Artificial Intelligence Regulations 2025

Jurisdiction:
Malta
enforcing
Effective:
Oct 10, 2025
Authority:
Malta Digital Innovation Authority
Official text

Obligations Covered

Human Oversight

Timeline

MilestoneDateNotes
Legal Notice 226 publishedOct 10, 2025Government Gazette No. 21,519; AI Regulations (S.L. 591.05)
Legal Notice 227 publishedOct 10, 2025IDPC supervisory powers for high-risk AI and prohibited practices
Initial commencementOct 10, 2025Publication and initial administrative framework; specified regulations have deferred commencement
Deferred commencementAug 2, 2026LN 226 reg. 1(3): regs. 4, 5, 6, 8, 9, 10; LN 227 reg. 1(3): regs. 5 to 7 and 9 to 12

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Provisions (2)

AI System Classification and Market Surveillance

Copy link to this provision

enforcing
Effective:
Aug 2, 2026
Risk tier:
all (enhanced for high-risk)
Scope:
Providers, or where applicable their authorised representatives, placing high-risk AI systems referred to in point 2 of Annex III on the Maltese market; importers of high-risk AI systems on reasoned request from national competent authorities
high-impact
LN 226/2025 adds no Maltese classification or general risk-assessment duty: classification follows Article 6 and Annex III of Regulation (EU) 2024/1689. The two operator requirements below retain their own named actors; this grouped section has no common role or asserted obligation-category mapping. Institutional context: MDIA is market-surveillance authority and single point of contact (reg. 3), coordinates with the specified sectoral authorities, and is Notifying Authority; the National Accreditation Board performs the Article 28(1) assessment and monitoring (reg. 7). MDIA establishes and runs the national regulatory sandbox (reg. 9); participation is a facility, not an operator duty. Registration, importer-information and sandbox provisions commence on 2026-08-02; the earlier institutional designations and penalty provisions are not deferred by the grouped Effective date. Penalties qualification: Imposed by MDIA and without prejudice to the Chapter XII penalties of Regulation (EU) 2024/1689. Appeals lie under Part IX of the MDIA Act.

Requirements

RequirementDetails
Annex III point 2 registrationThe provider or, where applicable, the authorised representative must register high-risk AI systems referred to in point 2 of Annex III of Regulation (EU) 2024/1689 with MDIA, in the manner MDIA prescribes by guidelines or other binding documentation (reg. 8)
Importer informationOn a reasoned request, importers must supply national competent authorities with the information and documentation referred to in Article 23(5), in Maltese or English, to demonstrate conformity with Section 2 of Regulation (EU) 2024/1689 (reg. 6)

Penalties

ViolationFine
Infringement of the regulations or of Regulation (EU) 2024/1689 (reg. 11(1))Up to €350,000 per infringement or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher
Continuing infringement (reg. 11(2))A daily penalty of €12,000 for each day the infringement persists, instead of or in addition to the reg. 11(1) penalty
Infringement by a public authority or body (reg. 11(5))Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists

High-Risk AI Oversight and Biometric Controls

Copy link to this provision

Obligation:
Human Oversight
enforcing
Effective:
Aug 2, 2026
Risk tier:
high
Scope:
Law-enforcement authorities using real-time remote biometric identification in publicly accessible spaces in Malta, within LN 227 reg. 6 and its Article 5 safeguards
The requirements below concern law-enforcement use of real-time remote biometric identification in publicly accessible spaces, with the statutory urgency exception. Institutional context: IDPC supervises the reg. 3 high-risk systems and prohibited practices, establishes the reg. 11 registry, and exercises corrective powers. These institutional functions are not duties assigned to deployers. The Effective date describes the core biometric controls; earlier administrative and penalty provisions retain their own commencement under reg. 1(3). Penalties qualification: Article 20 of the Data Protection Act applies mutatis mutandis to Commissioner decisions; appeals lie to the Information and Data Protection Appeals Tribunal.

Requirements

RequirementDetails
Biometric authorizationReal-time remote biometric identification in publicly accessible spaces for law enforcement requires prior Magistrate authorisation; in duly justified urgency, authorisation must be requested without undue delay and within 24 hours. Rejection requires immediate termination and deletion of data, results and outputs (reg. 6(2), effective 2026-08-02)
IDPC notificationEach law-enforcement use of real-time remote biometric identification in publicly accessible spaces must be notified to IDPC, excluding sensitive operational data (reg. 6(4))
Adverse decisionsNo decision producing an adverse legal effect on a person may be based solely on the output of the real-time remote biometric identification system (reg. 6(3))

Penalties

ViolationFine
Infringement of the regulations or of Regulation (EU) 2024/1689 by an operator (reg. 13(1))Administrative penalties, warnings and non-monetary measures imposed by the Commissioner; amounts follow Chapter XII of Regulation (EU) 2024/1689 — LN 227 states no separate operator scale
Infringement by a public authority or body (reg. 13(3))Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists
Cite this regulation

Permalink: https://everyailaw.com/regulation/mt-ai-regulations/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Artificial Intelligence Regulations 2025”, EveryAILaw.com, Sep 8, 2026. https://everyailaw.com/regulation/mt-ai-regulations/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.