Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy: AI Compliance Requirements
Lithuania's Valstybinė duomenų apsaugos inspekcija (VDAI) supervises GDPR compliance. Lithuania adopted its AI Strategy in 2019 and has invested heavily in a tech startup ecosystem (Vilnius is the fastest-growing startup hub in the Baltics). Lithuania's National Cybersecurity Centre (NKSC) has published AI security guidelines. Key sectors: fintech (Revolut EU HQ in Vilnius), legal tech, logistics AI.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
May 25, 2018
August 2, 2026
€20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover
What Your Business Must Do
3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
GDPR AI Compliance — VDAI Supervision
CriticalVDAI actively monitors AI data processing. Lithuania hosts major fintech operations (Revolut, Western Union EU processing). AI systems in financial services, credit scoring, and fraud detection processing Lithuanian resident data require DPIA, lawful basis documentation, and automated decision-making rights implementation (GDPR Art. 22).
EU AI Act — Fintech AI High-Risk Obligations
High PriorityLithuanian-regulated fintechs using AI for credit decisions, transaction fraud detection, AML/KYC screening, or customer risk scoring face EU AI Act Annex III high-risk classification. Conformity assessment, technical documentation, and human oversight required. Lithuanian Bank (Lietuvos bankas) has issued supplementary AI governance guidance for supervised entities. NOTE: the "Digital Omnibus" amendment (Regulation (EU) 2026/1744, in force 2026-07-27) deferred stand-alone high-risk (Annex III) conformity obligations from 2026-08-02 to 2027-12-02.
Deadline: December 2, 2027
EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)NKSC AI Cybersecurity Guidelines
Medium PriorityLithuania's National Cybersecurity Centre (NKSC) has published AI security guidelines covering adversarial attacks, model poisoning, and AI supply chain risks. Relevant to any AI system classified as critical infrastructure or handling sensitive personal data. Implement AI-specific security controls: input validation, output monitoring, model versioning, and incident response plans.
Who Does This Apply To?
Applies to: any organisation established in Lithuania, and any organisation outside Lithuania processing the personal data of Lithuanian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. Because Lithuania hosts major fintech operations, AI in credit scoring, transaction fraud detection and AML/KYC is a priority. As an EU member state, Lithuania is fully subject to the EU AI Act: such fintech AI faces Annex III high-risk classification requiring conformity assessment, technical documentation and human oversight. The Valstybinė duomenų apsaugos inspekcija (VDAI) treats AI-driven account restrictions as Article 22 automated decisions with significant effects — requiring a real-time human-escalation path, customer notification, and review of AI-triggered restrictions. The National Cybersecurity Centre (NKSC) AI security guidelines (adversarial attacks, model poisoning, AI supply-chain risk) apply to critical or sensitive-data AI. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.
Recent Regulatory Guidance
VDAI AI and Fintech — Lithuanian Bank AI Governance Guidance (2024)
VDAI and Lietuvos bankas issued joint guidance for Lithuanian fintech AI: (1) AI-driven account restrictions require real-time human escalation path; (2) AML/KYC AI decisions must include customer notification and review mechanism; (3) NKSC AI security guidelines apply to AI systems handling financial data; (4) Cross-border AI data transfers for model training require SCCs + TIA.
Frequently Asked Questions
Does Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy apply to my business?
Lithuania's Valstybinė duomenų apsaugos inspekcija (VDAI) supervises GDPR compliance. Lithuania adopted its AI Strategy in 2019 and has invested heavily in a tech startup ecosystem (Vilnius is the fastest-growing startup hub in the Baltics).… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy is: €20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy?
The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://vdai.lrv.lt/enLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan