Serbia’s first AI law turns regulation into an industrial policy test

Supported byClarion Owners Engineers

Serbia is preparing its first dedicated law on artificial intelligence, a move that marks the country’s transition from early-stage AI strategy into binding regulation. The draft framework is designed to govern the safe and responsible use of AI systems while preserving space for the domestic technology sector to grow. Its core logic follows the European model: AI systems will be classified according to risk, certain forms of use will be prohibited, and final responsibility for high-impact decisions will remain with a human operator rather than an algorithm.

The proposed law comes at a moment when AI has already moved beyond the software sector and into public administration, finance, health, media, education, retail, transport, energy and industrial management. That shift has changed the regulatory question. Serbia is no longer deciding whether AI should be encouraged. It is deciding under what conditions AI can be trusted.

Supported byVirtu Energy

The Ministry of Science, Technological Development and Innovation has framed the new law as a regulation of risk rather than a regulation of technology itself. That distinction is important. AI systems are not all the same. A recommendation engine used by an online shop, an automated customer-service assistant and a diagnostic tool used in healthcare do not carry the same public-interest risk. Nor does a system used to optimise warehouse logistics raise the same legal concern as one used in employment screening, credit scoring, biometric identification or public-sector decision-making.

The Serbian draft appears to recognise this difference by introducing a tiered model of control. Low-risk systems would face lighter obligations, while high-risk applications would be subject to stronger requirements on transparency, documentation, data quality, accountability and human supervision. Certain uses would be banned outright, particularly where AI could be deployed in ways that violate fundamental rights, manipulate individuals, enable discriminatory treatment or remove meaningful human control from decisions that affect people’s lives.

For business, this is more than a compliance story. It is the beginning of an AI governance market. Serbian companies that develop or deploy AI will need to map where these systems are used, document their training and operating logic, identify the risks attached to each use case, and introduce internal controls before regulators, clients or foreign partners demand them. Banks, insurers, telecoms operators, healthcare providers, HR platforms, software exporters and public-sector IT vendors will be among the first groups exposed to the new compliance burden.

Supported byClarion Energy

The law also carries a clear European integration signal. Serbia’s proposed framework is being shaped in line with the EU AI Act, the world’s most advanced attempt to regulate artificial intelligence through a horizontal legal structure. For a candidate country whose technology companies sell services into the European market, this alignment is commercially necessary. Serbian AI developers cannot build one compliance culture for the domestic market and another for EU clients. The closer the domestic framework is to the EU’s risk-based model, the easier it becomes for Serbian firms to prove that their systems meet international expectations.

That does not mean the law will be easy to implement. Serbia has a strong software and engineering base, but AI regulation requires more than programmers. It requires regulators who understand model risk, auditors who can test AI systems, public officials who know how to procure AI responsibly, judges and lawyers who can interpret algorithmic accountability, and company boards that understand that AI risk is now a governance issue rather than an IT issue.

Supported by

The most sensitive area will be public-sector use. Serbia has invested heavily in digital government, e-services and data infrastructure. AI can make administration faster and cheaper, but it can also amplify errors, bias and opaque decision-making if introduced without safeguards. Systems used in welfare, taxation, policing, inspections, education, healthcare or citizen profiling will demand stricter supervision because errors in these areas can affect rights, livelihoods and access to public services.

The proposed requirement that a human being must retain final decision-making authority is therefore central. But in practice, “human oversight” must mean more than a formal signature at the end of an automated process. A human supervisor must be able to understand the basis of the AI output, challenge it, override it and bear responsibility for the final decision. Without that, oversight becomes administrative theatre.

The private sector faces a similar issue. Many companies already use AI tools informally, often without central approval or documentation. Employees use generative AI to draft contracts, analyse customer data, write code, prepare marketing materials and summarise internal documents. In regulated industries, this creates hidden exposure. Confidential information can be uploaded into external systems, biased outputs can enter business decisions, and AI-generated material can be mistaken for verified analysis. Serbia’s new law will likely accelerate the need for internal AI policies, approved tool lists, staff training and audit trails.

The legislation may also reshape the local technology market. Compliance can be costly, but it can also become a competitive advantage. Serbian firms that can demonstrate responsible AI design, documented data governance and EU-compatible risk controls will be better positioned to win enterprise clients, government tenders and cross-border contracts. The same applies to universities, research centres and science and technology parks, which could become part of a broader ecosystem for AI testing, certification, training and applied research.

The strategic question is whether Serbia can use regulation to support innovation rather than slow it. A badly designed law could create uncertainty, deter smaller developers and push experimentation into legal grey zones. A well-designed law could do the opposite: give investors, clients and public institutions confidence that AI systems built or used in Serbia are safe, documented and internationally credible.

That balance will be difficult. Start-ups and SMEs cannot absorb the same compliance costs as banks or large telecoms groups. The law will therefore need proportionate obligations, regulatory sandboxes and practical guidance. Serbia’s AI ecosystem will not benefit from abstract principles alone. It will need templates, sectoral rules, model documentation standards, procurement guidance and supervisory capacity.

The timing is also significant for Serbia’s wider industrial policy. AI is no longer only a digital-sector issue. It is becoming embedded in electricity trading, grid forecasting, manufacturing quality control, mining, logistics, agriculture, healthcare diagnostics and financial risk management. For a country trying to position itself as a regional technology and investment hub, credible AI regulation can help attract projects that require both engineering capacity and regulatory predictability.

There is also a labour-market dimension. AI will change the structure of work in Serbian companies, especially in administration, customer support, programming, accounting, media production, legal services and analytics. Regulation cannot stop that transformation, but it can impose boundaries around accountability and transparency. Employers will need to explain when AI is used in decisions affecting workers, especially recruitment, evaluation, productivity monitoring and termination.

The law’s biggest test will be enforcement. Serbia has often been able to draft frameworks aligned with European standards, while practical implementation has lagged. AI regulation will expose that gap quickly. If enforcement is weak, companies will treat the law as another paper obligation. If enforcement is unpredictable, it could discourage investment. If the rules are clear and applied consistently, the law could become part of Serbia’s credibility package for investors and technology clients.

The planned AI law should therefore be read as more than a legal update. It is an attempt to define the operating conditions for a technology that will shape competitiveness, public administration and corporate governance over the next decade. Serbia has already built parts of the AI ecosystem through strategy, digital infrastructure, universities, science and technology parks and private-sector software capacity. The new law is the point at which that ecosystem becomes subject to formal rules.

For Serbian business, the message is direct: AI adoption is moving from experimentation to regulated deployment. Companies that wait for inspections or client pressure will be late. The immediate task is to identify where AI is already being used, classify the risk, document the process, assign responsibility and prepare internal controls. In the next phase, AI compliance will sit alongside data protection, cybersecurity, financial controls and ESG reporting as a standard part of corporate governance.

Serbia’s first AI law will not determine whether the country becomes an AI economy. That process is already under way. The law will determine whether that economy develops with enough trust, transparency and institutional discipline to be taken seriously by citizens, investors and European partners.

Supported by

RELATED ARTICLES

spot_img
spot_img
Supported byClarion Energy