Lithuania - AI Regulatory Sandbox Policy
AI Regulatory Sandbox Policy
Lithuania
RAI-LT-NA-AIRESAX-2024Lithuania has adopted a national AI regulatory sandbox policy to implement the EU AI Act and accelerate safe AI innovation. The Innovation Agency (Inovacijų agentūra) is designated to operate the sandbox with the Communications Regulatory Authority (RRT) as market surveillance authority, and the initiative includes targeted support for SMEs, access to HPC resources, supervised testing of high-risk systems and reporting obligations under EU law.
Summary
The Lithuanian AI Regulatory Sandbox Policy establishes a supervised national pilot environment for the development, testing and validation of innovative artificial intelligence (AI) systems prior to market placement. The policy implements the EU Artificial Intelligence Act (AI Act) obligations requiring Member States to ensure at least one national AI regulatory sandbox operational by 2 August 2026. Lithuania’s approach assigns primary operational responsibilities to the national Innovation Agency (Inovacijų agentūra), with the Communications Regulatory Authority (RRT) designated as the market surveillance authority and single contact point for market supervision. The Ministry of the Economy and Innovation (EIMIN) has published policy statements and submitted legislative amendments to align domestic law with the AI Act (notably adjustments to the Law on Technology and Innovation and the Law on Information Society Services) and to empower national bodies to establish and run sandbox activities. The sandbox is designed to support SMEs and start-ups (priority access and free-of-charge arrangements are foreseen), to offer regulatory guidance and conformity pathways (including assistance toward notified-body assessment and certification of high‑risk AI systems), and to provide selected participants with access to high-performance computing (HPC) resources and tailored consultations. The policy foregrounds risk management, fundamental‑rights safeguarding, data protection safeguards consistent with Article 59 of the AI Act (allowing limited further processing of personal data for public‑interest AI projects in a sandbox under strict conditions), and cross‑agency cooperation with data protection and sectoral authorities. Participating providers remain civilly liable for harms caused during sandbox testing but—consistent with Article 57 of the AI Act—may be protected from administrative fines under the AI Regulation if they adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith. The Lithuanian programme further allocates EU funds to implement the sandbox nationally (regional split and project cycles have been announced), sets transparent application and selection procedures, and requires annual reporting from national competent authorities to the EU AI Office/Board. The policy emphasises monitoring, publication of non-sensitive exit summaries, and coordination with EU-level tools and platforms to facilitate cross-border cooperation and evidence-based regulatory learning. Primary implementing instruments and operational rules (eligibility, confidentiality, testing oversight, suspension powers, documentation and publication standards, incident reporting, and mechanisms to involve notified bodies and market surveillance entities) are to be established by the Innovation Agency and cooperating authorities pursuant to the amendments lodged by the Ministry of Economy and Innovation.
Full article
Read full text ↗Overview
The Lithuanian AI Regulatory Sandbox Policy creates a supervised national environment for testing innovative AI systems before they are placed on the market. The initiative implements the requirements of the EU Artificial Intelligence Act (Article 57) and positions the national Ministry of the Economy and Innovation and the Innovation Agency (Inovacijų agentūra) as central actors. The sandbox aims to foster innovation, facilitate compliance pathways (particularly for SMEs and start-ups), and support conformity assessment processes while ensuring that risks to health, safety and fundamental rights are identified and mitigated. National authorities will coordinate with the EU AI Office and the AI Act Board, and the scheme is designed to enable cross‑border cooperation where appropriate.
Definitions
Key terms used for the sandbox policy follow the EU AI Act lexicon and national implementing documents: "AI regulatory sandbox" means a controlled environment supervised by a competent authority for the development, training, testing and validation of AI systems under an agreed sandbox plan; "provider/prospective provider" means the natural or legal person offering or intending to offer an AI system; "notified body" refers to entities authorized to carry out conformity assessment of high‑risk AI systems; "market surveillance" denotes the activities performed by the designated national authority (RRT in Lithuania) to verify compliance and carry out corrective actions when necessary.
Governance and Institutional Framework
Lithuania designates the Innovation Agency as the primary competent authority to create and operate the AI sandbox and to act as the national notifying authority for conformity assessment matters; the Communications Regulatory Authority (RRT) is appointed as market surveillance authority and single contact point for market supervision. The Ministry of the Economy and Innovation has led legislative amendments (to the Law on Technology and Innovation and the Law on Information Society Services) to allocate roles, and will coordinate inter-agency cooperation with the State Data Protection Inspectorate and other sectoral regulators. National authorities are required to allocate sufficient resources and to liaise with the EU AI Office/Board as set out in the AI Act.
Key Focus Areas
The sandbox policy focuses on four principal areas: (1) Information and outreach — centralised, one‑stop information on the AI Act and sandbox services made available online and through events; (2) Regulatory guidance and conformity pathways — hands‑on regulatory advice, pre‑certification support and help to prepare documentation for conformity assessment and notified bodies; (3) Supervised testing of AI systems (including staged real‑world tests for certain high‑risk systems with market surveillance oversight); (4) Technical and infrastructural support — access to HPC resources, technical testbeds and expert assessment services. The programme emphasises SME prioritisation (free or low‑cost access), simplified application processes, and the publication of non‑sensitive exit reports to support lawful market access.
Implementation Framework
Implementation is led by the Innovation Agency which will publish operational rules (eligibility, application, selection, confidentiality, data handling, duration and exit procedures). Projects must agree a sandbox plan with the competent authority that sets scope, duration, testing conditions, risk mitigation measures and reporting obligations. The Communications Regulatory Authority will supervise market surveillance aspects and may permit selected testing of AI systems that would otherwise require full conformity assessment prior to market placement, thereby enabling pre‑certification trials under strict safeguards. The national approach integrates data protection supervision for projects handling personal data (consistent with Article 59 of the AI Act) and includes mechanisms for involvement of other competent authorities when sectoral law is engaged.
Monitoring and Evaluation
National competent authorities will maintain oversight through mandatory documentation, incident reporting and tailored monitoring of each sandbox project. Lithuania will submit annual reports to the EU AI Office/Board once the sandbox is established, containing lessons learned, incidents, mitigation outcomes and recommendations for policy adaptation. The Innovation Agency will publish abstracts of annual reports and (with confidentiality safeguards) exit summaries from sandbox projects to foster regulatory learning and share best practices nationally and across the EU.
Penalties, Liability, and Appeals
Providers participating in the sandbox remain liable under national and Union liability law for damages caused during testing. However, the AI Act specifies that if prospective providers adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith, administrative fines under the AI Regulation will not be imposed for infringements discovered in the sandbox context. National competent authorities retain full supervisory and corrective powers, including the ability to suspend or terminate a testing project where significant risks to health, safety or fundamental rights are identified. The sandbox operating rules will set procedures for appeals and dispute resolution regarding supervisory decisions.
Relationship to Other Instruments
The sandbox policy is explicitly linked to the EU AI Act (Regulation (EU) 2024/1689) and national amendments to the Law on Technology and Innovation and the Law on Information Society Services. It also complements national innovation support programmes and HPC initiatives, and coordinates with data protection law (GDPR) and sectoral regulation (e.g., health, transport) where relevant. The Innovation Agency will also assess and support the accreditation of notified bodies for conformity assessment, aligning national practice with EU delegated and implementing acts.
International Alignment
The Lithuanian sandbox is designed to be interoperable with EU systems and to facilitate cross‑border cooperation among national competent authorities, per the AI Act’s requirement to inform the AI Office and the Board and to enable cooperation. The policy aligns with EU guidance and the EU AI Office’s single interface and reporting structures, and aims to share lessons and test outcomes to contribute to EU‑level regulatory learning and harmonisation.
Implementation Timeline
| Event | Date |
|---|---|
| EU AI Act entered into force | 2024-08-02 |
| Lithuania: Ministry announcement submitting amendments and sandbox plans | 2024-11-21 |
| Public presentation of the sandbox (planned) | 2025-10-09 |
| Ministry funding allocation signed (project funding) | 2025-11-17 |
| Start of capacity-building consultations for selected businesses | 2026-01-01 |
| Sandbox to be operational (AI Act deadline) | 2026-08-02 |
Sources and References
Requirements for a company
What an organisation has to do under Lithuania - AI Regulatory Sandbox Policy, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.
Must do
9- Agree on a sandbox plan with the competent authority.Providers participating in the AI regulatory sandbox.
- Ensure data protection safeguards align with Article 59 of the EU AI Act.Providers whose sandbox projects handle personal data.
- Mitigate risks to avoid damages caused during testing.Providers participating in the AI regulatory sandbox.
- Adhere to the agreed sandbox plan.Providers participating in the AI regulatory sandbox.
- Follow the competent authority’s guidance in good faith.Providers participating in the AI regulatory sandbox.
- Adhere to strict safeguards during pre-certification trials.Providers testing high-risk AI systems in the sandbox.
- +3 more in the table below
Must not do
0Nothing in this category.
Should do
1- Contribute to non-sensitive exit reports.Providers completing a sandbox project.
Should not do
0Nothing in this category.
Who must do what
The obligations under Lithuania - AI Regulatory Sandbox Policy, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers participating in the AI regulatory sandbox. | Agree on a sandbox plan with the competent authority. “Projects must agree a sandbox plan with the competent authority that sets scope, duration, testing conditions, risk mitigation measures and reporting obligations.” | Before starting testing | Implementation Framework | Critical |
| 2 | Providers whose sandbox projects handle personal data. | Ensure data protection safeguards align with Article 59 of the EU AI Act. “The national approach integrates data protection supervision for projects handling personal data (consistent with Article 59 of the AI Act)” | Before starting testing | Implementation Framework | Critical |
| 3 | Providers participating in the AI regulatory sandbox. | Mitigate risks to avoid damages caused during testing. “Providers participating in the sandbox remain liable under national and Union liability law for damages caused during testing.” | Throughout the testing period | Penalties, Liability, and Appeals | Critical |
| 4 | Providers participating in the AI regulatory sandbox. | Adhere to the agreed sandbox plan. “if prospective providers adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith” | Throughout the testing period | Penalties, Liability, and Appeals | Critical |
| 5 | Providers participating in the AI regulatory sandbox. | Follow the competent authority’s guidance in good faith. “if prospective providers adhere to the agreed sandbox plan and follow the competent authority’s guidance in good faith” | Throughout the testing period | Penalties, Liability, and Appeals | Critical |
| 6 | Providers testing high-risk AI systems in the sandbox. | Adhere to strict safeguards during pre-certification trials. “enabling pre‑certification trials under strict safeguards.” | During pre-certification trials | Implementation Framework | Critical |
| 7 | Providers applying for or participating in the AI regulatory sandbox. | Comply with the operational rules published by the Innovation Agency. “Implementation is led by the Innovation Agency which will publish operational rules (eligibility, application, selection, confidentiality, data handling, duration and exit procedures).” | Before and during participation | Implementation Framework | Important |
| 8 | Providers participating in the AI regulatory sandbox. | Provide mandatory documentation for the sandbox project. “National competent authorities will maintain oversight through mandatory documentation, incident reporting and tailored monitoring of each sandbox project.” | As required by the sandbox plan | Monitoring and Evaluation | Important |
| 9 | Providers participating in the AI regulatory sandbox. | Report incidents related to the sandbox project. “National competent authorities will maintain oversight through mandatory documentation, incident reporting and tailored monitoring of each sandbox project.” | Immediately upon occurrence | Monitoring and Evaluation | Important |
| 10 | Providers completing a sandbox project. | Contribute to non-sensitive exit reports. “The programme emphasises SME prioritisation (free or low‑cost access), simplified application processes, and the publication of non‑sensitive exit reports to support lawful market access.” | Upon completion of the project | Key Focus Areas | Recommended |
Related Regulations
National AI Strategy update / National AI Governance Forum
Lithuania95% similar
Amendments to the Law on Information Society Services (measures to implement EU AI Act / accelerate AI development)
Lithuania95% similar
Amendments to the Law on Technology and Innovation (measures to implement EU AI Act / accelerate AI development)
Lithuania95% similar
Amendments implementing the EU Artificial Intelligence Act: Amendments to the Law on Technology and Innovation (XV-105) and the Law on Information Society Services (XV-106) to implement Regulation (EU) 2024/1689 (Lithuanian AI Act implementation amendments)
Lithuania94% similar
Action Plan for the Development of Artificial Intelligence Technologies in Lithuania 2023–2026
Lithuania92% similar
© Regulations.AI · updated on 13-Jun-2026