Slovakia AI Conformity Assessment Act
Act No. 318/2025 Coll., amending and supplementing Act No. 56/2018 Coll. on product conformity assessment (EU AI Act adaptation)
Zákon č. 318/2025 Z. z. o zmene a doplnení zákona č. 56/2018 Z. z. o posudzovaní zhody výrobkov (adaptácia na akt EÚ o umelej inteligencii)
Slovakia
RAI-SK-NA-ACTNO31-2025Act No. 318/2025 Coll.
Slovakia's Act No. 318/2025 Coll. integrates the EU AI Act into national law, focusing on conformity assessment for AI systems.
Summary
Read full text ↗Plain English
Overview
Act No. 318/2025 Coll., officially known in Slovak as Zákon č. 318/2025 Z. z., ktorým sa mení a dopĺňa zákon č. 56/2018 Z. z. o posudzovaní zhody výrobkov, sprístupňovaní určeného výrobku na trhu a o zmene a doplnení niektorých zákonov v znení neskorších predpisov, represents a pivotal legislative development in Slovakia's regulatory landscape for artificial intelligence. This Act serves as a crucial national adaptation measure to align Slovak law with the directly applicable Regulation (EU) 2024/1689, commonly referred to as the EU AI Act. Its primary objective is to integrate the comprehensive framework established by the EU AI Act into the existing national legal system, specifically by amending the Act No. 56/2018 Coll. on product conformity assessment. The amendment ensures that AI systems placed on the Slovak market or otherwise used within the country adhere to the stringent safety, ethical, and transparency requirements set forth by the European Union. By modifying the conformity assessment procedures, Slovakia aims to create a robust mechanism for verifying that AI products and services comply with the new EU standards, thereby fostering trust in AI technologies while safeguarding fundamental rights and promoting innovation.
The significance of Act No. 318/2025 Coll. extends beyond mere legislative alignment; it establishes the practical mechanisms through which the EU AI Act's provisions will be enforced at a national level. Coming into effect on January 1, 2026, this Act precedes the full applicability of certain EU AI Act obligations, demonstrating Slovakia's proactive approach to AI governance. It specifically addresses the need for a revised conformity assessment framework that can accommodate the unique characteristics and risks associated with AI systems, particularly those classified as 'high-risk' under the EU AI Act. This includes defining the roles and responsibilities of economic operators, notified bodies, and market surveillance authorities in the context of AI. The Act is expected to have a profound impact on developers, deployers, and users of AI systems across various sectors in Slovakia, compelling them to re-evaluate their compliance strategies and operational practices to meet the newly stipulated requirements for safety, transparency, and accountability in the AI lifecycle.
Definitions
This Act, in its capacity as an adaptation measure for the EU AI Act, implicitly or explicitly incorporates a range of definitions critical for understanding AI regulation. Central to this framework is the definition of an "AI system," which generally refers to a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. The classification of AI systems into different risk categories is also paramount, with "high-risk AI systems" being a key focus. These are AI systems that pose significant risks to the health, safety, or fundamental rights of individuals, as detailed in Annex III of the EU AI Act, encompassing areas like critical infrastructure, education, employment, law enforcement, and democratic processes. The amendment to the Conformity Assessment Act means that terms related to "conformity assessment" itself are redefined or clarified in the context of AI. This refers to the process of demonstrating whether specific requirements relating to an AI system have been fulfilled, typically involving procedures like internal control, quality management systems, or assessment by a third-party notified body.
Furthermore, the Act's framework relies on definitions of various "economic operators" involved in the AI value chain, including providers (developers or manufacturers of AI systems), deployers (those using AI systems in a professional context), importers, and distributors. Each of these roles carries specific obligations under the EU AI Act, which are then integrated into Slovak law through this amendment. "Notified bodies" are another crucial concept; these are independent third-party organizations designated by national authorities to carry out conformity assessment tasks for high-risk AI systems before they are placed on the market or put into service. The Act also addresses "market surveillance authorities," which are responsible for ensuring that AI systems available on the market comply with the legal requirements and do not endanger public health, safety, or other public interests. These definitions collectively form the linguistic and conceptual backbone for the effective implementation and enforcement of AI regulations within Slovakia, ensuring a common understanding and application of the rules across all stakeholders.
Governance and Institutional Framework
The governance and institutional framework established or reinforced by Act No. 318/2025 Coll. is designed to ensure effective oversight and enforcement of AI regulations in Slovakia, in line with the EU AI Act. While Slovakia has not opted for a standalone AI regulator, the responsibilities for AI oversight are distributed among existing authorities whose mandates have been expanded to incorporate the EU AI Act's requirements. A key player in this framework is the Ministry of Investment, Regional Development and Informatization (MIRRI), which, according to the draft Slovak AI Act (a related but distinct legislative initiative), is expected to bear primary responsibility for AI regulation. However, the Conformity Assessment Act amendment specifically empowers existing market surveillance authorities, such as the Slovak Trade Inspection, to act as lead authorities for consumer products and services, enabling them to order corrective measures, withdrawals, and bans of non-compliant AI systems. This distributed model leverages existing expertise and infrastructure, aiming for efficiency in a rapidly evolving technological landscape.
Beyond these general authorities, the Act also necessitates the designation of "notifying authorities" and "market surveillance authorities" specifically for AI systems, as mandated by the EU AI Act. The notifying authority is responsible for assessing, designating, and monitoring the notified bodies that perform conformity assessments for high-risk AI systems. This ensures that the technical expertise and independence of these assessment bodies are maintained to the highest standards. Furthermore, sector-specific authorities will play a crucial role in regulating AI within their respective domains, such as the National Security Authority for cybersecurity aspects of AI, or authorities responsible for health and medical devices where AI is integrated. This multi-layered approach to governance aims to provide comprehensive coverage, addressing both horizontal AI risks and sector-specific challenges, thereby creating a robust system for the supervision and enforcement of AI regulations across the Slovak Republic.
Key Focus Areas
Act No. 318/2025 Coll. primarily focuses on integrating the risk-based approach of the EU AI Act into Slovakia's conformity assessment framework. This means that AI systems are categorized based on their potential to cause harm, with corresponding levels of regulatory scrutiny. The highest level of scrutiny is reserved for "high-risk AI systems," which are subject to stringent requirements before they can be placed on the market or put into service. These requirements, now embedded in Slovak law through this amendment, include robust risk management systems, high-quality training, validation, and testing data, detailed technical documentation, transparent information provision to users, human oversight, a high level of accuracy, robustness, and cybersecurity. The amendment ensures that the existing national conformity assessment procedures are updated to specifically address these technical and ethical requirements for AI, requiring providers to demonstrate compliance through rigorous testing and documentation. This focus ensures that AI systems with the greatest potential for societal impact are developed and deployed responsibly, minimizing risks to health, safety, and fundamental rights.
Another key focus area is the establishment of clear obligations for all economic operators involved in the AI value chain. Providers of high-risk AI systems, for instance, are now legally bound to implement quality management systems, conduct pre-market conformity assessments, and ensure ongoing post-market monitoring. Deployers of high-risk AI systems also bear significant responsibilities, including ensuring human oversight, monitoring the system's operation, and conducting fundamental rights impact assessments where appropriate. The amendment to the Conformity Assessment Act provides the legal basis for these obligations within the Slovak national context, specifying how these duties are to be fulfilled and what documentation is required. Furthermore, the Act emphasizes the importance of transparency and explainability in AI systems, particularly for those interacting with individuals or making decisions that affect them. This includes requirements for clear labeling when AI is used (e.g., chatbots) and ensuring that AI outputs are understandable and explainable to the average user, thereby fostering public trust and accountability in AI technologies.
Implementation Framework
The implementation framework for Act No. 318/2025 Coll. is designed to translate the principles and requirements of the EU AI Act into actionable national procedures, primarily through the existing conformity assessment mechanisms. This involves a significant overhaul of how products, now including AI systems, are evaluated for compliance before they enter the market. For high-risk AI systems, the Act mandates a pre-market conformity assessment, which can involve either an internal control procedure carried out by the provider or a third-party assessment by a notified body. The choice of procedure depends on the specific characteristics and risks of the AI system, as well as whether harmonized standards or common specifications are available. The amendment outlines the administrative steps and technical requirements for these assessments, ensuring that providers submit comprehensive technical documentation, demonstrate the effectiveness of their risk management systems, and provide evidence of data governance and human oversight measures. The goal is to establish a clear and predictable pathway for AI systems to achieve compliance, thereby facilitating their responsible deployment across Slovakia and the wider EU market.
Beyond the initial conformity assessment, the implementation framework also places a strong emphasis on post-market surveillance and monitoring. This involves ongoing checks by market surveillance authorities to ensure that AI systems continue to comply with the requirements throughout their lifecycle. Providers are required to implement robust post-market monitoring systems, collect data on the performance and incidents of their AI systems, and take corrective actions when necessary. The Act empowers national authorities to conduct audits, request additional information, and impose measures such as withdrawal or recall of non-compliant AI systems. Furthermore, the framework supports the establishment of regulatory sandboxes, which are controlled environments where innovative AI systems can be tested under regulatory supervision before full market deployment. These sandboxes are crucial for fostering innovation while ensuring that emerging AI technologies meet safety and ethical standards. By integrating these pre-market and post-market mechanisms, Slovakia aims to create a dynamic and responsive regulatory environment that can adapt to the rapid advancements in AI technology.
Monitoring and Evaluation
The monitoring and evaluation mechanisms embedded within Act No. 318/2025 Coll. are critical for ensuring the continuous effectiveness and adaptation of AI regulation in Slovakia. These mechanisms are designed to track the performance of AI systems on the market, assess their ongoing compliance with legal requirements, and identify any unforeseen risks or impacts. Market surveillance authorities, such as the Slovak Trade Inspection, are tasked with proactive monitoring, conducting checks, and investigating complaints related to AI systems. This includes verifying the accuracy of technical documentation, auditing quality management systems, and, where necessary, carrying out tests on deployed AI systems. The Act also requires providers of high-risk AI systems to implement their own post-market monitoring systems, collecting data on incidents, malfunctions, and any serious adverse events. This continuous feedback loop is essential for identifying emerging risks, assessing the practical application of the regulatory framework, and informing future policy adjustments.
Furthermore, the evaluation aspect of the Act involves a broader assessment of the regulatory framework's impact on innovation, economic development, and the protection of fundamental rights. This includes gathering data on the number of AI systems placed on the market, the types of high-risk AI systems, the incidents reported, and the effectiveness of enforcement actions. The insights gained from this monitoring and evaluation process will be crucial for informing national policy decisions and contributing to the broader European review of the EU AI Act. Regular reporting and data sharing with the European Commission and other Member States will ensure a harmonized approach to AI governance across the EU. This iterative process of monitoring and evaluation underscores a commitment to adaptive regulation, acknowledging that AI technology is rapidly evolving and that the regulatory framework must be flexible enough to address new challenges while continuing to promote responsible innovation. The Act, therefore, lays the groundwork for a dynamic regulatory ecosystem that learns and evolves alongside AI itself.
Penalties, Liability, and Appeals
Act No. 318/2025 Coll., in its role of adapting Slovak law to the EU AI Act, incorporates a robust system of penalties for non-compliance, designed to deter violations and ensure the integrity of the AI regulatory framework. The EU AI Act itself stipulates substantial fines, which are mirrored in the national legislation. For instance, violations of the requirements for high-risk AI systems can lead to fines of up to €30 million or 6% of the company's global annual turnover, whichever is higher. Breaches of transparency requirements can incur penalties of up to €20 million or 4% of global annual turnover, while providing false information to regulators may result in fines of up to €10 million or 2% of global annual turnover. These significant penalties underscore the seriousness with which non-compliance is treated and aim to incentivize economic operators to prioritize safety, ethics, and transparency in their AI development and deployment. The Act outlines the national authorities responsible for imposing these fines, ensuring that enforcement actions are consistent and proportionate.
Regarding liability, the Act, by amending the Conformity Assessment Act, implicitly strengthens the legal basis for holding providers and deployers of AI systems accountable for damages caused by their non-compliant systems. While the EU AI Act includes provisions on liability, national laws like this amendment provide the procedural and substantive mechanisms for individuals to seek redress. This could involve claims for damages resulting from defective AI systems or from breaches of fundamental rights due to AI deployment. The Act is expected to clarify the burden of proof in such cases, potentially shifting it to the provider in certain circumstances, especially for high-risk AI systems where transparency is lacking. Furthermore, the Act establishes clear avenues for appeals against decisions made by supervisory authorities, such as the imposition of fines or orders for corrective measures. This ensures due process and allows affected parties to challenge regulatory decisions, promoting fairness and accountability within the enforcement regime. The combination of stringent penalties, clarified liability pathways, and accessible appeal mechanisms creates a comprehensive framework for ensuring responsible AI development and deployment in Slovakia.
Relationship to Other Instruments
Act No. 318/2025 Coll. does not operate in a vacuum but is intricately linked with a broader ecosystem of national and European legal instruments. Its fundamental relationship is with the directly applicable Regulation (EU) 2024/1689, the EU AI Act, which it is designed to adapt and implement within the Slovak legal order. This means that while the EU AI Act sets the overarching harmonized rules, the Slovak amendment provides the necessary national institutional and procedural framework for its effective application, particularly concerning conformity assessment, market surveillance, and enforcement. Beyond the EU AI Act, this amendment interacts with Slovakia's existing Act No. 56/2018 Coll. on product conformity assessment, which it specifically modifies to include AI systems. This ensures a consistent approach to product safety and market surveillance, extending established principles to the novel domain of artificial intelligence.
Furthermore, the Act has important connections to other sectoral legislation. For instance, it complements Act No. 69/2018 Coll. on cybersecurity by ensuring that AI systems, especially those supporting critical infrastructure or services, adhere to robust cybersecurity standards and incident reporting duties. It also interacts with data protection laws, such as the GDPR and its national implementing legislation, by emphasizing the need for high-quality data governance in AI systems, particularly for high-risk applications that process personal data. The amendment also considers the Act on Information Technologies in Public Administration, which sets standards for the procurement and operation of AI systems used by public authorities, including requirements for human oversight, transparency, and the protection of citizens' rights. This web of interconnected legislation ensures that AI governance in Slovakia is comprehensive, addressing technological, ethical, and societal dimensions within a coherent legal framework, and preventing regulatory fragmentation across different domains.
International Alignment
The primary purpose and effect of Act No. 318/2025 Coll. is to ensure Slovakia's robust international alignment with the European Union's pioneering regulatory framework for artificial intelligence. By amending its national Conformity Assessment Act, Slovakia is directly integrating the provisions of the EU AI Act, thereby contributing to a harmonized approach to AI governance across all EU Member States. This alignment is critical for maintaining the integrity of the EU's single market, ensuring that AI systems can be developed, placed on the market, and used across borders without encountering disparate national regulatory hurdles. The Act ensures that Slovak businesses and public authorities operate under the same high standards for AI safety, ethics, and transparency as their counterparts in other EU countries, fostering a level playing field and promoting fair competition.
This commitment to international alignment extends beyond mere compliance; it positions Slovakia as an active participant in shaping the global discourse on AI regulation. By adopting and implementing the EU AI Act, Slovakia contributes to the EU's ambition to set a global standard for responsible AI development, influencing international norms and best practices. The Act's provisions, particularly those related to conformity assessment and market surveillance, are designed to be interoperable with the broader EU framework, facilitating cooperation between national authorities and the European AI Office. This ensures that enforcement actions and regulatory oversight are coordinated across the Union, enhancing the effectiveness of the entire system. Ultimately, Slovakia's alignment through this Act reinforces its commitment to European values, including the protection of fundamental rights, democratic principles, and the rule of law, in the context of advanced technological development, demonstrating a forward-looking approach to digital governance on the international stage.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| EU AI Act published in Official Journal | 2024-07-12 | Regulation (EU) 2024/1689 entered into force on the twentieth day following its publication. |
| Entry into force of Act No. 318/2025 Coll. | 2026-01-01 | Amends Act No. 56/2018 Coll. on product conformity assessment, with effect from this date. |
| Prohibition of unacceptable AI practices (EU AI Act) | 2024-08-02 | Certain AI systems posing clear threats to fundamental rights are banned. |
| Rules on high-risk AI systems (EU AI Act) | 2026-08-02 | Most obligations for high-risk AI systems become applicable. |
| General purpose AI rules (EU AI Act) | 2026-08-02 | Obligations for general-purpose AI models become applicable. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Identify AI Systems | Categorize all AI systems in use or under development according to the EU AI Act's risk classification (unacceptable, high, limited, minimal risk). |
| High-Risk AI Conformity Assessment | For high-risk AI systems, implement a robust quality management system and conduct a pre-market conformity assessment, either internally or via a notified body, as required by the Act. |
| Technical Documentation | Prepare and maintain comprehensive technical documentation for all high-risk AI systems, demonstrating compliance with the Act's requirements for data governance, human oversight, accuracy, robustness, and cybersecurity. |
| Risk Management System | Establish and continuously update a risk management system throughout the AI system's lifecycle, identifying, analyzing, and mitigating potential risks. |
| Human Oversight | Ensure that high-risk AI systems are designed and deployed with effective human oversight mechanisms, allowing for human intervention and control. |
| Transparency and Information | Provide clear, understandable information to users of AI systems, especially when interacting with AI (e.g., chatbots), and ensure explainability of AI outputs where relevant. |
| Post-Market Monitoring | Implement a system for post-market monitoring of high-risk AI systems, collecting data on performance, incidents, and taking corrective actions as necessary. |
| Fundamental Rights Impact Assessment | For high-risk AI systems, particularly those used by public authorities, conduct a fundamental rights impact assessment to identify and mitigate potential adverse impacts. |
| Data Governance | Ensure high-quality training, validation, and testing data for AI systems, adhering to data governance principles and relevant data protection laws. |
| Notified Body Engagement | If required for high-risk AI systems, engage with a designated notified body for third-party conformity assessment and certification. |
| Compliance with Penalties | Familiarize with the penalty regime for non-compliance and ensure all measures are in place to avoid violations, including internal audits and training. |
Sources and References
| Source | Type |
|---|---|
| scpc.sk: 2025 Legislation (On 1.1. 2026, Act No. 318/2025 Coll., amending and supplementing Act No. 56/2018 Coll.) | government |
| scpc.sk: News (Act No. 318/2025 Coll., amending and supplementing Act No. 56/2018 Coll.) | government |
| Ministerstvo investícií, regionálneho rozvoja a informatizácie SR: Návrh zákona o organizácii štátnej správy v oblasti umelej inteligencie (Proposal for a law on the organization of public administration in the field of artificial intelligence) | government |
| Ministerstvo investícií, regionálneho rozvoja a informatizácie SR: Zodpovedná digitalizácia: MIRRI predstavilo návrhy zákonov o umelej inteligencii a správe údajov (Responsible digitalization: MIRRI presented draft laws on artificial intelligence and data management) (August 01 2025) | government |
Slovakia's Act No. 318/2025 Coll. integrates the European Union's Artificial Intelligence Act into national law, establishing new compliance requirements for anyone developing, importing, distributing, or using AI systems in Slovakia. This pivotal legislation affects a broad range of "economic operators," including AI system providers (developers or manufacturers), deployers (those using AI professionally), importers, and distributors. Its primary focus is on "high-risk AI systems"—those posing significant threats to health, safety, or fundamental rights, such as AI used in critical infrastructure, employment, or law enforcement.
Key obligations under this law include: - **Rigorous Conformity Assessment:** High-risk AI systems must undergo a thorough pre-market assessment to prove they meet strict safety, ethical, and transparency standards. This involves either internal checks by the provider or evaluation by an independent third-party "notified body." - **Risk Management and Data Quality:** Providers must implement robust risk management systems throughout an AI system's lifecycle and ensure the use of high-quality data for training, validation, and testing. - **Transparency and Human Oversight:** High-risk AI systems need clear information for users, effective human oversight, and outputs that are understandable and explainable. - **Prohibition of Unacceptable AI:** The underlying EU AI Act, now integrated into Slovak law, also outright bans certain AI practices deemed unacceptable, such as social scoring or real-time remote biometric identification in public spaces by law enforcement.
While the Slovak Act itself takes effect on January 1, 2026, a crucial point for businesses is the staggered applicability of the EU AI Act's provisions. For example, the ban on unacceptable AI practices already applies since August 2, 2024, and most rules for high-risk and general-purpose AI systems will apply from August 2, 2026. This means companies must track the EU AI Act's specific timelines, not just the Slovak law's effective date, to ensure continuous compliance.
Non-compliance carries substantial financial penalties. Violations related to high-risk AI systems can result in fines up to €30 million or 6% of a company's global annual turnover, whichever is higher. Breaches of transparency rules could mean fines up to €20 million or 4% of global turnover, and providing false information to regulators may incur fines up to €10 million or 2% of turnover. Market surveillance authorities also have the power to order corrective measures, product withdrawals, or outright bans of non-compliant AI systems.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Slovakia AI Conformity Assessment Act. Not legal advice — verify against the official text before relying on it.
- #1CriticalImplementation Timeline⏰ Aug 2, 2024
Applies to: All economic operators involved with AI systems
“Prohibition of unacceptable AI practices (EU AI Act) - Certain AI systems posing clear threats to fundamental rights are banned.”
- #2CriticalKey Focus Areas⏰ Before placing on market
Applies to: Providers of high-risk AI systems
“The highest level of scrutiny is reserved for 'high-risk AI systems,' which are subject to stringent requirements before they can be placed on the market or put into service.”
- #3CriticalKey Focus Areas⏰ Before placing on market
Applies to: Providers of high-risk AI systems
“These requirements, now embedded in Slovak law... include... detailed technical documentation...”
- #4CriticalKey Focus Areas⏰ Before placing on market
Applies to: Providers of high-risk AI systems
“These requirements... include robust risk management systems, high-quality training, validation, and testing data...”
- #5CriticalKey Focus Areas⏰ Before placing on market
Applies to: Providers of AI systems
“These requirements... include robust... high-quality training, validation, and testing data...”
- #6CriticalImplementation Framework⏰ Before placing on market
Applies to: Providers of high-risk AI systems
“For high-risk AI systems, the Act mandates a pre-market conformity assessment, which can involve... a third-party assessment by a notified body.”
- #7CriticalKey Focus Areas⏰ Before placing on market or deployment
Applies to: Providers and deployers of high-risk AI systems
“These requirements... include... human oversight, a high level of accuracy, robustness, and cybersecurity.”
- #8CriticalKey Focus Areas⏰ Before placing on market or deployment
Applies to: Providers and deployers of AI systems
“The Act emphasizes the importance of transparency and explainability in AI systems, particularly for those interacting with individuals...”
- #9CriticalImplementation Framework⏰ Ongoing, after placing on market
Applies to: Providers of high-risk AI systems
“Providers are required to implement robust post-market monitoring systems, collect data on the performance and incidents of their AI systems, and take corrective actions when necessary.”
- #10CriticalPenalties, Liability, and Appeals⏰ Jan 1, 2026
Applies to: All economic operators involved with AI systems
“The EU AI Act itself stipulates substantial fines, which are mirrored in the national legislation.”
- #11ImportantKey Focus Areas⏰ Before placing on market or deployment
Applies to: Providers and deployers of AI systems
“AI systems are categorized based on their potential to cause harm, with corresponding levels of regulatory scrutiny.”
- #12ImportantKey Focus Areas⏰ Before deployment
Applies to: Deployers of high-risk AI systems
“Deployers of high-risk AI systems also bear significant responsibilities, including... conducting fundamental rights impact assessments where appropriate.”
Related Regulations
Draft Act on the Organization of Public Administration in the Field of Artificial Intelligence (government bill submitted to interdepartmental comment procedure)
Slovakia88% similar
Draft Act on the Organization of State Administration in the Field of Artificial Intelligence (national bill to establish oversight, notifying authority and regulatory sandbox)
Slovakia88% similar
Slovakia AI Regulation Overview
Slovakia86% similar
Zakon o izvajanju Uredbe (EU) o določitvi harmoniziranih pravil o umetni inteligenci / Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (national implementing act)
Slovenia86% similar
Government Plenipotentiary for Artificial Intelligence (appointment and statute establishing the office/splnomocnenec vlády SR pre umelú inteligenciu)
Slovakia86% similar
© Regulations.AI — created on 12-Jun-2026 using Gemini 2.5 Flash