AI regulation in Poland is shaped primarily by the EU AI Act, the world';s first comprehensive legal framework for artificial intelligence, which applies directly across all EU member states including Poland. For businesses operating in or from Poland, this means binding obligations that are already in force for the highest-risk categories of AI, with further requirements rolling in on a staggered schedule. Understanding which rules apply now, which are imminent, and how Poland';s national authorities are preparing to enforce them is essential for any company developing, deploying or importing AI systems in the Polish market. This guide covers the EU AI Act';s structure and timeline, Poland';s national implementation steps, sector-specific considerations, compliance obligations for businesses, and the practical risks of non-compliance.
The EU AI Act is an EU regulation, meaning it has direct legal effect in Poland without requiring transposition into Polish national law. It entered into force across the EU in the summer of a recent year and applies in phases. The Act establishes a risk-based classification system for AI systems: unacceptable risk, high risk, limited risk, and minimal risk. Each tier carries distinct obligations for providers, deployers, importers and distributors.
For Polish businesses, the most immediate impact falls on providers and deployers of high-risk AI systems. High-risk systems include those used in critical infrastructure, education, employment, essential private and public services, law enforcement, migration management, and the administration of justice. Any company in Poland that develops or deploys AI in these areas must comply with the Act';s requirements for conformity assessments, technical documentation, data governance, transparency, human oversight, and post-market monitoring.
The Act also introduces obligations for general-purpose AI models, including large language models. Providers of such models must maintain technical documentation, comply with copyright law, and publish summaries of training data. For models classified as presenting systemic risk, additional obligations apply, including adversarial testing and incident reporting. Polish companies building on top of foundation models or integrating them into products must understand where their obligations begin and where the upstream provider';s obligations end.
A common mistake among Polish founders and technology companies is assuming that because the AI Act is an EU instrument, compliance is someone else';s problem - the platform provider';s, the cloud vendor';s, or the EU';s. In practice, the Act assigns obligations based on the role a company plays in the AI value chain, not simply on where the AI system was built.
While the EU AI Act is self-executing, member states are required to designate national competent authorities to supervise and enforce the regulation. Poland is in the process of establishing its national AI supervisory framework. The Office of Competition and Consumer Protection (UOKiK) and the Personal Data Protection Office (UODO) are among the bodies expected to play significant roles, given their existing mandates over consumer protection and data privacy respectively.
Poland';s government has also been developing a national AI strategy, which sets out policy priorities for AI adoption in the public sector, research, and industry. This strategy does not create binding legal obligations in itself, but it signals where regulatory attention and public procurement requirements are likely to focus in the near term.
The Polish Financial Supervision Authority (KNF) is the relevant supervisory body for AI systems used in financial services. The KNF has issued guidance on the use of AI in credit scoring, fraud detection, and customer onboarding, and it is expected to align its supervisory expectations with the EU AI Act';s requirements for high-risk systems in the financial sector.
In practice, foreign companies entering the Polish market with AI products should not wait for Poland';s national supervisory structure to be fully formalised before beginning compliance work. The EU AI Act';s obligations apply regardless of whether the national authority has been formally designated. A non-obvious requirement for non-EU providers is the obligation to appoint an authorised representative established in the EU - which can be in Poland - before placing a high-risk AI system on the Polish or broader EU market.
The EU AI Act';s obligations do not all apply at once. The regulation follows a staggered implementation schedule that businesses in Poland must map carefully against their product and deployment timelines.
The prohibition on unacceptable-risk AI systems - those that use subliminal manipulation, exploit vulnerabilities of specific groups, or enable real-time remote biometric identification in public spaces by law enforcement except in narrow circumstances - became applicable in the early months of the regulation';s entry into force. Any Polish company or foreign company operating in Poland must have already ceased any such practices.
Obligations for providers of general-purpose AI models became applicable approximately one year after the regulation entered into force. This is a critical deadline for Polish AI companies building or fine-tuning large models, as well as for companies integrating such models into commercial products.
The full set of obligations for high-risk AI systems - including conformity assessments, CE marking where applicable, registration in the EU database of high-risk AI systems, and post-market monitoring - apply from approximately two years after entry into force. For AI systems already on the market before the regulation entered into force, transitional provisions allow additional time, but these windows are not indefinite.
Obligations related to AI systems used by public authorities in Poland, particularly in areas such as biometric categorisation and emotion recognition, are subject to specific timelines and, in some cases, outright prohibitions. Polish public sector entities procuring AI systems must ensure their vendors can demonstrate compliance before contracts are signed.
Poland has a significant technology and outsourcing sector, a growing fintech ecosystem, and a large manufacturing base that is increasingly adopting AI-driven automation. Each of these sectors faces distinct compliance considerations under the current regulatory framework.
In financial services, AI systems used for credit decisions, insurance pricing, and anti-money laundering are classified as high-risk under the EU AI Act. Polish banks, insurers, and payment institutions must conduct conformity assessments, maintain detailed technical documentation, and ensure that human oversight mechanisms are in place. The KNF';s existing supervisory expectations around model risk management provide a useful baseline, but the AI Act adds additional layers of documentation and transparency requirements.
In healthcare, AI systems used for diagnosis, treatment recommendations, or patient triage are also classified as high-risk. Polish healthcare providers and medtech companies must navigate the intersection of the AI Act with the EU Medical Device Regulation and the General Data Protection Regulation (GDPR). The interaction between these frameworks is complex: a medical AI system may need to satisfy conformity requirements under both the Medical Device Regulation and the AI Act, and data used to train or operate the system must comply with GDPR as implemented in Poland through the Act on Personal Data Protection.
In manufacturing and logistics, AI systems used for safety components in machinery are high-risk. Polish manufacturers exporting to other EU markets must ensure their AI-enabled products carry the required documentation and, where applicable, CE marking. A practical scenario: a Polish robotics company integrating an AI-based quality control system into a production line must assess whether the system qualifies as a safety component, conduct a conformity assessment, and register the system in the EU database before the product can be placed on the market.
In the public sector, Polish government agencies using AI for administrative decisions - such as benefit eligibility assessments or permit processing - must comply with transparency obligations and ensure that individuals have the right to a meaningful explanation of AI-assisted decisions. This intersects with existing obligations under Polish administrative procedure law and the GDPR';s provisions on automated decision-making.
If your business operates across any of these sectors and you are uncertain how the AI Act';s risk classification applies to your specific systems, reaching out to specialised legal counsel early is advisable. Contact info@vlolawfirm.com - we can help structure the compliance approach correctly the first time.
For companies operating in Poland, the practical compliance checklist under the EU AI Act depends on the role the company plays and the risk classification of its AI systems. The following obligations are the most significant for the majority of businesses.
Providers of high-risk AI systems must:
Deployers of high-risk AI systems - companies that use such systems in their operations but did not develop them - have a distinct but overlapping set of obligations. Deployers must use AI systems in accordance with the provider';s instructions, implement human oversight measures, monitor system performance, and inform employees whose work is affected by the AI system. Polish employers using AI in recruitment, performance management, or workforce monitoring must also consider obligations under Polish labour law and the GDPR.
Providers of general-purpose AI models must maintain technical documentation, comply with EU copyright law regarding training data, and publish summaries of training content. For models presenting systemic risk, additional obligations include adversarial testing, cybersecurity measures, and incident reporting to the European AI Office.
Many underestimate the documentation burden. The AI Act requires not just a one-time assessment but ongoing record-keeping, monitoring logs, and the ability to demonstrate compliance to a supervisory authority on request. Polish companies that have not yet begun building these documentation processes are already behind the curve.
The EU AI Act establishes a tiered penalty structure. Violations involving prohibited AI practices - the unacceptable-risk category - can attract fines of up to EUR 35 million or seven percent of global annual turnover, whichever is higher. Violations of other obligations, including those applicable to high-risk systems and general-purpose AI models, can attract fines of up to EUR 15 million or three percent of global annual turnover. Providing incorrect or misleading information to authorities can attract fines of up to EUR 7.5 million or one percent of global annual turnover.
These are EU-level maximums. National competent authorities in Poland will have discretion in applying penalties, taking into account factors such as the severity of the infringement, the degree of cooperation with authorities, and whether the company took corrective action promptly. However, the scale of potential fines means that non-compliance is a material financial risk for any business of meaningful size.
Enforcement is expected to ramp up as national supervisory structures are consolidated and the European AI Office builds its capacity to oversee general-purpose AI models. Polish companies should not assume that enforcement will be slow or lenient in the early years. Regulators across the EU have signalled that they intend to use the AI Act';s enforcement tools actively, particularly in sectors such as financial services and healthcare where AI-related harms are most visible.
A practical scenario: a Polish HR technology company providing an AI-based candidate screening tool to employers across the EU would be classified as a provider of a high-risk AI system under the Act';s employment category. If the company has not conducted a conformity assessment, registered the system, and put in place the required documentation and monitoring processes, it faces potential fines, market withdrawal orders, and reputational damage across all EU markets where it operates.
What AI systems are currently prohibited in Poland under the EU AI Act?
The EU AI Act prohibits a specific set of AI practices across all EU member states, including Poland. These include AI systems that use subliminal or manipulative techniques to distort behaviour in ways that cause harm, systems that exploit vulnerabilities of specific groups such as children or people with disabilities, social scoring systems operated by public authorities, and most uses of real-time remote biometric identification in publicly accessible spaces by law enforcement. These prohibitions are not aspirational - they are legally binding and already in force. Polish companies and public bodies must have already reviewed their AI deployments to ensure none fall within these categories. The consequences of operating a prohibited system include the highest tier of fines under the Act and potential criminal referrals under national law.
How long does AI Act compliance typically take, and what does it cost for a Polish company?
The timeline and cost of compliance depend heavily on the risk classification of the AI systems involved and the maturity of the company';s existing governance processes. For a company deploying a high-risk AI system with no prior compliance infrastructure, building the required quality management system, conducting a conformity assessment, preparing technical documentation, and registering the system can take several months and involve significant professional fees. Companies that already have robust data governance and model risk management processes - common in regulated sectors such as banking - will find the incremental effort more manageable. For general-purpose AI model providers, the documentation and transparency obligations are ongoing rather than one-time, adding to the compliance cost over time. Professional and legal fees for a comprehensive AI Act compliance programme typically start from the low thousands of EUR for simpler cases and scale significantly for complex, multi-system deployments.
Does a non-EU company need to comply with AI regulation in Poland if it sells AI products there?
Yes. The EU AI Act applies on a market-access basis, similar to the GDPR. If a non-EU company places an AI system on the Polish or broader EU market, or if the output of an AI system is used in the EU, the Act';s obligations apply. Non-EU providers of high-risk AI systems are required to appoint an authorised representative established in the EU before placing their system on the market. This representative takes on legal responsibility for compliance on behalf of the provider. Non-EU providers of general-purpose AI models with systemic risk must engage directly with the European AI Office. Ignoring these obligations does not reduce legal exposure - it simply means the company is non-compliant from the moment it enters the EU market.
AI regulation in Poland is no longer a future concern - it is a present compliance reality shaped by the EU AI Act';s phased but already-active obligations. Polish companies and foreign businesses operating in Poland must classify their AI systems, understand their role in the AI value chain, and build the governance, documentation, and monitoring processes the Act requires. The regulatory framework will continue to develop as Poland';s national supervisory structure matures and enforcement capacity grows across the EU.
VLO Law Firms advises international clients on AI regulation in Poland. We can assist with AI system risk classification, conformity assessment preparation, technical documentation review, authorised representative appointments, and ongoing compliance monitoring. To request a consultation, contact: info@vlolawfirm.com