policy · Effective Jan 1, 2024
RO regulates AI through Romanian AI Legislative Proposal L255/2024 (Rejected).
Romanian AI Legislative Proposal L255/2024 (Rejected) · effective 2024
Updated 60 days ago · 2 sources · confidence: medium
Overview
Romania’s approach to artificial intelligence regulation is characterized by a dual focus on rapid European integration and the preservation of national security interests. As an EU Member State, Romania is bound by the Artificial Intelligence Act (Regulation (EU) 2024/1689), which serves as the primary horizontal regulatory instrument. The Romanian government has adopted a philosophy of 'trustworthy AI,' emphasizing that technological advancement must align with fundamental rights, transparency, and safety. This approach is codified in the National Strategy in the field of Artificial Intelligence 2024–2027 (SN-IA), which transitions the country from early-stage conceptualization to a structured roadmap for public and private sector adoption. The strategy reflects a broader national ambition to position Romania as a regional hub for AI research and development while ensuring that digital transformation does not compromise social cohesion or individual liberties. The maturity level of Romania's AI regulatory environment has evolved significantly since 2022. Initially driven by high-level strategic mandates from the Supreme Council of National Defence (CSAT), the framework has become increasingly granular. The establishment of the Romanian Committee for Artificial Intelligence (CRIA) and the Interministerial Commission for SN-IA implementation demonstrates a commitment to multi-stakeholder governance. Romania’s regulatory philosophy is also heavily influenced by its robust cybersecurity sector; consequently, national AI policies often intersect with cyber-resilience mandates. This is evident in the involvement of technical agencies such as the National Cybersecurity Directorate (DNSC) in AI oversight, reflecting a belief that AI safety is inseparable from the integrity of the underlying digital infrastructure. Furthermore, the National Recovery and Resilience Plan (PNRR) provides the financial backbone for these initiatives, allocating significant resources to the digitalization of public administration and the development of advanced computing capabilities. This financial commitment ensures that the regulatory framework is not merely a set of restrictions but a proactive guide for sustainable technological growth.
Regulatory approach
Romania employs a hybrid regulatory approach that combines the horizontal, risk-based requirements of the EU AI Act with targeted national policy instruments. The core of the Romanian framework is risk-based, mirroring the EU’s classification of AI systems into prohibited, high-risk, limited-risk, and minimal-risk categories. However, Romania has also explored more prescriptive national measures through various legislative proposals, such as the Law on Artificial Intelligence (B154/2024). These domestic initiatives often seek to define AI categories more specifically—distinguishing between Narrow AI, General AI, and Super-Intelligence—and propose explicit prohibitions on AI-driven human resource automation and certain biometric uses that go beyond the baseline EU requirements. In addition to binding European regulations, Romania relies heavily on 'soft law' and strategic frameworks to guide the public sector. The National Strategic Framework (CSN-IA) and various Government Memoranda provide non-binding but authoritative guidance for public administration. This approach allows the government to remain agile, testing AI applications in controlled environments—such as tax risk modeling and administrative simplification—before enacting rigid statutory rules. Furthermore, Romania’s regulatory stance is increasingly sectoral, as seen in the specific legislative focus on the 'deepfake' phenomenon (PL-x 471/2023). This suggests a preference for addressing high-visibility societal risks through surgical domestic legislation while leaving the broader technical regulation of AI models to the harmonized European framework. The Romanian government also emphasizes 'Ethics by Design,' encouraging developers to integrate human oversight and transparency from the earliest stages of the AI lifecycle. This is supported by the Scientific and Ethics Council within CRIA, which provides ongoing assessments of emerging AI trends to ensure they remain within the bounds of Romanian social and legal norms. The governance of AI in Romania is distributed across several key executive and advisory bodies. The Ministry of Research, Innovation and Digitalization (MCID) serves as the primary policy lead, exercising state authority over the national AI agenda. MCID is supported by the Authority for the Digitalisation of Romania (ADR), which acts as the technical implementer, particularly regarding the 'government cloud' and the integration of AI into public services. Together, these bodies chair the Interministerial Commission for SN-IA, ensuring that AI policy is coordinated across all ministries, including Health, Finance, and Justice. This centralized coordination is intended to prevent regulatory fragmentation and ensure a unified Romanian voice in European AI forums. Complementing the executive branch is the Romanian Committee for Artificial Intelligence (CRIA), an advisory body that brings together experts from academia, the private sector, and civil society. CRIA is tasked with providing ethical and scientific guidance through its specialized Scientific and Ethics Council. For enforcement, Romania relies on existing sectoral regulators. The National Authority for Management and Regulation in Communications (ANCOM) and the National Cybersecurity Directorate (DNSC) play critical roles in market surveillance and infrastructure security. Furthermore, the National Supervisory Authority for Personal Data Processing (ANSPDCP) remains the ultimate arbiter for AI applications involving personal data, ensuring that automated decision-making processes comply with privacy standards. The collaboration between these bodies is formalized through various memoranda of understanding, ensuring that technical expertise from DNSC and ADR informs the policy decisions made by MCID and the ethical reviews conducted by CRIA.
Enforcement & penalties
Enforcement of AI regulations in Romania follows a tiered structure, primarily dictated by the EU AI Act's penalty regime. Non-compliance with prohibited AI practices can result in administrative fines of up to €35 million or 7% of the total worldwide annual turnover of the preceding financial year, whichever is higher. For breaches related to high-risk AI system requirements or transparency obligations, fines can reach €15 million or 3% of turnover. These penalties are designed to be effective, proportionate, and dissuasive, with the Romanian state expected to designate a national market surveillance authority to oversee the imposition of these fines once the EU AI Act is fully operationalized. At the national level, supplementary enforcement mechanisms are being developed through specific legislation. The proposed 'Deepfake Law' (PL-x 471/2023) introduces a mix of administrative and criminal sanctions. It empowers the National Audiovisual Council (CNA) to order the removal of unlabelled deepfake content and impose fines on broadcasters. More controversially, the bill includes provisions for criminal penalties, including prison terms, for the malicious creation and dissemination of deepfakes intended to cause reputational harm or fraud. Appeals against administrative sanctions follow the standard Romanian administrative litigation procedure, allowing entities to challenge regulator decisions in the appellate courts (Curtea de Apel). The Romanian judicial system is also preparing for an increase in AI-related litigation by providing specialized training for judges on technical concepts such as algorithmic bias and the 'black box' problem, ensuring that the enforcement of these penalties remains fair and grounded in technical reality.
Data protection
The data protection framework in Romania is anchored in the General Data Protection Regulation (GDPR) and its national implementing legislation, Law No. 190/2018. This framework is central to AI regulation, as most AI systems deployed in Romania rely on the processing of personal data for training, validation, and operation. The Romanian data protection authority, ANSPDCP, has issued guidance emphasizing that AI developers must adhere to the principles of data minimization, purpose limitation, and 'privacy by design.' For AI systems involving automated individual decision-making, including profiling, Romanian law reinforces the right of the data subject to obtain human intervention and to contest the decision. Data localization and sovereignty are also emerging themes within the Romanian framework, particularly concerning the 'Government Cloud' project. Under the National Recovery and Resilience Plan (PNRR), Romania is establishing a secure infrastructure for public data, which includes strict access controls and security vetting for AI service providers. While Romania does not have a general data localization law for the private sector, the Law on National Security and various cybersecurity decrees impose specific data handling requirements for AI systems used in critical infrastructure. This ensures that while Romania remains open to global AI providers, the data of its citizens and the integrity of its public institutions are protected by rigorous security standards. The ANSPDCP also monitors the use of AI in the workplace, ensuring that employee monitoring systems do not infringe upon the fundamental right to privacy or lead to discriminatory outcomes based on automated performance metrics.
Sector-specific rules
Sector-specific AI regulation in Romania is most advanced in the audiovisual and cybersecurity domains. The National Audiovisual Council (CNA) has been increasingly active in monitoring AI-generated content in media, focusing on the prevention of disinformation and the protection of electoral integrity. The pending Deepfake Law will formalize the CNA's role as the primary regulator for AI-manipulated media, requiring broadcasters to provide clear visual and audible warnings for synthetic content. In the financial sector, the National Bank of Romania (BNR) and the Financial Supervisory Authority (ASF) monitor the use of AI in algorithmic trading and credit scoring, ensuring that these systems do not introduce systemic risk or discriminatory biases. In the healthcare sector, AI is regulated as part of the broader framework for medical devices and digital health services. The National Agency for Medicines and Medical Devices (ANMDMR) oversees the certification of AI-based diagnostic tools, aligning with the EU Medical Device Regulation (MDR). Furthermore, the National AI Strategy identifies healthcare as a priority sector for 'innovation sandboxes,' where AI-driven solutions can be tested under regulatory supervision. In the transport sector, Romania is aligning its rules for autonomous vehicles with European standards, focusing on liability and safety testing. These sectoral efforts are coordinated through the Interministerial Commission to ensure that specialized rules do not conflict with the horizontal mandates of the EU AI Act. The agricultural sector is also seeing emerging guidelines for the use of AI in precision farming, focusing on data sharing and the environmental impact of automated machinery.
International alignment
Romania’s AI strategy is explicitly designed to ensure maximum alignment with international and Euro-Atlantic standards. As a member of the European Union, Romania participates in the EU AI Board and contributes to the development of harmonized standards through CEN-CENELEC. The country is also a signatory to the OECD Principles on Artificial Intelligence, committing to the promotion of innovative, trustworthy AI that respects human rights and democratic values. This international alignment is viewed as essential for attracting foreign investment and ensuring that Romanian AI startups can scale within the European Single Market. Beyond the EU, Romania maintains strong strategic partnerships in the field of advanced technology and cybersecurity. The Memorandum of Understanding with Google (July 2024) and ongoing cooperation with major technology providers like NVIDIA reflect an ambition to leverage global expertise for national digital transformation. Romania also participates in NATO’s DIANA (Defence Innovation Accelerator for the North Atlantic) initiative, focusing on the dual-use applications of AI for collective security. By aligning its national security vetting and cybersecurity standards with NATO and EU frameworks, Romania seeks to become a trusted partner for high-tech defense and aerospace projects involving artificial intelligence. Romania also actively engages in the Three Seas Initiative, promoting regional cooperation on digital infrastructure and AI research to enhance the connectivity and resilience of Central and Eastern Europe.
What's next
The future of AI regulation in Romania will be dominated by the full implementation of the EU AI Act. Over the next 24 months, the Romanian government is expected to formally designate its National AI Office and the various market surveillance authorities required by the Regulation. This will involve significant capacity-building efforts within MCID and ADR to handle conformity assessments and the management of regulatory sandboxes. There is also an expected push to consolidate the various 'deepfake' and 'cyber-crime' legislative initiatives into a more coherent National Digital Code that addresses the evolving risks of generative AI and large language models. On the policy front, the National Strategy 2024–2027 will move into its 'roadmap' phase, with specific funding calls for AI Centers of Excellence and public-private partnerships. The government has signaled an interest in developing a 'National AI Hub' that provides shared computing resources and curated datasets for researchers and SMEs. Additionally, as the EU AI Act’s provisions on 'General Purpose AI' (GPAI) come into force, Romania will likely update its national security protocols to address the risks associated with systemic models. These developments will be closely monitored by the Interministerial Commission to ensure that Romania remains a competitive and secure environment for AI innovation through the end of the decade. Pilot projects for AI in public administration, such as automated tax auditing and judicial document processing, are expected to serve as the first real-world tests for the new regulatory framework.
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
central_coordinator
Primary policy-making body for research and digital transformation.
enforcement
Technical implementation of digital public services and AI adoption.
data_protection
Enforcement of GDPR and data protection laws in AI.
advisory
Ensures the security of national digital infrastructure and AI systems.
No tracked timeline events yet
Last checked May 26, 2026
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
regulation · Effective Jan 1, 2024
regulation · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2022
sectoral
Regulation of audiovisual media, including AI-generated content.