Serbia sits at a crossroads of two AI-governance orbits. The profile is a jurisdiction harmonizing toward the European framework while keeping a foot in the China-led one, with its own binding AI rules one drafting cycle away.
The shape is a European-facing jurisdiction whose AI-specific weight is still soft. Two AI strategies and a set of ethics guidelines sit in the soft tier, a binding AI law is drafting, and the binding tier is general law an AI dispute would meet. The distinctive material is in the regional band, where Serbia holds commitments in both the European and the China-led systems.
Serbia's data-protection statute, closely modelled on the European regulation and supervised by the Commissioner for Information of Public Importance and Personal Data Protection. Article 38 carries the safeguard against solely automated individual decisions, including profiling, that produce legal or similarly significant effects. The statute most likely to govern an AI or data harm, and the closest thing to an AI-relevant operator duty in force.
Source: Ministry of Public Administration; the CommissionerThe cybersecurity and critical-information-infrastructure framework. Technology-neutral, with no AI-specific provision.
Source: national legal information systemThe copyright statute. The author is the natural person who created the work. The limitations are a closed statutory catalogue in Articles 41 to 57, with no open fair-use clause. There is no computer-generated-works provision and no text-and-data-mining exception, and the European mining exception has not been transposed.
Source: WIPO LexThe patent statute. The inventor is a natural person, who holds the moral right to be named, so an artificial intelligence cannot be designated inventor. No Serbian filing naming an AI as inventor is known. Neither the copyright nor the patent law addresses artificial intelligence.
Source: WIPO LexSerbia's first national AI strategy, an early mover in south-east Europe, setting goals for the economy, public services and skills. Policy that tasks state bodies and creates no operator duties.
Source: government AI portalThe successor strategy. Its first pillar is the creation and harmonization of the institutional and legal framework, which is where it announces the move toward a binding AI law and an AI council, alongside skills, infrastructure and a national AI platform. Still policy, but the policy that sets the binding law in motion.
Source: government AI portal; the legal information systemPrinciples and a developer and user self-assessment questionnaire, built explicitly on the UNESCO 2021 recommendation. A voluntary framework, not an operator duty.
Source: government releaseThe dedicated AI law the 2025 strategy contemplates, modelled on the European Union act with risk tiers, an AI agency, a register of high-risk systems, and human-oversight and transparency duties. It would be Serbia's first binding AI framework, but at the cut-off it is a working-group draft, not a tabled bill, so it binds nothing yet.
Source: state news agency; ministryConfirmed founding member; signed in Shanghai on 16 Jul 2026; no named Serbian signatory identified. Official source: Serbian state news agency; the government conclusion establishing the basis to conclude the agreement.
Signatory; the Paris statement on inclusive and sustainable artificial intelligence, 11 Feb 2025. Official source: Elysee official statement and signatory list.
Party to Convention 108; signed the modernizing protocol 22 Nov 2019 and ratified it 26 May 2020. Official source: Council of Europe treaty office charts.
Adopted 2021, as a UNESCO member; participant in the responsible-AI global-index pilot; a completed readiness assessment was not separately confirmed. Official source: unesco.org.
Adopted by consensus 22 Sep 2024; applies to Serbia as a UN member. Official source: A/RES/79/1 annex, un.org.
Adopted by consensus in 2024; Serbia bound as a UN member; no co-sponsorship asserted. Official source: UN records.
Axes: specificity (x, 0-100) is how squarely the instrument is written for AI; force (y, 0-100) is how hard it binds. Placements are editorial judgments for the comparison plot; the tier column is the authoritative classification. The pattern is a European-facing country whose binding tier is general law, whose AI-specific texts are soft strategies and guidelines, and whose binding AI law is drafting.
Tap a marker
The binding and prescriptive corner is the crowded one: the CAC-led measures put force and detail together, service by service. The sector guidance sits just left of the binding line, nonbinding in form but treated as obligatory. Dashed markers are drafts; the National AI Law would consolidate the whole stack into one statute.
No adjudicated court case where artificial intelligence is materially at issue was found in Serbia. The load-bearing Serbian story is not litigation at all: a biometric mass-surveillance project in Belgrade was checked by the data-protection regulator and by parliament rather than by a court. Two matters are recorded below, neither an adjudicated court case, and per the fabrication screen no case or decision number is invented.
No AI-generated evidence or hallucinated-citation court matter was found, and no adjudicated election-deepfake case surfaced.
Serbia holds the human line in statute while harmonizing toward Europe: authorship and inventorship stay with natural persons and the copyright limitations are closed with no mining lane, but a binding AI law is drafting and the European training exception is a pending accession obligation.
The AI-IP Index reads a country on two questions that usually get folded together. Accommodation asks how far the law will go to protect intellectual property that a machine helped produce. Institution asks how much administrative machinery sits behind that law: its guidance, its international submissions, its disclosure duties.
A country can be generous on paper and have built almost nothing, or cautious and highly organised, so the two are scored apart and reported as a pair. Each rests on three questions, scored 0, 0.5 or 1.
How far the law will protect intellectual property that a machine helped make.
How much administrative machinery sits behind that law.
The scale runs the same way on both axes: 0 is the open or developed end, 1 is the restrictive or absent one, and 0.5 sits between for anything conditional or untested. Read as a pair, the two scores show whether AI-assisted work can be protected here, and whether the office has said so in writing.
Within each axis the three questions carry equal weight. That is a deliberate choice, not an oversight. An AI developer might reasonably value freedom to train above patent inventorship, but weighting is where indices lose their credibility, so the score stays a flat mean and the choice is stated in the open. Each cell also cites a statute section, a case or an office page, so any single score can be challenged without disputing the rest.
Two positions are worth naming. A country can be open on the law but thin on machinery, an open-but-undeveloped stance that bets on ambiguity. Or it can be restrictive on rights yet run an active office, a restrictive-but-developed stance that reflects a settled policy choice rather than a gap. The pair of scores tells those two apart where a single ranking would blur them.
A rubric is only as good as the results it produces on cases where the answer is already known. These three jurisdictions sit outside this series and are scored with the same six questions, as a check. Their law is the best documented anywhere, so if the scale puts them where the law actually sits, the scale is doing its job. They are reference points, not editions.
Firm judicial settlement at both poles and the weakest statutory position on training. The courts have closed the door on AI inventors and AI authors, while everything on training rides on unresolved fair-use litigation. There is no per se duty to declare AI use in a filing, only a candour duty that bites where the use is material.
Thaler v. Vidal, 43 F.4th 1207 (Fed. Cir. 2022); Thaler v. Perlmutter (D.C. Cir. 2025), cert. denied 2 Mar 2026; Bartz v. Anthropic (N.D. Cal. 2025); USPTO revised inventorship guidance, 90 Fed. Reg. 54636 (28 Nov 2025); 89 Fed. Reg. 58128 (17 Jul 2024); 89 Fed. Reg. 25609 (11 Apr 2024).
The most permissive statutory position on training and the strongest transparency duty in force, sitting over an authorship question no court has answered. Read the label carefully: training and transparency run through EU law, but patents run through the EPO under the European Patent Convention, which is not an EU institution and covers 39 states.
Directive (EU) 2019/790, arts. 3 and 4; Regulation (EU) 2024/1689, art. 53(1)(c) and (d); EPO J 8/20 (2021); EPO Guidelines G-II 3.3.1 (2026 edition); Infopaq C-5/08; Painer C-145/10.
Liberal on patents since the Supreme Court abandoned the Aerotel test in February 2026, conservative on copyright, and currently thin on AI-specific machinery after the dedicated AI examination guidance was withdrawn. Section 9(3) nominally protects a work with no human author for 50 years, the widest AI-output right on paper, but no court has ever applied it to generative AI.
CDPA 1988 ss. 9(3), 12(7), 29A, 178; Thaler v Comptroller-General [2023] UKSC 49; Comptroller-General v Emotional Perception AI [2026] UKSC 3; UKIPO practice notice, 14 Jul 2026; Data (Use and Access) Act 2025 ss. 135 to 137.
The check earned its keep twice. The untested rule held: section 9(3) of the UK Copyright Act reads like the widest AI-output right anywhere, yet because no court has applied it to generative AI it scores as untested rather than open, which is the correct answer and the one a headline reading would miss. The check also exposed a limit worth stating. The Institution axis measures AI-specific machinery, not general office capacity, so a long-established office can score poorly when it has withdrawn its AI guidance and imposes no disclosure duty. Read that axis as what an office has built for AI, nothing wider.
Each row below carries the test we applied and the finding behind the score, with a source. The rationale, not the number, is the point.
Scores verified 21 July 2026, against AIP Index codebook v1.0. A score is only true as of its date.
What we look forA granted patent or a clearly workable examination route, not merely a silent statute.
The findingThe patent law confines the inventor to a natural person, who holds the moral right to be named, so an AI-assisted invention with a human inventor is open in principle while the machine cannot be named. No AI-specific examination practice or guidance exists, and no Serbian filing naming an artificial intelligence as inventor is known, so the point is untested.
What we look forProtection applied where human choices shape the work, and refusal of purely machine output.
The findingThe copyright law defines the author as the natural person who created the work, so a human who directs an AI tool and contributes authorship can hold copyright, while purely AI-generated output has no qualifying author. There is no computer-generated-works provision, and no registration practice or ruling tests the point, so it is untested.
What we look forA statutory or judicial mining lane. Silence scores against the miner, since the reserved-rights default governs.
The findingThere is no training or text-and-data-mining exception. The copyright limitations are a closed statutory catalogue in Articles 41 to 57, with no open fair-use clause and no mining carve-out, and the European mining exception has not been transposed. With copyright silent, the reserved-rights default governs the use of works for training. This is the question most likely to move on European-accession harmonization.
What we look forA traceable, substantive submission on the record, not bare membership.
The findingSerbia is a WIPO member, but the WIPO Conversation submissions record shows no traceable submission from Serbia or its Intellectual Property Office, and no substantive session participation was found. Membership without a submission earns the middle.
What we look forA standalone AI examination text, not AI handled quietly under general practice.
The findingNo dedicated guidance from the Intellectual Property Office on examining AI-related filings was found; its published guidance is the ordinary filing and examination rules. A reasonable-search negative.
What we look forA mandatory declaration inside the filing, not a proposal or an informal request.
The findingNo filing requires declaring AI use, and no in-force instrument imposes a labeling or transparency duty on AI-generated content in the intellectual-property field. The forthcoming AI law would add transparency duties, but it is not in force.
Method. Six questions, three per axis, scored 0, 0.5 or 1 against AIP Index codebook v1.0. The three questions in each axis are weighted equally by choice, and the two axes are reported as a pair, never blended into one number. Every score cites a statute, case or office page, carries a verified date, and records its direction of travel apart from the level. Positions are editorial judgements read from primary law and office practice, not official scores. WIPO's public catalogue of IP-office AI initiatives does not score jurisdictions on this basis, so the readings here come straight from the source law. Not legal advice.
Serbia sits at a crossroads of two AI-governance orbits. It is a European Union candidate and a Council of Europe member with a data-protection law modelled on the European regulation, and it ratified the modernized Council of Europe data-protection convention early. It signed the Paris summit statement on artificial intelligence. Yet it has not signed the Council of Europe treaty on artificial intelligence, and it is a founding member of the China-led World AI Cooperation Organization. On the domestic side its AI-specific layer is entirely soft: two national AI strategies and a set of ethics guidelines, none of which binds an operator. A binding AI law, modelled on the European Union act, is in active drafting but has not reached parliament. What binds today is general, technology-neutral law: the data-protection statute with its automated-decision safeguard, the information-security law, and the copyright and patent statutes, which confine authorship and inventorship to natural persons. The profile is a jurisdiction harmonizing toward the European framework while keeping a foot in the China-led one, with its own binding AI rules one drafting cycle away.
The site does three things: it maps every instrument that governs AI in Serbia, 14 of them, ordered by how hard each one binds; it reads the same instruments a second time by how squarely each is written for AI; and it records the matters where AI meets the law, with what was searched and found empty stated as plainly as what was found. Every claim traces to a primary source, and absences are recorded rather than papered over.
A membership claim enters this table only from an official list: a declaration annex, a treaty signature table, an organization's own record or an official government statement. Serbia's distinctive feature is that it holds commitments in both the European and the China-led AI orbits; the WAICO entry carries a caveat set out below.
Know of a ruling or proceeding in Serbia where AI is central? Send a source link; it will be reviewed before publishing.
Submit a case