The EU AI Act in Austria

How Regulation (EU) 2024/1689 applies in Austria, and the 12 AI instruments Austria has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Austria’s own AI instruments

12 records tracked for Austria, beyond the EU-level Act above.

National authority in Austria

Named in Austria’s own records, not inferred.

Per Austria - AI Implementation Plan

Per Austria - Digital Sovereignty Measures (2025)

Per Austria - AI Service Office (BGBl. I Nr. 6/2024)

Per Austria - Data Strategy

Per Austria - Information Access Law (BGBl. I Nr. 5/2024)

Per Austria - AI Advisory Board

Per Austria - AI Measures Package

Per Austria - Digital Competence Initiative

Per Austria - Digital Decade Strategy

Per Austria - Public Sector Digital Transformation

Per Austria - AI for Climate Action

Per Austria - National AI Strategy

Penalties in Austria

As stated in Austria’s own records.

Per Austria - AI Implementation Plan

  • The Plan itself is a policy instrument and does not impose new fines; enforcement for AI systems is expected to follow the EU AI Act and its national transposition, including administrative fines and measures where provided by law.
  • Breach of contractual or funding conditions tied to Plan measures may lead to contractual remedies, grant recovery or eligibility consequences.
  • Non‑compliance with sectoral legal obligations (data protection, safety, procurement) remains subject to existing national regulatory and judicial sanctions.

Per Austria - Digital Sovereignty Measures (2025)

  • Procurement remedies and sanctions under BVergG for breaches of procurement rules
  • Contractual remedies including termination and financial recovery for non‑compliant funded projects
  • Managerial/administrative accountability measures for failure to report or implement required actions
  • Standard statutory liability under data protection and other substantive laws for breaches (e.g., GDPR enforcement action by the Data Protection Authority)

Per Austria - AI Service Office (BGBl. I Nr. 6/2024)

  • The KI-Servicestelle itself does not levy sanctions; enforcement and fines for AI Act breaches are exercised by national competent authorities and follow AI Act provisions (e.g., administrative fines up to EUR 35 million or 7% of global turnover for the most serious infringements). See RTR guidance on sanctions: <a href="https://www.rtr.at/rtr/service/ki-servicestelle/ai-act/Sanktionen.de.html">RTR — AI Act: Sanktionen</a>.
  • Non-compliance with AI Act obligations can lead to administrative fines, corrective orders, or market withdrawal obligations enforced by designated authorities.
  • Other national penalties or civil liability may follow from related domestic law (e.g., data protection breaches under GDPR may trigger supervisory fines and civil claims).

Per Austria - Data Strategy

  • The Strategy itself does not prescribe criminal penalties, but non-compliance with data protection obligations (GDPR) or sectoral law remains enforceable under existing legislation.
  • Future implementing laws (for example the national Data Access Act) may include administrative sanctions, supervisory measures and penalties for breaches of statutory access or interoperability duties.
  • Organisations misusing protected public data or failing to comply with conditions for access may face contractual, administrative or judicial remedies under applicable rules.

Per Austria - Information Access Law (BGBl. I Nr. 5/2024)

  • No specific administrative fines for failure to publish or to answer are set out in the IFG itself; enforcement primarily relies on administrative remedies and judicial review (request for Bescheid and appeal to administrative courts).
  • Criminal liability for unlawful disclosure by officials remains in a revised provision in the Criminal Code (§ 310 StGB: 'violation of a duty to maintain secrecy'), with penalties up to imprisonment in defined circumstances. (<a href="https://www.ris.bka.gv.at/Dokumente/Bundesnormen/NOR40270789/NOR40270789.html">RIS: § 310 StGB</a>)
  • Judicial orders by administrative courts can require that access be granted and specify the extent of disclosure; non‑compliance with court orders can lead to further legal consequences under administrative procedure rules.
  • Potential civil claims for damages where unlawful non‑disclosure causes loss, subject to general tort and administrative liability rules.
  • Reputational, oversight and corrective measures by supervisory bodies (including the DSB in relation to personal data aspects) and possible internal disciplinary measures for public servants where relevant.

Per Austria - AI Advisory Board

  • The KI‑Beirat is an advisory body and imposes no direct penalties; enforcement and administrative penalties for non‑compliance with applicable statutory obligations (e.g., under the EU AI Act, data protection law, telecoms/media regulation) are imposed by the competent authorities under their respective legal frameworks.
  • Failure by public authorities to consult required oversight organs where mandated (e.g., KommAustria in media matters) could trigger administrative review under national oversight rules.

Per Austria - AI Measures Package

  • The measures package prepares Austria for enforcement under the EU AI Act; expected administrative fines will follow the EU-tiered system for serious breaches once applicable.
  • National administrative measures, including orders to remedy and market surveillance actions, may be imposed by the relevant authority once operational.
  • Civil liability for damages remains subject to existing Austrian civil law and any supplementary EU liability rules adopted in relation to AI.
  • Reputational and practical sanctions (procurement/ineligibility) may apply for public contracts if transparency and compliance obligations are not met.

Per Austria - Digital Competence Initiative

  • Recovery of misused or improperly reported public funds under standard public funding rules.
  • Suspension or termination of funding contracts for non‑performance or breach of contractual obligations.
  • Administrative audits and follow‑up measures where reporting or compliance deficits are identified.
  • Denial of accreditation for providers that fail to meet mapping, quality or data protection requirements.

Per Austria - Digital Decade Strategy

  • The roadmap itself does not establish new criminal sanctions; non-compliance is managed through administrative and funding mechanisms.
  • Failure to deliver assigned measures may lead to reallocation of national programme funds or reduced priority for discretionary funding.
  • Where implementation requires statutory or regulatory steps, existing enforcement mechanisms under sectoral law (e.g., data protection authority, regulatory agencies) remain applicable.
  • EU-level corrective recommendations may follow from the State of the Digital Decade assessments if national trajectories fall short.

Per Austria - Public Sector Digital Transformation

  • The DAA is a strategic administrative programme and does not itself create new criminal sanctions; statutory penalties under existing laws (e.g., GDPR fines enforced by the Austrian Data Protection Authority) remain applicable.
  • Administrative consequences for non-implementation include corrective instructions, internal audits, withholding or reprioritisation of budgetary allocations, and reputational accountability through mandatory reporting.
  • Remedies and sanctions for legal violations arising from DAA-related projects (e.g., procurement irregularities, data-protection breaches) are pursued under applicable sectoral and administrative law.

Per Austria - AI for Climate Action

  • Reduction or recovery (clawback) of grant funds for ineligible costs or misuse of funds.
  • Suspension of payments pending corrective actions or audit outcomes.
  • Termination of funding agreement in case of serious contractual breaches.
  • Debarment or exclusion from future public funding in cases of fraud or repeated non-compliance.
  • Obligation to repay funds with interest if material misrepresentations are discovered.

Per Austria - National AI Strategy

  • AIM AT 2030 itself does not impose penalties — enforcement and penalties will derive from applicable sectoral and EU legislation (e.g., GDPR enforcement fines; future AI Act administrative sanctions)
  • Non‑compliance with existing sectoral safety rules (e.g., transport, medical devices) remains subject to existing enforcement regimes and penalties
  • Any conformity assessment or registration obligations enacted to implement the EU AI Act will include administrative sanctions as provided by that regulation

Austria overview

The full picture of AI regulation in Austria, beyond just the EU AI Act.

Austria AI regulation overview →