Montenegro has not enacted an artificial intelligence statute, and the EU AI Act does not apply to it. Both of those things are true, and both are routinely used to reach the wrong conclusion — that an AI system deployed in Montenegro sits in a regulatory vacuum until accession.
It does not. Four provisions already in force reach directly into the systems companies are actually deploying: automated screening of job candidates, credit and risk scoring, performance monitoring, and biometric identification. Three of them sit in the data protection act and one in a statute adopted in February 2026. None of them mention artificial intelligence. All of them apply to it.
This page sets out what applies today, what does not apply and why, and the two documents that tell you where this is heading.
The four provisions that already bite
| Obligation | Provision | What it catches |
|---|---|---|
| No decision based solely on automated processing | Data protection act, Art. 15a | Screening, scoring, performance and behaviour assessment |
| Prior consent of the supervisory authority for special-risk automated processing | Data protection act, Art. 28(1) | Profiling systems, biometrics, public-area video |
| Explain the manner of automated processing on request, within 15 days | Data protection act, Art. 43(2)(7) | Any Art. 15a system |
| ICT risk management, testing and incident reporting | Digital operational resilience act, Sl. list CG 14/26 | AI in regulated financial entities |
Article 15a is the one most companies are unknowingly in breach of. When deciding on a person's rights, obligations and interests, an assessment of their personal characteristics and abilities that is relevant to the decision may not be based solely on automated processing. The Act then names what it means, and the list reads like a specification for a modern HR or fintech stack: results of work at the workplace, reliability, creditworthiness, behaviour and similar.
There are two exits, both narrow. Article 15a(2)(1) allows a solely automated decision where, in the course of concluding or performing a contract, the data subject's request has been accepted, or where appropriate measures protect their legitimate interests — the Act gives the example of the possibility for the person to express their view. Article 15a(2)(2) allows it where a law prescribes it, provided that law also prescribes safeguards. In practice this means a human who can actually change the outcome, documented, and not a rubber stamp added to the workflow diagram after the fact.
Article 28(1) is the provision that turns an AI rollout into a permit process. Where a controller plans automated processing that presents a special risk to rights and freedoms, it must obtain the supervisory authority's consent before each such processing — and the Act says "especially" where the processing involves special categories of data, data relating to the assessment of personality, ability or behaviour, public-area video surveillance, or biometric data. Article 28(2) disapplies the requirement where processing rests on a law, on the person's consent, or on the necessity of performing a contract with them, so the contract and consent routes matter — but a profiling engine that scores personality or behaviour is squarely inside the "especially" list.
Article 43(2)(7) is Montenegro's explainability right, and it exists without any AI statute. On a written request, after verifying identity, the controller must respond within 15 days stating whether the person's data is processed and, if it is, provide additional information — including, at point 7, the manner of the automated processing in a case under Article 15a. If you cannot describe how your model reaches a decision in terms a person can understand, you cannot answer that request. That is a design constraint on model selection and documentation, not a disclosure exercise you can run later.
The digital operational resilience act, Sl. list CG 14/26 of 9 February 2026, adds a layer for regulated financial entities. It transposes EU Regulation 2022/2554 and, under its Article 2(1), applies to credit institutions, payment institutions, registered account information providers, e-money institutions and crypto-asset service providers. Article 54 gives them 24 months from entry into force to comply. AI systems in those firms are ICT systems, and the ICT risk management, testing and incident reporting obligations reach them — the wider payments picture is in our note on Montenegro's payment services regime.
Copyright: two gaps, and neither favours the assumption people make
Two questions come up in every AI project, and Montenegrin copyright law answers them less comfortably than most templates assume. The statute is the Zakon o autorskom i srodnim pravima, Sl. list CG 37/2011, 53/2016, 145/2021 and 48/2024.
Can you train on protected material? There is no dedicated text-and-data-mining exception. The limitations chapter runs from Article 45 to Article 60 and contains the familiar catalogue — temporary acts of reproduction, teaching, quotation, official proceedings, works in public places, free adaptations, research through dedicated terminals — but nothing corresponding to Articles 3 and 4 of the EU's 2019 Digital Single Market Directive, and no opt-out mechanism of the kind that regime created. Article 49 covers transient and incidental copying, and Article 60 covers on-premises research terminals; neither is a training-data permission.
The practical consequence is that Montenegro offers no statutory safe harbour for training on protected works — not a permissive regime, and not a prohibitive one either, but an unaddressed one. Anyone building a training pipeline that touches Montenegrin rights holders is relying on licences, on public domain material, or on an argument the statute does not supply.
Who owns the output? Article 4 defines a work as an individual intellectual creation in literature, science or art, expressed in a particular way. Article 9 is titled "Natural person" and states plainly that the author is the natural person who created the work. On the face of those two provisions, output generated without a human creator has no author and therefore no copyright, and the live question for AI-assisted work is whether the human contribution is itself an individual intellectual creation under Article 4. We are not aware of Montenegrin case law resolving where that threshold sits, and we are not going to invent one.
What that leaves is contractual. Where the deliverable is a computer program, Article 115 vests all economic rights in the employer or the commissioning party by operation of law, unlimited and exclusive; other categories behave differently, including a five-year reversion under Article 100. We set that allocation out in full, with the clause-drafting consequences, in our note on IT contracts in Montenegro.
The EU AI Act: not binding, not irrelevant
Regulation (EU) 2024/1689 is EU law. Montenegro is a candidate state, not a member, and the Regulation does not apply of its own force on Montenegrin territory. There is no transposition and no Montenegrin equivalent.
That is not the same as saying it cannot reach you. The Regulation's scope provisions extend to operators established outside the Union in defined circumstances connected to the Union market and to the use of system outputs there, which is why a Montenegrin company selling an AI product into the EU, or supplying a European customer, has to run the analysis rather than assume geography answers it. The European Commission's own AI Act pages confirm that the prohibited-practice rules became effective in February 2025 and that further obligations phase in on a staggered basis.
We are deliberately not reproducing the Regulation's article numbers or its full application timetable here. EUR-Lex was returning "temporarily not fully available" throughout the day this page was written, 25 August 2026, and we could not retrieve the authentic text of Articles 2 and 113 to verify against. Read those two articles directly before relying on any date or scope statement, including ours. A page that quotes an unverified timetable is worse than one that says it could not check.
What Montenegro has actually committed to
Treaty signatures are a better guide than commentary, and they are precise, public and datable. Read at the Council of Europe Treaty Office on 25 August 2026:
| Instrument | Montenegro's position |
|---|---|
| Framework Convention on AI and Human Rights, Democracy and the Rule of Law (CETS 225), opened at Vilnius 05/09/2024 | Signed 05/11/2024; not ratified; not in force for Montenegro |
| Convention 108 on automatic processing of personal data (ETS 108) | In force for Montenegro since 06/06/2006 |
| Additional Protocol on supervisory authorities and transborder data flows (ETS 181) | In force for Montenegro since 01/07/2010 |
| Convention 108+ (CETS 223), the modernised data protection text | Neither signed nor ratified |
Two things follow. Montenegro was an early signatory of the first binding international treaty on AI, six weeks after it opened. And that treaty is not yet in force anywhere: it requires five ratifications including at least three Council of Europe member States, and as at 25 August 2026 the Treaty Office records one ratification or accession and twenty signatures not followed by ratification. Signature is a statement of direction, not an obligation you can be held to yet.
The contrast with the row below it is the useful part. Montenegro signed the new AI convention promptly while remaining outside Convention 108+, the modernised data protection text that most of Europe has moved to. Its AI commitments are running ahead of its data protection ones, which is the reverse of the order in which the obligations will actually bite.
Where the policy is, measured rather than asserted
In 2024 the UNDP and the Government of Montenegro published an Artificial Intelligence Landscape Assessment, scoring readiness across three pillars on a scale running from basic (above 0 to 1) to transformative (above 4 to 5):
- Government as a user of AI: 2.4 — systemic phase
- Government as an enabler of the AI ecosystem: 3.2 — differentiating phase
- Ethical AI, meaning the legal and policy framework: 1.4 — opportunistic phase
Read those three numbers in order. The state is furthest ahead at promoting AI and furthest behind at governing it, and the gap between the second and third figures is the space your compliance programme has to cover on its own. A national AI strategy for 2026–2030 has been in preparation, and the Ministry of Public Administration has established a directorate for artificial intelligence and takes part in the Council of Europe's Committee on Artificial Intelligence. None of that is an adopted binding instrument yet.
The same report notes that a draft replacement data protection law was prepared in March 2024 and was expected to be adopted after European Commission review. As at 25 August 2026 it has not been — which is why Articles 15a, 28 and 43 of the 2008 statute, and not a GDPR-aligned successor, are what governs your AI system today. The background to that is in our note on why Montenegro is not a GDPR country.
What to do before the strategy arrives
Four steps, none of which wait on legislation. Inventory every system that assesses a person — candidates, employees, borrowers, customers — and test each one against Article 15a: is a human genuinely capable of changing the outcome, and is that documented? For anything that scores personality, ability or behaviour, resolve the Article 28 consent question before deployment, not after, and file it with the filing-system record described in our note on what a foreign company must actually file. Write the Article 43 explanation now, in plain language, while the model is being chosen. And if training data or model weights move across borders, run the transfer analysis in our note on cross-border data transfers.
If you are deploying or procuring an AI system that touches Montenegro — or selling one from Montenegro into the EU — send us the system description, the data flows and the human-oversight design, and we will tell you which of these provisions you are already inside and what has to change before it goes live. This work sits in our AI practice, alongside data protection and IT and technology.
Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24), the consolidated Zakon o autorskom i srodnim pravima (Sl. list CG 37/2011, 53/2016, 145/2021, 48/2024) and the Zakon o digitalnoj operativnoj otpornosti finansijskog sektora (Sl. list CG 14/26). Treaty status is from the Council of Europe Treaty Office and readiness scores from the UNDP and Government of Montenegro Artificial Intelligence Landscape Assessment for Montenegro, 2024. All read on 25 August 2026. Translations are ours. General information on Montenegrin law, not advice on a specific system.




