Blog · Regulations
AI Act in Poland: who it covers and what to do
Since 2 August 2026, most of the EU AI Act has applied, and since July Poland has had an act that designates the national supervisory authority. For a company with a chatbot on its website, or one that answers calls through an AI voice agent, this means a handful of concrete obligations – most of them simpler than they seem. Below is what you can take from it in practical terms.
This text is a general guide, not legal advice. Classifying a specific system can be ambiguous, and when in doubt it is worth consulting a lawyer.
Two legal acts you need to know
Regulation (EU) 2024/1689 – commonly called the AI Act – applies directly in all EU member states. It entered into force on 1 August 2024, but its provisions kicked in in stages.
The Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003) is the Polish implementing legislation. It does not repeat the obligations from the AI Act – it designates the authority that enforces them and creates a framework for regulatory sandboxes.
What already applies – the timeline
- 1 August 2024 – the AI Act enters into force, no obligation is active yet.
- 2 February 2025 – bans on certain practices start to apply (including social scoring and emotion recognition at work and in schools), along with the AI literacy obligation.
- 2 August 2025 – rules on general-purpose AI models (GPAI), governance and penalties.
- 2 August 2026 – the remainder of the regulation, including the transparency obligations in Article 50 and the rules for high-risk systems listed in Annex III.
- 2 December 2026 – deadline for systems that generate synthetic content and were placed on the market before 2 August 2026: by this date they must meet the requirements of Article 50(2).
- 2 August 2027 – GPAI models placed on the market before August 2025, and high-risk systems built into regulated products.
The nearest deadline that affects ordinary companies: 2 December 2026. If your chatbot or content generator was already running before 2 August 2026, it must be brought into line with the requirements for labeling synthetic content. That is less than three months away.
Provider or deployer – this changes everything
The AI Act spreads obligations unevenly. The most fall on the provider – the one who creates the system and places it on the market under its own name. Far fewer fall on the deployer – a company that uses a ready-made system in its own business.
In a typical setup, where an agency builds and maintains a chatbot on its own platform, the agency is the provider and the client is the deployer. One exception to watch for: if a company puts its own brand on the system or substantially changes its intended purpose, it becomes the provider itself – with the full package of obligations.
Is my chatbot a "high-risk system"?
Usually not. High risk means the categories in Annex III – including recruitment and employee evaluation, access to education, credit scoring, health and life insurance, critical infrastructure and law enforcement. A chatbot that answers questions about your offer and books appointments does not fall into these categories.
But watch out for borderline cases: a bot that screens job candidates, or a system that assesses a customer's creditworthiness, is a different conversation. If your system makes, or materially influences, decisions about people in these areas, check the classification before you go live.
What you actually need to do – a checklist for a company with a chatbot
- Tell people it is AI. A person interacting with the system should know they are talking to a machine – unless that is obvious. In practice: one sentence at the start of the chat and one sentence in the voice agent's greeting.
- Label machine-generated content. If the system generates text, images, audio or video, its output must be labeled in a machine-readable format. The deadline for systems that were already running: 2 December 2026.
- Make sure your team is competent. The obligation in Article 4 applies to both providers and deployers and has applied since February 2025. It does not require certificates – documented training for the people who use the system is enough.
- Leave a path to a human. Formally required for high-risk systems, but in customer service it is a basic rule anyway: the bot should be able to hand the conversation over and not try to resolve matters it was not prepared for.
- Keep documentation. What is deployed, on which model, what data goes into the system, who is responsible on your side. In an inspection, this is the first thing they will ask about.
- Close the GDPR thread. The AI Act does not replace GDPR – if the bot processes personal data, you need a legal basis, information in your privacy policy and a data processing agreement with the provider.
KRiBSI – who enforces this in Poland
The Act of 3 July 2026 established the Commission for AI Development and Security (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji, KRiBSI) as the market surveillance authority within the meaning of Article 70(1) of Regulation 2024/1689. Complaints from citizens, businesses and institutions about the operation of AI systems can be submitted to the Commission.
What KRiBSI does: it receives complaints, examines whether systems comply with the rules, imposes administrative fines, issues binding individual opinions and runs regulatory sandboxes. During the parliamentary work, powers of an order-issuing nature, such as withdrawing a system from the market, were dropped. The Commission's decisions are subject to judicial review, and the act protects trade secrets in the proceedings it conducts.
A separate topic is regulatory sandboxes: a controlled environment in which you can test a solution under the supervision of the authority, with the possibility of temporarily setting aside some of the rules. Poland is one of the first countries in Europe to launch them – for companies building their own AI products, this is a real option, not a decoration.
Penalties
The ranges in the regulation are high: up to EUR 35 million or 7% of worldwide turnover for using prohibited practices, up to EUR 15 million or 3% for breaching most other obligations, and up to EUR 7.5 million or 1% for giving the authorities incorrect information. For small and medium-sized enterprises, the lower of the two values applies, which really changes the scale of the risk.
In practice, for a company with a chatbot the most likely scenario is not a fine but a customer complaint and an investigation. The cost is then mostly time and the need to show your documentation – which you either have or you do not.
Summary in three sentences
If you use a chatbot or a voice agent in contact with customers, the AI Act applies to you, but most likely in its mildest form: tell people it is AI, label machine-generated content, train your team and keep documentation. The nearest hard deadline is 2 December 2026 for systems launched before August. If your system touches recruitment, creditworthiness or health – verify the classification before you go any further.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (AI Act), in particular Articles 4, 50, 70, 99 and 113.
- Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003).
- Ministry of Digital Affairs, announcement of 27 July 2026 on the signing of the act on AI systems.
FAQ
Common questions
Does the AI Act apply to a sole proprietorship?
Yes – the regulation does not exempt companies because of their size. The difference is in the scale of penalties: for small and medium-sized enterprises, the lower of the two values (the amount or the percentage of turnover) applies. The information obligations for a chatbot are the same regardless of company size.
I use ChatGPT to write texts. Do I have to report anything?
There is no obligation to register or report anything. The obligation to label synthetic content rests primarily with the provider of the system that generates it. If you publish AI-generated material as your own, it is worth labeling it – both because of the deepfake rules in Article 50 and out of plain honesty toward your audience.
Does the bot have to say it is a bot in every message?
No. The information should be given when the interaction begins, so the other person knows what they are dealing with. In a chat, a welcome message is enough; on the phone, one sentence at the start of the call.
What if the provider is a company from outside the EU?
The AI Act also applies when the system is placed on the EU market or its output is used in the EU. A non-EU provider must appoint an authorized representative. As a deployer, it is worth checking in the contract who formally acts as the provider – if that is not specified, the risk is yours.
Compliance audit
We will check if your AI is compliant with the rules
With every implementation we go through this list together with the client: system classification, information notices, content labeling, documentation and the GDPR thread. If you already have a bot running – we will check it against the 2 December 2026 deadline.
- info@axisway.com
- +48 516 068 354
- ul. Szewska 8, 50-122 Wrocław