[codicts-css-switcher id=”346″]

Global Law Experts Logo
greek ai law

Greek AI Law 5321/2026: Practical Compliance Guide for Businesses

By Global Law Experts
– posted 1 hour ago

Last reviewed: August 12, 2026

The new Greek AI law, Law 5321/2026, published in the Government Gazette on 20 July 2026 (FEK A’ 114/20-07-2026), establishes Greece’s national framework for implementing the EU AI Act, Regulation (EU) 2024/1689. For businesses that develop, deploy, import or distribute artificial intelligence systems in Greece, the law triggers concrete, time-sensitive compliance obligations spanning risk classification, technical documentation, human oversight measures and governance appointments. This guide delivers a step-by-step compliance playbook designed for general counsel, compliance officers, CTOs and business leaders who need jurisdiction-specific direction rather than abstract policy summaries. Companies that have already begun setting up operations in Greece should treat AI compliance as a parallel regulatory workstream.

TL;DR, What Businesses Must Do Now

Before diving into the detail, here are the immediate actions every organisation using or providing AI systems in Greece should prioritise under Law 5321/2026 and the EU AI Act:

  • Inventory all AI systems. Catalogue every AI-powered tool, model and automated decision-making system across business units, including third-party and SaaS solutions.
  • Classify each system by risk level. Apply the four-tier risk classification (unacceptable, high, limited, minimal) set out in Regulation (EU) 2024/1689 and reflected in the Greek AI law.
  • Run a Data Protection Impact Assessment (DPIA). Where AI systems process personal data, a joint DPIA satisfying both GDPR and AI Act requirements is critical.
  • Appoint a Responsible Person / AI Compliance Officer. Designate internal ownership of AI governance obligations, reporting lines and incident-response authority.
  • Prepare technical documentation and recordkeeping. Build or update technical files, risk assessments, training-data descriptions, accuracy metrics and decision logs for every high-risk system.
  • Implement human oversight controls. Ensure that humans can intervene in, override or shut down high-risk AI outputs, and document the oversight procedures.
  • Update contracts and procurement clauses. Require AI providers to supply conformity declarations, technical files and incident-reporting commitments before procurement.
  • Establish incident response and reporting processes. Create a clear protocol for detecting, recording and reporting serious AI incidents to the competent Greek authority.

Each of these steps is unpacked in full below, with practical templates, governance structures and enforcement context.

Overview: Greek AI Law 5321/2026 and EU AI Act Compliance

Law 5321/2026 is Greece’s national implementing measure for the EU AI Act, which was adopted as Regulation (EU) 2024/1689 by the European Parliament and Council on 13 June 2024. The Regulation is directly applicable across the EU, meaning its substantive obligations, risk classification, conformity assessment, transparency and human oversight, bind Greek companies without further transposition. What the Greek AI law adds is the national institutional and enforcement architecture: it designates competent supervisory authorities, establishes procedures for market surveillance and enforcement actions, provides for the publication of enforcement decisions, and clarifies administrative penalties and procedural rules within the Greek legal order.

The law also amends earlier national provisions on AI and digital governance, consolidating Greece’s regulatory landscape into a single reference framework. For businesses, the practical effect is that EU AI Act compliance obligations are now enforceable on Greek soil through clearly identified national bodies, with Greek-specific procedural rules governing investigations, hearings and the imposition of sanctions.

Key Dates and References

Date Event Why It Matters
13 June 2024 Regulation (EU) 2024/1689 (EU AI Act) adopted Sets EU-wide obligations for AI providers, deployers, importers and distributors
1 August 2024 EU AI Act enters into force Starts phased compliance deadlines across all Member States
2 February 2025 Prohibitions on unacceptable-risk AI apply Banned practices (social scoring, real-time biometric ID in public spaces without exception, manipulative AI) become enforceable
2 August 2025 Obligations for general-purpose AI models apply Providers of foundation / general-purpose models must comply with transparency and systemic-risk rules
2 August 2026 Main high-risk AI obligations apply Providers and deployers of high-risk systems must meet full conformity, documentation, oversight and reporting requirements
20 July 2026 Law 5321/2026 published (FEK A’ 114/20-07-2026) Establishes Greek competent authority, enforcement procedures, penalty framework and publication obligations

Scope and Risk Classification Under the Greek AI Law: Which Systems Are Covered

Regulation (EU) 2024/1689, as operationalised in Greece by Law 5321/2026, applies a risk-based classification that determines the intensity of obligations. Every organisation must map each of its AI systems to one of four tiers.

The Four Risk Categories

  • Unacceptable risk (prohibited). AI practices that pose a clear threat to fundamental rights are banned outright. Examples include social-scoring systems by public authorities, real-time remote biometric identification in publicly accessible spaces (subject to narrow law-enforcement exceptions), and AI that deploys subliminal, manipulative or exploitative techniques causing significant harm.
  • High risk. Systems listed in Annex III of the Regulation or embedded in products already subject to EU harmonised safety legislation. Categories include AI used in recruitment and employment screening, credit scoring, critical infrastructure management, education and vocational training assessments, law enforcement, migration and asylum processing, and healthcare diagnostics or triage.
  • Limited risk (transparency obligations). AI systems that interact with natural persons, chatbots, emotion-recognition tools, deep-fake generators, must disclose that the user is interacting with or consuming AI-generated content.
  • Minimal risk. Systems posing negligible risk (spam filters, AI-assisted inventory management, basic recommendation engines) face no mandatory obligations, though voluntary codes of conduct are encouraged.

Which Businesses Are in Scope

The AI regulatory requirements in Greece apply to four categories of economic operators, regardless of where the AI system was developed:

  • Providers, organisations that develop or commission an AI system and place it on the market or put it into service under their own name or trademark.
  • Deployers, businesses that use an AI system under their authority in a professional capacity (this captures most Greek enterprises purchasing or licensing AI tools).
  • Importers, entities that bring an AI system from a non-EU country onto the Greek / EU market.
  • Distributors, businesses in the supply chain that make an AI system available on the market without being provider or importer.

If your company uses AI-powered HR screening software, automated underwriting tools, AI-driven medical devices or biometric access systems, industry observers expect those deployments to fall squarely within the high-risk category and attract the most demanding compliance obligations.

Core Obligations by Risk Class, AI Regulatory Requirements Greece

Understanding the obligations is the foundation of any AI compliance checklist for Greece. The requirements scale with the risk level of the system.

High-Risk Systems: Full Compliance Suite

High-risk AI systems trigger the most extensive regulatory burden under both the EU AI Act and the Greek AI law. Providers must establish and maintain a quality-management system, prepare detailed technical documentation covering design, development methodology, data governance, accuracy metrics and cybersecurity measures, and undergo conformity assessment before placing the system on the market. Post-market monitoring is mandatory: providers must actively track the system’s performance, log anomalies and report serious incidents to the competent national authority.

Deployers, the businesses actually using high-risk AI, bear their own distinct set of duties. They must ensure that input data is relevant and sufficiently representative, implement human oversight measures proportionate to the system’s risks, keep logs automatically generated by the system, and inform natural persons when they are subject to an AI-driven decision in domains such as employment, creditworthiness or public services.

Limited-Risk Systems: Transparency First

Operators of limited-risk AI systems must ensure that end users know they are interacting with an AI. This applies to chatbots, emotion-recognition systems and generators of synthetic content (deepfakes). The disclosure must be clear, timely and accessible. Failure to label AI-generated content properly may expose a business to enforcement action even where the underlying system poses limited safety risk.

Unacceptable-Risk Systems: Outright Prohibition

There is no compliance pathway for unacceptable-risk AI, these systems must be decommissioned or never deployed. Businesses should audit their current AI inventory specifically for practices that could fall within the prohibited categories, including any form of social scoring, covert biometric categorisation or manipulative targeting of vulnerable groups.

Obligations Comparison Table, Provider vs Deployer

Obligation Provider (Developer / Seller) Deployer (Business Using System)
Conformity assessment Required for high-risk systems; must complete conformity assessment procedure (self-assessment or third-party, depending on system category) and issue a declaration of conformity before placing on market Must verify that procured AI systems have valid conformity declarations and CE marking (where applicable) before deploying
Technical documentation Maintain comprehensive technical file covering system architecture, training data, risk assessment, accuracy and robustness testing, and cybersecurity measures Maintain deployment records, logs of AI-generated decisions, input-data documentation and mitigation controls applied in production
Post-market monitoring Operate a post-market monitoring system; report serious incidents and malfunctions to competent authority; implement corrective actions Report serious incidents involving the AI system to the competent authority; cooperate with provider investigations and corrective measures
Human oversight Design systems to allow effective human oversight; provide clear instructions for use Assign qualified personnel to oversee AI outputs; ensure humans can intervene, override or halt the system
Transparency & disclosure Provide deployers with information needed to fulfil transparency obligations to end users Inform affected individuals that they are subject to AI-driven decisions; disclose AI interaction in limited-risk contexts

Practical 8-Step AI Compliance Checklist for Greek Businesses

This compliance playbook converts the legal obligations into eight operational steps, each with a defined owner, deliverable and timeframe. Organisations that have already obtained a Greek tax identification number (AFM) and registered their business will recognise the importance of structured regulatory workflows, the AI compliance process follows the same logic.

Step 1: Inventory All AI Systems

Owner: CTO / IT Director. Deliverable: Centralised AI system register. Catalogue every AI-powered application across business units, including third-party SaaS, embedded ML models and automated decision-making tools. Record the system name, provider, purpose, data inputs, outputs and current deployment status.

Step 2: Classify Each System by Risk Level

Owner: AI Compliance Officer / Legal. Deliverable: Risk classification matrix. Apply the four-tier framework to each inventoried system. Cross-reference Annex III of Regulation (EU) 2024/1689 to identify high-risk use cases. Flag any system that could fall within the prohibited category for immediate review. An AI risk assessment template tailored for Greek companies will be available as a supporting resource.

Step 3: Align Data Governance with GDPR

Owner: Data Protection Officer. Deliverable: Joint DPIA (GDPR + AI Act). Where AI systems process personal data, particularly in high-risk contexts, run a combined Data Protection Impact Assessment that addresses both GDPR requirements and the AI Act’s data-governance obligations. Verify lawful basis, data minimisation, purpose limitation and storage-period compliance.

Step 4: Prepare Technical Documentation and Recordkeeping

Owner: Engineering Lead / CTO. Deliverable: Technical file per high-risk system. Compile system architecture descriptions, training-data provenance, testing and validation results, accuracy and robustness metrics, cybersecurity measures and instructions for use. Deployers must additionally maintain logs of AI-generated decisions and any human-override interventions.

Step 5: Implement Human Oversight and Human-in-the-Loop Controls

Owner: Operations / Business Unit Leads. Deliverable: Documented oversight procedures. Assign qualified staff to supervise high-risk AI outputs. Define escalation criteria: when must a human review an AI recommendation? When can the system be overridden or halted? Train oversight personnel on the system’s limitations, known failure modes and bias risks.

Step 6: Complete Conformity Assessment and Third-Party Audits

Owner: Legal / Quality. Deliverable: Conformity declaration or third-party audit report. Providers of high-risk AI systems must complete the appropriate conformity assessment procedure, either self-assessment against harmonised standards or engagement of a notified body, depending on the system category under Annex III. Deployers should verify conformity evidence before activating any newly procured high-risk system.

Step 7: Update Contracts and Procurement Clauses

Owner: Legal / Procurement. Deliverable: Revised vendor agreements. Insert AI-specific clauses into contracts with AI providers and licensors. Clauses should require the provider to supply the conformity declaration, technical file, post-market monitoring commitments and incident-notification obligations. Include indemnification provisions for regulatory non-compliance and audit rights. A procurement clause template for Greek businesses is a high-priority supporting resource.

Step 8: Establish Incident Response and Reporting Processes

Owner: AI Compliance Officer / Risk. Deliverable: AI incident-response plan. Create a protocol for identifying, documenting and reporting serious AI incidents, system malfunctions, safety hazards, fundamental-rights violations or fatalities, to the competent Greek authority. Define internal escalation paths, communication templates and remediation procedures. Test the protocol at least annually through tabletop exercises.

Template Snippets

Sample RACI row for risk classification:

Task R (Responsible) A (Accountable) C (Consulted) I (Informed)
Risk classification of AI system AI Compliance Officer General Counsel CTO, DPO Board / Audit Committee

Sample contract clause (procurement): “The Provider warrants that the AI System has undergone conformity assessment in accordance with Regulation (EU) 2024/1689 and shall, upon request, furnish the Deployer with the conformity declaration, technical documentation, post-market monitoring plan and records of serious incidents. The Provider shall notify the Deployer within [48/72] hours of becoming aware of any serious incident or material non-compliance.”

AI Governance in Greece, Roles, Policies and RACI

Effective AI governance requires clearly defined internal roles. Law 5321/2026, read alongside the EU AI Act, creates practical pressure on organisations to formalise ownership of AI compliance tasks. Industry observers expect the following roles to become standard across Greek businesses deploying high-risk AI:

  • Board / Executive Sponsor. Provides strategic oversight, approves the AI risk-appetite statement, receives periodic compliance reports and authorises budget for AI governance resources.
  • AI Compliance Officer / Responsible Person. Owns the day-to-day compliance programme, risk classification, documentation oversight, incident management and regulatory liaison with the competent authority.
  • Data Protection Officer (DPO). Ensures GDPR alignment, leads or co-leads joint DPIAs, and coordinates with the Hellenic Data Protection Authority (HDPA) on AI-related data-processing activities.
  • CTO / Engineering Owner. Manages technical documentation, system architecture records, testing protocols, logging infrastructure and cybersecurity controls.

Board Reporting Cadence and KPIs

The likely practical effect of the new enforcement regime will be to incentivise quarterly AI governance reports to the board. Key performance indicators to track include: number of AI systems inventoried vs classified, percentage of high-risk systems with completed conformity assessments, open DPIA actions, incident-response drill results and any regulatory correspondence received from the competent authority.

Task R (Responsible) A (Accountable) C (Consulted) I (Informed)
AI system inventory CTO AI Compliance Officer Business Unit Leads Board
Risk classification AI Compliance Officer General Counsel CTO, DPO Board
DPIA (joint GDPR/AI) DPO General Counsel AI Compliance Officer, CTO Board, HDPA (if required)
Technical documentation CTO / Engineering AI Compliance Officer Legal Board
Incident reporting AI Compliance Officer General Counsel CTO, DPO Board, Competent Authority

GDPR Interplay and Data Protection Checkpoints for AI Systems in Greece

The intersection of GDPR and the EU AI Act, and by extension Law 5321/2026, is one of the most operationally complex areas for Greek businesses. AI systems routinely process personal data at scale, making GDPR compliance a prerequisite rather than a parallel track. The Hellenic Data Protection Authority (HDPA) retains its supervisory competence over personal-data processing, and early indications suggest it will coordinate closely with the designated AI competent authority on enforcement involving AI-driven data processing.

When to Consult the HDPA and When to Run Joint Assessments

A joint GDPR/AI assessment is advisable whenever a high-risk AI system processes personal data as a core function, for example, CV-screening tools, biometric access systems, credit-scoring models or healthcare triage algorithms. The DPIA required under Article 35 of the GDPR should be expanded to incorporate the AI Act’s data-governance requirements: training-data representativeness, bias testing, accuracy measurement and transparency disclosure. Where the DPIA indicates that the processing is likely to result in a high risk to individuals’ rights and freedoms that cannot be mitigated, prior consultation with the HDPA under Article 36 of the GDPR is mandatory.

Additionally, where sector-specific rules apply (financial services, healthcare, employment), businesses should verify whether the HDPA or another sectoral regulator should be the primary point of contact.

Enforcement, AI Penalties in Greece and Publication Obligations, How to Reduce Exposure

Law 5321/2026 converts the EU AI Act’s enforcement provisions into Greek administrative procedure. The law designates the competent national authority responsible for market surveillance, investigations and the imposition of administrative sanctions. Regulation (EU) 2024/1689 sets maximum penalty thresholds, up to €35 million or 7% of global annual turnover for prohibited AI practices, up to €15 million or 3% for other infringements, and the Greek AI law provides the procedural machinery for imposing those fines domestically, including hearing rights, appeal routes and publication of enforcement decisions.

The publication requirement is significant: enforcement decisions may be made public, which amplifies reputational risk beyond the financial penalty itself. For Greek companies or multinationals with Greek operations, this creates a powerful incentive to invest proactively in compliance rather than risk public censure.

Practical Mitigation Strategies

  • Maintain meticulous records. Comprehensive technical documentation, decision logs and DPIA records demonstrate good faith and may reduce the severity of any enforcement action.
  • Engage early with the competent authority. Voluntary disclosure of non-compliance or system malfunctions, before a formal investigation is launched, is widely expected to be treated as a mitigating factor.
  • Implement remediation plans promptly. Where a compliance gap is identified, document the remediation timeline, assign ownership and track progress. Presenting a credible remediation plan may forestall or reduce penalties.
  • Test incident-response protocols. Run annual tabletop exercises simulating an AI incident. Document the drill, lessons learned and corrective actions taken.
  • Seek independent audit. Engaging an external auditor or law firm to conduct a pre-enforcement AI compliance review provides an independent assessment that can be presented as evidence of diligent effort.

Next Steps

Compliance with the Greek AI law is not a one-off project, it requires ongoing governance, periodic reassessment and continuous monitoring as delegated and implementing acts are issued at EU level and as the competent Greek authority publishes additional guidance. Businesses operating in Greece should begin with the eight-step checklist outlined above and consider engaging qualified legal counsel to conduct a gap analysis tailored to their specific AI portfolio and sector.

For companies navigating the broader landscape of doing business in Greece, Global Law Experts maintains a directory of specialist lawyers with expertise in regulatory compliance, technology law and corporate governance across Greek jurisdictions. Proactive investment in AI compliance today reduces enforcement exposure, protects reputation and positions your organisation as a trusted operator under the new Greek AI law framework.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Diomidis Papacharalampous at P&C LAW FIRM, a member of the Global Law Experts network.

Sources

  1. Official Journal of the European Union (EUR-Lex), Regulation (EU) 2024/1689 (EU AI Act)
  2. Government Gazette (FEK) / National Printing Office, FEK A’ 114/20-07-2026 (Law 5321/2026)
  3. AADE / ELIB, Official legislative print view of Law 5321/2026
  4. Hellenic Data Protection Authority (HDPA)
  5. European Commission, AI Act Regulatory Framework Policy Page
  6. OECD, AI Policy Observatory

FAQs

What does Greek Law 5321/2026 require of companies using AI systems?
Law 5321/2026 (FEK A’ 114/20-07-2026) establishes Greece’s national framework for enforcing Regulation (EU) 2024/1689 (the EU AI Act). It designates competent authorities, sets out enforcement procedures, and requires businesses to classify AI systems by risk, maintain documentation, implement human oversight and report serious incidents.
All AI systems placed on the market or put into service in Greece are potentially in scope. The obligations vary by risk class (unacceptable, high, limited, minimal) and apply to providers, deployers, importers and distributors regardless of where the system was developed.
Start by inventorying all AI systems, classifying each by risk level, running joint GDPR/AI DPIAs for high-risk systems, appointing an AI Compliance Officer and updating procurement contracts to require conformity declarations from providers.
Law 5321/2026 designates the competent national authority responsible for market surveillance and enforcement. Enforcement decisions, including administrative fines and remedial orders, may be published, amplifying reputational consequences for non-compliant businesses.
The penalty framework aligns with Regulation (EU) 2024/1689. Maximum fines reach up to €35 million or 7% of global annual turnover for deploying prohibited AI practices, and up to €15 million or 3% for other infringements. The Greek law provides the procedural framework for imposing these domestically.
AI systems that process personal data must comply with both the GDPR and the AI Act. A joint DPIA addressing data-governance, bias, accuracy and transparency requirements is recommended. The Hellenic Data Protection Authority (HDPA) retains supervisory competence over personal-data aspects of AI processing.
The official text is published in the Government Gazette as FEK A’ 114 dated 20 July 2026. It can be accessed through the National Printing Office’s search portal at search.et.gr or through the official AADE legislative library.
how to notarize a contract in Liechtenstein
By Global Law Experts

posted 44 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Greek AI Law 5321/2026: Practical Compliance Guide for Businesses

Send welcome message

Custom Message