Technology

There Is No AI Act in Montenegro — and Four Provisions Already Regulate Your AI System

No AI Act here, but Articles 15a, 28 and 43 already govern automated decisions, profiling and explainability — plus the treaty Montenegro signed.

Rohat Kahraman· 25 August 2026Updated · 25 August 2026
Abstract cover for an article on which Montenegrin legal provisions already apply to artificial intelligence systems

Montenegro has not enacted an artificial intelligence statute, and the EU AI Act does not apply to it. Both of those things are true, and both are routinely used to reach the wrong conclusion — that an AI system deployed in Montenegro sits in a regulatory vacuum until accession.

It does not. Four provisions already in force reach directly into the systems companies are actually deploying: automated screening of job candidates, credit and risk scoring, performance monitoring, and biometric identification. Three of them sit in the data protection act and one in a statute adopted in February 2026. None of them mention artificial intelligence. All of them apply to it.

This page sets out what applies today, what does not apply and why, and the two documents that tell you where this is heading.

The four provisions that already bite

ObligationProvisionWhat it catches
No decision based solely on automated processingData protection act, Art. 15aScreening, scoring, performance and behaviour assessment
Prior consent of the supervisory authority for special-risk automated processingData protection act, Art. 28(1)Profiling systems, biometrics, public-area video
Explain the manner of automated processing on request, within 15 daysData protection act, Art. 43(2)(7)Any Art. 15a system
ICT risk management, testing and incident reportingDigital operational resilience act, Sl. list CG 14/26AI in regulated financial entities

Article 15a is the one most companies are unknowingly in breach of. When deciding on a person's rights, obligations and interests, an assessment of their personal characteristics and abilities that is relevant to the decision may not be based solely on automated processing. The Act then names what it means, and the list reads like a specification for a modern HR or fintech stack: results of work at the workplace, reliability, creditworthiness, behaviour and similar.

There are two exits, both narrow. Article 15a(2)(1) allows a solely automated decision where, in the course of concluding or performing a contract, the data subject's request has been accepted, or where appropriate measures protect their legitimate interests — the Act gives the example of the possibility for the person to express their view. Article 15a(2)(2) allows it where a law prescribes it, provided that law also prescribes safeguards. In practice this means a human who can actually change the outcome, documented, and not a rubber stamp added to the workflow diagram after the fact.

Article 28(1) is the provision that turns an AI rollout into a permit process. Where a controller plans automated processing that presents a special risk to rights and freedoms, it must obtain the supervisory authority's consent before each such processing — and the Act says "especially" where the processing involves special categories of data, data relating to the assessment of personality, ability or behaviour, public-area video surveillance, or biometric data. Article 28(2) disapplies the requirement where processing rests on a law, on the person's consent, or on the necessity of performing a contract with them, so the contract and consent routes matter — but a profiling engine that scores personality or behaviour is squarely inside the "especially" list.

Article 43(2)(7) is Montenegro's explainability right, and it exists without any AI statute. On a written request, after verifying identity, the controller must respond within 15 days stating whether the person's data is processed and, if it is, provide additional information — including, at point 7, the manner of the automated processing in a case under Article 15a. If you cannot describe how your model reaches a decision in terms a person can understand, you cannot answer that request. That is a design constraint on model selection and documentation, not a disclosure exercise you can run later.

The digital operational resilience act, Sl. list CG 14/26 of 9 February 2026, adds a layer for regulated financial entities. It transposes EU Regulation 2022/2554 and, under its Article 2(1), applies to credit institutions, payment institutions, registered account information providers, e-money institutions and crypto-asset service providers. Article 54 gives them 24 months from entry into force to comply. AI systems in those firms are ICT systems, and the ICT risk management, testing and incident reporting obligations reach them — the wider payments picture is in our note on Montenegro's payment services regime.

Two questions come up in every AI project, and Montenegrin copyright law answers them less comfortably than most templates assume. The statute is the Zakon o autorskom i srodnim pravima, Sl. list CG 37/2011, 53/2016, 145/2021 and 48/2024.

Can you train on protected material? There is no dedicated text-and-data-mining exception. The limitations chapter runs from Article 45 to Article 60 and contains the familiar catalogue — temporary acts of reproduction, teaching, quotation, official proceedings, works in public places, free adaptations, research through dedicated terminals — but nothing corresponding to Articles 3 and 4 of the EU's 2019 Digital Single Market Directive, and no opt-out mechanism of the kind that regime created. Article 49 covers transient and incidental copying, and Article 60 covers on-premises research terminals; neither is a training-data permission.

The practical consequence is that Montenegro offers no statutory safe harbour for training on protected works — not a permissive regime, and not a prohibitive one either, but an unaddressed one. Anyone building a training pipeline that touches Montenegrin rights holders is relying on licences, on public domain material, or on an argument the statute does not supply.

Who owns the output? Article 4 defines a work as an individual intellectual creation in literature, science or art, expressed in a particular way. Article 9 is titled "Natural person" and states plainly that the author is the natural person who created the work. On the face of those two provisions, output generated without a human creator has no author and therefore no copyright, and the live question for AI-assisted work is whether the human contribution is itself an individual intellectual creation under Article 4. We are not aware of Montenegrin case law resolving where that threshold sits, and we are not going to invent one.

What that leaves is contractual. Where the deliverable is a computer program, Article 115 vests all economic rights in the employer or the commissioning party by operation of law, unlimited and exclusive; other categories behave differently, including a five-year reversion under Article 100. We set that allocation out in full, with the clause-drafting consequences, in our note on IT contracts in Montenegro.

The EU AI Act: not binding, not irrelevant

Regulation (EU) 2024/1689 is EU law. Montenegro is a candidate state, not a member, and the Regulation does not apply of its own force on Montenegrin territory. There is no transposition and no Montenegrin equivalent.

That is not the same as saying it cannot reach you. The Regulation's scope provisions extend to operators established outside the Union in defined circumstances connected to the Union market and to the use of system outputs there, which is why a Montenegrin company selling an AI product into the EU, or supplying a European customer, has to run the analysis rather than assume geography answers it. The European Commission's own AI Act pages confirm that the prohibited-practice rules became effective in February 2025 and that further obligations phase in on a staggered basis.

We are deliberately not reproducing the Regulation's article numbers or its full application timetable here. EUR-Lex was returning "temporarily not fully available" throughout the day this page was written, 25 August 2026, and we could not retrieve the authentic text of Articles 2 and 113 to verify against. Read those two articles directly before relying on any date or scope statement, including ours. A page that quotes an unverified timetable is worse than one that says it could not check.

What Montenegro has actually committed to

Treaty signatures are a better guide than commentary, and they are precise, public and datable. Read at the Council of Europe Treaty Office on 25 August 2026:

InstrumentMontenegro's position
Framework Convention on AI and Human Rights, Democracy and the Rule of Law (CETS 225), opened at Vilnius 05/09/2024Signed 05/11/2024; not ratified; not in force for Montenegro
Convention 108 on automatic processing of personal data (ETS 108)In force for Montenegro since 06/06/2006
Additional Protocol on supervisory authorities and transborder data flows (ETS 181)In force for Montenegro since 01/07/2010
Convention 108+ (CETS 223), the modernised data protection textNeither signed nor ratified

Two things follow. Montenegro was an early signatory of the first binding international treaty on AI, six weeks after it opened. And that treaty is not yet in force anywhere: it requires five ratifications including at least three Council of Europe member States, and as at 25 August 2026 the Treaty Office records one ratification or accession and twenty signatures not followed by ratification. Signature is a statement of direction, not an obligation you can be held to yet.

The contrast with the row below it is the useful part. Montenegro signed the new AI convention promptly while remaining outside Convention 108+, the modernised data protection text that most of Europe has moved to. Its AI commitments are running ahead of its data protection ones, which is the reverse of the order in which the obligations will actually bite.

Where the policy is, measured rather than asserted

In 2024 the UNDP and the Government of Montenegro published an Artificial Intelligence Landscape Assessment, scoring readiness across three pillars on a scale running from basic (above 0 to 1) to transformative (above 4 to 5):

  • Government as a user of AI: 2.4 — systemic phase
  • Government as an enabler of the AI ecosystem: 3.2 — differentiating phase
  • Ethical AI, meaning the legal and policy framework: 1.4 — opportunistic phase

Read those three numbers in order. The state is furthest ahead at promoting AI and furthest behind at governing it, and the gap between the second and third figures is the space your compliance programme has to cover on its own. A national AI strategy for 2026–2030 has been in preparation, and the Ministry of Public Administration has established a directorate for artificial intelligence and takes part in the Council of Europe's Committee on Artificial Intelligence. None of that is an adopted binding instrument yet.

The same report notes that a draft replacement data protection law was prepared in March 2024 and was expected to be adopted after European Commission review. As at 25 August 2026 it has not been — which is why Articles 15a, 28 and 43 of the 2008 statute, and not a GDPR-aligned successor, are what governs your AI system today. The background to that is in our note on why Montenegro is not a GDPR country.

What to do before the strategy arrives

Four steps, none of which wait on legislation. Inventory every system that assesses a person — candidates, employees, borrowers, customers — and test each one against Article 15a: is a human genuinely capable of changing the outcome, and is that documented? For anything that scores personality, ability or behaviour, resolve the Article 28 consent question before deployment, not after, and file it with the filing-system record described in our note on what a foreign company must actually file. Write the Article 43 explanation now, in plain language, while the model is being chosen. And if training data or model weights move across borders, run the transfer analysis in our note on cross-border data transfers.

If you are deploying or procuring an AI system that touches Montenegro — or selling one from Montenegro into the EU — send us the system description, the data flows and the human-oversight design, and we will tell you which of these provisions you are already inside and what has to change before it goes live. This work sits in our AI practice, alongside data protection and IT and technology.

Statutory references are to the consolidated Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24), the consolidated Zakon o autorskom i srodnim pravima (Sl. list CG 37/2011, 53/2016, 145/2021, 48/2024) and the Zakon o digitalnoj operativnoj otpornosti finansijskog sektora (Sl. list CG 14/26). Treaty status is from the Council of Europe Treaty Office and readiness scores from the UNDP and Government of Montenegro Artificial Intelligence Landscape Assessment for Montenegro, 2024. All read on 25 August 2026. Translations are ours. General information on Montenegrin law, not advice on a specific system.

Frequently asked questions

Does the EU AI Act apply in Montenegro?

Not of its own force. Montenegro is a candidate state, not an EU member, and Regulation (EU) 2024/1689 has not been transposed into Montenegrin law. That does not make it irrelevant: its scope provisions extend to operators established outside the Union in circumstances connected to the Union market and to the use of system outputs there, so a Montenegrin company selling an AI product into the EU still has to run the analysis. Read Articles 2 and 113 of the Regulation directly — EUR-Lex was unavailable when this page was written and we have not reproduced their text or dates unverified.

So is there no AI regulation in Montenegro at all?

There is no AI statute. There are four provisions that already apply to AI systems: Articles 15a, 28 and 43 of the data protection act, and the digital operational resilience act (Sl. list CG 14/26) for regulated financial entities. None of them uses the words "artificial intelligence", and all of them reach automated decision-making, profiling and ICT risk.

Can we run fully automated hiring or credit decisions?

Not as a default. Article 15a provides that when deciding on a person's rights, obligations and interests, the assessment of their personal characteristics and abilities relevant to that decision may not be based solely on automated processing — and the examples it gives include results of work at the workplace, reliability, creditworthiness and behaviour. Article 15a(2) allows a solely automated decision only where, in concluding or performing a contract, the person's request was accepted or appropriate safeguards protect their legitimate interests (the Act's example is the possibility for the person to express their view), or where a law prescribes it with safeguards.

What counts as adequate human involvement?

The Act does not define it, but the structure of Article 15a(2)(1) points to a person who can actually affect the outcome and a route for the individual to put their case. A reviewer who approves model output without the authority or information to change it does not take the decision out of "solely automated". Document who the human is, what they see, and what they are empowered to do.

Do we need permission before deploying an AI system?

Possibly, and it is a real gate. Article 28(1) requires the supervisory authority's prior consent before each instance of automated processing that presents a special risk to rights and freedoms, and lists as particular cases special categories of data, data relating to the assessment of personality, ability or behaviour, public-area video surveillance, and biometric data. Article 28(2) disapplies it where processing rests on a law, the person's consent, or the necessity of performing a contract with them.

Does anyone have a right to an explanation of our model?

Yes, and it predates any AI statute. Under Article 43, on a written request and after verifying identity, the controller must reply within 15 days confirming whether the person's data is processed and, if so, provide further information — including at Article 43(2)(7) the manner of the automated processing in a case under Article 15a. Practically, that is a constraint on model choice and documentation, not a disclosure task to solve later.

Can we train a model on copyrighted material under a Montenegrin exception?

There is no dedicated text-and-data-mining exception. The limitations run from Article 45 to Article 60 of the copyright act and cover the familiar catalogue — transient copying, teaching, quotation, official proceedings, works in public places, free adaptations, research through dedicated terminals — with nothing equivalent to Articles 3 and 4 of the EU's 2019 Digital Single Market Directive and no opt-out mechanism. Article 49 is about transient and incidental copies and Article 60 about on-premises research terminals; neither is a training permission.

Is AI-generated output protected by copyright in Montenegro?

On the face of the statute, purely machine-generated output is not. Article 4 defines a work as an individual intellectual creation expressed in a particular way, and Article 9 — headed "Natural person" — provides that the author is the natural person who created the work. For AI-assisted work the question becomes whether the human contribution is itself an individual intellectual creation under Article 4. We are not aware of Montenegrin case law fixing that threshold, so treat it as unresolved rather than settled either way.

Then how do we secure rights in AI-assisted deliverables?

By contract, and by category. Where the deliverable is a computer program, Article 115 of the copyright act vests all economic and other rights in the employer or the commissioning party, unlimited and exclusive, unless otherwise agreed. Other categories differ — a work created in employment is assigned to the employer for only five years under Article 100 before reverting to the author. The drafting consequences are set out in our note on IT contracts in Montenegro.

Has Montenegro signed the Council of Europe AI convention?

Yes, and early. The Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) opened for signature at Vilnius on 05/09/2024, and the Council of Europe Treaty Office records Montenegro's signature on 05/11/2024. There is no ratification and it is not in force for Montenegro.

Is that convention in force anywhere?

Not yet. It requires five ratifications including at least three Council of Europe member States. As at 25 August 2026 the Treaty Office records one ratification or accession and twenty signatures not followed by ratification. A signature indicates direction; it is not an obligation that binds you today.

Is a national AI law coming?

A national artificial intelligence strategy for 2026–2030 has been in preparation and the Ministry of Public Administration has established a directorate for artificial intelligence and participates in the Council of Europe's Committee on Artificial Intelligence. None of that is an adopted binding instrument. The nearer-term change is the draft replacement data protection law prepared in March 2024, which as at 25 August 2026 remains unadopted.

How ready is Montenegro, on any objective measure?

The UNDP and the Government published an Artificial Intelligence Landscape Assessment for Montenegro in 2024, scoring three pillars on a scale from basic (above 0 to 1) to transformative (above 4 to 5): government as a user of AI 2.4 (systemic), government as an enabler of the ecosystem 3.2 (differentiating), and ethical AI — the legal and policy framework — 1.4 (opportunistic). The state is furthest ahead at promoting AI and furthest behind at governing it.

We are a bank or a payment institution. Is there anything extra?

Yes. The Zakon o digitalnoj operativnoj otpornosti finansijskog sektora, Sl. list CG 14/26 of 9 February 2026, transposes EU Regulation 2022/2554 and applies under its Article 2(1) to credit institutions, payment institutions, registered account information providers, e-money institutions and crypto-asset service providers. Article 54 gives financial entities 24 months from entry into force to comply. AI systems in those firms are ICT systems and fall inside the ICT risk management, testing and incident reporting regime.

Where should we start if we are deploying AI in Montenegro now?

Inventory every system that assesses a person and test it against Article 15a, asking whether a human can genuinely change the outcome and whether that is documented. Resolve the Article 28 consent question before deployment for anything scoring personality, ability or behaviour. Draft the Article 43 explanation while the model is still being selected. And if training data or model weights cross borders, run the transfer analysis separately, because that sits under Articles 41 and 42 of the same act.