Action Plan of the National Artificial Intelligence Strategy 2030 (NAIS) for 2025 (Implementační plán programu Digitální Česko / Akční plán NAIS 2025)
in_forcepolicy · Effective Jan 1, 2025
CZ regulates AI through Action Plan of the National Artificial Intelligence Strategy 2030 (NAIS) for 2025 (Implementační plán programu Digitální Česko / Akční plán NAIS 2025).
Action Plan of the National Artificial Intelligence Strategy 2030 (NAIS) for 2025 (Implementační plán programu Digitální Česko / Akční plán NAIS 2025) · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
The Czech Republic has adopted a forward-looking and comprehensive approach to artificial intelligence (AI) regulation, firmly rooted in its commitment to fostering innovation while ensuring ethical, secure, and trustworthy AI deployment. The nation's regulatory philosophy is primarily shaped by its foundational National Artificial Intelligence Strategy (NAIS) of 2019, which laid the groundwork for a strategic vision aimed at positioning the Czech Republic as a leading European hub for AI development and application. This initial strategy outlined key priority areas, including research and development, education, ethical and legal aspects, and international cooperation, setting the stage for a coordinated national effort. The subsequent evolution of this strategy, particularly through the adoption of the updated NAIS 2030 and its annual implementation packages like the 2025 Action Plan, demonstrates a clear progression from high-level policy to concrete, actionable measures. The current regulatory landscape is characterized by a blend of strategic policy documents, binding legislation, and forthcoming adaptive laws designed to integrate the overarching European Union AI Act. This multi-faceted approach reflects a mature understanding of AI's complex challenges and opportunities, emphasizing a risk-based framework that seeks to balance technological advancement with societal protection. The Czech Republic's efforts are deeply intertwined with EU-level initiatives, ensuring harmonization and interoperability with broader European digital policies. The ongoing development of the Draft Adaptation Act to implement the EU AI Act underscores the country's commitment to establishing a robust and enforceable regulatory environment, complete with designated national competent authorities and a focus on practical implementation mechanisms such as regulatory sandboxes and conformity assessment.
Regulatory approach
The Czech Republic's regulatory approach to AI is distinctly horizontal, primarily driven by the imperative to transpose and implement the European Union's Artificial Intelligence Act. This means that, rather than developing entirely new, sector-specific AI laws from scratch, the national framework will largely adopt the comprehensive, risk-based classification and obligations set forth in the EU AI Act. The Draft Adaptation Act, currently in preparation, exemplifies this horizontal strategy by focusing on establishing the necessary national institutional and procedural mechanisms for the EU Regulation to function effectively within the Czech legal system. It aims to designate competent authorities for market surveillance, conformity assessment, and the operation of regulatory sandboxes, ensuring a consistent application of AI rules across various sectors while allowing for some national discretion on enforcement tools and minor offence categorization. This horizontal, risk-based approach is complemented by a mix of binding legal instruments and soft law. While the EU AI Act, once fully implemented, will impose binding obligations on providers and deployers of AI systems, the Czech Republic's National AI Strategy (NAIS) and its annual Action Plans serve as crucial soft law instruments. These policy documents provide strategic direction, allocate funding, and establish compliance expectations (e.g., documentation, auditability, safety testing) that, while not directly punitive, link funding eligibility and project support to demonstrable adherence to ethical and safety guidelines. The Act on Cybersecurity, No. 264/2025 Sb., further contributes a binding, horizontal layer by establishing mandatory cybersecurity requirements for a broad range of essential and important services, many of which increasingly rely on AI systems. This dual approach of binding regulation for critical aspects (like cybersecurity and high-risk AI) and guiding policy for broader ecosystem development allows for flexibility and responsiveness to rapid technological changes, while maintaining a clear commitment to a trust-oriented AI environment. The governance of AI in the Czech Republic is characterized by a multi-level, hybrid model involving several key ministries and specialized agencies, with the Ministry of Industry and Trade (MPO) serving as the central coordinator. MPO is designated as the principal coordinator (gestor) for the implementation of both the National Artificial Intelligence Strategy (NAIS) and the forthcoming EU AI Act. It chairs the Working Group for AI under the Digital Economy & Society framework, facilitating inter-ministerial coordination and stakeholder engagement. The Committee for Artificial Intelligence, also convened by MPO, acts as a crucial advisory and coordination forum, bringing together representatives from government, supervisory authorities, research, industry, and civil society to prepare policy proposals and monitor progress on the national AI agenda. Enforcement and oversight responsibilities are distributed among existing national regulators, reflecting a pragmatic approach to leveraging established expertise. The National Cyber and Information Security Office (NÚKIB) is the central administrative body for cybersecurity, responsible for enforcing the Act on Cybersecurity, including registration, oversight, incident evaluation, and imposing administrative sanctions. For the implementation of the EU AI Act, the Draft Adaptation Act designates specific roles: the Úřad pro technickou normalizaci, metrologii a státní zkušebnictví (ÚNMZ) as the notifying authority for conformity assessment bodies; the Český telekomunikační úřad (ČTÚ) as the primary market surveillance authority and public contact point; the Úřad pro ochranu osobních údajů (ÚOOÚ) for market surveillance in areas related to privacy and data protection; and the Česká národní banka (ČNB) for supervising AI in financial institutions. Additionally, the Česká agentura pro standardizaci (ČAS) is tasked with establishing and operating a national regulatory sandbox, and the Public Defender of Rights (Ombudsman) will play a role in monitoring human-rights related concerns.
Enforcement & penalties
The penalty and enforcement mechanisms in the Czech Republic's AI regulatory framework are evolving, with a clear distinction between existing cybersecurity legislation and the forthcoming implementation of the EU AI Act. Under the Act on Cybersecurity, No. 264/2025 Sb., the National Cyber and Information Security Office (NÚKIB) possesses enhanced powers to issue security measures, orders of compliance, and impose administrative sanctions and fines for breaches. These fines can reach statutory maximums, including amounts up to tens of millions CZK, and in extreme cases, turnover-based measures under related enforcement frameworks. The Act also allows for coercive fines and measures targeting management in serious instances of non-compliance, underscoring a robust enforcement regime for critical cybersecurity obligations. For AI systems falling under the scope of the EU AI Act, the Draft Adaptation Act to Implement the EU Artificial Intelligence Act will align national administrative offence regimes with the EU's enforcement architecture. While the EU AI Act itself defines the overarching penalty regimes, the national adaptation allows for limited discretion on sanctions and remedial measures, including provisions for admonitions and potentially lowered fines for less serious breaches, particularly to support SMEs. The draft also proposes a five-year statutory limitation period for certain administrative offences and emphasizes procedural measures that prioritize remedial steps and informal corrective action for minor infringements. Furthermore, the Action Plan of the National Artificial Intelligence Strategy 2030 for 2025, while primarily a funding and implementation framework, establishes compliance expectations that can lead to conditional funding, project suspension, or reallocation for non-demonstrable compliance and risk mitigation.
Data protection
As a member state of the European Union, the Czech Republic is directly subject to the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), which forms the cornerstone of its data protection framework. This means that any AI system developed, deployed, or used within the Czech Republic must adhere to the stringent requirements of the GDPR, including principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability. The National Artificial Intelligence Strategy (NAIS) and its subsequent Action Plans explicitly integrate data protection and privacy-by-design principles as cross-cutting activities, emphasizing their critical role in fostering trustworthy AI. This commitment extends to mandating risk assessments for high-impact AI systems that include considerations for data protection and privacy impacts. The regulatory oversight for data protection within the context of AI is primarily vested in the Úřad pro ochranu osobních údajů (ÚOOÚ), the Czech Office for Personal Data Protection. Under the forthcoming Draft Adaptation Act to Implement the EU Artificial Intelligence Act, ÚOOÚ is specifically designated to exercise market surveillance in areas implicating privacy and data protection, ensuring that AI systems comply with both the AI Act's requirements and existing GDPR obligations. This dual role underscores the interconnectedness of AI regulation and data protection, ensuring that the deployment of AI technologies does not compromise fundamental rights related to personal data. While there are no specific data localization requirements unique to AI beyond those potentially implied by GDPR's international data transfer rules, the emphasis on robust data governance and cybersecurity measures within the NAIS and the Act on Cybersecurity further strengthens the overall data protection framework for AI systems.
Sector-specific rules
While the Czech Republic's overarching AI regulatory framework, particularly through the upcoming EU AI Act adaptation, adopts a largely horizontal approach, there are clear indications of sector-specific considerations embedded within its governance and implementation strategies. The National Artificial Intelligence Strategy (NAIS) and its Action Plan for 2025 identify several priority domains for AI application, including healthcare, mobility, defence, manufacturing, and public services. The Action Plan specifically includes measures to fund applied AI pilots in these priority sectors and to create guidance materials and ethics/legal toolkits to support public-sector procurement and deployment, suggesting a tailored approach to addressing sector-specific challenges and opportunities. Furthermore, the Draft Adaptation Act to Implement the EU Artificial Intelligence Act designates existing sectoral regulators to perform market surveillance within their respective domains. For instance, the Česká národní banka (ČNB) is tasked with supervising AI in financial institutions, while the Úřad pro ochranu osobních údajů (ÚOOÚ) will oversee AI systems impacting privacy and data protection. The Český telekomunikační úřad (ČTÚ) is designated as the primary market surveillance authority, indicating its role in AI systems within the electronic communications sector. This distribution of enforcement responsibilities ensures that sector-specific expertise is leveraged for effective oversight. Additionally, the Act on Cybersecurity, No. 264/2025 Sb., applies broadly across critical sectors such as energy, transport, health, financial services, digital infrastructure, water, food, manufacturing, and public administration, imposing mandatory cybersecurity requirements that are highly relevant to AI systems deployed in these sensitive areas. This layered approach combines horizontal AI regulation with sector-specific oversight and cybersecurity mandates to address the unique risks and requirements of different industries.
International alignment
The Czech Republic's AI regulatory strategy is profoundly shaped by its strong commitment to international alignment, particularly with the European Union's comprehensive framework. The National Artificial Intelligence Strategy (NAIS) of 2019 and its subsequent updates, including the NAIS 2030 Action Plan for 2025, explicitly frame national regulatory and governance work to align with ongoing EU-level initiatives. This includes operational alignment with the EU's AI Act and complementary Digital Europe programmes, demonstrating a clear intent to harmonize national efforts with the broader European digital single market and regulatory landscape. The country actively participates in EU discussions and initiatives, ensuring that its national policies reflect and contribute to the development of a coherent European approach to AI. The most significant manifestation of this international alignment is the Draft Adaptation Act to Implement the EU Artificial Intelligence Act. This proposed national law is explicitly designed to operationalize the EU AI Act within the Czech legal and institutional environment, rather than creating a parallel, independent regulatory regime. It adopts the EU Regulation’s substantive obligations and risk-based classifications, focusing instead on designating national competent authorities, establishing procedural mechanisms, and aligning national administrative offence regimes. Beyond the EU, the Czech Republic's approach to AI also reflects broader international principles, such as those promoted by the OECD, particularly concerning trustworthy AI, human-centered design, and ethical considerations. The Act on Cybersecurity, No. 264/2025 Sb., further reinforces this international alignment by transposing key elements of the European Union’s NIS2 Directive, ensuring a harmonized approach to cybersecurity across critical sectors, which is essential for the secure deployment of AI systems.
What's next
The Czech Republic's AI regulatory landscape is poised for significant developments, with the Draft Adaptation Act to Implement the EU Artificial Intelligence Act representing the most critical piece of pending legislation. This draft bill, currently undergoing inter-ministerial consultation, is expected to be submitted to parliament and is targeted for entry into force around 2026. Its approval will solidify the national institutional framework for the EU AI Act, officially designating market surveillance authorities, establishing the national regulatory sandbox, and setting out procedural and language requirements for conformity documentation. The ongoing work of the Committee for Artificial Intelligence, convened by MPO, will continue to guide these implementation efforts, including advising on institutional roles, capacity building, and promoting regulatory sandboxes. Beyond the direct implementation of the EU AI Act, future developments will also include the annual updating and revision of the Action Plan of the National Artificial Intelligence Strategy 2030. This annual cycle ensures that the national strategy remains responsive to rapid technological advancements and evolving regulatory landscapes, with the next annual review and update anticipated by March 2026. Furthermore, the Act on Cybersecurity, which came into force in November 2025, will be supported by ongoing implementing decrees and NÚKIB guidance, providing further clarity and operational details for organizations subject to its expanded cybersecurity requirements. These continuous efforts underscore the Czech Republic's commitment to building a dynamic and adaptive regulatory environment for AI, balancing innovation with robust governance and security.
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
act · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
central_coordinator
Principal coordinator (gestor) for NAIS and EU AI Act implementation; chairs the Working Group for AI.
central_coordinator
Central administrative body for cybersecurity, including protection of classified information and cryptographic protection.
enforcement
Notifying authority for conformity assessment bodies under the EU AI Act; responsible for technical standardization and metrology.
central_coordinator
Jul 9, 2025 · news
Czech government bans DeepSeek usage in public administration
Open source →policy · Effective Jan 1, 2019
strategy · Effective Jan 1, 2030
Primary market surveillance authority and central public contact point for the EU AI Act.
data_protection
Market surveillance in areas implicating privacy and data protection under the EU AI Act; oversees GDPR compliance.
enforcement
Supervises AI in entities under its remit (financial institutions) as a market surveillance authority for the EU AI Act.
advisory
Establishes and operates the national regulatory sandbox for safe testing of AI systems.
enforcement
Protects persons against the conduct of authorities; has a human-rights monitoring function for AI Act enforcement and sandbox governance.