Skip to content
A member-service floor seen from above: rows of desks with low dividers, staff working in telephone headsets.

CATCH MORE WITH THE SAME STAFF

Random checks miss hundreds of millions of kronor.

The same number of checks as today, aimed at the cases where the errors are most likely to be. More of them get found. The risk selection and the impact assessment are built as one delivery, so the system survives supervision.

THE COLLISION

Two supervisors. One trap.

The Swedish Unemployment Insurance Inspectorate (Inspektionen för arbetslöshetsförsäkringen, IAF) used its own predictive models to measure what random checks miss, and put the 2024 figure at between 156 and 383 million kronor in undetected incorrect payments.

Its 2025 report is explicit: AI-based risk selection beats random sampling, and the funds should build more automated controls.

What such selection does to the people in it has already been examined and published. In a national agency's model that picked temporary parental benefit cases for investigation, a woman who had made no error was more than 1.7 times as likely to be flagged as a man who had made none. That is the finding of Svenska Dagbladet and Lighthouse Reports, published in November 2024 from data released by the Swedish Social Insurance Inspectorate (Inspektionen för socialförsäkringen, ISF). The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) has since concluded its supervision of that system. Any organisation building similar selection logic now builds it with that finding on the record, and what you test your own model for, before it goes into operation, is your decision to make.

Here is the trap. IAF is right on substance: the control work can get better, and AI is how. But IAF's supervision does not cover data protection. That is IMY's table.

Follow the recommendation without the impact assessment, and the same pattern can arrive in your own selection without anyone having asked the question in time.

That is the work we do: the risk selection and the impact assessment built together, as one delivery, in operation, so the system survives supervision.

PRIVATE ASSOCIATION, PUBLIC DUTIES

Private association, public duties.

In Sweden, an unemployment fund is a private association that exercises public authority: it decides on a statutory benefit, under state supervision, with decisions appealable to court.

Benefits eligibility, including reducing and reclaiming payments, sits on the high-risk list of the EU AI Act, which is EU law. And the strong legal assessment is that Swedish funds count as private entities providing public services, which carries the fundamental rights impact assessment duty in its own right.

One honesty most advisers skip: case law does not exist yet. We present this as what it is, a strong assessment rather than settled law. Planning on the safe side of it costs little. Discovering the hard way costs a system.

FOR THE UNIONS

The duties your own agreements already contain.

A November 2025 survey by the Swedish trade union Unionen found that only 14 percent of local clubs say the introduction of AI was preceded by co-determination, consultation, or even a discussion.

Yet in Sweden the negotiation duty for new technology already sits in the Development Agreement (Utvecklingsavtalet). You already have standing to be in the room before a system is introduced, and that standing is worth most while the design is still open.

On top of it, the workplace information duty for high-risk AI covers every high-risk system at the workplace and is sanctioned like the other deployer duties. Writing it into your own policy now is what lets a local representative point to a rule the day the question arrives.

And underneath everything: union membership is special-category data by definition, so any AI that touches member records inherits that weight from day one.

The other side of the ledger is the opportunity. Member value scales: advisory and training built once can reach every member. A trade union federation that lifts its elected representatives lifts the whole movement's negotiating position on AI.

TRANSITION ORGANISATIONS

Where the rules are genuinely more open.

For transition organisations the legal picture is less settled, and we say so. Collectively agreed benefits are not automatically the same as public benefits in the rules' eyes, and we will not oversell you a duty that may not exist.

The work there starts from value instead: matching, career analysis and adviser support that make the transition faster for the people in it, built with the data care the assignment deserves.

WHAT TO DO, IN ORDER

What to do, in order.

01

Start with the assessment.

What you run, what the recommendation actually requires of you, and what your members' data demands. In Sweden, no tendering duty applies to your segment, so it starts on a signature, not a procurement.

02

Build controls that survive supervision.

For funds moving toward risk selection: the system and the impact assessment as one delivery, with the documentation and ownership that make it defensible.

03

Write the policy people actually follow.

Member data is sensitive by definition. A workable policy unlocks usage; an unworkable one hides it.

04

Lift the organisation.

Leadership sessions delivered by Ampliro, and role-specific programmes for staff and elected representatives through AIUC, our education arm. Built for effect, not attendance.

PROOF

Delivered inside the partner model.

Our work in this segment includes the AI pre-study and training programme for Trygghetsstiftelsen, and engagements with teams at Almega and Trygghetsfonden TSL. The consultant who leads your engagement is the person who delivered those.

QUESTIONS

Before you build AI-based controls.

No, a recommendation from the Swedish Unemployment Insurance Inspectorate (IAF) to build AI-based controls is not a clearance. IAF supervises unemployment insurance, not data protection, and the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten) is the authority that covers AI processing personal data. IMY has already concluded a supervision of a national agency's case-selection AI, so selection logic of this kind is now built with that finding on the record. The answer is not to ignore the recommendation, but to build the control and the impact assessment at the same time.

The strong assessment is that the high-risk rules reach an unemployment fund, because the fund decides a statutory benefit under state supervision. Benefits eligibility sits on the high-risk list in Annex III of the EU AI Act, with requirements from 2 December 2027. Annex I, meaning AI embedded in products, applies from 2 August 2028. Settled case law does not exist yet, and we say so plainly rather than letting the assessment look like decided law.

A trade union is already touched by the EU AI Act today, even though it is not a public authority. The AI literacy duty in Article 4 and the prohibitions in Article 5 have applied since 2 February 2025, and the penalty provisions in Article 99 since 2 August 2025. The transparency duties in Article 50 apply from 2 August 2026. And the negotiation duty for new technology has long sat in the Development Agreement (Utvecklingsavtalet), entirely independent of the AI Act.

No, the 2 August 2030 outer limit in Article 111.2 of the EU AI Act is given to public bodies and to no one else. A union or an unemployment fund that is not a public authority has no equivalent transitional rule, and instead falls under the relief for high-risk systems left substantially unchanged. This is often confused. New systems follow the ordinary calendar, meaning 2 December 2027 for Annex III and 2 August 2028 for Annex I.

The fundamental rights impact assessment in Article 27 binds two kinds of deployer, and only one of them is public bodies. Public bodies and private actors providing public services are covered for Annex III systems except point 2. Every deployer of creditworthiness assessment of natural persons, or of risk assessment and pricing in life and health insurance, is covered regardless, purely commercial actors included. An unemployment fund deciding a statutory benefit belongs to the first group. The duty applies from 2 December 2027.

A member organisation normally does not have to procure an AI Readiness Assessment. An organisation that is not a contracting authority can buy the assessment directly, so the work starts on a signature rather than on a tender. If you are a public body, the assessment is normally scoped so that it can be bought by direct award. We still write the decision basis so that it holds up under scrutiny in the board.

Ask the question in time.

One conversation settles where you stand: what you run, what the recommendation actually requires of you, and what your members' data demands. If the honest answer is that little applies to you, that is what you will hear. And if your current setup already holds, we will say so.