EU AI Act in Poland 2026: What It Means for Your Business

May 4, 2026

EU AI Act in Poland 2026: What It Means for Your Business

AI transparency obligations have applied since 2 August 2026, and from 28 October 2026 Poland’s new regulator can inspect and fine. Find out which AI tools in your company are covered and what you actually need to do.

Does your company use AI for recruitment? Do you have a chatbot on your website? Are you using automated lead scoring?

All of this is governed by hard European law with fines reaching 35 million euros. Part of it has applied since 2 August 2026, and from 28 October 2026 a national authority enforces it in Poland.

Don’t panic — most Polish B2B companies are in a better position than they think. But there is one catch that almost every article on this topic misses. We’ll get to it in a moment.

What Is the AI Act and Why Does It Affect Me

Regulation (EU) 2024/1689 is the world’s first comprehensive law regulating artificial intelligence. It entered into force on 1 August 2024.

The key principle: it applies to every company that offers or uses AI in the EU — regardless of where it is based. A US startup selling you AI software? Subject to the AI Act. A Polish company using that software? Also subject to the AI Act.

The AI Act works like building regulations for AI: the higher the risk, the stricter the standards.

Timeline: What Already Applies, What Is Coming

  • 1 August 2024 — AI Act enters into force
  • 2 February 2025 — Ban on unacceptable-risk AI systems — already in effect
  • 2 August 2025 — Rules for general-purpose AI models (GPT-4, Claude, Gemini)
  • 2 August 2026 — Transparency obligations (Article 50): chatbots and voice agents must disclose they are AI — in force
  • 11 August 2026 — Main provisions of the Polish AI systems act enter into force
  • 28 October 2026 — KRiBSI begins inspections, proceedings and administrative fines
  • 2 December 2026 — End of the transition period for machine-readable marking of AI-generated content
  • 2 December 2027 — High-risk systems under Annex III (recruitment, scoring, employee assessment)
  • 2 August 2028 — High-risk systems under Annex I (AI embedded in products and machinery)

September 2026 update: high-risk systems were originally due on 2 August 2026. The EU Digital Omnibus, in force since 27 July 2026, moved those deadlines to December 2027 and August 2028. It did not touch Article 50 — the duty to tell people they are talking to AI. That one landed on time, and it is the one that reaches the most companies.

Four Risk Categories — Where Does Your Company Fall

Unacceptable Risk — Absolute Ban (since February 2025)

  • Systems that manipulate users subliminally
  • Emotion recognition in workplaces and schools
  • Social scoring of citizens by public authorities
  • Predictive policing based on personal characteristics
  • Creating facial recognition databases by mass scraping

If your HR team had an idea for AI to “analyse candidate mood during job interviews” — that just became illegal.

High Risk — Full Documentation by December 2027

This is the catch. High-risk systems are not only military and medical. They include very common business applications:

  • Recruitment — any AI system for CV screening, candidate ranking, employee evaluation
  • Credit and insurance scoring — automated creditworthiness assessment
  • Employee performance management — if AI decides on bonuses, promotions, dismissals
  • Critical infrastructure (energy, water, transport)
  • Educational assessment systems

For these applications, full documentation, conformity assessment, registration in the EU AI Database and designated human oversight are required.

Limited Risk — Transparency Obligations (in force since 2 August 2026)

This is the only part of the AI Act whose deadline has already passed:

  • Chatbots and voice agents — must tell the person they are interacting with AI, at the latest at the first interaction
  • Generative AI producing text, images or audio — marking in a machine-readable format (systems already on the market before 2 August 2026 have until 2 December 2026)
  • Deepfakes and AI-generated text on matters of public interest — mandatory disclosure

Minimal Risk — No Additional Requirements

  • Spam filters
  • Product recommendation tools in e-commerce
  • Most productivity AI tools (AI writing assistants, Copilot)
  • BI analytics and sales prediction

The Key Distinction: Provider vs. Deployer

Provider — you create or deploy an AI system for others. Full obligations: technical documentation, certification, EU AI Database registration, CE marking, designated AI officer.

Deployer — you buy a ready-made AI tool (SaaS, API) and use it in your business. Lighter obligations: use according to provider instructions, human oversight, incident monitoring and reporting, informing employees.

Most Polish B2B companies are deployers — using ChatGPT, Copilot, no-code AI tools. Good news: the scope of obligations is much smaller than for companies building their own systems.

Bad news: if you use AI for recruitment or employee assessment — you are a deployer of a high-risk system and the obligations are concrete, even though the deadline moved to December 2027.

What Your Company Must Do — Checklist

If you use AI for recruitment or employee assessment (high risk):

  • Conduct a Fundamental Rights Impact Assessment (FRIA) before deployment
  • Ensure human oversight — no decision can be fully automatic
  • Inform employees and their representatives about AI use
  • Retain system logs for a minimum of 6 months
  • Verify that your tool provider has technical documentation and certification

If you have a chatbot or use generative AI (limited risk):

  • Add a clear notice: “You are talking to an AI assistant”
  • Provide the option to connect with a human
  • Label AI-generated content where published

For all companies:

  • Inventory all AI tools you use and determine their risk category
  • Verify that your SaaS and API providers are updating their products for AI Act compliance
  • Designate someone responsible for AI Act compliance in your company

Fines — What They Really Cost

  • Using prohibited AI systems — €35M or 7% of global annual turnover
  • Breaching high-risk obligations — €15M or 3% of global annual turnover
  • Providing incorrect information to authorities — €7.5M or 1.5% of global annual turnover

For SMEs and startups the lower of the two values applies. A company with 5M PLN annual revenue faces a maximum of around 450,000 PLN for a general breach, not €15M.

But fines are not the only risk. Reputational damage, lawsuits from employees dismissed “by an algorithm”, liability for discriminatory hiring decisions — these can cost more than the fine.

Poland: The AI Systems Act and the Authority That Inspects

The Polish AI systems act was published in the Journal of Laws on 27 July 2026, with its main provisions in force from 11 August 2026. The act:

  • Creates KRiBSI — the Commission for the Development and Safety of Artificial Intelligence as the national market surveillance authority and single point of contact
  • From 28 October 2026 switches on the rules on inspections, proceedings, settlements reducing fines, and administrative penalties
  • Allows companies to request an individual opinion from KRiBSI when their classification is unclear
  • Creates a regulatory sandbox for SMEs and startups

Important: the AI Act as an EU regulation applies directly in Poland without additional transposition. The Polish act clarifies supervision and national sanctions.

Summary

The AI Act is not a threat to most Polish companies — as long as you understand which category you operate in.

Three things to do now:

  1. Inventory all AI tools in your company
  2. Check the category — recruitment and employee assessment = high risk
  3. Designate someone responsible — not necessarily a lawyer, but someone who knows your processes

The nearest real date is 28 October 2026, when KRiBSI starts inspecting and fining. High-risk documentation has until December 2027, but the duty to disclose AI applies right now — and checking it takes minutes.

Book a free consultation with Prospere AI — we will help assess where your company stands →