AI Act Guide
The Artificial Intelligence framework in force after Greek Law 5321/2026 and the Digital Omnibus — competent authorities, deadlines already running, and the three parallel reporting obligations, with references to the Government Gazette.
1. The two acts and what changed
Regulation (EU) 2024/1689 (the AI Act) entered into force on 1 August 2024, with staged application. The general application date of 2 August 2026 did not change — the Article 50 transparency obligations already apply. The Digital Omnibus, however, moved the two heavy high-risk waves:
| Date | What applies | Who it concerns |
|---|---|---|
| 2.2.2025 | Prohibited practices (Art. 5) and AI literacy | Everyone |
| 2.8.2025 | General-purpose AI (GPAI) obligations, governance, penalty regime | GPAI providers |
| 2.8.2026 | General application; Article 50 transparency (chatbots, deepfakes, synthetic content); start of enforcement | Everyone — already in force |
| 2.12.2026 | New prohibitions (non-consensual intimate imagery, CSAM); end of the transitional period for machine-readable marking | Generative AI providers |
| 2.8.2027 | Mandatory operation of a national regulatory sandbox | Member States |
| 2.12.2027 | High-risk obligations of Annex III — standalone systems (deferred from 2.8.2026) | Providers and deployers |
| 2.8.2028 | High-risk obligations of Annex I — AI embedded in regulated products (MDR/IVDR) | Product manufacturers |
| 2.8.2030 | Compliance of pre-existing high-risk systems used by public authorities (Art. 111 of the Regulation) | Public sector |
2. The three deadlines to put in your calendar
Every public body already operating an AI system must declare it «without delay and in any case no later than 31.12.2026» (Law 5321/2026 Art. 25 §2). For new systems the declaration is a prerequisite before operation (Art. 21).
Standalone high-risk systems: full risk-management system, data quality, documentation, human oversight, conformity assessment.
Pre-existing systems of private operators are exempt until a substantial design change — the public sector is not: compliance by 2.8.2030 regardless of modification (Art. 111).
3. Who supervises what in Greece (Law 5321/2026)
| Body | Role | Provision |
|---|---|---|
| Hellenic DPA | Market surveillance authority for prohibited practices, Annex III high-risk and Article 50 transparency; single point of contact with the Commission; recipient of the single complaints system | Arts. 3, 4, 7 |
| EETT | Notifying authority for notified bodies; hosts the AI Coordination and Expertise Centre | Arts. 5, 6 |
| DPA + EETT | Joint supervision of the national AI regulatory sandbox — the legal basis was enacted a year ahead of the mandatory deadline | Art. 12 |
| Special Secretariat for AI (Ministry of Digital Governance) | Keeper of the Public-Sector AI Systems Registry; AI Observatory | Arts. 21, 22 |
4. The Greek particularities — stricter than the Regulation
| Provision | What it says | Why it matters |
|---|---|---|
| Real-world testing (Art. 13) | Approval is granted «only upon express written permission»; «the expiry of the thirty (30) day period … shall not be deemed to constitute approval» | It overrides the tacit approval allowed by Art. 60(4) of the Regulation. A pilot in a clinical setting does not start because the authority stayed silent |
| Periodic penalty payments (Art. 16) | Up to «two percent (2%) of the average daily total worldwide turnover» for non-compliance with an order; ceases upon proof of compliance | An enforcement mechanism on top of the Regulation's fines (up to €35m or 7% for prohibited practices, up to €15m or 3% for other infringements) |
| Deepfakes (Art. 23) | Criminal penalties for removing or altering the Article 50 transparency markings on deepfake content | Already in force, since it attaches to Article 50 which applies from 2.8.2026 |
| Whistleblowers (Art. 20) | AI Act infringements are brought within the scope of Law 4990/2022 (whistleblowing) | The organisation's internal reporting channels must be extended to cover AI |
5. An incident on an AI system: three reports, one event
For a healthcare entity within NIS2 scope, an incident affecting a high-risk AI system can trigger three parallel notification regimes:
| Framework | Recipient | Deadline |
|---|---|---|
| Law 5160/2024 Art. 16 (NIS2) | National Cybersecurity Authority / CSIRT | 24 hours early warning · 72 hours notification · 1 month final report |
| Regulation 2024/1689 (serious incident) | Hellenic DPA as market surveillance authority | Per the Regulation — slower |
| GDPR Art. 33 (if personal data affected) | Hellenic DPA as supervisory authority | 72 hours |
6. AI Act and NIS2: cumulative application, not hierarchy
The Regulation governs the system (design, training data, human oversight, model robustness); NIS2 governs the entity (networks, systems, the organisation's overall risk management). Compliance with one does not discharge the other. Article 15 of the Regulation («accuracy, robustness and cybersecurity») expressly names data and model poisoning, adversarial examples and model evasion — threats the entity's cybersecurity programme must now cover by name.
7. What did NOT change — the scope of the repeal
Article 26 of Law 5321/2026 provides: «From the entry into force of this law, Chapter B΄ of Part A΄ of Law 4961/2022 is repealed». Chapter B΄ comprises Articles 3–14 — the first national attempt to regulate AI (algorithmic impact assessments, registries etc.), replaced without automatic continuity.
Articles 18–20 of the same law — the Information and Communication Systems Security Officer, duties, risk-analysis plan — belong to Chapter C΄ («Information and network security provisions») and remain fully in force. Everything in the Security Officer Guide is untouched by the new law.
8. Immediate action list for a healthcare entity
| # | Action | Basis |
|---|---|---|
| 1 | Map every AI system in operation — from imaging-support tools to appointment routing and chatbots | Prerequisite for everything below |
| 2 | Registry declaration for public bodies — existing systems by 31.12.2026, new ones before operation | Law 5321/2026 Arts. 21, 25 §2 |
| 3 | Risk classification per system: prohibited / high-risk (Annex I or III — this decides the deadline) / transparency / minimal | Reg. 2024/1689 as amended |
| 4 | Transparency compliance now: user notice for chatbots, marking of synthetic content and deepfakes | Art. 50 — in force since 2.8.2026 |
| 5 | Extend whistleblowing channels to cover AI infringements | Law 5321/2026 Art. 20 → Law 4990/2022 |
| 6 | Unify incident response so one event produces all three reports (NCA 24h, DPA ×2) | Law 5160/2024 Art. 16 · Reg. 2024/1689 · GDPR Art. 33 |
| 7 | Add AI threats (data poisoning, adversarial examples, model evasion) to the risk assessment and threat register | Reg. 2024/1689 Art. 15 + NIS2 Art. 21 |
| 8 | No real-world pilot of a high-risk system without express written permission | Law 5321/2026 Art. 13 |
Sources and references
- Law 5321/2026 (Gazette A΄ 114 of 20.07.2026) — implementing measures for Regulation (EU) 2024/1689, amendment of Law 4961/2022 and other provisions. In particular Articles 3–7 (authorities), 12–13 (innovation and testing), 16–20 (penalties, whistleblowers), 21–23 (public sector, deepfakes), 25–26 (transitional and repealed provisions).
- Regulation (EU) 2024/1689 (AI Act), in particular Articles 5, 6 and Annexes I/III, 15, 50, 60, 99, 111.
- Regulation (EU) 2026/1744 (the «Digital Omnibus on AI») — Official Journal 24.07.2026, in force 27.07.2026. Deferral of high-risk deadlines, new Article 5 prohibitions.
- Law 4961/2022 (Gazette A΄ 146 of 27.07.2022) — Articles 18–20 (Security Officer) remain in force; only Articles 3–14 (Chapter B΄ of Part A΄) were repealed.
- Law 5160/2024 (Gazette A΄ 195 of 27.11.2024) — NIS2 transposition; Article 16 on the 24/72-hour notification deadlines.
- Law 4990/2022 — protection of persons reporting infringements (whistleblowing).
- All article identifiers verified against the original Gazette texts.
