Slovenia's ZIUDHPUI: AI Act Implementation Law, Explained | TLY

Slovenia's ZIUDHPUI: AI Act Implementation Law, Explained

While most trackers still list Slovenia as a country that had not yet passed its AI Act plumbing, Ljubljana already did the work. On 23 October 2025 the National Assembly adopted a law with an unlovely acronym, ZIUDHPUI, and on 6 November it appeared in the Official Gazette as item 3035. It is short, it is dull, and it is exactly the kind of instrument that decides who can knock on a company's door over an AI system. This is the piece that answers a question the EU AI Act itself does not: in Slovenia, who actually enforces it.

Key Facts

Instrument
Zakon o izvajanju uredbe (EU) o dolocitvi harmoniziranih pravil o umetni inteligenci (ZIUDHPUI), the Act on the Implementation of Regulation (EU) 2024/1689.
Issuer and citation
Republic of Slovenia; Uradni list RS 85/2025, page 9899, item 3035, dated 6 November 2025. Adopted by the National Assembly on 23 October 2025, promulgated by President Natasa Pirc Musar on 31 October 2025.
Effective date
21 November 2025, the fifteenth day after publication (Article 45).
Who is covered
Providers, deployers, importers and distributors of AI systems reaching the Slovenian market, plus public-sector bodies that run AI systems.
Consequence
Fines from EUR 2,000 up to EUR 35,000,000 or 7 percent of worldwide annual turnover for the most serious prohibited-practice breaches (Article 26).
Status
In force.

What changed: the AI Act finally got a Slovenian chassis

The EU AI Act, Regulation (EU) 2024/1689, applies directly across the bloc. What it does not do is appoint the national referees. It tells each member state to name notifying authorities, market-surveillance authorities, a single point of contact, and to set penalties in domestic law. That is the gap the ZIUDHPUI fills. Article 1 states the purpose plainly.

"Ta zakon doloca pristojne organe za izvajanje in nadzor nad izvajanjem Uredbe (EU) 2024/1689 ... ter prekrske in globe v zvezi z izvajanjem Uredbe 2024/1689/EU in tega zakona."

English gloss: "This Act designates the competent authorities for the implementation of and supervision over the implementation of Regulation (EU) 2024/1689 ... and the offences and fines related to the implementation of Regulation 2024/1689/EU and this Act." Before this law, a Slovenian company facing a question about a high-risk system had no named regulator to answer to. Now it does.

What the rule actually requires: five watchdogs, one front door, a sandbox

The heart of the statute is Article 6, which spreads market surveillance across five bodies rather than parking it in a single new agency.

"Naloge organov za nadzor trga po Uredbi 2024/1689/EU izvajajo: Agencija za komunikacijska omrezja in storitve Republike Slovenije, Informacijski pooblascenec, Banka Slovenije, Agencija za zavarovalni nadzor in Trzni inspektorat Republike Slovenije."

English gloss: the market-surveillance tasks under the AI Act are carried out by the Agency for Communication Networks and Services (AKOS), the Information Commissioner, the Bank of Slovenia, the Insurance Supervision Agency, and the Market Inspectorate. The division follows the risk map. Under Article 10, the Information Commissioner owns the prohibited-practice rules of Article 5 and several Annex III uses, including biometrics and law-enforcement systems. The Bank of Slovenia takes creditworthiness systems used by banks, the insurance regulator takes AI in insurance pricing, and AKOS carries the broad remainder plus the transparency duties of Article 50.

AKOS is the load-bearing name here. Article 7 makes it the single point of contact required by Article 70 of the AI Act, Article 15 puts it in the chair of a coordination council that convenes the five bodies at least quarterly, and Article 17 makes it responsible for the regulatory sandbox under Article 57 of the AI Act. Article 40 sets a hard deadline: the first sandbox must be running by 2 August 2026. The law also stands up a National Council for Ethics in AI (Article 23), a five-member advisory body serving a five-year term, and it obliges public-sector bodies to publish details of the AI systems they use through a single information point (Article 21).

Penalties and enforcement: from EUR 2,000 to EUR 35 million

The penalty chapter is where the statute has teeth, and it is graduated by both the offence and the size of the offender. The AI-literacy duty of Article 4 of the AI Act, often treated as soft, is backed by real numbers. Under Article 25, a company that fails to ensure sufficient AI literacy among staff faces EUR 25,000 to EUR 250,000, rising to EUR 100,000 to EUR 450,000 for a large company, with lower fixed brackets for sole traders, responsible persons and individuals.

The severe tier sits in Article 26, on prohibited practices. For an ordinary breach the brackets mirror the literacy figures, but the law reaches for the AI Act's headline maximum when the conduct is aggravated by the scale of harm, unlawful gain, or intent. In that case the fine runs "up to EUR 35,000,000 or up to seven percent of total worldwide annual turnover for the preceding business year, whichever is higher." Enforcement is not quiet: Article 16 requires the authorities to publish the identity of a sanctioned entity, the nature of the breach, and the operative decision, keeping it online for three years. Slovenia also created dedicated state AI supervisors seated at the Information Commissioner (Article 12), so the biometrics and prohibited-practice cases get specialists rather than borrowed inspectors.

How Slovenia's implementation compares

The value of a national implementation law is in its specifics. The table below sets the ZIUDHPUI against the EU baseline and two neighbours that legislated in the same window.

FeatureEU AI Act (Reg 2024/1689)Slovenia (ZIUDHPUI)Hungary (Act LXXV/2025)Latvia (AI Centre Law)
Enforcement modelLeaves authority design to statesFive existing regulators share surveillanceNational implementation actNew AI Centre plus sandbox
Single point of contactRequired (Art. 70)AKOS (Art. 7)Designated in national actVia the AI Centre
Regulatory sandboxRequired by 2 Aug 2026 (Art. 57)AKOS, first by 2 Aug 2026 (Arts 17, 40)Provided forCore purpose of the law
Top fineEUR 35M or 7% turnoverEUR 35M or 7% turnover (Art. 26)Follows AI Act maximaFollows AI Act maxima
Ethics or advisory bodyNot mandated nationallyNational Council for Ethics in AI (Art. 23)Not a named councilCentred on the AI Centre

The pattern worth noting is architectural. Latvia built a new institution. Slovenia distributed the work across regulators that already exist, then bolted on a coordination council to keep them aligned. For a company, that means the door you knock on depends on what your system does, not on one central AI office.

What the ZIUDHPUI does NOT do

The law is narrower than its subject sounds. It does not create new substantive obligations for AI systems; the duties still come from Regulation (EU) 2024/1689, and the ZIUDHPUI only names who enforces them and how they are punished. It does not build a new AI agency the way Latvia did; every enforcer is an existing Slovenian body. It does not set its own definitions, since Article 2 simply adopts the AI Act's terms. It does not change the AI Act's staggered application dates, so a Slovenian obligation still bites on the EU timetable rather than on this statute's entry into force. And it does not reach military, defence or national-security systems for the public-sector transparency duty, which Article 21 expressly carves out. Read it as an enforcement map, not as a second rulebook.

Frequently asked questions

What is the ZIUDHPUI?

Slovenia's national law implementing the EU AI Act, published in Uradni list RS 85/2025 on 6 November 2025. It names the competent authorities and sets the offences and fines.

Which authorities enforce the AI Act in Slovenia?

Five, under Article 6: AKOS, the Information Commissioner, the Bank of Slovenia, the Insurance Supervision Agency, and the Market Inspectorate. AKOS is also the single point of contact.

What are the maximum fines?

Up to EUR 35,000,000 or 7 percent of worldwide annual turnover, whichever is higher, for aggravated prohibited-practice breaches (Article 26). Lesser breaches run from EUR 2,000 to EUR 450,000.

When did it take effect?

21 November 2025, the fifteenth day after publication (Article 45).

Primary sources

Related tracker coverage