policy · Effective Jan 1, 2024
RS regulates AI through Belgrade Ministerial Declaration on Artificial Intelligence.
Belgrade Ministerial Declaration on Artificial Intelligence · effective 2024
Updated 60 days ago · 2 sources · confidence: medium
Overview
The Republic of Serbia has adopted a highly proactive and strategic approach to the regulation and development of artificial intelligence, positioning itself as a pioneer in Southeast Europe. Serbia was the first country in the region to adopt a dedicated National Strategy for the Development of Artificial Intelligence (2020-2025) and has recently updated this framework with a successor strategy covering 2024-2030. The Serbian regulatory philosophy is characterized by a dual focus: fostering rapid technological innovation to drive economic growth while ensuring that AI deployment remains 'human-centric' and aligned with European ethical standards. This approach is deeply integrated with Serbia's broader digitalization agenda and its aspirations for European Union accession. The government views AI as a critical engine for GDP growth, aiming to integrate these technologies across the public administration, healthcare, and energy sectors. The maturity of Serbia's AI ecosystem is evidenced by its significant institutional investments, including the establishment of the Institute for Artificial Intelligence Research and Development and the deployment of a National AI Platform at the State Data Center in Kragujevac. Serbia's leadership in global AI governance was further solidified in 2024 when it assumed the co-chairmanship of the Global Partnership on Artificial Intelligence (GPAI) and hosted the Belgrade Summit. While the current regulatory environment relies heavily on 'soft law' instruments—such as strategies, ethical guidelines, and ministerial declarations—there is a clear trajectory toward 'hard law' codification as the country prepares to transpose the EU AI Act into its domestic legal framework. This transition is supported by a robust digital infrastructure and a growing community of AI researchers and startups.
Regulatory approach
Serbia currently employs a horizontal, strategy-led regulatory approach that emphasizes ethical principles and infrastructure readiness over prescriptive, sector-specific prohibitions. The framework is primarily 'soft' in nature, utilizing non-binding guidelines and strategic policy documents to shape the behavior of developers and users. The 2023 Ethical Guidelines for the Development, Implementation and Use of Reliable and Responsible AI serve as the primary reference point for ethical compliance, drawing heavily from UNESCO and EU frameworks. This approach allows for flexibility in a rapidly evolving technological landscape while establishing a clear government expectation for 'trustworthy AI' that respects human rights and democratic values. The government has prioritized the creation of an enabling environment, providing state-of-the-art computing resources to researchers and companies that adhere to these ethical standards. Despite the current reliance on non-binding instruments, Serbia is moving toward a risk-based regulatory model. The government has already begun identifying 'high-risk' AI applications—particularly in healthcare, critical infrastructure, and public administration—that will require enhanced oversight. This transition is being managed through the Office for Information Technologies and eGovernment (ITE) and the Ministry of Science, Technological Development and Innovation. By aligning its domestic policy with the EU AI Act's risk classifications, Serbia aims to ensure that its local AI industry remains competitive and compatible with the European Single Market, effectively adopting a 'pre-alignment' strategy before formal legal transposition. This proactive stance is intended to minimize the 'compliance shock' for Serbian businesses when the EU AI Act becomes fully applicable to third-country providers. The governance of AI in Serbia is multi-layered, involving specialized technical offices, traditional ministries, and independent regulatory authorities. The Office for Information Technologies and eGovernment (ITE) serves as the primary technical executor, managing the National AI Platform and the State Data Center. The ITE is responsible for the digital infrastructure that enables AI development across the public sector and ensures that all government-led AI projects comply with technical and security standards. Complementing this is the Ministry of Science, Technological Development and Innovation, which provides the policy lead on research initiatives and oversees the Institute for Artificial Intelligence Research and Development. This institute is a dedicated body focused on bridging the gap between academic research and industrial application, hosting several research clusters in areas like computer vision and natural language processing. Enforcement of ethical and data-related standards currently falls under the jurisdiction of existing regulators. The Commissioner for Information of Public Importance and Personal Data Protection is the primary authority for ensuring that AI systems comply with the Law on Personal Data Protection, particularly regarding automated decision-making and profiling. Additionally, the Council for Artificial Intelligence, a multi-stakeholder body comprising government officials, academics, and industry experts, provides strategic guidance and monitors the implementation of the National AI Strategy. This collaborative governance model ensures that AI policy is not siloed but integrated across various sectors of the Serbian economy, from agriculture to finance.
Enforcement & penalties
Currently, there are no AI-specific penal codes or administrative fines in Serbia; instead, enforcement is achieved through the application of existing legal frameworks. The most significant enforcement mechanism resides within the Law on Personal Data Protection. Under this law, the Commissioner can impose administrative fines of up to 2,000,000 RSD (approximately €17,000) for legal entities, which is notably lower than the EU's GDPR maximums but is often supplemented by corrective orders, such as the suspension of data processing or the deletion of illegally trained models. For public sector entities, non-compliance with government decrees regarding AI use can lead to administrative sanctions and the withdrawal of access to the National AI Platform. As Serbia aligns with the EU AI Act, a more rigorous penalty regime is expected. The government has indicated that future legislation will likely mirror the EU's tiered fine structure for prohibited AI practices and non-compliance with high-risk system requirements. Beyond financial penalties, the Serbian government utilizes 'reputational enforcement' through its ethical self-assessment portal, where organizations are encouraged to publicly demonstrate their compliance with the 2023 Ethical Guidelines. This 'name and shame' or 'name and fame' approach is designed to encourage voluntary compliance among startups. Appeals against regulatory decisions, such as those made by the Commissioner for Data Protection, are handled through the Administrative Court of Serbia, ensuring a level of judicial oversight and due process for AI developers. The future Law on AI is expected to introduce a dedicated AI Inspectorate with the power to conduct on-site audits and seize non-compliant algorithms.
Data protection
The data protection framework in Serbia is defined by the Law on Personal Data Protection (2018), which was drafted to be an exact mirror of the EU's GDPR. This law is the cornerstone of AI regulation in the country, as it governs the collection, storage, and processing of personal data used to train machine learning models. Article 38 of the Law is particularly relevant to AI, as it grants individuals the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or significantly affect them. This provides a critical safeguard against opaque algorithmic decision-making in sectors like banking, insurance, and employment. Serbia does not impose strict data localization requirements for general AI development, allowing for the cross-border flow of data to countries that provide an 'adequate level of protection' (primarily EU/EEA members). However, for AI systems utilized by the public administration, data must be processed within the State Data Center in Kragujevac, which meets Tier III+ security standards. The Commissioner for Data Protection has been increasingly active in issuing opinions on AI-related privacy issues, emphasizing that the principles of 'privacy by design' and 'privacy by default' must be integrated into the earliest stages of the AI development lifecycle. Furthermore, the Serbian framework requires a Data Protection Impact Assessment (DPIA) for any AI system that involves large-scale processing of sensitive data or systematic monitoring of public areas, ensuring that risks to fundamental rights are mitigated before the system is deployed.
Sector-specific rules
While Serbia maintains a horizontal strategy, specific sectors have begun integrating AI-related requirements into their operational frameworks. In Healthcare, the Ministry of Health and the Institute for Public Health are developing protocols for the use of AI in diagnostics and personalized medicine, ensuring that these systems are treated as medical devices subject to rigorous clinical validation. The 2023 Ethical Guidelines specifically identify healthcare AI as a high-risk domain, requiring human-in-the-loop oversight for any system analyzing genetic or health-related data. This ensures that AI assists, rather than replaces, medical professionals in critical decision-making processes. In the Infrastructure and Energy sectors, the government has prioritized the use of AI for smart grid management and traffic optimization. The National AI Platform provides the computing power for these initiatives, but they are governed by the Law on Information Security, which mandates strict cybersecurity audits for any AI system connected to critical national infrastructure. Furthermore, in Agriculture, Serbia has promoted 'Smart Agriculture' initiatives through the BioSense Institute, which uses AI and remote sensing to optimize crop yields. While these are currently promoted through subsidies and innovation grants rather than restrictive laws, they must comply with environmental protection standards and data sharing agreements between the state and private farmers. The financial sector, overseen by the National Bank of Serbia, has also begun issuing recommendations for the use of AI in credit scoring, emphasizing the need for explainability and the prevention of discriminatory outcomes in automated lending.
International alignment
Serbia's AI policy is explicitly designed to achieve maximum alignment with international standards, particularly those of the European Union and the OECD. As a candidate country for EU membership, Serbia is committed to transposing the EU AI Act. The government has established a working group to monitor the Act's implementation in Brussels and to draft the corresponding Serbian legislation. This 'shadowing' of EU law ensures that Serbian AI startups can scale into the European market without facing regulatory barriers. Serbia's 2023 Ethical Guidelines were specifically modeled after the EU's High-Level Expert Group on AI (HLEG) recommendations, ensuring substantive convergence even before formal legal adoption. On the global stage, Serbia is an active member of the Global Partnership on Artificial Intelligence (GPAI). The 2024 Belgrade Ministerial Declaration, endorsed by 44 countries, reflects Serbia's commitment to the OECD AI Principles, which emphasize inclusive growth, sustainable development, and well-being. Serbia also maintains bilateral agreements with various nations for AI research collaboration, but these are always framed within the context of 'responsible AI.' By hosting the GPAI Summit and co-chairing the organization with Slovakia, Serbia has positioned itself as a bridge between emerging AI economies and established regulatory powers, advocating for a balanced approach that promotes innovation while safeguarding fundamental rights. This international alignment is not merely political but also technical, as Serbia adopts international standards for AI interoperability and data exchange.
What's next
The next 24 months will be a transformative period for Serbian AI regulation as the country moves from strategic planning to legislative execution. The primary focus will be the implementation of the Strategy for the Development of Artificial Intelligence 2024-2030, which includes plans for the creation of 'AI Sandboxes.' These regulatory sandboxes will allow companies to test innovative AI solutions in a controlled environment with regulatory oversight, providing a pathway for safe experimentation in high-risk sectors like fintech and autonomous transport. This initiative is expected to be formalized through a government decree or a specific amendment to the Law on Innovation Activity. Legislatively, the most significant upcoming milestone is the drafting of a dedicated Law on Artificial Intelligence. This law will serve as the national transposition of the EU AI Act, establishing a formal classification system for AI risks, mandatory transparency requirements for generative AI, and a national oversight body (an 'AI Office' with expanded enforcement powers). Additionally, the government plans to expand the National AI Platform's capabilities, incorporating more diverse datasets and providing enhanced access for small and medium-sized enterprises (SMEs). As Serbia continues its EU accession negotiations, the alignment of its AI framework with European digital sovereignty and safety standards will remain the top priority for the Ministry of Science and the ITE. There are also plans to introduce AI-specific curricula in primary and secondary schools, ensuring that the future workforce is equipped to handle the ethical and technical challenges of an AI-driven economy.
policy · Effective Jan 1, 2024
guideline · Effective Jan 1, 2023
policy · Effective Jan 1, 2019
advisory
Management of national digital infrastructure and AI platform
central_coordinator
Policy lead for AI research and strategic development
data_protection
Enforcement of data privacy and transparency laws
advisory
Technical advisory and applied AI research
Aug 13, 2024 · law_amended
Serbian data protection regulator launches investigation into Meta's and X's AI training practices
Open source →