The EU AI Act in Lithuania
How Regulation (EU) 2024/1689 applies in Lithuania, and the 8 AI instruments Lithuania has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Lithuania’s own AI instruments
8 records tracked for Lithuania, beyond the EU-level Act above.
Lithuania - AI Act Implementation (XV-106)
Lithuania · 2025 · 1 Apr 2025
Lithuania - AI Act Implementation Amendments (XV-105, XV-106)
Lithuania · 2025 · 1 Apr 2025
Lithuania - AI Development Amendments (XV-105)
Lithuania · 2025 · 23 Jan 2025
Lithuania - AI Regulatory Sandbox Policy
Lithuania · 2024 · 3 Jul 2024
Lithuania - AI Use in Public Sector
Lithuania · 2024 · 9 May 2024
Lithuania - National AI Strategy Update
Lithuania · 2024 · 1 Jan 2026
Lithuania - AI Development Action Plan
Lithuania · 2022 · 1 Aug 2022
Lithuania - AI Strategy
Lithuania · 2019 · 1 Apr 2019
National authority in Lithuania
Named in Lithuania’s own records, not inferred.
Per Lithuania - AI Act Implementation (XV-106)
- Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) — Designated national market surveillance authority and Single Contact Point; responsible for enforcement, inspections, corrective measures and annual reporting.
- Innovation Agency (Inovacijų agentūra) — Designated notifying authority responsible for assessing and notifying conformity assessment bodies, coordinating the AI sandbox, and supporting start-up assessments.
- Ministry of the Economy and Innovation (EIMIN) — Policy coordination, funding and oversight for innovation programmes and publication of guidance and press material supporting implementation.
Per Lithuania - AI Act Implementation Amendments (XV-105, XV-106)
- Innovation Agency (Inovacijų agentūra) — Notifying authority; operator of AI sandbox; assessor for conformity assessment bodies.
- Communications Regulatory Authority (Ryšių reguliavimo tarnyba — RRT) — Market surveillance authority and single contact point for AI market surveillance and enforcement.
Per Lithuania - AI Development Amendments (XV-105)
- Innovation Agency (Inovacijų agentūra) — National notifying authority; assesses and approves notified/conformity assessment bodies; administers sandbox business support and notified body accreditation.
- Communications Regulatory Authority (RRT / Ryšių reguliavimo tarnyba) — National market surveillance authority; single point of contact for enforcement and EU cooperation; responsible for market checks, corrective measures and reporting.
- Ministry of Economy and Innovation (Ekonomikos ir inovacijų ministerija) — Policy coordination, oversight of sandbox strategic design, lead on drafting secondary implementing acts and guidance.
Per Lithuania - AI Regulatory Sandbox Policy
- Innovation Agency (Inovacijų agentūra) — National competent authority to establish and operate the AI regulatory sandbox; notifying authority and assessor for conformity assessment matters.
- Communications Regulatory Authority (RRT) — Designated market surveillance authority and single contact point for market supervision under the AI Act.
- Ministry of the Economy and Innovation (EIMIN) — Policy lead, proposing legislative amendments and coordinating national implementation and funding.
- State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) — Data protection supervision and co‑supervision for sandbox projects that process personal data (GDPR compliance).
Per Lithuania - AI Use in Public Sector
- Seimas of the Republic of Lithuania — Legislative adopter and political guidance provider for the resolution.
- Government of the Republic of Lithuania — Coordinate implementation, propose administrative and legislative measures and oversee cross-ministry cooperation.
- State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) — National supervisory authority for data protection; enforces GDPR and national data protection rules related to AI processing of personal data.
- National Cyber Security Centre (NCSC) / CERT-LT — Advisory and operational role on cybersecurity of public-sector IT systems including AI model integrity and incident response.
Per Lithuania - National AI Strategy Update
- Ministry of the Economy and Innovation (EIMIN) — Policy lead and coordinator for national AI strategy updates, legislative proposals and funding programmes.
- Innovation Agency (Inovacijų agentūra) — Operational lead for the national AI sandbox (DI smėliadėžė), SME support and innovation adoption programmes.
- State Data Agency (Valstybės duomenų agentūra) — Manager of the State Data Lake, responsible for secure public data access, provenance, and data governance to support AI testing and public‑sector AI.
- Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) — National competent authority for market surveillance and the single contact point for AI-related market oversight and cross‑border cooperation.
- Seimas (Parliament) — legislative oversight — Parliamentary consideration and approval of legal amendments required to operationalise the strategy and sandbox.
Per Lithuania - AI Development Action Plan
- Ministry of Economy and Innovation (Ekonomikos ir inovacijų ministerija) — Lead coordinator and policy sponsor for the Action Plan
- Communications Regulatory Authority of the Republic of Lithuania (Ryšių reguliavimo tarnyba, RRT) — Proposed market surveillance and contact point functions for communications/equipment-related AI issues; partner for conformity and market checks
- Innovation Agency (Inovacijų agentūra) — Implementation partner for funding, talent programs, sandboxes and coordination with industry
- State Data Protection Inspectorate (VDAI) — Data protection oversight for AI initiatives handling personal data
- Ministry of Economy and Innovation of the Republic of Lithuania — Lead policy owner and coordinator for national AI strategy and implementation
- Agency for Science, Innovation and Technology (MITA) — Implementation partner for innovation, GovTech and support to startups and pilots
- Ministry of Education, Science and Sport of the Republic of Lithuania — Responsible for education reform, higher education programs and scholarships related to AI
Penalties in Lithuania
As stated in Lithuania’s own records.
Per Lithuania - AI Act Implementation (XV-106)
- Administrative fines for non-compliance with high-risk system obligations (administrative sanctioning powers aligned with the AI Act and national administrative procedure).
- Corrective measures including orders to modify systems, withdrawal or recall of non-compliant systems from the market.
- Temporary or permanent suspension of placing the AI system on the market or putting it into service.
- Public publication of enforcement decisions and non-compliance findings.
- Civil liability remains available to harmed individuals under national law (compensation and redress).
- Potential additional sectoral sanctions where sector-specific safety or licencing rules are breached (e.g., healthcare or transport-specific penalties).
Per Lithuania - AI Development Amendments (XV-105)
- Administrative measures: RRT may order suspension of placing an AI system on the market, require corrections, or order recalls.
- Fines and penalties: national administrative fines and sanctions consistent with EU AI Act ceilings and principles; severe breaches may trigger percentage‑based turnover fines as set in the EU Act.
- Publication of enforcement actions and names of non‑compliant providers where permitted by law.
- Potential withdrawal of notified body status for entities failing to comply with assessment or reporting obligations.
- Sanctions for providing false information to authorities or obstructing market surveillance activities.
Per Lithuania - AI Regulatory Sandbox Policy
- Providers remain civilly liable for damages caused during sandbox experimentation under national and Union liability law.
- National competent authorities retain power to suspend or terminate participation where risks cannot be mitigated.
- Administrative fines under the AI Regulation will generally not be imposed for infringements identified during sandbox participation if the provider followed the sandbox plan and the authority’s guidance in good faith (per Article 57 of the AI Act), but other enforcement measures and corrective orders may apply.
- Failure to follow data protection safeguards may result in data‑protection enforcement actions by the State Data Protection Inspectorate consistent with GDPR.
- Non‑compliance with national criminal or public‑security law (e.g., unlawful processing of sensitive data) may lead to criminal investigations or prosecution.
Per Lithuania - AI Use in Public Sector
- Resolution does not itself create new fines; where GDPR or sectoral law violations occur, supervisory and administrative sanctions (including fines) remain available under existing law.
- Administrative corrective measures by supervisory authorities (for example, orders to suspend processing or to remediate systems).
- Civil liability and compensatory claims under general liability rules where harm is caused by negligent deployment or operation of AI systems.
- Reputational and operational remedies (suspension or withdrawal of systems) enforced by relevant public authorities.
- Potential criminal liability under existing criminal law where misuse or unlawful processing meets criminal offence thresholds.
Per Lithuania - National AI Strategy Update
- Administrative fines and corrective orders aligned with the enforcement framework of the EU Artificial Intelligence Act, applied by national competent authorities (e.g., RRT and sectoral regulators).
- Market restrictions or withdrawal orders for non‑conforming high‑risk AI systems.
- Obligations to remedy deficiencies, suspend deployments or require additional conformity assessments.
- Potential civil liability and judicial remedies under Lithuanian law for harms caused by AI systems (redress pathways to be clarified in implementing acts).
Per Lithuania - AI Development Action Plan
- The Action Plan itself does not establish new fines or criminal penalties; compliance consequences arise from existing sectoral laws (data protection, consumer protection, safety regulations).
- Where deployment of AI systems violates existing legal requirements (e.g., GDPR breaches), standard administrative fines and enforcement measures from data protection and sectoral regulators apply.
- Public procurement or funding misuse may trigger administrative sanctions and recovery of funds under applicable public finance rules.
- Future binding AI-specific regulatory acts (national or EU-level) may impose penalties and enforcement measures distinct from this Plan.
- None specified within the strategy itself; the document is non-binding and does not prescribe administrative penalties.
- Existing legal frameworks continue to apply in cases of unlawful conduct (e.g., data protection breaches subject to GDPR enforcement).
- Any future binding regulations or sector-specific rules referenced by the strategy would define penalties and enforcement mechanisms at the time of their adoption.
Lithuania overview
The full picture of AI regulation in Lithuania, beyond just the EU AI Act.
Lithuania AI regulation overview →