Romania - AI Legal Framework (B154/2024)
Draft Law regarding Artificial Intelligence, B154/2024
Proiect de lege privind Inteligența Artificială, B154/2024
Romania
RAI-RO-NA-DBPRAXX-2024Draft Law B154/2024 (registered as L255/2024 at the Senate and PLX336/2024 at the Chamber of Deputies) is a national proposal to create a legal framework for the development, deployment and protection of artificial intelligence in Romania. The proposal sets out definitions, institutional responsibilities, risk-based obligations for providers and users, registration and assessment requirements, and enforcement mechanisms while aligning with EU-level action on AI.
Summary
Draft Law B154/2024 (Senate registration L255/2024; Chamber registration PLX336/2024) is a parliamentary proposal initiated in March 2024 to establish a national legal framework addressing artificial intelligence (AI) across technical, economic, societal and security domains. The initiative was introduced by deputies Daniel Florea and Andi-Gabriel Grosaru and advanced through Senate procedures before being transmitted to the Chamber of Deputies for further debate. The Senate record and associated committee reports show the initiative was debated by specialised parliamentary committees, consulted with public bodies (including ANCOM, the national cyber bodies and national research institutes) and received negative advisory opinions from the Consiliul Economic și Social and the Consiliul Legislativ. The proposal was ultimately rejected by the Senate plenary on 21 May 2024 and transmitted to the Chamber of Deputies where it continued in committee review and produced further opinions through 2024–2025.
Substantively, the draft law is comprehensive and prescriptive. It sets out objectives to support development, deployment and protection of AI, to provide national-level rules on classification of AI systems, and to introduce obligations for developers, providers and deployers (including risk assessment, documentation, cybersecurity measures, transparency requirements and registration/conformity mechanisms). It also seeks to protect fundamental rights, including by limiting certain biometric or privacy-intrusive uses and by preventing AI-based displacement of labour in certain circumstances (the text and sponsor materials emphasise safeguarding employment and public order). The bill contemplates institutional oversight and cooperation with national cyber and communications authorities, and foresees incident reporting and market surveillance obligations. It draws on European developments (including reference to the EU's AI regulatory package) and anticipates mechanisms for alignment with EU rules.
The parliamentary materials available on the Senate website (the legislative file L255/2024 and linked documents such as the exposition of motives and committee reports) show strong expert engagement but also substantial concerns from advisory bodies about scope, prescriptiveness and potential conflict or overlap with pending or adopted EU-level regulation. The Consiliul Legislativ and Consiliul Economic și Social issued negative opinions, noting that the subject is complex and that EU-level harmonisation (the EU Artificial Intelligence Act and related instruments) reduces the space for divergent national rules. Committee reports further document hearings with ANCOM, DNSC (Directoratul Național de Securitate Cibernetică), the SRI National Cyberint Centre and research institutions. The legislative file records that the Senate committee produced a report recommending rejection and the Senate plenary rejected the bill (97 votes against, none in favour, no abstentions) on 21 May 2024, after which the file was transmitted to the Chamber of Deputies. The Chamber's files record subsequent referral to multiple committees and additional advisory opinions into 2025, including a commission report of rejection dated 15 April 2025.
For stakeholders, the bill would impose a mix of administrative, technical and procedural duties: mandatory risk classification, documentation and record-keeping, conformity and registration for certain categories, transparency to users and public bodies, incident reporting, cybersecurity safeguards, and a sanctions regime. The proposal also envisages institutional coordination for supervision and market surveillance and explicitly references cooperation with national cyber authorities and communications regulators. Observers and advisory bodies recommended a more incremental, sectoral and EU-aligned approach rather than a broad prescriptive national statute.
Primary official sources for the bill include the Senate legislative file page and the PDFs attached there: the sponsor submission, the exposition of motives, Consiliul Economic și Social aviz and Consiliul Legislativ aviz, and the Senate committee report. These are published on the official Senate portal and are the principal documentary basis for the analysis of B154/2024.
Full article
Read full text ↗Overview
Draft Law B154/2024 (Senate file L255/2024; Chamber of Deputies PLX336/2024) is a national legislative proposal introduced on 19 March 2024 to regulate artificial intelligence in Romania. The legislative dossier (see the Senate file L255/2024) includes the sponsors' submission, an exposition of motives, committee reports and advisory opinions from the Consiliul Economic și Social and the Consiliul Legislativ. The bill aims to create a domestic framework covering AI development, deployment, protection, oversight and sanctions; it adopts a risk-based approach and references the European AI regulatory initiative as a background policy driver. Key procedural steps and official documents are available from the Senate legislative page and linked PDFs: sponsor submission and cover letter (adresa inițiatorului), exposition of motives (expunerea de motive), Consiliul Economic şi Social opinion (aviz CES), and Consiliul Legislativ opinion (aviz Consiliul Legislativ).
Definitions
The bill proposes explicit definitions intended to structure regulatory scope. Typical definitions include: 'artificial intelligence' and its variants (narrow/specialized AI, general-purpose AI, and 'superintelligence'), 'AI system' (software and hardware delivering automated decision-making or outputs), 'provider' (developer or organisation placing AI systems on the market or putting them into service), 'user' (legal or natural persons deploying the AI system), 'high-risk system' (categories identified by anticipated impact on safety, rights and public order), and 'personal data' as per GDPR cross-reference. These definitions aim to align with EU concepts while also proposing national-specific categories; advisory bodies raised concerns about novelty and national-level departures from EU terminology (see the Consiliul Legislativ opinion linked above).
Governance and Institutional Framework
The draft sets out a governance architecture that combines parliamentary oversight, sectoral committee roles and executive/administrative supervision. The Senate committee report documents that hearings included ANCOM (communications regulator), the national cyber bodies (the Centre for Cyberint within the SRI and the Directoratul Național de Securitate Cibernetică - DNSC) and national research institutes such as ICI Bucureşti (ICI Bucureşti). The bill contemplates either designating an existing authority or creating a new national supervisory body tasked with market surveillance, registration of certain AI systems, coordination of conformity assessments, and liaison with EU-level bodies. It requires interagency cooperation on cybersecurity, civil-protection and law-enforcement interfaces and foresees advisory and technical panels for methodology and standards. The legislative material indicates that the Government and relevant ministries would play roles in secondary regulation and that consultation with the Consiliul Economic şi Social and the Consiliul Legislativ is foreseen by procedure; both issued negative opinions, primarily on grounds of timing relative to EU harmonisation and the complexity of the subject.
Key Focus Areas
The bill concentrates on a set of cross-cutting areas: (1) risk classification and prohibitions — it proposes categories for systems that present unacceptable or high risk and, in some cases, limits on specific uses (the exposition of motives describes uses in military, judicial and biometric contexts and expresses intent to limit replacement of human labour); (2) transparency and disclosure — obligations to provide information to users and subjects impacted by AI outputs, labeling of AI-generated content where relevant, and documentation to enable audits; (3) conformity and registration — obligations to demonstrate compliance for high-risk systems through technical documentation, internal risk assessments and, in certain cases, independent conformity assessment and formal registration with a national registry; (4) data protection and privacy — cross-reference to GDPR compliance, special safeguards for biometric and sensitive data processing; (5) cybersecurity and model security — requirements for technical and organisational measures to ensure model integrity, availability and confidentiality; (6) safety, testing and evaluation — pre-deployment testing, validation and monitoring; and (7) market surveillance and enforcement — powers for administrative inspections, incident reporting obligations and sanctions. Committee hearings and the Consiliul Economic şi Social opinion flagged the breadth and prescriptive character of the proposed measures and recommended alignment with EU instruments and sector-specific rules.
Implementation Framework
Implementation is designed as a mix of primary law and delegated/secondary acts. The bill envisages that detailed technical rules, conformity procedures and registration mechanisms would be specified through Government decisions or ministerial regulations, with timelines for providers to comply after publication. It foresees capacity-building measures for public authorities and resources for market surveillance, including potential fees for registration or conformity procedures. The draft also anticipates cooperation with EU institutions (following the EU AI Act architecture) and proposes bilateral coordination between national cyber authorities and communications regulators for joint oversight of dual-use or critical AI systems. Several advisory opinions recommended postponement or narrowing of national implementing powers pending EU-level finalisation, and the Senate committee report highlights practical challenges for rapid nationwide enforcement without additional institutional capacity.
Monitoring and Evaluation
Monitoring mechanisms include mandatory reporting (periodic and incident-based) by providers and users, obligations to retain documentation that permits audits, and requirements to run post-market monitoring and continuous risk assessments. The bill sets out indicators and reporting templates to be adopted in secondary legislation and foresees public annual reporting by the supervising authority on compliance, market trends and enforcement actions. There is an expectation of cooperation with national cybersecurity bodies for incident handling and with statistical/regulatory agencies to evaluate economic and social impacts. Advisory opinions requested clearer metrics, resource estimates and planned administrative timelines for evaluation to avoid uneven application across sectors.
Penalties, Liability, and Appeals
Enforcement mechanisms include administrative sanctions (fines and corrective measures), orders to suspend or withdraw non-compliant systems from the market, and criminal or administrative liability where unlawful behaviour or negligence is established. The bill also contemplates civil liability provisions for harm caused by AI systems, with obligations to ensure remediation and access to redress for affected individuals. Affected parties would retain appeal rights in administrative courts against supervisory decisions. Committee reports and the Consiliul Legislativ opinion emphasise the need to calibrate penalties in proportion to risk and avoid duplicative liability regimes given existing consumer protection, labour and data protection laws.
Relationship to Other Instruments
The draft explicitly references EU legislative work on AI and related EU instruments. Advisory materials and committee reports repeatedly stress that the proposed national law must be read against the EU AI Act and existing Romanian legal instruments (GDPR, national cybersecurity laws, consumer protection, labour law). The Consiliul Legislativ's opinion highlights that EU-level harmonised regulation substantially constrains national measures where EU competence applies. The bill envisages amendments to or interplay with sectoral laws where AI systems interact with regulated sectors (healthcare, finance, telecommunications) and proposes coordination mechanisms to avoid regulatory overlap. The Senate committee record lists consultations with ANCOM and national cyber bodies to identify these interdependencies.
International Alignment
The exposition of motives and committee materials indicate the sponsors' aim to align Romania with EU-level AI regulatory objectives while also preserving national security and operational needs. The draft references the EU AI initiative and calls for Romania to harmonise domestic approaches with European norms. Advisory opinions caution against premature or unilateral national measures that could diverge from the EU AI Act (already the dominant legal reference for AI in EU member states). The bill's approach to international alignment includes provisions for cross-border enforcement cooperation, data-sharing protocols with EU bodies, and conformity evaluation frameworks that can interoperate with EU conformity assessment processes.
Implementation Timeline
| Milestone | Date |
|---|---|
| Bill registered at Senate (b154/L255) | 2024-03-19 |
| Sent for CES and Consiliul Legislativ avize | 2024-03-26 |
| Consiliul Economic şi Social aviz (negative) | 2024-04-16 |
| Consiliul Legislativ aviz (negative) | 2024-04-17 |
| Committee hearings and reports | May 2024 (reports dated 13–29 May 2024) |
| Senate plenary vote (rejected) | 2024-05-21 |
| Transmitted to Chamber of Deputies (PLX336/2024) | 2024-05-27 |
| Chamber committee reviews and Government opinion (negative) | June 2024–April 2025 |
Sources and References
| Source | Type |
|---|---|
| Senate legislative file L255/2024 (Propunere legislativă privind Inteligența Artificială) | Primary Source |
| Exposition of motives (expunerea de motive) | Primary Source |
| Consiliul Legislativ aviz (negative) | Primary Source |
| Consiliul Economic şi Social aviz (negative) | Primary Source |
Requirements for a company
What an organisation has to do under Romania - AI Legal Framework (B154/2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.
Must do
12- Classify your AI system according to its risk level.All providers and users of AI systems.
- Conduct and document internal risk assessments for high-risk AI systems.Providers of high-risk AI systems.
- Register high-risk AI systems with the national registry.Providers of high-risk AI systems.
- Implement technical and organisational measures to ensure AI model integrity, availability, and confidentiality.All operators of AI systems.
- Provide information to users and subjects impacted by AI outputs.Providers and users of AI systems.
- Label AI-generated content where relevant.Providers and users of AI systems.
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Romania - AI Legal Framework (B154/2024), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All providers and users of AI systems. | Classify your AI system according to its risk level. “risk classification and prohibitions — it proposes categories for systems that present unacceptable or high risk” | Before placing on market or putting into service | — | Critical |
| 2 | Providers of high-risk AI systems. | Conduct and document internal risk assessments for high-risk AI systems. “obligations to demonstrate compliance for high-risk systems through technical documentation, internal risk assessments” | Before placing on market or putting into service | — | Critical |
| 3 | Providers of high-risk AI systems. | Register high-risk AI systems with the national registry. “formal registration with a national registry” | Before placing on market or putting into service | — | Critical |
| 4 | All operators of AI systems. | Implement technical and organisational measures to ensure AI model integrity, availability, and confidentiality. “requirements for technical and organisational measures to ensure model integrity, availability and confidentiality” | Before putting into service | — | Critical |
| 5 | Providers and users of AI systems. | Provide information to users and subjects impacted by AI outputs. “obligations to provide information to users and subjects impacted by AI outputs” | Before putting into service | — | Critical |
| 6 | Providers and users of AI systems. | Label AI-generated content where relevant. “labeling of AI-generated content where relevant” | Before putting into service | — | Critical |
| 7 | Providers of AI systems. | Retain technical documentation to enable audits. “documentation to enable audits; obligations to retain documentation that permits audits” | — | — | Critical |
| 8 | Providers of AI systems. | Conduct pre-deployment testing and validation of AI systems. “pre-deployment testing, validation and monitoring” | Before placing on market or putting into service | — | Critical |
| 9 | Providers of AI systems. | Run post-market monitoring and continuous risk assessments. “requirements to run post-market monitoring and continuous risk assessments” | — | — | Critical |
| 10 | Providers and users of AI systems. | Report incidents to the supervising authority. “incident reporting obligations; mandatory reporting (periodic and incident-based)” | — | — | Critical |
| 11 | Providers and users of AI systems. | Ensure remediation and access to redress for affected individuals. “obligations to ensure remediation and access to redress for affected individuals” | — | — | Critical |
| 12 | Providers and users of AI systems processing personal data. | Comply with GDPR and apply special safeguards for biometric and sensitive data processing. “cross-reference to GDPR compliance, special safeguards for biometric and sensitive data processing” | — | — | Critical |
Related Regulations
Romanian AI Legislative Proposal L255/2024 (Rejected)
Romania94% similar
Government Memorandum No. 20D/31781/MN on Artificial Intelligence (establishing national AI initiatives and governance structures)
Romania89% similar
Cadru Strategic Național în domeniul Inteligenței Artificiale (CSN-IA) — National Strategic Framework for Artificial Intelligence (document submitted to public consultation, October 2023)
Romania89% similar
Law on the responsible use of technology in the context of the deepfake phenomenon (PL-x No. 471/2023)
Romania89% similar
Draft AI Act presented by political party 'Da, Bulgaria' (project bill for an AI law)
Bulgaria88% similar
© Regulations.AI · updated on 13-Jun-2026