AI vendor contracts in Romania under the EU AI Act and GDPR

AI Vendor Contracts in Romania: EU AI Act and GDPR Clauses

An AI vendor contract should do more than grant access to a platform. It should identify the system and intended use, allocate regulatory roles, control the use of business and personal data, preserve evidence, set performance and security obligations, and provide a workable exit if the supplier, model or law changes.

Key points for companies buying AI services in Romania:

  • Classify the AI use and the parties’ roles before negotiating warranties and liability.
  • Do not assume that a standard SaaS agreement or a GDPR DPA covers AI-specific risk.
  • State whether prompts, files, outputs and usage data may be retained or used for training.
  • Require enough information, logs and cooperation to meet the customer’s own legal duties.
  • Connect service changes, security incidents and regulatory events to notice, remediation and exit rights.

This guide is intended for Romanian companies, foreign groups operating in Romania, technology suppliers, procurement teams and businesses implementing generative or other AI tools. It focuses on contract structure. For the wider regulatory framework, read our EU AI Act guide for foreign companies.

Why does an AI vendor contract need a separate review?

AI services can change after signature. A supplier may replace a model, add a subprocessor, change data-retention settings, modify safety controls or alter the geographic delivery chain. Outputs may also be probabilistic rather than repeatable. These features create risks that are not fully addressed by ordinary clauses on software access, uptime and confidentiality.

The EU AI Act allocates obligations according to the system, risk category and operator role. The GDPR applies in parallel where personal data is processed. The contract cannot transfer away statutory responsibility, but it can secure the information, instructions, evidence and cooperation needed for each party to perform its own obligations.

Practical distinction: the AI Act analysis, the GDPR role analysis and the commercial allocation of risk are related but separate. A supplier described as a “provider” under the AI Act is not automatically a “processor” under the GDPR.

Start with the AI use, not the vendor’s template

Before redlining the agreement, the customer should record what the system will do, whose decisions it will influence, what data enters the system, who receives the output and whether the tool will be integrated into employment, credit, insurance, education, essential services, biometric or other sensitive workflows. The same product can create different legal exposure when deployed for a different purpose.

Contract navigator
Build the AI contract in five connected layers

Select a layer to see the question that should be answered before signature.

System and intended use

Identify the product, model, version, functions, integrations, users, prohibited uses and decision context. Classification begins with the actual deployment.

AI vendor due diligence before contract negotiation

A customer cannot negotiate intelligently without basic information about the service. The due-diligence request should be proportionate to the use and risk, but it commonly covers:

  • the legal entity supplying the service and the entities supporting it;
  • the model or models used, hosting locations and material third-party dependencies;
  • the intended purpose, known limitations and prohibited uses;
  • data sources, retention rules and whether customer data is used for training or improvement;
  • security controls, incident history, business continuity and disaster recovery;
  • testing, accuracy or performance information relevant to the deployment;
  • subcontractors, subprocessors and international data transfers; and
  • the supplier’s process for regulatory requests, complaints, audit evidence and system changes.

For high-risk deployments, the customer may require contractual access to sufficient documentation, instructions, logs and compliance information to enable it to perform its own obligations under the AI Act. The scope of access should reflect the parties’ respective roles and may need to protect the supplier’s trade secrets and intellectual-property rights. The European Commission’s AI Act information page and its AI Act Service Desk are useful starting points, but the contract must still reflect the particular system and transaction.

What if the service relies on a general-purpose AI model?

Where the service relies on a general-purpose AI model, the customer should also consider whether contractual information rights are needed regarding the model provider, model updates, transparency documentation and downstream restrictions affecting the deployment. These provisions should be tailored to the customer’s position in the AI value chain and should not imply that the customer is entitled to the provider’s complete technical documentation.

What clauses should an AI vendor agreement contain?

Contract layerWhat the clause should resolveRisk if unclear
System and permitted useProduct, model, version, functionality, users, integrations, territories, intended purpose and prohibited uses.The service is used outside its tested or agreed purpose.
Regulatory rolesAI Act operator roles, GDPR roles, responsibility matrix and cooperation duties.Each party assumes the other will supply evidence or perform a mandatory task.
Data and trainingPermitted inputs, retention, model training, improvement, isolation, deletion and export.Confidential or personal data is retained or reused beyond the customer’s expectation.
Performance and oversightRelevant metrics, limitations, testing, human review, logs, notices and remediation.Outputs cannot be evaluated, challenged or reconstructed when a problem occurs.
Security and incidentsTechnical measures, vulnerability management, notification triggers, timing and cooperation.The customer learns too late or receives too little information to respond lawfully.
IP and output rightsRights in inputs, outputs, configurations, documentation, feedback and third-party materials.The customer lacks the rights needed for its intended commercial use.
Change controlNotice of model, policy, subprocessor, location and functionality changes, plus testing and objection rights.A compliant deployment becomes materially different during the contract.
Liability and exitWarranties, indemnities, caps, insurance, suspension, termination, transition, export and deletion.The remedy is commercially unusable when the service fails or must be withdrawn.

Click a row, or focus it and press Enter, to highlight one negotiation layer.

1. Define the system, version and intended purpose

The agreement should identify what is actually being supplied. “AI services” is rarely sufficient. The specification should address the model or service version, functions, interfaces, customer environment, authorised users, territories, dependencies and intended use. If classification or performance depends on a specific configuration, that configuration should be documented.

2. Allocate AI Act and GDPR roles separately

The parties should record their assumed roles under the AI Act and set out who provides instructions, documentation, logs, notices and regulatory cooperation. A separate analysis is required under the GDPR. Depending on the facts, the parties may be controller and processor, independent controllers or, in a narrower class of cases, joint controllers.

Where the supplier processes personal data on the customer’s behalf, Article 28 GDPR terms may be required. See our dedicated guide to the Data Processing Agreement in Romania. The DPA should not be treated as the complete AI contract, and the main agreement should not conflict with it.

3. Control prompts, files, outputs and training use

The contract should distinguish customer content, personal data, telemetry, feedback and output. It should state whether each category may be stored, reviewed by humans, used to improve the service or used to train a shared model. Where “no training” is promised, the clause should explain its scope, including whether safety review, abuse monitoring or service analytics remain permitted.

The European Data Protection Board has emphasised that whether an AI model is anonymous must be assessed case by case. A supplier’s assertion that its model is anonymous should therefore be supported by facts rather than accepted as a label. See the EDPB’s summary of Opinion 28/2024.

4. Make performance, limitations and human oversight usable

Conventional uptime metrics do not measure output quality. Depending on the use, the contract may need agreed tests, documented limitations, error reporting, performance monitoring, bias or drift controls, escalation and human-review requirements. The AI Act’s accuracy requirements should not be treated as a guarantee of error-free outputs. Any contractual accuracy or performance commitment should define the relevant task, dataset, test method, threshold and remedy.

5. Require evidence and audit cooperation

The customer may need records to complete an impact assessment, answer a regulator, investigate a complaint or demonstrate human oversight. The agreement should define which information is available, in what format, how quickly and subject to what confidentiality protections. In practice, enterprise suppliers may satisfy some audit requirements through independent certifications, reports and controlled information-sharing mechanisms rather than unrestricted customer audits. Those materials can support due diligence, but they do not automatically answer system-specific questions.

6. Coordinate security and incident notification

Security clauses should address access controls, encryption where appropriate, vulnerability management, segregation, personnel access, business continuity and incident cooperation. Notification should be triggered by defined events and delivered early enough for the customer to meet its own legal and operational duties. Different events may activate different regimes, so a personal-data breach, an incident affecting the AI system and an ordinary service outage should not be collapsed into one undefined term.

7. Address intellectual property and third-party claims

The contract should distinguish rights in customer inputs, supplier technology, configurations, fine-tuning, documentation, feedback and outputs. It should also allocate responsibility for claims involving training material, output, trademarks, confidential information and third-party components. Broad statements that the customer “owns the output” may be insufficient if the supplier cannot grant exclusivity or if protectability depends on applicable law and human contribution. Ownership language should be assessed together with applicable copyright rules, which may require sufficient human authorship for copyright protection.

8. Control subcontractors, subprocessors and model dependencies

An AI service may depend on model providers, cloud infrastructure, safety services and specialist subprocessors. The contract should identify the relevant chain, require notice of material changes and preserve appropriate objection or termination rights. For personal data, the subprocessor mechanism must align with Article 28 GDPR and any applicable international-transfer safeguards.

9. Regulate model and policy changes

Suppliers often reserve broad rights to modify models, acceptable-use policies and technical features. The customer should seek prior notice of material changes, enough information to reassess the deployment and a remedy when a change materially reduces functionality, alters data use, affects compliance or creates an unacceptable risk.

10. Connect liability to the risks that matter

Liability provisions should be read together with warranties, indemnities, insurance and remedies. A general cap may be commercially unsuitable for confidentiality breaches, unlawful data use, IP claims or deliberate misconduct, while unlimited liability for every model error may be unacceptable to a supplier, particularly where outputs remain subject to human review. The negotiated position should reflect control, foreseeability, fees, insurance and the consequences of the intended use.

11. Preserve suspension, termination and transition rights

The contract should explain what happens if the service becomes prohibited, materially non-compliant, insecure or unsuitable for the agreed purpose. Exit terms should cover data and prompt export, configuration records, transition assistance, continuing access where necessary, deletion, certification and surviving confidentiality or audit duties.

12. Align the whole contract suite

The main agreement, order form, specification, DPA, security schedule, service levels and online policies should be checked together. An order of precedence is important where one document allows training while another prohibits it, or where a linked policy can be changed unilaterally. Our broader contract review checklist explains the commercial clauses that remain relevant alongside the AI-specific controls.

Customer and supplier priorities are not identical

A customer usually seeks transparency, stable functionality, control of its data, evidence for compliance and practical exit rights. A supplier needs a defined intended use, customer cooperation, restrictions against misuse, protection for reusable technology and a liability position proportionate to fees and control. A balanced contract should not hide this tension. It should identify which party can prevent, detect and remedy each risk.

Practical experience: how Atrium approaches an AI contract review

A typical client mandate begins with the operating facts, not a generic AI checklist. Atrium Romanian Lawyers first maps the proposed use, data flows, parties, model dependencies and decisions affected by the tool. We then review the full contract suite, identify provisions that do not match the deployment and separate mandatory compliance points from negotiable commercial risk.

The work may include a priority risk report, tracked changes, replacement clauses and a negotiation list for the business and technical teams. Particular attention is given to training rights, confidentiality, GDPR roles, security incidents, documentation, model changes, intellectual property, liability and exit. This section describes our review method and does not disclose any client’s confidential facts.

AI vendor contract checklist before signature

  1. Document the system, intended use, users and decision context.
  2. Complete the AI Act role assessment and determine whether the deployment may involve prohibited, high-risk, transparency or other regulated AI use cases.
  3. Map personal data, confidential information and international transfers.
  4. Collect the main agreement, order, DPA, security schedule and linked policies.
  5. Confirm whether customer data, prompts or outputs may be used for training.
  6. Test whether supplier documentation supports the customer’s compliance duties.
  7. Define relevant performance measures, limitations and human oversight.
  8. Align incident notification with legal and operational deadlines.
  9. Review IP ownership, licences, third-party material and claims.
  10. Control material changes to models, policies, locations and subcontractors.
  11. Model liability for realistic failure scenarios.
  12. Plan suspension, export, transition and deletion before deployment begins.

Frequently asked questions

Does every AI vendor contract need a GDPR DPA?

No. A DPA is required where the factual relationship meets the controller-processor conditions under Article 28 GDPR. Other arrangements may involve independent or joint controllers. The roles should be assessed from the actual processing, not only from the labels in the contract.

Can an AI supplier use customer prompts to train its model?

That depends on the contract, product settings, supplier role, transparency and applicable data-protection and confidentiality rules. The agreement should state clearly which data may be used, for what purpose, for how long and whether an effective opt-out or enterprise isolation applies.

Does an AI Act clause transfer compliance responsibility to the supplier?

No. A contract can allocate tasks, information duties, warranties and remedies, but it cannot remove statutory obligations imposed on a party by law. Each operator should understand and perform the duties attached to its own role.

Should the contract name the underlying AI model?

Usually, the system and relevant dependencies should be described with enough precision to understand what is being supplied. If the supplier may change the underlying model, the contract should address notice, testing, material degradation, data implications and the customer’s available remedies.

Who owns AI-generated output?

The answer depends on the contract, the output, applicable intellectual-property law, human contribution and third-party material. The agreement should distinguish ownership from a licence to use and should address infringement claims and supplier restrictions.

Can a Romanian lawyer review a foreign vendor’s English-language AI contract?

Yes, where the agreement concerns a Romanian company, Romanian operations or applicable EU and Romanian requirements. The scope should identify whether separate advice is needed for clauses governed exclusively by another country’s law.

Negotiating an AI vendor contract connected with Romania?

Atrium Romanian Lawyers assists customers and technology suppliers with AI, SaaS and IT contract review, drafting and negotiation, including GDPR, security, intellectual-property, liability and exit provisions.

Discuss the contract with a Romanian lawyer

Disclaimer: This article provides general information and does not constitute legal advice. The appropriate contract and compliance analysis depends on the system, intended use, data, parties, operator roles, applicable law and complete contract suite.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.

EU AI Act in Romania: 2026 Guide for Foreign Companies

Artificial intelligence and digital regulation · 2026

EU AI Act in Romania: 2026 Guide for Foreign Companies

Foreign companies operating in Romania may be subject to the EU AI Act even when the parent company, vendor or development team is outside the European Union. This practical guide explains the scope rules, the obligations already applying in 2026, the later high-risk deadlines and the records a Romanian business should build now.

The analysis should be read together with the official AI Act text, the Commission’s AI Act implementation page and the current guidance available through the AI Act Service Desk.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.
AI compliance is a governance process: classify, document, train and monitor.

What is the practical answer for a foreign company?

A Romanian subsidiary, branch or other local operation should begin with an inventory of the AI systems it provides, deploys, imports, distributes or uses for work. The company should then identify whether the system is prohibited, high-risk, subject to transparency duties, or outside the main AI Act obligations. The label used by the vendor is not decisive: the same tool may create different legal questions depending on its function, users, outputs and place of use.

Scope first

Map the Romanian entity, the foreign group, the provider, the deployer, the users and where the output is used. A foreign parent does not automatically remove EU exposure.

Article 2 analysis

Obligations now

AI literacy, prohibited-practice controls, GPAI-related obligations and the new transparency rules must be considered according to the applicable role and system.

2026 operating baseline

Evidence later

Keep an AI register, vendor file, training record, human-oversight process and incident route so the business can show how it reached its classification.

Governance that scales
Key point: the AI Act does not create a universal “AI officer” requirement for every Romanian business. Responsibility must be allocated in a way that fits the company’s systems, roles, risk profile and existing compliance structure.

AI Act timeline for companies operating in Romania

The original AI Act timetable has been supplemented by the Digital Omnibus on AI. The current implementation page of the European Commission identifies the dates below. A deadline table should be treated as a planning tool, not as a substitute for checking the final text and any sector-specific transition rule.

Completed1 August 2024
Entry into force

The Regulation entered into force. The legal framework began its transition period, while later provisions were scheduled to apply in stages.

Applied2 February 2025
Prohibitions and literacy

The prohibited-practice rules and the Article 4 AI-literacy obligation became applicable. Businesses should already have training and prohibited-use controls in place.

Applied2 August 2026
Transparency and supervision

Transparency obligations for certain AI systems, broader enforcement powers and the Commission’s AI Office and national authorities’ implementation work become operational.

Deferred2 December 2027
Selected high-risk uses

Following the Digital Omnibus, high-risk systems in sensitive Annex III areas, including employment, apply from this date. Product-embedded high-risk rules have a later transition.

Rule or milestoneCurrent application pointWhat the Romanian operation should do
Prohibited AI practicesApplied from 2 February 2025; an additional prohibition concerning certain non-consensual intimate or child sexual abuse material applies from 2 December 2026.Screen use cases before procurement or deployment and escalate any practice that may manipulate, exploit, socially score or infer protected characteristics.
AI literacyApplied from 2 February 2025 and enforced by national market-surveillance authorities from 2 August 2026.Adopt role-based training and retain evidence of the measures taken, rather than relying on a generic awareness email.
Transparency rulesApplied from 2 August 2026 for the relevant Article 50 systems and outputs.Review chatbot notices, synthetic-content marking, deepfake disclosures and the editorial process for public-interest text.
Annex III high-risk systemsSelected high-risk use cases, including employment, apply from 2 December 2027 after the Digital Omnibus transition.Classify and plan early. The later date does not remove GDPR, employment, consumer or fundamental-rights duties that may apply now.
High-risk systems in regulated productsExtended transition until 2 August 2028 under the current Commission summary.Coordinate product-safety, sectoral and AI Act analysis with the provider and any notified-body or conformity route.

The Commission’s current AI Act timeline identifies the staged dates and the changes introduced by the Digital Omnibus.

Does the AI Act apply to a foreign company operating in Romania?

Often, yes. The scope is not limited to companies incorporated in an EU Member State. The Regulation covers providers placing AI systems or general-purpose AI models on the Union market, deployers located in the Union, and providers or deployers in a third country where the output produced by the system is used in the Union. Importers, distributors, certain product manufacturers, authorised representatives and affected persons are also expressly addressed.

This creates several common patterns for international groups. A US or UK parent may provide a generative AI platform used by its Romanian subsidiary. A Romanian company may deploy a recruitment tool supplied by a vendor in another country. A group may centralise procurement and security while the local entity makes decisions affecting Romanian workers or customers. The legal analysis should identify each role instead of treating “the group” as a single operator.

Question 1Is the system used in the EU?

If the Romanian entity deploys the system, or its output is used in Romania or elsewhere in the Union, the scope analysis moves beyond the location of the parent company.

Question 2Who provides it?

Record the provider, importer, distributor, group company, authorised representative and vendor chain. Contract labels are useful evidence but do not replace the legal role analysis.

Question 3Who deploys it?

Identify the business unit that determines the purpose and use. The deployer may be the Romanian company, a foreign shared-service centre or another group entity depending on the facts.

Question 4Who is affected?

Employees, applicants, customers and other persons in the Union may be affected even when the technical processing or model hosting takes place outside Romania.

Do not rely on the hosting location alone: cloud hosting, a foreign parent or a vendor’s “EU AI Act compliant” statement does not by itself determine whether the Romanian entity has obligations.

Which AI uses should a Romanian company classify first?

A useful first inventory is operational rather than theoretical. Start with tools that make recommendations, rank people, generate customer-facing outputs, analyse sensitive information, control access to services or influence employment decisions. Include tools purchased by individual teams if company data or company accounts are used.

Business useWhy it needs early reviewFirst evidence to collect
Recruitment, CV screening or candidate scoringEmployment and access-to-self-employment uses are listed in Annex III and may engage high-risk analysis once the relevant rules apply.Vendor description, decision logic, data sources, human review and impact on applicants.
Employee monitoring, task allocation or performance evaluationAI used to affect working relationships or monitor behaviour may fall within the employment category and also raise labour-law and GDPR questions.Purpose, affected groups, indicators, decision owner, notice, consultation and challenge route.
Customer chatbot or voice assistantInteractive systems may require a clear notice that the person is interacting with AI unless the interaction is obvious in context.Interface screenshots, notice wording, escalation to a person and accessibility check.
AI-generated public-facing images, audio or textArticle 50 can require machine-readable marking or disclosure, subject to the relevant exception and content type.Generation workflow, labelling method, human review, editorial responsibility and publication record.
Credit, insurance, access or eligibility decisionsSome essential private or public service uses are listed as high-risk and can intersect with anti-discrimination and sectoral rules.Decision criteria, datasets, human oversight, explanation path and affected-person rights.

Do not classify a system only by the word “AI” in a sales brochure. Ask what the tool actually does, which people it affects, whether it generates or ranks content, whether it makes or supports a decision, and whether it is integrated into a regulated product. The Commission’s AI Act Service Desk provides tools and guidance that can support this initial assessment.

Which AI practices are prohibited?

The AI Act bans certain practices because their risks are considered unacceptable. Examples include harmful manipulation or deception, harmful exploitation of vulnerabilities, social scoring, certain forms of individual criminal-offence prediction, untargeted scraping to create facial-recognition databases, workplace or education emotion recognition, and biometric categorisation to infer protected characteristics, subject to the precise legal wording and exceptions.

For a foreign company with Romanian staff, the workplace emotion-recognition prohibition deserves particular attention. A vendor may market a “wellbeing”, “engagement” or “productivity” product without describing it as emotion recognition. The business should look at the functionality and the data signals used, not only the product name. The same applies to tools that claim to infer personality, intent, reliability or risk from communications.

Procurement gate

Require the business owner to describe the system’s purpose, data sources, affected people and output before purchase or activation.

Red-flag review

Escalate tools involving vulnerability exploitation, social scoring, biometric inference, emotion recognition or behavioural prediction.

Decision record

Record why the company concluded that a use is permitted, prohibited, outside scope or subject to another compliance route.

What transparency duties apply from 2 August 2026?

Article 50 covers specific interactions and outputs. A provider of an AI system intended to interact directly with natural persons must ensure that people are informed that they are interacting with an AI system unless this is obvious in context. Providers of systems generating synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the stated limits and exceptions.

Deployers have additional duties in defined situations. People exposed to emotion-recognition or biometric-categorisation systems must be informed. A deployer of an image, audio or video deepfake must disclose that the content was artificially generated or manipulated, subject to the artistic and other exceptions. Text generated or manipulated by AI and published to inform the public on matters of public interest must also be disclosed, but the obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

This is why the website’s ordinary AI Notice and a public disclosure under Article 50 should not be treated as identical. An editorial footer may be useful transparency, but it does not automatically satisfy every machine-readable marking or user-facing notice requirement. Each workflow should be checked according to the system, output, audience and publication context.

Practical control: create a short content decision tree: AI-assisted editing, substantially generated content, deepfake or synthetic media, public-interest text, customer interaction. Assign the corresponding label, machine-readable marker, human review and approval record.

Does every AI-generated business article or image need a label?

No single answer applies to every output. The AI Act distinguishes between the type of system, the type of output and the way the content is published or presented. Standard editing that does not substantially alter the input may fall within an exception to the machine-readable marking duty. A human review and editorial-control exception may apply to certain public-interest text. Deepfakes have their own disclosure rule, while chatbots require a direct-interaction analysis.

The company should document the workflow instead of making a broad statement such as “all AI content is exempt” or “all AI content must be labelled in the same way”. Keep the prompt or source material where appropriate, the generated version, the human changes, the responsible editor, the final label and the publication channel. This is particularly useful where content is repurposed across websites, advertisements, social media and customer communications.

What does AI literacy require?

Article 4 requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy for staff and other persons dealing with the operation and use of AI systems on their behalf. The measures should take account of technical knowledge, experience, education, training, the context in which the systems are used and the people or groups on whom the systems are used.

This is a context-based obligation, not a fixed annual course or a universal certification. A marketing employee using a writing assistant, an HR manager using a candidate-ranking tool and an engineer managing a model deployment do not need identical training. The employer should explain relevant limitations, data handling, hallucination and reliability risks, prohibited uses, escalation routes, human review and the consequences of relying on outputs.

Identify AI users

List employees, contractors and other persons acting on the company’s behalf who operate or use an AI system. Include occasional users where the risk justifies it.

Match training to context

Separate basic safe-use guidance from role-specific instruction for HR, legal, customer service, developers, procurement and management.

Keep training records

Retain the audience, date, topics, materials, completion evidence and any follow-up testing or policy acknowledgement.

Update after change

Reassess training when a new system, material model update, high-risk use, incident or regulatory guidance changes the risk profile.

The Commission’s AI-literacy Q&A explains that enforcement of Article 4 is handled by national market-surveillance authorities and that there is no one-size-fits-all competence framework. A Romanian business should therefore build a proportionate internal record rather than wait for a template course.

What should employers know about recruitment and workplace AI?

Annex III identifies AI systems intended for recruitment or selection, including targeted job advertising, application analysis and candidate evaluation. It also identifies systems used to make decisions affecting terms of work-related relationships, promotion or termination, allocate tasks based on individual behaviour or personal traits, or monitor and evaluate performance and behaviour.

Under the current Commission timeline, the rules for high-risk systems in these sensitive areas apply from 2 December 2027 following the Digital Omnibus transition. This does not create a compliance holiday. A Romanian employer must still consider GDPR, Romanian labour law, anti-discrimination rules, information duties, collective arrangements, employment records, confidentiality and the possibility of human challenge. A vendor’s score should not become an unexplained substitute for a lawful employment decision.

Before deploying such a tool, the employer should identify who makes the final decision, what the AI output means, whether a person can disregard it, what data is used, whether a candidate or employee can obtain an explanation, and what happens if the system produces an incorrect or discriminatory result. The analysis should also consider whether the foreign group’s HR platform is being deployed by the Romanian entity or merely accessed for central administration.

Separate the dates: the later high-risk deadline concerns the AI Act’s high-risk requirements. It does not suspend GDPR or employment-law obligations that may arise from the same processing or decision today.

Vendor contracts and AI due diligence

A foreign company should not accept a short vendor statement as its entire AI Act file. The contract and due-diligence record should allow the Romanian operation to understand the system’s intended purpose, role allocation, technical limitations, data use, security, logging, human oversight, incident cooperation, transparency features and change-management process.

Purpose and role

Ask whether the supplier is a provider, GPAI provider, importer, distributor or another operator, and whether the Romanian entity is a deployer. Retain the product description, role matrix and contract.

Data and outputs

Check what data is processed, where it is stored, whether prompts or outputs train a model, and whether personal data can be isolated. Keep the data-flow map, DPA and security schedule.

Human oversight

Confirm whether the operator can intervene, override, suspend or test the system and whether those limits are communicated. Keep the operating procedure and testing logs.

Incidents and changes

Agree how model changes, outages, security events and regulatory requests are communicated. Keep notice SLAs, version history and audit rights.

Exit and continuity

Plan how the company will retrieve records, delete data and continue operations if the tool is withdrawn or reclassified. Keep the exit and retention plan.

Where the tool is supplied by a group company, the intercompany agreement should be tested in the same way as an external vendor contract. The Romanian entity may need practical access to information even when procurement, model management and security are centralised abroad.

How does the AI Act interact with GDPR and Romanian employment law?

The AI Act does not replace GDPR. Article 2 expressly preserves the application of Union data-protection, privacy and communications rules. A company may therefore need a lawful basis, purpose limitation, data minimisation, transparency, retention controls, processor arrangements, security measures and, where relevant, a data-protection impact assessment in addition to its AI Act analysis.

Workplace deployment adds another layer. If an AI tool ranks applicants, monitors employees, allocates tasks or recommends termination, the employer should consider the Labour Code, anti-discrimination protections, employee information and consultation, internal policies and the safeguards around automated decision-making. A human reviewer is important, but “human in the loop” is not a complete answer if the reviewer simply approves an unexplained score.

For customer-facing systems, consumer-protection and sectoral obligations may also apply. For regulated products, product-safety rules, conformity assessment and technical documentation may interact with the AI Act. The right approach is a combined compliance map that shows which regime addresses which risk.

AI Act

Classifies the system and creates duties tied to the operator role, risk level, transparency, literacy and governance.

GDPR

Controls personal-data processing, individual rights, security, profiling and the relationship between controller and processor.

Employment and sector law

Protects workers, customers and regulated activities through additional information, fairness, safety and challenge requirements.

Who supervises the AI Act in Romania?

Enforcement is shared. The European Commission’s AI Office supervises general-purpose AI providers and certain connected systems, while national competent authorities supervise other AI systems. The European Data Protection Supervisor has a specific role for systems used by EU institutions. The Romanian entity should monitor the national designation and implementation measures relevant to its activity instead of assuming that every question goes to one central EU authority.

The AI Act also allows complaints, investigations, information requests and other enforcement tools. The applicable authority may consider the nature, gravity and duration of an infringement, affected persons, the operator’s size and turnover, cooperation, responsibility, mitigation and whether the conduct was intentional or negligent.

What penalties can apply?

Article 99 sets maximum levels for several categories, while Member States establish the detailed national penalty and enforcement rules. Non-compliance with prohibited practices can reach up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Other listed operator obligations, including certain deployer and transparency duties, can reach up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Incorrect, incomplete or misleading information supplied to authorities can attract a separate maximum of EUR 7.5 million or 1% of worldwide annual turnover.

For SMEs and start-ups, Article 99 provides a lower-of-the-two limits approach for the amounts or percentages referred to in the provision. The figures are maximums, not automatic fines. Authorities must assess the individual circumstances and procedural safeguards remain relevant. Companies should avoid both extremes: treating the maximum as inevitable or assuming that a small local subsidiary has no exposure because the parent owns the technology.

Practical AI Act compliance checklist for a Romanian operation

01 · InventoryBuild the AI register

List systems, vendors, users, business owners, locations, outputs, affected people and group-company relationships. Include pilots and shadow AI.

02 · ClassifyAssign the legal route

Screen scope, prohibited practices, high-risk categories, transparency duties, GPAI dependencies, sector rules and applicable transition dates.

03 · ControlPut safeguards in place

Set access rules, human review, notices, marking, training, procurement controls, incident escalation and data-protection measures.

04 · EvidenceKeep the decision trail

Retain the classification rationale, vendor file, contract, training evidence, approvals, tests, incidents, changes and review date.

Create an inventory

Owner: Legal, IT, procurement and business owners. Output: an AI register with purpose, provider, deployer, data and affected persons.

Approve use cases

Owner: management with legal and security input. Output: a classification note, prohibited-use sign-off and escalation route.

Train users

Owner: HR, compliance and system owners. Output: role-based AI-literacy materials and completion evidence.

Review public outputs

Owner: marketing, communications and editorial owners. Output: a disclosure, marking and human-review record.

Monitor change

Owner: system owner and vendor manager. Output: version, incident, access, performance and reassessment logs.

Common mistakes made by foreign groups

“The parent handles it”

Central governance can help, but the Romanian operation still needs to know its role, local use, affected people and evidence available to it.

“The vendor is compliant”

Vendor compliance material is an input. It does not answer whether the Romanian entity is a deployer, importer or affected operator in the actual workflow.

“The deadline is 2027”

The later high-risk date does not postpone AI literacy, prohibited-practice controls, transparency duties or GDPR and employment-law analysis.

“A human checked it”

A nominal reviewer may not provide meaningful oversight. Define authority to challenge, override, document and stop the system.

“A footer solves labelling”

Website disclosure, user notice and machine-readable marking answer different questions. Match the control to the content and channel.

“Only official AI tools count”

Shadow AI used with company data can create the same confidentiality, data-protection and output risks as an approved platform.

Frequently asked questions

Does the AI Act apply if our parent company is outside the EU?

It may. Scope can arise because the Romanian entity deploys an AI system in the Union or because output from a third-country system is used in the Union. Analyse the actual provider, deployer, importer and output-use roles.

Are AI recruitment tools high-risk from 2 August 2026?

Not necessarily under the current transition timetable. Annex III includes recruitment and worker-management uses, but the Commission currently identifies 2 December 2027 for the selected sensitive high-risk areas after the Digital Omnibus changes. GDPR, employment and anti-discrimination duties can apply earlier.

Must employees disclose every use of ChatGPT or another writing assistant?

No universal AI Act rule requires disclosure of every private drafting step. The right control depends on the system, output, audience, content type, company policy and whether Article 50 applies. The employer should set a clear internal policy for confidential or regulated material.

Is an AI officer mandatory in Romania?

The AI Act does not impose a universal AI-officer title for every company. A foreign group should nevertheless allocate responsibility for inventory, classification, training, procurement, transparency, incidents and regulatory liaison.

Does using a human reviewer remove AI Act and GDPR risk?

No. Meaningful human oversight can be important, but it does not erase the underlying classification, transparency, data-protection, fairness or employment-law analysis. The reviewer must have information, time and authority to challenge the output.

Can we rely entirely on the AI vendor’s compliance statement?

No. Vendor material should be verified against the Romanian workflow, contract, data, users and role allocation. Keep evidence of the questions asked, the answers received and the decision made by the company.

Need to assess AI use in a Romanian business?

A Romanian business lawyer can help map the group structure, classify AI systems, review vendor terms, align GDPR and employment safeguards, and prepare a proportionate evidence file.

Contact Atrium Romanian Lawyers

This page provides general information only and does not constitute legal advice, a legal opinion or the creation of a lawyer-client relationship. Legal solutions depend on the specific facts, systems, contracts and legislation in force at the relevant time.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.