MargelisLT

EU AI Act in Lithuania: who supervises it and what companies must do

In Lithuania, the national competent authority for market surveillance under the EU AI Act — and the country's single point of contact — is the Communications Regulatory Authority of the Republic of Lithuania (RRT), since 1 April 2025. The notifying authority, responsible for conformity assessment bodies for high-risk AI systems, is Inovacijų agentūra (Lithuania's innovation agency), since 2 August 2025. The obligation that reaches the largest number of companies is Article 50 transparency, which applies from 2 August 2026.

This is an operational summary with primary sources, not legal advice. Whether a specific obligation applies to your company is a question for your lawyer. Last checked 11 September 2026.

Who supervises the AI Act in Lithuania?

AuthorityRoleSince
Communications Regulatory Authority (RRT)
Ryšių reguliavimo tarnyba
National competent authority: market surveillance authority and single point of contact. Coordinates supervisory methodology with sector regulators.1 Apr 2025
Inovacijų agentūraNotifying authority — responsible for the conformity assessment bodies that certify high-risk AI systems.2 Aug 2025
EU AI Act Service DeskThe European Commission's free information point: regulation text, deadlines, interpretation.live

Legal basis: by Government Resolution No. 860 of 16 October 2024, amendments to the Law on Technology and Innovation and the Law on Information Society Services were submitted to the Seimas, which approved them on 14 January 2025. The mandates and dates are published by the Ministry of the Economy and Innovation and by RRT.

Does this apply to me if my company is not in Lithuania?

It can. The AI Act applies to providers placing AI systems on the EU market regardless of where they are established, and to providers and deployers outside the EU where the output produced by the system is used in the Union. If you sell an AI-enabled product into Lithuania, or your Lithuanian subsidiary deploys one, Lithuanian market surveillance is the authority that can ask you questions — and RRT is the single point of contact you are looking for.

Am I a provider or a deployer?

The regulation separates two roles, and most companies are deployers rather than providers.

What are the deadlines?

DateWhat applies
2 Feb 2025Article 4 AI literacy duty already applies.
1 Apr 2025RRT begins acting as market surveillance authority and single point of contact in Lithuania.
2 Aug 2025Inovacijų agentūra begins acting as notifying authority.
2 Aug 2026Article 50 transparency obligations apply; enforcement of the Article 4 duty begins.
2 Dec 2026Transition period for the marking obligation for systems already on the market, under the 2026 Digital Omnibus amendment.

Regulation text: Regulation (EU) 2024/1689 on EUR-Lex. Timeline overview: European Commission.

Five practical steps

  1. Write down where AI actually runs in your operations. Not an abstract list of tools, but workflows: what drafts text to a customer, what speaks on the phone, what screens candidates. Each entry needs an owner and a date. Done looks like: a table where every row has a responsible person.
  2. Assign a role to each workflow — provider or deployer. That determines whether you owe marking (Art. 50(2)) or disclosure (Art. 50(4)).
  3. Turn on marking where you generate. The Commission's Code of Practice names C2PA Content Credentials as an example mechanism; metadata and watermarking are also used in practice. What matters is that the mark travels with the file.
  4. Give people written work rules (Art. 4). One page per role: what the AI may do, what it may not, who checks the result. Literacy is evidenced by a training record, not by a declaration.
  5. Make the marking checkable without you. This is the step most guidance skips: a mark nobody can independently confirm is worth little to an auditor. You need a record a third party can read and compare.

What does a breach cost?

Breaching the Article 50 transparency obligations falls under Article 99(4): administrative fines of up to EUR 15,000,000 or 3% of total worldwide annual turnover, whichever is higher. Article 4 carries no direct fine, but weak AI literacy can be treated as an aggravating factor when other breaches are assessed.

What we did ourselves — and how to check it

Rūpestėlis Holding UAB (Margelis.ai) signed both sections of the European Commission's Code of Practice on transparency of AI-generated content; the Commission published the signatory list on 31 July 2026. That means we carry the same obligations, and you can check our implementation without taking our word for it.

Every AI-assisted item we publish carries a signed receipt. The receipt holds the text, its sources, a timestamp and an Ed25519 signature. Open the registry, take any entry, and verify it has not been altered.

Registry: margelis.ai/verify · Our Article 50 implementation status: margelis.ai/our-article-50-posture.html

This is not a certificate, and it is not a compliance guarantee for you. It is a worked example of what marking looks like when it can be checked from the outside.

Open the Article 50 checklist — 16 checks, no sign-up

Frequently asked questions

Who is the AI Act authority in Lithuania?
The Communications Regulatory Authority of the Republic of Lithuania (RRT) is the national competent authority for market surveillance and the single point of contact, since 1 April 2025. Inovacijų agentūra is the notifying authority for conformity assessment bodies, since 2 August 2025.
We are a US company selling software into Lithuania. Are we in scope?
Possibly yes. The AI Act reaches providers placing systems on the EU market wherever they are established, and providers and deployers outside the EU whose system output is used in the Union. RRT is the Lithuanian single point of contact for questions.
Do I have to mark AI content if I only use a third-party tool?
Then you are a deployer, not a provider. The marking obligation under Article 50(2) sits with the system's provider. As a deployer you may owe disclosure under Article 50(4) in defined cases, and the Article 4 AI literacy duty applies to you in any event.
Is there an official EU AI Act certificate for Article 50?
No. There is no separate certificate for the Article 50 transparency obligations. There is a duty to mark, to disclose, and to be able to show it. Anyone selling an "AI Act certificate" for Article 50 is calling it something it is not.
When do fines start?
Article 50 obligations apply from 2 August 2026; systems already on the market have a transition period for the marking obligation until 2 December 2026 under the 2026 Digital Omnibus amendment. Fine levels are set by Article 99(4).

Sources

Margelis.ai is operated by Rūpestėlis Holding UAB (Vilnius, Lithuania). This page was prepared with AI assistance and reviewed by a human; its publication receipt is in the registry. Related: Article 50 marking and proof · checklist · lietuviškai.