Technology

When an AI System Causes Loss in Montenegro, Three Existing Regimes Decide Who Pays

No AI liability act exists — Article 148(1) presumes fault, Article 168 presumes causation, and Article 176 defines a product as a movable thing.

Rohat Kahraman· 5 September 2026Updated · 5 September 2026
Abstract cover for a guide to liability for AI systems under Montenegrin obligations law

Montenegro has no artificial intelligence statute and no AI liability statute. We have set out elsewhere which provisions already regulate an AI system on the compliance side. This page answers the separate question that arrives after something has gone wrong: a model scored a customer wrongly, an automated process rejected a claim it should not have, a tool produced output a client relied on and lost money. Who pays, and what does the claimant have to prove?

The answer sits in the general law of obligations, and the three regimes there behave very differently from one another — differently enough that the choice of regime, rather than the facts, often decides the case.

Article numbers are from a consolidated text of the Zakon o obligacionim odnosima that includes the most recent amending act — chain "Službeni list CG" br. 047/08 of 07.08.2008, 004/11 of 18.01.2011, 022/17 of 03.04.2017 and 123/24 of 23.12.2024 — read on 5 September 2026. General information, not advice on a specific dispute.

Regime 1: the general rule already reverses the burden

Common-law readers usually assume a claimant must prove fault. Article 148(1) does the opposite: whoever causes damage to another is bound to compensate it unless he proves that the damage arose without his fault. Fault is presumed once damage and causation are established, and the defendant carries the burden of disproving it.

Article 148(2) goes further for a defined category: for damage from things or activities from which an increased danger of damage to the surroundings arises, liability attaches without regard to fault at all. Article 148(3) preserves other statutory cases of no-fault liability.

Article 149 defines what is recoverable: reduction of property (ordinary damage), prevention of its increase (lost profit) and violation of personality rights (non-material damage). Lost profit is inside the concept, not a separate head to be argued for.

Who the defendant actually is

An AI system does not have legal personality, so the claim lands on people and companies around it.

Article 164(1) makes an employer liable for damage an employee causes to a third party in work or in connection with work, unless the employer proves the employee acted as they should have in the circumstances. Article 164(2) allows the injured party to claim directly from the employee where the damage was caused intentionally. Article 164(4) gives the employer recourse against the employee for intent or gross negligence, and Article 164(5) limits that recourse to six months from the date compensation was paid. Article 165 extends the same rules to other employers, and Article 166(1) makes a legal person liable for damage caused to a third party by its organ in performing or in connection with performing its functions.

Read practically: where an employee deploys or relies on an AI tool and a third party is harmed, the company is the defendant, and its escape route under Article 164(1) is to show that the employee behaved as they should have — which turns on what instructions, training and controls existed.

Regime 2: dangerous things, and the presumption that decides cases

Article 167(1) defines dangerous things as movable or immovable things whose position, use, properties or mere existence represent an increased danger of damage to the surroundings; Article 167(2) defines dangerous activities correspondingly.

Article 168 is the provision that matters most in this chapter. Damage arising in connection with a dangerous thing or activity is deemed to originate from it, unless it is proved that they were not the cause. Causation is presumed, and the defendant must break the link.

Article 169 identifies the defendant: for damage from a dangerous thing, its holder (imalac); for damage from a dangerous activity, the person carrying that activity on. Article 171(1) shifts responsibility to a person to whom the holder entrusted the thing for use, or who is obliged to supervise it and is not employed by the holder; Article 171(2) keeps the holder liable alongside where the damage arose from a hidden defect or property the holder did not point out. And Article 171(4) states a rule with an obvious modern application: a holder who entrusted a dangerous thing to a person not qualified or not authorised to handle it answers for the resulting damage.

The escape routes are narrow. Under Article 172(1) the holder is released by proving the damage came from a cause outside the thing whose effect could not be foreseen, avoided or removed; Article 172(2) by proving the damage was caused exclusively by the act of the injured party or of a third party which the holder could not foresee and whose consequences it could not avoid. Article 172(3) allows partial release for contributory conduct, and Article 172(4) makes a contributing third party liable jointly and severally. Article 172(5) closes a gap that defendants often try to use: a person the holder used in operating the thing is not regarded as a third party.

Whether an AI system is an opasna stvar within Article 167(1) is, so far as we have been able to establish, unresolved in Montenegro, and we are not going to manufacture an answer. What can be said is what the statute makes relevant: Article 167(1) turns on position, use, properties or mere existence creating increased danger, not on the technology's novelty; and the consequence of the classification is severe, because it brings both Article 148(2) no-fault liability and the Article 168 causation presumption. Any assessment of an autonomous or safety-adjacent deployment has to price that possibility rather than assume it away.

Regime 3: the defective-product chapter, and the definition that may exclude software

Article 175(1) imposes liability without regard to fault on a person who puts into circulation a thing they produced which, because of a defect they did not know of, presents a danger of damage to persons or things. Article 175(2) adds a second limb aimed squarely at documentation: the producer answers for the dangerous properties of the thing if it did not take everything necessary to prevent foreseeable damage by warning, by safe packaging or by another appropriate measure. Article 175(3) then allocates proof: the injured person must prove the defect, the damage and the causal link — no Article 168 presumption here.

Article 177(1) defines defectiveness by expectation rather than by malfunction: a product is defective if, taking account of all the circumstances and in particular the way it was presented, the purposes for which it may reasonably be expected to be used, and the time it was put into circulation, it does not provide the safety justifiably expected of such a product. Article 177(2) adds that a product is not defective merely because a better one was later put on the market — which matters when a model is superseded by a more accurate version.

Article 178 widens the defendant class considerably. The producer is the maker of the finished product, the maker of raw material or of a component, and anyone who presents themselves as the producer by putting their name, trade mark or other distinguishing sign on it — the badging rule, which reaches a company that ships a third-party model under its own brand. Article 178(2) treats an importer for sale, lease or other circulation as producer, jointly and severally with those in Article 178(1). Article 178(3) treats any supplier as producer where the producer cannot be identified, unless the supplier informs the injured party within a reasonable time of who supplied it. Article 179 makes multiple liable persons jointly and severally liable.

Article 180(1) lists the defences, and one is the familiar development-risk defence: that the state of science or technical knowledge at the time of putting into circulation did not permit the defect to be discovered. The others are non-circulation; the defect and its cause not existing at the time of circulation; the product not made for sale, lease or business purposes; the defect resulting from compliance with mandatory rules in force; and the damage being caused exclusively by the injured party, someone they answer for, or an unforeseeable third party. Article 180(2) gives a component producer a defence where the defect was caused by the design of the main product or by the main producer's instructions.

Article 181 is short and absolute: the producer's liability cannot be excluded or limited in advance by agreement with the injured party. A limitation-of-liability clause in terms of use does not answer a claim by the person actually harmed.

Article 182(1) gives three years from when the injured party knew or should have known of the damage, the defect and the producer; Article 182(2) extinguishes the right ten years after the product was put into circulation, unless proceedings were begun against the producer within that period.

And then the definitional point that decides whether any of this applies. Article 176(1) provides that a product is any movable thing, as well as an independent part built into a movable or immovable thing; Article 176(2) adds electrical and other forms of energy. There is no software limb. A model delivered as a service, with no movable thing anywhere in the supply, does not obviously sit inside that definition — and the chapter that would otherwise impose no-fault liability on its maker may therefore not reach it at all. Whether Montenegro follows the newer European approach to that question is a legislative matter we are not going to predict.

The three regimes side by side

General delict (Art. 148(1))Dangerous thing or activity (Arts. 148(2), 167–172)Defective product (Arts. 175–182)
FaultPresumed; defendant disprovesIrrelevantIrrelevant for the Art. 175(1) defect limb
CausationClaimant provesPresumed under Art. 168Claimant proves (Art. 175(3))
DefendantThe person who caused the damage; employer under Arts. 164–166The holder, or the person carrying on the activity (Art. 169)Producer, brand-owner, importer, and supplier as fallback (Art. 178)
Reaches pure software?Yes — no thing requiredTurns on whether it is an opasna stvar under Art. 167(1); unresolvedDoubtful — Art. 176(1) defines a product as a movable thing
Can it be contracted out of?Subject to the general limits on exclusion clausesNot against an injured third partyNo — Art. 181

What follows before deployment

The exposure is not evenly distributed, and the drafting decisions that change it are made early.

Where your company builds and badges the system, Article 178(1) puts you in the producer class whether or not you wrote the model, and Article 181 means the terms of use will not protect you from a third party's claim. The controls that actually help are the ones Article 175(2) and Article 177(1) make relevant: warnings, the way the system is presented, and the uses for which it may reasonably be expected to be used — because a use you documented as out of scope is a different case from one your marketing invited.

Where your company deploys someone else's system, Article 164(1) makes you the likely defendant for what your staff do with it, and your defence is evidence that they acted as they should have. Article 171(4) points to the same file from the other side: entrusting a dangerous thing to someone not qualified or authorised to handle it is itself a basis of liability, which turns access control and training into a liability question rather than an operational one.

And in both cases, the compliance provisions do not disappear. An automated decision made without a human who can genuinely change the outcome is a breach on the data protection side and, in a damages claim, is also evidence about fault — the compliance layer is set out in what already regulates your AI system in Montenegro.

Before the system goes into production

If you are deploying, reselling or building an AI system that touches Montenegro, send us the supply chain — who built it, whose brand is on it, who operates it and who the end users are — together with your current terms and your internal documentation. We will map which of the three regimes a claimant would reach for, where Article 178 puts each party in the chain, what Article 181 does to your liability clause, and which of the Article 172 and Article 180 defences your documentation currently supports. The contract layer for technology supply is in the four clauses in your SaaS contract, the non-material damage heads in non-pecuniary damages, the deadlines in limitation periods for claims, and how we run these files sits with our AI law practice.

Frequently asked questions

Is there an AI liability law in Montenegro?

No. There is no artificial intelligence statute and no dedicated AI liability act. Claims are decided under the general law of obligations — the fault-based rule in Article 148(1), the no-fault rule for dangerous things and activities in Articles 148(2) and 167 to 172, and the defective-product chapter in Articles 175 to 182.

Does the claimant have to prove that our company was at fault?

Not under the general rule. Article 148(1) requires the person who caused the damage to compensate it unless he proves the damage arose without his fault, so fault is presumed and the burden of disproving it sits with the defendant.

Could an AI system count as a "dangerous thing"?

The question is open. Article 167(1) defines dangerous things by whether their position, use, properties or mere existence represent an increased danger of damage to the surroundings, and we have not identified Montenegrin case law resolving how that applies to AI systems. The stakes of the classification are high, because it brings no-fault liability under Article 148(2) and the causation presumption in Article 168.

Is software a "product" for the defective-product rules?

Doubtfully, on the current text. Article 176(1) defines a product as any movable thing, or an independent part built into a movable or immovable thing, and Article 176(2) adds forms of energy. There is no express software limb, so a model supplied purely as a service may fall outside Articles 175 to 182 altogether.

Can we cap AI liability in our terms of use?

Not against the injured party under the product chapter. Article 181 provides that the producer's liability cannot be excluded or limited in advance by agreement with the injured party. A cap may still operate between contracting parties, but it does not answer a claim by the person actually harmed.

We only resell a third-party model under our own brand. Are we exposed?

Yes, potentially as a producer. Article 178(1) treats a person who presents themselves as the producer by putting their name, trade mark or other distinguishing sign on the product as the producer. Article 178(2) treats importers as producers jointly and severally, and Article 178(3) treats any supplier as producer where the producer cannot be identified, unless the supplier names its own supplier within a reasonable time.

Is there a development-risk defence?

Yes, within the product chapter. Article 180(1) releases the producer where it proves that the state of science or technical knowledge at the time the product was put into circulation did not permit the defect to be discovered. The same paragraph carries five other defences, including that the damage was caused exclusively by the injured party or by an unforeseeable third party.

How long does a claim last?

For defective-product claims, Article 182(1) gives three years from when the injured party knew or should have known of the damage, the defect and the producer, and Article 182(2) extinguishes the right ten years after the product was put into circulation unless proceedings were started within that period. Other claims run on the general limitation rules.