The EU AI Act in Bulgaria

How Regulation (EU) 2024/1689 applies in Bulgaria, and the 5 AI instruments Bulgaria has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Bulgaria’s own AI instruments

5 records tracked for Bulgaria, beyond the EU-level Act above.

National authority in Bulgaria

Named in Bulgaria’s own records, not inferred.

Per Bulgaria - AI in Education Strategy

Per Bulgaria - AI Regulation Draft (RAI-BG-NA-DAPBPXX-2025)

Per Bulgaria - AI Coordinated Plan (2021)

Per Bulgaria - Digital Transformation Strategy

Per Bulgaria - National AI Strategy

Penalties in Bulgaria

As stated in Bulgaria’s own records.

Per Bulgaria - AI in Education Strategy

  • Temporary suspension of use of a non-compliant AI system in public schools
  • Removal from the Ministry’s approved-providers list and prohibition from public procurement for a defined period
  • Administrative fines and sanctions coordinated with Commission for Personal Data Protection for GDPR breaches
  • Clawback of implementation funding and ineligibility for future public grants
  • Contract termination and claims for damages under procurement and contractual law
  • Public disclosure of enforcement actions and non-compliance reports

Per Bulgaria - AI Regulation Draft (RAI-BG-NA-DAPBPXX-2025)

  • Administrative fines proportional to turnover for serious breaches (aligned with EU maxima in Regulation (EU) 2024/1689)
  • Orders to suspend or withdraw non-conforming AI systems from the market or put into service
  • Corrective measures and mandatory remediation plans enforced by supervisory authorities
  • Public naming and blacklisting for repeat or egregious offenders
  • Civil liability for damages caused by negligent deployment of AI systems and mechanisms for compensatory relief
  • Criminal sanctions for deliberate misuse of AI in contexts that endanger public safety or national security (subject to criminal law procedures)

Per Bulgaria - AI Coordinated Plan (2021)

  • The Coordinated Plan itself does not establish penalties; it is non-binding guidance.
  • Enforcement and penalties relevant to AI use are provided by separate binding instruments (for example, the AI Act and sectoral EU laws), which set out administrative fines, corrective measures and enforcement mechanisms.

Per Bulgaria - Digital Transformation Strategy

  • The Strategy itself does not establish direct administrative fines or criminal penalties; enforcement of obligations stemming from implementation measures is effected under existing sectoral and national laws.
  • Non-compliance with data protection obligations will be subject to GDPR enforcement and fines by the Commission for Personal Data Protection under applicable law.
  • Sectoral regulators (e.g., electronic communications regulator) retain sanctioning powers under their respective legal frameworks for breaches in licensed sectors.
  • Public procurement irregularities arising during Strategy implementation are subject to administrative review, contracting authority sanctions and remedies under procurement law.
  • Where funding conditions are breached, EU and national funding instruments may require recovery of funds or apply financial corrections.

Per Bulgaria - National AI Strategy

  • The Concept itself does not set new administrative or criminal penalties; enforcement of requirements is expected through subsequent regulatory acts and existing legislation (e.g., Data Protection Act/GDPR, sectoral safety rules).
  • Where applicable, existing sanctions (under GDPR and applicable sectoral laws) continue to apply to non‑compliant actors.
  • Future regulatory instruments proposed in the Concept could create new enforcement and penalty mechanisms subject to legislative procedures.

Bulgaria overview

The full picture of AI regulation in Bulgaria, beyond just the EU AI Act.

Bulgaria AI regulation overview →