AI Act in Poland: What Companies Need to Do to Comply With the New Rules
New AI Act provisions took effect on August 2, 2026. Transparency requirements are now in force, but the deadline for high-risk AI systems has been pushed back. At the same time, the Polish president signed a law creating the country’s first AI regulatory authority.
TL;DR
Since August 2026, companies that deploy chatbots, generate content using AI, use emotion recognition, or operate biometric categorization systems must comply with the transparency requirements under Article 50 of the AI Act. Fines for non-compliance can reach EUR 15 million or 3% of annual worldwide turnover. The deadline for high-risk AI system requirements (recruitment, credit scoring, critical infrastructure) has been deferred to December 2027. Poland has established the Commission for the Development and Security of Artificial Intelligence (KRiBSI), which is expected to begin enforcement later in 2026. However, some provisions have been in effect since February 2025, and the transparency requirements since August 2026. Companies should now carry out an inventory of the AI systems they use, implement the required transparency labels, and provide AI literacy training, a requirement that has been in effect since February 2025.
The AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive law governing the use of artificial intelligence. Its provisions apply directly across all EU Member States, with no need for separate national transposition, and are rolling out in phases. Most of the rules were originally set to take effect by August 2026, but in May the European Parliament and the Council of the EU agreed to push back the deadline for high-risk AI system requirements. Around the same time, Poland passed a law creating a dedicated AI regulatory body. This article explains which rules are in effect now, which deadlines have changed, and what steps companies operating in Poland should take.

Transparency Rules Now in Force
The provisions that came into force in August deal with transparency in how users interact with AI systems. On July 20, 2026, the European Commission published guidelines (and on July 24, an FAQ to them) explaining how companies should implement these requirements.
Article 50 of the AI Act requires both providers and deployers of AI systems to be transparent with users. The requirements cover four categories of systems. Providers of AI systems designed for direct interaction with people, such as chatbots or voice assistants, must build them so that users know they are communicating with a machine. According to the Commission’s guidelines, this notice should appear at the start of the conversation; a mention buried in terms of service or product documentation is not enough.
Providers of systems that generate images, audio, video, or text must tag their outputs with machine-readable metadata (for example, using the C2PA standard) so that the content can be automatically identified as AI-generated. Systems already on the market before August 2 have until December 2, 2026, to meet this requirement.
Companies that deploy emotion recognition or biometric categorization systems must inform the people affected. Content produced using deepfake technology, meaning audio, video, or images that look authentic but were generated or manipulated by AI, must also be clearly labeled. Notably, this labeling requirement applies even when the creator had no intention to mislead. The same obligation covers AI-generated text published in the context of public debate, such as news articles or opinion pieces, unless a human had editorial control and a named person or entity bears editorial responsibility for the publication. The labeling requirement does not apply to content used under law for the purpose of detecting, preventing, or prosecuting criminal offenses. In the case of content with a clearly artistic, creative, satirical, or fictional character, it is sufficient to disclose the artificial origin of the material in a way that does not hinder the enjoyment of the work.
As of August 2, the European AI Office also gains full enforcement powers over providers of general-purpose AI models (GPAI), including the ability to impose fines of up to EUR 15 million or 3% of annual worldwide turnover.
High-Risk AI: New Deadlines, Same Requirements
The AI Act’s original timeline called for the high-risk AI system requirements to take effect on August 2, 2026, as well. High-risk systems are those that can significantly affect fundamental rights or people’s safety. In May 2026, the European Parliament and the Council of the EU agreed to defer these obligations.
The change was introduced through the first amendment to the AI Act, which the Council formally adopted on June 29, 2026. The deferral was prompted by the lack of finalized technical standards and tools that were supposed to help companies comply. Under the amended timeline, high-risk AI systems such as automated candidate screening in recruitment, credit scoring tools, and AI used in critical infrastructure or education must meet the AI Act’s requirements by December 2, 2027. Providers of AI systems embedded in products regulated by sector-specific legislation, such as medical devices or machinery, have until August 2, 2028.
The scope of the requirements has not changed. Even though the deadlines have shifted, companies that already use high-risk AI systems should start preparing now. Developing technical documentation, putting risk management processes in place, ensuring human oversight, and completing conformity assessments all take time, and the months ahead are worth using well.
The deferral does not affect the Article 50 transparency requirements, which apply from August. The only exception is the metadata labeling obligation described above: providers of systems already on the market before August 2 have until December 2, 2026, to comply.
Poland’s New AI Regulator
The AI Act applies directly in Poland as an EU regulation, but enforcement requires a national market surveillance authority. On July 24, 2026, the Polish president signed the Act on Artificial Intelligence Systems, which creates that authority.
The new regulator is the Commission for the Development and Security of Artificial Intelligence, known by its Polish acronym KRiBSI. It is an independent body, with organizational support provided by the Ministry of Digital Affairs. Its chair is appointed for a five-year term by the Sejm (the lower house of the Polish parliament) with the Senate’s approval. According to a statement by the Deputy Minister of Digital Affairs, the appointment is expected in October 2026, with the full commission in place by November. KRiBSI will include representatives from Poland’s competition authority (UOKiK), the telecoms regulator (UKE), the financial supervisory authority (KNF), and the broadcasting council (KRRiT). Poland’s data protection authority (UODO) retains separate competences for assessing AI systems in relation to personal data protection.
KRiBSI will have the power to conduct inspections, open proceedings for violations, impose fines, and in extreme cases order the withdrawal of an AI system from the market. Individuals will also be able to file complaints about AI systems used by banks, employers, or healthcare providers.
Two additional mechanisms are worth noting. Companies can request an individual interpretive opinion from KRiBSI, which allows them to verify whether a planned AI deployment complies with the rules before it goes live. The law also requires at least one regulatory sandbox to be set up, a controlled environment where AI solutions can be tested under regulatory supervision. For small and medium-sized enterprises (SMEs), participation in the sandbox is free of charge.
The law was published on July 27, 2026, and the provisions on inspections and fines take effect on October 28, 2026. Fines for violating transparency requirements can reach EUR 15 million or 3% of annual worldwide turnover. For prohibited AI practices, the ceiling is EUR 35 million or 7% of turnover.
The AI Act’s 2025 Deadlines
August 2026 is an important milestone, but some AI Act requirements came into force well before that and already apply to virtually every company using artificial intelligence.
Article 4 of the AI Act, in effect since February 2, 2025, requires both providers and deployers of AI systems to ensure an adequate level of AI literacy among staff and others who operate these systems. What counts as adequate depends on context; the bar is different for an IT team deploying a language model than for a customer service agent using a chatbot. The European Commission has emphasized that the required competencies must be proportionate to how a company actually uses AI.
Article 5, also in effect since February 2, 2025, prohibits AI practices deemed unacceptable, including social scoring, subliminal manipulation, indiscriminate facial image scraping from the internet, and emotion recognition in the workplace and educational institutions.
Despite these rules being in force for over a year, many companies across Europe have yet to act on them. A survey by the advisory firm Vision Compliance published in April 2026 found that 78% of organizations in the EU had not taken meaningful steps toward AI Act compliance. The survey is not limited to Polish companies but covers businesses in finance, technology, healthcare, energy, and retail, the sectors where the AI Act imposes the most requirements.
Getting Your Company Ready

The obligations the AI Act places on a company depend on whether it is a provider of an AI system or a deployer, and on the system’s risk level. To figure that out, a company first needs to know what AI tools it actually uses.
That makes an inventory the most important starting point. Beyond the AI solutions approved by the IT department, companies should also account for tools that employees use on their own, such as publicly available language models. Uncontrolled use of AI within an organization means the company may not have a complete picture of its regulatory obligations, because it may not even realize it qualifies as a deployer of a given AI system under the law.
For each identified AI system, the next step is to determine its risk level. The AI Act defines four tiers: unacceptable (prohibited systems, such as social scoring), high (for example, AI in recruitment or credit scoring), limited (such as chatbots), and minimal (such as spam filters). The risk level determines which requirements apply and by when.
Companies that operate chatbots or publish AI-generated or AI-manipulated content should implement the required labels and notices without delay. The Article 50 transparency requirements apply from August with no transition period. As noted above, the only exception is the extended metadata labeling deadline for providers of systems already on the market before August 2.
Article 4 of the AI Act also requires every company using AI to provide AI literacy training for its staff. For that training to be meaningful, a company should first establish clear rules for how AI is used internally and identify who relies on it and to what extent. A guide covering the organizational side of AI deployment can help with that process.
It is worth keeping in mind that the inventory and risk classification are not one-off tasks. Employees may start using new AI tools, models change over time, and KRiBSI can request documentation at any point. Keeping things in order is easier when a company uses a single environment for managing access to AI models and logging how they are used.
FAQ
Does the AI Act Apply to Small and Medium-Sized Companies?
Yes. The AI literacy requirement under Article 4 applies to every company that uses AI systems, regardless of size. The Article 50 transparency requirements also set no size threshold. The difference is in how fines are calculated: for SMEs, the lower of the two values (percentage of turnover or fixed amount) applies, which offers some relief compared to large corporations. KRiBSI’s regulatory sandboxes are free of charge for SMEs.
Do I Have to Label Every Piece of AI-Generated Content?
No. Article 50 of the AI Act distinguishes between two obligations. Providers of AI systems that generate content (text, images, audio, video) must ensure that all outputs carry machine-readable metadata identifying their artificial origin. This is a technical obligation that falls on the creator of the model, not on the company using it. Systems that serve only as an assistive tool for standard editing are exempt. Deployers, meaning companies that use AI systems, are required to visibly label content in two cases: when they publish deepfakes (realistic audio, video, or images resembling real people or events) and when they publish AI-generated text on matters of public interest, unless the text has undergone human editorial review and a named person or entity bears editorial responsibility for the publication. The labeling requirement does not apply to content used under law for the purpose of detecting, preventing, or prosecuting criminal offenses. In the case of content with a clearly artistic, creative, satirical, or fictional character, it is sufficient to disclose the artificial origin of the material in a way that does not hinder the enjoyment of the work.
When Will KRiBSI Start Conducting Inspections?
KRiBSI will gain its enforcement powers, including the ability to conduct inspections and impose fines, on October 28, 2026, three months after the law was published in Poland’s official gazette. It is worth noting, however, that the Article 50 transparency requirements have applied since August 2, and violations committed from that date onward can serve as grounds for proceedings once KRiBSI is operational.
Sources
1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonized rules on artificial intelligence (AI Act), 2024 – https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689
2. European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems, 2026 – https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations
3. European Commission, FAQ: Transparency obligations under Article 50 of the AI Act, 2026 – https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
4. Council of the EU, Artificial intelligence: Council and Parliament agree to simplify and streamline rules, 2026 – https://www.consilium.europa.eu/en/press/press-releases/2026/05/07/artificial-intelligence-council-and-parliament-agree-to-simplify-and-streamline-rules/
5. Kancelaria Prezesa Rady Ministrów, Projekt ustawy o systemach sztucznej inteligencji, 2026 – https://www.gov.pl/web/premier/projekt-ustawy-o-systemach-sztucznej-inteligencji2
6. Prawo.pl, Prezydent podpisał ustawę o systemach sztucznej inteligencji, 2026 – https://www.prawo.pl/biznes/prezydent-podpisal-ustawe-o-systemach-ai,1541891.html
7. Bankier.pl, AI pod kontrolą państwa. Powstanie pierwsza taka piaskownica regulacyjna w UE, 2026 – https://www.bankier.pl/wiadomosc/AI-pod-kontrola-panstwa-Powstanie-pierwsza-taka-piaskownica-regulacyjna-w-UE-9173741.html
8. European Commission, European AI Office, 2024 – https://digital-strategy.ec.europa.eu/en/policies/ai-office
9. Vision Compliance, 2026 EU AI Act Readiness Analysis, 2026 – https://uspolitics.einnews.com/pr_news/903074846/vision-compliance-releases-2026-eu-ai-act-readiness-report-finds-78-of-enterprises-unprepared-for-obligations
10. Extentum.AI, Shadow AI: GDPR Risks and Data Leaks, 2026 – https://extentum.ai/shadow-ai-gdpr-risks-data-leaks/
11. Extentum.AI, GenAI Implementation Guide, 2026 – https://extentum.ai/genai-implementation-guide/
12. Extentum.AI, Platform, 2026 – https://extentum.ai/platform/