All guidesGuide 09 · Doing business in Croatia

Artificial intelligence in business: legal risks and basic obligations

For companies, institutions and public-law bodies that already use or plan to introduce artificial intelligence systems.

10 min readLegal review 23 August 2026

Practice areaArtificial intelligence law and digital compliance

Artificial intelligence is already part of everyday business: it is embedded in office suites, search and document-processing tools, customer support, recruitment, video surveillance, analytics and numerous specialised systems. An organisation may therefore be using AI before that use has been formally identified or recorded.

Legal risk often arises from the actual use of a tool rather than its product name. The same tool may be used for routine text formatting or may contribute to a decision that significantly affects an employee, customer or citizen. The applicable obligations depend on the system's purpose, the organisation's role, the data involved and the consequences of its use.

This guide provides a basic overview of the issues to identify before introducing or expanding the use of artificial intelligence. A detailed assessment must address the particular system and the actual business process in which it is used.

Summary

Key points

  • The first step is to determine where AI is actually being used, including functions built into existing systems and licences.
  • The AI Act follows a risk-based approach, and the applicable obligations also depend on the organisation's role in relation to the system.
  • Personal data, trade secrets, confidential information and intellectual property rights must be considered alongside the obligations under the AI Act.
  • Systems that affect people's rights, employment, access to services or the work of public bodies require particularly careful assessment.
  • The supplier contract, technical documentation and system settings are just as important as the internal rules of use.
  • Effective governance links an AI-system register, clear responsibilities, tool approval, human oversight, incident response and staff training.
01

Artificial intelligence is already part of business

Organisations most often introduce artificial intelligence in two ways: by deliberately procuring a dedicated AI system or through the gradual addition of AI functions to tools already in use, such as office suites, document-management systems, video-conferencing platforms, monitoring systems, accounting software or customer-support tools.

At the same time, employees may independently use publicly available generative tools to draft text, summarise documents, translate, analyse data or create code. Such use can speed up work, but may also expose the organisation to risk if personal data, trade secrets, confidential documents or third-party protected content are entered into the tool.

The initial assessment should therefore cover systems, licences and suppliers as well as actual working practices. This makes it possible to determine which uses should be permitted, restricted, subject to additional review or governed by specific procedures.

02

Risks and obligations under the Artificial Intelligence Act

The AI Act links obligations to the system's purpose and level of risk and to the organisation's role in its development, placing on the market or deployment.

The EU Artificial Intelligence Act distinguishes prohibited practices, high-risk systems, systems subject to specific transparency obligations and other uses carrying a lower regulatory burden. Classification depends on the system's intended purpose and the circumstances of use, not merely on the product name or general description.

The rules apply in phases. AI-literacy obligations and most of the original prohibitions have applied since 2 February 2025, while most other provisions have applied since 2 August 2026. Following the July 2026 amendments, the requirements and obligations for Annex III high-risk systems apply from 2 December 2027, and those for Annex I product-related high-risk systems from 2 August 2028. Separate transitional dates apply to certain new prohibitions and marking obligations, including 2 December 2026. The applicable date must be checked against the type of system and the organisation's role.

The role of the organisation

An organisation may be the deployer of a system, but in certain circumstances it may also assume the obligations of a provider. This may occur when it places the system on the market under its own name, substantially modifies it or changes its intended purpose.

Before implementation, the organisation should determine the system's purpose, the persons affected, the data processed, its role in decision-making and the respective legal positions of the organisation and supplier. A supplier's compliance statement is only one element of the assessment.

03

Generative artificial intelligence, data and confidentiality

Generative tools can create text, images, sound, code and other content. Their output may contain inaccuracies, fabricated facts, bias or passages resembling protected works. It must therefore be reviewed before being used in legal, business or public communications.

Confidential and personal data should be entered only into approved tools with known processing settings and an appropriate contractual framework. In particular, the organisation should verify whether the supplier uses submitted data for model training, how long it is retained, where it is processed, who can access it and how it is deleted.

Where personal data is processed, data-protection law applies regardless of the system's classification under the AI Act. The organisation should determine the purpose and legal basis of the processing, the scope and retention period of the data, data-subject rights, security measures and any transfer outside the European Economic Area.

04

Decisions about people, human supervision and transparency

Special care is required where an AI system evaluates, ranks or profiles individuals or affects employment, access to education, credit, insurance, public services or the exercise of rights. In addition to the AI Act, data-protection, employment, equal-treatment, administrative-procedure and consumer-protection rules may apply.

For decisions producing legal or similarly significant effects, the actual role of automation and the possibility of human intervention should be established. Human oversight is effective only when the responsible person understands the system's limitations, can verify the relevant data and has the authority to change or stop the outcome and give reasons for doing so.

Certain systems must inform individuals that they are interacting with artificial intelligence, while labelling duties may apply to synthetic or manipulated content. The precise obligation depends on the type of system and content, the method of publication and the organisation's role.

05

Suppliers and contractual liability

Most organisations acquire an AI system as a service or as part of a broader information solution. Before contracting, they should obtain a clear description of its purpose and limitations, data sources and flows, security measures, subcontractors, oversight mechanisms and the documentation required to meet their own obligations.

The agreement should address permitted use, service levels, confidentiality, data processing and storage, intellectual property rights, incident reporting, cooperation with oversight, system changes, audit rights, liability and the return or deletion of data when the service ends.

Responsibilities are distributed between suppliers and users according to their actual roles. The organisation retains responsibility for its own choice of purpose, data, users and ways of including the system in the business process.

06

Essential internal governance

The scope of the documentation should correspond to the size of the organisation, the purpose of the system and the level of risk. A basic framework usually comprises several related elements.

Documentation should reflect actual procedures. A register without an assigned owner, a rule without an approval process or training without clear instructions has limited value. In practice, employees should know which tools they may use, what data they may enter, when further review is required and to whom a problem should be reported.

  • an AI-system register recording purposes, suppliers, users and key data
  • rules of permitted and restricted use, especially for generative tools
  • procedure for checking and approving a new system or significant changes to an existing system
  • clearly defined responsibilities for procurement, legal assessment, IT security, data protection and business use
  • rules for human oversight, reviewing outputs and informing people affected by the system
  • a procedure for reporting errors, incidents, unreliable outputs or suspected unauthorised use
  • training adapted to the role of employees and the risks of the tools they actually use
  • regular checking of suppliers, settings, uses and regulatory changes
07

Signs that require a more detailed assessment

A more detailed legal, organisational and technical assessment is particularly important where the system processes sensitive or extensive personal data or biometric data, monitors behaviour, profiles individuals or contributes to decisions affecting their rights or opportunities.

Situations requiring additional review

The appearance of one of these elements is a signal for a deeper analysis. The final classification and necessary measures depend on the actual function of the system, the data, the legal effect and the context of use.

  • systems related to employment, performance evaluation or termination of employment
  • biometric identification, categorisation of persons or advanced analysis of video surveillance
  • systems that affect access to public services, education, credit, insurance or other important rights
  • automated decision-making with legal or comparable significant effect
  • training or adapting the model on internal, confidential or personal data of the organisation
  • public posting of synthetic content and systems that interact directly with users
  • connecting AI systems with key business, security or infrastructure processes
  • transfer of data to third parties or to countries outside the European Economic Area
08

How we can help

We assess how artificial intelligence is actually used within an organisation and establish a practical framework for responsible use based on the systems, suppliers, data and risks identified.

We begin by reviewing key systems, licences and suppliers and mapping current uses. We then classify risks, set priorities and prepare rules, documentation and an implementation plan tailored to the organisation's actual processes.

Our support may include

  • initial assessment and mapping of the use of artificial intelligence
  • establishment of an AI-system register and risk classification
  • rules for the use of generative artificial intelligence and approved tools
  • determination of responsibility and procedure for approving new AI systems
  • verification of suppliers, licences, contracts and terms of use
  • assessment of obligations under the AI Act and data-protection law
  • arrangements for human oversight, transparency and incident response
  • preparation of practical forms, notices and internal documentation
  • employee education adapted to their roles and risk level
  • creation of an implementation plan with clearly defined priorities

Where the identified uses require it, our support extends to detailed impact assessments, high-risk-system analysis, more complex contractual arrangements, technical verification and other specific measures.

The goal is to establish a proportionate and enforceable system that enables the organisation to use artificial intelligence with clear rules, risk management and documented responsibilities.

Practical answers

Frequently asked questions

Are employees allowed to use publicly available generative AI tools?

Use should be governed according to the type of task, the data submitted and the terms and settings of the particular tool. Approved tools, clear rules and review of outputs support safer use for appropriate tasks.

Is every AI system high risk?

Classification depends on the purpose and context of use, the people affected and the organisation's role. Many tools are lower risk, while systems connected with significant decisions about people or specifically regulated areas require a more detailed assessment.

Is it enough to comply with the GDPR?

Data-protection law and the AI Act are related but distinct legal frameworks. Employment law, consumer protection, equal-treatment rules, intellectual property law, sector-specific regulation and contractual obligations may also apply.

Who is responsible when we procure an AI system from an external supplier?

The supplier and the organisation have obligations arising from their actual roles. The supplier is responsible for its solution and contractual obligations, and the organisation is responsible for the choice of purpose, method of use, data, users and inclusion of the system in its own process.

Must all content created with the help of artificial intelligence be labelled?

Labelling duties depend on the type of system and content, the method of publication and the role of the person producing or publishing it. Specific rules apply, among other things, to deepfakes, certain synthetic content and direct interaction with an artificial intelligence system.

What is a reasonable first step for the organisation?

The first step is to review key systems, licences and vendors and map actual usage patterns. Such an overview shows where the risks are greatest and which measures should be implemented first.

Author and sources

Professional and legal review

Author
Joint Law Office of Petar Petrinić and Vojko Braut
Last reviewed

Official sources and links

A specific matter

The legal approach should serve the actual objective.

A decision with legal, tax or financial consequences requires an analysis of the specific circumstances.

Contact us