A draft law that will shape Cyprus' national framework for implementing the European Union's Artificial Intelligence Act (AI Act) has been released for public consultation.
According to the philosophy underpinning the regulation, certain uses of artificial intelligence are considered to pose an unacceptable risk to fundamental rights, safety and health and are therefore prohibited.
The proposed Artificial Intelligence Law of 2026 seeks to establish the national structures required for the implementation of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689).
The bill does not introduce separate Cypriot rules on artificial intelligence. Instead, its purpose is to ensure the effective application of the EU regulation, which already applies across all EU member states.
Implementation of the AI Act is taking place gradually, in accordance with the timetable set out in Article 113 of the regulation, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI).
A representative of the Office of the Commissioner of Communications told Politis that national legislation is required because each member state must designate the competent authorities responsible for implementation, as well as define their powers relating to inspections, supervision and administrative sanctions.
What the bill provides
According to the Office of the Commissioner of Communications, the bill provides for:
- The establishment of Cyprus' national AI governance framework.
- The designation of competent authorities and their responsibilities.
- The creation of a market surveillance and monitoring framework.
- Compliance procedures and administrative enforcement measures.
- National mechanisms required for implementation of the regulation.
- The creation of an AI Regulatory Sandbox to support responsible innovation.
At the same time, a second bill concerning the organisational structure of the Office of the Commissioner of Communications is also being promoted.
The proposal would establish a dedicated Artificial Intelligence Directorate, which would assume the new responsibilities assigned to the Commissioner under the European regulation.
Who is affected by the AI Act?
The regulation is aimed primarily at providers and deployers of AI systems rather than ordinary users.
Its provisions establish the conditions under which AI systems may be developed and used within the European Union.
The central philosophy of the AI Act is based on risk assessment.
AI systems are classified into different categories depending on the risk they may pose.
Some systems are prohibited entirely.
Others are classified as high-risk and are subject to strict compliance obligations.
Lower-risk applications are generally subject to transparency requirements, such as informing users when they are interacting with an AI system.
Prohibited practices
Particular importance is attached to Article 5 of the AI Act, which defines prohibited AI practices.
Under the regulation, certain uses of AI are deemed to create unacceptable risks to fundamental rights, safety and health and are therefore not permitted.
Through these provisions, the European Union seeks to ensure that artificial intelligence is developed in a manner that is trustworthy, ethical and consistent with European values.
The issue has attracted increased public attention because of the growing use of deepfakes and other forms of misleading content generated through AI technologies.
According to the Office of the Commissioner of Communications, the regulation includes specific prohibitions covering certain uses of AI systems involved in the creation of such content.
It also establishes transparency obligations to ensure that users know when they are interacting with synthetic or artificially generated material.
In the case of deepfakes, users must be informed that the content has been generated or artificially manipulated.
Role of supervisory authorities
Competent market-surveillance authorities will play a central role in the new framework, each within its area of responsibility.
The authorities will be responsible for monitoring and verifying compliance of AI systems after they are placed on the market or put into operation.
Among other duties, they will verify that high-risk AI systems have undergone the required conformity-assessment procedures before being marketed or deployed and that they continue to comply with regulatory requirements throughout their operational lifecycle.
The objective is continuous and effective oversight of systems that may significantly affect citizens' fundamental rights, health, safety or opportunities.
Transitional framework already in place
Although the bill has not yet been enacted, there is no institutional vacuum, according to the Office of the Commissioner of Communications.
Since 2025, a Council of Ministers decision has already assigned specific responsibilities to designated authorities, including:
- The Office of the Commissioner of Communications.
- The Office of the Commissioner for Personal Data Protection.
The new legislation is intended to refine the existing framework and provide greater clarity regarding responsibilities, procedures and enforcement mechanisms.
Consultation remains open
Public consultation on the draft law is being conducted through the government's e-Consultation platform and will remain open until 16 September 2026.
The Office of the Commissioner of Communications is inviting citizens, businesses, professional associations and organisations to submit comments and proposals to help shape the final framework for implementation of the AI Act in Cyprus.
As a representative of the office noted, the higher the risks associated with the use of artificial intelligence, the greater the importance of aligning with European standards.



