Clear Rules, More AI Use: Why Nordic Workplaces Struggle with AI Governance

Finnish organisations have closed the AI guideline gap faster than their Nordic neighbours, yet governance still trails everyday use. Recent Nordic data suggests that clear rules do not slow AI adoption down – they speed it up. The problem is not the rules but rules without owners, skills or a strategy behind them.

Martti Asikainen | 23.9.2026 | Photo created with Gemini AI

An illustration in a graphic, high-contrast comic style showing a corporate leader with sharp features, dark hair, and a yellow tie standing at a desk. He is holding his hand to his head in a facepalm gesture of frustration, looking toward a large glass wall. Beyond the glass, a busy open-plan office is filled with employees typing intently on their laptops. The foreground desk features scattered crumpled papers and a marker. Photo created with Gemini AI.

In one year, the share of Finnish knowledge workers who say their employer has no AI guidelines fell from 21 to 7 per cent. Over the same period, the share who always follow those guidelines rose from 58 to 68 per cent (Solita 2026a).

By Nordic standards, that is fast progress. In the same Kantar survey of over 3,000 knowledge workers, commissioned by Solita, only 14 per cent of Swedish and 10 per cent of Danish employees still reported having no internal AI guidelines at all.

On paper, Finland has largely solved the problem. In practice, it has solved the easier half of it. Having a guideline is not the same as having one that works, and the gap between the two seems to be the point where most AI governance fails.

Do Rules Really Slow Us Down?

Many business leaders still treat AI guidelines as a handbrake: necessary for compliance, harmful for momentum. The Nordic data points the other way. Denmark combines the region’s highest guideline compliance, at 71 per cent, with its highest AI use: 65 per cent use generative AI at work and 24 per cent do so daily.

In Finland the equivalent figures are 62 and 17 per cent, and in Sweden 53 and 14 per cent (Solita 2026a). Solita’s Rebecca Hammel calls this the most common misconception among leaders, arguing that it is the lack of clarity, not the guidelines themselves, that holds people back (Solita 2026b).

Of course, there is one caveat. This is a cross-sectional survey, and it shows an association, not a cause. Organisations that use AI heavily may simply write rules because they need them. But the explanation makes sense, and it matches what we see in the field. 

In my work as an AI trainer, the question I have heard most often in Finnish workshops is not how to write a better prompt. The question is whether I’m actually allowed to do this. People who don’t know where the line is either stay well back from it or cross it without telling anyone.

Why Is Governance So Hard?

But why is governance so hard to get right? The first reason is speed. In FAIR’s own survey of Finnish companies already using AI, 85 per cent of active users had started within the last three years (FAIR 2026). Most governance structures were built for IT procurement cycles measured in years, not for tools that employees can adopt over a lunch break.

The second is knowledge. The same survey found that GDPR was rated as moderately or well understood by almost all respondents, scoring 4.15 out of 5, whereas only around one in four were familiar with the EU AI Act. Organisations are writing AI rules with a regulatory map that is, for most of them, largely blank.

The third is ownership. Deloitte’s Nordic data shows that strategic preparedness fell from 61 to 43 per cent and talent preparedness from 33 to just 14 per cent, even as three in four Nordic organisations planned to substantially increase AI investment. Meanwhile, only 20 per cent of Nordic organisations have made anyone responsible for measuring whether AI initiatives deliver value, against 32 per cent globally. (Deloitte 2026; Asikainen 2026c)

Tools faster than rules

It’s time to face the fact that access is spreading fast. According to Deloitte, the share of organisations where at least 40 per cent of staff can use approved AI tools rose from 37 to 56 per cent in a year. Yet only 16 per cent report extensive redesign of work around the technology (Deloitte 2026; Asikainen 2026b).

Taken together with everything above, these figures do not describe careless employees. They describe tools arriving faster than the rules, skills and roles that should come with them. When management provides neither, people fill the gap themselves.

KPMG found that roughly half of employees use AI without permission and 44 per cent knowingly bypass company guidelines, while only 26 per cent of Finns feel their AI skills are sufficient (KPMG 2025; Asikainen 2026a). The question is never why one person reached for a personal account. It is what made that the easiest option.

Nordic working culture plays a part too. Deloitte notes that strong labour protections, high union membership and a tradition of social dialogue mean that Nordic companies tend to negotiate significant workplace changes rather than impose them, which slows change but may reduce resistance (Deloitte 2026; Asikainen 2026b). Consensus takes time, and AI tools do not wait for the minutes to be approved.

Guidelines exist, guidance doesn’t

Finland’s seven per cent figure is a real improvement. But when we look at the rest of the breakdown a different picture appears. According to the survey, only 13 per cent of Finnish respondents follow their employer’s guidelines only sometimes, and 11 per cent don’t know whether any guidelines exist at all (Solita 2026a).

For one in ten employees, the rules might as well not be there. In my work with organisations, I’ve noticed that many guidelines list forbidden tools, add a clause about sensitive data, and that’s about it. It stops there. In other words, employees learn what they may not do and remain unsure about everything else.

At the same time, the regulation has also changed in a way that could tempt organisations to relax. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It rewrote Article 4 so that providers and deployers must take measures to support the development of AI literacy, without having to guarantee any specific level of literacy for any individual. Also, high-risk obligations for stand-alone systems have been pushed back to 2 December 2027.

Reading this as permission to wait would be a mistake. An obligation of effort can only be shown through the measures actually taken, which makes documentation more important, not less. In Finland, the Act on the Supervision of Certain AI Systems (1377/2025) took effect at the start of 2026, spreading oversight across 15 authorities, with Traficom acting as the national coordinator (Traficom 2026). And the business case for clear guidance never depended on the regulator anyway.

Making the rules worth following

In my experience, people yearn for clarity. Organisations should write permissions, not only prohibitions. A simple green, amber and red model with concrete, role-specific examples (“summarising public tender documents: green; pasting customer contracts into a personal account: red”) answers the question employees are actually asking.

It’s equally important to name an owner and equip managers. Someone must be accountable for keeping the guidelines current and for asking whether AI is delivering value. A document without an owner goes out of date within months. Solita’s report makes a related point: managers should be trained to explain the rules, not merely pass them on (Solita 2026a).

As in any organisational change, it’s important to ask the people already using AI. Employees working through unofficial channels have already found out where AI helps and where it fails. They are not the problem to be managed, but the most direct route to a realistic policy which delivers (Asikainen 2026c). The approved route should be easy route. If the approved tool is slower or clumsier than a personal account, in the end no guideline will compete with it, because we are all stressed out and busy with our daily work.

I would put my money on the Nordic tradition. The same habit of workplace negotiation that slows change can also make AI rules more legitimate. Involving shop stewards and staff representatives takes longer on paper, but in my experience, rules people helped shape are more likely to be followed, because they feel ownership of them.

It’s also important to document the actions. Record who received what guidance and training, and when. Under the amended Article 4, the effort is the evidence.

Found, understood and followed

Finland’s progress shows that this is not a problem that takes years to solve. Solita’s data suggests it can change quickly once it is prioritised (Solita 2026a). Whether a guideline exists is the easiest part. What matters is whether an employee under deadline pressure can find it, understand it, and trust it more than the AI app on their own browser.

The argument that AI guidelines slow organisations down misses the more important question: what is the lack of clear guidance already costing? For organisations unsure where to start, free services such as Finnish AI Region (FAIR) can help map current AI use and build guidelines people will actually follow.

Author

Martti Asikainen

Communications Lead, AI Coach
Finnish AI Region
martti.asikainen@haaga-helia.fi

This article was written as part of the ReiluAI – AI and Equity in Work Communities project, funded by Haaga-Helia University of Applied Sciences and the Finnish Work Environment Fund.

References

Asikainen, M. (2026a, February 13). Good Intentions, Bad Consequences: Your Employees Are Probably Using AI in Secret. Finnish AI Region.

Asikainen, M. (2026b, March 25). Nordic workers gain rapid access to AI tools, but fear of mass job losses remains low, survey finds. Finnish AI Region.

Asikainen, M. (2026c, April 15). The Problem Is the AI Strategy — Or Rather, the Lack of One. Finnish AI Region.

Deloitte. (2026). State of AI in the Nordics 2026. Deloitte AI Institute.

European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union.

European Union. (2026). Regulation (EU) 2026/1744 (Digital Omnibus on AI). Official Journal of the European Union, 24 July 2026.

FAIR. (2026). AI Implementation in Finnish Businesses 2026. Finnish AI Region & Haaga-Helia University of Applied Sciences. Survey conducted by Taloustutkimus, 3 December 2025–3 February 2026.

KPMG. (2025). Trust, attitudes and use of artificial intelligence: A global study 2025. KPMG International & The University of Melbourne.

Solita. (2026a). How AI is transforming Nordic work life 2026. Survey conducted by Kantar Media, 30 October–11 November 2025.

Solita. (2026b, June 18). Nordic workplaces struggle with AI guidelines and governance. Solita.

Traficom. (2026). Uudet säännöt vahvistavat luottamusta tekoälyyn Euroopassa. Finnish Transport and Communications Agency.

White logo of Finnish AI Region (FAIR EDIH). In is written FAIR - FINNISH AI REGION, EDIH
Euroopan unionin osarahoittama logo

Finnish AI Region
2022-2025.
Medialle