The EU AI Act in Slovakia

How Regulation (EU) 2024/1689 applies in Slovakia, and the 16 AI instruments Slovakia has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Slovakia’s own AI instruments

16 records tracked for Slovakia, beyond the EU-level Act above.

National authority in Slovakia

Named in Slovakia’s own records, not inferred.

Per Slovakia - AI Governance Bill (LP/2025/401)

Per Slovakia - AI in Education Guidelines

Per Slovakia - AI Plenipotentiary Office (368/2025)

Per Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025)

Per Slovakia - Public Sector Data Management (2025)

Per Slovakia - Digital Transformation Framework (UV-46042/2024)

Per Slovakia - Digital Skills Strategy

Per Slovakia - Digital Transformation Plan

Per Slovakia - DESI Index Improvement Strategy

Per Slovakia - National Cybersecurity Strategy (5/2021)

Per Slovakia - Public Administration Digital Transformation

Per Slovakia - Research and Innovation Strategy

Per Slovakia - AI Ethics Commission (2020)

Per Slovakia - Digital Transformation Action Plan

Per Slovakia - Digital Transformation Strategy (Government Resolution No. 206/2019)

Penalties in Slovakia

As stated in Slovakia’s own records.

Per Slovakia - AI Governance Bill (LP/2025/401)

  • Administrative fines for breaches of obligations (classification and documentation failures, missing registration/notification) scaled by the gravity of the breach and by annual turnover.
  • Orders to suspend placing on the market or use of non‑compliant AI systems (temporary or permanent) until remedial measures are taken.
  • Seizure or withdrawal of access to AI systems where public safety or fundamental rights are at risk.
  • Sanctions for failure to cooperate with supervisory authorities, including daily penalties until compliance is achieved.
  • Criminal or administrative referral where offences intersect with national criminal law (fraud, data misuse) as applicable.

Per Slovakia - AI in Education Guidelines

  • This guidance is non-binding; however, breaches that involve unlawful processing of personal data remain subject to enforcement under the GDPR and national data-protection legislation, including potential administrative fines and corrective measures.
  • Misuse of AI that results in discrimination or harm may lead to liability under national administrative and civil law and could affect eligibility for public funding.
  • Academic misconduct by students using AI in violation of school rules is subject to school disciplinary procedures.

Per Slovakia - AI Plenipotentiary Office (368/2025)

  • The statute does not introduce new administrative penalties or criminal sanctions — enforcement and penalties for unlawful AI practices remain within the competence of relevant statutory regulators or future implementing legislation.
  • Employment, disciplinary or labour-related penalties for secretariat staff are governed by civil service and labour laws referenced in the statute (e.g., Act No. 55/2017; Act No. 311/2001).
  • If an implementing law is adopted to operationalise aspects of the EU AI Act, applicable enforcement and penalty regimes will derive from that legislation.

Per Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025)

  • Administrative fines scaled to the severity of breach, particularly for breaches affecting high‑risk systems (aligned with AIA principles).
  • Orders to suspend placement on the market, to withdraw systems from service, or to mandate corrective measures.
  • Revocation of sandbox participation approval and temporary bans on placing tested systems on the market in case of serious violations.
  • Public corrective notices and publication of enforcement actions (subject to confidentiality safeguards).
  • Referral to criminal prosecution in cases of intentional fraud, falsification of conformity documentation, or actions causing serious harm.

Per Slovakia - Public Sector Data Management (2025)

  • Administrative corrective orders requiring remedial measures and publication of corrective actions.
  • Administrative fines proportional to the gravity of non‑compliance and to follow national sanctioning frameworks (amounts to be specified by secondary regulation).
  • Suspension of recognition/certification for intermediaries or data altruism organisations that breach governance conditions.
  • Civil liability for damage caused by negligent disclosure or failure to implement mandated safeguards.
  • Public naming or reporting of recurrent non‑compliant public sector bodies in annual oversight reports.

Per Slovakia - Digital Transformation Framework (UV-46042/2024)

  • Administrative escalation to the Government Council and possible suspension or reallocation of earmarked public funds for non-compliant projects.
  • Referral to sectoral supervisory authorities (e.g., Office for Personal Data Protection) where implementation breaches applicable law (GDPR, sectoral statutes), with those authorities retaining their powers to impose statutory sanctions.
  • Contractual remedies and liability enforcement through procurement and PPP contracts (e.g., remedies for vendor non-performance).
  • Reputational and political consequences via public reporting and parliamentary scrutiny for persistent non-compliance.
  • Where legislative implementing acts are adopted under the framework, those acts may establish specific administrative penalties or enforcement measures.

Per Slovakia - Digital Skills Strategy

  • The NSDZaAP and accompanying government resolution do not create new criminal penalties; non-compliance is addressed through administrative and contractual remedies (e.g., funding reallocation, contractual sanctions under grant or procurement agreements) and Ministry-level accountability.
  • Failure to provide required reports may trigger governance interventions and potential impacts on programme funding or prioritisation.

Per Slovakia - Digital Transformation Plan

  • Administrative consequences, including reduced priority for future funding if milestones are not met.
  • Potential funding suspension or reallocation for projects failing to comply with eligibility or reporting requirements.
  • Audits and corrective recommendations by national audit bodies or managing authorities.
  • Sectoral legal sanctions where applicable (e.g., breaches of data protection regulation may trigger fines under GDPR and national law).
  • Contractual remedies and liability claims under standard public procurement and grant agreements.

Per Slovakia - DESI Index Improvement Strategy

  • The strategy itself does not establish new criminal penalties; implementation failures are managed through administrative and funding mechanisms.
  • Non-performance or failure to meet Action Plan milestones can lead to re-prioritisation of funds or reduced prioritisation for future EU-funded projects.
  • Standard administrative and financial recovery provisions attached to EU funding instruments (RRF, cohesion funds) apply to mismanagement or non-compliance by beneficiaries.
  • Public-sector accountability actions (performance reviews, managerial sanctions under public service rules) may be taken where responsibilities are not fulfilled.

Per Slovakia - National Cybersecurity Strategy (5/2021)

  • Administrative sanctions and enforcement measures applicable under Act No. 69/2018 Z. z. for failures in reporting, protection or compliance.
  • Sectoral regulatory penalties where public sector regulations or sector-specific rules are breached (e.g., procurement, data-protection rules).
  • Criminal prosecution for cybercrime offences under the Slovak Criminal Code and related legislation when applicable.
  • Contractual or procurement remedies (suspension or termination) where public procurement security obligations are violated.
  • Reputational and operational consequences (remediation obligations, mandatory audits) imposed by supervising authorities.

Per Slovakia - Public Administration Digital Transformation

  • Withholding or conditional release of centrally allocated funds for projects that do not meet NKIVS compliance requirements.
  • Mandatory corrective action plans and project suspension where architecture or security obligations are materially breached.
  • Administrative enforcement measures under Act No. 95/2019 Z.z. and Act No. 69/2018 Z.z., including fines or sanctions where statutory duties are violated.
  • Audit findings and reputational consequences published in official monitoring reports may affect leadership accountability and budget allocations.
  • Procurement disqualifications or corrective procurement procedures where procurement obligations under NKIVS-aligned guidance are breached.

Per Slovakia - Research and Innovation Strategy

  • Ineligibility of calls or projects for EU cohesion funding where alignment with SK RIS3 2021+ is a baseline condition and VAIA methodological guidance has not been followed.
  • Administrative recovery or withholding of funds where projects fail to meet contractual reporting, eligibility or KPI obligations under managing authority rules.
  • Standard administrative or financial sanctions applicable under national and EU funding rules for fraud, misrepresentation or misuse of funds.

Per Slovakia - AI Ethics Commission (2020)

  • CERAI itself does not impose penalties; enforcement and penalties remain under the competence of sectoral and national regulators (e.g., Data Protection Authority) where legal breaches are identified.
  • Non-compliance with applicable laws (e.g., GDPR) may trigger standard administrative sanctions under national law.
  • Contractual remedies and liability clauses may be applied where procurement governance is inadequate.

Per Slovakia - Digital Transformation Action Plan

  • No new statutory criminal or administrative penalties are established by the AP itself
  • Failure to deliver measures may result in administrative corrective action, including suspension or reallocation of project funding
  • Non‑compliance with contractual obligations on funded projects may trigger contractual sanctions, repayment of funds or ineligibility for future funding
  • Regulatory violations (e.g., data protection breaches) remain subject to usual administrative fines and enforcement by competent authorities under applicable law

Per Slovakia - Digital Transformation Strategy (Government Resolution No. 206/2019)

  • The Strategy itself contains no bespoke sanctions; penalties for non‑compliance arise under sectoral laws (e.g., GDPR enforcement fines by DPA, cybersecurity breach sanctions under sector regulations or administrative law).
  • Failure to comply with EU programme rules when using EU funds may result in financial corrections in accordance with EU rules.
  • Procurement or grant misuse may trigger standard administrative and financial penalties per Slovak public finance and procurement law.

Slovakia overview

The full picture of AI regulation in Slovakia, beyond just the EU AI Act.

Slovakia AI regulation overview →