Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025)
Draft Act on the Organization of State Administration in the Field of Artificial Intelligence
Návrh zákona o organizácii štátnej správy v oblasti umelej inteligencie
Slovakia
RAI-SK-NA-DOSAFXX-2025The draft Slovak Act establishes a national institutional framework to implement the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) at the member-state level. It designates the Ministry of Investments, Regional Development and Informatization (MIRRI) as the central oversight and notifying authority, sets up a national regulatory sandbox, notification/registration duties, conformity and market-surveillance processes, and aligns enforcement and penalties with the AIA while safeguarding data protection and fundamental rights.
Summary
Read full text ↗Plain English
Overview
The Draft Act on the Organization of State Administration in the Field of Artificial Intelligence (the "Draft Act") was published to inter‑ministerial consultation by the Ministry of Investments, Regional Development and Informatization (MIRRI) on 1 August 2025 and is designed to implement the member‑state level arrangements required by the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). The Draft Act establishes a central national authority for AI oversight, specifies a role for sectoral regulators and supervisory bodies, and creates a formal regulatory sandbox for supervised testing and innovation. The Draft Act is explicitly framed to align with the AIA while providing practical national procedures for notification/registration, conformity assessment, market surveillance and sanctions. For the official announcement see MIRRI press release (1 Aug 2025) and the legislative dossier hosted on the national legal portal at Slov-Lex (legislative process entry). The Draft Act aims to balance legal certainty and rights protection with support for innovation through a regulated sandbox and streamlined national notification procedures.
Definitions
The Draft Act imports key definitions from the EU Artificial Intelligence Act, including: 'AI system', 'provider', 'user' (deployer), 'high‑risk AI system', 'conformity assessment', 'notifying authority' and 'regulatory sandbox'. It supplements EU definitions with Slovak‑specific operational terms, such as 'national notifying authority' (the body designated to receive registration and notifications for high‑risk systems placed on the Slovak market), 'sandbox operator' (entities authorised to host or supervise sandbox activities) and 'public‑sector AI deployment' (any AI used in the exercise of public powers or in delivery of public services). The Draft defines reporting periods, the format of technical documentation and the classification process to determine when an AI system must be treated as high‑risk at the national level. Definitions also clarify confidentiality carve‑outs for business secrets while preserving transparency obligations for fundamental‑rights relevant systems.
Governance and Institutional Framework
The Draft Act designates MIRRI as the central coordinating and oversight authority for the national implementation of the AIA and as the principal notifying authority for systems requiring national notification. MIRRI will operate registers for notified high‑risk systems and for approved participants in the national regulatory sandbox. The Act envisages formal cooperation mechanisms (memoranda, joint‑units) between MIRRI, the Office for Personal Data Protection (Úrad na ochranu osobných údajov), the National Security Authority (NBÚ) and sectoral regulators (e.g., health, financial sector regulators). It provides MIRRI with supervisory powers (inspections, information requests, orders to suspend or recall systems) and empowers sectoral bodies to carry out sector‑specific conformity assessments. The institutional design emphasizes single‑window reporting for providers, delegated powers to accredited conformity assessment bodies, and an obligation for authorities to participate in the European AI Office network for cross‑border coordination. See the MIRRI announcement and the legislative file at MIRRI (1 Aug 2025) and the AIA text on EUR‑Lex at EUR‑Lex (AI Act).
Key Focus Areas
The Draft Act concentrates on the following principal areas: (1) designation and powers of the national notifying authority and coordinating body; (2) national procedures for notification and registration of high‑risk AI systems and maintenance of a national register (with confidentiality safeguards); (3) operation of a regulatory sandbox that allows providers to test systems under controlled conditions with data protection and safety measures; (4) conformity assessment and accreditation of testing and auditing bodies; (5) documentation, logging and record‑keeping obligations (including technical documentation, risk assessments, and post‑market monitoring); (6) market surveillance and corrective action mechanisms (inspections, mandatory fixes, withdrawals and public notices); (7) enforcement powers and administrative penalties tailored to the gravity of breaches; (8) mandatory cooperation with the Data Protection Authority for systems processing personal data; (9) cybersecurity and resilience requirements for models and operational systems; and (10) mandatory transparency and user‑information rules (including labeling and disclosure for certain non‑high‑risk systems). The Draft also requires public authorities to complete AI impact assessments before deploying AI in critical public functions and promotes audited procurement of AI in public contracts. This approach preserves proportionality: obligations scale with the risk classification of the system and sectoral sensitivities (e.g., healthcare, finance, law enforcement).
Implementation Framework
Implementation under the Draft Act will be staged. Providers and deployers will be required to notify or register AI systems that meet the national criteria for high risk; conformity assessment procedures will be channelled through accredited conformity assessment bodies; and MIRRI will maintain a sandbox application and approval process with clear entry and exit criteria. The Draft sets out procedural rules for inter‑agency coordination, timelines for authorities to act on notifications and sanctions, and provisions enabling delegated rules or implementing decrees to refine technical and operational detail (to adapt to evolving standards). Public procurement guidance and templates for technical documentation and data‑protection impact assessments are planned to accompany the law to reduce compliance costs. The Draft contemplates digital submission modalities and a single national portal for notifications and sandbox applications to simplify administrative interactions.
Monitoring and Evaluation
The Draft Act requires periodic reporting by MIRRI to the Government and Parliament on the state of AI oversight (including statistics on notifications, inspections, sanctions and sandbox outcomes). It mandates regular reviews of the national register, post‑market monitoring reports from providers, and mechanisms to collect and publish anonymized incident data to inform systemic risk analysis. MIRRI will be required to evaluate the sandbox scheme annually (participant outcomes, data protection incidents, transfers of tested systems to the market) and to recommend legislative amendments when needed. The Act establishes key performance indicators (KPIs) for oversight activity, reporting timelines and public transparency obligations for aggregated enforcement data.
Penalties, Liability, and Appeals
The Draft aligns administrative sanctions with the AIA's risk‑based approach: breaches relating to high‑risk systems, data governance failures, or circumvention of conformity assessments attract higher fines and stronger corrective measures (orders to suspend use, withdrawal, public corrective notices). The Act sets administrative procedures for imposing fines and decisions, and provides an administrative appeals channel (initial internal review by MIRRI or competent authority followed by judicial review in administrative courts). Liability issues remain primarily governed by existing civil and tort law, but the Draft clarifies that administrative enforcement does not preclude civil liability and enables evidence‑sharing between enforcement and civil claim processes. The Draft also includes criminal‑law referral mechanisms where intentional misconduct causes harm or where fraudulent declarations are made to gain certification or entry to the sandbox.
Relationship to Other Instruments
The Draft Act is explicitly framed as a national implementation measure of the EU AI Act and references the Data Governance Act and GDPR where relevant. It cross‑references national laws on cyber security and public procurement, and requires coordination with the national Data Protection Authority on matters involving personal data. The Draft avoids duplicating provisions that fall under EU competence but clarifies domestic procedures (e.g., designation of authorities, sanctioning frameworks and national registers). The legislative dossier on Slov‑Lex (see Slov‑Lex entry) lists interdependencies and proposed implementing decrees to ensure alignment across sectors and to avoid conflicts with sectoral regulation.
International Alignment
The Draft emphasizes Slovakia's intent to align closely with EU mechanisms (including the European AI Office and cross‑border supervisory cooperation structures) and to avoid unnecessary divergence from the AIA. International alignment provisions require MIRRI to enter into cooperation arrangements with EU counterparts, to contribute to EU‑level standardization activities and to ensure that national conformity assessment and accreditation are recognized in cross‑border contexts where the AIA provides for mutual recognition. The Draft explicitly prohibits measures that would fragment the internal market while enabling targeted national rules where the AIA permits Member State discretion (e.g., public‑sector procurement, biometric systems in law enforcement). The Act calls for coordination with OECD and Council of Europe AI policy instruments where relevant.
Implementation Timeline
| Milestone | Date / Timeline |
|---|---|
| Publication to inter‑ministerial consultation (MIRRI) | 2025‑08‑01 |
| EU AIA first provisions enter into application | 2025‑08‑02 (phased application) |
| Designation of national notifying authority | Within statutory period following adoption (expected Q4 2025 / Q1 2026) |
| Operational national sandbox (pilot phase) | Within 6–12 months of designation |
| Full national register of notified high‑risk systems | Operational within 12 months of designation |
Compliance Checklist
| Requirement | Action for Providers/Deployers |
|---|---|
| Notification / registration (high‑risk) | Prepare technical documentation; submit to national register; engage accredited conformity assessor |
| Conformity assessment | Select accredited conformity body; complete assessment before placing on market |
| Documentation & logging | Maintain technical file, logs and post‑market monitoring reports for required retention period |
| Data protection impact assessment | Coordinate with Data Protection Authority; document safeguards and lawful basis for processing |
| Cybersecurity measures | Apply model‑security standards; perform red‑teaming and vulnerability testing |
| Sandbox participation | Apply to MIRRI sandbox portal; agree on testing conditions and reporting |
Sources and References
Slovakia is preparing a new law to implement the European Union Artificial Intelligence Act, establishing a national framework for oversight and regulation that will affect companies and public bodies developing or deploying AI systems in the country.
The draft Act, published in August 2025, designates the Ministry of Investments, Regional Development and Informatization (MIRRI) as the central authority. MIRRI will oversee AI, act as the national notifying body, and manage a new national regulatory sandbox. This law primarily targets providers and users (also called deployers) of AI systems, especially those classified as "high-risk" under the EU AI Act, as well as public authorities using AI.
Key obligations for those in scope include: - **Registering high-risk AI systems**: Companies must notify and register their high-risk AI systems with MIRRI before placing them on the Slovak market. - **Conformity assessment**: These systems must undergo a conformity assessment by accredited bodies to ensure they meet safety and fundamental rights standards. - **Documentation and monitoring**: Providers and users must maintain detailed technical documentation, logs, and conduct post-market monitoring. - **Transparency**: Certain AI systems, even non-high-risk ones, will have transparency and user-information requirements, such as labeling. Public authorities must also complete AI impact assessments before deploying AI in critical public functions.
While the EU AI Act's first provisions began phased application in August 2025, Slovakia's national framework, including the designation of MIRRI and the full national register, is expected to become operational within 6-12 months of the draft law's adoption, likely in late 2025 or early 2026.
Failure to comply can lead to significant administrative penalties, mirroring the EU AI Act's risk-based approach. Breaches related to high-risk systems or data governance failures can result in higher fines, orders to suspend use, or even system withdrawal. There are also administrative appeal channels and potential criminal referrals for intentional misconduct.
A practical innovation in this draft is the national regulatory sandbox. This allows AI providers to test their systems under controlled conditions, with safeguards for data protection and safety, before full market deployment. This offers a unique opportunity for supervised innovation but requires an application and approval process through MIRRI.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Slovakia - AI State Administration Act (RAI-SK-NA-DOSAFXX-2025). Not legal advice — verify against the official text before relying on it.
- #1Critical
Applies to: Providers of high-risk AI systems.
“national procedures for notification and registration of high‑risk AI systems”
- #2Critical⏰ Before placing on market
Applies to: Providers of high-risk AI systems.
“conformity assessment procedures will be channelled through accredited conformity assessment bodies”
- #3Critical
Applies to: Providers and deployers of AI systems.
“documentation, logging and record‑keeping obligations (including technical documentation, risk assessments, and post‑market monitoring)”
- #4Critical
Applies to: Providers and deployers of AI systems.
“cybersecurity and resilience requirements for models and operational systems”
- #5Critical
Applies to: Providers and deployers of AI systems processing personal data.
“mandatory cooperation with the Data Protection Authority for systems processing personal data”
- #6Critical
Applies to: Providers and deployers of AI systems processing personal data.
“document safeguards and lawful basis for processing”
- #7Critical
Applies to: Providers seeking certification or sandbox entry.
“criminal‑law referral mechanisms where intentional misconduct causes harm or where fraudulent declarations are made”
- #8Critical⏰ Before deploying AI
Applies to: Public authorities deploying AI in critical public functions.
“public authorities to complete AI impact assessments before deploying AI in critical public functions”
- #9Important
Applies to: Providers and deployers of AI systems.
“mandatory transparency and user‑information rules (including labeling and disclosure)”
- #10Important
Applies to: Providers wishing to test AI systems in a sandbox.
“operation of a regulatory sandbox that allows providers to test systems under controlled conditions”
- #11Important
Applies to: Public authorities procuring AI.
“promotes audited procurement of AI in public contracts”
- #12Recommended
Applies to: Providers and deployers of AI systems, especially public authorities.
“Public procurement guidance and templates for technical documentation and data‑protection impact assessments are planned”
Related Regulations
Draft Act on the Organization of Public Administration in the Field of Artificial Intelligence (government bill submitted to interdepartmental comment procedure)
Slovakia97% similar
Government Plenipotentiary for Artificial Intelligence (appointment and statute establishing the office/splnomocnenec vlády SR pre umelú inteligenciu)
Slovakia93% similar
Slovakia AI Regulation Overview
Slovakia93% similar
Draft Act on the Management of Selected Categories of Public Sector Data (data governance bill supporting AI/data reuse)
Slovakia93% similar
Draft Adaptation Act to Implement the EU Artificial Intelligence Act (Adaptační návrh zákona o umělé inteligenci) — draft national AI law
Czech Republic92% similar
© Regulations.AI — created on 13-Jun-2026