Does Artificial Intelligence Regulations 2025 require Human Oversight?
Malta • enforcing
Yes — 1 provision
Requirements at a glance
This regulation imposes 3 specific requirements for Human Oversight across 1 provision:
- Biometric authorization — Real-time remote biometric identification in publicly accessible spaces for law enforcement requires prior Magistrate authorisation; in duly justified urgency, authorisation must be requested without undue delay and within 24 hours. Rejection requires immediate termination and deletion of data, results and outputs (reg. 6(2), effective 2026-08-02)
- IDPC notification — Each law-enforcement use of real-time remote biometric identification in publicly accessible spaces must be notified to IDPC, excluding sensitive operational data (reg. 6(4))
- Adverse decisions — No decision producing an adverse legal effect on a person may be based solely on the output of the real-time remote biometric identification system (reg. 6(3))
High-Risk AI Oversight and Biometric Controls
The requirements below concern law-enforcement use of real-time remote biometric identification in publicly accessible spaces, with the statutory urgency exception. Institutional context: IDPC supervises the reg. 3 high-risk systems and prohibited practices, establishes the reg. 11 registry, and exercises corrective powers. These institutional functions are not duties assigned to deployers. The Effective date describes the core biometric controls; earlier administrative and penalty provisions retain their own commencement under reg. 1(3).
Penalties qualification: Article 20 of the Data Protection Act applies mutatis mutandis to Commissioner decisions; appeals lie to the Information and Data Protection Appeals Tribunal.
Requirements
| Requirement | Details |
|---|---|
| Biometric authorization | Real-time remote biometric identification in publicly accessible spaces for law enforcement requires prior Magistrate authorisation; in duly justified urgency, authorisation must be requested without undue delay and within 24 hours. Rejection requires immediate termination and deletion of data, results and outputs (reg. 6(2), effective 2026-08-02) |
| IDPC notification | Each law-enforcement use of real-time remote biometric identification in publicly accessible spaces must be notified to IDPC, excluding sensitive operational data (reg. 6(4)) |
| Adverse decisions | No decision producing an adverse legal effect on a person may be based solely on the output of the real-time remote biometric identification system (reg. 6(3)) |
Penalties
| Violation | Fine |
|---|---|
| Infringement of the regulations or of Regulation (EU) 2024/1689 by an operator (reg. 13(1)) | Administrative penalties, warnings and non-monetary measures imposed by the Commissioner; amounts follow Chapter XII of Regulation (EU) 2024/1689 — LN 227 states no separate operator scale |
| Infringement by a public authority or body (reg. 13(3)) | Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists |