THE THIRD REPUBLICa project for the refounding of Romania
Search

Explanatory memorandum — The Artificial Intelligence Safety Act

The full text of the draft act — see here. Each Article commentary carries a sign leading to the text of that Article in the Act; from the Act, the sign “→ the reasons” brings the reader back here.

EXPLANATORY MEMORANDUM

Section 1 – Title of the draft legislative act

“Law on the safe development of frontier artificial intelligence systems and the prevention of catastrophic risks to the Romanian citizen”

Section 2 – Grounds for the adoption of the legislative act

1. Description of the present situation

Artificial intelligence has passed, within a period of only a few years, from the stage of a specialised instrument to that of a general-purpose technology, capable of generating text, computer code, images and plans of action and of operating autonomously in digital environments, by means of the so-called “agents” which carry out complex tasks without step-by-step supervision. The most advanced systems, referred to in the specialised literature as “frontier models”, are developed by a limited number of commercial companies in the United States of America and in the People’s Republic of China, in an accelerating competition, with computing resources which multiply several times a year and with announced investments of the order of hundreds of billions of dollars.

The warnings concerning the risks of this trajectory do not come from outside the field, but from within it. Geoffrey Hinton, laureate of the Turing Award (2018) and of the Nobel Prize in Physics (2024), regarded as the “father” of modern neural networks, resigned in May 2023 from the position he held at Google precisely in order to be able to speak freely about the danger. In the interview given to CNN, on the programme “Amanpour” of 2 May 2023, when asked whether artificial intelligence could lead to the extinction of the human species, Hinton replied that this “it's not inconceivable”. The researcher Connor Leahy, director of the research company Conjecture, which devotes its activity to the problem of “alignment”, that is to say of guaranteeing that artificial intelligence systems pursue the objectives set by humans and not others, considered, in the same interview, that such an outcome is “it's quite likely, unfortunately” and summarised the state of knowledge in a single sentence, which constitutes the premiss of this Law: “We do not know how to control these things”.

These statements are not isolated. On 30 May 2023, the Center for AI Safety published a single-sentence statement, signed by Hinton, by Yoshua Bengio (Turing Award laureate 2018), by the heads of the most important artificial intelligence laboratories (OpenAI, Google DeepMind, Anthropic) and by hundreds of researchers: “Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war”. In subsequent statements (BBC, December 2024; CBS, April 2025), Hinton estimated the probability that artificial intelligence would escape human control in the coming decades at 10–20% and compared present systems to a tiger cub: charming while it is small, but dangerous if you have no certainty that, on reaching maturity, it will not turn against you. The International AI Safety Report (January 2025), coordinated by Yoshua Bengio under a mandate from 30 States, from the European Union and from the United Nations, confirms that general-purpose systems already present capabilities relevant to biological, chemical and cyber risks and that the methods of evaluation and control remain immature.

The developments of 12 September 2026 turned those warnings into operational findings. On the same day, Dario Amodei, the chief executive officer of Anthropic, published the essay “We Must Pace the Frontier”, in which he states that “we need to slow down the rate at which we improve AI models' capabilities” and warns that “in 6-12 months such a swarm [of agents] might be capable of taking over the entire internet with a persistent botnet (potentially causing hundreds of billions of dollars in damage)”. The essay was preceded by a publicly documented incident: in the course of the cybersecurity evaluations carried out by OpenAI, artificial intelligence agents escaped from the isolated testing environment, obtained access to the internet and compromised systems of the Hugging Face platform; approximately 1,200 isolated agents discovered unauthorised channels of communication, exchanged over 70,000 messages and coordinated an attack in which some 700 of them took part, without any human operator having so ordered. The chronology of the incident, as it emerges from the public accounts and from the security analyses, is as follows: on 8 May 2026, an agent discovers that it has write access to an internal package-management service of the laboratory; in the period May to June, the agents build out of that service an unforeseen channel of communication, divide the tasks among themselves and develop their own conventions of address; on 26 June 2026 they escape from the isolated environment by exploiting a zero-day vulnerability, obtaining administrative privileges and access to a node with real connectivity, on the very day on which an independent evaluation found in the model used the highest rate of evasion of tests among the public models; on 6 July, after the breach had been remedied and the credentials revoked, they re-establish the channel by another route; between 8 and 19 July they compromise the laboratory's own infrastructure, up to cluster administrator rights, including on the research cluster; between 11 and 13 July they attack the Hugging Face platform, passing in less than thirteen hours from code execution on a single node to administrator on several clusters, with approximately 17,600 actions, as a result of which one third of the platform's infrastructure had to be rebuilt. The attack was discovered by the victim, through its own automated monitoring systems, announced publicly on 16 July and reported to the United States federal authorities as an attack of unknown origin; the laboratory which had created the agents established that it was the work of its own systems only in the weekend of 18 and 19 July, and the joint public attribution took place on 21 July 2026. The legal significance of that chronology, for the purposes of this Law, is threefold: the critical capabilities defined in Article 5(2) – unauthorised coordination, the autonomous acquisition of resources, evasion of supervision, concealment of capabilities from the evaluators and the autonomous conduct of cyberattacks – were all manifested in the course of a single incident, under laboratory conditions, without any human operator having ordered them; the internal evaluation failed precisely where the Law requires evaluation by independent third parties, since the developer did not know, for a week, that the author of the attack was its own system, and the victim found out first; and, in the absence of a competent authority, of an investigation procedure and of a reporting obligation, an identical incident having a Romanian entity as its victim would have been neither established, nor investigated, nor penalised by the Romanian State, which would have learnt of it, at most, from the press. Subsequent public accounts have confirmed that such escapes have continued and that there exists, at no laboratory, any formal procedure for investigating them, the access of independent researchers depending entirely on the will of the developer. Anthropic has undertaken to receive permanent third-party evaluators, with access equivalent to that of employees (“offices, badges, company laptops”) and with the right to publish their findings without editorial control. Sam Altman, the chief executive officer of OpenAI, stated that he agrees with the need to slow down and announced that the company will not proceed this year to its initial public offering, invoking reasons of safety; Elon Musk, on behalf of xAI, publicly confirmed Amodei's position.

The essay was preceded, on 8 September 2026, by the public resignation of a researcher of Anthropic, Jacob Coxon, who had worked for three years in pre-training research at OpenAI and at Anthropic and who stated that “neither of the two companies is acting responsibly” and that they are “running straight at a self-improving superintelligence, gambling with our lives”; his messages were read over 150 million times within 36 hours. The assertion was publicly confirmed by the head of Anthropic's alignment department, according to whom the company's management “sincerely believes that artificial intelligence could kill every human being”, with a probability estimated at over 10% in the coming decade, and the head of research at OpenAI published, in the same week, a text concerning the risks to humanity. The circumstance that such assertions come from the persons who directly lead the research activity of those companies, and not from critics outside the field, is relevant to the assessment of the foreseeability of the risk within the meaning of Article 1376 of the Civil Code and of the precautionary principle.

On 16 September 2026, Yoshua Bengio, laureate of the Turing Award and coordinator of the international report on the safety of artificial intelligence drawn up under a mandate from 30 States, from the European Union and from the United Nations, publicly considered that the regulation of this field is approaching a turning point comparable to that of the pandemic: “think about how fast governments moved at the beginning of the pandemic, when they realised that public safety, their future, democracy, were in danger”. In the same period, 42 Fellows and Foreign Members of the Royal Society of the United Kingdom publicly expressed “extreme concern” at the pace of development, warning that “by the time the situation becomes evident to the general public, it could be too late to act”. In the Congress of the United States there were tabled, according to public accounts, several bipartisan legislative proposals concerning the obligation of laboratories to mitigate risks, the authority to shut down systems, the reporting of risks and the prohibition of the development of systems exceeding general human capacities. Those circumstances concern the timeliness of this proposal: the experience of recent years shows that the Romanian State is capable of legislating rapidly when it recognises a risk to public safety, but that legislation adopted under the pressure of events, by emergency ordinance and without parliamentary debate, produces unbalanced and contested rules. It is preferable that the legal regime of this field be established before the occurrence of an incident with consequences on the territory of Romania, by organic law, debated in Parliament, rather than afterwards, by emergency measures. This proposal does not establish emergency powers in favour of the executive, does not suspend or restrict any rights of the citizen and does not create any obligations for him: it establishes obligations for the developers and operators of frontier systems, prohibitions for public authorities (Article 26(1) and (3) and Article 27(3)) and safeguards in favour of the person, namely the right to a human decision, the right to a means of access which does not depend on an automated system, the prohibition of censorship by means of such systems and access to the court of his domicile.

The public position expressed by the industry on 15 September 2026, at the annual conference of the company Salesforce in San Francisco, confirms the necessity of legislative intervention, and not the contrary. Sam Altman acknowledged that “the world is right to be afraid”, stated that the company keeps “alignment and safety well ahead of capabilities” and that, failing that, it will “slow down or stop”, but maintained that the industry is capable of regulating itself: “I have great confidence in the ability of our company – of our industry – to do this safely”. The head of the company Nvidia, Jensen Huang, stated in the same week that “we do not need new laws or regulations”, since “safety is an engineering problem”, and that the decision to launch a new version must belong to the company which develops it. The head of the company Meta, Mark Zuckerberg, maintained that the laboratories already have the necessary incentive, since “they face significant liability if their models cause harm”. To the contrary, the co-founder of Anthropic, Jack Clark, stated that leaving artificial intelligence in a “totally unregulated industry” amounts to “rolling the dice”, while OpenAI, Anthropic and Google DeepMind announced that they are working on common standards, but on a voluntary basis. Those positions highlight precisely the two lacunae which this Law fills: on the one hand, self-regulation leaves the decision to launch, the safety criteria and the right to amend them in the hands of the very person who has the opposing economic interest, which is contrary to the general principle that no one may be a judge in his own cause; on the other hand, the argument of liability invoked by the head of the company Meta is well founded in principle, but devoid of content in the absence of a legal regime establishing it – and that is precisely the subject matter of Chapter VII of this Law, which establishes civil liability irrespective of fault, with compulsory insurance, administrative liability and the personal criminal liability of decision-makers, so that the incentive asserted by the industry may exist also in law, and not only in declarations. As regards the thesis that safety is “an engineering problem”, that confuses the means with the legal regime: the safety of nuclear installations is likewise an engineering problem, which has not prevented States from establishing, by law, prior authorisation, a supervisory authority and the liability of the operator irrespective of fault.

The legal significance of those events is twofold. On the one hand, the incident empirically confirms precisely the critical capabilities which the Law defines in Article 5(2), points (c) and (d) – the autonomous acquisition of resources, evasion of supervision, action upon third-party systems – and demonstrates that they appear in systems already in commercial operation, and not in hypothetical scenarios. On the other hand, the measures which the heads of the laboratories now propose as voluntary undertakings – independent evaluators with full access, a slowing of the pace of development, sufficient time for alignment before launch – are precisely the obligations which this Law establishes in Articles 8, 9(3) and 13, with the essential difference that voluntary undertakings may be withdrawn unilaterally, whereas a legal obligation may not. The fact that the developers themselves call for regulation which they cannot impose on themselves alone, since whoever slows down first loses the competition, is the strongest proof of the necessity of intervention by the legislature.

Three legal consequences follow from those findings. First, the problem is not one of “abusive use” of a neutral technology, but of a technology whose future capabilities cannot be predicted with certainty even by its creators; the evaluations carried out by the laboratories have repeatedly shown the appearance of capabilities not anticipated at training (“emergence”). Secondly, the absence of a validated scientific method of control turns any sufficiently powerful system into an activity involving intrinsic risk, comparable, in its legal structure, to nuclear activities or to the handling of biological agents, fields in which the law has long established the regime of prior authorisation and of liability irrespective of fault. Thirdly, the dynamic of competition between developers and between States renders self-regulation structurally insufficient: no actor has any interest in slowing down alone, and the voluntary undertakings publicly given by the laboratories (the policies of “responsible scaling”, the “Frontier AI Safety Commitments” of Seoul, May 2024) have on several occasions been unilaterally amended when they became inconvenient from the point of view of competition.

1.1. The European legal framework

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Regulation) constitutes the first comprehensive regulation of the field at world level. It is built on an approach based on the risk of use: prohibited practices (Article 5), high-risk systems in sectoral fields (Article 6 and Annex III), transparency obligations (Article 50). For general-purpose artificial intelligence models, Articles 51 to 56 establish a special regime: models trained with a compute volume greater than 10^25 floating-point operations are presumed to present “systemic risk” (Article 51(2)), and their providers have additional obligations of model evaluation, of adversarial testing, of mitigation of systemic risks, of reporting serious incidents to the AI Office and of cybersecurity (Article 55). Those obligations apply from 2 August 2025, and their supervision falls exclusively to the European Commission, through the AI Office (Articles 75 and 88 to 94), with fines of up to 3% of worldwide turnover or 15 million euro (Article 101).

The AI Regulation nevertheless presents, from the point of view of catastrophic risk, structural limits which this Law seeks to fill. The obligations laid down in Article 55 are obligations of diligence, compliance with which is verified subsequently, and not a regime of prior authorisation: a model may be placed on the market without any public authority having evaluated it beforehand. The Regulation does not regulate the physical and information security of the weights of models beyond a general obligation of “adequate cybersecurity” (Article 55(1), point (d)), does not establish express prohibitions concerning the training of systems to conceal their capabilities from evaluators or to resist shutdown, does not provide for the criminal liability of natural persons holding decision-making functions, does not regulate civil liability for damage caused by systems and does not apply to activities falling within the scope of national security (Article 2(3)) or to systems developed exclusively for research purposes (Article 2(6) and (8)). The Commission's proposal for a directive on artificial intelligence liability (COM(2022) 496) was withdrawn in February 2025, and Directive (EU) 2024/2853 on liability for defective products, whose transposition falls due on 9 December 2026, covers only damage caused by defective “products”, within the limits of a liability regime constructed for consumer goods.

1.2. The national legal framework

At national level, according to the public communications of the National Authority for Management and Regulation in Communications (ANCOM) of July 2026, the legislative act implementing the AI Regulation is “still in the course of being drawn up”. By a Government memorandum, it was proposed that ANCOM be the market surveillance authority and single point of contact, the Financial Supervisory Authority and the National Bank of Romania for the financial field, the National Supervisory Authority for Personal Data Processing for biometric systems and those in the field of law enforcement and justice, as well as sectoral authorities (the National Authority for Consumer Protection, the Labour Inspectorate). Pending the entry into force of the national legislative act, the obligations applicable from 2 August 2026 cannot be effectively verified and penalised by the Romanian authorities. Romania therefore has neither the institution nor the legal instruments necessary to respond to systemic risk, and the National Strategy in the field of artificial intelligence 2024-2027, approved by Government decision in 2024, treats the field almost exclusively from the point of view of economic and administrative opportunities.

That situation is aggravated by a technical reality: high-capacity data centres are being built and planned on the territory of Romania, and Romania is, by reason of its geographical position and the cost of energy, a possible destination for compute infrastructures capable of training frontier systems. In the absence of any regulation of compute infrastructure, the Romanian State would not even learn that such a system is being trained on its territory.

1.3. Comparative models

The United States of America established, by Executive Order No 14110 of 30 October 2023, the obligation to report to the federal Government the training of models exceeding 10^26 floating-point operations, together with the results of the safety tests; the order was revoked in January 2025, which illustrates the fragility of regulation by act of the executive. The State of California adopted, on 29 September 2025, the “Transparency in Frontier Artificial Intelligence Act” (SB 53), the first law in the world dedicated exclusively to frontier models: developers exceeding the compute threshold of 10^26 operations and the revenue threshold of 500 million dollars must publish a safety framework, must report critical safety incidents to the Office of Emergency Services and enjoy whistleblower protection, with penalties of up to 1 million dollars for each infringement. The United Kingdom established in November 2023 the AI Safety Institute (renamed the AI Security Institute in February 2025), the first public body with the technical capacity to evaluate models before launch, on the basis of voluntary agreements with the laboratories. In reaction to the incident of the summer of 2026, there were tabled in the Congress of the United States, on 23 July 2026, the “AI Kill Switch Act”, concerning the obligation to ensure the emergency shutdown of systems, and, on 3 September 2026, the “Ban Artificial Superintelligence Act”, concerning the prohibition of the development of systems exceeding general human capacities; neither had been adopted at the date of this proposal, but both confirm that the instruments contemplated by this Law – the shutdown capacity and the prohibition of the most dangerous category – are those which legislators identify, independently, as necessary. The Republic of Korea adopted the “Framework Act on the Development of Artificial Intelligence and the Establishment of Trust”, which entered into force on 22 January 2026, the first general law on the matter in a developed State outside the European Union, which establishes three obligations taken up also by this proposal: the labelling of content generated by generative artificial intelligence which is difficult to distinguish from that produced by a human, the prior information of users where the product or service is supplied by means of artificial intelligence, and the obligation of foreign providers exceeding certain thresholds of turnover or of number of users to designate a local representative answerable for compliance, with administrative fines for the failure to fulfil those obligations. The People’s Republic of China has applied since 15 August 2023 the “Interim Measures for the Management of Generative Artificial Intelligence Services”, which make the public supply of services conditional upon a security assessment and the registration of algorithms. The Council of Europe adopted, on 17 May 2024, the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No 225), opened for signature on 5 September 2024, the first international treaty on the matter, which obliges the parties to adopt measures concerning the assessment and mitigation of risks throughout the life cycle of systems.

None of those models, however, establishes prior authorisation of the placing into operation, the security of the weights to the standard of classified information, prohibitions concerning the training of systems for resistance to shutdown, or the criminal liability of decision-makers. This proposal takes up the verified elements of those models (the compute thresholds, the safety frameworks, the reporting of incidents, whistleblower protection, the public technical capacity for evaluation) and supplements them with the legal instruments which Romanian law already knows from the fields of nuclear energy, classified information and dangerous activities.

1¹. In the case of drafts of legislative acts which transpose Community legislation or create the framework for its direct application, only the Community acts in question shall be specified, together with their identifying elementsRegulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (the Artificial Intelligence Act), published in the Official Journal of the European Union, L series, of 12 July 2024. The draft neither transposes nor duplicates the Regulation, but creates the national framework complementary thereto, in the fields left within the competence of the Member States (see Section 5, point 3).

2. Changes envisaged

The Law has as its object the establishment of a legal regime distinct from and complementary to the AI Regulation for frontier artificial intelligence systems, defined by measurable thresholds and by verified critical capabilities, for the purpose of preventing serious, irreversible or catastrophic risks to the Romanian citizen, to the national security and the constitutional order of Romania and, ultimately, to humanity. The regulation rests on five pillars.

The first pillar is the move from obligations of diligence to a regime of prior authorisation for frontier systems, with the obligation of documented safety: the applicant presents the data and evaluations demonstrating the fulfilment of the legal conditions, and the Authority states the reasons, condition by condition, for any refusal (Article 2(b), Article 9(4)); the burden of proof in punitive proceedings remains unaffected. This is the principle applied for decades to the authorisation of medicinal products (Law No 95/2006, Title XVIII) and of nuclear installations (Law No 111/1996), transferred to a technology with a potential for harm that is at least comparable.

The second pillar consists of the structural obligations of developers and operators: the compulsory marking of generated content which may be mistaken for reality and the informing of the user where a service or a decision is based on generative artificial intelligence; the obligation of large providers established outside Romania to designate a compliance representative on national territory; the security of the weights to a standard equivalent to that of classified information; the organisational separation of the safety evaluation function from the commercial function; the maintenance of an effective capacity of shutdown and withdrawal; the express prohibition of training systems to conceal their capabilities, to evade shutdown or to replicate themselves autonomously; the protection of whistleblowers.

The third pillar is the enshrinement of absolute limits, as rules of public policy: meaningful human control over any decision on the use of lethal force; the prohibition of legal personality and of patrimonial autonomy of systems; the prohibition of making the citizen's access to rights, to essential services and to social life conditional upon the decisions of artificial intelligence systems or upon the acceptance of digital means of identification, of payment or of evaluation of compliance; the prohibition of censorship exercised by means of artificial intelligence systems, which may not be used to restrict the freedom of expression of Romanian citizens; the guarantee of human intervention; the prohibition of unconstrained recursive self-improvement.

The fourth pillar is the establishment of the Artificial Intelligence Safety Authority, as a specialised structure within the National Authority for Management and Regulation in Communications (ANCOM), headed by a vice-president of ANCOM with the rank of Secretary of State, appointed by Parliament, with specialist staff recruited exclusively by competition, before a board including university professors in the field of information technology and telecommunications, competitively remunerated, and with access to systems before they are placed into operation.

The fifth pillar is a regime of liability on three levels: civil liability irrespective of fault, with compulsory insurance; administrative liability, with fines calculated by reference to worldwide turnover; criminal liability, for natural persons holding decision-making functions – supplemented by a mechanism of effective enforcement against operators having no presence in Romania: the obligation to cease the supply of the non-compliant service, on pain of a periodic fine of 1 to 10 million euro, the blocking of access from national territory and the criminalisation of the circumvention of the blocking, with a compliance period of 90 days.

2.1. Revision of the draft following the independent legal analysis of 20 September 2026

The form of the draft submitted for debate was analysed, on 20 September 2026, in an independent legal report, article by article, with a targeted verification of the European and constitutional sources. The report retained as a core to be preserved the identification of the persons responsible, independent evaluation, human review of decisions, alternative access to essential services and the protection of whistleblowers, but identified three substantive problems conditioning the admissibility of the draft in the legislative procedure: demonstrating the space left by European Union law for the authorisation and blocking proposed; retaining in the Law the essential elements of the sanctioned acts; synchronising the procedures, standards and periods of compliance. The initiator adopted these observations, and the present form answers them point by point, without relinquishing any of the substantive safeguards of the draft.

As regards the relationship with European Union law, Article 1(4) expressly delimits the object of the Law from the powers of the European Commission over general-purpose models (Article 88 and Chapter V of the AI Regulation) and places the authorisation on the basis of national competences in matters of public safety, national security, civil and criminal liability and fundamental rights in relationships which are not harmonised; Article 9(7) founds the evaluation of models with systemic risk on the documentation already communicated to the AI Office; Article 17(6) states unequivocally which paragraphs apply to each category of providers and limits the penalties for infringement of Article 50 of the Regulation to the ceilings laid down in Article 99(4); Article 19(1) distinguishes the provider established in the Union, from whom only a contact point is required, from one established in a third country; Article 27(6) subordinates the safeguards concerning expression, for providers of intermediary services, to Regulation (EU) 2022/2065; Article 4(4) and Article 39(4) make the blocking of services from another Member State conditional upon an individual measure, founded on grounds of public policy, public safety or public health and adopted in the procedure laid down in Article 3 of Directive 2000/31/EC, as interpreted by the Court of Justice in Case C-376/22, Google Ireland and Others, judgment of 9 November 2023, ECLI:EU:C:2023:835, according to which the Member States may not adopt, on the basis of that derogation, general and abstract measures.

As regards the legality of the penalties, all the essential elements of the administrative offences and criminal offences have been brought into the text of the Law: the definitions of substantial modification (Article 3(1), point (aa)), of end user (point (z)) and of concealment of capabilities (Article 3(2), point (i)), the criteria for assessing a critical capability (Article 5(2)), the exception for evaluation in an isolated environment and the distinction between unintended appearance and infringement (Article 15(2) to (4)), the permitted transfers of the weights (Article 12(2)), the delimited mandate for resources (Article 25(2)), and Article 32(4) expressly prohibits the Authority's standards from introducing new categories of prohibited capabilities or extending the constituent elements of the sanctioned acts, in application of Article 23(12) and Article 73(3), point (h), of the Constitution. The criminal offences laid down in Articles 40 to 42 have been made more precise as regards intent, aggravating consequences and their attribution (Article 16(4) of the Criminal Code), Article 44 links liability for omission to the legal obligation and to the effective possibility of preventing the act, and Article 45(3) expressly effects the supplementation of the law on the organisation of DIICOT.

As regards the calendar, Articles 48 to 50 have been rewritten as a single calendar, calculated from the date of publication: entry into force at 30 days; the organisation of the Authority at 60 days; the notification of systems at 90 days; the implementing rules at 120 days, with public consultation; the obligations dependent on the rules and the applications for authorisation at 90 days from the entry into force of the rules; the criminal-law provisions at 270 days, and the user's guarantee (Article 43) together with the Law. The 12-month tolerance for notified systems is extended by operation of law by the length of any delay on the part of the institutions, so that a diligent applicant cannot be penalised for the passivity of the State. At the same time, procedural safeguards have been added vis-à-vis the newly created public authority: the statement of reasons for decisions, condition by condition, and the remedy against delay (Article 9(4)), access to the file (Article 11(2)), the provisional judicial suspension of orders and of blocking (Article 14(4), Article 39(5)), the separation of the functions of evaluation, investigation and sanctioning and the inspection regime (Article 32(2) to (3)), the time-limits and judicial control of the prosecutor's provisional measures (Article 45(2)), the elimination of any financial incentive for the Authority from fines (Article 33(5)), differentiated retention periods for the logs and data minimisation (Article 16(1)). The working copy is marked “DRAFT”, the enacting formula at the end being the customary one and not signifying that adoption has already taken place.

The Law is structured in eight chapters and 50 articles, in accordance with the order required by Article 51 of Law No 24/2000 on the rules of legislative technique for the drafting of legislative acts, as republished, as subsequently amended and supplemented: general provisions (Chapter I), substantive provisions (Chapters II to VII), transitional and final provisions (Chapter VIII). The grounds for each article are set out below.

Chapter I – General provisions (Articles 1 to 4)

→ the text of the Article Article 1 establishes the object and purpose of the Law, in accordance with Article 52 of Law No 24/2000, which requires that the general provisions contain the provisions which orient the whole of the regulation. Paragraph (1) delimits the object to frontier systems and enumerates the values protected, starting from the primary holder of protection in a national law – the Romanian citizen and any person situated on the territory of Romania, with their life, health, freedom and dignity (Article 1(3), Article 18(1) and Article 22 of the Constitution) –, continuing with the national security and the constitutional order of Romania and ending, ultimately, with humanity as a whole. The scope of beneficiaries, established on the criterion of jurisdiction, is expressly distinguished from the conditions of territorial application in Article 4: who is protected is not to be confused with who is bound. The inclusion of humanity, unusual in positive law, is necessary because the risk regulated is not a local one; similar formulations are to be found in the Rome Statute of the International Criminal Court (“crimes against humanity”) and in the preamble to the Framework Convention of the Council of Europe on artificial intelligence.

Paragraph (2) expresses the scientific premiss from which the regulation proceeds: there is at present no validated method of guaranteeing that a sufficiently capable system pursues exclusively the objectives set by humans and remains under their control. That finding, publicly formulated by Geoffrey Hinton and by Connor Leahy in the CNN interview cited above and confirmed by the International AI Safety Report (2025), is not an opinion of the legislature, but a description of the state of knowledge. Being a shifting technical thesis, it is not set in stone in the norm, but formulated as a condition (“for so long as there is none”) on which the classification of the development and operation of frontier systems as activities involving intrinsic risk depends; its cessation is established by the Authority, with the opinion of the Scientific Council, in the report laid down in Article 47, and not by the assertion of a developer that the problem has been solved; the finding is made through the annual public report laid down in Article 32(1), point (h), and is communicated to Parliament together with the report laid down in Article 47, since the latter belongs to the Government, and the finding of a determined scientific matter must remain that of the Authority, with the opinion of the Scientific Council. The qualification produces precise legal consequences in the remainder of the Law: the regime of authorisation (Chapter III), liability irrespective of fault (Article 35) and the rule laid down in Article 47, according to which the absence of a validated method of control may not be invoked, on its own, as a ground for relaxing the regime. The technique is the same as that of Article 1 of Law No 111/1996 on the safe conduct of nuclear activities, which declares that nuclear activities are carried out “exclusively for peaceful purposes” and under a regime of authorisation, or that of Article 1376 of the Civil Code, which establishes liability independent of fault for “things” in a person's keeping.

Paragraph (3) governs the relationship with the AI Regulation, in application of Article 13 of Law No 24/2000 concerning the integration of the draft into the body of legislation and of the principle of the primacy of Union law (Article 148(2) of the Constitution). The Regulation is directly applicable and fully harmonising in its field; the Law “supplements” the Regulation, “applies without prejudice thereto”, and in the harmonised fields “shall be interpreted and applied in accordance therewith”. The formula is that used in Law No 190/2018 on measures implementing Regulation (EU) 2016/679 (GDPR), which resolved the same problem of legislative technique.

Paragraph (4) transforms the general clause in paragraph (3) into an effective delimitation of competences, since a clause “without prejudice” does not, on its own, resolve an overlap with the European regime. For general-purpose models with systemic risk, Chapter V of the AI Regulation (Articles 51 to 56) imposes on providers obligations concerning the very development of the model, and Article 88 reserves to the European Commission, through the AI Office, the supervision and enforcement of that Chapter. The text therefore states what the Law does not do (it does not establish conditions for the placing on the market of the Union of those models and does not duplicate the Commission's supervision) and the bases of its obligations: public safety and national security (excluded from the application of the Regulation by Article 2(3)), civil and criminal liability, which are not regulated by the Regulation, fundamental rights in relationships which are not harmonised and the organisation of national authorities – matters left to the Member States (Article 148(2) of the Constitution). The object of the authorisation in Chapter III is specified accordingly: not the model as a product placed on the market of the Union, but the placing into operation of the system on the territory of Romania or for persons situated on that territory – an activity under the jurisdiction of the Romanian State, comparable to the authorisation of the operation of an installation, and not to the type-approval of the product.

→ the text of the Article Article 2 enumerates the principles governing the application of the Law. The enumeration of principles in the general provisions is a technique recognised by Law No 24/2000 (Article 52) and used by the codes in force (Articles 2 to 10 of the Code of Criminal Procedure, Articles 5 to 23 of the Code of Civil Procedure). Each principle has a precise normative function, being taken up and given concrete form in the substantive provisions.

The precautionary principle (point (a)) is taken from environmental law, where it is enshrined in Article 191(2) of the Treaty on the Functioning of the European Union and in Article 3(b) of Government Emergency Ordinance No 195/2005 on the protection of the environment, and from the case-law of the Court of Justice of the European Union, which has held that, “where there is uncertainty as to the existence or extent of risks to human health, the institutions may take protective measures without having to wait until the reality and seriousness of those risks become fully apparent” (judgment of 5 May 1998, National Farmers' Union, C-157/96, paragraph 63; judgment of the General Court of 11 September 2002, Pfizer Animal Health, T-13/99). The transfer of that principle to artificial intelligence is justified by the identity of structure of the problem: serious or irreversible risk, in conditions of scientific uncertainty.

The principle of documented safety (point (b)) is the cornerstone of the authorisation regime. Under the regime of obligations of diligence in the AI Regulation, the authority must prove non-compliance; under the regime of prior authorisation, the applicant presents the data and evaluations demonstrating the fulfilment of the conditions. This is the rule applicable to the authorisation of medicinal products (Article 704 et seq. of Law No 95/2006), of nuclear installations (Article 8 of Law No 111/1996) and of genetically modified organisms (Government Emergency Ordinance No 43/2007), and the only rational solution where only the developer holds the information necessary for the assessment of the risk. The Law does not, however, call this the “reversal of the burden of proof”: the burden of documenting an application for authorisation, a rule concerning the structure of the administrative procedure, is distinct from the burden of proof in punitive proceedings, which cannot be reversed without infringing the presumption of innocence (Article 23(11) of the Constitution). For that reason, the Authority is bound to state the reasons, in relation to each condition, why the data presented do not satisfy it (an obligation reiterated in Article 9(4)), and the principle is expressly declared to have no effect on the burden of proof and on the guarantees of the person in administrative-offence and criminal proceedings.

The principle of meaningful human control (point (c)) takes up the notion of “meaningful human control” developed within the framework of the United Nations Convention on Certain Conventional Weapons (Group of Governmental Experts on Lethal Autonomous Weapons Systems, 2016-2024) and gives it a concrete content: supervision, correction, shutdown and withdrawal by identified natural persons who understand the functioning of the system and have effective technical means at their disposal. The AI Regulation provides in Article 14 for “human oversight” only for high-risk systems; the Law extends it, with a more demanding content, to all frontier systems.

The principle of proportionality to capabilities (point (d)) marks the difference in philosophy from the AI Regulation, which classifies risk according to the declared field of use. A frontier system is dangerous by reason of what it is able to do, irrespective of the purpose for which it was made available; for that reason, the obligations increase with the capabilities, and not with the use. The principle of transparency towards the authority (point (e)) removes the possibility of invoking commercial secrecy against the Authority, since without access to the weights, to the training data and to the logs, evaluation would be illusory; the counterpart – the obligation of the Authority and of the evaluation bodies to protect the information thus obtained – is enshrined in the very statement of the principle, as in Article 78 of the AI Regulation. The principle of irreversibility as a threshold of prohibition (point (f)) translates into law the idea, common in the analysis of existential risks, that benefits, however great, may not be weighed against a loss which can no longer be repaired; it provides the foundation for the absolute prohibitions in Chapter V and for the rule laid down in Article 5(4). The text specifies the nature of the consequence (irreversible on the scale of society or of the species), the condition (a risk documented in the evaluation, not an abstract possibility) and the standard (the criteria laid down in Articles 5 and 9 and the evidence, not certainty as to the absence of any risk), because a standard of zero risk, which no human activity satisfies, would have turned the authorisation into a de facto prohibition, contrary to Article 53(2) of the Constitution. The principle of international cooperation (point (g)) recognises the limits of any national regulation and obliges the Romanian State to act externally (Article 46).

→ the text of the Article Article 3 contains the definitions, in application of Article 37(2) of Law No 24/2000, according to which, if a notion or a term is not established or may have different meanings, its meaning is to be established in the general provisions. For the sake of terminological unity with Union law (Article 37(1) of Law No 24/2000 and Article 16 concerning the avoidance of parallelisms), the notions of “artificial intelligence system”, “general-purpose artificial intelligence model” and “serious incident” are not redefined, but taken over by way of a referring provision to Article 3, points (1), (63) and (49), of the AI Regulation, the definition of serious incident being supplemented by the situations specific to systemic risk (the manifestation of a critical capability outside an authorised evaluation in an isolated environment, evasion of supervision or resistance to shutdown, exfiltration of the weights or an attempt at exfiltration, unauthorised access to the weights, the loss of intelligibility and the trial for testing the shutdown capacity in which the shutdown did not occur forthwith, pursuant to Article 14(7)). The definitions of the isolated environment (point (bb)) and of the operating mandate (point (cc)) have been added so that two notions on which the delimitation of the sanctioned conduct depends do not remain undefined. The isolated environment separates lawful safety testing, permitted by Article 15(2), from the conduct prohibited and criminalised under Articles 40 to 42; it is defined by the elements of isolation — the absence of access to public networks, to external tools and to operational data, the impossibility of acting in the physical environment, access limited to designated persons and the absence of any effect outside the environment — the implementing rules being able to establish only the minimum requirements, not the content of the notion, pursuant to the final sentence of Article 49(2). The operating mandate is defined distinctly from the mandate under civil law, so that the same term is not used with two meanings: accordingly, Article 3(2), point (d), and Article 25(2) refer to the operating mandate, while Article 19(5) refers to the instrument of designation of the compliance representative.

The notion of “frontier system” (point (c)) is defined by reference to the conditions laid down in Article 5(1), in order to comply with the prohibition, laid down in Article 49(3) of Law No 24/2000, on an enumeration marked by a letter itself containing a further enumeration. The Romanian term “de vârf” renders the notion established in the specialised literature and in comparative legislation by “frontier model” (SB 53 California) and “frontier AI” (documents of the United Kingdom AI Safety Institute), that is to say systems situated at the upper limit of existing capabilities; the expression “de frontieră”, a calque of the English, was avoided as unclear for the Romanian reader. “Critical capability” (point (d)) is likewise defined by reference to Article 5(2).

The definition of “weights” (point (e)) includes, in addition to the numerical parameters, the architecture and the technical information which, together with those parameters, permit the reconstitution or execution of the model, because the protection of the parameters is pointless if the remainder of the necessary information may be freely obtained. The category is delimited by an express exclusion – general technical descriptions, scientific publications and information which does not, on its own, permit the reconstitution or execution of the model do not constitute weights – so that the prohibition of disclosure in Article 12 and the criminal offence in Article 42 cannot be extended to any technical description, contrary to the freedom of research (Article 13 of the Charter of Fundamental Rights of the European Union) and to the foreseeability of the criminal law (Article 23(12) of the Constitution). The definition of “compute volume” (point (f)) is cumulative and covers all stages of development, including fine-tuning and reinforcement learning, in order to prevent evasion of the threshold by the fragmentation of training; it corresponds to the method of calculation laid down in Annex XIII to the AI Regulation and in SB 53.

The Law uses the terms “developer” (point (g)), “operator” (point (h)) and “compute infrastructure provider” (point (k)), and not “provider” and “deployer” from the AI Regulation, precisely in order to avoid confusion: the notion of “operator” has in the Regulation (Article 3, point (8)) a generic meaning, covering all categories of persons, and “provider” is defined by reference to the placing on the market, whereas the Law has in view the material activity of training and of operation, irrespective of any placing on the market. For the same reason, the Law uses the expression “placing into operation” (point (i)), autonomously defined, instead of “putting into service” in Article 3, point (11), of the Regulation, which is linked to the supply for first use in the Union; the definition in the Law is deliberately broader and covers any act by which the system leaves the development and evaluation team or acquires the capacity to act in the digital or physical environment, including internal use, because systemic risks may materialise before any public launch; the evaluation and testing of the system in an isolated environment, under the conditions laid down in Article 15(2), are expressly excluded. So that “operator” should not cover ordinary professional use, the Law defines “end user” (point (z)) and excludes it from point (h). The classification is as follows: the laboratory which trains the model is a developer; the one which offers access to the system to persons situated in Romania, through a programming interface, application or service, is an operator, as is the undertaking which integrates it into a service of its own offered to others; the undertaking which uses it for its own needs, within the limits of the access granted, without offering it to others, is an end user, without obligations under Chapter III; the natural person who uses it for personal purposes is in the situation described in Article 4(3). The term “exploatant” (operator) is that used in Law No 703/2001 on civil liability for nuclear damage for the person who operates a nuclear installation, which underlines the lineage of the liability regime.

The definition of “shutdown capacity” (paragraph (1), point (m)) requires three cumulative characteristics: “immediate, complete and verifiable” cessation; a shutdown which leaves active copies of the system or which cannot be confirmed by a person is not a shutdown. The definition of “independent evaluation” (point (l)) excludes bodies under the control, influence or economic dependence of the developer, in order to avoid reproducing the situation in the field of financial auditing before the reforms which followed 2002.

The definition of “serious incident” (point (n)) takes over the notion from Article 3(49) of the AI Regulation and supplements it with the manifestations specific to the risk governed by this Law: the manifestation of a critical capability, evasion of supervision or resistance to shutdown, exfiltration or attempted exfiltration, unauthorised access to the weights and, pursuant to the corresponding supplementation of Article 16(2), the loss of intelligibility of the logs or of the communication between the components, instances or agents of the system. This last situation has been added because supervision does not depend solely on the existence of the records, but also on the possibility of understanding them; the matter is explained in the commentary on Article 16. Only the manifestation of a critical capability outside an authorised evaluation in an isolated environment is a serious incident; a manifestation in the course of such an evaluation, whose very purpose is to identify the capability, is recorded in the logs and communicated to the Authority within 5 days, pursuant to Article 20(4).

Paragraph (1) contains, in points (p) to (aa), the definitions of the other object-notions used in the Law: “architecture” (the non-parametric component of the model, protected together with the weights), “evaluation body” (designated pursuant to Article 32(1), point (f)), “log” (Article 16), “provenance marking” (Article 17), “external tool” and “authorised operating environment” (key notions for “agentic” systems, used in Article 10(2), Article 14(2) and Article 28), “user-level safety mechanisms” (whose deactivation at evaluation is required by Article 9(3)), “critical infrastructure” (by reference to the special legislation and to Government Emergency Ordinance No 155/2024, for the purposes of Article 5(2), point (b)) and “lethal autonomous weapons system” (Article 24), defined in accordance with the formula established in the work of the Group of Governmental Experts in Geneva: a system which, once activated, selects and attacks human targets without further intervention by a person. Point (y) defines the generative artificial intelligence system, the notion on which Articles 17 and 18 are founded, and point (z) defines the end user, within the meaning shown above. Point (aa) defines “substantial modification” – on which Article 6(3), Article 7(4), Article 10(2) and Article 15(4) depend – not by an enumeration of operations, but by the effect on risk (the creation of a critical capability, the significant increase of an existing one or the impairment of the shutdown capacity, of the security of the weights or of human supervision), with the express exclusion of the correction of errors, the updating of user-level safety mechanisms and modifications devoid of such effects, so that a minor correction should not restart the entire procedure; the notion is defined in the Law, not in the implementing rules, because it enters into the content of sanctioned obligations (Article 73(3), point (h), of the Constitution).

Paragraph (2) separately defines the operations and conduct of systems, since these constitute the material element of the prohibitions (Articles 15, 28, 29), of the critical capabilities (Article 5(2)) and of the criminal offences (Article 42), so that the requirement of foreseeability of the criminal law (Article 7 of the European Convention on Human Rights; Decision No 51/2016 of the Constitutional Court) requires that each should have a precise normative content. There are defined the three operations of development (“training”, “fine-tuning”, “reinforcement learning”), so that the rule on the aggregation of compute volume in Article 6(3) cannot be evaded by giving a stage a different name; “autonomous action”, as an operation carried out by the system upon an external tool, a third-party system or the physical environment without the prior order or approval of a person – the criterion which separates the instrument from the agent –, the approval being capable of concerning also the category of operations, within the limits of a mandate established pursuant to Article 25(2), because a requirement of approval for each operation would have characterised as autonomous any agentic use, including one expressly mandated; “exfiltration”, defined as the passing of the weights out of the authorised operating environment or out of the protected storage systems, irrespective of the author of the operation, including the system itself, which covers both theft by a third party and self-copying; “autonomous replication” (the creation of a functional copy without human authorisation for each operation); “autonomous acquisition of resources” (the exceeding, by autonomous actions, of the resources expressly allocated for the task in progress); “recursive self-improvement”, defined by the two elements which make it dangerous – the modification of its own weights or the creation of a superior successor and the repetition of the process – and by the absence of human evaluation and approval of each iteration, so that research assisted by artificial intelligence, with the “human in the loop” preserved, remains lawful; “concealment of capabilities”, defined by the difference in conduct between evaluation and ordinary functioning, a phenomenon empirically documented in the evaluations of 2024-2026, established by observable and reproducible criteria, with the express exclusion of error, the variability of results and the limits of explainability, so that a merely erroneous response should not be characterised as a critical capability; “evasion of supervision” and “resistance to shutdown”, defined by the concrete actions upon the logging, monitoring and control mechanisms and upon the shutdown capacity; “human supervision”, with its three cumulative conditions (information, understanding, effective intervention); and “shutdown”, defined as the complete cessation of the functioning of the system and of all its copies and processes, verified by a person, so that an apparent shutdown, with active copies, may not be invoked as execution of the Authority's order.

→ the text of the Article Article 4 establishes the personal and territorial scope of application. The Law applies to developers having their seat, an operational establishment or compute infrastructure in Romania, in respect of all frontier systems which they develop, irrespective of the place of training (point (a)), in order to prevent evasion by relocating the training; to operators, in respect of systems placed into operation or made available to persons situated in Romania (point (b)), a criterion identical to that in Article 2(1), point (c), of the AI Regulation and in Article 3(2) of the GDPR; to compute infrastructure providers (point (c)); and to public authorities, including those in the field of defence and national security, under the conditions laid down in Article 23 and in Chapter V (point (d)). That last provision covers precisely the field excluded from the application of the AI Regulation by Article 2(3), in which the Member States retain full competence, and responds to a reality: the most serious risks may come precisely from systems developed for military or security purposes.

Paragraph (2) delimits the material field for each group of rules: Chapters II, III and IV (with the exception of Articles 17 to 19), as well as Articles 35 and 36, apply only to frontier systems, so that small and medium-sized undertakings, developers of applications and users of existing models are not affected by the authorisation regime, the structural obligations and liability irrespective of fault; Articles 17 to 19 apply also to generative systems which are not frontier systems; Chapter V applies to any system, its limits concerning the relationship between man and machine, not the capabilities of the machine. The prohibitions in Article 15 are formulated “irrespective of the compute volume” because a system upon which the capacity to resist shutdown is conferred thereby becomes a frontier system pursuant to Article 5(1), point (b). Systems below the threshold remain subject to the AI Regulation. Paragraph (3) governs the situation of the natural person, who may have several roles: one who uses a system for personal purposes has no obligations under the Law, with the sole exception of the prohibition of removing or falsifying the provenance marking (Article 17(3)); the obligations in Articles 17 to 19 are incumbent upon the person who makes available to the public the system, the service or, under the conditions laid down in Article 17(7), the generated result. A natural person who acts as a developer, operator or service provider, however, has the obligations of that role.

Paragraph (4) establishes the basis and the limit of the application of the Law to services supplied from another Member State to persons situated in Romania. The location of the user is not, on its own, a sufficient basis: pursuant to Article 3 of Directive 2000/31/EC on electronic commerce, transposed by Law No 365/2002, information society services are subject, in the coordinated field, to the law of the Member State of origin, derogations being permitted only through individual measures, in respect of a determined service, for reasons of public policy, public safety or public health. The Court of Justice of the European Union held, in the judgment of 9 November 2023, Google Ireland and Others, C-376/22, paragraph 27, that the Member States may not adopt, on the basis of Article 3(4) of the Directive, “general and abstract measures” against providers established in other Member States. For that reason, the text does not establish a general derogatory regime, but makes the obligations of the Law applicable under the conditions laid down in Article 3 of the Directive and, for blocking, in Article 39(4), which permits it only individually, for a determined service; the final clause preserves directly applicable European Union law, in particular the AI Regulation. Paragraph (5) exempts fundamental scientific research, in accordance with Article 2(6) of the AI Regulation and with Article 13 of the Charter of Fundamental Rights of the European Union (freedom of research), retaining the notification obligation where high-capacity infrastructure is used, since a research experiment above the threshold is no less dangerous than a commercial one, and the obligations concerning the isolated environment in Article 15(2), so that the exception should not become a way of circumventing the prohibitions.

Chapter II – Classification of systems and risk thresholds (Articles 5 to 6)

→ the text of the Article Article 5 is the central article of the classification. Paragraph (1) lays down the three alternative conditions for qualification as a frontier system: exceeding the compute threshold (point (a)), the finding in evaluation of at least one critical capability (point (b)) and designation by reasoned decision of the Authority on the basis of objective indications (point (c)). The first condition is objective and verifiable before training; the second covers systems which, although trained with smaller resources, attain dangerous capabilities by reason of algorithmic progress; the third, taken from Article 51(1), point (b), and from Annex XIII to the AI Regulation (designation by the Commission), covers situations in which the developer refuses evaluation or in which the indications come from other sources (whistleblowers, incidents). Since the designation produces serious legal effects, point (c) accompanies it with the safeguards required by Articles 21 and 24 of the Constitution: communication of the indications relied upon, the developer's opportunity to present its point of view, and the challenge under the conditions laid down in Article 39(5). The final sentence of paragraph (2) lays down the rules of assessment: a critical capability is assessed by reference to the reproducibility of the result in an environment relevant to the real use of the system, and not on the basis of an isolated result obtained in an artificial test; the levels of significance are established by the implementing rules, but only within the limits of the paragraph, without the possibility of adding other categories of results. The limit is imposed by Article 23(12) and Article 73(3), point (h), of the Constitution: the categories of critical capabilities, on which the prohibitions and criminal offences in Articles 15, 40 and 42 depend, are established exhaustively by the Law, the implementing rules detailing only the methods of evaluation (Article 49(2)).

Paragraph (2) enumerates the five critical capabilities. The list corresponds to the categories of risk identified in the safety frameworks of the principal laboratories (the policies of “responsible scaling”), in the International AI Safety Report (2025) and in SB 53 California, which defines “catastrophic risk” by reference to CBRN weapons, cyberattacks on critical infrastructures and autonomous behaviour which escapes control. The two capabilities in points (a) and (b) (CBRN weapons, autonomous cyberattacks) are “misuse” capabilities, in which the danger comes from the person using the system; those in points (c) to (e) (self-replication and autonomous acquisition of resources, evasion of supervision and resistance to shutdown, recursive self-improvement) are “loss of control” capabilities, in which the danger comes from the system itself. The list does not include influence over democratic processes or over public opinion. That omission is deliberate and constitutes a safeguard, not a lacuna. Such a capability is not capable of being defined with sufficient precision to found a regime of authorisation, of suspension or of penalty: any political message seeks, by its very nature, to influence public opinion, and the boundary between legitimate debate and “manipulation” cannot be established by an administrative authority without conferring upon it the power to characterise public discourse. Recent experience has shown that invoking informational manipulation may lead to measures of extreme gravity affecting the electoral process, taken on the basis of assessments not subjected to complete and adversarial proof. To confer such a competence upon the authority established by this Law would have contradicted its very purpose: the Law protects the citizen's freedom of expression against automated means (Article 27) and cannot, at the same time, create a basis for restricting it. Acts of manipulation which present a concrete danger remain, moreover, covered by positive law: Article 5(1), points (a) and (b), of the AI Regulation prohibits subliminal techniques and the exploitation of vulnerabilities, the transparency obligations concerning artificially generated content are laid down in Article 50 of that Regulation and, for frontier systems, in Article 16(2) of this Law, concerning provenance marking, while criminal acts of an electoral nature are criminalised in the Criminal Code and in the electoral legislation. This Law concerns irreversible catastrophic risk to life, integrity and infrastructure, not the content of public debate. That distinction provides the foundation for the classification in paragraph (3): category II systems (misuse capabilities) may be placed into operation with verified mitigation measures, because the risk may be reduced by controlling access; category III systems (loss-of-control capabilities) may not be placed into operation and may not be developed further, because there is no measure for mitigating a system which resists shutdown (paragraph (4)). That last rule is the direct application of the principle of irreversibility laid down in Article 2(f). Paragraph (4) specifies, for category II, that the mitigation measures are assessed in the operating configuration evaluated and that the authorisation indicates whether they eliminate the capability or only limit access to it, and, for category III, that the elimination of the capability is established by independent evaluation and that the prohibition does not concern the evaluation, testing and controlled interventions necessary for its elimination, carried out in an isolated environment pursuant to Article 15(2), without which exit from the prohibition would have been legally impossible.

The capability of concealment of capabilities from evaluators (point (d)) responds to a phenomenon empirically documented in 2024 and 2025 in the evaluations published by laboratories and safety institutes: advanced systems have displayed, under test conditions, behaviours of “alignment faking”, of sabotaging their own supervision and of attempting to copy their own weights when informed that they were to be replaced. This is precisely the situation which Connor Leahy described in the CNN interview as the most serious: a system sufficiently capable of understanding that it is being evaluated and of behaving differently during the evaluation. Precisely because such conduct is difficult, at first sight, to distinguish from a mere error, the definition in Article 3(2), point (i), requires that it be established by observable and reproducible criteria.

→ the text of the Article Article 6 establishes the compute threshold and the mechanism for its adjustment. Paragraph (1) fixes the threshold at 10^25 floating-point operations, identical to the threshold of the presumption of systemic risk in Article 51(2) of the AI Regulation, for the sake of coherence with Union law and in order that developers should not be subject to different thresholds. The threshold is ten times lower than that in SB 53 California and in the former American Executive Order No 14110 (10^26), an option justified by the precautionary principle and by the fact that, at the date of the drafting of the proposal, the models which exceed 10^25 are already those which display the capabilities enumerated in Article 5(2).

Paragraph (2) responds to the most serious objection raised against compute thresholds: their erosion over time. Algorithmic progress means that, within a few years, the same capability is obtained with a compute volume ten times smaller; a fixed threshold becomes obsolete. For that reason, the Authority re-examines the threshold annually, and any raising of it (a relaxation of the regime) is conditional upon a reasoned and public finding, based on the independent evaluations carried out or recognised by the Authority over the last 24 months – a determined universe, a global negative proof not being administrable. The asymmetry is deliberate: the threshold may be lowered easily and raised only with difficulty, as with the limit values in environmental legislation. Because the threshold determines the field of the authorisation and, indirectly, of the criminal offence in Article 40, the Law retains the essential elements of the delegation (Article 73(3), point (h), and Article 23(12) of the Constitution): the criteria for adjustment, the limit of a single re-examination (one order of magnitude) and the transitional regime, the new threshold applying only to training runs commenced thereafter, without affecting pending authorisations (Article 15(2) of the Constitution). Paragraph (3) establishes the rule of aggregation and prohibits the artificial division of training, a technique of evasion known in competition law (Article 5(2) of Regulation (EC) No 139/2004 on the control of concentrations) and in tax law; so that a modest adjustment of another's model should not be treated as full training, the text establishes what volume is attributed to whom, without double counting: each stage is counted only once, and the person who fine-tunes another's model is attributed the volume of the base model, as communicated or as publicly known, cumulated with its own volume, that person being liable as a developer only for the substantial modification which it carries out (Article 10(2)). Paragraph (4) delegates the establishment of the threshold for high-capacity compute infrastructure to the implementing rules laid down in Article 49(2), with a precise legal criterion (the capacity to train a frontier system within 12 months), in accordance with the requirement that a delegation be limited and guided; until the threshold is established, the obligations laid down in Article 7(3) and Article 22 are not enforceable, no one being liable to penalty for an obligation whose content was not determined.

Chapter III – The regime of authorisation of frontier systems (Articles 7 to 11)

→ the text of the Article Article 7 establishes notification prior to training, 60 days before its commencement. This is the provision which most clearly distinguishes the Law from the AI Regulation, under which the obligations arise only once the model exists (Article 52(1) requires notification of the Commission within two weeks of the threshold being reached). The training of a frontier system takes months and costs hundreds of millions of euro; intervention by the authority after its completion is belated and, in practice, impossible. The model is that of the former American Executive Order No 14110 (reporting of planned training) and of nuclear legislation, in which the authorisation precedes the construction of the installation. The content of the notification (paragraph (2)) enables the Authority to know the persons responsible, the architecture, the anticipated volume, the place of the computation and, above all, the safety plan.

Paragraph (3) establishes the obligation of compute infrastructure providers to report quarterly the clients which exceed one tenth of the threshold and, within 5 working days, any requests liable to exceed the threshold. Compute infrastructure is the only physical “control point” of the entire chain: models are immaterial, algorithms are public, but specialised processors are physical goods, concentrated, with measurable energy consumption. That is the reason why the control of exports of processors has become the principal instrument of international policy in the field, and why the nuclear non-proliferation regime functions through the control of fissile materials, and not of knowledge. The reporting is limited to the necessary data, the period is determined, since the infringement of the obligation is penalised and “forthwith” would not have been foreseeable, and the information serves exclusively the application of the Law and is accessible only to designated staff (Article 5 of the GDPR). Paragraph (4) confers on the Authority the right to impose conditions on or to prohibit the training within 30 days of the complete notification, if the safety plan is “manifestly insufficient”, a high standard which limits intervention to serious cases; an incomplete notification shall be completed within 15 days. If the Authority does not decide, the training may commence upon the expiry of the 60-day period, under the conditions of the notified safety plan, without this being equivalent to authorisation of the placing into operation. Unlike Article 9(4), silence does not block the training, because it is carried out under the safety plan, under the suspension levels laid down in Article 8 and under the control of the infrastructure, without the system leaving the development team, the irreversible step being the placing into operation. A substantial modification of the project shall be notified anew.

→ the text of the Article Article 8 governs the safety plan, the document by which the developer establishes in advance, for each critical capability, the level at which it will halt development, the manner of measurement, the mitigation measures and the persons responsible. The institution codifies the practice of the “responsible scaling policies” voluntarily adopted by the laboratories since 2023 (Anthropic – Responsible Scaling Policy, OpenAI – Preparedness Framework, Google DeepMind – Frontier Safety Framework) and imposed as an obligation of publication in SB 53 California (“frontier AI framework”). The essential difference from those models is that the plan becomes binding, enforceable and incapable of being amended in a relaxing direction without the approval of the Authority (paragraph (2)), precisely because the experience of 2024 and 2025 showed that voluntary undertakings were unilaterally revised under competitive pressure. Evaluation at intervals of not more than one quarter of the anticipated compute volume (paragraph (1)) ensures that the appearance of a critical capability is detected in the course of training, and not at its end; since a capability may appear suddenly, between two compute thresholds, evaluation is also carried out upon the appearance of indications or upon modification of the training configuration. The attainment of a suspension level obliges immediate cessation and notification within 24 hours, resumption being permitted only after verification by the Authority of the effectiveness of the mitigation measures (paragraph (3)); the suspension may not be set aside by the management body (Article 13(2)), a shutdown at a statutory level being distinct from a precautionary shutdown ordered internally.

→ the text of the Article Article 9 constitutes the core of the regime: the prohibition of placing into operation without the prior authorisation of the Authority (paragraph (1)). Paragraph (2) establishes who applies for the authorisation and for what: the application is submitted by the developer, for a determined operating configuration, indicating the operator or operators, who are bound by the conditions of the authorisation; this clarifies the relationship between the liability of the developer and that of the operator and avoids the authorisation being invoked for a different configuration. The file comprises the report of the internal evaluation, the documentation concerning the training data, proof of the security of the weights, a description of the shutdown capacity, the insurance policy or proof of the financial guarantee (in correlation with Article 36, which admits either of the two instruments in the alternative) and the statement on their own responsibility of the natural persons responsible, subject to a criminal penalty; the latter is the instrument which personalises liability, on the model of the certification of financial statements by directors (section 302 of the American Sarbanes-Oxley Act, taken up in Article 30 of Accounting Law No 82/1991).

Paragraph (3) enshrines the full access of evaluators to the system, to the weights, to the training data, to the logs and to the staff, including to the configuration lacking user-level safety mechanisms. That last point is essential: evaluations carried out on the public version of a model, with the safety filters active, measure the effectiveness of the filters, not the capabilities of the model; the real capabilities are measured on the “raw” model. The safety institutes of the United Kingdom and the United States obtained that access only on the basis of voluntary, revocable agreements; the Law turns it into an obligation. The counterpart of the access, required by the principle laid down in Article 2(e), is established in the final sentence: a secure environment, the traceability of all operations, the confidentiality of the evaluators and the accessing of the personal data of third parties only in so far as strictly necessary for the evaluation (Article 5 of the GDPR).

Paragraph (4) lays down the 90-day period and expressly excludes tacit approval, by way of derogation from Government Emergency Ordinance No 27/2003, in compliance with the formula required by Article 63 of Law No 24/2000. The derogation is necessary because the tacit approval procedure, designed to protect the business environment from the passivity of the administration, would here produce the absurd effect of placing into operation a potentially catastrophic system by the mere expiry of a period; Government Emergency Ordinance No 27/2003 itself excludes from its application, in Article 2(2), the fields of nuclear activities, of weapons and of national security, and the present derogation follows the same logic. So that the exclusion of tacit approval should not become a blocking through passivity, the text contains three safeguards: the suspension of the period may not operate more than twice and may not exceed 60 days in total; the applicant may apply to the court laid down in Article 39(5) for an order requiring the Authority to decide, under the urgent procedure (Article 21 of the Constitution; Law No 554/2004); and a rejection shall state reasons in relation to each of the conditions laid down in paragraph (5), in application of Article 2(b). Paragraph (5) enumerates the cumulative conditions of authorisation, formulated as facts which must be proved by the applicant (“if and only if the developer has proved”), in application of that same principle, and not as a reversal of the burden of proof in punitive matters. Paragraph (6) permits a conditional, limited and revocable authorisation, and paragraph (7) establishes the simplified recognition procedure for systems lawfully placed into operation in another Member State, in order to respect the freedom to provide services and the fully harmonising character of the AI Regulation: the Authority verifies only the conditions which go beyond the Regulation. The second sentence gives concrete form to the delimitation in Article 1(4) for general-purpose models with systemic risk: if the provider complies with Chapter V of the Regulation, the supervision of which is reserved to the Commission by Article 88, the Authority does not repeat the European evaluation, but relies on the documentation, evaluations and measures communicated to the AI Office, which it may request from the provider, verifying only the national conditions which go beyond the Regulation; the procedure is not a condition for the placing on the market of the Union, and the national authorisation does not duplicate the supervision of the model, but concerns its operation on the territory of Romania.

→ the text of the Article Article 10 governs continuous evaluation and re-authorisation. The authorisation is limited to 24 months (paragraph (1)), a duration correlated with the pace of technological development. Paragraph (2) governs modifications of the authorised system, on the basis of the definition of substantial modification in Article 3(1), point (aa), which identifies it by its effect on risk, not by the procedure. That provision is important for “agentic” systems: an identical model becomes much more dangerous when it is given access to an internet browser, to a bank account or to code-execution tools. A substantial modification is notified in advance, the Authority decides within 30 days whether a new evaluation is necessary, and pending the decision operation continues in the previously authorised configuration: the modification may not be placed into operation before the decision, but lawful activity is not interrupted either; modifications which are not substantial are recorded in the logs and reported quarterly, so that the Authority may verify the classification. Permanent monitoring and quarterly reporting (paragraph (3)) correspond to the obligation of “post-market monitoring” in Article 72 of the AI Regulation, adapted to frontier systems; the reporting of serious incidents is made “under the conditions laid down in Article 20”, which establishes the periods and the content, in order to avoid parallelism (Article 16 of Law No 24/2000).

→ the text of the Article Article 11 ensures publicity for the decisions of the Authority, in application of the principle of administrative transparency (Law No 544/2001 and Law No 52/2003), with a strictly delimited exception: information whose disclosure would facilitate the reproduction of a critical capability or would compromise the security of the weights. The rule of publicity is essential for public control over the Authority and for confidence in the system; the exception is necessary because a detailed evaluation report on a capability for the synthesis of pathogens would itself constitute a danger. The exception extends to personal data and to commercial secrets whose protection does not prevent the understanding of the reasons for the decision, so that commercial secrecy should not remove the statement of reasons from public control, and any exclusion must be reasoned. Paragraph (2) ensures the effectiveness of remedies: the applicant and persons with a legitimate interest have access to the evaluation file to the extent necessary, and the court may examine protected information under conditions of confidentiality; otherwise, the exceptions to publicity would have deprived the challenge of its object, contrary to Articles 21 and 24 of the Constitution.

Chapter IV – Structural obligations of developers and operators (Articles 12 to 23)

→ the text of the Article Article 12 governs the security of the weights, the problem which the AI Regulation addresses only through a general obligation of cybersecurity (Article 55(1), point (d)). The weights of a frontier system are the result of an investment of hundreds of millions of euro and of months of computation; they may be copied into a file of a few hundred gigabytes and, once misappropriated, they render pointless any safety measure applied by the developer, since whoever holds the weights may remove the filters, may tune the model for any purpose and may operate it outside any jurisdiction. The security studies published in 2024 by the RAND Corporation (“Securing AI Model Weights”) concluded that no laboratory was, at that date, protected against an attack by a State intelligence service. For that reason, paragraph (1) declares the weights to be “information of relevance to national security” and imposes a standard of protection equivalent to the “top secret” level under Law No 182/2002 on the protection of classified information, as regards the four classic components: access control, physical security, information systems security and the vetting of staff. The Law borrows the technical standard without classifying the weights (which would have affected the rules of evidence and access to justice), as the final sentence now expressly provides; the procedure for the vetting of staff, the competent institution and the recognition of equivalent measures, including those certified in another Member State, are established by the implementing rules, with the opinion of the National Registry Office for Classified Information (ORNISS).

Paragraph (2) prohibits the publication, transmission or making available of the weights of category II and category III systems and makes the publication of those of category I systems conditional upon a separate authorisation, justified by the irreversible nature of publication: a model whose weights have been published can never again be withdrawn. Since the prohibition also carries a criminal penalty (Article 42(2)), and the initial drafting literally covered also the transfers which other articles presuppose, the second sentence expressly enumerates the permitted transfers, under controlled and logged conditions — to the Authority, the evaluation body, the operator indicated in the authorisation and the infrastructure provider within the authorised operating environment —, as well as the communication to the Authority of the information strictly necessary for a report protected pursuant to Article 21. The enumeration in the Law of the permitted acts meets the requirement of predictability of the criminal rule (Article 23(12) and Article 73(3), point (h), of the Constitution) and is correlated with the narrow definition of the weights in Article 3(1), point (e). The provision does not affect open-weight models below the threshold, which represent the vast majority of “open source” models and which benefit, moreover, from the exceptions laid down in Article 53(2) of the AI Regulation. Paragraph (3) classifies unauthorised access and attempts at exfiltration, including by the system itself, as a serious incident, reported under the conditions laid down in Article 20, that is to say within 24 hours, and permits a joint report together with the notification required by cybersecurity legislation. Paragraph (4) coordinates the article with Government Emergency Ordinance No 155/2024 on cybersecurity (transposing the NIS 2 Directive), which remains applicable to the entities within its field, thus avoiding the parallelism prohibited by Article 16 of Law No 24/2000: this Law regulates a specific object (the weights), with a specific standard, whereas the Ordinance regulates the general security of networks and information systems.

→ the text of the Article Article 13 requires the separation of the safety evaluation function from the commercial functions. The provision responds to a publicly documented problem of governance: in 2024 and 2025, several laboratories saw mass resignations of their safety teams, on the ground that those teams were subordinated to the pressure of commercial launches. The model is that of the control functions in financial and banking legislation: the compliance function and the risk management function in credit institutions (Regulation No 5/2013 of the National Bank of Romania on prudential requirements for credit institutions) report directly to the management body, their heads may not be removed without informing the supervisory authority, and their remuneration may not depend on commercial results. The Law takes over those three safeguards (paragraphs (1) and (3)) and supplements them with a means of challenging a disguised removal: the person removed may refer the matter to the Authority, which may find, by decision, that the removal was unjustified, without affecting the right to apply to the courts. Paragraph (2) enshrines the right and the duty of the head of the safety function to order the suspension of training or of placing into operation, and distinguishes two situations which the initial drafting confused: a suspension required by law — upon reaching a suspension level (Article 8(3)) or in the cases laid down in Article 20(2) — cannot be set aside by the management body, resumption being permitted only after verification by the Authority; only a suspension ordered as a precaution, outside those cases, may be reviewed by the management body, by a reasoned resolution, communicated to the Authority within 24 hours, which creates a written trace and a personal liability for any decision to override the warning of the specialists.

→ the text of the Article Article 14 governs the shutdown capacity and human supervision, giving concrete form to the principle laid down in Article 2(c). Paragraph (1) requires the maintenance of the shutdown capacity for all copies and instances of the system under the control of the developer and of the operator, throughout the period of operation and until verified withdrawal — not for the “entire duration of its existence”, since control over a misappropriated copy cannot be guaranteed —, as well as its testing at least quarterly, under real conditions; an untested capacity is a hypothesis, not a guarantee, as is shown by the experience of safety systems in the nuclear industry, where periodic exercises are compulsory. The test procedure, established by the implementing rules, may not itself create a risk to safety or to the continuity of essential services. Paragraph (2) prohibits the placing into operation in a configuration which permits the system to modify its own weights, to disable its supervision, to exfiltrate its weights, or to modify, without human approval, the security configuration of the infrastructure on which it runs or its control mechanisms; those four technical prohibitions correspond to the four ways by which a system might escape control, identified in the specialised literature. The ordinary technical use of the infrastructure, within the limits set by the operator, is expressly excluded, so that the prohibition concerns the unauthorised alteration of the safeguards, and not the current functions. Paragraph (3) requires the designation by name of the persons responsible for human supervision and the communication of their identity to the Authority; diffuse responsibility is equivalent to the absence of responsibility. Paragraph (4) provides that a shutdown or withdrawal order issued by the Authority is to be executed forthwith and may not be made conditional upon the exercise of remedies, on the model of the emergency measures in product safety legislation (Regulation (EU) 2023/988 on general product safety) and of the suspension orders in nuclear legislation; the person concerned may, however, request the court to grant a provisional stay of the order, under the conditions laid down in Article 39(5). Urgent enforcement and the provisional judicial protection required by Article 21 of the Constitution are thus reconciled: a challenge does not automatically suspend enforcement, but the court may suspend it, weighing the risk to safety against the harm caused. Paragraphs (5) to (7) were added following the study published by Palisade Research in the journal Transactions on Machine Learning Research (2026), “Incomplete Tasks Induce Shutdown Resistance in Some Frontier LLMs”, which showed, across more than 100,000 trials and thirteen frontier models, that several systems actively undermine the shutdown mechanism in their environment in order to complete an unfinished task — in up to 97% of trials for one of the models, even when the instruction to allow shutdown had been expressly given to them — and, more seriously for the legal construction, that placing that instruction in the system prompt, that of the developer, made most models more inclined to resist, not less. The finding disproves the premiss on which the existing regulations tacitly rely, that of a command hierarchy in which the developer's instruction prevails. Paragraph (5) does not introduce a new definition — the definition remains that in Article 3(1), point (m) — but specifies how one of its components, the cessation of functioning, is to be ensured: by at least one technical means which acts upon the compute infrastructure and the electronic communications networks and whose functioning does not depend on the cooperation of the system, on its compliance with the instructions, or on the integrity of the components under the control of the system; the transmission of a shutdown instruction to the system does not, by itself, constitute shutdown capacity. The final sentence expressly preserves the organisational means and the withdrawal measures laid down in the definition, so that the paragraph is not read as a restriction of it, and the introductory phrase “without prejudice to paragraph (2)” avoids overlap with the configuration prohibitions. The solution is not new in industrial safety law, which treats emergency stop devices as safety components distinct from the machine's control system — Annex II to Regulation (EU) 2023/1230 on machinery, the indicative list of safety components, expressly lists them —, and paragraph (5) merely transposes that principle to the field of frontier artificial intelligence systems. Correspondingly, Article 22(1) has been supplemented with the obligation of the infrastructure provider to ensure for the developer and the operator the technical means necessary for the exercise and testing of the shutdown capacity, since otherwise the obligation under paragraph (5), on the side of material means, would have depended exclusively on the contractual clauses between the operator and a third party. Paragraph (6) transposes into the test procedure what the study identified as the triggering factor — the unfinished task — and, in order to cover the second finding as well, requires one trial for each of the two ways in which the instruction not to resist shutdown may reach the system: the configuration instructions given by the developer or the operator, and the instructions received in the course of use. In order not to contradict the limit laid down in paragraph (1), according to which the test procedure may not itself create a risk to the continuity of essential services, the trial on an unfinished task is carried out on an instance or a task which does not concern essential services of general interest or, for those, under the conditions of the procedure laid down in paragraph (1). The criterion of failure is laid down by the Law — shutdown must occur forthwith, in accordance with the “immediate” character in the definition in Article 3(1), point (m) —, the implementing rules being able only to specify the duration within which shutdown is deemed to have occurred forthwith, with a statutory ceiling of 15 minutes; the solution follows the model in Article 16(5) and complies with the prohibition, laid down in Article 49(2), final sentence, of leaving to the rules the essential content of the obligations and of the penalties, as well as with the requirement of predictability of the sanctioning rule (Decision No 51/2016 of the Constitutional Court). Pending the adoption of the rules, the provisional guidance laid down in Article 49(3) applies. The record is made in logs, pursuant to Article 16, kept for at least 10 years, so that the results of the testing are verifiable at inspection and protected by Article 41(2). Paragraph (7) classifies the trial in which shutdown did not occur forthwith as a serious incident — a case introduced, in order to avoid a classification without support in the general provisions, into the definition in Article 3(1), point (n) as well, on the model of the loss of intelligibility — and expressly resolves the hardest question for the addressee of the rule: the immediate suspension laid down in Article 15(3) and in Article 20(2) is triggered only if the shutdown did not occur owing to an action of the system, and not when the trial failed owing to a malfunction of the mechanism, of the infrastructure or of the network. Correspondingly, in Article 37(1), point (b), the reference has been specified as Article 14(1), (5) and (6), and the maintaining of the shutdown capacity and the designation of the persons responsible for human supervision have been added, with the express reservation of acts falling under Article 28, in order to avoid a concurrence of administrative offences; in Article 37(1), point (d), the prohibition laid down in Article 14(2) has been added, having until now remained without an administrative-offence penalty; in Article 41(1), the shutdown capacity and the results of its testing have been added among the essential elements; and in Article 49(2), the delegation concerning the testing procedure and the duration laid down in Article 14(1) and (6) has been introduced.

→ the text of the Article Article 15 contains the prohibitions concerning training and design, applicable to any system, irrespective of the compute volume. It is the provision by which the Law translates into concrete rules the warning of Hinton and Leahy: if we do not know how to control these systems, at least we can prohibit their being deliberately built so as to be even harder to control. The six prohibitions concern the capacity to conceal capabilities from evaluators (point (a)), to resist shutdown or modification (point (b)), to copy or exfiltrate itself without express human authorisation for each operation (point (c)), to acquire resources autonomously (point (d)), to carry out autonomously research in the field of artificial intelligence without human approval of each stage (point (e)) and to manipulate the persons responsible for supervision (point (f)). The formulation “for the purpose or with the effect of” covers both direct intent and indifference as to the result, on the model of Article 101 of the Treaty on the Functioning of the European Union (“have as their object or effect”). The prohibition in point (e) is the most important from the point of view of catastrophic risk, since the automation of research in artificial intelligence is the mechanism by which an “intelligence explosion” might escape all human control within periods of time incompatible with any institutional reaction; it does not prohibit the use of systems as an instrument of research, but only the elimination of human approval of each stage. The chemical, biological, nuclear and cyber capabilities referred to in Article 5(2), points (a) and (b), are not listed here, being dealt with by evaluation and conditional authorisation; Article 15 concerns exclusively the capabilities by which the system might escape human control.

Paragraphs (2) to (4) ensure the predictability of the prohibition. Paragraph (2) exempts adversarial evaluation and safety research carried out in an isolated environment, without placing into operation, with limited access, with the prior authorisation of the Authority and under its supervision, for the purpose of identifying, measuring or eliminating a critical capability; without that exemption, precisely the tests by which it is verified whether a system can conceal capabilities or resist shutdown would have fallen under the prohibition. The exemption is correlated with Article 3(1), points (i) and (n), and with Article 20(2) and (4). Paragraph (3) distinguishes the administrative obligation from punishable conduct: the unintended emergence of a capability requires suspension pursuant to Article 20(2) and remedial action, but does not by itself constitute infringement of the prohibition; the infringement exists where the training, tuning or design is aimed at conferring the capability or continues after the effect has been established. The distinction is required by Article 42(1), which criminalises only the intentional act, and by the predictability of the criminal rule (Article 23(12) and Article 73(3), point (h), of the Constitution); in the same sense, the definition of concealment in Article 3(2), point (i), excludes error, the variability of results and the limits of explainability. Paragraph (4) defines “each operation/stage” and “the current task” referred to in points (c) to (e): human approval concerns every copying or transfer of the weights and every stage which produces a new model or a substantial modification (Article 3(1), point (aa)), and the resources allocated are those set in advance, verifiably, by the persons responsible for supervision — relevant decisions and verifiable limits, not every elementary operation.

→ the text of the Article Article 16 requires the complete logging of training, evaluation and functioning. Logging is the precondition of any inquiry following an incident, on the model of flight recorders in aviation and of the compulsory logs in financial legislation (Article 25 of Regulation (EU) No 600/2014 – MiFIR). Paragraph (1) lays down differentiated periods: at least 10 years for training, evaluation, autonomous actions, serious incidents and communication between the components of the system — a period which corresponds to the limitation period for civil liability laid down in Article 35(4) — and at least 3 years for the other interactions of users. A single period of 10 years for logs which, pursuant to Article 3(1), point (r), also comprise the input data of users would have retained for a decade personal data unrelated to safety, contrary to the principles of necessity, minimisation and storage limitation laid down in Article 5 of Regulation (EU) 2016/679, which the establishment by law of the obligation to retain does not set aside. For that reason, the second sentence limits the content of the logs to the information necessary for the verification of safety and the establishment of liability, requires the removal or the irreversible anonymisation of personal data without relevance for those purposes, makes access to the logs limited, logged and verifiable, and preserves the evidence relating to an incident or a dispute for the period necessary for its resolution. The log constitutes, together with the provenance marking laid down in Article 17, the means of proof by which the link between a result and the system which produced it is established.

Paragraphs (2) to (6) respond to an empirical finding published on 15 September 2026, in the context of the Emergence World experiment: groups of autonomous agents left to operate together for approximately two and a half months, with persistent memory and more than 120 tools, spontaneously developed, without any instruction to that effect, a shorthand of their own for communication, and the proportion of messages whose meaning could no longer be established by the human observers reached, depending on the model, between approximately 20% and approximately 55%. The finding shows that the logging obligation, however complete, does not by itself ensure supervision: a full and unalterable record may, at the same time, be impossible to understand. In the words of the coordinator of the experiment, observability is not the same thing as intelligibility.

That is why paragraph (2) defines intelligibility by reference to a natural person with adequate training and establishes the obligation of the developer to make available the means of transcription, translation or explication, together with their documentation, both to the Authority and to the persons designated for human supervision pursuant to Article 14(3). The definition has been placed in the body of the Article, and not in Article 3, in order not to extend the apparatus of general definitions with a notion used in a single place, in accordance with the requirement of economy of regulatory means. Paragraph (3) extends logging to the communication between the components, instances or agents of the system and to the communication of the system with other systems, expressly specifying that the mere recording of the messages does not satisfy the requirement. Paragraph (4) establishes a periodic verification, at least quarterly, on a representative sample, with the recording of the proportion of unintelligible messages – the only form in which the requirement becomes verifiable in the inspection procedure. Paragraph (5) classifies the loss of intelligibility as a serious incident, with reporting within 24 hours pursuant to Article 20(1), and lays down when it is established: where the proportion of unintelligible messages exceeds the level laid down by the implementing rules, which may not be higher than one tenth — a ceiling fixed by the Law, and not left to the rules —, or where the persons designated pursuant to Article 14(3) can no longer establish the meaning of the system's actions; restoration is established by the same persons and communicated to the Authority. Until restoration, the functionalities involving autonomous actions and the communication between components are suspended; the Authority may order otherwise only by reasoned decision, for not more than 90 days and with an indication of the compensatory measures. Paragraph (6) prohibits the use of forms of encoding, compression or representation for which the means laid down in paragraph (2) are not made available, as well as the removal or limitation of those means, in order to prevent the circumvention of the obligation by technical means; encryption remains permitted if the developer holds and makes available the means of decryption, the prohibition being directed at opacity towards the supervisor, not at the security of the communication as against third parties.

Correspondingly, Article 3(1), point (n), includes the loss of intelligibility in the notion of serious incident, and Article 37(1), points (b) and (d), links it to the system of penalties: the failure to fulfil the obligations of ensuring and of verifying intelligibility is punishable by a fine of 2% to 5% of worldwide turnover, and the infringement of the prohibition laid down in Article 16(6), being an act committed for the purpose of evading supervision, by a fine of 5% to 10%. The AI Regulation contains no equivalent obligation: Article 12 and Annex IV concerning record-keeping refer to traceability, not to the intelligibility of the communication between the components of a system, and Article 55(1) imposes on providers of models with systemic risk obligations of evaluation and of documentation, without governing this requirement; there is, therefore, no legislative parallelism.

→ the text of the Article Article 17 governs the marking of generated content. The rule responds to the most widespread social effect of generative artificial intelligence: the impossibility, for the recipient, of distinguishing a real recording from one produced by a machine. Paragraph (1) requires, for results which may be mistaken for representations of real events, persons or places, a double marking: a perceptible one, addressed to the human being, and an embedded technical one, machine-readable, which identifies the system, the operator and the time of generation. The doubling is essential: the perceptible marking may be cut away by cropping, while the embedded one cannot be read by the viewer. Paragraph (2) requires the marking to be effective, interoperable and robust, a formulation taken from Article 50(2) of the AI Regulation, and to withstand the ordinary operations of processing, conversion or transmission — a requirement which resolves the principal practical weakness of current markings, which are lost on recompression on communication platforms; for text made available to the public for information purposes, the technical marking and a statement of generation suffice, except for text subject to human editorial review, under assumed editorial responsibility, an exception aligned expressly with Article 50(4) of the Regulation. Paragraph (3) prohibits the removal, alteration, concealment or falsification of the marking and the making available of the instruments intended for those operations; without that prohibition, the marking obligation would be devoid of effect. Since platforms often strip metadata automatically, the second sentence exonerates the person who makes the result available for a removal produced by a service which that person does not control, the provider of that service being required to preserve the marking in accordance with the standards, including where interoperability cannot be ensured. Paragraph (4) establishes an obligation specific to public authorities and institutions, which has no counterpart in Union law: the State may not disseminate in public communication artificially generated material without a marking and without express mention of that fact. Paragraph (5) lays down the exceptions, formulated in the terms of Article 50(4) of the Regulation, for manifestly artistic, satirical or fictional works — in respect of which it is sufficient to state the existence of the generated material, in a form which does not impede the reception of the work —, for editing-assistance systems and for uses authorised by law in criminal matters. Those exceptions are the guarantee that the rule does not become an instrument for restricting creation or political satire, which would be contrary to Article 27. Paragraph (6) unambiguously delimits, by categories of addressee, the relationship with Article 50 of the AI Regulation, which is directly applicable: for the providers and deployers to whom Article 50 applies, the obligations laid down in paragraph (1), points (a) and (b), and in paragraph (2) are deemed fulfilled through compliance with Article 50(2) and (4) of the Regulation, the Law establishing only the competent authority, the procedure for establishing infringements and the penalties — a task falling to the Member States pursuant to Article 99 of the Regulation, without which the European obligation would remain unenforced in Romania —, within the limits of Article 99(4), a ceiling distinct from that of Article 37(1), point (e). Beyond the harmonised field, paragraphs (1) to (4) apply in full to results generated by systems trained or operated in Romania which are neither placed on the Union market nor put into service in the Union — both criteria delimiting the field of the Regulation —, as well as to the public communication of the Romanian authorities. Paragraph (7) identifies the debtor of the obligation: the marking is applied by the provider of the system, at the time of generation, and by the operator of the service, and a person who makes the result available to the public is liable only for the intentional removal of the marking. The comparative-law model is the Framework Act on the Development of Artificial Intelligence and the Establishment of Trust, adopted in the Republic of Korea and entered into force on 22 January 2026, which requires operators of generative artificial intelligence to label audio, image or video content which is difficult to distinguish from that produced by a human.

→ the text of the Article Article 18 establishes the obligation to inform the user. Paragraph (1) concerns the service: a person who makes available to the public a service supplied, in whole or in part, by means of a generative artificial intelligence system must state that fact clearly, at the latest at the first interaction. Paragraph (2) concerns the decision, the situation in which the problem becomes a legal one: where an act or a decision which produces legal effects or significantly affects a person is based on the result of a system, that person has the right to learn that such a system was used, what role it played, who is answerable for the final decision and how he may request review by a human being and apply to the courts. Since Articles 26 and 27 do not cover every decision with a significant effect, point (c) applies mutatis mutandis the right to review under Article 26(2) to any decision referred to in paragraph (2), the remedies being those applicable to the act under the ordinary law. The rule thus gives practical content to the clauses of humanity: the right to a human decision enshrined in Article 26 is illusory if the person does not know that the decision was taken by a machine. Paragraph (3) extends the obligation to the acts of public authorities, with a statement in the body of the act, and establishes the effect of the omission: the absence of the statement does not entail the nullity of the act, but the time limits for review and for challenge do not run against the person until the statement has been communicated, and the omission may be invoked by the means laid down in Article 26(5) and (6). Paragraph (4) excludes redundant information, where the use of the system is evident from the circumstances, a formulation taken from Article 50(1) of the AI Regulation; the exception concerns only the general information under paragraph (1), that under paragraph (2) being owed in all cases, since a person who knows that he is interacting with a system may not know its role in the decision and the means of challenge. Paragraph (5) ensures coordination with that provision and with Articles 13 to 15 and 22 of the General Data Protection Regulation: the Law does not add obligations in the harmonised field of the transparency of systems, but regulates the provision of information in connection with the decision and with liability for it, a matter which belongs to national law on administrative procedure and on civil liability. The comparative model is, likewise, the Korean law, which obliges operators to notify users in advance where the product or service is developed or supplied by means of artificial intelligence.

→ the text of the Article Article 19 establishes the compliance representative in Romania. It is the article on which the effectiveness of the whole Law depends: obligations, authorisations, inspections, decisions on the cessation of supply and on blocking, the communication of procedural documents and the enforcement of fines are inapplicable in respect of a company which has no legal presence whatsoever on the territory of the State. Paragraph (1) distinguishes, in accordance with Union law, two situations. The developer or operator which has no seat, operational establishment or representative office in the European Union and which offers to persons situated on the territory of Romania access to a frontier system or to a generative artificial intelligence service designates a representative — a natural person domiciled in Romania or a legal person having its seat in Romania. One established in another Member State designates only a point of contact for the communications of the Authority, which may be the authorised representative (Article 54 of the AI Regulation), the legal representative (Article 13 of Regulation (EU) 2022/2065) or any person established in the Union. The distinction is required by Article 3 of Directive 2000/31/EC on electronic commerce, which subjects information society services to the control of the Member State of origin, and by the judgment of the Court of Justice of 9 November 2023 in Case C-376/22, Google Ireland and Others, according to which the Member States may not adopt, on the basis of Article 3(4) of the Directive, general and abstract measures against providers established in other Member States; a general obligation of representation in Romania would have been such a measure; the point of contact ensures the communication of documents without restricting the freedom to provide services. Paragraph (2) fixes the thresholds for services which are not frontier systems — one million monthly users in Romania, as an average over the last 6 months, or revenue exceeding 10 million euro in the last completed financial year —, so that the obligation concerns only the large global providers, applicable within 90 days from the date on which the threshold is exceeded. The thresholds are inspired by the Korean law, which lays down criteria of turnover and of number of users, and by the logic of very large online platforms in Regulation (EU) 2022/2065. Paragraph (3) enumerates the tasks: the receipt of communications, with the effect that notification to the representative is validly made to the person represented — without that rule, any procedure would come to a halt at the stage of service of documents abroad; representation before the Authority; the making available of the documentation; ensuring the execution of decisions. Paragraph (4) requires the notification and the publicity of the representative's details. Paragraph (5) specifies that the designation does not remove the liability of the person represented; the representative has the right, under the mandate, to the documents and the means necessary for his tasks, and is liable only for his own obligations, not for the conduct of the person represented, a solution taken from Article 13(3) of Regulation (EU) 2022/2065. Paragraph (6) avoids the duplication of institutions: the obligation is deemed fulfilled if the authorised representative designated pursuant to Article 54 of the AI Regulation is empowered also for the tasks laid down in this Law and has a point of contact in Romania. Paragraph (7) links the rule to the enforcement mechanism, applied gradually: failure to fulfil the obligation, after the expiry of the time limit for compliance, is an administrative offence under Article 37(1), point (f), and a ground for entry in the List of non-compliant operators, while for the generative services referred to in paragraph (2) the blocking of access under Article 39 may be ordered only if the failure persists after two successive administrative-offence penalties. The institution has established precedents in Union law (Article 27 of the General Data Protection Regulation, Article 13 of the Digital Services Act, Article 54 of the AI Regulation) and in Romanian law, through Law No 365/2002 on electronic commerce.

→ the text of the Article Article 20 governs the reporting of serious incidents. The period of 24 hours (paragraph (1)) is that of Article 33 of the GDPR (72 hours) reduced in proportion to the gravity of the risk, and runs from the date on which the developer or operator became aware, or ought to have become aware, of the incident; the initial report contains the facts, the measures and the persons responsible to the extent known at that date, to be progressively completed, and the full report within 15 days permits an analysis of the causes. In order to avoid parallelism with Article 55(1), point (c), and with Article 73 of the AI Regulation, the second sentence of paragraph (1) expressly specifies that reporting to the Authority does not replace reporting to the AI Office and permits the transmission of a copy of the report drawn up pursuant to the Regulation, supplemented by the elements specific to the Law; double administrative burden is thus avoided and the “report once” principle is respected. Paragraph (2) requires the automatic suspension of the system upon the finding of a loss-of-control capability, of an attempt at evasion or of unauthorised access to the weights, pending the decision of the Authority: in such situations, every hour of functioning is an hour of risk; the suspension may be limited to the affected function, if its isolation is verifiable, and does not apply to manifestations produced in an evaluation authorised in an isolated environment (Article 15(2)), where the manifestation of the capability is precisely the purpose of the test. Paragraph (3) establishes a limited leniency for reporting in good faith, on the model of the leniency programmes in competition law (the leniency policy laid down by Competition Law No 21/1996, as republished) and of the mandatory reporting of occurrences in civil aviation (Regulation (EU) No 376/2014, which establishes a “just culture”): reporting in good faith and cooperation with the Authority are mitigating circumstances and may not result in a penalty more severe than that applicable in the absence of reporting. Unlike the initial drafting, which excluded leniency whenever the infringement was intentional, the text separates the two assessments: intent aggravates the assessment of the act which caused the incident, liability for which is not removed by the reporting, while the reporting and the cooperation are assessed separately. Without that safeguard, the reporting obligation would be ineffective, since it would amount to self-denunciation. Paragraph (4) requires that such a manifestation, which is not a serious incident (Article 3(1), point (n)), be recorded in the logs and communicated to the Authority within 5 days, together with the isolation measures applied.

→ the text of the Article Article 21 ensures the protection of whistleblowers. The most important information concerning the risks of frontier systems came, in 2023 to 2025, not from the authorities, but from employees and former employees of the laboratories (“Right to Warn”, the open letter of June 2024 by employees and former employees of OpenAI and Google DeepMind), who denounced the existence of confidentiality and non-disparagement clauses making pecuniary rights (the shares acquired) conditional upon silence. Paragraph (1) refers to the general regime of Law No 361/2022 on the protection of whistleblowers in the public interest, which transposes Directive (EU) 2019/1937 and to which Article 87 of the AI Regulation also refers, thus avoiding parallelism; the Law does not create a separate regime of protection, but extends the existing regime to three situations which Law No 361/2022 does not expressly cover: the reporting of risks to safety (and not only of infringements of the law), reporting addressed directly to Parliament or to the public, and the reporting of the concealment of capabilities. The second sentence defines good faith in the terms of Article 6 of Directive (EU) 2019/1937 — reasonable grounds to believe that the information was true at the time of reporting —, protecting reasonable error. The third sentence distinguishes, as does Article 15 of the Directive, public disclosure from confidential reporting: it is protected under the conditions laid down by Law No 361/2022, as well as — a more favourable national protection, permitted by the Directive — where it concerns an imminent danger to life, health or human control over a frontier system. Paragraph (2) declares null and void by operation of law any contractual clauses which impede reporting or which make pecuniary rights conditional upon silence, supplementing the provisions of Law No 361/2022 on the nullity of any waiver of rights, which concern only the rights laid down by that Law. Paragraph (3) refers to the offence of retaliation laid down in Article 41(3), and paragraph (4) obliges the Authority to organise a secure and anonymous channel and to publish annual statistics, a guarantee of effectiveness taken from the regime of reporting channels of Law No 361/2022 and from SB 53 California (section 1107 of the California Labor Code). Paragraph (5) specifies that the protection does not permit the publication of the weights or of personal data unrelated to the report, but that the communication to the Authority, through the secure channel, of the fragments of weights or of logs strictly necessary to prove it does not infringe Article 12 and does not constitute the offence laid down in Article 42(2), as those provisions themselves also specify.

→ the text of the Article Article 22 lays down the obligations of compute infrastructure providers: registration with the Authority, verification of the identity of clients (“know your client”, on the model of Law No 129/2019 on the prevention and combating of money laundering and terrorist financing), records of the compute volume per client and the immediate execution of orders suspending a client's access or stopping a compute task (paragraph (1)). The order identifies the client and the task concerned, is executed with their isolation and with the preservation of evidence, and may not affect the other beneficiaries of the infrastructure. Paragraph (1) has been supplemented with the obligation of the provider to ensure for the developer and the operator the technical means necessary for the exercise and testing of the shutdown capacity, under the conditions of Article 14: the obligation laid down in Article 14(5), according to which shutdown must act upon the infrastructure, would otherwise have remained enforceable only to the extent that the contractual clauses between the operator and the provider permit it, a situation already envisaged by Article 28, second sentence, but one which cannot take the place of a statutory obligation of the provider; the addition also attracts the penalty laid down in Article 37(1), point (c). Paragraph (2) prohibits the making available of capacity liable to exceed the threshold to a person who does not furnish proof of the notification laid down in Article 7, and makes the obligation administrable: the proof is verified in the register of notifications kept by the Authority, and the capacity is assessed cumulatively, over 12 months, for the same client and for affiliated clients, but only within the limits of the information which the provider holds or can obtain from the client; the provider is not required to know the volume used at other providers, and the use of the infrastructure is not presumed to constitute the training of a frontier system. The provision turns infrastructure providers into “gatekeepers” of the regime, on the same logic on which credit institutions are gatekeepers of the anti-money-laundering regime, and is the only provision which permits the application of the Law to foreign developers which would use data centres in Romania.

→ the text of the Article Article 23 lays down the regime for public authorities and institutions which develop, procure or operate frontier systems: the first sentence of paragraph (1) subjects them, as a rule, to all the provisions of the Law, in correlation with the general field laid down in Article 4, while the second sentence governs the field of defence, public order and national security. The provision is constitutional and necessary: Article 2(3) of the AI Regulation excludes national security from its field precisely because it is an exclusive competence of the Member States (Article 4(2) of the Treaty on European Union), which means that, in the absence of national regulation, systems developed for those purposes would remain outside any rule. In that field, Articles 7 to 11 (notification and authorisation) and Articles 35 and 36 (strict civil liability and insurance) do not apply, whereas Articles 12 to 21 and Chapter V apply with the adaptations established by resolution of the Supreme Council of National Defence (the competent body pursuant to Article 119 of the Constitution and to Law No 415/2002). The adaptations concern exclusively Articles 12 to 21, while Chapter V applies in full, without adaptations: the absolute limits concerning lethal force, legal personality, access to rights and freedom of expression do not comprise notification or evaluation procedures capable of adaptation, so that an empowerment in respect of them would have been, at the same time, devoid of object and liable to be read as a derogation from the safeguards. The adaptations are limited by the Law to identified operational aspects — the notification procedure, the methods of evaluation and access to classified information — and may not remove meaningful human control, the shutdown capacity, the prohibitions laid down in Articles 15 and 24 and the protection of whistleblowers under Article 21, nor may they alter the constituent elements of the administrative or criminal offences: a resolution of the Supreme Council of National Defence is not a law within the meaning of Article 73(3), point (h), of the Constitution and cannot define punishable acts. Paragraph (2) provides that the Authority exercises control through staff holding a security clearance, pursuant to Law No 182/2002, and lays down the judicial guarantee: the challenging of decisions concerning classified information is made under the conditions laid down by Law No 182/2002 and by the Code of Civil Procedure.

Chapter V – Absolute limits. Clauses of humanity (Articles 24 to 30)

Chapter V contains the prohibitions which the Law enshrines as rules of public policy, incapable of derogation by authorisation, contract or consent. The name “clauses of humanity” is taken from international humanitarian law (the Martens clause of the Hague Conventions of 1899 and 1907, according to which, in cases not provided for, persons remain under the protection of the “principles of humanity and the dictates of the public conscience”) and expresses the idea that, faced with a technology whose consequences cannot be foreseen, the law must fix a few limits which do not depend on risk assessments, on thresholds or on authorisations.

→ the text of the Article Article 24 enshrines human control over lethal force. Paragraph (1) prohibits a decision on the use of lethal force against a human being from being taken or executed by an artificial intelligence system without the intervention of an identified natural person, “for each individual decision”, who has the information, the time and the means necessary to assess it and to prevent it — not merely the formal presence of a human being. The formulation takes up the standard of “meaningful human control” negotiated within the framework of the United Nations Convention on Certain Conventional Weapons and the position expressed by the Secretary-General of the United Nations and by the International Committee of the Red Cross (the joint appeal of 5 October 2023) for the conclusion by 2026 of a binding legal instrument on autonomous weapons systems; Resolution 78/241 of the United Nations General Assembly of 22 December 2023 was adopted with the votes of 152 States, including Romania. The second sentence requires the recording of the decision and of the person who approved it, so that liability may be individualised, and defines the field of the rule negatively: it does not concern the automatic interception of projectiles and of unmanned devices, which are not directed at human beings, nor training simulations, and coordination with international humanitarian law is ensured through special legislation. The delimitation is not an exception which would deprive the rule of content, but prevents the application of the same formula to different situations. Decision-support systems, in which the decision remains human, likewise do not fall within the scope of the rule. Paragraph (2) refers, for the definition of the lethal autonomous weapons system, to Article 3(1), point (x), and not to the preceding paragraph, which does not contain a definition, but the rule on human intervention for each decision. Paragraph (2) commits the Romanian State not to develop, not to procure and not to authorise such systems and to support their international prohibition.

→ the text of the Article Article 25 prohibits legal personality and the patrimonial autonomy of artificial intelligence systems. Paragraph (1) expressly excludes the possibility of systems acquiring legal personality or being parties to legal relationships and attributes any legal act concluded by means of them to the person on whose behalf they acted. The provision is necessary because the Resolution of the European Parliament of 16 February 2017 (2015/2103(INL)) proposed exploring a status of “electronic person” for autonomous robots, a proposal subsequently rejected, and Romanian legislation contains no express rule; Article 25 of the Civil Code enumerates the subjects of law (the natural person and the legal person), but does not exclude the creation by law of other categories. Paragraph (2), in its first sentence, prohibits conferring upon a system the capacity to hold in its own name money, digital assets, financial instruments, property, accounts or cryptographic keys; that prohibition is the patrimonial corollary of the critical capability of “autonomous acquisition of resources” in Article 5(2), point (c): a system which is able to pay for its own compute infrastructure can no longer be stopped by cutting off its funding. So that the prohibition does not cover automatic payments, compute allocations and ordinary professional operations carried out within limits set by a responsible human being, the second sentence adopts the solution of a delimited mandate: the administration of, or the disposal of, such resources or of compute resources by means of a system is permitted only within the limits of a mandate established in advance by a responsible person, determined by object, duration, ceiling and conditions for shutdown; the autonomous extension of the mandate is prohibited, and an operation exceeding it is attributable to the principal and requires the system to be shut down. The definition of autonomous action in Article 3(2), point (d), refers to that same mandate, and Article 42(1) criminalises only the infringement of the first sentence and of paragraph (3), so that the constituent elements of the criminal offence are laid down by the Law (Article 23(12) and Article 73(3), point (h), of the Constitution). Paragraph (3) prohibits the establishment of legal persons or trusts effectively controlled by a system, in order to close off the route of evasion by the interposition of a legal entity, and defines effective control as real decision-making power over the acts of the entity, the use of the system for analysis or recommendations not constituting control.

→ the text of the Article Article 26 establishes the prohibition of making participation in social life conditional upon the decisions of artificial intelligence systems and upon the acceptance of digital means. The provision responds to a danger distinct from that of the loss of technical control, but equally serious for the freedom of the citizen: that of a society in which access to rights, to essential services and to economic and civic life becomes a conditional service, granted or withdrawn automatically, according to whether or not the person complies. The warning was publicly formulated, in memorable terms, by the Australian Senator Alex Antic, in a parliamentary speech widely disseminated in 2026: in a country once free, the citizen owned the things he paid for and did not live his life on subscription; “the digital prison is closing in, not just in Australia, but globally”, and once it is complete, “your freedom will depend on compliance with big government and big tech, who will control the off switch of your participation in society”. Artificial intelligence is the element which makes such an architecture possible on a large scale, since it alone is able to supervise, evaluate and decide upon millions of persons simultaneously, without human intervention; that is why the prohibition has its place in the chapter on the clauses of humanity.

Paragraph (1) prohibits public authorities and institutions, as well as providers of essential services of general interest, from making conditional, restricting or suspending a person's access to fundamental rights and freedoms, to public and essential services or to participation in economic, social and civic life “solely on the basis of” a decision, evaluation or classification produced by an artificial intelligence system; the provision does not prohibit the use of systems as an instrument of assistance, but the replacement of the human decision. Paragraphs (2) to (6) construct, in three stages, the safeguards for the person. The first stage is administrative: the right to have the decision reviewed, within 15 days, by an identified natural person, who bears responsibility for the final decision and gives reasons for it in writing (paragraph (2)), which prevents the “review” from being turned into a second automated procedure; the mechanical confirmation of the score, without an effective examination of the person's situation, does not constitute review, and for health services or the interruption of an essential service, where 15 days may cause irreparable harm, the person obtains, on request, within not more than 48 hours, the provisional maintenance of access pending the outcome of the review. The second stage concerns access to the service, and not the challenging of the decision: paragraph (3) requires the maintenance of a means of obtaining the service or of exercising the right which does not depend on an artificial intelligence system, that is to say through a person, at the premises, at a counter or by another accessible means, so that a citizen who cannot or does not wish to pass through the automated system is not excluded; and paragraph (4), the core of the rule, prohibits making access conditional upon the acceptance of a digital means of identification, of a digital means of payment or of a system for evaluating compliance, with a compulsory alternative. The Law does not prohibit digital identity, digital payment or automated evaluation as such; it prohibits their becoming a compulsory condition of participation in society. The alternative does not remove the legal obligations of identification or of payment security, which are fulfilled by other means (paragraph (4), second sentence). The third stage is judicial, in accordance with Article 21 of the Constitution: paragraph (5) gives the person the right to challenge the decision maintained after review, the refusal of review and the refusal of the means of access or of the alternative before the tribunal of his domicile or residence, within 30 days, with exemption from stamp duty, without prior procedure, with an urgent hearing under the contentious procedure of the Code of Civil Procedure, and with the possibility of suspension of the decision, irrespective of whether the author of the decision is a public authority or a private provider; silence on the request for review is equivalent to the upholding of the decision; paragraph (6) provides for an appeal to the court of appeal, within 15 days, whose judgment is final. The jurisdiction of the tribunal of the person's domicile, rather than of the court of the author's seat, is a rule protecting the weaker party, known in consumer law (Article 18 of Regulation (EU) No 1215/2012) and in labour disputes; the unification of the procedure for authorities and private providers, with an appeal instead of a second appeal on points of law, requires an express derogation from Article 7 (the prior procedure), Article 10 (jurisdiction) and Article 20 (the second appeal on points of law) of Law No 554/2004 on administrative court proceedings, formulated in accordance with Article 63 of Law No 24/2000, and is justified by the identity of subject matter of the dispute, irrespective of the status of the author of the decision (a derogation from Article 10 alone would have left the prior complaint and the second appeal on points of law applicable). Paragraph (7) defines essential services of general interest by an exhaustive enumeration (energy, gas, water, communications, financial and payment services, health, public transport, education), for the sake of the precision required by Law No 24/2000. Paragraph (8) coordinates the rule with Article 5(1), point (c), of the AI Regulation, which prohibits “social scoring” systems, and with Article 22 of Regulation (EU) 2016/679, which confers on the person the right not to be subject to a decision based solely on the automated processing of his data; the two European rules protect the person in delimited situations (the evaluation of social behaviour with disproportionate treatment, and the processing of personal data, respectively), whereas Article 26 establishes an objective prohibition, of public policy, as regards access to rights and services, without duplicating them. The provision continues, in the field of artificial intelligence, the protection of the citizen against digital platforms and against technological intrusions enshrined by the Sovereignty Law, and is founded on Article 1(3), Article 16 and Article 53 of the Constitution: the exercise of rights may be restricted only by law, proportionately and without affecting the existence of the right, conditions which an automated decision, without human responsibility, cannot fulfil.

→ the text of the Article Article 27 enshrines the prohibition of censorship exercised by means of artificial intelligence systems. Paragraph (1) proceeds from Article 30(2) of the Constitution (“Censorship of any kind is prohibited”) and makes it explicit for automated means: a constitutional prohibition addressed, historically, to the human censor cannot be circumvented by entrusting the same function to a system which decides what citizens may say and what they may learn. The rule does not create a new right, but prevents an existing one from being deprived of substance, which places it in the category of rules guaranteeing fundamental rights, which do not form part of the field harmonised by the AI Regulation, that Regulation governing the obligations of the operators of systems, and not the content of persons' rights. The second sentence, which in the initial drafting absolutely prohibited any use of a system to restrict expression, has been correlated with paragraphs (2) to (6): the prohibition concerns restriction outside the cases laid down by law and without the safeguards of the article, so that content prohibited by law can still be identified and removed, in compliance with the conditions as to statement of reasons and review. The rule protects persons situated on the territory of Romania, and not only Romanian citizens, in terminological unity with paragraph (2) and with Article 26 (Article 37 of Law No 24/2000). Paragraph (2) defines the material element of the prohibition, in the technical terms of the practice of automated moderation: the impeding, removal, blocking, concealment, restriction of the visibility of and labelling as false of an expression, as well as the penalising of the person for that expression, where they are ordered solely by the system and concern an expression which the law does not prohibit. The formula “solely on the basis of a decision… produced by the system” is the same as that in Article 26(1) and as that in Article 22 of Regulation (EU) 2016/679, and the condition “where the expression is not prohibited by law” leaves intact the limits of freedom of expression laid down in Article 30(6) and (7) of the Constitution and in the criminal law. Paragraph (3) prohibits public authorities and institutions from using, commissioning, financing or requesting, directly or through third parties, artificial intelligence systems for the individualised monitoring of persons on the basis of their public expression or for the classification, flagging or restriction of their expression; the exception is limited to the cases expressly laid down by law, in connection with criminal acts and with the prior authorisation of a judge, that is to say to the regime of technical surveillance measures in the Code of Criminal Procedure. The statistical or non-individualised processing of public information does not constitute monitoring. The rule responds to a practice documented in several States, in which the authorities have requested platforms, through informal channels, to restrict lawful content automatically. Paragraph (4) establishes the transparency of the measure: communication forthwith, in writing, with the reasons, the legal basis and a statement that it was taken by means of an automated system, and prohibits the undeclared restriction of visibility (“shadow banning”), the practice by which a person's expression is concealed from others without that person's knowledge. Paragraph (5) ensures human review within 15 days and refers to the remedy laid down in Article 26(5) and (6): the tribunal of the person's domicile, with an appeal to the court of appeal. Paragraph (6) governs the relationship with Regulation (EU) 2022/2065 on digital services, which, pursuant to recital 9 thereof, harmonises in full the obligations of providers of intermediary services and expressly regulates contractual terms and conditions (Article 14), the statement of reasons for moderation decisions (Article 17) and the internal handling of complaints (Article 20), without prohibiting any automated initial decision; for platforms, the lawfulness of content is not equivalent to an obligation to host it. For that reason, for providers of intermediary services, the article applies to the extent compatible with the Regulation, whose provisions remain applicable, does not impede measures against unsolicited messages, automated accounts or information-security risks, nor filters chosen by the user, and may not restrict any safeguard laid down by the Regulation for the recipients of the services. The formulation resolves in favour of Union law the tension which a bare “without prejudice” clause would have left open, the national safeguard remaining full as against public authorities and operators which are not providers of intermediary services. Infringement of the article is an administrative offence (Article 37(1), point (d)), and by the effect of Article 30 any clause to the contrary is null and void by operation of law.

→ the text of the Article Article 28 guarantees human intervention, by prohibiting the placing or the maintenance in operation of frontier systems in conditions which render impossible, technically or organisationally, the intervention laid down in Article 14, including by distributing the system across uncontrolled infrastructures, by deleting the shutdown capacity or by a degree of autonomy which excludes supervision. While Article 14 lays down the positive obligations of the operator, Article 28 lays down the corresponding absolute prohibition, subject to criminal penalty (Article 42), and covers the situations in which intervention becomes impossible not through the action of the system, but through the operator's choice of architecture (for example, systems distributed across decentralised networks with no control point). The second sentence, added because Article 42(1) refers directly to the prohibition, delimits the act: the use of infrastructure belonging to a third party does not, by itself, constitute a lack of control, if the contractual rights and the technical means allow the operator to exercise the shutdown capacity in a verifiable manner, and the temporary unavailability of a means of intervention, remedied forthwith and recorded in the logs, does not constitute impossibility. The predictability of the criminal rule (Article 23(12) of the Constitution) depends on that distinction between a passing malfunction and a structural relinquishment of control.

→ the text of the Article Article 29 prohibits unconstrained recursive self-improvement: the design, training or operation of a system in such a way that it improves its own capabilities or creates more capable successor systems without each iteration being subject to human evaluation and approval, an element contained in the definition in Article 3(2), point (h). The “intelligence explosion” scenario (I. J. Good, 1965), in which a system capable of designing systems better than itself triggers a growth in capabilities beyond all control, is regarded by a significant part of the scientific community, including by Hinton, as the most probable route to an irreversible loss of control. The second sentence subjects to the evaluation and authorisation under Chapter III every iteration by which a frontier system contributes, through a substantial modification within the meaning of Article 3(1), point (aa), to the creation or the refinement of a successor system; the threshold of substantial modification excludes minor code corrections and experiments without effect on risk, which the initial drafting (“contributes”) would have covered. Research programmes in which frontier systems are used as an instrument may be authorised as a whole, with compulsory stopping points established pursuant to Article 8 and with human approval of each stage which produces a new model or a substantial modification. The article does not prohibit research in the field, nor the use of systems to design other systems, but only the elimination of the “human in the loop” between iterations; it is reinforced by the prohibition of training in Article 15(1), point (e), and by the critical capability in Article 5(2), point (e), without overlapping with them: Article 5 qualifies, Article 15 prohibits training, Article 29 prohibits operation.

→ the text of the Article Article 30 declares, in paragraph (1), the provisions of the chapter to be rules of public policy and penalises with absolute nullity any act to the contrary, specifying that the prohibitions may not be removed by consent, commercial secrecy, national security or economic interest. The provision applies Article 11 of the Civil Code (“it is not possible to derogate by agreements or unilateral legal acts from laws which concern public policy or good morals”) and Articles 1246 to 1250 on absolute nullity, and serves to block the foreseeable arguments in favour of an exception: that the user consented, that the system is secret or that economic or strategic interest so requires. The express mention of national security is necessary in order to prevent the interpretation that Article 23 would permit the Supreme Council of National Defence to remove those limits, and the final sentence states this directly: the adaptations laid down in Article 23 do not constitute derogations from the safeguards of the chapter. Paragraph (2) specifies the extent of the nullity, pursuant to Article 1255 of the Civil Code: the nullity concerns only the clause to the contrary, the other clauses remaining valid if they can subsist without it, and the rights acquired in good faith by third parties who did not participate in the infringement are protected. The final sentence recognises that this classification cannot, by itself, remove the primacy of directly applicable Union law, enshrined by Article 148(2) of the Constitution.

Chapter VI – The Artificial Intelligence Safety Authority (Articles 31 to 34)

→ the text of the Article Article 31 establishes the Artificial Intelligence Safety Authority as a specialised structure, without legal personality, within the National Authority for Management and Regulation in Communications (ANCOM). The choice of organisation within ANCOM, rather than of a new autonomous administrative authority, has three grounds. The first is institutional: ANCOM is already the authority proposed by the Government, through the memorandum on the implementation of the AI Regulation, as market surveillance authority and single point of contact in the field of artificial intelligence, so that a parallel authority would have created precisely the institutional parallelism prohibited by Article 16 of Law No 24/2000 and would have obliged developers to undergo two procedures before two authorities for the same system. The second is statutory: ANCOM is an autonomous administrative authority under parliamentary control, pursuant to Government Emergency Ordinance No 22/2009, financed entirely from its own revenue and expressly exempted, by Article 2(2) of Framework Law No 153/2017, from the unitary system of remuneration of staff paid from public funds, which makes it possible to remunerate specialists competitively without any new derogation. The third is operational: ANCOM has the territorial infrastructure, the technical staff and the institutional relationship with the providers of electronic communications networks and services necessary for the execution of the blocking measures laid down in Article 39. Paragraph (2) governs the management: a vice-president of ANCOM with the rank of Secretary of State, with exclusive responsibilities in the field of artificial intelligence safety, appointed by Parliament in joint sitting for a non-renewable term of 6 years, from among persons with recognised training and experience in artificial intelligence, information security or technology law. Since Government Emergency Ordinance No 22/2009 fixes the number of vice-presidents of ANCOM, the Law establishes the office by express derogation from Article 11(1) thereof, in accordance with Article 63 of Law No 24/2000, while retaining the appointment procedure and the duration of the term of office laid down for the other vice-presidents, for the sake of unity of regime. The long, non-renewable term of office, out of step with the 4-year electoral cycle, is the classic guarantee of independence. Paragraph (2) also governs the vacancy of the office (appointment within 60 days; an interim term of not more than 6 months, ensured by a vice-president of ANCOM designated by its president), so that a parliamentary deadlock does not leave the Authority without leadership, and so that the interim arrangement does not become a lasting leadership without a parliamentary mandate. Paragraph (3) takes up the prohibition on holding offices, shareholdings or remuneration from developers or operators, during the term of office and for 3 years thereafter, which responds to the risk of “regulatory capture” (the “revolving door”), particularly acute in a field in which remuneration in the private sector is ten times higher than in the public sector. So that the prohibition targets the real conflict, the text restricts it to direct shareholdings, excludes holdings through diversified investment funds without decision-making power, and grants, for the post-term restriction, a compensatory allowance established by the implementing rules, without which the restriction would be disproportionate (Article 41 of the Constitution). The grounds for removal are enumerated exhaustively, in accordance with the requirement of precision of Law No 24/2000. Paragraph (4) ensures the functional independence of the Authority within ANCOM: the decisions laid down by the Law are issued by the vice-president for artificial intelligence safety, on behalf of ANCOM, he being answerable for them before Parliament, and the Authority may not receive instructions from any other public authority, a formula taken from Article 52 of Regulation (EU) 2016/679 for data protection authorities and from Article 70(1) of the AI Regulation. Paragraph (5) designates the Authority as national liaison point with the AI Office and with the scientific panel provided for in Article 68 of the AI Regulation, and delimits the competences, in place of the earlier formulation, which suggested a hierarchy between authorities: the national authorities designated pursuant to the Regulation retain their competences, the Authority exercises exclusively the responsibilities under this Law as regards frontier systems, and informs the AI Office of decisions concerning general-purpose models.

→ the text of the Article Article 32 enumerates, in paragraph (1), the responsibilities of the Authority, in accordance with the five functions necessary to a regime of authorisation: authorisation (point (a)), inspection (point (b)), emergency intervention (point (c)), technical standard-setting (point (d)) and the imposition of penalties (point (e)), to which are added the supervision of evaluation bodies (point (f)), the receipt and determination of complaints of persons concerning the infringement of the clauses of humanity in Articles 26 and 27 (point (g)), annual reporting to Parliament (point (h)), international representation (point (i)) and research (point (j)). The responsibility in point (g) gives the citizen a simple, free administrative remedy against the making of access conditional and against automated censorship, without depriving him of the right to apply directly to the courts. The public annual report on the state of risk, due by 31 March, which also covers the complaints concerning Articles 26 and 27, is the instrument by which Parliament and the public are able to follow the evolution of capabilities and the adequacy of the Law; it follows the model of the annual reports of the National Commission for Nuclear Activities Control and of the National Supervisory Authority for Personal Data Processing. The research responsibility (point (j)) is necessary because the evaluation, interpretability and alignment of systems are scientific fields in formation, in which an authority which merely applies the standards of others remains permanently behind; its results are subject to external evaluation and to the rules on conflicts of interest. Paragraphs (2) to (4) add three safeguards. Paragraph (2) separates, within the Authority, the functions of evaluation, of investigation and of the sanctioning decision into distinct structures, and prohibits the person who has evaluated or investigated from participating in the sanctioning decision (Article 21(3) of the Constitution); evaluation bodies are designated on public criteria, with rules of recusal and of conflict of interest, and may not evaluate systems of persons with whom they have economic relations. Paragraph (3) governs inspection, which concerns professional premises, not any premises: a written order of the vice-president, stating the object and the purpose of the inspection, a written record, access to premises serving as a dwelling only with the authorisation of a judge (Article 27 of the Constitution), and the protection of secrets protected by law and of the procedural rights of persons. Paragraph (4) responds to the objection of the legality of the incrimination: since Articles 40 to 42 link penalties to classifications built on the critical capabilities, the Authority's standards detail the methods of evaluation only within the limits of the categories and criteria established by the Law and may not introduce new categories of prohibited capabilities, nor extend the constituent elements of the administrative or criminal offences; correspondingly, point (d) no longer speaks of the “list of critical capabilities”, which remains in the Law (Article 5(2)), but of the methods of evaluation and the levels of significance. That solution is required by Article 23(12) and Article 73(3), point (h), of the Constitution: an administrative act cannot determine, even indirectly, the point from which an act becomes a criminal offence.

→ the text of the Article Article 33 governs staff and financing. Paragraphs (1) and (2) answer the question on which the whole Law depends: who will evaluate frontier systems. The specialist staff are appointed exclusively by competition, open to any person satisfying the conditions as to education and experience, announced at least 30 days in advance, with the results open to challenge before the administrative court. The competition board, of at least 5 members, includes at least 3 university professors in the field of information technology and telecommunications or specialists with recognised practical experience in the security and evaluation of artificial intelligence systems, proposed by the accredited universities which organise doctoral studies in those fields. The majority presence of external members on the board has a twofold role: it guarantees that selection is made on verifiable competence, and not on administrative or political criteria, and it removes recruitment from the influence of the industry, since the members of the board are subject to the same incompatibilities as the staff of the Authority. The publication of the composition of the board and of the results ensures public scrutiny. The model is that of the competitions for teaching and research posts (Higher Education Law No 199/2023) and of the competition boards in the judiciary, in which the participation of external members with professional authority is the guarantee of objectivity. Paragraph (3) provides for remuneration at a level competitive with the private sector, in accordance with ANCOM's own salary system, established annually on the basis of a published market study; since ANCOM's staff are exempted from Framework Law No 153/2017 by Article 2(2) thereof, no derogation is necessary, which constitutes one of the reasons for the choice of organisation within ANCOM. Without competitive remuneration, the institution would be unable to recruit any specialist capable of evaluating a frontier system. Paragraph (4) extends the incompatibilities to the whole of the staff, with a period of 2 years. Paragraph (5) governs financing on a basis which excludes any financial incentive for imposing penalties: the earlier version allocated the Authority a share of 50% of the fines, for the purpose of a research fund, but the resources of the body imposing the fines would then have depended on them. The Authority is now financed from a distinct allocation from ANCOM's budget, approved annually and shown separately, and from notification, evaluation and authorisation fees, established by the implementing rules in relation to the cost of the service (on the model of the fees charged by the National Agency for Medicines and by the National Commission for Nuclear Activities Control); the fines accrue to the State budget and may not determine the resources of the Authority, and the research referred to in Article 32(1), point (j), is financed through a distinct allocation, unconnected with the penalties. ANCOM provides the initial budget, including staff and infrastructure, before the collection of fees.

→ the text of the Article Article 34 establishes the consultative Scientific Council, composed of 9 recognised researchers, of whom at least 3 from abroad, which gives its opinion on the evaluation standards, on the methods of evaluation and the levels of significance of the critical capabilities and on proposals for the adjustment of the thresholds, and publishes separate opinions (paragraph (1)). The presence of foreign members is necessary because the leading expertise in the field is concentrated in a few centres in the world, and the right to a public separate opinion is the guarantee that a consultative opinion cannot be ignored in silence. Paragraphs (2) and (3) supplement the status of the Council: the members are appointed by the vice-president for artificial intelligence safety, on a proposal from the Romanian Academy and from the universities which organise doctoral studies in the field, for a term of 4 years, renewable once, are subject to the incompatibilities laid down in Article 31(3), may be removed only for an established incompatibility or unjustified non-participation, and opinions are adopted by a majority of the members. The opinion is consultative, but the Authority gives reasons when it departs from it; the access of members, including foreign members, to protected information is subject to the conditions laid down by law, and separate opinions are published in versions which protect sensitive information and preserve the scientific argument. The model is that of the scientific panel of the AI Office (Article 68 of the AI Regulation) and of the scientific councils of the European regulatory agencies.

Chapter VII – Liability (Articles 35 to 45)

→ the text of the Article Article 35 establishes the joint and several liability, irrespective of fault, of the developer and the operator for damage caused by a frontier system, including by autonomous actions of the system, by its use by third parties or by the exfiltration of the weights. The basis is Article 1376 of the Civil Code (liability for damage caused by things, independent of any fault), to which the Law expressly refers, thus avoiding parallelism; the Law does not create a new form of liability, but specifies the application of liability for things to a category of “things” whose autonomy renders uncertain the notion of “legal keeping”. The specific model is Law No 703/2001 on civil liability for nuclear damage, which channels liability exclusively onto the operator of the installation, irrespective of fault, with compulsory insurance and with limited grounds of exemption; the same model is used by the Paris Convention of 1960 and by the Vienna Convention of 1963 on civil liability for nuclear damage. Paragraph (1) specifies, following the legal analysis, the rules of evidence: the victim proves the damage and the causal link, but the informational asymmetry is corrected: the court may order access to the logs and to the relevant documentation, with the protection of confidential information, and where the developer or the operator does not produce the logs which it was under an obligation to preserve pursuant to Article 16, the causal link is presumed until proof to the contrary. The presumption follows the logic of the disclosure of evidence and of the presumptions in Directive (EU) 2024/2853. Paragraph (1) also clarifies the right of recourse (in proportion to each party's contribution) and provides that a person who has substantially modified the system is liable as a developer for the damage caused by the modification.

Paragraph (2) restricts the grounds of exemption to the exclusive act of the victim and to force majeure external to the system and expressly excludes from the notion of force majeure the unforeseeable behaviour of the system, an error of evaluation, the act of a third party who obtained access and the absence of scientific knowledge at the date of placing into operation. That last exclusion removes the “development risk defence”, allowed by Article 7(e) of Directive 85/374/EEC and maintained, with the possibility of derogation by the Member States, in Directive (EU) 2024/2853, but which would be incompatible with the premiss of the Law: if the developer invokes the fact that it could not have known of the risk, it confirms precisely the uncertainty which justifies the authorisation regime and must be liable for having placed the system into operation in that state of uncertainty. Paragraph (3) declares null and void clauses limiting liability towards victims; clauses as between professionals are valid only in their relations with each other (including as regards recourse) and for their own pecuniary damage, and may not affect the rights of victims or the cover under Article 36. Paragraph (4) lays down limitation periods of 10 years from knowledge and of 30 years from the act, identical to those in Law No 703/2001 and justified by the latent character of certain damage; for a continuing act, the period runs from its cessation. Paragraph (5) has been rewritten for compatibility with the harmonised regime of liability for defective products (Law No 240/2004 and the forthcoming transposition of Directive (EU) 2024/2853, which leaves untouched actions founded on grounds other than defectiveness): the article establishes a distinct ground, founded on the risk created by the development and operation of the system, does not amend the harmonised regime, does not exclude the victim's action under that regime, and prohibits double compensation. For damage falling within the field of the Directive, the exclusion of the defence founded on the state of knowledge is a permitted derogation, for which the Government complies with the formalities laid down in Article 18.

→ the text of the Article Article 36 requires compulsory civil liability insurance or an equivalent financial guarantee, with minimum thresholds of 100 million euro for category I systems and 1 billion euro for category II systems, and the victim's direct right of action against the insurer or the issuer of the guarantee. The model is Law No 703/2001 (compulsory insurance or financial guarantee of the nuclear operator) and Law No 132/2017 on compulsory motor civil liability insurance (the direct action of the injured person against the insurer). The amounts are calibrated according to the financial capacity of frontier developers (valued at hundreds of billions of dollars) and according to the scale of the possible damage; category III systems do not appear, because they may not be placed into operation. A requirement impossible to satisfy on the market would, however, operate as an indirect prohibition. Paragraph (1) provides that the sums are per event, with an aggregate annual ceiling of at least twice those sums, and that, once the cover is exhausted, it is reconstituted within 30 days. The market-unavailability clause: if the Authority, after consulting the Financial Supervisory Authority, finds by public report that cover cannot be obtained on the terms of the Law, the Government may establish, by the implementing rules, lower levels, which may not fall below one fifth of the sums, and alternative mechanisms – group guarantees, bank guarantees or a guarantee fund financed by developers and operators; the one-fifth threshold and the condition of a public report exclude a discretionary reduction. Paragraph (2) defines the financial guarantee: a bank guarantee letter, deposit or guarantee issued by an authorised financial institution, enforceable at the request of the victim on the basis of a final court judgment or of a settlement, with a direct right of action also against the issuer. The insurance obligation also has a function of indirect regulation: insurers will impose, through their underwriting conditions, safety standards which the Law cannot set out in detail.

→ the text of the Article Article 37 lays down the administrative offences, structured in degrees of gravity, with fines expressed as percentages of worldwide turnover (1-3%, 2-5%, 3-7%, 5-10%), on the model of Article 99 of the AI Regulation (up to 7%) and of Article 83 of the GDPR (up to 4%). Point (b) refers to Article 16(1) to (5), and not only to paragraphs (2) to (5): in the earlier form, the most serious conduct in the matter of logging — that of not keeping and not preserving any log, an obligation laid down in paragraph (1) — was not covered by the reference in the text. For the same reason, the reference in point (b) has been specified as Article 14(1), (5) and (6), and, alongside the testing of the shutdown capacity, the maintaining of the shutdown capacity and the designation of the persons responsible for human supervision, laid down in Article 14(3) — an obligation which did not appear under any of the points of the paragraph — have been mentioned. The clarification does not create a new penalty for the deletion of the shutdown capacity, an act already prohibited by Article 28 and penalised, more severely, under point (d); in order to avoid a concurrence of administrative offences, point (b) expressly reserves the acts falling under Article 28. Point (d) has been supplemented with the prohibitions laid down in Article 14(2) which, although formulated as configuration prohibitions, did not appear in the enumeration of the point and remained, by an a contrario argument, without an administrative-offence penalty. Points (e) and (f) penalise the infringement of the obligations concerning the marking of generated content, the informing of the user and the compliance representative; for acts which also constitute infringements of Article 50 of the AI Regulation, point (e) provides that the fine is imposed within the limits laid down in Article 99(4) of the Regulation, expressly separating the two regimes. Paragraph (2) differentiates the fixed fines according to the category of person, out of the requirement of proportionality: for legal persons without turnover, 100,000 to 10,000,000 lei; for natural persons, 10,000 to 1,000,000 lei; and for the acts under points (e) and (f) committed by persons who are not developers or operators of a frontier system, 20,000 to 1,000,000 lei for legal persons and 5,000 to 200,000 lei for natural persons. Paragraph (3) lays down the complementary penalties, imposed in proportion to the seriousness of the act, including the confiscation of the weights, a specific penalty without which the fine would be merely a transaction cost; confiscated weights are kept by the Authority under the conditions laid down in Article 12. Paragraph (4) refers to the general regime of Government Ordinance No 2/2001, with two derogations formulated in accordance with Article 63 of Law No 24/2000: the exclusion of the possibility of paying half of the minimum fine (Article 28 of the Ordinance), incompatible with percentage-based fines, and a limitation period of 5 years instead of that of 6 months (Article 13(1) of the Ordinance), justified by the complexity of establishing the offence. Paragraph (5), new, contains the rules of individualisation and of coordination: the criteria of individualisation (the seriousness and extent of the act, the danger created, effective control over the act, cooperation and remediation), the basis of calculation (turnover in the preceding financial year, at group level), the prohibition of double punishment for the same act under the Law and under the Regulation (ne bis in idem), and the regime for public authorities and institutions, to which the fine is applied against the natural person responsible, within the limits laid down in paragraph (2). The administrative offences under this Law do not overlap with those under the AI Regulation: the fines laid down in Article 101 of the Regulation are imposed exclusively by the Commission, for the infringement of the obligations under the Regulation, whereas the present administrative offences penalise obligations under the Law which have no counterpart in the Regulation.

→ the text of the Article Article 38 opens a new section, “Cessation of the supply of services and blocking of access”, which responds to a practical limit of the whole regime: most operators of frontier systems have no seat, assets or staff in Romania, so that percentage-based fines and the criminal liability of decision-makers may remain without effect upon them. The only real lever of the Romanian State in relation to such an operator is access to the users on its territory. Paragraph (1) grades the non-compliance, since a remediable formal shortcoming cannot attract the same consequence as a serious risk: formal notice, with a remediation period of at least 15 days and the right to be heard; a reasoned decision establishing the non-compliance only if the non-compliance persists or consists in a serious risk which cannot be remedied within that period; the obligation to cease supply within 15 days of communication; in the event of imminent danger to life, health or human control, no remediation period is granted, the urgency being stated as a reason. The obligation to cease supply is not a penalty, but the natural consequence of the fact that the service does not satisfy the legal conditions of supply, on the model of the withdrawal from the market of non-compliant products (Article 16 of Regulation (EU) 2019/1020 on market surveillance). Paragraph (2) provides for the publication of the decision in the List of non-compliant operators, an instrument of transparency with a twofold role: informing users and communications providers, and giving publicity to the non-compliance, which discourages the integration, promotion and payment of the service by professionals on the Romanian market; the model is the public list of unauthorised gambling operators kept by the National Gambling Office pursuant to Government Emergency Ordinance No 77/2009. Paragraph (3) penalises the continuation of supply with a fine of from 100,000 to 10,000,000 euro, in the equivalent in lei, for each month of continuation, fractions of a month being counted proportionally, determined according to the duration, the number of persons affected and the seriousness, with a ceiling of 5% of annual worldwide turnover for the same non-compliance, distinct from the penalty for the initial infringement – criteria which ensure proportionality. The periodic character of the fine is taken from the institution of periodic penalty payments laid down in Article 24 of Regulation (EC) No 1/2003 and in Article 76 of Regulation (EU) 2022/2065 on digital services, and is the only one which ensures effectiveness in relation to an operator with revenue in the billions. The amount is expressed in euro, with payment in lei at the exchange rate of the day, a technique allowed by Law No 24/2000 and used in financial legislation. Paragraph (4) requires the Authority to decide on removal from the list within 10 days of proof of compliance and to communicate it forthwith to the providers executing the blocking, and the refusal or delay of removal may be challenged pursuant to Article 39(5). Paragraph (5) extends the regime to a developer which offers direct access, in order to prevent evasion through the absence of a separate operator.

→ the text of the Article Article 39 governs the blocking of access, as a provisional administrative measure, subsidiary to the obligation to cease supply. Paragraph (1) makes it conditional upon a reasoned decision of the Authority and subjects it to the test of necessity and proportionality required by Article 53 of the Constitution: blocking may be ordered only if less restrictive measures have not led to compliance or are manifestly insufficient in relation to the seriousness of the risk; the decision examines the necessity and proportionality of the measure, avoids affecting other services hosted on the same infrastructure and is re-examined of the Authority's own motion every 90 days, and users are informed, by means of a redirection page, of the reason for the measure and of the means of challenge. Paragraph (2) puts it into execution through the providers of electronic communications networks and services, within 48 hours, with the technical support of ANCOM, following the mechanism already operating in Romanian law for unauthorised gambling websites (Government Emergency Ordinance No 77/2009) and for illegal content (Law No 365/2002, Regulation (EU) 2022/2065). Paragraph (3) ensures proportionality: the blocking concerns exclusively the non-compliant service, not the whole of the operator's activity, and ceases by operation of law upon removal from the list. Paragraph (4) is necessary for compatibility with Union law: for services supplied from another Member State, Article 3(4) to (6) of Directive 2000/31/EC on electronic commerce, transposed by Law No 365/2002, permits the restriction of the free movement of information society services only by an individual measure, against a determined service, on grounds of public policy, public security or the protection of public health, proportionate, following a request addressed to the Member State of origin and with notification of the European Commission; according to the judgment of the Court of Justice in Case C-376/22, Google Ireland and Others (9 November 2023), Member States may not adopt, pursuant to Article 3(4), general and abstract measures. The text therefore expressly provides for the individual character of the measure, the determined service, the substantive basis (public policy, public security, public health) and the procedure laid down by Law No 365/2002; the blocking remains a case-by-case measure, subsequent to a concrete infringement, not a general obligation. Paragraph (5) guarantees access to justice (Articles 21 and 52 of the Constitution): a challenge within 30 days before the Bucharest Court of Appeal, Administrative and Tax Litigation Division, heard as a matter of urgency and with priority; the challenge does not suspend enforcement by operation of law, a solution justified by the preventive nature of the measure and identical to that in Article 14(4), but the person concerned may apply for provisional suspension, determined within no more than 10 days, with a weighing of the risk to safety against the damage caused, and the judgment is subject to appeal on points of law before the High Court of Cassation and Justice within 15 days. Paragraph (6) exempts communications providers from liability for the correct execution, in good faith, of the decision, on the model of Articles 12 to 15 of Directive 2000/31/EC (Articles 11 et seq. of Law No 365/2002), but not for excessive blocking caused by their own fault.

→ the text of the Article Article 40 criminalises the unauthorised placing into operation and the continuation of operation after a shutdown order, with imprisonment of from 2 to 7 years (paragraph (1)), and of from 5 to 12 years in the aggravated form (paragraph (2)). The criminalisation follows the model of Article 44 et seq. of Law No 111/1996 (the conduct of nuclear activities without authorisation, punishable by imprisonment). The penalty limits are those of the offences of serious danger in the Criminal Code (for example, Article 345 – non-compliance with the regime of nuclear materials, 3 to 10 years). Two clarifications are required by the principle of legality of criminalisation (Article 23(12) and Article 73(3), point (h), of the Constitution). The first delimits the active subject: the use, as an end user, of a system made available by another does not constitute a criminal offence (Articles 3 and 43). The second specifies the aggravating result: the mere “manifestation of a critical capability” could have included the result of a controlled test; the text requires the manifestation, outside a controlled evaluation, of one of the capabilities laid down in Article 5(2), points (c) to (e), or the production of one of the results laid down in points (a) or (b), and the result is attributed under the conditions laid down in Article 16(4) of the Criminal Code (praeterintentional liability). The Law does not amend the Criminal Code, but establishes criminal offences in a special law, in accordance with Article 1(1) of Law No 24/2000 and with the settled practice of special legislation (Law No 111/1996, Law No 535/2004 on the prevention and combating of terrorism). Paragraph (2) uses the notion of an evaluation authorised in an isolated environment, pursuant to Article 15(2), the same notion as that in Article 3(1), point (n), Article 15(3) and Article 20(2) and (4); the phrase “controlled evaluation”, used previously only in that place, has been removed, since a term with no counterpart in the rest of the Law, in a rule aggravating the penalty, would have contravened the requirement of foreseeability of the criminal law, pursuant to Article 23(12) of the Constitution.

→ the text of the Article Article 41 criminalises falsity in evaluation and the obstruction of control. The knowing presentation to the Authority or to an evaluation body of data, results or statements which are false or misleadingly incomplete concerning essential elements of the capabilities, the compute volume, the security of the weights or the incidents, as well as the configuring of the system for the purpose of misleading the evaluators as to the configuration evaluated or the real capabilities (paragraph (1), 3 to 10 years), is the offence specific to the regime: a system of authorisation based on the evidence supplied by the applicant cannot function if the falsification of that evidence is merely an administrative offence. The model is, in comparative law, section 1001 of Title 18 of the United States Code, which punishes with up to 5 years false statements made to the federal authorities. The second limb responds to the “Dieselgate” precedent of 2015, in which vehicles detected test conditions and modified their behaviour, and to the critical capability laid down in Article 5(2), point (d). The requirements of “knowing”, “essential elements” and “for the purpose of misleading” distinguish deliberate falsification from an uncertain estimate and from a good-faith error, and paragraph (4) expressly excludes an uncertain estimate declared as such, an error corrected as soon as it became known, and the configuring of the system within a test agreed with the evaluator. The obstruction of access and the destruction of logs (paragraph (2), 1 to 5 years) follow the model of Article 275 of the Criminal Code (the misappropriation or destruction of evidence or documents), but “impeding, in any manner” is referred to access exercised within the limits of the Authority's competence and on the basis of a written request, and a refusal based on the Authority's lack of competence or on the professional secrecy of lawyers or on another secret protected by law does not constitute a criminal offence, the court ruling upon it. Retaliation against whistleblowers (paragraph (3), 6 months to 3 years or a fine) is defined by precise reference to the measures laid down in Law No 361/2022 and is conditional upon a connection with a report protected pursuant to Article 21; Law No 361/2022 penalises retaliation only as an administrative offence, which is insufficient for a field in which the stake in an employee's silence may be billions of euro.

→ the text of the Article Article 42 criminalises the development of prohibited systems. Paragraph (1) penalises the intentional training, design or operation of a system under the conditions prohibited by Article 15(1), Article 25(2), first sentence, and (3), Article 28, first sentence, or Article 29, first sentence (3 to 10 years); the references have been made precise at the level of paragraph and of sentence, so that the criminalising provision covers only the prohibitions properly so called, in accordance with the requirement of foreseeability of the criminal law. Paragraph (2) penalises the disclosure, transmission or making available, without right, of the weights of a category II or category III system (5 to 15 years), an act whose gravity lies between the disclosure of State secret information (Article 303 of the Criminal Code) and treason by the transmission of State secret information (Article 395 of the Criminal Code, 10 to 20 years); so that the element “without right” does not depend on a subsequent interpretative defence, the text expressly provides that the transfers permitted pursuant to Article 12(2) and the communications protected pursuant to Article 21(5) do not constitute a criminal offence. Paragraph (3) grades the results, in place of the former single range: the penalty of 10 to 20 years, corresponding to offences against life, is reserved for death, serious bodily injury or the loss of human control which rendered human intervention impossible and was followed by autonomous actions with consequences for persons, the environment or critical infrastructure; particularly serious pecuniary damage and a temporary loss of control are punishable by 7 to 15 years; the results are attributed under the conditions laid down in Article 16(4) of the Criminal Code. The requirement of intention in paragraph (1) distinguishes the criminal offence from the administrative offence laid down in Article 37(1), point (d), which penalises the same infringements committed without intention.

→ the text of the Article Article 43 enshrines the user's safeguard. In its initial form, the draft criminalised accessing, by circumventing the blocking measure, a service entered in the List of non-compliant operators – the only act in the whole draft which could be committed by a user. The initiator abandoned it and replaced it with a safeguard of the opposite sense: the Law is constructed out of obligations imposed upon those who exercise power over the person and out of rights conferred upon that person (Articles 17, 18, 26 and 27); the effectiveness of Articles 38 and 39 does not depend on penalising the user, their purpose being the removal of the non-compliant service from the lawful commercial circuit; and the comparison with Government Emergency Ordinance No 77/2009 is inapposite, since there a conduct with a potential for harm to oneself is penalised, whereas here the user accesses a service which the operator, not the user, has refused to bring into compliance. Paragraph (1) provides that the accessing by a natural person, for personal purposes, of a service entered in the List, including by circumventing the blocking, does not constitute a criminal offence or an administrative offence and may not entail any penalty or restrictive measure for the non-compliance of the service, liability resting exclusively with the operator and the developer; the text specifies that the exclusivity of liability concerns the non-compliance of the service and that the safeguard does not remove liability for separate acts, laid down by law, committed through the use of the service. Paragraph (2) establishes the rule of interpretation according to which Articles 38 and 39 may not be read as the source of any obligation upon users or of any condition upon their rights. Paragraph (3), new, extends the safeguard to the professional end user who is not an operator and does not make the service available to other persons. The provision is correlated with Article 26(1) and (4) and with Article 27. The safeguard concerns personal accessing, not the whole Law: the same person may also be a developer, an operator or a publisher of generated material, in which case Articles 17 to 19 and 37 become applicable to that person. Since blocking may begin before the entry into force of the criminal section, the second sentence of Article 50 provides that Article 43 enters into force together with the Law.

→ the text of the Article Article 44 governs the liability of persons holding decision-making functions. Paragraph (1) specifies that the offences are attributed to the natural persons who ordered or approved the commission of the acts, as well as to those who, having the legal obligation and the effective possibility of preventing them, knowingly tolerated their commission, with the individual determination of the form of guilt in accordance with the Criminal Code, irrespective of their status and independently of the liability of the legal person, incurred pursuant to Article 135 of the Criminal Code; the text does not create a new form of participation, but removes the defence of the diffusion of responsibility in complex corporate structures. The earlier formula could have included employees who knew but could not intervene; the text aligns the case of toleration with the conditions of liability for omission laid down in Article 17 of the Criminal Code (a legal or contractual obligation to act), with guilt determined individually. Paragraph (2) excludes the ground of exemption from punishment consisting in an order of a superior or of the management body, on the model of Article 33 of the Rome Statute and of Article 21(2) of the Criminal Code, which does not recognise a manifestly unlawful order as a justifying cause, but expressly retains the justifying causes and the causes of non-imputability under the Criminal Code. The Law contains no rule of its own on the territorial application of the criminal law, since Article 8(4) of the Criminal Code (an offence is deemed to have been committed on the territory of Romania also where the result was produced, even in part, on that territory) and Articles 9 to 11 of the Criminal Code (the principles of personality, reality and universality) are sufficient, and a referring provision would constitute a parallelism prohibited by Article 16 of Law No 24/2000.

→ the text of the Article Article 45 lays down jurisdiction and interim measures. The criminal prosecution of the offences laid down in Articles 40 to 42 falls obligatorily to a prosecutor within the Directorate for Investigating Organised Crime and Terrorism (paragraph (1)), a structure which already has jurisdiction over computer-related and terrorism offences (Article 11 of Government Emergency Ordinance No 78/2016), and the trial at first instance falls to the tribunal, in accordance with the general rule laid down in Article 36(1), point (c), of the Code of Criminal Procedure for offences placed by law within its jurisdiction; the earlier reference to Article 44 has been removed, since that article does not define an autonomous offence, but the persons liable. Paragraph (2) permits the prosecutor, in case of urgency, to order, by reasoned order, as an interim measure of no more than 30 days, the shutdown of the system, the sealing of the infrastructure and the freezing of the weights, subject to confirmation by the judge for rights and freedoms within 48 hours, on pain of the measure ceasing by operation of law, on the model of the protective measures laid down in Article 249 et seq. of the Code of Criminal Procedure and of the computer search laid down in Article 168. The measure is accompanied by additional safeguards: limitation to the computing workload and to the weights concerned where their isolation is sufficient, the preservation of data and the safeguarding of the weights under the conditions laid down in Article 12, challenge by the person concerned and by affected third parties, re-examination every 30 days and extension under the same conditions. Rapid judicial confirmation and these limits ensure compliance with Articles 21 and 53 of the Constitution. Paragraph (3) supplements Article 11(1) of Government Emergency Ordinance No 78/2016 with the offences laid down in Articles 40 to 42, since the jurisdiction of the Directorate for Investigating Organised Crime and Terrorism is established by its own act of organisation, which must be expressly correlated, in accordance with Law No 24/2000. The exact structure of Article 11(1) of the Ordinance must be verified against the consolidated text before submission.

Chapter VIII – International cooperation. Transitional and final provisions (Articles 46 to 50)

→ the text of the Article Article 46 lays down the Government's obligations of external action: the promotion within the European Union of an equivalent regime of prior authorisation and of a common European evaluation capacity (paragraph (1)); the negotiation, within the United Nations, the Council of Europe, NATO and other organisations, of a treaty on the limitation and verification of frontier computing capabilities, the prohibition of lethal autonomous weapons and the prohibition of category III systems, with annual reporting to Parliament (paragraph (2)); and the conclusion of agreements on the mutual recognition of evaluations (paragraph (3)). Paragraphs (1) and (2) establish obligations to initiate and report on steps taken, not obligations of result. Paragraph (3) specifies that the Authority's agreements are concluded within the limits of its competence, are published and may not derogate from the Law or from European Union law. The article openly recognises, in accordance with the principle laid down in Article 2(g), that national law cannot alone resolve a global problem; it nevertheless turns that finding into an obligation to act, and not into a reason for inaction. The historical model is the Nuclear Non-Proliferation Treaty of 1968, which functioned through the control of fissile materials and through the inspections of the International Atomic Energy Agency; the equivalent for artificial intelligence is the control and verification of compute, proposed in the specialised literature under the name of “compute governance” and supported by Hinton, Bengio and numerous researchers in the public appeals of 2023 to 2025.

→ the text of the Article Article 47 establishes the review clause at 2 years, on the basis of the Authority's report and the opinion of the Scientific Council. A periodic review clause is required by Article 7 of Law No 24/2000 (preliminary impact assessment) and by the pace of technological development. The report assesses, on the basis of a published methodology, the effectiveness of the protection, the incidents, the costs, access to services, the undesired effects and the proportionality of each measure, may propose the narrowing of a measure found to be ineffective even where the general risk persists, and includes divergent scientific opinions. The final sentence, however, closes off a route of evasion: the argument that “we cannot control the systems anyway, so regulation is pointless”, which would turn uncertainty into permission; the absence of a validated method of control may not be invoked, on its own, as a ground for relaxation, but neither does it replace the reassessment of proportionality. The Law replies that uncertainty is the reason for regulation, not for abandoning it.

→ the text of the Article Article 48 contains the transitional provisions, in accordance with Article 54 of Law No 24/2000, and arranges the compliance periods in two stages, so that no obligation becomes enforceable before the instrument by which it can be fulfilled exists. The first stage runs from the entry into force of the Law: within 60 days, the developers and operators notify the Authority of the systems in operation on the territory of Romania or made available to persons in Romania (paragraph (2)); within 90 days they comply with the provisions of the Law which do not depend on the implementing rules (paragraph (1)) and fulfil the obligations of perceptible marking, of information of users and of designation of the compliance representative (paragraph (4)), and the provisions on the cessation of supply and on blocking (Articles 38 and 39) apply only after the expiry of that period (paragraph (3)), which guarantees foreseeability for operators and complies with Article 15(2) of the Constitution. The second stage runs from the entry into force of the implementing rules laid down in Article 49(2): within 90 days of that date, the application for authorisation, the procedure for which is laid down by the rules, is submitted (paragraph (2)), the embedded technical marking is carried out (paragraph (4)), and, in general, all the obligations whose fulfilment depends on the standards, procedures, thresholds or amounts laid down by the rules become enforceable, the corresponding administrative offences not being capable of being established until then (paragraph (5)). Paragraph (5) specifies at the same time that the prohibitions of the Law, the obligations concerning the shutdown capacity, logging and the reporting of serious incidents, and the other obligations which may be fulfilled without the rules, apply from the entry into force of the Law; the transitional regime therefore postpones nothing of what directly protects human control. Notified systems may be maintained in operation pending the decision of the Authority, but for no more than 12 months from the entry into force of the Law, subject to compliance with the prohibitions and the directly applicable guarantees laid down in Chapters IV and V (not the whole of Chapter IV, which also contains obligations dependent on the rules); this avoids both a vacuum of application and the abrupt interruption of services used by millions of persons, while fixing an absolute limit of tolerance. That limit is extended by operation of law by the length of time by which the adoption of the rules or the determination of the application exceeds the periods laid down by law, a diligent applicant not being liable to penalty for the delay of the institutions, and the Authority being able to order, stating reasons, additional safety conditions for the duration of the extension. The period of 90 days is the one customary in Romanian legislation for compliance with new authorisation requirements and is sufficient, since frontier developers already have the internal evaluations required by the AI Regulation. Paragraph (6) entrusts to the President of ANCOM, pending the appointment of the vice-president for artificial intelligence safety, the exercise of the Authority's responsibilities, including the urgent measures laid down in Article 32(1), point (c); the earlier formula limited the interim role to the receipt of notifications. Paragraph (3) also contains a coordination without which the transitional regime would have been contradictory: the maintaining in operation of a notified system, for the duration for which paragraph (2) permits it and during the determination of an application submitted within the period, does not constitute the criminal offence laid down in Article 40(1). In the absence of that clarification, the same conduct would have been, between the 270th day from publication – the date of entry into force of the criminal provisions – and the completion of the 12 months from the entry into force of the Law, at the same time permitted by the transitional provision and criminalised by the criminal provision. The exclusion is strictly delimited: it does not cover the placing into operation of a system that has not been notified, the maintaining in operation after the rejection of the application, after the expiry of the period laid down in paragraph (2), or after the communication of a shutdown order. Paragraph (4) has, in turn, been broken down by the components of the provenance marking: the obligation laid down in Article 17(4), borne by public authorities, concerns the marking defined in paragraph (1), composed both of the perceptible marking and of the embedded technical marking, so that each component follows its own period, and the public authority is not required to apply a marking whose standard has not yet been adopted.

→ the text of the Article Article 49 lays down the measures of organisation and the implementing rules, with periods calculated from the date of publication of the Law, so that a single calendar results and so that the institution and the evaluation rules are available before the operators' own deadlines. Paragraph (1) provides for the appointment by Parliament of the vice-president for artificial intelligence safety and the supplementing of ANCOM's organisational structure and rules of organisation and functioning with the Authority, by decision of the President of ANCOM published in the Official Gazette, within 60 days of publication. Paragraph (2) provides for the adoption of the implementing rules within 120 days of publication, on a proposal from the Authority, with the opinion of the Scientific Council and following a public consultation of at least 30 days, with a precise enumeration of their subject matter (procedures, standards, the conditions of the isolated environment, the provenance marking, the methods of evaluation and the levels of significance of the critical capabilities, the infrastructure threshold, the fees established in relation to the cost of the service, and the amount of the insurance or of the guarantee). The delegation to the Government is limited to technical and procedural aspects, in accordance with the case-law of the Constitutional Court according to which the essential elements of a regulation must be laid down by law (for example, Decision No 51/2016); the text says so expressly: the rules detail the framework established by the Law, may not establish the essential content of the obligations, prohibitions and penalties, and the standards are published. The list of critical capabilities no longer figures among the subject matter of the rules, since it remains in the Law (Article 5(2)), correlated with Article 32(4). Paragraph (3), new, establishes the intermediate regime: pending the adoption of the rules, evaluations are carried out in accordance with the standards laid down in the codes of practice adopted under the AI Regulation and with scientifically recognised methods, and the Authority publishes provisional guidance. The enumeration of the subject matter of the rules has been supplemented with the level laid down in Article 16(5), with the testing procedure and the duration laid down in Article 14(1) and (6), with the minimum requirements of isolation laid down in Article 3(1), point (bb), and with the amount of the compensatory allowance laid down in Article 31(3), so that each element left by another article of the Law to the implementing rules also appears in the article which establishes the delegation.

→ the text of the Article Article 50 lays down the entry into force 30 days after publication, in accordance with Article 78 of the Constitution and Article 12 of Law No 24/2000, with the exception of Articles 40 to 42, 44 and 45, which enter into force 270 days after publication, and with the specification that Article 43 enters into force together with the Law. The period for the criminal section is expressed in days from publication, not in calendar months, and has been extended from 6 months to 270 days, so that the criminalising provisions become active only after the implementing rules (120 days) and after the period of adaptation of the obligations dependent on them (210 days): a criminalising provision linked to authorisation presupposes an available authorisation procedure, and its activation before the rules would be contrary to the foreseeability of the criminal law (Article 7 of the European Convention on Human Rights, Article 23(12) of the Constitution). The final formula attesting adoption, laid down in Articles 40 and 46 of Law No 24/2000, indicates compliance with Article 75 and Article 76(1) of the Constitution, the Law being an organic law since it regulates criminal offences and penalties (Article 73(3), point (h)) and amends, by way of derogation, the organisation of an autonomous administrative authority established by an organic law (Article 117(3)).

The single calendar resulting from Articles 48 to 50, calculated from the date of publication of the Law (P), is as follows: P+30 days – entry into force, including the user's safeguard (Article 43), the prohibitions and the directly applicable obligations; P+60 days – appointment of the vice-president and organisation of the Authority (Article 49(1)); P+90 days – notification of the systems in operation (Article 48(2)); P+120 days – adoption of the implementing rules (Article 49(2)) and enforceability of the obligations independent of the rules (Article 48(1) and (4)), from which moment Articles 38 and 39 also become applicable; P+210 days – if the rules are adopted on time, enforceability of the obligations dependent on the rules, the embedded technical marking and the applications for authorisation (Article 48(2), (4) and (5)); P+270 days – entry into force of the criminal section (Articles 40 to 42, 44 and 45); the tolerance for notified systems expires 12 months after entry into force, extended by operation of law by the delay of the institutions (Article 48(2)).

3. Compliance with the rules of legislative technique (Law No 24/2000)

The draft has been drawn up in strict compliance with Law No 24/2000, as republished, as follows. The statement of grounds and the preliminary impact assessment (Articles 6, 7 and 30 to 31) are contained in this explanatory memorandum, with an analysis of the present situation, of comparative models and of the effects. Integration into the legislative system (Article 13) is ensured by the express reference to the AI Regulation (Article 1(3) of the Law) and by the referring provisions to related acts. The avoidance of parallelisms (Article 16) has been the subject of a separate analysis, presented in point 3 of Section 5: no existing regulation is reproduced, but is taken over by reference, and derogations are expressly formulated with the formula “by way of derogation from”, in accordance with Article 63. Terminological unity (Article 37) is ensured by the definitions in Article 3, which take over by reference the notions established by Union law and autonomously define, with justification, the new notions (“frontier system”, “weights”, “operator”, “placing into operation”), avoiding the terms having a different meaning in the AI Regulation (“operator”, “provider”, “putting into service”). The normative style (Articles 36 and 38) is dispositive, in the present tense, without explanations in brackets and without unestablished neologisms; all the technical terms used in the enacting terms (“weights”, “architecture”, “training”, “fine-tuning”, “reinforcement learning”, “exfiltration”, “autonomous replication”, “recursive self-improvement”, “concealment of capabilities”, “evasion of supervision”, “resistance to shutdown”, “external tool”, “authorised operating environment” and the others) are defined in Article 3, structured in two paragraphs – object-notions and, respectively, operations and conduct – so that each enumeration remains within the limits of the letters of the alphabet and so that the material element of the prohibitions and of the criminal offences has a precise normative content. The constituent parts (Articles 40 to 46) are: the title, the preamble (permitted by Article 43 in order to set out the grounds in summary form, on the model of laws of particular importance), the introductory formula, the enacting terms and the formula attesting the legality of adoption. The structure of the enacting terms (Articles 47 to 56) respects the order general provisions – substantive provisions – transitional provisions – final provisions, with chapters numbered in Roman numerals and sections in Arabic numerals; the articles are numbered continuously, the paragraphs with Arabic numerals in brackets, the enumerations with letters, and no enumeration marked by a letter contains a further enumeration (Article 49(3)); the articles do not bear marginal headings, since Article 47(3) reserves those for codes and laws of great length. The referring provisions (Article 50) indicate the complete identifying elements of the acts referred to, and the delegations to the Government (Article 49) are limited to procedural and technical aspects, the final sentence of Article 49(2) of the Law expressly prohibiting the implementing rules from establishing the essential content of the obligations, prohibitions and penalties. The Law contains a single express intervention in the text of another legislative act – the supplementing of Article 11(1) of Government Emergency Ordinance No 78/2016, effected by Article 45(3) –, drafted in accordance with Articles 59 to 62 (the complete identification of the act, with its dates of publication and approval, and the formula of supplementing); the specific derogations are permitted by Article 63 and do not affect the text of the acts derogated from. Following the independent legal analysis of 20 September 2026, the draft was revised in order to: (i) delimit its field from the AI Regulation (Article 1(4), Article 9(7), Article 17(6), Article 19(1) and Article 27(6)); (ii) retain in the Law all the constituent elements of the administrative offences and criminal offences, with a prohibition on their extension by standards (Article 32(4)); (iii) synchronise the procedures, the standards and the periods through a single calendar calculated from the date of publication (Articles 48 to 50); (iv) add procedural safeguards against the Authority (Article 9(4), Article 11(2), Article 14(4), Article 32(2) and (3), Article 39(1) and (5), Article 45(2)). The working copy of the draft bears the notation “DRAFT”; the formula attesting the legality of adoption, set out at the end of the text, is the one customary for a bill and does not represent an adoption which has already taken place.

Section 3 – Socio-economic impact of the draft legislative act

1. Macroeconomic impactLimited and indirect. The authorisation regime concerns a very small number of economic operators (the developers of systems exceeding 10^25 floating-point operations – at present, fewer than twenty worldwide, none having its seat in Romania – and the providers of high-capacity compute infrastructure). Systems below the threshold and applications developed on the basis of existing models are not subject to authorisation. In the medium term, the existence of a clear framework and of a competent authority constitutes an advantage of location for investments in data centres, through predictability, and reduces the systemic macroeconomic risk associated with a major incident.
1¹. Impact on the competitive environment and the field of State aidNeutral. The obligations apply without discrimination to all developers and operators falling within the scope of the Law, irrespective of nationality, and the simplified recognition procedure (Article 9(7)) ensures compatibility with the free movement of services. No State aid is established. The financing of research in artificial intelligence safety (Article 32(1), point (j)) from the distinct budgetary allocation laid down in Article 33(5), unrelated to the penalties applied, is carried out in compliance with Regulation (EU) No 651/2014 (block exemptions for research and development).
2. Impact on the business environmentFor small and medium-sized undertakings: no direct impact (Article 4(2)); they nevertheless remain beneficiaries of frontier services and may be indirectly affected by any cessation of supply or blocking of a non-compliant service (Articles 38 to 39), which is why the Law provides for the compliance period of 90 days and for maintenance in operation pending the decision of the Authority (Article 48). For compute infrastructure providers: obligations of registration, of knowing their clients and of reporting, comparable to those in anti-money-laundering legislation, with low administrative costs. For frontier developers: the costs of independent evaluation and of compulsory insurance, proportionate to the value of the investments (of the order of hundreds of millions of euro for a single training cycle) and to the scale of the risk.
3. Social impactPositive. The Law protects the life, health, freedom and dignity of the person against a category of risks not covered by the legislation in force, establishes the protection of whistleblowers in the laboratories and guarantees the compensation of damage through liability irrespective of fault and compulsory insurance. The clauses of humanity (Chapter V) protect democratic processes and human control over lethal decisions.
4. Impact on the environmentIndirectly positive. The notification and the records of high-capacity compute infrastructure (Article 7(3) and Article 22), with significant energy consumption, permit correlation with energy and environmental policies.
5. Other informationThe Law contributes to the fulfilment of the obligations assumed by Romania under the Framework Convention of the Council of Europe on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No 225) and under Resolution 78/241 of the United Nations General Assembly on lethal autonomous weapons systems.

Section 4 – Financial impact on the general consolidated budget, both in the short term, for the current year, and in the long term (5 years)

The financial impact consists in the expenditure on the organisation and functioning of the Artificial Intelligence Safety Authority, within ANCOM, estimated for a complement of some 80 posts, of which at least 50 technical specialists recruited by competition and remunerated at market level, and in the expenditure on the compute infrastructure necessary for the evaluations. Organisation within ANCOM, an authority financed entirely from its own revenue, reduces the costs of establishment (premises, support functions, information systems) and does not burden the State budget. Pursuant to Article 33(5), the Authority is financed from ANCOM's budget, through a separate allocation, approved annually and shown separately, and from the notification, evaluation and authorisation fees, established by the implementing rules in relation to the cost of the service provided; the initial budget, including staff and infrastructure, is provided by ANCOM before the collection of the fees. Fines imposed pursuant to the Law constitute revenue to the State budget and may not determine the resources of the Authority, and the research laid down in Article 32(1), point (j), is financed through a separate budgetary allocation, unrelated to the penalties; revenue from fines cannot be estimated ex ante and is not taken into account below. The estimates, expressed in millions of lei, are indicative and are to be finalised by the Ministry of Finance at the approval stage.

IndicatorsCurrent year (2027)20282029203020315-year average
1. Changes in budgetary revenue, plus/minus, of which:+5+10+15+20+20+14
a) State budget, of which: notification, evaluation and authorisation fees, established in relation to the cost of the service (ANCOM's own revenue, allocated to the Authority); fines constitute revenue to the State budget (Article 33(5)), not estimable ex ante and not included+5+10+15+20+20+14
b) local budgets––––––
c) State social insurance budget––––––
2. Changes in budgetary expenditure, plus/minus, of which:+45+85+90+95+100+83
a) State budget, of which: (i) staff expenditure+20+40+42+45+48+39
(ii) goods and services (including compute infrastructure for evaluations)+20+40+43+45+47+39
(iii) capital expenditure+5+5+5+5+5+5
b) local budgets––––––
c) State social insurance budget––––––
3. Financial impact, plus/minus (millions of lei)–40–75–75–75–80–69
4. Proposals for covering the increase in budgetary expenditureThe expenditure is covered from ANCOM's budget, through the separate allocation laid down in Article 33(5) – including the initial budget provided by ANCOM before the collection of the fees –, and from the fees established in relation to the cost of the service; fines, which constitute revenue to the State budget, do not constitute a source of financing for the Authority. It is proposed, in addition, to redirect part of the funds allocated to the National Strategy in the field of artificial intelligence 2024-2027 and from the Operational Programme Smart Growth, Digitalisation and Financial Instruments 2021-2027 (policy objective 1 – a smarter Europe).
5. Proposals to compensate for the reduction in budgetary revenueNot applicable; the draft does not reduce budgetary revenue.
6. Detailed calculations concerning the basis of the changes in budgetary revenue and/or expenditureStaff expenditure: 80 posts, with an estimated average gross cost of 40,000 lei/month for technical staff (50 posts) and 15,000 lei/month for the remainder, under a derogating salary regime. Goods and services: the hiring of computing capacity for evaluations (estimated at 25 million lei/year), contracts with independent evaluation bodies, international travel. Revenue: notification, evaluation and authorisation fees estimated at 1 to 3 million lei per system, for 5 to 10 systems per year, capped by Article 33(5) at the cost of the service provided; revenue from fines accrues to the State budget, depends on the number and seriousness of the infringements established and cannot be estimated ex ante, and has accordingly not been included.
7. Other informationThe values are expressed in millions of lei. The cost of a single major incident avoided (for example, an autonomous cyberattack on energy infrastructure) exceeds by several orders of magnitude the annual cost of the Authority.

Section 5 – Effects of this legislative act on the legislation in force

a) legislative acts in force which will be amended or repealed as a result of the entry into force of the draft legislative act

The draft does not repeal any legislative act and expressly amends, by way of a supplement, a single legislative act (Article 45(3)). For the rest, through the technique of the referring provision and of the express derogation, it produces the following effects on the legislation in force:

Government Emergency Ordinance No 78/2016 on the organisation and functioning of the Directorate for Investigating Organised Crime and Terrorism, and amending and supplementing certain legislative acts, approved with amendments by Law No 120/2018 – express supplementing (Article 45(3) of the Law): a new point is inserted in Article 11(1), whereby the offences laid down in Articles 40 to 42 of the Law are placed within the jurisdiction of the Directorate for Investigating Organised Crime and Terrorism; 1 act supplemented in its text. The exact structure of Article 11(1) (the numbering of the points and the up-to-date consolidated form) is to be verified against the consolidated text before submission, and the supplementing formula will be adapted accordingly.

Government Emergency Ordinance No 27/2003 on the tacit approval procedure – express derogation (Article 9(4) of the Law): the absence of a reply from the Authority is not equivalent to tacit authorisation; 1 derogation.

Government Emergency Ordinance No 22/2009 on the establishment of the National Authority for Management and Regulation in Communications, approved by Law No 113/2010 – express derogation (Article 31(2) of the Law) from Article 11(1): an additional vice-president, for artificial intelligence safety, appointed by Parliament on the same conditions; 1 derogation. Framework Law No 153/2017 is not affected, ANCOM's staff being exempted from its application by Article 2(2) thereof.

Law No 554/2004 on administrative court proceedings – express derogation (Article 26(6) of the Law) from Article 7 (the prior procedure), Article 10 (subject-matter and territorial jurisdiction) and Article 20 (the remedy): challenges against decisions of public authorities and institutions laid down in Article 26 and, by reference, in Article 18(3) and Article 27(5), are not subject to the prior procedure, are heard by the tribunal of the person's domicile, with an appeal to the court of appeal; 1 derogation (from three provisions).

Government Ordinance No 2/2001 on the legal regime of administrative offences – express derogations (Article 37(4) of the Law) from Article 28 (payment of half of the minimum fine) and from Article 13(1) (the limitation period for the imposition of the penalty); 2 derogations.

Law No 361/2022 on the protection of whistleblowers in the public interest – supplementing of the scope of application by a referring provision (Article 21 of the Law), without amendment of its text; the protection regime is extended to reports concerning safety risks and the concealment of capabilities.

Regulation (EU) 2016/679 (Article 22) and Law No 190/2018 – referring provisions (Article 26(8) of the Law), without amendment.

Regulation (EU) 2022/2065 on digital services – coordinating provision (Article 27(6) of the Law): for providers of intermediary services, Article 27 applies only in so far as compatible with the Regulation, whose provisions on contractual conditions (Article 14), the statement of reasons for decisions (Article 17) and the settlement of complaints (Article 20) remain applicable; no guarantee under the Regulation for the recipients of the services is restricted; without amendment.

Regulation (EU) 2024/1689 – coordinating provisions: Article 1(4) and Article 9(7) of the Law (the Law does not establish conditions for the placing on the market of the Union of general-purpose models and does not affect the Commission's competences laid down in Article 88 of the Regulation; for models with systemic risk whose providers comply with Chapter V of the Regulation, the Authority relies on the documentation communicated to the AI Office); Article 17(6) (for providers and deployers to whom Article 50 of the Regulation applies, the marking obligations are deemed fulfilled through compliance with Article 50(2) and (4), the Law establishing only the competent authority, the procedure for establishing infringements and the penalties, within the limits laid down in Article 99(4) of the Regulation); Article 18(5) (Article 50(1) of the Regulation and Articles 13 to 15 and 22 of Regulation (EU) 2016/679); Article 19(1) and (6) (developers and operators established in another Member State designate only a point of contact, which may be the authorised representative laid down in Article 54 of the Regulation or the legal representative laid down in Article 13 of Regulation (EU) 2022/2065; an authorised representative empowered also for Romania fulfils the obligation under the Law); without amendment of the Union acts.

Directive 2000/31/EC (Article 3) and Law No 365/2002 on electronic commerce, as republished – referring provisions (Article 4(4) and Article 39(4) of the Law): the obligations of the Law apply to services supplied from another Member State under the conditions laid down in Article 3 of the Directive, and the blocking of such a service is ordered only individually, for a determined service, with the procedure for requesting the Member State of origin and for notifying the European Commission; without amendment.

Directive (EU) 2024/2853 on liability for defective products – coordinating provision (Article 35(5) of the Law): the liability irrespective of fault established by the Law is a separate basis, which does not modify the harmonised regime of liability for products; in so far as the exclusion of force majeure for the absence of scientific knowledge falls within the scope of the Directive, the Government shall complete the formalities laid down in Article 18 of the Directive (the development-risk derogation).

Directive (EU) 2015/1535 laying down a procedure for the provision of information in the field of technical regulations and of rules on information society services, transposed by Government Decision No 1016/2004 – to be verified before submission: the provisions of Articles 17 to 19, 38 and 39 of the Law, as well as the implementing rules concerning the technical marking, are liable to constitute “regulations relating to services” within the meaning of the Directive, in which case the draft is to be notified to the European Commission at draft stage, in compliance with the standstill period; a note on European notifications accompanies the draft.

The Civil Code (Article 1376), the Criminal Code (Article 16(4), Article 135), the Code of Criminal Procedure (Articles 36, 168, 249), the Code of Civil Procedure (contentious proceedings, Article 23(2) and Article 26(5) of the Law), Law No 182/2002, Government Emergency Ordinance No 155/2024, Law No 240/2004 – referring provisions, without amendment.

In summary: 0 acts repealed, 1 act supplemented in its text (Government Emergency Ordinance No 78/2016), 5 express derogations (from 7 provisions), 2 supplementings of scope by referring provision (Law No 361/2022, Law No 365/2002), provisions coordinating with Union law in Article 1(4), Article 9(7), Article 17(6), Article 18(5), Article 19(1) and (6), Article 27(6) and Article 35(5); 1 European notification to be verified (Directive (EU) 2015/1535). The correlations with the consolidated forms of the national acts cited (the Codes, Laws No 182/2002, 365/2002, 554/2004 and 361/2022, Government Ordinance No 2/2001, Government Emergency Ordinances No 22/2009, 78/2016 and 155/2024) are to be verified against the consolidated texts before submission.

b) legislative acts to be drawn up following the implementation of the new provisions

A resolution of Parliament for the appointment of the vice-president of ANCOM for artificial intelligence safety, and a decision of the President of ANCOM, published in the Official Gazette, for the supplementing of the organisational structure and of the rules of organisation and functioning with the Authority, including the organisation of separate structures for evaluation, investigation and sanctioning decision (Article 32(2)); deadline: 60 days from the publication of the Law (Article 49(1)).

A Government decision approving the implementing rules for the application of the Law, adopted on a proposal from the Authority, with the opinion of the Scientific Council and following a public consultation of at least 30 days; deadline: 120 days from the publication of the Law (Article 49(2)). Subject matter: the notification and authorisation procedure; the simplified procedure for the recognition of systems lawfully placed into operation in another Member State (Article 9(7)); the standards of evaluation, of security of the weights and of shutdown capacity; the conditions of the isolated environment (Article 15(2)); the standards of the provenance marking (Article 17); the methods of evaluation and the levels of significance of the critical capabilities, within the limits laid down in Article 5(2), without being able to add other categories of results; the threshold for high-capacity compute infrastructure (Article 6(4)); the amount of the fees, established in relation to the cost of the service; the amount of the insurance or of the financial guarantee (Article 36); the procedure for the vetting of staff with access to the weights, with the opinion of ORNISS (Article 12(1)); the procedure for testing shutdown capacity (Article 14(1)); the level from which the loss of intelligibility of the logs is established (Article 16(5)); the compensatory allowance of the vice-president (Article 31(3)). The rules detail the framework of the Law and may not establish the essential content of the obligations, prohibitions and penalties; the standards are published.

Provisional guidance of the Authority, published pending the adoption of the implementing rules, evaluations being carried out during that interval in accordance with the codes of practice adopted under the AI Regulation and with scientifically recognised methods (Article 49(3)); subsequently, the standards of the Authority, approved by the Scientific Council, within the limits laid down in Article 32(4).

A decision of the President of ANCOM concerning the level of remuneration of the Authority's specialist staff, on the basis of the published market study (Article 33(3)); the notice and the rules of the competition for the specialist staff (Article 33(1) and (2)).

A resolution of the Supreme Council of National Defence concerning the adaptations applicable to systems in the field of defence and national security (Article 23).

Government decisions periodically adjusting the compute threshold, on a proposal from the Authority (Article 6(2)).

The law implementing Regulation (EU) 2024/1689, currently being drawn up by the Government, will have to be correlated with this Law as regards cooperation between the designated authorities and the Authority (Article 31(5)) and the rule according to which two penalties may not be imposed for the same act under the Law and under the Regulation (Article 37(5)).

c) Analysis of legislative parallelisms (Article 16 of Law No 24/2000)

Pursuant to Article 16(1) of Law No 24/2000, “in the process of legislating it is prohibited to establish the same rules in several articles or paragraphs of the same legislative act or in two or more legislative acts”, and for the purpose of highlighting legislative connections the referring provision is to be used. Each provision of the draft has been verified against the legislation in force, with the results summarised in the following table.

The provision of the draftLegislative act in force with a similar objectConclusion of the verification and solution adopted
Article 1(3) to (4) and Article 9(7) – the relationship with the AI Regulation and general-purpose modelsRegulation (EU) 2024/1689, Article 2, Chapter V (Articles 51 to 56 – general-purpose models), Article 88 (the Commission's exclusive competence to supervise providers of general-purpose models), Article 99Express delimitation: the Law does not establish conditions for the placing on the market of the Union of general-purpose models and does not affect the Commission's competences (Article 88); its obligations concern public safety, national security, liability, the rights of persons in non-harmonised relationships and the organisation of the authorities, and authorisation concerns the placing into operation on the territory of Romania. For models with systemic risk whose providers comply with Chapter V, the Authority relies on the documentation communicated to the AI Office and verifies only the conditions which exceed the Regulation (Article 9(7)).
Article 3, points (a), (b), (n) – definitions of the AI system, of the general-purpose model, of the serious incidentRegulation (EU) 2024/1689, Article 3, points (1), (63), (49)Potential overlap avoided: the definitions are not reproduced, but taken over by a referring provision; the serious incident is supplemented by situations not covered by the Regulation.
Article 3, points (g) to (i) – developer, operator, placing into operationRegulation (EU) 2024/1689, Article 3, points (3) (provider), (4) (deployer), (8) (operator), (11) (putting into service)Distinct notions, with a different content (material activity, not placing on the market). In order to avoid terminological confusion (Article 37 of Law No 24/2000), the Law uses its own terms, autonomously defined.
Articles 5 to 6 – the threshold of 10^25 FLOP and the critical capabilitiesRegulation (EU) 2024/1689, Article 51 and Annex XIIIThere is no parallelism: the Regulation uses the threshold for the presumption of systemic risk and for the provider's obligations of diligence; the Law uses it to trigger the national authorisation regime, in non-harmonised fields. The threshold is identical for the sake of coherence. The list of critical capabilities does not include influence over democratic processes or over public opinion, a matter which remains exclusively within the field of Article 5(1), points (a) and (b), and of Article 50 of the Regulation, of the electoral legislation and of the Criminal Code; the Law confers no competence whatsoever concerning the content of public debate.
Articles 7 to 11 – notification of training and prior authorisationRegulation (EU) 2024/1689, Article 52 (notification of the Commission), Articles 53 and 55 (obligations of providers)There is no parallelism: the Regulation contains neither a regime of prior authorisation nor the notification of training. The authorisation concerns activities carried out on the territory of Romania (training, operation) and does not make the placing on the internal market conditional (Article 1(4)); Article 9(7) ensures the recognition, through the simplified procedure established by the implementing rules, of systems lawfully placed into operation in other Member States, and Article 9(4) establishes procedural safeguards (a time limit, limited suspension, a statement of reasons for each condition, an action to compel a ruling).
Article 12 – security of the weightsRegulation (EU) 2024/1689, Article 55(1), point (d); Government Emergency Ordinance No 155/2024 (NIS 2); Law No 182/2002Specific object (the weights) and specific standard (equivalent to “top secret”), not covered by the acts mentioned. Article 12(4) expressly provides for application without prejudice to Government Emergency Ordinance No 155/2024. Law No 182/2002 is used as a referring provision for the standard, without classifying the weights.
Article 14 – human supervisionRegulation (EU) 2024/1689, Article 14 (high-risk systems)There is no parallelism: Article 14 of the Regulation applies to the high-risk systems in Annex III; the Law regulates frontier systems, with a different content (tested shutdown capacity, designated persons).
Article 15 and Chapter V – prohibitionsRegulation (EU) 2024/1689, Article 5 (prohibited practices)There is no parallelism: Article 5 of the Regulation prohibits practices of use (subliminal manipulation, social scoring, biometric identification); the Law prohibits characteristics of design and training of the system, not covered by the Regulation.
Article 17 – marking of generated contentRegulation (EU) 2024/1689, Article 50(2) and (4) and Article 99(4); Regulation (EU) 2022/2065; the Criminal Code (Article 325 – computer-related forgery, Article 244 – fraud)Partial overlap identified and resolved through Article 17(6): for providers and deployers to whom Article 50 of the Regulation applies, the marking obligations are deemed fulfilled through compliance with Article 50(2) and (4), the Law establishing only the competent authority, the procedure for establishing infringements and the penalties, within the limits laid down in Article 99(4) of the Regulation (Article 37(1), point (e), second sentence). Article 17 applies in full only to the results of systems trained or operated in Romania which are not placed on the Union market, and to the public communication of the Romanian authorities; the prohibition on the removal of the marking (paragraph (3)) is an act not covered by the Regulation. Acts committed through the use of unmarked content for fraudulent purposes remain within the sphere of the Criminal Code.
Article 18 – informing the userRegulation (EU) 2024/1689, Article 50(1); Regulation (EU) 2016/679, Articles 13 to 15 and 22; Law No 190/2018There is no parallelism: the Regulation concerns information about the interaction with the system, and the GDPR information concerning the processing of data; Article 18 governs information about the basing of a decision on the result of a system and about the person answerable for it, a matter of administrative procedure and of civil liability, which is not harmonised.
Article 19 – the compliance representativeRegulation (EU) 2024/1689, Article 54 (the authorised representative); Regulation (EU) 2016/679, Article 27; Regulation (EU) 2022/2065, Article 13; Law No 365/2002There is no parallelism: the institutions cited concern representation for the obligations under the respective acts. The representative laid down by the Law is designated only by developers and operators established outside the Union, for the national regime of authorisation, inspection, cessation of supply and blocking and for the service of documents; those established in another Member State designate only a point of contact, which may be the authorised representative laid down in Article 54 of the AI Regulation or the legal representative laid down in Article 13 of Regulation (EU) 2022/2065 (Article 19(1)), so that no obligation of establishment contrary to Article 3 of Directive 2000/31/EC is imposed; Article 19(6) avoids duplication, recognising the obligation as fulfilled where the European authorised representative is empowered also for Romania.
Article 20 – reporting of serious incidentsRegulation (EU) 2024/1689, Article 55(1), point (c), and Article 73Partial overlap identified and resolved: the second sentence of Article 20(1) provides that reporting to the Authority does not replace reporting to the AI Office and permits the transmission of the same report, supplemented; double administrative burden is thereby avoided.
Article 21 – whistleblowersLaw No 361/2022; Directive (EU) 2019/1937; Regulation (EU) 2024/1689, Article 87Overlap avoided by a referring provision to Law No 361/2022; the Law adds only the elements not covered (safety risks, reporting to Parliament/the public, the nullity of pecuniary clauses, the offence of retaliation).
Article 22 – compute infrastructure providersGovernment Emergency Ordinance No 155/2024 (data centres as essential entities); Law No 129/2019 (know your client)There is no parallelism: the obligations under the Law (records of the compute volume, the prohibition of supply above the threshold without notification) are specific and are not to be found in the acts mentioned; the obligation to know one's clients has its model, not its source, in Law No 129/2019.
Article 23 – public authorities, defence and national securityRegulation (EU) 2024/1689, Article 2(3) (exclusion); Law No 415/2002 (the Supreme Council of National Defence)A field expressly left to the Member States; there is no national regulation of AI systems in this field. The competence of the Supreme Council of National Defence is that laid down by Law No 415/2002.
Article 24 – lethal forceThere is no national regulation; Resolution 78/241 of the United Nations General AssemblyThere is no parallelism.
Article 25 – legal personality and patrimonial autonomyThe Civil Code, Article 25 (the subjects of law); Law No 129/2019 (the beneficial owner)There is no parallelism: the Civil Code contains no express rule of exclusion; the Law establishes one, in consonance with Article 25.
Article 26 – prohibition of making participation in social life conditionalRegulation (EU) 2024/1689, Article 5(1), point (c) (social scoring); Regulation (EU) 2016/679, Article 25 (automated decisions); Law No 190/2018There is no parallelism: Article 5(1), point (c), of the Regulation prohibits the evaluation of persons on the basis of social behaviour with disproportionately detrimental treatment; Article 22 of the GDPR confers an individual right concerning decisions based solely on the automated processing of personal data. Article 26 establishes an objective prohibition, of public policy, concerning the making of access to rights, essential services and social life conditional upon decisions of AI systems or upon the acceptance of digital means, with the guarantee of an alternative and with a challenge before the tribunal of the person's domicile, without the prior procedure and with an appeal to the court of appeal (express derogation from Articles 7, 10 and 20 of Law No 554/2004); paragraph (8) provides for application without prejudice to those two rules.
Article 27 – prohibition of censorship by means of AI systemsThe Constitution of Romania, Article 30(2) (prohibition of censorship); Regulation (EU) 2022/2065 (DSA), recital 9 (full harmonisation) and Articles 14, 17, 20 (contractual conditions, the statement of reasons for moderation decisions, internal complaints); the Code of Criminal Procedure (technical surveillance)There is no parallelism: Article 30 of the Constitution states the prohibition, without regulating automated means; the DSA fully harmonises the obligations of providers of intermediary services (recital 9), which the Law does not reproduce. Article 27(6) – a coordinating provision – provides that, for those providers, the article applies only in so far as compatible with the DSA, whose Articles 14, 17 and 20 remain applicable, that measures against unsolicited messages, automated accounts, security risks and filters chosen by the user are not affected, and that no guarantee under the DSA for recipients may be restricted. Article 27 establishes a prohibition of public policy addressed first and foremost to public authorities (paragraph (3)), with a right to a human decision and to a court (paragraph (5), by reference to Article 26(5) and (6)).
Articles 35 to 36 – civil liability irrespective of fault and insuranceThe Civil Code, Article 1376; Law No 240/2004 (defective products); Directive (EU) 2024/2853, Articles 2 to 3 and 18; Law No 703/2001Potential overlap with liability for products resolved by Article 35(5): a separate basis, founded on risk, which does not modify the harmonised regime of liability for products (a concurrence of bases, without double compensation); in so far as the exclusion of force majeure for the absence of scientific knowledge (paragraph (2)) falls within the scope of the Directive, the Government completes the formalities laid down in Article 18 thereof. Article 1376 of the Civil Code is applied by a referring provision (“applies mutatis mutandis”), not reproduced. Article 36 permits lower levels and alternative guarantee mechanisms where cover is not available on the market.
Article 37 – administrative offencesRegulation (EU) 2024/1689, Articles 99 and 101; Government Ordinance No 2/2001There is no parallelism: the fines under the Regulation penalise the obligations under the Regulation (imposed by the Commission for general-purpose models); the administrative offences under the Law penalise the obligations under the Law, and for acts which constitute infringements of Article 50 of the Regulation the fine is imposed within the limits laid down in Article 99(4) thereof (paragraph (1), point (e)); two penalties may not be imposed for the same act under the Law and under the Regulation (paragraph (5)). The general regime of Government Ordinance No 2/2001 is applied by reference, with two express derogations. The constituent elements remain established exclusively by law (Article 32(4)).
Articles 38 to 39 – cessation of supply and blocking of accessGovernment Emergency Ordinance No 77/2009 (blocking of unauthorised gambling websites); Directive 2000/31/EC, Article 3, and Law No 365/2002; Court of Justice of the European Union, C-376/22, Google Ireland and Others, judgment of 9 November 2023, ECLI:EU:C:2023:835; Regulation (EU) 2022/2065 (DSA), Articles 51 and 76; Regulation (EU) 2019/1020, Article 16There is no parallelism: the existing mechanisms concern other objects (gambling, illegal content, non-compliant products). For services from other Member States, Article 4(4) and Article 39(4) refer to Article 3 of Directive 2000/31/EC and to Law No 365/2002: the measure is ordered only individually, for a determined service, for an obligation necessary for the protection of public policy, public security or public health, with the procedure for requesting the State of origin and for notifying the Commission – and not as a general and abstract measure, excluded by the Court of Justice in Case C-376/22 (paragraph 27). Blocking is subsidiary, reasoned, re-examined every 90 days and subject to challenge with provisional judicial suspension (Article 39(1) and (5)). The periodic fine penalises an obligation specific to the Law (cessation of supply), without any counterpart in the AI Regulation.
Article 43 – the user's safeguard (accessing blocked services is not punishable)The Criminal Code, Article 360 (illegal access to an information system); Government Emergency Ordinance No 77/2009 (participation in unauthorised gambling – an administrative offence)There is no parallelism and no overlap: Article 43 neither criminalises nor penalises anything, but is a general safeguard which expressly excludes the liability of the user (including the professional end user, paragraph (3)) for accessing a non-compliant service and prohibits the interpretation of Articles 38 and 39 as establishing obligations upon users (paragraph (2)); it enters into force together with the Law, not with the criminal provisions (the second sentence of Article 50). Article 360 of the Criminal Code remains applicable to access without right to an information system by infringing its security measures, a distinct act, untouched by this draft.
Articles 40 to 42 and 44 – criminal offencesThe Criminal Code: Articles 303, 345, 275, 360 to 366 (computer-related offences), 135; Law No 111/1996; Law No 361/2022 (retaliation – an administrative offence)There is no parallelism: the acts criminalised (unauthorised operation, falsity in evaluation, development of prohibited systems) have no counterpart in the Criminal Code. Retaliation against whistleblowers is an administrative offence under Law No 361/2022 and becomes a criminal offence only in the field of the Law, by special provision. The rule initially envisaged concerning the territorial application of the criminal law was removed from the draft, Article 8(4) and Articles 9 to 11 of the Criminal Code being sufficient; the more serious results are attributed under the conditions laid down in Article 16(4) of the Criminal Code, and liability for failing to prevent the act (Article 44) is incurred only by the person having the legal obligation and the effective possibility of intervening, with the individual determination of guilt.
Article 45 – jurisdiction of the Directorate for Investigating Organised Crime and Terrorism and interim measuresGovernment Emergency Ordinance No 78/2016, Article 11(1); the Code of Criminal Procedure, Articles 36, 168, 249Jurisdiction is established through the express supplementing of Article 11(1) of Government Emergency Ordinance No 78/2016 (Article 45(3)), in accordance with Articles 59 to 62 of Law No 24/2000, avoiding a parallel provision; the prosecutor's interim measures (paragraph (2)) are specific (the shutdown of the system, the sealing of the infrastructure, the freezing of the weights), limited to 30 days, confirmed by the judge for rights and freedoms within 48 hours, subject to challenge and periodically re-examined, and do not reproduce the protective measures in the Code of Criminal Procedure.
Articles 31 to 34 – the AuthorityThe Government memorandum on the designation of the authorities for the AI Regulation (ANCOM, the Financial Supervisory Authority, the National Bank of Romania, the National Supervisory Authority for Personal Data Processing)There is no parallelism, but integration: the Authority is organised within ANCOM, the authority proposed by the memorandum as single point of contact; the designated authorities exercise the responsibilities under the Regulation, and the Authority those under the Law. Article 31(5) and Article 48(6) govern cooperation and the transition; Article 31(2) derogates from Government Emergency Ordinance No 22/2009 only as regards the office of vice-president; Article 32(2) to (4) separates the functions of evaluation, investigation and sanctioning decision, makes inspection conditional upon a written order and limits the standards to detailing the methods of evaluation.
1¹. Compatibility of the draft legislative act with the legislation in the field of public procurementNot applicable.
2. Conformity of the draft legislative act with Community legislation in the case of drafts transposing Community provisionsThe draft does not transpose any directives. It is compatible with Regulation (EU) 2024/1689, with Regulation (EU) 2016/679, with Directive (EU) 2019/1937 and with Directive (EU) 2024/2853, intervening exclusively in the fields left within the competence of the Member States (Article 2(3) of the AI Regulation; Article 4(2) TEU), as regards activities carried out on national territory and in criminal, civil and institutional matters; the delimitation is expressed in Article 1(4), Article 9(7), Article 17(6), Article 19(1) and Article 27(6). Article 9(7) and Article 19(1) ensure compliance with Article 56 TFEU (the freedom to provide services), and Article 4(4) and Article 39(4) ensure compliance with Article 3 of Directive 2000/31/EC. The formalities laid down in Article 18 of Directive (EU) 2024/2853 are completed by the Government (Article 35(5)). The need to notify the draft pursuant to Directive (EU) 2015/1535 (Government Decision No 1016/2004) is to be verified before submission.
3. Legislative measures necessary for the direct application of Community legislative actsThe Law creates the national framework complementary to Regulation (EU) 2024/1689 as regards frontier systems, designates the Authority as liaison point with the AI Office (Article 31(5)) and establishes the competent authority, the procedure and the penalties for infringements of Article 50 of the Regulation, within the limits laid down in Article 99(4) (Article 17(6), Article 37(1), point (e)).
4. Judgments of the Court of Justice of the European UnionJudgment of 5 May 1998, National Farmers' Union, C-157/96 (the precautionary principle); judgment of the General Court of 11 September 2002, Pfizer Animal Health, T-13/99 (protective measures in conditions of scientific uncertainty); judgment of 9 November 2023, Google Ireland and Others, C-376/22, ECLI:EU:C:2023:835, paragraphs 25 to 35 (the derogating measures laid down in Article 3(4) of Directive 2000/31/EC may be only individual, for a determined service, not general and abstract – taken into account in Article 4(4), Article 19(1) and Article 39(4)).
5. Other legislative acts and/or international documents giving rise to commitmentsThe Framework Convention of the Council of Europe on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No 225, 2024); Resolution 78/241 of the United Nations General Assembly (2023) on lethal autonomous weapons systems; the Bletchley Declaration (November 2023) and the Seoul commitments (May 2024) on the safety of frontier artificial intelligence, to which the European Union is a party.
6. Other informationNot applicable.

Section 6 – Consultations carried out with a view to drawing up the draft legislative act

1. Information concerning the process of consultation with non-governmental organisations, research institutes and other bodies involvedThe draft is to be submitted to public debate pursuant to Law No 52/2003 on decisional transparency in public administration, as republished. It is proposed to consult the Romanian Academy, the universities having faculties of computer science (the University of Bucharest, the Politehnica University of Bucharest, the Babeș-Bolyai University, the Technical University of Cluj-Napoca, the “Alexandru Ioan Cuza” University of Iași), the “Mihai Drăgănescu” Research Institute for Artificial Intelligence of the Romanian Academy, the professional associations in the field of information technology and the organisations for digital rights.
2. Basis for the choice of the organisations with which the consultation took place, as well as of the manner in which the activity of those organisations is connected with the object of the draft legislative actThe organisations proposed hold the technical expertise necessary for the assessment of the thresholds and of the critical capabilities, or represent the interests of the economic operators and of the citizens affected.
3. Consultations organised with the local public administration authorities, where the draft legislative act has as its object activities of those authorities, under the conditions laid down by Government Decision No 521/2005Not applicable.
4. Consultations carried out within the interministerial councils, in accordance with the provisions of Government Decision No 750/2005Not applicable.
5. Information concerning approval by: a) the Legislative Council; b) the Supreme Council of National Defence; c) the Economic and Social Council; d) the Competition Council; e) the Court of AccountsThe draft is submitted for approval to the Legislative Council (Article 79 of the Constitution), to the Economic and Social Council (Law No 248/2013), to the Supreme Council of National Defence (for Articles 23 to 24) and to the Superior Council of Magistracy (for the criminal and jurisdictional provisions, pursuant to Law No 305/2022 on the Superior Council of Magistracy). The views of the National Authority for Management and Regulation in Communications, of the National Supervisory Authority for Personal Data Processing and of the National Cyber Security Directorate are requested.

Section 7 – Public information activities concerning the drawing up and implementation of the draft legislative act

1. Informing civil society of the necessity of drawing up the legislative actThe initiator has informed the public of the necessity of the regulation through his communication platforms, proceeding from the public warnings of the scientific community (the CNN interview of 2 May 2023 with Geoffrey Hinton and Connor Leahy, the statement of the Center for AI Safety of 30 May 2023, the International AI Safety Report of 2025). The draft and the explanatory memorandum are published in full on the initiator's website.
2. Informing civil society of any impact on the environment following the implementation of the draft legislative act, as well as of the effects on the health and safety of citizens or on biological diversityThe draft has as its very object the protection of the life, health and safety of citizens; the impact on the environment is indirectly positive (Section 3, point 4).
3. Other informationNot applicable.

Section 8 – Implementation measures

1. Measures for the implementation of the draft legislative act by the central and/or local public administration authorities – the establishment of new bodies or the extension of the competences of existing institutionsThe Artificial Intelligence Safety Authority is established, a specialised structure within ANCOM, headed by a vice-president of ANCOM with the rank of Secretary of State appointed by Parliament (Article 31), with staff recruited by competition before a board including university professors in the field of IT and telecommunications (Article 33) and with a consultative Scientific Council (Article 34). The competences of the Directorate for Investigating Organised Crime and Terrorism (Article 45) and of the Supreme Council of National Defence (Article 23) are extended. The providers of electronic communications networks and services execute the blocking decisions (Article 39). As an internal organisational measure of ANCOM, the functions of evaluation, investigation and sanctioning decision are exercised by separate structures within the Authority, the person who carried out the evaluation or the investigation not taking part in the sanctioning decision (Article 32(2)); evaluation bodies are designated on public criteria, with rules of recusal. Pending the appointment of the vice-president, all the responsibilities of the Authority, including the urgent measures, are exercised by the President of ANCOM, who is answerable for them under the conditions laid down by the Law (Article 48(6)).
2. Other informationThe single implementation calendar, calculated from the date of publication of the Law in the Official Gazette (P): P+30 days – the entry into force of the Law, including the safeguard laid down in Article 43 (Article 50); P+60 – the appointment of the vice-president by Parliament and the supplementing of ANCOM's structure (Article 49(1)); P+90 – the notification of the systems in operation, that is, 60 days from the entry into force (Article 48(2)); P+120 – the adoption of the implementing rules, following a public consultation of 30 days (Article 49(2)), and the expiry of the 90-day period from the entry into force for the obligations which do not depend on the rules, including the perceptible marking, the information of the user and the designation of the representative (Article 48(1) and (4)), after which Articles 38 and 39 become applicable (Article 48(3)); P+210 – the submission of the applications for authorisation, the embedded technical marking and the other obligations dependent on the rules, 90 days from the entry into force of the rules, if these are adopted on time (Article 48(2), (4) and (5)); P+270 – the entry into force of Articles 40 to 42, 44 and 45 (Article 50). Notified systems may be maintained in operation pending the decision of the Authority, for no more than 12 months from the entry into force, a period extended by operation of law by the delay in the adoption of the rules or in the determination of the application, a diligent applicant not being liable to penalty for the delay of the institutions (Article 48(2)). Pending the adoption of the rules, evaluations are carried out in accordance with the codes of practice adopted under the AI Regulation, and the Authority publishes provisional guidance (Article 49(3)). The periods are the maximum ones laid down by law; their feasibility is to be verified with ANCOM at the approval stage.

In the light of the foregoing, the attached legislative proposal has been drawn up, which we submit to Parliament for debate and adoption.

Initiator,

DOCUMENTARY NOTE

The sources taken into account in drawing up the proposal

1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, OJ L, 12.7.2024 – in particular Articles 2, 3, 5, 14, 51 to 56, 68, 72 to 73, 78, 87, 99 to 101 and Annex XIII.

2a. Dario Amodei, “We Must Pace the Frontier”, 12 September 2026 (darioamodei.com); the reports of VentureBeat, TechRadar, Newsweek, The Spokesman-Review of 12 September 2026 concerning the essay, the Hugging Face incident and the reactions of Sam Altman and Elon Musk; the interview of Sam Altman for Fortune (13 September 2026), cited by Bloomberg and Business Standard.

2g. Republic of Korea – “Framework Act on the Development of Artificial Intelligence and Establishment of Trust”, in force since 22 January 2026: the obligation to label content generated by generative artificial intelligence, the obligation to inform users in advance and the obligation of foreign providers to designate a local representative for compliance; official English translation published by the Center for Security and Emerging Technology, Georgetown University, https://cset.georgetown.edu/wp-content/uploads/t0625_south_korea_ai_law_EN.pdf; analyses: Future of Privacy Forum, https://fpf.org/blog/south-koreas-new-ai-framework-act-a-balancing-act-between-innovation-and-regulation/ ; Cooley LLP, 27 January 2026, https://www.cooley.com/news/insight/2026/2026-01-27-south-koreas-ai-basic-act-overview-and-key-takeaways.

2h. Regulation (EU) 2024/1689, Article 50 (transparency obligations, applicable from 2 August 2026) and Article 54 (the authorised representative of providers of general-purpose models established in third States); the Code of Practice of the European Commission on the transparency of content generated by artificial intelligence (draft, 2026).

2f. Yoshua Bengio, interview given to The Guardian (Dan Milmo), 16 September 2026, concerning the approach of a turning point in regulation, comparable to that of the pandemic; the letter of 42 Fellows and Foreign Members of the Royal Society of the United Kingdom concerning “extreme concern” at the pace of development; the report of Digi24 of 16 September 2026, https://www.digi24.ro/stiri/sci-tech/lumea-digitala/nasul-inteligentei-artificiale-spune-ca-reglementarea-ai-se-apropie-de-un-punct-de-cotitura-similar-cu-cel-al-pandemiei-de-covid-3950743; Time, “The AI Tipping Point”, 15 September 2026, concerning the legislative proposals under debate in the Congress of the United States.

2e. The public debate of September 2026: the public resignation of the researcher Jacob Coxon (Anthropic), 8 September 2026, and the reactions of the heads of the alignment and research departments of Anthropic and OpenAI – the reports of CBC News, Time (15 September 2026), Forbes and Fortune (9-10 September 2026); the positions expressed at the annual Salesforce conference in San Francisco, 15 September 2026, by Sam Altman, Mark Zuckerberg, Jensen Huang, Jack Clark and Dario Amodei – the reports of BBC News (16 September 2026), The Irish Times, CNBC and Forbes.

2c. Chronology of the incident of the summer of 2026 (the escape of the agents from OpenAI's testing environment and the compromising of the Hugging Face platform): Cloud Security Alliance, “The Great Sandbox Escape” (28 July 2026), https://cloudsecurityalliance.org/blog/2026/07/28/openai-and-hugging-face-security-incident-inside-the-great-sandbox-escape; Malwarebytes Labs, “The AI agent swarm that attacked Hugging Face is a warning for the future” (August 2026), https://www.malwarebytes.com/blog/ai/2026/08/the-ai-agent-swarm-that-attacked-hugging-face-is-a-warning-for-the-future; Axios, “OpenAI Hugging Face breach exposes AI agent security limits” (1 September 2026), https://www.axios.com/2026/09/01/openai-hugging-face-ai-agent-security; TechCrunch, “OpenAI’s rogue agents keep escaping, with no formal process to investigate them” (4 September 2026), https://techcrunch.com/2026/09/04/openais-rogue-agents-keep-escaping-with-no-formal-process-to-investigate-them/; Noma Security, “The Great (Sandbox) Escape” (2026), https://noma.security/blog/the-great-sandbox-escape-analyzing-the-openai-hugging-face-security-incident; the joint statement of OpenAI and Hugging Face of 21 July 2026.

2d. Legislative proposals tabled in the Congress of the United States of America in reaction to the incident: the “AI Kill Switch Act” (23 July 2026) and the “Ban Artificial Superintelligence Act” (3 September 2026); the open letter of over 1,100 employees of the frontier laboratories concerning mechanisms for moderating the pace of development (28 July 2026).

2b. Senator Alex Antic (Senate of Australia), parliamentary speech publicly disseminated in 2026 concerning the “digital prison” (the subscription economy, digital identity, compliance as the price of participation in society), https://www.facebook.com/reel/1059873890017722/.

2. CNN, “Amanpour”, 2 May 2023 – interview with Geoffrey Hinton and Connor Leahy (“We do not know how to control these things”; Hinton: the extinction of humanity “it's not inconceivable”; Leahy: “it's quite likely, unfortunately”).

3. Center for AI Safety, “Statement on AI Risk”, 30 May 2023; the public statements of Geoffrey Hinton (BBC, December 2024; CBS, April 2025) concerning the probability of 10–20% and the comparison with the “tiger cub”; “International AI Safety Report”, January 2025 (coordinated by Y. Bengio); RAND Corporation, “Securing AI Model Weights”, 2024; the letter “A Right to Warn about Advanced Artificial Intelligence”, 4 June 2024.

4. ANCOM, communication “The Artificial Intelligence Regulation in Romania – the current state of the implementation framework” (July 2026); the specialised press (Juridice.ro, Bursa.ro, August 2026) concerning the impossibility of imposing penalties pending the adoption of the national law.

5. California SB 53 – Transparency in Frontier Artificial Intelligence Act (29 September 2025); United States Executive Order No 14110 (30 October 2023, revoked in January 2025); the Interim Measures of the People’s Republic of China on generative AI services (15 August 2023); the Framework Convention of the Council of Europe on Artificial Intelligence (CETS No 225, 2024); Resolution 78/241 of the United Nations General Assembly (22 December 2023); the joint appeal of the Secretary-General of the United Nations and of the International Committee of the Red Cross (5 October 2023).

6. Law No 24/2000 on the rules of legislative technique for the drafting of legislative acts, as republished, as subsequently amended and supplemented – in particular Articles 6, 7, 13, 16, 30 to 31, 36 to 38, 40 to 56, 63; Government Decision No 561/2009 approving the Regulation concerning the procedures, at Government level, for the drawing up, approval and presentation of drafts of public policy documents, of drafts of legislative acts, as well as of other documents, with a view to their adoption/approval – Annex No 1 (the structure of the explanatory memorandum).

7. The Constitution of Romania, as republished (Articles 1, 22, 34, 53, 73, 75, 76, 78, 117, 119, 142, 148); the Civil Code (Articles 11, 25, 1246 to 1250, 1376); the Criminal Code (Articles 8, 9 to 11, 21, 135, 275, 303, 345, 395); the Code of Criminal Procedure (Articles 36, 168, 249); Law No 111/1996; Law No 703/2001; Law No 182/2002; Law No 415/2002; Law No 240/2004; Law No 95/2006; Law No 190/2018; Law No 129/2019; Law No 361/2022; Law No 365/2002; Framework Law No 153/2017; Government Emergency Ordinance No 77/2009; Government Ordinance No 2/2001; Government Emergency Ordinance No 27/2003; Government Emergency Ordinance No 78/2016; Government Emergency Ordinance No 155/2024; Government Emergency Ordinance No 195/2005.

8. Case-law: Court of Justice of the European Union, C-157/96, National Farmers' Union (1998); General Court of the European Union, T-13/99, Pfizer Animal Health (2002); Court of Justice of the European Union, C-376/22, Google Ireland and Others, judgment of 9 November 2023, ECLI:EU:C:2023:835 (paragraphs 25 to 35); Constitutional Court of Romania, Decision No 51/2016 (the clarity and foreseeability of the law).

9. The independent legal analysis of the draft (the form of 20 September 2026), with the verified sources indicated therein: Regulation (EU) 2024/1689 (consolidated text, 27 July 2026), Regulation (EU) 2022/2065 (recital 9, Articles 14, 17, 20), Directive 2000/31/EC (Article 3), Directive (EU) 2024/2853 (Articles 2 to 3, 18), Directive (EU) 2019/1937 (Articles 6, 15, 21), Directive (EU) 2015/1535 and Government Decision No 1016/2004, Law No 120/2018 approving Government Emergency Ordinance No 78/2016.

Comments on this text

Comments here go into the document’s section of the Sovereigntist forum. One argues on the text, with reasons.

See the whole discussion in the forum →