Serbia is preparing its first dedicated legislation governing artificial intelligence (AI), establishing a regulatory framework intended to oversee the safe and responsible deployment of AI systems while supporting the growth of the country’s technology sector. The proposed law would move Serbia from strategic planning into binding regulation and introduce a risk-based model similar to the approach adopted by the European Union (EU).
Under the draft framework, AI applications would be categorized according to their level of risk. Certain uses would be prohibited, while high-impact decisions would remain subject to final human authority rather than being delegated entirely to automated systems. The legislation arrives as AI adoption expands beyond software development into public administration, finance, healthcare, media, education, retail, transport, energy and industrial operations.
Risk-Based Framework for AI Systems
The Ministry of Science, Technological Development and Innovation has positioned the initiative as a framework for managing risk rather than regulating technology itself. The distinction reflects the differing impacts of AI applications across sectors. Systems used for online retail recommendations, customer service automation and logistics optimization would not be treated in the same way as tools deployed for employment screening, credit assessments, biometric identification or public-sector decision-making.
The proposed legislation introduces varying levels of oversight depending on the potential impact of individual systems. Low-risk applications would face lighter compliance requirements, while high-risk deployments would be subject to stricter standards covering transparency, documentation, data quality, accountability and human supervision. The draft also contemplates outright bans on specific uses of AI, particularly where systems could infringe fundamental rights, facilitate discrimination, manipulate individuals or eliminate meaningful human involvement in decisions affecting citizens.
New Compliance Requirements for Business
For businesses, the framework introduces new governance and compliance requirements. Companies developing or deploying AI technologies would need to identify where AI is used, document training and operational processes, evaluate risks associated with specific applications and establish internal control mechanisms. Sectors expected to face early compliance obligations include banking, insurance, telecommunications, healthcare, human resources technology, software exports and public-sector IT services.
The legislation is being developed in line with the EU AI Act, reflecting Serbia’s broader European integration agenda and the commercial realities facing domestic technology firms operating in European markets.
For Serbian companies supplying AI-enabled services to European clients, regulatory alignment is expected to simplify compliance requirements and support efforts to demonstrate adherence to international standards. The closer Serbia’s framework remains to the EU’s risk-based approach, the easier it may become for domestic firms to meet expectations from foreign customers and partners.
Regulatory Capacity and Oversight
Implementation will require expertise beyond software engineering. Effective oversight will depend on regulators capable of assessing model risk, auditors able to evaluate AI systems, procurement officials familiar with responsible AI acquisition practices and legal professionals equipped to interpret questions of algorithmic accountability. Corporate boards will also face increasing pressure to treat AI oversight as a corporate governance issue rather than a purely technical matter.
One of the most sensitive areas addressed by the proposed framework concerns AI deployment within government institutions. Serbia has invested significantly in digital government services, e-administration platforms and data infrastructure, creating conditions for broader AI adoption across the public sector.
While AI may improve administrative efficiency and reduce operating costs, its use in welfare administration, taxation, policing, inspections, education, healthcare and citizen profiling raises concerns related to transparency, bias and accountability. Systems operating in these areas are expected to require stronger safeguards because errors could affect legal rights, access to services and economic opportunities.
Human Oversight and Corporate Controls
The draft legislation places particular emphasis on maintaining human authority over final decisions. Under the proposed approach, human oversight would require more than formal approval of automated outcomes. Supervisors would need the ability to understand AI-generated outputs, challenge recommendations, override system decisions and assume responsibility for final actions.
Private-sector organizations face parallel challenges as AI tools become embedded in daily operations. Many companies already use generative AI applications for contract drafting, customer analysis, software development, marketing content creation and document summarization, often without centralized oversight.
Such practices may create compliance and operational risks, particularly in regulated industries. Confidential information may be entered into external platforms, biased outputs may influence business decisions and AI-generated content may be treated as verified analysis without sufficient review. The forthcoming legislation is expected to accelerate adoption of internal AI governance measures, including formal AI policies, approved technology lists, employee training programs and documented audit processes.
Market Opportunities and Industrial Impact
The regulatory framework could also influence the development of Serbia’s technology market. Although compliance obligations may increase operational costs, documented AI governance practices could become a competitive differentiator for companies seeking enterprise contracts, government procurement opportunities and international business.
Organizations capable of demonstrating responsible AI development, robust data governance and alignment with European regulatory standards may strengthen their position in domestic and cross-border markets. Universities, research institutions and science and technology parks could also play a larger role in AI testing, certification, training and applied research activities.
The timing of the legislation coincides with expanding AI adoption across sectors including electricity trading, grid forecasting, manufacturing quality control, mining, logistics, agriculture, healthcare diagnostics and financial risk management. As Serbia seeks to strengthen its position as a regional technology hub and investment destination, predictable AI regulation could support projects that require both engineering expertise and stable regulatory conditions.
The labour market is also expected to be affected as AI reshapes work in administration, customer support, programming, accounting, media production, legal services and analytics. The proposed framework would establish requirements around transparency and accountability, particularly when AI tools influence recruitment, employee evaluation, productivity monitoring or termination decisions.
Enforcement Will Be Critical
The effectiveness of the legislation will depend heavily on enforcement. While Serbia has previously adopted regulatory frameworks aligned with European standards, implementation has at times lagged behind legislative development. Weak enforcement could reduce the law to a formal compliance obligation, while inconsistent application could create uncertainty for businesses and investors. Clear rules and predictable supervision, by contrast, could strengthen Serbia’s attractiveness to technology clients, foreign investors and digital economy projects.
The proposed legislation represents a broader effort to define the conditions under which AI technologies will operate within Serbia’s economy and public sector. The country has already developed elements of an AI ecosystem through strategic initiatives, digital infrastructure investments, universities, science and technology parks and private-sector software capabilities. For businesses, the transition signals a shift from experimental AI adoption toward regulated deployment. Companies are expected to increasingly integrate AI governance alongside data protection, cybersecurity, financial controls and ESG reporting within broader corporate governance structures.


