EU AI Act in Romania: supervision and next steps

This page answers a narrow question: if you build or run AI from Romania, mostly for clients elsewhere in the Union, what already binds you, who supervises you, and what has to be finished before the next hard date. It is written for engineering and product leaders at Romanian software services, outsourcing and product companies, not for litigators.

What the Act says, and where Romania fits

Regulation (EU) 2024/1689 is a regulation, not a directive. It applies directly in Romania without a transposition law. There is no waiting period while Bucharest legislates, and no Romanian statute that can soften a requirement. The only things Member States were asked to do domestically are institutional: designate authorities, set penalty levels within the ceilings the Act fixes, and stand up a sandbox.

Article 70 required each Member State to designate at least one notifying authority and at least one market surveillance authority, and to communicate them to the Commission, by 2 August 2025. Article 57 required at least one national AI regulatory sandbox to be operational by 2 August 2026. Article 99 required Member States to lay down rules on penalties and notify them.

Romania has been slower than several other Member States on all three. Before you rely on any statement about which Romanian body supervises you, check the Commission's published list of national competent authorities rather than press reporting, because the position has been moving. What matters commercially is the part that does not move:

An incomplete national designation does not suspend a single obligation in the Regulation. Article 5 has bitten since 2 February 2025 and the enforcement architecture has been live since 2 August 2026, whatever the state of the Romanian institutional map.

There is also a second exposure that Romanian services firms underrate. Market surveillance under this Regulation is not confined to your home state. If you place a system on the market in Germany, Spain or the Netherlands, the authority in that Member State can act against the product there. A thin supervisory presence in Romania buys you very little if your customers are in Frankfurt and Amsterdam.

Provider or deployer, and why outsourcing blurs it

The Act allocates duties by role, not by size or by where your developers sit. A provider develops an AI system or a general purpose AI model and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in the course of its activity. Providers carry the heavy end: risk management, data governance, technical documentation, conformity assessment, registration. Deployers carry Article 26 duties, which are real but far lighter.

For a Romanian outsourcing house the honest answer is usually that you are neither by default and both by accident. Three provisions decide it.

  • Article 25(1). You become the provider of a high-risk system already on the market if you put your name or trademark on it, if you make a substantial modification to it, or if you modify its intended purpose so that it becomes high-risk. Rebranding a client's model as your own accelerator, or repurposing a scoring engine built for one use into another, flips the role.
  • Article 25(4). If you supply tools, services, components or processes used in a high-risk system, you must, by written agreement, give the provider the information, capabilities, technical access and assistance they need to comply. This is the clause that will land in your master services agreements whether you negotiate it or not. It does not apply to third parties making tools available under a free and open source licence.
  • Article 2(1). Territorial scope follows the market and the output, not the developer's location. Building from Cluj for a US client does not remove you from scope if the system is placed on the Union market or its output is used in the Union.

In practice, for bespoke build work where the client brands and operates the result, the client is the provider and you are an Article 25(4) supplier. For anything you productise, licence repeatedly or badge as your own, assume you are the provider and price the compliance work into the deal.

What that concretely requires

If you are a provider of an Annex III high-risk system: a documented risk management system running across the lifecycle under Article 9; data governance for training, validation and testing sets under Article 10; a technical file matching Annex IV under Article 11, written before placing on the market and kept current; automatic logging under Article 12, retained for the lifetime of the system and at minimum six months; human oversight designed in under Article 14; instructions for use under Article 13 in a language easily understood by deployers in the Member State concerned, which for Romanian deployers means Romanian; registration in the EU database under Article 49 before placing on the market; post-market monitoring under Article 72 and serious incident reporting under Article 73.

If you are an Article 25(4) supplier only, your deliverable is narrower but contractual: model cards, dataset provenance, evaluation results, log schemas, versioning, and a support commitment your client can point to when their auditor asks. Write it into the statement of work rather than promising it later.

Two obligations apply to almost everyone regardless of role. Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf, and has applied since 2 February 2025. Article 50 transparency, enforceable since 2 August 2026, requires disclosure when users interact with an AI system, machine readable marking of synthetic audio, image, video and text, and clear labelling of deepfakes.

The dates that bind

DateStatusWhat applies
2 February 2025In forceArticle 5 prohibitions, Article 4 AI literacy
2 August 2026In forceEnforcement powers live, Article 50 transparency, Article 53 GPAI obligations enforceable
2 December 2027453 days awayAnnex III standalone high-risk obligations, as extended by the Digital Omnibus provisional agreement of May 2026, still pending formal adoption
2 August 2028FutureAnnex I embedded high-risk obligations

Penalty ceilings under Article 99 are set in the Regulation: up to 35 million euro or 7 percent of worldwide annual turnover for breaching Article 5, up to 15 million euro or 3 percent for most other provider and deployer obligations, and up to 7.5 million euro or 1 percent for supplying incorrect, incomplete or misleading information to authorities. For SMEs the lower of the fixed amount and the percentage applies.

What to do in the next quarter

  1. Build a role register per client engagement. One row per system or material feature, naming the client, the intended purpose, whether it touches an Annex III area, and your role: provider, deployer, or Article 25(4) supplier. Have the account owner and an engineer sign it. Most Romanian services firms discover two or three engagements where they have quietly become the provider.
  2. Rewrite the compliance annex in your standard MSA. Cover the Article 25(4) information and access duty, retention of logs, notification when you make changes that could count as substantial modification under Article 25(1), and a cooperation clause for serious incident reporting under Article 73. Do it once, centrally, rather than per deal.
  3. Start the Annex IV technical file now for anything Annex III. With 453 days to 2 December 2027 and multi-week client review cycles, the file is the long pole. Begin with architecture, data provenance, evaluation methodology and known limitations, and keep it in version control alongside the code.
  4. Turn on and prove logging. Article 12 requires automatic recording of events over the lifetime of the system. Set retention to at least six months, longer where sector rules demand it, and document what each log field is for.
  5. Run Article 4 literacy training and keep the attendance record. A half day for engineering, sales and delivery leads, repeated for new joiners, with a dated list of participants. It is cheap and it is the first thing an authority asks for.

If you are unsure whether a given engagement makes you a provider or an Article 25(4) supplier, the free screener at https://www.getactcomply.com/check walks through the classification questions and returns a role and obligation list per system.

Check your EU AI Act risk in 5 minutes

Free risk classifier. No signup required. Enforcement is already live.

Run the free screener