What the AI Act actually is
The EU AI Act (Regulation (EU) 2024/1689) is the first broad law regulating artificial intelligence anywhere. It entered into force on 1 August 2024 and applies directly in every member state, including Slovenia and Croatia, so there is no separate local law you need to wait for. National laws only add the enforcement plumbing on top.
It does not regulate AI by technology. It regulates AI by risk: what the system is used for, and who it can affect.
The four risk tiers, in plain terms
The Act sorts every AI use into one of four tiers.
- Unacceptable risk (banned). Practices like social scoring by authorities, manipulative systems that exploit vulnerable people, and most real-time biometric surveillance in public. These have been prohibited since 2 February 2025.
- High risk. AI used in hiring, worker management, credit scoring, essential services, medical devices, critical infrastructure and similar. Allowed, but with strict duties before and after it goes live.
- Limited risk. Chatbots, voice agents and generative content aimed at people. The core duty here is transparency.
- Minimal risk. Everything else, from spam filters to internal productivity tools. No mandatory obligations beyond basic AI literacy in your team.
The key insight for a normal company: your risk tier depends on the use case, not the tool. The same language model can be minimal risk in a support chatbot and high risk in a CV-screening system.
Where a typical SI or HR company lands
Most businesses deploying AI today are running customer-service voice agents, website chatbots, or an internal assistant that answers from company documents (RAG). In almost all of these cases you are in limited or minimal risk.
That is good news. It means you are not facing conformity assessments or registration. But limited risk is not zero duty. If your AI speaks to customers or generates content, the transparency rules apply to you.
You cross into high risk only if the AI makes or materially supports decisions about people in sensitive areas: who gets hired, who gets a loan, who gets access to an essential service. If that is your use case, treat it as a compliance project from day one and involve qualified counsel.
The transparency duties that hit most companies
From 2 August 2026, Article 50 sets out disclosure duties that apply to ordinary business AI:
- Tell people they are talking to AI. If a chatbot or voice agent interacts with a person, that person must know it is a machine, unless it is obvious.
- Label AI-generated content. Synthetic audio, image, video and text produced by your systems should be detectable as artificially generated.
- Flag deepfakes and generated text published to inform the public, with narrow exceptions for art, satire and editorial review.
For a call center or a website assistant, this is straightforward. A short spoken or written line at the start of the interaction usually covers it. The point is to do it deliberately, not to bury it.
The dates that matter
The Act arrives in stages. These are the verified milestones:
- 2 February 2025: bans on unacceptable-risk AI and the AI-literacy duty took effect.
- 2 August 2025: rules for general-purpose AI models, governance and penalties began to apply.
- 2 August 2026: most remaining duties, including high-risk obligations under Annex III and the Article 50 transparency rules, start to apply.
- 2 August 2027: high-risk AI built into regulated products (Annex I) and older general-purpose models must be fully compliant.
For most businesses, 2 August 2026 is the date to plan around.
What non-compliance costs
Penalties scale with the breach:
- Up to 35 million EUR or 7% of global annual turnover for using banned practices.
- Up to 15 million EUR or 3% for breaching high-risk, general-purpose or transparency obligations.
- Up to 7.5 million EUR or 1% for giving regulators incorrect or misleading information.
The higher of the fixed sum or the percentage applies.
Who enforces it in Slovenia and Croatia
Slovenia adopted its implementation act (ZIUDHPUI), in force since 21 November 2025. AKOS is the single point of contact and keeps the register of high-risk systems. Market surveillance is shared across the Information Commissioner, the Bank of Slovenia, the Insurance Supervision Agency, the Market Inspectorate and AKOS.
Croatia is still finalizing its setup. A working group under the Ministry of Justice, Administration and Digital Transformation, with AZOP among others, is preparing the implementing law and naming the supervisory bodies. As of mid-2026 the single point of contact was not yet formally designated, so confirm the current status before relying on a specific authority.
How to deploy AI responsibly under the Act
You do not need a legal department to get the fundamentals right. Build with these in place:
- Transparency by design. Disclose the AI up front in every customer-facing agent.
- Human in the loop. Keep a person able to review, override and escalate, especially for anything sensitive.
- Grounding and citations. Answer from your own data with sources, so responses can be checked and hallucination risk drops.
- Audit logs. Record what the system did and why, which the high-risk regime expects and every serious buyer wants.
- Role-based access and EU data residency. Limit who can see what, and keep processing in the EU. This is where the AI Act meets GDPR. We cover that in detail in our guide on GDPR-compliant AI in the EU.
How Vandri builds with this in mind
We do not sell an "AI Act certified" badge, because no such thing exists for most business systems. What we do is build so your compliance is easier to demonstrate.
Our platform, vCore, ships with EU data residency and EU processing, grounding with citations to reduce hallucination, audit logging, role-based access, human-in-the-loop controls and clear AI disclosure built into voice and chat agents. We follow GDPR and ISO 27001 principles across every system. When your legal or security team asks how a deployment maps to the Act, you get straight answers, not a sticker. See how this is built into our platform.
Talk it through
If you are planning an AI project and are not sure which risk tier it lands in, tell us the use case. We will give you an honest read on where it sits under the Act and what safeguards it needs. Book a call or explore our solutions.
This article is general orientation, not legal advice. For a specific project, confirm the classification and obligations with qualified legal counsel or your data protection officer.