What the protective security analysis must say about AI tools
The content requirement is not in the Act. The ordinance says what the analysis must identify, the agency regulations list the steps, and which regulation applies depends on who supervises you.

Key insights
- The Swedish protective security analysis is governed at three levels. The Act requires it, the ordinance says what it must identify, and agency regulations list the steps it must contain.
- PMFS 2022:1 applies to every operator except those within the supervisory areas of the Armed Forces and FMV. Within those areas only the records check provisions in its chapter 1, section 2 apply.
- Under PMFS 2022:1 chapter 2, section 10 the operator's most senior executive must adopt the analysis, and section 11 requires it to be handed to the supervisory authority on request.
- The ordinance requires updating when needed and at least every two years. AI features arrive faster than that, which makes the words when needed the governing ones.
- The protective security agreement duty in chapter 4, section 1 is triggered by access at konfidentiell or higher. The transfer duties in sections 13 to 15 have no such threshold.
The assumption that AI is banned in security-sensitive work does not hold, and that question has been answered. The question that comes straight after is the harder one: what, then, should the protective security analysis say?
The answer is more specific than most expect. This is Swedish national law and not EU law, so the levels described below are Sweden's own, and the answer sits at a level most readers never open. Which text applies to you depends on which authority supervises your activity.
The analysis is governed at three levels
The Swedish Protective Security Act (säkerhetsskyddslagen, SFS 2018:585), chapter 2 section 1, says that anyone who conducts security-sensitive activities, in whole or in part, must investigate the need for protective security, that the investigation is called a protective security analysis (säkerhetsskyddsanalys), and that it must be documented. The same section then ties everything else to it: taking the analysis as the starting point, the operator must plan and take the protective security measures needed. What the analysis must contain, the Act says nothing about.
The next level fills that in. Under chapter 2 section 1 of the Protective Security Ordinance (säkerhetsskyddsförordningen, SFS 2021:955), the analysis must identify which security-classified information and which other security-sensitive activity exists in the organisation, and which threats and vulnerabilities attach to those assets. It must contain an assessment of which protective security measures are necessary, and it must be updated when needed and at least every two years.
The third level is the one that carries the concrete answer. The Swedish Security Service (Säkerhetspolisen) writes that protective security is regulated in the Protective Security Act and the Protective Security Ordinance, and in regulations from various authorities, among them the Security Service. The words among them are the whole point, and they are also where most readers move too fast.
Which regulation applies is the first question
The Security Service's regulations on protective security, PMFS 2022:1, state in chapter 2 section 1 that the operator must produce a protective security analysis containing the steps set out in sections 2 to 9. Seven of them fall on the operator: a description of the activity and which parts of it are of importance for Sweden's security, identification of the assets, an assessment of them in terms of confidentiality, integrity and availability, a division into consequence levels, the security threats, the vulnerabilities, and last the assessment of necessary measures. One of the eight steps falls not on the operator but on the Security Service, which between the security threats and the vulnerabilities supplies descriptions of dimensioning antagonistic capabilities.
Then comes the provision that decides whether any of this applies to the reader at all. Under chapter 1 section 2 of the same regulations, for the Swedish Armed Forces (Försvarsmakten) and the Swedish Defence Materiel Administration (Försvarets materielverk, FMV), and for operators within their supervisory areas, only the provisions on the procedure for records checks (registerkontroll) in chapter 6 sections 7 to 15 apply.
Whoever falls under the Armed Forces' supervision reads the Armed Forces' own regulations on protective security, FFS 2025:3, instead. The authority states that its rules cover agencies and activities that form part of Swedish total defence, the agencies it has supervisory responsibility for, and all activity within the defence industry.
So before a single sentence about AI is written into the analysis, another question has to be settled: which authority supervises this activity. The answer decides which text lists the steps.
Where an AI tool belongs among the steps
The rest of this section assumes PMFS 2022:1, that is, every operator except those within the supervisory areas of the Armed Forces and the Defence Materiel Administration.
Most analyses that mention AI at all mention it in the last step, among the measures. The tool is described as a technical choice, usually with one sentence about which services are approved and which are not.
That is not wrong. It is late.
An AI tool rarely changes what is secret, but often where the secret passes.
An AI tool touches two steps further up. It touches the identification of the assets, if the tool itself becomes a system of importance for Sweden's security. And it touches the vulnerabilities, if it opens a new route in to assets that are already identified. The difference shows in two cases that look identical on a requirements list: a summarisation feature inside a case management system already approved for its security classification opens no new route, while the same feature in a system that passes the text on to a model held by an external supplier does.
Two provisions further down the chapter tend to be read as formalities. Under chapter 2 section 10, the operator's most senior executive or equivalent body must adopt the protective security analysis, and under section 11 it must be handed, on request, to the supervisory authority and to the Security Service.
Those two meet a third thing. The risks in relation to AI development are, in the Security Service's assessment, a business risk and a management question and not only a technical risk. The authority's assessment and the formal requirements in the regulations therefore point at the same desk: what is written into the analysis about AI is something the most senior executive signs, and something a supervisory authority can call in.
Three instruments, not one
In its text on the effect of AI models on cyber security, published on 24 June 2026, the Security Service writes that developments in the AI field make it important to work actively with the protective security analysis, the measures in the protective security plan, and specific protective security assessments.
That is the most useful sentence in the whole body of material, because it separates three things that get mixed together in practice.
The analysis is the frame. The protective security plan sets out, in the Security Service's description, how the need for the protective security measures identified in the analysis is met, when the measures are to be taken, and which function is responsible for them. The specific protective security assessment is something other than both, and it belongs not to chapter 2 but to chapter 4.
When the AI tool is also a procedure
An operator intending to carry out a procurement, enter into an agreement, or begin a collaboration with another party must conclude a protective security agreement with that party, if the party may gain access through the procedure to security-classified information in the classification konfidentiell (confidential) or higher, or to other security-sensitive activity of corresponding importance for Sweden's security. The agreement must be in place before access is given.
Before such a procedure begins, the operator must also identify, through a specific protective security assessment, which security-classified information or which other security-sensitive activity the counterparty may gain access to. The assessment is followed by a suitability review, and both must be documented. A procedure judged unsuitable may not be started. Where it concerns information in the classification hemlig (secret) or higher, the supervisory authority must also be consulted before the procedure starts.
An AI tool that is bought in can be such a procedure. That is hard to take in, because the purchase rarely feels like one. Nobody moves a function out of the building. Somebody activates a licence.
The threshold, however, belongs to particular provisions and not to the chapter as a whole. It is the protective security agreement duty in chapter 4 section 1 that is triggered by access at konfidentiell or higher. The duty in sections 13 to 15, to make a specific protective security assessment and a suitability review and to consult ahead of a transfer of the security-sensitive activity or of property of importance for Sweden's security, has no such threshold at all.
The notification duty that starts at the turn of the year
Chapter 4 section 1 a of the Protective Security Act was introduced by SFS 2026:764, which builds on government bill 2025/26:182. The amendments entered into force on 1 July 2026.
The new section catches precisely the space that otherwise falls between the cracks. It covers procurements, agreements and collaborations that are ongoing, where the counterparty may gain access at konfidentiell or higher, and which are not covered by the protective security agreement duty. Such procedures must be notified to the supervisory authority without delay. The Security Service states that the duty is to be discharged from 1 January 2027. That a failure to notify may lead to a sanction fee follows from chapter 7 of the Protective Security Act in its wording from 1 July 2026.
The form of the notification is regulated too. Through PMFS 2026:16, in force on 1 July 2026, the Security Service prescribes that notification is to be made in the manner the supervisory authority directs.
The duty points first of all backwards, at what is already running. An organisation that does not know which of its existing agreements give a counterparty that access has until the turn of the year to find out.
The pull against our own conclusion
Here is an objection that carries weight.
If the steps are already listed in the regulations, and the analysis is to be updated at least every two years anyway, why would AI require any particular attention? The rules are written technology-neutral on purpose, and an analysis done properly catches a new feature the same way it catches new premises or a new employee.
The two-year limit is a floor and not a cadence, and that difference is what the question hangs on.
The objection holds so far as no new requirement on the content of the analysis has arrived. What has changed is the distance between the two phrases in the same provision. When needed and at least every two years was a reasonable construction while the assets moved at the pace of organisational change. AI features arrive inside software that is already installed, without a purchasing decision being taken and without a supplier being changed. Anyone who reads every two years as a cadence will fall behind, and anyone who reads when needed as the governing phrase needs to know what a need looks like.
That answer does not belong in the analysis. It belongs in the protective security plan, which is where the measures acquire an owner and a date.
The two questions that decide what applies
Before any of this can be applied, two questions have to be answered, and most readers skip the first.
Which authority supervises the activity, and therefore which regulation lists the steps? For the Armed Forces, the Defence Materiel Administration and operators within their supervisory areas, the Armed Forces' regulations apply. For every other operator the answer is PMFS 2022:1 chapter 2, whichever authority supervises them.
Can anyone outside the organisation gain access through the tool, and if so to information in which security classification? If the answer is konfidentiell or higher, chapter 4 section 1 applies: a protective security agreement, preceded by a specific protective security assessment and a suitability review, consultation at hemlig or higher, and for ongoing procedures outside the agreement duty a notification under section 1 a from 1 January 2027. If the answer is that nobody outside gains access, or that the access sits below that level, chapter 2 applies: the steps of the analysis, the protective security plan, and the review of separation requirements that the classification calls for.
A third body of rules points its own way and is worth holding apart from both. Article 2(3) of the EU AI Act consists of three sentences, and the one that applies here exempts AI systems where and in so far as they are placed on the market, put into service or used, with or without modification, exclusively for military, defence or national security purposes, regardless of the type of entity carrying out those activities. Two limbs do all the work: the exemption applies where and in so far as the system is used that way, so partially and never for the organisation as a whole, and it applies only where the use is exclusively of that kind. Recital 24 states that a system placed on the market or put into service for an exempted purpose and at the same time for one or more non-exempted purposes, such as civilian or law enforcement purposes, falls within the regulation.
For a defence supplier that is the difference between being exempt and having certain systems exempt. And the exemption says nothing about the Protective Security Act, which is Swedish national law with a scope of its own. A system can sit outside the EU AI Act and fully inside the protective security rules at the same time.
Neither of the two questions can be answered from a supplier list. The first is settled by what the organisation does, the second by which security classifications actually occur in the workflows where the tool is to be used, and that map is rarely finished before somebody asks for it.
How the question is handled at suppliers in the defence sector is described on the page on defence and security.
Common questions
A protective security analysis (säkerhetsskyddsanalys) is the investigation of the need for protective security that chapter 2, section 1 of the Swedish Protective Security Act (säkerhetsskyddslagen, SFS 2018:585) requires of anyone conducting security-sensitive activities, in whole or in part. It must be documented, and measures must be planned taking it as the starting point. What it must contain is set out first in the Protective Security Ordinance (SFS 2021:955) and then in the regulations of the applicable authority.
It depends on which authority supervises the activity. PMFS 2022:1, issued by the Swedish Security Service (Säkerhetspolisen), applies to every operator except those within the supervisory areas of the Swedish Armed Forces (Försvarsmakten) and the Swedish Defence Materiel Administration (Försvarets materielverk, FMV), and its chapter 2 lists the steps. Under chapter 1, section 2 of those same regulations, only the provisions on the procedure for records checks (registerkontroll) in chapter 6, sections 7 to 15 apply within those areas. For operators in those areas the Armed Forces' regulations on protective security, FFS 2025:3, apply instead.
Under chapter 2, section 1 of the Protective Security Ordinance the analysis must be updated when needed and at least every two years. The two-year limit is a floor and not a cadence. When a new AI feature changes where information passes or who can reach it, it is the words when needed that govern, not the calendar.
For an operator under PMFS 2022:1, an AI tool touches three of the steps in chapter 2: the identification of assets, if the tool itself becomes a system of importance for Sweden's security; the vulnerabilities, if it opens a new route in to assets already identified; and the assessment of necessary measures. Most analyses cover the tool only in the last of those. How the measures are then met, when they are to be taken and who is responsible for them belongs to the protective security plan and not to the analysis.
It must be made before a procedure begins that is covered by the protective security agreement duty, that is, when the counterparty may gain access to security-classified information in the classification konfidentiell (confidential) or higher, or to other security-sensitive activity of corresponding importance. Both the assessment and the suitability review that follows must be documented. For a transfer under chapter 4, sections 13 to 15, corresponding duties apply with no classification threshold at all.
A protective security agreement must be concluded if the counterparty may gain access through the procedure to security-classified information in the classification konfidentiell (confidential) or higher, and the agreement must be in place before access is given. What decides the question is therefore not what the service is called, but which information the counterparty may reach.
SFS 2026:764 introduced chapter 4, section 1 a of the Protective Security Act. It covers ongoing procurements, agreements and collaborations where the counterparty may gain access at konfidentiell (confidential) or higher and which are not covered by the protective security agreement duty. The Swedish Security Service states that the duty is to be discharged from 1 January 2027. That failure to notify may lead to a sanction fee follows from chapter 7 of the same Act.
No. The EU AI Act exempts AI systems in Article 2(3) where and in so far as they are placed on the market, put into service or used exclusively for military, defence or national security purposes. The exemption is therefore partial and attaches to the purpose rather than to the organisation, and recital 24 states that systems serving both exempted and non-exempted purposes fall within the regulation. It also says nothing about the Protective Security Act, which is Swedish national law with a scope of its own.
If this lands on your desk, we should talk.
Ampliro Insights
New analysis, roughly weekly.
We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.
We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.