Malta - AI Regulations (226/2025)

226 of 2025 - Artificial Intelligence Regulations, 2025 (Legal Notice)

Malta

RAI-MT-NA-22AIRXX-2025
Effective: 10 Oct 2025
In Force(In Force)Checked 8 Sep 2026

Malta - AI Regulations (226/2025) is In Force in Malta as of 8 Sep 2026, according to legislation.mt.

RegulationGovernance and OversightConformity Assessment and RegistrationMarket Surveillance
Export PDF

Legal Notice 226 of 2025 establishes Malta's framework for implementing the EU AI Act, setting risk-management and transparency rules for AI providers and deployers. Enforced primarily by the Malta Digital Innovation Authority, the regulation took effect on 10 October 2025 and is in force.

Summary

Legal Notice 226 of 2025 (Artificial Intelligence Regulations, 2025) is a national implementing legal notice published in the Government Gazette of Malta on 10 October 2025. The Legal Notice sets out Malta's institutional and procedural framework for enforcing the EU Artificial Intelligence Act (Regulation (EU) 2024/1689 and related instruments), assigning primary supervisory responsibilities to the Malta Digital Innovation Authority (MDIA) for the majority of AI systems, establishing the MDIA as the national Notifying Authority for conformity assessment bodies, and creating rules for market surveillance, enforcement, and the national AI regulatory sandbox. LN 226 defines roles and cooperative mechanisms between MDIA and other national authorities, including the Malta Information and Data Protection Commissioner (IDPC), the Malta Financial Services Authority (MFSA), and sectoral regulators; LN 227 complements LN 226 by designating the IDPC for a subset of high‑risk systems (those listed in Annex III and otherwise data‑sensitive systems).

The regulation incorporates a risk‑based approach mirroring the EU framework: obligations for providers and deployers of high‑risk AI systems (risk management systems, technical documentation, logs and record keeping, post‑market monitoring, and conformity assessment), transparency and information duties for certain systems (including general-purpose models and tools used for generating content), human oversight requirements, and cybersecurity and data governance measures. LN 226 also establishes the national processes for registration and conformity assessment, including where MDIA will act as the Notifying Authority to recognise conformity assessment bodies and to operate the national AI sandbox. The Legal Notice provides MDIA with enforcement powers including administrative sanctions, daily penalties for ongoing breaches, inspection rights, and coordination powers with other MSAs and EU bodies.

Practically, LN 226 places the following duties on economic operators: conduct and document risk management procedures; maintain technical documentation and logs; carry out or obtain conformity assessments for high‑risk systems; register certain AI systems in national/eu databases when required; implement measures to ensure model and data security; and provide transparency information to users and affected persons. It also sets administrative pathways for authorisations, urgent measures to withdraw or restrict systems, and obligations for incident reporting and recall or correction campaigns in the event of systemic risks. LN 226 is intended to align Malta's national enforcement and market surveillance with the EU AI Act while leveraging national competences (MDIA and IDPC) and coordinating with sectoral regulators for domain‑specific systems (e.g., finance, healthcare). The Legal Notice is accompanied by LN 227 (designation of IDPC) and guidance from MDIA and IDPC for stakeholders to operationalise compliance.

Full article

Read full text ↗

Overview

Legal Notice 226 of 2025 ("Artificial Intelligence Regulations, 2025") is Malta's primary national implementing instrument for the EU Artificial Intelligence Act framework. Published in the Government Gazette on 10 October 2025, LN 226 designates the Malta Digital Innovation Authority (MDIA) as the principal national market surveillance authority and Notifying Authority for the recognition of conformity assessment bodies in relation to AI systems. The Notice establishes national enforcement powers, reporting and registration arrangements, and the national AI regulatory sandbox. LN 226 is intended to complement and operate alongside Legal Notice 227 of 2025, which designates the Information and Data Protection Commissioner (IDPC) for certain data‑sensitive and Annex III high‑risk AI systems. For an official announcement and summary of designations, see the IDPC notice and the MDIA website for guidance materials and tools.

Definitions

LN 226 incorporates key definitions aligned with the EU AI Act (e.g., "AI system", "provider", "operator", "user", "high‑risk AI system", "conformity assessment", "market surveillance authority"). The Legal Notice clarifies national terms where necessary (for example, specifying the MDIA as the "Notifying Authority" and defining "national market surveillance" processes). These definitions are functionally harmonised with Regulation (EU) 2024/1689 to ensure consistent interpretation across Member States while allowing LN 226 to designate specific national bodies and procedural rules for Malta.

Governance and Institutional Framework

Under LN 226, the Malta Digital Innovation Authority (MDIA) is assigned primary supervisory duties including: acting as Malta's default Market Surveillance Authority (MSA) for AI systems not specifically allocated to another authority; serving as the Notifying Authority responsible for recognising conformity assessment bodies; operating the national AI regulatory sandbox; issuing guidance and non‑binding technical standards; and coordinating national enforcement and international cooperation. The Legal Notice requires MDIA to coordinate with the Information and Data Protection Commissioner (IDPC) and sectoral regulators (e.g., the Malta Financial Services Authority) when systems overlap sectoral or data protection competencies. LN 226 establishes formal cooperation and information‑sharing channels, requires memoranda of understanding between agencies where appropriate, and sets out the procedure for referral of cases between MDIA and other competent authorities to ensure clarity of responsibilities and to avoid regulatory gaps or duplication.

Key Focus Areas

LN 226 emphasises a risk‑based supervisory model mirroring the EU approach and focuses on: (1) conformity assessment and registration for high‑risk AI systems; (2) mandatory risk management systems, technical documentation and data governance; (3) transparency obligations (user notices, deepfake labeling, general‑purpose model disclosures where relevant); (4) human oversight and operational limits on automated decision‑making; (5) cybersecurity and model security (including requirements for vulnerability management, patching and secure design); (6) post‑market monitoring and incident reporting duties; and (7) market surveillance and enforcement powers including corrective measures, recalls, and administrative fines. The Notice also addresses novel national mechanisms such as the MDIA‑operated regulatory sandbox to support innovation while safeguarding rights, and processes to coordinate cross‑border enforcement with EU authorities and notified conformity assessment bodies.

Implementation Framework

LN 226 specifies practical steps for implementation: MDIA is tasked with developing secondary guidance and templates (for technical documentation, post‑market monitoring reports, and risk management records); procedures for registration and national importation/distribution oversight; accreditation and notification of conformity assessment bodies (in line with national accreditation rules and EU standards); inspection protocols and sampling methodologies for market surveillance; and formal rules to run the national AI regulatory sandbox with confidentiality and IP safeguards for participants. The Legal Notice mandates that providers and importers maintain technical files and make them available to MDIA and other competent authorities on request, and prescribes timelines for conformity assessment outcomes and corrective actions where non‑conformity is detected.

Monitoring and Evaluation

LN 226 establishes continuous monitoring mechanisms. Providers of high‑risk AI systems must implement post‑market monitoring and report serious incidents or malfunctions to MDIA (and IDPC where personal data or fundamental rights issues arise). MDIA is required to publish periodic enforcement and market‑surveillance reports, to maintain a register of notified conformity assessment bodies, and to evaluate the national sandbox outcomes. The Notice introduces metrics for assessing regulatory impact (compliance rates, incidents reported, corrective actions taken, time to close enforcement files) and foresees stakeholder consultations to refine guidance and harmonise practice with EU and international standards.

Penalties, Liability, and Appeals

LN 226 grants MDIA administrative enforcement powers including inspections, orders to suspend or withdraw non‑compliant systems, and the imposition of administrative fines for breaches. National reporting indicates that MDIA may levy significant sanctions calibrated to severity, including fixed fines and daily penalties for ongoing breaches; secondary reporting on the instrument references national maximums and proportionality principles for penalties. The Legal Notice also preserves existing civil and criminal liability pathways under Maltese law, including rights for affected persons to seek civil remedies. Procedural safeguards include rights of appeal against administrative decisions to independent tribunals and requirements that enforcement decisions be reasoned and proportionate.

Relationship to Other Instruments

LN 226 operates in tandem with the EU AI Act and complementary national measures. It explicitly coordinates with Legal Notice 227 of 2025, which designates the IDPC as the Market Surveillance Authority for certain Annex III high‑risk AI systems and data‑sensitive implementations. LN 226 references the Data Protection Act (Cap. 586), sectoral rules (e.g., MFSA rules for financial services; health sector legislation), and national cybersecurity guidelines. It instructs MDIA to enter into MoUs with sectoral authorities and to rely on established accreditation and conformity infrastructures where possible, thereby ensuring that national implementation is consistent with both sectoral protections and data protection obligations.

International Alignment

LN 226 deliberately aligns Maltese domestic measures with the EU AI Act and international standards to ensure interoperability and facilitate cross‑border trade in AI systems. The Legal Notice tasks MDIA with cooperation in the European AI Board, participation in EU market surveillance networks, and recognition of conformity assessment bodies in line with EU rules. LN 226 also encourages alignment with international standards for AI safety, cybersecurity (e.g., ISO/IEC series), and data governance to reduce fragmentation and to help local providers comply with external market requirements.

Implementation Timeline

DateMilestone
2025-10-10Publication of Legal Notice 226 of 2025 in the Government Gazette (MDIA designated as primary national authority).
2025-10-10Publication of Legal Notice 227 of 2025 (IDPC designated for certain high‑risk AI systems).
Q4 2025MDIA issues initial guidance, templates and starts accepting notifications for the national AI sandbox and conformity assessment bodies.
2026 (rolling)Phased enforcement and registration deadlines in line with EU AI Act timelines; MDIA and IDPC publish joint operational procedures.

Sources and References

SourceType
226 of 2025 - Artificial Intelligence Regulations, 2025 (Government Gazette / ELI)Primary Source

Requirements for a company

What an organisation has to do under Malta - AI Regulations (226/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

7
  • Complete required conformity assessment and registration before placing high-risk AI systems on the market.Providers of high-risk AI systems
  • Implement post-market monitoring and report serious incidents or malfunctions to the MDIA.Providers of high-risk AI systems
  • Maintain technical files and make them available to MDIA and competent authorities on request.Providers and importers of AI systems
  • Establish mandatory risk management systems, technical documentation, and data governance frameworks.Providers of high-risk AI systems
  • Fulfill transparency obligations including user notices, deepfake labeling, and general-purpose model disclosures.Providers and deployers of AI systems
  • Incorporate human oversight controls and operational limits on automated decision-making.Providers and operators of high-risk AI systems
  • +1 more in the table below

Must not do

1
  • Do not place on the market or operate AI systems that have been suspended or ordered withdrawn.Providers and operators of AI systems

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Malta - AI Regulations (226/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers of high-risk AI systemsComplete required conformity assessment and registration before placing high-risk AI systems on the market.
“conformity assessment and registration for high‑risk AI systems”
Before placing on market—Critical
2Providers of high-risk AI systemsImplement post-market monitoring and report serious incidents or malfunctions to the MDIA.
“Providers of high‑risk AI systems must implement post‑market monitoring and report serious incidents or malfunctions to MDIA”
——Critical
3Providers and importers of AI systemsMaintain technical files and make them available to MDIA and competent authorities on request.
“providers and importers maintain technical files and make them available to MDIA and other competent authorities on request”
——Critical
4Providers of high-risk AI systemsEstablish mandatory risk management systems, technical documentation, and data governance frameworks.
“mandatory risk management systems, technical documentation and data governance”
Before placing on market—Critical
5Providers and deployers of AI systemsFulfill transparency obligations including user notices, deepfake labeling, and general-purpose model disclosures.
“transparency obligations (user notices, deepfake labeling, general‑purpose model disclosures where relevant)”
Before placing on market—Critical
6Providers and operators of high-risk AI systemsIncorporate human oversight controls and operational limits on automated decision-making.
“human oversight and operational limits on automated decision‑making”
——Critical
7Providers of AI systemsImplement model cybersecurity measures including vulnerability management, patching protocols, and secure design.
“cybersecurity and model security (including requirements for vulnerability management, patching and secure design)”
——Critical
8Providers and operators of AI systemsDo not place on the market or operate AI systems that have been suspended or ordered withdrawn.
“orders to suspend or withdraw non‑compliant systems, and the imposition of administrative fines for breaches.”
——Critical

© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 8 Sep 2026 using Gemini 3.6 Flash