Trackers
Trackers

AI Regulation in Lithuania: 2026 Update

AI regulation in Lithuania is shaped primarily by the EU AI Act, the first comprehensive binding legal framework for artificial intelligence in the world, which applies directly across all EU member states including Lithuania. For businesses operating in or from Lithuania, compliance is not optional - the Act creates hard obligations, tiered by risk, with significant penalties for non-compliance. This guide covers the current regulatory landscape, the national implementation picture, the roles of competent authorities, key obligations for businesses, and what founders and managers should prioritise right now.

The EU AI Act and its direct effect in Lithuania

The EU AI Act is an EU regulation, meaning it applies directly in Lithuania without requiring separate national transposition. It entered into force in stages, with the most critical provisions - including rules on prohibited AI practices and obligations for high-risk AI systems - now in effect or entering effect on a rolling basis.

The Act classifies AI systems into four risk tiers: unacceptable risk (prohibited), high risk, limited risk, and minimal risk. Each tier carries a distinct set of obligations. Businesses in Lithuania that develop, deploy, import or distribute AI systems must identify which tier applies to their products and services before they place them on the market or put them into service.

Prohibited AI practices under the Act include systems that use subliminal manipulation to distort behaviour, exploit vulnerabilities of specific groups, enable real-time remote biometric identification in public spaces by law enforcement in most circumstances, and social scoring by public authorities. These prohibitions applied from an early stage of the Act';s rollout and are fully binding in Lithuania now.

High-risk AI systems - covering areas such as critical infrastructure, education, employment, essential private and public services, law enforcement, migration, and administration of justice - face the most demanding compliance requirements. Providers of such systems must implement risk management systems, use high-quality training data, maintain technical documentation, ensure human oversight, and register their systems in the EU database for high-risk AI.

Lithuania';s national AI strategy and competent authorities

Lithuania has developed a national AI strategy that aligns with the EU';s broader ambitions, emphasising digital transformation, public sector modernisation and the development of a competitive AI ecosystem. The strategy sets out priorities for AI adoption in healthcare, public administration and the private sector, and identifies investment in AI skills and infrastructure as a national priority.

For enforcement of the EU AI Act, Lithuania has designated a national competent authority responsible for market surveillance and enforcement. The State Data Inspectorate (Valstybinė duomenų apsaugos inspekcija), which already oversees GDPR compliance, plays a central role in the AI regulatory framework, particularly where AI systems process personal data. Coordination between the data protection authority and other sectoral regulators - such as those overseeing financial services, healthcare and telecommunications - is a key feature of the national enforcement architecture.

The Communications Regulatory Authority (Ryšių reguliavimo tarnyba) is relevant for AI systems deployed in electronic communications and digital services. In the financial sector, the Bank of Lithuania (Lietuvos bankas) supervises AI applications used by regulated financial institutions, including credit institutions, payment service providers and investment firms. Businesses must identify which regulator has primary oversight of their specific AI use case.

Lithuania has also been active in EU-level coordination through the European AI Office, which was established to support consistent application of the AI Act across member states. Lithuanian authorities participate in this coordination structure, which matters for businesses operating cross-border within the EU.

High-risk AI obligations for businesses operating in Lithuania

For businesses that develop or deploy high-risk AI systems in Lithuania, the compliance burden is substantial. The EU AI Act sets out a detailed list of requirements that providers - meaning those who develop and place AI systems on the market - must meet before their systems can be used.

Key obligations for providers of high-risk AI systems include:

  • Establishing and maintaining a risk management system throughout the AI system';s lifecycle.
  • Ensuring training, validation and testing datasets meet quality criteria and are relevant, representative and free of errors to the extent possible.
  • Preparing and keeping up to date technical documentation that demonstrates conformity with the Act';s requirements.
  • Implementing automatic logging of events to enable traceability.
  • Designing systems to allow effective human oversight by natural persons.

Deployers - meaning organisations that use high-risk AI systems in a professional context - also carry obligations. They must use systems in accordance with the provider';s instructions, monitor operation, ensure human oversight is in place, and report serious incidents to the relevant authority. A common mistake among Lithuanian businesses is assuming that because they did not develop the AI system themselves, they carry no compliance responsibility. Deployers face real obligations and real penalties.

Conformity assessment is required before a high-risk AI system is placed on the market. For many categories, providers can conduct a self-assessment against harmonised standards. For certain high-risk categories - such as biometric identification systems - third-party conformity assessment by a notified body is mandatory. Lithuania has notified bodies operating in relevant sectors, and businesses should confirm whether their system requires third-party assessment early in the development process.

Registration in the EU database for high-risk AI systems is a hard requirement. Providers must register before placing the system on the market. Deployers of certain high-risk systems used in public-facing contexts must also register. Failure to register is a clear compliance failure that regulators can identify without conducting a detailed technical audit.

If your business develops or deploys AI systems that may fall into the high-risk category, reaching out early for legal structuring advice is worthwhile. We can help structure the setup correctly the first time. Contact info@vlolawfirm.com for an initial consultation.

GDPR intersection with AI regulation in Lithuania

AI systems that process personal data - which covers the vast majority of commercially deployed AI - must comply with both the EU AI Act and the General Data Protection Regulation (GDPR). Lithuania has a mature GDPR enforcement environment, with the State Data Inspectorate having issued decisions and guidance on data processing practices since the regulation came into force.

The intersection of GDPR and AI creates layered obligations. Under GDPR, individuals have rights including the right not to be subject to solely automated decision-making that produces legal or similarly significant effects, unless specific conditions are met. Article 22 of GDPR is directly relevant to AI systems used in credit scoring, recruitment, insurance pricing and similar contexts. Lithuanian businesses using AI in these areas must ensure they have a lawful basis for automated processing and that appropriate safeguards - including the right to human review - are in place.

Data protection impact assessments (DPIAs) are required under GDPR for high-risk processing activities. Where an AI system also qualifies as high-risk under the EU AI Act, the DPIA and the AI Act';s risk management documentation should be coordinated to avoid duplication and ensure consistency. In practice, many businesses treat these as separate workstreams, which creates inefficiency and gaps.

The State Data Inspectorate has signalled that it will treat AI-related data protection failures as a priority enforcement area. Businesses should expect that AI systems processing personal data will receive scrutiny from both an AI Act and a GDPR perspective. Maintaining clear records of processing activities, data flows and automated decision-making logic is essential.

A non-obvious requirement is that GDPR';s data minimisation principle applies to AI training data. If a Lithuanian business trains an AI model on personal data, it must ensure that only data necessary for the specified purpose is used, that the data is accurate, and that retention periods are respected. Using historical datasets without reviewing them for GDPR compliance before training is a common and costly mistake.

Sector-specific AI rules in Lithuania

Beyond the horizontal EU AI Act framework, several sectors in Lithuania have specific rules that interact with AI deployment. Understanding these sector-specific layers is essential for businesses in regulated industries.

In financial services, the Bank of Lithuania has issued guidance on the use of algorithmic decision-making and AI in credit assessment, anti-money laundering screening and customer onboarding. Financial institutions must ensure that AI systems used in regulated activities are explainable, auditable and subject to human oversight. The Bank of Lithuania expects institutions to be able to demonstrate to supervisors how AI-driven decisions are made and to show that model risk management frameworks cover AI models.

In healthcare, AI systems used for diagnosis, treatment recommendations or patient monitoring are likely to qualify as medical devices under EU medical device regulations, in addition to being subject to the EU AI Act. The State Medicines Control Agency (Valstybinė vaistų kontrolės agentūra) is the relevant authority for medical device regulation. Businesses developing AI-powered health tools must navigate both regulatory frameworks simultaneously.

In public procurement and public administration, Lithuanian law requires transparency and accountability in automated decision-making by public authorities. The Law on Public Administration sets out principles of legality, proportionality and transparency that apply when public bodies use AI to support or make administrative decisions. Public sector AI deployments must be documented and, where they affect individuals'; rights, subject to review mechanisms.

Media and content platforms operating in Lithuania are subject to the Law on the Provision of Information to the Public, which has been updated to address AI-generated content and deepfakes in the context of electoral integrity and public information. Platforms using AI to generate or recommend content should review their obligations under this framework.

Compliance steps for businesses in Lithuania

Practical compliance with AI regulation in Lithuania requires a structured approach. Businesses that treat AI compliance as a one-time exercise rather than an ongoing programme will find themselves exposed as the regulatory framework matures and enforcement intensifies.

A practical compliance programme for a Lithuanian business should address the following:

  • AI system inventory: identify all AI systems in use or under development, classify them by risk tier under the EU AI Act, and document the classification rationale.
  • Gap analysis: compare current practices against the requirements applicable to each risk tier, and identify gaps in documentation, risk management, human oversight and data governance.
  • Technical documentation: prepare or update technical documentation for high-risk systems, ensuring it covers the system';s intended purpose, design logic, training data, performance metrics and limitations.
  • Governance and accountability: designate internal responsibility for AI compliance, establish escalation procedures for incidents, and ensure senior management is informed of material AI risks.
  • Supplier and partner due diligence: where AI systems are procured from third-party providers, review contracts to ensure obligations are clearly allocated and that providers can demonstrate conformity.

Scenario one: a Lithuanian fintech company uses an AI model to assess creditworthiness for consumer loans. The system falls within the high-risk category under the EU AI Act and is also subject to GDPR';s Article 22 and the Bank of Lithuania';s model risk guidance. The company must conduct a conformity assessment, register the system in the EU database, implement a DPIA, and ensure borrowers can request human review of automated decisions.

Scenario two: a Lithuanian software company develops an AI-powered recruitment tool that screens CVs and ranks candidates. This is a high-risk use case under the EU AI Act. The company must comply with provider obligations, including technical documentation, risk management and registration, even if the tool is used internally rather than sold to third parties. Treating an internal deployment as outside the Act';s scope is a common and serious mistake.

For businesses that need to move quickly on compliance or are uncertain about their risk classification, specialist legal advice is the most efficient path. We can assist with documents, filings and regulatory strategy. Contact info@vlolawfirm.com to discuss your situation.

FAQ

What are the penalties for non-compliance with the EU AI Act in Lithuania?

The EU AI Act sets out a tiered penalty structure. Violations involving prohibited AI practices can attract fines of up to 35 million EUR or 7% of global annual turnover, whichever is higher. Non-compliance with other obligations - such as failing to meet requirements for high-risk systems - can result in fines of up to 15 million EUR or 3% of global annual turnover. Providing incorrect or misleading information to authorities carries lower but still significant penalties. Lithuanian enforcement authorities have the power to conduct market surveillance, request documentation, and impose these fines. Businesses should not assume that enforcement will be slow to develop - the regulatory infrastructure is in place and active.

How long does it take to achieve compliance with the EU AI Act for a high-risk AI system?

The timeline depends heavily on the complexity of the system and the maturity of the organisation';s existing governance frameworks. For a business starting from scratch, a realistic compliance programme for a high-risk AI system typically takes several months, covering inventory and classification, gap analysis, documentation preparation, conformity assessment and registration. Businesses that already have strong data governance and risk management frameworks in place can move faster. The key risk is underestimating the documentation burden - technical documentation for high-risk systems is detailed and must be maintained throughout the system';s lifecycle, not just at the point of initial compliance.

Does the EU AI Act apply to small and medium-sized enterprises in Lithuania?

Yes, the EU AI Act applies to SMEs, though it includes some proportionality provisions designed to reduce the burden on smaller businesses. SMEs that are providers of high-risk AI systems benefit from reduced fees for conformity assessment by notified bodies and from regulatory sandboxes that allow testing of AI systems in a controlled environment with regulatory support. Lithuania';s competent authorities are expected to operate or participate in such sandboxes. However, the core obligations - risk management, technical documentation, human oversight, registration - apply to SMEs just as they apply to large enterprises. SMEs that develop or deploy high-risk AI should not assume they are exempt.

Conclusion

AI regulation in Lithuania is now a live compliance matter, not a future concern. The EU AI Act is in force, national authorities are active, and the intersection with GDPR creates layered obligations that require coordinated management. Businesses that invest in structured compliance programmes now will be better positioned as enforcement intensifies and as the regulatory framework continues to develop.

VLO Law Firms advises international clients on AI regulation in Lithuania. We can assist with risk classification, technical documentation, conformity assessment preparation, GDPR coordination, regulatory filings, and ongoing compliance programme design. To request a consultation, contact: info@vlolawfirm.com