The EU AI Act in Romania
How Regulation (EU) 2024/1689 applies in Romania, and the 8 AI instruments Romania has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Romania’s own AI instruments
8 records tracked for Romania, beyond the EU-level Act above.
Romania - AI Legal Framework (B154/2024)
Romania · 2024
Romania - AI Legislative Proposal (L255/2024)
Romania · 2024
Romania - Cooperation on AI and Cloud
Romania · 2024 · 15 Jul 2024
Romania - National Coordination Committee
Romania · 2024 · 23 Apr 2024
Romania - National AI Strategy
Romania · 2023
Romania - Responsible Technology Use (PL-x 471/2023)
Romania · 2023
Romania - AI Committee Establishment
Romania · 2022 · 4 May 2023
Romania - National AI Governance (20D/31781)
Romania · 2022 · 11 Nov 2022
National authority in Romania
Named in Romania’s own records, not inferred.
Per Romania - AI Legal Framework (B154/2024)
- Senate Committee for Communications, Information Technology and Artificial Intelligence (Comisia pentru comunicaţii, tehnologia informaţiei şi inteligenţă artificială) — Reporting parliamentary committee; conducted hearings and adopted a report of rejection in the Senate stage
- Autoritatea Naţională pentru Administrare şi Reglementare în Comunicaţii (ANCOM) — Sectoral regulator consulted on communications and platform implications; party to hearings
- Directoratul Naţional de Securitate Cibernetică (DNSC) — National civil cybersecurity authority (consulted for cyber risk and incident handling)
- Serviciul Român de Informaţii — Centrul Naţional Cyberint (SRI) — National intelligence service cyber-centre consulted for national security implications and threat intelligence
- Institutul Naţional de Cercetare-Dezvoltare în Informatică (ICI Bucureşti) — Technical research institute consulted for testing, evaluation and research perspectives
Per Romania - Cooperation on AI and Cloud
- Ministry of Research, Innovation and Digitalization (MCID) — Lead Government signatory and coordination for research, innovation and digitalisation policy.
- Romanian Government / Prime Minister's Office (Palatul Victoria) — Strategic oversight and public announcement of high-level cooperation.
- National Supervisory Authority for Personal Data Processing (ANSPDCP) — Data protection supervisory authority; oversight of GDPR compliance and DPIAs.
- National Cybersecurity Directorate (CNA / DNSC or successor agency) — Coordination and advice on cybersecurity resilience for government infrastructure.
Per Romania - National Coordination Committee
- Authority for the Digitalisation of Romania (Autoritatea pentru Digitalizarea României - ADR) — Coordinate digitalisation policy, host of digital platforms and PNRR digital projects; potential secretariat / technical partner
- National Supervisory Authority for Personal Data Processing (ANSPDCP) — Data protection supervisory authority; enforces GDPR and national data protection law
- National Cybersecurity Directorate (DNS) — National authority for cybersecurity, responsible for critical infrastructure resilience and secure information exchange
- National Authority for Management and Regulation in Communications (ANCOM) — Telecoms regulator with responsibilities for certain digital services and infrastructure oversight
- National Institute of Statistics (INS) — Producer and custodian of official statistics and data‑sharing for statistical purposes
- National Authority for Consumer Protection (ANPC) — Consumer protection authority overseeing unfair commercial practices in digital markets
- National Audiovisual Council (CNA) — Audiovisual regulator with remit over broadcast and related online audiovisual services
- Competition Council (Consiliul Concurenței) — Competition regulator responsible for market interventions, merger control and abuse of dominance in digital markets
- Ministry of Research, Innovation and Digitalisation (MCID) — Policy lead for national research, innovation and digital strategy and EU policy coordination
Per Romania - National AI Strategy
- Autoritatea pentru Digitalizarea României (ADR) — National coordinator / implementing authority for the CSN-IA project and lead for policy coordination
- Universitatea Tehnică din Cluj-Napoca (UTCN) — Project partner and academic contributor (RDI, expertise, consultative role)
- Ministry of Research / Ministry of Research, Innovation and Digitalisation (as relevant) — Policy partner and contributor to national RDI and education alignment
Per Romania - Responsible Technology Use (PL-x 471/2023)
- Consiliul Național al Audiovizualului (CNA) — Primary supervisory and enforcement authority for audiovisual broadcasting and dissemination; monitors compliance, issues removal orders and administrative sanctions.
- National Supervisory Authority for Personal Data Processing (ANSPDCP) — Supervisory authority for data-protection aspects of identification/retention obligations and cross-border data requests.
- Chamber of Deputies (Legislative authority / final decision-maker) — Decisional chamber for PL-x 471/2023; will debate, amend and adopt/reject the bill as the chamber of final decision.
Per Romania - AI Committee Establishment
- Ministry of Research, Innovation and Digitalization (MCID) — Technical secretariat and implementing authority for the Committee; responsible for organisation, budget and coordination
- Prime Minister / Prime Minister's Office — Patronage and high-level political oversight of the Committee; strategic alignment with government priorities
- Secretariat General of the Government (SGG) — Coordination and liaison with government institutions; recipient of Committee reports for policy action
Per Romania - National AI Governance (20D/31781)
- Ministry of Research, Innovation and Digitization (Ministerul Cercetării, Inovării și Digitalizării - MCID) — Technical secretariat for the Romanian Committee for AI; lead implementing authority for the memorandum.
- Prime Minister's Office (Cancelaria Prim-ministrului) — Patronage and high-level coordination of the Committee and national strategy implementation.
- Romanian Government - Secretariat General — Facilitates inter-ministerial coordination and government-level oversight of national policy initiatives.
- National Data Protection Authority (ANSPDCP) — Oversight of personal data protection and GDPR compliance in AI projects processing personal data.
Penalties in Romania
As stated in Romania’s own records.
Per Romania - AI Legal Framework (B154/2024)
- Administrative fines for breaches of documentation, registration and transparency obligations (scale to be set in secondary legislation).
- Corrective orders requiring modification, suspension or withdrawal of non-compliant AI systems from service.
- Periodic penalty payments for failure to comply with supervisory orders.
- Civil liability exposure for damages caused by negligent design, deployment or failure to mitigate risks.
- Potential criminal liability where provider or deployer acts with wilful intent to cause harm or evade legal obligations (as defined under national criminal law).
Per Romania - Cooperation on AI and Cloud
- The MoU is non-binding and does not impose statutory administrative penalties by itself.
- Any contractual projects following the MoU will contain standard commercial remedies, service-level credits, and indemnities as negotiated in those contracts.
- Breach of applicable law (e.g., GDPR) during pilots may trigger enforcement action by national regulators including fines and corrective orders.
- Dispute resolution for project contracts to be defined in each subsequent agreement (mediation/arbitration/competent national courts).
Per Romania - National Coordination Committee
- The memorandum itself does not create new penalties; enforcement and sanctions remain under the competence of existing regulators (e.g., fines under GDPR by ANSPDCP, sanctions from the Competition Council, measures from ANPC, ANCOM, CNA or DNS as applicable).
- Failure to cooperate is addressed through administrative channels and existing public administration rules rather than new penal provisions in the memorandum.
- Any joint or coordinated market intervention will be executed under the legal powers of the responsible regulator(s); usual appeal and remedy processes under national law remain available to affected parties.
Per Romania - National AI Strategy
- The CSN-IA is a draft strategic framework and does not itself impose new penalties; enforcement and sanctions are to be defined in follow-up legislation and sectoral regulation.
- Existing enforcement regimes apply where relevant (e.g., GDPR fines for data protection breaches, consumer protection sanctions, sectoral penalties in health/transport).
- The framework recommends establishing conformity assessment and market surveillance mechanisms that will include administrative measures and potential sanctions once operative rules are adopted.
Per Romania - Responsible Technology Use (PL-x 471/2023)
- Administrative fines for first-time labeling/notification violations (statutory ranges established by the bill; repeated violations trigger higher fines).
- Escalated administrative fines where non-compliance is repeated (higher upper limits for recidivism).
- Regulatory orders from CNA to suspend broadcast or remove content immediately where deepfake material is unlabelled or malicious.
- In amended Chamber provisions: criminal sanctions (fines and custodial sentences) for malicious creation and distribution in specific circumstances (these provisions generated public controversy and calls for reform).
- Potential civil liability and damages claims by victims for reputational and privacy harm under general civil law.
- Referral to criminal prosecution under existing Criminal Code provisions where acts constitute fraud, extortion, falsification, or other established offences.
Per Romania - AI Committee Establishment
- The memorandum itself does not establish new criminal or administrative penalties; enforcement is administrative and organizational in nature
- Non-compliance with membership adhesion or confidentiality rules may result in exclusion or suspension from Committee activities
- Misuse of public funds related to Committee activities is subject to existing public finance, administrative and criminal sanctions under Romanian law
- Failure by public authorities to cooperate may be remedied through standard administrative review procedures and internal MCID measures
- Operational consequences (loss of access to funding or coordination roles) are the principal enforcement mechanisms available under the ordinance
Per Romania - National AI Governance (20D/31781)
- The memorandum itself does not establish criminal penalties; it is a strategic policy directive.
- Administrative consequences for non‑compliance with reporting or funding conditions (e.g., suspension or reallocation of project funding) may be applied under applicable public administrative rules.
- Sectoral legal liabilities and enforcement continue to be governed by existing sectoral laws (e.g., health, finance regulations) and GDPR for data protection breaches.
- Failure to implement obligations may lead to reputational and funding impacts; implementing ordinances may specify additional administrative measures.
- Specific sanctions, fines or liability regimes (including conformity assessment enforcement) will be implemented through future regulatory or legislative acts as required.
Romania overview
The full picture of AI regulation in Romania, beyond just the EU AI Act.
Romania AI regulation overview →