Romania - Cooperation on AI and Cloud

Memorandum of Understanding between the Government of Romania and Google (15 July 2024) — cooperation on digital infrastructure, cloud, cybersecurity and use of advanced technologies including AI

Memorandum de Înțelegere între Guvernul României și Google (15 iulie 2024) — cooperare în infrastructura digitală, cloud, cibernetică și utilizarea tehnologiilor avansate, inclusiv IA

Romania

RAI-RO-NA-MUBGRXX-2024
Effective: July 15, 2024
In Force(In Force)
PolicyGovernance and OversightCybersecurity and Model SecurityData Protection and Privacy
Export PDF

On 15 July 2024 the Government of Romania and Google signed a Memorandum of Understanding to cooperate on the development of digital infrastructure, government cloud adoption, cybersecurity resilience, research and innovation and the deployment of advanced technologies including artificial intelligence. The MoU establishes a framework for technical cooperation, capacity building, and exploratory steps toward cloud region and data centre investment, while indicating non-binding commitments for information sharing, skills development and piloting public-sector projects.

Summary

On 15 July 2024 the Government of Romania (represented by the Minister of Research, Innovation and Digitalization, Bogdan Ivan) and representatives of Google (including senior Google Cloud executives) signed a Memorandum of Understanding (MoU) setting out a framework for cooperation in areas of digital infrastructure, cloud adoption, cybersecurity, innovation, research and the responsible use of advanced technologies including artificial intelligence (AI). The MoU is non-binding and intended to create structured channels for technical assistance, knowledge exchange, pilots of public-sector digital services, workforce upskilling and exploratory investment planning (including discussion of a potential Google Cloud region / data centre presence).

The agreement emphasises accelerating the Romanian public administration’s cloud migration (the “government cloud”), increasing operational efficiency through cloud-native services and AI-enabled tools, and strengthening national cyber resilience via exchange of best practices and capacity-building initiatives. The MoU identifies priorities such as modernization of tax and public services IT systems, digital transformation of citizen-facing services, joint pilots for AI-powered improvements in public administration, and collaboration on research and innovation programs.

Key elements of the MoU include establishing a joint working group, regular technical-level consultations, data protection and security commitments consistent with applicable law, and capacity-building initiatives for civil servants and technical teams. While the MoU does not itself change legal or regulatory obligations, it commits the parties to explore pilot projects, to exchange expertise on cloud security and incident response, and to consider investment and infrastructure needs such as a Google Cloud region. The Romanian press and official communications (Palatul Victoria / Government of Romania) reported the signing and statements by the Prime Minister stressing the strategic importance of cooperation with Google for digital transformation and cyber resilience. Google representatives highlighted alignment with Romania’s digital objectives and Europe’s Digital Decade 2030 targets.

Because the instrument is an MoU rather than a procuring contract or legally binding regulation, it focuses on cooperation principles, timelines for exploratory work and identified deliverables rather than prescriptive regulatory requirements. Official coverage and government statements make clear that subsequent project-level agreements, procurement procedures, conformity with EU rules (including GDPR and upcoming sectoral AI rules) and national procurement law will be required before operational deployments involving personal data or critical infrastructure. The MoU therefore functions as a policy-level enabling instrument to accelerate partnership formation, technical exchange and potential private investment, while leaving legal compliance, procurement and formal decision-making to subsequent processes.

Full article

Read full text ↗

Overview

The Memorandum of Understanding (MoU) signed on 15 July 2024 between the Government of Romania and Google creates a formal cooperation framework for: (a) modernising public-sector IT and adopting cloud-first architectures; (b) strengthening national cybersecurity posture and incident response capabilities; (c) piloting and responsibly deploying advanced technologies, including artificial intelligence (AI); and (d) supporting research, innovation and workforce development. The signing ceremony took place at Palatul Victoria and was publicly reported by the Government and national media; statements by the Prime Minister and the Minister for Research stressed an ambition to operationalise a government cloud and accelerate digital public services. Key public reporting may be consulted via official government communications and reputable press coverage such as Digi24 (15 July 2024) and the ministry/legal press reporting JURIDICE (15 July 2024).

Definitions

For the purpose of interpreting the MoU the following working definitions are used: "Government Cloud"—a technical and organisational programme to migrate public administration IT services to accredited cloud environments; "Advanced Technologies"—machine learning, AI systems, cloud-native services, data platforms and related automation; "Cyber Resilience"—the ability of public institutions to prevent, detect and respond to cyber incidents; "Joint Working Group"—the technical/strategic body established under the MoU to coordinate pilots and exchanges; and "Pilot Project"—any limited-scope technical implementation co-designed under the MoU. These definitions are used in public descriptions and are to be refined in implementation documents and project-level agreements.

Governance and Institutional Framework

The MoU establishes a bilateral governance architecture that typically includes: (1) a high-level strategic steering committee (senior officials from the Government and Google) to align objectives and review progress; (2) a joint working group of technical experts (cloud engineers, cybersecurity specialists, data protection officers and policy leads) to design pilots and co-develop operational roadmaps; and (3) designated contact points within the Ministry of Research, Innovation and Digitalization and relevant agencies. Government reporting indicated the involvement of the Prime Minister’s Office and the Ministry of Research, Innovation and Digitalization (MCID); national cybersecurity and data protection authorities will be consulted at project stage to ensure legal compliance. For background and official statements see the Government’s communications and media reporting such as Europa FM (15 July 2024). Implementation documents will specify membership, decision-making rules, and escalation mechanisms.

Key Focus Areas

The MoU identifies a set of priority focus areas: (a) Digital Infrastructure & Cloud — assess and accelerate the migration of public services to secure cloud platforms, explore a Google Cloud region or data centre investment and advise on network, power and resiliency requirements; (b) Cybersecurity & Resilience — share best practices, training and joint exercises to strengthen detection, response and supply-chain security; (c) AI & Advanced Technologies — pilot AI-enabled tools to improve administrative efficiency and citizen experience while adopting responsible AI principles; (d) Research & Innovation — support R&D collaborations with universities and local industry to scale innovation; (e) Skills & Capacity Building — deliver training for civil servants and technical teams; and (f) Policy & Standards Advice — exchange on regulatory approaches, alignment with EU digital objectives, and public procurement processes. Press coverage and official statements emphasised cloud operationalisation and tax system modernization; see reporting at Romania Insider (15 July 2024) and Business24 (15 July 2024). These focus areas will be elaborated in project-level scopes and feasibility studies.

Implementation Framework

Implementation follows a staged, non-binding approach: stage 0 — joint assessment and scoping (technical, legal, procurement and impact assessments); stage 1 — pilot design and proof-of-concept (small, time-limited projects that validate technical assumptions and governance); stage 2 — scaling subject to procurement, regulatory approval and risk assessment; stage 3 — long-term operational arrangements and investment decisions (including any data centre or cloud-region investment, which remain subject to due diligence and financing decisions). The parties committed to form a Joint Working Group and to prepare implementation roadmaps, data protection impact assessments (DPIAs) where necessary, and memoranda for each pilot specifying data flows, security controls and compliance obligations. The MoU explicitly leaves procurement, legal compliance and regulatory approvals outside its direct effect, requiring formal competitive processes when applicable.

Monitoring and Evaluation

Monitoring is structured around periodic reporting to the steering committee and technical dashboards maintained by the Joint Working Group. Metrics will track: project milestones, cloud migration readiness, training outputs, cybersecurity exercise outcomes, and evaluation of AI pilots using predefined safety and performance metrics. Independent or third-party technical reviews and DPIAs are foreseen for projects that process personal data or are security-sensitive. The MoU’s monitoring approach emphasises transparency of progress to government stakeholders and the need for alignment with national digital strategies and EU targets such as the Digital Decade.

Penalties, Liability, and Appeals

As an MoU the document does not establish administrative sanctions or statutory penalties; it is a cooperative, non-binding instrument. The MoU signals that any liability and appeals arrangements for concrete projects will be addressed in subsequent contractual agreements and procurement documents, which will set indemnities, warranties, limitation of liability, service-level obligations and dispute-resolution clauses. Where projects involve personal data, parties committed to respect applicable laws (e.g., GDPR) and to coordinate with the supervisory authority (ANSPDCP). For legal analysis and commentary see coverage at JURIDICE (15 July 2024).

Relationship to Other Instruments

The MoU complements existing national digital strategies, the government’s cloud programme and sectoral legislation. It is explicitly subordinate to: (a) national procurement and competition law; (b) EU law including GDPR and the proposed EU AI Act (to the extent applicable to future AI pilots); and (c) sectoral regulatory requirements for critical infrastructure (energy, health, finance). The MoU may be referenced in subsequent public procurement documentation and memoranda of understanding with other suppliers, but it neither replaces nor supersedes legal or regulatory requirements. Media reports suggest further MoUs or project agreements may follow if pilots are successful; see reporting in Curs de guvernare (15 July 2024).

International Alignment

The MoU frames the collaboration within broader European objectives including the Digital Decade 2030 goals and the EU’s regulatory trajectory for AI and data governance. Google stated alignment with EU targets and interoperability standards, and both parties committed to coordinate with EU institutions and to align pilots with applicable European standards and security expectations. Any investment in cloud regions or data centres would be subject to cross-border data transfer rules and EU state-aid and procurement scrutiny where relevant. See public statements by government and Google and coverage at Romania Insider and Business24.

Implementation Timeline

MilestoneTarget DateNotes
Signing of MoU2024-07-15Public signing and announcement at Palatul Victoria
Formation of Joint Working GroupQ3 2024Technical terms of reference to be agreed
Scoping and DPIAs for initial pilotsQ3–Q4 2024Legal and technical assessments to precede pilots
Pilot implementation (proof-of-concept)Q4 2024 – Q1 2025Limited-scope projects (e.g., tax system analytics, citizen-facing services)
Evaluation and scaling decisionQ2 2025Decisions contingent on procurement and regulatory clearance

Sources and References

SourceType
Digi24 – Government signs MoU with Google (15 July 2024)Primary Source (official communiqué reported by Government)
JURIDICE – Legal commentary (15 July 2024)Primary/Official report
Europa FM – coverage and embedded government social post (15 July 2024)Primary/Official reporting

Requirements for a company

What an organisation has to do under Romania - Cooperation on AI and Cloud, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Conduct Data Protection Impact Assessments for pilot projects involving personal data.Government of Romania and Google (for relevant pilot projects)
  • Respect applicable data protection laws, including GDPR, for projects involving personal data.Government of Romania and Google (for projects involving personal data)
  • Follow national procurement and competition law for any services or investments.Government of Romania (for procurement of services/investments)
  • Align future AI pilots with the proposed EU AI Act, to the extent applicable.Government of Romania and Google (for AI pilots)
  • Consult national cybersecurity and data protection authorities at the project stage.Government of Romania and Google (when designing projects)
  • Form a Joint Working Group of technical experts to design pilots and roadmaps.Government of Romania and Google
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Romania - Cooperation on AI and Cloud, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Government of Romania and Google (for relevant pilot projects)Conduct Data Protection Impact Assessments for pilot projects involving personal data.
data protection impact assessments (DPIAs) where necessary
Q3–Q4 2024Implementation FrameworkCritical
2Government of Romania and Google (for projects involving personal data)Respect applicable data protection laws, including GDPR, for projects involving personal data.
Where projects involve personal data, parties committed to respect applicable laws (e.g., GDPR)
Before pilot implementationPenalties, Liability, and AppealsCritical
3Government of Romania (for procurement of services/investments)Follow national procurement and competition law for any services or investments.
requiring formal competitive processes when applicable.
Before scaling or long-term operational arrangementsImplementation FrameworkCritical
4Government of Romania and Google (for AI pilots)Align future AI pilots with the proposed EU AI Act, to the extent applicable.
EU law including GDPR and the proposed EU AI Act (to the extent applicable to future AI pilots)
Before pilot implementationRelationship to Other InstrumentsCritical
5Government of Romania and Google (when designing projects)Consult national cybersecurity and data protection authorities at the project stage.
national cybersecurity and data protection authorities will be consulted at project stage to ensure legal compliance.
Before pilot design and proof-of-conceptGovernance and Institutional FrameworkImportant
6Government of Romania and GoogleForm a Joint Working Group of technical experts to design pilots and roadmaps.
The parties committed to form a Joint Working Group
Q3 2024Implementation FrameworkImportant
7Joint Working GroupPrepare implementation roadmaps for all cooperation activities.
and to prepare implementation roadmaps
Before pilot design and proof-of-conceptImplementation FrameworkImportant
8Joint Working GroupPrepare memoranda for each pilot specifying data flows, security controls, and compliance.
and memoranda for each pilot specifying data flows, security controls and compliance obligations.
Before pilot implementationImplementation FrameworkImportant
9Government of Romania and Google (for security-sensitive projects)Conduct independent or third-party technical reviews for security-sensitive projects.
Independent or third-party technical reviews... foreseen for projects that... are security-sensitive.
Before scaling or long-term operational arrangementsMonitoring and EvaluationImportant
10Joint Working GroupProvide periodic reporting to the steering committee on project progress and outcomes.
Monitoring is structured around periodic reporting to the steering committee
OngoingMonitoring and EvaluationImportant
11Joint Working GroupMaintain technical dashboards to track project milestones, readiness, and outcomes.
technical dashboards maintained by the Joint Working Group.
OngoingMonitoring and EvaluationImportant
12Government of Romania and GoogleAlign cooperation activities with broader European objectives, including Digital Decade 2030 goals.
The MoU frames the collaboration within broader European objectives including the Digital Decade 2030 goals
OngoingInternational AlignmentImportant

© Regulations.AI · updated on 13-Jun-2026