Cyprus - AI Regulation Implementation (2024/1689)

Governance Framework for the Implementation of Regulation (EU) 2024/1689 on Artificial Intelligence in Cyprus

Cyprus

RAI-CY-NA-GIE2AXX-2024
Adopted(Adopted)
PolicyGovernance and OversightMarket SurveillanceConformity Assessment and Registration
Export PDF

This framework describes Cyprus’s national governance arrangements and initial steps for implementing Regulation (EU) 2024/1689 (the AI Act). It documents the designation of national competent authorities, the delegation of market surveillance roles, duties for protecting fundamental rights, and the phased plan to operationalise supervisory, conformity and enforcement mechanisms in line with the AI Act.

Summary

In November 2024 the Deputy Ministry of Research, Innovation and Digital Policy (DMRID) completed the first formal national step required by Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act) by notifying the European Commission of the Cypriot public authorities responsible for protecting fundamental rights under Article 77. Cyprus followed up with a Council of Ministers decision (22 January 2025) and a DMRID notice in February 2025 designating the national coordinating authority and national competent authorities for notification, market surveillance and single point of contact functions. The framework establishes: (1) DMRID as the national coordinator and representative to the European Artificial Intelligence Board; (2) the Office of the Commissioner for Electronic Communications and Postal Regulation (OCECPR / Commissioner of Communications) as the notifying authority, a Market Surveillance Authority (MSA) and Cyprus’s single point of contact; and (3) the Commissioner for Personal Data Protection as an MSA for specific high-risk Annex III categories and as the authority for data-protection related prohibited practices enforcement where within its competence. The national list of authorities to protect fundamental rights includes the Commissioner for Personal Data Protection, the Commissioner for Administration and the Protection of Human Rights (Ombudsman) and the Attorney-General; these authorities will be granted additional powers from 2 August 2026 in accordance with the AI Act. The framework outlines Cyprus’s obligations to establish regulatory sandboxes, national registries and to notify national penalty regimes to the Commission. It also commits Cyprus to operationalise conformity assessment, post-market monitoring and coordination with EU-level structures (AI Office / European AI Board). The national implementation is phased to mirror the EU timetable: prohibitions and early obligations from 2 February 2025, GPAI and certain governance chapters from 2 August 2025, and the full set of high-risk obligations by 2 August 2026 (with other staged dates as required by the AI Act). The framework focuses on capacity building (competent authorities and market surveillance), clarity for industry (notifying authority and single point of contact), protection of fundamental rights (designation of oversight authorities), and coordination with personal data protection obligations under the GDPR. It also foresees the possible designation of additional market surveillance authorities by the Council of Ministers for sectoral supervision and the launch of national support measures (guidance, training, and SME support projects). Penalties for infringements will be set by Cyprus in national law in line with Article 99 of the AI Act; the AI Act provides upper limits (up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, and lower tiers for other breaches). The framework entry documents the official sources and initial regulatory architecture that will inform draft secondary legislation, operational guidance and stakeholder engagement in Cyprus through 2025–2026.

Full article

Read full text ↗

Overview

The Republic of Cyprus launched its national governance framework to implement Regulation (EU) 2024/1689 (the AI Act) - EUR-Lex by completing the first statutory step required under the Act on 6 November 2024 (notification of national authorities under Article 77) and by a Council of Ministers decision to designate national competent authorities on 22 January 2025. The Deputy Ministry of Research, Innovation and Digital Policy (DMRID) acts as national coordinator and represents Cyprus at the European Artificial Intelligence Board; the Commissioner of Electronic Communications has been designated as Notifying Authority, Market Surveillance Authority (MSA) and Single Point of Contact; and the Commissioner for Personal Data Protection has been designated as an MSA for several Annex III categories and will exercise enforcement powers for data-protection-related prohibited practices within her remit. These actions were communicated to the Commission as required by the Regulation and are recorded in official ministry notices and press releases. The national framework emphasises phased implementation, inter-agency cooperation, and support for SMEs as Cyprus prepares for the staged application dates set out in the AI Act, including full application of high-risk obligations on 2 August 2026. For details see the DMRID announcement at First milestone for the implementation of Regulation (EU) 2024/1689 on Artificial Intelligence in Cyprus and the follow-up designation notice at Regulation (EU) 2024/1689 establishing harmonised rules on Artificial Intelligence (AI Act).

Definitions

This framework uses the definitions from Regulation (EU) 2024/1689. Key terms include 'AI system' (means software that is developed with machine learning, logic-and-knowledge-based approaches or statistical approaches and can, for a given set of human-defined objectives, generate outputs such as content, predictions, recommendations or decisions), 'provider' (developer or operator placing AI on the market), 'deployer' (natural or legal person placing an AI system into service), 'notified body' (organisations designated to perform conformity assessment), 'market surveillance authority' (national agencies tasked with supervision and enforcement) and 'general-purpose AI (GPAI)' (models intended for broad tasks and adaptable across contexts). These definitions are retained verbatim for legal compatibility with the AI Act (see AI Act, EUR-Lex).

Governance and Institutional Framework

Cyprus’ governance model aligns with Article 70–78 of the AI Act. The Council of Ministers designated the Deputy Ministry of Research, Innovation and Digital Policy (DMRID) as national coordinator and representative to the European Artificial Intelligence Board; the Commissioner of Electronic Communications serves as Notifying Authority, Market Surveillance Authority and Single Point of Contact; and the Commissioner for Personal Data Protection has been designated as a Market Surveillance Authority for specific Annex III high-risk categories and for enforcement of data-protection-related prohibited practices within its remit. The national list of authorities tasked with protection of fundamental rights comprises the Commissioner for Personal Data Protection, the Commissioner for Administration and the Protection of Human Rights (Ombudsman), and the Attorney-General; those authorities will be vested with expanded powers under the AI Act effective from 2 August 2026. The national architecture provides for (i) inter-agency coordination and cross-notification, (ii) establishment of national AI regulatory sandboxes (operational by 2 August 2026 in line with Article 57), (iii) sectoral MSAs to be appointed as required by Council decision, and (iv) an enforcement and penalty regime to be transposed into national secondary rules as required by Article 99. Full details of the national designations are set out by DMRID in its public notices. See the DMRID press releases for the official designations at November 6, 2024 notice and February 6, 2025 follow-up.

Key Focus Areas

The Cyprus implementation framework concentrates on the following key pillars: (1) governance and oversight — establishing DMRID as national coordinator and ensuring representation at EU bodies; (2) market surveillance and conformity — designating a notifying authority and MSAs and preparing for ex ante conformity assessments by notified bodies; (3) protection of fundamental rights and data privacy — ensuring cooperation between the Commissioner for Personal Data Protection and other oversight bodies to enforce Article 5 prohibitions and high‑risk safeguards; (4) transparency and documentation — imposing technical documentation, logs and user-facing disclosures for high‑risk and GPAI systems; (5) risk management and safety testing — requiring providers and deployers to adopt risk-management systems, validation, adversarial testing and incident reporting; (6) cyber‑security and model integrity — aligning with national cybersecurity priorities and the role of the Commissioner of Communications/DSA for resilience and incident handling; and (7) support for innovation — establishing AI regulatory sandboxes, guidance and SME outreach to promote compliance while fostering experimentation. These focus areas mirror the risk-based approach of the AI Act and reflect Cyprus’s commitment to combine rights protection with innovation support. Further information on national coordination and MSA roles is available from the DMRID notices and the Commissioner for Personal Data Protection website at Office of the Commissioner for Personal Data Protection.

Implementation Framework

Operational implementation will follow a staged approach: (A) immediate administrative measures — publication of the list of authorities, internal coordination protocols and initial guidance to industry; (B) legislative adoption — drafting of national secondary instruments and penalty rules required by Article 99 to be notified before the AI Act’s application date; (C) institutional capacity building — staffing and training of MSAs, designation procedures for notified bodies, and interoperable IT systems for registries and complaint handling; (D) technical processes — establishing conformity-assessment procedures, post‑market surveillance plans, incident reporting channels and audit trails; and (E) stakeholder engagement — guidance, consultations, sandboxes and SME support projects (including EU-funded initiatives such as CERV or national programmes). Cyprus will provide a single point of contact to reduce legal fragmentation and will consider designating additional sectoral MSAs where specialist knowledge is required. See the official DMRID designation notice for the initial architecture and planned next steps at DMRID AI Act notice.

Monitoring and Evaluation

Monitoring is organised along two tracks: ex ante conformity (notified bodies and self‑assessment for lower‑risk systems) and ex post market surveillance (MSAs). Cyprus’s MSAs will conduct targeted inspections, require technical documentation and, where necessary, order corrective measures, suspensions or withdrawals. The national framework mandates periodic reporting to the DMRID and coordination with the European AI Board and the AI Office. Key performance indicators include number of registered high‑risk systems, sandbox participants, conformity assessments completed, incidents reported, enforcement actions taken, and SME outreach metrics. The Commissioner for Personal Data Protection will maintain a close interface with MSAs on data‑protection incidents and DPIA compliance to ensure consistent remedies under both the GDPR and the AI Act. Official monitoring responsibilities and cooperation mechanisms are described in the national notices and in the AI Act text at EUR-Lex.

Penalties, Liability, and Appeals

Member States must adopt national penalty regimes in line with Article 99. The AI Act establishes upper limits for administrative fines (e.g., up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited AI practices and tiered lower maxima for other breaches). Cyprus must notify the Commission of its national penalties before the AI Act’s application date and ensure penalties are effective, proportionate and dissuasive. Liability and redress remain available under national civil law and EU law; the framework ensures that affected persons can lodge complaints with MSAs and pursue remedies in courts. Decisions by national authorities are subject to internal appeal and judicial review in accordance with Cypriot law and EU law. See Article 99 and Chapter XII of the AI Act at AI Act text for the EU-level penalty structure.

Relationship to Other Instruments

The Cyprus framework is explicitly designed to operate alongside and in coordination with existing laws: the General Data Protection Regulation (GDPR) as implemented in Cyprus, sectoral EU product safety and transport rules, and national cybersecurity law. The Commissioner for Personal Data Protection will exercise enforcement powers where AI-related conduct engages personal data rights and will cooperate with OCECPR on overlapping cybersecurity and communications matters. National sandbox rules will be drafted to respect existing product-safety regimes and to interoperate with EU-level guidelines and standards referenced by the AI Act. The relationship to existing national instruments is documented in DMRID communications and the respective supervisors’ public material (examples: Data Protection Commissioner; Office of the Commissioner of Communications pages on gov.cy commissioners).

International Alignment

Cyprus’s approach emphasises full alignment with EU obligations and close cooperation with the European AI Board and the AI Office. The national framework also contemplates bilateral and multilateral cooperation for cross‑border enforcement, information‑sharing and capacity building, particularly within the EU and with neighbouring states. Cyprus will follow EU guidance on general‑purpose AI, prohibited practices, and standards. Where appropriate, Cyprus will promote interoperability with international standards (ISO, IEC) and engage in EU diplomatic and technical fora to ensure that its national measures do not create trade or interoperability barriers. For EU-level obligations and timelines, see the official AI Act publication at EUR-Lex.

Implementation Timeline

EventDate
Publication of AI Act in Official Journal (OJ L 2024/1689)2024-07-12
Entry into force (20 days after OJ publication)2024-08-01
Cyprus notifies national authorities under Article 77 (first milestone)2024-11-06
Council decision designating national competent authorities2025-01-22
DMRID public designation / press release2025-02-06
Prohibitions and Chapters I–II apply (EU phased application)2025-02-02
GPAI / certain governance chapters apply at EU level2025-08-02
Full application of high‑risk obligations (AI Act)2026-08-02

Sources and References

SourceType
Regulation (EU) 2024/1689 (Artificial Intelligence Act) - EUR-LexPrimary Source
First milestone for the implementation of Regulation (EU) 2024/1689 on Artificial Intelligence in Cyprus - DMRIDPrimary Source
Regulation (EU) 2024/1689 establishing harmonised rules on Artificial Intelligence (AI Act) - DMRIDPrimary Source
Office of the Commissioner for Personal Data Protection (Cyprus)Primary Source

Requirements for a company

What an organisation has to do under Cyprus - AI Regulation Implementation (2024/1689), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Transpose the AI Act's enforcement and penalty regime into national law.Cypriot Government
  • Notify the European Commission of the national penalty regime.Cypriot Government
  • Register high-risk AI systems with the national authority.Providers of high-risk AI systems
  • Adopt a robust risk-management system for AI systems.Providers and deployers of AI systems
  • Perform validation and adversarial testing for AI systems.Providers and deployers of AI systems
  • Implement an incident reporting mechanism for AI systems.Providers and deployers of AI systems
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Cyprus - AI Regulation Implementation (2024/1689), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Cypriot GovernmentTranspose the AI Act's enforcement and penalty regime into national law.
an enforcement and penalty regime to be transposed into national secondary rules as required by Article 99.
Feb 2, 2025Article 99Critical
2Cypriot GovernmentNotify the European Commission of the national penalty regime.
Cyprus must notify the Commission of its national penalties before the AI Act’s application date
Feb 2, 2025Article 99Critical
3Providers of high-risk AI systemsRegister high-risk AI systems with the national authority.
Key performance indicators include number of registered high‑risk systems
Aug 2, 2026Critical
4Providers and deployers of AI systemsAdopt a robust risk-management system for AI systems.
requiring providers and deployers to adopt risk-management systems
Aug 2, 2026Critical
5Providers and deployers of AI systemsPerform validation and adversarial testing for AI systems.
requiring providers and deployers to adopt... validation, adversarial testing
Aug 2, 2026Critical
6Providers and deployers of AI systemsImplement an incident reporting mechanism for AI systems.
requiring providers and deployers to adopt... incident reporting
Aug 2, 2026Critical
7Providers of high-risk and GPAI systemsProvide technical documentation for high-risk and GPAI systems.
imposing technical documentation, logs and user-facing disclosures for high‑risk and GPAI systems
Aug 2, 2026Critical
8Providers of high-risk and GPAI systemsMaintain logs for high-risk and GPAI systems.
imposing technical documentation, logs and user-facing disclosures for high‑risk and GPAI systems
Aug 2, 2026Critical
9Providers of high-risk and GPAI systemsProvide user-facing disclosures for high-risk and GPAI systems.
imposing technical documentation, logs and user-facing disclosures for high‑risk and GPAI systems
Aug 2, 2026Critical
10Providers and deployers of AI systems processing personal dataEnsure Data Protection Impact Assessments (DPIAs) and data governance for AI processing.
The Commissioner for Personal Data Protection will maintain a close interface with MSAs on data‑protection incidents and DPIA compliance
Aug 2, 2026Critical
11Deputy Ministry of Research, Innovation and Digital Policy (DMRID)Establish national AI regulatory sandboxes.
establishment of national AI regulatory sandboxes (operational by 2 August 2026 in line with Article 57)
Aug 2, 2026Article 57Important
12Cypriot National AuthoritiesEnsure inter-agency coordination and cross-notification among national authorities.
The national architecture provides for (i) inter-agency coordination and cross-notification
Important

© Regulations.AI · updated on 13-Jun-2026