Skip to content
Flag_of_Latvia.svg

Latvia

Tools Tools
CounteR | Criminal Intelligence Support Information System | Digital Forensics Data Processing Platform | ECLI.ai | Endzelīns | FIDR Advanced | iBorderCtrl | Justs | LEAD-PRO | Lexu AI | Project FIDR | Specialised systems
Tasks Tasks
Administrative support | Case management | Charging support | Data review and analysis | Evidence review and analysis | Legal research, analysis, and drafting support | Operational support | Predictive analytics
Users
Law enforcement | Prosecutors | Courts | Defence | Victims
Scope Scope
Nationwide
Training Training
Not mandatory or systematic
Regulation Regulation
Use of AI in Latvia’s criminal justice system is governed primarily by the EU AI Act, alongside GDPR and the Law Enforcement Directive (as implemented domestically), and the National Cybersecurity Law (NIS2)
Insight Insights
Latvia’s Prosecution Service is piloting one of the more advanced generative AI applications identified across the Atlas to date: a RAG-based large language model that reviews case materials for minor offences (e.g. driving under the influence) and generates recommendations on procedural direction and sentencing, drawing on statutes, guidelines, caselaw, and a curated set of anonymised prior decisions—with human oversight retained throughout and no reliance permitted on its output alone
Information uploaded as at July 2026

AT A GLANCE

In Latvia, at every stage of the criminal process, at least one actor is using AI in some form. In law enforcement, AI is used for operational and predictive support, notably Project FIDR and its successor FIDR Advanced, developed with Europol to dismantle organised crime networks, and CounteR, which monitors the web for extremist content. Prosecutors use AI for machine translation, automated anonymisation, and a RAG-based tool in development to support sentencing recommendations in minor offences. Courts use AI mainly for administrative support — anonymising judgments, transcribing hearings, and powering a virtual assistant — while the defence increasingly relies on commercial caselaw research platforms. Training remains ad hoc rather than mandatory across all groups.

There is no single framework governing AI in criminal proceedings; its use is addressed through a combination of EU and domestic instruments. The EU AI Act is the primary governing framework, classifying justice and law enforcement AI systems as high-risk, with the Ministry of Smart Administration coordinating its implementation and the Ombudsman acting as the fundamental rights authority. This sits alongside the GDPR/Law Enforcement Directive, national cybersecurity legislation, and Latvia’s 2025 AI Centre and AI Development laws. The Bar Council issued AI guidelines for advocates in January 2026, but no equivalent guidance exists for the judiciary, and deepfakes targeting elections are separately criminalised.

USE

Law enforcement


The Latvian State Police employs a range of digital and AI-enabled tools across several operational domains, including web monitoring, criminal intelligence and analysis, traffic monitoring, digital forensics and cybercrime investigation, and border control. Oversight of all AI use is exercised by the ICT Governance Board, which includes the Chief Information and Data Protection Officers.

Operational support

Project FIDR is an AI-powered data analytics tool used to identify and combat organised criminal groups at national, regional and transnational levels (the specific technical tools used were not disclosed publicly). Project FIDR ran from 2021 to 2024, initiated by Latvia with the Lithuanian Criminal Police Board and the Estonian Police and Border Guard Board as accredited partners, and with the operational and analytical support of Europol. Over the course of Project FIDR (2021–2024), 72 persons were detained across more than 50 cross-border operations and over 8.2 tonnes of drugs seized, with an estimated market value of hundreds of millions of euros. Nine organised criminal groups were identified and disrupted.

The successor initiative, FIDR Advanced, was launched in January 2025 with a €2.3 million EU budget. Running until 2027, it expands the scope of Project FIDR beyond drug trafficking to include money laundering, cybercrime, human trafficking and arms trafficking. Its main objective is to equip law enforcement agencies with proactive tools leveraging cutting-edge data analytics and AI to identify and dismantle organised criminal networks.

CounteR is a tool reportedly used by the State Police of Latvia for detecting radical content online. The platform works in 12 languages, monitoring the open, deep, and dark web, and analysing text and images to detect radical content, extremist ideologies, and hate speech. Whilst the research and pilot phase was concluded on 30 April 2024, as at July 2026, it is unclear whether new pilots are underway or whether the project has moved into full implementation.

Latvia collaborates with the Law Enforcement Assistance for Disaster Prediction and Recovery Optimisation Platform (LEAD-PRO) to coordinate security at large public events. This project is a collaboration between Lithuania, Latvia, and Spain’s Valencia region. LEAD-PRO uses AI tools for disaster prediction and prevention as well as for suggesting solutions for post-disaster recovery. These include the use of robotics to navigate hazardous waste and Unmanned Aerial Systems (UAV/UAS) over key target areas. It also provides cybersecurity training to law enforcement.

The Latvian Police also uses a Technological Platform for the recognition and storage of vehicle registration plates, built by the Information Centre of the Ministry of Interior together with the State Police and Latvian State Roads. The platform recognises and stores registration plates for public order, investigative, or search purposes. According to the official launch announcement, the project began on 2 April 2024 and entered into operation on 31 March 2026.

Predictive analytics

iBorderCtrl is an EU Horizon 2020 project tested in Latvia, as well as Hungary and Greece. iBorderCtrl supported border control through a package of tools, including biometric verification, document authentication, risk-assessment, and deception detection (detecting lies based on facial expressions). The project ran from 1 September 2016 to 31 August 2019.

Data review and analysis

As at July 2026, Latvia has reportedly deployed facial recognition technology in law enforcement, though it is primarily experimental and its use localised. Latvia has not yet expanded to real-time biometric identification systems, but such systems are now generally prohibited under Article 5(1)(h) of the EU AI Act (see below), subject to certain narrowly defined exceptions.

The Digital Forensics Data Processing Platform was launched in March 2025, with a budget of €2 million and a purpose of strengthening the State Police’s capacity to investigate cybercrime and related serious offences through hardware, software, server infrastructure, a digital forensics platform, and training. No information suggesting discontinuation as at July 2026 has been identified.

The Criminal Intelligence Support Information System was developed by the State Police with the Information Centre of the Ministry of the Interior, aiming to assist law enforcement with data review and analysis. The project began at the end of 2023 and serves as a centralised platform for the accumulation and circulation of criminal intelligence data, and includes a dedicated analytical tool designed to support investigators with information analysis. Its functions include information exchange, record-keeping, and data analysis across units of the Ministry of the Interior, including the State Police and the State Border Guard.

WhatsApp Image 2025-10-02 at 20.29.29

Prosecutors

According to a Thematic Study by the Consultative Council of European Prosecutors on the use of AI by prosecution services across Council of Europe Member States (October 2025), AI is used in Latvia by the prosecution services across multiple areas: automated machine translation; anonymisation of prosecutorial decisions; and legal research, through publicly available general-purpose AI tools.

Case management

Since 2022, the government of Latvia has operated Endzelīns, an AI-based machine translation platform. In 2025, the tool was made available to prosecutors, and Endzelīns’ deep machine-learning translation engine was adapted to the language needs of law enforcement institutions. The tool supports translations for multilingual prosecutorial work, including handling documents and communications across various languages, such as Latvian, English, French, German, and Russian.

The Latvian Prosecution Service has also introduced an AI-enabled anonymisation function. The tool uses AI to automate the anonymisation of prosecutorial outputs, including procedural decisions (such as penal orders issued by prosecutors), as a means to reduce manual processing and improve efficiency. The process is subject to human-in-the-loop verification, and publication only occurs where the prosecutor is satisfied that the anonymisation is appropriate.

Charging support

As at July 2026, the Latvian Prosecution Service is developing a generative AI large language model that uses retrieval-augmented generation (‘RAG’) to assist evidence review and decision-making. The tool analyses new materials and prepares recommendations on procedural direction or the sentence to be applied to cases concerning minor crimes, including driving under the influence of alcohol, narcotic, psychotropic, toxic, or other intoxicating substances, with the aim of promoting consistency in the penalty ranges applied. The model reportedly draws on statutory provisions, related guidelines, caselaw explanations, and a selected body of anonymised high-quality decisions. Prosecutors will not be able to rely solely on the tool’s output, and human oversight will apply throughout. The system is being designed to be scalable, so that other criminal laws and prosecutorial tasks may be added.

Legal research, analysis and drafting support

Prosecutors may use publicly available AI tools (such as general-purpose large language models) for legal research. As at July 2026, no dedicated legal research AI system has been reportedly used by prosecutors.

Courts

Most AI developments in the Latvian judiciary are guided by the Court Administration—a state institution responsible for the organisational, financial, and administrative support of the country’s court system—and aim to improve case management, broadly understood as the provision of administrative support to courts.

Case management

The Court Administration of Latvia announced in August 2025 that a new anonymisation tool with AI elements has been introduced into document processing. This effort builds on prior anonymisation tools that relied on algorithms and selective reviews by Court Administration staff. The tool automatically identifies and processes personal data in court decisions, replaces sensitive data with pseudonyms, and allows manual correction and supplementation by staff. By the end of 2025, the tool had anonymised 411,005 court decisions.

The Court Administration of Latvia has also integrated a transcription capability into its broader audio or video recording system, which was introduced to digitise the recording of court hearings. As at July 2026, the transcription feature is being tested and uses AI to automatically convert spoken audio from court proceedings into written text, streamlining how hearings are documented. The wider system also stores hearing data, identifies judges and participants, and lets users mark significant procedural moments with timestamps or bookmarks.

In 2019, the Court Administration developed a prediction model for the duration of civil cases. The tool uses machine learning fed by data on resolved cases, judges, courts, case types, previous durations, and party information to predict how long a civil case will take. The current operational status of this tool as at July 2026 has not been confirmed in publicly available sources.

Legal research, analysis and drafting support

As at July 2026, no specific AI tool for legal research has been publicly identified as officially sanctioned for use within the courts, though the Supreme Court is reportedly developing an AI-powered caselaw search tool (meklētājs) to enable judges to locate court rulings and other materials more easily. As at July 2026, this system is not operational.

Defence

Reported use of AI by defence counsel in Latvia is limited. Nevertheless, there is a growing use of AI tools for legal research, analysis and drafting support.

Legal research, analysis and drafting support

Two Latvian-developed AI legal research tools are in active commercial use by legal practitioners, which may include Latvian defence lawyers. Both tools are private-sector commercial products:

Lexu AI

Lexu AI is an AI-powered caselaw research platform developed by the Latvian company Lexu AI. Its features include semantic (natural language) search of Latvian court decisions, AI-generated case summaries, similar ruling identification, citation generation, and advanced filtering by law article or judge name. The platform has a formal cooperation agreement with the Faculty of Law at the University of Latvia, and has been adopted as a daily tool by COBALT, one of the leading Baltic law firms. Lexu AI is working to integrate features for the CJEU and ECtHR databases.

ECLI.ai

ECLI.ai was developed by Latvian law firm iLaw in collaboration with technology partners and launched in March 2026. It is an AI-enabled intelligent database built on the European Case Law Identifier (‘ECLI’) system, providing structured access to Latvian court decisions and legal acts. Features include full anonymised rulings in one place, automatic citation generation, analysis of relationships between legal acts, and tracking of case progress across court instances.

Victims

In Latvia, victims of crime (cietušie) have formal legal standing under the Criminal Procedure Law (Kriminālprocesa likums) (‘CPL’). Under Section 95 CPL, a victim is a natural or legal person who has suffered moral, physical, or financial harm as a result of a criminal offence. Victims are entitled to participate in criminal proceedings as a party (procesa dalībnieks), with rights including: the right to be informed of the proceedings; the right to submit evidence and applications; the right to access case materials; the right to make statements at trial; and the right to appeal procedural decisions. Under Section 96 CPL, victims who choose not to participate actively nonetheless retain certain notification rights. Victims may also bring a civil claim within criminal proceedings (Section 350 et seq. CPL). Latvia’s victim participation framework thus affords victims direct legal standing as a party to criminal proceedings.

Administrative support

A virtual AI assistant, called Justs, has also been introduced by the Court Administration of Latvia. Built on Hugo.lv, a public administration language tool, Justs uses natural language processing to respond to users’ most frequently asked questions about court services, electronic procedures, and contact information. The assistant operates around the clock, reducing the need for in-person visits to court offices and alleviating routine workload from court staff. Its knowledge base is continuously updated by human trainers and expands through ongoing user interactions.

TRAINING

As at July 2026, there is no mandatory or systematic training on the responsible use of AI by law enforcement, prosecutors, judges, or legal professionals in Latvia, though ad hoc training initiatives have been provided.

For law enforcement, under the UN Interregional Crime and Justice Research Institute ‘AI for Safer Children’ initiative, a regional training was held in Riga in May 2024, bringing together over 30 law enforcement participants from the Latvian State Police (including the Cybercrime Enforcement Department) and Estonian law enforcement. Participants explored the application of various AI tools throughout an investigative workflow, including victim and suspect identification, with presentations from technology providers including SAS Software, Web-IQ, ZiuZ, Epieos, GeoComply, and Griffeye Analyze DI Core. As at July 2026, there are no reports of further training initiatives for law enforcement officers in Latvia.

We are very happy that the AI for Safer Children team managed to come to Latvia and put together this whole nice agenda. It was very interesting and exciting, and it was great that some of the tool providers could come in person. It was a great opportunity to learn from our colleagues and make some direct contacts. There are only benefits to this kind of training. […] One person to check everything is impossible. That is why it is great that they created some tools to help us humans to find where there is actual child sexual abuse material.

Janis Markuns, Chief of the Cybercrime Enforcement Department, State Police of Latvia, May 2024
elina-emurlaeva-nkOutgo2eiw-unsplash

For prosecutors, the Prosecutor General’s Office has carried out recurring training activity in this area. According to its annual reports, the prosecution service organised 16 training events for 181 participants in 2024 in the field of information and communication technologies, including cybersecurity and AI, and 12 events for 93 participants in 2025 on digital skills, AI, cybersecurity, and related topics.

For judges, the Supreme Court has reported on a seminar entitled ‘Digitalisation and AI in Criminal Law,’ which forms part of an EU-supported 2024–2027 project comprising 12 seminars held across different EU cities. The seminar addressed electronic evidence, digital investigation methods, and the impact of AI on criminal proceedings, and was aimed at judges, prosecutors, and investigators.

As at July 2026, there are no reports of training programmes for Latvian lawyers on the responsible use of AI.

REGULATION

Latvia’s regulatory framework for AI in criminal proceedings is shaped primarily by EU law. As at July 2026, there are no express national statutory regulations or judicial guidelines governing the use of AI in criminal proceedings specifically. However, existing laws regulating data protection and criminal procedure may be construed to regulate the use of AI, as set out below.

AI regulations

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is a key part of the legal framework regulating the use of AI across the EU. It entered into force on 1 August 2024, and sets out a comprehensive legal framework aiming to ‘guarantee safety, fundamental rights and human-centric AI’. The EU AI Act is being phased between 2025 and 2030. Latvia is obliged to implement and comply with the provisions of the Act, which set out a harmonised legal framework for ‘the development, the placing on the market, the putting into service, and the use’ of AI systems across the EU.

The EU AI Act introduces a risk-based approach, categorising AI systems into four levels of risk, banning ‘unacceptable-risk’ systems, and imposing strict obligations on high-risk systems. The rules on prohibited uses have applied since 2 February 2025, the rules on general-purpose AI models and the designation of competent national authorities have applied since 2 August 2025, while obligations related to the use of high-risk AI systems are being introduced later.

The EU AI Act includes explicit references to AI systems related to the administration of justice, and to criminal proceedings. These are mainly classified as high-risk given ‘their potentially significant impact on ... the rule of law, individual freedoms ... the right to an effective remedy and to a fair trial’ as well as the right to defence and the presumption of innocence, particularly if ‘such AI systems are not sufficiently transparent, explainable [or] documented’. The Act highlights the potential ‘difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation’.

EU AI Act’s risk-based approach

Unacceptable risk (prohibited)

AI systems posing ‘a clear threat to safety, livelihood and rights of people’ are prohibited. This includes uses in law enforcement and criminal justice such as (1) assessing or predicting an individual’s criminal offence risk ‘based solely on the profiling of a natural person or on assessing their personality traits and characteristics’; (2) undertaking ‘untargeted scraping of the internet or CCTV footage’ to build or expand facial recognition databases; and (3) deploying ‘real-time remote biometric identification systems in public spaces or biometric categorisation to infer race, religion or other protected characteristics’, although narrow exceptions exist.

High-risk (subject to strict obligations)

AI systems that ‘can pose serious risks to health, safety or fundamental rights’ are deemed ‘high-risk’ under Article 6. This includes the use of AI (1) to assess the risks of persons ‘becoming the victim of criminal offences’, (2) to assess the risk of persons ‘offending or re-offending’ in certain circumstances and to profile persons during investigations or prosecutions, (3) to evaluate the reliability of evidence ‘in the course of investigations or prosecution of criminal offences’, (4) for remote biometric identification, biometric categorisation in certain circumstances, and emotion recognition, and (5) ‘to assist judicial authorities in researching and interpreting facts and law’ and ‘applying the law to the facts’ (emphasis added). AI systems used for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases are not considered high-risk.


High-risk AI systems are subject to strict obligations for developers, providers and users, including risk assessment, human oversight, the use of high-quality training data and ensuring explainability, accuracy, robustness and cybersecurity. When AI systems assist judicial decision-making, the persons concerned must be informed about the use of AI systems, and be provided with explanations about the role of AI in the decision-making process.

Limited risk (subject to transparency obligations)

This category refers to the risk associated with a need for transparency around the use of AI such as chatbots. Specific disclosure obligations apply for this category.

Minimal risk (no requirements)

Minimal risk or no risk AI systems are not subjected to any requirements.

Articles 51-56 of the EU AI Act establish a specific regime for ‘general-purpose AI models’, defined in Article 3(63) as models trained on large datasets capable of performing a wide range of tasks. They typically include large language models (‘LLMs’) that can be integrated into legal research platforms, drafting tools or judicial support systems. Providers of such models must:

  • maintain technical documentation;
  • provide information to downstream integrators;
  • comply with EU copyright law; and
  • publish a summary of training data.

Under Articles 55-56, additional obligations apply to general-purpose AI models presenting systemic risk, including risk assessment, mitigation measures and incident reporting. The framework is particularly relevant to the judicial sector given that courts and prosecutors may rely on external LLM-based tools rather than developing their own systems.

In terms of governance and enforcement of the EU AI Act, the Act adopts a two-pronged approach. At the EU-level, according to Articles 64-69 of the AI Act, the AI Office of the European Commission and an AI Board (Article 65) are the main actors. The AI Office enjoys enforcement powers with respect to obligations of general-purpose AI models (Article 88 et seqq.). The AI Board assists the European Commission and the Member States in facilitating coherent applications of the AI Act, and therefore contributes to the coordination among national authorities (Article 66(a)).

According to Latvia’s AI Act implementation report (February 2025), the Ministry of Smart Administration and Regional Development is the authority responsible for overall implementation of the AI Act and for cooperation with the European Commission. Market surveillance for prohibited AI practices and high-risk AI systems is carried out across sectors, with bodies such as the State Security Service and the Office for Constitutional Protection responsible for surveillance within their respective domains. The Ombudsman performs the functions of the authority for the protection of fundamental rights under the Act.

Several non-binding guidelines have already been published by the European Commission to provide further directions when implementing the AI Act:

  • Guidelines on prohibited artificial intelligence (AI) practices (published on 04 February 2025) provide legal explanations and practical examples of AI practices that are deemed unacceptable and hence prohibited by Article 5 of the AI Act, due to their potential risks to European values and fundamental rights. The guidelines specifically address practices such as harmful manipulation, social scoring, and real-time remote biometric identification, among others.
  • Guidelines on AI system definition (published on 06 February 2025) explain the practical application of the legal concept of AI to assist providers and other relevant persons in determining whether a software system constitutes an AI system. The guidelines elaborate on each of the seven elements of the definition of an AI system provided by Article 3(1) AI Act: (1) machine-based system, (2) autonomy, (3) adaptiveness, (4) AI system objectives, (5) inferencing how to generate outputs using AI techniques, (6) outputs that can influence physical or virtual environments, and (7) interaction with the environment.
  • As at July 2026, other guidelines are being developed by the European Commission. For instance, the Commission has issued Draft guidelines on the classification of high-risk AI systems, setting out the Commission’s interpretation of certain concepts that are relevant for classification purposes, and contain practical examples of AI systems that should or should not be classified as high-risk. High-risk uses of AI systems may include, for example, tools for the assessment of an individual’s risk of offending or reoffending, generating risk scores, profiling identified persons, or otherwise supporting operational law-enforcement decision-making. The Guidelines emphasise that classification depends on the system’s intended purpose and practical use, rather than solely on how it is labelled by the provider.

Other European Regulations and Guidelines

At the European level, the AI Act coexists with additional regulations and guidelines:

Ethics Guidelines for Trustworthy Artificial Intelligence (2019)

Prior to the adoption of the AI Act, the High-Level Expert Group on AI set up by the European Commission presented the Ethics Guidelines for Trustworthy Artificial Intelligence on 8 April 2019. These guidelines provide a framework to achieve trustworthy AI based on fundamental rights as enshrined in the Charter of Fundamental Rights of the European Union (EU Charter).

The Guidelines put forward a set of seven key requirements that AI systems should meet in order to be deemed trustworthy:

  1. Human agency and oversight
  2. Technical robustness and safety
  3. Privacy and data governance
  4. Transparency
  5. Diversity, non-discrimination and fairness
  6. Societal and environmental well-being
  7. Accountability

The Guidelines are non-binding; Latvia, as an EU Member State, is encouraged to apply them through national AI strategies and public procurement, but they impose no legal obligations.

European Declaration on Digital Rights and Principles for the Digital Decade (2022)

The European Commission adopted on 26 January 2022 the European Declaration on Digital Rights and Principles for the Digital Decade. This Declaration affirms the commitment of European institutions to ‘ensuring transparency’ in AI, guaranteeing the quality of data, preventing these tools from being used to predetermine individuals’ choices, and providing safeguards to protect individuals’ fundamental rights. Chapter III specifically declares that everyone shall be able to make ‘free and informed choices in the digital environment, while being protected from risks and harm to their health, safety, and fundamental rights’.

The Declaration is a political declaration without binding legal force; it provides interpretive guidance for EU institutions and Member States implementing digital legislation, including the EU AI Act.

Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (2024)

The Council of Europe adopted in May 2024 the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, which is the ‘first-ever international legally binding treaty’ regulating AI. The Convention establishes rules relating to respect for fundamental rights at all stages of the AI systems lifecycle, which must be transposed into the domestic law of the signatory states.

The Convention establishes seven fundamental principles for AI systems development: human dignity and individual autonomy (Article 7), transparency and oversight (Article 8), accountability and responsibility (Article 9), equality and non-discrimination (art. 10), privacy and personal data protection (Article 11), reliability (Article 12) and safe innovation (Article 13).

The Convention applies across all public and private uses of AI where human rights may be affected, including within law enforcement, prosecution and judicial activities. It mandates risk and impact assessments to mitigate potential harms and provides safeguards such as the right to challenge AI-driven decisions.

The Convention has been signed on 5 September 2024 by Latvia (as part of EU signature), but has not yet come into force. Once it is in force, it will require Latvia to ensure its legal framework provides for individual remedies and oversight mechanisms in relation to AI systems affecting human rights.

European Ethical Charter on the use of AI in judicial systems and their environment (2018)

Similarly, the European Ethical Charter on the use of AI in the judicial systems and their environment has been adopted by the Council of Europe’s European Commission for the Efficiency of Justice (CEPEJ) in December 2018. It lays out five basic principles relating to the use of AI in judicial systems:

  1. Respect for fundamental rights (‘ensure that the design and implementation of AI tools and services are compatible with fundamental rights’),
  2. Non-discrimination (‘specifically prevent the development or intensification of any discrimination between individuals or groups of individuals’),
  3. Quality and security (‘with regard to the processing of judicial decisions and data, use certified sources and intangible data with models conceived in a multi-disciplinary manner, in a secure technological environment’),
  4. Transparency, impartiality and fairness (‘make data processing methods accessible and understandable, authorise external audit’),
  5. Under user control (‘preclude a prescriptive approach and ensure that users are informed actors and in control of their choices’).

The Charter is a soft-law instrument of the Council of Europe applicable to all Member States including Latvia; it is not legally binding but provides the authoritative normative framework for AI in judicial systems.

Additional domestic AI-specific legislation

Additional AI-specific laws have entered into force in Latvia, including:

  • Law on the Latvian AI Centre (2025): establishes the Latvian AI Centre as a State-supported public foundation to coordinate national AI policy, manage a regulatory sandbox (‘special regulatory environment’) for testing and developing AI solutions, and foster cooperation between public authorities, private sector and academia. Administrative acts issued by the Centre may be appealed under the Administrative Procedure Law.
  • Law on the Development of AI (2025): sets strategic objectives for Latvia’s national AI ecosystem, including the promotion of AI literacy and the ethical use of automated systems in public administration. Liability for unlawful AI use remains governed by existing administrative, civil and criminal law.

Guidelines for practitioners

As at July 2026, the only publicly available guidelines issued for practitioners in Latvia relate to prosecutors. There are no publicly available judicial guidelines or bar association guidance expressly addressing the use of AI in criminal proceedings. The general professional ethics obligations applicable to lawyers and judges under Latvian law, including duties of competence and confidentiality, apply to AI use, though no authoritative specific guidance has been issued in this regard.

As at July 2026, Latvia has not formally engaged with the UNESCO Guidelines for the Use of AI Systems in Courts and Tribunals (2025).

Latvian Council of Sworn Advocates, Guidelines on the Use of Artificial Intelligence Tools in Advocates’ Practice (2026)

In January 2026, the Latvian Council of Sworn Advocates issued Guidelines on the Use of Artificial Intelligence Tools in Advocates’ Practice, grounded in the Latvian Sworn Advocates Code of Ethics, the General Data Protection Regulation (see below), and EU law including the EU AI Act. The Guidelines aim to promote conscious, responsible, ethical AI use, and to identify and prevent risks to confidentiality, data protection, and client interests in order to strengthen public trust in the profession.

The Guidelines impose ten core obligations:

    1. Regulatory compliance: advocates have an ongoing duty to align AI use with applicable law and Bar guidance;
    2. Competence and informed choice: advocates should understand a tool’s data sources, hallucination risk, and limits before use. Advocates cannot use AI to give advice in areas beyond their own expertise;
    3. Confidentiality and data protection: advocates should assess a tool’s data handling before inputting client data and anonymise inputs if confidentiality cannot be guaranteed. Explicit informed consent is required before inputting identifying data into self-learning tools without an opt-out;
    4. Independence and professional responsibility: the advocate, not the tool, is responsible for all decisions;
    5. Verification and supervision: AI output must be checked for factual or legal accuracy before use, and an advocate remains liable for all AI output adopted as their own;
    6. Client information and consent: an advocate retains control and can disclose AI use to clients while personally handling final review;
    7. Advertising and public communication: AI-generated marketing must be truthful, not misleading, and AI chatbots interacting with the public must disclose that they are AI, and not an advocate;
    8. Collaboration and staff training: firms should set internal procedures on AI use and train staff on ethics and risks;
    9. Traceability and cybersecurity: advocates should keep documentation of which tools are used and how, and implement safeguards against unauthorised data access; and
    10. General precautions: advocates should treat AI adoption like outsourcing or hiring staff, requiring prior assessment, clear policies, and active oversight.

Regional guidelines on judiciary’s use of AI

There are several European-level guidelines that address the judiciary’s use of AI, most notably the European Ethical Charter on the use of AI in judicial systems and their environment adopted by the European Commission for the Efficiency of Justice (CEPEJ) of the Council of Europe (discussed above).

Other initiatives have given rise to guidelines for justice system professionals and for lawyers:

Sector

Title

Contents

Council of Bars and Law Societies of Europe

Considerations on the Legal Aspects of Artificial Intelligence (2020)

According to the Council of Bars and Law Societies of Europe, for the sake of transparency and in order to enable individuals to defend their rights, it seems appropriate that the persons impacted by the use of an AI system should be duly informed that AI is being used and that data concerning the individual may be considered by an automated system.


The Considerations are non-binding but carry persuasive authority for Latvian advocates.

Council of Bars and Law Societies of Europe

Guide on the Use of Artificial Intelligence-Based Tools by Lawyers and Law Firms in the EU (2022)

The Guide emphasises that lawyers should have at least a general understanding of how AI tools function. Where such understanding is lacking, this should be clearly communicated to clients and taken into account in the provision of legal services. Ultimately, under existing professional rules, lawyers remain fully responsible for the quality of their services and the outcomes for their clients, even where AI tools are used.


The Guide is non-binding but carries persuasive authority for Latvian advocates.

Court of Justice of the EU

Artificial Intelligence Strategy (2023)

While the AI Strategy does not address the disclosure of AI use, it emphasises that once AI solutions, procedures, methods and governance are put in place, staff awareness and knowledge level should ensure that the reasoning behind AI algorithms are clear and understandable, both for those created in-house and those acquired.


The Strategy is applicable to Latvia in the sense that Latvia’s courts are bound by CJEU rulings and operate within the EU judicial system.

European Bars Federation

Guidelines 2.0 on How Lawyers Should Take Advantage of the Opportunities Offered by Large Language Models and Generative AI (2024)

The Guidelines explain that lawyers should maintain transparent communication with their clients regarding the use of generative AI in their legal practice. Lawyers should clearly explain the fact that they use it, as well as the purpose of such use, benefits, limitations, and guarantees, ensuring that clients understand the role of this technology in legal matters.


The Guidelines are applicable to Latvia. The Latvian Council of Sworn Advocates is a member of the European Bars Federation.

Council of Europe

Use of Generative AI by Judicial Professionals in a Work-Related Context (2024)

The aim of this note is to give some preliminary thought to what judges and other public sector justice professionals can expect from the use of generative AI tools in a judicial context. The Council reiterated that it is essential, in particular in the case of justice, to be transparent about the use of generative AI as the relationship with the litigant is based on trust.


Applicable to Latvia as a Council of Europe Member State.

Criminal procedure rules

Though no specific provisions governing the admissibility, challenge, or disclosure of AI-generated or AI-reviewed evidence have been identified in Latvian criminal procedure law, existing Latvian criminal procedure rules establish standards for evidence admissibility that may apply to AI-generated or AI-analysed evidence.

Criminal Procedure Law (2005)

Evidence in criminal proceedings is governed by Chapter 9 (Sections 127–137) of the Criminal Procedure Law. Under Section 127, evidence consists of any facts obtained in the manner prescribed by law and consolidated in the required procedural form, which directly or indirectly confirm or refute circumstances to be established in criminal proceedings. Evidence must satisfy three criteria: relevance (attiecināmība) — the facts must bear on the circumstances to be proved; admissibility (pieļaujamība) — the facts must have been obtained from lawful sources and through lawful means, without use of prohibited techniques; and reliability (ticamība) — the content must be credible.

Under Section 130(1), facts obtained during criminal proceedings may only be used as evidence if obtained and procedurally consolidated in the manner prescribed by the Criminal Procedure Law, and failure to satisfy these requirements renders evidence inadmissible. Section 136 separately recognises electronic evidence (elektroniskie pierādījumi) as a distinct category — defined as facts in electronic information form processed, stored or transmitted by automated data processing devices or systems — with data types including subscriber data, location data, traffic data, content data and metadata. This is the existing procedural category most directly applicable to AI-processed material, pending any future AI-specific evidentiary provisions.

Under Section 11(3) of the Criminal Procedure Law, documents that do not contain testimony must be translated using a machine translation tool, with a corresponding annotation. Full or partial human translation is provided only where the person directing the proceedings considers it necessary. This provision is significant in two respects: firstly, it is one of the very few provisions of Latvian criminal procedure law that expressly addresses AI-related tools; and secondly, it mandates the use of AI for a specific task, making machine translation the default method and human translation the exception requiring case-by-case justification by the prosecuting authority.

Amendments to the Criminal Code (2024)

In 2024, the Saeima (Latvian Parliament) approved amendments to the Criminal Code, introducing two new AI-related criminal offences:
  1. Article 90.1 criminalises the deliberate production or dissemination of deepfake content that is intentionally inaccurate and intended to discredit a political party, electoral alliance, or candidate standing in parliamentary, local authority, or European Parliament elections. The offence applies only during the pre-election campaign period or on election day, and carries a maximum penalty of five years’ imprisonment, together with temporary deprivation of liberty, probation supervision, or community service as alternatives.
  2. Article 90.2 criminalises the deliberate production or dissemination of false discrediting deepfake content targeting candidates for the position of highest state officials who are elected, appointed or confirmed by the Saeima during the legally prescribed process of election, appointment, or approval of a state official. The same penalty range provided for under Article 90.1 applies.

These amendments are supplemented by further Amendments to the Pre‑election Agitation Law (Grozījumi Priekšvēlēšanu aģitācijas likumā), which were adopted by the Saeima (Parliament of the Republic of Latvia) on 24 October 2024 and promulgated by the President on 6 November 2024. These amendments entered into force on 7 November 2024. The package inserts a new Article 3.1 imposing mandatory labelling where AI systems produce paid pre‑election content depicting a person or fabricated event (image, audio or video), prohibits automated fake or anonymous social‑media accounts, and grants the Corruption Prevention and Combating Bureau (Korupcijas novēršanas un apkarošanas birojs) authority to order the removal of AI‑generated agitation material.

Futuristic Code Display

Data protection legislation

In addition to the EU AI Act, EU data protection regulations must be observed with regard to the use of AI in criminal proceedings. The EU AI Act does not seek to affect existing Union law governing the processing of personal data (according to Article 2 No. 7 AI Act and Recital 10). Data protection law governing the use of personal data may be relevant with regard to various stages of the AI lifecycle. Personal data can be relevant during AI development (e.g., collection and use of data for training) and AI use (e.g., personal data as input data).

On 25 January 2012, the European Commission presented the Data Protection Reform package, proposing a directive (LED) and a regulation (GDPR). On 27 April 2016, the European Parliament and the Council adopted:

  • The Law Enforcement Directive (Directive (EU) 2016/680) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data (‘LED’).
  • The General Data Protection Regulation (Regulation (EU) 2016/679) of the European Parliament and of the European Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (‘GDPR’).

The GDPR remains the primary regulation for ‘general’ processing of data, but the LED is the lex specialis for criminal matters, since it governs processing ‘for the purposes of the prevention, investigation, detection, or prosecution of criminal offences or the execution of criminal penalties’. These regulations have distinct scopes of application that are intended to be complementary.

In both regulations, ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 3 (1) LED and Article 4 (1) GDPR). As at July 2026, this term also includes pseudonymised data as indicated by Article 4 (5) GDPR. Recital 26 sentence 2 of the GDPR points out that identifiability should (still) be recognised in view of pseudonymised personal data that could be assigned to a natural person based on additional information.

On 6 and 25 May 2018 respectively, the GDPR and the LED were implemented across all EU Member States.

EU Directive 2016/680, Law Enforcement Directive (LED) (2016)

The directive governs the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection, and prosecution of criminal offences or the execution of criminal penalties.

The rights of data subjects are recognised but may be limited in order to ensure the proper conduct of investigations, prevention, and the prosecution of offences. These rights include the right to information, the right of access (often exercised indirectly through the supervisory authority), and the right to rectification or erasure. As such, the directive imposes obligations on data controllers that are comparable to those of the GDPR, but creates additional obligations that are specific to the criminal context:

  1. There must be a clear distinction among categories of data subjects: those suspected of committing or planning a criminal offence, those who have been convicted, victims of crimes, and individuals who may be at risk of becoming victims. It also includes third parties connected to a crime, such as potential witnesses, people who can provide information, and contacts or associates of the individuals mentioned above, as set out in Article 6.
  2. The processing of special categories of personal data is strictly regulated under Article 9(2) of the GDPR and requires the data subject’s consent, which shall be freely given and well-informed, or for a legitimate purpose. But the LED establishes a specific exception for criminal matters: Article 10 permits the processing of sensitive data without consent when it is strictly necessary, provided that appropriate safeguards are implemented.
  3. The LED also addresses automated individual decision-making. A decision ‘based solely on automated processing, including profiling, which produces an adverse legal effect concerning the data subject or significantly affects him or her’, is prohibited unless authorised by Union or Member State law to which the controller is subject and which provides appropriate safeguards for the data subject´s rights and freedoms of at least the right to obtain human intervention on the part of the controller (Article 11 (1)). The EU legislator specifies that this right to intervention comprises the right to express his or her point of view, to obtain an explanation of the decision reached after such assessment or to challenge the decision (Recital 38). Furthermore, such decisions shall not be based on special category data, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union memberships, as well as genetic data, biometric data, data concerning health or a natural person’s sex life or sexual orientation, unless suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place (Article 11 (2)). The LED further prohibits profiling resulting in discrimination against natural persons on the basis of special category data (Article 11 (3)).
  4. In order to protect individuals’ rights during criminal investigations, Articles 13 and 14 provide for information and access rights, while allowing limitations where their exercise could undermine ongoing investigations or prosecutions.
  5. Article 16 complements these safeguards by providing the right to request the rectification of inaccurate data and the erasure of data, and in the event of refusal, the possibility of lodging a complaint with a supervisory authority or seeking judicial remedy.
  6. Finally, Articles 27 and 29 impose obligations relating to risk assessment and data security, requiring competent authorities to assess the impact of high-risk processing operations and to implement appropriate technical and organisational measures throughout the criminal procedure.

Latvia’s Law on the Processing of Personal Data of Natural Persons in Criminal Proceedings and Administrative Offence Proceedings, adopted 8 July 2019 and entering into force on 5 August 2019, transposes the Law Enforcement Directive (EU) 2016/680 into Latvian law.

Regulation (EU) 2016/679, General Data Protection Regulation (GDPR)

The GDPR protects fundamental rights in the digital landscape by imposing obligations on data controllers and processors upon all processing of personal data. Hence, in the area of criminal justice, the GDPR is relevant for (i) the processing of personal data collected by competent authorities for the purposes set out above but intended to be further processed for other purposes, (ii) the processing by public bodies for other purposes from the outset (this includes, e.g., archiving conducted by criminal justice authorities), and (iii) any processing by natural persons or private entities (Article 9 (1) and (2) LED, Article 2 (1) GDPR, Recital 19 to GDPR).

Obligations placed on data controllers include: lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability; transparency and information duties; security obligations; data protection impact assessments. The GDPR also grants basic rights to data subjects such as access, rectification and erasure of personal data.

Compared to the LED, the GDPR establishes a higher level of protection regarding the lawfulness of processing. Several aspects of criminal proceedings are subject to the following provisions of the GDPR:

  1. Article 10 requires the processing of personal data relating to criminal convictions and offences to be carried out ‘only under the control of official authority’, and to provide for ‘appropriate safeguards for the rights and freedoms of data subjects’.
  2. Paragraph 1 of Article 22 prohibits any decision that produces legal or similar effects based exclusively on automated data processing. This serves as a key safeguard against ‘algorithmic judges’ or fully automated sanctions.
  3. Paragraph 1 of Article 35 provides that the controller must carry out a data protection impact assessment prior to any processing likely to pose a high risk to the rights and freedoms of individuals, particularly when new technologies are involved. A single assessment may cover multiple similar processing operations presenting comparable risks.

Latvia’s Personal Data Processing Law 2018, entering into force on 5 July 2018, is the primary GDPR-implementing law.

EU AI Act (Regulation (EU) 2024/1689)

Acknowledging both existing data privacy regulations and the relevance of personal data in the AI context, the EU AI Act contains several provisions addressing the use of such data in the course of complying with broader obligations under the AI Act:

  1. The EU AI Act provides a (narrow) legal basis for the processing of special category personal data in the context of training or testing a high-risk AI system. Where such processing is strictly necessary for the purpose of ensuring bias detection and correction in relation to a high-risk system, the providers of such systems may exceptionally process special category data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. Exceptional circumstances exist where (in addition to the requirements for such processing set out in the LED or the GDPR) certain cumulative conditions are met, including where there are technical limitations and state-of-the-art security measures, including pseudonymisation, as well as strict security safeguards (Article 10 No. 5 sentence 2 AI Act).
  2. The data sets for training, validation, and testing of AI systems shall be subject to appropriate data governance and management practices that, in the case of personal data, shall also concern the original purpose of the data collection (Article 10 No. 2 (b) AI Act).
  3. Where applicable, deployers of high-risk AI systems shall use the information provided for such systems under their transparency obligation (Article 13 AI Act) for conducting a data protection impact assessment under the LED or the GDPR (Article 26 No. 9 AI Act).

Cybersecurity laws

EU AI Act (Regulation (EU) 2024/1689)

For high-risk AI systems, the EU AI Act requires resilience against attempts by unauthorised third parties to alter their use, outputs, or performance by exploiting system vulnerabilities (Article 15 (5)), which is confirmed by the underlying Recital 76, emphasising the crucial role of cybersecurity.

EU Cybersecurity Act (2019) and EU Cyber Resilience Act (2024)

As regards the demonstration of compliance with the AI Act’s cybersecurity requirements for high-risk AI systems, two other European regulations may be relevant:

EU Cybersecurity Act (‘CSA’) - Regulation (EU) 2019/881

Aims to achieve a high level of cybersecurity, cyber resilience and trust within the EU and sets forth a framework for the establishment of voluntary European cybersecurity certification schemes for so-called ICT products, i.e., an element or a group of elements of a network or information system (Articles 1 (1) (b), 2 (13) CSA). Where high-risk AI systems are also ICT products, compliance with the cybersecurity requirements laid down in the EU AI Act can be presumed by demonstrating certification under the CSA in so far as such certification covers the AI Act’s respective requirements (Articles 42 No. 2, 15 No. 1, 5 AI Act). Concerning law enforcement and criminal justice, this would be particularly relevant for high-risk AI-enabled software, for instance allowing for biometric identification. In January 2026, the European Commission announced a Proposal for a Regulation for the EU Cybersecurity Act (‘The Cybersecurity Act 2’) aiming at, inter alia, further simplifying the certification process.

Cyber Resilience Act (‘CRA’) - Regulation (EU) 2024/2847

Whereas the CSA establishes a voluntary certification framework, the CRA aims at ensuring that digital products and services are secure by design, resilient against threats, and able to maintain security throughout their life cycle, and sets out mandatory cybersecurity requirements for products with digital elements made available on the market. With most of its provisions applying from December 2027, the CRA will concern a wide range of products placed on the EU market, including AI-enabled software. For high-risk AI systems, compliance with the CRA requirements shall also be deemed to satisfy the AI Act’s cybersecurity requirements in so far as those requirements are covered under the CRA (Recital 51 to the CRA).

EU NIS2 Directive (2022) and Implementing Legislation

At the domestic level, Latvian cybersecurity law is primarily based on the implementation of the EU NIS2 Directive (Directive (EU) 2022/2555), which imposes strict risk management, incident notification, and security obligations on critical entities and public bodies.

In particular, the EU NIS2 Directive establishes a high common level of cybersecurity across the EU, requiring entities subject to the framework to implement comprehensive cybersecurity risk management measures, covering access control, supply chain security, physical security of network systems, and human resources security, while management bodies are personally accountable for approving and overseeing such measures. On incident reporting, the Directive introduces a tiered architecture requiring an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and further reports as the situation develops. At the governance level, Member States must establish national cybersecurity strategies, designate competent authorities, and set up Computer Security Incident Response Teams.

In June 2024, the Saeima (Latvian Parliament) adopted the National Cybersecurity Law to implement the NIS2 Directive.

charlesdeluvio-pjAH2Ax4uWk-unsplash

Human rights

Latvia’s constitutional framework and international obligations provide a layered system of human rights protection relevant to AI use in criminal proceedings.

At the national level, Latvia’s Constitution (Satversme) guarantees the right to a fair trial and access to counsel (Article 92), the right to privacy and protection of personal data (Article 96), and equality before the law (Article 91). These rights apply directly to AI use across the criminal justice chain.

Latvia is also bound by the European Convention on Human Rights, in particular Articles 6 (fair trial), 8 (private and family life) and 14 (non-discrimination), and by the EU Charter of Fundamental Rights, including Articles 7 (privacy), 8 (data protection), 21 (non-discrimination) and 47 (right to an effective remedy and a fair trial). The Charter of Fundamental Rights of the European Union applies to the processing of personal data by AI systems falling within EU law scope, including in the context of criminal proceedings governed by the LED and the EU AI Act. Under Latvia’s implementation plan for the EU AI Act, the Ombudsman has been designated to perform the functions and tasks of the authority for the protection of fundamental rights under the AI Act.

Moreover, the Council of Europe Framework Convention on AI and Human Rights, Democracy, and the Rule of Law deserves special mention as a multilateral initiative, being the first legally binding international treaty specifically designed to regulate AI. Opened for signature in September 2024, its primary objective is to ensure that as AI technologies evolve, they do not erode the fundamental pillars of modern society: human rights, democratic integrity, and the rule of law. As at July 2026, the Convention has not yet entered into force, as the minimum number of five ratifications has not yet been reached. Accordingly, as at July 2026, the Convention has no binding effect in Latvia. The Convention focuses on the lifecycle of AI systems, from design to decommissioning, and mandates adherence to seven fundamental principles: human dignity, transparency, accountability, equality, privacy, reliability, and safe innovation. It requires signatories to establish independent oversight bodies and provide clear legal remedies for individuals who suffer harm due to AI systems.

Latvia ratified the International Covenant on Civil and Political Rights (‘ICCPR’) in 1992. The most directly relevant provisions in the AI and criminal justice context are: Article 14 (right to a fair trial, including the right to be informed of charges, to examine witnesses, and to have adequate time and facilities for the preparation of a defence); Article 17 (right to privacy, applicable to AI-enabled surveillance and data processing); and Article 26 (equality before the law and non-discrimination, relevant to AI systems that may generate or perpetuate discriminatory outcomes in risk assessment or sentencing support). Moreover, the UN Human Rights Committee’s General Comment No. 32 (2007) on Article 14 provides interpretive guidance on fair trial standards applicable to AI-assisted proceedings. No specific national instrument implementing the ICCPR specifically addressing AI has been identified in Latvia.

Latvia ratified the Convention on the Rights of the Child (‘CRC’) in 1992. In the criminal justice context, the most relevant provisions are: Article 37 (prohibition of arbitrary deprivation of liberty; requirement that detention be used only as a measure of last resort); and Article 40 (right of children in conflict with the law to fair treatment and age-appropriate proceedings). AI risk assessment tools used in juvenile proceedings — including any future extension of the prosecution service’s petty crime consistency tool to minors — would need to satisfy the CRC’s best-interests-of-the-child standard (Article 3) and the principle that proceedings take into account the child's age and maturity. No specific instrument implementing CRC measures addressing AI in juvenile proceedings has been identified in Latvia.

Outlook

The EU AI Act will be fully applicable in Latvia from 2 August 2026, with high-risk system requirements covering law enforcement, risk assessment, biometric identification and crime analytics driving significant regulatory and operational change across the criminal justice sector. Under the original Act timeline, rules for high-risk AI systems embedded in regulated products apply from 2 August 2027, though the Council’s Digital Omnibus general approach of March 2026 (see below) proposed extending both deadlines, and that position had not yet resulted in final legislation as of the date of this entry.

European Commission’s Proposed Digital Omnibus Regulation (2025)

In November 2025, the European Commission published its Digital Omnibus Regulation Proposal, a reform package to simplify and streamline existing EU regulations concerning the digital space, including the GDPR and EU AI Act. Respective amendments to the LED are to follow.

Notably, the European Commission intends to amend the definition of the term ‘personal data’ in Article 4 (1) GDPR by stating that information is ‘not to be considered personal data for a given entity when it does not have means reasonably likely to be used to identify the natural person to whom the information relates.’ Accordingly, such an entity would not fall within the scope of the GDPR regarding the processing of such data. This approach is generally in line with CJEU case law establishing that existing additional information enabling an entity to identify the data subject does not as such mean that pseudonymised data are to be considered personal data in all cases and for every person. In other words, personal data can be pseudonymised for one entity and anonymised (and thus not identifiable) for another (EDPS v SRB, 4 September 2025, CJEU, C‑413/23 P). Such an amendment wording would, if implemented, significantly reshape the legal test to be conducted to assess applicability of the GDPR (i.e., the assessment of the existence of personal data) towards an entity-focussed approach and largely exclude pseudonymised data from the scope of the GDPR.

The European Commission, through its Digital Omnibus Regulation, also intends to clarify that the processing of personal data in the context of AI development may be carried out for purposes of a legitimate interest where appropriate (Article 6(1)(f) GDPR). Such an amendment would address an issue that has been widely debated since the emergence of LLMs, and which has also been subject to a dedicated Opinion of the European Data Protection Board (Opinion 28/2024, 18 December 2024, EDPB).

CASES

As at July 2026, there are no reported cases addressing the use of AI tools in criminal proceedings in Latvia.