
Artificial Intelligence (AI) Act
The AI Act is the world’s first piece of legislation concerning artificial intelligence. Officially called Regulation (EU) 2024/1689, it is intended to ensure secure and transparent development and utilization of AI in line with European values. It came into effect on 1 August 2024 and its provisions start to apply gradually.
The Regulation applies directly across the entire EU, which means that it is effective without the need for implementation at the national level. However, every Member State, including Poland, has to adopt laws in terms of e.g. supervision and penalties.
The AI Act is intended to ensure that artificial intelligence systems functioning in the European Union are secure, transparent, and ethical. Instead of regulating the technology itself, it focuses on the risks related to specific use of AI.
AI Act – comprehensive support from Cybernite
Table of contents
- Which law implements the AI Act in Poland?
- What is the purpose of the AI Act?
- Who does the AI Act apply to?
- Risk pyramid: What requirements does the AI Act introduce?
- When do the regulations start to apply?
- What obligations does the AI Act introduce?
- What are the penalties for non-compliance with the AI Act?
- Obligations for business
- Summary
Which law implements the AI Act in Poland?
As an EU Regulation, the AI Act applies in Poland directly. However, for the system to function efficiently, a so-called supporting law is necessary.
In Poland, this is the Law on Artificial Intelligence Systems. As at February 2026, legislative work on that Law has been completed. The main element of the Law is the establishment of a new supervisory authority: the Commission for the Development and Security of Artificial Intelligence (KRiBSI), which is attached to the Ministry of Digitization. The Commission monitors the market, issues certificates, and imposes penalties.
What is the purpose of the AI Act?
The main goals of the AI Act are to:
- Ensure the security of AI systems
- Protect the rights of citizens and users
- Increase trust to AI technologies
- Consolidate the principles of using AI in the EU
- Establish a predictable legal framework for business
The European Union decided that artificial intelligence can generate great benefits, but, at the same time, entails real legal, ethical, and operational risks that need to be regulated.
Who does the AI Act apply to?
The scope of application is very broad, including e.g.:
- Manufacturers and providers of AI systems,
- Companies that use AI in its processes (e.g. HR, marketing, data analysis),
- Suppliers of AI-based solutions (including SaaS),
- Organizations from outside of the EU if their AI systems are used in the EU or affect people in the EU.
The size of the company does not matter: the AI Act applies to corporations, SMEs, and start-ups; however, there are certain facilitations for smaller entities.
Risk pyramid: What requirements does the AI Act introduce?
The AI Act divides artificial intelligence systems into four categories. The category into which the given system is classified determines the obligations of the organization:
- Unacceptable risk (PROHIBITED systems)
Some applications of AI in the EU have been completely illegal since February 2025. These include:
- Systems that manipulate behaviors (e.g. subliminal advertisements encouraging hazardous activities).
- Social scoring: the evaluation of citizens by governments.
- Identification of emotions in workplaces or schools (with a few exceptions).
- High risk (the strictest requirements)
These are the systems that affect important areas of life, e.g. AI used in recruitment processes (evaluation of CVs), banking (credit scoring), education, or health care.
- Requirements: The need to carry out conformity assessment, have detailed technical documentation in place, ensure human supervision over the system, and guarantee high-quality data for training (in order to avoid e.g. racism or sexism in the algorithms).
- Limited risk (obligation to inform)
This concerns systems such as chatbots (e.g. ChatGPT) and image generators.
- Requirements: Transparency. The user has to know that they are talking to a machine and AI-generated content (deepfakes) has to be properly labeled.
- Minimal risk
Spam filters or video games. In this respect, the AI Act does introduce any additional obligations.
When do the regulations start to apply?
The AI Act becomes applicable in stages, so that business has time to prepare.
- February 2025: The prohibition of systems posing an unacceptable risk came into effect.
- August 2025: The requirements for general-purpose AI models (GPAI) started to apply.
- August 2026: Most of the regulations will come into effect, including those concerning high-risk systems (e.g. in HR and finance).
- August 2027: Requirements for high-risk systems built into already regulated products (e.g. cars, medical devices) will come into effect.
What obligations does the AI Act introduce?
- Obligations for high risk systems
Suppliers and users have to e.g.:
- Carry out risk assessment,
- Ensure high quality of training datasets,
- Keep technical documentation,
- Allow for human supervision over the functioning of AI,
- Ensure precision, resilience, and cybersecurity of the system.
- Transparency
Users have to be informed when:
- They interact with an AI system,
- Content is generated or modified by AI (e.g. deepfake).
- Organizational obligations
Companies have to:
- Implement AI management procedures,
- Monitor the functioning of systems,
- Respond to incidents and irregularities,
- Train the personnel that uses AI.
What are the penalties for non-compliance with the AI Act?
The AI Act provides for very high financial penalties.
The maximum sanctions are as follows:
- Up to EUR 35 million or 7% of global annual turnover - for the most serious violations (e.g. use of prohibited systems)
- Up to EUR 15 million or 3% of turnover - for violations of other obligations
- Up to EUR 7.5 million or 1% of turnover - for misinformation
Additionally, the following may be imposed or occur:
- Obligation to remove the system from the market,
- Prohibition of using the given solution,
- Reputation and contractual losses.
Obligations for business
The AI Act imposes various requirements, depending on the type of the system. For companies, the following will be the most important:
A. Obligations in terms of documentation
- Full technical documentation,
- Test reports and risk assessment reports,
- Manuals.
B. Risk management
- High-risk systems have to undergo a process of risk identification, assessment, and mitigation,
- Human supervision over key AI decisions.
C. Data quality
- The obligation to use high quality data sets,
- Verification of data in view of bias.
D. Reporting of incidents
Companies that implement high-risk systems have to report major incidents to supervisory authorities.
E. CE marking for high-risk systems
Once the requirements have been met, the system may be placed on the EU market as “AI Act-compliant”.
Summary
The AI Act is a key piece of EU legislation that regulates the development and use of artificial intelligence. The obligations for companies depend on the system’s level of risk; the strictest requirements apply to high-risk solutions. The implementation schedule covers the years 2024–2027. Even though the regulation applies directly, Poland is still working on a domestic law that will specify the principles of supervision and the sanctions.
For business, the AI Act means primarily the need to produce an inventory of the tools used. If the company uses ready-made AI solutions (e.g. for recruitment purposes), it needs to make sure that the provider supplied the relevant documentation and certificates. If the company develops AI tools, it needs to implement risk assessment processes already at the stage of writing the code. Improving AI literacy among employees (so that they use AI consciously and safely) is an overriding obligation that applies to nearly everyone.
Text by professor Grzegorz Strupczewski
Within the framework of Cybernite Status we help assess the organization’s current level of security and regulatory preparedness.
Through Cybernite Safe, we provide regular support in terms of cybersecurity management, performance of regulatory obligations, and compliance with industry standards, using the Cybersecurity as a Service (CSaaS) model.

Do you need support with respect to NIS2/KSC, CRA, DORA, or the AI Act, from confirming that you are subject to them, through gap analysis, to verification and supplementation of existing actions?
Cybernite helps organize documentation, implement the missing elements, and maintain compliance in practice.