Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025)

Draft Act on the Organization of State Administration in the Field of Artificial Intelligence

Návrh zákona o organizácii štátnej správy v oblasti umelej inteligencie

Slovakia

RAI-SK-NA-DOSAFXX-2025
Draft(Being written or scoped)
BillGovernance and OversightConformity Assessment and RegistrationSafety, Testing, and Evaluation
Export PDF

The draft Slovak Act establishes a national institutional framework to implement the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) at the member-state level. It designates the Ministry of Investments, Regional Development and Informatization (MIRRI) as the central oversight and notifying authority, sets up a national regulatory sandbox, notification/registration duties, conformity and market-surveillance processes, and aligns enforcement and penalties with the AIA while safeguarding data protection and fundamental rights.

Overview

The Draft Act on the Organization of State Administration in the Field of Artificial Intelligence (the "Draft Act") was published to inter‑ministerial consultation by the Ministry of Investments, Regional Development and Informatization (MIRRI) on 1 August 2025 and is designed to implement the member‑state level arrangements required by the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). The Draft Act establishes a central national authority for AI oversight, specifies a role for sectoral regulators and supervisory bodies, and creates a formal regulatory sandbox for supervised testing and innovation. The Draft Act is explicitly framed to align with the AIA while providing practical national procedures for notification/registration, conformity assessment, market surveillance and sanctions. For the official announcement see MIRRI press release (1 Aug 2025) and the legislative dossier hosted on the national legal portal at Slov-Lex (legislative process entry). The Draft Act aims to balance legal certainty and rights protection with support for innovation through a regulated sandbox and streamlined national notification procedures.

Definitions

The Draft Act imports key definitions from the EU Artificial Intelligence Act, including: 'AI system', 'provider', 'user' (deployer), 'high‑risk AI system', 'conformity assessment', 'notifying authority' and 'regulatory sandbox'. It supplements EU definitions with Slovak‑specific operational terms, such as 'national notifying authority' (the body designated to receive registration and notifications for high‑risk systems placed on the Slovak market), 'sandbox operator' (entities authorised to host or supervise sandbox activities) and 'public‑sector AI deployment' (any AI used in the exercise of public powers or in delivery of public services). The Draft defines reporting periods, the format of technical documentation and the classification process to determine when an AI system must be treated as high‑risk at the national level. Definitions also clarify confidentiality carve‑outs for business secrets while preserving transparency obligations for fundamental‑rights relevant systems.

Governance and Institutional Framework

The Draft Act designates MIRRI as the central coordinating and oversight authority for the national implementation of the AIA and as the principal notifying authority for systems requiring national notification. MIRRI will operate registers for notified high‑risk systems and for approved participants in the national regulatory sandbox. The Act envisages formal cooperation mechanisms (memoranda, joint‑units) between MIRRI, the Office for Personal Data Protection (Úrad na ochranu osobných údajov), the National Security Authority (NBÚ) and sectoral regulators (e.g., health, financial sector regulators). It provides MIRRI with supervisory powers (inspections, information requests, orders to suspend or recall systems) and empowers sectoral bodies to carry out sector‑specific conformity assessments. The institutional design emphasizes single‑window reporting for providers, delegated powers to accredited conformity assessment bodies, and an obligation for authorities to participate in the European AI Office network for cross‑border coordination. See the MIRRI announcement and the legislative file at MIRRI (1 Aug 2025) and the AIA text on EUR‑Lex at EUR‑Lex (AI Act).

Key Focus Areas

The Draft Act concentrates on the following principal areas: (1) designation and powers of the national notifying authority and coordinating body; (2) national procedures for notification and registration of high‑risk AI systems and maintenance of a national register (with confidentiality safeguards); (3) operation of a regulatory sandbox that allows providers to test systems under controlled conditions with data protection and safety measures; (4) conformity assessment and accreditation of testing and auditing bodies; (5) documentation, logging and record‑keeping obligations (including technical documentation, risk assessments, and post‑market monitoring); (6) market surveillance and corrective action mechanisms (inspections, mandatory fixes, withdrawals and public notices); (7) enforcement powers and administrative penalties tailored to the gravity of breaches; (8) mandatory cooperation with the Data Protection Authority for systems processing personal data; (9) cybersecurity and resilience requirements for models and operational systems; and (10) mandatory transparency and user‑information rules (including labeling and disclosure for certain non‑high‑risk systems). The Draft also requires public authorities to complete AI impact assessments before deploying AI in critical public functions and promotes audited procurement of AI in public contracts. This approach preserves proportionality: obligations scale with the risk classification of the system and sectoral sensitivities (e.g., healthcare, finance, law enforcement).

Implementation Framework

Implementation under the Draft Act will be staged. Providers and deployers will be required to notify or register AI systems that meet the national criteria for high risk; conformity assessment procedures will be channelled through accredited conformity assessment bodies; and MIRRI will maintain a sandbox application and approval process with clear entry and exit criteria. The Draft sets out procedural rules for inter‑agency coordination, timelines for authorities to act on notifications and sanctions, and provisions enabling delegated rules or implementing decrees to refine technical and operational detail (to adapt to evolving standards). Public procurement guidance and templates for technical documentation and data‑protection impact assessments are planned to accompany the law to reduce compliance costs. The Draft contemplates digital submission modalities and a single national portal for notifications and sandbox applications to simplify administrative interactions.

Monitoring and Evaluation

The Draft Act requires periodic reporting by MIRRI to the Government and Parliament on the state of AI oversight (including statistics on notifications, inspections, sanctions and sandbox outcomes). It mandates regular reviews of the national register, post‑market monitoring reports from providers, and mechanisms to collect and publish anonymized incident data to inform systemic risk analysis. MIRRI will be required to evaluate the sandbox scheme annually (participant outcomes, data protection incidents, transfers of tested systems to the market) and to recommend legislative amendments when needed. The Act establishes key performance indicators (KPIs) for oversight activity, reporting timelines and public transparency obligations for aggregated enforcement data.

Penalties, Liability, and Appeals

The Draft aligns administrative sanctions with the AIA's risk‑based approach: breaches relating to high‑risk systems, data governance failures, or circumvention of conformity assessments attract higher fines and stronger corrective measures (orders to suspend use, withdrawal, public corrective notices). The Act sets administrative procedures for imposing fines and decisions, and provides an administrative appeals channel (initial internal review by MIRRI or competent authority followed by judicial review in administrative courts). Liability issues remain primarily governed by existing civil and tort law, but the Draft clarifies that administrative enforcement does not preclude civil liability and enables evidence‑sharing between enforcement and civil claim processes. The Draft also includes criminal‑law referral mechanisms where intentional misconduct causes harm or where fraudulent declarations are made to gain certification or entry to the sandbox.

Relationship to Other Instruments

The Draft Act is explicitly framed as a national implementation measure of the EU AI Act and references the Data Governance Act and GDPR where relevant. It cross‑references national laws on cyber security and public procurement, and requires coordination with the national Data Protection Authority on matters involving personal data. The Draft avoids duplicating provisions that fall under EU competence but clarifies domestic procedures (e.g., designation of authorities, sanctioning frameworks and national registers). The legislative dossier on Slov‑Lex (see Slov‑Lex entry) lists interdependencies and proposed implementing decrees to ensure alignment across sectors and to avoid conflicts with sectoral regulation.

International Alignment

The Draft emphasizes Slovakia's intent to align closely with EU mechanisms (including the European AI Office and cross‑border supervisory cooperation structures) and to avoid unnecessary divergence from the AIA. International alignment provisions require MIRRI to enter into cooperation arrangements with EU counterparts, to contribute to EU‑level standardization activities and to ensure that national conformity assessment and accreditation are recognized in cross‑border contexts where the AIA provides for mutual recognition. The Draft explicitly prohibits measures that would fragment the internal market while enabling targeted national rules where the AIA permits Member State discretion (e.g., public‑sector procurement, biometric systems in law enforcement). The Act calls for coordination with OECD and Council of Europe AI policy instruments where relevant.

Implementation Timeline

MilestoneDate / Timeline
Publication to inter‑ministerial consultation (MIRRI)2025‑08‑01
EU AIA first provisions enter into application2025‑08‑02 (phased application)
Designation of national notifying authorityWithin statutory period following adoption (expected Q4 2025 / Q1 2026)
Operational national sandbox (pilot phase)Within 6–12 months of designation
Full national register of notified high‑risk systemsOperational within 12 months of designation

Compliance Checklist

RequirementAction for Providers/Deployers
Notification / registration (high‑risk)Prepare technical documentation; submit to national register; engage accredited conformity assessor
Conformity assessmentSelect accredited conformity body; complete assessment before placing on market
Documentation & loggingMaintain technical file, logs and post‑market monitoring reports for required retention period
Data protection impact assessmentCoordinate with Data Protection Authority; document safeguards and lawful basis for processing
Cybersecurity measuresApply model‑security standards; perform red‑teaming and vulnerability testing
Sandbox participationApply to MIRRI sandbox portal; agree on testing conditions and reporting

Sources and References

SourceType
MIRRI – press release: Responsible digitalisation, MIRRI presented draft laws on AI and data governance (1 Aug 2025)Primary Source
Slov‑Lex – legislative process entry for the draft AI law (LP/2025/401)Primary Source
EUR‑Lex – Regulation (EU) 2024/1689 (Artificial Intelligence Act)Primary Source
Plain English

Slovakia is preparing a new law to implement the European Union Artificial Intelligence Act, establishing a national framework for oversight and regulation that will affect companies and public bodies developing or deploying AI systems in the country.

The draft Act, published in August 2025, designates the Ministry of Investments, Regional Development and Informatization (MIRRI) as the central authority. MIRRI will oversee AI, act as the national notifying body, and manage a new national regulatory sandbox. This law primarily targets providers and users (also called deployers) of AI systems, especially those classified as "high-risk" under the EU AI Act, as well as public authorities using AI.

Key obligations for those in scope include: - **Registering high-risk AI systems**: Companies must notify and register their high-risk AI systems with MIRRI before placing them on the Slovak market. - **Conformity assessment**: These systems must undergo a conformity assessment by accredited bodies to ensure they meet safety and fundamental rights standards. - **Documentation and monitoring**: Providers and users must maintain detailed technical documentation, logs, and conduct post-market monitoring. - **Transparency**: Certain AI systems, even non-high-risk ones, will have transparency and user-information requirements, such as labeling. Public authorities must also complete AI impact assessments before deploying AI in critical public functions.

While the EU AI Act's first provisions began phased application in August 2025, Slovakia's national framework, including the designation of MIRRI and the full national register, is expected to become operational within 6-12 months of the draft law's adoption, likely in late 2025 or early 2026.

Failure to comply can lead to significant administrative penalties, mirroring the EU AI Act's risk-based approach. Breaches related to high-risk systems or data governance failures can result in higher fines, orders to suspend use, or even system withdrawal. There are also administrative appeal channels and potential criminal referrals for intentional misconduct.

A practical innovation in this draft is the national regulatory sandbox. This allows AI providers to test their systems under controlled conditions, with safeguards for data protection and safety, before full market deployment. This offers a unique opportunity for supervised innovation but requires an application and approval process through MIRRI.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025). Not legal advice — verify against the official text before relying on it.

  1. #1Critical

    Applies to: Providers of high-risk AI systems.

    national procedures for notification and registration of high‑risk AI systems
  2. #2CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    conformity assessment procedures will be channelled through accredited conformity assessment bodies
  3. #3Critical

    Applies to: Providers and deployers of AI systems.

    documentation, logging and record‑keeping obligations (including technical documentation, risk assessments, and post‑market monitoring)
  4. #4Critical

    Applies to: Providers and deployers of AI systems.

    cybersecurity and resilience requirements for models and operational systems
  5. #5Critical

    Applies to: Providers and deployers of AI systems processing personal data.

    mandatory cooperation with the Data Protection Authority for systems processing personal data
  6. #6Critical

    Applies to: Providers and deployers of AI systems processing personal data.

    document safeguards and lawful basis for processing
  7. #7Critical

    Applies to: Providers seeking certification or sandbox entry.

    criminal‑law referral mechanisms where intentional misconduct causes harm or where fraudulent declarations are made
  8. #8CriticalBefore deploying AI

    Applies to: Public authorities deploying AI in critical public functions.

    public authorities to complete AI impact assessments before deploying AI in critical public functions
  9. #9Important

    Applies to: Providers and deployers of AI systems.

    mandatory transparency and user‑information rules (including labeling and disclosure)
  10. #10Important

    Applies to: Providers wishing to test AI systems in a sandbox.

    operation of a regulatory sandbox that allows providers to test systems under controlled conditions
  11. #11Important

    Applies to: Public authorities procuring AI.

    promotes audited procurement of AI in public contracts
  12. #12Recommended

    Applies to: Providers and deployers of AI systems, especially public authorities.

    Public procurement guidance and templates for technical documentation and data‑protection impact assessments are planned

© Regulations.AI — created on 13-Jun-2026