The EU AI Act in Slovakia
How Regulation (EU) 2024/1689 applies in Slovakia, and the 16 AI instruments Slovakia has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Slovakia’s own AI instruments
16 records tracked for Slovakia, beyond the EU-level Act above.
Slovakia - AI Governance Bill (LP/2025/401)
Slovakia · 2025 · 1 Jan 2026
Slovakia - AI in Education Guidelines
Slovakia · 2025 · 1 Aug 2025
Slovakia - AI Plenipotentiary Office (368/2025)
Slovakia · 2025 · 5 Jul 2025
Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025)
Slovakia · 2025
Slovakia - Public Sector Data Management (2025)
Slovakia · 2025
Slovakia AI Conformity Assessment Act
Slovakia · 2025 · 1 Jan 2026
Slovakia - Digital Transformation Framework (UV-46042/2024)
Slovakia · 2024 · 20 Nov 2024
Slovakia - Digital Skills Strategy
Slovakia · 2022 · 1 Jan 2023
Slovakia - Digital Transformation Plan
Slovakia · 2022 · 14 Dec 2022
Slovakia - DESI Index Improvement Strategy
Slovakia · 2021 · 12 May 2021
Slovakia - National Cybersecurity Strategy (5/2021)
Slovakia · 2021 · 7 Jan 2021
Slovakia - Public Administration Digital Transformation
Slovakia · 2021 · 14 Dec 2021
Slovakia - Research and Innovation Strategy
Slovakia · 2021 · 16 Nov 2021
Slovakia - AI Ethics Commission (2020)
Slovakia · 2020 · 2 Nov 2020
Slovakia - Digital Transformation Action Plan
Slovakia · 2019 · 3 Jul 2019
Slovakia - Digital Transformation Strategy (Government Resolution No. 206/2019)
Slovakia · 2019 · 7 May 2019
National authority in Slovakia
Named in Slovakia’s own records, not inferred.
Per Slovakia - AI Governance Bill (LP/2025/401)
- Ministry of Investments, Regional Development and Informatization (MIRRI) — Designated general market surveillance authority; single contact point; policy coordination and sandbox operator
- Office for Personal Data Protection (Úrad na ochranu osobných údajov — ÚOOÚ) — Sectoral supervisory authority for data protection and privacy compliance (GDPR alignment)
- National Security Authority (Národný bezpečnostný úrad — NBÚ) — Sectoral authority for cybersecurity and national security aspects of AI systems
- Slovak Trade Inspection (Slovenská obchodná inšpekcia — SOI) — Sectoral market surveillance authority for consumer protection and product conformity
- State Institute for Drug Control (Štátny ústav pre kontrolu liečiv — ŠÚKL) — Sectoral authority for medical and healthcare‑related AI systems
Per Slovakia - AI in Education Guidelines
- Ministry of Education, Science, Research and Sport of the Slovak Republic — Policy lead, publisher of the national AI in education initiative and platform; coordinates national rollout and guidance
- National Institute of Education and Youth (NIVaM) — Implementation partner for teacher training and methodological support
- AI in Education platform (national project) — Central repository of methodological materials, downloadable guidance and training offers
- Office for Personal Data Protection of the Slovak Republic — Enforcement authority for data protection rules (GDPR) and guidance on lawful processing
Per Slovakia - AI Plenipotentiary Office (368/2025)
- Ministry of Investments, Regional Development and Informatization (MIRRI) — Host ministry — provides administrative and secretariat support for the Plenipotentiary; coordination partner for policy development
- Government of the Slovak Republic — Appointing authority and recipient of Plenipotentiary reports; approves statute and any amendments
Per Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025)
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI) — Central coordinating and notifying authority; oversees national implementation of the AI Act and operates the regulatory sandbox.
- Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov) — National data protection authority — oversight on personal data processing in AI systems and coordination on DPIAs.
- National Security Authority (Národný bezpečnostný úrad - NBÚ) — Coordination on cybersecurity and national security aspects of AI systems and cooperation on model security.
- European Artificial Intelligence Office / European Commission (coordination) — EU-level coordination and network participation for cross-border cooperation and standard-setting.
Per Slovakia - Public Sector Data Management (2025)
- Ministry of Investments, Regional Development and Informatization (MIRRI) / Data Coordination Unit — Policy lead, technical standardisation, designation of competent bodies and guidance issuer
- Úrad na ochranu osobných údajov Slovenskej republiky (Data Protection Authority) — Supervisory authority for GDPR/national data protection compliance; cooperation on DPIAs and high‑risk dataset oversight
- Národná rada Slovenskej republiky (Parliament) — legislative publisher — Legislative oversight and enactment; publication of official text and explanatory materials
Per Slovakia - Digital Transformation Framework (UV-46042/2024)
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI) — National coordinator for digital transformation; secretariat for the Government Council; lead on roadmap preparation and monitoring.
- Government Office of the Slovak Republic (Úrad vlády SR) — Publishes government decisions and coordinates high-level government processes; recipient of reports and decisions arising from the Council.
- Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR) — Supervisory authority for GDPR and data protection obligations; involved for DPIAs and privacy compliance reviews.
Per Slovakia - Digital Skills Strategy
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI) — Lead coordinating ministry and primary implementer / gestor for cross-cutting digital skills policy.
- Government of the Slovak Republic (Office of the Government / Rokovania portal) — Approving authority; issues resolution assigning implementation and reporting obligations to ministries and public bodies.
Per Slovakia - Digital Transformation Plan
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI SR) — Lead coordinator and publisher of the Action Plan; responsible for implementation coordination and reporting.
- Government Office of the Slovak Republic — Oversight of government-level policy coordination and inter-ministerial processes.
- Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR) — Supervision of personal data protection compliance for projects under the Action Plan.
- National Security Authority (Národný bezpečnostný úrad – NBÚ) — National authority for cybersecurity and protection of critical information infrastructure.
- Ministry of Education, Science, Research and Sport (MŠVVaŠ SR) — Lead for digital skills and education-related measures.
- Ministry of Health of the Slovak Republic — Responsible for health-sector pilots and alignment of digital health measures with sector regulation.
Per Slovakia - DESI Index Improvement Strategy
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI) — Policy lead and coordinator for digital transformation; responsible for strategy publication, monitoring and inter-ministerial coordination.
- Government of the Slovak Republic — Approving authority for national strategy and owner of governance oversight.
- Ministry of Finance of the Slovak Republic — Budgetary authority; responsible for allocation and oversight of national co-financing and RRF linkage.
Per Slovakia - National Cybersecurity Strategy (5/2021)
- Národný bezpečnostný úrad (NBÚ) — Lead national authority for cybersecurity policy, coordination, monitoring and implementation of the Strategy
- SK-CERT (National CSIRT) — National incident response team responsible for technical coordination, alerts and incident handling
- Government Office of the Slovak Republic — Strategic oversight and adoption of national policies and Action Plans
- Sectoral ministries and regulators (e.g., Ministry of Interior, Ministry of Health, Ministry of Finance) — Sectoral implementation, supervision and enforcement within respective sectors
Per Slovakia - Public Administration Digital Transformation
- Ministry of Investments, Regional Development and Informatization (MIRRI) — Primary coordinator and lead ministry for NKIVS implementation, author of the NKIVS document and convenor of governance bodies.
- NASES (National Agency for Network and Electronic Services) — Provider and operator of central eGovernment platforms and integrations (portal services, central deliveries) and technical implementer for shared services.
- National Cybersecurity Authority / CSIRT and NBÚ — Oversight and operational cybersecurity responsibilities, incident response coordination and enforcement of cybersecurity obligations.
- Office for Personal Data Protection (Úrad pre ochranu osobných údajov - ÚOOÚ) — Data protection regulator ensuring GDPR and national data protection compliance in public-sector digital services.
Per Slovakia - Research and Innovation Strategy
- Research and Innovation Authority (VAIA) — Central coordinator, publisher of SK RIS3 2021+ documents, methodological guidance and monitoring reports
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI / MIRDI) — Lead ministry for strategy preparation and domain coordination (Digital transformation domain among others)
- Government Council for Science, Technology and Innovation (SGCSTI) & PCS3 — Political oversight and permanent committee for RIS3 implementation and coordination
- Managing Authorities of Operational Programme Slovakia (OP SK) — Apply the strategy as a baseline condition for specific RDI objectives when designing and implementing calls
Per Slovakia - AI Ethics Commission (2020)
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI) — Hosting ministry; established CERAI as an independent expert advisory commission and provides secretariat support.
- Office for Personal Data Protection of the Slovak Republic — Data protection regulator — enforces GDPR-related obligations that apply to AI systems handling personal data.
Per Slovakia - Digital Transformation Action Plan
- Office of the Deputy Prime Minister for Investments and Informatization (Vice‑Premier's Office) — Coordinating authority and publisher / overseer of the Action Plan
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI) — Policy lead on informatization and implementation partner; publishes strategic documents and coordinates technical implementation
- National Cybersecurity Authority (Národný bezpečnostný úrad – NBÚ) — Advisor and regulator for cybersecurity requirements in public IT projects
Per Slovakia - Digital Transformation Strategy (Government Resolution No. 206/2019)
- Ministry of Investments, Regional Development and Informatization of the Slovak Republic (MIRRI) — Primary coordinator and operational lead for the Strategy; hosts Digital Agenda Section and action plan coordination.
- Office of the Deputy Prime Minister for Investments and Informatization (Office of the Vice‑Premier) — Political sponsor and government office that submitted the Strategy for government approval.
- Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov) — National Data Protection Authority (GDPR supervisory authority) responsible for enforcing personal data protection obligations referenced by the Strategy.
- Relevant sectoral ministries (Economy, Education, Health, Transport, Interior) — Responsible for sectoral implementation of measures within their statutory competencies and reporting to MIRRI.
Penalties in Slovakia
As stated in Slovakia’s own records.
Per Slovakia - AI Governance Bill (LP/2025/401)
- Administrative fines for breaches of obligations (classification and documentation failures, missing registration/notification) scaled by the gravity of the breach and by annual turnover.
- Orders to suspend placing on the market or use of non‑compliant AI systems (temporary or permanent) until remedial measures are taken.
- Seizure or withdrawal of access to AI systems where public safety or fundamental rights are at risk.
- Sanctions for failure to cooperate with supervisory authorities, including daily penalties until compliance is achieved.
- Criminal or administrative referral where offences intersect with national criminal law (fraud, data misuse) as applicable.
Per Slovakia - AI in Education Guidelines
- This guidance is non-binding; however, breaches that involve unlawful processing of personal data remain subject to enforcement under the GDPR and national data-protection legislation, including potential administrative fines and corrective measures.
- Misuse of AI that results in discrimination or harm may lead to liability under national administrative and civil law and could affect eligibility for public funding.
- Academic misconduct by students using AI in violation of school rules is subject to school disciplinary procedures.
Per Slovakia - AI Plenipotentiary Office (368/2025)
- The statute does not introduce new administrative penalties or criminal sanctions — enforcement and penalties for unlawful AI practices remain within the competence of relevant statutory regulators or future implementing legislation.
- Employment, disciplinary or labour-related penalties for secretariat staff are governed by civil service and labour laws referenced in the statute (e.g., Act No. 55/2017; Act No. 311/2001).
- If an implementing law is adopted to operationalise aspects of the EU AI Act, applicable enforcement and penalty regimes will derive from that legislation.
Per Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025)
- Administrative fines scaled to the severity of breach, particularly for breaches affecting high‑risk systems (aligned with AIA principles).
- Orders to suspend placement on the market, to withdraw systems from service, or to mandate corrective measures.
- Revocation of sandbox participation approval and temporary bans on placing tested systems on the market in case of serious violations.
- Public corrective notices and publication of enforcement actions (subject to confidentiality safeguards).
- Referral to criminal prosecution in cases of intentional fraud, falsification of conformity documentation, or actions causing serious harm.
Per Slovakia - Public Sector Data Management (2025)
- Administrative corrective orders requiring remedial measures and publication of corrective actions.
- Administrative fines proportional to the gravity of non‑compliance and to follow national sanctioning frameworks (amounts to be specified by secondary regulation).
- Suspension of recognition/certification for intermediaries or data altruism organisations that breach governance conditions.
- Civil liability for damage caused by negligent disclosure or failure to implement mandated safeguards.
- Public naming or reporting of recurrent non‑compliant public sector bodies in annual oversight reports.
Per Slovakia - Digital Transformation Framework (UV-46042/2024)
- Administrative escalation to the Government Council and possible suspension or reallocation of earmarked public funds for non-compliant projects.
- Referral to sectoral supervisory authorities (e.g., Office for Personal Data Protection) where implementation breaches applicable law (GDPR, sectoral statutes), with those authorities retaining their powers to impose statutory sanctions.
- Contractual remedies and liability enforcement through procurement and PPP contracts (e.g., remedies for vendor non-performance).
- Reputational and political consequences via public reporting and parliamentary scrutiny for persistent non-compliance.
- Where legislative implementing acts are adopted under the framework, those acts may establish specific administrative penalties or enforcement measures.
Per Slovakia - Digital Skills Strategy
- The NSDZaAP and accompanying government resolution do not create new criminal penalties; non-compliance is addressed through administrative and contractual remedies (e.g., funding reallocation, contractual sanctions under grant or procurement agreements) and Ministry-level accountability.
- Failure to provide required reports may trigger governance interventions and potential impacts on programme funding or prioritisation.
Per Slovakia - Digital Transformation Plan
- Administrative consequences, including reduced priority for future funding if milestones are not met.
- Potential funding suspension or reallocation for projects failing to comply with eligibility or reporting requirements.
- Audits and corrective recommendations by national audit bodies or managing authorities.
- Sectoral legal sanctions where applicable (e.g., breaches of data protection regulation may trigger fines under GDPR and national law).
- Contractual remedies and liability claims under standard public procurement and grant agreements.
Per Slovakia - DESI Index Improvement Strategy
- The strategy itself does not establish new criminal penalties; implementation failures are managed through administrative and funding mechanisms.
- Non-performance or failure to meet Action Plan milestones can lead to re-prioritisation of funds or reduced prioritisation for future EU-funded projects.
- Standard administrative and financial recovery provisions attached to EU funding instruments (RRF, cohesion funds) apply to mismanagement or non-compliance by beneficiaries.
- Public-sector accountability actions (performance reviews, managerial sanctions under public service rules) may be taken where responsibilities are not fulfilled.
Per Slovakia - National Cybersecurity Strategy (5/2021)
- Administrative sanctions and enforcement measures applicable under Act No. 69/2018 Z. z. for failures in reporting, protection or compliance.
- Sectoral regulatory penalties where public sector regulations or sector-specific rules are breached (e.g., procurement, data-protection rules).
- Criminal prosecution for cybercrime offences under the Slovak Criminal Code and related legislation when applicable.
- Contractual or procurement remedies (suspension or termination) where public procurement security obligations are violated.
- Reputational and operational consequences (remediation obligations, mandatory audits) imposed by supervising authorities.
Per Slovakia - Public Administration Digital Transformation
- Withholding or conditional release of centrally allocated funds for projects that do not meet NKIVS compliance requirements.
- Mandatory corrective action plans and project suspension where architecture or security obligations are materially breached.
- Administrative enforcement measures under Act No. 95/2019 Z.z. and Act No. 69/2018 Z.z., including fines or sanctions where statutory duties are violated.
- Audit findings and reputational consequences published in official monitoring reports may affect leadership accountability and budget allocations.
- Procurement disqualifications or corrective procurement procedures where procurement obligations under NKIVS-aligned guidance are breached.
Per Slovakia - Research and Innovation Strategy
- Ineligibility of calls or projects for EU cohesion funding where alignment with SK RIS3 2021+ is a baseline condition and VAIA methodological guidance has not been followed.
- Administrative recovery or withholding of funds where projects fail to meet contractual reporting, eligibility or KPI obligations under managing authority rules.
- Standard administrative or financial sanctions applicable under national and EU funding rules for fraud, misrepresentation or misuse of funds.
Per Slovakia - AI Ethics Commission (2020)
- CERAI itself does not impose penalties; enforcement and penalties remain under the competence of sectoral and national regulators (e.g., Data Protection Authority) where legal breaches are identified.
- Non-compliance with applicable laws (e.g., GDPR) may trigger standard administrative sanctions under national law.
- Contractual remedies and liability clauses may be applied where procurement governance is inadequate.
Per Slovakia - Digital Transformation Action Plan
- No new statutory criminal or administrative penalties are established by the AP itself
- Failure to deliver measures may result in administrative corrective action, including suspension or reallocation of project funding
- Non‑compliance with contractual obligations on funded projects may trigger contractual sanctions, repayment of funds or ineligibility for future funding
- Regulatory violations (e.g., data protection breaches) remain subject to usual administrative fines and enforcement by competent authorities under applicable law
Per Slovakia - Digital Transformation Strategy (Government Resolution No. 206/2019)
- The Strategy itself contains no bespoke sanctions; penalties for non‑compliance arise under sectoral laws (e.g., GDPR enforcement fines by DPA, cybersecurity breach sanctions under sector regulations or administrative law).
- Failure to comply with EU programme rules when using EU funds may result in financial corrections in accordance with EU rules.
- Procurement or grant misuse may trigger standard administrative and financial penalties per Slovak public finance and procurement law.
Slovakia overview
The full picture of AI regulation in Slovakia, beyond just the EU AI Act.
Slovakia AI regulation overview →