Cybersecurity 2026

FINLAND Law and Practice Contributed by: Rosa Lång, Joona Linner, Toni Tainio and Oliver Lönnblad, Lieke Attorneys Ltd

plain language, and contain at least the contact details of the data protection officer, a description of the likely consequences and the measures taken or proposed to address the breach. Principles of information security-based processing of personal data Certain GDPR obligations and requirements can affect how cybersecurity risk management can be imple - mented. Under the GDPR, processing personal data is allowed only where a legal basis for such processing exists. The most relevant of these for cybersecurity risk management are compliance with legal obliga - tions, public interest and legitimate interest. Further - more, the GDPR includes requirements, for example, to use personal data only for the purpose for which it was collected, to minimise the amount of person - al data collected and the time it is retained, and to ensure the integrity and confidentiality of personal data processed. 6.2 Cybersecurity and AI Legislative Framework AI systems and solutions are regulated in Finland by Regulation (EU) 2024/1689 of the European Parlia - ment and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amend - ing Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (the Artificial Intelli - gence Act, or AI Act). The AI Act entered into force in 2024, and its application starts gradually, with final obligations applicable from August 2027. Risk Management Framework In line with the approach adopted in cybersecurity legislation, the AI Act applies a risk-based regula - tory framework under which the obligations imposed increase in proportion to the level of risk associated with the AI system, as determined by reference to its intended purpose and functionalities. The AI Act requires high-risk AI systems to achieve an appropri - ate level of accuracy, robustness and cybersecurity, and to be designed and developed in a manner that ensures resilience against attempts by unauthorised third parties to exploit system vulnerabilities. In addi - tion to the cybersecurity threats applicable to most

ICT systems, the AI Act requires AI-specific vulner - abilities to be taken into account, including data and model poisoning, model evasion, confidentiality attacks and model flaws. Incident Reporting The AI Act includes an incident reporting scheme that requires providers of high-risk AI systems to report serious incidents to the market surveillance author - ity. The competent market surveillance authority is determined based on the sector of the product into which the AI system is incorporated. The report must be submitted no later than 15 days after the provider has become aware of the incident. However, the more serious the incident, the shorter the expected report - ing timeframe. Supervision and Enforcement Compliance with the AI Act is enforced through the EU market surveillance framework established under Regulation (EU) 2019/1020, as supplemented by the enforcement provisions of the AI Act. In addi - tion, administrative fines of up to EUR15 million or up to 3% of total worldwide annual turnover may be imposed, or, in the case of prohibited AI practices, up to EUR35 million or up to 7% of total worldwide annual turnover, whichever is higher. Furthermore, the supply of incorrect, incomplete or misleading informa - tion is subject to administrative fines of up to EUR7.5 million or up to 1% of total worldwide annual turnover, whichever is higher. Interaction With General Cybersecurity and Data Protection Obligations The AI Act operates alongside and complements other applicable EU regulations. Where an AI system is embedded in a product with digital elements, the cybersecurity requirements of the CRA apply in par - allel, and compliance with the essential cybersecu - rity requirements of the CRA is deemed to satisfy the cybersecurity requirements for high-risk AI systems under the AI Act. Similarly, to the extent that an AI sys - tem processes personal data, the obligations under the GDPR, including requirements for data protection by design, apply concurrently with the obligations under the AI Act.

109 CHAMBERS.COM

Powered by