Lithuania - AI Regulatory Sandbox Policy

AI Regulatory Sandbox Policy

Lithuania

RAI-LT-NA-AIRESAX-2024
Adopted(Adopted)
PolicyGovernance and OversightConformity Assessment and RegistrationSafety, Testing, and Evaluation
Export PDF

Lithuania has adopted a national AI regulatory sandbox policy to implement the EU AI Act and accelerate safe AI innovation. The Innovation Agency (Inovacijų agentūra) is designated to operate the sandbox with the Communications Regulatory Authority (RRT) as market surveillance authority, and the initiative includes targeted support for SMEs, access to HPC resources, supervised testing of high-risk systems and reporting obligations under EU law.

Summary

The Lithuanian AI Regulatory Sandbox Policy establishes a supervised national pilot environment for the development, testing and validation of innovative artificial intelligence (AI) systems prior to market placement. The policy implements the EU Artificial Intelligence Act (AI Act) obligations requiring Member States to ensure at least one national AI regulatory sandbox operational by 2 August 2026. Lithuania’s approach assigns primary operational responsibilities to the national Innovation Agency (Inovacijų agentūra), with the Communications Regulatory Authority (RRT) designated as the market surveillance authority and single contact point for market supervision. The Ministry of the Economy and Innovation (EIMIN) has published policy statements and submitted legislative amendments to align domestic law with the AI Act (notably adjustments to the Law on Technology and Innovation and the Law on Information Society Services) and to empower national bodies to establish and run sandbox activities. The sandbox is designed to support SMEs and start-ups (priority access and free-of-charge arrangements are foreseen), to offer regulatory guidance and conformity pathways (including assistance toward notified-body assessment and certification of high‑risk AI systems), and to provide selected participants with access to high-performance computing (HPC) resources and tailored consultations. The policy foregrounds risk management, fundamental‑rights safeguarding, data protection safeguards consistent with Article 59 of the AI Act (allowing limited further processing of personal data for public‑interest AI projects in a sandbox under strict conditions), and cross‑agency cooperation with data protection and sectoral authorities. Participating providers remain civilly liable for harms caused during sandbox testing but—consistent with Article 57 of the AI Act—may be protected from administrative fines under the AI Regulation if they adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith. The Lithuanian programme further allocates EU funds to implement the sandbox nationally (regional split and project cycles have been announced), sets transparent application and selection procedures, and requires annual reporting from national competent authorities to the EU AI Office/Board. The policy emphasises monitoring, publication of non-sensitive exit summaries, and coordination with EU-level tools and platforms to facilitate cross-border cooperation and evidence-based regulatory learning. Primary implementing instruments and operational rules (eligibility, confidentiality, testing oversight, suspension powers, documentation and publication standards, incident reporting, and mechanisms to involve notified bodies and market surveillance entities) are to be established by the Innovation Agency and cooperating authorities pursuant to the amendments lodged by the Ministry of Economy and Innovation.

Full article

Read full text ↗

Overview

The Lithuanian AI Regulatory Sandbox Policy creates a supervised national environment for testing innovative AI systems before they are placed on the market. The initiative implements the requirements of the EU Artificial Intelligence Act (Article 57) and positions the national Ministry of the Economy and Innovation and the Innovation Agency (Inovacijų agentūra) as central actors. The sandbox aims to foster innovation, facilitate compliance pathways (particularly for SMEs and start-ups), and support conformity assessment processes while ensuring that risks to health, safety and fundamental rights are identified and mitigated. National authorities will coordinate with the EU AI Office and the AI Act Board, and the scheme is designed to enable cross‑border cooperation where appropriate.

Definitions

Key terms used for the sandbox policy follow the EU AI Act lexicon and national implementing documents: "AI regulatory sandbox" means a controlled environment supervised by a competent authority for the development, training, testing and validation of AI systems under an agreed sandbox plan; "provider/prospective provider" means the natural or legal person offering or intending to offer an AI system; "notified body" refers to entities authorized to carry out conformity assessment of high‑risk AI systems; "market surveillance" denotes the activities performed by the designated national authority (RRT in Lithuania) to verify compliance and carry out corrective actions when necessary.

Governance and Institutional Framework

Lithuania designates the Innovation Agency as the primary competent authority to create and operate the AI sandbox and to act as the national notifying authority for conformity assessment matters; the Communications Regulatory Authority (RRT) is appointed as market surveillance authority and single contact point for market supervision. The Ministry of the Economy and Innovation has led legislative amendments (to the Law on Technology and Innovation and the Law on Information Society Services) to allocate roles, and will coordinate inter-agency cooperation with the State Data Protection Inspectorate and other sectoral regulators. National authorities are required to allocate sufficient resources and to liaise with the EU AI Office/Board as set out in the AI Act.

Key Focus Areas

The sandbox policy focuses on four principal areas: (1) Information and outreach — centralised, one‑stop information on the AI Act and sandbox services made available online and through events; (2) Regulatory guidance and conformity pathways — hands‑on regulatory advice, pre‑certification support and help to prepare documentation for conformity assessment and notified bodies; (3) Supervised testing of AI systems (including staged real‑world tests for certain high‑risk systems with market surveillance oversight); (4) Technical and infrastructural support — access to HPC resources, technical testbeds and expert assessment services. The programme emphasises SME prioritisation (free or low‑cost access), simplified application processes, and the publication of non‑sensitive exit reports to support lawful market access.

Implementation Framework

Implementation is led by the Innovation Agency which will publish operational rules (eligibility, application, selection, confidentiality, data handling, duration and exit procedures). Projects must agree a sandbox plan with the competent authority that sets scope, duration, testing conditions, risk mitigation measures and reporting obligations. The Communications Regulatory Authority will supervise market surveillance aspects and may permit selected testing of AI systems that would otherwise require full conformity assessment prior to market placement, thereby enabling pre‑certification trials under strict safeguards. The national approach integrates data protection supervision for projects handling personal data (consistent with Article 59 of the AI Act) and includes mechanisms for involvement of other competent authorities when sectoral law is engaged.

Monitoring and Evaluation

National competent authorities will maintain oversight through mandatory documentation, incident reporting and tailored monitoring of each sandbox project. Lithuania will submit annual reports to the EU AI Office/Board once the sandbox is established, containing lessons learned, incidents, mitigation outcomes and recommendations for policy adaptation. The Innovation Agency will publish abstracts of annual reports and (with confidentiality safeguards) exit summaries from sandbox projects to foster regulatory learning and share best practices nationally and across the EU.

Penalties, Liability, and Appeals

Providers participating in the sandbox remain liable under national and Union liability law for damages caused during testing. However, the AI Act specifies that if prospective providers adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith, administrative fines under the AI Regulation will not be imposed for infringements discovered in the sandbox context. National competent authorities retain full supervisory and corrective powers, including the ability to suspend or terminate a testing project where significant risks to health, safety or fundamental rights are identified. The sandbox operating rules will set procedures for appeals and dispute resolution regarding supervisory decisions.

Relationship to Other Instruments

The sandbox policy is explicitly linked to the EU AI Act (Regulation (EU) 2024/1689) and national amendments to the Law on Technology and Innovation and the Law on Information Society Services. It also complements national innovation support programmes and HPC initiatives, and coordinates with data protection law (GDPR) and sectoral regulation (e.g., health, transport) where relevant. The Innovation Agency will also assess and support the accreditation of notified bodies for conformity assessment, aligning national practice with EU delegated and implementing acts.

International Alignment

The Lithuanian sandbox is designed to be interoperable with EU systems and to facilitate cross‑border cooperation among national competent authorities, per the AI Act’s requirement to inform the AI Office and the Board and to enable cooperation. The policy aligns with EU guidance and the EU AI Office’s single interface and reporting structures, and aims to share lessons and test outcomes to contribute to EU‑level regulatory learning and harmonisation.

Implementation Timeline

EventDate
EU AI Act entered into force2024-08-02
Lithuania: Ministry announcement submitting amendments and sandbox plans2024-11-21
Public presentation of the sandbox (planned)2025-10-09
Ministry funding allocation signed (project funding)2025-11-17
Start of capacity-building consultations for selected businesses2026-01-01
Sandbox to be operational (AI Act deadline)2026-08-02

Sources and References

SourceType
EIMIN: EIMIN initiative accelerates development of artificial intelligence in LithuaniaPrimary Source
EIMIN (LT): Pagalba šalies verslams – padės prisitaikyti prie naujojo ES DI reglamentoPrimary Source
AI Act Service Desk: National resources (Lithuania)Primary Source
Inovacijų agentūra (Innovation Agency) – official sitePrimary Source
Communications Regulatory Authority (RRT) – AboutPrimary Source
EIMIN: EIMIN skiria finansavimą DI reguliacinei smėliadėžei (2025-11-17)Primary Source
EU AI Act – Article 57 (AI regulatory sandboxes)Primary Source

Requirements for a company

What an organisation has to do under Lithuania - AI Regulatory Sandbox Policy, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.

Must do

9
  • Agree on a sandbox plan with the competent authority.Providers participating in the AI regulatory sandbox.
  • Ensure data protection safeguards align with Article 59 of the EU AI Act.Providers whose sandbox projects handle personal data.
  • Mitigate risks to avoid damages caused during testing.Providers participating in the AI regulatory sandbox.
  • Adhere to the agreed sandbox plan.Providers participating in the AI regulatory sandbox.
  • Follow the competent authority’s guidance in good faith.Providers participating in the AI regulatory sandbox.
  • Adhere to strict safeguards during pre-certification trials.Providers testing high-risk AI systems in the sandbox.
  • +3 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Contribute to non-sensitive exit reports.Providers completing a sandbox project.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Lithuania - AI Regulatory Sandbox Policy, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers participating in the AI regulatory sandbox.Agree on a sandbox plan with the competent authority.
Projects must agree a sandbox plan with the competent authority that sets scope, duration, testing conditions, risk mitigation measures and reporting obligations.
Before starting testingImplementation FrameworkCritical
2Providers whose sandbox projects handle personal data.Ensure data protection safeguards align with Article 59 of the EU AI Act.
The national approach integrates data protection supervision for projects handling personal data (consistent with Article 59 of the AI Act)
Before starting testingImplementation FrameworkCritical
3Providers participating in the AI regulatory sandbox.Mitigate risks to avoid damages caused during testing.
Providers participating in the sandbox remain liable under national and Union liability law for damages caused during testing.
Throughout the testing periodPenalties, Liability, and AppealsCritical
4Providers participating in the AI regulatory sandbox.Adhere to the agreed sandbox plan.
if prospective providers adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith
Throughout the testing periodPenalties, Liability, and AppealsCritical
5Providers participating in the AI regulatory sandbox.Follow the competent authority’s guidance in good faith.
if prospective providers adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith
Throughout the testing periodPenalties, Liability, and AppealsCritical
6Providers testing high-risk AI systems in the sandbox.Adhere to strict safeguards during pre-certification trials.
enabling pre‑certification trials under strict safeguards.
During pre-certification trialsImplementation FrameworkCritical
7Providers applying for or participating in the AI regulatory sandbox.Comply with the operational rules published by the Innovation Agency.
Implementation is led by the Innovation Agency which will publish operational rules (eligibility, application, selection, confidentiality, data handling, duration and exit procedures).
Before and during participationImplementation FrameworkImportant
8Providers participating in the AI regulatory sandbox.Provide mandatory documentation for the sandbox project.
National competent authorities will maintain oversight through mandatory documentation, incident reporting and tailored monitoring of each sandbox project.
As required by the sandbox planMonitoring and EvaluationImportant
9Providers participating in the AI regulatory sandbox.Report incidents related to the sandbox project.
National competent authorities will maintain oversight through mandatory documentation, incident reporting and tailored monitoring of each sandbox project.
Immediately upon occurrenceMonitoring and EvaluationImportant
10Providers completing a sandbox project.Contribute to non-sensitive exit reports.
The programme emphasises SME prioritisation (free or low‑cost access), simplified application processes, and the publication of non‑sensitive exit reports to support lawful market access.
Upon completion of the projectKey Focus AreasRecommended

© Regulations.AI · updated on 13-Jun-2026