AI regulation in Croatia is governed primarily by the EU AI Act, which applies directly across all EU member states, including Croatia. Businesses deploying or developing artificial intelligence systems in Croatia must now navigate a layered compliance framework that combines EU-level obligations with emerging national implementation measures. This guide covers the current regulatory landscape, the risk-based classification system, sector-specific rules, enforcement structures, compliance timelines, and the practical steps Croatian-market operators need to take.
The EU AI Act is a directly applicable EU regulation, meaning it does not require transposition into Croatian national law to take effect. It entered into force across the EU and is being phased in progressively, with different provisions applying at different stages. Croatia, as an EU member state, is fully subject to its requirements without any opt-outs or national derogations on the core framework.
The Act establishes a risk-based classification system for AI systems. Systems are divided into four tiers: unacceptable risk (prohibited outright), high risk (subject to strict conformity obligations), limited risk (transparency obligations only), and minimal risk (largely unregulated). The classification of a given AI system determines the entire compliance burden a Croatian-market operator faces.
Prohibited AI practices under the Act include social scoring by public authorities, real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions), and systems that exploit psychological vulnerabilities. These prohibitions applied from an early stage of the Act';s phased rollout, meaning Croatian operators must already have removed or restructured any systems falling into these categories.
A common mistake among foreign companies entering the Croatian market is assuming that because Croatia is a smaller EU economy, enforcement attention will be lower. In practice, the EU AI Act creates uniform obligations regardless of market size, and national market surveillance authorities are required to be operational and active.
The high-risk category is the most consequential for most commercial operators. High-risk AI systems are those used in areas such as critical infrastructure, employment decisions, access to education, essential private and public services, law enforcement, migration management, and administration of justice. If an AI system is used in Croatia in any of these domains, it must meet a demanding set of requirements before being placed on the market or put into service.
Requirements for high-risk AI systems include:
In practice, founders and technology companies should consider whether their product falls into a high-risk category at the earliest design stage, not after launch. Retrofitting compliance into an already-deployed system is significantly more costly and disruptive than building it in from the outset.
Limited-risk systems - such as chatbots or AI-generated content tools - face lighter obligations, primarily around transparency. Users must be informed they are interacting with an AI system. This applies directly to Croatian-market deployments, including customer service tools, marketing automation, and AI-generated media.
While the EU AI Act is directly applicable, member states including Croatia are required to designate national competent authorities responsible for market surveillance and enforcement. Croatia has been in the process of designating its national supervisory structure, consistent with the Act';s requirements for member states to notify the European Commission of their designated authorities.
The Croatian Regulatory Authority for Network Industries (HAKOM) has existing competence in digital and communications sectors and is likely to play a role in the broader digital regulatory ecosystem. However, the specific designation of a national AI supervisory authority - or the allocation of AI Act enforcement responsibilities to an existing body - is a key development that Croatian-market operators must monitor closely.
At the EU level, the European AI Office, established within the European Commission, has direct supervisory authority over general-purpose AI (GPAI) models. This is particularly relevant for Croatian companies or international companies operating in Croatia that develop or deploy large-scale AI models, including foundation models and systems built on top of them.
General-purpose AI models with systemic risk - defined by reference to training compute thresholds set out in the Act - face the most demanding obligations, including adversarial testing, incident reporting to the European AI Office, and cybersecurity measures. Croatian companies building on top of GPAI models as deployers face a different, lighter set of obligations, but must still ensure their downstream use complies with the Act.
Many underestimate the documentation burden. The Act requires technical documentation to be maintained and made available to national authorities on request. For Croatian operators, this means establishing internal document management processes that can produce compliant records on short notice.
Croatia';s economy includes significant activity in tourism, maritime industries, financial services, and increasingly in technology and digital services. Each of these sectors intersects with AI regulation in specific ways.
In financial services, AI systems used for credit scoring, insurance underwriting, or fraud detection may qualify as high-risk under the Act';s Annex III, which lists high-risk use cases in access to essential private services. Croatian financial institutions and fintech operators must assess their AI tools against this classification carefully. The Croatian National Bank (Hrvatska narodna banka) and the Croatian Financial Services Supervisory Agency (HANFA) remain the primary sectoral regulators, and AI compliance obligations layer on top of existing financial regulation rather than replacing it.
In employment, AI systems used for recruitment, performance evaluation, or workforce management decisions are explicitly listed as high-risk. Croatian employers using automated CV screening, AI-driven interview tools, or algorithmic performance management systems must comply with the full high-risk requirements. This is an area where many businesses have deployed AI tools without fully appreciating the regulatory classification.
In healthcare, AI systems used as medical devices or in clinical decision support are subject to both the AI Act and existing medical device regulation. Croatian healthcare providers and health technology companies face a dual compliance burden that requires careful coordination between regulatory frameworks.
A non-obvious requirement is that the obligations under the Act apply not only to developers but also to deployers - businesses that put AI systems into use in a professional context, even if they did not build the system themselves. A Croatian company using an off-the-shelf AI recruitment tool is a deployer and carries its own compliance obligations under the Act.
If your organisation is assessing its AI compliance position in Croatia, we can assist with classification analysis, documentation review, and structuring your internal governance framework. Contact us at info@vlolawfirm.com.
The EU AI Act';s phased implementation means that different obligations have become applicable at different points. The prohibition on unacceptable-risk practices was among the first provisions to apply. Obligations for GPAI models and the governance framework followed. High-risk system requirements are applying progressively, with the full framework for high-risk systems listed in Annex III becoming applicable at a later stage in the rollout.
Croatian operators should not interpret the phased timeline as a reason to delay compliance work. Regulators across the EU, including Croatian authorities, are expected to begin active enforcement as each phase of the Act applies. The Act provides for significant penalties for non-compliance, including fines calculated as a percentage of global annual turnover, with higher percentages for the most serious violations such as prohibited practices.
In practice, the compliance preparation timeline for a high-risk AI system is substantial. Conducting a conformity assessment, preparing technical documentation, implementing a quality management system, and registering in the EU database for high-risk AI systems can take several months even for well-resourced organisations. Croatian companies that have not yet begun this process should treat it as an urgent priority.
The EU database for high-risk AI systems is a public register maintained at EU level. Operators of certain high-risk AI systems are required to register before placing the system on the market or putting it into service. This is a concrete, verifiable compliance step that national authorities can check.
A common mistake is treating AI compliance as a one-time exercise. The Act requires ongoing monitoring, incident reporting, and post-market surveillance for high-risk systems. Croatian operators must build these processes into their operational structures, not treat them as a project with a defined end date.
For most businesses operating in Croatia, the practical starting point is an AI inventory and classification exercise. This means identifying all AI systems in use or under development, mapping them against the Act';s risk categories, and determining the applicable obligations for each.
Key steps in building a compliant AI programme in Croatia include:
Contracts with AI vendors and technology providers also require review. Croatian companies deploying third-party AI systems must ensure their contracts with providers allocate compliance responsibilities correctly and provide access to the technical documentation and information needed to meet deployer obligations.
Data governance is a parallel concern. The AI Act';s requirements for high-risk systems include data quality standards for training data. Croatian operators must ensure their data practices align with both the AI Act and the General Data Protection Regulation (GDPR), which continues to apply in full alongside the new AI framework.
The intersection of the AI Act and GDPR is particularly relevant for AI systems that process personal data - which covers a large proportion of commercial AI applications. Croatian operators should ensure their data protection impact assessments and AI conformity assessments are coordinated rather than conducted in isolation.
---
Does the EU AI Act apply to small and medium-sized enterprises in Croatia?
The EU AI Act applies to all operators placing AI systems on the EU market or putting them into service within the EU, regardless of company size. However, the Act includes some proportionality provisions for SMEs, particularly around the format of technical documentation and access to regulatory sandboxes. Croatian SMEs are not exempt from the core obligations, but they may benefit from simplified documentation formats and from national or EU-level support programmes designed to assist smaller operators with compliance. The key point is that size does not determine whether the Act applies - it may affect how certain obligations are implemented in practice.
How long does it take to achieve compliance for a high-risk AI system in Croatia?
Achieving full compliance for a high-risk AI system is not a short process. Depending on the complexity of the system and the maturity of the organisation';s existing governance structures, the process typically takes several months from start to completion. This includes conducting a conformity assessment, preparing and finalising technical documentation, implementing a quality management system, establishing human oversight mechanisms, and completing registration in the EU database. Organisations that are starting from scratch with limited internal AI governance infrastructure should plan for a longer timeline. Beginning the process well before the applicable deadline is strongly advisable.
What is the difference between a provider and a deployer under the EU AI Act, and which obligations apply to Croatian businesses in each role?
A provider is an entity that develops an AI system and places it on the market or puts it into service under its own name or trademark. A deployer is an entity that uses an AI system in a professional context. The distinction matters because providers carry the primary compliance burden for high-risk systems, including conformity assessment and technical documentation. Deployers have a lighter but still significant set of obligations, including implementing human oversight, monitoring system performance, and informing affected individuals in certain cases. Many Croatian businesses will be deployers rather than providers, particularly those using commercial AI software. Deployers cannot simply assume the provider has handled all compliance - they must verify this and fulfil their own obligations independently.
---
AI regulation in Croatia is now a live compliance matter, not a future concern. The EU AI Act applies directly, its phased obligations are progressively taking effect, and national enforcement structures are being established. Croatian businesses and international operators active in the Croatian market must classify their AI systems, assess their obligations, and build the governance processes required to remain compliant on an ongoing basis.
VLO Law Firms advises international clients on AI regulation in Croatia. We can assist with AI system classification, conformity assessment preparation, vendor contract review, data governance alignment, and ongoing compliance monitoring. To request a consultation, contact: info@vlolawfirm.com