Skip to content
Flag_of_Lithuania.svg

Lithuania

Tools Tools
Justis | LEAD-PRO | LITEKO | Specialised systems | STARLIGHT | TeDIA
Tasks Tasks
Case management | Data analysis, review and surveillance | Operational support | Predictive analytics
Users
Law enforcement | Courts
Scope Scope
Nationwide
Training Training
Not systematic or mandatory
Regulation Regulation
AI use in criminal justice is governed primarily by EU‑level laws (GDPR, LED and the EU AI Act), complemented by Lithuanian data protection, criminal procedure and cybersecurity laws
Insight Insights
InsightsLithuania’s LITEKO judicial information system has used algorithm-based random case allocation to safeguard transparency and prevent judge-shopping for over a decade —predating the AI Act by many years— and has recently added a workload-calculation feature to further inform how cases are distributed among judges
Information uploaded as at July 2026

AT A GLANCE

In law enforcement, AI supports operational and predictive functions, including cross-border coordination through LEAD-PRO and STARLIGHT, AI-enabled body-worn and in-car cameras from Motorola Solutions, a crime-hotspot prediction model developed via the national GovTech ecosystem, and a fraud/corruption risk-assessment tool under development with the OECD. Prosecutors and defence counsel have no publicly reported use of AI as at July 2026. Courts use AI mainly for administrative support, including automatic transcription, algorithm-based case allocation and workload calculation within the LITEKO system, and a pilot chatbot (TeDIA) assisting with press releases on court judgments. Training remains voluntary and ad hoc, though AI now features in judicial induction training and academic/professional conferences.

There is no dedicated framework governing AI in criminal proceedings in Lithuania, and its use is instead addressed through a layered combination of EU and domestic law. The EU AI Act is the primary governing framework, classifying justice and law enforcement systems as high-risk, with several ombudsperson-type bodies designated to safeguard fundamental rights, Innovation Agency Lithuania coordinating implementation, and the Communications Regulatory Authority acting as market surveillance authority. This sits alongside the GDPR and the LED (as domestically transposed), the amended Cyber Security Law (implementing NIS2), and the Code of Criminal Procedure’s general evidentiary requirements, which apply irrespective of AI involvement. No AI-specific professional guidelines exist for judges, prosecutors, or lawyers, though general ethics codes are understood to extend to AI use, and Lithuania is developing an AI regulatory sandbox and public-sector AI Competence Centre. Taken together, tools such as LEAD-PRO, STARLIGHT, LITEKO and TeDIA illustrate how AI is beginning to enter Lithuanian criminal justice practice well ahead of any dedicated domestic regulatory framework, which is precisely why the EU AI Act’s risk-based classification, together with the data protection and criminal procedure safeguards discussed in detail below, currently supplies the main legal constraints on their use.

USE

Law enforcement

Operational support

Lithuanian law enforcement collaborates with the Law Enforcement Assistance for Disaster Prediction and Recovery Optimization Platform (LEAD-PRO) to coordinate security at large public events. This project is a collaboration between Lithuania, Latvia, and Spain’s Valencia region. LEAD-PRO uses AI tools for disaster prediction and prevention as well as for suggesting solutions for post-disaster recovery. These include the use of robotics to navigate hazardous-waste sites and Unmanned Aerial Vehicles/Systems (UAV/UAS) to monitor key target areas. It also provides cybersecurity training to law enforcement.

Law enforcement agencies in Lithuania also rely on a range of advanced digital command‑and‑control and situational awareness technologies that incorporate limited AI functionalities, particularly in the processing of video data, object detection and alert generation. A notable example is the nationwide deployment of AI‑enabled in‑car video and body‑worn camera systems supplied by Motorola Solutions (discussed below), which use computer‑vision algorithms to support real-time monitoring, officer safety and evidentiary documentation.

Lithuanian law enforcement agencies also participate in STARLIGHT, an EU project using AI for cross-border collaboration, intelligence sharing, and collective security amongst different domestic enforcement jurisdictions. STARLIGHT aims to integrate AI into law enforcement systems around the EU, increasing the knowledge and training of law enforcement agencies with AI tools, including how to protect their own AI use and increase cybersecurity. STARLIGHT also functions to improve efficiency in the operational support of law enforcement and to integrate AI sustainability into the long-term operations of law enforcement agencies. It also promotes better responses to the criminal misuse of AI by individuals, which amplifies existing cybersecurity vulnerabilities and introduces new threats to law enforcement agencies.

Predictive analytics

One publicly documented example of AI use in Lithuanian law enforcement comes from the national GovTech ecosystem. UAB Telesoftas, working with Vytautas Magnus University’s Faculty of Informatics, developed a machine-learning model— presented through GovTech Lab Lithuania — that predicts crime hotspots’ and identifies events likely to require police intervention. The system supports forecasting, prioritisation, and planning of police activity, aiding operational decision-making and resource allocation rather than generating evidence for criminal proceedings. Publicly available information indicates the system operates under human oversight and does not automate or replace officers’ discretionary decisions. Because the model is used to forecast likely locations and timing of police intervention rather than to assess or predict the risk that a specific, identified individual will offend or re-offend, it appears to fall outside the narrower high-risk category described in the EU AI Act framework for individual risk-profiling (discussed below), though a formal classification assessment does not appear to have been made public.

Data analysis, review and surveillance

Lithuanian police use M500 video surveillance system cameras, which in turn use AI to assist in threat detection and save footage for later evidence. The cameras are installed into the police force’s vehicles. The cameras are provided by Motorola Solutions with an online VideoManager platform. As these cameras are used for threat detection and evidence capture in the field, they could potentially be viewed as bearing on the evaluation of evidence in criminal proceedings, a use identified as high-risk under the EU AI Act (discussed below), although publicly available information does not confirm whether any such classification assessment has been carried out.

Lithuania’s Special Investigative Service is testing and developing a risk-assessment tool that uses AI-driven data analytics to detect fraud and corruption in the disbursement of public funds. The tool is being developed jointly by the Special Investigative Service, the Organisation for Economic Co-operation and Development, the Government Transparency Institute, and the European Commission’s Technical Support Instrument.

Prosecutors

As at July 2026, there have been no reported examples of prosecutors in Lithuania using AI in criminal proceedings.

Screenshot 2026-08-22 at 13.19.45

Courts

Case management

Lithuanian courts have reported the implementation of speech recognition and automatic transcription tools in selected courts. These systems are designed to process audio or video recordings of court hearings and automatically generate written transcripts, with the stated objective of reducing administrative burdens on court staff and accelerating the preparation of hearing transcripts, protocols and records. Their deployment is framed as a workflow‑efficiency and case‑management measure and is not described as influencing judicial deliberation, legal reasoning or adjudicative outcomes.

Active since 2004, LITEKO is Lithuania’s main judicial information system—a state system for processing procedural documents and for handling, accessing, and analysing cases. The system consists of several modules: case registration, online publication of court decisions, court statistics, inter-institutional information exchange, case search, document templates, court scheduling, and the distribution of cases to judges. It was initially created to digitalise court documents but has increasingly introduced AI elements. Algorithm-based solutions in the case-distribution module have helped ensure transparency through random case allocation for more than a decade. As at July 2026, the LITEKO system includes a feature for calculating the judge’s workload to assist with the allocation of cases. A virtual assistant named ‘Justis’ is reportedly being trained in Lithuania to be integrated within the LITEKO system in the future.

In 2024, Vilnius University, in collaboration with the Supreme Court of Lithuania, launched a pilot project called TeDIA to explore whether AI may assist in preparing press releases of court judgments. The project reportedly aims to enhance public trust in the judiciary by creating concise, clear, citizen-focused press releases. TeDIA consists of a chatbot based on ChatGPT, and was trained using detailed, court-specific instructions and developed with input from journalists, linguists, cybersecurity experts, and court staff. The user can upload to TeDIA a Word file with an anonymised court ruling and a prompt asking the chatbot to draft a press release. Once created, the AI-generated draft must be reviewed. Pilot testing at the Supreme Court of Lithuania began in January 2025.

Defence

As at July 2026, there are no publicly reported examples of defence counsel in Lithuania making use of AI.

Victims

As at July 2026, there are no publicly reported examples of victims in Lithuania making use of AI in criminal proceedings.

TRAINING

As at July 2026, there is no mandatory training programme on the responsible use of AI available to judges, prosecutors, law enforcement officials or lawyers in Lithuania. Instead, training appears to be voluntary and offered on an ad hoc basis.

For judges, it was reported that the 2025 training programme for newly appointed judges included the topics ‘Artificial intelligence Tools and their Potential for use in Court’, ‘Using Artificial Intelligence in the Work of a Judge’, and ‘The Digital Era: the Legal Framework and Artificial Intelligence’. Training and expertise development also occurs mainly through academic and research initiatives, such as the ‘TeismAI’ Project (Artificial Intelligence in Courts: Challenges and Opportunities), which examines the implications of AI for courts and due process.

For lawyers, the Lithuanian Bar Association, the Association of Lithuanian Young Lawyers, and the Ministry of Justice have organised conferences surrounding the implications of AI use in legal practice. This training and awareness-raising activity is organised through professional bodies responsible for the legal profession, rather than through the prosecutorial hierarchy discussed above, which as at July 2026 has no publicly reported AI-related activity of its own. Because prosecutors and defence lawyers may therefore be developing AI literacy through entirely separate institutional channels, and at a different pace, this structural divide could translate into an uneven understanding of the capabilities and limitations of AI tools between the prosecution and the defence, with potential implications for the effective exercise of adversarial rights and equality of arms in criminal proceedings.

REGULATION

As at July 2026, Lithuania does not have a dedicated or comprehensive legislative framework regulating the use of AI technologies in criminal proceedings. Instead, the use of AI in criminal proceedings is governed by a layered framework combining EU law with national legislation on data protection, criminal procedure, cybersecurity and human rights.

AI regulations

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is a key part of the legal framework regulating the use of AI across the EU. It entered into force on 1 August 2024, and sets out a comprehensive legal framework aiming to ‘guarantee safety, fundamental rights and human-centric AI’. The EU AI Act is being phased between 2025 and 2030. Lithuania is obliged to implement and comply with the provisions of the Act, which set out a harmonised legal framework for ‘the development, the placing on the market, the putting into service, and the use’ of AI systems across the EU.

The EU AI Act introduces a risk-based approach, categorising AI systems into four levels of risk, banning ‘unacceptable-risk’ systems, and imposing strict obligations on high-risk systems. The rules on prohibited uses have applied since 2 February 2025, the rules on general-purpose AI models and the designation of competent national authorities have applied since 2 August 2025 while obligations related to the use of high-risk AI systems are being introduced later.

The EU AI Act includes explicit references to AI systems related to the administration of justice, and to criminal proceedings. These are mainly classified as high-risk given ‘their potentially significant impact on ... the rule of law, individual freedoms ... the right to an effective remedy and to a fair trial’ as well as the right to defence and the presumption of innocence, particularly if ‘such AI systems are not sufficiently transparent, explainable [or] documented’. The Act highlights the potential ‘difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation’.

EU AI Act’s risk-based approach

Unacceptable risk (prohibited)

AI systems posing ‘a clear threat to safety, livelihood and rights of people’ are prohibited. This includes uses in law enforcement and criminal justice such as (1) assessing or predicting an individual’s criminal offence risk ‘based solely on the profiling of a natural person or on assessing their personality traits and characteristics’; (2) undertaking ‘untargeted scraping of the internet or CCTV footage’ to build or expand facial recognition databases; and (3) deploying ‘real-time remote biometric identification systems in public spaces or biometric categorisation to infer race, religion or other protected characteristics’ although narrow exceptions exist.

High-risk (subject to strict obligations)

AI systems that ‘can pose serious risks to health, safety or fundamental rights’ are deemed ‘high-risk’ under Article 6. This includes the use of AI (1) to assess the risks of persons ‘becoming the victim of criminal offences’, (2) to assess the risk of persons ‘offending or re-offending’ in certain circumstances and to profile persons during investigations or prosecutions, (3) to evaluate the reliability of evidence ‘in the course of investigations or prosecution of criminal offences’, (4) for remote biometric identification, biometric categorisation in certain circumstances, and emotion recognition, and (5) ‘to assist judicial authorities in researching and interpreting facts and law’ and ‘applying the law to the facts’ (emphasis added). AI systems used for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases are not considered high-risk.


High-risk AI systems are subject to strict obligations for developers, providers and users, including risk assessment; human oversight, the use of high-quality training data and ensuring explainability, accuracy, robustness and cybersecurity. When AI systems assist judicial decision-making, the persons concerned must be informed about the use of AI systems, and be provided with explanations about the role of AI in the decision-making process.

Limited risk (subject to transparency obligations)

This category refers to the risk associated with a need for transparency around the use of AI such as chatbots. Specific disclosure obligations apply for this category.

Minimal risk (no requirements)

Minimal risk or no risk AI systems are not subjected to any requirements.

Articles 51-56 of the EU AI Act establish a specific regime for ‘general-purpose AI models’, defined in Article 3(63) as models trained on large datasets capable of performing a wide range of tasks. They typically include large language models (LLMs) that can be integrated into legal research platforms, drafting tools or judicial support systems. Providers of such models must:

  • maintain technical documentation;
  • provide information to downstream integrators;
  • comply with EU copyright law; and
  • publish a summary of training data.

Under Articles 55-56, additional obligations apply to general-purpose AI models presenting systemic risk, including risk assessment, mitigation measures and incident reporting. The framework is particularly relevant to the judicial sector given that courts and prosecutors may rely on external LLM-based tools rather than developing their own systems.

In terms of governance and enforcement of the EU AI Act, the Act adopts a two-pronged approach. At the EU-level, according to Articles 64-69 of the AI Act, the AI Office of the European Commission and an AI Board (Article 65) are the main actors. The AI Office enjoys enforcement powers with respect to obligations of general-purpose AI models (Article 88 et seqq.). The AI Board assists the European Commission and the member States in facilitating coherent applications of the AI Act, and therefore contributes to the coordination among national authorities (Article 66(a)).

Lithuania has taken steps to implement the EU AI Act by identifying national authorities responsible for safeguarding fundamental rights in the context of high-risk AI systems listed in Annex III. The designated bodies include the Office of the Equal Opportunities Ombudsperson, the Seimas Ombudsmen’s Office, the Office of the Ombudsperson for Children’s Rights, and the Office of the Inspector of Journalist Ethics. Lithuania has also designated Innovation Agency Lithuania to perform notification‑related and institutional‑coordination functions under the AI Act framework, while the Communications Regulatory Authority (‘RRT’) acts as the competent market‑surveillance authority. In this capacity, the RRT is responsible for monitoring compliance and exercising the supervisory and enforcement powers attributed to market‑surveillance authorities under EU law. Official amendments were also made to domestic legislation to incorporate the EU AI Act into the Law on Technology and Innovation and the Law on Information Services.

Several non-binding guidelines have already been published by the European Commission to provide further directions when implementing the AI Act:

  • Guidelines on prohibited artificial intelligence (AI) practices (published on 04 February 2025) provide legal explanations and practical examples of AI practices that are deemed unacceptable and hence prohibited by Article 5 of the AI Act, due to their potential risks to European values and fundamental rights. The guidelines specifically address practices such as harmful manipulation, social scoring, and real-time remote biometric identification, among others.
  • Guidelines on AI system definition (published on 06 February 2025) explain the practical application of the legal concept of AI to assist providers and other relevant persons in determining whether a software system constitutes an AI system. The guidelines elaborate on each of the seven elements of the definition of an AI system provided by Article 3(1) AI Act: (1) machine-based system, (2) autonomy, (3) adaptiveness, (4) AI system objectives, (5) inferencing how to generate outputs using AI techniques, (6) outputs that can influence physical or virtual environments, and (7) interaction with the environment.
  • As at July 2026, other guidelines are being developed by the European Commission. For instance, the Commission has issued Draft guidelines on the classification of high-risk AI systems, setting out the Commission’s interpretation of certain concepts that are relevant for classification purposes, and contain practical examples of AI systems that should or should not be classified as high-risk. These draft guidelines focus on interpreting the scope of the exemptions in Article 6(3) of the EU AI Act, under which an AI system performing a narrow procedural task, or merely improving the result of a previously completed human activity without materially influencing the substance of a decision, falls outside the high-risk category. Tools that assess an individual’s risk of offending, reoffending, or becoming a victim of crime, or that are used to evaluate evidence in investigations or prosecutions, are treated as falling outside these exemptions and therefore remain classified as high-risk under Annex III, consistent with the classification described above.

Other European Regulations and Guidelines

At the European level, the AI Act coexists with additional regulations and guidelines:

Ethics Guidelines for Trustworthy Artificial Intelligence (2019)

Prior to the adoption of the AI Act, the High-Level Expert Group on AI set up by the European Commission presented the Ethics Guidelines for Trustworthy Artificial Intelligence on 8 April 2019. These guidelines provide a framework to achieve trustworthy AI based on fundamental rights as enshrined in the Charter of Fundamental Rights of the European Union (EU Charter).

The Guidelines put forward a set of seven key requirements that AI systems should meet in order to be deemed trustworthy:

  1. Human agency and oversight
  2. Technical robustness and safety
  3. Privacy and data governance
  4. Transparency
  5. Diversity, non-discrimination and fairness
  6. Societal and environmental well-being
  7. Accountability

This Guideline is a non-binding EU soft-law instrument that provides guidance across all EU Member States, including Lithuania, but does not itself impose binding legal obligations.

European Declaration on Digital Rights and Principles for the Digital Decade (2022)

The European Commission adopted on 26 January 2022 the European Declaration on Digital Rights and Principles for the Digital Decade. This Declaration affirms the commitment of European institutions to ‘ensuring transparency’ in AI, guaranteeing the quality of data, preventing these tools from being used to predetermine individuals’ choices, and providing safeguards to protect individuals’ fundamental rights. Chapter III specifically declares that everyone shall be able to make ‘free and informed choices in the digital environment, while being protected from risks and harm to their health, safety, and fundamental rights’.

This Guideline is a non-binding EU soft-law instrument that provides guidance across all EU Member States, including Lithuania, but does not itself impose binding legal obligations.

Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (2024)

The Council of Europe adopted in May 2024 the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, which is the ‘first-ever international legally binding treaty’ regulating AI. The Convention establishes rules relating to respect for fundamental rights at all stages of the AI systems lifecycle, which must be transposed into the domestic law of the signatory states.

The Convention establishes seven fundamental principles for AI systems development: human dignity and individual autonomy (Article 7), transparency and oversight (Article 8), accountability and responsibility (Article 9), equality and non-discrimination (Article 10), privacy and personal data protection (Article 11), reliability (Article 12) and safe innovation (Article 13).

The Convention applies across all public and private uses of AI where human rights may be affected, including within law enforcement, prosecution and judicial activities. It mandates risk and impact assessments to mitigate potential harms and provides safeguards such as the right to challenge AI-driven decisions.

The Convention has been signed on 5 September 2024 by Lithuania(as part of EU signature), but has not yet come into force and therefore does not yet create binding obligations for Lithuania.

European Ethical Charter on the use of AI in judicial systems and their environment (2018)

Similarly, the European Ethical Charter on the use of AI in judicial systems and their environment has been adopted by the Council of Europe’s European Commission for the Efficiency of Justice (CEPEJ) in December 2018. It lays out five basic principles relating to the use of AI in judicial systems:

  1. Respect of fundamental rights (‘ensure that the design and implementation of AI tools and services are compatible with fundamental rights’),
  2. Non-discrimination (‘specifically prevent the development or intensification of any discrimination between individuals or groups of individuals’),
  3. Quality and security (‘with regard to the processing of judicial decisions and data, use certified sources and intangible data with models conceived in a multi-disciplinary manner, in a secure technological environment’),
  4. Transparency, impartiality and fairness (‘make data processing methods accessible and understandable, authorise external audit’),
  5. ‘Under user control’ (‘preclude a prescriptive approach and ensure that users are informed actors and in control of their choices’).

The Charter is a non-binding Council of Europe instrument; as a Council of Europe member state, Lithuania is encouraged to have regard to it in judicial practice, although it is not legally binding.

Guidelines for practitioners

As at July 2026, there are no AI-specific professional guidelines in Lithuania governing the responsible use of AI by law enforcement, prosecutors, courts and lawyers in criminal proceedings. The conduct of legal practitioners is nonetheless constrained by general principles of judicial and professional ethics, as well as European soft-law instruments, including the CEPEJ European Ethical Charter on the Use of AI in judicial systems and their environment (discussed above).

Lithuanian judges are bound by the Code of Ethics of the Judges of the Republic of Lithuania (2006), which emphasises judicial independence, personal responsibility for decisions, confidentiality, impartiality, and the duty to maintain professional competence. While the Code does not make explicit reference to AI, these principles are generally understood as requiring that judicial reasoning and decision-making in criminal cases remain human‑driven, accountable and capable of explanation, thereby precluding reliance on opaque, autonomous or outcome‑determinative AI systems.

For lawyers, general professional duties of competence, independence, confidentiality and honesty toward the court apply equally where AI or generative tools are used. These obligations are reflected and reinforced by guidance adopted at European level (discussed below).

As at July 2026, there are no publicly reported examples of Lithuania formally adopting or specifically referencing the UNESCO Guidelines for the Use of AI Systems in Courts and Tribunals (2025).

Regional guidelines on judiciary’s use of AI

As an EU and Council of Europe member state, Lithuania falls within the scope of the following pan-European guidance instruments on the judiciary’s use of AI (see below). They constitute non-binding sector guidance relevant to legal professionals and courts operating in Lithuania, rather than directly binding law.

In fact, there are several European-level guidelines that address the judiciary’s use of AI, most notably the European Ethical Charter on the use of AI in judicial systems and their environment adopted by the CEPEJ of the Council of Europe (discussed above).

Other initiatives have given rise to guidelines for justice system professionals and for lawyers:

Sector

Title

Contents

Council of Bars and Law Societies of Europe

Considerations on the Legal Aspects of Artificial Intelligence (2020)

According to the Council of Bars and Law Societies of Europe, for the sake of transparency and in order to enable individuals to defend their rights, it seems appropriate that the persons impacted by the use of an AI system should be duly informed that AI is being used and that data concerning the individual may be considered by an automated system.

Council of Bars and Law Societies of Europe

Guide on the Use of Artificial Intelligence-Based Tools by Lawyers and Law Firms in the EU (2022)

The Guide emphasises that lawyers should have at least a general understanding of how AI tools function. Where such understanding is lacking, this should be clearly communicated to clients and taken into account in the provision of legal services. Ultimately, under existing professional rules, lawyers remain fully responsible for the quality of their services and the outcomes for their clients, even where AI tools are used.

Court of Justice of the EU

Artificial Intelligence Strategy (2023)

While the AI Strategy does not address the disclosure of AI use, it emphasises that once AI solutions, procedures, methods and governance are put in place, staff awareness and knowledge level should ensure that the reasoning behind AI algorithms should be clear and understandable, both for those created in-house and those acquired.

European Bars Federation

Guidelines 2.0 on How Lawyers Should Take Advantage of the Opportunities Offered by Large Language Models and Generative AI (2024)

The Guidelines explain that lawyers should maintain transparent communication with their clients regarding the use of generative AI in their legal practice. Lawyers should clearly explain the fact that they use it, as well as the purpose of such use, benefits, limitations, and guarantees, ensuring that clients understand the role of this technology in legal matters.

Council of Europe

Use of Generative AI by Judicial Professionals in a Work-Related Context (2024)

The aim of this note is to give some preliminary thought to what judges and other public sector justice professionals can expect from the use of generative AI tools in a judicial context. The Council reiterated that it is essential, in particular in the case of justice, to be transparent about the use of generative AI as the relationship with the litigant is based on trust.

Criminal procedure rules

Code of Criminal Procedure of the Republic of Lithuania, 2002

Criminal proceedings in Lithuania are governed by the Code of Criminal Procedure, which establishes the core principles on the collection, admissibility and evaluation of evidence. These rules apply irrespective of whether information has been generated, processed or analysed with the assistance of algorithmic or AI‑based tools. Most notably, Article 20 of the Code provides that evidence in criminal proceedings consists only of data obtained in accordance with the law and capable of proving or disproving circumstances relevant for the fair resolution of the case. This general legality and reliability requirement operates as a functional constraint on the use of AI‑assisted investigative techniques.

While the Code does not expressly regulate AI‑generated outputs, its principles of lawfulness, verifiability, adversarial examination and judicial assessment require that any AI‑assisted results influencing investigative steps or evidentiary priorities remain open to scrutiny and challenge by the defence.

Screenshot 2026-08-22 at 08.20.36

Data protection legislation

In addition to the EU AI Act, EU data protection regulations must be observed with regard to the use of AI in criminal proceedings. The EU AI Act does not seek to affect existing Union law governing the processing of personal data (according to Article 2 No. 7 AI Act and Recital 10). Data protection law governing the use of personal data may be relevant with regard to various stages of the AI lifecycle. Personal data can be relevant during AI development (e.g., collection and use of data for training) and AI use (e.g., personal data as input data).

On 25 January 2012, the European Commission presented the Data Protection Reform package, proposing a directive (LED) and a regulation (GDPR). On 27 April 2016, the European Parliament and the Council adopted:

  • The Law Enforcement Directive (Directive (EU) 2016/680) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data) (‘LED’)
  • The General Data Protection Regulation (Regulation (EU) 2016/679) of the European Parliament and of the European Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (‘GDPR’).

The GDPR remains the primary regulation for ‘general’ processing of data, but the LED is the lex specialis for criminal matters, since it governs processing ‘for the purposes of the prevention, investigation, detection, or prosecution of criminal offences or the execution of criminal penalties’. These regulations have distinct scopes of application that are intended to be complementary.

The GDPR became directly applicable across the EU on 25 May 2018, while all EU Member States were required to transpose the LED into national law by 6 May 2018.

In both regulations, ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 3(1) LED and Article 4(1) GDPR). As at July 2026, this term also includes pseudonymised data as indicated by Article 4(5) GDPR. Recital 26 sentence 2 of the GDPR points out that identifiability should (still) be recognised in view of pseudonymised personal data that could be assigned to a natural person based on additional information.

EU Directive 2016/680, Law Enforcement Directive (LED) (2016)

The directive governs the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection, and prosecution of criminal offences or the execution of criminal penalties.

The rights of data subjects are recognised but may be limited in order to ensure the proper conduct of investigations, prevention, and the prosecution of offences. These rights include the right to information, the right of access (often exercised indirectly through the supervisory authority), and the right to rectification or erasure. As such, the directive imposes obligations on data controllers that are comparable to those of the GDPR, but creates additional obligations that are specific to the criminal context:

  1. There must be a clear distinction among categories of data subjects: those suspected of committing or planning a criminal offence, those who have been convicted, victims of crimes, and individuals who may be at risk of becoming victims. It also includes third parties connected to a crime, such as potential witnesses, people who can provide information, and contacts or associates of the individuals mentioned above, as set out in Article 6.
  2. The processing of special categories of personal data is strictly regulated under Article 9(2) of the GDPR and requires the data subject’s consent, which shall be freely given and well-informed, or for a legitimate purpose. But the LED establishes a specific exception for criminal matters: Article 10 permits the processing of sensitive data without consent when it is strictly necessary, provided that appropriate safeguards are implemented.
  3. The LED also addresses automated individual decision-making. A decision ‘based solely on automated processing, including profiling, which produces an adverse legal effect concerning the data subject or significantly affects him or her’, is prohibited unless authorised by Union or Member State law to which the controller is subject and which provides appropriate safeguards for the data subject’s rights and freedoms of at least the right to obtain human intervention on the part of the controller (Article 11(1)). The EU legislator specifies that this right to intervention comprises the right to express his or her point of view, to obtain an explanation of the decision reached after such assessment or to challenge the decision (Recital 38). Furthermore, such decisions shall not be based on special category data, unless suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests are in place (Article 11(2)). Special category (or sensitive) personal data refers to data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data used for identification purposes, health data, and data concerning a person’s sex life or sexual orientation (see Article 9 GDPR and Article 10 LED, both referenced above).
  4. In order to protect individuals’ rights during criminal investigations, Articles 13 and 14 provide for information and access rights, while allowing limitations where their exercise could undermine ongoing investigations or prosecutions.
  5. Article 16 complements these safeguards by providing the right to request the rectification of inaccurate data and the erasure of data, and in the event of refusal, the possibility of lodging a complaint with a supervisory authority or seeking judicial remedy.
  6. Finally, Articles 27 and 29 impose obligations relating to risk assessment and data security, requiring competent authorities to assess the impact of high-risk processing operations and to implement appropriate technical and organisational measures throughout the criminal procedure.

In Lithuania, the LED has been transposed through the Law of the Republic of Lithuania on the Legal Protection of Personal Data Processed for the Purposes of Prevention, Investigation, Detection or Prosecution of Criminal Offences, the Execution of Criminal Penalties, or for National Security or Defence Purposes. This law sets out specific requirements applicable to competent authorities, including enhanced obligations concerning data accuracy, logging, purpose specification and storage limitation, as well as restrictions on the use of automated processing and profiling in criminal justice contexts. In line with the LED, Lithuanian law emphasises a case‑by‑case assessment of the lawfulness, necessity and proportionality of personal‑data processing operations and requires the implementation of appropriate safeguards where automated decision‑making or profiling techniques are employed, particularly where such processing may produce adverse legal effects for individuals.

Compliance with the LED regime in Lithuania is supervised by the State Data Protection Inspectorate, which exercises oversight and enforcement powers aligned with those applicable under the GDPR, while taking due account of the specificities of criminal justice, public security and law‑enforcement activities.

Regulation (EU) 2016/679, General Data Protection Regulation (GDPR)

The GDPR protects fundamental rights in the digital landscape by imposing obligations on data controllers and processors upon all processing of personal data. Hence, in the area of criminal justice, the GDPR is relevant for (i) the processing of personal data collected by competent authorities for the purposes set out above but intended to be further processed for other purposes, (ii) processing by public bodies for other purposes from the outset (this includes, e.g., archiving conducted by criminal justice authorities), and (iii) any processing by natural persons or private entities (Article 9(1) and (2) LED, Article 2(1) GDPR, Recital 19 to GDPR).

Obligations placed on data controllers include: lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability; transparency and information duties; security obligations; and data protection impact assessments. The GDPR also grants basic rights to data subjects such as access, rectification and erasure of personal data.

Compared to the LED, the GDPR establishes a higher level of protection regarding the lawfulness of processing. Several aspects of criminal proceedings are subject to the following provisions of the GDPR:

  1. Article 10 requires the processing of personal data relating to criminal convictions and offences to be carried out ‘only under the control of official authority’, and to provide for ‘appropriate safeguards for the rights and freedoms of data subjects’.
  2. Paragraph 1 of Article 22 prohibits any decision that produces legal or similar effects based exclusively on automated data processing. This serves as a key safeguard against ‘algorithmic judges’ or fully automated sanctions.
  3. Paragraph 1 of Article 35 provides that the controller must carry out a data protection impact assessment prior to any processing likely to pose a high risk to the rights and freedoms of individuals, particularly when new technologies are involved. A single assessment may cover multiple similar processing operations presenting comparable risks.

In Lithuania, the GDPR is supplemented by the Law of the Republic of Lithuania on Legal Protection of Personal Data (1996), which sets out national rules in areas left to Member States’ discretion and designates the State Data Protection Inspectorate (VDAI) as the competent supervisory authority. The national framework further specifies, inter alia, rules on the processing of personal identification numbers, data processing in the employment context, and applicable supervision and enforcement mechanisms for both public and private sector entities.

EU AI Act (Regulation (EU) 2024/1689)

Acknowledging both existing data privacy regulations and the relevance of personal data in the AI context, the EU AI Act contains several provisions addressing the use of such data in the course of complying with broader obligations under the AI Act:

  1. The EU AI Act provides a (narrow) legal basis for the processing of special category personal data in the context of training or testing a high-risk AI system. Where such processing is strictly necessary for the purpose of ensuring bias detection and correction in relation to a high-risk system, the providers of such systems may exceptionally process special category data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. Exceptional circumstances exist where (in addition to the requirements for such processing set out in the LED or the GDPR) certain cumulative conditions are met, including where there are technical limitations and state-of-the-art security measures, including pseudonymisation, as well as strict security safeguards (Article 10 No. 5 sentence 2 AI Act, (6)).
  2. The data sets for training, validation, and testing of AI systems shall be subject to appropriate data governance and management practices that, in the case of personal data, shall also concern the original purpose of the data collection (Article 10 No. 2 (b) AI Act).
  3. Where applicable, deployers of high-risk AI systems shall use the information provided for such systems under their transparency obligation (Article 13 AI Act) for conducting a data protection impact assessment under the LED or the GDPR (Article 26 No. 9 AI Act).

Cybersecurity laws

EU AI Act (Regulation (EU) 2024/1689)

For high-risk AI systems, the EU AI Act requires resilience against attempts by unauthorised third parties to alter their use, outputs, or performance by exploiting system vulnerabilities (Article 15(5)), which is confirmed by the underlying Recital 76, emphasising the crucial role of cybersecurity.

EU Cybersecurity Act (2019) and EU Cyber Resilience Act (2024)

As regards the demonstration of compliance with the AI Act’s cybersecurity requirements for high-risk AI systems, two other European regulations may be relevant:

EU Cybersecurity Act (‘CSA’) - Regulation (EU) 2019/881

Aims to achieve a high level of cybersecurity, cyber resilience and trust within the EU and sets forth a framework for the establishment of voluntary European cybersecurity certification schemes for so-called ICT products, i.e., an element or a group of elements of a network or information system (Articles 1(1)(b), 2(13) CSA). Where high-risk AI systems are also ICT products, compliance with the cybersecurity requirements laid down in the EU AI Act can be presumed by demonstrating certification under the CSA in so far as such certification covers the AI Act’s respective requirements (Articles 42 No. 2, 15 No. 1, 5 AI Act). Concerning law enforcement and criminal justice, this would be particularly relevant for high-risk AI-enabled software, for instance allowing for biometric identification. In January 2026, the European Commission announced a Proposal for a Regulation for the EU Cybersecurity Act (‘The Cybersecurity Act 2’) aiming at, inter alia, further simplifying the certification process.

Cyber Resilience Act (‘CRA’) - Regulation (EU) 2024/2847

Whereas the CSA establishes a voluntary certification framework, the CRA aims at ensuring that digital products and services are secure by design, resilient against threats, and able to maintain security throughout their life cycle, and sets out mandatory cybersecurity requirements for products with digital elements made available on the market. With most of its provisions applying from December 2027, the CRA will concern a wide range of products placed on the EU market, including AI-enabled software. For high-risk AI systems, compliance with the CRA requirements shall also be deemed to satisfy the AI Act’s cybersecurity requirements in so far as those requirements are covered under the CRA (Recital 51 to the CRA).

EU NIS2 Directive (2022) and Implementing Legislation

At the domestic level, Lithuanian cybersecurity law is primarily based on the implementation of the EU NIS2 Directive (Directive (EU) 2022/2555), which imposes strict risk management, incident notification, and security obligations on critical entities and public bodies.

In particular, EU NIS2 Directive establishes a high common level of cybersecurity across the EU, requiring entities subject to the framework to implement comprehensive cybersecurity risk management measures, covering access control, supply chain security, physical security of network systems, and human resources security, while management bodies are personally accountable for approving and overseeing such measures. On incident reporting, the Directive introduces a tiered architecture requiring an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and further reports as the situation develops. At the governance level, Member States must establish national cybersecurity strategies, designate competent authorities, and set up Computer Security Incident Response Teams.

At the domestic level, the Law on Cyber Security of the Republic of Lithuania (2014) was amended in 2024 to transpose the NIS2 Directive. The amended Cyber Security Law imposes risk‑management, technical and organisational security, and incident‑notification obligations on a broad range of entities, including public authorities and other bodies designated as ‘essential’ or ‘important’ cybersecurity entities. For public sector bodies involved in justice and law enforcement, this includes obligations to implement adequate safeguards to ensure the confidentiality, integrity and availability of network and information systems supporting AI applications, as well as to report significant cybersecurity incidents to the National Cyber Security Centre (NCSC).

Code and Bokeh Lights-1

Human rights

Lithuania is bound by the European Convention on Human Rights, in particular Articles 6 (fair trial), 8 (private and family life) and 14 (non-discrimination), and by the EU Charter of Fundamental Rights, including Articles 7 (privacy), 8 (data protection), 21 (non-discrimination) and 47 (right to an effective remedy and a fair trial). The Charter of Fundamental Rights of the European Union applies to the processing of personal data by AI systems falling within EU law scope, including in the context of criminal proceedings governed by the LED and the EU AI Act.

Moreover, the Council of Europe Framework Convention on AI and Human Rights, Democracy, and the Rule of Law deserves special mention as a multilateral initiative, being the first legally binding international treaty specifically designed to regulate AI. Opened for signature in September 2024, its primary objective is to ensure that as AI technologies evolve, they do not erode the fundamental pillars of modern society: human rights, democratic integrity, and the rule of law. As at July 2026, the Convention has not yet entered into force, as the minimum number of five ratifications has not been reached yet. Accordingly, as at July 2026, the Convention has no binding effect in Lithuania. The Convention focuses on the lifecycle of AI systems, from design to decommissioning, and mandates adherence to seven fundamental principles: human dignity, transparency, accountability, equality, privacy, reliability, and safe innovation. It requires signatories to establish independent oversight bodies and provide clear legal remedies for individuals who suffer harm due to AI systems.

Lithuania is a state party to both the International Covenant on Civil and Political Rights (‘ICCPR’) and the Convention on the Rights of the Child (‘CRC’). Potentially relevant provisions include Article 14 of the ICCPR (right to a fair trial) and Article 40 of the CRC (right of children in conflict with the law to fair treatment). These provisions reinforce the fair trial and due process principles already discussed above in connection with the ECHR and the EU Charter.

Outlook

Future development and deployment of AI in Lithuania

Lithuania’s approach to AI in criminal justice can be described as cautious and incremental. While technical capacity and institutional interest are evident (particularly in policing analytics and judicial experimentation), the expanding EU regulatory framework, especially the EU AI Act, is likely to channel future developments toward tightly governed, transparent and human‑supervised uses. Ongoing academic research and policy discussion aligned with Lithuania’s Artificial Intelligence Strategy suggest that further guidance or soft‑law instruments may emerge rather than rapid, large‑scale deployment.

Lithuania is also developing an AI regulatory sandbox within the Innovation Agency, intended as a mechanism to support businesses in complying with the AI Act and related regulations. The sandbox will provide expert guidance, helping companies mitigate the significant financial risks associated with non-compliance, including substantial fines, and prepare for conformity assessment and certification procedures. The Innovation Agency comes as part of a push to ensure that European AI tech can still compete in a saturated and competitive market. The sandbox exists alongside an AI Factory, LitAI, coordinated by Vilnius University. It is a national centre that can provide businesses with computing, access to data, and specialist teams.

In parallel, the government has initiated the establishment of an AI Competence Centre for the public sector within the State Digital Solutions Agency. This initiative aims to strengthen AI literacy and promote compliance with the AI Act across public administration. The development of the regulatory sandbox and the AI Competence Centre can be understood as a direct institutional response to the implementation challenges posed by the EU AI Act discussed above, particularly the need to build the technical and legal expertise required to classify AI systems correctly, to conduct the risk assessments and conformity procedures applicable to high-risk systems, and to support public-sector bodies, including those in the justice and law-enforcement sectors, in meeting their obligations under the Act.

European Commission’s Proposed Digital Omnibus Regulation (2025)

In November 2025, the European Commission published its Digital Omnibus Regulation Proposal, a reform package to simplify and streamline existing EU regulations concerning the digital space, including the GDPR and EU AI Act. Respective amendments to the LED are to follow.

Notably, the European Commission intends to amend the definition of the term ‘personal data’ in Article 4(1) GDPR by stating that information is ‘not to be considered personal data for a given entity when it does not have means reasonably likely to be used to identify the natural person to whom the information relates.’ Accordingly, such an entity would not fall within the scope of the GDPR regarding the processing of such data. This approach is generally in line with CJEU case law establishing that existing additional information enabling an entity to identify the data subject does not as such mean that pseudonymised data are to be considered personal data in all cases and for every person. In other words, personal data can be pseudonymised for one entity and anonymised (and thus not identifiable) for another (EDPS v SRB, 4 September 2025, CJEU, C‑413/23 P). Such an amendment wording would, if implemented, significantly reshape the legal test to be conducted to assess applicability of the GDPR (i.e., the assessment of the existence of personal data) towards an entity-focussed approach and largely exclude pseudonymised data from the scope of the GDPR.

The European Commission, through its Digital Omnibus Regulation, also intends to clarify that the processing of personal data in the context of AI development may be carried out for purposes of a legitimate interest where appropriate (Article 6(1)(f) GDPR). Such an amendment would address an issue that has been widely debated since the emergence of LLMs, and which has also been subject to a dedicated Opinion of the European Data Protection Board (Opinion 28/2024, 18 December 2024, EDPB).

CASES

As at July 2026, there are no publicly reported cases in Lithuania directly addressing the use of AI tools in criminal proceedings.