Croatia - AI Act Transposition Process (2025)

National transposition process / working group for the EU Artificial Intelligence Act (transposition of the EU AI Act)

Nacionalni proces transpozicije / radna grupa za EU Uredbu o umjetnoj inteligenciji (transpozicija EU AI Uredbe)

Croatia

RAI-HR-NA-NTPWGXX-2025
Draft(Being written or scoped)
BillGovernance and OversightConformity Assessment and Registration
Export PDF

Croatia has established an inter-ministerial working group to draft national implementing legislation for Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act). The working group is chaired by the Ministry of Justice, Administration and Digital Transformation and includes representatives from line ministries, the national data protection authority and civil society; the process aligns national implementation with EU deadlines and designated supervisory authorities. Ministry listing.

Summary

This bill entry documents Croatia’s formal national transposition process for the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), focusing on the multi-stakeholder working group convened to draft national implementing legislation and administrative arrangements. The EU AI Act, adopted at EU level on 13 June 2024 and published as Regulation (EU) 2024/1689, establishes a risk-based, horizontal regulatory framework for AI systems across the Union and foresees a phased application of its provisions. Croatia has responded by assembling a dedicated working group led by the Ministry of Justice, Administration and Digital Transformation to prepare a national draft law to ensure coherent domestic implementation and to designate or coordinate national competent authorities and market surveillance bodies. The official list of participants and institutional leads is published on the ministry’s website and shows broad representation from central government (ministries of justice, economy, science/education, infrastructure and transport), data protection authorities, academic institutions (technical universities and research networks such as CARNet), business organisations (Croatian Chamber of Commerce, HUP-ICT) and civil society (ombudsperson offices). See the ministry’s published working-group roster for full membership. Ministry working group page. Key implementation coordination tasks for Croatia include: (1) mapping the Act’s obligations to existing national law (including interactions with the GDPR and sectoral safety/product rules); (2) designating and publishing the national competent authorities and bodies responsible for monitoring high-risk AI systems and fundamental-rights oversight (Croatia has designated the Personal Data Protection Agency and several ombuds institutions among competent authorities); (3) defining procedural requirements for conformity assessment, registration and market surveillance; (4) establishing documentation, incident reporting and transparency obligations for providers and deployers; (5) setting criminal, administrative or civil penalties in line with EU maxima while ensuring due process; and (6) preparing capacity-building and guidance for small and medium-sized enterprises and public-sector procurers. The Croatian Personal Data Protection Agency (AZOP) has already published guidance-type notices explaining initial applicability timelines (Chapters I and II began to apply early in 2025 and the broader application window begins in 2026) and has published the list of national authorities submitted to the Commission. See AZOP’s guidance for details. AZOP notice. The working group’s outputs are expected to include a draft implementing statute (or amendments to domestic law), secondary regulation and administrative guidance for regulated actors (providers, deployers, importers and distributors), an approach to national market surveillance powered by existing agencies, and a timetable that respects EU-level deadlines and reporting obligations. The Croatian approach emphasises cross-sectoral coordination and protecting fundamental rights (with ombudsperson offices explicitly included in the working group) while seeking to preserve innovation via risk-proportionate measures and support for industry adaptation. National stakeholders, including industry associations and academic experts, are participating in the drafting process via the working group or associated consultations, enabling practical input on conformity assessment, evaluation/testing requirements and sectoral impacts in finance and healthcare. The ministry’s working-group notice is the primary domestic source listing membership and administrative lead. Ministry page, and the EU text and official publication may be consulted for the full regulatory obligations. Regulation (EU) 2024/1689 (AI Act) — official text.

Full article

Read full text ↗

Overview

Croatia’s national transposition process for the EU Artificial Intelligence Act is organised through an inter-ministerial working group convened by the Ministry of Justice, Administration and Digital Transformation. The group’s mandate is to prepare a draft implementing law and related administrative measures that will operationalise Regulation (EU) 2024/1689 within Croatia, identify the national supervisory and market surveillance authorities required by the AI Act, and coordinate technical and sectoral guidance to stakeholders. The working-group membership published by the ministry includes representatives from central ministries, the Croatian Personal Data Protection Agency (AZOP), the ombudsperson's offices, academic and research institutions and industry bodies, reflecting an approach designed to balance rights protection, market functioning and innovation. The national transposition work explicitly references the EU instrument and timelines (Regulation (EU) 2024/1689) and coordinates with national authorities already designated for fundamental-rights oversight. See the ministry’s official listing and AZOP’s role for initial guidance. Ministry working-group roster and AZOP information.

Definitions

The working group’s draft transposition text will adopt and interpret key definitions from the AI Act—"AI system", "provider", "deployer", "general-purpose AI model", "high-risk AI system", "remote biometric identification" and "fundamental rights impacts"—to ensure legal coherence across national law. Definitions will mirror the EU regulation where possible to preserve the harmonised single market approach, while clarifying procedural terms for Croatia's administrative processes (e.g., registers, notification and supervisory coordination). Clarifying the scope of excluded uses (military, national security, strictly research activities where permitted) and the threshold for what constitutes "placing on the market" or "putting into service" will be essential to give effect to obligations for providers and deployers in domestic context.

Governance and Institutional Framework

Croatia’s working group is chaired by the Ministry of Justice, Administration and Digital Transformation and includes the Ministry of Economy, the Ministry of Science, Education and Youth, Ministry of Sea, Transport and Infrastructure, CARNet, AZOP and multiple ombudsperson offices, along with academic and industry representatives. This institutional mix aims to synchronize: (a) designation and publication of national competent bodies for fundamental-rights oversight and high-risk AI monitoring (as required by Article 77 of the AI Act); (b) assignment of market surveillance roles under product-safety analogues; (c) responsibilities for conformity assessment and registration; and (d) national enforcement mechanisms. Official lists submitted by Croatia to the Commission and summarized by AZOP identify prime bodies for oversight; the transposition bill will formalise these institutional roles and their coordination mechanisms. The ministry-hosted roster provides the authoritative membership list of the drafting group. Working group membership and AZOP publication.

Key Focus Areas

The transposition effort concentrates on several substantive and procedural focus areas. Substantively, the draft must translate the AI Act’s risk-based rules into enforceable national obligations: prohibitions of unacceptable practices (e.g., social scoring and certain biometric categorisations), obligations for high-risk systems (risk management systems, data governance and documentation), transparency and human oversight measures, and specific duties for general-purpose AI models where applicable. Procedurally, the transposition bill must create or empower registration systems, designate conformity assessment authorities, align sanctions and administrative procedures with the AI Act’s enforcement framework, and guarantee effective judicial and administrative redress for affected persons. Additional focus includes (1) aligning the AI Act’s requirements with GDPR and national data-protection law; (2) defining the interface between sectoral authorities (finance, healthcare, transport) and the central supervisory bodies; (3) specifying technical and organisational requirements for cybersecurity, adversarial testing and model evaluation; (4) building national capacity for market surveillance and technical evaluation labs; and (5) developing guidance and transitional arrangements for small and medium-sized enterprises and public sector procurers. The working group aggregates expertise from public administration, data protection, academia and industry to shape risk-calibrated obligations and practical compliance pathways.

Implementation Framework

The proposed implementation framework will include: (a) a legal instrument (primary legislation or amendments) that gives domestic effect to the AI Act’s requirements where national measures are allowed or needed (administrative designations, enforcement powers, penalty schedules); (b) secondary (subordinate) regulation or ministerial rules describing registry procedures, reporting templates and market surveillance workflows; (c) technical guidance and sectoral annexes for healthcare and financial services to clarify compliance expectations; and (d) a stakeholder consultation and phased rollout plan aligned with EU application dates. The ministry-led drafting process will coordinate input from AZOP (data protection), Agencija za elektroničke medije (media oversight for related uses), ombuds institutions (fundamental rights concerns) and industry stakeholders to ensure the domestic framework is implementable and coherent with EU obligations. For the full EU legal baseline, see the official publication of Regulation (EU) 2024/1689. EU official text.

Monitoring and Evaluation

Monitoring will rely on a combination of national supervisory authorities and sectoral market surveillance bodies. AZOP has already outlined the initial applicability timetable and published a list of national competent authorities; formal transposition will set out reporting obligations, data collection and incident reporting channels for serious incidents and systemic risks. Evaluation will include periodic reviews against the Act’s review clauses and technical standards, and cooperation through the European AI Board. The national framework will require mandated reporting from conformity assessors, registries of high-risk systems, and centralized incident reporting channels to enable aggregate risk analysis and targeted inspections. Capacity-building plans for inspection, technical testing and judicial training are expected components of the evaluation strategy. AZOP guidance.

Penalties, Liability, and Appeals

The transposition draft will align national administrative penalties and enforcement pathways with the AI Act’s sanctioning architecture, which includes substantial maximum fines for the most serious breaches at EU level. Domestic implementing rules will specify administrative procedures, rights to appeal before administrative courts, and the interplay with civil liability regimes where injured persons seek redress. The bill must ensure legal certainty in enforcement (procedural safeguards, proportionality principles) and provide for cooperation between national enforcement authorities and the European AI Board for cross-border cases.

Relationship to Other Instruments

The national implementing framework must be harmonised with the GDPR (Regulation (EU) 2016/679), product safety and sectoral legislation (healthcare, transport, financial services), the national data-protection law and other relevant statutes. The working group will assess overlaps, carve-outs and subsidiarity points, ensuring the transposition respects EU primacy where the AI Act is directly applicable while integrating national procedural rules for surveillance, sanctioning and judicial remedies. Practical measures will include cross-references, delegated powers for agencies, and formal memoranda of understanding between enforcement bodies.

International Alignment

Croatia’s transposition is explicitly framed to preserve the EU single-market approach and avoid fragmentation; the ministry’s process therefore adopts the EU definitions and obligations to maintain cross-border legal certainty. National authorities will cooperate with EU structures (the European AI Board and the new AI Office where relevant) and align with international data-protection and human-rights frameworks. This alignment will be reflected in the transposition bill’s emphasis on interoperability with EU-level conformity assessments, cross-border supervisory cooperation and adherence to EU guidance documents and standards.

Implementation Timeline

EventDate
Adoption of Regulation (EU) 2024/1689 (AI Act)2024-06-13
AI Act entered into force2024-08-01
Member States deadline to designate bodies under Article 77(2)2024-11-02
Chapters I & II began to apply (per AZOP summary)2025-02-02
Phased broader application begins (general effective application start per EU)2026-08-02
Working group roster published by Ministry (drafting start / public listing)2025-04-01

Sources and References

SourceType
Ministry of Justice, Administration and Digital Transformation — Working group listing for draft implementing law (Croatia)Primary Source
Croatian Personal Data Protection Agency (AZOP) — AI Act applicability and list of designated authoritiesPrimary Source
Publications Office of the EU — Regulation (EU) 2024/1689 (Artificial Intelligence Act) — official textPrimary Source

Requirements for a company

What an organisation has to do under Croatia - AI Act Transposition Process (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

8
  • Classify AI systems against AI Act risk categories and document assessments.Providers and deployers of AI systems.
  • Implement data management policies and record data sources.Providers and deployers of AI systems.
  • Maintain technical files and model cards for inspection.Providers and deployers of AI systems.
  • Complete required conformity procedures and register high-risk systems.Providers and deployers of high-risk AI systems.
  • Provide user information, warnings, and synthetic content disclosures.Providers and deployers of AI systems.
  • Establish processes to report serious incidents to national authorities.Providers and deployers of AI systems.
  • +2 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Croatia - AI Act Transposition Process (2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers and deployers of AI systems.Classify AI systems against AI Act risk categories and document assessments.
Classify AI systems against AI Act risk categories and document assessments
Aug 2, 2026Critical
2Providers and deployers of AI systems.Implement data management policies and record data sources.
Implement data management policies and record data sources
Aug 2, 2026Critical
3Providers and deployers of AI systems.Maintain technical files and model cards for inspection.
Maintain technical files and model cards for inspection
Aug 2, 2026Critical
4Providers and deployers of high-risk AI systems.Complete required conformity procedures and register high-risk systems.
Complete required conformity procedures and register high-risk systems
Aug 2, 2026Critical
5Providers and deployers of AI systems.Provide user information, warnings, and synthetic content disclosures.
Provide user information, warnings, and synthetic content disclosures
Aug 2, 2026Critical
6Providers and deployers of AI systems.Establish processes to report serious incidents to national authorities.
Establish processes to report serious incidents to national authorities
Aug 2, 2026Critical
7Providers and deployers of AI systems.Adopt model-security measures and adversarial testing protocols.
Adopt model-security measures and adversarial testing protocols
Aug 2, 2026Critical
8Providers and deployers of AI systems.Design and document human-in-the-loop controls.
Design and document human-in-the-loop controls
Aug 2, 2026Critical

© Regulations.AI · updated on 13-Jun-2026