AI regulation in Bulgaria is shaped primarily by the EU AI Act, which applies directly across all EU member states, including Bulgaria. Businesses deploying or developing artificial intelligence systems in Bulgaria must now navigate a structured compliance framework that classifies AI systems by risk, imposes mandatory requirements on high-risk applications, and establishes enforcement mechanisms at both EU and national level. This guide covers the current regulatory landscape, the national enforcement architecture, sector-specific considerations, compliance obligations, and the practical steps businesses should take to remain on the right side of the law.
The EU AI Act is the world';s first comprehensive horizontal legal framework for artificial intelligence. It entered into force across the European Union and applies directly in Bulgaria without requiring transposition into national law. The Act establishes a risk-based classification system that divides AI systems into four categories: unacceptable risk, high risk, limited risk, and minimal risk.
Systems classified as posing unacceptable risk are prohibited outright. These include AI tools that use subliminal manipulation, exploit vulnerable groups, or enable real-time remote biometric identification in public spaces by law enforcement, subject to narrow exceptions. High-risk systems - covering areas such as critical infrastructure, employment decisions, credit scoring, education, and law enforcement - face the most demanding requirements. Providers and deployers of high-risk AI must implement conformity assessments, maintain technical documentation, register in the EU database of high-risk AI systems, and ensure human oversight mechanisms are in place.
Limited-risk systems, such as chatbots and deepfake generators, face transparency obligations. Users must be informed they are interacting with an AI system. Minimal-risk systems, which represent the vast majority of AI applications currently in use, face no mandatory requirements under the Act, though voluntary codes of conduct are encouraged.
For Bulgarian businesses, the practical implication is straightforward: the Act applies to any provider placing an AI system on the EU market, any deployer using an AI system within the EU, and any importer or distributor involved in the supply chain. A Bulgarian company using an AI-powered recruitment tool, a credit institution deploying an automated loan assessment system, or a healthcare provider using AI-assisted diagnostics all fall within the Act';s scope.
The EU AI Act requires each member state to designate a national competent authority responsible for supervising and enforcing the regulation. Bulgaria has designated the Commission for Personal Data Protection (CPDP) as the primary national supervisory authority for AI matters, building on its existing role as the national data protection authority under the General Data Protection Regulation.
This choice reflects a deliberate policy decision. AI systems frequently process personal data, and the intersection of data protection law and AI regulation is substantial. The CPDP brings established institutional capacity, legal expertise in technology oversight, and existing relationships with the European Data Protection Board. In practice, this means Bulgarian businesses dealing with AI compliance questions will often be engaging with the same authority they already interact with on GDPR matters.
A non-obvious requirement for many foreign founders is that the CPDP';s remit under AI regulation extends beyond data protection. It covers market surveillance, conformity assessment oversight, and the handling of complaints from individuals affected by AI systems. Businesses should not assume that AI compliance is purely a data protection matter - it encompasses product safety, transparency, and fundamental rights considerations that go beyond the GDPR framework.
Bulgaria has also established coordination mechanisms with the European AI Office, which sits within the European Commission and oversees the regulation of general-purpose AI models at EU level. For businesses deploying large language models or other general-purpose AI systems, the European AI Office is the primary point of contact for enforcement, while the CPDP handles national-level matters.
For businesses operating high-risk AI systems in Bulgaria, the compliance obligations are substantial and ongoing. The EU AI Act sets out a detailed list of requirements that providers - meaning those who develop or place AI systems on the market - must satisfy before deployment.
Providers of high-risk AI systems must establish a quality management system covering the entire lifecycle of the AI system. This includes risk management procedures, data governance practices, technical documentation, record-keeping, and post-market monitoring. The quality management system must be documented and kept up to date throughout the system';s operational life.
Conformity assessment is a central requirement. Depending on the type of high-risk AI system, conformity assessment may be carried out by the provider itself through internal checks, or it may require involvement of a notified body - an independent third-party organisation accredited to assess conformity. Bulgaria has accredited conformity assessment bodies operating in related technical fields, and the national accreditation body, the Executive Agency for Accreditation, is responsible for the accreditation of notified bodies under EU product safety legislation, a role that extends to AI under the Act.
Registration in the EU database of high-risk AI systems is mandatory before market placement. The database is publicly accessible and maintained by the European Commission. Bulgarian providers must register their systems and keep registration information current. Deployers - meaning businesses that use high-risk AI systems developed by others - must also register in certain cases, particularly in the public sector.
Human oversight is a recurring theme throughout the Act';s high-risk provisions. High-risk AI systems must be designed to allow natural persons to monitor their operation, intervene when necessary, and override or stop the system. In practice, this means that fully automated decision-making in high-risk domains is generally not permissible without meaningful human review mechanisms.
A common mistake among foreign businesses entering the Bulgarian market is assuming that CE marking or product safety compliance in other domains automatically satisfies AI Act requirements. The AI Act introduces additional, AI-specific obligations that sit alongside existing product safety frameworks, not in place of them.
General-purpose AI models - large-scale AI systems capable of performing a wide range of tasks, such as large language models - are subject to a distinct set of obligations under the EU AI Act. Providers of these models must maintain technical documentation, comply with EU copyright law, and publish summaries of training data. Models classified as posing systemic risk face additional requirements, including adversarial testing, incident reporting to the European AI Office, and cybersecurity measures.
For Bulgarian businesses, the most relevant scenario is typically that of a deployer rather than a provider of general-purpose AI. A Bulgarian company integrating a large language model into its customer service operations, legal research workflows, or content generation processes is a deployer. Deployers have their own obligations: they must use AI systems in accordance with the provider';s instructions, implement appropriate human oversight, and ensure that their use does not create prohibited or high-risk applications not contemplated by the original provider.
Sector-specific regulation adds another layer of complexity. In the financial sector, the Bulgarian National Bank and the Financial Supervision Commission have issued guidance on the use of AI in banking, insurance, and investment services, drawing on European Banking Authority and European Securities and Markets Authority guidelines. Financial institutions using AI for credit scoring, fraud detection, or algorithmic trading must satisfy both AI Act requirements and sector-specific supervisory expectations.
In healthcare, AI-assisted diagnostic tools and medical devices incorporating AI are subject to the EU Medical Devices Regulation in addition to the AI Act. The Bulgarian Drug Agency oversees medical device regulation in Bulgaria. Businesses in this sector face a dual compliance burden that requires careful coordination between regulatory frameworks.
In the public sector, Bulgarian government bodies and municipalities using AI systems for administrative decisions - such as benefit assessments, permit processing, or law enforcement support - face heightened scrutiny. The Act imposes stricter transparency and oversight requirements on public sector deployers, and the CPDP has signalled that it will prioritise oversight of public sector AI use.
If your business is navigating the intersection of AI regulation and sector-specific requirements in Bulgaria, early legal advice can prevent costly compliance gaps. Contact info@vlolawfirm.com - we can help structure the setup correctly the first time.
The EU AI Act establishes a tiered penalty regime. Violations involving prohibited AI practices attract the highest fines, set at a percentage of global annual turnover or a fixed amount, whichever is higher. Violations of other obligations, including high-risk system requirements, attract lower but still significant penalties. Providing incorrect or misleading information to authorities carries its own penalty tier.
The CPDP, as Bulgaria';s national competent authority, has the power to conduct investigations, request documentation, carry out on-site inspections, issue warnings, require corrective action, and impose administrative fines. The authority can also refer matters to the European AI Office where general-purpose AI models are involved.
In practice, enforcement in the early phase of the Act';s application is likely to focus on the most serious violations and on sectors where AI use is most visible and consequential. Financial services, healthcare, and public administration are the areas where Bulgarian supervisors are most likely to direct initial enforcement attention. Businesses in these sectors should treat compliance as an immediate operational priority rather than a future planning exercise.
A common mistake is treating AI compliance as a one-time project. The Act imposes ongoing obligations: post-market monitoring, incident reporting, documentation updates, and regular review of conformity assessments. Businesses must build compliance into their operational processes, not treat it as a box to tick at launch.
Many underestimate the documentation burden. The Act requires detailed technical documentation covering the AI system';s purpose, design, training data, performance metrics, risk management measures, and human oversight mechanisms. For businesses without dedicated technical and legal resources, assembling and maintaining this documentation is a significant undertaking.
Another non-obvious requirement is the obligation to report serious incidents. Providers of high-risk AI systems must report serious incidents - meaning incidents that result in death, serious harm, or significant disruption to critical infrastructure - to the CPDP within defined timeframes. Deployers must notify providers of any serious incidents they become aware of. Failure to report is itself a compliance violation.
Practical scenarios illustrate the stakes. A Bulgarian fintech company deploying an AI credit scoring tool must conduct a conformity assessment, register the system in the EU database, implement human oversight, and maintain ongoing documentation. If the system produces discriminatory outcomes, the company faces both AI Act enforcement and potential GDPR liability. A foreign software provider placing an AI recruitment tool on the Bulgarian market must ensure its system meets high-risk requirements before any Bulgarian employer uses it - the provider cannot shift compliance responsibility to the deployer for obligations that rest with the provider.
Does the EU AI Act apply to small and medium-sized businesses in Bulgaria?
The EU AI Act applies to all businesses operating within its scope, regardless of size, though it includes some proportionality provisions for SMEs. Small and medium-sized enterprises benefit from reduced fees for conformity assessment in certain cases, access to regulatory sandboxes, and simplified documentation templates. However, the core obligations - risk classification, conformity assessment for high-risk systems, transparency requirements, and human oversight - apply to SMEs just as they do to large corporations. A Bulgarian SME using AI for credit decisions or employment screening cannot claim exemption from high-risk requirements on grounds of size alone. The practical challenge for SMEs is that compliance costs can be proportionally higher, making early legal and technical advice particularly valuable.
How long does it take to achieve compliance with the EU AI Act for a high-risk AI system in Bulgaria?
The timeline depends heavily on the complexity of the AI system and the state of existing documentation and governance processes. For a business starting from scratch, building a quality management system, completing technical documentation, conducting a conformity assessment, and registering in the EU database typically takes several months. Businesses that already have robust data governance and product safety processes in place may be able to move faster. The conformity assessment process itself, particularly where a notified body is involved, can add weeks or months depending on the body';s capacity and the complexity of the assessment. Businesses should plan for a compliance timeline measured in months rather than weeks, and should begin the process well before any planned deployment date.
What is the relationship between the EU AI Act and GDPR compliance in Bulgaria?
The EU AI Act and the GDPR are complementary but distinct frameworks. Many AI systems process personal data, which means both frameworks apply simultaneously. The GDPR governs how personal data is collected, processed, and stored, while the AI Act governs the design, deployment, and oversight of AI systems. In Bulgaria, both frameworks are supervised by the CPDP, which creates a degree of administrative coherence. However, compliance with one framework does not automatically satisfy the other. A business that has completed a GDPR data protection impact assessment for an AI system still needs to conduct an AI Act conformity assessment if the system is high-risk. Conversely, AI Act technical documentation does not substitute for GDPR records of processing activities. Businesses should treat the two frameworks as parallel obligations requiring coordinated but separate compliance efforts.
AI regulation in Bulgaria is now a concrete operational reality, not a future prospect. The EU AI Act applies directly, the CPDP is the designated national authority, and enforcement mechanisms are in place. Businesses developing or deploying AI systems in Bulgaria must classify their systems, meet applicable requirements, and build ongoing compliance processes. The cost of non-compliance - both in financial penalties and reputational terms - significantly outweighs the cost of getting compliance right from the outset.
VLO Law Firms advises international clients on AI regulation in Bulgaria. We can assist with risk classification, conformity assessment preparation, technical documentation review, regulatory engagement with the CPDP, and ongoing compliance monitoring. To request a consultation, contact: info@vlolawfirm.com