Lithuania - AI Development Amendments (XV-105)
Amendments to the Law on Technology and Innovation
Įstatymo dėl technologijų ir inovacijų pakeitimai
Lithuania
RAI-LT-NA-ATIMIXX-2025Amendments to the Law on Technology and Innovation (adopted 14 January 2025) implement key institutional and practical measures to enable Lithuania to apply the EU Artificial Intelligence Act, accelerate AI development through a national "AI sandbox", and assign national roles for conformity assessment and market surveillance. They revise the definition and support mechanisms for start‑ups and vest new functions in the Innovation Agency and the Communications Regulatory Authority.
Summary
In January 2025 the Seimas adopted targeted amendments to the Law on Technology and Innovation (adopted 14 January 2025, published in the official TAR on 22 January 2025) to prepare Lithuania for implementation of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and to stimulate national AI development. The package (consolidated into Act No. XV-105) designates national implementing bodies, clarifies institutional responsibilities, creates a legal basis for an AI pilot environment ("AI sandbox"), and introduces measures to accelerate start‑up support and conformity assessment capacity.
Key institutional changes include designation of the Innovation Agency as the national notifying authority responsible for assessing and approving bodies that will act as notified/conformity assessment bodies under the EU AI Act, and designation of the Communications Regulatory Authority (RRT) as the national market surveillance authority and single point of contact for enforcement and reporting. The amendments empower the Innovation Agency to assess business development potential of start‑ups seeking public support, effectively refining the national "start‑up" definition to include an innovation potential test in addition to age/size criteria.
Operationally, the Act enables creation of an AI sandbox (pilot regulatory environment) administered at national level to allow controlled testing of AI systems; clarifies that notified bodies (companies, research and academic institutions) may undertake conformity assessments for high‑risk AI systems; and requires market surveillance functions for AI systems in line with the EU Act. The amendments also link national measures to data protection and information society obligations, and phase certain provisions into force at dates aligned with EU transitional timelines. Several provisions have staggered effective dates (some parts effective 2025‑01‑23, others 2025‑08‑02 or 2026‑01‑01). The law strengthens Lithuania's capacity to both accelerate commercial AI development and to fulfil EU obligations on risk‑based obligations, transparency, conformity assessment and market oversight.
Full article
Read full text ↗Overview
The amendments adopted by the Seimas on 14 January 2025 (registered as Act No. XV-105 and published in the official TAR on 22 January 2025) revise the Law on Technology and Innovation to support two parallel objectives: (1) prepare national institutions and processes for implementation of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), and (2) accelerate domestic AI development through an authorised pilot environment or "AI sandbox". The package assigns core roles to the Innovation Agency and the Communications Regulatory Authority, authorises conformity assessment by notified bodies, introduces a business‑potential assessment for start‑up classification, and establishes a legal basis for supervised testing environments where AI products can be developed and trialled under controlled conditions. The Ministry of Economy and Innovation communicated the changes as part of Lithuania's strategy to be among the first EU Member States to operationalise national arrangements for the EU AI Act and to stimulate a competitive AI ecosystem (Ministry press release).
Definitions
The amendment package updates the Law's definitional section to cross‑reference the EU AI Act risk taxonomy and to add national operational definitions: "AI sandbox" (pilot regulatory environment for supervised testing of AI systems), "notified body" (organisation approved by the national notifying authority to perform conformity assessments), and an enriched "start‑up" definition that combines firm age (registered no longer than five years) with an "innovation and growth potential" assessment performed by the Innovation Agency. The law expressly aligns national definitions with the EU Act's categories (unacceptable, prohibited, high‑risk, limited‑risk, and minimal‑risk systems) and clarifies that high‑risk AI systems placed on the Lithuanian market must follow EU conformity assessment and registration rules. The amendments also create a statutory link between technology oversight and existing information society and data protection obligations, directing implementing authorities to coordinate with data protection and consumer protection bodies.
Governance and Institutional Framework
Institutionally, the amendments designate the Innovation Agency as the national notifying authority responsible for: (a) assessing and approving bodies seeking notification to act as conformity assessment entities; (b) coordinating national capacity building for conformity assessment and certification; and (c) administrating elements of the AI sandbox related to business support and experimentation. The Communications Regulatory Authority (RRT) is named the national market surveillance authority and single point of contact for enforcement, market oversight, and cross‑border cooperation with EU authorities. The law tasks the Ministry of Economy and Innovation with overall policy coordination and with supervising the launch and governance of the AI sandbox. These arrangements are described in official materials and the Ministry's public communications (Ministry announcement). The law also authorises formal cooperation arrangements with other agencies (including the State Data Agency and the Data Protection Authority) to ensure coherent enforcement across areas such as personal data protection and cybersecurity.
Key Focus Areas
The amendments concentrate on several substantive areas: (1) conformity assessment & certification — providing a national route for organisations (companies, research institutions, notified bodies) to obtain the right to assess and certify high‑risk AI systems in accordance with EU rules; (2) market surveillance & enforcement — empowering RRT to conduct market checks, require corrective actions, and coordinate EU‑level information exchanges; (3) regulatory experimentation — creating the AI sandbox to enable supervised trials, data access under controlled conditions, and iterative compliance testing; (4) start‑up support — introducing an Innovation Agency assessment to target public incentives at firms with demonstrable innovation potential; and (5) registration, documentation and transparency obligations to align with EU recordkeeping, technical documentation and information provision requirements. The package emphasises rapid but responsible market entry, ensuring that accelerated development activities remain aligned with the EU AI Act's risk‑based safeguards, including requirements on human oversight, robustness, accuracy, and cybersecurity.
Implementation Framework
The Act contains implementing authority delegations and transitional provisions: the Innovation Agency is empowered to adopt technical procedures for evaluating candidate notified bodies and to design sandbox governance rules; RRT receives explicit powers to perform surveillance, issue remedial orders, and liaise with the European AI Board under EU procedures. The law requires domestic legislation, secondary regulations and administrative acts to be prepared by the Ministry and delegated authorities to operationalise conformity assessment procedures, sandbox entry criteria, and reporting formats. Several provisions are aligned with EU timelines: most national arrangements are timed to be operational before or in parallel with EU application phases (noting the EU Act partial application dates of 2025‑02‑02, 2025‑08‑02 and 2026‑08‑02). The e‑Seimas consolidated record and official explanatory memorandum provide the legislative detail and staged effective dates (Seimas decision record & e‑TAR publication).
Monitoring and Evaluation
The law requires monitoring mechanisms and reporting: RRT must maintain market surveillance logs, report significant incidents and enforcement actions to the Innovation Agency and the European AI Board, and publish regular sectoral reviews of AI market developments. The Innovation Agency must publish annual assessments of start‑up programs and sandbox outcomes, including evaluation metrics for innovation impact and compliance performance. The amendments anticipate use of administrative data and sandbox results to perform ex post evaluation and to adjust guidance for conformity assessment. These monitoring obligations are intended to create a feedback cycle linking experimentation outputs to regulatory refinement and capacity building.
Penalties, Liability, and Appeals
While large sanction amounts for severe breaches remain anchored in the EU AI Act (including percentage‑based turnover fines for the most serious infringements), the national amendments specify enforcement competencies, administrative sanction procedures and appeal routes at the domestic level. RRT is authorised to apply administrative measures (orders to suspend placing on the market, recall, corrective instructions) and to impose fines under national administrative law consistent with EU maxima. The law affirms affected entities' rights to administrative review and judicial appeal and requires procedural safeguards during investigations. Explanatory materials note that national sanctioning practice must be compatible with the EU Act's penalty ceilings and principles of proportionality.
Relationship to Other Instruments
The amendments explicitly link the Law on Technology and Innovation to the Law on Information Society Services and to existing data protection, consumer protection and product safety legislation, creating cross‑references to ensure consistent obligations across frameworks. Notified bodies and conformity assessment procedures must account for requirements under the Law on Information Society Services where relevant. The package also anticipates Memoranda of Understanding between the Innovation Agency, RRT, the State Data Agency and the Data Protection Inspectorate to coordinate technical documentation access, incident reporting and joint investigations.
International Alignment
The Act implements the EU AI Act obligations and positions Lithuania as an active participant in EU coordination efforts. It adopts the EU risk taxonomy and conformity assessment model and enables domestic notified bodies to be assessed for participation in the EU conformity network. The law's sandbox mechanism is designed for interoperability with EU experimentation initiatives and to attract cross‑border testing collaborations. Key international documents are the EU AI Act text and Commission guidance; national implementing rules are to be drafted taking into account EU implementing acts and advice from the European AI Board (EU AI Act (Reg. 2024/1689)).
Implementation Timeline
| Event | Date |
|---|---|
| Seimas adoption (Act No. XV-105) | 2025-01-14 |
| Publication in TAR (official gazette) | 2025-01-22 |
| Certain provisions in force (articles 9(4) & 9(5)) | 2025-01-23 |
| Main Act effective date (general scope) | 2025-04-01 |
| Specific provisions (article 5(4)) effective | 2025-08-02 |
| Further staged provision (article 5(5)) effective | 2026-01-01 |
| EU AI Act phased dates for Member State alignment (reference) | 2025-02-02 / 2025-08-02 / 2026-08-02 |
Sources and References
| Source | Type |
|---|---|
| Seimas decision record (Act No. XV-105) | Primary Source |
| e‑TAR publication — consolidated edition | Primary Source |
| Ministry of Economy and Innovation announcement | Primary Source |
| EU Artificial Intelligence Act (Regulation (EU) 2024/1689) | Primary Source |
Requirements for a company
What an organisation has to do under Lithuania - AI Development Amendments (XV-105), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
8- Classify AI systems according to the EU AI Act risk taxonomy.Providers of AI systems.
- Ensure high-risk AI systems undergo EU conformity assessment and registration.Providers of high-risk AI systems placed on the Lithuanian market.
- Prepare technical documentation, logs, and provide required information to market surveillance authorities.Providers of AI systems, especially high-risk ones.
- Cooperate with the Communications Regulatory Authority (RRT) on market surveillance and enforcement.Providers of AI systems on the Lithuanian market.
- Implement corrective actions and comply with orders from the Communications Regulatory Authority (RRT).Providers of AI systems subject to market surveillance.
- Ensure compliance with data protection and cybersecurity obligations for AI systems.Providers of AI systems.
- +2 more in the table below
Must not do
0Nothing in this category.
Should do
2- Apply for supervised testing via the Innovation Agency and AI sandbox entry rules.Developers of AI systems seeking supervised testing.
- Submit to an Innovation Agency assessment to qualify as a start-up for public support.Firms seeking start-up classification for public incentives.
Should not do
0Nothing in this category.
Who must do what
The obligations under Lithuania - AI Development Amendments (XV-105), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers of AI systems. | Classify AI systems according to the EU AI Act risk taxonomy. “The law expressly aligns national definitions with the EU Act's categories (unacceptable, prohibited, high‑risk, limited‑risk, and minimal‑risk systems)” | Before placing on market | — | Critical |
| 2 | Providers of high-risk AI systems placed on the Lithuanian market. | Ensure high-risk AI systems undergo EU conformity assessment and registration. “high-risk AI systems placed on the Lithuanian market must follow EU conformity assessment and registration rules.” | Aug 2, 2025 | — | Critical |
| 3 | Providers of AI systems, especially high-risk ones. | Prepare technical documentation, logs, and provide required information to market surveillance authorities. “registration, documentation and transparency obligations to align with EU recordkeeping, technical documentation and information provision requirements.” | Before placing on market | — | Critical |
| 4 | Providers of AI systems on the Lithuanian market. | Cooperate with the Communications Regulatory Authority (RRT) on market surveillance and enforcement. “RRT is named the national market surveillance authority and single point of contact for enforcement, market oversight” | — | — | Critical |
| 5 | Providers of AI systems subject to market surveillance. | Implement corrective actions and comply with orders from the Communications Regulatory Authority (RRT). “RRT is authorised to apply administrative measures (orders to suspend placing on the market, recall, corrective instructions)” | — | — | Critical |
| 6 | Providers of AI systems. | Ensure compliance with data protection and cybersecurity obligations for AI systems. “formal cooperation arrangements with other agencies [...] to ensure coherent enforcement across areas such as personal data protection and cybersecurity.” | Before placing on market | — | Critical |
| 7 | Organizations wishing to become notified bodies for AI systems. | Seek approval from the Innovation Agency to act as a conformity assessment entity. “Innovation Agency as the national notifying authority responsible for: (a) assessing and approving bodies seeking notification to act as conformity assessment entities” | Before performing conformity assessments | — | Important |
| 8 | Notified bodies performing conformity assessments. | Account for requirements under the Law on Information Society Services during conformity assessment. “Notified bodies and conformity assessment procedures must account for requirements under the Law on Information Society Services where relevant.” | Before performing conformity assessments | — | Important |
| 9 | Developers of AI systems seeking supervised testing. | Apply for supervised testing via the Innovation Agency and AI sandbox entry rules. “creating the AI sandbox to enable supervised trials, data access under controlled conditions, and iterative compliance testing” | — | — | Recommended |
| 10 | Firms seeking start-up classification for public incentives. | Submit to an Innovation Agency assessment to qualify as a start-up for public support. “introducing an Innovation Agency assessment to target public incentives at firms with demonstrable innovation potential” | — | — | Recommended |
Related Regulations
Amendments to the Law on Information Society Services (measures to implement EU AI Act / accelerate AI development)
Lithuania97% similar
Amendments implementing the EU Artificial Intelligence Act: Amendments to the Law on Technology and Innovation (XV-105) and the Law on Information Society Services (XV-106) to implement Regulation (EU) 2024/1689 (Lithuanian AI Act implementation amendments)
Lithuania97% similar
AI Regulatory Sandbox Policy
Lithuania95% similar
National AI Strategy update / National AI Governance Forum
Lithuania94% similar
Action Plan for the Development of Artificial Intelligence Technologies in Lithuania 2023–2026
Lithuania92% similar
© Regulations.AI · updated on 13-Jun-2026