Malta - Ethical AI Framework

Malta — Towards Ethical and Trustworthy AI (Malta's Ethical AI Framework)

Malta

RAI-MT-NA-MTETAXX-2019
Adopted(Adopted)
GuidelineGovernance and OversightConformity Assessment and RegistrationRisk Management
Export PDF

Malta’s Ethical AI Framework ("Towards Trustworthy AI") is a non‑binding national guidance published in October 2019 that sets out principles and practical control practices to promote ethical, transparent and human-centric deployment of AI. It establishes four core principles — human autonomy, prevention of harm, fairness and explicability — and underpins Malta’s voluntary national AI certification initiative managed by the Malta Digital Innovation Authority (MDIA).

Overview

Malta’s Ethical AI Framework, published in October 2019 as part of the Malta.AI national strategy package, is a non‑binding, principles‑based document titled "Malta: Towards Trustworthy AI". The Framework sets out four core ethical principles — human autonomy, prevention of harm, fairness and explicability — and describes governance and control practices intended to translate those principles into operational measures for designers, vendors, deployers and public bodies. It was developed by the Malta.AI Taskforce with contributions from the Malta Digital Innovation Authority (MDIA) and published for consultation and adoption alongside an ambition to create a voluntary national AI certification scheme. The original consultation and publication materials are available from the Government of Malta and the Malta.AI project portal; the finalised document is commonly referenced on the Malta.AI repository. For official announcements on the strategy and certification programme see the Government press release on 3 October 2019 and the MDIA consultation pages (Malta: Towards Ethical and Trustworthy AI (vFINAL), Government press release, 3 Oct 2019, MDIA consultation).

Definitions

The Framework defines core terms for practical governance (brief, non-exhaustive): "AI system" (systems exhibiting behaviour that approximates cognitive functions typically associated with human intelligence, reflecting definitions used by EU bodies), "lifecycle" (design, development, deployment, monitoring, decommissioning), "human oversight" (meaningful control by competent humans over significant outcomes), "risk assessment" (systematic identification and mitigation of safety, privacy and socio‑ethical risks), and "certification" (voluntary third‑party evaluation against the Framework’s control practices). These definitions are aligned with international references such as the EU HLEG and OECD guidance and are intended to be technology‑neutral and lifecycle‑oriented.

Governance and Institutional Framework

The Framework envisages a layered governance model. At the national level, the Malta Digital Innovation Authority (MDIA) was assigned ownership of implementation actions within the 2019 AI Strategy and was tasked to: (a) host guidance for applicants to the proposed national AI certification scheme; (b) establish a National Technology Ethics Committee to provide oversight and advise on cross‑cutting legal and ethical issues; and (c) coordinate the set‑up of audit and accreditation arrangements (systems auditors and ITA arrangements). The Framework also anticipates a Technology Regulation Advisory Committee to advise on legal gaps (liability, IP, procurement). Sectoral regulators (health, financial services, telecommunications) are expected to interpret and apply the Framework within sector‑specific regulatory regimes. The MDIA website and news pages provide further details on institutional arrangements and consultation milestones (MDIA, Government press release).

Key Focus Areas

The Framework translates the four core ethical principles into focus areas and operational control practices. Major focus areas include: risk identification and lifecycle risk management (including DPIA‑style assessments where personal data are used); human‑centric design and meaningful human oversight to preserve human autonomy; bias and fairness mitigation, including dataset governance and fairness testing; explicability and transparency, including documentation, model cards and user notices to enable challenge and recourse; robust systems testing, validation and assurance processes; security and resilience (threat modelling, adversarial testing, patching and incident response); and accountability mechanisms including logging, provenance, and audit trails. The Framework also outlines expectations for procurement, vendor assessments, third‑party audits, and continuous monitoring practices for deployed systems. Many of these practices are explicitly designed to be compatible with GDPR requirements and international standards to facilitate cross‑border coherence.

Implementation Framework

Implementation is staged and voluntary. The MDIA and Malta.AI Taskforce recommended operational steps: create guidance notes for implementers; define nomenclature and classification for AI use cases; develop auditor control objectives; establish auditor accreditation and systems auditor registries; launch a voluntary national AI certification based on audit outcomes; and run regulatory and data sandboxes to allow experimental deployments under controlled conditions. The Framework recommends organizational responsibilities (board and executive levels), policies for procurement and supplier management, and templates for technical and governance artefacts (risk registers, model documentation, test plans). Implementation guidance emphasises interoperability with sectoral compliance obligations and international best practices, while offering checklists and documentation templates to aid practical adoption.

Monitoring and Evaluation

Monitoring is proposed as a mix of self‑reporting, third‑party audits (for certification), and oversight by the National Technology Ethics Committee and MDIA. Key performance indicators recommended include adoption rates, number of certified systems, incidents and near‑misses logged, audit results, complaint volumes and remediation times, and periodic reviews of the Framework itself to reflect technological and legal developments. The MDIA envisaged using its web portal to publish progress metrics and to coordinate stakeholder feedback loops. Sandboxes and pilot projects are expected to yield empirical evidence for refining controls and calibration of certification criteria.

Penalties, Liability, and Appeals

As a non‑binding framework, it does not set statutory penalties. Instead, the Framework links to existing legal obligations (notably data protection law) where binding sanctions may apply. The document explains that failure to follow the Framework could affect access to voluntary certification, public procurement opportunities, or lead to reputational and contractual consequences. Liability for harms caused by AI remains governed by existing civil and sectoral laws; the Framework recommends that Malta’s advisory committees explore the need for targeted legislative measures (for example on tort liability, product safety or supply‑chain responsibilities). The Framework also recommends establishing appeals channels within certification and auditing processes to address contested audit outcomes. For binding enforcement (e.g., GDPR), complainants retain their rights to approach the Information and Data Protection Commissioner.

Relationship to Other Instruments

The Framework is explicitly designed to align with, complement and not supplant existing instruments. It references and builds on the EU High‑Level Expert Group on AI’s guidelines, OECD AI Principles, and existing Maltese legislation (including data protection law and the MDIA’s ITAS/Innovative Technology Arrangements framework). The document positions the Framework as the ethical foundation for the MDIA’s voluntary AI certification and for the national AI Strategy actions such as sandboxes and advisory committees. It therefore acts as an integrative instrument linking ethical guidance, auditor frameworks and MDIA certification processes.

International Alignment

International alignment is a core objective: the Framework seeks compatibility with the EU HLEG Trustworthy AI Guidelines and OECD AI Principles to facilitate cross‑jurisdictional interoperability and to make Malta an attractive jurisdiction for trusted AI development. The Framework’s voluntary certification programme was designed with an eye toward recognition in export markets and alignment with emerging international standards. Malta’s approach intentionally emphasises technology neutrality and references to European policy developments (including anticipated EU legislative initiatives) to ensure the Framework can be mapped to supranational obligations.

Implementation Timeline

DateEvent
2019-08-09Public consultation launched for "Malta: Towards Trustworthy AI" (Government press release, 9 Aug 2019).
2019-09-06Consultation period for Malta.AI consultation document (deadline indicated in early materials).
2019-10-01Final materials published in October 2019; MDIA advanced consultation on certification guidance through Autumn 2019 (MDIA consultation).
2019-10-03Launch of Malta National AI Strategy and public announcement of the voluntary AI certification programme (Gov.mt press release, 3 Oct 2019).
2019-11-01MDIA consultation period for AI certification guidance (closing date indicated in MDIA material).

Compliance Checklist

RequirementAction/Artefact
Principle mappingMap project features to the four ethical principles (human autonomy, harm prevention, fairness, explicability)
Risk assessmentDocument lifecycle risk register and mitigation plan; conduct DPIA if personal data involved
DocumentationProduce model cards, system documentation, data lineage and provenance records
Testing & validationMaintain test plans, results, robustness and adversarial testing evidence
Human oversightDefine roles for meaningful human oversight and escalation procedures
Security & resilienceImplement cybersecurity controls, incident response plan and patching processes
Fairness & bias mitigationPerform bias audits, representativeness tests and mitigation steps
Third‑party audit / certificationPrepare for systems auditor review and evidence required for MDIA voluntary certification

Sources and References

SourceType
Malta: Towards Ethical and Trustworthy AI (vFINAL)Primary Source
Government press release: Launch of Malta’s National AI Strategy (03 Oct 2019)Primary Source
Malta Digital Innovation Authority (MDIA) – AI consultation and guidancePrimary Source
EU AI Watch – Malta AI Strategy Report (reference to Framework)Secondary Source
Plain English

Malta's Ethical AI Framework, adopted in October 2019, provides non-binding national guidance for anyone designing, developing, deploying, or managing artificial intelligence (AI) systems, including companies, vendors, and public bodies. Its primary aim is to foster the ethical, transparent, and human-centric use of AI across the country.

The framework is built on four core ethical principles: ensuring human autonomy, preventing harm, promoting fairness, and demanding explicability. To translate these principles into practical measures, it recommends several key operational controls for organisations throughout an AI system's lifecycle. These include: - Thorough risk identification and management, similar to Data Protection Impact Assessments, to address potential safety, privacy, and socio-ethical risks. - Designing systems with meaningful human oversight to ensure competent human control over significant outcomes. - Actively mitigating bias and ensuring fairness, for instance, through careful dataset governance and rigorous fairness testing. - Providing clear explanations and transparency about how AI systems function, using documentation like "model cards" and user notices to enable challenge and recourse.

While this framework became effective on October 3, 2019, it does not impose direct legal penalties. This is a crucial distinction: it serves as guidance, not a law with statutory fines. However, ignoring the framework could still lead to significant business repercussions. Companies might miss out on Malta's voluntary national AI certification, which could impact public procurement opportunities or result in reputational damage. Liability for any harm caused by AI systems would still be governed by existing civil and sectoral laws, such as data protection regulations. A practical pitfall for readers is to assume "non-binding" means "ignorable"; adherence is strongly encouraged through market incentives and alignment with broader legal obligations.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Malta - Ethical AI Framework. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Designers, developers, and deployers of AI systems processing personal data.

    DPIA‑style assessments where personal data are used
  2. #2ImportantBefore placing on market

    Applies to: Designers, developers, and deployers of AI systems.

    risk identification and lifecycle risk management
  3. #3ImportantBefore placing on market

    Applies to: Designers and developers of AI systems.

    human‑centric design and meaningful human oversight to preserve human autonomy
  4. #4ImportantBefore placing on market

    Applies to: Designers, developers, and deployers of AI systems.

    bias and fairness mitigation, including dataset governance and fairness testing
  5. #5ImportantBefore placing on market

    Applies to: Designers, vendors, and deployers of AI systems.

    explicability and transparency, including documentation, model cards and user notices
  6. #6ImportantBefore placing on market

    Applies to: Designers, developers, and deployers of AI systems.

    robust systems testing, validation and assurance processes
  7. #7ImportantBefore placing on market

    Applies to: Designers, developers, and deployers of AI systems.

    security and resilience (threat modelling, adversarial testing, patching and incident response)
  8. #8ImportantBefore placing on market

    Applies to: Designers, developers, and deployers of AI systems.

    accountability mechanisms including logging, provenance, and audit trails
  9. #9Important

    Applies to: Deployers of AI systems.

    continuous monitoring practices for deployed systems
  10. #10RecommendedBefore placing on market

    Applies to: Designers, developers, and deployers of AI systems.

    Map project features to the four ethical principles (human autonomy, harm prevention, fairness, explicability)
  11. #11Recommended

    Applies to: Providers and deployers seeking voluntary AI certification.

    launch a voluntary national AI certification based on audit outcomes

© Regulations.AI — created on 13-Jun-2026