AI concepts
AI Act (the EU regulation governing artificial intelligence)
Regulation (EU) 2024/1689 of the European Parliament of 13 June 2024, governing artificial intelligence systems in the European Union. It applies in stages: a ban on prohibited practices from February 2025, requirements for general-purpose models from August 2025, full requirements for high-risk systems from August 2026, and full application from August 2027.
Primary source: EUR-Lex 32024R1689, Komisja Europejska Dyrekcja Generalna ds. Łączności
The AI Act is the first horizontal AI regulation in the world. Penalties for breaches reach 35 million euro or 7 percent of global annual turnover, harsher than the GDPR. For Polish enterprise firms, a significant part of the obligations starts to apply from August 2026, which for deployments planned in 2025 and 2026 means designing for compliance from day one.
Four risk categories
Prohibited practices. Citizen social scoring, subliminal manipulation, real-time biometric identification in public spaces (with exceptions for law enforcement). An absolute ban from February 2025.
High-risk systems. Annex III of the regulation: recruitment, creditworthiness assessment, access to education, critical infrastructure, justice, law enforcement. Requirements: risk assessment, technical documentation, transparency, human oversight, log retention, audit by a notified body. Applies from August 2026.
Limited-risk systems. Chatbots, deepfakes, content generation. Requirement: transparency toward the user (a notice that this is AI).
Minimal-risk systems. Everything else. No specific regulatory requirements, but good practices are recommended.
What this specifically changes for Polish firms
Most Polish enterprise deployments will fall into the limited-risk category (customer service chatbots, content generation in marketing). Here the cost of compliance is moderate: a UX fix (a "you are talking to AI" notice), a privacy policy, documentation.
Firms in finance, insurance, healthcare, legal, HR, and education may fall into the high-risk category. Here the requirements are capital-intensive. The cost of compliance estimated by the European Commission: 6,000 to 7,000 euro per system at the deployment stage plus 5,000 to 7,000 euro a year to maintain. For a mid-sized firm with three AI deployments that is 30 to 60 thousand euro in the first year.
The GPAI document
General Purpose AI models (GPT, Claude, Gemini, Mistral) have separate requirements for providers. From the perspective of firms deploying AI: you have to verify whether the provider has published the required documents (transparency template) and contractually delivered the data needed for downstream compliance.
The Polish supervisory authority
In Poland, the role of notified body and national supervisory authority has been held since November 2025 by UKE as the coordinating institution, with the involvement of PUODO (for personal data) and KNF (for the financial sector).
Mapping AI Act risk per use case in your company is part of the AI Readiness Audit. Implementing an AI Act compliance policy is delivered within Cybersecurity & AI Policy.