Most writing about the AI Act in Poland answers a lawyer’s question: what applies, and from when. Companies ask us something else: “we only use ChatGPT, Copilot and a chatbot from a supplier — what do we need in place before KRiBSI starts inspecting on 28 October 2026?” We answer that second question, explaining along the way what the AI Act is, when it applies from, and what the Polish Act adds.
We write for a company that only uses AI rather than building models — for a deployer, as the Regulation calls it. The legal position is as at 6 September 2026. This describes the technical and organisational side, not legal advice — the legal assessment belongs to your lawyer or data protection officer.
In brief: four dates and three obligations
- The AI Act applies directly in Poland, in stages from 2 February 2025; the Polish Act organises supervision, it does not add obligations.
- Article 50 applies from 2 August 2026: a chatbot has to disclose itself, and generated content has to be labelled.
- The Polish Act has applied since 11 August 2026, and KRiBSI inspects, takes complaints and fines from 28 October 2026.
- High-risk systems under Annex III — from 2 December 2027. The deadline was postponed, not abolished.
- A company that only uses AI has three obligations today — AI literacy (Article 4), transparency (Article 50), not using prohibited practices (Article 5) — plus one task the Regulation does not require outright, but without which none of them can be documented: a register of AI systems.
What the AI Act is — and what it is not
The AI Act, Regulation (EU) 2024/1689, regulates AI systems by the risk of their use — not the technology and not the data. There are four levels: prohibited practices; high-risk systems with extensive obligations; systems with transparency obligations (they talk to people or generate content); and everything else, on which the Regulation imposes nothing beyond Article 4 on AI literacy. Most office tools land in that last group.
The Regulation also knows two roles with fundamentally different obligations: a provider builds the system or places it on the market under its own name; a deployer uses it in its business and answers for how it is used.
What the AI Act is not: it is not a data protection law — the GDPR (RODO in Polish) runs in parallel, and the AI Act also covers systems with no personal data. It is not a ban on using ChatGPT: it is the use that is compliant or not, not the tool. We set the two regimes side by side in GDPR and an LLM rollout.
When the AI Act applies: the timetable after the Digital Omnibus
Amending Regulation 2026/1744 (the Digital Omnibus on AI) entered into force on 27 July 2026 and moved some of the deadlines, so texts written before July 2026 are out of date on this point. The EU dates: Regulation 2026/1744 on EUR-Lex and the Commission’s page on the AI regulatory framework; the Polish ones come from the Act discussed below.
| Date | What | Status |
|---|---|---|
| 2 February 2025 | Prohibited practices (Article 5), AI literacy (Article 4) | in force |
| 2 August 2025 | Obligations of GPAI model providers, supervision, penalties (Article 99) | in force |
| 27 July 2026 | Digital Omnibus; new wording of Article 4 | in force |
| 2 August 2026 | Transparency (Article 50); supervisory powers of national authorities; enforcement against GPAI | in force |
| 11 August 2026 | Polish Act on Artificial Intelligence Systems (Journal of Laws 2026, item 1003); KRiBSI created | in force |
| 28 October 2026 | KRiBSI inspections, complaints, penalties and binding opinions (Chapters 3–5, 8, 9 and Articles 8–18 of the Act) | from |
| 2 December 2026 | End of the grace period on machine-readable labelling for generative systems from before 2 August 2026; new prohibition in Article 5 | from |
| 2 August 2027 | EU deadline for national sandboxes to be operating; compliance of GPAI models from before 2 August 2025 | from |
| 2 December 2027 | High-risk systems under Annex III (previously 2 August 2026) | from |
| 2 August 2028 | High-risk systems in products under Annex I (previously 2 August 2027) | from |
The Omnibus moved the high-risk obligations to fixed dates, no longer tied to standards. It did not move Article 50, Article 4, Article 5 or the supervisory powers. 2 August 2026 is the general start of the Regulation’s application, not its “entry into force” — from that day Article 50 applies and national authorities have supervisory powers. The only slack in Article 50 is four months, to 2 December 2026, for providers of generative systems from before 2 August 2026, on machine-readable labelling; it does not cover a deployer’s information duties. “Deadline postponed” is not the same as “nothing to do”.
The AI Act in Poland: the Act of 3 July 2026 and KRiBSI
The Regulation applies directly; the national Act exists so that someone enforces it. The Act of 3 July 2026 on Artificial Intelligence Systems (Journal of Laws 2026, item 1003) runs to 127 articles in 10 chapters: passed on 11 June, signed on 24 July, promulgated on 27 July 2026; it entered into force on 11 August 2026, apart from the parts deferred to 28 October 2026 (Article 127). The text is on eli.gov.pl, and the Ministry of Digital Affairs summary is on gov.pl.
KRiBSI — the Commission for the Development and Security of Artificial Intelligence — is the market surveillance authority within the meaning of Article 70(1) of the AI Act and the single point of contact (Article 5 of the Act). It comprises a chair elected by the Sejm, the lower house of the Polish parliament, with the Senate’s consent, two deputies and four members nominated by the President of UOKiK (the competition and consumer protection office), KNF (the financial regulator), KRRiT (the broadcasting council) and the President of UKE (the telecoms regulator) (Article 19). Statutory deadlines, not press reports about candidates: a chair within two months of entry into force, so around 11 October 2026, and a first sitting within three months. Budget: up to 9.30m zł in 2026 and 23.74m zł in 2027 (Article 126).
What changes on 28 October 2026
KRiBSI gains its executive powers: inspections (Chapter 3), proceedings and the complaints register (Chapter 4), settlements mitigating sanctions (Chapter 5), penalties (Chapter 8). Binding individual opinions also start (Articles 8–18): an application costs 150 zł, the answer comes within 30 days, the opinion binds KRiBSI and other state authorities, and anonymised opinions are published. For a company with a real classification question that is cheaper than guessing — but a lawyer writes the application. Regulatory sandboxes (Chapter 7) already run today: 6–12 months, free for micro, small and medium-sized companies (Article 93(1)).
A correction to the July reports: the Act does not make the President of UODO, the Polish data protection authority, a market surveillance authority for AI systems — UODO gives an opinion on data protection in the sandboxes (Article 92) and nominates a member of the recruitment panel for the deputy chairs (Article 32).
Provider or deployer — three questions that put your company in order
A company using off-the-shelf tools is most likely a deployer — different, and usually far lighter, obligations than a provider’s. The exception is a tool you built yourself, for example your own n8n workflow with a model, exposed to clients under your brand. There the role is not obvious, and Article 25 — tightened by the Omnibus for substantial modifications — is a question for a lawyer, not an engineer.
Three questions for every use:
- Is it on the list of prohibited practices (Article 5)? Example: inferring emotions in the workplace, including in recruitment and during a probationary period, prohibited since 2 February 2025; the candidate’s consent does not lift that. If yes — stop, and a lawyer, today.
- Does it fall under Annex III — employment, education, essential services, biometrics, consumer credit? The obligations arrive on 2 December 2027, but have a lawyer classify it now: documentation and logging are cheaper to design in than to bolt on.
- Does it talk to people or generate content (Article 50)? If yes — check disclosure and labelling, below.
Whatever comes through with “no, no, no” is left with Article 4 and a line in the register. That is most office automation.
A register of AI systems: template and an example at a 60-person company
Without a register, every conversation about compliance is about systems nobody has counted — and tools brought in by teams on their own initiative are rarely written down anywhere. A spreadsheet with nine columns is enough: system and provider · who uses it · what for · what data goes in · role · obligations today · lawyer needed · owner · review date.
The example below is an illustration, not a client: a B2B trading company, 60 people, three departments. The “obligations today” column is an engineer’s first pass, confirmed by a lawyer — not a classification.
| System | Who | What for | Data | Role | Obligations today | Lawyer |
|---|---|---|---|---|---|---|
| ChatGPT Team, 14 seats | sales, marketing, board | quotes, translations | quote text, sometimes client contacts | deployer | Article 4; GDPR | no |
| Microsoft 365 Copilot, 60 licences | everyone | email and meeting summaries | mail and documents | deployer | Article 4; GDPR | no |
| Website chatbot (supplier’s SaaS) | customer service | availability and order status | email, order number | deployer | Article 50 — does it disclose itself; Article 4 | only if the bot decides anything |
| n8n workflow with a model (in-house) | accounts | reading invoices, proposing a posting, a human approves | counterparty data, sole traders included | to be determined | Article 4; GDPR | yes, as to the role |
| ATS (applicant tracking system) with “AI matching” | HR | CV ranking | candidate data | deployer | Annex III from 2 December 2027; today: does it analyse emotions (Article 5) | yes, now |
| Description generator in the e-commerce platform | marketing | product descriptions | no personal data | deployer | Article 4; machine labelling sits with the provider | no |
| Voicebot on the helpline | planned | — | — | — | disclosure designed in from day one | at design time |
The outcome: no prohibited practices — once the ATS supplier confirms that “matching” does not infer emotions; one Annex III candidate goes to a lawyer now; two systems under Article 50 wait on the supplier’s answer; all six in use fall under Article 4. The effort, also illustrative: two 90-minute workshops with department heads, about two hours of writing it down and a licence list from IT — 5–6 hours of work. The biggest find is usually something IT did not know about, such as a ChatGPT account paid for on a department card. The register has a date and an owner; it is updated with every new tool, not once a year.
Article 50: chatbot, voicebot and generated content — what to check before 28 October
Article 50 has three levels, each with a different action on your side.
A person talks to a system (paragraph 1). The person has to be clearly informed, at the latest at the first interaction, unless it is obvious from the circumstances. The provision addresses how the system is built, so the provider, but whether the message arrives is decided by your configuration: the greeting, the flow, what sits in front of the bot window. We do not use the “obviousness” exemption and always disclose — details under voicebot implementation. Action: open your own chatbot as a customer and read the first sentence.
Generated content (paragraph 2). Machine-readable labelling is the provider’s obligation for a generative system; systems from before 2 August 2026 have until 2 December 2026, newer ones from day one. Action: an email to every supplier with three questions — does the system disclose itself, does it label content machine-readably and from when, and can that be verified. Put the answers in the register.
Deployer obligations (paragraphs 3–4). Paragraph 3 covers emotion recognition and biometric categorisation — a trading company usually has neither, and emotion recognition in the workplace is prohibited outright. Paragraph 4 applies to you when you publish a deepfake — generated or manipulated image, audio or video that could pass for authentic — or generated text informing the public on matters of public interest, unless it has been through human editorial review and someone carries editorial responsibility for the publication. Product descriptions and sales quotes are not that kind of text; a recording with a “digital CEO” already looks like content to disclose. Before you base a decision on this, read paragraph 4 in the consolidated AI Act text on EUR-Lex. The Commission’s final Article 50 guidelines are not out yet (draft of 8 May 2026); the Code of Practice on AI-generated content was published on 10 June 2026.
Article 4 after the Omnibus: an obligation of effort, not a certificate
Article 4 covers AI literacy and has bound every provider and deployer since 2 February 2025, whatever the size of the company. Until 27 July 2026 it spoke of ensuring, as far as possible, a sufficient level of literacy among staff; since 27 July 2026 it speaks of taking measures to support the development of AI literacy among staff and other people operating systems on your behalf — and states outright that it does not require any given level to be guaranteed in any individual. An obligation of effort, not of result.
Who checks. Since August 2026, the market surveillance authorities — in Poland, KRiBSI. The penalty catalogue in Article 99 does not list Article 4 — sanctioning it was left to national law, and the Polish Act sets no range of its own here; how that works in Polish law is for a lawyer to resolve. What the Act does say is what to expect in an inspection: the chair of KRiBSI sets “the manner and method of checking the level of knowledge and competence of those inspected” (Article 25(3)), and the annual report to the Sejm describes “the general level of knowledge and competence of those inspected” (Article 26(2)(2)). So an inspection will ask what your people know — and what you have on paper for it. We found no Polish guide to Article 4 as at the date of writing; there is the Commission Q&A on AI literacy.
One page of evidence: (1) a list of tools and the people who use them — the register; (2) rules of use: what may be pasted in, what may not, when a human checks the output; (3) a short introduction to each tool on your own processes — with a date, an attendance list and the material; (4) a named owner and a review date. With us that introduction is a stage of an AI rollout in the company, on the tools the company actually runs — not a separate course; a certificate from external training does nothing on its own under this provision.
High-risk systems and prohibited practices — when it is a matter for a lawyer
Annex III covers, among other things, recruitment and worker management, education, access to essential services, consumer creditworthiness and biometrics — from 2 December 2027, as a fixed date, not a conditional one. The Commission’s classification guidelines (Article 6(5)) were due by 2 February 2026; there is a draft of 19 May 2026, and we have not found a final version. No harmonised standard has been cited in the Official Journal of the EU (as at June 2026). Two Omnibus reliefs that matter to SMEs: components for user assistance, performance, convenience or automation are not safety components (Article 6), and a fundamental rights impact assessment may be based on the GDPR DPIA (Article 27). From 2 December 2026 Article 5 gains a new prohibition: non-consensual intimate content and child sexual abuse material.
You call a lawyer when the system touches employment, credit, education or access to services; when it decides anything itself in relation to a person; when you are building something under your own brand for clients; when the supplier cannot answer three questions about Article 50; when someone proposes “emotion analysis” in anything. We do not build candidate-scoring systems ourselves — it is an item on the list of what we don’t do.
Penalties: how much, who imposes them and how it works in Poland
Article 99 has three thresholds, unchanged by the Omnibus: prohibited practices — up to 35 million euro or 7% of worldwide annual turnover, whichever is higher; operator obligations, Article 50 included — up to 15 million euro or 3%; false information given to the authorities — up to 7.5 million euro or 1%. For SMEs, start-ups included, the lower of the two amounts applies (Article 99(6)); the Omnibus extended that rule to small mid-cap companies. The amounts stay in euro — the Act converts them at the average rate of NBP, the Polish central bank, as at 28 January of the year in question.
In Poland KRiBSI imposes penalties by decision, “in the cases, amounts and on the conditions” of Chapter XII of the AI Act (Article 104 of the Act); it may reduce a penalty by 10–50% where the infringement was remedied within three months of a warning. An appeal goes to the Regional Court in Warsaw — the competition and consumer protection court; payment within 30 days of the decision becoming final. Obstructing an inspection is a petty offence (Articles 112–113). Chapter 8 applies from 28 October 2026 — before that KRiBSI cannot impose any penalty.
What this article does not settle — and when the AI Act is not your first problem
- It does not settle classification or the legal basis. That is the lawyer and the data protection officer; we prepare the material they work on.
- When the AI Act is mainly a register and one page of evidence. Two or three office tools, none of them talking to customers, nothing touching employment or credit. An external audit is overkill then — write it up yourself in one afternoon. We say that even when it means no contract.
- When compliance is the wrong first project. No process owner, tools arriving by themselves, nobody knowing what goes into the model. Order in the data and the process first — the AI Act comes with it.
- When you need a lawyer, not an engineer. The list in the previous section — and, from 28 October 2026, a binding KRiBSI opinion.
- What will still change. Final guidelines on Articles 6 and 50, standards, KRiBSI practice. This text is dated and will be updated.
A list for 28 October 2026 — and what next
- A register of AI systems with the role, the obligations and an owner for every row.
- Three questions — Article 5, Annex III, Article 50 — asked of every row.
- The chatbot’s first sentence checked, and the supplier’s answer to the three Article 50 questions.
- A set of Article 4 evidence, with dates.
- The “lawyer: yes” rows handed to a lawyer with the register attached.
- GDPR alongside the AI Act: processing agreements, and company accounts rather than private ones — what to ask every supplier is collected on the page on data security and GDPR.
- The date of the next register review.
If the register shows more than a few systems, if something talks to customers, or if something touches employment, we have described the technical side — the register of systems, the controls implemented in the scope your lawyer sets, the documented workshop — under the AI Act technical compliance sprint. Tell us what you use. We will tell you where we would start — including when the answer is “write the register up yourself, you don’t need a sprint”.