Slovenia - AI Regulation Implementation (85/2025)

Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence

Zakon o izvajanju Uredbe (EU) o določitvi harmoniziranih pravil o umetni inteligenci / Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (national implementing act)

Slovenia

RAI-SI-NA-ZOIUEXX-2025
Effective: 21 Nov 2025
In Force(In Force)Checked 9 Sep 2026

Slovenia - AI Regulation Implementation (85/2025) is In Force in Slovenia as of 9 Sep 2026, according to uradni-list.si.

ActGovernance and OversightMarket SurveillanceConformity Assessment and Registration
Export PDF

The Act on the Implementation of the EU AI Act establishes national oversight and enforcement rules for AI providers and deployers, adopted by the National Assembly in 2025. In force as of 21 November 2025, the act (Uradni list RS No. 85/2025) designates sectoral supervisors, with compliance monitored by the Information Commissioner and AKOS.

Summary

The Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (ZIUDHPUI) was adopted by the National Assembly on 23 October 2025, proclaimed on 31 October 2025 and published in the Uradni list RS (No. 85/2025). The Act's primary purpose is to allocate and specify national competences and procedures required for the application, enforcement and operationalisation of Regulation (EU) 2024/1689 (the EU Artificial Intelligence Regulation / AI Act) in Slovenia. Because the EU Regulation applies directly across Member States, the national Act does not duplicate or change the substantive obligations on providers, deployers or users of AI systems. Instead, it: (i) designates the 'notifying' (priglasitveni) authorities for different categories of high‑risk AI systems (assigning ministries and sectoral agencies depending on Annexes of the EU Regulation); (ii) identifies market surveillance authorities (including the Agency for Communication Networks and Services (AKOS), the Information Commissioner, Banka Slovenije, the Insurance Supervision Agency and the Market Inspectorate) and sets rules for coordination, funding and operational independence; (iii) establishes the ministry responsible for information society as the national contact point and the competent body for certain registries, regulatory sandboxes and coordination tasks; (iv) creates a National Council for Ethics in AI and tasks the ministry for digital transformation with public awareness, SME outreach and sandbox promotion; (v) delegates oversight of conformity assessment bodies to the national accreditation authority and prescribes the inspectorates and procedures that will exercise inspection powers; and (vi) transposes enforcement/penalty modalities required by the EU Regulation into Slovenian administrative procedure practice, including specifying which domestic laws supplement enforcement steps and which procedural rules apply for sectoral supervisors. The Act also requires alignment of agency statutes and budgetary provisions so that sectoral supervisors (e.g., AKOS, Banka Slovenije, AZN) have funding from the state budget sufficient to fulfil their tasks. The law sets a commencement clause: it enters into force fifteen days after publication in the Uradni list, which gives an effective date in November 2025. Practically, the Act provides legal clarity for authorities, confirms a single national contact point for industry and citizens, and enables regulated testing environments (regulatory sandboxes), while reserving the AI Regulation's substantive requirements (prohibited practices, high‑risk obligations, transparency rules, general purpose model rules, and the EU database) as the primary compliance framework. For details of the enacted text see the official publication in the Uradni list and the Ministry of Digital Transformation announcements.

Full article

Read full text ↗

Overview

The Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (ZIUDHPUI) organises how Slovenia will apply and enforce Regulation (EU) 2024/1689 (the EU AI Regulation). The law does not add new substantive restrictions on AI systems — those are set by the EU Regulation — but specifies which national authorities will act as notifying bodies for different categories of high‑risk systems, which agencies will perform market surveillance and enforcement, and how coordination and financing will operate. The Act also provides for establishment of a national ethics council, regulatory sandboxes, a public register and outreach programmes for SMEs and public authorities. See the official text in the Uradni list and the Ministry announcement: Uradni list RS, No. 85/2025 (ZIUDHPUI) and Ministry for Digital Transformation – announcement, 24 Oct 2025.

Definitions

The Act relies on the terminology of Regulation (EU) 2024/1689; expressions used in the national law mean the same as those in the EU Regulation. Key terms therefore include: 'AI system', 'provider', 'deployer', 'high‑risk AI system' (as defined by Annexes I and III of the EU Regulation), 'notified body/priglasitveni organ', 'market surveillance authority', 'post‑market monitoring', 'regulatory sandbox' and 'national contact point'. The Act adds no new substantive definitions but maps EU Annex categories to specific Slovenian ministries and agencies for administrative purposes; for the EU text see Regulation (EU) 2024/1689 (EU AI Regulation).

Governance and Institutional Framework

The Act designates sectoral competent authorities: the ministry responsible for the internal market (as notifying authority for many Annex I systems), the ministry responsible for infrastructure, the ministry responsible for health and the Public Agency for Medicines and Medical Devices for medical device‑related AI systems. It names market surveillance authorities: AKOS, the Information Commissioner (Informacijski pooblaščenec), Banka Slovenije, the insurance supervision function (referred to through government channels) and the Market Inspectorate. The statute establishes the ministry for digital transformation as the central coordinator and the authority in charge of regulatory sandboxes and an SME outreach programme. The law assigns oversight of conformity assessment bodies to the national accreditation body and instructs the inspectorate for the information society to monitor publicity, literacy and public sector publication duties. Institutional independence is preserved for regulatory agencies; the Act also requires alignment of agency statutes and provides for state budget financing for agency enforcement tasks. See the enacted provisions in the official publication: Uradni list RS (ZIUDHPUI).

Key Focus Areas

The Act focuses on (1) clear allocation of responsibilities for notifying and supervising high‑risk systems; (2) operational arrangements for post‑market monitoring and market surveillance; (3) provisions to enable and supervise regulatory sandboxes (controlled testing environments) to support innovation while ensuring safety; (4) institutional support for public awareness, SME outreach and AI literacy; (5) funding and staffing requirements for supervisory bodies; (6) rules on cooperation and information‑sharing among national supervisors and with the European AI Office and AI Board; and (7) national measures needed to implement enforcement and administrative sanctions compatible with the EU Regulation. The Act explicitly preserves the EU Regulation’s substantive categories — prohibited uses, high‑risk systems and transparency obligations — and concentrates national measures on enforcement, administrative procedure, and support mechanisms for compliance. For the EU framework and timelines see the AI Regulation (EU) and the Ministry materials (Digitalisation – GOV.SI).

Implementation Framework

The Act sets out concrete administrative steps: ministries and sectoral agencies are listed as notifying authorities for specific Annex categories of the EU Regulation (e.g., market ministry, infrastructure, health, medicines agency). It requires the national accreditation body to evaluate conformity assessment bodies. Agencies named as market surveillance authorities are empowered to use authority deriving from existing inspection and technical conformity acts; where sectoral rules apply (banking, insurance) relevant sectoral legal procedures and sanctions regimes supplement the AI enforcement powers. The Act mandates that AKOS act as the single contact point for industry and the public to provide information and access to sandboxes and support. Agencies must align their statutes and be allocated budgetary resources (state funds) sufficient to carry out their responsibilities. Where the Act refers to procedural law (e.g., administrative procedure, inspection acts), it instructs agencies to follow those laws for enforcement actions, appeals, and judicial review. See the text in the Uradni list for article‑level detail: ZIUDHPUI (Uradni list RS).

Monitoring and Evaluation

The Act requires post‑market monitoring arrangements consistent with the EU Regulation: market surveillance authorities must maintain records, request documentation (including technical documentation generated under the AI Regulation), and report significant incidents. The national inspectorate for the information society is charged with oversight of public sector transparency obligations and literacy measures; agencies are required to cooperate and exchange findings. The Act instructs the national accreditation body to assess conformity bodies and report deficiencies. Agencies will participate in EU‑level cooperation mechanisms (AI Board, European AI Office) and share data through the EU high‑risk systems database when required by the EU Regulation. Periodic reporting and coordination meetings are mandated to evaluate resource sufficiency and enforcement outcomes.

Penalties, Liability, and Appeals

The Act implements administrative enforcement measures and specifies which national authorities may impose sanctions for breaches of obligations under the EU Regulation. It does not substitute the monetary penalty scales set in the EU Regulation (e.g., tiered fines for banned practices, high‑risk non‑compliance and reporting failures), but it provides the procedural basis for imposing administrative fines, corrective measures, orders to cease deployment, recalls, and publication of non‑compliance. Where sectoral supervisors (e.g., Banka Slovenije or the insurance supervision authority) are responsible, the Act directs the use of sectoral enforcement powers and remedies under banking, consumer credit or insurance law. The Act also clarifies appeal routes: where administrative appeal is not permitted (certain agency decisions), judicial review is available. The detailed penalty formulas are governed primarily by the EU Regulation and by the relevant sectoral national laws referenced in the Act.

Relationship to Other Instruments

The Act explicitly references Regulation (EU) 2024/1689 and aligns national administrative procedures with existing Slovenian laws (laws on electronic communications as applicable to AKOS, banking law for Banka Slovenije, insurance law for AZN, and inspection laws for inspectorates). It also requires agencies to apply existing technical conformity, accreditation and inspection laws when exercising powers under the Act. Where the EU Regulation amends or interacts with other EU legal instruments referenced in the Act, the national law points to the applicable domestic statutes for procedural detail. In short, the Act is a coordination and allocation instrument linking the EU Regulation to the domestic institutional and procedural framework; it neither duplicates nor modifies the EU substantive rules.

International Alignment

The Act ensures Slovenia’s compliance with EU obligations and cooperation with EU‑level bodies. It mandates that national supervisors participate in EU coordination mechanisms and share documentation necessary for cross‑border enforcement, consistent with Article 70+ of the EU Regulation. The law supports information exchange with the European AI Office, the AI Board and other Member State authorities, and it establishes national points of contact to facilitate cross‑border market surveillance and conformity assessment recognition. Additionally, by enabling sandboxes and outreach, the Act seeks to align national innovation policy with EU innovation support measures.

Implementation Timeline

EventDateSource
Public consultation opened (draft published)2025-03-14Ministry announcement (14 Mar 2025)
Government consideration / draft circulated2025-07-25Analysis reporting draft in government procedure (25 Jul 2025)
Parliament adoption (Državni zbor)2025-10-23Uradni list RS (adoption recorded)
Presidential proclamation2025-10-31Uradni list RS (proclamation text)
Publication in Uradni list2025-11-06Uradni list RS, No. 85/2025
Entry into force (15 days after publication)2025-11-21ZIUDHPUI, Article 45 (Začetek veljavnosti)

Sources and References

SourceType
Uradni list RS, No. 85/2025 — Zakon o izvajanju uredbe (EU) o določitvi harmoniziranih pravil o umetni inteligenci (ZIUDHPUI)Primary Source
Ministry for Digital Transformation – public announcement (24 Oct 2025)Primary Source / Government announcement
Regulation (EU) 2024/1689 — Official text (EU AI Regulation)Primary Source (EU)

Requirements for a company

What an organisation has to do under Slovenia - AI Regulation Implementation (85/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Act as the designated notifying authority for specific high-risk AI system categories.Ministries and agencies designated as notifying authorities.
  • Establish and maintain notification procedures for high-risk AI systems.Ministries and agencies designated as notifying authorities.
  • Act as the designated market surveillance authority for AI systems.Designated market surveillance authorities (AKOS, Information Commissioner, Banka Slovenije, insurance supervision, Market Inspectorate).
  • Set inspection plans and conduct conformity checks for AI systems.Designated market surveillance authorities.
  • Request and maintain technical documentation from AI system providers and deployers.Designated market surveillance authorities.
  • Perform enforcement actions and impose sanctions for breaches of the EU AI Regulation.Designated market surveillance authorities and sectoral supervisors.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Slovenia - AI Regulation Implementation (85/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Ministries and agencies designated as notifying authorities.Act as the designated notifying authority for specific high-risk AI system categories.
“The Act designates sectoral competent authorities: the ministry responsible for the internal market (as notifying authority for many Annex I systems)”
Ongoing—Critical
2Ministries and agencies designated as notifying authorities.Establish and maintain notification procedures for high-risk AI systems.
“Notifying authorities / ministries: Establish notification procedures, receive documentation, coordinate with AKOS and other surveillance authorities”
Ongoing—Critical
3Designated market surveillance authorities (AKOS, Information Commissioner, Banka Slovenije, insurance supervision, Market Inspectorate).Act as the designated market surveillance authority for AI systems.
“It names market surveillance authorities: AKOS, the Information Commissioner (Informacijski pooblaščenec), Banka Slovenije”
Ongoing—Critical
4Designated market surveillance authorities.Set inspection plans and conduct conformity checks for AI systems.
“Market surveillance authorities: Set inspection plans, request technical documentation, carry out conformity checks and enforcement actions”
Ongoing—Critical
5Designated market surveillance authorities.Request and maintain technical documentation from AI system providers and deployers.
“market surveillance authorities must maintain records, request documentation (including technical documentation generated under the AI Regulation)”
Ongoing—Critical
6Designated market surveillance authorities and sectoral supervisors.Perform enforcement actions and impose sanctions for breaches of the EU AI Regulation.
“The Act implements administrative enforcement measures and specifies which national authorities may impose sanctions for breaches of obligations”
Ongoing—Critical
7The national accreditation body.Oversee and evaluate conformity assessment bodies.
“The law assigns oversight of conformity assessment bodies to the national accreditation body”
Ongoing—Critical
8The Ministry for Digital Transformation.Act as the central coordinator for AI implementation and manage regulatory sandboxes.
“The statute establishes the ministry for digital transformation as the central coordinator and the authority in charge of regulatory sandboxes”
Ongoing—Critical
9The national inspectorate for the information society.Monitor public sector transparency obligations, AI literacy, and public sector publication duties.
“the inspectorate for the information society to monitor publicity, literacy and public sector publication duties.”
Ongoing—Critical
10AKOS.Act as the single contact point for industry and the public regarding AI information and support.
“The Act mandates that AKOS act as the single contact point for industry and the public to provide information and access to sandboxes and support.”
Ongoing—Critical
11All designated agencies and ministries.Align agency statutes and secure sufficient budgetary resources for AI-related responsibilities.
“Agencies must align their statutes and be allocated budgetary resources (state funds) sufficient to carry out their responsibilities.”
Ongoing—Critical
12All designated agencies and ministries.Participate in EU-level cooperation mechanisms and share necessary data with EU bodies.
“Agencies will participate in EU‑level cooperation mechanisms (AI Board, European AI Office) and share data through the EU high‑risk systems database”
Ongoing—Critical

© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 9 Sep 2026 using Gemini 3.6 Flash