AI regulation in Hungary is shaped primarily by the EU AI Act, the first comprehensive binding legal framework for artificial intelligence in the European Union, which applies directly in Hungary without requiring separate national transposition. Businesses deploying, developing or importing AI systems in Hungary must understand both the EU-level obligations and the national enforcement structures that give those rules practical effect. This guide covers the current regulatory landscape, the risk-based classification system, sector-specific rules, compliance obligations, enforcement authorities and the practical steps companies operating in Hungary need to take.
The EU AI Act and its direct application in Hungary
The EU AI Act is a directly applicable EU regulation, meaning it carries the force of law in Hungary without the Hungarian Parliament needing to pass a separate implementing statute. The Act entered into force in the summer of recent years and applies in phases, with the most significant obligations for high-risk AI systems becoming fully applicable across the EU, including Hungary, in the current regulatory cycle.
The Act establishes a risk-based framework. AI systems are classified into four tiers: unacceptable risk (prohibited outright), high risk (subject to strict pre-market and ongoing obligations), limited risk (transparency obligations only) and minimal risk (largely unregulated). The classification determines the entire compliance burden a business faces.
Prohibited AI practices under the Act include social scoring by public authorities, real-time remote biometric identification in public spaces by law enforcement with narrow exceptions, and AI systems that exploit psychological vulnerabilities. These prohibitions apply in Hungary as they do across the EU, and Hungarian authorities are empowered to enforce them.
High-risk AI systems - those used in critical infrastructure, employment decisions, credit scoring, education, law enforcement and migration management - face the heaviest obligations. Providers of such systems must conduct conformity assessments, maintain technical documentation, register in the EU database of high-risk AI systems, implement quality management systems and ensure human oversight mechanisms are in place before placing a system on the Hungarian market.
Hungary';s national AI strategy and institutional framework
Hungary has developed a national AI strategy that frames AI adoption as a priority for economic competitiveness and public sector modernisation. The strategy sets out ambitions for AI investment, research and education, and it shapes how national authorities approach both promotion and oversight of AI technologies.
On the enforcement side, Hungary has designated the Hungarian Intellectual Property Office (HIPO) - known in Hungarian as the Szellemi Tulajdon Nemzeti Hivatala - as a key body involved in AI-related matters, particularly around intellectual property questions arising from AI-generated content. However, the primary market surveillance and enforcement authority for the EU AI Act in Hungary is the body designated under the national market surveillance framework, which coordinates with the European AI Office established at EU level.
The European AI Office, a body of the European Commission, holds direct supervisory authority over general-purpose AI (GPAI) models and their providers, regardless of where those providers are established. This means that a Hungarian company developing a GPAI model - such as a large language model - is subject to oversight by the European AI Office, not solely by Hungarian national authorities.
Hungary';s Consumer Protection Authority and sector-specific regulators - including the National Bank of Hungary (Magyar Nemzeti Bank, MNB) for financial services and the National Media and Infocommunications Authority (NMHH) for media and communications - play important roles in AI oversight within their respective domains. The MNB, for instance, has issued guidance on the use of AI in financial services, reflecting the sector';s particular sensitivity to algorithmic decision-making.
In practice, founders and compliance officers should identify which national authority has competence over their specific sector before mapping their AI compliance obligations. A common mistake is treating AI regulation as a single-authority matter when in reality it involves layered oversight across multiple bodies.
Risk classification in practice: what it means for businesses in Hungary
Understanding where an AI system falls in the risk hierarchy is the first and most consequential compliance decision a business in Hungary must make. The classification is not always straightforward, and misclassification - particularly underestimating risk level - is one of the most frequent errors made by foreign companies entering the Hungarian market.
High-risk classification triggers a demanding set of obligations. Providers must establish a quality management system covering data governance, technical documentation, record-keeping, transparency to deployers and post-market monitoring. Deployers - businesses that use a high-risk AI system developed by a third party - also carry obligations, including conducting fundamental rights impact assessments in certain cases, ensuring human oversight and informing affected individuals where required.
A practical scenario: a Hungarian fintech company using an AI-powered credit scoring tool sourced from a non-EU vendor is a deployer of a high-risk AI system. The company must verify that the vendor has completed the required conformity assessment, obtain the relevant technical documentation, register the use where required and implement human oversight so that credit decisions can be reviewed and challenged. Failure to do so exposes the company to enforcement action by the MNB and potentially to fines under the EU AI Act.
A second scenario: a Hungarian HR technology startup developing an AI tool that screens CVs and ranks job applicants is a provider of a high-risk AI system. The startup must complete a conformity assessment before placing the product on the market, maintain detailed technical documentation, register in the EU high-risk AI database and ensure the system can be audited. The startup cannot simply launch the product and address compliance later - the obligations are pre-market.
For limited-risk systems, such as chatbots, the main obligation is transparency: users must be informed they are interacting with an AI. This is a relatively light burden, but non-compliance still carries reputational and regulatory risk.
We can help structure your AI compliance approach correctly from the outset. Contact us at info@vlolawfirm.com to discuss your specific situation.
General-purpose AI models: obligations for Hungarian developers and users
General-purpose AI (GPAI) models represent a distinct and increasingly important category under the EU AI Act. A GPAI model is an AI model trained on large amounts of data that can perform a wide range of tasks and be integrated into various downstream applications. Large language models are the most prominent example.
Providers of GPAI models - including Hungarian companies developing such systems - must comply with a specific set of obligations under the Act. These include preparing and maintaining technical documentation, publishing a summary of training data used (with particular attention to copyright compliance), putting in place a policy to respect EU copyright law and registering the model in the EU database. Models with systemic risk - those trained using very large computational resources - face additional obligations including adversarial testing, incident reporting and cybersecurity measures.
Hungarian companies that integrate GPAI models into their own products are downstream deployers. They must ensure that the GPAI provider has complied with its obligations and that the integrated system, taken as a whole, meets the requirements applicable to its risk classification. A non-obvious requirement is that downstream integration can itself trigger high-risk classification if the resulting application falls into a high-risk use case, even if the underlying GPAI model is not itself classified as high risk.
The European AI Office is the primary supervisor for GPAI model providers. Hungarian national authorities cooperate with the Office but do not hold primary jurisdiction over GPAI models. This creates a dual-track compliance structure that many Hungarian companies find unfamiliar.
Many underestimate the copyright dimension of GPAI compliance. The EU AI Act requires GPAI providers to implement a policy for complying with EU copyright law, including the Text and Data Mining exception under the Copyright in the Digital Single Market Directive. Hungarian companies training models on web-scraped data must assess whether their data collection practices comply with this framework.
Sector-specific AI rules in Hungary
Beyond the horizontal EU AI Act framework, several sector-specific rules affect AI use in Hungary. These rules sit alongside the Act and, in some cases, impose additional or more specific obligations.
In financial services, the MNB has been active in setting expectations for AI governance. Financial institutions using AI in credit decisions, fraud detection, algorithmic trading or customer-facing applications must address AI-related risks within their existing risk management frameworks. The MNB';s supervisory expectations align with European Banking Authority (EBA) and European Securities and Markets Authority (ESMA) guidance on AI, which emphasises explainability, fairness and human oversight.
In healthcare, AI systems used as medical devices are subject to the EU Medical Device Regulation (MDR) and the In Vitro Diagnostic Regulation (IVDR) in addition to the AI Act. The National Institute of Pharmacy and Nutrition (OGYÉI) is the competent authority for medical device regulation in Hungary. AI-powered diagnostic tools, clinical decision support systems and patient monitoring applications must satisfy both regulatory frameworks, which can create a significant compliance burden.
In the public sector, Hungarian government bodies deploying AI in administrative decisions - such as benefit assessments or permit processing - must comply with the AI Act';s requirements for high-risk systems and with the general principles of Hungarian administrative law, including the right to an explanation and the right to appeal. The Act of General Rules of Administrative Proceedings (Act CL of 2016) provides the procedural framework within which AI-assisted decisions must operate.
Data protection is a cross-cutting concern. The General Data Protection Regulation (GDPR) applies to any AI system that processes personal data, which covers the vast majority of commercially deployed AI. The Hungarian National Authority for Data Protection and Freedom of Information (NAIH) is the supervisory authority for GDPR in Hungary. NAIH has issued guidance on AI and data protection and has enforcement powers that operate independently of the AI Act framework. Businesses must address both regimes simultaneously.
Compliance obligations, timelines and enforcement
The EU AI Act';s obligations apply on a phased timeline. Prohibited AI practices became enforceable first. Obligations for GPAI model providers and the governance framework for national authorities followed. Full obligations for high-risk AI systems in Annex III of the Act - covering employment, credit, education and similar domains - apply within the current regulatory window. Sector-specific high-risk systems listed in Annex II, which are already covered by existing EU product safety legislation, have a longer transition period.
Hungarian businesses should not treat these timelines as distant deadlines. Conformity assessments, technical documentation and quality management systems take time to prepare. A common mistake is beginning compliance work only when a deadline is imminent, leaving insufficient time to address gaps identified during the assessment.
Enforcement of the EU AI Act in Hungary is carried out by the designated national market surveillance authority, which coordinates with the European AI Office and other EU member state authorities through the AI Board. Penalties for non-compliance are significant. Violations of prohibited AI practices can attract fines of up to a percentage of global annual turnover, with the specific thresholds set out in the Act. Violations of other obligations carry lower but still substantial penalties. For SMEs and startups, the Act provides for proportionate enforcement, but this does not mean exemption.
Practical compliance steps for businesses operating in Hungary include:
- Conducting an AI inventory to identify all AI systems in use or under development.
- Classifying each system according to the EU AI Act';s risk tiers.
- Assigning compliance responsibilities to a named individual or team.
- Engaging with the relevant national authority early, particularly for novel or uncertain use cases.
- Documenting all compliance decisions and maintaining records for audit purposes.
In practice, founders should consider that enforcement authorities are still building their capacity and interpretive guidance is evolving. Early engagement with regulators and proactive documentation are the most effective risk management strategies available.
---
Frequently asked questions
Does the EU AI Act apply to small Hungarian companies and startups?
Yes, the EU AI Act applies to all providers and deployers of AI systems within the EU, regardless of company size. However, the Act includes provisions designed to reduce the burden on SMEs and startups, such as simplified technical documentation requirements and access to regulatory sandboxes. Hungarian startups developing high-risk AI systems should engage with the national competent authority early to understand which simplified procedures are available to them. The proportionality provisions do not eliminate compliance obligations - they adjust how those obligations are fulfilled. Ignoring the Act on the basis of company size is a significant legal risk.
How long does it take to prepare for EU AI Act compliance in Hungary, and what does it cost?
The timeline and cost depend heavily on the risk classification of the AI systems involved. For a minimal-risk system, compliance may require only a brief review and minor documentation updates - a matter of weeks and modest professional fees. For a high-risk system, the process is substantially more demanding: a conformity assessment, quality management system, technical documentation package and registration can take several months and involve professional fees starting from the low thousands of EUR for straightforward cases, rising considerably for complex systems or those requiring third-party conformity assessment bodies. Ongoing compliance - post-market monitoring, incident reporting, annual reviews - adds to the recurring cost. Businesses should budget for both initial setup and continuous compliance.
What is the role of the Hungarian data protection authority (NAIH) in AI regulation?
NAIH enforces the GDPR in Hungary, which applies to virtually all AI systems that process personal data. NAIH has issued guidance on AI and data protection, covering topics such as automated decision-making under GDPR Article 22, data minimisation in AI training and the use of biometric data. NAIH operates independently of the EU AI Act enforcement framework but coordinates with other authorities where cases overlap. A business facing an AI-related complaint in Hungary may find itself dealing with both NAIH (on data protection grounds) and the market surveillance authority (on AI Act grounds) simultaneously. Addressing both frameworks in an integrated compliance programme is strongly advisable.
---
Conclusion
AI regulation in Hungary is a layered framework combining the directly applicable EU AI Act, sector-specific EU and national rules, GDPR obligations and evolving national enforcement structures. Businesses operating in Hungary must classify their AI systems accurately, meet pre-market and ongoing obligations appropriate to that classification and engage with the relevant national and EU-level authorities. The regulatory environment is developing rapidly, and early, structured compliance is significantly less costly than reactive remediation.
VLO Law Firms advises international clients on AI regulation in Hungary. We can assist with AI system classification, conformity assessment preparation, regulatory engagement, data protection compliance and ongoing monitoring of legislative developments. To request a consultation, contact: info@vlolawfirm.com