Lithuania - AI Act Implementation (XV-106)

Amendments to the Law on Information Society Services (measures to implement EU AI Act / accelerate AI development)

Įstatymo dėl informacinės visuomenės paslaugų pakeitimai (priemonės, skirtos ES AI akto įgyvendinimui / AI plėtrai paspartinti)

Lithuania

RAI-LT-NA-AISSMXX-2025
Effective: April 1, 2025
In Force(In Force)
ActGovernance and OversightConformity Assessment and RegistrationMarket Surveillance
Export PDF

In January 2025 the Seimas of the Republic of Lithuania adopted targeted amendments to the Law on Information Society Services to align national roles and procedures with the EU Artificial Intelligence Act and to accelerate safe AI development (including an AI regulatory sandbox). The amendments designate the Communications Regulatory Authority (RRT) as the national market surveillance authority and single contact point and the Innovation Agency as the notifying authority for conformity assessment and support the creation of notified bodies, conformity procedures, and market surveillance functions.

Overview

The Act (adopted by the Seimas on 14 January 2025 as law No. XV-106) amends the Law on Information Society Services (No. X-614) to implement key operational requirements of the EU Artificial Intelligence Act and to accelerate safe AI development in Lithuania. It designates national competent authorities, clarifies market surveillance and notifying roles, and creates legal pathways for conformity assessment, notified bodies, and a national AI sandbox for experimental testing. The legislative instrument is available in the national registry and official publication; see the official legal entry at e-tar / legal act (EN) and the Seimas project page at Seimas (LT). The Ministry of the Economy and Innovation published explanatory material and press notices summarizing institutional changes and the rationale for creating an AI sandbox: Ministry press release.

Definitions

The amendments adopt and incorporate definitions consistent with the EU AI Act, clarifying terms used in national practice: "AI system" (software developed using machine learning, logic- and knowledge-based approaches, or statistical methods that outputs a decision, recommendation or prediction), "provider" (natural or legal person placing an AI system on the EU market), "deployer" (entity using an AI system within Lithuania), "high-risk AI system" (categories referenced in Annex III of the AI Act, e.g., critical infrastructure, education, employment, law enforcement, migration, biometric identification, healthcare, essential services), "notified body" (conformity assessment entity assessed and notified by the national notifying authority), and "market surveillance" (activities by the national authority to enforce compliance and remove unsafe AI from the market). The law ties these definitions directly to the text and annexes of the EU AI Act while keeping cross-references to existing national terms used in the Information Society Services Act.

Governance and Institutional Framework

The amendment creates a two-body national governance model aligned with the AI Act: the Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) is designated as the national market surveillance authority and Single Contact Point; the Innovation Agency (Inovacijų agentūra) is designated as the national notifying authority responsible for assessing and notifying conformity assessment bodies and coordinating an AI sandbox. The Ministry of the Economy and Innovation acts as the policy coordinator and sponsor for the sandbox and support programmes. The law requires the RRT to develop surveillance procedures, establish information-sharing channels with sectoral authorities, and to publish annual enforcement reports; the Innovation Agency must define criteria for notifying bodies, maintain a public registry of notified bodies, and operate transparent application and appeal procedures. See the government implementation page for the national competent authority designations at EIMIN - national competent authorities and the public registry entry at Seimas - legal act.

Key Focus Areas

The Act focuses on: (1) institutional designation and cooperation — assigning RRT and the Innovation Agency concrete roles and coordinating with other national bodies protecting fundamental rights (e.g., the Equal Opportunities Ombudsperson and Ombudsmen offices); (2) conformity assessment — enabling notified bodies (private, academic, or public) to certify compliance of high-risk AI systems through harmonised procedures; (3) market surveillance and enforcement — granting the RRT powers to inspect technical documentation, demand source code or datasets under specific safeguards, order corrective measures, and impose administrative penalties; (4) AI sandbox and innovation facilitation — creating a legal mechanism for supervised pilot testing with reduced procedural friction under oversight and time-limited derogations where the sandbox is used solely for testing and evaluation; (5) transparency and user information — obliging providers to disclose system capabilities, limitations, and instructions for safe use; and (6) data governance and cybersecurity — mandating technical and organizational measures to preserve data quality, integrity, and model security. Together these elements balance innovation incentives (sandbox, start-up assessment and targeted public support) with a robust compliance regime for high-risk AI systems.

Implementation Framework

Operational implementation is staged: the law enters into force on 1 April 2025; market surveillance duties for RRT commence from that date while certain notifying authority powers for the Innovation Agency are scheduled from 2 August 2025 to align with notification and accreditation timelines. The Innovation Agency will publish procedures for designation of notified bodies, accreditation criteria, and a public registry; it will also host the AI sandbox operational rules, application procedures, and privacy safeguards. The RRT will issue market surveillance guidance, define technical documentation formats, and coordinate a national single point of contact for cross-border cooperation with the European AI Office. The amendments require interagency memoranda of understanding, cross-training, and budgetary allocations; explanatory materials and guidance documents are posted by the Ministry at EIMIN press release and by the national registry at e-tar.

Monitoring and Evaluation

The law mandates periodic monitoring: the RRT must publish annual surveillance reports (including enforcement actions, risk assessments, and corrective measures). The Innovation Agency must report on notified-body designations, sandbox participants and outcomes, and the Ministry will monitor economic impact indicators (start-up growth, investment, AI adoption metrics). The act also requires a three-year ex-post evaluation plan to assess whether the sandbox and conformity mechanisms effectively support innovation while protecting rights. Data collection duties for monitoring must respect data protection rules; coordination with the national Data Protection Inspectorate and sectoral oversight bodies is required. The Act calls for publication of anonymised summaries of market surveillance outcomes to foster transparency and accountability.

Penalties, Liability, and Appeals

Penalties are administrative and aligned with the AI Act’s framework. The RRT may order corrective measures (withdrawal, suspension, required modifications), impose administrative fines for non-compliance, and publish decisions. The law specifies procedures for administrative appeals and judicial review; affected providers or notified bodies may appeal administrative measures to the competent administrative courts. Liability and redress obligations remain coordinated with existing civil liability rules—providers and deployers can be held civilly liable under national law for harms caused by non-compliant AI systems. The law also contains provisions enabling faster enforcement in public-safety exigencies and safeguards for trade secrets during inspections.

Relationship to Other Instruments

The amendment explicitly interfaces with EU instruments (the EU AI Act, the Digital Services Act and existing EU market surveillance regulations) and national statutes (Law on Technology and Innovation, Data Protection rules, consumer protection law, sector-specific safety regimes such as health or transport). It amends specific articles of the Law on Information Society Services to align national institutional roles with EU obligations; cross-references to the Law on Technology and Innovation ensure coordination where state support and start-up assessment are concerned. The law also references accreditation and standardisation instruments (national accreditation body) to operationalise notified-body qualifying requirements.

International Alignment

The Act is explicitly designed to implement the EU AI Act and to ensure Lithuania meets the EU deadline for designating national competent authorities. It positions Lithuania to participate in EU-level cooperation (European AI Board and AI Office coordination), cross-border market surveillance, and to notify conformity assessment bodies to the EU internal market. The Act therefore supports interoperability with other member states’ enforcement frameworks and strengthens Lithuania’s capacity to be an EU hub for regulated AI testing and certification. See EU-level guidance on market surveillance and national competent authorities at EU - Market Surveillance under AI Act.

Implementation Timeline

EventDateNotes
Draft registered (XIVP-4235)2024-10-18Draft law submitted to Seimas register.
Seimas adoption (law No. XV-106)2025-01-14Formal adoption of amendments.
Published in official gazette (TAR)2025-01-22Publication date; legal publication completed.
Entry into force (major provisions)2025-04-01RRT market surveillance and sandbox enabling provisions become effective.
Innovation Agency notified-body powers operational2025-08-02Start of notification activities by the Innovation Agency per implementation notes.

Compliance Checklist

WhoRequired actionsDeadline / Notes
Providers (high-risk AI)Maintain technical documentation; perform risk and fundamental-rights impact assessments; ensure conformity assessment and register systems where required; implement transparency and user information obligations.Before placing on market/putting into service; ongoing post-market monitoring.
DeployersFollow provider instructions, implement risk mitigation, cooperate with market surveillance; maintain logs and incident reporting.Ongoing; immediate reporting when safety incidents occur.
Notified bodiesApply for designation to Innovation Agency; perform conformity assessments per notified scope; maintain impartiality and confidentiality.As soon as practicable following Innovation Agency procedures (from Aug 2025).
RRT (market surveillance)Establish surveillance procedures, accept complaints, perform inspections, impose corrective measures, publish enforcement reports.Operational from 1 Apr 2025.

Sources and References

SourceType
Lietuvos Respublikos informacinės visuomenės paslaugų įstatymo Nr. X-614 1, 2, 23 straipsnių ir priedo pakeitimo įstatymas (XV-106)Primary Source
Seimas - Legal Act record (LT)Primary Source
Ministry of the Economy and Innovation - press releasePrimary Source
European Commission - Market Surveillance under the AI ActSecondary / Context
Plain English

Lithuania has updated its Law on Information Society Services to implement the EU Artificial Intelligence (AI) Act, creating a new regulatory framework for companies developing or deploying AI systems within the country. This law primarily applies to "providers" – those placing AI systems on the EU market – and "deployers" – entities using AI systems in Lithuania, especially those dealing with "high-risk" AI systems, such as those used in critical infrastructure, education, employment, or law enforcement.

The new rules, effective April 1, 2025, introduce several key obligations. Providers of high-risk AI systems must ensure their products undergo a "conformity assessment" to prove compliance, maintain detailed technical documentation, and provide clear information to users about the system's capabilities and limitations. Deployers, in turn, are expected to follow provider instructions, implement risk mitigation measures, and report any safety incidents. To support innovation, the law also establishes an AI regulatory sandbox, allowing companies to test AI systems in a supervised environment with reduced procedural hurdles.

The Communications Regulatory Authority (RRT) is designated as the national market surveillance authority, tasked with enforcing these rules. The RRT can inspect technical documentation, demand source code or datasets under safeguards, order corrective actions like system withdrawal or suspension, and impose administrative fines for non-compliance. Separately, the Innovation Agency will act as the national notifying authority, responsible for assessing and approving "notified bodies" – third-party entities that will certify AI systems. The Innovation Agency's powers for designating these bodies become operational on August 2, 2025.

A practical consideration for businesses is navigating this dual-agency structure: the RRT handles enforcement, while the Innovation Agency manages certification and the innovation sandbox. Companies should be aware that while the sandbox offers a path for experimental testing, it still operates under oversight. Non-compliant AI systems can also lead to civil liability under existing national laws for any harm caused. The RRT will publish annual enforcement reports, ensuring transparency in how the law is applied.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Lithuania - AI Act Implementation (XV-106). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus AreasBefore placing on market/putting into service

    Applies to: Providers of high-risk AI systems.

    ensure conformity assessment and register systems where required
  2. #2CriticalKey Focus AreasBefore placing on market

    Applies to: Providers of high-risk AI systems.

    obliging providers to disclose system capabilities, limitations, and instructions for safe use
  3. #3CriticalKey Focus AreasOngoing

    Applies to: Providers of high-risk AI systems.

    mandating technical and organizational measures to preserve data quality, integrity, and model security.
  4. #4CriticalKey Focus AreasUpon request

    Applies to: Providers of high-risk AI systems.

    granting the RRT powers to inspect technical documentation, demand source code or datasets under specific safeguards
  5. #5CriticalGovernance and Institutional FrameworkApr 1, 2025

    Applies to: Communications Regulatory Authority (RRT).

    the RRT to develop surveillance procedures, establish information-sharing channels with sectoral authorities
  6. #6CriticalGovernance and Institutional FrameworkAug 2, 2025

    Applies to: Innovation Agency.

    the Innovation Agency must define criteria for notifying bodies, maintain a public registry of notified bodies, and operate transparent application and appeal procedures.
  7. #7ImportantCompliance ChecklistOngoing

    Applies to: Deployers of AI systems within Lithuania.

    Follow provider instructions, implement risk mitigation, cooperate with market surveillance
  8. #8ImportantCompliance ChecklistAs soon as practicable from 2025-08-02

    Applies to: Entities seeking to become notified bodies.

    Apply for designation to Innovation Agency
  9. #9ImportantCompliance ChecklistOngoing, once designated

    Applies to: Designated notified bodies.

    perform conformity assessments per notified scope; maintain impartiality and confidentiality.
  10. #10ImportantMonitoring and EvaluationAnnually, starting 2026

    Applies to: Communications Regulatory Authority (RRT).

    the RRT must publish annual surveillance reports (including enforcement actions, risk assessments, and corrective measures).
  11. #11ImportantImplementation FrameworkAug 2, 2025

    Applies to: Innovation Agency.

    it will also host the AI sandbox operational rules, application procedures, and privacy safeguards.
  12. #12ImportantMonitoring and EvaluationOngoing

    Applies to: RRT and Innovation Agency.

    Data collection duties for monitoring must respect data protection rules; coordination with the national Data Protection Inspectorate

© Regulations.AI — created on 13-Jun-2026