Skip to content
Tillbaka till bloggen
Sweden Funds AI Cops Before the Rules Even Exist
Svensk Teknik

Sweden Funds AI Cops Before the Rules Even Exist

F
Fredrik BrunnbergVD & Skribent
4 juni 20268 min läsning

We're Hiring Referees for a Game That Hasn't Started

Here's what's happening right now in Sweden. IMY, our privacy watchdog, is getting a budget increase to enforce the EU AI Act. At the same time, the EU just pushed the high-risk system requirements to 2027. The European Commission only now appointed its scientific panel and advisory forum to guide implementation. And in the US, companies are scrambling over a possible August 2026 compliance deadline that may itself shift. So Sweden is staffing up to police rules that don't exist yet, for technology we barely participate in building.

I run a tech company in Jönköping. We build AI solutions and ship software for clients across Europe and beyond. From where I sit, this is not a policy nuance. This is a strategic miscalculation that tells you everything about how Sweden and the EU think about technology.

We are world-class at creating the apparatus of control. We are terrible at creating the thing being controlled.

What IMY's Budget Increase Actually Means

Let me be specific. According to MLex reporting from this month, IMY is set to receive additional funding earmarked for AI Act enforcement duties. This makes Sweden one of the first EU member states to materially invest in regulatory readiness for the AI Act.

On the surface, that sounds responsible. Proactive, even. Sweden front-running the rest of the EU on regulatory preparedness. Classic Nordic governance. We love being the best at rules.

But think about what this means in practice. We are allocating public money to hire people whose job is to oversee AI systems. The AI Act's high-risk provisions won't be enforceable until 2027 at the earliest. The scientific panel that's supposed to define what "high-risk" actually means in practice just got formed. The compliance frameworks are drafts of drafts. Nobody knows what the final requirements look like.

So these new hires at IMY will spend 12 to 18 months doing... what exactly? Building internal processes for rules that haven't been finalized. Attending working groups. Writing position papers. Meanwhile, every month that passes, the actual AI systems they will eventually regulate get more complex, more capable, and more entrenched.

This is the regulatory equivalent of buying furniture for a house that hasn't been designed yet.

The Swedish Paradox: Great at Governing, Bad at Building

Sweden has produced Spotify, Klarna, King, Mojang. We punch well above our weight in software. But when it comes to the foundational AI layer, we are spectators. There is no Swedish foundation model of global relevance. No Nordic equivalent of Mistral, let alone OpenAI or Anthropic or DeepSeek.

This isn't just about bragging rights. Foundation models are the platform layer. Everything else is built on top. If you don't control or meaningfully contribute to that layer, you're a consumer. You're dependent. In geopolitical terms, you're a client state of whoever builds the models you rely on.

France understood this. Mistral exists because French policymakers and investors decided that having a European foundation model mattered. Germany is pushing. The UAE is pushing. Saudi Arabia is pushing. Sweden? We're hiring compliance officers.

As an AI development company in Europe, we at HEIMLANDR see this tension every day. Our clients want to build with AI. They want agents, automation, intelligent systems. We help them do that. But the underlying models, the inference infrastructure, the training data pipelines. Those come from somewhere else. And now we're adding a regulatory layer on top that makes it harder for anyone here to catch up.

The EU's Timing Problem Is Worse Than You Think

The 18-month delay on high-risk system requirements isn't just a scheduling inconvenience. It creates a specific and dangerous dynamic.

Companies building AI products right now face a choice. Build for the current draft requirements and risk having to rebuild when the final rules come. Or wait for clarity and fall behind commercially. Most companies, especially smaller ones, especially Nordic startups, choose a third option: don't build anything ambitious at all. The regulatory uncertainty becomes a tax on ambition.

In the US, the picture is different but equally messy. There's talk of an August 2026 compliance deadline that keeps shifting. American companies are lobbyist-shopping for exemptions. The result is that US firms operate in a looser environment, ship faster, and then deal with regulation after they have market power. Europe does the opposite. We regulate first, then wonder why nobody built anything.

In Asia, it's a different game entirely. China is pushing state-backed foundation models. South Korea and Japan are investing in semiconductor independence. They're not spending their AI budgets on hiring regulators.

Here's the comparison that should keep Swedish policymakers up at night. China has dozens of foundation models in production. The US has the biggest and most capable ones. France has Mistral. Sweden has... a well-funded privacy authority.

What the AI Act Actually Needs (And Isn't Getting)

I'm not against regulation. That's a lazy take, and it's not mine. AI systems that make decisions about people's lives, credit, healthcare, criminal justice, those need oversight. I believe that.

But the AI Act as it's being implemented has three fundamental problems.

First, the timeline is backwards. You need to understand the technology before you regulate it. The EU is doing it the other way around. Hiring enforcers before the rules are done. Appointing scientific panels after the legislative text is already locked.

Second, it's biased toward large incumbents. The compliance burden of the AI Act is substantial. Big companies with legal departments and dedicated compliance teams can absorb it. A 15-person AI startup in Jönköping cannot. This is how you ensure Europe never produces its own OpenAI. Not by banning it, but by making the paperwork so heavy that only companies with $10 billion in revenue can afford to play.

Third, it treats AI as a product category instead of an infrastructure layer. AI is not like medical devices or cars. It's more like electricity or the internet. You don't regulate electricity by classifying every possible appliance that might use it. You set safety standards for the infrastructure and let people build. The AI Act tries to enumerate and classify every possible AI application. That approach doesn't scale and it doesn't adapt.

What Sweden Should Be Doing Instead

Here's what responsible AI policy looks like if you actually want both innovation and safety.

Fund the builders, not just the watchers. For every krona going to IMY's AI enforcement budget, at least five should go to AI research, compute infrastructure, and startup grants for companies building foundational AI technology. WASP (the Wallenberg AI program) is doing good work but it's not enough. We need compute clusters. We need data policy that enables training, not just restricts it.

Create regulatory sandboxes that actually work. Let companies build and test AI systems in controlled environments before the rules are final. Let the regulation learn from reality instead of the other way around. Sweden has talked about this. The execution is slow.

Back European open-source AI. This is where smaller countries can actually compete. You don't need to build GPT-7. You need to support and contribute to open models, open datasets, open tooling. The GitHub ecosystem is full of projects that matter here.

Treat compliance as a product, not a department. At HEIMLANDR, when we build SaaS platforms or AI systems for clients, compliance is a feature we engineer in. It's not a separate process managed by separate people. That mindset difference is everything.

Where This Goes: 2027 and Beyond

Let me paint the trajectory as I see it.

By 2027, when the AI Act's high-risk provisions finally kick in, the models will be two generations ahead of what legislators imagined when they wrote the text. GPT-4 class models were the reference point. By 2027, we'll be looking at systems with genuine agentic capabilities, long-horizon planning, and multi-modal reasoning that makes today's models look like calculators.

The enforcement gap will be enormous. IMY's new hires will be trying to apply 2024 rules to 2027 technology. The scientific panel will be scrambling to issue guidance that's already outdated. And every update cycle for the regulation will take 18 to 24 months because that's how EU legislative machinery works.

On the path toward AGI, or whatever you want to call the next level of capability, the regulatory question isn't "how do we classify these systems." It's "how do we maintain any meaningful oversight at all when the systems evolve faster than our ability to understand them." The AI Act doesn't even begin to address this. It's a snapshot of 2023 thinking being enforced in 2027.

For European tech companies, the strategic play is clear. Build for global markets. Treat EU compliance as a constraint to engineer around, not a ceiling on ambition. And keep your infrastructure flexible because the rules will change, probably multiple times.

For Swedish companies specifically: stop waiting for regulatory clarity. It's not coming. Build, ship, and adapt. That's always been the Swedish tech playbook. Spotify didn't wait for music licensing clarity. Klarna didn't wait for fintech regulation to settle. Don't let the AI Act become the excuse for inaction.

What to Look At

If you're a CTO or founder trying to stay ahead of this, here are some things worth your time.

CISO Assistant is an open-source GRC platform that supports 150+ compliance frameworks including GDPR, NIS2, and SOC 2. When the AI Act requirements do finalize, tools like this will be how you actually manage compliance without drowning in spreadsheets. It does automatic control mapping across frameworks, which is going to be critical when you need to prove AI Act compliance alongside GDPR and NIS2 simultaneously.

Prowler is the most widely used open-source cloud security platform. If you're running AI workloads in the cloud (and you are), automated security auditing isn't optional. The AI Act will have infrastructure security requirements. Getting your cloud posture right now saves pain later.

Comp is positioning itself as an AI-native compliance platform, an open-source alternative to Vanta and Drata. Worth watching as the AI Act requirements crystallize. The companies that treat compliance as software engineering rather than legal departments will move faster.

Baserow is a GDPR-compliant, self-hosted, no-code platform for building databases and automations. For teams that need to prototype AI-adjacent workflows without shipping data to US-based SaaS platforms, this is practical and real.

The Bottom Line from Jönköping

I write this from a tech company in Jönköping, not from a policy think tank in Brussels or a VC office in San Francisco. What I see is this: Sweden is good at building software. We have the engineering talent. We have the infrastructure. We have one of the highest rates of tech adoption in the world.

And we're choosing to spend our AI budget on referees instead of players.

If you're a founder, a CTO, or someone who actually builds things. Don't wait for the regulators to tell you what's allowed. Build the thing. Make it good. Make it safe because you care about the people using it, not because a compliance checklist told you to. And if you need help doing that, if you need to hire AI developers in Sweden who actually ship, you know where to find us.

The countries that win the AI era won't be the ones with the best-funded regulators. They'll be the ones with the best builders. Sweden has the raw ingredients. The question is whether we'll use them, or just keep writing rules about how others should.

Fredrik Brunnberg is the CEO of HEIMLANDR.IO, building AI and software solutions from Jönköping, Sweden. This is the daily HEIMLANDR briefing. If you found this valuable, share it with someone who builds things.

#AI Act#Sweden tech policy#EU regulation#AI development Europe#software development Sweden
F
Fredrik Brunnberg

VD & Skribent

VD för HEIMLANDR.IO. Punk rock-teknik från Jönköping, Sverige. Bygger AI-system, blockchain-infrastruktur och skriver om vart branschen faktiskt är på väg — inget ekokammare, ingen hype.