AI for business

AI for businesses in Slovenia and the EU

What the EU AI Act means for a normal company, a 10-step checklist for adopting AI safely, and a free AI usage policy you can generate and download in a minute.

Main obligations

The EU AI Act sorts AI by risk. For most companies that use general AI tools (ChatGPT, Copilot, Gemini) these are the rules that matter:

Transparency

Customers must know when they are interacting with AI — e.g. a chatbot (from 2 August 2026).

Labelling content

Deepfakes (AI images, video, audio of real people or events) must be labelled. AI text published to inform the public on matters of public interest must be labelled unless a person has reviewed it editorially. In Slovenian media, the Media Act requires labelling of all AI content.

AI literacy

Staff who use AI must have sufficient AI knowledge (since 2 February 2025). The law does not literally demand a written policy — but a short policy plus training is the simplest proof.

Data protection

Don’t put personal data into AI tools without a legal basis and a data processing agreement with the provider (GDPR and ZVOP-2).

What we recommend

  • Prepare a short AI policy for employees — use the generator below.
  • Appoint a person responsible for AI in the company.
  • Before use, check each provider: data processing agreement, no training on your data, EU hosting where possible.

For companies that introduce AI in a structured way, these rules are not an obstacle — they are a chance for clear rules and higher quality of work.

Slovenian law on AI

ZIUDHPUI — AI Act implementation act

In force since 21 November 2025. The national law that makes the AI Act enforceable in Slovenia: it names the authorities, procedures and fines.

AKOS — the central AI authority

The Agency for Communication Networks and Services is the single point of contact, a market surveillance authority and runs AI regulatory sandboxes (the first by 2 August 2026) — also the entry point for SMEs.

Who supervises

Market surveillance: Information Commissioner, Bank of Slovenia, Insurance Supervision Agency, Market Inspectorate and AKOS. Notifying authorities: the ministries for the economy, infrastructure, health and digital transformation, and the medicines agency (JAZMP).

National Council for AI Ethics

A new advisory body on the ethical use of AI.

Public sector register

High-risk AI systems used in the public sector are recorded and published.

Fines

Up to €35 million or 7% of worldwide annual turnover for the most serious breaches.

Media Act (ZMed-1)

In force since 27 September 2025. Media content made fully or partly with generative AI must be clearly recognisable, separated from other content and labelled at its beginning and end; publishers must explain how they use AI.

GDPR and ZVOP-2

Personal data processed with AI remains under GDPR and the Slovenian Personal Data Protection Act, supervised by the Information Commissioner.

EU AI Act — what applies when

  1. The AI Act enters into force.

  2. Banned AI practices apply, and companies must ensure AI literacy of staff who use AI.

  3. Rules for general-purpose AI models (e.g. the models behind ChatGPT, Claude, Gemini) and penalties apply.

  4. Transparency duties apply: tell people when they interact with AI and label deepfakes.

  5. Obligations for stand-alone high-risk AI (e.g. hiring, credit, education) — postponed by the 2026 Digital Omnibus.

  6. High-risk AI inside regulated products (machinery, medical devices …).

Four risk levels

Unacceptable — banned

Social scoring, manipulation exploiting vulnerabilities, untargeted scraping of faces, emotion recognition at work or school.

High risk — strict rules

AI used for hiring and HR decisions, credit scoring, education and exams, critical infrastructure, access to essential services.

Limited risk — transparency

Chatbots must say they are AI; deepfakes and AI-generated content must be labelled.

Minimal risk — no new duties

Most everyday uses: writing help, translation, spam filters, coding assistants.

What this means for a typical company

  • Train staff who use AI (AI literacy) — this already applies.
  • Don’t let AI make decisions about people (hiring, promotions, credit) without human review and proper compliance.
  • Tell customers when they chat with AI; label AI images or voices of real people.
  • GDPR still applies: personal data in AI tools needs a legal basis and a data processing agreement.
  • Fines for banned practices reach €35 million or 7% of global turnover.

10-step checklist for adopting AI

Your progress is saved in this browser only.

0 / 10

Free AI usage policy — generator

Fill in three fields and download a one-page policy for your team.

This template is a starting point, not legal advice. Adapt it to your company and have it reviewed if needed.

# Artificial intelligence usage policy — [COMPANY]

Effective: 25/09/2026 · Person responsible for AI: [CONTACT]

## 1. Purpose
We use AI tools to work faster and better while protecting client data, trade secrets and trust. This policy applies to all employees and contractors.

## 2. Approved tools
Only these tools may be used for work, with company accounts:
- ChatGPT (Business / Enterprise)
- Microsoft 365 Copilot
New tools must be approved by [CONTACT] before first use.

## 3. Data — what we NEVER enter
- personal data of clients, employees or partners (names, ID numbers, addresses, health data …),
- confidential client information and trade secrets,
- passwords, API keys and other credentials,
- non-public financial data and contracts, except in tools explicitly approved by [CONTACT].
Allowed: public information, anonymised content, your own drafts without sensitive data.

## 4. Humans stay accountable
- A person reviews every AI output before use — especially facts, numbers, sources and legal statements.
- AI does not make decisions about people (hiring, evaluation, credit) without a human.
- The employee who delivers the work is responsible for it.

## 5. Transparency
- We tell customers when they are interacting with AI (e.g. a chatbot).
- AI-generated images, video or voice showing real people or events are labelled.

## 6. Training
Everyone using AI at work completes basic AI training (AI literacy under the EU AI Act) and refreshes it yearly.

## 7. Incidents
If you enter sensitive data by mistake or notice a wrong or harmful output, report it immediately to: [CONTACT].

## 8. Review
This policy is reviewed every 6 months or when a new tool is introduced.
Which tools? See our picks →