Legal blog

New Decree on the Conformity Assessment of High-Risk AI Systems

2026-01-06 | IT Law

New Decree on the Conformity Assessment of High-Risk AI Systems

1. The Place of the Decree within the Hungarian AI Regulatory Framework

The decree, which enters into force on 23 January 2026, aims to establish detailed rules concerning the designation of bodies responsible for certifying the prior technical conformity of high-risk AI systems. This regulation is directly linked to the domestic implementation of Regulation (EU) 2024/1689 (the AI Act).

In designing the implementation model, the Hungarian legislator relied on existing conformity assessment structures. Accordingly:

  • as a general rule, the designation of conformity assessment bodies is governed by Act CXXXIII of 2009 on the Activities of Conformity Assessment Bodies;

  • the authority responsible for designation is the AI Notifying Authority, which, in this capacity, builds upon existing accreditation and administrative mechanisms.


2. Scope of Application – To Whom and to What Does the Decree Apply?

The scope of the decree expressly covers:

  • conformity assessment bodies responsible for verifying compliance with requirements applicable to high-risk artificial intelligence systems; and

  • the procedure for the designation of such bodies.

It is important to emphasise that the decree does not independently define what qualifies as a high-risk AI system. This continues to be governed by the AI Act and the related body of EU law. The Hungarian implementing decree focuses exclusively on the procedural and institutional framework.


3. Liability Insurance

One of the key provisions of the decree is that it makes liability insurance for conformity assessment bodies an integral part of the accreditation procedure.

This regulatory approach conveys a clear legal policy message: the conformity assessment of high-risk AI systems is an activity involving substantial liability risks, and the legislator therefore requires the existence of adequate financial safeguards.


4. Fees for the Designation Procedure

The decree lays down detailed rules on the administrative service fees payable for the designation procedure, which in practice represent a non-negligible cost factor for conformity assessment bodies.

The fees are as follows:

  • HUF 250,000 per accredited status; and

  • an additional HUF 20,000 for each product group and each conformity assessment procedure (module).

In the case of data modification, a uniform administrative service fee of HUF 20,000 is payable.

The legislation also precisely defines the method and timing of payment, as well as the earmarked use of the fees—the amounts collected may be used exclusively to cover personnel and material costs related to the designation procedure.


5. What Does This Mean for Companies Developing and Deploying AI Systems?

Although the formal addressees of the decree are conformity assessment bodies, its indirect impact on market participants is also significant.

Developers and distributors of high-risk AI systems must take into account that:

  • conformity assessment is conducted within a strictly regulated and institutionalised procedure;

  • only designated and accredited bodies are entitled to certify prior conformity;

  • the costs and duration of such procedures must be factored into project planning in advance.

Accordingly, the decree indirectly encourages undertakings to incorporate legal and compliance considerations into the design of their AI systems already at the development stage.


Our colleagues continuously monitor developments in the legal regulation of artificial intelligence. If you are an AI developer and have questions regarding the legal implications of AI development, please feel free to contact our law firm.

Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services

2026-08-07
Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services

The market of digital finance and crypto-assets is continuously developing, to which domestic legislation must also dynamically adapt. Act XXXVIII of 2026 on the Repeal of Certain Statutory Provisions Concerning Crypto-Asset Conversion Services, entering into force on 7 August 2026, constitutes a significant milestone in this doctrinal field.

The focus of the legislation is the phasing out of the previously introduced validation obligation, as well as the termination of the related criminal law and administrative authority proceedings, the purpose of which is to establish uniform regulation and to create the conditions for customers to use services in a safe and transparent manner.

Read more

Changes to the Rules on the Authorisation of Crypto-Asset Service Providers in Hungary

2026-08-06
Changes to the  Rules on the Authorisation of Crypto-Asset Service Providers in Hungary

On 2 August 2026, Decree No. 7/2026 (VII. 30.) of the Supervisory Authority for Regulatory Affairs (SZTFH)entered into force. The Decree lays down the detailed rules governing the authorisation and registration of crypto-asset service providers engaged in crypto-asset exchange validation activities. At the same time, it repeals the previously applicable SZTFH Decrees No. 10/2025 (VI. 26.) and No. 12/2025 (VI. 26.), which regulated the same subject matter.

The primary objective of the new Decree is to align the Hungarian regulatory framework with the European Union's legal framework governing crypto-assets while ensuring a more coherent and transparent system for the authorisation and supervision of service providers operating in this sector.

Read more

New regulation on cybersecurity auditors and vulnerability assessors (Decree No. 6/2026. (VI. 8.) SZTFH)

2026-06-18
New regulation on cybersecurity auditors and vulnerability assessors (Decree No. 6/2026. (VI. 8.) SZTFH)

The President of the Supervisory Authority for Regulated Activities (SZTFH) has issued Decree No. 6/2026. (VI. 8.) SZTFH, which comprehensively amends certain decrees on the subject of cybersecurity. The explicit intention of the legislator is to ease the situation of enterprises, significantly reduce administrative burdens, and promote market competition in the information technology security sector.

Read more