Does Artificial Intelligence Regulations 2025 require Human Oversight?

Malta • enforcing

Yes — 1 provision

Requirements at a glance

This regulation imposes 3 specific requirements for Human Oversight across 1 provision:

High-Risk AI Oversight and Biometric Controls

Copy link to this provision

Obligation:
Human Oversight
enforcing
Effective:
Aug 2, 2026
Risk tier:
high
Scope:
Law-enforcement authorities using real-time remote biometric identification in publicly accessible spaces in Malta, within LN 227 reg. 6 and its Article 5 safeguards
The requirements below concern law-enforcement use of real-time remote biometric identification in publicly accessible spaces, with the statutory urgency exception. Institutional context: IDPC supervises the reg. 3 high-risk systems and prohibited practices, establishes the reg. 11 registry, and exercises corrective powers. These institutional functions are not duties assigned to deployers. The Effective date describes the core biometric controls; earlier administrative and penalty provisions retain their own commencement under reg. 1(3). Penalties qualification: Article 20 of the Data Protection Act applies mutatis mutandis to Commissioner decisions; appeals lie to the Information and Data Protection Appeals Tribunal.

Requirements

RequirementDetails
Biometric authorizationReal-time remote biometric identification in publicly accessible spaces for law enforcement requires prior Magistrate authorisation; in duly justified urgency, authorisation must be requested without undue delay and within 24 hours. Rejection requires immediate termination and deletion of data, results and outputs (reg. 6(2), effective 2026-08-02)
IDPC notificationEach law-enforcement use of real-time remote biometric identification in publicly accessible spaces must be notified to IDPC, excluding sensitive operational data (reg. 6(4))
Adverse decisionsNo decision producing an adverse legal effect on a person may be based solely on the output of the real-time remote biometric identification system (reg. 6(3))

Penalties

ViolationFine
Infringement of the regulations or of Regulation (EU) 2024/1689 by an operator (reg. 13(1))Administrative penalties, warnings and non-monetary measures imposed by the Commissioner; amounts follow Chapter XII of Regulation (EU) 2024/1689 — LN 227 states no separate operator scale
Infringement by a public authority or body (reg. 13(3))Capped at €50,000 per infringement, plus a daily penalty of up to €50 for each day it persists
View full regulation View obligation Obligation matrix