Malta - AI Regulations (226/2025)

226 of 2025 - Artificial Intelligence Regulations, 2025 (Legal Notice)

Malta

RAI-MT-NA-22AIRXX-2025
Effective: October 10, 2025
In Force(In Force)
RegulationGovernance and OversightConformity Assessment and RegistrationMarket Surveillance
Export PDF

Legal Notice 226 of 2025 establishes Malta's national implementing framework for the EU Artificial Intelligence Act, designating the Malta Digital Innovation Authority (MDIA) as the primary national market surveillance and competent authority for most AI systems while setting national enforcement powers, conformity assessment and sandbox arrangements. It complements Legal Notice 227 of 2025 which designates the Information and Data Protection Commissioner for specified high‑risk, data‑sensitive AI systems.

Overview

Legal Notice 226 of 2025 ("Artificial Intelligence Regulations, 2025") is Malta's primary national implementing instrument for the EU Artificial Intelligence Act framework. Published in the Government Gazette on 10 October 2025, LN 226 designates the Malta Digital Innovation Authority (MDIA) as the principal national market surveillance authority and Notifying Authority for the recognition of conformity assessment bodies in relation to AI systems. The Notice establishes national enforcement powers, reporting and registration arrangements, and the national AI regulatory sandbox. LN 226 is intended to complement and operate alongside Legal Notice 227 of 2025, which designates the Information and Data Protection Commissioner (IDPC) for certain data‑sensitive and Annex III high‑risk AI systems. For an official announcement and summary of designations, see the IDPC notice and the MDIA website for guidance materials and tools.

Definitions

LN 226 incorporates key definitions aligned with the EU AI Act (e.g., "AI system", "provider", "operator", "user", "high‑risk AI system", "conformity assessment", "market surveillance authority"). The Legal Notice clarifies national terms where necessary (for example, specifying the MDIA as the "Notifying Authority" and defining "national market surveillance" processes). These definitions are functionally harmonised with Regulation (EU) 2024/1689 to ensure consistent interpretation across Member States while allowing LN 226 to designate specific national bodies and procedural rules for Malta.

Governance and Institutional Framework

Under LN 226, the Malta Digital Innovation Authority (MDIA) is assigned primary supervisory duties including: acting as Malta's default Market Surveillance Authority (MSA) for AI systems not specifically allocated to another authority; serving as the Notifying Authority responsible for recognising conformity assessment bodies; operating the national AI regulatory sandbox; issuing guidance and non‑binding technical standards; and coordinating national enforcement and international cooperation. The Legal Notice requires MDIA to coordinate with the Information and Data Protection Commissioner (IDPC) and sectoral regulators (e.g., the Malta Financial Services Authority) when systems overlap sectoral or data protection competencies. LN 226 establishes formal cooperation and information‑sharing channels, requires memoranda of understanding between agencies where appropriate, and sets out the procedure for referral of cases between MDIA and other competent authorities to ensure clarity of responsibilities and to avoid regulatory gaps or duplication.

Key Focus Areas

LN 226 emphasises a risk‑based supervisory model mirroring the EU approach and focuses on: (1) conformity assessment and registration for high‑risk AI systems; (2) mandatory risk management systems, technical documentation and data governance; (3) transparency obligations (user notices, deepfake labeling, general‑purpose model disclosures where relevant); (4) human oversight and operational limits on automated decision‑making; (5) cybersecurity and model security (including requirements for vulnerability management, patching and secure design); (6) post‑market monitoring and incident reporting duties; and (7) market surveillance and enforcement powers including corrective measures, recalls, and administrative fines. The Notice also addresses novel national mechanisms such as the MDIA‑operated regulatory sandbox to support innovation while safeguarding rights, and processes to coordinate cross‑border enforcement with EU authorities and notified conformity assessment bodies.

Implementation Framework

LN 226 specifies practical steps for implementation: MDIA is tasked with developing secondary guidance and templates (for technical documentation, post‑market monitoring reports, and risk management records); procedures for registration and national importation/distribution oversight; accreditation and notification of conformity assessment bodies (in line with national accreditation rules and EU standards); inspection protocols and sampling methodologies for market surveillance; and formal rules to run the national AI regulatory sandbox with confidentiality and IP safeguards for participants. The Legal Notice mandates that providers and importers maintain technical files and make them available to MDIA and other competent authorities on request, and prescribes timelines for conformity assessment outcomes and corrective actions where non‑conformity is detected.

Monitoring and Evaluation

LN 226 establishes continuous monitoring mechanisms. Providers of high‑risk AI systems must implement post‑market monitoring and report serious incidents or malfunctions to MDIA (and IDPC where personal data or fundamental rights issues arise). MDIA is required to publish periodic enforcement and market‑surveillance reports, to maintain a register of notified conformity assessment bodies, and to evaluate the national sandbox outcomes. The Notice introduces metrics for assessing regulatory impact (compliance rates, incidents reported, corrective actions taken, time to close enforcement files) and foresees stakeholder consultations to refine guidance and harmonise practice with EU and international standards.

Penalties, Liability, and Appeals

LN 226 grants MDIA administrative enforcement powers including inspections, orders to suspend or withdraw non‑compliant systems, and the imposition of administrative fines for breaches. National reporting indicates that MDIA may levy significant sanctions calibrated to severity, including fixed fines and daily penalties for ongoing breaches; secondary reporting on the instrument references national maximums and proportionality principles for penalties. The Legal Notice also preserves existing civil and criminal liability pathways under Maltese law, including rights for affected persons to seek civil remedies. Procedural safeguards include rights of appeal against administrative decisions to independent tribunals and requirements that enforcement decisions be reasoned and proportionate.

Relationship to Other Instruments

LN 226 operates in tandem with the EU AI Act and complementary national measures. It explicitly coordinates with Legal Notice 227 of 2025, which designates the IDPC as the Market Surveillance Authority for certain Annex III high‑risk AI systems and data‑sensitive implementations. LN 226 references the Data Protection Act (Cap. 586), sectoral rules (e.g., MFSA rules for financial services; health sector legislation), and national cybersecurity guidelines. It instructs MDIA to enter into MoUs with sectoral authorities and to rely on established accreditation and conformity infrastructures where possible, thereby ensuring that national implementation is consistent with both sectoral protections and data protection obligations.

International Alignment

LN 226 deliberately aligns Maltese domestic measures with the EU AI Act and international standards to ensure interoperability and facilitate cross‑border trade in AI systems. The Legal Notice tasks MDIA with cooperation in the European AI Board, participation in EU market surveillance networks, and recognition of conformity assessment bodies in line with EU rules. LN 226 also encourages alignment with international standards for AI safety, cybersecurity (e.g., ISO/IEC series), and data governance to reduce fragmentation and to help local providers comply with external market requirements.

Implementation Timeline

DateMilestone
2025-10-10Publication of Legal Notice 226 of 2025 in the Government Gazette (MDIA designated as primary national authority).
2025-10-10Publication of Legal Notice 227 of 2025 (IDPC designated for certain high‑risk AI systems).
Q4 2025MDIA issues initial guidance, templates and starts accepting notifications for the national AI sandbox and conformity assessment bodies.
2026 (rolling)Phased enforcement and registration deadlines in line with EU AI Act timelines; MDIA and IDPC publish joint operational procedures.

Compliance Checklist

RequirementOperator/Provider Action
ClassificationDetermine whether AI system is prohibited, high‑risk, or subject to transparency obligations.
Risk ManagementImplement a documented risk management system and risk mitigation measures.
Technical DocumentationPrepare and maintain technical files and datasets documentation for inspection.
Conformity AssessmentObtain or perform conformity assessment where required; use notified bodies if necessary.
Transparency NoticesProvide user notices, labelling for synthetic content and disclose limits of system capabilities.
Post‑Market MonitoringEstablish processes for logging, incident reporting and corrective action.

Sources and References

SourceType
226 of 2025 - Artificial Intelligence Regulations, 2025 (Government Gazette / ELI)Primary Source
Plain English

Malta's Artificial Intelligence Regulations, 2025, establish the national framework for implementing the EU AI Act, primarily applying to providers, operators, and users of AI systems within the country, especially those deemed "high-risk."

This new law designates the Malta Digital Innovation Authority (MDIA) as the main national regulator, overseeing most AI systems, recognizing conformity assessment bodies, and running a national AI regulatory sandbox. However, for high-risk AI systems that are data-sensitive, the Information and Data Protection Commissioner (IDPC) takes charge, requiring careful coordination between these two bodies.

Businesses developing or deploying AI in Malta face several key obligations. They must: - Ensure their high-risk AI systems undergo conformity assessment and are registered. - Implement robust risk management systems, backed by detailed technical documentation and sound data governance. - Meet transparency requirements, such as providing user notices, labeling synthetic content like deepfakes, and disclosing capabilities of general-purpose models. - Establish post-market monitoring processes and report any serious incidents or malfunctions.

The regulations officially took effect on October 10, 2025, with phased enforcement and registration deadlines expected throughout 2026, aligning with the broader EU AI Act timeline. Non-compliance carries significant consequences. The MDIA has powers to inspect, order the suspension or withdrawal of non-compliant systems, and impose substantial administrative fines, including daily penalties for ongoing breaches. Existing civil and criminal liabilities also remain, and businesses have rights of appeal against administrative decisions.

A practical pitfall for businesses is navigating the dual regulatory landscape. While MDIA is the default, understanding when your AI system falls under the IDPC's remit for data-sensitive applications is crucial to avoid missteps and ensure compliance with the correct authority.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Malta - AI Regulations (226/2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalCompliance ChecklistBefore placing on market

    Applies to: Providers and operators of AI systems.

    Determine whether AI system is prohibited, high‑risk, or subject to transparency obligations.
  2. #2CriticalKey Focus Areas

    Applies to: Providers of high-risk AI systems.

    mandatory risk management systems, technical documentation and data governance
  3. #3CriticalKey Focus AreasBefore placing on market

    Applies to: Providers of high-risk AI systems.

    conformity assessment and registration for high‑risk AI systems
  4. #4CriticalImplementation Timeline2026 (rolling)

    Applies to: Providers of high-risk AI systems.

    Phased enforcement and registration deadlines in line with EU AI Act timelines
  5. #5CriticalImplementation Framework

    Applies to: Providers and importers.

    mandates that providers and importers maintain technical files and make them available to MDIA
  6. #6CriticalMonitoring and Evaluation

    Applies to: Providers of high-risk AI systems.

    Providers of high‑risk AI systems must implement post‑market monitoring and report serious incidents
  7. #7CriticalMonitoring and Evaluation

    Applies to: Providers of high-risk AI systems.

    report serious incidents or malfunctions to MDIA (and IDPC where personal data or fundamental rights issues arise)
  8. #8ImportantKey Focus Areas

    Applies to: Providers of AI systems subject to transparency obligations.

    transparency obligations (user notices, deepfake labeling, general‑purpose model disclosures where relevant)
  9. #9ImportantKey Focus Areas

    Applies to: Providers of AI systems.

    human oversight and operational limits on automated decision‑making
  10. #10ImportantKey Focus Areas

    Applies to: Providers of AI systems.

    cybersecurity and model security (including requirements for vulnerability management, patching and secure design)

© Regulations.AI — created on 13-Jun-2026