carry out inspections, including remote ones, and request documents and access to systems
Poland’s AI Systems Act: what companies and public bodies must be able to prove from 28 October 2026
The Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026 item 1003) is the Polish law that establishes the AI supervisory authority and the rules for inspections, complaints and fines for breaches of the EU AI Act. From 28 October 2026 the Commission for the Development and Security of Artificial Intelligence can inspect companies and public bodies and impose fines
What the act is
The obligations for AI systems themselves come from the EU AI Act (Regulation 2024/1689), which applies directly in Poland. The act does not add a new list of requirements. Instead, it provides the means to enforce them: a supervisory authority, inspections, complaint handling, fines, individual opinions and a regulatory sandbox
The act does not cover people who use AI purely for private purposes. When an employee uses an AI tool at work, the organisation is the deployer of the AI system — and it is responsible for compliance
The AI Act is not the same as the AI Systems Act
AI Act: EU Regulation 2024/1689, directly applicable in Poland; it is the source of obligations for AI systems themselves
AI Systems Act: the Polish act (Journal of Laws 2026 item 1003) adds no new list of requirements; it provides the means to enforce them: supervisory authority, inspections, complaints, fines, individual opinions and a regulatory sandbox
The Act adds not a single new duty for AI systems — all of them come from the AI Act. It adds an authority which, from 28.10.2026, will check whether you can prove them
Timeline
| Date | What starts to apply | Legal basis |
|---|---|---|
| 2.02.2025 | AI literacy (Art. 4) and the ban on prohibited practices (Art. 5) | AI Act |
| 2.08.2026 | Transparency obligations (Art. 50), including labelling of deepfakes and AI-generated content. For generative systems placed on the market before that date, machine-readable marking is due by 2.12.2026 | AI Act, Regulation 2026/1744 |
| 11.08.2026 | The main part of the act enters into force | Journal of Laws 2026 item 1003 |
| by 11.10.2026 | Appointment of the KRiBSI chair by the Sejm with the Senate’s consent | Act, Art. 125(2) |
| 28.10.2026 | Inspections, complaints and administrative fines — KRiBSI can enforce the AI Act | Act |
| by 11.11.2026 | First KRiBSI meeting | Act, Art. 125(3) |
| 2.12.2027 | Obligations for high-risk systems in Annex III (e.g. recruitment, creditworthiness, access to public services) — moved from 2.08.2026 | AI Act, Regulation 2026/1744 |
| 2.08.2028 | Obligations for high-risk systems in Annex I (AI in regulated products, e.g. medical devices, machinery) | AI Act, Regulation 2026/1744 |
Who supervises
The market surveillance authority and national contact point is the Commission for the Development and Security of Artificial Intelligence (KRiBSI). It consists of a chair, two deputies and four members nominated by the heads of UOKiK, KNF, KRRiT and UKE (Art. 19). The Commission is supported by the minister responsible for digital affairs
KRiBSI can:
handle complaints about AI systems from individuals, companies and institutions
impose fines and issue warnings, e.g. ordering employees to be informed that an AI system is in use
issue individual opinions and run a regulatory sandbox
Obligations — what you need to be able to prove
| Obligation | From | How to prove it |
|---|---|---|
| Inventory of AI systems used in the organisation (the basis for all other obligations) | now | Register: system, provider, purpose, data, business owner, risk assessment |
| Staff AI literacy (Art. 4) | 2.02.2025 | Role-based training programme, attendance list, materials |
| No prohibited practices (Art. 5) | 2.02.2025 | Assessment of every use case in the register against Art. 5 |
| Transparency (Art. 50): labelling deepfakes and content published in the public interest, informing people about emotion recognition | 2.08.2026 | Labelling procedure, label templates, publication log |
| AI use rules and control of tools outside the inventory (shadow AI) | now | AI use policy, blocked or replaced tools, usage logs |
| Obligations of a deployer of a high-risk system (Art. 26), including human oversight, logs and informing employees | 2.12.2027 | Provider instructions, designated oversight staff, retained logs, notice to employees |
| Fundamental rights impact assessment (Art. 27) — public bodies and selected private deployers of high-risk systems | 2.12.2027 | Assessment report before the system goes live |
What you must be able to prove by 28.10.2026
Two questions — duties that apply to your organisation and the evidence an inspection will ask for
Check your own organisation
Choose the type of organisation and how you use AI — the list of duties with evidence appears immediately, nothing is sent anywhere. Basis: the AI Act and the Polish AI Systems Act (as of 3.10.2026)
Is your AI system high-risk
Three questions — the AI Act risk class and the duties that follow from it, with dates and legal basis
Classify the system
Choose the area, the impact on the decision and the type of task — the risk class and the list of duties appear immediately, nothing is sent anywhere. Basis: Art. 6 and Annex III of the AI Act (as of 3.10.2026)
Fines
Fine levels are set by the AI Act (Art. 99):
For large companies the higher of the two amounts applies; for SMEs and start-ups, the lower. Euro amounts are converted into zloty at the NBP average rate of 28 January of the given year (Art. 104)
The act provides three ways to reduce a fine:
No reduction applies if the breach led to death or serious harm to health. A fine can be paid in instalments or deferred. Decisions can be appealed to the Regional Court in Warsaw — Court of Competition and Consumer Protection (Art. 109)
€35m — or 7% of global turnover — prohibited practices (Art. 5): manipulation, social scoring, emotion recognition at work [highest threshold]
€15m — or 3% of turnover — other duties, including transparency (Art. 50) and deployer duties (Art. 26) [most common case]
€7.5m — or 1% of turnover — false or incomplete information given to the authority during an inspection [also for silence]
How to prove it with SAIE
The requirements are the same for everyone, but the evidence has to be your own. In SAIE it is produced as part of everyday work:
a single gateway to models: an inventory of models in use, access policies, personal data masking and a WORM log of requests. Tools outside the inventory can be replaced with safe access instead of a ban
answers from your organisation’s documents with source citations, i.e. a trail of what each result was based on
initial assessment and AI Act audit, AI policy and registers
an Art. 4 literacy programme for public administration and companies
Sources
- Act of 3 July 2026 on artificial intelligence systems, Journal of Laws 2026 item 1003
- Regulation (EU) 2024/1689 (AI Act)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
For information only, not legal advice. As of 3.10.2026
Questions about the Polish AI Systems Act
Who enforces the AI Act in Poland?
The Commission for the Development and Security of Artificial Intelligence (KRiBSI). From 28 October 2026 it can carry out inspections, handle complaints and impose fines
What fines apply for breaching the AI Act?
Up to €35m or 7% of turnover for prohibited practices, up to €15m or 3% of turnover for other obligations and up to €7.5m or 1% of turnover for incorrect information. SMEs pay according to the lower of the two amounts
Does the act apply to public bodies?
Yes. A public body that uses AI systems at work is a deployer under the AI Act — it must ensure staff AI literacy, transparency and, from 2.12.2027, the obligations for high-risk systems, including a fundamental rights impact assessment. The act sets no separate fine rules for public bodies — fines are imposed on any entity obliged to comply with the AI Act (Art. 104)
What should we do before 28 October 2026?
List the AI systems used in your organisation, check them against prohibited practices, adopt an AI use policy, train your staff and decide how you label AI-generated content
Is an employee using ChatGPT at work already “deploying an AI system”?
Yes — at work the deployer is the organisation, not the employee. That is why the tool should be in the inventory and covered by the policy and training. An employee’s statement that they use AI “at their own risk” transfers nothing