Malta - Ethical AI Framework
Malta — Towards Ethical and Trustworthy AI (Malta's Ethical AI Framework)
Malta
RAI-MT-NA-MTETAXX-2019Malta’s Ethical AI Framework ("Towards Trustworthy AI") is a non‑binding national guidance published in October 2019 that sets out principles and practical control practices to promote ethical, transparent and human-centric deployment of AI. It establishes four core principles — human autonomy, prevention of harm, fairness and explicability — and underpins Malta’s voluntary national AI certification initiative managed by the Malta Digital Innovation Authority (MDIA).
Summary
Read full text ↗Plain English
Overview
Malta’s Ethical AI Framework, published in October 2019 as part of the Malta.AI national strategy package, is a non‑binding, principles‑based document titled "Malta: Towards Trustworthy AI". The Framework sets out four core ethical principles — human autonomy, prevention of harm, fairness and explicability — and describes governance and control practices intended to translate those principles into operational measures for designers, vendors, deployers and public bodies. It was developed by the Malta.AI Taskforce with contributions from the Malta Digital Innovation Authority (MDIA) and published for consultation and adoption alongside an ambition to create a voluntary national AI certification scheme. The original consultation and publication materials are available from the Government of Malta and the Malta.AI project portal; the finalised document is commonly referenced on the Malta.AI repository. For official announcements on the strategy and certification programme see the Government press release on 3 October 2019 and the MDIA consultation pages (Malta: Towards Ethical and Trustworthy AI (vFINAL), Government press release, 3 Oct 2019, MDIA consultation).
Definitions
The Framework defines core terms for practical governance (brief, non-exhaustive): "AI system" (systems exhibiting behaviour that approximates cognitive functions typically associated with human intelligence, reflecting definitions used by EU bodies), "lifecycle" (design, development, deployment, monitoring, decommissioning), "human oversight" (meaningful control by competent humans over significant outcomes), "risk assessment" (systematic identification and mitigation of safety, privacy and socio‑ethical risks), and "certification" (voluntary third‑party evaluation against the Framework’s control practices). These definitions are aligned with international references such as the EU HLEG and OECD guidance and are intended to be technology‑neutral and lifecycle‑oriented.
Governance and Institutional Framework
The Framework envisages a layered governance model. At the national level, the Malta Digital Innovation Authority (MDIA) was assigned ownership of implementation actions within the 2019 AI Strategy and was tasked to: (a) host guidance for applicants to the proposed national AI certification scheme; (b) establish a National Technology Ethics Committee to provide oversight and advise on cross‑cutting legal and ethical issues; and (c) coordinate the set‑up of audit and accreditation arrangements (systems auditors and ITA arrangements). The Framework also anticipates a Technology Regulation Advisory Committee to advise on legal gaps (liability, IP, procurement). Sectoral regulators (health, financial services, telecommunications) are expected to interpret and apply the Framework within sector‑specific regulatory regimes. The MDIA website and news pages provide further details on institutional arrangements and consultation milestones (MDIA, Government press release).
Key Focus Areas
The Framework translates the four core ethical principles into focus areas and operational control practices. Major focus areas include: risk identification and lifecycle risk management (including DPIA‑style assessments where personal data are used); human‑centric design and meaningful human oversight to preserve human autonomy; bias and fairness mitigation, including dataset governance and fairness testing; explicability and transparency, including documentation, model cards and user notices to enable challenge and recourse; robust systems testing, validation and assurance processes; security and resilience (threat modelling, adversarial testing, patching and incident response); and accountability mechanisms including logging, provenance, and audit trails. The Framework also outlines expectations for procurement, vendor assessments, third‑party audits, and continuous monitoring practices for deployed systems. Many of these practices are explicitly designed to be compatible with GDPR requirements and international standards to facilitate cross‑border coherence.
Implementation Framework
Implementation is staged and voluntary. The MDIA and Malta.AI Taskforce recommended operational steps: create guidance notes for implementers; define nomenclature and classification for AI use cases; develop auditor control objectives; establish auditor accreditation and systems auditor registries; launch a voluntary national AI certification based on audit outcomes; and run regulatory and data sandboxes to allow experimental deployments under controlled conditions. The Framework recommends organizational responsibilities (board and executive levels), policies for procurement and supplier management, and templates for technical and governance artefacts (risk registers, model documentation, test plans). Implementation guidance emphasises interoperability with sectoral compliance obligations and international best practices, while offering checklists and documentation templates to aid practical adoption.
Monitoring and Evaluation
Monitoring is proposed as a mix of self‑reporting, third‑party audits (for certification), and oversight by the National Technology Ethics Committee and MDIA. Key performance indicators recommended include adoption rates, number of certified systems, incidents and near‑misses logged, audit results, complaint volumes and remediation times, and periodic reviews of the Framework itself to reflect technological and legal developments. The MDIA envisaged using its web portal to publish progress metrics and to coordinate stakeholder feedback loops. Sandboxes and pilot projects are expected to yield empirical evidence for refining controls and calibration of certification criteria.
Penalties, Liability, and Appeals
As a non‑binding framework, it does not set statutory penalties. Instead, the Framework links to existing legal obligations (notably data protection law) where binding sanctions may apply. The document explains that failure to follow the Framework could affect access to voluntary certification, public procurement opportunities, or lead to reputational and contractual consequences. Liability for harms caused by AI remains governed by existing civil and sectoral laws; the Framework recommends that Malta’s advisory committees explore the need for targeted legislative measures (for example on tort liability, product safety or supply‑chain responsibilities). The Framework also recommends establishing appeals channels within certification and auditing processes to address contested audit outcomes. For binding enforcement (e.g., GDPR), complainants retain their rights to approach the Information and Data Protection Commissioner.
Relationship to Other Instruments
The Framework is explicitly designed to align with, complement and not supplant existing instruments. It references and builds on the EU High‑Level Expert Group on AI’s guidelines, OECD AI Principles, and existing Maltese legislation (including data protection law and the MDIA’s ITAS/Innovative Technology Arrangements framework). The document positions the Framework as the ethical foundation for the MDIA’s voluntary AI certification and for the national AI Strategy actions such as sandboxes and advisory committees. It therefore acts as an integrative instrument linking ethical guidance, auditor frameworks and MDIA certification processes.
International Alignment
International alignment is a core objective: the Framework seeks compatibility with the EU HLEG Trustworthy AI Guidelines and OECD AI Principles to facilitate cross‑jurisdictional interoperability and to make Malta an attractive jurisdiction for trusted AI development. The Framework’s voluntary certification programme was designed with an eye toward recognition in export markets and alignment with emerging international standards. Malta’s approach intentionally emphasises technology neutrality and references to European policy developments (including anticipated EU legislative initiatives) to ensure the Framework can be mapped to supranational obligations.
Implementation Timeline
| Date | Event |
|---|---|
| 2019-08-09 | Public consultation launched for "Malta: Towards Trustworthy AI" (Government press release, 9 Aug 2019). |
| 2019-09-06 | Consultation period for Malta.AI consultation document (deadline indicated in early materials). |
| 2019-10-01 | Final materials published in October 2019; MDIA advanced consultation on certification guidance through Autumn 2019 (MDIA consultation). |
| 2019-10-03 | Launch of Malta National AI Strategy and public announcement of the voluntary AI certification programme (Gov.mt press release, 3 Oct 2019). |
| 2019-11-01 | MDIA consultation period for AI certification guidance (closing date indicated in MDIA material). |
Compliance Checklist
| Requirement | Action/Artefact |
|---|---|
| Principle mapping | Map project features to the four ethical principles (human autonomy, harm prevention, fairness, explicability) |
| Risk assessment | Document lifecycle risk register and mitigation plan; conduct DPIA if personal data involved |
| Documentation | Produce model cards, system documentation, data lineage and provenance records |
| Testing & validation | Maintain test plans, results, robustness and adversarial testing evidence |
| Human oversight | Define roles for meaningful human oversight and escalation procedures |
| Security & resilience | Implement cybersecurity controls, incident response plan and patching processes |
| Fairness & bias mitigation | Perform bias audits, representativeness tests and mitigation steps |
| Third‑party audit / certification | Prepare for systems auditor review and evidence required for MDIA voluntary certification |
Sources and References
| Source | Type |
|---|---|
| Malta: Towards Ethical and Trustworthy AI (vFINAL) | Primary Source |
| Government press release: Launch of Malta’s National AI Strategy (03 Oct 2019) | Primary Source |
| Malta Digital Innovation Authority (MDIA) – AI consultation and guidance | Primary Source |
| EU AI Watch – Malta AI Strategy Report (reference to Framework) | Secondary Source |
Malta's Ethical AI Framework, adopted in October 2019, provides non-binding national guidance for anyone designing, developing, deploying, or managing artificial intelligence (AI) systems, including companies, vendors, and public bodies. Its primary aim is to foster the ethical, transparent, and human-centric use of AI across the country.
The framework is built on four core ethical principles: ensuring human autonomy, preventing harm, promoting fairness, and demanding explicability. To translate these principles into practical measures, it recommends several key operational controls for organisations throughout an AI system's lifecycle. These include: - Thorough risk identification and management, similar to Data Protection Impact Assessments, to address potential safety, privacy, and socio-ethical risks. - Designing systems with meaningful human oversight to ensure competent human control over significant outcomes. - Actively mitigating bias and ensuring fairness, for instance, through careful dataset governance and rigorous fairness testing. - Providing clear explanations and transparency about how AI systems function, using documentation like "model cards" and user notices to enable challenge and recourse.
While this framework became effective on October 3, 2019, it does not impose direct legal penalties. This is a crucial distinction: it serves as guidance, not a law with statutory fines. However, ignoring the framework could still lead to significant business repercussions. Companies might miss out on Malta's voluntary national AI certification, which could impact public procurement opportunities or result in reputational damage. Liability for any harm caused by AI systems would still be governed by existing civil and sectoral laws, such as data protection regulations. A practical pitfall for readers is to assume "non-binding" means "ignorable"; adherence is strongly encouraged through market incentives and alignment with broader legal obligations.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under Malta - Ethical AI Framework. Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before placing on market
Applies to: Designers, developers, and deployers of AI systems processing personal data.
“DPIA‑style assessments where personal data are used”
- #2Important⏰ Before placing on market
Applies to: Designers, developers, and deployers of AI systems.
“risk identification and lifecycle risk management”
- #3Important⏰ Before placing on market
Applies to: Designers and developers of AI systems.
“human‑centric design and meaningful human oversight to preserve human autonomy”
- #4Important⏰ Before placing on market
Applies to: Designers, developers, and deployers of AI systems.
“bias and fairness mitigation, including dataset governance and fairness testing”
- #5Important⏰ Before placing on market
Applies to: Designers, vendors, and deployers of AI systems.
“explicability and transparency, including documentation, model cards and user notices”
- #6Important⏰ Before placing on market
Applies to: Designers, developers, and deployers of AI systems.
“robust systems testing, validation and assurance processes”
- #7Important⏰ Before placing on market
Applies to: Designers, developers, and deployers of AI systems.
“security and resilience (threat modelling, adversarial testing, patching and incident response)”
- #8Important⏰ Before placing on market
Applies to: Designers, developers, and deployers of AI systems.
“accountability mechanisms including logging, provenance, and audit trails”
- #9Important
Applies to: Deployers of AI systems.
“continuous monitoring practices for deployed systems”
- #10Recommended⏰ Before placing on market
Applies to: Designers, developers, and deployers of AI systems.
“Map project features to the four ethical principles (human autonomy, harm prevention, fairness, explicability)”
- #11Recommended
Applies to: Providers and deployers seeking voluntary AI certification.
“launch a voluntary national AI certification based on audit outcomes”
Related Regulations
Malta — The Ultimate AI Launchpad: A Strategy and Vision for Artificial Intelligence in Malta 2030
Malta95% similar
AI Innovative Technology Arrangement (AI ITA) scheme / National AI certification programme (MDIA)
Malta93% similar
Ethics Guidelines for Trustworthy AI (High-Level Expert Group on AI)
European Union93% similar
AI Ethics Framework (Australia) / Australia’s AI Ethics Principles
Australia93% similar
Ethical Artificial Intelligence Framework
Hong Kong92% similar
© Regulations.AI — created on 13-Jun-2026