Punk rock tech from Jönköping, Sweden. Building AI systems, blockchain infrastructure, and writing about where this industry is actually heading — no echo chamber, no hype.