{"id":145830,"date":"2026-08-12T09:19:08","date_gmt":"2026-08-12T09:19:08","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=145830"},"modified":"2026-08-14T15:30:45","modified_gmt":"2026-08-14T15:30:45","slug":"greece-artificial-intelligence","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/greece-artificial-intelligence\/","title":{"rendered":"Greece: Artificial Intelligence"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-145830","comparative_guide","type-comparative_guide","status-publish","hentry","guides-artificial-intelligence","jurisdictions-greece"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Nikolinakos &amp; Partners Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2020\/07\/Logo-Nikolinakos-Partners-Law-Firm.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Nikolinakos &amp; Partners Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2020\/07\/Logo-Nikolinakos-Partners-Law-Firm.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of Artificial Intelligence laws and regulations applicable in Greece<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What is the legal definition of \u201cartificial intelligence\u201d in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Greek legislation does not provide a definition for the term \u201cartificial intelligence\u201d. However, the definition given in the European AI Act Regulation 2024\/1689 for AI systems is accepted, according to which an \u201cAI system\u201d means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Greece has developed a national policy framework for artificial intelligence, evolving in stages. AI was initially incorporated into the <em>Digital Transformation Bible 2020\u20132025<\/em>.<\/p>\n<p>The framework was further developed in November 2024 with <em>A Blueprint for Greece\u2019s AI Transformation<\/em>, prepared by the government\u2019s High-Level Advisory Committee on AI. It serves as the main strategic roadmap, focusing on innovation and entrepreneurship, education and research, regulation and governance, and AI deployment in the public sector, alongside flagship projects for implementation.<\/p>\n<p>Implementation is under way, with key measures including:<\/p>\n<ul>\n<li>the deployment and expansion of mAigov, the generative-AI assistant on gov.gr;<\/li>\n<li>the establishment of Pharos, the Greek AI Factory, supporting research, start-ups, public bodies and industry;<\/li>\n<li>the development of the DAEDALUS supercomputer, providing core high-performance computing infrastructure; and<\/li>\n<li>the creation, in January 2026, of a Special Secretariat for Artificial Intelligence and Data Governance.<\/li>\n<\/ul>\n<p>Implementation is increasingly aligned with the EU Artificial Intelligence Act. Greece has taken initial steps, including identifying competent authorities and introducing, in July 2026, a bill establishing the national framework for the AI Act\u2019s application and enforcement, based on its risk-based approach.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be\/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p><strong><u>Law 4961\/2022<\/u><\/strong> introduces inter alia a national framework for regulating AI technologies, imposing the following obligations:<\/p>\n<p>A. Public Entities<\/p>\n<ul>\n<li>Algorithmic Impact Assessment: in addition to a GDPR impact assessment, entities must prepare an algorithmic impact assessment evaluating risks to the rights, freedoms and legitimate interests of affected individuals. Safeguards to be specified by Presidential Decree.<\/li>\n<li>Transparency of Operation: public entities must provide information on the AI system, including start time, operational parameters and decisions made or supported by it. Complaints regarding transparency violations are examined by the National Transparency Authority.<\/li>\n<li>AI System Register: public entities must maintain a register of the AI systems they use.<\/li>\n<\/ul>\n<p>B. Private Entities<\/p>\n<ul>\n<li>AI in Employment: before using an AI system affecting decision-making on employees or applicants (working conditions, selection, hiring, evaluation), enterprises must inform employees. This extends to digital platforms with contracts of dependent work, independent services or projects. Employers must also conduct an impact assessment, with sanctions for non-compliance imposed by the Hellenic Labour Inspectorate.<\/li>\n<li>Ethical Use of Data: medium or large private entities (per Art. 2 of Law 4308\/2014) must adopt a data ethics policy; entities preparing a corporate governance statement under Art. 152 of Law 4548\/2018 must include information on it. Content to be specified by Joint Ministerial Decision.<\/li>\n<li>Registry of AI Systems: medium or large private entities must maintain a register of the AI systems they use.<\/li>\n<li>Public Contracts: contracts for AI design or development must oblige the contractor to (1) provide the contracting authority with information ensuring transparent operation, subject to military, commercial and industrial secrecy; (2) deliver the system under conditions allowing the authority to study its functionality and parameters, make improvements, and publish or distribute them; and (3) ensure compliance with the legal framework, particularly human dignity, privacy and data protection, non-discrimination, gender equality, freedom of expression, accessibility for persons with disabilities, employee rights and good governance.<\/li>\n<\/ul>\n<p>The provisions of Law 4961\/2022 do not affect rights and obligations under the GDPR and its implementing Law 4624\/2019. Law 4961\/2022 predates the AI Act and remains in force; although the AI Act prevails under the primacy principle, the national law is not repealed and retains significance for obligations with no AI Act equivalent (notably the employer-disclosure duties and the registry requirements).<\/p>\n<p><strong><u>The AI Act<\/u><\/strong> (Regulation (EU) 2024\/1689), published 12 July 2024, is binding and directly applicable in Greece on its staggered timeline (prohibitions and AI-literacy duties from 2 February 2025; GPAI and governance from 2 August 2025; most high-risk requirements from 2 August 2026). It adopts a risk-based approach, dividing systems into unacceptable (prohibited), high (subject to specific requirements), and low or minimal risk (fewer or no requirements), with specific rules for general-purpose AI.<\/p>\n<p>Each Member State had to designate at least one notifying authority and one market surveillance authority by 2 August 2025. Greece effects this through a <strong><u>draft implementing law<\/u><\/strong><u>, &#8220;Measures for the Implementation of Regulation (EU) 2024\/1689 and Amendment of Law 4961\/2022,&#8221;<\/u> which went to public consultation from 21 June to 6 July 2026. It designates the Hellenic Data Protection Authority (HDPA) as the central market surveillance authority and single point of contact, and the Hellenic Telecommunications and Post Commission (EETT) as the notifying authority. It also establishes an Artificial Intelligence Coordination and Expertise Centre, a regulatory sandbox for start-ups and SMEs, a central registry for public-sector AI systems, an AI Observatory, and a national enforcement regime. As it remains in consultation, provisions may change before adoption.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers\/clients?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Particularly, law 4961\/2022 introduced sector-specific transparency obligations regarding the use of AI systems.<\/p>\n<p>Public sector. Public sector entities using AI systems must provide information regarding the operation of the system, including its purpose, the time of operation, the operational parameters and whether decisions are made or supported by the AI system. Complaints concerning breaches of these transparency obligations fall within the competence of the National Transparency Authority.<\/p>\n<p>Private sector. In the private sector, employers using AI systems that affect decisions relating to recruitment, selection, working conditions, evaluation or promotion must inform employees or job applicants before the system is first used and carry out an impact assessment to safeguard their rights. Law 4961\/2022 further provides that medium and large private entities shall adopt a data ethics policy regarding the use of AI systems and maintain a register of the AI systems they use. However, certain aspects of these obligations remain subject to the issuance of the ministerial acts provided for by the Law.<\/p>\n<p>Where AI systems involve the processing of personal data, the GDPR and Law 4624\/2019 continue to apply. Controllers must comply with the transparency requirements of the GDPR, while Article 22 GDPR grants individuals the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal effects or similarly significantly affect them.<\/p>\n<p>The AI Act introduces additional transparency obligations applicable in Greece. In particular, persons must be informed when interacting with certain AI systems, unless this is obvious from the circumstances. Specific transparency obligations also apply to emotion recognition and biometric categorisation systems and to AI-generated or manipulated content, including deepfakes. In addition, high-risk AI systems are subject to documentation, record-keeping, logging and human oversight requirements, which contribute to the explainability, traceability and auditability of such systems. However, the AI Act does not impose a general obligation to disclose the use of AI to customers or clients in all circumstances; disclosure is required only in the cases expressly provided for by the Regulation.<\/p>\n<p>Finally, the draft law implementing the AI Act, as recently submitted to the Hellenic Parliament, proposes the establishment of the national supervisory and enforcement framework for the AI Act, including the designation of the competent authorities, the creation of a centralised complaints mechanism and amendments to certain provisions of Law 4961\/2022. As the draft law has not yet been enacted, these provisions are not yet in force.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the current national legal framework, Law 4961\/2022 establishes sector-specific safeguards aimed at ensuring appropriate human oversight over the use of AI systems. In particular, private sector employers using AI systems that affect decision-making processes relating to employees or job applicants, including recruitment, selection, evaluation or working conditions, must inform the affected individuals before the system is first used and conduct an impact assessment to safeguard their rights. Although Law 4961\/2022 does not establish a general &#8220;human-in-the-loop&#8221; obligation applicable to all AI systems, it reflects the principle that AI-assisted decision-making should remain subject to meaningful human oversight where individuals&#8217; rights may be affected.<\/p>\n<p>Where AI systems process personal data, the General Data Protection Regulation (GDPR) and its implementing Law 4624\/2019 also apply. In particular, Article 22 GDPR provides that individuals have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal effects or similarly significantly affect them, unless one of the exceptions provided by the GDPR applies. In such cases, data subjects must be afforded appropriate safeguards, including the right to obtain human intervention, express their point of view and contest the decision.<\/p>\n<p>The AI Act further reinforces these safeguards by requiring high-risk AI systems to be designed and developed in a manner that enables effective human oversight throughout their lifecycle. Providers must incorporate appropriate human oversight measures into such systems, while deployers must ensure that high-risk AI systems are used under the supervision of natural persons with the necessary competence, training and authority to monitor their operation, correctly interpret their outputs and intervene where necessary to prevent or minimise risks to health, safety or fundamental rights.<\/p>\n<p>The draft law further complements the existing framework by establishing the national institutional and supervisory framework for the implementation of the AI Act. Although it does not introduce additional substantive requirements regarding human oversight, it reinforces the enforcement of the AI Act through the designation of the competent authorities, the establishment of an AI Coordination and Expertise Centre and an AI Regulatory Sandbox, which are expected to support the consistent application of the human oversight requirements laid down in the AI Act. As the draft law has not yet been enacted, these provisions are not yet in force.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under the current national legal framework, Law 4961\/2022 contains specific safeguards intended to prevent discriminatory or unfair outcomes resulting from the use of AI systems in the employment context. In particular, employers using AI systems that affect decisions concerning employees or job applicants, including recruitment, selection, evaluation or working conditions, must inform the affected individuals before the system is first used. The information provided must include, at a minimum, the parameters on which the decision is based, while the use of such systems must comply with the principles of equal treatment and non-discrimination in employment. The provision expressly refers to protected characteristics including gender, race, colour, ethnic origin, religion or beliefs, disability or chronic condition, age, family or social status, sexual orientation, gender identity and gender characteristics.<\/p>\n<p>More generally, the prohibition of discrimination under Law 4443\/2016 on equal treatment, as well as the relevant provisions of Greek labour legislation, continue to apply where AI systems are used in employment or other decision-making processes. Where AI systems involve the processing of personal data, the General Data Protection Regulation (GDPR) and its implementing Law 4624\/2019 also apply. Controllers must comply with the principles of lawfulness, fairness, transparency, purpose limitation and data minimisation, while Article 22 GDPR provides safeguards against decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects.<\/p>\n<p>The AI Act further strengthens this framework by requiring providers of high-risk AI systems to establish risk management and data governance measures designed to identify, prevent and mitigate risks to health, safety and fundamental rights, including discriminatory outcomes arising from biased datasets or the operation of AI systems. High-risk AI systems must also comply with requirements relating to data quality, technical documentation, record-keeping, human oversight, accuracy, robustness and cybersecurity.<\/p>\n<p>The draft law complements this framework by establishing the national supervisory and enforcement mechanisms for the application of the AI Act in Greece. In particular, it designates the competent authorities responsible for supervising compliance with the AI Act, including its provisions on high-risk AI systems and the protection of fundamental rights, while also strengthening institutional oversight through the establishment of an AI Coordination and Expertise Centre and an AI Regulatory Sandbox. As the draft law has not yet entered into force, these provisions are not yet applicable.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Greek law does not currently establish a specific civil liability regime for damage caused by artificial intelligence systems. Accordingly, liability arising from AI-related harm is assessed under the existing rules on product liability, contractual and tort liability, as well as data protection law, depending on the nature of the damage and the legal relationship between the parties.<\/p>\n<p>Where an AI system qualifies as a product, liability for defective products is primarily governed by the Consumer Protection Law (Law 2251\/1994), which implements the existing EU product liability framework. Under this regime, producers are subject to strict liability for damage caused by defective products, provided that the injured party proves the defect, the damage suffered and the causal link between the defect and the damage. Proof of fault is not required. Depending on the circumstances of the case and the role of each actor in the supply chain, liability may also extend to importers, distributors or other economic operators where the conditions laid down in the applicable legislation are satisfied.<\/p>\n<p>Outside the product liability regime, AI-related harm may also give rise to contractual or tort liability under the Greek Civil Code. In such cases, developers, deployers, operators or other persons involved in the design, deployment or use of an AI system may be held liable where the applicable conditions for contractual or tort liability are met. Liability is allocated according to the general principles of Greek civil law and depends on the conduct of each party, the existence of fault where required, the contractual relationship between the parties and the causal link between the conduct and the damage suffered. In principle, the burden of proving the unlawful act or omission, the damage and the causal link rests with the claimant.<\/p>\n<p>Where AI systems involve the unlawful processing of personal data, the General Data Protection Regulation (GDPR) and its implementing Law 4624\/2019 also apply. Controllers and processors may incur liability for infringements of the GDPR, while data subjects are entitled to compensation for material or non-material damage in accordance with Article 82 GDPR.<\/p>\n<p>At EU level, Directive (EU) 2024\/2853 introduces a revised product liability framework, expressly extending the notion of &#8220;product&#8221; to software and adapting the liability regime to digital technologies, including AI-enabled products. The Directive also introduces important changes regarding the disclosure of evidence and the burden of proof in technically complex cases. However, it has not yet been transposed into Greek law, and the current product liability regime under Law 2251\/1994 continues to apply. It should also be noted that no AI-specific civil liability regime currently exists at EU level following the withdrawal of the proposed AI Liability Directive.<\/p>\n<p>The AI Act does not establish a civil liability regime or regulate compensation claims for AI-related harm. Instead, it lays down obligations for providers, deployers and other relevant operators concerning the design, development, placing on the market, putting into service and use of AI systems. Failure to comply with those obligations may be taken into account when assessing liability under the applicable civil, consumer protection or data protection framework.<\/p>\n<p>Finally, the draft law complements this framework by establishing the national supervisory and enforcement mechanisms for the application of the AI Act in Greece. While it does not introduce a separate civil liability regime, it designates the competent supervisory authorities, lays down the national enforcement framework and administrative sanctions for infringements of the AI Act, and amends certain provisions of Law 4961\/2022.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What cybersecurity obligations apply to AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The growing deployment of artificial intelligence across all layers of information and communication technology (ICT)\u00a0\u00a0 infrastructure has significantly increased the relevance of the EU&#8217;s horizontal cybersecurity framework to AI systems. In Greece, Joint Ministerial Decision No. 1689\/2025, adopted pursuant to Law 5160\/2024 implementing the NIS2 Directive, establishes an extensive cybersecurity compliance regime. The framework encompasses, inter alia, ICT risk assessment and risk management procedures, supply chain security requirements, internal governance policies and processes, as well as audit and oversight mechanisms.<\/p>\n<p>Entities falling within the scope of the NIS2 regime under Article 7 of Law 5160\/2024, together with public sector bodies subject to Article 18 of Law 4961\/2022, are further required to appoint an Information Technology Systems and Communications Security Officer. This function serves as the internal officer responsible for overseeing and monitoring compliance with cybersecurity obligations.<\/p>\n<p>An important innovation introduced by Law 5160\/2024 concerns corporate governance. The legislation requires the management body to approve the organisation&#8217;s cybersecurity risk management measures at the policy level and introduces the possibility of personal liability for members of management in cases of non-compliance. This governance model has elevated cybersecurity from a predominantly technical matter to a board-level compliance priority, attracting increased attention from senior management and corporate directors.<\/p>\n<p>Against this regulatory background, Article 15 of the AI Act imposes additional cybersecurity obligations on providers of high-risk AI systems by requiring them to ensure an appropriate level of protection throughout the system&#8217;s lifecycle, including resilience against adversarial manipulation, data poisoning attacks, and model extraction techniques. These requirements operate cumulatively with, rather than as a substitute for, the obligations arising under NIS2 and, where applicable, DORA. The interaction between these regimes is particularly significant for regulated entities that are subject to cybersecurity governance and supply chain oversight requirements, as well as for economic operators that assume the status of provider pursuant to Article 25 of the AI Act.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Is the use of artificial intelligence insured and\/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The use of artificial intelligence (AI) in Greece is not currently governed by a specific insurance framework, but in principle, it is both insurable and increasingly being covered through existing types of insurance, depending on the context and associated risks, such as general civil liability insurance. Cyber insurance is increasingly relevant where AI systems are exposed to cybersecurity threats or are deployed within critical ICT environments. Although policies available on the Greek market generally do not provide AI-specific coverage, they may respond to losses arising from cyber incidents involving AI systems, such as unauthorised access, data breaches, ransomware attacks, business interruption, or network security failures, provided that the event falls within the scope of the policy and is not excluded. Coverage remains highly dependent on the contractual terms and applicable exclusions.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No. According to Greek patent law \u039d\u03bf.1733\/1987, an inventor can only be human. According to Article 6 of the above law, the person applying for a patent is considered to be an inventor. \u0391lthough in many countries this issue has been a subject of debate, for the time being in Greece, AI cannot be considered an inventor.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Do images or works generated by and\/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is currently no specific legislation or case law addressing the issue of copyright protection for AI generated images. However, the Greek copyright law No. 2121\/1993 generally accepts only natural persons as authors.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>When using artificial intelligence (AI) systems in the workplace, several key issues need to be considered to ensure ethical, legal, and effective implementation. AI raises important risks in terms of:<\/p>\n<ul>\n<li>Biases: AI systems can produce decisions that reproduce prohibited discrimination, biases and prejudice.<\/li>\n<li>Privacy: AI systems used by employers to make decisions about employees\u2019 personal data. Consequently, the principles established by the GDPR, such as purpose limitation, transparency, and legitimate basis for processing, must be followed. Employees can also exercise all rights granted under the GDPR and Greek Law 4624\/2019, such as the right to be informed about what AI tools are being used by the employer and how their data are being processed by these tools. Moreover, Article 22 of the GDPR applies in this context, granting employees the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect them.<\/li>\n<\/ul>\n<p>According to article 9 of the Law 4961\/2022 any private sector business that uses an artificial intelligence system affecting any decision-making process regarding employees or job applicants, and impacts working conditions, selection, hiring, or evaluation, must provide sufficient and clear information to each employee or job applicant before its first use. This information should at least include the parameters on which the decision is based, subject to cases requiring prior notification and consultation, and ensure compliance with the principles of equal treatment and anti-discrimination in employment and work due to gender, race, color, national or ethnic origin, genetic background, religious or other beliefs, disability or chronic condition, age, family or social status, sexual orientation, gender identity, or characteristics.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main privacy\/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The development and use of Artificial Intelligence (AI) systems\u2014particularly during the training phase, but also throughout their deployment\u2014raises significant concerns regarding the protection of personal data. One of the primary issues is the lack of transparency. Often, data subjects are unaware that they are being subjected to automated processing or decision-making by algorithms. Even when such processing is disclosed, the information provided is often insufficient or too technical to offer a clear understanding of the &#8220;logic&#8221; of the system, the significance of the outcomes, or the potential consequences. This lack of clarity severely hinders the exercise of fundamental rights, such as access, objection, and rectification.<\/p>\n<p>Furthermore, AI systems rely heavily on the processing of vast amounts of data, which conflicts with the principle of data minimization. The constant demand for more and more information\u2014commonly referred to as &#8220;data bulimia&#8221;\u2014intensifies the risk of excessive data collection and processing. In many cases, the data used are not entirely accurate, and the AI models themselves may produce conclusions or predictions that are biased, unfair, or simply incorrect. Using data for purposes beyond those initially specified represents a serious threat to the principle of purpose limitation. This challenge is further compounded when systems generate new information or profiles through algorithmic processes, often without the individual&#8217;s prior consent and without clear oversight regarding the final use of that data.<\/p>\n<p>Regarding the legal basis for processing personal data through AI, this may be established on grounds such as contractual necessity, legitimate interest, or public interest\u2014provided that meaningful human intervention in automated decisions is ensured. Special attention must be given to consent, which is frequently cited as a lawful basis but faces practical limitations: for consent to be valid, it must be freely given, explicit, specific, and informed\u2014conditions that are rarely met adequately in the context of complex and opaque AI systems.<\/p>\n<p>In conclusion, the particular nature of AI systems calls for a reassessment and strengthening of privacy safeguards, in order to ensure the effective protection of personal data in an increasingly complex and evolving technological landscape.<\/p>\n<p>Guidelines and rulings. At national level, the HDPA has not issued a dedicated general guideline on AI, but has addressed it through case-specific opinions. Opinion 9\/2026 (July 2026) on Greece\u2019s draft AI Act implementation law welcomes HDPA\u2019s designation as market surveillance authority for prohibited practices, high-risk systems, and transparency obligations, but stresses this requires adequate staffing\/funding; otherwise the new mandate could undermine both new and existing functions. It recommends staffing exemptions, special allowances, and faster recruitment.<\/p>\n<p>Opinion 8\/2026 (June 2026), concerning the National Transparency Authority\u2019s use of an AI system to generate recommendations for auditors, found no new processing purpose was introduced, but flagged that AI-generated categorization, scoring, and prioritization of complaints can materially affect how a case proceeds. It called for meaningful human intervention before any AI-generated recommendation is acted upon (explicit approval by the competent auditing body), and for clear, comprehensible information to data subjects on the criteria and logic used by the system.<\/p>\n<p>Further opinions are expected as the AI Act\u2019s implementation progresses in Greece and more public bodies deploy AI systems.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Greece, data scraping is subject to regulation under several legal regimes. In detail, under the GDPR and Law 4624\/2019, collecting personal data through scraping without a valid legal basis (such as consent or legitimate interest) is generally prohibited, even if the data is publicly available. Moreover, data scraping can violate copyright or sui generis database rights protected by Law 2121\/1993, especially when it involves extracting substantial portions of protected content. Regarding competition issues, according to Law 3959\/2011 and relevant EU competition rules, scraping may raise issues where it is used to hinder competition or where dominant firms impose unjustified restrictions on access to essential data. However, to date, there are no known Greek court rulings that directly address the legality of data scraping for AI training. Nonetheless, such practices must align with existing privacy, IP, and competition laws.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">To what extent is the prohibition of data scraping in the terms of use of a website enforceable?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The data mining exception under Article 21B of L. 2121\/1993 applies only if rightholders have not explicitly restricted such use\u2014e.g., through machine-readable formats or metadata, website terms, or platform conditions. These restrictions must be clear, specific, and easily identifiable to be enforceable. If a website has already prohibited data scraping via its terms of use, users may only rely on Article 21A, and only for research purposes. Non-cultural heritage institutions may otherwise only invoke Article 21B. In practice, many publishers and content providers widely restrict text and data mining, often through explicit prohibitions on automated access. Widespread reservations like these can render the exception ineffective. Moreover, if scraping involves substantial copying of copyrighted material, it may constitute infringement. Directive 96\/9\/EC also protects databases, and unauthorized extraction of significant parts may lead to legal liability. Lastly, Decision 35\/2022 of the Hellenic Data Protection Authority ruled that Clearview AI Inc. violated data protection laws by scraping online selfies for commercial facial recognition. The company was fined \u20ac20 million for breaching principles of lawfulness and transparency.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Greece has no single dedicated AI regulator; it uses a decentralised model built on existing bodies, coordinated by the Ministry of Digital Governance and AI and its Special Secretariat for AI and Data Governance.<\/p>\n<p>Under the draft implementing law, the HDPA is designated as the principal market surveillance authority and single point of contact (covering prohibited practices, certain high-risk systems and transparency obligations), and EETT as the notifying authority.<\/p>\n<p>As this remains a draft law under public consultation, its provisions may change before adoption, and we expect the final designations and enforcement framework to be confirmed once it is enacted, followed by secondary legislation setting out the operational detail.<\/p>\n<p>Enforcement is already active through data-protection law, ahead of full AI Act application. The HDPA already handles complaints, conducts audits and imposes fines, and has been increasingly focused on automated decision-making, biometric and surveillance technologies.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, AI adoption in Greece is growing, albeit gradually. While the overall penetration remains relatively low\u2014around 8.9% of businesses with more than 10 employees used AI technologies as of 2025, according to Eurostat\u2014there is increasing interest and experimentation across sectors. The primary sectors leading AI adoption in Greece include:<\/p>\n<ul>\n<li>Information Technology and Communications \u2013 with approximately 62% of companies reporting full or partial AI integration, especially in automation, analytics, and customer engagement tools.<\/li>\n<li>Financial Services and Insurance \u2013 deploying AI for tasks such as risk assessment, fraud detection, and claims automation.<\/li>\n<li>Healthcare \u2013 utilizing AI for diagnostics, patient data analysis, and telemedicine solutions.<\/li>\n<li>Retail and Consumer Services \u2013 applying AI in personalization, inventory management, and demand forecasting.<\/li>\n<\/ul>\n<p>According to recent surveys (e.g., National Bank of Greece, SEV), around 1 in 3 SMEs in Greece have started experimenting with AI tools, although often at a preliminary level. Overall, while Greece currently lags behind the EU average in AI adoption, the momentum is building, especially in sectors with high digital maturity or international exposure.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is artificial intelligence used in the legal sector, by lawyers and\/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are several AI tools specifically designed for lawyers, providing multiple possibilities to law professionals such as document review and analysis, document automation, predictive analytics and even legal research. However, whether these tools are used in practice or not, cannot be confirmed by publicly available data.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>While AI presents clear advantages, it must be approached with caution, awareness of ethical risks, and a commitment to ongoing learning. Successful integration depends on understanding both the technology and its legal implications.<\/p>\n<p>Challenges:<\/p>\n<ul>\n<li>Job Disruption: AI may automate routine legal tasks, potentially reducing demand for traditional roles. Legal<br \/>\nprofessionals must adapt by developing new, tech-savvy skill sets.<\/li>\n<li>Complex Outputs: Interpreting AI-generated results like predictive analytics or natural language outputs requires technical understanding. Lawyers must learn how to explain these outcomes clearly to clients and courts.<\/li>\n<li>Data Privacy &amp; Security: With AI\u2019s reliance on large datasets, safeguarding client information becomes critical. Legal practitioners must be familiar with cybersecurity and data protection laws.<\/li>\n<li>Liability Issues: Determining responsibility for harm caused by AI is complex. Traditional tort principles struggle to assign fault when an AI acts unpredictably, beyond its original programming.<\/li>\n<li>Contractual Attribution: In AI-influenced contracts, defining fault or accountability can be unclear, especially when outcomes deviate from expected behavior without direct user involvement.<\/li>\n<\/ul>\n<p>Opportunities:<\/p>\n<ul>\n<li>Efficiency Gains: AI tools can automate tasks like document review and legal research, freeing lawyers to focus on strategy and complex analysis.<\/li>\n<li>Smarter Decisions: Machine learning enables data-driven insights into case outcomes, risks, and trends, enhancing legal advice and planning.<\/li>\n<li>Enhanced Research: AI-powered platforms streamline legal research and precedent analysis, improving speed and accuracy.<\/li>\n<li>Faster Due Diligence: Contract review and risk flagging can be accelerated using AI, allowing lawyers to concentrate on higher-level issues.<\/li>\n<li>Innovation in Services: AI enables new legal specialties, such as advising on algorithmic accountability or autonomous systems law, helping lawyers evolve and expand their practice areas.<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The most significant legal developments in Greece over the next 12 months are expected to arise from the implementation and enforcement of the EU AI Act. A national implementing bill is currently before Parliament and is expected to define the competent supervisory authorities, their respective powers, the sanctions framework and the coordination mechanisms for AI oversight.<\/p>\n<p>As the AI Act\u2019s principal provisions become applicable, Greek businesses and public bodies will need to classify their AI systems, allocate responsibilities across supply chains and introduce appropriate governance, documentation, transparency, human-oversight and risk-management procedures. Particular attention is likely to be given to high-risk uses in employment, healthcare, financial services, education and the public sector, as well as to the interaction between the AI Act, the GDPR, consumer protection and anti-discrimination law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">5613<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/145830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=145830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}