Artificial Intelligence Regulations 2025
Obligations Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Legal Notice 226 published | Oct 10, 2025 | Government Gazette No. 21,519; AI Regulations (S.L. 591.05) |
| Legal Notice 227 published | Oct 10, 2025 | IDPC supervisory powers for high-risk AI and prohibited practices |
| Regulations in force | Oct 10, 2025 | Immediate effect upon publication |
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Provisions (2)
AI System Classification and Market Surveillance #
Malta's dual-authority model (MDIA for market surveillance, IDPC for fundamental rights) creates a practical enforcement structure that other small EU member states may follow. LN 226/2025 adds no Maltese classification duty of its own — classification runs on Article 6 and Annex III of Regulation (EU) 2024/1689. What Malta does add is reg. 8, a national registration duty for the narrow Annex III point 2 (critical infrastructure) class, and reg. 11 penalty amounts that stand alongside the Chapter XII tiers rather than restating them.
Requirements
| Requirement | Details |
|---|---|
| Annex III point 2 registration | The provider or, where applicable, the authorised representative must register high-risk AI systems referred to in point 2 of Annex III of Regulation (EU) 2024/1689 with MDIA, in the manner MDIA prescribes by guidelines or other binding documentation (reg. 8) |
| Importer information | On a reasoned request, importers must supply national competent authorities with the information and documentation referred to in Article 23(5), in Maltese or English, to demonstrate conformity with Section 2 of Regulation (EU) 2024/1689 (reg. 6) |
| Market surveillance and single point of contact | MDIA is the market surveillance authority and national single point of contact, coordinating with the Malta Financial Services Authority for regulated financial institutions and with sectoral authorities for Annex I Section A products (reg. 4) |
| Notifying authority | MDIA is the Notifying Authority and may notify only conformity assessment bodies satisfying Article 31; the Article 28(1) assessment and monitoring is carried out by the National Accreditation Board (Malta). Appeals against notified-body decisions lie to MDIA (reg. 7) |
| Regulatory sandbox | MDIA is the sole national authority responsible for establishing and running the Article 57 national AI regulatory sandbox. Participation is a facility, not an obligation (reg. 9) |
Penalties
| Violation | Fine |
|---|---|
| Infringement of the regulations or of Regulation (EU) 2024/1689 (reg. 11(1)) | Up to €350,000 per infringement or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher |
| Continuing infringement (reg. 11(2)) | A daily penalty of €12,000 for each day the infringement persists, instead of or in addition to the reg. 11(1) penalty |
| Infringement by a public authority or body (reg. 11(5)) | Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists |
| Imposed by MDIA and without prejudice to the Chapter XII penalties of Regulation (EU) 2024/1689. Appeals lie under Part IX of the MDIA Act. |
High-Risk AI Oversight and Biometric Controls #
Requirements
| Requirement | Details |
|---|---|
| IDPC supervision | Information and Data Protection Commissioner supervises high-risk AI systems (Annex III) and prohibited practices |
| High-risk AI registry | IDPC maintains a registry of high-risk AI systems |
| Biometric authorization | Real-time remote biometric identification in public spaces for law enforcement requires prior Magistrate authorization |
| IDPC notification | Law enforcement must notify IDPC of biometric identification use (excluding sensitive data) |
| Corrective powers | IDPC can issue warnings, impose corrective measures, and order withdrawal of non-compliant AI systems |
Penalties
| Violation | Fine |
|---|---|
| Infringement of the regulations or of Regulation (EU) 2024/1689 by an operator (reg. 13(1)) | Administrative penalties, warnings and non-monetary measures imposed by the Commissioner; amounts follow Chapter XII of Regulation (EU) 2024/1689 — LN 227 states no separate operator scale |
| Infringement by a public authority or body (reg. 13(3)) | Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists |
| Article 20 of the Data Protection Act applies mutatis mutandis to Commissioner decisions; appeals lie to the Information and Data Protection Appeals Tribunal. |
Cite this regulation
Permalink: https://everyailaw.com/regulation/mt-ai-regulations/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “Artificial Intelligence Regulations 2025”, EveryAILaw.com, Sep 7, 2026. https://everyailaw.com/regulation/mt-ai-regulations/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.