Our Expert in Greece
No results available
Last reviewed: August 12, 2026
The new Greek AI law, Law 5321/2026, published in the Government Gazette on 20 July 2026 (FEK A’ 114/20-07-2026), establishes Greece’s national framework for implementing the EU AI Act, Regulation (EU) 2024/1689. For businesses that develop, deploy, import or distribute artificial intelligence systems in Greece, the law triggers concrete, time-sensitive compliance obligations spanning risk classification, technical documentation, human oversight measures and governance appointments. This guide delivers a step-by-step compliance playbook designed for general counsel, compliance officers, CTOs and business leaders who need jurisdiction-specific direction rather than abstract policy summaries. Companies that have already begun setting up operations in Greece should treat AI compliance as a parallel regulatory workstream.
Before diving into the detail, here are the immediate actions every organisation using or providing AI systems in Greece should prioritise under Law 5321/2026 and the EU AI Act:
Each of these steps is unpacked in full below, with practical templates, governance structures and enforcement context.
Law 5321/2026 is Greece’s national implementing measure for the EU AI Act, which was adopted as Regulation (EU) 2024/1689 by the European Parliament and Council on 13 June 2024. The Regulation is directly applicable across the EU, meaning its substantive obligations, risk classification, conformity assessment, transparency and human oversight, bind Greek companies without further transposition. What the Greek AI law adds is the national institutional and enforcement architecture: it designates competent supervisory authorities, establishes procedures for market surveillance and enforcement actions, provides for the publication of enforcement decisions, and clarifies administrative penalties and procedural rules within the Greek legal order.
The law also amends earlier national provisions on AI and digital governance, consolidating Greece’s regulatory landscape into a single reference framework. For businesses, the practical effect is that EU AI Act compliance obligations are now enforceable on Greek soil through clearly identified national bodies, with Greek-specific procedural rules governing investigations, hearings and the imposition of sanctions.
| Date | Event | Why It Matters |
|---|---|---|
| 13 June 2024 | Regulation (EU) 2024/1689 (EU AI Act) adopted | Sets EU-wide obligations for AI providers, deployers, importers and distributors |
| 1 August 2024 | EU AI Act enters into force | Starts phased compliance deadlines across all Member States |
| 2 February 2025 | Prohibitions on unacceptable-risk AI apply | Banned practices (social scoring, real-time biometric ID in public spaces without exception, manipulative AI) become enforceable |
| 2 August 2025 | Obligations for general-purpose AI models apply | Providers of foundation / general-purpose models must comply with transparency and systemic-risk rules |
| 2 August 2026 | Main high-risk AI obligations apply | Providers and deployers of high-risk systems must meet full conformity, documentation, oversight and reporting requirements |
| 20 July 2026 | Law 5321/2026 published (FEK A’ 114/20-07-2026) | Establishes Greek competent authority, enforcement procedures, penalty framework and publication obligations |
Regulation (EU) 2024/1689, as operationalised in Greece by Law 5321/2026, applies a risk-based classification that determines the intensity of obligations. Every organisation must map each of its AI systems to one of four tiers.
The AI regulatory requirements in Greece apply to four categories of economic operators, regardless of where the AI system was developed:
If your company uses AI-powered HR screening software, automated underwriting tools, AI-driven medical devices or biometric access systems, industry observers expect those deployments to fall squarely within the high-risk category and attract the most demanding compliance obligations.
Understanding the obligations is the foundation of any AI compliance checklist for Greece. The requirements scale with the risk level of the system.
High-risk AI systems trigger the most extensive regulatory burden under both the EU AI Act and the Greek AI law. Providers must establish and maintain a quality-management system, prepare detailed technical documentation covering design, development methodology, data governance, accuracy metrics and cybersecurity measures, and undergo conformity assessment before placing the system on the market. Post-market monitoring is mandatory: providers must actively track the system’s performance, log anomalies and report serious incidents to the competent national authority.
Deployers, the businesses actually using high-risk AI, bear their own distinct set of duties. They must ensure that input data is relevant and sufficiently representative, implement human oversight measures proportionate to the system’s risks, keep logs automatically generated by the system, and inform natural persons when they are subject to an AI-driven decision in domains such as employment, creditworthiness or public services.
Operators of limited-risk AI systems must ensure that end users know they are interacting with an AI. This applies to chatbots, emotion-recognition systems and generators of synthetic content (deepfakes). The disclosure must be clear, timely and accessible. Failure to label AI-generated content properly may expose a business to enforcement action even where the underlying system poses limited safety risk.
There is no compliance pathway for unacceptable-risk AI, these systems must be decommissioned or never deployed. Businesses should audit their current AI inventory specifically for practices that could fall within the prohibited categories, including any form of social scoring, covert biometric categorisation or manipulative targeting of vulnerable groups.
| Obligation | Provider (Developer / Seller) | Deployer (Business Using System) |
|---|---|---|
| Conformity assessment | Required for high-risk systems; must complete conformity assessment procedure (self-assessment or third-party, depending on system category) and issue a declaration of conformity before placing on market | Must verify that procured AI systems have valid conformity declarations and CE marking (where applicable) before deploying |
| Technical documentation | Maintain comprehensive technical file covering system architecture, training data, risk assessment, accuracy and robustness testing, and cybersecurity measures | Maintain deployment records, logs of AI-generated decisions, input-data documentation and mitigation controls applied in production |
| Post-market monitoring | Operate a post-market monitoring system; report serious incidents and malfunctions to competent authority; implement corrective actions | Report serious incidents involving the AI system to the competent authority; cooperate with provider investigations and corrective measures |
| Human oversight | Design systems to allow effective human oversight; provide clear instructions for use | Assign qualified personnel to oversee AI outputs; ensure humans can intervene, override or halt the system |
| Transparency & disclosure | Provide deployers with information needed to fulfil transparency obligations to end users | Inform affected individuals that they are subject to AI-driven decisions; disclose AI interaction in limited-risk contexts |
This compliance playbook converts the legal obligations into eight operational steps, each with a defined owner, deliverable and timeframe. Organisations that have already obtained a Greek tax identification number (AFM) and registered their business will recognise the importance of structured regulatory workflows, the AI compliance process follows the same logic.
Owner: CTO / IT Director. Deliverable: Centralised AI system register. Catalogue every AI-powered application across business units, including third-party SaaS, embedded ML models and automated decision-making tools. Record the system name, provider, purpose, data inputs, outputs and current deployment status.
Owner: AI Compliance Officer / Legal. Deliverable: Risk classification matrix. Apply the four-tier framework to each inventoried system. Cross-reference Annex III of Regulation (EU) 2024/1689 to identify high-risk use cases. Flag any system that could fall within the prohibited category for immediate review. An AI risk assessment template tailored for Greek companies will be available as a supporting resource.
Owner: Data Protection Officer. Deliverable: Joint DPIA (GDPR + AI Act). Where AI systems process personal data, particularly in high-risk contexts, run a combined Data Protection Impact Assessment that addresses both GDPR requirements and the AI Act’s data-governance obligations. Verify lawful basis, data minimisation, purpose limitation and storage-period compliance.
Owner: Engineering Lead / CTO. Deliverable: Technical file per high-risk system. Compile system architecture descriptions, training-data provenance, testing and validation results, accuracy and robustness metrics, cybersecurity measures and instructions for use. Deployers must additionally maintain logs of AI-generated decisions and any human-override interventions.
Owner: Operations / Business Unit Leads. Deliverable: Documented oversight procedures. Assign qualified staff to supervise high-risk AI outputs. Define escalation criteria: when must a human review an AI recommendation? When can the system be overridden or halted? Train oversight personnel on the system’s limitations, known failure modes and bias risks.
Owner: Legal / Quality. Deliverable: Conformity declaration or third-party audit report. Providers of high-risk AI systems must complete the appropriate conformity assessment procedure, either self-assessment against harmonised standards or engagement of a notified body, depending on the system category under Annex III. Deployers should verify conformity evidence before activating any newly procured high-risk system.
Owner: Legal / Procurement. Deliverable: Revised vendor agreements. Insert AI-specific clauses into contracts with AI providers and licensors. Clauses should require the provider to supply the conformity declaration, technical file, post-market monitoring commitments and incident-notification obligations. Include indemnification provisions for regulatory non-compliance and audit rights. A procurement clause template for Greek businesses is a high-priority supporting resource.
Owner: AI Compliance Officer / Risk. Deliverable: AI incident-response plan. Create a protocol for identifying, documenting and reporting serious AI incidents, system malfunctions, safety hazards, fundamental-rights violations or fatalities, to the competent Greek authority. Define internal escalation paths, communication templates and remediation procedures. Test the protocol at least annually through tabletop exercises.
Sample RACI row for risk classification:
| Task | R (Responsible) | A (Accountable) | C (Consulted) | I (Informed) |
|---|---|---|---|---|
| Risk classification of AI system | AI Compliance Officer | General Counsel | CTO, DPO | Board / Audit Committee |
Sample contract clause (procurement): “The Provider warrants that the AI System has undergone conformity assessment in accordance with Regulation (EU) 2024/1689 and shall, upon request, furnish the Deployer with the conformity declaration, technical documentation, post-market monitoring plan and records of serious incidents. The Provider shall notify the Deployer within [48/72] hours of becoming aware of any serious incident or material non-compliance.”
Effective AI governance requires clearly defined internal roles. Law 5321/2026, read alongside the EU AI Act, creates practical pressure on organisations to formalise ownership of AI compliance tasks. Industry observers expect the following roles to become standard across Greek businesses deploying high-risk AI:
The likely practical effect of the new enforcement regime will be to incentivise quarterly AI governance reports to the board. Key performance indicators to track include: number of AI systems inventoried vs classified, percentage of high-risk systems with completed conformity assessments, open DPIA actions, incident-response drill results and any regulatory correspondence received from the competent authority.
| Task | R (Responsible) | A (Accountable) | C (Consulted) | I (Informed) |
|---|---|---|---|---|
| AI system inventory | CTO | AI Compliance Officer | Business Unit Leads | Board |
| Risk classification | AI Compliance Officer | General Counsel | CTO, DPO | Board |
| DPIA (joint GDPR/AI) | DPO | General Counsel | AI Compliance Officer, CTO | Board, HDPA (if required) |
| Technical documentation | CTO / Engineering | AI Compliance Officer | Legal | Board |
| Incident reporting | AI Compliance Officer | General Counsel | CTO, DPO | Board, Competent Authority |
The intersection of GDPR and the EU AI Act, and by extension Law 5321/2026, is one of the most operationally complex areas for Greek businesses. AI systems routinely process personal data at scale, making GDPR compliance a prerequisite rather than a parallel track. The Hellenic Data Protection Authority (HDPA) retains its supervisory competence over personal-data processing, and early indications suggest it will coordinate closely with the designated AI competent authority on enforcement involving AI-driven data processing.
A joint GDPR/AI assessment is advisable whenever a high-risk AI system processes personal data as a core function, for example, CV-screening tools, biometric access systems, credit-scoring models or healthcare triage algorithms. The DPIA required under Article 35 of the GDPR should be expanded to incorporate the AI Act’s data-governance requirements: training-data representativeness, bias testing, accuracy measurement and transparency disclosure. Where the DPIA indicates that the processing is likely to result in a high risk to individuals’ rights and freedoms that cannot be mitigated, prior consultation with the HDPA under Article 36 of the GDPR is mandatory.
Additionally, where sector-specific rules apply (financial services, healthcare, employment), businesses should verify whether the HDPA or another sectoral regulator should be the primary point of contact.
Law 5321/2026 converts the EU AI Act’s enforcement provisions into Greek administrative procedure. The law designates the competent national authority responsible for market surveillance, investigations and the imposition of administrative sanctions. Regulation (EU) 2024/1689 sets maximum penalty thresholds, up to €35 million or 7% of global annual turnover for prohibited AI practices, up to €15 million or 3% for other infringements, and the Greek AI law provides the procedural machinery for imposing those fines domestically, including hearing rights, appeal routes and publication of enforcement decisions.
The publication requirement is significant: enforcement decisions may be made public, which amplifies reputational risk beyond the financial penalty itself. For Greek companies or multinationals with Greek operations, this creates a powerful incentive to invest proactively in compliance rather than risk public censure.
Compliance with the Greek AI law is not a one-off project, it requires ongoing governance, periodic reassessment and continuous monitoring as delegated and implementing acts are issued at EU level and as the competent Greek authority publishes additional guidance. Businesses operating in Greece should begin with the eight-step checklist outlined above and consider engaging qualified legal counsel to conduct a gap analysis tailored to their specific AI portfolio and sector.
For companies navigating the broader landscape of doing business in Greece, Global Law Experts maintains a directory of specialist lawyers with expertise in regulatory compliance, technology law and corporate governance across Greek jurisdictions. Proactive investment in AI compliance today reduces enforcement exposure, protects reputation and positions your organisation as a trusted operator under the new Greek AI law framework.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Diomidis Papacharalampous at P&C LAW FIRM, a member of the Global Law Experts network.
posted 18 minutes ago
posted 44 minutes ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message