AI for businesses in Slovenia and the EU
What the EU AI Act means for a normal company, a 10-step checklist for adopting AI safely, and a free AI usage policy you can generate and download in a minute.
Main obligations
The EU AI Act sorts AI by risk. For most companies that use general AI tools (ChatGPT, Copilot, Gemini) these are the rules that matter:
Customers must know when they are interacting with AI — e.g. a chatbot (from 2 August 2026).
Deepfakes (AI images, video, audio of real people or events) must be labelled. AI text published to inform the public on matters of public interest must be labelled unless a person has reviewed it editorially. In Slovenian media, the Media Act requires labelling of all AI content.
Staff who use AI must have sufficient AI knowledge (since 2 February 2025). The law does not literally demand a written policy — but a short policy plus training is the simplest proof.
Don’t put personal data into AI tools without a legal basis and a data processing agreement with the provider (GDPR and ZVOP-2).
What we recommend
- Prepare a short AI policy for employees — use the generator below.
- Appoint a person responsible for AI in the company.
- Before use, check each provider: data processing agreement, no training on your data, EU hosting where possible.
For companies that introduce AI in a structured way, these rules are not an obstacle — they are a chance for clear rules and higher quality of work.
Slovenian law on AI
In force since 21 November 2025. The national law that makes the AI Act enforceable in Slovenia: it names the authorities, procedures and fines.
The Agency for Communication Networks and Services is the single point of contact, a market surveillance authority and runs AI regulatory sandboxes (the first by 2 August 2026) — also the entry point for SMEs.
Market surveillance: Information Commissioner, Bank of Slovenia, Insurance Supervision Agency, Market Inspectorate and AKOS. Notifying authorities: the ministries for the economy, infrastructure, health and digital transformation, and the medicines agency (JAZMP).
A new advisory body on the ethical use of AI.
High-risk AI systems used in the public sector are recorded and published.
Up to €35 million or 7% of worldwide annual turnover for the most serious breaches.
In force since 27 September 2025. Media content made fully or partly with generative AI must be clearly recognisable, separated from other content and labelled at its beginning and end; publishers must explain how they use AI.
Personal data processed with AI remains under GDPR and the Slovenian Personal Data Protection Act, supervised by the Information Commissioner.
EU AI Act — what applies when
The AI Act enters into force.
Banned AI practices apply, and companies must ensure AI literacy of staff who use AI.
Rules for general-purpose AI models (e.g. the models behind ChatGPT, Claude, Gemini) and penalties apply.
Transparency duties apply: tell people when they interact with AI and label deepfakes.
Obligations for stand-alone high-risk AI (e.g. hiring, credit, education) — postponed by the 2026 Digital Omnibus.
High-risk AI inside regulated products (machinery, medical devices …).
Four risk levels
Social scoring, manipulation exploiting vulnerabilities, untargeted scraping of faces, emotion recognition at work or school.
AI used for hiring and HR decisions, credit scoring, education and exams, critical infrastructure, access to essential services.
Chatbots must say they are AI; deepfakes and AI-generated content must be labelled.
Most everyday uses: writing help, translation, spam filters, coding assistants.
What this means for a typical company
- Train staff who use AI (AI literacy) — this already applies.
- Don’t let AI make decisions about people (hiring, promotions, credit) without human review and proper compliance.
- Tell customers when they chat with AI; label AI images or voices of real people.
- GDPR still applies: personal data in AI tools needs a legal basis and a data processing agreement.
- Fines for banned practices reach €35 million or 7% of global turnover.
10-step checklist for adopting AI
Your progress is saved in this browser only.
Free AI usage policy — generator
Fill in three fields and download a one-page policy for your team.
This template is a starting point, not legal advice. Adapt it to your company and have it reviewed if needed.
# Artificial intelligence usage policy — [COMPANY] Effective: 25/09/2026 · Person responsible for AI: [CONTACT] ## 1. Purpose We use AI tools to work faster and better while protecting client data, trade secrets and trust. This policy applies to all employees and contractors. ## 2. Approved tools Only these tools may be used for work, with company accounts: - ChatGPT (Business / Enterprise) - Microsoft 365 Copilot New tools must be approved by [CONTACT] before first use. ## 3. Data — what we NEVER enter - personal data of clients, employees or partners (names, ID numbers, addresses, health data …), - confidential client information and trade secrets, - passwords, API keys and other credentials, - non-public financial data and contracts, except in tools explicitly approved by [CONTACT]. Allowed: public information, anonymised content, your own drafts without sensitive data. ## 4. Humans stay accountable - A person reviews every AI output before use — especially facts, numbers, sources and legal statements. - AI does not make decisions about people (hiring, evaluation, credit) without a human. - The employee who delivers the work is responsible for it. ## 5. Transparency - We tell customers when they are interacting with AI (e.g. a chatbot). - AI-generated images, video or voice showing real people or events are labelled. ## 6. Training Everyone using AI at work completes basic AI training (AI literacy under the EU AI Act) and refreshes it yearly. ## 7. Incidents If you enter sensitive data by mistake or notice a wrong or harmful output, report it immediately to: [CONTACT]. ## 8. Review This policy is reviewed every 6 months or when a new tool is introduced.
Official sources
- European Commission — AI Act
- EUR-Lex — Regulation (EU) 2024/1689
- Informacijski pooblaščenec RS — umetna inteligenca
- AKOS — Agencija za komunikacijska omrežja in storitve
- Uradni list — Zakon o medijih (ZMed-1)
General information, not legal advice. Last reviewed September 2026.