Skip to content

Artificial Intelligence and Criminal Liability under Serbian Law: Who is responsible when an AI system causes legally relevant harm?

When an artificial intelligence system generates a fraudulent message, approves a dangerous transaction, or controls a device that causes injury, the immediate question is usually: who should be held responsible – the developer, the manufacturer, the user, the operator, or the system itself?

Under Serbian law, the starting point is more straightforward than it may first appear. An AI system cannot be the perpetrator of a criminal offence. It has neither legal personality nor the capacity for criminal responsibility required by the Serbian Criminal Code. The analysis must therefore focus not on the supposed “will of the algorithm”, but on the conduct and omissions of the people and organisations that develop, deploy, control or use the system.

This does not mean that every harmful AI output amounts to a criminal offence. Criminal liability in Serbia arises only where the elements of a specific offence, unlawfulness, the culpability of an identifiable offender and the necessary connection between the offender’s conduct and the prohibited result have all been established. That sequence matters. It prevents technological complexity from becoming a shortcut to strict or collective criminal liability.

 

The first question is not “Who is guilty?” but “What is the offence?”

The Serbian Criminal Code begins with the principle of legality: no one may be punished for conduct that was not defined by law as a criminal offence before it was committed. It also provides that a punishment or warning measure may be imposed only on an offender who is culpable. Under Article 14, a criminal offence is an act prescribed by law as a criminal offence, which is unlawful and culpable.

The fact that an AI system produced an inaccurate, discriminatory or dangerous output is therefore not sufficient in itself. The first step is to identify whether the relevant conduct satisfies the statutory elements of a particular criminal offence. Only then is it possible to ask who acted, who was legally required to intervene and what form of culpability accompanied that conduct.

The concepts of actus reus and mens rea may be useful in comparative discussion, but an analysis under Serbian law should remain anchored in the categories used by the Criminal Code: an act or omission, unlawfulness, mental capacity, intent and – only where the statute expressly provides for it – negligence. From this perspective, an AI system is a tool, a product or a source of risk, not a bearer of criminal culpability.

How can liability be attributed to a human actor?

Intentional use of an AI system

The clearest cases are those in which a person deliberately uses AI as an instrument for committing an offence. Suppose someone generates a convincing false message or clones a director’s voice in order to deceive an employee and obtain an unlawful financial benefit. The AI system does not become the perpetrator. Liability attaches to the person who designed and carried out the deception, provided that the elements of fraud under Article 208 of the Criminal Code are met. If the conduct involves manipulating data in order to influence the result of electronic data processing, the offence of computer fraud under Article 301 may also be relevant.

The same logic applies to the unauthorised use of a person’s image, voice or personal data. Depending on the precise conduct and its consequences, Articles 144-146 – unauthorised photography, unauthorised publication or display of another person’s recording, and unauthorised collection of personal data – may come into play. A deepfake is not automatically a criminal offence, however. Every element of the relevant statutory offence must still be proved.

Negligence is not a general formula for every AI-related risk

Where the harmful result was not intended, attention often turns to foreseeability. Article 26 of the Criminal Code distinguishes between conscious negligence – where the offender was aware that the conduct could constitute an offence but carelessly assumed that the result would not occur or could be prevented – and unconscious negligence, where the offender was unaware of that possibility although, in the circumstances and given the offender’s personal characteristics, they were required and able to recognise it.

This rule is important for high-risk uses of AI, but it has a clear limit. Under Article 22(2), negligence is a basis of criminal culpability only where the law expressly provides for the negligent form of the particular offence. Neither the degree of a system’s autonomy nor the seriousness of the resulting harm can replace that statutory requirement.

In practice, the relevant questions will include what the responsible person knew about the system’s limitations, what risk signals were available, whether testing had been conducted, whether the provider had issued warnings and whether human intervention could reasonably have been expected. Foreseeability is not an independent criminal offence. It is part of the assessment of negligence where negligent commission is punishable by law.

Liability for failure to supervise

Article 15 of the Criminal Code recognises that a criminal offence may be committed by omission. This is particularly important in the AI context: an operator fails to respond to a warning, a manager fails to provide mandatory human oversight, or a professional does not stop a system despite having a duty to do so.

It is not enough to say that a person “could have prevented” the result. A specific duty to act must be identified. That duty may arise from legislation, secondary rules, professional standards, a contract, an assumed function or the person’s prior creation of a risk. It must also be shown that the omission satisfied the elements of the relevant offence. The more clearly roles and responsibilities are documented throughout the AI system’s life cycle, the easier it becomes to determine who had the legal and practical duty to intervene.

Developers and manufacturers are not liable merely because they created the system

A professional role does not by itself establish criminal responsibility. To hold a developer, manufacturer or systems integrator criminally liable, the prosecution would have to prove a specific act or omission, a relevant duty, a causal contribution and the required form of culpability in relation to a particular offence.

Liability may become relevant where, for example, a known critical defect was deliberately concealed, safeguards were intentionally removed, or a system was deployed despite a clear and foreseeable risk in a field where negligent conduct is punishable. Conversely, an outcome that could not reasonably have been predicted, detected or prevented must not be transformed retrospectively into criminal culpability merely because the consequences were serious.

Corporate criminal liability: why organisational choices matter

AI systems are frequently developed and used within companies, which makes Serbia’s Law on the Liability of Legal Entities for Criminal Offences particularly important. Under Article 6, a legal entity is liable for an offence committed within its activities or authority by a responsible person acting with the intention of obtaining a benefit for the legal entity. Liability may also arise where the absence of supervision or control by a responsible person enabled an individual under that person’s supervision to commit an offence for the benefit of the legal entity.

This model can apply directly to organisational risks associated with AI. A decision to disregard safety warnings in order to launch a product sooner, remove human review to reduce costs, or continue using a system after serious incidents may be legally relevant. Even here, liability is not automatic: Article 7 provides that the liability of the legal entity is founded on the culpability of the responsible person.

The following will therefore be important when responsibility is assessed:

  1. clearly assigned roles and authority for approving and supervising the system;
  2. risk assessments before deployment and after significant changes to the model;
  3. technical records of model versions, inputs, outputs and human interventions;
  4. procedures for reporting, investigating and remedying incidents;
  5. staff training and a genuine – rather than merely formal – ability to stop the system.

These measures do not provide absolute immunity from criminal liability. They are evidence of who managed the risk, which dangers were known and whether the system of oversight operated in practice.

Does Serbia already have a dedicated AI statute?

According to publicly available official sources, as of July 2026 Serbia has not yet enacted a comprehensive statute governing the development and use of AI systems. A working group charged with drafting such legislation was established in 2024, but an announced future text cannot serve as a basis for criminal liability unless and until it is enacted and enters into force.

The current national framework includes the Strategy for the Development of Artificial Intelligence in the Republic of Serbia for 2025-2030 and the 2023 Ethical Guidelines for the Development, Application and Use of Reliable and Responsible Artificial Intelligence. The Guidelines expressly state that they are non-binding. These instruments are important for risk governance and the development of good practice, but they do not themselves define criminal offences or prescribe criminal penalties.

Until dedicated legislation is adopted, the existing horizontal and sector-specific framework continues to apply. This includes the Criminal Code, the Law on the Liability of Legal Entities for Criminal Offences and legislation governing personal data protection, non-discrimination, consumer protection, product safety and information security. A breach of those rules may help establish unlawfulness or the applicable standard of care, but a regulatory violation does not automatically become a criminal offence.

Where does the EU AI Act fit into this picture?

Regulation (EU) 2024/1689 – the EU AI Act – entered into force on 1 August 2024 and applies in stages. It is not Serbian domestic law and does not confer criminal legal personality on an AI system. Its approach is regulatory: it allocates obligations among providers, deployers, importers and other actors, particularly in relation to high-risk systems.

The AI Act may nevertheless be practically important for businesses established in Serbia where they place AI systems on the EU market or where the output produced by their systems is used in the European Union. It is also an important reference point for the future alignment of Serbian law. Its requirements concerning documentation, risk management and human oversight may be relevant when establishing facts and standards of conduct. They cannot, however, displace the Serbian principle of legality or the requirement to prove a particular offence and the culpability of a particular offender.

Three practical scenarios

a) A cloned executive voice and a fraudulent payment

An employee uses an AI tool to clone the chief executive’s voice and instructs the accounting department to transfer money to an account controlled by the employee. The central issues are not the „autonomy“ of the tool, but the user’s intent, the deception and the financial consequence. Depending on the method used, the conduct may amount to fraud or computer fraud. AI is the instrument of the offence.

b) An algorithmic decision that discriminates

A company uses a recruitment model that systematically places members of a particular group at a disadvantage. Such conduct may trigger rules on non-discrimination, employment and personal data protection. Criminal liability does not follow from the discriminatory output alone. The elements of a specific offence and the relevant form of culpability must be established. This example shows why criminal, civil, administrative and misdemeanour liability should not be conflated.

c) A safety warning is disabled

A responsible person knows that an AI system controlling a technical process produces unreliable warnings but allows its operation to continue without the required human oversight. If injury or danger results, the legal assessment will depend on the relevant statutory offence, the existence of a duty to stop the system, causation and the required intent or negligence. If deficient supervision enabled an offence to be committed for the benefit of a legal entity, the conditions under Article 6 of the Law on the Liability of Legal Entities may also need to be examined.

A practical test: six questions to ask before concluding that criminal liability exists

  1. Which specific criminal offence may have been committed? Neither “AI-related harm” nor “algorithmic error” is an offence in its own right.
  2. Who engaged in the legally relevant conduct? Developers, providers, integrators, operators, deployers, end users and responsible persons within an organisation must be distinguished.
  3. Who had a legal duty to act? In omission cases, the source and content of the particular duty must be identified.
  4. What form of culpability does the law require? Negligence is sufficient only where the negligent form of that offence is expressly punishable.
  5. Is there a causal connection? A model error must be distinguished from poor-quality data, faulty integration, a human decision or a later failure of supervision.
  6. Are the conditions for corporate criminal liability satisfied? The benefit to the legal entity, the role of the responsible person and any absence of supervision or control must be examined.

Is “electronic personhood” the answer?

The possibility of granting a highly autonomous system a form of “electronic personhood” has appeared in European debates on robotics. Such a status neither exists nor is necessary under Serbian criminal law. An AI system cannot understand the prohibition, form criminal intent, or experience punishment. Formally treating it as an offender could instead weaken the responsibility of the people and companies that determine its purpose, data, safeguards and deployment.

A more useful direction for legislative reform is to define roles and duties throughout the AI system’s life cycle: documentation and traceability, risk assessment, human oversight, incident reporting and the power to intervene. Such rules can clarify the applicable standard of care and make proof easier. They should not create an indeterminate concept of “guilt for the algorithm”, which would be incompatible with the principles of legality and personal culpability.

Conclusion

The principal challenge that AI presents to Serbian criminal law is not the absence of possible responsible actors. It is the difficulty of reliably identifying conduct, duty, culpability and causation within a complex technical and organisational system. In other words, the central problems concern traceability, allocation of responsibility and evidence.

The existing legal framework already allows the deliberate misuse of AI to be treated as the use of an instrument for committing an offence. In cases expressly provided for by law, it also allows negligent conduct or an omission to be examined and, subject to specific conditions, the liability of a legal entity to be established. Future AI legislation could make that framework more predictable by defining the duties of the relevant actors and the standards of effective oversight.

Put simply, an AI system does not enter the dock. A natural person or a legal entity may do so – but only where every statutory condition for that defendant’s criminal liability has been proved.

 

Tagged as
Law and Governance South East Europe Konrad Adenaurer Stiftung - Rule of Law - South East Europe © 2026 Law and Governance South East Europe
All rights reserved.