policy · Effective Jan 1, 2025
HR regulates AI through National transposition process / working group for the EU Artificial Intelligence Act.
National transposition process / working group for the EU Artificial Intelligence Act · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Croatia’s regulatory landscape for artificial intelligence (AI) is currently undergoing a significant transition from a strategy-led policy framework to a formal, binding legislative regime driven by its obligations as a European Union Member State. Historically, Croatia’s approach was defined by high-level national development goals, such as the National Development Strategy 2030 and the Digital Croatia Strategy 2032, which identified AI as a key driver for economic growth and public sector efficiency. However, with the adoption of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), the focus has shifted toward the establishment of a robust national governance structure and the formal transposition of EU-wide rules into the domestic legal order. This process is being spearheaded by the Ministry of Justice, Administration and Digital Transformation (MPUDT), which now serves as the central hub for digital policy following the consolidation of various administrative functions previously held by the Central State Office for the Development of Digital Society (SDURDD). The government views AI not merely as a technical challenge but as a strategic asset for national resilience and sovereignty. This philosophy is reflected in the National Recovery and Resilience Plan (NPOO), which allocates substantial funding toward the digital transition, including AI-enabled public services like the automated anonymization of judicial decisions and the modernization of the healthcare system. The overarching goal is to position Croatia as a competitive player within the EU digital economy while ensuring that technology adoption does not compromise the safety or fundamental rights of its citizens. By participating in the EU's harmonized approach, Croatia aims to provide a stable and predictable environment for businesses, fostering innovation through initiatives like the Smart Specialization Strategy (S3) while maintaining high standards of democratic oversight and administrative transparency.
Regulatory approach
Croatia employs a hybrid regulatory approach that combines horizontal, risk-based oversight with sectoral policy integration. The horizontal element is anchored in the EU AI Act, which classifies AI systems based on their potential to cause harm—ranging from "unacceptable risk" (which are prohibited) to "high risk" (which require strict conformity assessments and human oversight). This horizontal framework ensures that AI applications across all domains, from recruitment to law enforcement, adhere to a uniform set of safety and fundamental rights standards. By aligning its national legislation with this EU regulation, Croatia avoids a fragmented legal landscape, providing certainty for businesses and developers operating within the Single Market. The Ministry of Justice, Administration and Digital Transformation is currently leading a multi-sectoral working group to map these EU obligations to existing national laws, ensuring a seamless integration with Croatia's administrative and judicial procedures. Complementing this binding horizontal regulation is a series of "soft law" instruments and strategic plans that guide the development and adoption of AI. The National Plan for the Development of Artificial Intelligence to 2032 and the accompanying Action Plan for 2026–2028 serve as policy roadmaps, focusing on non-regulatory levers such as investment, skills development, and data access. This dual approach allows the government to be prescriptive where safety is concerned while remaining flexible and supportive in areas of research and economic development. Furthermore, Croatia emphasizes an "Entrepreneurial Discovery Process" (EDP) within its Smart Specialization Strategy, which involves continuous dialogue between the state, academia, and the private sector to identify emerging AI trends and adjust funding priorities accordingly. This ensures that the regulatory environment remains responsive to technological advancements without stifling the growth of the domestic ICT sector or the burgeoning startup ecosystem in Zagreb and Osijek. The primary authority responsible for the coordination of AI policy in Croatia is the Ministry of Justice, Administration and Digital Transformation (MPUDT). Following recent administrative reforms, the MPUDT has taken over the functions of the former Central State Office for the Development of Digital Society (SDURDD), centralizing the governance of digital transformation. The ministry chairs the inter-ministerial working group tasked with the national transposition of the EU AI Act. This group includes representatives from the Ministry of Economy, the Ministry of Science and Education, and the Ministry of the Interior, ensuring that AI governance is integrated across different policy domains. The MPUDT is also responsible for overseeing the implementation of the Digital Croatia Strategy and the National AI Plan, acting as the main interface between the government and the European Commission on digital matters. In terms of enforcement and oversight of fundamental rights, the Croatian Personal Data Protection Agency (AZOP) plays a critical role. Given the inherent link between AI and data processing, AZOP has been designated as a key competent authority for monitoring the impact of AI systems on privacy and data protection. Furthermore, Croatia’s governance model includes a strong emphasis on human rights oversight through the participation of various ombudsperson offices, such as the People's Ombudsperson and the Ombudsperson for Children, in the AI working groups. These bodies are tasked with ensuring that AI systems, particularly those used in the public sector, do not lead to discrimination or the erosion of civil liberties. Market surveillance and technical conformity are expected to be handled by specialized agencies under the Ministry of Economy, aligning with existing product safety and technical standard frameworks to ensure that AI products entering the Croatian market are safe and reliable.
Enforcement & penalties
Enforcement of AI regulations in Croatia is primarily governed by the administrative and penal provisions set forth in the EU AI Act, which will be operationalized through national implementing legislation. The Act establishes a tiered system of financial penalties designed to be "effective, proportionate, and dissuasive." For the most severe violations, such as the deployment of prohibited AI practices like social scoring or certain biometric identification systems, fines can reach up to €35 million or 7% of the total worldwide annual turnover of the preceding financial year, whichever is higher. Non-compliance with obligations related to high-risk AI systems or transparency requirements can result in fines of up to €15 million or 3% of turnover. Providing incorrect or misleading information to notified bodies or national competent authorities can lead to fines of up to €7.5 million or 1.5% of turnover. Beyond financial penalties, the Croatian enforcement framework includes administrative measures such as the power to order the withdrawal of non-compliant AI systems from the market or to mandate corrective actions. The Ministry of Justice, Administration and Digital Transformation, in coordination with market surveillance authorities, will oversee these processes. Affected individuals and organizations will have the right to administrative and judicial redress, as guaranteed by the Croatian Administrative Procedure Act and the Constitution. The transposition process specifically aims to align these new AI-specific sanctions with existing national legal principles, ensuring due process and the right to appeal decisions made by regulatory bodies. For public sector entities, non-compliance may also lead to budgetary sanctions or the suspension of funding under the National Recovery and Resilience Plan, creating a strong incentive for government agencies to adhere to the highest standards of AI ethics and safety.
Data protection
The data protection framework in Croatia is anchored in the EU General Data Protection Regulation (GDPR), which is directly applicable and supplemented by the national Act on the Implementation of the General Data Protection Regulation (Zakon o provedbi Opće uredbe o zaštiti podataka). The Personal Data Protection Agency (AZOP) is the central supervisory authority responsible for enforcing these rules. In the context of AI, the GDPR provides the foundational legal basis for data processing, including requirements for lawful basis, purpose limitation, and data minimization. AI systems that process personal data must undergo a Data Protection Impact Assessment (DPIA) whenever the processing is likely to result in a high risk to the rights and freedoms of individuals, which is a common occurrence for AI-driven analytics and profiling. Croatia’s approach to AI data governance also emphasizes the availability of anonymized and open data for innovation, as outlined in the Digital Croatia Strategy 2032. The government is working to establish frameworks for secure data sharing between the public and private sectors, utilizing the State Shared Services Centre (CDU or "state cloud") to ensure data sovereignty and security. While promoting data access, the framework maintains strict safeguards against re-identification and unauthorized access. AZOP has issued specific guidance on the intersection of AI and data protection, clarifying how principles like "privacy by design" and the right to an explanation of automated decisions apply to AI systems. This ensures that as Croatia moves toward more advanced AI applications, the core protections of the GDPR remain the bedrock of its digital society, protecting citizens from algorithmic bias and unauthorized surveillance while still allowing for the development of data-intensive AI solutions.
Sector-specific rules
While the EU AI Act provides a horizontal foundation, Croatia is integrating AI-specific considerations into various sectoral regulations. In the healthcare sector, the Ministry of Health is overseeing the digital transformation of the Central Healthcare Information System (CEZIH), where AI is being explored for diagnostic support and administrative efficiency. These applications must comply with both the AI Act’s high-risk requirements and the specific safety standards for medical devices. Similarly, in the financial sector, the Croatian National Bank (HNB) and the Croatian Financial Services Supervisory Agency (HANFA) monitor the use of AI in algorithmic trading, credit scoring, and anti-money laundering (AML) efforts. These bodies ensure that AI deployment in finance remains transparent and does not introduce systemic risks to the national economy. The transport and infrastructure sector is another area of focus, particularly regarding autonomous mobility and smart city technologies. The Ministry of Sea, Transport and Infrastructure is involved in the development of regulatory sandboxes and pilot projects for AI-driven traffic management and logistics. These initiatives are designed to test the safety and efficiency of AI systems in real-world conditions before broader deployment. Additionally, the Ministry of the Interior regulates the use of AI in security and law enforcement, ensuring that any use of biometric identification or predictive policing tools adheres to the strict prohibitions and oversight mechanisms mandated by the EU AI Act and national constitutional protections. This sectoral approach ensures that the unique risks and technical requirements of different industries are addressed by the relevant specialized authorities, preventing a one-size-fits-all approach that could be either too lax or too restrictive for specific use cases.
International alignment
Croatia’s AI policy is fundamentally aligned with the European Union’s strategic digital agenda. As a Member State, Croatia is a direct participant in the EU’s "Coordinated Plan on Artificial Intelligence," which aims to align national strategies to create a unified European AI ecosystem. The transposition of the EU AI Act is the most significant manifestation of this alignment, ensuring that Croatia’s domestic rules are fully harmonized with the rest of the Union. This alignment extends to other key EU digital regulations, such as the Data Act, the Data Governance Act, and the Digital Services Act, which collectively form the "European Data Space" that Croatia is actively building toward. This ensures that Croatian AI startups and researchers can scale their solutions across the EU without facing fragmented regulatory hurdles. Beyond the EU, Croatia adheres to the OECD Principles on Artificial Intelligence, which emphasize human-centric values, transparency, and accountability. The government participates in international forums such as the Council of Europe, which is developing a framework convention on AI and human rights. Croatia also engages in regional cooperation within the Danube and Adriatic-Ionian regions to promote digital connectivity and shared AI research initiatives. By participating in these international frameworks, Croatia seeks to position itself as a trustworthy partner in the global AI landscape, committed to the ethical development of technology. This international alignment is not only a matter of legal compliance but also a strategic choice to attract foreign investment and participate in high-value global research networks, ensuring that Croatia remains at the forefront of the global digital transition.
What's next
The next three years will be a critical period for the formalization of AI regulation in Croatia. The primary focus will be the completion of the national transposition of the EU AI Act, which is expected to result in a new primary statute or significant amendments to existing administrative laws by 2025. This legislation will officially designate the national supervisory authorities and establish the procedural framework for conformity assessments and market surveillance. Simultaneously, the government is expected to finalize and adopt the "National Plan for the Development of Artificial Intelligence to 2032," which will trigger the implementation of the 2026–2028 Action Plan. This Action Plan will include specific budgetary allocations for AI research, public sector pilot projects, and national digital literacy campaigns. Another significant development will be the expansion of regulatory sandboxes, which are explicitly encouraged by the EU AI Act to foster innovation. Croatia plans to establish these controlled environments to allow startups and SMEs to test high-risk AI systems under regulatory supervision, providing a pathway for faster market entry while ensuring safety. Furthermore, as the EU AI Act’s phased application begins—with prohibitions on certain practices taking effect as early as 2025—the Croatian government will focus on capacity building within its enforcement agencies. This includes training for judges, prosecutors, and administrative officials on the technical and legal nuances of AI oversight. The integration of AI into the national cybersecurity strategy will also be a priority, as the government seeks to protect critical infrastructure from AI-driven threats and ensure the resilience of its digital systems against emerging risks like deepfakes and automated disinformation campaigns.
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2021
central_coordinator
Lead authority for digital transformation and AI policy coordination.
data_protection
National supervisory authority for data protection and fundamental rights in AI.
sectoral
Regulates electronic communications and digital infrastructure.
Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
Open source →