Slovenia's ZIUDHPUI: AI Act Implementation Law, Explained
By Anthony Guerriero, Founder and AI policy analyst, The Leveraged Years. Published 6 November 2025. Last verified: 2026-07-25.
While most trackers still list Slovenia as a country that had not yet passed its AI Act plumbing, Ljubljana already did the work. On 23 October 2025 the National Assembly adopted a law with an unlovely acronym, ZIUDHPUI, and on 6 November it appeared in the Official Gazette as item 3035. It is short, it is dull, and it is exactly the kind of instrument that decides who can knock on a company's door over an AI system. This is the piece that answers a question the EU AI Act itself does not: in Slovenia, who actually enforces it.
Key Facts
- Instrument
- Zakon o izvajanju uredbe (EU) o dolocitvi harmoniziranih pravil o umetni inteligenci (ZIUDHPUI), the Act on the Implementation of Regulation (EU) 2024/1689.
- Issuer and citation
- Republic of Slovenia; Uradni list RS 85/2025, page 9899, item 3035, dated 6 November 2025. Adopted by the National Assembly on 23 October 2025, promulgated by President Natasa Pirc Musar on 31 October 2025.
- Effective date
- 21 November 2025, the fifteenth day after publication (Article 45).
- Who is covered
- Providers, deployers, importers and distributors of AI systems reaching the Slovenian market, plus public-sector bodies that run AI systems.
- Consequence
- Fines from EUR 2,000 up to EUR 35,000,000 or 7 percent of worldwide annual turnover for the most serious prohibited-practice breaches (Article 26).
- Status
- In force.
What changed: the AI Act finally got a Slovenian chassis
The EU AI Act, Regulation (EU) 2024/1689, applies directly across the bloc. What it does not do is appoint the national referees. It tells each member state to name notifying authorities, market-surveillance authorities, a single point of contact, and to set penalties in domestic law. That is the gap the ZIUDHPUI fills. Article 1 states the purpose plainly.
"Ta zakon doloca pristojne organe za izvajanje in nadzor nad izvajanjem Uredbe (EU) 2024/1689 ... ter prekrske in globe v zvezi z izvajanjem Uredbe 2024/1689/EU in tega zakona."
English gloss: "This Act designates the competent authorities for the implementation of and supervision over the implementation of Regulation (EU) 2024/1689 ... and the offences and fines related to the implementation of Regulation 2024/1689/EU and this Act." Before this law, a Slovenian company facing a question about a high-risk system had no named regulator to answer to. Now it does.
What the rule actually requires: five watchdogs, one front door, a sandbox
The heart of the statute is Article 6, which spreads market surveillance across five bodies rather than parking it in a single new agency.
"Naloge organov za nadzor trga po Uredbi 2024/1689/EU izvajajo: Agencija za komunikacijska omrezja in storitve Republike Slovenije, Informacijski pooblascenec, Banka Slovenije, Agencija za zavarovalni nadzor in Trzni inspektorat Republike Slovenije."
English gloss: the market-surveillance tasks under the AI Act are carried out by the Agency for Communication Networks and Services (AKOS), the Information Commissioner, the Bank of Slovenia, the Insurance Supervision Agency, and the Market Inspectorate. The division follows the risk map. Under Article 10, the Information Commissioner owns the prohibited-practice rules of Article 5 and several Annex III uses, including biometrics and law-enforcement systems. The Bank of Slovenia takes creditworthiness systems used by banks, the insurance regulator takes AI in insurance pricing, and AKOS carries the broad remainder plus the transparency duties of Article 50.
AKOS is the load-bearing name here. Article 7 makes it the single point of contact required by Article 70 of the AI Act, Article 15 puts it in the chair of a coordination council that convenes the five bodies at least quarterly, and Article 17 makes it responsible for the regulatory sandbox under Article 57 of the AI Act. Article 40 sets a hard deadline: the first sandbox must be running by 2 August 2026. The law also stands up a National Council for Ethics in AI (Article 23), a five-member advisory body serving a five-year term, and it obliges public-sector bodies to publish details of the AI systems they use through a single information point (Article 21).
Penalties and enforcement: from EUR 2,000 to EUR 35 million
The penalty chapter is where the statute has teeth, and it is graduated by both the offence and the size of the offender. The AI-literacy duty of Article 4 of the AI Act, often treated as soft, is backed by real numbers. Under Article 25, a company that fails to ensure sufficient AI literacy among staff faces EUR 25,000 to EUR 250,000, rising to EUR 100,000 to EUR 450,000 for a large company, with lower fixed brackets for sole traders, responsible persons and individuals.
The severe tier sits in Article 26, on prohibited practices. For an ordinary breach the brackets mirror the literacy figures, but the law reaches for the AI Act's headline maximum when the conduct is aggravated by the scale of harm, unlawful gain, or intent. In that case the fine runs "up to EUR 35,000,000 or up to seven percent of total worldwide annual turnover for the preceding business year, whichever is higher." Enforcement is not quiet: Article 16 requires the authorities to publish the identity of a sanctioned entity, the nature of the breach, and the operative decision, keeping it online for three years. Slovenia also created dedicated state AI supervisors seated at the Information Commissioner (Article 12), so the biometrics and prohibited-practice cases get specialists rather than borrowed inspectors.
How Slovenia's implementation compares
The value of a national implementation law is in its specifics. The table below sets the ZIUDHPUI against the EU baseline and two neighbours that legislated in the same window.
| Feature | EU AI Act (Reg 2024/1689) | Slovenia (ZIUDHPUI) | Hungary (Act LXXV/2025) | Latvia (AI Centre Law) |
|---|---|---|---|---|
| Enforcement model | Leaves authority design to states | Five existing regulators share surveillance | National implementation act | New AI Centre plus sandbox |
| Single point of contact | Required (Art. 70) | AKOS (Art. 7) | Designated in national act | Via the AI Centre |
| Regulatory sandbox | Required by 2 Aug 2026 (Art. 57) | AKOS, first by 2 Aug 2026 (Arts 17, 40) | Provided for | Core purpose of the law |
| Top fine | EUR 35M or 7% turnover | EUR 35M or 7% turnover (Art. 26) | Follows AI Act maxima | Follows AI Act maxima |
| Ethics or advisory body | Not mandated nationally | National Council for Ethics in AI (Art. 23) | Not a named council | Centred on the AI Centre |
The pattern worth noting is architectural. Latvia built a new institution. Slovenia distributed the work across regulators that already exist, then bolted on a coordination council to keep them aligned. For a company, that means the door you knock on depends on what your system does, not on one central AI office.
What the ZIUDHPUI does NOT do
The law is narrower than its subject sounds. It does not create new substantive obligations for AI systems; the duties still come from Regulation (EU) 2024/1689, and the ZIUDHPUI only names who enforces them and how they are punished. It does not build a new AI agency the way Latvia did; every enforcer is an existing Slovenian body. It does not set its own definitions, since Article 2 simply adopts the AI Act's terms. It does not change the AI Act's staggered application dates, so a Slovenian obligation still bites on the EU timetable rather than on this statute's entry into force. And it does not reach military, defence or national-security systems for the public-sector transparency duty, which Article 21 expressly carves out. Read it as an enforcement map, not as a second rulebook.
Frequently asked questions
What is the ZIUDHPUI?
Slovenia's national law implementing the EU AI Act, published in Uradni list RS 85/2025 on 6 November 2025. It names the competent authorities and sets the offences and fines.
Which authorities enforce the AI Act in Slovenia?
Five, under Article 6: AKOS, the Information Commissioner, the Bank of Slovenia, the Insurance Supervision Agency, and the Market Inspectorate. AKOS is also the single point of contact.
What are the maximum fines?
Up to EUR 35,000,000 or 7 percent of worldwide annual turnover, whichever is higher, for aggravated prohibited-practice breaches (Article 26). Lesser breaches run from EUR 2,000 to EUR 450,000.
When did it take effect?
21 November 2025, the fifteenth day after publication (Article 45).
Primary sources
- ZIUDHPUI, full text, Uradni list RS 85/2025, item 3035
- Regulation (EU) 2024/1689 (the EU AI Act), EUR-Lex