Malta - AI Certification Programme
AI Innovative Technology Arrangement (AI ITA) scheme / National AI certification programme (MDIA)
Malta
RAI-MT-NA-AITAAXX-2019The Malta Digital Innovation Authority (MDIA) established a voluntary certification and assurance pathway for Innovative Technology Arrangements (ITAs), explicitly encompassing AI, to promote trustworthy adoption through certification, sandboxing and alignment with national AI strategy goals launched in 2019. The ITAS Certification Regulations (Subsidiary Legislation 591.01) (2024) and MDIA guidance tools (AI Control Objectives, MDIA-TAS) operationalise assessment, documentation, technical administration and registration requirements for certified ITAs.
Summary
Read full text ↗Plain English
Overview
The AI Innovative Technology Arrangement (AI ITA) scheme in Malta sits within the broader Innovative Technology Arrangements and Services (ITAS) certification ecosystem administered by the Malta Digital Innovation Authority (MDIA). Initiated as part of the national AI strategy work begun in 2019, the scheme provides a voluntary, risk-based pathway for recognising and certifying technology arrangements — explicitly including AI systems — against published control objectives, guidance documents and assessment blueprints. The MDIA’s ITAS pages and related guidance materials explain the operational benefits of certification (transparency, trust, auditability) and the available tools such as the Innovative Technology Arrangement guidelines and the Technology Assurance Sandbox (MDIA-TAS). The legal underpinning for the certification mechanics is set out in the ITAS Certification Regulations (Subsidiary Legislation 591.01) published on the Maltese legislation portal.
Definitions
Key terms used in the scheme: "Innovative Technology Arrangement (ITA)" — software / architectures used to design and deliver DLT, smart contracts and other designated technologies including AI; "Certificate" — MDIA-issued recognition that states the identity and assessed attributes/behaviours of the ITA; "Technical Administrator" — person or entity appointed to maintain and represent the technical operation of an ITA; "Systems Auditor" — registered auditor that performs conformity and security assessments; and "MDIA-TAS" — the MDIA’s Technology Assurance Sandbox for iterative development and assessment. These definitions and operational descriptions are described in MDIA guidance materials and the ITAS legislative instruments published by the Government of Malta.
Governance and Institutional Framework
The MDIA is the primary authority responsible for the governance, certification and monitoring of ITAs. The MDIA’s mandate (established under the MDIA Act and elaborated in sectoral guidance) focuses on promoting legal, ethical and transparent innovation. The Authority issues guidelines, blueprints and technical nomenclatures to guide applicants through the assurance lifecycle. MDIA governance includes the review of applicant documentation, system testing or access to the software where necessary, and the registration of technical roles (e.g., systems auditors, technical administrators). The MDIA coordinates with other national stakeholders and sector regulators to ensure certified ITAs meet sector-specific regulatory expectations — the MDIA’s public materials detail how certification supports public-sector pilots and national AI strategy projects such as those in health and transport. See MDIA resources at Malta AI Strategy and Vision and the MDIA ITA service page at Innovative Technology Arrangement.
Key Focus Areas
1) Conformity assessment and certification: Applicants present comprehensive technical and governance documentation, evidence of control objectives implementation and, where required, invite technical review and audits. Certificates enumerate permitted behaviours and identifiers that must be made observable to users. 2) Risk management and safety: Certification is risk-proportionate; MDIA materials emphasise threat modelling, attack surface management, robustness testing and incident preparedness. 3) Transparency and disclosure: The MDIA expects clear documentation, user-facing disclosures and identifiable certificate metadata (unique certificate number; identification of ITA). 4) Data protection and privacy: Certified arrangements must align with GDPR and national privacy requirements; documentation should include data flows, legal basis for processing and data minimisation steps. 5) Cybersecurity and model security: The MDIA’s control objectives and sandbox guidance include cryptographic protections, secure key management and resilience testing. 6) Accountability and documentation: Appointment of named technical administrators and maintenance of auditable logs is a core certification expectation. 7) Market surveillance and ongoing monitoring: Certification is not a one-time event; certified ITAs may be subject to periodic reviews, audits and notifications to the MDIA for material changes. 8) International alignment: The MDIA positions the scheme to align with EU instruments (e.g., the EU AI Regulation) and international standards to facilitate cross-border trust and recognition.
Implementation Framework
Process steps: pre-engagement with MDIA/TAS; sandboxed testing or staged technical assessment; submission of conformity documentation and evidence; systems audit (where required); issuance of certificate (including certificate metadata to be made publicly accessible on the ITA); and post-certification monitoring. The MDIA provides an iterative route via the MDIA-TAS for projects to mature controls and evidence over time. Fees, registration processes and the formal legal mechanics are set out in the ITAS subsidiary regulations and fee schedules published by the Government (including updates enacted in 2023–2024). The MDIA’s blueprint documents and assessment-level options enable applicants to tailor the assurance pathway to the technology’s complexity and intended use-cases. Relevant MDIA resources: Innovative Technology Arrangement and the MDIA national strategies pages at Malta AI Strategy and Vision.
Monitoring and Evaluation
Monitoring is a continuous activity: the MDIA may require periodic reporting, notify registered auditors of changes and coordinate market surveillance with sectoral regulators. Evaluation metrics include conformity to control objectives, the outcome of security tests, incident reports and evidence of effective governance. The MDIA provides guidance and templates for documentation and has signalled the rollout of the Technology Assurance Assessment Framework (TAAF) to expand assessment models and make monitoring more granular and standardised. For nascent technologies, the MDIA-TAS enables staged acceptance with measurable go/no-go milestones.
Penalties, Liability, and Appeals
Because the ITAS scheme is primarily voluntary, enforcement focuses on certification status (issuance, suspension, revocation), fee recovery and publication of adverse findings rather than criminal sanctions. The MDIA’s regulations and guidance set out administrative remedies including the ability to refuse or withdraw certificates, require remedial actions and publish decisions that affect market reputation. Entities remain subject to national laws (including civil liability regimes and sector-specific enforcement) and to EU rules such as the GDPR and the EU AI Regulation where applicable. The MDIA provides administrative appeal routes and procedures described in its guidance and in the subsidiary legislation; affected entities can follow prescribed internal review and appeal mechanisms while cooperating with any sectoral regulator investigations.
Relationship to Other Instruments
The ITAS certification regime is complementary to broader regulatory instruments: it operates alongside the MDIA Act, the repealed/updated ITAS Act provisions (historic) and the ITAS Certification Regulations (Subsidiary Legislation 591.01). It is also designed to operate in harmony with EU-level frameworks (notably the EU AI Regulation and GDPR) and sectoral Maltese laws (health, financial services). MDIA certifications do not replace statutory licensing in regulated sectors but offer an assurance layer that regulators and procurers can rely upon as part of oversight and procurement evaluation. See the ITAS legislative listing and MDIA policy pages for cross-references and updates.
International Alignment
Malta’s approach emphasizes harmonisation with international standards and EU law. The MDIA explicitly references international best practices in its AI Control Objectives and intends the TAAF and ITAS certification to be interoperable with EU obligations, facilitating cross-border trust. This alignment helps Malta attract investment and supports national objectives to be an AI launchpad while ensuring compliance with the EU AI Regulation (as an EU Member State), GDPR and applicable sectoral law. The MDIA also participates in international fora and shares guidance to promote inter-authority cooperation.
Implementation Timeline
| Event | Date |
|---|---|
| MDIA / Malta National AI Strategy public launch and early engagement | 2019-10-15 |
| MDIA established (MDIA Act entry into force) | 2018-07-15 |
| ITAS Act and related laws came into force (initial ITA regime operational) | 2018-11-01 |
| MDIA introduces Technology Assurance Sandbox (MDIA-TAS) | 2021-01-01 |
| ITAS Certification Regulations (Subsidiary Legislation 591.01) published | 2024-06-14 |
| Ongoing: TAAF development and AI Strategy realignment (public consultations) | 2024-2025 |
Compliance Checklist
| Requirement | Checklist Item |
|---|---|
| Documentation | Maintain technical, governance and data-flow documentation; publish certificate metadata |
| Technical Administration | Appoint and register a Technical Administrator (if applicable) |
| Risk Assessment | Perform threat modelling and risk assessment aligned to MDIA control objectives |
| Audit and Testing | Complete systems audits and robustness testing; remediate findings via MDIA-TAS |
| Data Protection | Demonstrate GDPR alignment and appropriate data minimisation measures |
| Security | Implement cryptographic protections, key management and incident response plans |
| Registration & Fees | Complete any required registrations and pay applicable fees as per subsidiary legislation |
| Post-certification Monitoring | Submit periodic reports and notify MDIA of material changes |
Sources and References
Malta's AI Innovative Technology Arrangement (AI ITA) scheme provides a voluntary certification pathway for companies developing or deploying AI systems and other innovative technologies, aiming to foster trust and ensure responsible adoption.
This scheme, overseen by the Malta Digital Innovation Authority (MDIA), is open to any entity creating or using "Innovative Technology Arrangements" (ITAs), which explicitly includes artificial intelligence systems, distributed ledger technologies, and smart contracts. While participation is voluntary, certification signals adherence to national and international standards for trustworthy technology.
To get certified, companies must submit comprehensive technical and governance documentation, demonstrating how their system meets specific control objectives. They also need to ensure transparency by providing clear user-facing disclosures and making certificate metadata publicly accessible. A key requirement is appointing a "Technical Administrator" responsible for the system's technical operation and maintaining auditable logs of its activities. Companies must also undergo systems audits and robustness testing, with the option to use the MDIA's Technology Assurance Sandbox (MDIA-TAS) for iterative development and assessment.
The ITAS Certification Regulations, which detail the legal mechanics, were published on June 14, 2024, making the scheme fully operational. Certification is not a one-time event; it requires ongoing monitoring, periodic reviews, and notifying the MDIA of any significant changes to the system.
Since this is a voluntary scheme, enforcement primarily involves the MDIA's ability to refuse, suspend, or revoke a certificate, recover fees, or publish adverse findings that could impact a company's reputation. It's crucial to remember that this certification does not replace other national laws, such as civil liability regimes, or EU regulations like the General Data Protection Regulation (GDPR) or the upcoming EU AI Act. Companies remain fully accountable under these broader legal frameworks. A key practical pitfall is assuming certification is a "set it and forget it" process; continuous compliance and communication with the MDIA are essential.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Malta - AI Certification Programme. Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas: 4) Data protection and privacy
Applies to: Providers of AI systems seeking certification.
“Certified arrangements must align with GDPR and national privacy requirements”
- #2CriticalRelationship to Other Instruments
Applies to: Providers of AI systems seeking certification.
“It is also designed to operate in harmony with EU-level frameworks (notably the EU AI Regulation and GDPR)”
- #3ImportantKey Focus Areas: 6) Accountability and documentation⏰ Before applying for certification
Applies to: Entities seeking certification for an Innovative Technology Arrangement.
“Appointment of named technical administrators... is a core certification expectation.”
- #4ImportantDefinitions⏰ Before submitting for certification
Applies to: Entities seeking certification for an Innovative Technology Arrangement.
“Systems Auditor — registered auditor that performs conformity and security assessments”
- #5ImportantKey Focus Areas: 1) Conformity assessment and certification⏰ Before submitting for certification
Applies to: Applicants for ITA certification.
“Applicants present comprehensive technical and governance documentation, evidence of control objectives implementation”
- #6ImportantKey Focus Areas: 2) Risk management and safety⏰ Before applying for certification
Applies to: Providers of AI systems seeking certification.
“MDIA materials emphasise threat modelling, attack surface management, robustness testing and incident preparedness.”
- #7ImportantKey Focus Areas: 5) Cybersecurity and model security⏰ Before applying for certification
Applies to: Providers of AI systems seeking certification.
“The MDIA’s control objectives and sandbox guidance include cryptographic protections, secure key management and resilience testing.”
- #8ImportantKey Focus Areas: 6) Accountability and documentation
Applies to: Certified Innovative Technology Arrangements.
“maintenance of auditable logs is a core certification expectation.”
- #9ImportantKey Focus Areas: 1) Conformity assessment and certification⏰ Upon certification
Applies to: Certified Innovative Technology Arrangements.
“Certificates enumerate permitted behaviours and identifiers that must be made observable to users.”
- #10ImportantKey Focus Areas: 7) Market surveillance and ongoing monitoring⏰ As soon as changes occur
Applies to: Certified Innovative Technology Arrangements.
“certified ITAs may be subject to periodic reviews, audits and notifications to the MDIA for material changes.”
- #11ImportantKey Focus Areas: 7) Market surveillance and ongoing monitoring
Applies to: Certified Innovative Technology Arrangements.
“certified ITAs may be subject to periodic reviews, audits”
- #12ImportantImplementation Framework⏰ As per MDIA fee schedules
Applies to: Applicants for and holders of ITA certification.
“Fees, registration processes and the formal legal mechanics are set out in the ITAS subsidiary regulations”
Related Regulations
Malta — The Ultimate AI Launchpad: A Strategy and Vision for Artificial Intelligence in Malta 2030
Malta94% similar
Malta — Towards Ethical and Trustworthy AI (Malta's Ethical AI Framework)
Malta93% similar
226 of 2025 - Artificial Intelligence Regulations, 2025 (Legal Notice)
Malta92% similar
227 of 2025 - Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (Legal Notice)
Malta90% similar
Malta AI Regulation Overview
Malta90% similar
© Regulations.AI — created on 13-Jun-2026