act · Effective Jan 1, 2025
SI regulates AI through Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (ZIUDHPUI).
Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (ZIUDHPUI) · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Slovenia's regulatory approach to Artificial Intelligence is characterized by a rapid and structured alignment with European Union standards, transitioning from a policy-driven environment to a rigorous legislative framework. The cornerstone of this landscape is the Act on the Implementation of the (EU) Regulation on Harmonised Rules on Artificial Intelligence (ZIUDHPUI), adopted in late 2025. This Act serves as the essential national link to the EU AI Act, ensuring that the direct obligations of the Union-wide regulation are supported by domestic administrative procedures, designated oversight bodies, and clear enforcement mechanisms. Slovenia positions itself as a proactive participant in the digital decade, leveraging its strong academic heritage in AI research—most notably through the Jožef Stefan Institute and the UNESCO-sponsored International Research Centre on Artificial Intelligence (IRCAI) in Ljubljana—to foster an ecosystem that prioritizes human-centric, trustworthy, and innovative technology deployment. The Slovenian philosophy regarding AI regulation emphasizes the balance between technological competitiveness and the protection of fundamental rights. This is articulated through several strategic pillars: the National Programme for AI (NpUI), the Digital Slovenia 2030 strategy, and the Strategy for the Digital Transformation of the Economy. These documents collectively outline a vision where AI acts as a general-purpose technology driving productivity in key sectors such as healthcare, manufacturing, and public services. By establishing the Ministry for Digital Transformation as a central coordinating hub, Slovenia has created a unified administrative structure intended to reduce fragmentation and provide legal certainty for both providers and deployers of AI systems operating within its jurisdiction. This overview reflects a nation that views AI not merely as a technical challenge but as a societal transformation requiring robust democratic oversight.
Regulatory approach
Slovenia employs a hybrid regulatory model that is primarily horizontal but allows for deep sectoral specialization. The horizontal layer is dictated by the risk-based classification system of the EU AI Act, which Slovenia has operationalized through the ZIUDHPUI. This means that AI systems are regulated based on their potential for harm, with prohibited practices (such as social scoring or certain biometric identification) being strictly banned, while high-risk systems (such as those used in critical infrastructure or law enforcement) are subject to stringent conformity assessments and post-market monitoring. For lower-risk systems, the approach is more permissive, focusing on transparency and voluntary codes of conduct to encourage innovation without imposing undue administrative burdens on small and medium-sized enterprises (SMEs). The national approach is also characterized by a shift from soft law to binding mandates. While early strategies like the 2021 NpUI provided guidelines and ethical recommendations, the 2025 Implementation Act introduced hard legal requirements for national authorities to monitor the market and intervene when systems fail to meet safety or transparency standards. A unique feature of the Slovenian approach is the emphasis on regulatory sandboxes—controlled environments where innovative AI solutions can be tested under the supervision of competent authorities. This allows for real-world validation of technologies before they reach the broader market, ensuring that safety and ethical considerations are integrated into the development lifecycle rather than addressed solely after deployment. Furthermore, the Slovenian government has prioritized the 'once-only' principle and the reduction of bureaucratic hurdles for AI startups, aiming to make the regulatory environment a competitive advantage rather than a barrier to entry. The governance of AI in Slovenia is a multi-layered system led by the Ministry for Digital Transformation (MDP). As the national contact point, the MDP is responsible for coordinating the activities of various sectoral regulators and ensuring that Slovenia meets its obligations under the European AI Office and the European Artificial Intelligence Board. The MDP also oversees the establishment of the National Council for Ethics in AI, an advisory body tasked with evaluating the social and ethical impacts of emerging technologies. This centralized coordination is designed to provide a single point of entry for industry stakeholders and citizens seeking information on AI compliance and rights. Enforcement is distributed among several specialized market surveillance authorities. The Agency for Communication Networks and Services (AKOS) plays a pivotal role in monitoring digital services and infrastructure, while the Information Commissioner (Informacijski pooblaščenec) retains jurisdiction over AI systems that process personal data. Other key bodies include Banka Slovenije for AI applications in the financial sector and the Market Inspectorate for general consumer-facing AI products. These agencies are granted powers to conduct inspections, request technical documentation, and order the withdrawal of non-compliant systems from the market. The ZIUDHPUI ensures these bodies have the necessary budgetary independence and technical expertise to fulfill their mandates effectively. The governance structure also includes a strong emphasis on inter-agency cooperation, with regular joint task force meetings to address cross-sectoral AI challenges, such as the use of AI in smart cities or integrated transport networks.
Enforcement & penalties
Penalties for non-compliance with AI regulations in Slovenia are directly aligned with the administrative fine structure established by the EU AI Act, but are executed through national administrative and inspection procedures. For the most severe violations, such as the deployment of prohibited AI practices, fines can reach up to €35 million or 7% of the offender's total worldwide annual turnover for the preceding financial year, whichever is higher. Non-compliance with obligations related to high-risk AI systems or transparency requirements can result in fines of up to €15 million or 3% of turnover. Providing incorrect or misleading information to national authorities carries a penalty of up to €7.5 million or 1.5% of turnover. The enforcement process follows the General Administrative Procedure Act (ZUP) and the Inspection Act (ZIN). When a market surveillance authority identifies a breach, it typically issues a compliance order or a temporary suspension of the AI system. If the provider fails to rectify the issue, the authority can impose the aforementioned administrative fines. Slovenia also emphasizes a corrective approach for SMEs and startups, where penalties may be moderated based on the scale of the entity and the nature of the infringement, provided the entity demonstrates a good-faith effort to comply. Appeals against enforcement decisions are handled through the Slovenian administrative court system, ensuring judicial oversight of regulatory actions. The ZIUDHPUI also introduces the possibility of periodic penalty payments to compel compliance with orders issued by market surveillance authorities, ensuring that enforcement is not just a one-time event but a continuous process of oversight.
Data protection
The data protection framework in Slovenia is anchored by the EU General Data Protection Regulation (GDPR) and the national Personal Data Protection Act (ZVOP-2). Because AI systems rely heavily on large datasets, the Information Commissioner of the Republic of Slovenia (IP-RS) acts as a critical regulator in the AI space. The ZVOP-2 provides specific rules for the processing of personal data in the public and private sectors, including requirements for Data Protection Impact Assessments (DPIAs) which are mandatory for high-risk AI processing activities. The framework emphasizes the principles of data minimization, purpose limitation, and transparency, ensuring that individuals are informed when their data is used to train or operate AI models. Slovenia does not impose general data localization requirements beyond those specified in the GDPR for transfers to third countries. However, for AI systems used in critical national infrastructure or high-security public administration, specific security protocols may require data to be stored or processed within the European Economic Area (EEA). The Information Commissioner has the power to audit AI systems to ensure that automated decision-making processes do not result in unlawful discrimination or breaches of privacy. Furthermore, the ZIUDHPUI requires that any AI market surveillance involving personal data must be conducted in close coordination with the Information Commissioner to prevent regulatory overlap and ensure consistent protection of citizens' rights. This integrated approach ensures that the development of AI does not come at the expense of the fundamental right to privacy, which is a core value in the Slovenian legal tradition.
Sector-specific rules
In the healthcare sector, AI systems that qualify as medical devices are regulated by the Public Agency for Medicines and Medical Devices (JAZMP). These systems must comply with both the EU Medical Device Regulation (MDR) and the specific high-risk requirements of the AI Act. This dual-layered oversight ensures that AI-driven diagnostics and treatment recommendations meet the highest standards of clinical safety and efficacy. The 2021 NpUI identifies health as a top priority area, leading to specific pilot projects and funding for AI integration in the national healthcare system, provided they adhere to strict ethical guidelines regarding patient data and algorithmic bias. The financial and insurance sectors are governed by Banka Slovenije and the Insurance Supervision Agency (AZN), respectively. These bodies monitor the use of AI in credit scoring, risk assessment, and fraud detection. Under the ZIUDHPUI, these sectoral regulators are designated as the competent authorities for AI systems used by the entities they supervise. This ensures that AI regulation is integrated into existing prudential supervision frameworks. For example, Banka Slovenije evaluates whether AI models used for lending decisions are transparent and do not lead to systemic financial risks or unfair exclusion of consumers. Similarly, in the transport sector, the Ministry of Infrastructure oversees the testing and deployment of autonomous vehicles and AI-managed logistics, focusing on physical safety and liability. The Slovenian approach is to empower existing sectoral experts with AI-specific mandates rather than creating entirely new agencies for every industry, which leverages existing institutional knowledge and maintains regulatory stability.
International alignment
Slovenia’s AI regulatory framework is almost entirely synchronized with the European Union’s legislative agenda. As a Member State, Slovenia participated in the negotiation of the EU AI Act and was among the first to draft a comprehensive national implementation act (ZIUDHPUI). This alignment ensures that AI products developed in Slovenia can move freely across the EU Single Market, provided they meet the harmonized standards. Slovenia also actively participates in the European AI Office and the AI Board, contributing to the development of Union-wide guidelines on general-purpose AI models and systemic risks. This international cooperation extends to participation in EU-funded research initiatives like Horizon Europe and the Digital Europe Programme. Beyond the EU, Slovenia adheres to the OECD Principles on Artificial Intelligence, which promote innovative and trustworthy AI that respects human rights and democratic values. The country is also a member of the Global Partnership on Artificial Intelligence (GPAI), where it collaborates on international projects related to data governance and the future of work. Slovenia’s international strategy emphasizes 'strategic autonomy' within the EU framework, aiming to reduce dependence on non-European technology providers while maintaining open channels for global research collaboration. This is reflected in the Digital Slovenia 2030 strategy, which highlights the importance of international standards and interoperability in the global AI landscape. By hosting IRCAI, Slovenia also plays a unique role in the global South-North dialogue on AI, focusing on how AI can contribute to the UN Sustainable Development Goals (SDGs).
What's next
The next phase of AI regulation in Slovenia will focus on the full operationalization of the ZIUDHPUI and the establishment of the National Council for Ethics in AI. This council is expected to play a major role in shaping the 'soft law' aspects of AI, such as ethical charters for public sector AI use and guidelines for AI in education. Additionally, the Ministry for Digital Transformation is expected to launch the first national AI regulatory sandbox by 2026. This sandbox will provide a legal 'safe space' for companies to test high-risk AI systems under regulatory supervision, helping to refine the technical standards that will be used for formal conformity assessments. Legislatively, Slovenia is monitoring the development of the EU AI Liability Directive and the revised Product Liability Directive. Once these are finalized at the Union level, Slovenia will need to update its national civil code and consumer protection laws to address specific questions of liability for damages caused by AI systems. There is also an ongoing effort to update the National Programme for AI (NpUI) to reflect the rapid advancements in generative AI and large language models (LLMs). Future policy updates are likely to include specific measures for 'Slovenian language technologies' to ensure that AI models are culturally and linguistically representative of the Slovenian population, preventing digital marginalization in the age of global AI platforms. The government is also exploring the use of AI to enhance public administration efficiency, with several 'AI-first' pilot projects planned for the 2026-2028 period.
act · Effective Jan 1, 2025
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2021
central_coordinator
National contact point and central coordinator for AI policy and sandboxes.
sectoral
Market surveillance authority for digital services and AI in communications.
data_protection
Oversight of data protection and privacy in AI systems.
enforcement
Supervision of AI applications within the banking and financial sector.
advisory
General market surveillance for consumer AI products.
Aug 21, 2025 · law_amended
Slovenia adopts act implementing EU AI Act
Open source →Feb 10, 2025 · news
Paris Charter on AI signed
Open source →