Skip to content
Back to blog
Sweden's Digital Amnesia: We Wrote the Rulebook, Forgot to Read It
Swedish Tech

Sweden's Digital Amnesia: We Wrote the Rulebook, Forgot to Read It

F
Fredrik BrunnbergCEO & Writer
July 23, 20267 min read

Here is the joke nobody in Brussels or Stockholm wants to say out loud. The country that helped write the world's most ambitious AI rulebook can't get a patient record to move between two hospitals in the same region. Sweden exports governance. Sweden imports dysfunction. Both are true at the same time, and this week gave us three separate proofs of it.

I run an AI development company in Europe out of Jönköping, not Stockholm, not Berlin, not London. That matters for how I see this. From here, the gap between what the state demands of us and what the state can do itself is not theoretical. It shows up in every public sector RFP we look at, every healthcare integration project that stalls on procurement rules written for a world without APIs, every data center conversation where politicians argue about symbolism while missing the actual infrastructure question.

Three Headlines, One Diagnosis

This week, Dagens Medicin reported that Swedish healthcare is falling behind in digital care not because of technology and not because of budget, but because of organization. Read that again. It is not a funding gap. It is not a talent gap. Sweden has the engineers, the money, and the infrastructure. What it does not have is the organizational maturity to deploy any of it coherently across 21 regions that each run their own systems, their own procurement, their own definition of "digital."

The same week, Regeringen rolled out the Digitaliseringsstrategin 2025-2030, a new national digitalization strategy meant to fix exactly this. I want to believe it. I have read enough Swedish government strategies to know the pattern: strong language, weak enforcement, five-year horizon, and a change of government before anyone measures the result.

Then Dala-Demokraten publishes an op-ed arguing Sweden is "erasing its democratic memory," a warning about how fragmented digital record-keeping and inconsistent archiving practices are quietly destroying institutional continuity. And Dagens industri covers the Social Democrats demanding new requirements on data center establishment, a policy response to the reality that Sweden has become one of Europe's preferred data center locations without anyone in government fully deciding what that should cost, environmentally or politically.

Three stories. One diagnosis. Sweden is trying to regulate a digital future it has not operationally caught up to in its own back yard.

The EU AI Act Was Written By People Who Don't Run IT Departments

I am not against the EU AI Act. Somebody had to write rules for this, and better a democratic bloc than a handful of Californian labs deciding unilaterally. But there is a specific kind of arrogance in a government mandating risk classification, conformity assessments, and human oversight requirements for private AI systems while its own hospitals cannot share a discharge summary between two towns twenty kilometers apart.

The AI Act assumes an operating environment of competence. It assumes the entities enforcing it, and often the entities it applies to when public bodies deploy AI themselves, actually understand their own systems well enough to audit them. Dagens Medicin's reporting says otherwise. If a regional healthcare organization cannot manage basic interoperability in 2026, what confidence should we have that it can meaningfully assess whether its own AI triage tool is "high risk" under Article 6, document its risk management system under Article 9, or maintain the technical documentation required under Annex IV?

This is not a Swedish problem alone. The SVT coverage of regional IT failures reads the same as anything coming out of Germany's Gesundheitsamt digitalization mess or the UK's NHS IT graveyard. But Sweden has positioned itself, rhetorically, as a digital leader. That posture is now colliding with a Digitaliseringsstrategin that reads like an admission the last one didn't work.

Nordic Self-Image vs Global Reality

Here is where the Nordic lens actually matters. Sweden has built a global brand on being organized, transparent, technologically fluent. Spotify, Klarna, Northvolt (before it wasn't), the whole "startup nation" narrative. That brand gets Sweden a seat at the table when the EU writes AI policy. Ministers from smaller, less "digitally credible" member states defer to Swedish and Nordic voices on tech governance almost by reflex.

Compare that to how Singapore or Estonia actually operate. Estonia's X-Road system means a citizen's medical, tax, and property records interoperate by design, not by five-year strategy document. Singapore's GovTech function operates like a startup with state authority: fast iteration, centralized data architecture, real accountability for delivery. Neither country lectures the world on AI ethics as loudly as the EU does. Both quietly out-execute Sweden on the actual digital plumbing that AI governance depends on.

The US, meanwhile, has almost no federal AI regulation with teeth, and its healthcare digitalization is arguably worse than Sweden's in different ways, fragmented by insurance systems instead of regional government. But American AI companies do not wait for permission. They ship, they break things, they get sued, they adjust. Sweden's model is the opposite: legislate first, capability second, hope the gap closes itself.

It usually does not close itself. That is the entire lesson of this week's news cycle.

Data Centers: Where Ideology Meets Infrastructure

The Social Democrats' push for new data center establishment requirements, covered by Dagens industri, is the clearest example of regulation chasing a phenomenon nobody planned for. Sweden became attractive to hyperscalers because of cheap, clean electricity and political stability. Now that the electricity is less cheap, the grid is strained, and the political optics of foreign tech giants consuming national power capacity look bad, the response is to add requirements after the fact.

I am not opposed to sensible conditions on data center buildout. Energy grid impact, local employment commitments, environmental review, these are legitimate concerns. But watch the sequencing. Sweden invited the investment, benefited from the jobs and tax base, and is now negotiating the rules retroactively because nobody modeled AI-driven compute demand into energy policy five years ago. That is not governance. That is improvisation dressed as policy.

Every AI workload we run at HEIMLANDR, every AI agent we deploy for a client, depends on compute that lives somewhere physical, on a grid, in a jurisdiction. The politics of where that compute sits is about to become one of the defining questions of the next five years, and Sweden is currently making that decision reactively instead of strategically.

Where This Actually Goes

Extend this two to five years and the contradiction gets sharper, not softer. As AI systems get closer to genuine autonomous capability, the EU AI Act's tiering system (minimal risk, limited risk, high risk, unacceptable risk) will need constant reinterpretation. Nobody wrote that framework with agentic AI systems in mind, systems that chain decisions, act on real-world APIs, and modify their own behavior based on outcomes. The Act's current text already looks dated against what agent frameworks can do in mid-2026.

Now overlay that on a Swedish state that still cannot standardize patient records across regions. When AI systems start making higher-stakes decisions in healthcare, social services, and infrastructure management, the entities responsible for oversight will be the same regional bodies Dagens Medicin says are organizationally behind today. Nobody solves an organizational maturity problem by adding an AI compliance layer on top of it. You cannot GRC your way out of dysfunction.

The honest path toward anything resembling AGI-adjacent capability requires infrastructure Sweden has not built: unified data governance, interoperable public systems, energy planning that treats compute demand as a first-order variable, not an afterthought. The countries that get this right will not be the ones with the strictest rulebook. They will be the ones whose operational base can actually support what the rulebook demands. Right now that is not obviously Sweden, and it is not obviously the EU as a bloc either. It might end up being Denmark, might end up being Singapore, might end up being a US state that decides to actually build state-level AI infrastructure competently.

What To Look At

If you are a founder or a public sector CTO trying to actually solve interoperability, auditability, and compliance instead of just talking about it, a few tools worth your attention this week:

  • CISO Assistant, an open source GRC platform mapping to ISO 27001, NIST CSF, GDPR, NIS2, DORA, and more. If your organization is going to be audited under the AI Act's documentation requirements, you need something like this before the audit, not during it.
  • immudb, an immutable, tamperproof database built for zero trust environments. Sweden's "erasing democratic memory" problem is partly a data integrity and audit trail problem. This is the kind of infrastructure that actually prevents record loss instead of writing a strategy document about preventing record loss.
  • Lynis and Prowler, security auditing and cloud compliance tools that automate what most regional IT departments are still doing manually, or not doing at all. If you are procuring AI systems for public sector use, ask your vendor if they run something like this. If they don't have an answer, that tells you what you need to know.

What To Actually Do About It

If you run a company in Sweden or anywhere in the EU building AI products, do not wait for the state to model good behavior before you adopt it yourself. Build your own compliance and audit infrastructure now, treat data integrity as a product feature, not a legal afterthought, and assume regulators will eventually catch up to standards you should already be meeting.

If you are a founder wondering whether to build here, the answer is yes, but with clear eyes. Software development in Sweden benefits from real engineering talent, low corruption, and a functioning legal system. It does not benefit from fast public sector decision-making. Build your product for the market you're targeting, use Sweden for the talent and the trust signal, and do not expect the government's digital infrastructure to move at your speed.

We built HEIMLANDR as a punk rock tech company in Jönköping specifically because we didn't want to wait for permission from Stockholm bureaucracy or Brussels committees to build things that work. If you want to hire an AI developer in Sweden who understands both the opportunity and the mess, that's the entire premise of what we do, whether it's AI solutions, rapid MVP builds, or full fullstack development for regulated industries that need to move faster than the regulator.

The gap between Sweden's regulatory ambition and its operational reality is not going to close by itself, and it is not going to close because of a new five-year strategy document. It closes when builders stop waiting and start shipping systems that are more disciplined than the rules require, not less. That is the only version of "compliance" that actually protects anyone. Everything else is theater with better branding.

Fredrik Brunnberg is the CEO of HEIMLANDR.IO, building AI and software solutions from Jönköping, Sweden. This is the daily HEIMLANDR briefing. If you found this valuable, share it with someone who builds things.

#EU AI Act#Swedish healthcare#digitalization strategy#AI governance#Nordic tech policy#data centers Sweden#AI development company Europe
F
Fredrik Brunnberg

CEO & Writer

CEO of HEIMLANDR.IO. Punk rock tech from Jönköping, Sweden. Building AI systems, blockchain infrastructure, and writing about where this industry is actually heading — no echo chamber, no hype.