What the AI Act is and what counts as an AI system
The AI Act is a Regulation and therefore applies directly in EU Member States. Polish legislation complements it mainly through national supervision, procedures and sanctions. After the July 2026 amendments, the consolidated text of Regulation 2024/1689 is the relevant legal reference.[1]
An AI system is a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from inputs how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. Not every script, spreadsheet or deterministic business rule falls within that definition. Commission guidance assists classification but is not legally binding; the final interpretation belongs to the courts.[3]
Timeline after the Digital Omnibus on AI
| Date | What becomes applicable |
|---|---|
| 1 August 2024 | The AI Act entered into force. |
| 2 February 2025 | Article 4 on AI literacy and the original eight groups of prohibited practices. |
| 2 August 2025 | Provisions on GPAI, EU-level governance, notified bodies and national penalty rules; Article 101 penalties for GPAI providers became enforceable one year later. |
| 27 July 2026 | Regulation (EU) 2026/1744 entered into force. |
| 2 August 2026 | General application date for much of the Regulation, including Article 50, and full Commission enforcement of GPAI obligations. |
| 2 December 2026 | Two new prohibitions, and the adaptation deadline for technical marking under Article 50(2). |
| 2 August 2027 | At least one national regulatory sandbox operational; GPAI models placed on the market before 2 August 2025 must comply with Chapter V. |
| 2 December 2027 | Classification, requirements and obligations for high-risk systems under Article 6(2) and Annex III. |
| 2 August 2028 | The corresponding rules for product-related high-risk systems covered through Annex I. |
These dates follow the consolidated Article 113 and Regulation 2026/1744, not the original 2024 calendar.[1][2]
Roles: a provider is not the same as a deployer
The Regulation covers, among others, providers placing AI systems or GPAI models on the EU market, deployers established or located in the EU, importers and distributors. It may also apply to providers and deployers outside the EU where the output of a system is used in the Union. Personal non-professional use and certain national-security, defence and pre-market research activities are outside or specially treated by the Regulation.
- Provider - develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name or trademark.
- Deployer - uses an AI system under its authority in a professional context.
- Importer - places on the EU market a system bearing the name or trademark of an entity from a third country.
- Distributor - makes a system available in the supply chain without being the provider or importer.
Roles can change. A deployer, importer or distributor can become subject to provider obligations when it puts its own name on a high-risk system, makes a substantial modification, or changes the intended purpose in a way that makes the system high-risk. A SaaS contract therefore does not replace analysis of the actual deployment.
The open-source exemptions are not a general immunity. They do not remove all high-risk or transparency obligations, and GPAI exemptions depend on the conditions in Chapter V.
The "four risk levels" are a useful simplification, not a universal label
The familiar pyramid of unacceptable risk, high risk, transparency risk, and minimal or no risk is useful communication shorthand and is used by the Commission.[4] It is not a mandatory single procedure for assigning every AI system one of four labels.
- Article 5 prohibits specifically defined practices, not technologies as such.
- Article 6 and Annexes I and III determine when a system is high-risk.
- Article 50 imposes transparency duties for selected systems and content regardless of the informal phrase "limited risk".
- Other AI uses may have few product-specific AI Act obligations but can still be governed by GDPR, labour, consumer, copyright, sectoral and cybersecurity law.
- GPAI models have their own regime; the legal status of a model is not the same as the classification of a system built on that model.
Prohibited practices
Since 2 February 2025, Article 5 prohibits eight groups of practices subject to detailed conditions and exceptions:
- harmful manipulation or deception that materially impairs informed decision-making and causes or is reasonably likely to cause significant harm;
- exploitation of vulnerabilities due to age, disability or a particular social or economic situation with a comparable harmful effect;
- social scoring where it leads to unjustified or disproportionate detrimental treatment or treatment in an unrelated context;
- individual prediction of criminal offending based solely on profiling or assessment of personality traits, subject to the exceptions in the Regulation;
- untargeted scraping of facial images from the internet or CCTV to build or expand facial-recognition databases;
- emotion inference in workplaces and educational institutions except for defined medical or safety purposes;
- biometric categorization used to infer sensitive characteristics such as race, political opinions, trade-union membership, religion, sex life or sexual orientation, subject to statutory exceptions;
- real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes except in narrowly defined situations and with the safeguards of Article 5.
From 2 December 2026, two additional prohibitions introduced by Regulation 2026/1744 apply to certain systems generating or manipulating non-consensual intimate material and material representing child sexual abuse. The new provisions are technically qualified: they target systems whose design, training, architecture, available capabilities or functions make prohibited output a reasonably foreseeable and repeatable result without material technical modification and where adequate safeguards do not reliably prevent it.[2][5]
Two practical consequences follow. An application built expressly for such a purpose is covered directly, while a provider of a general-purpose model answers for the effectiveness of its safeguards rather than for the theoretical capability of the model. That effectiveness has to be demonstrable, not merely declared.
When a system is high-risk
There are two principal routes to high-risk status. It is not enough to observe that a system operates in an "important sector". Intended purpose, function and the conditions of Article 6 all have to be checked.
Product-safety route - Article 6(1)
A system can be high-risk when it is a product, or a safety component of a product, covered by Union harmonization legislation in Annex I and the product is subject to third-party conformity assessment. This can include certain machinery, medical devices, toys, lifts, vehicles, rail and aviation systems. After the 2026 amendment, functions unrelated to safety, such as convenience or ordinary performance optimization, should not automatically be treated as safety components. The corresponding high-risk obligations apply from 2 August 2028.
Annex III route - Article 6(2)
Annex III lists uses in eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services; law enforcement; migration, asylum and border control; and administration of justice and democratic processes. Examples can include recruitment systems, creditworthiness assessment of natural persons, or systems assisting judicial authorities. The main requirements for this group apply from 2 December 2027.
The Article 6(3) exception
Article 6(3) contains a limited exception for Annex III systems that do not pose a significant risk of harm to health, safety or fundamental rights and do not materially influence the outcome of decision-making, where they perform one of the specified narrow or preparatory functions. Profiling of natural persons prevents use of that exception. Providers relying on it must document the assessment before the system is placed on the market or put into service and satisfy the applicable registration requirements.
The Commission published draft classification guidance in 2026. As of the update date of this article it remains interpretive material rather than a binding source of law; the binding criteria stay in Article 6 and Annex III.[6]
Provider duties across the life cycle
Where the high-risk regime applies, compliance is a life-cycle process rather than a one-off conformity file. Provider obligations include, among other things:
- an iterative risk-management system throughout the life cycle (Article 9);
- data and data-governance requirements for training, validation and testing data where used (Article 10);
- technical documentation, kept current (Article 11 and Annex IV);
- automatic logging that allows risks and material changes to be identified (Article 12);
- instructions and information for deployers (Article 13);
- effective human oversight designed into the system (Article 14);
- appropriate accuracy, robustness and cybersecurity throughout the life cycle (Article 15);
- a quality-management system, conformity assessment, the EU declaration of conformity and CE marking where required;
- registration in the EU database before placing on the market or putting into service, subject to statutory exceptions;
- post-market monitoring, corrective action and serious-incident reporting.
Conformity assessment does not always mean a notified body is involved. The route depends on system type and sectoral product law. CE marking is a conformity signal under applicable Union requirements, not a certificate that the predictions of the model are objectively good.
These requirements should not be reduced to a checklist of documents. Cybersecurity under Article 15, for example, means analyzing attacks that can manipulate model inputs, outputs, training or retrieval data, compromise integrations or misuse privileged tools. Security testing, hardening, logging and incident response can therefore support AI Act compliance without becoming separate legal requirements solely because they are common security practices.
Deployer duties and the fundamental-rights impact assessment
A deployer of a high-risk system must use it according to the instructions, assign competent human oversight, monitor its operation and keep logs under its control for the required period. Where the deployer controls input data, those data must be relevant and sufficiently representative in relation to the intended purpose. Material incidents or unexpected risks also trigger cooperation and escalation duties.
Before a high-risk system is used in the workplace, the employer informs worker representatives and the people affected. Where the system makes or supports a decision concerning a natural person, that person should be informed that the system is being used. Where personal data are processed, the deployer uses information from the provider for purposes including a data protection impact assessment where Article 35 GDPR requires one.
FRIA is not required of every deployer
A fundamental-rights impact assessment under Article 27 is not universal. It applies before first use to specified deployers and specified Annex III systems, including public-law bodies and private entities providing public services, as well as certain creditworthiness and life or health insurance uses. Its scope covers the process, the period and frequency of use, the categories of people affected, specific risks, human oversight and the measures to be taken if a risk materializes. A GDPR DPIA and an AI Act FRIA may overlap in evidence and governance, but they assess different legal interests and neither automatically replaces the other.
Transparency under Article 50
Article 50 distinguishes provider duties from deployer duties and does not require every text that received stylistic assistance from AI to carry an AI label.[7]
- Systems interacting directly with people must generally be designed so that the person is informed that they are interacting with AI, unless this is obvious to a reasonably well-informed, observant and circumspect person.
- Synthetic content: providers of systems generating or manipulating audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated, subject to exceptions such as standard editing that does not materially alter the content.
- Emotion recognition and biometric categorization: the deployer informs the people exposed to the system and complies with data-protection law.
- Deepfakes: the deployer discloses that the content is artificially generated or manipulated. For artistic, satirical or comparable creative work, the manner of disclosure may be adapted so that it does not hamper the display of the work.
- Text on matters of public interest: disclosure is required where a deployer publishes AI-generated or manipulated text, with an exception where the content has undergone human review or editorial control and a natural or legal person bears editorial responsibility for the publication.
For content-generation systems placed on the market before 2 August 2026, the amendment set 2 December 2026 as the deadline for adapting technical marking. The Commission has published guidance and a voluntary code on transparency; the code is a way of demonstrating compliance, not an exemption from Article 50.
GPAI and systemic risk
A general-purpose AI model displays significant generality and can competently perform a wide range of distinct tasks, which makes it integrable into many downstream systems or applications. The Chapter V obligations primarily concern providers of models, not every company using a finished assistant.
Duties of every GPAI provider
- preparing and keeping up to date the technical documentation of the model;
- providing downstream system providers with the information needed to understand the capabilities and limitations of the model;
- establishing a policy to comply with Union copyright law, including respect for text-and-data-mining reservations;
- publishing a sufficiently detailed summary of the content used for training, following the Commission template;
- appointing an EU representative where the provider is established in a third country, unless an exception applies.
Certain models released under a free and open-source licence may be exempt from part of the documentation and information duties where the conditions of Article 53(2) are met. The exemption does not cover the copyright policy or the training-data summary and does not apply to models with systemic risk.
GPAI with systemic risk
A presumption of systemic risk arises where the cumulative amount of computation used for training exceeds 1025 FLOP. The Commission may also designate a model on the basis of its capabilities or impact, so the compute threshold is not the only route. Providers of such models must, among other things, run and document evaluations, assess and mitigate systemic risks at Union level, report serious incidents and ensure an adequate level of cybersecurity.
Commission guidance clarifies the scope of these duties, the working threshold for qualifying a model as GPAI, and the treatment of model modifications.[8] The voluntary GPAI Code of Practice, published in July 2025 and recognized by the Commission and the AI Board as an adequate tool, supports demonstration of compliance in transparency, copyright and safety of models with systemic risk.[9] It is not a certificate and does not transfer responsibility away from the provider.
The distinction matters operationally. A company using a third-party GPAI service normally remains a deployer of the system it operates under its authority. It does not become the provider of the underlying foundation model merely because it adds prompts, company documents or retrieval.
AI literacy after the 2026 amendment
Since 2 February 2025, providers and deployers have had to take measures supporting the development of AI literacy among staff and other persons dealing with AI systems on their behalf. After the 2026 amendment, Article 4 does not impose a universal certificate, annual course, or one fixed proficiency level. Measures should be proportionate to the knowledge, experience, education and training of those people and to the context in which the AI system is used.[10]
A sensible programme can:
- inventory the tools and the people who use them;
- distinguish roles: ordinary user, reviewer of outputs, administrator, developer or integrator;
- cover the limits of the specific tool, hallucinations, bias, protection of data and trade secrets, copyright, safe prompting and how to escalate errors;
- keep an internal record of measures, participants and updates, even though the AI Act requires no particular certificate;
- be reinforced after a change of model, use case, affected groups or risk profile - not only on a calendar.
Telling staff to read the manual may not be enough. On the other hand, a small office using a text-editing tool does not need the programme appropriate to a team deploying AI in recruitment or diagnostics. A practical approach to such programmes is described on our Security Awareness training page.
Polish supervision and regulatory sandboxes
It is no longer correct to say that Poland has not selected its AI supervisory structure. The Act of 3 July 2026 on artificial intelligence systems, Journal of Laws 2026 item 1003, was promulgated on 27 July and largely entered into force on 11 August 2026. Specified provisions, including Articles 8-18 and Chapters 3-5, 8 and 9, apply from 28 October 2026.[11]
The Act establishes the Commission for the Development and Security of Artificial Intelligence as a market-surveillance authority and single point of contact. Its tasks include supervising compliance with the AI Act and the national act, conducting proceedings, information activities, issuing individual opinions and establishing and managing regulatory sandboxes. For specified products and sectors, competences remain tied to the authorities designated under sectoral law.
A regulatory sandbox is a controlled environment for development, training, validation or testing of an innovative system under the supervision of the competent authority. Participation is intended to increase legal certainty and ease market entry, but it does not suspend the AI Act, the GDPR or liability for damage. At least one national sandbox is to be operational by 2 August 2027; the amendment also allows a sandbox at Union level.
Enforcement and penalties
Fine levels are not automatic. The authority takes account of the nature, gravity and duration of the infringement, its consequences, intent or negligence, remedial action, cooperation and the size of the entity. The maximum ceilings in Article 99 are:
| Infringement | Maximum fine |
|---|---|
| Prohibited practices under Article 5 | EUR 35 million or 7% of total worldwide annual turnover for the preceding year; for an undertaking the higher figure applies |
| Specified operator and notified-body obligations, including Articles 26 and 50 | EUR 15 million or 3% of turnover |
| Incorrect, incomplete or misleading information | EUR 7.5 million or 1% of turnover |
| GPAI providers (Article 101) | EUR 15 million or 3% of worldwide turnover, whichever is higher |
For SMEs, including start-ups, the maximum is capped at the lower of the fixed and percentage figures. The Digital Omnibus extended part of that relief to small mid-cap companies, though not for the highest ceiling covering prohibited practices. The enforcement framework operated by the AI Office and national authorities has been in place since August 2026.[12]
The AI Act, the GDPR, NIS2 and standards
GDPR
The AI Act does not create a legal basis for processing personal data and does not replace the GDPR. Organizations must independently identify an Article 6 basis and, for special-category data, an Article 9 condition. A DPIA is required where processing is likely to result in high risk to individuals, not simply because the project uses AI. GDPR Article 22 concerns decisions based solely on automated processing that produce legal effects or similarly significantly affect a person, subject to its exceptions and safeguards.[13]
NIS2 and cybersecurity
NIS2 applies only where the organization and service fall within its scope and the relevant national implementing law. AI providers and cloud users are not automatically NIS2 entities. Where both regimes apply, vulnerability management, incident response, supply-chain security and continuity can support compliance with both, but compliance with one does not prove compliance with the other.
ISO/IEC 42001 and harmonised standards
ISO/IEC 42001:2023 establishes requirements for an AI management system and can help structure policies, roles, impact assessment and improvement. Certification is not required by the AI Act and does not by itself create legal conformity.[14]
A presumption of conformity can arise from voluntary use of a European harmonised standard only after its reference is published in the Official Journal of the EU and only within the scope of that reference. Publication by CEN-CENELEC and citation in the Official Journal are separate events.
On 12 July 2026, CEN-CENELEC published EN 18286:2026, Artificial intelligence - Quality management system for EU AI Act regulatory purposes, the first European standard produced for the AI Act.[16] As of 29 August 2026, its reference had not yet been published in the Official Journal for Article 40 purposes, so using it did not yet create the legal presumption associated with a harmonised standard; work on the remaining standards in the Commission standardisation request continues.[15]
What an organization should do now
- Build an inventory of AI systems and models, owners, purposes, users, data inputs and output recipients.
- Check the definition. Separate AI systems from ordinary deterministic automation.
- Determine the role: provider, deployer, importer or distributor, and whether any change shifts provider duties onto the organization.
- Screen for prohibited practices, including the two prohibitions applying from 2 December 2026.
- Assess both high-risk routes in Article 6 and the relevant annex entries; do not classify by sector name alone.
- Implement Article 50 transparency duties where applicable.
- Develop role-based AI literacy and retain evidence of the measures taken.
- Link AI governance to the GDPR: lawful bases, minimization, transfers, retention, contracts, Article 22 and DPIA.
- Manage suppliers and model changes, including security, logging, data use and subcontractors.
- Design genuine human oversight with authority to challenge, stop or reverse outcomes where required, and test it.
- Create an incident path connecting users, security, privacy, compliance and suppliers.
- Reassess after changes to the model, purpose, data, integrations, affected people or legislation.
Frequently asked questions
- Does the entire AI Act apply from 2 August 2026?
- No. Much of it does, but high-risk requirements for Annex III were moved to 2 December 2027 and product-related Annex I rules to 2 August 2028. Two new prohibited-practice rules apply from 2 December 2026.
- Does a company using ChatGPT or Copilot fall under the AI Act?
- Professional use generally makes the organization a deployer of the system it uses under its authority. It must respect applicable prohibitions and AI-literacy duties; further obligations depend on the use case. Merely using a finished tool does not make the company a GPAI model provider or automatically create a high-risk system.
- Must every AI-assisted item be labelled?
- No. Article 50 creates specific provider and deployer duties for specified interactions and synthetic content. It does not impose a universal label on every text that was edited with AI assistance.
- Does an ordinary website chatbot have to be registered in the EU database?
- Not merely because it is a chatbot. Registration obligations are tied to high-risk regimes and specific roles. Transparency to the user may nevertheless be required from 2 August 2026.
- Does AI literacy require an annual certificate?
- No. Article 4 requires proportionate measures supporting competence, not a universal certificate, annual course or one fixed training format.
- Who supervises the AI Act in Poland?
- The 2026 Polish act establishes the Commission for the Development and Security of Artificial Intelligence as a market-surveillance authority and single point of contact. The EU AI Office and sectoral authorities also have defined competences.
- Does ISO/IEC 42001 certify AI Act compliance?
- No. It can support governance but does not replace legal classification, conformity assessment or specific obligations. A legal presumption of conformity requires the conditions for a harmonised European standard to be met.
- What are the maximum fines?
- Up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices; up to EUR 15 million or 3% for specified other infringements; and up to EUR 7.5 million or 1% for certain incorrect, incomplete or misleading information, subject to the detailed rules of the Regulation and the SME limits.
Need consulting in this area?
A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.
Related content
Other competence areas
- IT security audit
- Vulnerability scanning
- Penetration testing
- Device and system hardening
- Email security audit
- KRI compliance audit
- KSC and NIS2 audit
- GDPR compliance audit
- Information security policy
- ISMS - information security management system
- Security awareness - onsite and online
- SOC 24/7 - monitoring and response
Compliance and regulation
Bibliography and sources
Sources checked as of 29 August 2026. Legal texts and official institutional materials are the primary basis; Commission guidance is interpretive and does not replace binding law or court interpretation.
- [1] regulationEuropean Parliament and Council of the EU (2024). Regulation (EU) 2024/1689 (AI Act) - consolidated text as of 27 July 2026. · EUR-Lex
- [2] regulationEuropean Parliament and Council of the EU (2026). Regulation (EU) 2026/1744 - the Digital Omnibus on AI. · EUR-Lex
- [3] guidelineEuropean Commission (2025). Guidelines on the definition of an artificial intelligence system. Shaping Europe's digital future. Updated in 2026 · digital-strategy
- [4] guidelineEuropean Commission (2026). AI Act - regulatory framework for AI. Shaping Europe's digital future. Updated 3 August 2026 · digital-strategy
- [5] guidelineEuropean Commission (2025). Guidelines on prohibited artificial intelligence practices. Shaping Europe's digital future. · digital-strategy
- [6] guidelineEuropean Commission (2026). Draft guidelines on the classification of high-risk AI systems. Shaping Europe's digital future. A draft, interpretive material only · digital-strategy
- [7] guidelineEuropean Commission (2026). Guidelines on transparency obligations for providers and deployers of AI systems. Shaping Europe's digital future. · digital-strategy
- [8] guidelineEuropean Commission (2025). Guidelines for providers of general-purpose AI models. Shaping Europe's digital future. Updated in 2026 · digital-strategy
- [9] guidelineEuropean Commission and AI Board (2025). General-Purpose AI Code of Practice. Shaping Europe's digital future. A voluntary code, not a certificate · digital-strategy
- [10] guidelineEuropean Commission (2026). AI Literacy - Questions & Answers. Shaping Europe's digital future. · digital-strategy
- [11] regulationParliament of the Republic of Poland (2026). Act of 3 July 2026 on artificial intelligence systems. Journal of Laws 2026 item 1003. Promulgated 27 July 2026, largely in force from 11 August 2026 · ELI
- [12] guidelineEuropean Commission (2026). The enforcement framework of the AI Act. Shaping Europe's digital future. Updated 24 August 2026 · digital-strategy
- [13] regulationEuropean Parliament and Council of the EU (2016). Regulation (EU) 2016/679 (GDPR). · EUR-Lex
- [14] standardISO/IEC (2023). ISO/IEC 42001:2023 - Artificial intelligence management system. · ISO
- [15] guidelineEuropean Commission (2026). Standardisation of the AI Act. Shaping Europe's digital future. Updated 3 August 2026 · digital-strategy
- [16] standardCEN-CENELEC (2026). EN 18286:2026 - Artificial intelligence - Quality management system for EU AI Act regulatory purposes. Published on 12 July 2026; its reference has not yet been published in the Official Journal of the EU · CEN-CENELEC