Slovakia - AI Governance Bill (LP/2025/401)

Draft Act on the Organization of Public Administration in the Field of Artificial Intelligence (government bill submitted to interdepartmental comment procedure)

Návrh zákona o organizácii verejnej správy v oblasti umelej inteligencie (vládny návrh predložený do medzirezortného pripomienkového konania)

Slovakia

RAI-SK-NA-DOPAFXX-2025
Draft(Being written or scoped)
BillGovernance and OversightConformity Assessment and RegistrationMarket Surveillance
Export PDF

A national draft law submitted by the Ministry of Investments, Regional Development and Informatization (MIRRI) to organise state administration and market surveillance for AI, implement key governance provisions of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), designate national and sectoral supervisory bodies, and set obligations, compliance mechanisms and sanctions for operators of high‑risk AI systems. The draft began interdepartmental comments in July–August 2025 and proposes national entry‑into‑force measures from 1 January 2026.

Overview

The Draft Act on the Organization of Public Administration in the Field of Artificial Intelligence (material LP/2025/401) was prepared and presented by the Ministry of Investments, Regional Development and Informatization (MIRRI) of the Slovak Republic and placed into interdepartmental (medzirezortné) comment procedure in July–August 2025. The draft aims to implement the governance and market‑surveillance-related obligations that Member States must fulfil under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and to create a national institutional framework for oversight, notification and cooperation among sectoral authorities. The ministry published a press announcement about the interdepartmental consultation and the proposed approach; the ministry identifies itself as the general market surveillance authority and single contact point required by the AI Act. For the official ministry announcement see MIRRI press release (29 July 2025). The EU Act that the draft seeks to implement is available at Regulation (EU) 2024/1689 (Artificial Intelligence Act).

Definitions

The draft defines key terms to align with the EU AI Act and domestic law: "AI system", "high‑risk AI system", "operator", "provider", "deployers", "placing on the market", "putting into service", "market surveillance", "single contact point", "notifying authority", "post‑market monitoring", "technical documentation", "register of AI systems", and "regulatory sandbox". The definitions reference the EU Act's wording where relevant but also include specific public‑administration adaptations (e.g., definitions for AI systems used by public authorities and those deployed in administrative decision‑making). The bill also cross‑references domestic terms from the Data Protection Act and cybersecurity legislation to avoid overlaps and to harmonise obligations for personal data processing and security measures.

Governance and Institutional Framework

The draft establishes a two‑tier national architecture: (1) a general national market surveillance authority designated as the single contact point and coordinator for cross‑border and EU Board cooperation (the ministry designates the Ministry of Investments, Regional Development and Informatization (MIRRI) for that role); and (2) sectoral supervisory authorities responsible for domain‑specific oversight and enforcement (e.g., the Office for Personal Data Protection for data protection issues, the National Security Authority (NBÚ) for cybersecurity and national security concerns, the Slovak Trade Inspection (SOI) for consumer and product market supervision, and the State Institute for Drug Control (ŠÚKL) for medical/healthcare AI oversight). The bill sets out competency rules (who notifies whom, who inspects, who may impose measures), mandates institutional cooperation and mutual assistance, and establishes a notifying authority for communications with the European AI Office and the European Artificial Intelligence Board. The draft also provides MIRRI with responsibilities beyond market surveillance: policy coordination, publication of annual reports on AI usage in the public sector, and maintenance of national registries and sandbox programmes. See the ministry announcement for the governance outline: MIRRI (29 July 2025).

Key Focus Areas

The bill concentrates on a set of core areas required to operationalise EU obligations and to manage AI‑related risks in the public domain: (a) designation of competent authorities and sectoral supervisors; (b) establishment of a single contact point and notifying authority consistent with Article 70 et seq. of the EU AI Act; (c) obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting); (d) transparency and human oversight safeguards for AI use in administrative decision‑making and public services; (e) data quality and privacy protections to be applied when AI systems process personal data (to be enforced in conjunction with the national data protection authority and GDPR rules); (f) cybersecurity and model‑security requirements (mandatory security measures and incident reporting harmonised with national cybersecurity law); (g) market surveillance, conformity assessment and registration procedures (including powers to request documentation, order corrective measures, and suspend systems); (h) enforcement, administrative sanctions and channels for appeals and judicial review; and (i) innovation facilitation through national regulatory sandboxes and standard‑setting guidance. Many of these elements explicitly derive from the EU Act's governance and high‑risk system obligations; see the EU text for the originating provisions: Regulation (EU) 2024/1689.

Implementation Framework

The draft provides procedural rules for implementation: designation orders for sectoral supervisory authorities; the creation and operation of a national AI systems register (for certain categories of high‑risk systems); template technical documentation and guidance; obligations to conduct conformity assessments (internal or third‑party) where required; notification procedures for new AI systems put on the Slovak market; rules for participation in national regulatory sandboxes (eligibility, oversight, reporting and exit conditions); and provisions to ensure interoperability of national registries and reporting channels with EU systems. The bill foresees delegated acts or ministerial implementing regulations to set detailed administrative procedures and technical standards (to allow faster updates as technology evolves). MIRRI is empowered to issue secondary implementing guidance and to coordinate standardisation work with sectoral authorities and standards bodies.

Monitoring and Evaluation

The draft mandates continuous monitoring and an annual national report to the government and parliament on the state of AI deployment in public administration, high‑risk system incidents, compliance actions and sandbox outcomes. It sets KPIs for the general market surveillance authority (e.g., number of inspections, response times, corrective actions) and requires a risk‑based approach to inspections and audits. The bill also requires the establishment of feedback loops with civil society, academic experts and industry, and explicitly instructs sectoral authorities to coordinate data collection to enable aggregated national indicators (while respecting confidentiality and data protection rules). Third‑party evaluation and reviews are foreseen for the sandbox programmes and for the effectiveness of oversight powers, with scheduled internal reviews to align with the EU timelines for AI Act evaluation.

Penalties, Liability, and Appeals

The draft grants enforcement powers to sectoral authorities and MIRRI: investigative powers, orders to suspend placing on the market or use, corrective measures and administrative fines. It foresees fines scaled by turnover and gravity of the offence for breaches of obligations related to high‑risk AI systems (documentation omissions, failure to notify, failure to implement post‑market monitoring, failure to cooperate with authorities). The act also preserves rights to administrative appeals and judicial review and explicitly provides for coordination with pending EU liability initiatives (the Directive on AI liability when adopted) but does not attempt to fully harmonise civil liability rules; it signals that separate follow‑up legislation on civil liability will be considered. The draft emphasises procedural safeguards for regulated entities and rights of affected persons, including notification obligations where automated decisions significantly affect individuals. See ministerial summary for proposed sanctions and approach to appeals: MIRRI press release.

Relationship to Other Instruments

The bill expressly cross‑references and amends or interacts with several domestic laws: the national Personal Data Protection framework (GDPR implementation and national law), the law on product conformity and market approvals, national cybersecurity legislation (Law on Cybersecurity), the law on IT in public administration, and electronic communications rules. It is designed to avoid substantive duplication with GDPR and existing safety/product rules by allocating sectoral competences and coordinating enforcement actions. The draft also anticipates updates to other statutes where necessary to ensure administrative powers and data‑sharing mechanisms are legally anchored. Commentary and legal analysis published contemporaneously highlight the cross‑sectoral amendments envisaged by the draft; see legal commentary at Právne listy (Sept 2025) and legislative summaries at Verejná správa SR (25 Aug 2025).

International Alignment

The draft frames Slovakia's approach as implementing and aligning with the EU Artificial Intelligence Act and participating in EU governance structures (AI Office, European Artificial Intelligence Board). It highlights the need for cross‑border cooperation, information exchange and interoperability of registries and notification mechanisms. The ministry emphasises that the national law will be regularly updated to reflect EU delegated and implementing acts and international standards, and it signals active cooperation in international fora (EU, OECD, UN) to promote harmonised rules and avoid fragmentation. See the EU AI Act text for the Union obligations and timeline: EU Regulation 2024/1689 and the ministry press release for the Slovak position: MIRRI (29 July 2025).

Implementation Timeline

MilestoneDate
Publication of MIRRI press release announcing interdepartmental comment2025-07-29
Interdepartmental (medzirezortné) comment period (start)2025-08-01
Interdepartmental comment period (end) — reported2025-08-21
Public legislative material publication / registration (LP/2025/401) noted2025-08-25
Proposed national effective date (draft)2026-01-01 (proposed)

Compliance Checklist

Action for Operators/ProvidersNotes
Determine classification of AI system (high‑risk or other)Use EU Act criteria and national guidance
Prepare technical documentation and conformity assessmentMaintain records for inspections
Register systems where requiredUse national register / notify competent authority
Implement data quality, privacy and cybersecurity safeguardsCoordinate with data protection officer and NBÚ
Establish post‑market monitoring and incident reportingDefine monitoring KPIs and reporting channels
Engage with sandbox if innovatingApply to national regulatory experimental environment

Sources and References

SourceType
MIRRI press release: Slovakia starts interdepartmental comment on AI law (29 July 2025)Primary Source
Regulation (EU) 2024/1689 (Artificial Intelligence Act) (13 June 2024)Primary Source
Verejná správa SR: summary of the draft (25 Aug 2025)Secondary Source
Právne listy: legal commentary on AI law implementation (Sept 2025)Secondary Source
Plain English

This draft Slovak law establishes a national framework for Artificial Intelligence (AI) governance and market surveillance, primarily impacting operators and providers of high-risk AI systems in Slovakia.

The bill, currently undergoing interdepartmental comments, aims to implement the EU Artificial Intelligence Act, setting up a national system for oversight and enforcement. It applies to anyone operating or providing AI systems, with a particular focus on "high-risk AI systems" as defined by the EU Act. This includes both private companies and public authorities using AI.

For those dealing with high-risk AI systems, key obligations include conducting conformity assessments to ensure systems meet safety and ethical standards, maintaining detailed technical documentation and records, and registering certain high-risk AI systems with a national register. Furthermore, operators must implement robust post-market monitoring, report any serious incidents, and ensure high standards for data quality, privacy, and cybersecurity in their AI systems.

The Ministry of Investments, Regional Development and Informatization (MIRRI) will act as the main market surveillance authority and single contact point. However, enforcement will be shared with several sectoral bodies, such as the Office for Personal Data Protection for privacy issues, the National Security Authority for cybersecurity, and the Slovak Trade Inspection for consumer protection. This multi-agency approach means businesses might interact with several different regulators depending on their AI system's application.

Breaches of these obligations can lead to significant administrative fines, scaled according to the company's turnover and the severity of the offense. Authorities will have powers to investigate, demand corrective measures, and even suspend the use or market placement of non-compliant systems. A practical pitfall for businesses is navigating this fragmented enforcement landscape, where different aspects of an AI system might fall under the purview of multiple national authorities, requiring careful coordination. The law is currently proposed to take effect on January 1, 2026.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 13 marked complete

Plain-English obligations under Slovakia - AI Governance Bill (LP/2025/401). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market or putting into service

    Applies to: Providers and operators of high-risk AI systems.

    obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)
  2. #2CriticalBefore placing on market

    Applies to: Providers of AI systems.

    obligations to conduct conformity assessments (internal or third‑party) where required
  3. #3CriticalBefore placing on market or putting into service

    Applies to: Providers and operators of high-risk AI systems.

    obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)
  4. #4CriticalBefore placing on market

    Applies to: Providers of certain high-risk AI systems.

    the creation and operation of a national AI systems register (for certain categories of high‑risk systems)
  5. #5CriticalBefore placing on market

    Applies to: Providers and operators of AI systems.

    notification procedures for new AI systems put on the Slovak market
  6. #6CriticalBefore placing on market or putting into service, and ongoing

    Applies to: Providers and operators of high-risk AI systems.

    obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)
  7. #7CriticalOngoing, upon incident occurrence

    Applies to: Providers and operators of high-risk AI systems.

    obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)
  8. #8CriticalBefore processing personal data

    Applies to: Operators of AI systems processing personal data.

    data quality and privacy protections to be applied when AI systems process personal data
  9. #9CriticalBefore putting into service

    Applies to: Operators of AI systems.

    cybersecurity and model‑security requirements (mandatory security measures and incident reporting harmonised with national cybersecurity law)
  10. #10CriticalOngoing, upon incident occurrence

    Applies to: Operators of AI systems.

    cybersecurity and model‑security requirements (mandatory security measures and incident reporting harmonised with national cybersecurity law)
  11. #11ImportantBefore putting into service

    Applies to: Deployers of AI systems in administrative decision-making and public services.

    transparency and human oversight safeguards for AI use in administrative decision‑making and public services
  12. #12ImportantBefore making such decisions

    Applies to: Deployers of AI systems making automated decisions.

    notification obligations where automated decisions significantly affect individuals
  13. #13Recommended

    Applies to: Innovators of AI systems.

    Engage with sandbox if innovating

© Regulations.AI — created on 13-Jun-2026