The EU AI Act in Greece

How Regulation (EU) 2024/1689 applies in Greece, and the 7 AI instruments Greece has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Greece’s own AI instruments

7 records tracked for Greece, beyond the EU-level Act above.

National authority in Greece

Named in Greece’s own records, not inferred.

Per Greece - Data Governance Implementation (5188/2025)

Per Greece - AI Fundamental Rights Supervisors

Per Greece - National AI Strategy

Per Greece - Omnibus Measures (5039/2023)

Per Greece - Digital Governance Framework (4961/2022)

Per Greece - National Digital Strategy (ΦΕΚ 2894/Β/2021)

Per Greece - Digital Governance Code (4727/2020)

Penalties in Greece

As stated in Greece’s own records.

Per Greece - Data Governance Implementation (5188/2025)

  • Administrative fines ranging from €10,000 to €100,000 for breaches of the implementing provisions (imposed after a prior hearing).
  • Warnings and documented corrective measures requiring remedial action within a specified timeframe.
  • Temporary suspension or removal from the national registers (e.g., for data altruism organisations or data intermediation providers).
  • Injunctive measures ordering cessation of non-compliant activity or requiring specific changes to processing/publishing practices.
  • Public publication of enforcement decisions and measures (transparency sanctions).
  • Preservation of rights to seek judicial review and appeals before the competent Administrative Court of Appeal.
  • Potential civil liability under existing national or Union rules, including GDPR-based claims and remedies.

Per Greece - AI Fundamental Rights Supervisors

  • This publication is a designation notice and does not itself impose new fines; enforcement and fines for AI Act non‑compliance are primarily within the remit of the national market surveillance authority as provided by the AI Act.
  • Potential administrative measures under the AI Act available to market surveillance authorities: warnings, orders to bring systems into compliance, temporary or permanent restrictions on placing systems on the market, and fines in accordance with AI Act sanctioning rules.
  • National remedies: affected parties may challenge administrative decisions under national administrative/judicial review procedures.
  • Article 77 authorities may trigger testing and referrals that can lead to market surveillance investigations and consequent sanctions.

Per Greece - National AI Strategy

  • As a strategy document, the Blueprint does not itself prescribe immediate penalties; it anticipates future legislation to introduce administrative fines and enforcement measures consistent with EU norms.
  • Future supervisory authority (recommended) to have powers to require corrective actions, impose administrative sanctions and suspend non-compliant high-risk deployments (to be defined in subsequent law).
  • Civil liability standards for harms caused by AI to be clarified in follow-up legislation, with remedies and compensation mechanisms envisaged.
  • Procurement sanctions and contract remedies for public-sector contractors failing to meet documentation, transparency or safety requirements (to be implemented in procurement rules).

Per Greece - Omnibus Measures (5039/2023)

  • Administrative sanctions and fines as provided for in the amended subject-matter statutes (e.g., consumer protection, transport infractions) — specifics are set in the respective enforcement provisions and implementing secondary legislation.
  • Revocation or suspension of authorizations or licenses for non-compliance with statutory or delegated requirements.
  • Administrative recovery of amounts paid in error where relief measures or benefits were wrongly granted.
  • Ordinary legal remedies and penalties under administrative and criminal law where fraud, false declarations or criminal acts are established in connection with benefits or authorizations.

Per Greece - Digital Governance Framework (4961/2022)

  • Administrative sanctions (monetary fines, directives to remedy non‑compliance, suspension of operations) as provided by delegated enforcement instruments.
  • Orders for market withdrawal or corrective measures for non‑conforming devices and services.
  • Civil liability for damages caused by defective digital products, AI decision harms or negligent operation of DLT/smart contract infrastructure.
  • Criminal liability where applicable under general criminal law provisions (e.g., where offences arise in the operation of regulated systems).

Per Greece - National Digital Strategy (ΦΕΚ 2894/Β/2021)

  • Administrative enforcement measures such as suspension or reallocation of project funding for non-compliance with strategy obligations (administrative consequences referenced in the governance and oversight provisions). ([digitalstrategy.gov.gr](https://digitalstrategy.gov.gr/website/static/website/assets/uploads/digital_strategy.pdf))
  • Performance and accountability actions against responsible officials where failure to implement assigned projects is established under administrative procedures.
  • Data protection enforcement and fines by the Hellenic Data Protection Authority under GDPR for privacy violations. ([dpa.gr](https://www.dpa.gr/en?utm_source=openai))
  • Cybersecurity-related regulatory enforcement by the National Cybersecurity Authority, including registration requirements and corrective measures under national cybersecurity law. ([cyber.gov.gr](https://www.cyber.gov.gr/?utm_source=openai))
  • Contractual or procurement consequences under public procurement and funding rules for projects that do not comply with stated conditions.

Per Greece - Digital Governance Code (4727/2020)

  • Administrative corrective measures and fines where provided by the Code or by delegated implementing acts.
  • Sectoral enforcement actions in coordination with regulators for breaches (for example, trust service non‑conformity coordinated with EETT or data protection breaches referred to the Hellenic Data Protection Authority under GDPR).
  • Reputational and operational remedies including orders to cease non‑compliant practices and to remediate accessibility/interoperability failures.

Greece overview

The full picture of AI regulation in Greece, beyond just the EU AI Act.

Greece AI regulation overview →