Croatia Public Sector AI Use Outpaces Internal Rules
By Suad Seferi ·

Artificial intelligence is already being used across Croatia’s public sector, but internal rules have not kept pace with adoption. A new study by Croatian civil society organisation Gong found that 50 of 78 public institutions surveyed are using or testing AI systems. Of those, 26 said they have no specific internal rules governing how the technology should be used. The research, conducted between February and August 2026 through access-to-information requests, identified 55 different AI systems in use or testing across public administration, healthcare, justice, security, finance and communication with citizens. Among the most commonly used tools are Microsoft Copilot and ChatGPT, alongside more specialised systems such as ANON, which is used to anonymise court decisions. Croatian institutions are also using AI-related systems for medical diagnostics and surgery, biometric identification, document processing, cybersecurity and virtual assistants. The findings offer one of the clearest pictures yet of how quickly AI is entering public administration in Croatia, while also exposing substantial differences in how institutions govern its use. 26 institutions use AI without specific rules According to Gong, only nine institutions reported both using AI and having specific rules governing its use. Those include the Croatian Parliament, the Financial Agency FINA, the City of Zagreb, APIS IT, the Croatian Regulatory Authority for Network Industries, the Croatian Financial Services Supervisory Agency and the Croatian Institute of Public Health. Another 10 institutions said they were preparing dedicated rules while already using or testing AI. The larger concern is the group of 26 public bodies that reported using or testing AI without having specific internal rules in place. That group includes Croatia’s ministries responsible for the interior, economy, culture and media, and regional development and EU funds. It also includes 10 courts, the Agency for Electronic Media, three major cities including Split, Rijeka and Osijek, two counties and four clinical hospital centres. Some other institutions told researchers that AI is covered through existing policies, particularly information-security and cybersecurity procedures, rather than separate AI-specific rules. AI is already being used in sensitive areas The issue becomes more significant when looking at what some of the systems actually do. Gong identified AI-related technologies being used for biometric identification, healthcare and security, areas where automated systems can directly affect individuals and their rights. Croatia’s Ministry of the Interior, for example, reported using three systems connected to biometric identification and security: ABIS, NABIS and a facial-recognition system whose manufacturer was not disclosed. Gong said these applications may carry particular risks for human rights and fundamental freedoms. The research also found eight AI solutions being used in healthcare and medicine, while 15 were used for information and document processing. Another 31 systems were classified as tools used for specific professional tasks within public institutions. Not every institution is using AI The picture across Croatia is far from uniform. Twenty-six public authorities told Gong they do not currently use AI. Croatia’s central government was among them, alongside 10 ministries, the Constitutional Court, the State Attorney’s Office, the Office for the Suppression of Corruption and Organised Crime and the Tax Administration. This produces an unusual situation in which individual ministries and agencies are already experimenting with or deploying AI while other major parts of the state report no use at all. It also makes it difficult to establish a single national picture of public-sector AI deployment. Gong said publicly available information from Croatian institutions, the European Commission and the OECD had previously provided only a fragmented overview, which prompted the organisation to conduct its own mapping exercise. A governance question, not only a technology question The findings come as European governments prepare for increasingly detailed obligations under the EU AI Act. For public institutions, the issue is not simply whether AI tools can improve administrative work. Authorities may need to know which systems are being used, what data they process, who is responsible for their operation and how decisions involving AI can be reviewed. Gong argues that Croatia should establish a unified and regularly updated public register of AI systems used by public authorities. The organisation is also calling for common national standards, clearer information for citizens and internal rules governing responsible AI use. Its research found that institutions do not even use a consistent approach to identifying and recording what constitutes an AI system. That difference matters as AI moves beyond general-purpose tools such as ChatGPT and Copilot into healthcare, courts, security systems and public-facing government services. Croatia now has an opportunity to establish common standards before different practices become embedded across individual institutions. The broader question is likely to appear elsewhere in Southeast Europe as governments increase their use of AI: adoption can happen department by department, while governance often has to be built across the entire state.