On 2 August 2026, the bulk of the obligations under Regulation (EU) 2024/1689, known as the Artificial Intelligence Act (AI Act), began to apply. The Regulation has been in force since 1 August 2024, but it is being introduced in phases: the prohibited practices and mandatory AI literacy have applied since 2 February 2025, the rules for general-purpose AI models and the governance system since 2 August 2025, and high-risk AI embedded in regulated products will be covered from 2 August 2027. This August, however, is the turning point: the rules for high-risk AI systems listed in Annex III now apply too, placing real obligations for the first time on the shoulders of companies that develop or use AI systems. For Macedonian businesses, especially IT and software companies working with EU clients, this is not a distant Brussels topic but a practical business question.
Does the EU AI Act apply to Macedonian companies?
Yes, in many cases it does. The Regulation has extraterritorial effect: it also applies to providers of AI systems established outside the EU when the output of their system is used in the Union. In other words, a Macedonian software company whose product is used by a client in Germany or the Netherlands may be directly covered, even though North Macedonia is not an EU member state.
Even when a company is not formally within scope, regulation arrives through contracts. EU clients, themselves covered by the Regulation, are beginning to demand compliance guarantees from their suppliers and developers: technical documentation, data rules, human oversight. In practice, this means the requirements of the Regulation are passed down the supply chain through so-called flow-down clauses.
North Macedonia does not yet have a dedicated domestic law on artificial intelligence, but alignment with EU law is part of the accession negotiation process and domestic regulation is a matter of time. Companies exporting services or software to the EU, however, must comply immediately, regardless of the fact that domestic legislation remains silent.
What risk categories does the Regulation introduce?
The Regulation divides AI systems into four categories according to risk: prohibited practices, high-risk systems, systems subject to transparency obligations, and minimal-risk systems. The greater the risk to people and their rights, the heavier the obligations for the provider and the user of the system.
| Category | Examples | Obligations |
|---|---|---|
| Prohibited practices | Social scoring, subliminal manipulation, emotion recognition in the workplace | Full prohibition, applicable since February 2025 |
| High risk | Recruitment and candidate screening, credit scoring, education, critical infrastructure | Risk management, technical documentation, human oversight, data quality |
| Transparency | Chatbots, generated and deepfake content | Clear disclosure that the user is interacting with AI, labelling of generated content |
| Minimal risk | The vast majority of tools in everyday business use | No new legal obligations |
For most firms, the key question is whether their system falls into the high-risk category. An HR tool for candidate selection, credit-scoring software or a system used in education are typical examples where the obligations are heaviest and where wrong classification costs the most.
How high are the penalties for non-compliance?
For prohibited practices, the fine reaches up to 35 million euros or 7% of the company's total worldwide annual turnover, whichever is higher. For other infringements the rates are lower, but still significant for any mid-sized firm. In practice, however, the first blow is rarely a regulator's fine. The contractual one comes much earlier: an EU client requesting proof of compliance and, failing that, terminating the cooperation or claiming damages under the contract.
What should companies do to prepare?
The first step is to build an inventory of all AI tools the company uses or develops and to classify each one against the risk categories of the Regulation. Only once the scope is known can a compliance plan be built. In short, the steps are:
- an inventory of the AI systems and tools you use or develop, including those embedded in your products;
- classification of each system by risk category, with a written reasoning of the assessment;
- a review of contracts with EU clients and negotiation of compliance clauses that clearly allocate responsibility (flow-down);
- technical documentation and records for the systems you develop, describing the data, testing and limitations;
- establishing human oversight over the decisions the system produces;
- data governance rules for the data used to train and operate the models;
- employee training, since AI literacy has been a legal obligation since February 2025.
Compliance with the AI Act is not a one-off formality but a process best built while the product is still being developed, not when a client is already asking for evidence. This is exactly where preventive law shows its value: a timely assessment of scope and risk is drastically cheaper than a fine, a lost client or a rework of a finished product.
Does your company develop or use AI systems for clients in the EU?
Whether the Regulation covers you directly or through your contractual relationships with EU clients is a question that requires a concrete analysis of your activities, your products and your contracts. A wrong assessment is costly in both directions: you either take on unnecessary expenses or remain exposed to risk.
We offer an assessment of the Regulation's scope over your activities, classification of your AI systems by risk, and preparation of the contractual framework with your EU clients.
Book a consultationRelated service: Corporate Law
Source: Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), EUR-Lex.
This text is general legal information and does not constitute legal advice for a specific case. For advice tailored to your situation, consult an attorney.