Artificial Intelligence Regulations 2025

Jurisdiction:
Malta
enforcing
Effective:
Oct 10, 2025
Authority:
Malta Digital Innovation Authority
Official text

Obligations Covered

Risk Assessment Human Oversight

Timeline

MilestoneDateNotes
Legal Notice 226 publishedOct 10, 2025Government Gazette No. 21,519; AI Regulations (S.L. 591.05)
Legal Notice 227 publishedOct 10, 2025IDPC supervisory powers for high-risk AI and prohibited practices
Regulations in forceOct 10, 2025Immediate effect upon publication

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Provisions (2)

AI System Classification and Market Surveillance #

Obligation:
Risk Assessment
enforcing
Effective:
Oct 10, 2025
Risk tier:
all (enhanced for high-risk)
Scope:
Providers, or where applicable their authorised representatives, placing high-risk AI systems referred to in point 2 of Annex III on the Maltese market; importers of high-risk AI systems on reasoned request from national competent authorities
high-impact
Malta's dual-authority model (MDIA for market surveillance, IDPC for fundamental rights) creates a practical enforcement structure that other small EU member states may follow. LN 226/2025 adds no Maltese classification duty of its own — classification runs on Article 6 and Annex III of Regulation (EU) 2024/1689. What Malta does add is reg. 8, a national registration duty for the narrow Annex III point 2 (critical infrastructure) class, and reg. 11 penalty amounts that stand alongside the Chapter XII tiers rather than restating them.

Requirements

RequirementDetails
Annex III point 2 registrationThe provider or, where applicable, the authorised representative must register high-risk AI systems referred to in point 2 of Annex III of Regulation (EU) 2024/1689 with MDIA, in the manner MDIA prescribes by guidelines or other binding documentation (reg. 8)
Importer informationOn a reasoned request, importers must supply national competent authorities with the information and documentation referred to in Article 23(5), in Maltese or English, to demonstrate conformity with Section 2 of Regulation (EU) 2024/1689 (reg. 6)
Market surveillance and single point of contactMDIA is the market surveillance authority and national single point of contact, coordinating with the Malta Financial Services Authority for regulated financial institutions and with sectoral authorities for Annex I Section A products (reg. 4)
Notifying authorityMDIA is the Notifying Authority and may notify only conformity assessment bodies satisfying Article 31; the Article 28(1) assessment and monitoring is carried out by the National Accreditation Board (Malta). Appeals against notified-body decisions lie to MDIA (reg. 7)
Regulatory sandboxMDIA is the sole national authority responsible for establishing and running the Article 57 national AI regulatory sandbox. Participation is a facility, not an obligation (reg. 9)

Penalties

ViolationFine
Infringement of the regulations or of Regulation (EU) 2024/1689 (reg. 11(1))Up to €350,000 per infringement or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher
Continuing infringement (reg. 11(2))A daily penalty of €12,000 for each day the infringement persists, instead of or in addition to the reg. 11(1) penalty
Infringement by a public authority or body (reg. 11(5))Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists
Imposed by MDIA and without prejudice to the Chapter XII penalties of Regulation (EU) 2024/1689. Appeals lie under Part IX of the MDIA Act.

High-Risk AI Oversight and Biometric Controls #

Obligation:
Human Oversight
enforcing
Effective:
Oct 10, 2025
Risk tier:
high
Scope:
Deployers of Annex III high-risk AI systems in Malta and law-enforcement authorities using real-time or post-remote biometric identification in publicly accessible spaces

Requirements

RequirementDetails
IDPC supervisionInformation and Data Protection Commissioner supervises high-risk AI systems (Annex III) and prohibited practices
High-risk AI registryIDPC maintains a registry of high-risk AI systems
Biometric authorizationReal-time remote biometric identification in public spaces for law enforcement requires prior Magistrate authorization
IDPC notificationLaw enforcement must notify IDPC of biometric identification use (excluding sensitive data)
Corrective powersIDPC can issue warnings, impose corrective measures, and order withdrawal of non-compliant AI systems

Penalties

ViolationFine
Infringement of the regulations or of Regulation (EU) 2024/1689 by an operator (reg. 13(1))Administrative penalties, warnings and non-monetary measures imposed by the Commissioner; amounts follow Chapter XII of Regulation (EU) 2024/1689 — LN 227 states no separate operator scale
Infringement by a public authority or body (reg. 13(3))Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists
Article 20 of the Data Protection Act applies mutatis mutandis to Commissioner decisions; appeals lie to the Information and Data Protection Appeals Tribunal.
Cite this regulation

Permalink: https://everyailaw.com/regulation/mt-ai-regulations/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Artificial Intelligence Regulations 2025”, EveryAILaw.com, Sep 7, 2026. https://everyailaw.com/regulation/mt-ai-regulations/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.