AI regulation in Slovakia is shaped primarily by the EU AI Act, the world';s first comprehensive legal framework for artificial intelligence, which applies directly across all EU member states including Slovakia. Businesses developing, deploying or importing AI systems in Slovakia must now navigate binding obligations, tiered risk classifications and enforcement mechanisms that carry significant penalties. This guide explains the current regulatory landscape, the competent Slovak authorities, compliance timelines, sector-specific considerations, and the practical steps that companies operating in Slovakia need to take.
The EU AI Act is a directly applicable EU regulation, meaning it does not require transposition into Slovak national law to take effect. It entered into force across the EU and is being phased in over a multi-year schedule. The Act classifies AI systems into four risk tiers: unacceptable risk (prohibited), high risk (heavily regulated), limited risk (transparency obligations) and minimal risk (largely unregulated).
For businesses in Slovakia, the most immediate practical consequence is that the prohibition on unacceptable-risk AI systems - such as social scoring by public authorities, real-time biometric surveillance in public spaces with narrow exceptions, and AI that exploits psychological vulnerabilities - is already in effect. Any Slovak company or foreign company operating in Slovakia that deploys such systems faces enforcement action.
High-risk AI systems cover a broad range of applications: AI used in recruitment and employment decisions, credit scoring, educational assessment, critical infrastructure management, law enforcement, migration and border control, and administration of justice. Providers and deployers of these systems in Slovakia must meet requirements on data governance, transparency, human oversight, accuracy and robustness, and must register their systems in the EU database maintained by the European Commission.
The limited-risk category applies to systems such as chatbots and deepfake generators, which must disclose to users that they are interacting with AI. This obligation is already relevant for Slovak businesses running customer-facing AI tools.
Slovakia has designated the Slovak Office for Standards, Metrology and Testing (ÚNMS SR) as the national market surveillance authority for the AI Act, alongside sector-specific regulators who retain oversight in their domains. The National Bank of Slovakia (NBS) supervises AI used in financial services. The Data Protection Authority (Úrad na ochranu osobných údajov) remains the competent body where AI processing intersects with personal data under the GDPR.
The Slovak government has also been developing a national AI strategy, building on the earlier National AI Strategy adopted in line with the EU';s coordinated plan on AI. Recent updates to this strategy emphasise investment in AI research, public-sector digitisation and upskilling of the workforce. While the strategy is not itself a binding legal instrument, it signals regulatory priorities and shapes how public procurement of AI systems will be handled.
Slovakia participates in the European AI Office, the central EU body responsible for overseeing general-purpose AI models (GPAI). Providers of GPAI models - including large language models - that are made available in Slovakia must comply with the AI Act';s GPAI chapter, which includes transparency obligations, copyright compliance documentation and, for models posing systemic risk, additional adversarial testing requirements.
A common mistake among foreign businesses entering Slovakia is assuming that national implementation acts are required before the AI Act applies. They are not. The regulation is self-executing. What Slovakia must do at the national level is designate and resource its market surveillance authorities, establish penalties within the ranges set by the AI Act, and create national sandboxes for AI testing - the last of which is an ongoing process.
Every business operating in Slovakia that develops or deploys AI should begin with a systematic risk classification exercise. The starting point is the AI Act';s Annex III, which lists the high-risk use cases. If a system falls within Annex III, the provider must conduct a conformity assessment before placing the system on the market or putting it into service.
For most high-risk systems, the conformity assessment can be conducted internally, without a notified body, provided the provider follows the harmonised standards that are being developed by European standardisation organisations (CEN/CENELEC). Where harmonised standards do not yet exist, providers must demonstrate compliance with the Act';s requirements through their own documented methodology.
In practice, Slovak companies should consider the following when classifying their AI systems:
A non-obvious requirement is that deployers - not just providers - carry obligations under the AI Act. A Slovak company that purchases a high-risk AI system from a third-party vendor and deploys it in its HR process is a deployer and must implement human oversight measures, conduct fundamental rights impact assessments where required, and maintain logs of system operation.
The AI Act';s obligations are being phased in over a schedule that businesses in Slovakia must track carefully. The prohibition on unacceptable-risk AI is already in force. Obligations on GPAI model providers followed shortly after. The full set of obligations for high-risk AI systems - including conformity assessments, technical documentation, EU database registration and post-market monitoring - apply from a later phase in the schedule.
For high-risk AI providers, the core compliance programme involves several parallel workstreams. Technical documentation must describe the system';s purpose, architecture, training data, performance metrics and limitations. A quality management system must be established, covering risk management, data governance, testing protocols and incident reporting. Post-market monitoring must be ongoing, with serious incidents reported to the relevant Slovak market surveillance authority.
Deployers of high-risk AI in Slovakia must implement the instructions for use provided by the provider, assign human oversight to a qualified person, and - where the deployer is a public body or the system affects a significant number of people - conduct a fundamental rights impact assessment. This assessment must be registered with the competent authority before deployment.
Many underestimate the documentation burden. The AI Act requires technical documentation to be maintained and updated throughout the system';s lifecycle, not just at the point of initial conformity assessment. For companies running multiple AI systems, this creates a significant ongoing compliance workload.
If your business is assessing its AI portfolio against these requirements, we can assist with classification, documentation and regulatory filings. Contact info@vlolawfirm.com for a structured consultation.
Beyond the horizontal AI Act, several sector-specific frameworks apply to AI in Slovakia and interact with the general regulation.
In financial services, the NBS applies EBA and EIOPA guidelines on the use of AI and machine learning in credit risk assessment, fraud detection and algorithmic trading. Slovak banks and insurers using AI must demonstrate model explainability, fairness and auditability to the NBS. The AI Act';s high-risk classification of AI used in creditworthiness assessment aligns with these existing supervisory expectations, but the AI Act adds formal conformity assessment requirements that go beyond current NBS guidance.
In healthcare, AI used as a medical device is regulated under the EU Medical Device Regulation (MDR) and the In Vitro Diagnostic Regulation (IVDR), administered in Slovakia by the State Institute for Drug Control (ŠÚKL). Where an AI system qualifies as a medical device, the MDR conformity assessment takes precedence, but the AI Act';s requirements apply in parallel where the system is also high-risk under Annex III.
In employment, Slovak labour law intersects with AI regulation in a specific way. The Labour Code imposes obligations on employers regarding transparency in automated decision-making affecting employees. Where an employer uses AI to screen applications, assess performance or determine working conditions, both the AI Act';s deployer obligations and the GDPR';s Article 22 provisions on automated individual decision-making apply simultaneously.
In public administration, Slovak public bodies procuring AI systems must comply with the AI Act as deployers and must also follow public procurement rules that increasingly require AI suppliers to demonstrate regulatory compliance as a condition of contract award.
The AI Act sets maximum penalties at the EU level, and Slovakia must establish a national penalty regime within those bounds. Violations involving prohibited AI practices attract the highest fines. High-risk AI non-compliance attracts substantial fines. Providing incorrect information to authorities attracts a lower but still significant penalty tier. These are maximum figures; actual penalties will depend on the severity, duration and nature of the infringement, and on the size of the company.
The Slovak market surveillance authority has powers to request documentation, conduct audits, order corrective measures and, in serious cases, withdraw a system from the market. The European AI Office has direct enforcement powers over GPAI model providers.
Practical risk management for companies in Slovakia involves several concrete steps. First, build an AI inventory - a register of all AI systems in use or development, with their risk classification and the legal basis for that classification. Second, assign clear internal ownership: a designated AI compliance officer or team responsible for monitoring regulatory developments and maintaining documentation. Third, establish a vendor management process that requires AI suppliers to provide the technical documentation and conformity declarations that the AI Act requires.
A common mistake is treating AI compliance as a one-time project rather than an ongoing programme. The AI Act requires post-market monitoring, incident reporting and documentation updates throughout a system';s operational life. Companies that complete a conformity assessment and then treat the matter as closed will find themselves non-compliant as their systems evolve.
Does the EU AI Act apply to Slovak companies that only use AI internally, with no customer-facing applications?
Yes, in many cases. The AI Act';s high-risk classification covers AI used in employment decisions, including internal HR tools used to screen candidates, assess employee performance or determine working conditions. A Slovak company using such a system is a deployer under the Act and must implement human oversight, maintain logs and, in certain cases, conduct a fundamental rights impact assessment. The fact that the system is not customer-facing does not remove the obligation. However, AI systems used purely for internal administrative tasks with no impact on individuals - such as automated scheduling of meeting rooms - are unlikely to fall within the high-risk categories.
How long does it take to complete a conformity assessment for a high-risk AI system in Slovakia?
The timeline depends heavily on the complexity of the system and the maturity of the company';s documentation. For a well-documented system with an established quality management system, a conformity assessment can be completed in a matter of weeks. For a system that requires significant documentation work, data governance improvements and testing, the process can take several months. Companies should also factor in the time required to register the system in the EU database maintained by the European Commission, which must be done before the system is placed on the market. Starting early and conducting a gap analysis against the Act';s requirements is the most effective way to manage the timeline.
What should a foreign company do before deploying an AI system in Slovakia?
A foreign company deploying an AI system in Slovakia must first determine whether it is acting as a provider or a deployer under the AI Act. If the company developed the system, it is a provider and must complete a conformity assessment, prepare technical documentation and appoint an EU representative if it has no establishment in the EU. If the company is purchasing a system from a third party and deploying it in Slovakia, it is a deployer and must verify that the provider has met their obligations, implement human oversight, and comply with deployer-specific requirements. In either case, the company should also assess whether Slovak sector-specific rules - such as NBS guidelines for financial services or ŠÚKL requirements for medical devices - apply alongside the AI Act.
AI regulation in Slovakia is now a substantive compliance discipline, not a future concern. The EU AI Act applies directly, enforcement authorities are designated, and the obligations on providers and deployers of high-risk AI are concrete and enforceable. Slovak and foreign businesses operating in Slovakia should treat AI compliance as an ongoing programme, beginning with a systematic inventory and risk classification of their AI systems.
VLO Law Firms advises international clients on AI regulation in Slovakia. We can assist with risk classification, conformity assessment preparation, technical documentation review, regulatory filings and ongoing compliance monitoring. To request a consultation, contact: info@vlolawfirm.com