Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

EU AI Act compliance in Bulgaria: who is in scope and what is owed

How EU AI Act applies to companies operating in or serving Bulgaria — scope tests, the obligations that follow, and the primary sources to verify each one against.

The EU Artificial Intelligence Act applies to organisations established in Bulgaria as well as entities outside Bulgaria whose AI systems' output is used within the European Union. Oversight is coordinated across Member States via the European AI Office and national market surveillance authorities. Regulated entities must determine whether their activities fall under provider, deployer, or importer roles to establish exact compliance duties.

Extraterritorial Scope and Market Reach in Bulgaria

The regulation applies to providers placing AI systems on the market or putting them into service within the Union, regardless of whether those providers are established within the EU or in a third country. For organisations operating in Bulgaria, this means local entities developing AI, as well as foreign vendors selling into the Bulgarian market, must assess their operational footprint. When an AI system is deployed within Bulgaria and its output is used in the EU, the framework applies directly to the deployer or provider involved.

Organisations must examine their supply chains to identify if they act as an /guides/eu-ai-act-compliance-guide subject or an intermediary. The legislation sets out clear jurisdictional triggers based on where the provider or deployer is established or where the system's output has an effect. European market surveillance authorities enforce these provisions across all Member States.

Entities that place general-purpose AI models on the market face specific rules regardless of their establishment location. If a model presents systemic risk, distinct obligations apply under the oversight of the European Commission. Bulgarian businesses integrating these foundational models into their own commercial applications must verify compliance status with their upstream suppliers using resources like /guides/ai-vendor-due-diligence-guide.

Market participants should review the primary legal text in Regulation (EU) 2024/1689 (EU AI Act) — full text to verify exact definitions of placing on the market and putting into service. National competent authorities in Bulgaria hold enforcement powers to inspect documentation, demand access to datasets, and execute market surveillance protocols.

Categorising AI Systems Under Annex III and General-Purpose Rules

Classification under the regulatory framework dictates the strictness of the governance requirements. Systems listed in /guides/eu-ai-act-high-risk-ai-systems-guide face rigorous mandatory requirements covering data governance, technical documentation, transparency, human oversight, and robustness. These high-risk categories include critical infrastructure, education, employment, essential services, law enforcement, and migration management.

Organisations must map their inventory against EU AI Act Annex III — high-risk AI systems to determine if their specific use cases trigger high-risk classification. If a system modifies its behavior or is deployed in sensitive domains, the classification may change, necessitating a re-evaluation of technical files and risk management systems.

In parallel, models meeting the definition of /glossary/general-purpose-ai-model are subject to baseline transparency requirements, while those exhibiting high-impact capabilities categorized as /glossary/systemic-risk-gpai must adhere to adversarial testing, evaluation, and serious incident reporting. Developers operating in Bulgaria must distinguish between standard machine learning deployments and foundational models.

The regulatory framework also sets strict prohibitions on specific /glossary/prohibited-ai-practice applications, such as biometric categorization systems that infer sensitive traits or social scoring. Entities must screen all internal and external AI use cases against these absolute prohibitions before initiating deployment.

Provider, Deployer, and Importer Obligations

The statute imposes distinct responsibilities depending on an organisation's economic role in the AI supply chain. An /glossary/ai-provider bears the primary responsibility for conformity assessments, establishing quality management systems, and maintaining technical documentation. When an entity in Bulgaria places its own brand on an AI system developed elsewhere, it assumes provider responsibilities under the law.

Conversely, an /glossary/ai-deployer uses the AI system under its authority, except when the system is used for personal non-professional activity. Deployers must ensure human oversight, monitor system operation, and inform natural persons where required by transparency provisions. They must also keep logs generated by the high-risk systems under their control.

The following table outlines the core operational duties across different market roles:

| Economic Role | Primary Duty | Reference Tool or Guide | |---|---|---| | Provider | Conduct /glossary/conformity-assessment | /tools/obligation-extractor | | Deployer | Maintain /glossary/post-market-monitoring inputs | /tools/ai-policy-generator | | Importer | Verify CE marking and documentation | /guides/ai-governance-framework-guide |

Importers and distributors verify that the provider has fulfilled its obligations, including drawing up /glossary/technical-documentation-annex-iv and affixing the CE marking. Each actor in the chain must cooperate with national competent authorities upon request.

Documenting Compliance and Establishing Governance Frameworks

Demonstrating alignment with the rules requires structured internal processes and verifiable audit trails. Organisations in Bulgaria should build governance structures that integrate technical documentation practices directly into their software development life cycles. Maintaining comprehensive records allows internal compliance teams and external auditors to inspect risk management policies, training data provenance, and testing outcomes.

Deployers and providers utilize compliance tooling to track obligations and map system architectures against regulatory thresholds. Teams can leverage /tools/obligation-extractor to parse statutory duties into actionable engineering tasks. Policies must be regularly updated to reflect changes in model architecture or intended deployment context.

External supervisory bodies examine whether technical files adequately describe system design, development processes, and validation methods. Establishing a repeatable review cycle ensures that documentation remains current throughout the operational lifecycle of the AI system, supporting ongoing /glossary/post-market-monitoring obligations.

Guidance documents published by European regulators, such as those found via EDPB — published documents, offer parallel data protection perspectives that intersect with AI governance. Legal and technical teams should review these materials alongside the primary legislative text to ensure cohesive implementation.

Supervision, Enforcement, and Market Surveillance in Bulgaria

Market surveillance authorities designated within Bulgaria monitor compliance with the regulation and investigate potential violations. These national authorities possess statutory powers to demand documentation, access source code under specific conditions, and order the withdrawal or recall of non-compliant AI systems from the market. Cooperation with these bodies is mandatory for all economic operators established or operating within the country.

At the Union level, the European Artificial Intelligence Office coordinates enforcement, particularly concerning general-purpose AI models and systemic risks. The European Commission outlines the overarching structure via European Commission — regulatory framework for AI, detailing how supervisory duties are distributed between national regulators and EU-level institutions.

Organisations facing inquiries from Bulgarian market surveillance authorities must present verified conformity records and technical dossiers upon request. Non-compliance can lead to substantial financial sanctions and operational restrictions. Compliance teams should maintain an active repository of all regulatory correspondence and audit reports to demonstrate diligence.

To prepare for potential enforcement actions, entities establish internal escalation pathways and incident reporting protocols. When a serious incident occurs, providers and deployers must notify the relevant market surveillance authorities without undue delay, outlining the nature of the malfunction and corrective actions taken.

Related on BizLegal

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does the EU AI Act apply to companies located in Bulgaria that build AI for export outside the EU?

The regulation applies if the AI system is placed on the market or put into service within the European Union, or if its output is used within the EU. Exporting systems entirely outside the EU without deployment or use inside the Union falls outside the scope, but jurisdictional triggers must be evaluated carefully against actual system usage.

What is the primary difference between a provider and a deployer under the regulation?

A provider develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority in the course of a professional activity, except when the system is used for personal non-professional tasks.

How do Bulgarian companies determine if their AI system is classified as high-risk?

Organisations must check whether their AI system is used as a safety component of a product subject to specific harmonization legislation, or if the use case falls squarely within the critical domains enumerated in Annex III of the regulation.

What documentation must be maintained for high-risk AI systems?

Providers of high-risk systems must draw up extensive technical documentation demonstrating conformity with all mandatory requirements, including detailed descriptions of the system architecture, training methodologies, data governance practices, and risk management systems.

Which authorities oversee compliance in Bulgaria?

Market surveillance authorities designated by the Member State oversee local enforcement, while the European AI Office supervises general-purpose AI models and systemic risks at the EU level. National regulators hold powers to inspect records and order market withdrawals.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-05.

Contact