University-run AI chat services in the Nordics: GPT UiO, ChatUiT, CurreChat, Aalto AI Assistant and Sikt KI-chat
Several Nordic universities do not just license a commercial chatbot: they run their own AI chat service, or use one built by a national sector body. This guide sets out, from the institutions' own pages read on 7 October 2026, who runs each service, which models it offers, where the processing happens and which data you may put into it.
The short answer
- Five services, two kinds of operator. GPT UiO (Oslo), ChatUiT (Tromsø), CurreChat (Helsinki) and the Aalto AI Assistant are run by the universities themselves. Sikt KI-chat is a national service from Sikt, a Norwegian government agency, which institutions sign up to.
- Most route to OpenAI models through Microsoft Azure in Europe, and several also run open-weight models on their own hardware. GPT UiO and Aalto both offer GPT-OSS on university infrastructure.
- The data rules differ more than the technology. ChatUiT is approved up to red data, GPT UiO allows red data only with certain models, Aalto allows confidential data but no special category data, CurreChat excludes confidential data, and OsloMet allows Sikt KI-chat up to yellow data.
- All five say prompts are not used to train models. Retention differs: CurreChat does not save chats automatically, Sikt keeps encrypted chat history for 180 days.
- A university service is not a blank cheque. You still need a legal basis, minimisation and, for sensitive projects, a DPIA.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers an AI assistant for research work with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
The five services at a glance
The table summarises what each institution publishes. "Data allowed" uses each institution's own classification scheme; the colours are not identical across universities, so read the section on each service before comparing.
| Service | Run by | Models (as published) | Where processing happens | Highest data class allowed |
|---|---|---|---|---|
| GPT UiO | University of Oslo | OpenAI GPT-5 family via Azure; GPT-OSS, GLM, Mistral, Kimi, Qwen, Gemma run locally [3] | Azure, European servers only; NTNU; UiO Educloud [2][3] | Red, with marked models only [4] |
| ChatUiT | UiT | Specific models not named on the pages we read (UiT refers to "the GPT model") | Not stated on the pages we read | Red [8] |
| CurreChat | University of Helsinki | OpenAI GPT-4 and GPT-3.5 named on an undated page [11] | Microsoft Azure, EU [11] | Internal; not confidential [10][11] |
| Aalto AI Assistant | Aalto University | GPT 5.1, GPT 5, GPT 4o via Azure; GPT-OSS-120B on-premises [12] | Azure OpenAI, EU area; Aalto on-premises [12] | Confidential; no special category data [12] |
| Sikt KI-chat | Sikt (national agency) | GPT-5.1 and Mistral Large named, among others [13] | Azure OpenAI in Sweden; AWS in Sweden and Ireland for profiles and history [14] | Yellow at OsloMet [15] |
GPT UiO (University of Oslo)
What it is and who runs it
The University of Oslo describes GPT UiO as a UiO-developed service that lets users work with AI models "within the privacy requirements set by UiO" [1]. Students and staff log in with Feide, the Norwegian education login, and the English page says "other partners" can also log in [1]. OsloMet, for example, lists GPT UiO among the AI tools it offers its own staff [15].
Models and where they run
GPT UiO is unusual in how many models it offers, and in how openly it lists where each one runs. On 7 October 2026 UiO's model overview listed [3]:
- Models run at NTNU: GPT-OSS (OpenAI) and GLM 4.7 (Z.ai), both marked for "up to Red data"; Mistral Large 3, Kimi K2.6 (Moonshot AI) and NorwAI Magistral (API only), marked for up to yellow data.
- Models run in UiO's Educloud: Qwen 3.6 (Alibaba Cloud) and Gemma 4 (Google DeepMind), up to yellow data.
- Models on Microsoft Azure: GPT-5 mini, GPT-5.1 Thinking, GPT-5.2 Codex and GPT-5.4 (API only), all up to yellow data.
The Norwegian help page says the Azure integration uses only servers in Europe, that conversations are stored at UiO, that data is not used to train the model further, and that Feide usernames are not visible to the model [2].
Validemic's analysis Note that some of the open-weight models listed come from developers outside the EEA, for example Moonshot AI and Alibaba Cloud. Because UiO runs them on NTNU or UiO hardware, the prompt does not go to those developers. Where a model is hosted matters more for data flows than who trained it.
What data is allowed
UiO uses four classes: green (open), yellow (restricted), red (confidential) and black (strictly confidential). Special categories of personal data, health information and personnel files are listed as red [6]. GPT UiO's terms say which classes can be processed "depends on the model", and the interface shows it [5]. The red data help page adds: "you must choose a model that supports this", and asks users to assess purpose and legal basis concretely, getting help if the legal basis is unclear [4].
The terms also make the user responsible for having "the necessary approvals" for processing personal data, expect users to follow any conditions set by REK (the regional research ethics committees), and tell users not to keep data in the service longer than needed [5].
UiO also runs TSD, its environment for sensitive research data. On 28 September 2026 UiO announced a pilot large language model inside TSD, stating that sensitive data can be processed "without leaving the TSD environment"; projects must switch it on [7].
ChatUiT (UiT The Arctic University of Norway)
UiT describes ChatUiT as its own chatbot, free for all UiT students and employees and reached at chat.uit.no with a UiT username and password [8]. The Nynorsk staff page calls it "UiT sin eigen ChatGPT" (UiT's own ChatGPT) for brainstorming, translation, structuring and proofreading [9].
On data, UiT's English page is short and clear: "ChatUiT is approved for use with green, yellow, and red data" [8]. It also says prompts and data "are not used to train the GPT model further" [8]. The same page reminds users of the GDPR's special categories and tells them not to put such data into Microsoft Copilot or "other tools that are not approved by UiT"; Copilot is limited to green and yellow data at UiT [8].
We did not find the current model names, the hosting provider or the region for ChatUiT on the public pages we read (checked 7 October 2026). UiT also runs Klartekst, a Whisper-based transcription service approved for green, yellow and red data; see our Whisper transcription guide.
CurreChat (University of Helsinki)
CurreChat is "a generative AI tool developed at the University of Helsinki", managed by the university's Educational Technology Services [10]. Staff have access automatically; students mainly use it through course-specific prompts set up by teachers, and token use is limited weekly [10].
The university's general page on generative AI says CurreChat uses GPT-4 and GPT-3.5 models "in the Microsoft Azure cloud environment" and that "CurreChat is located in Microsoft's cloud in the EU" [11]. That page carries no date, so the model list may be out of date. The same page says no identifying information about the user, such as the username, is passed to the language model [11].
Data rules: CurreChat may be used for internal data as well as public data, but "must not be used to process confidential or secret data" [11]. The helpdesk page repeats that confidential or secret information must not be discussed in CurreChat, says conversations are not used for training, and notes: "Conversations are not saved automatically" [10]. Users can export a conversation to a file or email.
Validemic's analysis CurreChat's design choice, no saved history by default and a focus on teaching, gives it a smaller data footprint than services that keep chat history. It also means researchers should not expect it to be cleared for confidential research data.
Aalto AI Assistant (Aalto University)
Aalto describes its assistant as "powered by the same language models as ChatGPT", built by Aalto IT Services with the School of Science research software engineering service, and offered to both staff and students [12]. The page, last updated 30 June 2026, lists GPT 5.1, GPT 5 and GPT 4o through Azure OpenAI, an Aalto.fi chatbot for staff, and GPT-OSS-120B, described as "run fully by Aalto on-premises. No data is sent to external providers." [12]
For the Azure models, Aalto states that Azure OpenAI data is in the EU area and that prompts and outputs are not available to OpenAI or used to improve OpenAI models [12]. Users can choose whether discussions are saved or use a private mode. Aalto covers the costs but asks users to keep them under €30 a month for staff and €5 for students [12].
Aalto's data rule is one of the most permissive on classification and one of the clearest on special category data: "You may use public, internal, and confidential data", but "Secret content is not permitted", and users must not "input special category or otherwise sensitive personal data into the service" [12].
Sikt KI-chat (national, Norway)
What it is
Sikt is the Norwegian government's shared-services agency for education and research, owned by the Ministry of Education and Research [16]. Sikt KI is its AI service for the knowledge sector, from the upper years of compulsory school and upper secondary schools to adult education, universities, university colleges and research institutes, and KI-chat is its chat module [13]. Institutions subscribe and pay a set-up fee, a monthly fee and usage costs. Sikt says a data processing agreement must be signed "before the service is taken into use" (our translation of "Det skal inngås en databehandleravtale før tjenesten tas i bruk") [13].
Models, hosting and retention
Sikt's service page names GPT-5.1 and Mistral Large among the models offered and states: "Språkmodellene kjører på servere i Europa, og data forlater ikke EU" (the language models run on servers in Europe, and data does not leave the EU) [13]. OsloMet's staff page, which describes the service as of November 2025, listed GPT-5, GPT-5 nano and GPT-4o at that time [15].
Sikt's privacy notice is more detailed than most university pages [14]:
- Roles: Sikt is controller for running and administering the service; the customer institution is normally controller for personal data in users' prompts and inputs.
- Sub-processors: Microsoft Azure OpenAI in Sweden for the language models, Azure Speech in an EU region, AWS in Sweden and Ireland for profiles, history and billing logs, and Feide or Entra ID for login.
- Retention: encrypted chat history for 180 days; usage data for three months; admin logs for 12 months.
- Access: Sikt says it has chosen not to have access to users' conversations.
Sikt also states that it does not use what users write in Sikt KI to train the language models [13].
What data is allowed
Sikt's own pages leave the classification decision to each institution. OsloMet, for example, says Sikt KI-chat "can be used to process data and personal data up to and including the yellow (internal) storage level", and that it has signed a data processing agreement and service agreement with Sikt [15]. Other institutions may set a different ceiling.
The sector picture: Sikt, CSC and Sunet
Each Nordic country has a sector body that provides shared IT to universities, and they have taken different approaches to AI.
- Norway: Sikt offers a ready-made chat service (Sikt KI) that institutions can adopt, alongside university-built services such as GPT UiO and ChatUiT [13][16].
- Finland: CSC, a non-profit company owned by the Finnish state and Finnish higher education institutions [17], focuses on research computing. Its Aitta platform hosts curated AI models on the LUMI supercomputer for research and development, with a web interface and an OpenAI-compatible API [18]. The Aitta page does not state whether personal data may be processed and points to a separate privacy notice. Finnish universities, as the Helsinki and Aalto examples show, have built their own chat interfaces.
- Sweden: Sunet, part of the Swedish Research Council, provides networking and shared services to universities [19]. Its AI offering we found is Sunet Scribe, a transcription service run in Sunet's own data centres in Sweden [20]. We did not find a Sunet-wide AI chat service in public documentation (checked 7 October 2026).
Validemic's analysis The pattern is a split between a shared layer (sector bodies providing infrastructure, models or a common service) and an institutional layer (each university deciding which data classes are allowed). A national service does not take away the institution's controller duties, which is why Sikt's privacy notice names the institution as controller for prompt content [14].
Why universities build their own
The institutions' own descriptions point to a few recurring reasons. We list them with what each source actually says, not as a claim about motives.
- Control over data location. GPT UiO limits Azure to European servers and stores conversations at UiO [2]; Sikt says data does not leave the EU [13]; Aalto runs GPT-OSS on-premises [12].
- No training on prompts. All five state that user inputs are not used to train models [2][8][10][12][13].
- Less identity leakage. GPT UiO and CurreChat say usernames are not passed to the model [2][11].
- Rules matched to the institution's classification scheme, so a researcher can tell from the interface which model is cleared for which data [4][5].
- Equal access. Access at no cost to users for students and staff, rather than paid personal subscriptions [8][12].
There are trade-offs. Services under active development may change or be interrupted; Helsinki says so explicitly for CurreChat [10]. Model lists change often, and some public pages lag behind. The university also takes on the work a vendor would otherwise do: security, logging, incident handling and keeping documentation current.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
How to assess a university-run AI service
Whether you are a DPO reviewing your own service, or a researcher deciding which tool to use, the questions are the same as for a commercial vendor, with a few additions.
- Who is controller and who is processor? For an in-house service, the university is controller and the cloud provider behind it (for example Microsoft for Azure OpenAI) is a processor or sub-processor. For a sector service, check the agreement: Sikt splits controllership between itself and the institution [14]. A processor contract must meet Article 28 GDPR, including instructions, security, sub-processor approval and deletion [21].
- Which model, where? Ask per model, not per service. GPT UiO shows that one interface can combine Azure-hosted and locally hosted models with different data ceilings [3].
- What does the provider keep? Chat history, logs, uploaded files and retention periods. Compare CurreChat (no automatic saving) with Sikt (180 days of encrypted history) [10][14].
- Is the data rule written down and specific? The best examples name the classes allowed per model and say what is excluded, as Aalto does for special category data [12].
- Are added features covered? File upload, assistants, API keys and speech features may involve extra sub-processors. Sikt lists Azure Speech separately [14]; GPT UiO has a separate page on using the service with API keys [1].
- Does the use need a DPIA? The EDPB says processing that meets two of its criteria, such as sensitive data, vulnerable data subjects or innovative technology, should in most cases get a DPIA [22]. Run our DPIA screening tool.
- AI Act duties. The university is a deployer. AI literacy measures and the prohibitions already apply; the high-risk rules for education apply from 2 December 2027. See our AI Act guide for universities.
For a wider view of what other European universities approve, see our sourced overview of 35 universities, and for research-specific GDPR questions, our guide for researchers using AI tools.
Sources
All sources retrieved 7 October 2026.
- University of Oslo, GPT UiO.
- University of Oslo, Hva er GPT UiO? (in Norwegian).
- University of Oslo, Which language models are available in GPT UiO?
- University of Oslo, Red (confidential) data in GPT UiO.
- University of Oslo, Terms of Service at GPT UiO, sections 5 and 6.
- University of Oslo, Classification of data and information.
- University of Oslo, TSD LLM: large language models inside TSD, 28 September 2026.
- UiT The Arctic University of Norway, Information about the use of artificial intelligence.
- UiT The Arctic University of Norway, ChatUiT (staff page, in Nynorsk).
- University of Helsinki IT Helpdesk, CurreChat.
- University of Helsinki IT Helpdesk, Generative AI at the University (undated).
- Aalto University, Aalto AI Assistant, updated 30 June 2026.
- Sikt, Sikt KI (in Norwegian).
- Sikt, Personvernerklæring for Sikt KI (privacy notice, in Norwegian).
- OsloMet, AI tools at OsloMet (staff page).
- Sikt, About Sikt.
- CSC, About us.
- CSC, Aitta: run AI models.
- Sunet, Om Sunet (in Swedish).
- Sunet, Sunet Scribe (in Swedish).
- European Data Protection Board, Data controller or data processor (SME data protection guide).
- European Data Protection Board, Be compliant: how to conduct a DPIA (SME data protection guide).
About this page
Sources checked on 7 October 2026. We read each university's and sector body's own service pages, help pages, terms and privacy notices as listed, in English, Norwegian and Swedish. Translations from Norwegian are ours. Model lists and data rules for these services change often, and some pages are undated; check the service itself before relying on a detail. Where we could not find a fact (for example ChatUiT's hosting region), we say so rather than guess. This page describes what institutions publish; it is not an assessment of any service and not legal advice. If you run one of these services and spot an error or an update, please contact us and we will correct it.
Frequently asked questions
What is GPT UiO?
GPT UiO is the University of Oslo's own AI chat service. Students and staff log in with Feide. It offers OpenAI models through Microsoft Azure and open-weight models run at NTNU and in UiO's Educloud. UiO says conversations are not used to train models and that the Azure integration uses only European servers. Some locally run models may be used with red (confidential) data.
Can I put personal data into a university AI chat service?
Often yes, within limits that differ by service. GPT UiO allows red data only with models marked for it. ChatUiT is approved for green, yellow and red data. Aalto allows public, internal and confidential data but no special category data. CurreChat must not be used for confidential or secret data. OsloMet allows Sikt KI-chat up to yellow (internal) data. You still need a legal basis and to minimise what you enter.
Is Sikt KI the same as GPT UiO?
No. Sikt KI is a national service from Sikt, the Norwegian government agency for shared services in education and research, offered to institutions under a data processing agreement. GPT UiO is run by the University of Oslo. Some institutions, such as OsloMet, give their users access to both.
Where does a university AI chat service process data?
It depends on the model you choose. Services that route requests to OpenAI models usually do so through Microsoft Azure in Europe: Sikt names Sweden as the Azure OpenAI region in its privacy notice, and Aalto says its Azure OpenAI data is in the EU area. Open-weight models may run on the university's own servers, as with GPT-OSS at Aalto and at NTNU for GPT UiO.
Why do universities build their own AI chat services?
Their own pages point to control: who can log in, where data is processed, whether prompts are used for training, how long chats are kept, and which data classes may be entered. Running the interface themselves lets universities set those rules and switch models without each user accepting consumer terms.
Does a university-run service remove the need for a DPIA?
No. The service settles some processor and hosting questions, but the use you make of it can still be high risk. If a project combines AI with sensitive data or vulnerable participants, screen it against the EDPB DPIA criteria and talk to your data protection officer.