act · Effective Jan 1, 2025
HU regulates AI through Government Decree 344/2025 on the implementation of the Act executing the EU AI Regulation.
Government Decree 344/2025 on the implementation of the Act executing the EU AI Regulation · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Hungary’s approach to artificial intelligence (AI) regulation has evolved from a policy-driven framework to a comprehensive, legally binding regime integrated with European Union standards. As of early 2026, the regulatory landscape is defined by the domestic implementation of the EU AI Act (Regulation (EU) 2024/1689), which was operationalized through Act LXXV of 2025. This legislative shift marks Hungary's transition into a mature regulatory phase where AI systems are governed by a risk-based hierarchy, ensuring that high-risk applications are subject to strict compliance and conformity assessments while prohibited practices are banned to protect fundamental rights. The government views AI not merely as a technical challenge but as a cornerstone of national economic strategy, aiming to leverage the technology to boost GDP and public sector efficiency. Historically, Hungary was among the first in the region to adopt a national strategy in 2020, but the 2025 updates reflect a more granular focus on enforcement and industrial application. The current framework is designed to provide legal certainty for developers while maintaining high safety standards for citizens, positioning Hungary as a stable hub for AI development within the Single Market.
Regulatory approach
Hungary employs a horizontal regulatory approach that is primarily risk-based, mirroring the architecture of the EU AI Act. This means that regulations apply across all sectors, but the intensity of oversight depends on the potential harm an AI system could cause. Under Act LXXV of 2025, AI systems are categorized into four levels: unacceptable risk (prohibited), high risk (subject to strict compliance and conformity assessment), limited risk (subject to transparency obligations), and minimal risk. This horizontal framework is supplemented by sectoral rules, particularly in finance and healthcare, where existing regulators like the Hungarian National Bank (MNB) integrate AI-specific oversight into their traditional mandates. The regulatory environment is a mix of binding 'hard law' and programmatic 'soft law.' While Act LXXV of 2025 and Government Decree 344/2025 provide the mandatory legal requirements and penalty structures, the National AI Strategy and various Government Resolutions provide the policy guidance and strategic direction. This hybrid approach allows the government to be prescriptive regarding safety and fundamental rights while remaining flexible in promoting research, development, and the adoption of AI in small and medium-sized enterprises (SMEs). The use of regulatory sandboxes, as mandated by the implementation acts, further illustrates a commitment to 'proportional oversight,' allowing for controlled experimentation before full-scale market entry. The governance of AI in Hungary is centralized but involves several key agencies with distinct mandates. The Minister responsible for Enterprise Development, situated within the Ministry of National Economy, serves as the primary AI Market Surveillance Authority and the national single point of contact. This office is responsible for investigating non-compliance, ordering corrective measures, and overseeing the national regulatory sandbox. The National Accreditation Authority (NAH) acts as the 'notifying authority,' tasked with the accreditation and supervision of third-party conformity-assessment bodies (notified bodies) that certify high-risk AI systems before they are placed on the market. Supporting these executive bodies is the Hungarian Artificial Intelligence Council, an advisory group chaired by the Government Commissioner for AI. The Council coordinates policy across different ministries and provides guidance on the interpretation of AI standards. For specific domains, sectoral regulators retain significant power; for instance, the Magyar Nemzeti Bank (MNB) acts as the market surveillance authority for AI systems used in the financial services sector, ensuring that AI deployment does not compromise prudential stability or consumer protection. This multi-layered structure ensures that while there is a central point of accountability, specialized expertise is utilized for high-stakes sectors like finance and healthcare.
Enforcement & penalties
Enforcement in Hungary is rigorous, with the power to impose administrative fines that mirror the tiered structure of the EU AI Act. Under Government Decree 344/2025, the Market Surveillance Authority can levy fines for prohibited AI practices, which can reach the Hungarian Forint equivalent of €35 million or 7% of a company's total worldwide annual turnover, whichever is higher. For non-compliance with obligations related to high-risk systems or transparency requirements, fines are scaled down but remain substantial, typically reaching up to €15 million or 3% of turnover. The Decree provides specific HUF ceilings to ensure legal clarity within the domestic administrative system, and payments must generally be made within 30 days of the final decision. Beyond financial penalties, the enforcement bodies have broad corrective powers. They can order the immediate withdrawal of an AI system from the market, mandate the suspension of its use, or require specific technical modifications to bring a system into compliance. The 2025 legislation also emphasizes the 'post-market surveillance' phase, requiring providers of high-risk systems to actively monitor their performance and report serious incidents to the authorities. Decisions made by the Market Surveillance Authority or the NAH are subject to judicial review under standard Hungarian administrative procedure laws, providing a pathway for appeals in the national court system, specifically through the Metropolitan Court of Budapest.
Data protection
AI regulation in Hungary is inextricably linked to the protection of personal data, governed primarily by the EU General Data Protection Regulation (GDPR) and the domestic Act CXII of 2011 on the Right to Informational Self-Determination and on the Freedom of Information (the 'Info Act'). The National Authority for Data Protection and Freedom of Information (NAIH) is the central regulator overseeing data processing activities. In the context of AI, the NAIH ensures that developers and deployers adhere to principles of data minimization, purpose limitation, and transparency, particularly when training large-scale models or deploying automated decision-making systems that affect individuals' rights. The National AI Strategy 2025–2030 further strengthens this framework by establishing the National Data Assets Agency, which is tasked with managing public data resources and enabling the safe, secondary use of non-personal data for AI training. Hungary does not generally impose strict data localization requirements beyond those found in EU law, but it does emphasize the creation of 'on-premise' secure systems for sensitive sectors like defense and public administration. The interplay between the AI Implementation Act and the Info Act requires that any AI system processing personal data must undergo a Data Protection Impact Assessment (DPIA) if it is likely to result in a high risk to the rights and freedoms of natural persons, ensuring that privacy is baked into the AI lifecycle from the design phase.
Sector-specific rules
While the horizontal AI Act provides the baseline, Hungary has developed specific rules for high-impact sectors. In the financial sector, the Magyar Nemzeti Bank (MNB) has issued guidelines and maintains strict oversight over the use of AI for credit scoring, risk assessment, and algorithmic trading. The MNB ensures that AI models used by banks are explainable and do not introduce systemic bias. In healthcare, Government Resolution 1406/2025 prioritizes the clinical validation of AI tools used in diagnostics and therapy. These systems must not only meet AI Act requirements but also comply with existing medical device regulations and undergo rigorous quality assurance before integration into the patient care pathway. The transport and autonomous systems sector is another priority, centered around the ZalaZONE automotive test track. Hungary has established specific regulatory exemptions for testing autonomous vehicles in controlled environments, serving as a precursor to the formal regulatory sandboxes mandated by the AI Act. Additionally, in public administration, the government has mandated a rollout strategy that includes mandatory risk assessments for any AI tool used in government services. This ensures that 'automated administration'—a flagship goal of the national strategy—remains transparent and subject to human oversight, particularly in areas like taxation, social benefits, and law enforcement, where automated decisions could have significant legal effects on citizens.
International alignment
Hungary’s AI regulatory framework is designed for maximum alignment with international standards, specifically those of the European Union and the OECD. As a member state, Hungary’s primary obligation is the implementation of the EU AI Act, which it has achieved through the 2025 legislative package. The government actively participates in EU-level coordination bodies, such as the European AI Board, to ensure that Hungarian enforcement practices remain consistent with those of other member states. Furthermore, the National AI Strategy explicitly adopts the OECD Principles on Artificial Intelligence, focusing on inclusive growth, sustainable development, and well-being. Beyond the EU, Hungary has signaled a pragmatic and multi-vector approach to technological diplomacy. Government Resolution 1404/2025 specifically identifies the United States, China, Israel, the United Arab Emirates, Germany, and Austria as key partners for bilateral cooperation in AI research, standardization, and industrial partnerships. This international outlook is supported by the Hungarian Investment Promotion Agency (HIPA), which evaluates the domestic environment to attract foreign direct investment (FDI) in data centers and AI infrastructure. By aligning its domestic rules with international norms and participating in the Visegrad Group (V4) digital cooperation initiatives, Hungary aims to facilitate cross-border data flows and technology transfers while maintaining a high level of protection for its citizens.
What's next
The Hungarian AI landscape is expected to undergo significant operational expansion through 2026 and 2027. A critical milestone is the full activation of regulatory sandboxes by August 2026, as specified in the transitional provisions of Act LXXV of 2025. These sandboxes will provide a legal 'safe space' for SMEs and startups to test innovative AI systems under the supervision of the Market Surveillance Authority without the immediate risk of full-scale administrative penalties. The government is also expected to release detailed sectoral guidelines for the use of AI in the judicial system, following the 2025 mandate to develop accreditation for judicial AI experts. In the realm of infrastructure, the rollout of the 'AI Factory' and the expansion of national supercomputing capacity remain top priorities to support domestic R&D. Legislatively, the government may introduce further amendments to the 'Info Act' to better accommodate the training of generative AI models on public data assets. Furthermore, as the EU AI Act’s provisions for general-purpose AI (GPAI) models become fully applicable, the Hungarian authorities will likely issue national guidance on transparency and copyright compliance for AI-generated content. The ongoing monitoring and biennial review of the National AI Strategy 2025–2030 will ensure that Hungary’s legal framework remains responsive to rapid technological breakthroughs like quantum computing and advanced autonomous systems, ensuring long-term competitiveness.
act · Effective Jan 1, 2025
central_coordinator
National AI Market Surveillance Authority and Single Point of Contact.
enforcement
National Notifying Authority for AI conformity assessment.
enforcement
Sectoral Market Surveillance Authority for the financial sector.
data_protection
Supervision of data protection and privacy in AI systems.
Nov 2, 2025 · guideline_issued
Hungary sets legal framework for responsible AI
Open source →May 29, 2025 · enforcement_action
Hungarian Competition Authority concludes investigation into Microsoft's Bing AI feature
Open source →Mar 18, 2025 · law_amended
Hungary bill banning LGBTQ+ Pride event and allowing police use of facial recognition, signed into law
Open source →Oct 20, 2024 · law_amended
Hungarian Competition Authority launches inquiry into impact of AI on competition
Open source →regulation · Effective Jan 1, 2025
regulation · Effective Jan 1, 2025
regulation · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2020