policy · Effective Jan 1, 2024
CY regulates AI through Governance Framework for the Implementation of Regulation (EU) 2024/1689 on Artificial Intelligence in Cyprus.
Governance Framework for the Implementation of Regulation (EU) 2024/1689 on Artificial Intelligence in Cyprus · effective 2024
Updated 60 days ago · 2 sources · confidence: medium
Overview
The Republic of Cyprus has adopted a proactive and structured approach to Artificial Intelligence (AI) regulation, transitioning from a policy-led strategy to a formal legal framework harmonized with European Union standards. The cornerstone of this evolution is the implementation of Regulation (EU) 2024/1689 (the EU AI Act), which provides a comprehensive, risk-based methodology for the development and deployment of AI systems. Cyprus’s regulatory philosophy is centered on the dual objectives of fostering technological innovation and ensuring the protection of fundamental rights, safety, and ethical standards. This approach is orchestrated by the Deputy Ministry of Research, Innovation and Digital Policy (DMRID), which serves as the central coordinating body for the nation's digital transformation and AI governance. The government views AI as a critical pillar of its 'Digital Cyprus' vision, aiming to modernize public services while maintaining a secure and trustworthy digital environment for its citizens and businesses. The maturity of Cyprus's AI landscape is reflected in its systematic institutional readiness. Since the publication of the National AI Strategy in 2020, the government has focused on building the necessary administrative capacity to enforce complex technical regulations. By early 2025, Cyprus had already designated its National Competent Authorities (NCAs) and established the primary governance architecture required to meet EU milestones. This includes a clear division of labor between telecommunications regulators, data protection authorities, and human rights ombudsmen. The overarching goal is to position Cyprus as a regional hub for ethical AI, leveraging its strategic location and its status as a member of the EU to attract investment while maintaining high levels of public trust and legal certainty. The integration of AI into the national economy is supported by the National Board for Research and Innovation, ensuring that regulatory measures are balanced with the need for economic growth and scientific advancement.
Regulatory approach
Cyprus employs a horizontal, risk-based regulatory approach that distinguishes between AI systems based on their potential to cause harm. This methodology follows the EU AI Act’s classification system: prohibited practices, high-risk systems, limited-risk systems requiring transparency, and minimal-risk systems. While the primary regulatory obligations are horizontal—applying across all sectors—Cyprus also maintains sectoral oversight through existing regulators in fields such as finance, health, and shipping. This hybrid model ensures that while the core technical requirements for AI are uniform, specific sectoral risks are managed by authorities with deep domain expertise. The transition from the non-binding 'soft law' of the 2020 National Strategy to the binding 'hard law' of the 2024 Implementation Framework marks a significant shift toward mandatory compliance and enforcement, requiring developers to undergo rigorous conformity assessments for high-risk applications. A key feature of the Cypriot approach is the emphasis on 'innovation-friendly' regulation. The government has committed to establishing national AI regulatory sandboxes by August 2026, which will allow businesses—particularly Small and Medium-sized Enterprises (SMEs) and startups—to test innovative AI systems under regulatory supervision before they reach the market. This proactive engagement is designed to reduce the compliance burden for smaller actors while ensuring that safety and fundamental rights are not compromised. Furthermore, the regulatory framework is dynamic, incorporating periodic reviews and updates to keep pace with rapid technological advancements, such as the emergence of general-purpose AI (GPAI) models and generative technologies. The Deputy Ministry actively engages with the private sector through the 'Digital Citizens Academy' and various industry forums to ensure that the regulatory burden remains proportionate to the risks involved, fostering a culture of 'compliance by design' among local developers. The governance of AI in Cyprus is decentralized among several specialized bodies, with the Deputy Ministry of Research, Innovation and Digital Policy (DMRID) acting as the National Coordinator. DMRID is responsible for high-level policy alignment and represents Cyprus at the European Artificial Intelligence Board. The operational enforcement of the AI Act is split between the Office of the Commissioner for Electronic Communications and Postal Regulation (OCECPR) and the Office of the Commissioner for Personal Data Protection. OCECPR serves as the Notifying Authority, the primary Market Surveillance Authority (MSA), and the national Single Point of Contact, giving it broad powers to inspect AI systems, demand technical documentation, and coordinate with EU-level bodies. This office is also responsible for overseeing the certification of third-party conformity assessment bodies. The Commissioner for Personal Data Protection holds a specialized mandate as a Market Surveillance Authority for high-risk AI systems listed in Annex III of the AI Act, particularly those involving biometric identification, emotion recognition, and data-driven profiling. Additionally, a group of 'Fundamental Rights Authorities' has been designated to monitor the impact of AI on civil liberties; this group includes the Commissioner for Administration and the Protection of Human Rights (Ombudsman) and the Attorney-General. These authorities are tasked with ensuring that AI deployments in sensitive areas—such as law enforcement, migration, and the judiciary—adhere to constitutional and international human rights standards. This multi-layered governance structure ensures that technical safety, data privacy, and fundamental rights are all subject to rigorous oversight, with clear channels for inter-agency cooperation and information sharing.
Enforcement & penalties
Enforcement of AI regulations in Cyprus follows the stringent penalty regime dictated by Article 99 of the EU AI Act. The framework distinguishes between different levels of infringements, with the most severe penalties reserved for prohibited AI practices, such as social scoring or manipulative AI. For such violations, fines can reach up to €35,000,000 or 7% of the total worldwide annual turnover of the preceding financial year, whichever is higher. Other non-compliance issues, such as failing to meet the requirements for high-risk AI systems or violating transparency obligations, carry lower but still substantial tiers of fines, reaching up to €15,000,000 or 3% of turnover. Providing misleading or false information to national competent authorities can result in fines of up to €7,500,000 or 1.5% of turnover, emphasizing the importance of transparency in the regulatory process. Beyond administrative fines, the Cypriot enforcement bodies possess the power to order the withdrawal of non-compliant AI systems from the market or to mandate specific corrective actions. The national implementation framework requires Cyprus to finalize a specific national penalty regime through secondary legislation, which will detail the exact administrative procedures for imposing sanctions and the appeals process. Decisions made by the Market Surveillance Authorities (OCECPR and the Data Protection Commissioner) are subject to judicial review by the Administrative Court of Cyprus, ensuring that enforcement actions are consistent with the principles of due process, proportionality, and the right to a fair trial. The authorities also have the power to impose periodic penalty payments to compel compliance with orders to cease an infringement or to provide required documentation during an investigation.
Data protection
The data protection framework in Cyprus is anchored by the General Data Protection Regulation (GDPR) and the national Law 125(I)/2018. This framework is critical to AI regulation because the vast majority of AI systems rely on the processing of personal data for training, validation, and testing. The Commissioner for Personal Data Protection is the primary regulator in this space, ensuring that AI developers and deployers adhere to principles of data minimization, purpose limitation, and transparency. In the context of AI, the Commissioner focuses on the lawfulness of data scraping, the accuracy of algorithmic outputs, and the rights of individuals to receive explanations for automated decisions that significantly affect them. The Commissioner has issued specific guidance on the use of AI in the workplace and the processing of biometric data, which are considered high-risk activities. Cyprus does not impose general data localization requirements, following the EU principle of the free flow of non-personal data. However, for AI systems used in critical infrastructure or government services, specific security protocols may require data to be stored within the European Economic Area (EEA). The intersection of the AI Act and the GDPR means that AI providers must conduct Data Protection Impact Assessments (DPIAs) alongside the required AI Fundamental Rights Impact Assessments (FRIAs) for high-risk systems. The Commissioner for Personal Data Protection has been granted explicit powers under the 2024 Governance Framework to enforce AI-related prohibitions where they overlap with data protection violations, such as unauthorized biometric surveillance or the use of AI for discriminatory profiling. This ensures a seamless regulatory environment where data privacy is treated as a foundational element of AI safety.
Sector-specific rules
While the AI Act provides a horizontal foundation, several sectors in Cyprus are subject to additional rules. In the financial sector, the Central Bank of Cyprus and the Cyprus Securities and Exchange Commission (CySEC) monitor the use of AI in algorithmic trading, credit scoring, and anti-money laundering (AML) protocols. These bodies ensure that AI-driven financial services comply with existing prudential requirements and consumer protection laws. CySEC has also established an 'Innovation Hub' to provide guidance to fintech firms using AI. In the healthcare sector, AI systems used as medical devices must comply with both the AI Act and the EU Medical Devices Regulation (MDR), with the Ministry of Health overseeing clinical safety and the eHealth Law governing the digital processing of patient records to ensure that AI-driven diagnostics do not compromise patient confidentiality. The shipping and maritime sector, a vital component of the Cypriot economy, is also seeing targeted AI integration. The Deputy Ministry of Shipping promotes the use of AI for autonomous vessel navigation and port logistics, guided by the Digital Strategy for Cyprus 2020-2025. These deployments must align with international maritime standards and national safety regulations. Furthermore, in the employment sector, the use of AI for recruitment and worker management is classified as high-risk under the AI Act, requiring employers to ensure transparency and prevent algorithmic bias. The Department of Labour, in collaboration with the Data Protection Commissioner, monitors these systems to prevent discriminatory practices in hiring and performance evaluation, ensuring that the transition to AI-enhanced workplaces does not erode labor rights or worker protections.
International alignment
Cyprus is fully aligned with the European Union’s digital sovereignty goals and the 'Brussels Effect' of AI regulation. As an EU Member State, Cyprus’s national laws are designed to be perfectly interoperable with the EU AI Act, ensuring that AI systems developed in Cyprus can be seamlessly marketed across the Single Market. Cyprus also participates actively in the European Artificial Intelligence Board and the AI Office, contributing to the development of EU-wide codes of practice and harmonized standards. This alignment extends to international principles, as Cyprus supports the OECD Principles on Artificial Intelligence and the Council of Europe’s Framework Convention on Artificial Intelligence, which emphasizes the protection of democracy and the rule of law in the age of automation. Beyond the EU, Cyprus leverages its bilateral agreements to foster R&I cooperation. The National Strategy for Research and Innovation 2024-2026 emphasizes alignment with the European Research Area (ERA) and participation in Horizon Europe projects. Cyprus has also sought to harmonize its digital policies with regional partners in the Mediterranean and the Middle East, particularly through the 'Med9' group, focusing on areas like cybersecurity and data sharing. By adhering to international standards (such as ISO/IEC 42001 for AI management systems), Cyprus ensures that its domestic industry remains competitive on a global scale while upholding the democratic values of the Western regulatory model. This international outlook is intended to attract global tech firms to establish their regional headquarters in Cyprus, benefiting from a stable and predictable legal environment.
What's next
The next two years will be a period of intense legislative and operational activity in Cyprus as the full provisions of the AI Act come into force. By August 2025, the government must ensure that the rules for General-Purpose AI (GPAI) are fully integrated into national oversight mechanisms. The most significant milestone will occur on August 2, 2026, when the full suite of obligations for high-risk AI systems becomes mandatory. To prepare for this, the Deputy Ministry of Research, Innovation and Digital Policy is expected to launch a series of national support measures, including technical guidance for SMEs and the official opening of the national AI regulatory sandbox. This sandbox will be a critical tool for fostering local innovation, providing a safe space for developers to experiment with new technologies under the guidance of regulators. Additionally, the Cypriot Parliament is expected to debate and pass secondary legislation to finalize the national penalty regime and further clarify the powers of the various Market Surveillance Authorities. There is also an ongoing focus on the 'Digital Citizens Academy,' which aims to raise AI literacy across the population, ensuring that citizens are aware of their rights regarding automated decision-making and can identify potential AI-driven misinformation. As AI technology continues to evolve, the government has signaled that it may designate additional sectoral market surveillance authorities (e.g., for transport or energy) to ensure that the unique risks of AI in critical infrastructure are managed by the most qualified agencies. The long-term goal is to create a resilient regulatory ecosystem that can adapt to the challenges of generative AI and future breakthroughs in artificial general intelligence.
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
central_coordinator
National Coordinator for AI and Digital Policy
sectoral
Notifying Authority, Market Surveillance Authority, and Single Point of Contact
data_protection
Market Surveillance Authority for specific high-risk AI and data protection enforcement
enforcement
Fundamental Rights Authority
Apr 9, 2025 · news
Cyprus criminalises AI-generated child pornography
Open source →