Malta AI and Regulation Brief · Edition 1
The EU AI Act is applying. Most operators have not noticed.
One email a month on what actually changed for Malta operators, in plain English, and what it means for how you run the place. September 2026.
The one thing to know this month
The EU AI Act's main obligations started applying on 2 August 2026.
Not proposed, not upcoming. Applying. If your business uses an AI system in its operations, most of the Act's general provisions now apply to you, and the transitional grace has largely gone.
Here is the distinction that decides how much of this is your problem: the Act separates providers, who build AI systems, from deployers, who use them. Almost every Malta operator is a deployer. That is the lighter position, but it is not an empty one. Deployers carry obligations around how a system is used, overseen and disclosed.
The practical step, before anything else: work out which role you are in and what risk category your use falls into. The Malta Digital Innovation Authority publishes two free self-assessment tools built for exactly this, the AI Classification Guide and the AI Compliance Role Finder. They exist so you do not have to pay someone to tell you which category you are in. Start there.
Sources: EU AI Act implementation timeline (independent tracker, last updated 31 August 2026); MDIA EU AI Act Self-Assessment Tools
Malta's regulators, what moved
IDPC: flagged the AI Act timelines, and it is a market surveillance authority
On 27 July 2026, the Information and Data Protection Commissioner formally drew attention to the AI Act timelines. This matters more than a routine notice, because the IDPC is Malta's Market Surveillance Authority for high-risk AI systems in law enforcement, migration and border control, and justice and democracy. In plain terms: for those categories, the IDPC is the body that will come and look.
Two more items from the IDPC this summer:
- 19 August 2026: the IDPC published its 2025 Annual Report covering regulatory work and enforcement activity. If you want to know what the data protection authority actually spent its year doing, it is there.
- 6 August 2026: the IDPC's AI Regulatory Manager sat on panels at an AI Act conference hosted by the MDIA. Read that as a signal: the data protection regulator and the digital innovation authority are coordinating on AI, not working in separate rooms.
Source: IDPC
MGA: the regulator has told the sector its audit trails are weak
On 29 July 2026, the Malta Gaming Authority published the findings of its Thematic Review on Governance Assurance, Key Functions. Across the sector it identified three common themes:
over-reliance on a limited number of senior decision-makers, insufficient evidence of challenge and impact assessment in strategic decision-making, and weaknesses in audit trails
What it means operationally. None of the three is a technology finding. The first means a process lives in someone's head. The second means decisions happen but the reasoning is not recorded. The third means nobody can reconstruct what happened six months later. All three are fixed by the same discipline: write the process down, agree one way of doing it, and make your systems record what they did while they did it.
Also from the MGA:
- Its 2025 Annual Report, published 7 July 2026, records 38 new licence applications and 19 licences issued in the year. Read that as a mature market: the change is happening inside the installed base, not among new entrants.
- Its published 2026 supervisory focus areas include internal controls around cash and crypto assets, operational resilience in IT, governance of key functions, player protection detection systems, and operator monthly ADR reporting. Every one of those is a process that must run consistently and prove it ran.
If you are thinking of using an outside provider for anything, read the MGA's Policy on Outsourcing by Authorised Persons first. Certain arrangements are classified as Material, including customer due diligence, player identity verification, fraud management and player funds. Where an arrangement is material, you need a named employee with enough knowledge of the outsourced service to challenge its performance, notified to the Authority, and contractual terms covering sub-contracting, change of ownership and exit. Starting in the internal back office, reporting and evidence assembly, gets you the benefit without triggering the material path on day one.
Sources: Thematic Review findings, 29 July 2026; 2025 Annual Report; Regulatory Oversight 2026; Policy on Outsourcing
MFSA: checked, nothing operational to report this month
I reviewed the MFSA's news and circulars pages. I did not identify a circular this month that changes an operational process for a typical operator. That is a finding, not an omission. When one lands, it will be here.
Source: MFSA circulars
Malta Enterprise: could not be checked this month
The Malta Enterprise site is behind bot protection that my research tooling correctly refuses to defeat. I will not report funding scheme terms I have not read. If you are considering a scheme, read the eligibility conditions on their site directly, and treat any summary, including one from me, as a pointer rather than a promise.
Deadline ahead: 2 December 2026
If your business uses AI to generate content shown to customers, audio, images, video or text, and that system was already in use before 2 August 2026, the transparency obligations in Article 50(2) of the AI Act must be met by 2 December 2026. In plain English: AI-generated content has to be identifiable as such. Three months from now. Worth putting in the diary.
Source: EU AI Act implementation timeline
One practical example, with the numbers
A service business here was losing enquiries it had no way of seeing. Not complaints. Calls that rang out while the team was with a customer. A call that never connects leaves no record anywhere, so it never appeared in a report and nobody had ever put a number on it.
We made it visible first, then followed up. Over six weeks: 369 missed callers, all contacted. 156 came back and booked, a 42% conversion among people who had already given up.
Worth 22,344 euro. The full booked value was 29,357. I quote the lower figure because it strips out the single largest booking, and one fortunate client is not a business case.
The connection to everything above: the fix was not clever technology. It was making an invisible process visible, then recording what happened. That is the same discipline the MGA is asking for. Governance and revenue turn out to be the same habit.
What I would do this month, in order
- Run the MDIA's two self-assessment tools. Twenty minutes. Know which AI Act role you are in.
- Pick one process your regulator has named in its focus areas and ask: could I reconstruct, from records alone, what happened in it last Tuesday?
- If you generate any customer-facing content with AI, put 2 December in the diary.
Reply to this email with the process that eats most of your time. That is the only question I ask, and the answer in your own words is worth more than any form.
Younes Boujoudar, AI and Automation Specialist and Kaizen Consultant, Kaizen Institute yboujoudar@kaizen.com
Not legal or compliance advice. This brief reports what regulators and agencies have published, with a link to every source. Confirm anything you act on with your own advisers and against the published text.
Next edition, October
Get it the day it goes out.
Answer three questions and the brief comes to you monthly, with the process that eats your time noted so the reply is relevant.
Answer three questions