The AI Act, what it requires and from whom
Regulation (EU) 2024/1689 applies directly, with no transposition into Croatian law. Obligations depend on your role and risk category, and the deadlines arrive in several steps.
What the Act is and how it is built
The AI Act applies directly, and the scope of obligations follows from role and risk category.
The AI Act, Regulation (EU) 2024/1689, was adopted on 13 June 2024, published on 12 July 2024 and entered into force on 1 August 2024. Being a regulation, it applies directly and is not transposed into Croatian law. National legislation is needed only for what the Act left to the member states: the competent authorities, the penalty framework and the regulatory sandbox.
The approach is risk based, with four categories. Unacceptable risk means a prohibition, under Article 5. High risk carries the bulk of the obligations. Limited risk carries the transparency duties of Article 50. Minimal risk carries no specific obligations under the Act.
Two paths lead to high risk. The first is Article 6(1): the system is a safety component of a product covered by the harmonised legislation of Annex I, a medical device for instance, and that product undergoes third-party conformity assessment. The second is Article 6(2) and Annex III, which lists eight areas, among them biometrics, critical infrastructure, education, employment, access to essential services including healthcare, law enforcement, migration and justice.
There is also a way out. Under Article 6(3) an Annex III system is not high risk if it poses no significant risk to health, safety or fundamental rights, because it performs a narrow procedural task or a preparatory task for an assessment, for example. The exception to that exception is plain: a system that profiles natural persons is always high risk. A provider relying on the way out must document the assessment and register the system in the European database.
Alongside this run separate rules for general-purpose AI models, in Articles 51 to 56. A model counts as one with systemic risk when it has high-impact capabilities, with a presumption tied to the amount of compute used in training. Providers of such models are supervised not by a national authority but by the European Commission.
The four risk categories
The category determines the scope of obligations, not the size of the organisation.
Scientific research and development as the sole purpose falls outside the scope of the Act, as do national security, defence and military purposes, and natural persons acting in a purely personal, non-professional capacity, under Article 2.
Who is who, and what binds them
The first question is not whether the system is high risk but which role you are in.
The role can change. A deployer becomes a provider if it puts its own name on a high-risk system, substantially modifies it, or repurposes it so that it becomes high risk, under Article 25. In addition, a fundamental rights impact assessment before first use is carried out by bodies governed by public law and private entities providing public services, and by deployers of systems for creditworthiness assessment and for risk assessment and pricing in life and health insurance, under Article 27. The duty does not extend to systems for managing critical infrastructure under point 2 of Annex III.
When the obligations start
The Act has been in force since 1 August 2024, but it does not apply all at once: it arrives in steps, and some of those have moved.
The amendments known as the Digital Omnibus are no longer a proposal. They were adopted as Regulation (EU) 2026/1744, published in the Official Journal of the European Union and in force since 27 July 2026, so the moved dates are binding. The transparency duties of Article 50 were not moved by those amendments and apply from 2 August 2026.
Fines
Three thresholds, and within each the higher of the two amounts applies.
For small and medium-sized enterprises and start-ups the lower of the two amounts applies, and Regulation (EU) 2026/1744 extended part of that relief to small mid-cap companies. Fines on Union institutions are imposed by the European Data Protection Supervisor, under Article 100. Member states set their own penalty rules and may provide for fining public authorities, under Article 99(8); in Croatia that depends on the implementing act, which has not yet been adopted.
Who supervises, and what is still open in Croatia
Part of the supervision is European and already running, part is national and not yet set up.
At European level, providers of general-purpose AI models are supervised by the European Commission through the AI Office. Alongside it sit the European Artificial Intelligence Board, the advisory forum and the scientific panel of independent experts.
The national level is a different story. Every member state was to designate a notifying authority and a market surveillance authority. In Croatia that has not yet happened: the implementing act, which would name the competent authorities, the regulatory sandbox and the penalty framework, has according to publicly available information not yet been adopted. That is why this page does not name a Croatian market surveillance authority: no statute has designated one.
What has been settled are the fundamental rights authorities, which Croatia notified to the Commission under Article 77(2): the Personal Data Protection Agency, the ombudswoman, the ombudswoman for children, the ombudswoman for gender equality, the ombudswoman for persons with disabilities, the State Electoral Commission and the Agency for Electronic Media. Those bodies may request and obtain documentation drawn up under the Act where they need it for their mandates.
The Act also gives individuals rights. Under Article 85 anyone who considers there has been an infringement may lodge a complaint with the market surveillance authority. Under Article 86 a person affected by a decision taken on the basis of the output of an Annex III high-risk system, where that decision produces legal effects or similarly significantly affects them, is entitled to a clear and meaningful explanation from the deployer about the role the system played in that decision. That right too does not extend to systems under point 2 of Annex III.
Frequently asked questions
Questions about the Act itself, not already answered above.
Does the Act reach us if we only use off-the-shelf tools?
It does. Anyone using a tool in the course of their activity is a deployer and carries the obligations of Article 26. On top of that, Article 4 on AI literacy applies whatever the risk category, in the simplified form given to it by Regulation (EU) 2026/1744.Does the Act reach companies outside the European Union?
It applies to providers placing systems on the Union market whatever their place of establishment, and to providers and deployers established in third countries where the output of the system is used in the Union. A provider of a high-risk system established outside the Union must appoint an authorised representative in the Union under Article 22; the same duty falls on providers of general-purpose AI models under Article 54.Do we have to label content produced by a machine?
You do, under Article 50. Outputs that are artificially generated or manipulated are marked in a machine-readable format, and people interacting with a system must know they are talking to a machine unless that is obvious. For deepfake content the disclosure duty falls on the deployer.When is a serious incident reported?
A provider of a high-risk system reports it to the market surveillance authority without delay and no later than 15 days from becoming aware. The deadline is 10 days where a person has died, and 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure. The deployer immediately informs the provider, under Article 26.Does the Act replace the General Data Protection Regulation?
It does not. They apply in parallel. If the system processes personal data you still need a legal basis, an information notice and, where required, a data protection impact assessment. The fundamental rights impact assessment of Article 27 may draw on a data protection impact assessment already carried out and supplement it.How we can help
This page is about the law. These are the four pieces of work that most often follow from it.
From the blog: artificial intelligence
The three latest texts on AI threats and AI governance.
Let us check your role and which parts of the Act really reach you.
Half an hour, no obligation. We go through the tools you use, the role you are in and the risk category they fall in.
