AI regulation in Greece is governed primarily by the EU AI Act, which applies directly across all member states, including Greece, without requiring separate national transposition. For businesses developing, deploying or importing AI systems in Greece, compliance is no longer optional - it is a live legal obligation with enforceable penalties. This guide covers the regulatory framework, national enforcement structures, sector-specific rules, compliance requirements by risk tier, and the practical steps that companies operating in Greece must take now.
The EU AI Act is a directly applicable regulation, meaning it takes effect in Greece without the need for a separate Greek statute. It establishes a risk-based classification system for AI systems and assigns obligations to providers, deployers, importers and distributors depending on the risk category of the system involved.
The Act distinguishes four risk tiers. Unacceptable-risk systems - such as social scoring by public authorities or real-time biometric surveillance in public spaces - are prohibited outright. High-risk systems, which include AI used in employment decisions, credit scoring, medical devices, critical infrastructure and law enforcement, carry the heaviest compliance burden. Limited-risk systems face transparency obligations only. Minimal-risk systems are largely unregulated, though voluntary codes of conduct apply.
For businesses active in Greece, the practical starting point is classification. A company must determine where its AI system sits in the risk hierarchy before it can assess what obligations apply. Misclassification is one of the most common and consequential errors foreign operators make when entering the Greek market.
The Act also introduces specific rules for general-purpose AI models, including large language models. Providers of such models must maintain technical documentation, comply with copyright rules and publish summaries of training data. Models deemed to carry systemic risk face additional requirements, including adversarial testing and incident reporting to the European AI Office.
Greece has designated the Hellenic Telecommunications and Post Commission (EETT) as one of the national competent authorities under the EU AI Act, alongside other sector regulators depending on the domain. The General Secretariat for Digital Governance under the Ministry of Digital Governance plays a coordinating role in national AI policy and implementation.
The national market surveillance authority is responsible for monitoring AI systems placed on the Greek market and has powers to request documentation, conduct audits and impose corrective measures. Where a high-risk AI system is found to be non-compliant, the authority can require withdrawal from the market, suspension of use or mandatory remediation.
Penalties under the EU AI Act are set at the EU level but enforced nationally. Violations involving prohibited AI practices can attract fines of up to 35 million EUR or 7% of global annual turnover, whichever is higher. Non-compliance with obligations for high-risk systems carries fines of up to 15 million EUR or 3% of global turnover. Providing incorrect or misleading information to authorities can result in fines of up to 7.5 million EUR or 1% of turnover. Greek authorities have the power to impose these penalties directly.
In practice, enforcement in the early phase of the Act';s application has focused on larger operators and high-risk sectors. Smaller businesses and startups are not exempt, however, and the national authority has signalled that it will prioritise sectors such as financial services, healthcare and employment technology.
Understanding which obligations apply requires a clear-eyed assessment of the AI system';s function and context of use. The EU AI Act';s Annex III lists the categories of high-risk AI systems in detail, and Greek businesses must map their products and use cases against this list carefully.
For high-risk AI systems, the core obligations include:
Conformity assessment is required before a high-risk AI system can be deployed. For most high-risk systems, providers can conduct a self-assessment against harmonised standards. For certain categories - particularly AI used in biometric identification and some safety-critical applications - third-party conformity assessment by a notified body is mandatory.
Deployers of high-risk AI systems - that is, businesses that use a third-party AI system in their operations - also carry obligations. They must conduct a fundamental rights impact assessment where the system affects individuals, ensure staff are trained to operate the system correctly, and maintain logs of the system';s operation. A common mistake among Greek businesses is assuming that because they did not build the AI system, they bear no compliance responsibility. The Act explicitly assigns obligations to deployers, not only to providers.
For limited-risk systems, the primary obligation is transparency. Chatbots and AI-generated content must be clearly identified as such. Users interacting with an AI system must be informed that they are not communicating with a human, unless this is obvious from context.
Beyond the horizontal AI Act framework, several sector-specific rules apply to AI use in Greece. These layer additional requirements on top of the general framework and, in some cases, impose stricter standards.
In financial services, the European Banking Authority and the European Securities and Markets Authority have issued guidance on the use of AI in credit decisions, fraud detection and algorithmic trading. Greek banks and investment firms supervised by the Bank of Greece and the Hellenic Capital Market Commission must align their AI governance frameworks with both the AI Act and these sectoral guidelines. AI systems used in credit scoring that affect consumers are classified as high-risk under the Act, triggering the full compliance regime.
In healthcare, AI systems used as medical devices or in vitro diagnostic devices are subject to the EU Medical Device Regulation and the In Vitro Diagnostic Regulation in addition to the AI Act. The National Organisation for Medicines (EOF) is the competent authority for medical device oversight in Greece. AI-powered diagnostic tools, clinical decision support systems and patient monitoring applications must satisfy both regulatory frameworks simultaneously.
In employment, AI systems used to screen job applicants, evaluate employee performance or make decisions about working conditions are classified as high-risk. Greek employers using such tools - whether developed in-house or procured from a vendor - must comply with the full high-risk regime and conduct fundamental rights impact assessments. The Greek Data Protection Authority (HDPA) retains jurisdiction over the data processing aspects of such systems under the GDPR, which continues to apply alongside the AI Act.
In education, AI systems used to assess students or determine access to educational institutions are also high-risk. Greek universities and schools deploying AI-based assessment tools must register these systems and maintain the required documentation.
If your business operates across multiple sectors or is uncertain how overlapping frameworks apply to your AI use cases, contact info@vlolawfirm.com. We can help structure the compliance approach correctly from the outset.
Greece has adopted a national AI strategy that frames AI as a driver of economic modernisation and public sector efficiency. The strategy sets priorities in areas including digital public services, agriculture, tourism and maritime industries - sectors where Greece has a comparative economic interest.
The Greek government has invested in AI infrastructure through the national broadband rollout and the development of data centres, partly supported by EU recovery and resilience funds. The Ministry of Digital Governance has also launched initiatives to promote AI literacy and skills development, recognising that talent availability is a constraint on AI adoption.
Greece participates actively in the EU AI Office, which was established to coordinate AI governance across member states and oversee compliance with the AI Act at the European level. The AI Office has authority over general-purpose AI model providers and can conduct investigations, request information and impose penalties at the EU level, supplementing national enforcement.
The regulatory environment in Greece is broadly supportive of AI innovation, but the government has made clear that compliance with the EU framework is non-negotiable. Businesses that treat the AI Act as a future concern rather than a present obligation are exposed to enforcement risk as the Act';s provisions come into full effect.
A practical scenario: a Greek fintech startup that has built an AI-powered loan origination system must register the system in the EU database, prepare technical documentation, implement a risk management system and ensure human oversight before processing any live applications. The startup cannot defer these steps until it reaches a certain scale - the obligations apply from the moment the system is placed on the market.
A second scenario: a multinational retailer deploying an AI-based HR screening tool across its Greek operations is a deployer, not a provider. It must nonetheless conduct a fundamental rights impact assessment, train its HR staff on the system';s limitations and maintain operational logs. The vendor';s CE marking does not discharge the retailer';s own obligations.
Compliance with AI regulation in Greece is a structured process, not a one-time exercise. Businesses should approach it as an ongoing governance obligation rather than a project with a defined end date.
The first step is an AI inventory. Businesses should catalogue all AI systems they develop, deploy or procure, including systems embedded in third-party software. Many organisations underestimate the number of AI systems in active use, particularly where AI features have been added to existing software products by vendors.
The second step is risk classification. Each system in the inventory must be assessed against the EU AI Act';s risk tiers. This requires legal and technical input, as classification depends on both the system';s technical function and the context in which it is used. The same underlying AI model may be minimal-risk in one application and high-risk in another.
The third step is gap analysis. For each high-risk system, businesses must assess current documentation, risk management processes, human oversight mechanisms and conformity assessment status against the Act';s requirements. Gaps must be remediated before the system can lawfully remain in use.
The fourth step is documentation and registration. High-risk systems must be registered in the EU database. Technical documentation must be prepared and maintained. Quality management systems must be established or updated.
The fifth step is ongoing monitoring. The AI Act requires post-market monitoring for high-risk systems. Providers must collect and analyse data on system performance, report serious incidents to the national authority within defined timeframes, and update documentation when the system changes materially.
Businesses that have not yet begun this process should treat it as urgent. The Act';s provisions for high-risk systems are already in force for new systems, and the transition periods for legacy systems are finite.
Does the EU AI Act apply to small and medium-sized businesses in Greece?
Yes, the EU AI Act applies to all businesses that develop, deploy, import or distribute AI systems in the EU, regardless of size. There are some limited procedural accommodations for SMEs - for example, reduced fees for accessing notified bodies and simplified documentation templates - but the substantive obligations apply equally. A small Greek company that deploys a high-risk AI system must comply with the full high-risk regime. The most common misconception among SMEs is that the Act targets only large technology companies. In practice, any business using AI in employment, credit, healthcare or education contexts faces direct obligations.
How long does it take to achieve compliance with the AI Act for a high-risk system?
The timeline depends on the complexity of the system and the maturity of the organisation';s existing governance processes. For a business starting from scratch, a realistic timeline for a single high-risk system runs from several months to over a year, covering inventory, classification, gap analysis, documentation, conformity assessment and registration. Organisations that already have ISO 9001 quality management systems or robust data protection frameworks in place can often adapt existing processes, which shortens the timeline. The most time-consuming elements are typically technical documentation and, where required, third-party conformity assessment. Businesses should not underestimate the internal resource commitment required.
What is the relationship between the AI Act and GDPR for AI systems processing personal data in Greece?
The AI Act and the GDPR apply simultaneously and independently. The GDPR governs the processing of personal data, including data used to train or operate AI systems. The AI Act governs the AI system itself, regardless of whether it processes personal data. Where an AI system processes personal data - which is common in high-risk applications such as HR screening, credit scoring and healthcare - both frameworks apply, and compliance with one does not satisfy the other. The Greek Data Protection Authority (HDPA) retains full jurisdiction over GDPR matters and has demonstrated a willingness to investigate AI-related data processing. Businesses must conduct both a GDPR data protection impact assessment and, where required by the AI Act, a fundamental rights impact assessment. These are related but distinct exercises.
AI regulation in Greece is a live and enforceable framework, not a future compliance horizon. The EU AI Act applies directly, national enforcement structures are operational, and sector-specific rules add further layers of obligation in financial services, healthcare, employment and education. Businesses that classify their AI systems accurately, build compliant governance processes and maintain required documentation are well positioned to operate lawfully and avoid enforcement risk.
VLO Law Firms advises international clients on AI regulation in Greece. We can assist with AI system classification, compliance gap analysis, technical documentation, fundamental rights impact assessments and regulatory filings with Greek and EU authorities. To request a consultation, contact: info@vlolawfirm.com