Artificial Intelligence Regulations 2025
Obligations Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Legal Notice 226 published | Oct 10, 2025 | Government Gazette No. 21,519; AI Regulations (S.L. 591.05) |
| Legal Notice 227 published | Oct 10, 2025 | IDPC supervisory powers for high-risk AI and prohibited practices |
| Initial commencement | Oct 10, 2025 | Publication and initial administrative framework; specified regulations have deferred commencement |
| Deferred commencement | Aug 2, 2026 | LN 226 reg. 1(3): regs. 4, 5, 6, 8, 9, 10; LN 227 reg. 1(3): regs. 5 to 7 and 9 to 12 |
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Provisions (2)
AI System Classification and Market Surveillance
LN 226/2025 adds no Maltese classification or general risk-assessment duty: classification follows Article 6 and Annex III of Regulation (EU) 2024/1689. The two operator requirements below retain their own named actors; this grouped section has no common role or asserted obligation-category mapping. Institutional context: MDIA is market-surveillance authority and single point of contact (reg. 3), coordinates with the specified sectoral authorities, and is Notifying Authority; the National Accreditation Board performs the Article 28(1) assessment and monitoring (reg. 7). MDIA establishes and runs the national regulatory sandbox (reg. 9); participation is a facility, not an operator duty. Registration, importer-information and sandbox provisions commence on 2026-08-02; the earlier institutional designations and penalty provisions are not deferred by the grouped Effective date.
Penalties qualification: Imposed by MDIA and without prejudice to the Chapter XII penalties of Regulation (EU) 2024/1689. Appeals lie under Part IX of the MDIA Act.
Requirements
| Requirement | Details |
|---|---|
| Annex III point 2 registration | The provider or, where applicable, the authorised representative must register high-risk AI systems referred to in point 2 of Annex III of Regulation (EU) 2024/1689 with MDIA, in the manner MDIA prescribes by guidelines or other binding documentation (reg. 8) |
| Importer information | On a reasoned request, importers must supply national competent authorities with the information and documentation referred to in Article 23(5), in Maltese or English, to demonstrate conformity with Section 2 of Regulation (EU) 2024/1689 (reg. 6) |
Penalties
| Violation | Fine |
|---|---|
| Infringement of the regulations or of Regulation (EU) 2024/1689 (reg. 11(1)) | Up to €350,000 per infringement or, for an undertaking, up to 1% of total worldwide annual turnover for the preceding financial year, whichever is higher |
| Continuing infringement (reg. 11(2)) | A daily penalty of €12,000 for each day the infringement persists, instead of or in addition to the reg. 11(1) penalty |
| Infringement by a public authority or body (reg. 11(5)) | Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists |
High-Risk AI Oversight and Biometric Controls
The requirements below concern law-enforcement use of real-time remote biometric identification in publicly accessible spaces, with the statutory urgency exception. Institutional context: IDPC supervises the reg. 3 high-risk systems and prohibited practices, establishes the reg. 11 registry, and exercises corrective powers. These institutional functions are not duties assigned to deployers. The Effective date describes the core biometric controls; earlier administrative and penalty provisions retain their own commencement under reg. 1(3).
Penalties qualification: Article 20 of the Data Protection Act applies mutatis mutandis to Commissioner decisions; appeals lie to the Information and Data Protection Appeals Tribunal.
Requirements
| Requirement | Details |
|---|---|
| Biometric authorization | Real-time remote biometric identification in publicly accessible spaces for law enforcement requires prior Magistrate authorisation; in duly justified urgency, authorisation must be requested without undue delay and within 24 hours. Rejection requires immediate termination and deletion of data, results and outputs (reg. 6(2), effective 2026-08-02) |
| IDPC notification | Each law-enforcement use of real-time remote biometric identification in publicly accessible spaces must be notified to IDPC, excluding sensitive operational data (reg. 6(4)) |
| Adverse decisions | No decision producing an adverse legal effect on a person may be based solely on the output of the real-time remote biometric identification system (reg. 6(3)) |
Penalties
| Violation | Fine |
|---|---|
| Infringement of the regulations or of Regulation (EU) 2024/1689 by an operator (reg. 13(1)) | Administrative penalties, warnings and non-monetary measures imposed by the Commissioner; amounts follow Chapter XII of Regulation (EU) 2024/1689 — LN 227 states no separate operator scale |
| Infringement by a public authority or body (reg. 13(3)) | Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists |
Cite this regulation
Permalink: https://everyailaw.com/regulation/mt-ai-regulations/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “Artificial Intelligence Regulations 2025”, EveryAILaw.com, Sep 8, 2026. https://everyailaw.com/regulation/mt-ai-regulations/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.