TWIN:DESK
What if an employee does not know how to “talk” to AI?
TWIN:DESK includes a Prompt Assistant that helps formulate instructions in line with the CRISPE-CDF prompt engineering standard
How can you prevent specific files from leaking at the point of upload?
A document can be marked confidential immediately. The system then permanently blocks its use in conversations with external cloud AI models
Is TWIN:DESK just a text window?
No. It is a multimodal AI workspace supporting voice commands, attachment analysis and “computer mode”, where AI agents perform tasks on the user's behalf
How does the interface adapt to different experience levels?
It reveals features progressively: beginners see a simple chat, while experts have full access to a terminal and workflow automation
Which Polish e-government systems does the platform integrate with?
EZD RP and EZD PUW, e-Doręczenia, KSeF 2.0 and ePUAP authentication
How is TWIN:DESK different from another AI chat?
It is an everyday workspace that builds institutional memory: it securely handles internal documents and knowledge bases (RAG) and includes tools for automating tasks and processes
How does the Model Council improve work quality?
A question goes to up to five selected models in parallel. The platform collects and compares their responses, then prepares one final answer — with greater confidence in the result
How can you control employees' AI usage costs?
The virtual accounting unit Twin:Coin hides complex token price lists and makes it easier to report and limit team costs
Does the assistant suggest actions itself, or does it need instructions?
It can work proactively: using email, task management and calendar integrations to prepare daily plans or meeting summaries
What happens when AI lacks the data needed to answer?
Instead of inventing an answer, TWIN:DESK records the gap in the Knowledge Gap Register. Managers get a concrete indication of which procedures and instructions need updating
Can an assistant be limited to one department's processes?
Yes. Dedicated workspaces provide their own avatar, system-prompt guidelines and assigned tools, such as a code interpreter for the IT department
What is a Cognitive Digital Twin?
A personal AI agent that learns how a user works and uses their knowledge, documents and activity history. It helps automate repetitive tasks and prepare recommendations — within the oversight boundaries set by the organisation
What is the local agent in TWIN:DESK for?
It enables use of the user's personal knowledge sources: local folders, Outlook email, Microsoft Teams and calendars. AI works with them locally, without copying sensitive data into a central RAG knowledge base
How is TWIN:DESK different from ChatGPT Enterprise and Copilot?
ChatGPT Enterprise and Microsoft 365 Copilot run in the vendor’s cloud. TWIN:DESK can run as SaaS, on-premises or air-gapped, answers from your organisation’s documents with source citations, matches the model to the confidentiality of the task — including several models at once in the Model Council — and integrates with Polish systems such as EZD RP and KSeF 2.0
Does TWIN:DESK work with EZD RP and SharePoint?
Yes. TWIN:DESK connects to EZD RP and EZD PUW through its integration layer, and documents from SharePoint and Microsoft 365 can serve as a knowledge source for assistants — with user permissions preserved
How much does TWIN:DESK cost?
The price depends on the number of users, the deployment option (SaaS, on-premises or air-gapped) and the scope of integrations. Model usage is accounted for in Twin:Coin, with limits for teams. The Offer Builder prepares an initial quote
PROXY:AI
What is PROXY:AI, and why should IT deploy it?
It is the central control layer — one router for different AI models. It addresses shadow AI and protects the organisation against sensitive data leaks and uncontrolled costs
How does PROXY:AI protect budgets against deliberate cost inflation?
FinOps and Anti-DoW mechanisms set tenant and user limits, including protection against denial-of-wallet attacks
What about high-risk operations?
PROXY:AI supports human-in-the-loop oversight: a critical process pauses until the appropriate person authorises it
How can we show an auditor why the system used a particular model?
The immutable WORM audit log records the complete operational history: model, configuration, invocation cost and data needed to reconstruct the decision
How does PROXY:AI control AI agents' permissions?
The MCP Gateway lets agents use only explicitly assigned tools, such as Jira, and records an audit trail of their actions
Does PROXY:AI also check what models generate?
Yes. Model responses are scanned again for sensitive data and dangerous instructions
Can new security rules be tested without risk?
Yes. The dry-run panel allows ABAC rules to be tested on simulated traffic before production deployment
Will the system block personal data from being sent to the cloud?
Yes. The AI Firewall analyses data in under 50 milliseconds and neutralises items such as Polish national ID and tax numbers and email addresses before they leave the organisation's network
How does PROXY:AI reduce query costs?
Semantic caching serves repeated questions with similar meanings from the cache, without querying an expensive model again
How does PROXY:AI protect models against user attacks?
Real-time guardrails filter requests and block attacks such as prompt injection and jailbreaks
What if we want to move to a newer model?
Zero-Code Switch: change the primary model in PROXY:AI settings without rewriting business application code
How does the ABAC Gateway differ from ordinary API access?
It does not admit requests blindly. For every request, it evaluates who is asking, from which environment, using which data and at what risk — then allows, restricts or blocks the operation
How is PROXY:AI different from Azure API Management, Cloudflare AI Gateway and LiteLLM?
Azure API Management and Cloudflare AI Gateway are gateways tied to a single vendor’s platform, and LiteLLM is open-source routing software that the organisation extends and maintains itself. PROXY:AI runs in the cloud, on-premises and air-gapped, and beyond routing it adds an AI firewall with data masking in 12 languages, ABAC evaluation, an MCP gateway for agents, a WORM register with evidence packs and budgets
Does PROXY:AI work with Bielik and PLLuM?
Yes. PROXY:AI supports local models, including Bielik and PLLuM, alongside cloud models. A policy decides which model is used — for example, requests containing confidential data go only to a local model
Working with us
Do you sign an NDA before the first call?
Yes, if you need one. We can use your template or provide ours — mutual, without exclusivity clauses or restrictions on your contacts with other providers. Many initial conversations take place without an NDA: we discuss architecture, regulations and our approach, rather than your data. When we move on to documents, processes or access to environments, an NDA is a requirement — on our side too
Can SAIE run fully on-premises without internet access?
Yes — this is one of the deployment patterns SAIE was designed for. Language models, the knowledge base, logs and agent orchestration run in your server room or an isolated network; model updates and patches are brought in on physical media under an agreed procedure. We use open models, including Polish models, so there is no dependency on an external API or telemetry sent to a provider. We use this approach in classified environments, defence and critical infrastructure — whether you need it depends on data classification and regulatory requirements, not trends
Do you participate in technical dialogue under Polish public procurement law?
Yes, and we treat it as a substantive project stage, not a formality. We respond to RFIs and RFPs, participate in technical and competitive dialogues, and map contracting authorities’ requirements to SAIE capabilities and obligations under the AI Act and the Polish Act on Artificial Intelligence Systems — so that the procurement specification can be drafted without the risk of invalidation. If you represent a contracting authority, we help formulate technology-neutral criteria for sovereignty, security and business continuity. We know the Ministry of Digital Affairs’ model clauses for AI procurement and structure our responses accordingly
How long does a Proof of Value take and what is delivered?
Usually 4–8 weeks, covering one jointly selected process and using your data — not demonstration data. We start by defining measurable success criteria (handling time, accuracy, the percentage of answers requiring correction) and finish by measuring them. You receive a report comparing results with the criteria, an assessment of risks and regulatory requirements for production deployment, an estimate of operating costs and a recommendation: scale up, change the scope or stop. “Stop” is an equally valid result — it saves a budget that would otherwise go towards production without evidence of benefits
Which language models do you support, including Polish ones?
Yes — Polish open models are our starting point, not an optional extra. We run the entire Bielik family locally (SpeakLeash and ACK Cyfronet AGH; 1.5B, 4.5B and 11B, Apache 2.0 licence), PLLuM models from the HIVE AI consortium led by NASK (PLLuM-12B and Llama-PLLuM 8B and 70B, including versions permitted for commercial use), and, where clients require them, Qra (OPI PIB and Gdańsk University of Technology) and Trurl (Voicelab). We also support international open models (Llama, Mistral, Qwen, Gemma) and, where data classification permits, commercial models accessed through APIs. We select models for the task and security requirements — different models for classifying correspondence, talking to employees or analysing documents — and test them on your data, not rankings. SAIE architecture lets you replace a model without rebuilding the rest of the system, so the decision is not permanent
Do you provide training for public institutions and state-owned companies?
Yes. We deliver open and dedicated training — from two-hour management workshops (“what the AI Act and the Polish Act on AI Systems mean for our organisation”) to programmes for teams using AI every day: safe use of tools, assessing whether deployment is justified using the Ministry of Digital Affairs’ Guide, and preparing an AI policy. Our materials draw on applicable regulations and what you will actually encounter in your institution or company, rather than examples from abroad. Dedicated training is delivered at your premises or remotely, with the option to procure it under Polish public procurement law
How do we book a demonstration?
Use the contact form and select the “Demonstration” topic. The meeting takes place in MS Teams
What does support look like after deployment?
We deliver software and services to a business / enterprise standard with full support, and tailor the scope of service to your needs. For organisations that want to maintain AI quality on an ongoing basis, we offer CogOps ongoing support: a monthly AI quality report, a compliance review and an up-to-date agent register
Will we receive the software source code?
Yes — the software code and training stay with the client, which ensures continuity without vendor lock-in. The form and scope of the handover are agreed in the contract
Training
How do we register for a course and how long does the whole process take?
You complete the form on the page: requester details, institution name and the selected courses with dates and number of participants. After submitting, you receive a copy of the registration and a proforma invoice (for paid training) at the e-mail address provided. Three days before the first day of training we send participants the link to the course
Who may register participants — must it be a person authorised to represent the institution?
Any person from the institution may submit a registration from a business e-mail address. For paid orders, please pay the proforma invoice you receive before the training date — this is a condition of participation
How does the free September–October edition work and who must subscribe to the newsletter?
For September and October dates, the first 5 people from one institution attend each course free of charge. The only condition: the requester subscribes to the allclouds.pl newsletter (one consent per registration, not every participant). Consent can be withdrawn at any time, including after the training. The newsletter contains information about upcoming dates, new materials and changes in regulations on AI in public administration — with no advertising of third-party products
What if we want to register more than 5 people for one course in the free edition?
Places from the sixth onwards are charged according to the November and December 2026 price list. For a group of 6–10 people the rate is PLN 170 net per paid place. Example: 8 people on one course in September cost 5 × PLN 0 + 3 × PLN 170 = PLN 510 net. The total number of people from one institution in a group may not exceed 18
Can one institution use free places on each of the eight courses?
Yes. The limit of 5 free participants applies to each course separately, so one institution can train up to 40 person-courses free of charge, including the same person on several courses. The only limit is the number of places in a group — registrations are accepted in order of submission
What happens after we submit the form — when and in what form do we receive confirmation?
After submitting the form you receive a confirmation of your registration at the e-mail address provided. For paid orders, the same e-mail includes a proforma invoice to be paid before the training. Three days before the first day of training we send participants the link to the course
Can we change the date or a participant after the registration is confirmed?
Yes, free of charge. A participant can be replaced by another person from the same institution up to the start of the training. Moving to another date from the calendar is possible up to 5 business days before the training, provided there are free places on the new date. Just send an e-mail to office@allclouds.pl
Until when can we cancel without charge?
Cancellation is possible up to 5 business days before the first day of training; after that we offer a change to another date or another participant instead of charging a fee
Can we order several courses in one registration, with different dates and numbers of participants?
Yes — the form lets you add any number of items, each with its own date and number of participants (e.g. 01 Foundations for 5 people in September and 03 Security for 3 people in October). The price is calculated automatically, and everything goes onto one confirmation and, for paid orders, one invoice
How do we order the complete path or a path for a selected role?
It is best to prepare such an order by selecting the courses one by one in the registration form. This lets you choose convenient dates for each course
When do you issue an invoice and when is payment due?
We issue a proforma invoice after receiving the registration. After receiving payment we issue a VAT invoice. On request, we split the VAT invoice by organisational unit
Are prices net or gross, and can training be VAT exempt?
We show net and gross prices on the page. Training financed entirely from public funds (Article 43(1)(29)(c) of the VAT Act) or at least 70% from public funds (§ 3(1)(14) of the Minister of Finance Regulation of 20 December 2013) is VAT exempt — in that case the gross price equals the net price. In practice, an institution financing training from its own budget selects the 100% option. The declaration template you receive with the order confirmation includes both options. If this applies to you, please complete, sign and return the declaration to office@allclouds.pl
Do participant-number discounts combine with the complete-path discount?
Yes. A team of 6–10 people on the complete path pays PLN 1,280 − 15% = PLN 1,088 net per person; a team of 11–18 people pays PLN 1,280 − 25% = PLN 960 net. Discounts are calculated from the number of people from one institution on a given course, not from the total number of people in the order
Which documents can we receive for the procurement request?
Whatever you need to carry out the procurement in line with your institution's procedures, for example: an offer, the training programme with a schedule, an order template, a template declaration of public funding, a GDPR information notice and — on request — company information (KRS, NIP, ISO 9001, ISO 14001, ISO 22301, ISO/IEC 27001, 27017, 27018 and 42001 certificates)
Do you sign contracts based on the institution's template and handle orders below the PLN 170,000 threshold?
Yes. We usually deliver training under an order or contract from the institution below the threshold of the Polish Public Procurement Act (PLN 170,000 net from 1 January 2026) — in line with your procurement rules. We accept the institution's contract templates after review; we also have our own one-page template
Which platform is used and do participants need to install anything?
Sessions take place online in MS Teams. A browser and the link we send before the training are enough; no accounts or software installation are needed. For exercises we use AI tools available in the browser. If your institution's security policy blocks certain services, please let us know when registering — we will choose an option that works on your network
Why is the course split into three days of 80 minutes, and can someone attend only one day?
Three 80-minute blocks on consecutive business days (always 10:00–11:20) are a deliberate choice: employees are not away from work for a whole day, and between blocks they have time to apply the material to their own tasks and come back with questions. The blocks form one whole and end with a shared document, so we do not sell individual days. If a participant misses a block, they can make it up on the next date of the same course at no extra cost
What are the minimum and maximum group sizes, and what happens if a group does not fill up?
A group has 8 to 18 people — small enough for the instructor to work with every participant, large enough to share experience between institutions. If fewer than 8 people are registered 3 business days before the date, we offer the nearest other date or — for registrations from one institution — a closed session. We never cancel a course without offering an alternative
Are sessions recorded and is the recording shared with participants?
We do not record sessions. Participants discuss examples from their own institutions freely, which requires certainty that the conversation stays within the group. Instead of a recording, participants receive materials, templates and a summary of each block
Are participants from different institutions in one group?
Yes, groups on open dates are mixed — deliberately, because sharing experience between institutions is one of the most highly rated parts of the training. The instructor makes sure protected information is not discussed; exercises use anonymised examples or examples we prepare. If you prefer a group made up only of your own institution, please order a closed course
What does a participant receive after the training?
Each participant receives: course materials in PDF, templates of the documents developed during the workshop (e.g. task map, checklist, tool register, pilot charter) and a named certificate of attendance listing the programme
Which AI tools are used in the exercises, and does the institution need its own licences?
Exercises use browser-based tools, our products and various large language models, including the Polish models PLLuM and Bielik. The institution does not need to buy any licences — we provide access to the exercise environment for the duration of the training
Is the institution's data entered during exercises, and how do you keep it secure?
No. Exercises use examples we prepare or anonymised materials, and one of the first things we teach is what must not be entered into AI tools. The allclouds exercise environment runs on infrastructure in Poland, and the company holds ISO/IEC 27001, 27017, 27018 and ISO/IEC 42001 (AI management system) certificates. Registration data is processed solely to deliver the training
What is “the document that is produced”, and can the institution use it formally?
Each course ends with a concrete working document that participants complete during the workshop for their own institution — e.g. a task map and checklist (01), a source catalogue (02), draft rules for using AI (03), a pilot charter (04). The documents follow the structure of the Ministry of Digital Affairs' guide and are prepared so that they can become an annex to an internal order, procedure or pilot request. The institution receives them in an editable format and may modify them freely; they require no licence or reference to allclouds
Does the training meet the AI literacy obligation under Article 4 of the AI Act, and how can this be documented?
Article 4 of the AI Act requires deployers of AI systems to ensure a sufficient level of AI literacy among their staff, taking into account the context of their work. The training programme covers the three competences indicated in the Ministry of Digital Affairs' guide: understanding the limitations of AI, critical evaluation of results and formulating instructions. Documentation consists of a named certificate listing the programme, the training programme and the document developed during the workshop. We are not a law firm — the final assessment of whether the scope is sufficient for a specific role is made by the institution, but we prepare the materials to make that assessment easier
Who delivers the training and what experience do they have with public administration?
The training is delivered by people who have designed and implemented AI solutions in institutions from regulated sectors and co-created the CDF methodology and the ISO/IEC 42001-certified AI management system
Can we order a closed course for one institution, on its own date or on-site?
Yes. We deliver closed courses online on a date agreed with the institution (group of 8–18 people). In the closed version, exercises are based on your institution's processes and documents (after anonymisation), and the resulting document refers directly to your structure. Pricing is individual — please write to us through the form, marking “closed course”
Can the programme be tailored to the institution?
On open dates the programme is fixed, but we choose examples to match the group (municipalities, districts, regional offices, central administration) and ask about the type of institution in the form. Course 06 has a separate variant for regional and central offices (internal assistant), and course 08 is designed for groups from several institutions. Full tailoring (your own processes, your own documents) is available in closed courses
Is consultation or support available after the training for implementing the documents developed?
Yes, at three levels: 30 days of e-mail consultation included in the price, paid implementation consultations (e.g. a review of a draft internal order or pilot charter with the instructor) and a pilot following the CDF methodology in the SAIE environment for institutions that want to test the solution on their own documents. Attending the training does not oblige you to take any of these options — the documents you develop belong entirely to you
Industries
Can civil servants use publicly available AI tools?
Only if the office has approved them: it has a contract with the provider, knows where the data goes and has trained its staff. A public chatbot on a private account does not meet these conditions, and the office is responsible for the data entered. It is safer to give civil servants a tool that runs in the office’s infrastructure or in a controlled cloud in Poland or the EU
How can you use AI without breaching GDPR?
Personal data may go only to tools covered by a data processing agreement and control over data location. PROXY:AI masks personal data before a query reaches the model and records every query in a log. TWIN:DESK can run entirely in the office’s infrastructure
Who is responsible for errors in content prepared with AI?
The civil servant who used it, and the office as the deployer of the AI system. That is why every TWIN:DESK answer includes a citation from the source, and the AI use policy sets out who checks the output before a letter is sent
Where should a public office start?
With an inventory of tools, an AI use policy and training for civil servants. Then a pilot on one process, e.g. draft replies in EZD (electronic document management system)
How can you limit hallucinations in banking applications?
By answering only from approved documents, with a source citation, and through human oversight of the decision. TWIN:DESK answers based on the organization’s documents with a citation, and PROXY:AI lets you route tasks to models proven in a given use case
How do you assess an AI provider and avoid concentration?
By being able to swap the model without rebuilding the process. PROXY:AI provides a single gateway to more than 100 models, both cloud and local. Changing a model is a configuration change, not a new deployment
How do you include an AI provider in the register of ICT contractual arrangements (DORA)?
Like any ICT service provider supporting important functions: with a risk assessment, an exit plan and information on data location. The WORM log in PROXY:AI documents which models processed data and when
Who is responsible for AI-supported decisions?
The doctor who makes the decision, and the facility as the deployer of the system. AI in SAIE prepares summaries and draft documents with a source citation, and a human always approves the decision
Can the system run entirely within the facility?
Yes. TWIN:DESK and PROXY:AI run on-premises, in the facility’s infrastructure, with local models
How do you divide responsibilities between the director, the DPO, the CISO and the provider?
The director is responsible for the deployment decision and the policy, the DPO (data protection officer) for the legal bases for data processing, the CISO for security and compliance with the KSC Act, and the provider for system documentation and support. The CDF methodology includes templates for these roles and registers
Does data leave the EEA?
Not unless the firm decides so. TWIN:DESK runs on-premises or in a cloud with data located in Poland or the EU, and PROXY:AI lets you allow only models that run locally or in the EU
Will our data be used to train models?
No, if the firm uses local models or providers whose contracts exclude training on client data. PROXY:AI lets you allow only such models and masks personal data before a query is sent
Does the tool provide adequate protection within the meaning of § 23e?
The assessment is up to the firm. SAIE gives it the basis for one: control over data location, case-level permissions, a log of who processed documents and when, and documentation to demonstrate due diligence
What legal framework ensures a safe deployment?
The AI Act, the amended KSC Act (NIS2) and an internal AI policy linked to the information security management system. The CDF methodology guides you through the Initial Assessment, the classification of use cases and documents you can show an auditor
On-premises or cloud AI?
For critical infrastructure data — on-premises. At LW Bogdanka, TWIN:DESK runs entirely in the client’s infrastructure, with no data going outside, and the deployment took two months
How do you organize historical data and access to it?
Start with the documents people search for most often, e.g. operating and emergency procedures, and assign permissions by department. At LW Bogdanka, about 80% of the knowledge base consisted of scans, which TWIN:DESK processed for search with citations
Are AI decisions traceable?
Yes. Every query and answer goes to the WORM log in PROXY:AI, and TWIN:DESK answers include a source citation
Does the solution ensure control over the technology?
Yes. Models run locally, code and configuration stay with the client, and the list of approved models and components is under the operator’s control
Does it work in an isolated server farm?
Yes. PROXY:AI with local models runs in air-gap mode, without an internet connection. We carry out deployments in classified environments together with integrators authorized for such work
How do you get the use of unauthorized AI tools under control?
Not with a ban, but with a safe tool, a policy and training. PROXY:AI routes traffic to approved models, masks data and records queries, and training teaches staff what must not be entered
How can you limit hallucinations?
By answering only from service documents, with a source citation, and by checking the output before use
For which document tasks is AI safe?
For summaries, searching procedures, and drafting notes and reports — always with human verification. Not for autonomous decisions concerning individuals
Is our tool an “AI system” under the AI Act?
This is decided by the definition in Article 3(1) of the AI Act: a system that infers from the input it receives how to generate outputs. The Initial Assessment in the CDF methodology classifies each use case and documents the rationale
Where is data processed, and can it be audited?
In the institution’s infrastructure or in a chosen cloud in Poland or the EU. The WORM log in PROXY:AI shows who processed data, when and with which model
How do you preserve the evidential value of findings when using AI?
By separating roles: the language model searches and summarizes with citations, and calculations are performed by deterministic tools. Every result can be reproduced from the log
Are our systems (SCADA, leak detection) high-risk systems?
AI that serves as a safety component in the management of water supply is listed in Annex III to the AI Act. The Initial Assessment in the CDF methodology settles this for each use case
Does the AI tool meet the NIS2 supply chain requirements?
SAIE provides the documentation needed to assess the supplier: data location, a processing log, the manufacturer’s ISO/IEC 27001 and 42001 certificates and an exit plan
How do you link the AI policy to the information security management system?
The AI policy becomes part of the ISMS: the same roles, asset register and review. Templates for the policy and registers are in the WDR documents
How do you control the AI used by the operator’s employees?
Through a single gateway: PROXY:AI replaces scattered API keys and provides team budgets and a WORM log of every query
Which AI application layer should you build on your own cloud?
TWIN:DESK and PROXY:AI run on the operator’s infrastructure and can serve customers as a service
What can you offer regulated customers beyond infrastructure?
A ready-to-use AI work environment with evidence of compliance — in the allclouds.pl partner program
Where may generative AI be used in a GMP environment?
The draft Annex 22 allows it in non-critical applications, under human oversight, and excludes it from quality-critical applications. Until the final text is published, working with documentation, summaries and search with citations is safe
How do you validate an AI tool and maintain data integrity?
By defining its intended use, testing it on reference data and keeping a full trail: who processed data, when and with which model (the WORM log in PROXY:AI)
How do you find out where employees are already using AI without your knowledge?
Through an inventory and a single gateway to models. Traffic routed through PROXY:AI shows who uses AI and for what
What client data must not be put into ChatGPT?
Tools without a data processing agreement and control over data location should not receive personal data, identification numbers, clients’ financial data or documents covered by professional secrecy. The AI use policy template includes a catalog of such data
Who is liable for an AI error, e.g. in a VAT rate?
The accounting firm, toward its client. AI prepares a proposal citing the relevant provision, and the accountant approves it
How do you write an AI policy for an accounting firm?
Based on the AI use policy template: approved tools, a data catalog, responsibility for the output and training
Can we put client documents into AI tools?
Only into approved tools, with a contract and control over data location, and only to the extent permitted by the contract with the client. In SAIE, each client’s data sits in a separate area with its own permissions
Who is responsible for AI-assisted output?
The consulting firm, toward its client. AI prepares material with a source citation, and the expert is responsible for the conclusion
Will the data stay in Poland?
Yes, if you decide so: on-premises or in a cloud with data located in Poland
Who does the CRA apply to?
Manufacturers, importers and distributors of products with digital elements placed on the EU market, including controllers and devices with software
Can you program PLCs with AI without sending out the client’s project?
Yes. Local models in SAIE are used within the company’s infrastructure, so code and documentation do not go to external services
How do you prepare to report vulnerabilities within 24 hours?
With a list of products and components, a reporting procedure and access to documentation in one place. TWIN:DESK answers with citations from technical documentation, which shortens the time needed to establish which products a vulnerability affects
From when must AI-generated content be labeled?
From 2 August 2026 (Article 50 of the AI Act). For systems placed on the market before that date, machine-readable marking is required by 2 December 2026
Does text under editorial control need to be labeled?
Text published to inform the public on matters of public interest does not need to be labeled if it has undergone editorial review and a person or newsroom holds responsibility for the publication (Article 50(4)). It is worth documenting this review
Who is responsible for labeling — the agency or the brand?
The entity that publishes the content, as the deployer of the AI system. It is worth setting out the scope in the contract with the agency
Can a researcher enter unpublished results into an AI tool?
Only into a tool that runs in the university’s infrastructure or guarantees that the data is not stored or used for training. PROXY:AI lets you use local models, including Bielik and PLLuM
How should AI in teaching be regulated?
Through a university policy that sets out the disclosure of AI involvement in student work, grading rules and approved tools
What AI tools should researchers get?
A shared gateway to local and cloud models with budgets for faculties and units, and for administrative staff — an assistant that answers from internal regulations with a citation
Where to start: what problem are we solving and how much is the loss costing us today?
With one process with a measurable loss, e.g. time spent searching for instructions or manual reporting. The Initial Assessment in the CDF methodology selects the use case and sets the criteria for the decision after the pilot
What data is needed?
Documents are enough to start: instructions, standards, service reports. TWIN:DESK also processes scans
What happens after an AI alert?
A human makes the decision. AI points to the source and proposes steps, and every action is recorded
When does EUDR apply, and how do you document due diligence?
From 30 December 2026 for large and medium-sized companies, and from 30 June 2027 for micro and small companies. You need geolocation data and documents from suppliers — TWIN:DESK organizes them and answers with citations
What ESG data will customers demand?
Most often data on emissions, the origin of raw materials and EUDR compliance. It is worth collecting it in one place from which you can quickly prepare a response for the customer
How do you transfer data from orders and CMR documents to the TMS?
Document agents in TWIN:DESK read data from documents and prepare it for the system, and a human approves the result before it is saved
How do you keep drivers’ and customers’ data secure?
Through a single gateway to models with personal data masking (PROXY:AI) and permissions by branch
Where should the decision be left to a human?
Wherever the outcome affects a customer or a driver: accepting a complaint, contractual penalties, carrier evaluation
How does AI help car dealers and service centres?
TWIN:DESK answers advisors’ questions from technical documentation, bulletins and warranty terms with the source cited, and agents prepare warranty claims and complaint responses. A human decides whether to accept a warranty claim
Regulations and choosing AI
Who enforces the AI Act in Poland?
The Commission for the Development and Security of Artificial Intelligence (KRiBSI). From 28 October 2026 it can carry out inspections, handle complaints and impose fines
What fines apply for breaching the AI Act?
Up to €35m or 7% of turnover for prohibited practices, up to €15m or 3% of turnover for other obligations and up to €7.5m or 1% of turnover for incorrect information. SMEs pay according to the lower of the two amounts
Does the act apply to public bodies?
Yes. A public body that uses AI systems at work is a deployer under the AI Act — it must ensure staff AI literacy, transparency and, from 2.12.2027, the obligations for high-risk systems, including a fundamental rights impact assessment. The act sets no separate fine rules for public bodies — fines are imposed on any entity obliged to comply with the AI Act (Art. 104)
What should we do before 28 October 2026?
List the AI systems used in your organisation, check them against prohibited practices, adopt an AI use policy, train your staff and decide how you label AI-generated content
Is an employee using ChatGPT at work already “deploying an AI system”?
Yes — at work the deployer is the organisation, not the employee. That is why the tool should be in the inventory and covered by the policy and training. An employee’s statement that they use AI “at their own risk” transfers nothing
Is an AI use policy mandatory?
The AI Act does not name such a document, but it requires deployers to ensure, among other things, staff AI literacy (Art. 4) and transparency (Art. 50). ISO/IEC 42001 requires an AI policy. Whether it is called a policy or AI usage rules does not matter; what counts is the content and the tools behind it. Without written rules these obligations are hard to prove during an inspection
Is it enough to ban staff from using ChatGPT?
A ban with no company alternative usually moves usage to private phones and accounts, i.e. into shadow AI. It is more effective to approve a safe tool with data controls and logging
Does the policy apply to B2B contractors?
It should. Labour law does not cover them, but the AI Act, GDPR and ISO standards apply to the organisation in the same way, whatever the form of engagement. The rules are worth including in contracts
What data must not be entered into AI tools?
It depends on the tool and the contract with the provider. Tools without a data processing agreement and control over data location should not receive personal data, trade secrets, client data or information protected by law. The template includes a list to tailor
Who should approve the policy?
The management board or head of the organisation, after consulting the DPO, information security and — where one exists — employee representatives
What is shadow AI?
The use of AI tools that the organisation has not approved and does not oversee, most often public chatbots on employees’ private accounts
Is using ChatGPT at work safe?
It depends on the version and the contract. On a private account the organisation has no contract with the provider, no say over data retention and no access to chat history. A tool approved by the organisation, with a contract, data controls and logging, is safe
Is it enough to block public chatbots?
A block with no company alternative moves usage to private devices. It is more effective to approve a safe tool and route traffic through an AI gateway
Who is liable when an employee pastes client data into a chatbot?
Towards the client and the supervisory authority — the organisation: it is the data controller under GDPR and the deployer under the AI Act. An employee’s statement that they use AI “at their own risk” transfers nothing
Where should a public office start?
With an inventory and a policy. Then a safe tool and training for staff — before a ban turns into a workaround
Bielik or PLLuM — which one for a public body?
For letters and official matters PLLuM is trained deliberately (Monitor Polski, the Journal of Laws, transcripts) and already runs in mObywatel and city halls. For general tasks — summaries, classification, chat — Bielik under Apache 2.0 has no licence restrictions. Behind a gateway you can have both and choose per task
Can a Polish model be used commercially?
Bielik — yes, all versions under Apache 2.0. PLLuM — it depends on the variant: the new models from May 2026 are under licences allowing commercial use, the older “‑nc” variants are non-commercial only. The licence is checked on the model card and entered in the system register
Do you need your own GPU server to run it?
Not always. Models up to 12 bn parameters run on one 24 GB card, Minitron 7B on a 6–8 GB card. Larger ones (PLLuM 70B) need a server with several cards — or a model at an operator in the EEA, available through the same gateway as local models
Does an open model exempt you from AI Act duties?
No. The deployer’s duties (register, literacy, prohibited practices, transparency) concern the use of the system, not its licence. An open model makes documentation easier — there is a model card and training data — but the register entry and the use policy are on the organisation’s side
Is a Polish model worse than global ones?
In general multilingual tasks — usually yes, because it is smaller. In Polish official and legal language PLLuM and Bielik often answer more accurately than global models of the same class, and the data does not leave the organisation. In practice both approaches are combined behind one gateway
Is ChatGPT Enterprise compliant with the AI Act?
The AI Act does not certify assistants. The deployer’s duties — system register, literacy, content labelling, no prohibited practices — rest with the organisation regardless of the chosen service. The provider can help with documentation, but the organisation gathers the evidence
Does Copilot send company data outside the organisation?
Processing takes place in the provider’s cloud, within the organisation’s tenant and under the provider’s contract terms (region, no training). For an organisation with an on-premises requirement, or one that cannot entrust data to an external processor, this criterion decides before the price does
Does your own AI environment mean building from scratch?
No. Your own environment is a ready platform — a model gateway, an assistant on documents, a log — deployed in the organisation’s infrastructure or at an operator in the EEA. It differs from open source in service, contract and methodology; from provider services in that the data and processes stay in the organisation
How do you compare the cost of a subscription and your own environment?
Over the same horizon (3 years) and the same components: licences or models, infrastructure, maintenance, competences, deployment time and exit cost. The licence price per user is one of six elements
How can you tell that an assistant made up an answer?
By the lack of a source. A language model answers fluently even when it has no data — hence non-existent articles of law and dates. An assistant working on the organisation’s documents (RAG) gives a citation and the place in the document; no source, no answer. The quiz in section 06 shows this on five pairs
Does a public office need an AI use policy?
Yes, if officials use AI tools — including private ones — with the office’s documents. As a deployer, the office is responsible for citizens’ data (GDPR) and for staff training (Art. 4 of the AI Act). The same template only needs adapting: the office’s document types, the approved tools and the person who approves the output