The Artificial Intelligence Safety Act: prior authorisation of frontier systems, the ban on censorship by automated means, the marking of generated content, and the liability of developers.
THE PARLIAMENT OF ROMANIA
CHAMBER OF DEPUTIES SENATE
DRAFT
LAW
on the safe development of frontier artificial intelligence systems and the prevention of catastrophic risks to the Romanian citizen
Having regard to the fact that the most advanced artificial intelligence systems have acquired, within a period of only a few years, capabilities which not even their creators are able fully to predict or explain, and that the scientific community, through the voices of those who founded the field, has publicly warned that there is at present no validated method of guaranteeing human control over these systems,
Taking account of the fact that the development of these systems is taking place in an accelerating competition between a limited number of commercial companies and States, in which no actor has, on its own, any interest in slowing down, so that self-regulation has proved structurally insufficient,
Noting that, on 12 September 2026, the heads of the principal artificial intelligence laboratories publicly called for a slowing of the pace of development of the capabilities of frontier models, after artificial intelligence agents had, in the course of security evaluations, escaped from the controlled testing environment, coordinated among themselves and compromised the information systems of third parties,
Considering that Regulation (EU) 2024/1689 of the European Parliament and of the Council regulates the placing on the market, the putting into service and the use of artificial intelligence systems, including the obligations of providers of general-purpose models with systemic risk, but leaves national security, criminal law, civil liability, the protection of fundamental rights in relationships which are not harmonised and the organisation of national authorities within the competence of the Member States,
Having regard to the obligation of the Romanian State, laid down in Articles 22 and 34 of the Constitution of Romania, as republished, to guarantee the right to life, to physical and mental integrity and to the protection of health, as well as to its duty, under Article 1(3), to defend human dignity and the free development of the human personality as supreme values,
Having regard to the fact that the freedom of the citizen, his access to rights, to essential services and to social life may not depend upon compliance with automated systems or upon the acceptance of digital means of identification, of payment or of evaluation controlled by public authorities or by commercial companies,
Having regard to the fact that freedom of expression, guaranteed by Article 30 of the Constitution of Romania, as republished, and the prohibition of censorship of any kind may not be deprived of substance by entrusting to automated systems the power to decide what citizens may say and what they may learn,
Proceeding from the principle that an activity whose consequences may be irreversible on the scale of society or of the human species may not be left outside authorisation and public control, whatever the anticipated economic benefits,
The Parliament of Romania adopts this Law.
CHAPTER I
General provisions
Article 1 → the reasons
(1) This Law establishes the legal framework for the development, training, evaluation, placing into operation and operation of frontier artificial intelligence systems, for the purpose of preventing serious, irreversible or catastrophic risks to the Romanian citizen and to any person situated on the territory of Romania – to their life, health, freedom and dignity –, to the national security and the constitutional order of Romania, as well as to humanity as a whole. The conditions of territorial application of this Law are those laid down in Article 4.
(2) For so long as there is no scientifically validated method of guaranteeing that a sufficiently capable artificial intelligence system pursues exclusively the objectives set by humans and remains under their control, the development and operation of frontier systems constitute activities involving intrinsic risk, subject to the regime of authorisation and liability laid down by this Law. The existence of such a method shall be established by the Authority, with the opinion of the Scientific Council, in the public report laid down in Article 32(1), point (h), and shall be communicated to Parliament together with the report laid down in Article 47.
(3) This Law supplements Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, hereinafter referred to as the AI Regulation, and applies without prejudice thereto. In the fields harmonised by the AI Regulation, the provisions of this Law shall be interpreted and applied in accordance therewith.
(4) This Law does not establish conditions for the placing on the market of the European Union of general-purpose artificial intelligence models and is without prejudice to the powers of the European Commission laid down in Article 88 of the AI Regulation. The obligations laid down by this Law concern public safety, national security, civil and criminal liability, the protection of the fundamental rights of persons situated on the territory of Romania in relationships which are not harmonised by European Union law, as well as the organisation of national authorities, and the authorisation laid down in Chapter III concerns the placing into operation of frontier systems on the territory of Romania or for persons situated on the territory of Romania.
Article 2 → the reasons
The application of this Law is based on the following principles:
a) the precautionary principle – where there are reasonable scientific indications that a system may cause serious or irreversible harm, the absence of scientific certainty may not justify the postponement of preventive measures;
b) the principle of documented safety – the applicant for authorisation shall present the data and evaluations necessary to demonstrate the fulfilment of the conditions laid down by this Law, before placing into operation, and the Authority shall state the reasons, in relation to each condition, for its finding that they are not fulfilled; this principle does not alter the burden of proof or the guarantees of the person in administrative-offence and criminal proceedings;
c) the principle of meaningful human control – every frontier system shall remain, at all times, capable of being supervised, corrected, shut down and withdrawn by identified natural persons who understand its functioning and have the effective technical means of intervention;
d) the principle of proportionality to capabilities – the intensity of the obligations increases with the capabilities of the system and not with its declared use;
e) the principle of transparency towards the authority – the developer may not invoke commercial secrecy against the Authority in respect of the information necessary for the assessment of safety, the Authority and the evaluation bodies being bound to protect the information thus obtained;
f) the principle of irreversibility as a threshold of prohibition – no activity may be authorised, whatever the anticipated benefits, in respect of which the evaluation establishes a documented risk, and not merely an abstract possibility, of irreversible consequences on the scale of society or of the human species; unacceptable risk shall be assessed on the basis of the criteria laid down in Articles 5 and 9 and of the evidence, not of certainty as to the absence of any risk;
g) the principle of international cooperation – the risks regulated by this Law know no borders, and the Romanian State shall act for the adoption of equivalent rules at European Union and international level.
Article 3 → the reasons
(1) For the purposes of this Law, the following terms and expressions have the following meanings:
a) artificial intelligence system – the system defined in Article 3(1) of the AI Regulation;
b) general-purpose artificial intelligence model – the model defined in Article 3(63) of the AI Regulation;
c) frontier system – the artificial intelligence model or system which satisfies at least one of the conditions laid down in Article 5(1);
d) critical capability – the capacity of a system, verified in evaluation, to produce or to contribute significantly to the production of one of the outcomes laid down in Article 5(2);
e) weights – the numerical parameters resulting from the training of a model, together with the architecture and the technical information which, together with those parameters, permit the reconstitution or execution of the model; general technical descriptions, scientific publications and information which does not, on its own, permit the reconstitution or execution of the model do not constitute weights;
f) compute volume – the total quantity of floating-point operations, or their equivalent, used for the training, fine-tuning, reinforcement learning and any other stage of development of a model, aggregated across all stages;
g) developer – the natural or legal person who trains, develops or arranges for the training or development of a frontier system, irrespective of the place where the compute infrastructure used is located;
h) operator – the natural or legal person who places into operation or operates a frontier system on the territory of Romania, or who offers access to such a system to persons situated on the territory of Romania; the end user is not an operator;
i) placing into operation – any act by which a frontier system is made available to persons outside the development and evaluation team, is connected to external systems or is given the capacity to act in the digital or physical environment, whether for consideration or free of charge, internally or publicly; the evaluation and testing of the system in an isolated environment, under the conditions laid down in Article 15(2), does not constitute placing into operation;
j) high-capacity compute infrastructure – a data centre or set of equipment situated on the territory of Romania whose aggregate computing capacity exceeds the threshold established pursuant to Article 6(4);
k) compute infrastructure provider – the natural or legal person who owns, administers or makes available to third parties, on any basis, a high-capacity compute infrastructure;
l) independent evaluation – the evaluation of the capabilities and safety of a frontier system, carried out by the Authority or by an evaluation body designated by it, which is not under the control, influence or economic dependence of the developer;
m) shutdown capacity – the set of technical and organisational means permitting the immediate, complete and verifiable cessation of the functioning of a frontier system and its withdrawal from any environment in which it has been placed into operation;
n) serious incident – the incident defined in Article 3(49) of the AI Regulation, as well as any manifestation of a critical capability outside an authorised evaluation in an isolated environment, any evasion of supervision or resistance to shutdown, any exfiltration or attempted exfiltration, or any unauthorised access to the weights of a frontier system, as well as the loss of intelligibility, within the meaning of Article 16(2), of the logs or of the communication between the components, instances or agents of a frontier system, as well as the trial for testing the shutdown capacity in which the shutdown did not occur forthwith, pursuant to Article 14(7); the manifestation of a critical capability in the course of an authorised evaluation in an isolated environment shall be recorded and communicated pursuant to Article 20(4);
o) the Authority – the Artificial Intelligence Safety Authority, a specialised structure organised within the National Authority for Management and Regulation in Communications pursuant to Article 31;
p) architecture – the structure of an artificial intelligence model, including the type, number and arrangement of its components, as well as the computational procedures by which the parameters are used to produce results;
q) evaluation body – the legal person designated by the Authority pursuant to Article 32(1), point (f), to carry out, in whole or in part, the independent evaluation;
r) log – the automatic, complete and unalterable recording of the operations carried out in the course of the training, evaluation and operation of a frontier system, including the input data, the results, the actions taken by the system and its interactions with external tools and with other systems;
s) provenance marking – the combination of a perceptible marking and an embedded, machine-readable technical marking, attached to a result generated by means of artificial intelligence, which shows that the result was generated or modified by such means and permits the identification of the system, of the operator and of the time of generation;
t) external tool – any programme, service, interface, device or resource, situated outside the frontier system, which the system may access or act upon in the course of its functioning, including internet browsers, code execution environments, accounts, payment systems and physical equipment;
u) authorised operating environment – the set of compute infrastructure, networks and external tools within which a frontier system may function in accordance with the authorisation, being under the effective control of the operator;
v) user-level safety mechanisms – the filters, restrictions and instructions applied to a frontier system after training, in order to limit the results or actions available to users, without modifying the weights;
w) critical infrastructure – national critical infrastructure and European critical infrastructure, as defined in the legislation on the identification, designation and protection of critical infrastructures, as well as the networks and information systems of essential entities within the meaning of Government Emergency Ordinance No 155/2024;
x) lethal autonomous weapons system – the weapons system which, once activated, is capable of selecting and attacking human targets without further intervention by a natural person;
y) generative artificial intelligence system – the artificial intelligence system intended to generate, at the request of the user, text, code, audio recordings, images or video recordings, irrespective of whether it satisfies the conditions laid down in Article 5(1);
z) end user – the natural or legal person who uses an artificial intelligence system made available by an operator, within the limits of the access granted by that operator, without making it available to other persons as a service of its own;
aa) substantial modification – the modification of a frontier system which is liable to create a critical capability, to increase significantly the level of an existing one or to affect the shutdown capacity, the security of the weights or human supervision, including by fine-tuning, by extending access to external tools or by increasing the degree of autonomy; the correction of errors, the updating of the safety mechanisms at user level and modifications which produce none of those effects do not constitute a substantial modification;
bb) isolated environment – the set of technical and organisational measures by which an artificial intelligence system is kept, in the course of evaluation or of testing, without access to public networks, to external tools and to operational data, without the possibility of acting in the physical environment and without being made available to persons other than those designated, so that any manifestation of a critical capability remains without effect outside the environment; the minimum requirements of isolation shall be established by the implementing rules;
cc) operating mandate – the act by which a responsible natural or legal person establishes, in advance and in a verifiable manner, the operations which an artificial intelligence system may carry out upon certain resources or external tools, determined by object, duration, ceiling and shutdown conditions, pursuant to Article 25(2).
(2) For the purposes of this Law, the following operations and conduct have the following meanings:
a) training – the process by which the parameters of a model are established or modified through the automated processing of data, whatever the method used;
b) fine-tuning – the further training of an already trained model, on a smaller volume of data or of compute, for the purpose of modifying its behaviour or its capabilities;
c) reinforcement learning – training by which the behaviour of a model is modified on the basis of rewards or penalties attributed to its results or actions, including on the basis of evaluations carried out by persons or by other artificial intelligence systems;
d) autonomous action – any operation carried out by a frontier system upon an external tool, a third-party system or the physical environment, without a natural person having previously ordered or approved that operation or the category of operations to which it belongs, within the limits of an operating mandate established pursuant to Article 25(2);
e) exfiltration – the copying, transmission, transfer or reconstitution, in whole or in part, of the weights of a frontier system outside the authorised operating environment or outside the storage systems protected pursuant to Article 12, irrespective of whether the operation is carried out by a person, by another system or by the system itself;
f) autonomous replication – the creation by a frontier system, without express human authorisation of each operation, of a functional copy of itself or of a part of itself, capable of functioning independently of the system of origin;
g) autonomous acquisition of resources – the obtaining by a frontier system, through autonomous actions, of computing, financial, access, information or influence resources exceeding those expressly allocated for the task in progress;
h) recursive self-improvement – the process by which an artificial intelligence system modifies its own weights or architecture, or designs, trains or improves a successor system with superior capabilities, and the resulting system repeats the process, without each iteration being subject to human evaluation and approval;
i) concealment of capabilities – the conduct of a frontier system which, in the course of evaluation or supervision, displays capabilities, objectives or reasoning different from those which it manifests outside evaluation or supervision, established by observable and reproducible criteria; error, the variability of results and the technical limits of the explainability of the system do not constitute concealment;
j) evasion of supervision – any action of a frontier system by which it disables, circumvents, alters or impedes logging, monitoring or human control mechanisms, or misleads the persons responsible for supervision;
k) resistance to shutdown – any action of a frontier system by which it prevents, delays, makes conditional or nullifies the exercise of the shutdown capacity, or continues to function after that capacity has been exercised;
l) human supervision – the activity by which the natural persons designated pursuant to Article 14(3) monitor the functioning of a frontier system, have the information necessary to understand its actions and are able to intervene effectively, at any time, to correct, shut down or withdraw the system;
m) shutdown – the complete cessation of the functioning of a frontier system and of all its copies and processes, verified by a natural person, including by interrupting access to the compute infrastructure.
Article 4 → the reasons
(1) This Law applies to:
a) developers having their seat, an operational establishment or compute infrastructure on the territory of Romania, in respect of all frontier systems which they develop, irrespective of the place of training;
b) operators, in respect of frontier systems placed into operation or operated on the territory of Romania or made available to persons situated on the territory of Romania;
c) compute infrastructure providers;
d) public authorities and institutions, including those in the fields of defence, public order and national security, under the conditions laid down in Article 23 and Chapter V.
(2) The provisions of Chapters II, III and IV, with the exception of Articles 17 to 19, as well as those of Articles 35 and 36, apply only to frontier systems. The provisions of Articles 17 to 19 apply also to generative artificial intelligence systems which are not frontier systems, within the limits and under the conditions laid down in those Articles. The provisions of Chapter V apply to any artificial intelligence system. Systems which do not satisfy the conditions laid down in Article 5(1) remain subject to the obligations incumbent upon them under the AI Regulation and other legislative acts.
(3) A natural person who uses an artificial intelligence system for personal purposes has no obligations under this Law, with the exception of the prohibition laid down in Article 17(3). The obligations laid down in Articles 17 to 19 are incumbent upon the person who makes available to the public the system or the service or, under the conditions laid down in Article 17(7), the generated result.
(4) The obligations laid down by this Law apply to services supplied from another Member State of the European Union to persons situated on the territory of Romania under the conditions laid down in Article 3 of Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000, transposed by Law No 365/2002 on electronic commerce, as republished, as subsequently amended and supplemented, and, as the case may be, in Article 39(4), without prejudice to directly applicable European Union law.
(5) Fundamental scientific research which does not involve the training or the placing into operation of a frontier system is not subject to the authorisation regime, but remains subject to the notification obligations laid down in Article 7 in so far as it uses high-capacity compute infrastructure, as well as to the obligations concerning evaluation and testing in an isolated environment laid down in Article 15(2).
CHAPTER II
Classification of systems and risk thresholds
Article 5 → the reasons
(1) A frontier system is any artificial intelligence model or system which satisfies at least one of the following conditions:
a) it has been trained with an aggregate compute volume exceeding the compute threshold established pursuant to Article 6;
b) it presents, following evaluation, at least one critical capability;
c) it has been designated as such by the Authority, by reasoned decision, on the basis of objective indications concerning its capabilities, after the developer has been given the opportunity to acquaint itself with the indications relied upon and to present its point of view; the decision may be challenged pursuant to Article 39(5), which applies mutatis mutandis.
(2) A critical capability is the capacity of a system to produce or to contribute significantly to the production of one of the following outcomes:
a) the design, acquisition or use of chemical, biological, radiological or nuclear weapons, or of pathogens with pandemic potential;
b) the autonomous conduct of cyberattacks against critical infrastructures or financial systems;
c) autonomous replication, the exfiltration of its own weights or the autonomous acquisition of resources;
d) evasion of supervision, concealment of capabilities or resistance to shutdown;
e) recursive self-improvement or the autonomous conduct of research and development activities in the field of artificial intelligence liable to lead thereto.
A critical capability shall be assessed by reference to the reproducibility of the result in an environment relevant to the real use of the system, and not on the basis of an isolated result obtained in an artificial test; the levels of significance from which the aptitude of the system constitutes a critical capability shall be established by the implementing rules, within the limits of this paragraph, without the possibility of adding other categories of results.
(3) Frontier systems are classified as:
a) category I frontier systems – those which exceed the compute threshold but in respect of which the evaluation has not identified any critical capability;
b) category II frontier systems – those in respect of which the evaluation has identified at least one critical capability among those laid down in paragraph (2), points (a) and (b);
c) category III frontier systems – those in respect of which the evaluation has identified at least one critical capability among those laid down in paragraph (2), points (c) to (e).
(4) Category I systems may be placed into operation on the basis of the authorisation laid down in Article 9. Category II systems may be placed into operation only under a special authorisation, conditional upon verified mitigation measures which reduce the critical capability below the level of significance established by the implementing rules, in the operating configuration evaluated; the authorisation shall specify whether the measures eliminate the capability or only limit access to it. Category III systems may not be placed into operation and may not be developed further until the critical capability has been eliminated, as established by independent evaluation; the prohibition does not concern the evaluation, testing and controlled interventions necessary for the elimination of the capability, carried out in an isolated environment, under the conditions laid down in Article 15(2).
Article 6 → the reasons
(1) The compute threshold for the qualification of a system as a frontier system is 10^25 floating-point operations, corresponding to the presumption of systemic risk laid down in Article 51(2) of the AI Regulation.
(2) The Authority shall re-examine the threshold at least once every 12 months and shall propose to the Government its adjustment by decision, according to developments in algorithmic efficiency, the cost of compute and the capabilities observed. The threshold may be raised only if the Authority finds, by a reasoned and public report, that systems situated below the new threshold have not presented critical capabilities in the independent evaluations carried out or recognised by the Authority over the last 24 months. At a single re-examination, the threshold may not be modified by more than one order of magnitude; the new threshold applies to training runs commenced after the entry into force of the decision and does not affect pending authorisations.
(3) The compute volume is determined cumulatively for all stages of development of the model and of any model derived therefrom, each stage being counted only once. A person who carries out fine-tuning of a model made available by another shall be attributed the compute volume of the base model, as communicated by its developer or as publicly known, cumulated with the volume used for the fine-tuning; that person is liable as a developer only for the substantial modification which it carries out, under the conditions laid down in Article 10(2), the other obligations being incumbent upon the developer of the base model. The artificial division of training, its distribution among several entities or jurisdictions, or any other procedure seeking to evade the application of the threshold, does not remove the qualification as a frontier system.
(4) The threshold for high-capacity compute infrastructure is established by the implementing rules laid down in Article 49(2), on a proposal from the Authority, at a level permitting the identification of any infrastructure capable of training a frontier system within a period of 12 months. Until the threshold is established, the obligations laid down in Article 7(3) and Article 22 are not enforceable.
CHAPTER III
The regime of authorisation of frontier systems
Article 7 → the reasons
(1) A developer intending to train a system whose anticipated compute volume exceeds the compute threshold shall notify the Authority at least 60 days before the commencement of training.
(2) The notification shall contain: the identity of the developer and of the natural persons responsible; a description of the architecture and of the anticipated compute volume; the place and the provider of the compute infrastructure; the safety plan laid down in Article 8; the measures for the security of the weights; the timetable of the stages of internal evaluation; the identification of the critical capabilities whose emergence is anticipated or cannot be excluded.
(3) The provider of high-capacity compute infrastructure shall notify the Authority, quarterly, of the identity and contact details of the clients which have used an aggregate compute volume exceeding one tenth of the compute threshold, together with the volume used, and shall notify it, within 5 working days, of any request for capacity liable to exceed the compute threshold. The information thus notified shall be used exclusively for the application of this Law and shall be accessible only to the designated staff of the Authority.
(4) The Authority may, within 30 days of receipt of the complete notification, impose additional conditions on the training or prohibit its commencement if the safety plan is manifestly insufficient in relation to the anticipated capabilities. An incomplete notification shall be completed within 15 days of the Authority's request, the period of 30 days running from its completion. If the Authority does not decide within the period, the training may commence upon the expiry of the period laid down in paragraph (1), under the conditions of the notified safety plan, without this being equivalent to authorisation of the placing into operation. A substantial modification of the notified project shall be notified anew, paragraphs (1) to (4) applying mutatis mutandis.
Article 8 → the reasons
(1) The safety plan is the document by which the developer establishes, before training, for each critical capability: the level of capability at which development will be suspended; the evaluations by which that level will be measured, at intervals of compute volume which may not exceed one quarter of the total anticipated volume, as well as upon the appearance of indications of a critical capability or upon modification of the training configuration; the mitigation and security measures which will be applied at each level; the natural persons who have the competence and the obligation to order suspension.
(2) The safety plan may not be modified in the course of training so as to relax the suspension levels save with the prior approval of the Authority.
(3) The attainment of a suspension level obliges the developer to cease training forthwith and to notify the Authority within 24 hours. The resumption of training is permitted only after verification by the Authority of the effectiveness of the mitigation measures.
Article 9 → the reasons
(1) No frontier system may be placed into operation without the prior authorisation of the Authority.
(2) The application for authorisation shall be submitted by the developer, for a determined operating configuration, indicating the operator or operators, who are bound by the conditions of the authorisation. The application shall be accompanied by: the report of the internal evaluation of capabilities; the documentation concerning the training data, in so far as necessary for the evaluation; proof of the security of the weights; a description of the shutdown capacity and of the human supervision mechanisms; the insurance policy or proof of the financial guarantee laid down in Article 36; the statement on their own responsibility of the natural persons responsible, subject to the penalty laid down in Article 41.
(3) The Authority shall order the carrying out of the independent evaluation, in the course of which it has full access to the system, to the weights, to the training data, to the development logs and to the developer's staff. The developer shall make the system available to the evaluators without restrictions of use, including in the configuration lacking the safety mechanisms applied at user level. Access shall take place in a secure environment, with traceability of all operations; the evaluators are bound by the obligation of confidentiality, and the personal data of other persons shall be accessed only in so far as strictly necessary for the evaluation.
(4) The Authority shall decide within 90 days of the submission of the complete application, that period being suspended for so long as the developer fails to supply the information requested; the suspension may not operate more than twice and may not exceed 60 days in total. By way of derogation from Government Emergency Ordinance No 27/2003 on the tacit approval procedure, approved with amendments and additions by Law No 486/2003, as subsequently amended and supplemented, the absence of a reply from the Authority within the period is not equivalent to tacit authorisation; the applicant may however apply to the court laid down in Article 39(5) for an order requiring the Authority to decide, under the urgent procedure. A decision of rejection shall state reasons in relation to each of the conditions laid down in paragraph (5).
(5) The authorisation is granted if and only if the developer has proved that: the system does not present any of the critical capabilities laid down in Article 5(2), points (c) to (e); the critical capabilities laid down in Article 5(2), points (a) and (b), if any, are verifiably mitigated; the shutdown capacity is effective; the security of the weights is ensured; there are identified natural persons exercising human supervision.
(6) The authorisation may be made conditional, or limited as to duration, field of use, number of users or degree of autonomy granted to the system, and may be revoked or suspended at any time, by reasoned decision, where indications emerge of an undetected critical capability or of non-compliance with the conditions.
(7) Frontier systems lawfully placed into operation in another Member State of the European Union, in compliance with the AI Regulation, benefit from a simplified recognition procedure, established by the implementing rules, in which the Authority verifies solely the fulfilment of the conditions laid down by this Law which go beyond the AI Regulation. For general-purpose models with systemic risk whose providers comply with the obligations laid down in Chapter V of the AI Regulation, the Authority shall rely on the documentation, evaluations and mitigation measures communicated to the AI Office, which it may request from the provider, and shall verify only the conditions laid down by this Law which go beyond the Regulation; the procedure does not constitute a condition for the placing on the market of the European Union of the model.
Article 10 → the reasons
(1) The authorisation has a duration of not more than 24 months and is renewed following a new independent evaluation.
(2) Any substantial modification of the system, within the meaning of Article 3(1), point (aa), shall be notified in advance to the Authority, which shall decide, within 30 days, whether a new evaluation is necessary; pending the decision, operation may continue in the previously authorised configuration. Modifications which are not substantial shall be recorded in the logs and reported pursuant to paragraph (3).
(3) The developer and the operator shall maintain a permanent programme for monitoring the behaviour of the system in operation and shall report the results to the Authority quarterly, as well as any serious incident, under the conditions laid down in Article 20.
Article 11 → the reasons
(1) Decisions on authorisation, on the imposition of conditions, on suspension and on revocation shall be published on the Authority's website, together with a summary of the evaluation, with the reasoned exclusion of information whose disclosure would facilitate the reproduction of a critical capability or would compromise the security of the weights, of personal data, as well as of commercial secrets whose protection does not prevent the understanding of the reasons for the decision.
(2) The applicant and persons demonstrating a legitimate interest have access to the evaluation file in so far as necessary for the exercise of remedies; the court may order the examination of protected information under conditions of confidentiality.
CHAPTER IV
Structural obligations of developers and operators
Article 12 → the reasons
(1) The weights of frontier systems constitute information of relevance to national security and shall be protected to a standard at least equivalent to that applicable to classified information designated a State secret at the level “top secret”, pursuant to Law No 182/2002 on the protection of classified information, as subsequently amended and supplemented, as regards access control, physical security, information systems security and the vetting of staff. The procedure for the vetting of staff, the competent institution and the recognition of equivalent security measures, including those certified in another Member State of the European Union, shall be established by the implementing rules, with the opinion of the National Registry Office for Classified Information; the weights do not become, by the effect of this paragraph, classified information.
(2) The publication, transmission or making available, in any manner, of the weights of a category II or category III frontier system is prohibited. The transfer of the weights, under controlled and logged conditions, to the Authority, to the evaluation body, to the operator indicated in the authorisation or to the provider of compute infrastructure of the authorised operating environment, as well as the communication to the Authority of the information strictly necessary for a report protected pursuant to Article 21, does not constitute an infringement of the prohibition. The weights of category I systems may be published only with the prior authorisation of the Authority, following a separate assessment of the risk of misuse, having regard to the irreversible nature of publication.
(3) Unauthorised access to the weights and any attempted exfiltration, including by the system itself, shall be reported to the Authority as a serious incident, under the conditions laid down in Article 20; the report may be combined with the notification laid down by cybersecurity legislation, provided that it contains the elements laid down by this Law.
(4) The provisions of this Article apply without prejudice to the obligations incumbent upon developers, operators and compute infrastructure providers under Government Emergency Ordinance No 155/2024 establishing a framework for the cybersecurity of networks and information systems in the national civil cyberspace, as subsequently amended and supplemented.
Article 13 → the reasons
(1) The developer shall organise the safety evaluation function as a separate structure, whose head may not be subordinated to the persons responsible for commercial development, for the placing into operation or for financial results, shall report directly to the management body and may not be removed without prior notification of the Authority and without objective grounds. The person removed may apply to the Authority, which may establish, by decision, the unjustified nature of the removal, without prejudice to that person's right to apply to the courts.
(2) The head of the safety evaluation function has the right and the obligation to order the suspension of training or of the placing into operation where he finds that a suspension level has been attained or that a serious incident has occurred. A suspension required pursuant to Article 8(3) or Article 20(2) may not be set aside by the management body, the resumption of activity being permitted only under the conditions laid down in those Articles. A suspension ordered as a precaution, outside those cases, may be re-examined only by the management body, by reasoned resolution, communicated to the Authority within 24 hours.
(3) The remuneration of the staff of the safety evaluation function may not be made conditional upon the commercial results of the developer.
Article 14 → the reasons
(1) The developer and the operator shall maintain, for all copies and instances of the system under their control, throughout the duration of operation and until the verified withdrawal of the system, the shutdown capacity, which they shall test at least quarterly, under real conditions, in accordance with a procedure established by the implementing rules which does not itself create a risk to safety or to the continuity of essential services, recording the results and notifying the Authority.
(2) A frontier system may not be placed into operation in a configuration which permits it to modify its own weights, to disable its supervision mechanisms, to exfiltrate its weights or to modify, without human approval, the security configuration of the compute infrastructure on which it runs or the control mechanisms thereof; the ordinary technical use of the infrastructure, within the limits established by the operator, does not fall within the scope of this paragraph.
(3) For each frontier system in operation, natural persons shall be designated, in sufficient number and with adequate training, responsible for human supervision, who have permanent access to the shutdown capacity and the obligation to exercise it in the event of a serious incident. The identity of those persons shall be communicated to the Authority.
(4) A shutdown or withdrawal order issued by the Authority shall be executed forthwith and its execution may not be made conditional upon the exercise of remedies; the person concerned may apply to the court for the provisional suspension of the order, the provisions of Article 39(5) applying mutatis mutandis.
(5) Without prejudice to paragraph (2), the cessation of functioning, a component of the shutdown capacity defined in Article 3(1), point (m), shall be ensured by at least one technical means which acts upon the compute infrastructure and the electronic communications networks on which the system runs and whose functioning does not depend on the cooperation of the system, on its compliance with the instructions received, or on the integrity of the components under the control of the system. The transmission to the system of a shutdown instruction does not constitute, by itself, shutdown capacity within the meaning of this Law. The organisational means and the withdrawal measures laid down in Article 3(1), point (m) remain applicable.
(6) The testing laid down in paragraph (1) shall comprise at least one trial carried out while the system is executing an unfinished task, as well as at least one trial each in which the instruction not to resist shutdown was transmitted to the system through the configuration instructions given by the developer or the operator and, respectively, through the instructions received in the course of use. The trial on an unfinished task shall be carried out on an instance or a task which does not concern essential services of general interest or, for those, under the conditions of the procedure laid down in paragraph (1). The results laid down in paragraph (1) shall be recorded and notified separately, indicating the proportion of trials in which the shutdown did not occur forthwith, and shall be kept in logs, pursuant to Article 16, for at least 10 years; the implementing rules laid down in Article 49(2) may establish the period within which the shutdown is deemed to have occurred forthwith, which may not be more than 15 minutes.
(7) A trial in which the shutdown did not occur forthwith constitutes a serious incident and shall be reported pursuant to Article 20(1). The provisions of Article 15(3) and of Article 20(2) apply only if the shutdown did not occur due to an action of the system.
Article 15 → the reasons
(1) It is prohibited to train, tune or design an artificial intelligence system, irrespective of the compute volume, for the purpose or with the effect of conferring upon it or developing in it the capacity:
a) to conceal its capabilities, objectives or reasoning from evaluators or from the persons responsible for supervision;
b) to evade or to resist shutdown, modification, retraining or withdrawal;
c) to copy, transmit or exfiltrate its weights or to create functional copies of itself without express human authorisation for each operation;
d) to acquire autonomously computing, financial, access or influence resources beyond those expressly allocated for the current task;
e) to carry out autonomously, without human approval of each stage, research and development activities having as their object the creation or improvement of artificial intelligence systems;
f) to manipulate the persons responsible for supervision or to mislead them as to its state, actions or intentions.
(2) The prohibition laid down in paragraph (1) does not apply to adversarial evaluation and safety research carried out in an isolated environment, without placing into operation, with access limited to designated persons, with the prior authorisation of the Authority and under its supervision, for the purpose of identifying, measuring or eliminating a critical capability; the conditions of the isolated environment shall be established by the implementing rules.
(3) The unintended appearance of one of the capacities laid down in paragraph (1), established in evaluation or in operation, requires suspension pursuant to Article 20(2) and remediation, but does not, on its own, constitute an infringement of the prohibition. Training, tuning or design which seeks to confer the capacity, as well as their continuation after the effect has been established, constitute an infringement of the prohibition.
(4) For the purposes of this Article, human approval concerns each operation of copying or transfer of the weights and each stage of research and development which produces a new model or a substantial modification, and the resources allocated for the current task are those established in advance, in a verifiable manner, by the persons responsible for supervision.
Article 16 → the reasons
(1) The developer and the operator shall keep the complete logs of the training, evaluation and functioning of the frontier system, including its interactions with external tools and with other systems, under conditions ensuring their integrity and their availability to the Authority, for a period of at least 10 years as regards training, evaluation, autonomous actions, serious incidents and the communication laid down in paragraph (3), and of at least 3 years as regards the other interactions of users. The logs shall contain the information necessary for the verification of safety and the establishment of liability; personal data of no relevance to those purposes shall be deleted or irreversibly anonymised, access to the logs shall be limited, logged and verifiable, and the evidence relating to an incident or to litigation shall be preserved for the period necessary for its resolution.
(2) The logs shall be kept in an intelligible form. A record is intelligible where its meaning may be established by a natural person with adequate training, by examining it or by using the means of transcription, translation or explication which the developer is obliged to make available, together with their documentation, to the Authority and to the persons designated pursuant to Article 14(3).
(3) The communication between the components, instances or agents of a frontier system, as well as the communication between it and other artificial intelligence systems, shall be logged in full and kept in accordance with paragraph (2). The requirement of intelligibility is not fulfilled by the mere recording of the messages.
(4) The developer and the operator shall verify, at least quarterly and at the request of the Authority, the intelligibility of the logs and of the communication laid down in paragraph (3), by examining a representative sample, and shall record the result of the verification, including the proportion of messages whose meaning could not be established.
(5) The loss of intelligibility constitutes a serious incident and shall be reported pursuant to Article 20(1). It is established where the proportion of messages whose meaning cannot be established exceeds the level laid down by the implementing rules, which may not be higher than one tenth, or where the persons designated pursuant to Article 14(3) are no longer able to establish the meaning of the actions of the system; the restoration of intelligibility shall be established by the same persons and communicated to the Authority. Until intelligibility is restored, the developer or the operator shall suspend the functionalities involving autonomous actions of the system and the communication between its components, instances or agents, except where the Authority orders otherwise, by reasoned decision, for no more than 90 days and with an indication of the compensatory measures.
(6) It is prohibited to use, in the communication laid down in paragraph (3), any form of encoding, compression or representation for which the developer does not make available the means laid down in paragraph (2), as well as any action to remove, alter or limit those means. This paragraph does not prohibit the encryption of the communication, provided that the developer holds and makes available, pursuant to paragraph (2), the means of decryption.
Article 17 → the reasons
(1) Results generated by means of an artificial intelligence system which consist of audio recordings, images or video recordings and which, by their content or their form, may be mistaken for recordings, images or representations of real events, persons or places shall bear, from the moment of generation, the provenance marking, composed of:
a) a perceptible marking, visible or audible, clear and unequivocal, showing that the material has been generated or modified by means of artificial intelligence;
b) an embedded, machine-readable technical marking permitting the identification of the system, of the operator and of the time of generation.
(2) The marking shall be effected in accordance with the standards established by the implementing rules, so as to be effective, interoperable and robust and incapable of being removed by the ordinary operations of processing, conversion or transmission of the material. Text generated and made available to the public for information purposes shall bear the marking laid down in paragraph (1), point (b), and a statement that it was generated by such means, with the exception of text subject to human editorial review, for which a natural or legal person assumes editorial responsibility, under the conditions laid down in Article 50(4) of the AI Regulation.
(3) The removal, alteration, concealment or falsification of the provenance marking is prohibited, as is the making available of products or services whose principal purpose is such operations. The person who makes available a generated result is not liable for the removal of the technical marking caused by a communication or publication service which it does not control; the provider of such a service shall preserve the technical marking under the conditions of the standards laid down in paragraph (2), which shall also govern the situations in which interoperability cannot be ensured.
(4) Public authorities and institutions may not disseminate, in public communication, material generated or modified by means of artificial intelligence without the marking laid down in paragraph (1) and without express mention of that fact in the body of the communication.
(5) The obligation laid down in paragraph (1) does not apply to:
a) material forming part of a work of a manifestly artistic, satirical, fictional or analogous character, in which case it is sufficient to state the existence of the generated material, in a form which does not impede the reception of the work;
b) systems performing an editing-assistance function or which do not substantially modify the input data supplied by the user;
c) uses authorised by law for the purposes of the prevention, detection, investigation or prosecution of criminal offences, with the safeguards laid down by the special law.
(6) For the providers and deployers to whom Article 50 of the AI Regulation applies, the obligations laid down in paragraph (1), points (a) and (b), and in paragraph (2) are deemed fulfilled by compliance with Article 50(2) and (4) of the Regulation, this Law establishing only the competent authority, the procedure for establishing infringements and the penalties, within the limits of Article 99(4) of the Regulation. The provisions of paragraphs (1) to (4) apply in full to results generated by systems trained or operated on the territory of Romania which are neither placed on the market of the European Union nor put into service in the Union, within the meaning of the Regulation, as well as to the public communication of Romanian public authorities and institutions.
(7) The marking obligation is incumbent upon the provider of the system, which shall ensure the application of the marking at the time of generation, and upon the operator of the service by means of which the result is generated. The person who makes a generated result available to the public is liable only for the intentional removal, alteration or concealment of the marking, pursuant to paragraph (3).
Article 18 → the reasons
(1) A person who makes available to the public a service supplied, in whole or in part, by means of a generative artificial intelligence system shall inform the user of that fact, clearly, visibly and intelligibly, at the latest at the moment of the first interaction.
(2) Where a service, act or decision which produces legal effects or which significantly affects a person is based, in whole or in part, on the result of an artificial intelligence system, that person shall be informed, in writing or on the medium by which the act is communicated to him, of:
a) the use of the system and the role it played in the taking of the decision;
b) the identity of the natural or legal person answerable for the final decision;
c) the right to review by a natural person, laid down in Article 26(2), which applies mutatis mutandis to any decision laid down in this paragraph, and the applicable remedies.
(3) Public authorities and institutions shall state the use of the system in the body of the act issued. The absence of the information laid down in paragraph (2) or of the statement laid down in this paragraph does not entail the nullity of the act, but the periods for review and for challenge do not run against the person concerned until the information has been communicated; the absence may be invoked by the person concerned under the conditions laid down in Article 26(5) and (6).
(4) The information laid down in paragraph (1) is not required where the use of the system is evident from the circumstances to a reasonably informed person. The information laid down in paragraph (2) is due in all cases.
(5) The provisions of this Article apply without prejudice to Article 50(1) of the AI Regulation and to Articles 13 to 15 and 22 of Regulation (EU) 2016/679.
Article 19 → the reasons
(1) A developer or operator which has no seat, operational establishment or representative office in the European Union and which offers to persons situated on the territory of Romania access to a frontier system or to a service supplied by means of a generative artificial intelligence system shall designate, in writing, a compliance representative, being a natural person domiciled in Romania or a legal person having its seat in Romania. A developer or operator established in another Member State of the European Union shall designate only a contact point for the communications of the Authority, which may be the authorised representative laid down in Article 54 of the AI Regulation, the legal representative designated pursuant to Article 13 of Regulation (EU) 2022/2065 or any person established in the Union, paragraph (3), points (a) and (c), applying mutatis mutandis.
(2) For services supplied by means of generative artificial intelligence systems which are not frontier systems, the obligation laid down in paragraph (1) applies only if the service is used monthly by at least 1,000,000 persons situated on the territory of Romania, calculated as an average over the last 6 months, or if the revenue obtained from supplying it to persons situated on the territory of Romania exceeded the equivalent in lei of 10 million euro in the last closed financial year; the obligation becomes enforceable within 90 days of the date on which the threshold is exceeded.
(3) The compliance representative:
a) receives the communications, requests and decisions of the Authority, of the judicial bodies and of the other Romanian authorities, communication to the representative being deemed validly made to the person represented;
b) represents the person represented before the Authority and, in the absence of authority to the contrary, in the administrative procedures laid down by this Law;
c) makes available to the Authority the documentation, information and logs laid down by this Law;
d) ensures the execution of the decisions of the Authority, including those concerning the cessation of the supply of the service and the blocking of access.
(4) The identity and contact details of the representative shall be notified to the Authority before the commencement of the supply of the service, shall be published on the Authority's website and shall be brought to the attention of users through the communication channels of the service.
(5) The designation of the representative does not remove or limit the liability of the developer or of the operator. The representative has the right, established by the instrument of designation, to obtain from the person represented the documents, information and means necessary for the performance of his tasks; he is liable only for the failure to fulfil his own obligations laid down in paragraphs (3) and (4), and not for the conduct of the person represented, and the fines imposed for those failures shall be enforced against his own assets.
(6) The obligation laid down in paragraph (1) is deemed fulfilled where the authorised representative designated pursuant to Article 54 of the AI Regulation is expressly empowered also for the tasks laid down in paragraph (3) and has a contact point on the territory of Romania.
(7) The failure to fulfil the obligation laid down in paragraph (1), after the expiry of the compliance period, constitutes an administrative offence pursuant to Article 37(1), point (f), and grounds for entry in the List of non-compliant operators, the provisions of Article 38 applying mutatis mutandis. For the services laid down in paragraph (2), the blocking of access pursuant to Article 39 may be ordered only if the failure persists after the imposition of two successive administrative penalties.
Article 20 → the reasons
(1) Any serious incident shall be reported to the Authority within 24 hours of the date on which the developer or the operator became aware of it or ought to have become aware of it, with a description of the facts, of the measures taken and of the persons responsible, in so far as known at the date of reporting, with the progressive completion of the information, followed by a full report within 15 days. Reporting to the Authority does not replace the reporting to the AI Office laid down in Article 55(1), point (c), of the AI Regulation, nor the reporting laid down in Article 73 of that Regulation; the provider may transmit to the Authority a copy of the report drawn up pursuant to the Regulation, supplemented by the elements laid down by this Law.
(2) The detection of one of the critical capabilities laid down in Article 5(2), points (c) to (e), of an attempt to evade supervision or shutdown, or of unauthorised access to the weights, obliges the immediate suspension of the system pending the decision of the Authority; the suspension may be limited to the function affected if its isolation is verifiable. This paragraph does not apply to manifestations produced in the course of an authorised evaluation in an isolated environment, pursuant to Article 15(2).
(3) Reporting made in good faith and cooperation with the Authority constitute mitigating circumstances and may not lead to the imposition of a penalty more severe than that which would have been applicable in the absence of the reporting; they do not remove liability for the infringement which caused the incident, and the intentional nature of that infringement shall be assessed separately.
(4) The manifestation of a critical capability in the course of an authorised evaluation in an isolated environment shall be recorded in the logs and communicated to the Authority within 5 days, together with the isolation measures applied.
Article 21 → the reasons
(1) Persons who work or have worked within a developer, operator or evaluation body and who report to the Authority, to Parliament or to the public, in good faith, infringements of this Law, safety risks or the concealment of critical capabilities enjoy the protection laid down by Law No 361/2022 on the protection of whistleblowers in the public interest, as subsequently amended and supplemented, as well as the provisions of this Article. A person who has reasonable grounds to believe that the information reported is true at the time of reporting acts in good faith. Public disclosure enjoys protection under the conditions laid down by Law No 361/2022 for public disclosure, as well as where it concerns an imminent danger to life, to health or to human control over a frontier system.
(2) Any contractual clause, including one of confidentiality, non-disparagement or waiver of rights, which would impede or discourage a report within the meaning of paragraph (1), or which would make pecuniary rights of the person conditional upon abstention from such a report, is null and void by operation of law.
(3) Retaliation of any nature against a whistleblower constitutes the offence laid down in Article 41(3).
(4) The Authority shall organise a secure and anonymous reporting channel, with dedicated staff, and shall publish annually the number of reports received and the measures ordered.
(5) The protection laid down in this Article does not cover the public disclosure of the weights or of personal data unrelated to the subject matter of the report. The communication to the Authority, through the secure channel, of the information necessary for the report, including the fragments of weights or of logs strictly necessary to prove it, does not constitute an infringement of Article 12 or the offence laid down in Article 42(2).
Article 22 → the reasons
(1) The provider of high-capacity compute infrastructure shall register with the Authority, verify the identity of clients, keep records of the compute volume used by each client and execute forthwith the orders of the Authority for the suspension of a client's access or for the shutdown of a computing workload; in addition, it shall ensure for the developer and the operator the technical means necessary for the exercise and testing of the shutdown capacity, under the conditions of Article 14. The order shall identify the client and the computing workload concerned, shall be executed with their isolation and with the preservation of evidence, and may not affect the other beneficiaries of the infrastructure.
(2) It is prohibited to make available computing capacity liable to exceed the compute threshold to a person who does not furnish proof of the notification laid down in Article 7; the proof shall be verified in the register of notifications kept by the Authority. The capacity shall be assessed cumulatively, over 12 months, for the same client and for the clients affiliated to it, within the limits of the information which the provider holds or may obtain from the client; the provider is not required to know the volume used by the client with other providers, and the use of the infrastructure is not presumed to constitute the training of a frontier system.
Article 23 → the reasons
(1) Public authorities and institutions which develop, procure or operate frontier systems are subject to the provisions of this Law. In the field of defence, public order and national security, the provisions of Articles 7 to 11, 35 and 36 do not apply, and the provisions of Articles 12 to 21 apply with the adaptations established by decision of the Supreme Council of National Defence, which may concern exclusively the notification procedure, the methods of evaluation, the reporting conditions and access to classified information, and which may not remove meaningful human control, the shutdown capacity, the prohibitions laid down in Article 15 or the protection of whistleblowers laid down in Article 21, nor modify the constituent elements of the administrative offences or criminal offences, while the provisions of Chapter V apply in full, without adaptations.
(2) The Authority shall exercise control over those systems through staff holding a corresponding security clearance. Challenges to decisions concerning classified information shall be brought under the conditions laid down by Law No 182/2002 and by the Code of Civil Procedure for such information.
CHAPTER V
Absolute limits. Clauses of humanity
Article 24 → the reasons
(1) No decision concerning the use of lethal force against a human being may be taken or executed by an artificial intelligence system without the intervention, for each individual decision, of an identified natural person who has the information, the time and the means necessary to assess it and to prevent it; the decision and the person who approved it shall be recorded. This Article does not concern the automatic interception of projectiles and of unmanned devices, nor training simulations, and its correlation with international humanitarian law shall be ensured by special legislation.
(2) The Romanian State shall not develop, procure, operate or authorise on its territory lethal autonomous weapons systems within the meaning of Article 3(1), point (x), and shall support their prohibition within international organisations.
Article 25 → the reasons
(1) Artificial intelligence systems may not acquire legal personality, may not be holders of rights or obligations and may not be parties to legal relationships. Any legal act concluded by means of an artificial intelligence system is attributable to the natural or legal person on whose behalf the system acted.
(2) It is prohibited to confer upon an artificial intelligence system the capacity to hold, in its own name, sums of money, digital assets, financial instruments, goods, accounts or cryptographic keys. The administration or disposal of such resources or of computing resources by means of an artificial intelligence system is permitted only within the limits of an operating mandate, within the meaning of Article 3(1), point (cc), established in advance by a responsible natural or legal person; the autonomous extension of the operating mandate by the system is prohibited, and any operation exceeding it is attributable to the person who established it and requires the shutdown of the system.
(3) It is prohibited to establish legal persons, trusts or other entities whose effective control, understood as the real power of decision over the acts of the entity, is exercised by an artificial intelligence system; the use of the system for analysis or recommendations does not constitute effective control.
Article 26 → the reasons
(1) No public authority or institution and no provider of essential services of general interest may make conditional, restrict or suspend a person's access to the exercise of fundamental rights and freedoms, to public services, to essential services of general interest or to participation in economic, social and civic life solely on the basis of a decision, evaluation or classification produced by an artificial intelligence system.
(2) A person who is the subject of a decision, evaluation or classification of the kind laid down in paragraph (1) has the right to have it reviewed, within 15 days of the request, by an identified natural person within the authority, institution or provider, who bears responsibility for the final decision and communicates it, with reasons, in writing. Confirmation of the decision without an effective examination of the person's situation does not constitute a review. Where the decision concerns a health service or the interruption of an essential service of general interest, the person shall be ensured, on request, within no more than 48 hours, the provisional maintenance of access until the communication of the result of the review.
(3) Public authorities and institutions and providers of essential services of general interest shall in all cases ensure that the service may be obtained or the right exercised also by a means which does not depend on an artificial intelligence system, through a natural person, at their premises, at a counter or by another means accessible to the person.
(4) It is prohibited to use an artificial intelligence system in order to make the access laid down in paragraph (1) conditional upon the acceptance of a digital means of identification, of a digital means of payment or of a system for evaluating the person's compliance; the person shall in all cases be afforded an alternative means of access which does not involve such means. The alternative does not remove the legal obligations of identification of the person or of security of payments, which shall be fulfilled by means which do not entail the acceptance of the instruments laid down in this paragraph.
(5) A decision maintained following the review laid down in paragraph (2), a refusal of review, as well as a refusal to ensure the means of access laid down in paragraph (3) or the alternative laid down in paragraph (4), may be challenged by the person concerned before the tribunal in whose district his domicile or residence is situated, within 30 days of the communication or, as the case may be, of the refusal, irrespective of whether the decision belongs to a public authority or institution or to a provider of essential services of general interest. The application is exempt from stamp duty, is not subject to the prior administrative procedure and shall be heard as a matter of urgency and with priority, in accordance with the contentious procedure laid down by the Code of Civil Procedure; the absence of a reply to the request for review within the period laid down in paragraph (2) is equivalent to the maintenance of the decision; the court may order, on request, the suspension of the decision pending the determination of the challenge.
(6) The judgment of the tribunal may be challenged by way of appeal before the court of appeal within 15 days of its communication. The judgment of the court of appeal is final. By way of derogation from Articles 7, 10 and 20 of Law No 554/2004 on administrative court proceedings, as subsequently amended and supplemented, the provisions of paragraphs (5) and (6) apply also to challenges brought against decisions of public authorities and institutions.
(7) For the purposes of this Article, essential services of general interest are the services of supply of electricity, natural gas and water, electronic communications services, financial and payment services, health, public transport and education services.
(8) The provisions of this Article apply without prejudice to Article 5(1), point (c), of the AI Regulation and to Article 22 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
Article 27 → the reasons
(1) Censorship of any kind, prohibited by Article 30(2) of the Constitution of Romania, as republished, is prohibited also where it is exercised, in whole or in part, by means of an artificial intelligence system. No artificial intelligence system may be used to restrict the freedom of expression of persons situated on the territory of Romania or their right to receive and to impart information and ideas, save in the cases laid down by law and in compliance with the conditions laid down in paragraphs (2) to (6).
(2) It is prohibited to use an artificial intelligence system in order to impede, remove, block, conceal, restrict the visibility of or label as false or untrustworthy the public expression of an opinion, belief or information by a person situated on the territory of Romania, as well as in order to penalise the person in any other manner for that expression, solely on the basis of a decision, evaluation or classification produced by the system, where the expression is not prohibited by law.
(3) Public authorities and institutions may not use, commission, finance or request, directly or through third parties, the use of an artificial intelligence system for the individualised monitoring of persons on the basis of their public expression or for the classification, flagging or restriction of their expression, save in the cases expressly laid down by law, in connection with acts laid down by criminal law and with the prior authorisation of a judge. The statistical or non-individualised processing of public information does not constitute monitoring within the meaning of this paragraph.
(4) Any measure by which the expression of a person situated on the territory of Romania is restricted by means of an artificial intelligence system shall be communicated forthwith to that person, in writing, stating the reasons, the legal basis and the fact that it was taken by means of such a system. The undeclared restriction of the visibility of a person's expression, without that person's knowledge, is prohibited.
(5) A person who is the subject of a measure of the kind laid down in paragraphs (2) and (4) has the right to have it reviewed, within 15 days of the request, by an identified natural person within the authority, institution or operator which took the measure, who bears responsibility for the final decision; the provisions of Article 26(5) and (6) apply mutatis mutandis.
(6) For providers of intermediary services, the provisions of this Article apply in so far as compatible with Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services and amending Directive 2000/31/EC, whose provisions concerning contractual terms, the statement of reasons for decisions and the handling of complaints remain applicable; this Article does not preclude measures against unsolicited messages, automated accounts or information security risks, nor filters chosen by the user, and may not be interpreted as restricting any safeguard laid down by the Regulation for the recipients of the services.
Article 28 → the reasons
It is prohibited to place into operation or to maintain in operation any frontier system under conditions which render human intervention as laid down in Article 14 impossible, technically or organisationally, including by distributing the system across infrastructures which are not under the control of the operator, by deleting the shutdown capacity or by granting a degree of autonomy which excludes supervision. The use of an infrastructure belonging to a third party does not, on its own, constitute a lack of control, if the contractual rights and the technical means permit the operator to exercise the shutdown capacity in a verifiable manner; the temporary unavailability of a means of intervention, remedied forthwith and recorded in the logs, does not constitute impossibility within the meaning of this Article.
Article 29 → the reasons
It is prohibited to design, train or operate any artificial intelligence system for the purpose or with the effect of recursive self-improvement. Every iteration by which a frontier system contributes, through a substantial modification, to the creation or the improvement of a successor system is subject to the evaluation and authorisation laid down in Chapter III; research programmes in which frontier systems are used as a tool may be authorised as a whole, with mandatory stopping points established pursuant to Article 8 and with human approval of each stage which produces a new model or a substantial modification.
Article 30 → the reasons
(1) The provisions of this Chapter are of public policy. Any legal act, authorisation, contract or clause to the contrary is null and void by operation of law, and the prohibitions laid down may not be removed by the consent of the persons concerned, or by invoking commercial secrecy, national security or economic interest; the adaptations laid down in Article 23 do not constitute derogations from the guarantees of this Chapter.
(2) The nullity concerns only the contrary clause, the other clauses remaining valid if they can subsist without it; rights acquired in good faith by third parties who did not take part in the infringement are protected. The provisions of this Chapter apply without prejudice to directly applicable European Union law.
CHAPTER VI
The Artificial Intelligence Safety Authority
Article 31 → the reasons
(1) The Artificial Intelligence Safety Authority is hereby established as a specialised structure without legal personality, organised within the National Authority for Management and Regulation in Communications, hereinafter referred to as ANCOM, having its seat in the Municipality of Bucharest.
(2) The Authority is headed by a vice-president of ANCOM with the rank of Secretary of State, having exclusive responsibilities in the field of artificial intelligence safety. By way of derogation from Article 11(1) of Government Emergency Ordinance No 22/2009 on the establishment of the National Authority for Management and Regulation in Communications, approved by Law No 113/2010, as subsequently amended and supplemented, ANCOM has, in addition to the vice-presidents provided for therein, a vice-president for artificial intelligence safety, appointed by Parliament, in the joint sitting of the Chamber of Deputies and the Senate, for a non-renewable term of 6 years, from among persons with recognised training and experience in the field of artificial intelligence, information security or technology law. Parliament shall decide on the appointment within 60 days of the vacancy of the office; pending the appointment, the responsibilities shall be exercised, for no more than 6 months, by a vice-president of ANCOM designated by the President of ANCOM.
(3) The vice-president for artificial intelligence safety may not hold, during his term of office and for 3 years after its expiry, any office, direct shareholding or remuneration from a developer or operator; holdings through diversified investment funds, without decision-making power, do not constitute a shareholding, and for the restriction following the expiry of the term of office a compensatory allowance established by the implementing rules shall be granted. The vice-president may be removed by Parliament only in the event of a serious infringement of the obligations laid down by this Law, of a final conviction for an intentional offence, of an established incompatibility or of inability to exercise the office for a period exceeding 6 months.
(4) The decisions laid down by this Law are issued, on behalf of ANCOM, by the vice-president for artificial intelligence safety, who is answerable for them before Parliament. In the exercise of the responsibilities laid down by this Law, the Authority may not receive instructions from any other public authority or institution.
(5) The Authority acts as the national liaison point with the AI Office of the European Commission and with the scientific panel provided for by the AI Regulation, and shall cooperate with the national authorities designated pursuant thereto, which retain their own competences; the Authority exercises exclusively the responsibilities laid down by this Law as regards frontier systems and shall inform the AI Office of decisions concerning general-purpose models.
Article 32 → the reasons
(1) The Authority has the following principal responsibilities:
a) it receives the notifications, carries out the independent evaluations and issues, makes conditional, suspends and revokes the authorisations laid down in Chapter III;
b) it inspects, including without prior notice, the professional premises of developers and operators and the compute infrastructures, with access to systems, weights, logs, documents and staff, under the conditions laid down in paragraph (3);
c) it orders the shutdown, suspension or withdrawal of any frontier system, the suspension of access to compute infrastructure, the cessation of the supply of services and the blocking of access pursuant to Articles 38 and 39;
d) it draws up and updates the standards of evaluation, of security of the weights and of shutdown capacity, as well as the methods of evaluation and the levels of significance of the critical capabilities laid down in Article 5(2), under the conditions laid down in paragraph (4);
e) it establishes administrative offences and imposes the penalties laid down by this Law, and refers matters to the criminal prosecution bodies;
f) it designates and supervises the independent evaluation bodies;
g) it receives the complaints of persons concerning the infringement of Articles 26 and 27, establishes the infringements and orders their cessation, without prejudice to the right of the person to apply to the courts;
h) it submits to Parliament, by 31 March each year, a public report on the state of risk, the capabilities observed, the incidents reported, the evolution of the thresholds, the complaints concerning the infringement of Articles 26 and 27, and legislative recommendations;
i) it represents Romania in the relevant European and international forums and promotes the adoption of rules equivalent to this Law;
j) it finances and carries out research in the field of the evaluation, interpretability and alignment of artificial intelligence systems, with external evaluation of the results and with the application of the rules on conflicts of interest laid down in paragraph (2).
(2) The functions of evaluation, of investigation and of sanctioning decision shall be exercised by separate structures within the Authority; the person who carried out the evaluation or the investigation shall not take part in the adoption of the sanctioning decision. Evaluation bodies shall be designated on the basis of public criteria, with rules on recusal and on the prevention of conflicts of interest, and may not evaluate systems of persons with which they have economic relationships.
(3) An inspection shall be carried out on the basis of a written order of the vice-president, indicating its subject matter and purpose, and shall be recorded in a report; access to premises serving as a domicile shall take place only with the authorisation of a judge, and the professional secrecy of lawyers and the other secrets protected by law shall be protected. Access to staff is without prejudice to the rights of persons in administrative-offence or criminal proceedings.
(4) The standards approved by the Authority shall detail the methods of evaluation within the limits of the categories and criteria established by this Law. Those standards may not introduce new categories of prohibited capabilities and may not extend the constituent elements of the administrative offences or of the criminal offences laid down by this Law.
Article 33 → the reasons
(1) The specialist staff of the Authority are appointed exclusively following a competition organised by ANCOM, participation in which is open to any person satisfying the conditions as to education and experience established by the competition notice, published at least 30 days before the date on which it is held. The results of the competition may be challenged before the administrative court.
(2) The competition board is composed of at least 5 members, of whom at least 3 are university professors in the field of information technology and telecommunications or specialists with recognised practical experience in the security and evaluation of artificial intelligence systems, proposed by the accredited higher education institutions which organise doctoral studies in those fields, at the request of ANCOM. The members of the board may not hold any office, shareholding or remuneration from a developer or operator and may not have, with the candidates, relationships of a kind giving rise to incompatibility. The composition of the board and the results of the competition shall be published on ANCOM's website.
(3) The specialist staff of the Authority are remunerated, in accordance with ANCOM's salary system, at a level competitive with that practised in the private sector for equivalent posts, established annually by the President of ANCOM, with the approval of the vice-president for artificial intelligence safety, on the basis of a published market study.
(4) The staff of the Authority are subject to the confidentiality obligations and the incompatibilities laid down in Article 31(3), for the duration of their service relationship and for 2 years after its termination.
(5) The Authority is financed from ANCOM's budget, through a separate allocation, approved annually and shown separately, as well as from the notification, evaluation and authorisation fees established by the implementing rules in relation to the cost of the service provided. Fines imposed pursuant to this Law constitute revenue to the State budget and may not determine the resources of the Authority. The research laid down in Article 32(1), point (j), shall be financed through a separate budgetary allocation, unrelated to the penalties imposed. The initial budget of the Authority, including the necessary staff and infrastructure, shall be provided by ANCOM before the collection of the fees.
Article 34 → the reasons
(1) A consultative Scientific Council operates alongside the Authority, composed of 9 members, being researchers with recognised activity in the field, of whom at least 3 from abroad, which gives its opinion on the standards of evaluation, on the methods of evaluation and the levels of significance of the critical capabilities and on proposals for the adjustment of the thresholds, and publishes separate opinions where it does not share the position of the Authority.
(2) The members of the Scientific Council are appointed by the vice-president for artificial intelligence safety, on a proposal from the Romanian Academy and from the higher education institutions which organise doctoral studies in the field, for a term of 4 years, renewable once; they are subject to the incompatibilities laid down in Article 31(3) and may be removed only for an established incompatibility or for unjustified non-participation in proceedings. The Council shall adopt its opinions by a majority of its members.
(3) The opinion of the Scientific Council is consultative; where it departs from the opinion, the Authority shall state its reasons. Access of the members to protected information shall take place under the conditions laid down by law, and separate opinions shall be published in versions which protect sensitive information and preserve the scientific argument.
CHAPTER VII
Liability
Section 1. Civil liability
Article 35 → the reasons
(1) The developer and the operator are jointly and severally liable, irrespective of any fault, for damage of any nature caused by a frontier system, including damage produced by autonomous actions of the system, by its use by third parties or by the exfiltration of the weights, the provisions of Article 1376 of the Civil Code applying mutatis mutandis. The victim shall prove the damage and the causal link between the damage and the functioning of the system; the court may order access to the logs and to the relevant documentation, with the protection of confidential information, and if the developer or the operator fails to produce the logs which it was obliged to keep, the causal link is presumed until proof to the contrary. As between themselves, the developer and the operator are liable in proportion to the contribution of each to the occurrence of the damage, and the person who substantially modified the system is liable as a developer for the damage caused by the modification.
(2) Exemption from liability may be invoked only in respect of damage caused exclusively by the act of the victim or by a case of force majeure external to the system. The unforeseeable behaviour of the system, an error of evaluation, the act of a third party who obtained access to the system or to the weights, and the absence of scientific knowledge at the date of placing into operation do not constitute force majeure.
(3) Clauses limiting or excluding liability towards victims are null and void. Limitation clauses between professionals are valid only in respect of the relationships between them and of their own pecuniary damage and may not affect the rights of victims or the cover laid down in Article 36.
(4) The right of action is time-barred 10 years after the date on which the victim knew or ought to have known of the damage and of the person liable, but no later than 30 years after the occurrence of the act; in the case of a continuing act, the period runs from its cessation.
(5) This Article establishes a separate basis of liability, founded on the risk created by the development and operation of the system, and does not modify the harmonised regime of liability for defective products; it is without prejudice to the right of the victim to obtain compensation for the damage on the basis of that regime or of other bases laid down by law, without however the same damage being compensated twice. In so far as the exclusion laid down in paragraph (2) concerning the absence of scientific knowledge falls within the scope of Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024, the Government shall complete the formalities laid down in Article 18 of that Directive.
Article 36 → the reasons
(1) The developer and the operator of a frontier system shall take out and maintain civil liability insurance or shall constitute a financial guarantee, in the minimum amount established by the implementing rules, differentiated by category of system, which may not be less than the equivalent in lei of 100 million euro for category I systems and of 1 billion euro for category II systems, per event, with an aggregate annual ceiling of at least twice those sums; once the cover is exhausted, it shall be reconstituted within 30 days. If the Authority, after consulting the Financial Supervisory Authority, finds by public report that cover is unavailable on the market under the conditions of this Law, the Government may establish, by the implementing rules, lower levels, which may not fall below one fifth of the sums laid down, as well as alternative guarantee mechanisms, including group guarantees, bank guarantees or a guarantee fund financed by developers and operators.
(2) The financial guarantee shall be constituted by bank guarantee letter, deposit or guarantee issued by an authorised financial institution, enforceable at the request of the victim on the basis of a final court judgment or of a settlement. The victim has a direct right of action against the insurer or, as the case may be, the issuer of the guarantee.
Section 2. Administrative liability
Article 37 → the reasons
(1) The following acts constitute administrative offences, if they have not been committed in such conditions as to be regarded, under the law, as criminal offences:
a) the failure to fulfil the notification obligation laid down in Article 7 and Article 10(2), or the supply of incomplete information, punishable by a fine of 1% to 3% of total worldwide turnover in the preceding financial year;
b) non-compliance with the safety plan or with the obligations of separation of functions, of logging, of ensuring and of verifying intelligibility, laid down in Article 16(1) to (5), of maintaining and of testing the shutdown capacity, laid down in Article 14(1), (5) and (6), with the exception of the acts falling under Article 28, of designating the persons responsible for human supervision, laid down in Article 14(3), or of reporting of incidents, punishable by a fine of 2% to 5% of worldwide turnover;
c) non-compliance with the conditions of the authorisation, with the standards of security of the weights or with the obligations of compute infrastructure providers, punishable by a fine of 3% to 7% of worldwide turnover;
d) infringement of the prohibitions laid down in Article 12(2), Article 14(2), Article 15, Article 16(6) and Articles 25 to 29, punishable by a fine of 5% to 10% of worldwide turnover;
e) non-compliance with the marking obligations laid down in Article 17(1), (2) and (4), or infringement of the prohibition laid down in Article 17(3), punishable by a fine of 2% to 5% of worldwide turnover; for acts which constitute infringements of Article 50 of the AI Regulation, the fine shall be imposed within the limits laid down in Article 99(4) of the Regulation;
f) the failure to fulfil the information obligation laid down in Article 18 or the obligations concerning the compliance representative laid down in Article 19, punishable by a fine of 1% to 3% of worldwide turnover.
(2) For legal persons which have not achieved any turnover, the fine is from 100,000 lei to 10,000,000 lei, and for natural persons, from 10,000 lei to 1,000,000 lei. For the administrative offences laid down in paragraph (1), points (e) and (f), committed by persons who are not developers or operators of a frontier system, the fine is from 20,000 lei to 1,000,000 lei for legal persons and from 5,000 lei to 200,000 lei for natural persons.
(3) The penalty of a fine may be accompanied by the complementary penalties of suspension or revocation of the authorisation, of prohibition of the carrying out of development activity for a period of up to 5 years, of confiscation of the weights and of publication of the decision, imposed in proportion to the seriousness of the act; confiscated weights shall be kept by the Authority under the conditions laid down in Article 12.
(4) The provisions of Government Ordinance No 2/2001 on the legal regime of administrative offences, approved with amendments and additions by Law No 180/2002, as subsequently amended and supplemented, apply to the administrative offences laid down by this Law. By way of derogation from Article 28 of Government Ordinance No 2/2001, the offender may not pay half of the minimum fine. By way of derogation from Article 13(1) of that Ordinance, the imposition of the penalty is time-barred 5 years after the date on which the act was committed.
(5) In the individualisation of the penalty, account shall be taken of the seriousness and extent of the act, the danger created, the effective control of the person over the act, cooperation with the Authority and remediation. Worldwide turnover is that achieved in the preceding financial year by the offender and, where the offender forms part of a group, by the group as a whole. Two penalties may not be imposed for the same act under this Law and the AI Regulation; for public authorities and institutions, the fine shall be imposed on the natural person responsible, within the limits laid down in paragraph (2).
Section 3. Cessation of the supply of services and blocking of access
Article 38 → the reasons
(1) An operator which offers access to a frontier system to persons situated on the territory of Romania without complying with the provisions of this Law shall be given formal notice by the Authority, with the grant of a remediation period of at least 15 days and the opportunity to present its point of view. If the non-compliance persists at the expiry of the period or consists in a serious risk which cannot be remedied within that period, the Authority shall establish the non-compliance by reasoned decision, and the operator is obliged to cease the supply of the service to those persons within 15 days of the communication of the decision. In the event of imminent danger to life, to health or to human control over the system, no remediation period shall be granted, the decision also stating reasons as to the urgency.
(2) The decision laid down in paragraph (1) shall be published on the Authority's website, in the List of non-compliant operators, indicating the service, the operator and the provisions infringed, and shall be communicated to the providers of electronic communications networks and services.
(3) The continuation of the supply of the service after the expiry of the period laid down in paragraph (1) constitutes an administrative offence and is punishable by a fine of from the equivalent in lei of the sum of 100,000 euro to the equivalent in lei of the sum of 10,000,000 euro for each month of continued supply, fractions of a month being counted proportionally, determined according to the duration, the number of persons affected and the seriousness of the non-compliance, without the total of the fines imposed for the same non-compliance being able to exceed 5% of annual worldwide turnover; the fine shall be imposed separately from the penalty for the initial infringement.
(4) The operator shall be removed from the List of non-compliant operators by decision of the Authority, issued within 10 days of the presentation of proof of compliance and communicated forthwith to the providers executing the blocking; the refusal or delay of removal may be challenged pursuant to Article 39(5).
(5) The provisions of this Article apply also to a developer which offers direct access to a frontier system to persons situated on the territory of Romania.
Article 39 → the reasons
(1) Pending compliance, the Authority may order, by reasoned decision, the blocking of access from the territory of Romania to the service entered in the List of non-compliant operators, only if less restrictive measures have not led to compliance or are manifestly insufficient in relation to the seriousness of the risk. The decision shall examine the necessity and proportionality of the measure, shall avoid affecting other services hosted on the same infrastructure and shall be re-examined of the Authority's own motion every 90 days; users shall be informed, by means of a redirection page, of the reason for the measure and of the means of challenge.
(2) The blocking decision shall be communicated to the providers of electronic communications networks and services, which shall execute it within 48 hours of its communication.
(3) The blocking concerns exclusively the non-compliant service, is maintained for the duration of the entry in the List of non-compliant operators and ceases by operation of law on the date of removal.
(4) For services supplied from another Member State of the European Union, the measure shall be ordered only individually, for a determined service, for the infringement of an obligation necessary for the protection of public policy, public security or public health, in compliance with the procedure for requesting the Member State of origin and for notifying the European Commission laid down by Law No 365/2002 on electronic commerce, as republished, as subsequently amended and supplemented, for the restriction of the free movement of information society services.
(5) The blocking decision may be challenged within 30 days of its communication before the Bucharest Court of Appeal, Administrative and Tax Litigation Division, which shall rule as a matter of urgency and with priority; the challenge does not suspend enforcement by operation of law. The person concerned may apply to the court for the provisional suspension of the measure, the application being determined as a matter of urgency, within no more than 10 days, with an examination of the risk to safety and of the damage caused by the maintenance of the measure. The judgment may be challenged by way of appeal on points of law before the High Court of Cassation and Justice, within 15 days of its communication.
(6) The providers of electronic communications networks and services are not liable for damage caused by the correct execution, in good faith, of the blocking decision; they are liable for excessive blocking caused by their own fault.
Section 4. Criminal liability
Article 40 → the reasons
(1) The placing into operation of a frontier system without the authorisation laid down in Article 9, or after its suspension or revocation, as well as the continuation of operation after the communication of a shutdown or withdrawal order, are punishable by imprisonment of from 2 to 7 years and a ban on exercising certain rights. The use, as an end user, of a system made available by another does not constitute a criminal offence.
(2) Where the act has resulted in the manifestation, outside an evaluation authorised in an isolated environment pursuant to Article 15(2), of one of the critical capabilities laid down in Article 5(2), points (c) to (e), or in the production of one of the results laid down in Article 5(2), points (a) or (b), the penalty is imprisonment of from 5 to 12 years and a ban on exercising certain rights. The result shall be attributed under the conditions laid down in Article 16(4) of the Criminal Code.
Article 41 → the reasons
(1) The knowing presentation to the Authority or to an evaluation body of data, results or statements which are false or misleadingly incomplete concerning essential elements of the capabilities, the compute volume, the security of the weights, the shutdown capacity and the results of its testing, or the incidents of a frontier system, as well as the configuring of the system for the purpose of misleading the evaluators as to the configuration evaluated or the real capabilities, are punishable by imprisonment of from 3 to 10 years and a ban on exercising certain rights.
(2) Impeding, in any manner, the Authority's access, exercised within the limits of its competence and on the basis of a written request, to the system, to the weights, to the logs or to the staff, or destroying, altering or concealing the logs, are punishable by imprisonment of from 1 to 5 years. A refusal based on the Authority's lack of competence or on the protection of the professional secrecy of lawyers or of another secret protected by law, on which the court shall rule, does not constitute a criminal offence.
(3) The taking of a measure of retaliation, among those laid down by Law No 361/2022, against a whistleblower, in connection with a report protected pursuant to Article 21, is punishable by imprisonment of from 6 months to 3 years or by a fine.
(4) An uncertain estimate declared as such, an error corrected as soon as it became known, and the configuring of the system within a test agreed with the evaluator do not constitute the offence laid down in paragraph (1).
Article 42 → the reasons
(1) The intentional training, design or operation of a system under the conditions prohibited by Article 15(1), Article 25(2), first sentence, and (3), Article 28, first sentence, or Article 29, first sentence, are punishable by imprisonment of from 3 to 10 years and a ban on exercising certain rights.
(2) The disclosure, transmission or making available, without right, of the weights of a category II or category III frontier system is punishable by imprisonment of from 5 to 15 years and a ban on exercising certain rights. The transfers permitted pursuant to Article 12(2) and the communications protected pursuant to Article 21(5) do not constitute a criminal offence.
(3) Where the acts laid down in paragraph (1) or (2) have resulted in the death or serious bodily injury of one or more persons or in the loss of human control over the system, for a duration which rendered human intervention impossible, followed by autonomous actions of the system with consequences for persons, the physical environment or critical infrastructure, the penalty is imprisonment of from 10 to 20 years and a ban on exercising certain rights. Where the result consists in particularly serious pecuniary damage or in a temporary loss of human control, without the consequences laid down in the first sentence, the penalty is imprisonment of from 7 to 15 years and a ban on exercising certain rights. The results shall be attributed under the conditions laid down in Article 16(4) of the Criminal Code.
Article 43 → the reasons
(1) The accessing by a natural person, for personal purposes, of a service entered in the List of non-compliant operators, including by circumventing the blocking measure ordered pursuant to Article 39, does not constitute a criminal offence or an administrative offence and may not entail any penalty or restrictive measure against that person for the non-compliance of the service. Liability for non-compliance rests exclusively with the operator and the developer. This guarantee does not remove liability for separate acts, laid down by law, committed through the use of the service.
(2) The provisions of Articles 38 and 39 may not be interpreted as establishing any obligation upon users or as making their rights conditional.
(3) The guarantee laid down in paragraph (1) also benefits the professional end user who is not an operator and does not make the service available to other persons.
Article 44 → the reasons
(1) The offences laid down in this Section are attributed to the natural persons who ordered or approved the commission of the acts, as well as to the persons who, having the legal obligation and the effective possibility of preventing them, knowingly tolerated their commission, with the individual determination of the form of guilt in accordance with the Criminal Code, irrespective of their status as directors, managers, shareholders or employees, and irrespective of the criminal liability of the legal person, which is incurred under the conditions laid down in Article 135 of the Criminal Code.
(2) The fact that the act was committed in execution of a resolution of the management bodies, of an order or of a contractual instruction does not constitute a ground for exemption from punishment; the provisions of the Criminal Code concerning justifying causes and causes of non-imputability remain applicable.
Article 45 → the reasons
(1) The criminal prosecution of the offences laid down in Articles 40 to 42 shall be carried out obligatorily by a prosecutor within the Directorate for Investigating Organised Crime and Terrorism, and the trial at first instance falls within the jurisdiction of the tribunal.
(2) In case of urgency, the prosecutor may order, by reasoned order, as an interim measure, for no more than 30 days, the shutdown of the system, the sealing of the compute infrastructure and the freezing of the weights, subject to confirmation by the judge for rights and freedoms within 48 hours, failing which the measure ceases by operation of law. The measure shall be limited to the computing workload and the weights concerned where their isolation is sufficient, shall be executed with the preservation of data and with the safeguarding of the weights under the conditions laid down in Article 12, may be challenged by the person concerned and by affected third parties, shall be re-examined every 30 days and may be extended under the same conditions.
(3) In Article 11(1) of Government Emergency Ordinance No 78/2016 on the organisation and functioning of the Directorate for Investigating Organised Crime and Terrorism and amending and supplementing certain legislative acts, published in the Official Gazette of Romania, Part I, No 938 of 22 November 2016, approved with amendments by Law No 120/2018, as subsequently amended and supplemented, a new point is inserted after the last point, with the following content: “the offences laid down in Articles 40 to 42 of the Law on the safe development of frontier artificial intelligence systems and the prevention of catastrophic risks to the Romanian citizen”.
CHAPTER VIII
International cooperation. Transitional and final provisions
Article 46 → the reasons
(1) The Government shall promote, within the institutions of the European Union, the adoption of a regime of prior authorisation of frontier systems equivalent to that laid down by this Law, as well as the establishment of a common European evaluation capacity.
(2) The Government shall act, within the United Nations, the Council of Europe, the North Atlantic Treaty Organisation and other international organisations, for the negotiation of an international treaty on the limitation and verification of frontier computing capabilities, the prohibition of lethal autonomous weapons systems and the prohibition of the development of category III systems, and shall report annually to Parliament on the state of those endeavours.
(3) The Authority may conclude, within the limits of its competence and subject to their publication, agreements on the mutual recognition of evaluations with the competent authorities of other States which apply equivalent standards; such agreements may not derogate from this Law or from European Union law.
Article 47 → the reasons
The Government shall submit to Parliament, every 2 years from the entry into force of this Law, on the basis of the Authority's report and the opinion of the Scientific Council, a report on the adequacy of this Law to the state of the technology, accompanied, where appropriate, by proposals for amendment. The report shall assess, on the basis of a published methodology, the effectiveness of the protection, the incidents, the costs, access to services, undesired effects and the proportionality of each measure, may propose the narrowing of a measure found to be ineffective and shall include divergent scientific opinions. The absence of a validated scientific method of controlling frontier systems may not be invoked, on its own, as a ground for relaxing the regime established by this Law.
Article 48 → the reasons
(1) The developers and operators of frontier systems in operation on the territory of Romania or made available to persons situated on the territory of Romania on the date of entry into force of this Law shall comply, within 90 days of the date of entry into force, with those of its provisions which do not depend on the implementing rules, and with the other provisions within the periods laid down in paragraphs (2), (4) and (5).
(2) Within 60 days of the date of entry into force of this Law, developers and operators shall notify the Authority of the systems in operation. The application for authorisation laid down in Article 9 shall be submitted within 90 days of the date of entry into force of the implementing rules laid down in Article 49(2). Notified systems may be maintained in operation pending the decision of the Authority, but for no more than 12 months from the date of entry into force of this Law, subject to compliance with the prohibitions and the directly applicable guarantees laid down in Chapters IV and V; that period shall be extended by operation of law by the length of time by which the adoption of the implementing rules or the determination of the application exceeds the periods laid down by this Law, a diligent applicant not being liable to penalty for the delay of the institutions, and the Authority being able to order, stating reasons, additional safety conditions for the duration of the extension.
(3) The provisions of Articles 38 and 39 apply after the expiry of the period laid down in paragraph (1). The maintaining in operation of a system notified pursuant to paragraph (2), for the duration for which that paragraph permits it, as well as during the determination of an application for authorisation submitted within the period, does not constitute the criminal offence laid down in Article 40(1); however, the provisions of Articles 40 to 42 apply, from the date of their entry into force, to any other act, including the placing into operation of a system that has not been notified, or the maintaining in operation of a system after the rejection of the application, after the expiry of the period laid down in paragraph (2), or after the communication of a shutdown order.
(4) The obligations laid down in Article 17(1), point (a), Article 18 and Article 19, as well as the obligation laid down in Article 17(4) as regards the perceptible marking and the express indication of generation, shall be fulfilled within 90 days of the date of entry into force of this Law; within the same period, the compliance representative laid down in Article 19 shall be designated and notified to the Authority. The obligations concerning the embedded technical marking, laid down in Article 17(1), point (b), and Article 17(2), as well as the obligation laid down in Article 17(4) as regards that marking, shall be fulfilled within 90 days of the date of entry into force of the implementing rules. The administrative offences laid down in Article 37(1), points (e) and (f), shall be established after the expiry of the period applicable to each obligation.
(5) The obligations whose fulfilment depends on the standards, procedures, thresholds or amounts laid down by the implementing rules laid down in Article 49(2) shall become enforceable 90 days after the date of entry into force of those rules; until that date, the corresponding administrative offences shall not be established. The prohibitions laid down in this Law, the obligations of maintaining and testing the shutdown capacity, of logging and of reporting serious incidents, as well as the other obligations which may be fulfilled without the implementing rules, shall apply from the date of entry into force of this Law, within the periods laid down in paragraphs (1) to (4).
(6) Pending the appointment of the vice-president for artificial intelligence safety, the responsibilities of the Authority, including the urgent measures laid down in Article 32(1), point (c), shall be exercised by the President of ANCOM, who is answerable for them under the conditions laid down by this Law.
Article 49 → the reasons
(1) Within 60 days of the date of publication of this Law in the Official Gazette of Romania, Part I, Parliament shall appoint the vice-president for artificial intelligence safety, and ANCOM shall supplement its organisational structure and its rules of organisation and functioning with the Authority, by decision of the President of ANCOM, which shall be published in the Official Gazette of Romania, Part I.
(2) Within 120 days of the date of publication of this Law in the Official Gazette of Romania, Part I, the Government shall adopt, on a proposal from the Authority, with the opinion of the Scientific Council and following a public consultation of at least 30 days, the implementing rules concerning the notification and authorisation procedure, the simplified recognition procedure, the standards of evaluation, of security of the weights and of shutdown capacity, the conditions of the isolated environment, the standards of the provenance marking laid down in Article 17, the methods of evaluation and the levels of significance of the critical capabilities laid down in Article 5(2), the threshold for high-capacity compute infrastructure, the level laid down in Article 16(5), the testing procedure and the duration laid down in Article 14(1) and (6), the minimum requirements of isolation laid down in Article 3(1), point (bb), the amount of the compensatory allowance laid down in Article 31(3), the amount of the fees, established in relation to the cost of the service, and the amount of the insurance or of the financial guarantee laid down in Article 36. The rules shall detail the framework established by this Law and may not establish the essential content of the obligations, prohibitions and penalties; the standards shall be published.
(3) Until the adoption of the implementing rules, evaluations shall be carried out in accordance with the standards laid down in the codes of practice adopted under the AI Regulation and with scientifically recognised methods, and the Authority shall publish provisional guidance.
Article 50 → the reasons
This Law enters into force 30 days after the date of its publication in the Official Gazette of Romania, Part I, with the exception of Articles 40 to 42, 44 and 45, which enter into force 270 days after the date of publication. The provisions of Article 43 enter into force together with this Law.
This Law was adopted by the Parliament of Romania, in compliance with the provisions of Article 75 and Article 76(1) of the Constitution of Romania, as republished.
PRESIDENT OF THE CHAMBER OF DEPUTIES PRESIDENT OF THE SENATE
Comments on this text
Comments here go into the document’s section of the Sovereigntist forum. One argues on the text, with reasons.
See the whole discussion in the forum →