act · Effective Jan 1, 2025
LT regulates AI through Amendments to the Law on Information Society Services (AI Implementation).
Amendments to the Law on Information Society Services (AI Implementation) · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Lithuania has emerged as a proactive leader in the European Union’s efforts to regulate artificial intelligence, transitioning rapidly from a strategy-based policy environment to a comprehensive, legally binding regulatory framework. The country’s philosophy is rooted in the dual objective of fostering a competitive AI ecosystem while ensuring the highest standards of safety, transparency, and fundamental rights. This approach was formalized in early 2019 with the publication of the 'Lithuanian Artificial Intelligence Strategy: A Vision of the Future,' which laid the groundwork for ethical AI development and public-sector adoption. Since then, Lithuania has shifted toward hard-law implementation, culminating in the landmark legislative package adopted by the Seimas in January 2025. This package, consisting of amendments to the Law on Technology and Innovation and the Law on Information Society Services, officially transposes the requirements of Regulation (EU) 2024/1689 (the EU AI Act) into the Lithuanian national legal order. The government has prioritized the digital transformation of the state, viewing AI as a critical component of its 'Digital Lithuania' roadmap, which seeks to automate administrative processes while maintaining strict democratic oversight. The maturity of Lithuania’s AI regulatory landscape is evidenced by its early designation of national competent authorities and the establishment of dedicated infrastructure for AI testing. Unlike jurisdictions that have adopted a wait-and-see approach to EU-level mandates, Lithuania has actively sought to operationalize the EU AI Act ahead of many of its peers. The national strategy emphasizes 'trustworthy AI,' a concept that integrates technical robustness with ethical considerations such as non-discrimination and human oversight. By aligning its national digital agenda with the State Data Lake initiative and the GovTech Lab, Lithuania has created a holistic environment where regulation is not merely a restrictive force but a catalyst for secure and scalable innovation. The government’s commitment is further backed by significant financial allocations for AI research, Lithuanian-language model development, and SME support, ensuring that the regulatory burden is balanced by institutional assistance. This proactive stance is also reflected in the country's participation in the D9+ group, where it advocates for a balanced approach to digital sovereignty and open markets.
Regulatory approach
Lithuania employs a horizontal, risk-based regulatory approach that is strictly aligned with the European Union’s classification of AI systems. This means that AI technologies are regulated based on their potential to cause harm, with categories ranging from 'unacceptable risk' (which are prohibited) to 'high-risk' (which are subject to stringent conformity assessments) and 'minimal risk.' The national framework does not seek to create a separate, standalone 'Lithuanian AI Act' but rather integrates EU requirements into existing national statutes. This integration ensures that AI regulation is consistent with broader laws governing information society services, technology innovation, and data protection. By amending the Law on Information Society Services, Lithuania has ensured that AI providers and deployers are subject to the same market surveillance and consumer protection standards that apply to other digital services, while adding specific layers of oversight for algorithmic transparency. This 'New Legislative Framework' (NLF) alignment ensures that AI products are treated with the same rigor as other high-stakes industrial products, such as medical devices or machinery. A defining characteristic of the Lithuanian approach is the use of 'soft law' and 'pilot environments' to complement binding regulations. The Seimas Resolution of May 2024 on public sector AI use serves as a high-level guidance document that sets political and administrative expectations without imposing immediate statutory penalties. Simultaneously, the creation of the 'DI smėliadėžė' (AI Regulatory Sandbox) represents a sophisticated 'regulatory experimentation' model. This sandbox allows developers to test innovative AI systems under the supervision of the Innovation Agency and the Communications Regulatory Authority (RRT) before they reach the market. This approach allows for 'regulatory learning,' where the government can refine its oversight techniques based on real-world data, and developers can ensure compliance in a controlled, low-risk environment. This blend of prescriptive EU-level rules and flexible national experimentation defines Lithuania's current regulatory posture, aiming to reduce the 'compliance gap' for startups while maintaining a high level of public trust in automated systems. The governance of AI in Lithuania is characterized by a dual-agency model that splits responsibilities between innovation support and market enforcement. The Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) serves as the National Market Surveillance Authority and the Single Point of Contact for the EU AI Act. In this capacity, RRT is responsible for monitoring the market, conducting inspections of AI systems, and ensuring that high-risk AI products meet technical and safety standards. RRT has the power to demand access to source code and datasets under specific conditions, order the withdrawal of non-compliant systems from the market, and coordinate with the European AI Office on cross-border enforcement actions. This role positions RRT as the primary 'policeman' of the AI ecosystem, ensuring that commercial deployments do not infringe on public safety or fundamental rights. The RRT also maintains a public registry of high-risk AI systems deployed within the jurisdiction. Complementing the enforcement role of RRT is the Innovation Agency (Inovacijų agentūra), which acts as the National Notifying Authority. The Agency's mandate is to assess and monitor 'notified bodies'—independent entities that perform conformity assessments for high-risk AI systems. Furthermore, the Innovation Agency is the lead operator of the national AI regulatory sandbox. This dual role allows the Agency to support the growth of the AI industry by providing a pathway to certification while simultaneously fostering innovation through supervised testing. Additionally, the National AI Governance Forum, led by the Ministry of the Economy and Innovation, provides a high-level coordination platform. It brings together representatives from the State Data Agency, the State Data Protection Inspectorate, and various ministries to ensure that AI policy remains coherent across different sectors of the government and economy. The Ministry of National Defence also plays a consultative role regarding the security implications of dual-use AI technologies.
Enforcement & penalties
Enforcement in Lithuania is designed to be dissuasive and proportionate, directly incorporating the penalty regime established by the EU AI Act. Under the 2025 amendments, the Communications Regulatory Authority (RRT) is empowered to impose significant administrative fines for non-compliance. For the most severe violations—such as the deployment of prohibited AI systems that use subliminal techniques or exploit vulnerabilities—fines can reach up to €35 million or 7% of the total worldwide annual turnover of the preceding financial year, whichever is higher. Violations related to the non-fulfillment of obligations for high-risk AI systems or transparency requirements for general-purpose AI models carry lower but still substantial penalties, typically up to €15 million or 3% of turnover. For SMEs and startups, the law provides for more flexible fine structures to avoid stifling innovation, focusing on corrective measures rather than purely punitive actions in the first instance, provided the violation was not intentional or grossly negligent. Beyond financial penalties, the enforcement framework includes a range of administrative sanctions and public corrective measures. RRT has the authority to issue formal warnings, order the immediate suspension of AI system operations, and mandate the recall of products from the market. In cases where an AI system poses a significant risk to fundamental rights or safety, the authority can require providers to implement specific technical changes or data governance improvements. All enforcement decisions are subject to judicial review under the Law on Administrative Proceedings, allowing affected parties to appeal RRT’s decisions in the Lithuanian administrative courts. This ensures that while enforcement is robust, it remains within the bounds of due process and legal certainty. The RRT is also required to publish an annual report on its enforcement activities, detailing the number of inspections conducted and the types of violations discovered, which serves as a transparency mechanism for the public.
Data protection
Data protection is a cornerstone of AI regulation in Lithuania, governed primarily by the EU General Data Protection Regulation (GDPR) and the national Law on Legal Protection of Personal Data. The State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI) is the primary supervisory authority responsible for ensuring that AI systems processing personal data comply with privacy-by-design and privacy-by-default principles. In the context of AI, VDAI focuses on the legality of data scraping for training models, the accuracy of automated decisions, and the right of individuals to receive an explanation for AI-driven outcomes. Lithuania’s 2025 AI amendments explicitly require that high-risk AI systems undergo a Fundamental Rights Impact Assessment (FRIA), which includes a rigorous evaluation of data privacy risks before the system can be deployed in sensitive areas like law enforcement or education. The VDAI has issued specific guidance on the use of biometric data in AI, emphasizing that facial recognition in public spaces is generally prohibited unless specific legal exemptions apply. A unique aspect of Lithuania’s data framework is the State Data Lake initiative managed by the State Data Agency. This centralized infrastructure is designed to facilitate the secure and ethical use of public sector data for AI training and analytics. The framework includes strict data localization and sovereignty requirements for sensitive government datasets, ensuring that AI systems used by the state do not compromise national security. Furthermore, the AI regulatory sandbox policy includes specific provisions (aligned with Article 59 of the EU AI Act) that allow for the processing of personal data for the development of certain AI systems in the public interest, provided that strict safeguards—such as pseudonymization and enhanced cybersecurity—are in place. This integrated approach ensures that Lithuania’s push for data-driven innovation does not come at the expense of the high privacy standards mandated by European law. The VDAI also collaborates with the RRT to ensure that algorithmic audits include a review of the underlying data governance practices.
Sector-specific rules
While Lithuania follows a horizontal regulatory model, specific sectors have seen the introduction of tailored guidelines and administrative requirements. The public sector is the most strictly guided, following the 2024 Seimas Resolution which mandates that any AI used by state or municipal institutions must maintain a 'human-in-the-loop.' This means that no administrative decision affecting a citizen's rights can be made solely by an algorithm; a human official must retain final decision-making authority. Additionally, public sector bodies are required to disclose when AI is being used in service delivery, ensuring a level of transparency that exceeds private sector requirements. This is particularly relevant in the 'GovTech' space, where the government actively pilots AI solutions for tax administration, healthcare diagnostics, and urban planning. The GovTech Lab Lithuania acts as a facilitator, helping public institutions define their needs and ensuring that the AI solutions they procure are compliant with national ethical standards. In the financial and information society sectors, AI deployment is governed by the intersection of the AI Act and existing regulations like the Digital Services Act (DSA) and financial stability rules. The Communications Regulatory Authority (RRT) coordinates with the Bank of Lithuania to ensure that AI used in credit scoring or insurance risk assessment does not lead to systemic bias or financial exclusion. Similarly, in the healthcare sector, AI-driven medical devices must comply with both the AI Act’s high-risk requirements and the EU Medical Device Regulation (MDR). Lithuania’s approach is to use the Innovation Agency as a bridge, helping developers in these specialized fields navigate the overlapping regulatory requirements through the AI sandbox, which offers sector-specific testing protocols for health-tech and fintech innovators. In the transport sector, the Ministry of Transport and Communications is developing specific rules for the testing of autonomous vehicles on public roads, which will integrate AI safety standards with traditional road safety requirements.
International alignment
Lithuania’s AI regulatory framework is designed to be 'EU-first,' with total alignment with the European Union’s digital strategy. By transposing the EU AI Act through national amendments in 2025, Lithuania has ensured that its domestic rules are fully interoperable with the single market. This alignment is strategic; it allows Lithuanian AI startups to scale across the EU without facing fragmented regulatory hurdles. Lithuania also participates actively in the EU AI Board and the European AI Office, contributing to the development of harmonized standards for AI safety and transparency. The country has positioned itself as a testing ground for EU-wide initiatives, often being among the first to volunteer for pilot projects involving cross-border data sharing and algorithmic auditing. This commitment to European integration is a core pillar of Lithuania's foreign and economic policy. Beyond the EU, Lithuania aligns its AI policy with the OECD Principles on Artificial Intelligence, which emphasize inclusive growth, sustainable development, and well-being. The 2019 National Strategy and subsequent updates explicitly reference these international norms. Lithuania is also a signatory to various international declarations on AI safety, reflecting its commitment to global cooperation on mitigating existential risks from advanced AI models. The country’s focus on 'Lithuanian-language AI' is another form of international alignment, as it seeks to protect linguistic diversity in the age of Large Language Models (LLMs), a priority shared by UNESCO and other international cultural bodies. Lithuania also closely follows the developments of the Council of Europe’s Framework Convention on Artificial Intelligence, ensuring that its national laws reflect the highest international standards for human rights and the rule of law. This multi-layered alignment ensures that Lithuania remains a respected and integrated player in the global effort to govern AI responsibly.
What's next
The next phase of Lithuania’s AI regulatory journey will focus on the full operationalization of the institutional framework established in 2025. By August 2025, the Innovation Agency is expected to have finalized the procedures for the accreditation of notified bodies, enabling the first wave of national conformity assessments for high-risk AI. Furthermore, the AI Regulatory Sandbox (DI smėliadėžė) is scheduled to become fully operational by early 2026. This will involve the launch of a dedicated digital platform for applications, the publication of technical testing protocols, and the first cohort of pilot projects. The government is also expected to release detailed 'Sectoral AI Guidelines' for the healthcare and energy sectors, providing more granular instructions on how to apply the horizontal rules of the AI Act to specific industrial contexts. These guidelines will be developed in consultation with industry stakeholders to ensure they are practically applicable. Another significant area of development is the expansion of the State Data Lake and its integration with AI development tools. Future legislative updates may introduce more specific rules on the 'secondary use' of public data for AI training, balancing the need for open data with the protection of intellectual property and privacy. Additionally, as the EU AI Act’s staged implementation continues through 2026 and 2027, Lithuania will likely introduce secondary legislation (Government Decrees) to refine the administrative procedures for market surveillance and cross-border cooperation. The National AI Governance Forum is also expected to evolve into a more permanent advisory body, potentially gaining statutory powers to recommend 'prohibited practices' to the government as AI technology evolves and new risks emerge. There is also an ongoing discussion regarding the creation of a national 'AI Ethics Committee' to provide non-binding opinions on the most complex societal impacts of emerging generative models.
act · Effective Jan 1, 2025
act · Effective Jan 1, 2025
sectoral
National Market Surveillance Authority and Single Contact Point for the EU AI Act.
enforcement
National Notifying Authority and operator of the AI Regulatory Sandbox.
data_protection
Supervision of personal data processing in AI systems under GDPR.
central_coordinator
Overall AI policy coordination and strategic leadership.
Feb 12, 2025 · news
Lithuanian parliament staff banned from using DeepSeek on official devices
Open source →Feb 6, 2025 · news
Lithuanian VDAI monitoring DeepSeek
Open source →policy · Effective Jan 1, 2024
Sources:
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2019