The EU AI Act in Romania

How Regulation (EU) 2024/1689 applies in Romania, and the 8 AI instruments Romania has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Romania’s own AI instruments

8 records tracked for Romania, beyond the EU-level Act above.

National authority in Romania

Named in Romania’s own records, not inferred.

Per Romania - AI Legal Framework (B154/2024)

Per Romania - Cooperation on AI and Cloud

Per Romania - National Coordination Committee

Per Romania - National AI Strategy

Per Romania - Responsible Technology Use (PL-x 471/2023)

Per Romania - AI Committee Establishment

Per Romania - National AI Governance (20D/31781)

Penalties in Romania

As stated in Romania’s own records.

Per Romania - AI Legal Framework (B154/2024)

  • Administrative fines for breaches of documentation, registration and transparency obligations (scale to be set in secondary legislation).
  • Corrective orders requiring modification, suspension or withdrawal of non-compliant AI systems from service.
  • Periodic penalty payments for failure to comply with supervisory orders.
  • Civil liability exposure for damages caused by negligent design, deployment or failure to mitigate risks.
  • Potential criminal liability where provider or deployer acts with wilful intent to cause harm or evade legal obligations (as defined under national criminal law).

Per Romania - Cooperation on AI and Cloud

  • The MoU is non-binding and does not impose statutory administrative penalties by itself.
  • Any contractual projects following the MoU will contain standard commercial remedies, service-level credits, and indemnities as negotiated in those contracts.
  • Breach of applicable law (e.g., GDPR) during pilots may trigger enforcement action by national regulators including fines and corrective orders.
  • Dispute resolution for project contracts to be defined in each subsequent agreement (mediation/arbitration/competent national courts).

Per Romania - National Coordination Committee

  • The memorandum itself does not create new penalties; enforcement and sanctions remain under the competence of existing regulators (e.g., fines under GDPR by ANSPDCP, sanctions from the Competition Council, measures from ANPC, ANCOM, CNA or DNS as applicable).
  • Failure to cooperate is addressed through administrative channels and existing public administration rules rather than new penal provisions in the memorandum.
  • Any joint or coordinated market intervention will be executed under the legal powers of the responsible regulator(s); usual appeal and remedy processes under national law remain available to affected parties.

Per Romania - National AI Strategy

  • The CSN-IA is a draft strategic framework and does not itself impose new penalties; enforcement and sanctions are to be defined in follow-up legislation and sectoral regulation.
  • Existing enforcement regimes apply where relevant (e.g., GDPR fines for data protection breaches, consumer protection sanctions, sectoral penalties in health/transport).
  • The framework recommends establishing conformity assessment and market surveillance mechanisms that will include administrative measures and potential sanctions once operative rules are adopted.

Per Romania - Responsible Technology Use (PL-x 471/2023)

  • Administrative fines for first-time labeling/notification violations (statutory ranges established by the bill; repeated violations trigger higher fines).
  • Escalated administrative fines where non-compliance is repeated (higher upper limits for recidivism).
  • Regulatory orders from CNA to suspend broadcast or remove content immediately where deepfake material is unlabelled or malicious.
  • In amended Chamber provisions: criminal sanctions (fines and custodial sentences) for malicious creation and distribution in specific circumstances (these provisions generated public controversy and calls for reform).
  • Potential civil liability and damages claims by victims for reputational and privacy harm under general civil law.
  • Referral to criminal prosecution under existing Criminal Code provisions where acts constitute fraud, extortion, falsification, or other established offences.

Per Romania - AI Committee Establishment

  • The memorandum itself does not establish new criminal or administrative penalties; enforcement is administrative and organizational in nature
  • Non-compliance with membership adhesion or confidentiality rules may result in exclusion or suspension from Committee activities
  • Misuse of public funds related to Committee activities is subject to existing public finance, administrative and criminal sanctions under Romanian law
  • Failure by public authorities to cooperate may be remedied through standard administrative review procedures and internal MCID measures
  • Operational consequences (loss of access to funding or coordination roles) are the principal enforcement mechanisms available under the ordinance

Per Romania - National AI Governance (20D/31781)

  • The memorandum itself does not establish criminal penalties; it is a strategic policy directive.
  • Administrative consequences for non‑compliance with reporting or funding conditions (e.g., suspension or reallocation of project funding) may be applied under applicable public administrative rules.
  • Sectoral legal liabilities and enforcement continue to be governed by existing sectoral laws (e.g., health, finance regulations) and GDPR for data protection breaches.
  • Failure to implement obligations may lead to reputational and funding impacts; implementing ordinances may specify additional administrative measures.
  • Specific sanctions, fines or liability regimes (including conformity assessment enforcement) will be implemented through future regulatory or legislative acts as required.

Romania overview

The full picture of AI regulation in Romania, beyond just the EU AI Act.

Romania AI regulation overview →