What this page decides
Two things are true about artificial intelligence in Montenegro, and both are routinely used to reach the wrong conclusion.
There is no Montenegrin artificial intelligence statute. And Regulation (EU) 2024/1689, the EU AI Act, does not apply of its own force on Montenegrin territory, because Montenegro is a candidate state and there is no transposition and no domestic equivalent.
Neither of those facts creates a regulatory vacuum. Four provisions already in force reach directly into the systems companies are actually deploying — automated screening of candidates, credit and risk scoring, performance monitoring, biometric identification. Three of them sit in the data protection act and one in a statute adopted in February 2026. None of them mentions artificial intelligence. All of them apply to it. A separate set of provisions, in the general law of obligations, decides who pays when the system causes loss — and there the classification questions are open in ways that change the size of the exposure.
This page gives the article numbers for both halves: what constrains a system before deployment, and what happens after something goes wrong. Scope: the article-level treatment below is Montenegrin. Our Türkiye practice handles the Turkish side of a cross-border technology file; we do not state Turkish statute on this page, because a page that mixes two regimes without citing either causes the mistake it is meant to prevent. General information on Montenegrin law, not advice on a specific system.
The four provisions that already apply
The statute is the Zakon o zaštiti podataka o ličnosti, "Službeni list Crne Gore" br. 079/08, 070/09, 044/12, 022/17 and 077/24. The supervisory authority's own list of applicable regulations, read on 10 September 2026, still names that Act and links to the 2024 consolidated text: no successor act appears on it.
| Obligation | Provision | What it catches |
|---|---|---|
| No decision based solely on automated processing | Data protection act, Article 15a | Screening, scoring, performance and behaviour assessment |
| Prior consent of the supervisory authority for special-risk automated processing | Data protection act, Article 28(1) | Profiling engines, biometrics, public-area video |
| Explain the manner of the automated processing on request, within 15 days | Data protection act, Article 43(2)(7) | Any Article 15a system |
| ICT risk management, testing and incident reporting | Digital operational resilience act, Sl. list CG 14/26 | AI inside regulated financial entities |
Article 15a is the provision most companies are unknowingly in breach of. When deciding on a person's rights, obligations and interests, an assessment of their personal characteristics and abilities relevant to that decision may not be based solely on automated processing. The Act then names what it means, and the list reads like a specification for a modern HR or fintech stack: results of work at the workplace, reliability, creditworthiness, behaviour and similar.
There are two exits and both are narrow. Article 15a(2)(1) permits a solely automated decision where, in concluding or performing a contract, the data subject's request has been accepted, or where appropriate measures protect their legitimate interests — the Act's own example is the possibility for the person to express their view. Article 15a(2)(2) permits it where a law prescribes it and that law also prescribes safeguards. In practice this means a human who can actually change the outcome, documented, rather than a review step added to the workflow diagram after the fact.
Article 28(1) turns an AI rollout into a permit question. Where a controller plans automated processing presenting a special risk to rights and freedoms, it must obtain the supervisory authority's consent before each such processing — and the Act says "especially" where the processing involves special categories of data, data relating to the assessment of personality, ability or behaviour, public-area video surveillance, or biometric data. Article 28(2) disapplies the requirement where processing rests on a law, on the person's consent, or on the necessity of performing a contract with them, so the contract and consent routes carry real weight. But a profiling engine that scores personality or behaviour sits squarely inside the "especially" list, and that question is resolved before deployment rather than after.
Article 43(2)(7) is Montenegro's explainability right, and it exists without any AI statute. On a written request, after verifying identity, the controller must respond within 15 days stating whether the person's data is processed and, if it is, provide further information — including, at point 7, the manner of the automated processing in a case under Article 15a. If you cannot describe how the model reaches a decision in terms a person can understand, you cannot answer that request. That is a constraint on model selection and documentation, not a disclosure exercise to be run later.
The financial-sector layer is newer, and its scope is far wider than most summaries show. The Zakon o digitalnoj operativnoj otpornosti finansijskog sektora, "Sl. list Crne Gore" br. 14/26, passed by Parliament on 2 February 2026, transposes Regulation (EU) 2022/2554. Read from the Central Bank of Montenegro's own copy of the Act on 10 September 2026, its Article 2(1) does not stop at banks: it lists 27 categories of financial entity. Credit institutions, payment institutions, registered account information providers and e-money institutions are only points 1 to 4. The list continues through investment firms, the central clearing depository, central counterparties, trading venues and trade repositories; alternative and open-end fund management companies, occupational pension institutions, data reporting service providers and benchmark administrators; insurance and reinsurance companies, branches of foreign insurers and reinsurers, and insurance brokerage and agency companies together with their ancillary and sole-trader variants; and ends at point 26 with crypto-asset service providers and point 27 with issuers of asset-referenced tokens.
Three structural provisions travel with that list. Article 2(2) carves out four groups, including insurance intermediaries classified as micro, small or medium entities and occupational pension institutions running schemes with no more than 15 members. Article 3(1) allocates the supervisor by category — the Central Bank of Montenegro for points 1 to 4, the Capital Market Commission for points 5 to 14, the Insurance Supervision Agency for points 15 to 25, and for points 26 and 27 the body designated by a separate law — so the regulator you answer to on an AI deployment follows the licence you hold, not the technology. And the commencement is layered in the way Montenegrin transposition statutes usually are: Article 56 brings the Act into force on the eighth day after publication, Article 54 gives financial entities 24 months from entry into force to bring themselves into compliance, and Article 55 defers a listed set of provisions until the day Montenegro accedes to the European Union.
AI systems inside those firms are ICT systems: the risk management, testing and incident reporting obligations reach them without any separate AI rule, and an insurance agency or a fund manager is as much inside that perimeter as a bank. The regulated-activity perimeter is on our fintech and crypto page.
The full treatment of these four provisions, with the deployment checklist, is in what already regulates your AI system in Montenegro, and the surrounding data protection duties — the filing-system notification, the officer, the employee-monitoring rules — are in what a foreign company must actually do and employer data obligations.
Training data and output: what the copyright act actually says
Two questions arrive in every AI project, and the Montenegrin copyright statute answers them less comfortably than most templates assume.
Start with the gazette chain, because ours needed correcting. The Act is the Zakon o autorskom i srodnim pravima, and the Government's own copyright page, read on 10 September 2026, gives the chain as "Službeni list CG" br. 37/11, 53/16, 145/21, 48/24, 84/24 and 100/24. Guidance that stops at 48/24 — including, until this reading, our own — is citing an incomplete chain. We verified the article numbers below against the text as enacted and the 145/21 amending act, both machine-readable and both read on 10 September 2026; we could not retrieve the 53/16, 48/24, 84/24 or 100/24 amending acts, so confirm the gazette before relying on a number in a document you are signing.
Can you train on protected material? There is no dedicated text-and-data-mining exception, and the structure of the Act is what makes that decisive. Article 45 does not open a general fair-use style enquiry: it provides that limitations on copyright are permitted only in the cases of Article 43, Articles 46 to 61, and Articles 76, 113, 114 and 144, and only where they do not conflict with normal exploitation of the work or unreasonably prejudice the author's legitimate interests. That is a closed list, and nothing in it corresponds to Articles 3 and 4 of the EU's 2019 Digital Single Market Directive or to the opt-out mechanism that regime created. Article 49 covers transient and incidental copying and Article 60 covers research through dedicated terminals in archives, libraries, museums and educational or scientific institutions; neither is a training-data permission.
The consequence is precise. Montenegro offers no statutory safe harbour for training on protected works — not a permissive regime, not a prohibitive one, but an unaddressed one. Anyone building a training pipeline that touches Montenegrin rights holders is relying on licences, on public domain material, or on an argument the statute does not supply.
Two further paragraphs of Article 45 cut the other way, in favour of the user. Article 45(2) provides that the permitted limitations cannot be the subject of waiver, and Article 45(3) makes void any contractual provision by which a user waives them. A licence term drafted to remove rights the Act grants does not achieve it here.
Who owns the output? Article 4 defines a work as an individual intellectual creation in literature, science or art expressed in a particular way — and its list of examples expressly includes computer programs. Article 9 is headed "Natural person" and states that the author is the natural person who created the work. On the face of those two provisions, output generated without a human creator has no author and therefore no copyright, and the live question for AI-assisted work is whether the human contribution is itself an individual intellectual creation under Article 4. We are not aware of Montenegrin case law fixing where that threshold sits, and we are not going to invent one.
What that leaves is contractual, and the categories do not behave alike. Where the deliverable is a computer program, Article 115 vests all economic and other rights in the employer or the commissioning party, unlimited and exclusive, unless otherwise agreed — and it covers commissioned work, not only employment. Everything around the program behaves differently: Article 100 deems a work created in employment assigned to the employer for five years from completion, after which the rights revert to the author, who is then obliged to re-assign on request against appropriate remuneration. Prompt libraries, evaluation sets, documentation, UI artwork and training material produced by a Montenegrin team therefore carry a clock the source code does not. The clause-drafting consequences are set out in the four clauses that decide a Montenegrin SaaS or outsourcing contract.
And copyright is the wrong instrument for most of what an AI business actually values. It does not protect an algorithm, a training pipeline, a scoring model or a set of model weights. A separate statute does, and it conditions protection on measures you must be able to prove you took — that analysis is in what actually protects your source code and your model and on our IT law page.
When it causes loss: three regimes decide who pays
The compliance question and the liability question are different, and the second one has no AI statute either. Claims are decided under the Zakon o obligacionim odnosima, chain "Službeni list CG" br. 047/08, 004/11, 022/17 and 123/24, read on 5 September 2026. An AI system has no legal personality, so the claim lands on the people and companies around it — and which regime a claimant reaches for often decides the case more than the facts do.
| General delict (Art. 148(1)) | Dangerous thing or activity (Arts. 148(2), 167–172) | Defective product (Arts. 175–182) | |
|---|---|---|---|
| Fault | Presumed; the defendant must disprove it | Irrelevant | Irrelevant for the Art. 175(1) defect limb |
| Causation | Claimant proves | Presumed under Art. 168 | Claimant proves (Art. 175(3)) |
| Defendant | Whoever caused the damage; employer under Arts. 164–166 | The holder, or the person carrying on the activity (Art. 169) | Producer, brand-owner, importer, supplier as fallback (Art. 178) |
| Reaches pure software? | Yes — no thing required | Turns on whether it is an opasna stvar under Art. 167(1); unresolved | Doubtful — Art. 176(1) defines a product as a movable thing |
| Can it be contracted out of? | Subject to the general limits on exclusion clauses | Not against an injured third party | No — Art. 181 |
Three features of that table change decisions made long before a dispute.
The burden is not where common-law templates assume. Article 148(1) provides that whoever causes damage is bound to compensate it unless he proves the damage arose without his fault. Fault is presumed once damage and causation are shown. And where your staff deploy or rely on the system, Article 164(1) makes the employer liable for damage an employee causes a third party in or in connection with work, unless the employer proves the employee acted as they should have in the circumstances — which turns instructions, training and access control into the evidence file that decides the claim.
Two classifications are genuinely open, and both are expensive if they go against you. Whether an AI system is a dangerous thing within Article 167(1) is unresolved in Montenegro so far as we have been able to establish, and we are not going to manufacture an answer. What the statute makes relevant is not the technology's novelty but whether its position, use, properties or mere existence represent an increased danger to the surroundings — and the consequence of that classification is severe, because it brings both Article 148(2) no-fault liability and the Article 168 presumption that damage arising in connection with the thing originated from it. In the other direction, Article 176(1) defines a product as a movable thing, or an independent part built into a movable or immovable thing, and Article 176(2) adds forms of energy. There is no software limb, so a model supplied purely as a service may fall outside Articles 175 to 182 altogether. An autonomous or safety-adjacent deployment has to price both possibilities rather than assume them away.
Your terms of use do less than they say. Article 178(1) treats anyone who presents themselves as the producer by putting their name, trade mark or other distinguishing sign on the product as the producer — the badging rule, which reaches a company shipping a third-party model under its own brand. Article 178(2) puts importers in the same class jointly and severally, and Article 178(3) reaches any supplier where the producer cannot be identified, unless the supplier names its own supplier within a reasonable time. Article 181 is then short and absolute: the producer's liability cannot be excluded or limited in advance by agreement with the injured party. A cap may still operate between contracting parties; it does not answer a claim by the person actually harmed. Article 180(1) carries the defences, including the development-risk defence, and Article 182 gives three years from knowledge of the damage, the defect and the producer, with a ten-year long-stop from circulation.
The full three-regime analysis, including the Article 171(4) rule on entrusting a dangerous thing to someone not qualified to handle it, is in when an AI system causes loss in Montenegro.
The EU AI Act: not binding, not irrelevant
Regulation (EU) 2024/1689 is EU law. Montenegro is a candidate state, not a member; the Regulation does not apply of its own force here and there is no Montenegrin equivalent.
That is not the same as saying it cannot reach you. Its scope provisions extend to operators established outside the Union in defined circumstances connected to the Union market and to the use of system outputs there — which is why a Montenegrin company selling an AI product into the EU, or supplying a European customer, has to run the analysis rather than assume geography answers it.
We are deliberately not reproducing the Regulation's article numbers, its penalty tiers or its application timetable on this page. EUR-Lex did not return the authentic text to us on 10 September 2026, as it did not on 25 August 2026 when we last tried, so we have not verified those figures against the source. Read the Regulation's scope and commencement articles directly before relying on any date, threshold or percentage, including one quoted to you by an adviser. A page that reproduces an unverified timetable is worse than one that says it could not check.
What Montenegro has committed to
Treaty signatures are a better guide to direction than commentary, and they are precise, public and datable. The Council of Europe Treaty Office was not reachable from our network on 10 September 2026; the positions below were read there on 25 August 2026 and should be re-checked against the Treaty Office before they are relied on.
| Instrument | Montenegro's position, read 25 August 2026 |
|---|---|
| Framework Convention on AI and Human Rights, Democracy and the Rule of Law (CETS 225), opened at Vilnius 05/09/2024 | Signed 05/11/2024; not ratified; not in force for Montenegro |
| Convention 108 on automatic processing of personal data (ETS 108) | In force for Montenegro since 06/06/2006 |
| Additional Protocol on supervisory authorities and transborder data flows (ETS 181) | In force for Montenegro since 01/07/2010 |
| Convention 108+ (CETS 223), the modernised data protection text | Neither signed nor ratified |
Two things follow. Montenegro was an early signatory of the first binding international treaty on AI, six weeks after it opened — but signature is a statement of direction, not an obligation that binds you today, and that convention requires five ratifications including at least three Council of Europe member States to enter into force.
The contrast with the row below it is the useful part. Montenegro signed the new AI convention promptly while remaining outside Convention 108+, the modernised data protection text most of Europe has moved to. Its AI commitments are running ahead of its data protection ones, which is the reverse of the order in which the obligations will actually bite.
The currency checks to make before you build against any of this
Three moving parts, and each of them can invalidate an article number in a compliance note written today.
The data protection act is being replaced. The Government's Predlog zakona o zaštiti podataka o ličnosti (parliamentary file EPA 1164 XXVIII) was published on 10 August 2026, and a set of 70 Government amendments was filed on 1 September 2026 after an earlier set was withdrawn following the Legislative Committee's legal-technical suggestions. Read on 10 September 2026, the supervisory authority's list of applicable regulations still names only the 2008 Act, so Articles 15a, 28 and 43 remain the provisions governing your AI system. Two features of the amendment set matter for planning: the article numbering shifts, so anything drafted today against a bill article number will cite the wrong number after adoption; and the amended commencement wording provides that the law applies six months after entry into force. The bill's own body is published as a scanned image without a text layer, so we make no claim about provisions we could not read. Why the regime in force is not GDPR is set out in Montenegro is not a GDPR country.
The copyright chain runs further than most citations show, as set out above: 37/11, 53/16, 145/21, 48/24, 84/24 and 100/24, with four of those amending acts not retrievable to us on 10 September 2026.
Training data and model weights that cross a border raise a separate permission question, which is not answered by the AI analysis at all — it runs on the transfer provisions of the data protection act, and it is set out in cross-border data transfers and on our data protection page.
What we do
We map a specific system against the provisions above rather than against a maturity framework. That means: testing each system that assesses a person against Article 15a and documenting whether a human can genuinely change the outcome; resolving the Article 28 prior-consent question before deployment for anything scoring personality, ability or behaviour; drafting the Article 43 explanation while the model is still being selected rather than after a request arrives; and running the transfer analysis separately where training data or weights move across a border.
On the liability side we map the supply chain — who built the system, whose brand is on it, who operates it, who the end users are — against Articles 164, 169, 178 and 181, and we tell you which of the Article 172 and Article 180 defences your current documentation actually supports. Where the deployment sits inside a regulated financial entity, the 14/26 obligations are run alongside. Where the counterparty entity is still being formed, the company-law questions are on our corporate law page.
If you are deploying, procuring, reselling or building an AI system that touches Montenegro — or selling one from Montenegro into the EU — send us the system description, the data flows, the human-oversight design and your current terms, before it goes live. We will tell you which of these provisions you are already inside and what has to change.
Legal basis
- Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24) — čl. 15a, 28, 43Consolidated text published by the supervisory authority (AZLP), read 10 September 2026. Automated decisions, prior consent for special-risk processing, and the 15-day explanation duty.Official text
- Zakon o autorskom i srodnim pravima (Sl. list CG 37/11, 53/16, 145/21, 48/24, 84/24, 100/24) — čl. 4, 9, 45, 49, 60, 100, 115Gazette chain from the Government's own copyright page, read 10 September 2026. No text-and-data-mining exception; the author is a natural person; rights in a computer program vest in the employer or commissioning party.Official text
- Zakon o digitalnoj operativnoj otpornosti finansijskog sektora (Sl. list CG 14/26) — čl. 2, 3, 54, 55, 56Central Bank of Montenegro's copy of the Act, read 10 September 2026. Article 2(1) lists 27 categories of financial entity; Article 54 gives 24 months to comply; Article 55 defers listed provisions to EU accession.Official text
- Zakon o obligacionim odnosima (Sl. list CG 047/08, 004/11, 022/17, 123/24) — čl. 148, 164, 167-172, 175-182Consolidated chain read 5 September 2026. Presumed fault, the dangerous-thing causation presumption, the defective-product chapter and the Article 181 bar on excluding producer liability.
Frequently asked questions
Does the EU AI Act apply to our Montenegrin company?
Not of its own force. Montenegro is a candidate state, not an EU member, and Regulation (EU) 2024/1689 has not been transposed into Montenegrin law; there is no domestic equivalent. That does not make it irrelevant, because its scope provisions extend to operators established outside the Union in defined circumstances connected to the Union market and to the use of system outputs there — so a Montenegrin company selling an AI product into the EU still has to run the analysis. We do not reproduce the Regulation's article numbers, penalty tiers or application dates on this page: EUR-Lex did not return the authentic text to us on 10 September 2026, as it did not on 25 August 2026, so read the scope and commencement articles directly rather than relying on a figure quoted second-hand.
So is there no AI regulation in Montenegro at all?
There is no AI statute. There are four provisions already in force that apply to AI systems: Articles 15a, 28 and 43(2)(7) of the Zakon o zaštiti podataka o ličnosti (Sl. list CG 079/08, 070/09, 044/12, 022/17, 077/24), and the Zakon o digitalnoj operativnoj otpornosti finansijskog sektora (Sl. list CG 14/26) for regulated financial entities. None of them uses the words 'artificial intelligence', and all of them reach automated decision-making, profiling, explainability and ICT risk. Separately, the general law of obligations decides who pays when a system causes loss.
Can we run fully automated hiring or credit decisions?
Not as a default. Article 15a provides that when deciding on a person's rights, obligations and interests, the assessment of their personal characteristics and abilities relevant to that decision may not be based solely on automated processing — and the examples the Act itself gives are results of work at the workplace, reliability, creditworthiness and behaviour. Article 15a(2) allows a solely automated decision only where, in concluding or performing a contract, the person's request was accepted or appropriate measures protect their legitimate interests (the Act's example is the possibility for the person to express their view), or where a law prescribes it together with safeguards. In practice that means a human who can genuinely change the outcome, documented — not a review step added to the workflow diagram afterwards.
Do we need permission before deploying an AI system?
Possibly, and it is a real gate rather than a formality. Article 28(1) requires the supervisory authority's consent before each instance of automated processing that presents a special risk to rights and freedoms, and names as particular cases special categories of data, data relating to the assessment of personality, ability or behaviour, video surveillance of public areas, and biometric data. Article 28(2) disapplies the requirement where the processing rests on a law, on the person's consent, or on the necessity of performing a contract with them — a carve-out that absorbs a good deal of ordinary commercial processing. A profiling engine that scores personality or behaviour sits squarely inside the Article 28(1) list, so the question is resolved before deployment rather than after.
Does anyone have a right to an explanation of our model?
Yes, and it predates any AI statute. Under Article 43(1), on a written request and after verifying identity, the controller must reply within 15 days confirming whether the person's data is processed. If it is, Article 43(2) requires further information, and point 7 of that paragraph is the manner of the automated processing in a case under Article 15a. Article 43(3) adds that the reply must be in writing and must be comprehensible. If you cannot describe how the model reaches a decision in terms a person can understand, you cannot answer that request — which makes it a constraint on model selection and documentation rather than a disclosure task to solve later.
Can we train on copyrighted material, and who owns the output?
There is no text-and-data-mining exception, and the structure of the Act is what makes that decisive. Article 45 of the Zakon o autorskom i srodnim pravima permits limitations on copyright only in the cases of Article 43, Articles 46 to 61, and Articles 76, 113, 114 and 144 — a closed list with nothing corresponding to Articles 3 and 4 of the EU's 2019 Digital Single Market Directive and no opt-out mechanism. Article 49 covers transient and incidental copying and Article 60 covers research through dedicated terminals; neither is a training permission. On output, Article 4 defines a work as an individual intellectual creation expressed in a particular way and Article 9 provides that the author is the natural person who created it, so purely machine-generated output has no author on the face of the statute; for AI-assisted work the open question is whether the human contribution is itself an individual intellectual creation, and we are not aware of Montenegrin case law fixing that threshold. Rights in deliverables are therefore secured by contract: Article 115 vests all rights in a computer program in the employer or commissioning party, while Article 100 assigns other works created in employment to the employer for only five years before they revert. Note the gazette chain runs to 37/11, 53/16, 145/21, 48/24, 84/24 and 100/24 (Government copyright page, read 10 September 2026); citations that stop at 48/24 are incomplete.
We are a regulated financial entity. Is there anything extra?
Yes, and the scope is wider than most summaries show. The Zakon o digitalnoj operativnoj otpornosti finansijskog sektora (Sl. list CG 14/26), passed on 2 February 2026, transposes Regulation (EU) 2022/2554, and its Article 2(1) lists 27 categories of financial entity — not only credit institutions, payment institutions, registered account information providers and e-money institutions, but investment firms, the central clearing depository, central counterparties, trading venues, trade repositories, fund management companies, occupational pension institutions, data reporting service providers, benchmark administrators, insurers and reinsurers, branches of foreign insurers and reinsurers, insurance brokerage and agency companies, and at points 26 and 27 crypto-asset service providers and issuers of asset-referenced tokens. Article 2(2) carves out four groups, including insurance intermediaries classified as micro, small or medium entities and occupational pension schemes with no more than 15 members. Article 3(1) allocates the supervisor by category, Article 54 gives 24 months from entry into force to comply, and Article 55 defers a listed set of provisions until EU accession. Read from the Central Bank of Montenegro's copy of the Act on 10 September 2026.
Who pays when an AI system causes loss, and can we cap it in our terms?
Three regimes in the Zakon o obligacionim odnosima decide it, and the choice of regime often matters more than the facts. Article 148(1) presumes fault: whoever causes damage must compensate it unless he proves it arose without his fault. Articles 148(2) and 167 to 172 apply to dangerous things and activities without regard to fault, and Article 168 presumes that damage arising in connection with such a thing originated from it — whether an AI system is a dangerous thing under Article 167(1) is unresolved in Montenegro. Articles 175 to 182 cover defective products, but Article 176(1) defines a product as a movable thing, so a model supplied purely as a service may fall outside that chapter entirely. On capping: Article 178(1) treats anyone who puts their name or trade mark on the product as its producer, and Article 181 provides that the producer's liability cannot be excluded or limited in advance by agreement with the injured party. A cap may still operate between contracting parties; it does not answer a claim by the person actually harmed.
Get Expert Advice
Initial assessment within the same business day.

