Skip to content

Writing · August 2026

Serbia Is Not Late in Adopting an Artificial Intelligence Act: Five Warnings and Recommendations for the Serbian Legislature

Serbia has one genuine advantage over the European Union in regulating artificial intelligence, and it comes entirely from timing. The Union holds the larger market, the stronger regulatory infrastructure and the experience of legislating first. Serbia, legislating second, gains access to the results of that experiment. It can read what the Union enacted alongside the criticism scholars made of it, the difficulties that surfaced during implementation, and the corrections the European legislator has already made.

That access comes with an obligation. A legislature drafting after the first large European experiment in this field has reason to learn from the problems the experiment has already exposed.

Serbia is preparing its first dedicated Artificial Intelligence Act. A working group at the Ministry of Science, Technological Development and Innovation is drafting it, the framework presented so far follows the European four-tier structure of risk, and the responsible state secretary has put adoption in December of this year. The draft remains internal to that process, so what follows addresses it as described in public. The EU's Artificial Intelligence Act should remain the principal reference for it, on the understanding that alignment and copying are distinct operations.

Risk Depends on Context as Well as Category

The European model attaches different obligations to different levels of risk. Some practices are banned, some systems are high-risk, others owe only transparency, and a large remainder stays under the ordinary law. A supplier knows in advance which regime governs it, and a supervisory authority knows what to require. Case-by-case assessment across the whole field would defeat administration, which explains the model's wide influence.

The cost appears where context and category come apart. Martin Ebers has shown that several load-bearing provisions depart from the risk logic they announce, and concludes that regulators outside the Union should scrutinise the European approach before adopting it. Nicoletta Rangone and Luca Megale add that a list settled in advance will over-include and under-include at once, since the same technology in a different setting produces different consequences.

Classification still earns its place, and the Act carries its own machinery for revision. Article 7 lets the Commission amend the list of high-risk uses by delegated act within the areas Annex III already covers, and Article 112 requires an annual assessment of whether that list needs changing. Those mechanisms belong in the Serbian statute as firmly as the categories. The law should settle the risk areas, the criteria and the consequences of classification, leaving a bounded secondary instrument to update concrete use cases. An open delegation to the executive would trade one defect for a worse one.

Human Control Requires More Than Human Presence

Serbian presentations of the future law repeat that the human stays at the centre of decision-making. The principle is right, and it is also the sentence in a statute that most easily stays inert.

The European Act answers more fully than its critics sometimes allow. Article 14 requires high-risk systems to be built so that the person overseeing them can understand their capacities and limits, stay alert to over-reliance on the output, disregard or override that output, and stop the system. Article 26(2) requires the deployer to entrust oversight to people with the necessary competence, training and authority. The Act reaches both the design of the system and the organisation of oversight around it.

Both duties operate at a distance from the behaviour they target. Johann Laux and Hannah Ruschemeier show that the split in responsibility for automation bias between provider and deployer diverges from the actual causes of that bias. The EU Agency for Fundamental Rights finds that providers lean heavily on human oversight as their mitigation of choice, while warning that supervisors may over-rely on it. A duty allocated on paper leaves open whether the decision-maker could understand, test and change the outcome in time.

Courts test this most sharply, because the Act treats systems assisting a judicial authority in researching and interpreting facts and law as high-risk. A judge exercises genuine oversight only with a practical way to see how the system shaped the material before them. In work presented at WeRobot 2026 I approached this through the idea of a control window, the interval in which the person deciding holds the information, time and authority to alter the result. Serbian law should tie oversight to what makes it exercisable, which is an explanation of the output, a trace of what the system did, time to react and a real chance to change the result.

Contestability Extends Beyond Transparency

The announced Serbian law will require labelling of images, video and audio generated or altered by artificial intelligence. That mirrors part of Article 50 of the European Act, and it is a sound provision as far as it goes.

The European instrument reaches past labelling. Article 85 gives any person the right to complain to a market surveillance authority, and Article 86 a right to a clear and meaningful explanation of the role an AI system played in a decision. That second right reaches only certain Annex III high-risk decisions producing legal effects or adversely affecting health, safety or fundamental rights, subject to exceptions and to whatever Union law already provides.

Transparency and contestability part company here. Contestability begins where knowledge that a system was used is joined by a practical means of examining the difference it made. Serbian data-protection law already covers decisions taken solely by automated processing, a narrower class. A dedicated AI statute earns its place in the wider one, where a system materially shapes a result and a human formally remains in the procedure.

In work on evidence taken from encrypted platforms I have argued that formal admissibility is a weaker safeguard than the practical capacity to challenge the process that produced the evidence, an argument set out at length for criminal procedure. The intuition carries across to AI regulation, while the conclusion stays with criminal procedure. Notice matters only where an explanation follows, the explanation only where it can be verified, and verification only where what it reveals can be contested and remedied. Where artificial intelligence materially affects a legal position, the capacity to contest belongs in the design of the system and of the procedure around it.

The Act Depends on Its Regulatory Infrastructure

Public accounts of the Serbian regime describe artificial intelligence partly through the logic of products, which is where much of the European machinery comes from. The Act leans on conformity assessment, notified bodies, harmonised standards and market surveillance, and it draws on a wider system lying outside its own text, from the AI Office and national authorities to Commission guidance, the GDPR and the Data Act.

Mélanie Gornet and Winston Maxwell show how unusual it is to ask technical standards to carry requirements about fundamental rights, since a rights violation is context-specific and ends in a judicial determination, a judgment lying beyond the reach of a certificate of conformity. A European Parliament study of the interaction between the AI Act and the rest of the Union's digital legislation maps the same dependence. A transplanted rule reproduces the system it came from only when the infrastructure that makes it operational travels with it.

Regulation (EU) 2026/1744 postponed the obligations in Sections 1 to 3 of Chapter III to 2 December 2027 for high-risk systems under Annex III and to 2 August 2028 for those under Annex I. Recital 40 blames the delayed availability of standards and guidance, and the delayed establishment of national competent authorities. The postponement speaks to implementation readiness and leaves the substantive justification of those obligations as a separate question. It confirms that statutory duties become operative through standards, guidance and institutional capacity, which belong to the regulatory architecture alongside the text.

Serbian institutions have capacity, and the operative question concerns which capacity each obligation requires. Public accounts of the draft mention a dedicated agency, a register of high-risk systems and supervision divided among existing inspectorates, with the institutional model still open. Before a duty is enacted, five things need answers. Who applies it, who supervises it, with what expertise, against which standard, and with what remedy attached.

AI Regulation Must Be Able to Learn

The European Act was adopted in June 2024 and amended in July 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026. The amendments reached substance. Article 4 was rewritten so that the duty on AI literacy is to take measures supporting its development, leaving each individual's level of knowledge outside the guarantee. New prohibited practices were added and the AI Office's powers enlarged.

The amendments leave the Act's design intact. They ran in both directions, easing some requirements and tightening others, which is what institutional learning looks like. That capacity sits inside the European instrument already, since Article 112 requires annual assessment of the high-risk and prohibited lists and periodic review of the wider regime. The 2026 amendment showed the need for correction arising in practice.

Serbia should copy that capacity for self-correction as deliberately as it copies the classifications. In practice that means periodic statutory review with reporting to the National Assembly, a legal basis for a regulatory sandbox, a route for updating risk classifications, and transitional periods tied to actual supervisory readiness. A good AI statute treats the legislature of 2026 as a poor forecaster of 2032 and provides for its own amendment.

What Serbia Should Take

The five recommendations reduce to one. A rule on risk, oversight, notice or enforcement is worth what the institution applying it can do, and what the mechanism revising it permits.

Serbia can build on regulation that already exists, and the European Act is where it should begin. Arriving later buys the chance to learn from four things at once, which are what the Union chose, where its critics located the flaws, where implementation broke down, and how the Union corrected itself. Alignment done well takes all four. Alignment done badly takes only the first.

Serbia should take the EU AI Act as its foundation and spend the time it has gained building the version its own institutions can actually operate.

Artificial IntelligenceAI RegulationEU AI ActSerbiaHuman OversightContestabilityLegal Transplants