Slovakia - AI Governance Bill (LP/2025/401)
Draft Act on the Organization of Public Administration in the Field of Artificial Intelligence (government bill submitted to interdepartmental comment procedure)
Návrh zákona o organizácii verejnej správy v oblasti umelej inteligencie (vládny návrh predložený do medzirezortného pripomienkového konania)
Slovakia
RAI-SK-NA-DOPAFXX-2025A national draft law submitted by the Ministry of Investments, Regional Development and Informatization (MIRRI) to organise state administration and market surveillance for AI, implement key governance provisions of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), designate national and sectoral supervisory bodies, and set obligations, compliance mechanisms and sanctions for operators of high‑risk AI systems. The draft began interdepartmental comments in July–August 2025 and proposes national entry‑into‑force measures from 1 January 2026.
Summary
Read full text ↗Plain English
Overview
The Draft Act on the Organization of Public Administration in the Field of Artificial Intelligence (material LP/2025/401) was prepared and presented by the Ministry of Investments, Regional Development and Informatization (MIRRI) of the Slovak Republic and placed into interdepartmental (medzirezortné) comment procedure in July–August 2025. The draft aims to implement the governance and market‑surveillance-related obligations that Member States must fulfil under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and to create a national institutional framework for oversight, notification and cooperation among sectoral authorities. The ministry published a press announcement about the interdepartmental consultation and the proposed approach; the ministry identifies itself as the general market surveillance authority and single contact point required by the AI Act. For the official ministry announcement see MIRRI press release (29 July 2025). The EU Act that the draft seeks to implement is available at Regulation (EU) 2024/1689 (Artificial Intelligence Act).
Definitions
The draft defines key terms to align with the EU AI Act and domestic law: "AI system", "high‑risk AI system", "operator", "provider", "deployers", "placing on the market", "putting into service", "market surveillance", "single contact point", "notifying authority", "post‑market monitoring", "technical documentation", "register of AI systems", and "regulatory sandbox". The definitions reference the EU Act's wording where relevant but also include specific public‑administration adaptations (e.g., definitions for AI systems used by public authorities and those deployed in administrative decision‑making). The bill also cross‑references domestic terms from the Data Protection Act and cybersecurity legislation to avoid overlaps and to harmonise obligations for personal data processing and security measures.
Governance and Institutional Framework
The draft establishes a two‑tier national architecture: (1) a general national market surveillance authority designated as the single contact point and coordinator for cross‑border and EU Board cooperation (the ministry designates the Ministry of Investments, Regional Development and Informatization (MIRRI) for that role); and (2) sectoral supervisory authorities responsible for domain‑specific oversight and enforcement (e.g., the Office for Personal Data Protection for data protection issues, the National Security Authority (NBÚ) for cybersecurity and national security concerns, the Slovak Trade Inspection (SOI) for consumer and product market supervision, and the State Institute for Drug Control (ŠÚKL) for medical/healthcare AI oversight). The bill sets out competency rules (who notifies whom, who inspects, who may impose measures), mandates institutional cooperation and mutual assistance, and establishes a notifying authority for communications with the European AI Office and the European Artificial Intelligence Board. The draft also provides MIRRI with responsibilities beyond market surveillance: policy coordination, publication of annual reports on AI usage in the public sector, and maintenance of national registries and sandbox programmes. See the ministry announcement for the governance outline: MIRRI (29 July 2025).
Key Focus Areas
The bill concentrates on a set of core areas required to operationalise EU obligations and to manage AI‑related risks in the public domain: (a) designation of competent authorities and sectoral supervisors; (b) establishment of a single contact point and notifying authority consistent with Article 70 et seq. of the EU AI Act; (c) obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting); (d) transparency and human oversight safeguards for AI use in administrative decision‑making and public services; (e) data quality and privacy protections to be applied when AI systems process personal data (to be enforced in conjunction with the national data protection authority and GDPR rules); (f) cybersecurity and model‑security requirements (mandatory security measures and incident reporting harmonised with national cybersecurity law); (g) market surveillance, conformity assessment and registration procedures (including powers to request documentation, order corrective measures, and suspend systems); (h) enforcement, administrative sanctions and channels for appeals and judicial review; and (i) innovation facilitation through national regulatory sandboxes and standard‑setting guidance. Many of these elements explicitly derive from the EU Act's governance and high‑risk system obligations; see the EU text for the originating provisions: Regulation (EU) 2024/1689.
Implementation Framework
The draft provides procedural rules for implementation: designation orders for sectoral supervisory authorities; the creation and operation of a national AI systems register (for certain categories of high‑risk systems); template technical documentation and guidance; obligations to conduct conformity assessments (internal or third‑party) where required; notification procedures for new AI systems put on the Slovak market; rules for participation in national regulatory sandboxes (eligibility, oversight, reporting and exit conditions); and provisions to ensure interoperability of national registries and reporting channels with EU systems. The bill foresees delegated acts or ministerial implementing regulations to set detailed administrative procedures and technical standards (to allow faster updates as technology evolves). MIRRI is empowered to issue secondary implementing guidance and to coordinate standardisation work with sectoral authorities and standards bodies.
Monitoring and Evaluation
The draft mandates continuous monitoring and an annual national report to the government and parliament on the state of AI deployment in public administration, high‑risk system incidents, compliance actions and sandbox outcomes. It sets KPIs for the general market surveillance authority (e.g., number of inspections, response times, corrective actions) and requires a risk‑based approach to inspections and audits. The bill also requires the establishment of feedback loops with civil society, academic experts and industry, and explicitly instructs sectoral authorities to coordinate data collection to enable aggregated national indicators (while respecting confidentiality and data protection rules). Third‑party evaluation and reviews are foreseen for the sandbox programmes and for the effectiveness of oversight powers, with scheduled internal reviews to align with the EU timelines for AI Act evaluation.
Penalties, Liability, and Appeals
The draft grants enforcement powers to sectoral authorities and MIRRI: investigative powers, orders to suspend placing on the market or use, corrective measures and administrative fines. It foresees fines scaled by turnover and gravity of the offence for breaches of obligations related to high‑risk AI systems (documentation omissions, failure to notify, failure to implement post‑market monitoring, failure to cooperate with authorities). The act also preserves rights to administrative appeals and judicial review and explicitly provides for coordination with pending EU liability initiatives (the Directive on AI liability when adopted) but does not attempt to fully harmonise civil liability rules; it signals that separate follow‑up legislation on civil liability will be considered. The draft emphasises procedural safeguards for regulated entities and rights of affected persons, including notification obligations where automated decisions significantly affect individuals. See ministerial summary for proposed sanctions and approach to appeals: MIRRI press release.
Relationship to Other Instruments
The bill expressly cross‑references and amends or interacts with several domestic laws: the national Personal Data Protection framework (GDPR implementation and national law), the law on product conformity and market approvals, national cybersecurity legislation (Law on Cybersecurity), the law on IT in public administration, and electronic communications rules. It is designed to avoid substantive duplication with GDPR and existing safety/product rules by allocating sectoral competences and coordinating enforcement actions. The draft also anticipates updates to other statutes where necessary to ensure administrative powers and data‑sharing mechanisms are legally anchored. Commentary and legal analysis published contemporaneously highlight the cross‑sectoral amendments envisaged by the draft; see legal commentary at Právne listy (Sept 2025) and legislative summaries at Verejná správa SR (25 Aug 2025).
International Alignment
The draft frames Slovakia's approach as implementing and aligning with the EU Artificial Intelligence Act and participating in EU governance structures (AI Office, European Artificial Intelligence Board). It highlights the need for cross‑border cooperation, information exchange and interoperability of registries and notification mechanisms. The ministry emphasises that the national law will be regularly updated to reflect EU delegated and implementing acts and international standards, and it signals active cooperation in international fora (EU, OECD, UN) to promote harmonised rules and avoid fragmentation. See the EU AI Act text for the Union obligations and timeline: EU Regulation 2024/1689 and the ministry press release for the Slovak position: MIRRI (29 July 2025).
Implementation Timeline
| Milestone | Date |
|---|---|
| Publication of MIRRI press release announcing interdepartmental comment | 2025-07-29 |
| Interdepartmental (medzirezortné) comment period (start) | 2025-08-01 |
| Interdepartmental comment period (end) — reported | 2025-08-21 |
| Public legislative material publication / registration (LP/2025/401) noted | 2025-08-25 |
| Proposed national effective date (draft) | 2026-01-01 (proposed) |
Compliance Checklist
| Action for Operators/Providers | Notes |
|---|---|
| Determine classification of AI system (high‑risk or other) | Use EU Act criteria and national guidance |
| Prepare technical documentation and conformity assessment | Maintain records for inspections |
| Register systems where required | Use national register / notify competent authority |
| Implement data quality, privacy and cybersecurity safeguards | Coordinate with data protection officer and NBÚ |
| Establish post‑market monitoring and incident reporting | Define monitoring KPIs and reporting channels |
| Engage with sandbox if innovating | Apply to national regulatory experimental environment |
Sources and References
| Source | Type |
|---|---|
| MIRRI press release: Slovakia starts interdepartmental comment on AI law (29 July 2025) | Primary Source |
| Regulation (EU) 2024/1689 (Artificial Intelligence Act) (13 June 2024) | Primary Source |
| Verejná správa SR: summary of the draft (25 Aug 2025) | Secondary Source |
| Právne listy: legal commentary on AI law implementation (Sept 2025) | Secondary Source |
This draft Slovak law establishes a national framework for Artificial Intelligence (AI) governance and market surveillance, primarily impacting operators and providers of high-risk AI systems in Slovakia.
The bill, currently undergoing interdepartmental comments, aims to implement the EU Artificial Intelligence Act, setting up a national system for oversight and enforcement. It applies to anyone operating or providing AI systems, with a particular focus on "high-risk AI systems" as defined by the EU Act. This includes both private companies and public authorities using AI.
For those dealing with high-risk AI systems, key obligations include conducting conformity assessments to ensure systems meet safety and ethical standards, maintaining detailed technical documentation and records, and registering certain high-risk AI systems with a national register. Furthermore, operators must implement robust post-market monitoring, report any serious incidents, and ensure high standards for data quality, privacy, and cybersecurity in their AI systems.
The Ministry of Investments, Regional Development and Informatization (MIRRI) will act as the main market surveillance authority and single contact point. However, enforcement will be shared with several sectoral bodies, such as the Office for Personal Data Protection for privacy issues, the National Security Authority for cybersecurity, and the Slovak Trade Inspection for consumer protection. This multi-agency approach means businesses might interact with several different regulators depending on their AI system's application.
Breaches of these obligations can lead to significant administrative fines, scaled according to the company's turnover and the severity of the offense. Authorities will have powers to investigate, demand corrective measures, and even suspend the use or market placement of non-compliant systems. A practical pitfall for businesses is navigating this fragmented enforcement landscape, where different aspects of an AI system might fall under the purview of multiple national authorities, requiring careful coordination. The law is currently proposed to take effect on January 1, 2026.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under Slovakia - AI Governance Bill (LP/2025/401). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before placing on market or putting into service
Applies to: Providers and operators of high-risk AI systems.
“obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)”
- #2Critical⏰ Before placing on market
Applies to: Providers of AI systems.
“obligations to conduct conformity assessments (internal or third‑party) where required”
- #3Critical⏰ Before placing on market or putting into service
Applies to: Providers and operators of high-risk AI systems.
“obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)”
- #4Critical⏰ Before placing on market
Applies to: Providers of certain high-risk AI systems.
“the creation and operation of a national AI systems register (for certain categories of high‑risk systems)”
- #5Critical⏰ Before placing on market
Applies to: Providers and operators of AI systems.
“notification procedures for new AI systems put on the Slovak market”
- #6Critical⏰ Before placing on market or putting into service, and ongoing
Applies to: Providers and operators of high-risk AI systems.
“obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)”
- #7Critical⏰ Ongoing, upon incident occurrence
Applies to: Providers and operators of high-risk AI systems.
“obligations for providers and operators of high‑risk AI systems (conformity, documentation, technical files, post‑market monitoring and incident reporting)”
- #8Critical⏰ Before processing personal data
Applies to: Operators of AI systems processing personal data.
“data quality and privacy protections to be applied when AI systems process personal data”
- #9Critical⏰ Before putting into service
Applies to: Operators of AI systems.
“cybersecurity and model‑security requirements (mandatory security measures and incident reporting harmonised with national cybersecurity law)”
- #10Critical⏰ Ongoing, upon incident occurrence
Applies to: Operators of AI systems.
“cybersecurity and model‑security requirements (mandatory security measures and incident reporting harmonised with national cybersecurity law)”
- #11Important⏰ Before putting into service
Applies to: Deployers of AI systems in administrative decision-making and public services.
“transparency and human oversight safeguards for AI use in administrative decision‑making and public services”
- #12Important⏰ Before making such decisions
Applies to: Deployers of AI systems making automated decisions.
“notification obligations where automated decisions significantly affect individuals”
- #13Recommended
Applies to: Innovators of AI systems.
“Engage with sandbox if innovating”
Related Regulations
Draft Act on the Organization of State Administration in the Field of Artificial Intelligence (national bill to establish oversight, notifying authority and regulatory sandbox)
Slovakia97% similar
Draft Act on the Management of Selected Categories of Public Sector Data (data governance bill supporting AI/data reuse)
Slovakia93% similar
Slovakia AI Regulation Overview
Slovakia92% similar
Government Plenipotentiary for Artificial Intelligence (appointment and statute establishing the office/splnomocnenec vlády SR pre umelú inteligenciu)
Slovakia92% similar
Draft AI Act presented by political party 'Da, Bulgaria' (project bill for an AI law)
Bulgaria92% similar
© Regulations.AI — created on 13-Jun-2026