Draft AI Act presented by political party 'Da, Bulgaria' (project bill for an AI law)
proposedpolicy · Effective Jan 1, 2025
BG regulates AI through Draft AI Act presented by political party 'Da, Bulgaria' (project bill for an AI law).
Draft AI Act presented by political party 'Da, Bulgaria' (project bill for an AI law) · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Bulgaria's overarching approach to Artificial Intelligence (AI) regulation is deeply rooted in its commitment to the European Union's vision for a human-centric and trustworthy AI ecosystem. The nation's strategy is characterized by a dual focus: on one hand, accelerating digital transformation and fostering innovation within its IT and research sectors, and on the other, establishing robust safeguards to mitigate the inherent risks associated with AI technologies. This philosophy is articulated in key national policy documents such as the 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030' and the 'Digital Transformation of Bulgaria for the period 2020–2030', both adopted in 2020. These foundational strategies outline a comprehensive program to enhance digital infrastructure, cultivate AI skills, bolster research capabilities, and unlock the economic potential of data, all while ensuring ethical considerations and fundamental rights are upheld. The emphasis is on creating an enabling environment for AI development and deployment, particularly in public services and high-impact sectors, by aligning national efforts with broader European strategic priorities and funding mechanisms.The maturity of Bulgaria's AI regulatory landscape is currently in a transitional phase, moving from broad strategic policy frameworks towards more specific legislative instruments. While the foundational concepts provide a strategic roadmap, the country is actively preparing for the national implementation of the forthcoming EU Artificial Intelligence Regulation (AI Act). This is evident in the 'Draft AI Act presented by political party 'Da, Bulgaria'', a project bill from 2025 that explicitly seeks to implement and clarify the national application of the EU AI Act, alongside adding Bulgaria-specific measures to stimulate investment, workforce training, and public-sector modernization. This draft legislation signifies a shift towards a more binding and prescriptive regulatory environment, complementing the existing soft law instruments. Furthermore, sector-specific initiatives, such as the 'Draft Strategy for the Development and Integration of Artificial Intelligence in Bulgarian Education', underscore a proactive stance in addressing AI's implications across critical domains, ensuring a balanced approach that promotes technological adoption while safeguarding societal values and individual rights, particularly those of vulnerable groups like children.
Regulatory approach
Bulgaria's regulatory approach to AI is a strategic blend of horizontal policy frameworks and emerging sector-specific and risk-based legislation, heavily influenced by its status as an EU Member State. The initial phase of regulation has been characterized by the adoption of high-level policy documents, which serve as 'soft law' instruments. These include the 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030' and the 'Digital Transformation of Bulgaria for the period 2020–2030'. These documents establish a horizontal vision for AI development and deployment across various sectors, focusing on strategic goals, investment priorities, and ethical principles, rather than imposing direct binding legal obligations or sanctions. They provide a common direction for ministries, public bodies, and stakeholders, encouraging coordinated action and alignment with EU-level policy guidance, such as the Coordinated Plan on Artificial Intelligence.However, the regulatory landscape is rapidly evolving towards a more binding and risk-based approach, primarily driven by the impending implementation of the EU AI Act. The 'Draft AI Act presented by political party 'Da, Bulgaria'' is a prime example of this evolution, proposing a horizontal, national legal framework explicitly designed to implement and clarify the EU AI Act's provisions. This draft bill adopts a risk-based methodology, categorizing AI systems into different risk levels (unacceptable, high-risk, medium-risk, low-risk) and imposing corresponding obligations on providers and deployers. For high-risk AI systems, it mandates conformity assessments, risk management systems, technical documentation, and registration. This approach reflects a move from purely aspirational policy to concrete legal requirements, ensuring that AI systems are developed and used in a manner that respects fundamental rights, safety, and transparency. Furthermore, the 'Draft Strategy for the Development and Integration of Artificial Intelligence in Bulgarian Education' also proposes a classification of educational AI uses by risk, outlining stricter requirements for medium- and high-risk systems, demonstrating a consistent application of the risk-based paradigm across specific sectors. Bulgaria's governance framework for AI is evolving, with existing institutions playing crucial roles and new dedicated bodies being proposed to manage the complexities of AI development and deployment. At the core of the proposed new structure, the 'Draft AI Act presented by political party 'Da, Bulgaria'' envisages the establishment of a National AI Coordinator. This entity is intended to serve as a single national contact point, coordinating efforts across different sectors and acting as a liaison with EU structures. The Coordinator's role would be multifaceted, encompassing facilitation of funding, public procurement reforms, running an implementation helpdesk, and coordinating funding streams for pilot projects and capacity-building initiatives. Supporting the National AI Coordinator would be a multi-stakeholder Consultative Council for Ethical AI, composed of representatives from government, academia, civil society, and industry, ensuring broad input on ethical considerations and policy development. Operational oversight, particularly for public-sector deployment and e-government integration, would fall under the purview of the Ministry of Electronic Government, which has also taken over the coordination of national AI policy since December 2021.Beyond these proposed new structures, existing regulatory bodies with established mandates will play critical roles in AI governance and enforcement. The Commission for Personal Data Protection (CPDP) is a key institution, responsible for overseeing the lawful processing of personal data in Bulgaria. Its mandate extends to ensuring compliance with the General Data Protection Regulation (GDPR) and national data protection laws, which are paramount given the data-intensive nature of AI systems. The CPDP would be involved in addressing personal data issues and automated decision-making oversight, especially concerning high-risk AI systems. Furthermore, the 'Draft Strategy for the Development and Integration of Artificial Intelligence in Bulgarian Education' proposes an inter-ministerial Steering Board chaired by the Ministry of Education and Science, including representatives from the CPDP, to approve and oversee education AI policy and procurement. This highlights a collaborative governance model where sector-specific ministries and established data protection authorities work in concert to manage AI-related risks and opportunities. The Bulgarian Academy of Sciences also plays a significant role in the foundational 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030', providing scientific input and supporting research excellence, indicating its continued involvement in shaping the national AI agenda.
Enforcement & penalties
While Bulgaria's current AI regulatory landscape is heavily influenced by strategic policy documents, the emerging 'Draft AI Act presented by political party 'Da, Bulgaria'' outlines specific penalties and enforcement mechanisms, aligning with the EU's risk-based approach. For clearly unacceptable AI practices, such as social scoring or unauthorized biometric mass surveillance, the draft proposes outright prohibitions. For high-risk AI systems that fail to comply with mandatory requirements (e.g., conformity assessments, risk management, transparency obligations), the enforcement measures would include administrative fines. These fines are expected to be significant enough to act as a deterrent, consistent with the penalties outlined in the EU AI Act. Additionally, regulatory bodies would have the power to issue orders to suspend or withdraw non-compliant AI systems from the market, ensuring that harmful or unsafe AI applications are promptly removed. The draft also envisions remedies for individuals who have been harmed by AI systems, allowing for civil claims and redress mechanisms.Enforcement responsibilities are designed to be distributed among several national supervisory roles, ensuring a comprehensive oversight framework. The Commission for Personal Data Protection (CPDP) would handle issues related to personal data and automated decision-making, leveraging its existing powers under GDPR. A dedicated AI oversight unit, potentially operating under the proposed National AI Coordinator or the Ministry of Electronic Government, would be responsible for market surveillance, verifying conformity, and monitoring market behavior of AI systems. This unit would coordinate with the European AI Board to ensure consistent application of the EU framework. For other national strategic documents like the 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030' and the 'Digital Transformation of Bulgaria for the period 2020–2030', enforcement is primarily achieved through governance, funding conditionality, and alignment with existing sectoral and constitutional legal frameworks (e.g., electronic communications, public procurement, administrative law), rather than specific new AI-related sanctions. However, the anticipated binding nature of the national AI Act, once adopted, will introduce a more direct and enforceable regime for AI governance.
Data protection
Bulgaria operates under a robust data protection framework, primarily governed by the General Data Protection Regulation (GDPR) of the European Union, which is directly applicable law in all Member States. This means that any processing of personal data by AI systems in Bulgaria must fully comply with GDPR principles, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. The Commission for Personal Data Protection (CPDP) serves as Bulgaria's independent supervisory authority for data protection, responsible for monitoring and enforcing GDPR compliance. Its mandate includes investigating complaints, conducting audits, issuing administrative fines for infringements, and providing guidance on data protection matters. The CPDP's involvement is explicitly anticipated in AI regulation, particularly for addressing personal data issues and overseeing automated decision-making processes, as highlighted in the 'Draft AI Act' and the 'Draft Strategy for the Development and Integration of Artificial Intelligence in Bulgarian Education'.Beyond the general GDPR framework, Bulgaria's emerging AI policies introduce additional safeguards, particularly concerning sensitive data categories and vulnerable individuals. The 'Draft Strategy for the Development and Integration of Artificial Intelligence in Bulgarian Education' places a central emphasis on child rights and enhanced data protection for minors. It mandates GDPR compliance, additional safeguards for processing children’s data, and requirements for local data residency or strict contractual restrictions for third-party providers handling pupil data. Furthermore, it stresses anonymization or minimization of learning analytics datasets and explicit parental/student information and consent procedures where legally required. Mandatory Data Protection Impact Assessments (DPIAs) are envisioned for any AI system processing pupil data. While specific data localization requirements are not broadly mandated across all AI applications, the emphasis on local data residency in certain sensitive contexts, coupled with strict contractual terms for third-party providers, reflects a cautious approach to data governance in critical sectors. The national 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030' and 'Digital Transformation of Bulgaria for the period 2020–2030' also consistently underscore the importance of ethical and socially responsible data use, cybersecurity by design, and privacy protection embedded across all digital transformation programs, reinforcing the nation's commitment to a strong data protection regime for AI.
Sector-specific rules
While Bulgaria's approach to AI regulation aims for a horizontal framework, significant attention is also given to sector-specific applications, particularly in areas deemed critical for public services and societal well-being. The most detailed sector-specific initiative identified is the 'Draft Strategy for the Development and Integration of Artificial Intelligence in Bulgarian Education', proposed in May 2025. This strategy is a national-level policy instrument designed to establish a comprehensive framework for AI use across pre-school, school, vocational, and higher education. It proposes an inter-ministerial governance body, mandatory risk assessments (including Data Protection Impact Assessments), and human-in-the-loop requirements for AI systems in schools. Crucially, it introduces a classification of educational AI uses by risk: low-risk tools (e.g., content recommendation), medium-risk systems (e.g., adaptive learning engines requiring stricter testing), and high-risk systems (e.g., automated high-stakes assessment, biometric identification) which would be restricted, require conformity assessment, or be prohibited unless rigorous safeguards are in place. The strategy also focuses on embedding AI literacy into curricula, upskilling teachers, piloting AI applications, and ensuring robust data protection for children's data.Beyond education, other national strategic documents, such as the 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030' and the 'Digital Transformation of Bulgaria for the period 2020–2030', identify several priority sectors for AI adoption and digital transformation. These include healthcare, agriculture, transport, environment, and public administration. While these documents do not yet detail specific AI regulations for each sector, they outline strategic goals such as fostering innovation and adoption of AI in these areas, improving efficiency, and enhancing the quality of public services through digital governance. For instance, in healthcare, the focus is on e-health and telemedicine; in transport, on smart transport solutions; and in public administration, on modernizing services using digital tools and interoperability standards. The 'Draft AI Act' also flags national security risks from malicious AI use, proposing tailored restrictions and oversight for security-sensitive applications, indicating an intent to develop sector-specific or use-case specific rules where national security is concerned. The ongoing operationalization of these national strategies through action plans is expected to lead to more detailed guidelines and potentially sector-specific rules in these identified priority areas.
International alignment
Bulgaria's approach to AI regulation is characterized by a strong and explicit commitment to international alignment, particularly with the European Union's comprehensive framework. As an EU Member State, Bulgaria is directly impacted by and actively contributing to the development and implementation of EU-level AI policies. The 'Coordinated Plan on Artificial Intelligence (2021 review)', published by the European Commission, serves as a key guiding document for Bulgaria. This plan outlines a coordinated strategy for accelerating investments in AI, ensuring timely implementation of national AI strategies, and aligning policies to support trustworthy, human-centric AI across the EU. Bulgaria is expected to align its national programs, funding streams (including Recovery and Resilience plans), and national AI strategy documents with the Plan’s actions, demonstrating a deep integration into the broader European AI ecosystem.Furthermore, the forthcoming EU Artificial Intelligence Regulation (AI Act) is a pivotal influence on Bulgaria's legislative agenda. The 'Draft AI Act presented by political party 'Da, Bulgaria'' explicitly states its design to implement and clarify the national application of the EU AI Act (Regulation (EU) 2024/1689). This includes mirroring EU-aligned definitions, adopting the EU's risk-based approach, and establishing national supervisory roles that coordinate with European AI governance bodies like the European AI Board. The draft also sets out provisions for monitoring, periodic public reporting, and stakeholder consultations that are intended to align national reporting with EU-level enforcement timelines. Similarly, the 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030' and the 'Digital Transformation of Bulgaria for the period 2020–2030' consistently emphasize alignment with EU strategic priorities, ethical principles for reliable AI, and benchmarks such as the Digital Economy and Society Index (DESI). This consistent emphasis across policy and legislative drafts underscores Bulgaria's dedication to harmonizing its AI regulatory framework with the overarching EU standards and principles, ensuring cross-border interoperability and fostering a unified European approach to AI governance.
What's next
Bulgaria's AI regulatory landscape is poised for significant future developments, primarily driven by the ongoing legislative process at both national and European levels. The most prominent upcoming change is the potential adoption of a national AI law, as exemplified by the 'Draft AI Act presented by political party 'Da, Bulgaria''. This project bill, publicly presented in September 2025, is explicitly designed to implement and clarify the national application of the EU Artificial Intelligence Regulation (Regulation (EU) 2024/1689). While the full legislative text had not yet been published on parliamentary information portals as of November 2025, its progression through public consultation and formal presentation indicates a strong intent to enact binding legislation that will significantly shape AI governance in Bulgaria. The adoption of such an act would introduce concrete legal obligations for AI providers and deployers, establish dedicated national oversight bodies like the National AI Coordinator, and formalize enforcement mechanisms, moving beyond the current framework of strategic policy guidance.In parallel with legislative developments, sector-specific policies and the operationalization of existing strategies are expected to continue. The 'Draft Strategy for the Development and Integration of Artificial Intelligence in Bulgarian Education', proposed in May 2025, is another key future development. Its formal adoption and phased implementation will introduce specific rules, governance structures, and capacity-building programs for AI use in the education sector, impacting curricula, teacher training, and the deployment of educational AI tools. The broader 'Concept for the Development of Artificial Intelligence in Bulgaria until 2030' also mandates the preparation of an operational National Action Plan/Roadmap by an Interdepartmental Working Group. This roadmap is expected to specify concrete measures, responsibilities, timelines, and key performance indicators for achieving the Concept's six strategic pillars. These ongoing efforts, coupled with continuous alignment with EU-level monitoring frameworks and the evolving guidance from the European AI Board, suggest a dynamic period of regulatory refinement and practical implementation aimed at balancing innovation with robust ethical and safety safeguards across all sectors of the Bulgarian economy and society.
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
data_protection
Oversees the lawful processing of personal data in Bulgaria, ensuring compliance with GDPR and national data protection laws, and involved in oversight of AI systems processing personal data.
central_coordinator
Coordinates national AI policy, responsible for public-sector deployment and e-government integration, and is expected to host or support the National AI Coordinator.
data_protection
Chairs the inter-ministerial Steering Board for AI in education, overseeing policy, procurement, curriculum integration, and teacher upskilling for AI use in educational settings.
advisory
Provides scientific input and expertise for national AI strategies, supports research excellence, technology transfer, and collaboration between academia and industry in AI development.
Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
Open source →