regulation · Effective Jan 1, 2025
UA regulates AI through Council of Europe Framework Convention on AI, Human Rights, Democracy, and Rule of Law.
Council of Europe Framework Convention on AI, Human Rights, Democracy, and Rule of Law · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Ukraine’s approach to artificial intelligence (AI) regulation is characterized by a strategic, phased transition designed to foster innovation while ensuring alignment with European democratic standards. Since 2020, the Ukrainian government, primarily through the Ministry of Digital Transformation, has viewed AI as a critical driver for national competitiveness, economic recovery, and defense. The regulatory philosophy is rooted in a 'bottom-up' model, which prioritizes the development of voluntary tools, industry self-regulation, and business support mechanisms before the imposition of mandatory legal requirements. This approach is intended to allow Ukraine’s thriving IT sector to adapt to global standards without the stifling effects of premature or overly prescriptive legislation. Furthermore, the integration of AI into the 'Diia' ecosystem—Ukraine's flagship digital government platform—serves as a practical laboratory for testing automated services in a real-world environment, emphasizing the state's role as both a regulator and a primary user of the technology. The maturity of Ukraine's AI landscape is high, with the country serving as a regional hub for AI development even amidst the challenges of the ongoing Russian invasion. The regulatory environment is currently navigating the 'Stage One' preparatory phase established by the 2023 Roadmap. This phase focuses on building a culture of responsible AI use through sectoral guidelines (covering media and marketing) and the implementation of a national regulatory sandbox. As of 2026, Ukraine is actively moving toward 'Stage Two,' which involves the enactment of comprehensive, binding legislation harmonized with the European Union’s AI Act. This transition is viewed as an economic and political necessity, ensuring that Ukrainian AI products can access the EU Single Market while upholding the fundamental rights of citizens.
Regulatory approach
Ukraine utilizes a hybrid regulatory approach that combines horizontal principles with sector-specific guidance. The horizontal framework is defined by the 'Concept of AI Development' and the 'White Paper on AI Regulation,' which establish universal expectations for transparency, human oversight, and risk management. However, recognizing that AI risks vary significantly across different domains, the government has released specific guidelines for high-impact sectors. This 'soft law' approach during the initial phase allows the government to function as a service provider—offering assessment methodologies and labeling schemes—rather than strictly as an enforcer. This minimizes the compliance burden on startups while preparing them for the eventual transition to 'hard law.' The risk-based methodology adopted by Ukraine mirrors the EU AI Act, categorizing systems based on their potential impact on human rights and safety. Systems identified as having 'medium' or 'high' human rights impact are encouraged to enter the national regulatory sandbox, where they undergo rigorous testing and receive expert feedback. This approach is explicitly designed to be adaptive; the government monitors technological evolution and international trends to refine domestic standards. Furthermore, Ukraine’s regulatory strategy is deeply influenced by its status as an EU candidate country, making the 'Brussels Effect' a primary driver of domestic policy. By aligning with the Council of Europe Framework Convention on AI in 2025, Ukraine has also committed to a legally binding international treaty that focuses on the protection of democracy and the rule of law in the age of automation. The primary architect and coordinator of AI policy in Ukraine is the Ministry of Digital Transformation (MDT). The MDT operates under a 'service function' mandate, focusing on creating the infrastructure for responsible AI rather than immediate punitive oversight. It is responsible for managing the regulatory sandbox, publishing assessment methodologies, and coordinating with international partners like the EU and the Council of Europe. Within the MDT, the Expert Committee on the Development of Artificial Intelligence provides the technical and legal expertise necessary to draft guidelines and evaluate sandbox applications. This committee is divided into specialized working groups covering public administration, education, security, and regulation, ensuring a multi-disciplinary approach to governance. In addition to the MDT, sectoral regulators play a vital role in enforcement within their respective jurisdictions. For instance, the National Council of Television and Radio Broadcasting oversees the implementation of AI guidelines within the media sector, ensuring that automated content does not violate information integrity standards. The State Service of Ukraine on Food Safety and Consumer Protection is tasked with monitoring AI in commercial contexts to prevent manipulative advertising and protect consumer rights. As Ukraine moves into Stage Two, these bodies are expected to gain expanded powers to conduct audits, issue cease-and-desist orders, and impose administrative fines for non-compliance with the forthcoming binding AI Law.
Enforcement & penalties
During the current Stage One (2024–2025), enforcement is primarily based on voluntary compliance and reputational incentives. There are no specific administrative fines for failing to follow the sectoral guidelines or the White Paper's recommendations. Instead, the government utilizes 'soft' enforcement mechanisms, such as the AI labeling scheme. Companies that voluntarily adhere to transparency and safety standards receive government-backed labels that enhance consumer trust and facilitate entry into international markets. However, AI developers remain subject to existing general laws, including data protection regulations and consumer protection statutes, which can carry penalties for privacy breaches or deceptive practices. The transition to Stage Two (expected 2026) will introduce a formal penalty regime harmonized with the EU AI Act. This is expected to include significant administrative fines for the deployment of prohibited AI practices or the failure of high-risk systems to meet technical and transparency requirements. Based on the legislative trajectory, these fines could reach up to several million euros or a percentage of a company's total global turnover. Enforcement will likely involve a tiered system where minor infractions result in warnings and corrective orders, while systemic violations of fundamental rights lead to heavy financial sanctions. An appeals process through the Ukrainian administrative court system will be available to ensure due process and prevent arbitrary regulatory actions.
Data protection
Ukraine’s data protection framework is currently governed by the Law of Ukraine 'On Protection of Personal Data' (2010). This law establishes the basic requirements for data processing, consent, and the rights of data subjects. However, to support the development of AI and align with European standards, Ukraine is in the process of harmonizing its domestic laws with the EU’s General Data Protection Regulation (GDPR). This includes the introduction of stricter requirements for data minimization, purpose limitation, and the processing of sensitive personal data, which are critical for training unbiased and secure AI models. The Ministry of Digital Transformation and the Ukrainian Parliament (Verkhovna Rada) have been working on updated legislation (such as Bill 5628) to create a more robust data protection authority with independent oversight powers. In the context of AI, the 2024 White Paper emphasizes that developers must conduct Data Protection Impact Assessments (DPIAs) when using personal data for AI training, especially for high-risk applications. Furthermore, the Council of Europe Framework Convention signed in 2025 reinforces these protections, mandating that AI systems must not undermine the right to privacy. Data localization is generally not required for civilian AI, but strict data residency and security protocols apply to AI systems used in the defense and national security sectors. The government is also exploring 'data altruism' frameworks to allow for the ethical sharing of public data for AI research and development.
Sector-specific rules
Sectoral regulation in Ukraine is currently most advanced in the media and marketing industries. The 'Guidelines for the Responsible Use of AI in Media' address the unique risks of generative AI in journalism, such as the creation of deepfakes and the automated spread of disinformation. These guidelines require media outlets to clearly label AI-generated content and maintain human editorial control over all published material. Similarly, the advertising guidelines focus on preventing 'dark patterns' and manipulative targeting. These rules emphasize that AI should not exploit the psychological vulnerabilities of consumers, particularly children, and require transparency regarding the use of personal data for algorithmic personalization. Beyond media and marketing, the government is developing frameworks for AI in education and public administration. In education, the focus is on ensuring equitable access to AI tools and preventing algorithmic bias in student assessments. In the public sector, the 'AI + Public Administration' working group is drafting protocols for the use of AI in government services to ensure transparency and prevent discriminatory outcomes in automated decision-making. While the defense sector is technically excluded from the civilian Council of Europe Convention, it is subject to separate, highly classified security protocols. Ukraine’s unique position as a wartime innovator means that defense AI is a primary focus, though these systems operate under a different governance structure focused on military necessity and international humanitarian law.
International alignment
Ukraine’s AI regulatory strategy is explicitly designed to achieve maximum alignment with international standards, particularly those of the European Union. The 2023 Roadmap and 2024 White Paper are structured to prepare the Ukrainian economy for the EU AI Act. This alignment is not merely a political goal but a commercial necessity, as the EU AI Act’s extraterritorial reach means that any Ukrainian company selling AI services in the EU must comply with its requirements. By adopting similar risk categories and transparency standards early, Ukraine aims to minimize the 'regulatory shock' for its IT industry when the EU Act becomes fully operational. In addition to EU alignment, Ukraine is a committed participant in global AI governance forums. As a member of the Council of Europe, Ukraine played an active role in drafting the Framework Convention on AI, Human Rights, Democracy, and Rule of Law, becoming one of its first signatories in May 2025. This treaty provides a legally binding foundation for Ukraine's domestic laws. Ukraine also adheres to the OECD AI Principles, which emphasize inclusive growth, human-centric values, and trustworthiness. These international commitments serve to signal to global investors that Ukraine is a safe and predictable environment for AI investment, even as it navigates the complexities of wartime governance. The country also participates in the Global Partnership on AI (GPAI) to share its unique experiences in deploying AI for resilience and recovery.
What's next
The most significant upcoming development in Ukraine’s AI landscape is the enactment of the 'Stage Two' binding legislation, often referred to as the 'Ukrainian AI Law.' This legislation is expected to be submitted to the Verkhovna Rada in late 2025 or early 2026, following the conclusion of the Stage One preparatory phase. The law will formally codify the risk-based approach, establish a permanent AI oversight authority, and introduce a comprehensive regime of penalties for non-compliance. It will also finalize the legal status of the regulatory sandbox, potentially offering 'safe harbor' provisions for innovative companies that participate in the testing program. Another key area of future development is the full ratification and implementation of the Council of Europe Framework Convention. This will require Ukraine to update various domestic statutes to ensure that AI systems used by both the public and private sectors do not infringe upon democratic processes or the rule of law. Furthermore, as the war continues, there is an expected push for clearer 'dual-use' regulations that bridge the gap between civilian AI ethics and military AI applications. The government is also expected to expand its sectoral guidelines to include healthcare and finance, addressing specific risks such as algorithmic bias in medical diagnostics and credit scoring. These developments will collectively move Ukraine toward a fully mature, EU-harmonized regulatory ecosystem that balances the urgent needs of national security with the long-term goals of democratic governance and economic integration.
regulation · Effective Jan 1, 2025
guideline · Effective Jan 1, 2024
central_coordinator
Primary coordinator of AI policy and digital development.
central_coordinator
Advisory body providing technical and regulatory expertise.
sectoral
Media sector regulator overseeing content and information integrity.
advisory
Consumer rights protection and advertising oversight.
Aug 15, 2025 · news
Ukraine imposes new sanctions on Russian, Chinese and Belarusian AI drone developers
Open source →Jun 26, 2025 · news
Zelenskyy calls for restricting supply of AI models suitable for military use to Russia
Open source →Oct 15, 2024 · law_amended
APAC and other regional tech ministers discuss AI regulation
Open source →Jun 28, 2024 · law_amended
The Ministry of Digital releases white paper on the future regulation of AI in Ukraine
Open source →Jan 23, 2024 · guideline_issued
Ministry of Digital Transformation publishes guidelines for the responsible of AI in media
guideline · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2023
Sources:
policy · Effective Jan 1, 2024
policy · Effective n/a
Oct 6, 2023 · law_amended
Ukraine Develops AI Regulation Roadmap
Open source →