Under the approach advanced by VARAM (the Ministry of Environmental Protection and Regional Development) and the Cabinet of Ministers' informative report of 25 February 2025, Latvia has chosen a distributed, or decentralised, model of AI governance and supervision, under which responsibility is divided among several institutions according to their competence. This means Latvia will not have a single central "AI regulator" — supervision of AI systems and compliance control will be carried out through cooperation among multiple authorities.
Key institutions and their roles
| VARAM | The lead institution responsible for coordinating AI Act implementation — national-level coordination and cooperation with the European Commission. |
| DVI (Data State Inspectorate) | Market surveillance functions in relation to prohibited AI practices and certain high-risk systems. The most likely candidate for the single point of contact function under Article 70 of the AI Act. |
| Ministry of Economics and LATAK | The Ministry of Economics will perform the functions of the notifying authority; the Latvian National Accreditation Bureau (LATAK) will act as the national accreditation body — significant roles in conformity assessment and certification processes. |
| Ombudsman | The authority responsible for fundamental rights protection — non-discrimination and public trust. |
| Bank of Latvia | Will supervise compliance with AI Act requirements among the financial institutions it supervises, as well as perform DORA supervisory functions in the financial sector. |
| Sector authorities | PTAC (Consumer Rights Protection Centre), Health Inspectorate, Civil Aviation Agency, Latvian Maritime Administration, State Railway Technical Inspectorate, State Technical Supervision Agency, CSDD (Road Traffic Safety Directorate), IKVD (State Education Quality Service), VDD (State Security Service), MIDD, SAB (Constitution Protection Bureau) — each within its own area of competence. |
At the same time, the future role of the Latvian Artificial Intelligence Centre (MIC) within the formal supervisory architecture is not yet fully clear. MIC is already building competence, fostering innovation, and running the AI Sandbox initiative, but its precise place among the supervisory, coordination, and competence institutions is still taking shape.
What organisations should do today
Organisations should not wait for the regulatory environment to fully stabilise. The institutional structure is already forming, and it is worth assessing early what this model means for a given sector, the AI systems in use, and the data and processes involved. In practice, this means the need to:
- identify the AI systems used within the organisation;
- assess potential risks;
- put data governance processes in order;
- define human oversight mechanisms;
- ensure auditable documentation;
- establish responsibility for the use and governance of AI systems.
The sooner an organisation understands its regulatory environment and begins preparing processes, documentation, and governance mechanisms, the smaller the implementation risks will be in the future.
PPPA's Perspective
Implementing the AI Act is not merely a matter of regulatory compliance. It is an opportunity for organisations to review and modernise their processes.
The more widely AI is used in preparing decisions and automating processes, the more important it becomes to be able to clearly describe, structure, and govern an organisation's processes. For precisely this reason, process algorithmisation, machine-readable processes, and manageable digital workflows are gaining increasing importance.
In the age of AI, the organisations that will be competitive are those able not only to use AI tools, but also to effectively govern the processes, knowledge, and decision-making logic on which those tools rely.
Sources
- VARAM information on Latvia's approach to AI Act implementation
- Cabinet of Ministers' informative report of 25 February 2025