Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

EU AI Act compliance in Croatia: who is in scope and what is owed

How EU AI Act applies to companies operating in or serving Croatia — scope tests, the obligations that follow, and the primary sources to verify each one against.

Organizations established in Croatia or operating within the European Union market must evaluate their exposure to Regulation (EU) 2024/1689 (EU AI Act). Compliance obligations depend on an entity's role in the AI value chain and the classification of the deployed or distributed systems. Entities should review primary legal sources and consult qualified legal counsel to determine specific applicability.

Extraterritorial Scope and Application in Croatia

The application of Regulation (EU) 2024/1689 (EU AI Act) extends to providers placing artificial intelligence systems on the market or putting them into service within the Union, regardless of whether those providers are established within the EU or in a third country. For organizations based in Croatia, this means domestic developers and distributors fall directly under the regulatory perimeter. Providers and deployers established in third countries are caught by the regulation if the output produced by the AI system is used within the Union. Market surveillance authorities in member states enforce these rules locally, meaning Croatian enterprises must assess their cross-border vendor relationships and internal deployments against EU standards.

When evaluating scope, organizations examine whether their operations involve placing systems on the market or putting them into service. A provider placing a system on the market is typically the entity that develops an AI system and puts it on the market under its own name or trademark. Conversely, a deployer uses an AI system under its authority, except where the system is used in the course of a personal non-professional activity. Compliance teams can utilize tools such as the tools/obligation-extractor to map specific statutory duties to their organizational profile.

Exemptions from the regulation apply in specific contexts, such as AI systems developed or used exclusively for military, defense, or national security purposes, regardless of the type of entity carrying out those activities. Research, development, and testing activities prior to placing systems on the market also receive specific treatment under the legislative framework. However, organizations must verify whether their commercial activities inadvertently cross the threshold into regulated deployment, particularly when integrating third-party models into customer-facing applications in Croatia.

To manage these requirements systematically, compliance operations teams often adopt structured frameworks. Reviewing resources like the guides/eu-ai-act-compliance-guide assists organizations in identifying operational gaps. Because supervisory enforcement involves national competent authorities cooperating at the EU level through the European AI Office, maintaining clear documentation of system deployments is necessary for regulatory readiness.

Distinguishing AI Providers, Deployers, and Other Market Actors

Regulation (EU) 2024/1689 (EU AI Act) defines distinct roles for entities interacting with artificial intelligence technologies, carrying different sets of obligations. An ai-provider is a natural or legal person, public authority, agency, or other body that develops an AI system or a general-purpose AI model or has an AI system or a general-purpose AI model developed and places it on the market or puts the system into service under its own name or trademark. Providers bear the primary burden for conformity, technical documentation, and quality management systems.

In contrast, an ai-deployer uses an AI system under its authority except where the system is used in the course of a personal non-professional activity. Deployers in Croatia must ensure the system is used in accordance with instructions, monitor its operation, and maintain input logs where under their control. Importers and distributors also have specific verification duties to ensure that providers have fulfilled conformity assessments and affixed the required CE marking before products reach the Croatian market.

| Market Role | Primary Responsibility | Key Reference | |---|---|---| | Provider | Conformity assessment, technical documentation, risk management | guides/eu-ai-act-high-risk-ai-systems-guide | | Deployer | Operational monitoring, adherence to instructions, human oversight | guides/ai-governance-framework-guide | | Importer | Verification of CE marking and provider documentation | guides/eu-ai-act-compliance-guide | | Distributor | Verification of conformity before making available | guides/eu-ai-act-compliance-guide |

Understanding these categorizations prevents misallocation of compliance resources. Organizations frequently operate in dual capacities, acting as a provider for proprietary tools while deploying third-party solutions internally. Clarifying these boundaries requires cross-functional collaboration between legal, engineering, and procurement departments, supported by structured vendor assessments found in the guides/ai-vendor-due-due-diligence-guide.

Identifying High-Risk AI Systems and Prohibited Practices

A critical phase of compliance under Regulation (EU) 2024/1689 (EU AI Act) involves screening existing and planned AI inventories against statutory risk categories. Prohibited practices include specific applications deemed to present unacceptable risks, such as manipulative techniques, exploitation of vulnerabilities, social scoring, and certain forms of biometric identification. Organizations operating in Croatia must immediately audit their AI portfolios to ensure no systems fall under these glossary/prohibited-ai-practice definitions.

Systems classified as high-risk are enumerated in statutory schedules and regulatory frameworks. Entities can reference the guides/eu-ai-act-high-risk-ai-systems-guide to understand how biometric identification, critical infrastructure management, education, employment, and essential public services are treated. High-risk systems are subject to strict mandatory requirements before being placed on the market, including risk management systems, data governance, technical documentation, and automated logging.

Before high-risk systems can be put into service in Croatia, providers must subject them to a glossary/conformity-assessment. This procedure verifies that the AI system meets all applicable regulatory requirements. Technical documentation must be drawn up in accordance with detailed standards to demonstrate conformity, as outlined in technical documentation requirements. Organizations can explore structured methodologies via the guides/ai-governance-framework-guide to streamline their internal assessment workflows.

General-purpose AI models present another tier of regulatory focus, particularly when classified as having systemic risk. Entities developing or distributing foundational models must evaluate whether their technology meets the definition of a glossary/general-purpose-ai-model or a glossary/systemic-risk-gpai. Transparency obligations and technical evaluation protocols apply to these models, requiring robust documentation and cooperation with European regulatory bodies.

Mandatory Compliance Obligations and Post-Market Governance

Once an organization determines its systems are subject to Regulation (EU) 2024/1689 (EU AI Act), a series of ongoing duties commences. For high-risk systems, providers must establish, implement, document, and maintain a quality management system that ensures regulatory compliance. This system covers regulatory compliance strategies, design control, examination procedures, and quality assurance processes. Teams looking to operationalize these requirements can generate baseline policy documents using the tools/ai-policy-generator.

Post-market monitoring is a statutory obligation requiring providers to actively and systematically collect, document, and analyze data concerning the performance of AI systems throughout their lifetime. Providers must feed this operational data into their risk management systems and report serious incidents to market surveillance authorities without undue delay. Implementing a structured glossary/post-market-monitoring protocol helps organizations capture performance drift and safety failures before they trigger regulatory penalties.

Deployers share governance responsibilities by ensuring human oversight measures are maintained during operation. If a deployer exercises control over a high-risk system, it must monitor the operation based on the provider's instructions and keep logs automatically generated by the system, where technically feasible. Reviewing detailed resources on guides/eu-ai-act-compliance-guide assists compliance officers in establishing clear operational boundaries between provider and deployer duties.

Internal record-keeping and technical documentation must be maintained for inspection by competent authorities upon request. Organizations must align their software development lifecycles with these governance mandates. Utilizing the guides/ai-vendor-due-diligence-guide ensures that third-party vendors supplying components or models to Croatian entities meet equivalent documentation and transparency standards.

Supervisory Enforcement and Institutional Oversight in the EU

Enforcement of Regulation (EU) 2024/1689 (EU AI Act) relies on a dual-layer institutional architecture comprising EU-level bodies and national competent authorities. At the Union level, the European Commission oversees general-purpose AI models, supported by the European AI Office established within the Commission. These bodies issue guidelines, coordinate joint investigations, and monitor systemic risks across member states, ensuring uniform application of the legal framework.

At the national level, each EU member state designates one or more competent authorities, including a market surveillance authority, to supervise the application and implementation of the regulation. Croatian organizations are subject to the oversight of designated national bodies that cooperate with European peers. These authorities possess inspection powers, the ability to request technical documentation, and the mandate to order corrective actions, product withdrawals, or recalls when non-compliance is identified.

Organizations must establish clear protocols for handling inquiries or audits from supervisory authorities. Because enforcement practices continue to evolve alongside regulatory guidance from the European Commission, maintaining up-to-date compliance records is essential. Compliance teams can consult the European Commission regulatory framework documentation via the European Commission regulatory framework for AI section to track supervisory updates and official interpretations.

Cross-border operations require careful coordination when multiple national authorities have jurisdiction. Entities selling software across several EU member states must ensure their compliance documentation satisfies the expectations of different market surveillance authorities. Reference materials available in the methodology library can assist compliance operations teams in designing robust cross-border review processes.

Uncertainties, Exemptions, and Verifying Obligations with Counsel

Certain applications of artificial intelligence present gray areas where statutory definitions may not neatly map to specific business models. For instance, determining whether a software tool constitutes a high-risk system under Annex III requires a detailed contextual analysis of its intended purpose and operational impact. Organizations in Croatia must avoid assumptions and verify ambiguous use cases directly against the statutory text of Regulation (EU) 2024/1689 (EU AI Act).

Exemptions related to scientific research, open-source software releases, and military applications require careful legal interpretation. While open-source AI models enjoy certain exemptions from specific provider obligations, commercial downstream distributors who fine-tune or integrate those models into high-risk systems may inherit full provider duties. Evaluating these risk transfers is critical for software development firms operating in the region.

Because regulatory interpretations develop through guidance documents published by the European AI Office and the European Data Protection Board, compliance teams should regularly monitor official publications such as the EDPB published documents section. These repositories provide insight into how supervisory bodies interpret overlapping requirements between data protection laws and artificial intelligence regulations.

Given the complexity of statutory enforcement and the absence of one-size-fits-all solutions, organizations should treat regulatory guidance as a baseline and retain qualified legal counsel to review specific deployment architectures. Internal compliance programs must remain adaptable to new regulatory interpretations and supervisory announcements issued by relevant authorities.

Related on BizLegal

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does Regulation (EU) 2024/1689 apply to companies based in Croatia?

Yes, entities established in Croatia are subject to the regulation if they develop, place on the market, put into service, or distribute AI systems within the European Union, or if the outputs of their systems are used within the Union.

What is the difference between an AI provider and an AI deployer?

An AI provider develops an AI system or has it developed and places it on the market under its own name or trademark. An AI deployer uses the system under its authority in a professional capacity, bearing operational oversight and monitoring duties.

Are open-source AI models completely exempt from the regulation?

Not entirely. While certain open-source models receive exemptions from specific transparency or documentation requirements, commercial entities that modify open-source models or integrate them into high-risk systems may still incur provider obligations.

How do organizations verify if their AI system is classified as high-risk?

Organizations must review the statutory criteria and Annex III classifications of Regulation (EU) 2024/1689, evaluating the intended purpose, sector of deployment, and potential impact on fundamental rights.

What authorities enforce these rules in Croatia?

Enforcement is carried out by designated national market surveillance authorities working in cooperation with the European AI Office and European Commission bodies at the EU level.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-05.

Contact