The EU AI Act in Malta

How Regulation (EU) 2024/1689 applies in Malta, and the 10 AI instruments Malta has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Malta’s own AI instruments

10 records tracked for Malta, beyond the EU-level Act above.

National authority in Malta

Named in Malta’s own records, not inferred.

Per Malta - AI Commissioner Designation (227/2025)

Per Malta - AI Regulations (226/2025)

  • Malta Digital Innovation Authority (MDIA)Primary national Market Surveillance Authority and Notifying Authority for AI; responsible for market surveillance, conformity assessment recognition, regulatory sandbox and enforcement.
  • Information and Data Protection Commissioner (IDPC)Designated national authority for market surveillance of certain high‑risk, data‑sensitive AI systems (per LN 227 of 2025) and custodian of data protection and fundamental rights oversight in AI deployments.
  • Malta Financial Services Authority (MFSA)Sectoral regulator coordinating with MDIA on AI systems used in financial services and supervising sector‑specific compliance where relevant.

Per Malta - Digital Education Strategy

Per Malta - Digital Innovation Authority (XIX/2024)

Per Malta - Digital Strategy (2023-2027)

Per Malta - National eSkills Strategy

Per Malta - AI Certification Programme

Per Malta - Ethical AI Framework

Per Malta - National AI Strategy

Per Malta - Digital Innovation Authority Act (XXXI/2018)

  • Malta Digital Innovation Authority (MDIA)National authority for recognition, certification and oversight of innovative technology arrangements and services; issues guidance, maintains registers and enforces the Act.

Penalties in Malta

As stated in Malta’s own records.

Per Malta - AI Commissioner Designation (227/2025)

  • Administrative penalty for public authorities or bodies: up to EUR 50,000 for each infringement.
  • Daily penalty of EUR 50 for each day the infringement persists.
  • Administrative measures available to the IDPC for private operators include warnings, orders to bring processing into compliance, temporary or permanent restrictions on placing AI systems into service, and other non‑monetary corrective measures as permitted under the AI Act and national law.
  • Operators and authorities remain liable under civil law for damages arising from unlawful processing; criminal liability may arise under separate national statutes where applicable.
  • Decisions by the IDPC imposing penalties or measures are subject to administrative and judicial review under Maltese law.

Per Malta - AI Regulations (226/2025)

  • Administrative fines and corrective measures for breaches, including orders to suspend or withdraw non‑compliant AI systems.
  • Daily penalties for continuing infringements (national rules provide for daily fines to enforce compliance).
  • Civil liability remains available to harmed individuals; regulators may require rectification or compensation actions where applicable.
  • Revocation of national notifications/recognitions for conformity assessment bodies or removal from national registers.

Per Malta - Digital Education Strategy

  • Administrative corrective actions for implementing units failing to meet assigned milestones or reporting obligations.
  • Contractual remedies and penalties under public procurement law for vendors breaching contract terms (including security/data clauses).
  • Data-protection enforcement actions under the Data Protection Act for breaches (administrative fines and remedial orders by the ODPC).
  • Reputational and managerial consequences within MEYR (reallocation of responsibilities, performance measures).

Per Malta - Digital Innovation Authority (XIX/2024)

  • Administrative measures including directions to comply, corrective action requirements, and notices.
  • Suspension or revocation of recognitions, registrations, approvals or authorisations granted by the MDIA.
  • Financial administrative penalties as may be specified in subsidiary regulations or rules.
  • Prohibition on placing a technology or service on the market or continuing operation pending remedial action.
  • Other enforcement measures provided by the Act or secondary legislation, including publication of non-compliance.

Per Malta - Digital Strategy (2023-2027)

  • The Strategy itself does not create new statutory penalties; compliance incentives are primarily administrative and financial (e.g., funding conditionality).
  • Sectoral regulatory penalties (e.g., GDPR fines enforced by the Office of the Information and Data Protection Commissioner) remain applicable where legal requirements are breached.
  • Failure to meet publicly signalled milestones may result in reprioritisation of funding, administrative remediation measures or reporting to Cabinet.

Per Malta - National eSkills Strategy

  • The Strategy itself does not create criminal penalties; non‑compliance may affect eligibility for public funding and partnership opportunities.
  • Entities failing to meet contractual obligations under funded programmes may be subject to standard funding recovery, suspension or ineligibility measures as set out in grant agreements.
  • Reputational impacts and loss of priority status in national initiatives are potential practical consequences for persistent non‑delivery.

Per Malta - AI Certification Programme

  • Refusal to grant certification where requirements are unmet.
  • Suspension or revocation of MDIA-issued certificates for material non-compliance.
  • Imposition of administrative fees and fee recovery where prescribed by subsidiary legislation.
  • Publication of adverse findings or sanctions affecting reputational standing and market access.
  • Obligation to remediate within timeframes or face escalated administrative measures.
  • Referral to sectoral regulators or enforcement authorities where statutory breaches are identified (including data protection authorities under GDPR).

Per Malta - Ethical AI Framework

  • The Framework itself imposes no statutory fines or criminal penalties.
  • Non‑compliance may affect eligibility for Malta’s voluntary AI certification and influence procurement or market acceptance.
  • Sectoral or existing statutory regimes (e.g., GDPR) continue to apply and can result in enforcement actions and fines by competent authorities for breaches (e.g., data protection violations).
  • Reputational and contractual consequences in private contracts or public procurement if ethical controls are absent or inadequate.

Per Malta - National AI Strategy

  • Administrative consequences tied to the certification programme, including suspension or revocation of certification for non-compliant systems.
  • Ineligibility for public procurement preference where a supplier refuses or fails to meet certification or ethical framework requirements.
  • Enforcement under existing legal regimes (e.g., GDPR fines and penalties) where data protection breaches occur.
  • Remediation orders and corrective action plans required by MDIA or relevant sectoral regulator for systems that pose unacceptable risks.
  • Reputational sanctions through public reporting and delisting from MDIA registries.

Per Malta - Digital Innovation Authority Act (XXXI/2018)

  • Administrative sanctions including fines and penalties for non-compliance with directives and conditions of recognition.
  • Suspension or revocation of recognition, certification or authorisation issued by the MDIA.
  • Public censure and publication of enforcement actions or decisions in public registers.
  • Remedial directions requiring corrective measures (including technical remediation and governance changes).
  • Referral to other national authorities for criminal or civil action where breaches engage other laws (e.g., AML, data breaches).

Malta overview

The full picture of AI regulation in Malta, beyond just the EU AI Act.

Malta AI regulation overview →