Lithuania - AI Act Implementation (XV-106)
Amendments to the Law on Information Society Services (measures to implement EU AI Act / accelerate AI development)
Įstatymo dėl informacinės visuomenės paslaugų pakeitimai (priemonės, skirtos ES AI akto įgyvendinimui / AI plėtrai paspartinti)
Lithuania
RAI-LT-NA-AISSMXX-2025In January 2025 the Seimas of the Republic of Lithuania adopted targeted amendments to the Law on Information Society Services to align national roles and procedures with the EU Artificial Intelligence Act and to accelerate safe AI development (including an AI regulatory sandbox). The amendments designate the Communications Regulatory Authority (RRT) as the national market surveillance authority and single contact point and the Innovation Agency as the notifying authority for conformity assessment and support the creation of notified bodies, conformity procedures, and market surveillance functions.
Summary
Read full text ↗Plain English
Overview
The Act (adopted by the Seimas on 14 January 2025 as law No. XV-106) amends the Law on Information Society Services (No. X-614) to implement key operational requirements of the EU Artificial Intelligence Act and to accelerate safe AI development in Lithuania. It designates national competent authorities, clarifies market surveillance and notifying roles, and creates legal pathways for conformity assessment, notified bodies, and a national AI sandbox for experimental testing. The legislative instrument is available in the national registry and official publication; see the official legal entry at e-tar / legal act (EN) and the Seimas project page at Seimas (LT). The Ministry of the Economy and Innovation published explanatory material and press notices summarizing institutional changes and the rationale for creating an AI sandbox: Ministry press release.
Definitions
The amendments adopt and incorporate definitions consistent with the EU AI Act, clarifying terms used in national practice: "AI system" (software developed using machine learning, logic- and knowledge-based approaches, or statistical methods that outputs a decision, recommendation or prediction), "provider" (natural or legal person placing an AI system on the EU market), "deployer" (entity using an AI system within Lithuania), "high-risk AI system" (categories referenced in Annex III of the AI Act, e.g., critical infrastructure, education, employment, law enforcement, migration, biometric identification, healthcare, essential services), "notified body" (conformity assessment entity assessed and notified by the national notifying authority), and "market surveillance" (activities by the national authority to enforce compliance and remove unsafe AI from the market). The law ties these definitions directly to the text and annexes of the EU AI Act while keeping cross-references to existing national terms used in the Information Society Services Act.
Governance and Institutional Framework
The amendment creates a two-body national governance model aligned with the AI Act: the Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) is designated as the national market surveillance authority and Single Contact Point; the Innovation Agency (Inovacijų agentūra) is designated as the national notifying authority responsible for assessing and notifying conformity assessment bodies and coordinating an AI sandbox. The Ministry of the Economy and Innovation acts as the policy coordinator and sponsor for the sandbox and support programmes. The law requires the RRT to develop surveillance procedures, establish information-sharing channels with sectoral authorities, and to publish annual enforcement reports; the Innovation Agency must define criteria for notifying bodies, maintain a public registry of notified bodies, and operate transparent application and appeal procedures. See the government implementation page for the national competent authority designations at EIMIN - national competent authorities and the public registry entry at Seimas - legal act.
Key Focus Areas
The Act focuses on: (1) institutional designation and cooperation — assigning RRT and the Innovation Agency concrete roles and coordinating with other national bodies protecting fundamental rights (e.g., the Equal Opportunities Ombudsperson and Ombudsmen offices); (2) conformity assessment — enabling notified bodies (private, academic, or public) to certify compliance of high-risk AI systems through harmonised procedures; (3) market surveillance and enforcement — granting the RRT powers to inspect technical documentation, demand source code or datasets under specific safeguards, order corrective measures, and impose administrative penalties; (4) AI sandbox and innovation facilitation — creating a legal mechanism for supervised pilot testing with reduced procedural friction under oversight and time-limited derogations where the sandbox is used solely for testing and evaluation; (5) transparency and user information — obliging providers to disclose system capabilities, limitations, and instructions for safe use; and (6) data governance and cybersecurity — mandating technical and organizational measures to preserve data quality, integrity, and model security. Together these elements balance innovation incentives (sandbox, start-up assessment and targeted public support) with a robust compliance regime for high-risk AI systems.
Implementation Framework
Operational implementation is staged: the law enters into force on 1 April 2025; market surveillance duties for RRT commence from that date while certain notifying authority powers for the Innovation Agency are scheduled from 2 August 2025 to align with notification and accreditation timelines. The Innovation Agency will publish procedures for designation of notified bodies, accreditation criteria, and a public registry; it will also host the AI sandbox operational rules, application procedures, and privacy safeguards. The RRT will issue market surveillance guidance, define technical documentation formats, and coordinate a national single point of contact for cross-border cooperation with the European AI Office. The amendments require interagency memoranda of understanding, cross-training, and budgetary allocations; explanatory materials and guidance documents are posted by the Ministry at EIMIN press release and by the national registry at e-tar.
Monitoring and Evaluation
The law mandates periodic monitoring: the RRT must publish annual surveillance reports (including enforcement actions, risk assessments, and corrective measures). The Innovation Agency must report on notified-body designations, sandbox participants and outcomes, and the Ministry will monitor economic impact indicators (start-up growth, investment, AI adoption metrics). The act also requires a three-year ex-post evaluation plan to assess whether the sandbox and conformity mechanisms effectively support innovation while protecting rights. Data collection duties for monitoring must respect data protection rules; coordination with the national Data Protection Inspectorate and sectoral oversight bodies is required. The Act calls for publication of anonymised summaries of market surveillance outcomes to foster transparency and accountability.
Penalties, Liability, and Appeals
Penalties are administrative and aligned with the AI Act’s framework. The RRT may order corrective measures (withdrawal, suspension, required modifications), impose administrative fines for non-compliance, and publish decisions. The law specifies procedures for administrative appeals and judicial review; affected providers or notified bodies may appeal administrative measures to the competent administrative courts. Liability and redress obligations remain coordinated with existing civil liability rules—providers and deployers can be held civilly liable under national law for harms caused by non-compliant AI systems. The law also contains provisions enabling faster enforcement in public-safety exigencies and safeguards for trade secrets during inspections.
Relationship to Other Instruments
The amendment explicitly interfaces with EU instruments (the EU AI Act, the Digital Services Act and existing EU market surveillance regulations) and national statutes (Law on Technology and Innovation, Data Protection rules, consumer protection law, sector-specific safety regimes such as health or transport). It amends specific articles of the Law on Information Society Services to align national institutional roles with EU obligations; cross-references to the Law on Technology and Innovation ensure coordination where state support and start-up assessment are concerned. The law also references accreditation and standardisation instruments (national accreditation body) to operationalise notified-body qualifying requirements.
International Alignment
The Act is explicitly designed to implement the EU AI Act and to ensure Lithuania meets the EU deadline for designating national competent authorities. It positions Lithuania to participate in EU-level cooperation (European AI Board and AI Office coordination), cross-border market surveillance, and to notify conformity assessment bodies to the EU internal market. The Act therefore supports interoperability with other member states’ enforcement frameworks and strengthens Lithuania’s capacity to be an EU hub for regulated AI testing and certification. See EU-level guidance on market surveillance and national competent authorities at EU - Market Surveillance under AI Act.
Implementation Timeline
| Event | Date | Notes |
|---|---|---|
| Draft registered (XIVP-4235) | 2024-10-18 | Draft law submitted to Seimas register. |
| Seimas adoption (law No. XV-106) | 2025-01-14 | Formal adoption of amendments. |
| Published in official gazette (TAR) | 2025-01-22 | Publication date; legal publication completed. |
| Entry into force (major provisions) | 2025-04-01 | RRT market surveillance and sandbox enabling provisions become effective. |
| Innovation Agency notified-body powers operational | 2025-08-02 | Start of notification activities by the Innovation Agency per implementation notes. |
Compliance Checklist
| Who | Required actions | Deadline / Notes |
|---|---|---|
| Providers (high-risk AI) | Maintain technical documentation; perform risk and fundamental-rights impact assessments; ensure conformity assessment and register systems where required; implement transparency and user information obligations. | Before placing on market/putting into service; ongoing post-market monitoring. |
| Deployers | Follow provider instructions, implement risk mitigation, cooperate with market surveillance; maintain logs and incident reporting. | Ongoing; immediate reporting when safety incidents occur. |
| Notified bodies | Apply for designation to Innovation Agency; perform conformity assessments per notified scope; maintain impartiality and confidentiality. | As soon as practicable following Innovation Agency procedures (from Aug 2025). |
| RRT (market surveillance) | Establish surveillance procedures, accept complaints, perform inspections, impose corrective measures, publish enforcement reports. | Operational from 1 Apr 2025. |
Sources and References
| Source | Type |
|---|---|
| Lietuvos Respublikos informacinės visuomenės paslaugų įstatymo Nr. X-614 1, 2, 23 straipsnių ir priedo pakeitimo įstatymas (XV-106) | Primary Source |
| Seimas - Legal Act record (LT) | Primary Source |
| Ministry of the Economy and Innovation - press release | Primary Source |
| European Commission - Market Surveillance under the AI Act | Secondary / Context |
Lithuania has updated its Law on Information Society Services to implement the EU Artificial Intelligence (AI) Act, creating a new regulatory framework for companies developing or deploying AI systems within the country. This law primarily applies to "providers" – those placing AI systems on the EU market – and "deployers" – entities using AI systems in Lithuania, especially those dealing with "high-risk" AI systems, such as those used in critical infrastructure, education, employment, or law enforcement.
The new rules, effective April 1, 2025, introduce several key obligations. Providers of high-risk AI systems must ensure their products undergo a "conformity assessment" to prove compliance, maintain detailed technical documentation, and provide clear information to users about the system's capabilities and limitations. Deployers, in turn, are expected to follow provider instructions, implement risk mitigation measures, and report any safety incidents. To support innovation, the law also establishes an AI regulatory sandbox, allowing companies to test AI systems in a supervised environment with reduced procedural hurdles.
The Communications Regulatory Authority (RRT) is designated as the national market surveillance authority, tasked with enforcing these rules. The RRT can inspect technical documentation, demand source code or datasets under safeguards, order corrective actions like system withdrawal or suspension, and impose administrative fines for non-compliance. Separately, the Innovation Agency will act as the national notifying authority, responsible for assessing and approving "notified bodies" – third-party entities that will certify AI systems. The Innovation Agency's powers for designating these bodies become operational on August 2, 2025.
A practical consideration for businesses is navigating this dual-agency structure: the RRT handles enforcement, while the Innovation Agency manages certification and the innovation sandbox. Companies should be aware that while the sandbox offers a path for experimental testing, it still operates under oversight. Non-compliant AI systems can also lead to civil liability under existing national laws for any harm caused. The RRT will publish annual enforcement reports, ensuring transparency in how the law is applied.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Lithuania - AI Act Implementation (XV-106). Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas⏰ Before placing on market/putting into service
Applies to: Providers of high-risk AI systems.
“ensure conformity assessment and register systems where required”
- #2CriticalKey Focus Areas⏰ Before placing on market
Applies to: Providers of high-risk AI systems.
“obliging providers to disclose system capabilities, limitations, and instructions for safe use”
- #3CriticalKey Focus Areas⏰ Ongoing
Applies to: Providers of high-risk AI systems.
“mandating technical and organizational measures to preserve data quality, integrity, and model security.”
- #4CriticalKey Focus Areas⏰ Upon request
Applies to: Providers of high-risk AI systems.
“granting the RRT powers to inspect technical documentation, demand source code or datasets under specific safeguards”
- #5CriticalGovernance and Institutional Framework⏰ Apr 1, 2025
Applies to: Communications Regulatory Authority (RRT).
“the RRT to develop surveillance procedures, establish information-sharing channels with sectoral authorities”
- #6CriticalGovernance and Institutional Framework⏰ Aug 2, 2025
Applies to: Innovation Agency.
“the Innovation Agency must define criteria for notifying bodies, maintain a public registry of notified bodies, and operate transparent application and appeal procedures.”
- #7ImportantCompliance Checklist⏰ Ongoing
Applies to: Deployers of AI systems within Lithuania.
“Follow provider instructions, implement risk mitigation, cooperate with market surveillance”
- #8ImportantCompliance Checklist⏰ As soon as practicable from 2025-08-02
Applies to: Entities seeking to become notified bodies.
“Apply for designation to Innovation Agency”
- #9ImportantCompliance Checklist⏰ Ongoing, once designated
Applies to: Designated notified bodies.
“perform conformity assessments per notified scope; maintain impartiality and confidentiality.”
- #10ImportantMonitoring and Evaluation⏰ Annually, starting 2026
Applies to: Communications Regulatory Authority (RRT).
“the RRT must publish annual surveillance reports (including enforcement actions, risk assessments, and corrective measures).”
- #11ImportantImplementation Framework⏰ Aug 2, 2025
Applies to: Innovation Agency.
“it will also host the AI sandbox operational rules, application procedures, and privacy safeguards.”
- #12ImportantMonitoring and Evaluation⏰ Ongoing
Applies to: RRT and Innovation Agency.
“Data collection duties for monitoring must respect data protection rules; coordination with the national Data Protection Inspectorate”
Related Regulations
Amendments implementing the EU Artificial Intelligence Act: Amendments to the Law on Technology and Innovation (XV-105) and the Law on Information Society Services (XV-106) to implement Regulation (EU) 2024/1689 (Lithuanian AI Act implementation amendments)
Lithuania97% similar
Amendments to the Law on Technology and Innovation (measures to implement EU AI Act / accelerate AI development)
Lithuania97% similar
AI Regulatory Sandbox Policy
Lithuania95% similar
National AI Strategy update / National AI Governance Forum
Lithuania94% similar
Action Plan for the Development of Artificial Intelligence Technologies in Lithuania 2023–2026
Lithuania92% similar
© Regulations.AI — created on 13-Jun-2026