Bulgaria - AI Regulation Draft (RAI-BG-NA-DAPBPXX-2025)

Draft AI Act presented by political party 'Da, Bulgaria'

Проект на Закон за изкуствения интелект, представен от политическа партия 'Да, България'

Bulgaria

RAI-BG-NA-DAPBPXX-2025
Draft(Being written or scoped)
BillGovernance and OversightConformity Assessment and RegistrationRisk Management
Export PDF

A draft national law on artificial intelligence prepared and presented by the Da, Bulgaria party (authors: Bozhidar Bozhanov, Elisaveta Belobradova, Aleksandar Simidchiev). The bill aims to implement and complement the EU AI Regulation (Regulation (EU) 2024/1689), establish national coordination and governance structures, promote investment and skills, and regulate risk-based uses of AI in the public and private sectors.

Overview

The Draft AI Act presented by "Да, България" (Da, Bulgaria) on 23 September 2025 sets out a national, horizontal framework to regulate the development, deployment and public-sector use of artificial intelligence in Bulgaria. The project states that it implements and clarifies the scope of Regulation (EU) 2024/1689 (AI Act) while adding national measures to support investment, training and secure public-sector adoption. The public presentation and explanatory notes are published by the authors and summarized by national news agencies; the party emphasises that the law is intended to both protect citizens' rights and boost competitiveness of Bulgarian IT and research sectors. Primary project announcement and materials can be found on the sponsoring party site and in national press reporting. Da, Bulgaria announcement (23 Sep 2025) and BTA press notice.

Definitions

The draft adopts an EU-aligned, technical set of definitions for terms such as "AI system", "provider", "deployer", "high-risk AI", "placing on the market", "conformity assessment", "personal/sensitive data", "model card", and "incident". Definitions are designed to mirror the EU AI Regulation so that national-level obligations apply to providers and deployers operating within Bulgaria or offering systems into the Bulgarian market. The bill clarifies that public-sector uses (administrative services, automated decision-support) and cross-border remote services targeted at Bulgarian citizens fall within scope. It also defines "open models" and provides an outline for controlled access to public archives for training such models.

Governance and Institutional Framework

The draft proposes creating a small, centralised National AI Coordinator (a single national contact point) supported by a multi-stakeholder Consultative Council for Ethical AI composed of government, academia, civil society and industry representatives. Operational oversight would be shared between the national coordinator, the Commission for Personal Data Protection (for data-protection issues and automated decision-making oversight), and the Ministry of Electronic Government (responsible for public-sector deployment and e-government integration). The bill also envisages a market-surveillance role for an AI oversight unit that will coordinate with the European AI Board. The party's materials describe the coordinator as a liaison to the EU structures and as a facilitator for funding and public procurement reforms. See the party announcement for governance outlines: public consultation note (04 Apr 2025) and the official press text.

Key Focus Areas

The draft concentrates on several interlocking policy goals: (1) Alignment and clarification of obligations under the EU AI Regulation at the national level; (2) enabling public-sector modernization by promoting trustworthy AI use in administrative services and sectoral public goods (healthcare, education, social services); (3) economic policy measures to stimulate private investment in AI (targeted funding, tax incentives, facilitation of EU funds and co-financing); (4) workforce development and upskilling for state employees and the wider labour force; (5) measures to open controlled public datasets (including archival media content) for non-commercial and research use to support local model development; and (6) national security safeguards to limit malicious AI use and protect critical infrastructure. The party documents highlight that the draft is intended to be non-restrictive for innovation while ensuring safeguards for rights and security. The BTA and national press coverage summarise these focus areas and stakeholder outreach. BTA announcement (23 Sep 2025).

Implementation Framework

Implementation follows a layered approach: providers and deployers of "high-risk" AI (as defined by the EU and national lists) must perform conformity assessments, produce technical documentation, and register systems with a national registry. The Ministry of Electronic Government would issue sector-specific guidance for public procurement and integration into e-government services. The National AI Coordinator would run an implementation helpdesk and coordinate funding streams for pilots and capacity-building. The draft envisages that public-sector procurement will include mandatory trustworthiness checks and model documentation requirements, and it suggests fast-track support for open-model initiatives using public archives under strict privacy and licensing conditions. Enforcement responsibilities are split between the data-protection authority (personal data matters), the national market-surveillance/AI oversight unit (conformity and market behaviour) and courts for civil claims.

Monitoring and Evaluation

The draft mandates periodic public reporting, continuous post-market monitoring of high-risk systems, and mandatory incident reporting for serious incidents and near-misses. The National AI Coordinator must publish an annual national AI report with metrics on adoption, incidents, enforcement actions and progress on skills and research investments. The law proposes an evaluation mechanism to measure economic impacts and rights-protection outcomes; it includes provisions for stakeholder consultations and a public registry of assessed high-risk systems. These monitoring provisions are intended to align national reporting with the European AI Board processes and the EU-level enforcement timeline.

Penalties, Liability, and Appeals

The draft foresees administrative sanctions for non-compliance (fines scaled to turnover or fixed maxima), orders to suspend or withdraw non-conforming systems, and requirements to remedy deficiencies within set timelines. Liability provisions include civil remedies for damages caused by AI systems and a framework to allocate responsibility between providers, deployers and integrators. The draft proposes administrative appeal routes and judicial review for enforcement decisions. While the party announcement and press coverage reference enforcement and penalties in principle, detailed fine schedules are to be set out in implementing rules and the final legislative text to ensure alignment with EU maxima and Bulgarian administrative procedure.

Relationship to Other Instruments

The proposal explicitly aims to implement and operate alongside the EU AI Regulation (Regulation (EU) 2024/1689) and to respect obligations under the General Data Protection Regulation (GDPR). It also references national administrative law, public procurement law and sectoral regulations (healthcare, consumer protection) as related legal instruments. The draft positions national measures as complementary clarifications rather than replacements for EU law, and seeks to ensure that public-data access and innovation support measures comply with copyright and data-protection regimes.

International Alignment

The draft frames Bulgaria's approach as closely aligned with EU regulation and the European AI Board's enforcement architecture, seeking interoperability with cross-border AI oversight and data-sharing principles across the Union. It recommends active participation in EU-level standardisation and encourages research partnerships with EU programmes. The proposal also commits to harmonising sanctions, conformity assessments and market surveillance approaches with other Member States to avoid market fragmentation. The sponsors underline that national measures are designed to be compatible with EU external obligations and to support Bulgarian industry in EU and international markets.

Implementation Timeline

MilestoneTarget date
Publication of draft for public consultation2025-04-04
Public presentation (venue: "Peroto", NDK)2025-09-23
Collection of signatures / parliamentary submission (anticipated)2025-Q4 (anticipated)
Parliamentary readings and committee review2026 (subject to legislative calendar)
Establishment of National AI Coordinator (if enacted)Within 6 months of enactment

Compliance Checklist

ObligationWhoAction
Risk assessment and mitigationProviders/Deployers (high-risk)Documented risk management system and mitigation plan
Conformity assessmentProviders of high-risk systemsSelf- or third-party conformity assessment; register results
Technical documentation / model cardProvidersMaintain and provide on request
RegistrationProviders of high-risk systemsEnter national registry
Incident reportingProviders/DeployersReport serious incidents to authorities within set timeframe

Sources and References

SourceType
Da, Bulgaria — presentation and project announcement (23 Sep 2025)Primary Source
BTA — press notice (23 Sep 2025)Primary Source
Publications Office of the EU — Regulation (EU) 2024/1689 (AI Act)Primary Source
Plain English

Bulgaria is considering a new national law on artificial intelligence that would regulate how AI systems are developed and used across the country, primarily for companies and public bodies operating within or targeting the Bulgarian market. This draft legislation, proposed by the 'Da, Bulgaria' political party, aims to implement and clarify the broader EU AI Regulation at a national level, while also fostering local innovation and ensuring citizen protection.

The proposed law applies to both providers and deployers of AI systems, especially those classified as "high-risk" under EU definitions. This includes entities based in Bulgaria or those offering AI services into the Bulgarian market, with a specific focus on public sector uses like administrative services and automated decision-making. Key obligations for those in scope include: - Performing detailed conformity assessments for high-risk AI systems. - Maintaining comprehensive technical documentation, often referred to as 'model cards'. - Registering high-risk systems with a national authority. - Promptly reporting any serious incidents involving AI systems.

To oversee these requirements, the draft proposes creating a new National AI Coordinator, supported by a multi-stakeholder Consultative Council for Ethical AI. Operational oversight would be shared with existing bodies like the Commission for Personal Data Protection and the Ministry of Electronic Government.

It's crucial to understand that this is currently a draft bill, and its effective date is unknown, with parliamentary review anticipated in 2026. Non-compliance could lead to administrative fines, which may be scaled to company turnover, orders to suspend or withdraw non-conforming systems, and civil remedies for damages caused by AI. A practical pitfall for businesses is the need to navigate both the overarching EU AI Regulation and these specific national rules, which introduce new layers of governance and compliance. The law also uniquely seeks to boost Bulgaria's tech sector by promoting investment, skills development, and opening up public datasets for local AI model training, alongside national security safeguards.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 9 marked complete

Plain-English obligations under Bulgaria - AI Regulation Draft (RAI-BG-NA-DAPBPXX-2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Providers and deployers of high-risk AI systems.

    providers and deployers of 'high-risk' AI... must perform conformity assessments
  2. #2CriticalBefore placing on market

    Applies to: Providers and deployers of high-risk AI systems.

    Risk assessment and mitigation... Documented risk management system and mitigation plan
  3. #3CriticalBefore placing on market

    Applies to: Providers and deployers of high-risk AI systems.

    produce technical documentation
  4. #4CriticalBefore placing on market

    Applies to: Providers and deployers of high-risk AI systems.

    register systems with a national registry.
  5. #5Critical

    Applies to: Providers and deployers of high-risk AI systems.

    continuous post-market monitoring of high-risk systems
  6. #6Critical

    Applies to: Providers and deployers of high-risk AI systems.

    mandatory incident reporting for serious incidents and near-misses.
  7. #7Critical

    Applies to: Public sector entities procuring AI systems.

    public-sector procurement will include mandatory trustworthiness checks
  8. #8Critical

    Applies to: Public sector entities procuring AI systems.

    model documentation requirements
  9. #9Important

    Applies to: Developers of open models using public archives.

    using public archives under strict privacy and licensing conditions.

© Regulations.AI — created on 13-Jun-2026