AI regulation in Latvia is governed primarily by the EU AI Act, the first comprehensive binding legal framework for artificial intelligence in the world, which applies directly across all EU member states including Latvia. Businesses operating in Latvia that develop, deploy or use AI systems must now navigate a layered compliance environment: EU-level obligations under the AI Act, national supervisory arrangements, and sector-specific rules in finance, healthcare and employment. This guide explains the current regulatory framework, the competent authorities, the risk classification system, key obligations for providers and deployers, and the practical steps Latvian and foreign businesses must take to remain compliant.
The EU AI Act is a directly applicable EU regulation, meaning it does not require transposition into Latvian national law to take effect. It entered into force in stages, with the most significant obligations - covering high-risk AI systems and general-purpose AI models - now fully in effect. The Act establishes a risk-based framework that classifies AI systems into four tiers: unacceptable risk (prohibited), high risk, limited risk, and minimal risk.
For businesses in Latvia, the practical consequence is that the Act applies regardless of where the AI system was developed. A Latvian company deploying an AI-powered recruitment tool, a credit-scoring system, or a medical diagnostic application falls squarely within the high-risk category and must comply with the full set of obligations. A foreign company placing an AI product on the Latvian market is equally subject to the Act';s requirements.
The prohibited category covers AI systems that pose an unacceptable threat to fundamental rights. These include systems that use subliminal manipulation, exploit vulnerabilities of specific groups, enable real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions), and social scoring by public authorities. Businesses must audit their AI deployments to confirm none fall into this category.
Latvia has designated the Data State Inspectorate (Datu valsts inspekcija) as the primary national competent authority for AI Act supervision in most sectors. This body already oversees data protection under the General Data Protection Regulation and has expanded its mandate to cover AI compliance. For AI systems used in financial services, the Financial and Capital Market Commission (Finanšu un kapitāla tirgus komisija, or FKTK) acts as the sectoral supervisory authority. In healthcare, the Health Inspectorate (Veselības inspekcija) plays a parallel role.
The Data State Inspectorate is responsible for market surveillance, receiving complaints, conducting investigations, and imposing administrative sanctions. It coordinates with the European AI Office, which was established within the European Commission to oversee general-purpose AI models and ensure consistent enforcement across member states.
Latvia has also participated in the broader EU effort to establish national AI sandboxes - controlled regulatory environments where businesses can test AI systems under supervisory oversight before full market deployment. The sandbox framework allows innovators to engage directly with regulators, identify compliance gaps early, and receive informal guidance. Businesses developing novel AI applications in Latvia should consider whether sandbox participation is appropriate before a full commercial launch.
A common mistake among foreign founders is assuming that because the AI Act is an EU regulation, national authorities play no meaningful role. In practice, the Data State Inspectorate has real investigative and sanctioning powers, and local engagement with the authority can significantly affect how a compliance issue is resolved.
The risk classification system is the operational core of the AI Act. Understanding where a specific AI system sits in the hierarchy determines the full scope of compliance obligations.
High-risk AI systems are defined in Annex III of the AI Act and cover eight domains: biometric identification and categorisation, critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice. Any AI system falling within these domains must meet a demanding set of requirements before it can be placed on the market or put into service in Latvia.
The obligations for providers of high-risk AI systems include:
Deployers - organisations that use a high-risk AI system in a professional context without being its developer - also carry obligations. They must conduct a fundamental rights impact assessment before deploying certain high-risk systems, ensure human oversight is in place, and inform employees or affected individuals where required by law. A Latvian employer using an AI tool to screen job applications, for example, must notify employees and maintain meaningful human review of automated decisions.
In practice, founders should consider that the boundary between "provider" and "deployer" is not always clear. A company that fine-tunes a third-party AI model on its own data and deploys it commercially may be reclassified as a provider, triggering the full set of provider obligations. Legal advice at the design stage is far more cost-effective than remediation after a supervisory inquiry.
General-purpose AI models (GPAI models) are a distinct category under the AI Act, covering large foundation models that can be adapted for a wide range of tasks. The regulation of GPAI models is handled primarily at the EU level by the European AI Office, but Latvian businesses that develop or deploy such models must understand their position in the supply chain.
Providers of GPAI models must prepare and maintain technical documentation, publish a summary of training data used (in compliance with copyright law), and implement a policy for complying with EU copyright rules. GPAI models that are assessed as posing systemic risk - generally those trained with very large computational resources - face additional obligations including adversarial testing, incident reporting to the European AI Office, and cybersecurity measures.
For most Latvian businesses, the more immediate question is how GPAI models they use from third-party providers (such as large language models accessed via API) affect their own compliance position. The Act creates a chain of responsibility: a GPAI model provider must supply downstream deployers with sufficient information to allow them to meet their own obligations. Businesses should review their contracts with AI model providers to confirm that the necessary technical documentation and usage information is available.
A non-obvious requirement is that businesses integrating GPAI models into products or services may inadvertently become providers of high-risk AI systems if the integrated product falls within Annex III. The integration of a general-purpose language model into an HR screening tool, for instance, does not reduce the compliance burden - it may increase it.
If your business is navigating the provider-deployer boundary or assessing obligations under the GPAI provisions, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Beyond the AI Act, Latvian businesses must account for sector-specific rules that interact with the general AI framework. These rules create additional obligations and, in some cases, stricter standards than the AI Act alone requires.
In financial services, the FKTK supervises AI use by banks, insurers, investment firms and payment service providers. The Digital Operational Resilience Act (DORA), which applies to financial entities across the EU, imposes requirements on the management of ICT risks including AI-driven systems. Financial institutions in Latvia using AI for credit scoring, fraud detection or algorithmic trading must demonstrate that these systems are explainable, auditable and subject to human oversight. The FKTK has issued guidance indicating that AI systems used in credit decisions must not produce outcomes that are discriminatory or that cannot be explained to affected customers on request.
In healthcare, AI systems used for diagnosis, treatment recommendations or patient monitoring are regulated both as AI systems under the AI Act and as medical devices under the EU Medical Device Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR). The Health Inspectorate in Latvia oversees compliance with these frameworks. Businesses developing AI-powered medical tools must navigate dual conformity requirements and should engage with the Health Inspectorate early in the product development cycle.
In employment, the AI Act';s requirements for human oversight of AI-assisted hiring, performance monitoring and termination decisions intersect with Latvia';s Labour Law (Darba likums). Employers must ensure that automated decisions affecting employment relationships are subject to meaningful human review and that employees are informed when AI tools are used in processes that affect them. The Data State Inspectorate has indicated that AI-driven employee monitoring tools will be scrutinised under both the AI Act and the GDPR.
A practical scenario: a Latvian fintech company using an AI model to assess loan applications must register the system as high-risk, conduct a conformity assessment, maintain technical documentation, and ensure the model';s outputs can be explained to applicants who receive adverse decisions. Failure to do so exposes the company to sanctions from both the FKTK and the Data State Inspectorate.
A second scenario: a software company based outside the EU that sells an AI-powered recruitment platform to Latvian employers is subject to the AI Act because its product is used in Latvia. It must appoint an EU representative, register the system in the EU database, and ensure its Latvian clients receive the documentation needed to fulfil their deployer obligations.
The AI Act establishes a tiered penalty structure. Violations involving prohibited AI systems can attract fines of up to EUR 35 million or 7% of global annual turnover, whichever is higher. Non-compliance with obligations for high-risk AI systems or GPAI models can result in fines of up to EUR 15 million or 3% of global annual turnover. Providing incorrect or misleading information to supervisory authorities can lead to fines of up to EUR 7.5 million or 1.5% of global annual turnover. For small and medium-sized enterprises and start-ups, the Act provides for proportionate application of penalties, though this does not eliminate the obligation to comply.
The Data State Inspectorate has the authority to order immediate suspension of a non-compliant AI system';s operation pending remediation. This is a significant practical risk for businesses whose operations depend on AI-driven processes.
Practical compliance steps for businesses operating in Latvia include the following:
Many underestimate the time required to prepare adequate technical documentation for high-risk AI systems. This is not a form-filling exercise - it requires detailed records of training data, model architecture, testing methodology, performance metrics and risk mitigation measures. Businesses that have not begun this process should treat it as urgent.
To discuss your compliance position and next steps, contact info@vlolawfirm.com. We can assist with documents and filings across the full AI Act compliance cycle.
Does the EU AI Act apply to Latvian start-ups and small businesses?
The EU AI Act applies to all businesses that develop, place on the market, or deploy AI systems in the EU, regardless of size. However, the Act includes specific provisions for small and medium-sized enterprises and start-ups, including proportionate penalties and access to regulatory sandboxes. Smaller businesses are not exempt from the core obligations - particularly for high-risk systems - but they may benefit from reduced administrative burdens in certain areas and from sandbox participation to test compliance approaches before full deployment. The Data State Inspectorate in Latvia is the first point of contact for SMEs seeking guidance on their specific obligations.
How long does it take to achieve compliance with the AI Act for a high-risk AI system?
The timeline depends heavily on the complexity of the system and the state of existing documentation. For a well-documented AI system with clear training data records and established testing protocols, a conformity assessment and technical documentation package can be prepared in several weeks to a few months. For systems where documentation is incomplete or where the risk classification is disputed, the process can take considerably longer. Registration in the EU database for high-risk AI systems is a separate step that follows completion of the conformity assessment. Businesses should not assume that compliance can be achieved quickly - planning ahead by at least six months before a planned deployment is a reasonable baseline.
What should a Latvian company do if it is unsure whether its AI system is high-risk?
The first step is a careful review of Annex III of the AI Act, which lists the domains and use cases that trigger high-risk classification. The European AI Office has published guidance documents that provide additional clarity on borderline cases. If uncertainty remains after this review, the company should seek legal advice and consider engaging informally with the Data State Inspectorate. Proceeding with deployment of a system that may be high-risk without completing the required conformity assessment is a significant legal and reputational risk. The cost of early legal advice is substantially lower than the cost of remediation or enforcement action.
AI regulation in Latvia is now a concrete operational reality, not a future prospect. The EU AI Act imposes binding obligations on businesses that develop or deploy AI systems, with the Data State Inspectorate and sector-specific authorities actively supervising compliance. The risk-based framework requires immediate action: inventory your AI systems, classify them correctly, and initiate conformity assessments for high-risk applications without delay.
VLO Law Firms advises international clients on AI regulation in Latvia. We can assist with AI system classification, conformity assessment preparation, technical documentation, regulatory sandbox applications, and ongoing compliance monitoring. To request a consultation, contact: info@vlolawfirm.com