The EU AI Act in Slovenia
How Regulation (EU) 2024/1689 applies in Slovenia, and the 4 AI instruments Slovenia has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Slovenia’s own AI instruments
4 records tracked for Slovenia, beyond the EU-level Act above.
Slovenia - AI Regulation Implementation (85/2025)
Slovenia · 2025 · 21 Nov 2025
Slovenia - Digital Transformation Strategy
Slovenia · 2023 · 23 Mar 2023
Slovenia - Digital Public Services Strategy
Slovenia · 2022 · 15 Dec 2022
Slovenia - AI Development Programme
Slovenia · 2021 · 27 May 2021
National authority in Slovenia
Named in Slovenia’s own records, not inferred.
Per Slovenia - AI Regulation Implementation (85/2025)
- Agencija za komunikacijska omrežja in storitve Republike Slovenije (AKOS) — Market surveillance authority; single contact point for sandboxes and information; priglasitveni tasks for certain Annex categories and coordination
- Informacijski pooblaščenec (Information Commissioner) — Market surveillance authority for data protection and aspects of high‑risk AI touching personal data and prohibited practices; oversight of privacy compliance under EU Regulation in assigned areas
- Banka Slovenije (Bank of Slovenia) — Market surveillance authority for high‑risk AI systems used by credit institutions (creditworthiness and similar financial uses)
- Agencija za zavarovalni nadzor (Insurance Supervision Agency) — AZN (sectoral supervisor) — Market surveillance authority for AI systems used in insurance risk assessment and pricing for life/health insurance, coordination with AGO and other agencies
- Tržni inšpektorat Republike Slovenije (Market Inspectorate) — Enforcement and inspection role for consumer‑facing high‑risk AI systems and for certain deployer categories (e.g., consumer credit by non‑bank providers)
- Ministry for Digital Transformation (Ministrstvo za digitalno preobrazbo) — Central coordinating ministry; responsible for national contact point, regulatory sandboxes, AI literacy and outreach; host of the national ethics body tasks
- Inšpektorat Republike Slovenije za informacijsko družbo (IRSID) — Supervisory body for public sector publication obligations and oversight of certain notification/inspection duties under the Act
Per Slovenia - Digital Transformation Strategy
- Ministry for Digital Transformation (Ministrstvo za digitalno preobrazbo) — Lead coordinator and implementing authority for DSI2030; prepares action plan and monitors implementation.
- Government Office for Digital Transformation (Služba Vlade Republike Slovenije za digitalno preobrazbo) — Secretariat support, stakeholder coordination and public consultation lead during strategy development and implementation.
- SI-CERT / National CSIRT (relevant national cybersecurity bodies) — Operational cybersecurity incident response, national cyber resilience coordination and sectoral guidance.
Per Slovenia - Digital Public Services Strategy
- Ministry for Digital Transformation (Ministrstvo za digitalno preobrazbo) — Coordinating authority for implementation, monitoring, and action-plan maintenance.
- Ministry of Public Administration (Ministrstvo za javno upravo) — Original preparing authority during strategy drafting; retained sectoral and historical responsibilities and contacts for public administration policy.
- Information Commissioner (Informacijski pooblaščenec / Data Protection Authority) — Enforcement of data protection obligations under GDPR for personal data processed by public bodies.
- Inspectorate for Information Society (Inšpektorat RS za informacijsko družbo) — Oversight and inspection activities in the information‑society/digital domain as part of ministry structures.
Per Slovenia - AI Development Programme
- Ministry of Public Administration (Ministrstvo za javno upravo) — Designated coordinating authority for preparation and initial monitoring of NpUI (per 2021 document); responsible for embedding measures into public administration where applicable.
- Ministry for Digital Transformation (Ministrstvo za digitalno preobrazbo) — Subsequent / parallel coordination on digital policy and operational working groups for NpUI implementation and planning successor strategies (MDP hosts digital strategy pages and working groups).
- Administration of the Republic of Slovenia for Information Security (Urad vlade za informacijsko varnost / URSIV) — Cybersecurity & information security partner referenced in NpUI for secure AI deployments and infrastructure resilience.
Penalties in Slovenia
As stated in Slovenia’s own records.
Per Slovenia - AI Regulation Implementation (85/2025)
- Administrative fines and corrective measures as foreseen by the EU Regulation (tiered fines for prohibited practices, high‑risk non‑compliance and procedural breaches), imposed via competent national authorities in accordance with national administrative procedures.
- Orders to suspend or prohibit the placing on the market, putting into service or use of non‑compliant AI systems.
- Ordering rectification measures, product recalls, or withdrawal from the market for AI systems found to present serious risks.
- Publication of non‑compliance and public reprimands as part of corrective actions.
- Sectoral enforcement measures (sanctions) under banking, insurance or consumer credit laws where those sectors are involved.
- Criminal or administrative liability under existing national laws if other offences are detected during enforcement (e.g., data protection breaches investigated by the Information Commissioner).
Per Slovenia - Digital Transformation Strategy
- The strategy itself does not introduce new legal penalties; enforcement of compliance is achieved via existing legal frameworks, funding conditionality and administrative oversight.
- Non-compliance with contractual or grant obligations under action plans may result in funding withdrawal, administrative measures or contractual remedies under the applicable legal instrument.
- Sectoral regulatory sanctions (for example in cybersecurity, data protection or public procurement) continue to apply under existing laws and respective supervisory authorities.
Per Slovenia - Digital Public Services Strategy
- The strategy itself does not create new statutory criminal penalties; non-compliance is addressed through administrative oversight, escalation and integration with funding decisions.
- Failure to comply with GDPR or national information-security laws can trigger penalties under existing regulatory regimes (e.g., Data Protection Authority enforcement).
- Institutions that fail to deliver may face reduced prioritisation in ministerial action plans and potential reallocation of programme funding.
- Accountability measures include ministerial review, public reporting of non‑delivery and ministerial instructions to remediate deficiencies.
Per Slovenia - AI Development Programme
- The NpUI is a strategic policy document and does not, by itself, create statutory penalties.
- Any enforcement or sanctions related to AI deployments will derive from applicable sectoral laws (e.g., GDPR, sector regulation) or future statutory AI legislation, not from NpUI directly.
- Non-compliance with ministry-level implementation instructions may lead to administrative consequences under public-sector governance rules, as determined by responsible ministries.
Slovenia overview
The full picture of AI regulation in Slovenia, beyond just the EU AI Act.
Slovenia AI regulation overview →