allclouds.pl
Knowledge

Poland’s AI Systems Act: what companies and public bodies must be able to prove from 28 October 2026

The Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026 item 1003) is the Polish law that establishes the AI supervisory authority and the rules for inspections, complaints and fines for breaches of the EU AI Act. From 28 October 2026 the Commission for the Development and Security of Artificial Intelligence can inspect companies and public bodies and impose fines

28.10.2026audits and fines
10sections
Journal of Laws 2026item 1003
3.10.2026legal status
01 / 10

What the act is

The obligations for AI systems themselves come from the EU AI Act (Regulation 2024/1689), which applies directly in Poland. The act does not add a new list of requirements. Instead, it provides the means to enforce them: a supervisory authority, inspections, complaint handling, fines, individual opinions and a regulatory sandbox

The act does not cover people who use AI purely for private purposes. When an employee uses an AI tool at work, the organisation is the deployer of the AI system — and it is responsible for compliance

OFTEN CONFUSED

The AI Act is not the same as the AI Systems Act

AI Act

AI Act: EU Regulation 2024/1689, directly applicable in Poland; it is the source of obligations for AI systems themselves

vs
Polish AI Systems Act

AI Systems Act: the Polish act (Journal of Laws 2026 item 1003) adds no new list of requirements; it provides the means to enforce them: supervisory authority, inspections, complaints, fines, individual opinions and a regulatory sandbox

0

The Act adds not a single new duty for AI systems — all of them come from the AI Act. It adds an authority which, from 28.10.2026, will check whether you can prove them

02 / 10

Timeline

DateWhat starts to applyLegal basis
2.02.2025AI literacy (Art. 4) and the ban on prohibited practices (Art. 5)AI Act
2.08.2026Transparency obligations (Art. 50), including labelling of deepfakes and AI-generated content. For generative systems placed on the market before that date, machine-readable marking is due by 2.12.2026AI Act, Regulation 2026/1744
11.08.2026The main part of the act enters into forceJournal of Laws 2026 item 1003
by 11.10.2026Appointment of the KRiBSI chair by the Sejm with the Senate’s consentAct, Art. 125(2)
28.10.2026Inspections, complaints and administrative fines — KRiBSI can enforce the AI ActAct
by 11.11.2026First KRiBSI meetingAct, Art. 125(3)
2.12.2027Obligations for high-risk systems in Annex III (e.g. recruitment, creditworthiness, access to public services) — moved from 2.08.2026AI Act, Regulation 2026/1744
2.08.2028Obligations for high-risk systems in Annex I (AI in regulated products, e.g. medical devices, machinery)AI Act, Regulation 2026/1744
03 / 10

Who supervises

The market surveillance authority and national contact point is the Commission for the Development and Security of Artificial Intelligence (KRiBSI). It consists of a chair, two deputies and four members nominated by the heads of UOKiK, KNF, KRRiT and UKE (Art. 19). The Commission is supported by the minister responsible for digital affairs

KRiBSI can:

1

carry out inspections, including remote ones, and request documents and access to systems

2

handle complaints about AI systems from individuals, companies and institutions

3

impose fines and issue warnings, e.g. ordering employees to be informed that an AI system is in use

4

issue individual opinions and run a regulatory sandbox

04 / 10

Obligations — what you need to be able to prove

ObligationFromHow to prove it
Inventory of AI systems used in the organisation (the basis for all other obligations)nowRegister: system, provider, purpose, data, business owner, risk assessment
Staff AI literacy (Art. 4)2.02.2025Role-based training programme, attendance list, materials
No prohibited practices (Art. 5)2.02.2025Assessment of every use case in the register against Art. 5
Transparency (Art. 50): labelling deepfakes and content published in the public interest, informing people about emotion recognition2.08.2026Labelling procedure, label templates, publication log
AI use rules and control of tools outside the inventory (shadow AI)nowAI use policy, blocked or replaced tools, usage logs
Obligations of a deployer of a high-risk system (Art. 26), including human oversight, logs and informing employees2.12.2027Provider instructions, designated oversight staff, retained logs, notice to employees
Fundamental rights impact assessment (Art. 27) — public bodies and selected private deployers of high-risk systems2.12.2027Assessment report before the system goes live
05 / 10

What you must be able to prove by 28.10.2026

Two questions — duties that apply to your organisation and the evidence an inspection will ask for

Tool · list of duties

Check your own organisation

Instant result · no e-mail
1 · What kind of organisation
2 · How you use AI
?

Choose the type of organisation and how you use AI — the list of duties with evidence appears immediately, nothing is sent anywhere. Basis: the AI Act and the Polish AI Systems Act (as of 3.10.2026)

An indicative list based on the AI Act and the Act — the scope of duties depends on the specific systems; it does not replace legal adviceLegal status: 3.10.2026
06 / 10

Is your AI system high-risk

Three questions — the AI Act risk class and the duties that follow from it, with dates and legal basis

Tool · AI Act classifier

Classify the system

Instant result · no e-mail
1 · What area does the system work in
2 · How does it affect a decision about a person
3 · Is it a narrow or auxiliary task (Art. 6(3) exception)
?

Choose the area, the impact on the decision and the type of task — the risk class and the list of duties appear immediately, nothing is sent anywhere. Basis: Art. 6 and Annex III of the AI Act (as of 3.10.2026)

Indicative classification based on Art. 6 and Annex III of the AI Act — the class depends on the specific use; it does not replace legal adviceLegal status: 3.10.2026
07 / 10

Fines

Fine levels are set by the AI Act (Art. 99):

For large companies the higher of the two amounts applies; for SMEs and start-ups, the lower. Euro amounts are converted into zloty at the NBP average rate of 28 January of the given year (Art. 104)

The act provides three ways to reduce a fine:

No reduction applies if the breach led to death or serious harm to health. A fine can be paid in instalments or deferred. Decisions can be appealed to the Regional Court in Warsaw — Court of Competition and Consumer Protection (Art. 109)

MAXIMUM FINES · ART. 99 AI ACTHigher value for large companies · lower for SMEs
35€m

€35m — or 7% of global turnover — prohibited practices (Art. 5): manipulation, social scoring, emotion recognition at work [highest threshold]

15€m

€15m — or 3% of turnover — other duties, including transparency (Art. 50) and deployer duties (Art. 26) [most common case]

7.5€m

€7.5m — or 1% of turnover — false or incomplete information given to the authority during an inspection [also for silence]

THREE WAYS TO REDUCE A FINE
THEACT, ARTS. 70, 84, 107 — 10–50% actions from the warning within 3 months of the decision (Art. 107)
20–70%settlement with the Commission: ending the breach and disclosing all circumstances (Art. 70)
30–90%settlement after self-reporting the breach (Arts. 70 and 84)
Amounts in euro are converted to zloty at the NBP average rate of 28 January of the given year (Art. 104) — a fine may be paid in instalments or deferred · Appeal: Regional Court in Warsaw (Art. 109) · below the block: No reduction applies where the breach caused death or serious harm to health
08 / 10

How to prove it with SAIE

The requirements are the same for everyone, but the evidence has to be your own. In SAIE it is produced as part of everyday work:

PROXY:AI

a single gateway to models: an inventory of models in use, access policies, personal data masking and a WORM log of requests. Tools outside the inventory can be replaced with safe access instead of a ban

TWIN:DESK

answers from your organisation’s documents with source citations, i.e. a trail of what each result was based on

CDF methodology and WDR documents

initial assessment and AI Act audit, AI policy and registers

AI training

an Art. 4 literacy programme for public administration and companies

FAQ

Questions about the Polish AI Systems Act

Who enforces the AI Act in Poland?

The Commission for the Development and Security of Artificial Intelligence (KRiBSI). From 28 October 2026 it can carry out inspections, handle complaints and impose fines

What fines apply for breaching the AI Act?

Up to €35m or 7% of turnover for prohibited practices, up to €15m or 3% of turnover for other obligations and up to €7.5m or 1% of turnover for incorrect information. SMEs pay according to the lower of the two amounts

Does the act apply to public bodies?

Yes. A public body that uses AI systems at work is a deployer under the AI Act — it must ensure staff AI literacy, transparency and, from 2.12.2027, the obligations for high-risk systems, including a fundamental rights impact assessment. The act sets no separate fine rules for public bodies — fines are imposed on any entity obliged to comply with the AI Act (Art. 104)

What should we do before 28 October 2026?

List the AI systems used in your organisation, check them against prohibited practices, adopt an AI use policy, train your staff and decide how you label AI-generated content

Is an employee using ChatGPT at work already “deploying an AI system”?

Yes — at work the deployer is the organisation, not the employee. That is why the tool should be in the inventory and covered by the policy and training. An employee’s statement that they use AI “at their own risk” transfers nothing

All questions →

https://www.allclouds.pl/en/wiedza/ustawa-o-systemach-sztucznej-inteligencji/