Why we deal with it in the design, not after it
Obligations for artificial intelligence, data and cybersecurity do not arrive at once — they are added in layers, and each layer rests on the previous one. A system that today has no register of models, no audit trail and no place for human oversight cannot be “tuned” by an amendment; it is rebuilt. That is why the design also accounts for what is still in the legislative process, and for every project we state which requirements are met, which are prepared and which wait for the final wording.
What we track
| Instrument | Status | What follows from it |
|---|---|---|
| Návrh zákona o umelej inteligencii (MIRRI SR) after the inter-ministerial comment procedure, heading to the Government Legislative Council and the Economic and Social Council Source: MIRRI SR, 13. 8. 2026 |
in preparation | A national framework for supervising the use of artificial intelligence. Under the current draft no new central authority is created — the tasks go to MIRRI as the general market surveillance body together with sectoral bodies (data protection, cybersecurity, regulated products). |
| Nariadenie (EÚ) 2024/1689 — akt o umelej inteligencii (AI Act) the main body of obligations applies from 2 August 2026 Source: EUR-Lex |
in force | Risk classification of systems, obligations of providers and deployers, transparency towards the person interacting with AI, technical documentation and human oversight for high-risk uses. |
| Návrh zákona o správe vybraných kategórií údajov verejného sektora in the legislative process together with the AI act Source: MIRRI SR |
in preparation | Rules for the re-use of public-sector data, registration of data intermediaries and data altruism organisations, supervision and sanctions. |
| Nariadenie (EÚ) 2023/2854 — akt o údajoch (Data Act) applies from 12 September 2025, Article 3(1) from 12 September 2026 Source: EUR-Lex |
in force | User access to data from a connected product, data sharing with third parties and switching between cloud providers without vendor lock-in. |
| Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti v znení zákona č. 366/2024 Z. z. (NIS2) the amendment has been in force since 1 January 2025 Source: Slov-Lex |
in force | Security measures, incident reporting and statutory-body accountability for thousands of new entities — the base layer on which the AI and product obligations are stacked. |
| Nariadenie (EÚ) 2024/2847 — akt o kybernetickej odolnosti (CRA) reporting of actively exploited vulnerabilities from 11 September 2026, most obligations from 11 December 2027 Source: EUR-Lex |
in force | Cybersecurity of products with digital elements: a bill of materials (SBOM), vulnerability handling and reporting within 24 and 72 hours. |
Status of legislation as of 25. 8. 2026. We update the page when the wording or the deadlines change — for a specific project always verify the status in the primary source as well.
What we do about it
- A register of systems and risk classification — we know what runs where and which risk category it falls into.
- An audit trail in a single schema (time, actor, action, resource, outcome) — transferable to security monitoring without rebuilding the application.
- Human oversight at the point of decision wherever the output has a legal or similarly significant effect.
- Data protection by design — minimisation, masking of sensitive data and processing within the EU.
- A bill of materials and vulnerability handling for products with digital elements.
- An incident procedure with the reporting deadlines (24 and 72 hours) rehearsed in advance, not improvised.
Need this assessed for a particular system?
Write to office@ioas.pro — we will go through what applies to you and what needs to be settled before deployment, with no obligation.