Compliance · EU regulation · 2026

The AI Act in 2026: what applies after the Digital Omnibus, current dates, GPAI and penalties

Why the AI Act exists

The AI Act is meant to harmonise the rules for placing AI systems on the EU market and using them, to support trustworthy and human-centric artificial intelligence, and to protect health, safety and fundamental rights. It does not regulate all automation identically: it prohibits narrowly described practices, imposes particular requirements on high-risk systems, establishes transparency obligations for selected systems, and creates a separate regime for general-purpose AI models (GPAI) [1].

Legal position at 24 August 2026. The AI Act, Regulation (EU) 2024/1689, applies as a rule from 2 August 2026. That does not mean every obligation started on one day. The Digital Omnibus on AI - Regulation (EU) 2026/1744 - postponed the rules for high-risk systems under annex III to 2 December 2027, and for systems linked to products under annex I to 2 August 2028 [2].

For a Polish organisation the most pressing matters today are the prohibited practices, measures developing AI literacy, the transparency obligations of article 50, data protection rules, and correctly establishing one's role in the AI chain. Buying access to a language model does not make a company a GPAI provider, and using AI does not automatically make a system high risk.

What the AI Act is, and whether a given solution is an AI system

The AI Act is a regulation and therefore applies directly in EU states; the Polish act supplements it above all with national supervision, procedures and sanctions. After the July 2026 changes the point of reference is the consolidated text of Regulation 2024/1689 [1].

An AI system is a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions influencing physical or virtual environments. Not every script, spreadsheet or deterministic business rule meets that definition. Commission guidelines help with classification but are not legally binding; final interpretation rests with the courts [3].

The timeline after the Digital Omnibus on AI

  • 1 August 2024 - the AI Act enters into force.
  • 2 February 2025 - article 4 on AI literacy and the eight original groups of prohibited practices start to apply.
  • 2 August 2025 - the provisions on GPAI, EU-level governance, notified bodies and national penalty rules start to apply; article 101 on penalties for GPAI providers began to apply a year later.
  • 27 July 2026 - Regulation 2026/1744 amending the AI Act enters into force.
  • 2 August 2026 - the general date of application, including article 50 on transparency; the Commission begins full enforcement of GPAI obligations.
  • 2 December 2026 - two new prohibitions start to apply, on generating or manipulating intimate material without consent and material depicting child sexual abuse. By that date, providers of content-generating systems placed on the market before 2 August 2026 have an adjustment period for the technical marking required by article 50(2).
  • 2 August 2027 - national authorities are to ensure at least one regulatory sandbox is operating; by that date providers of GPAI models placed on the market before 2 August 2025 must comply with chapter V.
  • 2 December 2027 - the classification rules, requirements and obligations for high-risk systems under article 6(2) and annex III start to apply.
  • 2 August 2028 - those rules start to apply to high-risk systems linked to products covered by annex I.

The current dates follow from article 113 of the consolidated text and from Regulation 2026/1744, not from the original 2024 schedule [1] [2]

Scope and roles: a provider is not the same as a deployer

The regulation covers, among others, providers placing AI systems or GPAI models on the EU market, deployers established or located in the EU, importers and distributors. It can also reach providers and deployers outside the EU where the output of the system is used in the Union. Excluded are, among other things, purely personal non-professional use and certain activities concerning national security, defence and pre-market research.

  • A provider develops a system or model, or has it developed, and places it on the market or into service under its own name or trademark.
  • A deployer uses an AI system under its authority, other than in a personal non-professional capacity.
  • An importer places on the EU market a system bearing the name of an entity from a third country.
  • A distributor makes a system available in the supply chain without being a provider or an importer.

Roles can change. A deployer, importer or distributor can take on the provider's obligations if it puts its own name on a high-risk system, makes a substantial modification to it, or changes its intended purpose so that it becomes high risk. That is why a contract with a SaaS provider does not replace analysis of how the system is actually deployed.

The exemption for solutions released under free and open licences is not a general immunity. It does not cover, among other things, high-risk systems and transparency obligations, and for GPAI it depends on the conditions set out in chapter V.

"Four levels of risk": a useful shorthand, not a universal label

The familiar pyramid - unacceptable risk, high risk, transparency risk, and minimal or no risk - organises the subject well and is used by the European Commission [4]. It should not, however, be treated as a single mandatory procedure for assigning one of four labels to every system.

  • Article 5 prohibits precisely described practices, not whole technologies.
  • Article 6 and annexes I and III determine when a system is high risk.
  • Article 50 imposes transparency obligations on selected systems and content regardless of the colloquial "limited risk" label.
  • For other uses the AI Act may impose no particular product obligations, but the GDPR, employment, consumer, copyright, sectoral and cybersecurity law can still apply.
  • GPAI models have a separate regime; the risk of a model is not the same as the classification of the system in which the model is used.

Prohibited practices: eight groups apply, two new from December 2026

Since 2 February 2025 the following groups of practice are prohibited. Each has detailed conditions and exceptions, so the mere presence of a function is not always enough to establish an infringement:

  1. Harmful manipulation or deception - where the technique materially impairs the ability to make an informed decision and causes, or is reasonably likely to cause, significant harm.
  2. Exploitation of vulnerability arising from age, disability or a specific social or economic situation, with an analogous effect of harmfully distorting behaviour.
  3. Social scoring of individuals or groups where it leads to detrimental treatment in an unrelated context, or to treatment that is unjustified or disproportionate. The prohibition is not limited to public administration.
  4. Individual prediction of criminal offending based solely on profiling or on assessing personality traits. Supporting a human assessment already based on objective, verifiable facts linked to criminal activity may be permissible.
  5. Untargeted scraping of facial images from the internet or CCTV to create or expand facial recognition databases.
  6. Inference of emotions in the workplace and in education, except for medical or safety-related uses.
  7. Biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, with statutory exceptions for certain datasets and law enforcement.
  8. Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes - outside narrow cases and subject to the safeguards in article 5.

From 2 December 2026 article 5 will additionally cover two prohibitions added by the Digital Omnibus on AI [2]. The first concerns systems generating or manipulating realistic image, video, audio or similar material depicting the intimate parts of an identifiable person or that person in sexual activity, without their freely given, specific, informed, unambiguous and explicit consent. The second concerns systems generating or manipulating material or representations within the meaning of article 2(c) and (e) of Directive 2011/93/EU, outside cases covered by a national ground for acting lawfully.

The prohibitions do not cover every model theoretically capable of producing such content. Under the added article 5(1a)(a) they apply where the design, training, architecture, capabilities or user-accessible functions of the system make such generation a reasonably foreseeable and reproducible outcome without substantial technical modification, and the system lacks reasonable and adequate technical safety measures and other safeguards reliably preventing it. The practical conclusion is twofold: an application built expressly for that purpose is caught outright, while a general-purpose model provider answers for the effectiveness of its safeguards rather than for the theoretical capability of the model. That effectiveness has to be demonstrable, not merely declared.

The Commission's 2025 guidelines help interpret the eight original groups, but they predate this amendment and do not replace the current text of the law [5].

When is a system high risk?

Classification has two main routes. It is not enough to say that a system operates in an "important industry". The intended purpose, the function and the conditions of article 6 all have to be checked.

A system linked to a product under annex I

A system is high risk where it is a product, or a safety component of a product, covered by the listed EU harmonisation legislation and where that product is subject to third-party conformity assessment. This concerns, among others, certain machinery, medical devices, toys, lifts, vehicles, rail and aviation. After the amendment, a function limited to convenience, performance optimisation, automation or quality control unrelated to safety is not a safety component. The relevant requirements apply from 2 August 2028.

A use listed in annex III

Annex III covers specific uses in eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services; law enforcement; migration, asylum and border control; and the administration of justice and democratic processes. Examples include screening job candidates, assessing an individual's creditworthiness, or a system assisting a judicial authority in establishing facts and applying the law. Requirements for this group apply from 2 December 2027.

The exception in article 6(3)

A system listed in annex III may not be high risk where it does not pose a significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of a decision, and where it performs one of the limited functions set out in article 6(3), such as a narrow procedural or preparatory task. The exception does not apply where the system profiles natural persons. A provider relying on it must document the assessment before placing the system on the market or putting it into service, and comply with the registration obligations in the current article 49.

The Commission published draft classification guidelines in 2026; at the date of this update the document remains supporting material rather than a binding source of law [6].

The high-risk system provider: requirements across the lifecycle

Once the relevant provisions start to apply to a given group, the provider will have to combine product requirements with organisational management. The most important elements are:

  1. an iterative risk management system across the whole lifecycle (article 9);
  2. data governance for training, validation and testing data, where the system uses such data (article 10);
  3. technical documentation kept up to date (article 11 and annex IV);
  4. automatic logging enabling identification of risks and substantial modifications (article 12);
  5. information and instructions for the deployer (article 13);
  6. design for effective human oversight (article 14);
  7. appropriate accuracy, robustness and cybersecurity across the lifecycle (article 15);
  8. a quality management system, conformity assessment, an EU declaration of conformity and CE marking where required;
  9. registration in the EU database before placing on the market or putting into service, subject to statutory exceptions;
  10. post-market monitoring, corrective action and reporting of serious incidents.

Conformity assessment does not always mean the involvement of a notified body. The route depends on the type of system and the relevant sectoral rules. Nor should CE marking be equated with a certificate of the quality of a model's predictions - it signifies declared conformity with the applicable Union requirements.

The deployer: obligations depend on the use

Article 26 concerns deployers of high-risk systems. It covers, among other things, using the system in accordance with the instructions, assigning competent people to oversight, ensuring input data under the organisation's control is relevant and sufficiently representative, monitoring operation, responding to risk, and keeping logs under the deployer's control for at least six months, unless other law provides otherwise.

Before deploying a high-risk system in the workplace, the employer is to inform workers' representatives and the people affected. Where the system takes or supports a decision concerning a natural person, that person should be informed that the system is being used. Where personal data is processed, the deployer uses the provider's information to carry out a data protection impact assessment where article 35 of the GDPR requires one.

A fundamental rights impact assessment is not mandatory for every deployer

The fundamental rights impact assessment under article 27 is required before first use of certain annex III systems by public law bodies, private entities providing public services, and deployers using systems to assess creditworthiness or to price and assess risk in life and health insurance. Its scope covers the process, the duration and frequency of use, the categories of person affected, the specific risks, human oversight, and the measures to take if a risk materialises. It can be coordinated with the GDPR data protection impact assessment, but the two answer different legal questions.

Transparency from 2 August 2026: who marks what?

Article 50 separates the obligations of providers and deployers. It does not create a general duty to label every text in which AI helped improve the style [7].

  • Systems interacting directly with people: the provider is to design them so that the person is informed they are interacting with AI, unless that is obvious to a reasonably well-informed and observant person from the circumstances.
  • Synthetic content: the provider of a system generating or manipulating audio, image, video or text is to ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. The obligation has exceptions, among them standard editing that does not substantially alter the content.
  • Emotion recognition and biometric categorisation: the deployer informs the people exposed to the system and observes the applicable data protection rules.
  • Deepfakes: the deployer discloses that the content has been artificially generated or manipulated. For artistic, satirical, creative or analogous works, the manner of disclosure may be adapted so as not to hamper enjoyment of the work.
  • Text on matters of public interest: disclosure is required where a deployer publishes text generated or manipulated by AI. An exception covers content that underwent human review or editorial control where a natural or legal person holds editorial responsibility for publication.

For content-generating systems placed on the market before 2 August 2026, the amendment allowed technical marking to be brought into line by 2 December 2026. The Commission has published guidelines and a voluntary transparency code; the code is a way of demonstrating compliance, not an exemption from article 50.

GPAI: the obligations fall mainly on model providers

A general-purpose AI model displays significant generality and can competently perform a wide range of distinct tasks, which means it can be integrated into many downstream systems or applications. The obligations of chapter V fall above all on model providers, not on every company using an off-the-shelf chatbot.

Obligations of every GPAI provider

  • drawing up and keeping up to date the model's technical documentation;
  • supplying downstream system providers with the information needed to understand the model's capabilities and limitations;
  • putting in place a policy to comply with Union copyright law, including respecting reservations of rights for text and data mining;
  • publishing a sufficiently detailed summary of the content used to train the model, following the Commission's template;
  • appointing a representative in the EU where the provider is established in a third country, unless an exception applies.

Certain models released under a free and open licence may be exempt from part of the documentation and information obligations where they meet the conditions of article 53(2). The exemption does not cover the copyright policy or the training data summary, and does not apply to models with systemic risk.

GPAI with systemic risk

A presumption of systemic risk arises where the cumulative amount of computation used for training exceeds 1025 FLOP. The Commission may also designate a model on the basis of its capabilities or impact, so the compute threshold is not the only route. The provider of such a model must, among other things, conduct and document evaluations, assess and mitigate systemic risks at Union level, report serious incidents and ensure an adequate level of cybersecurity.

Commission guidelines set out the scope of the obligations, a working threshold for qualifying models as GPAI, and rules on model modification [8]. The voluntary GPAI Code of Practice, published in July 2025 and recognised by the Commission and the AI Board as an adequate tool, helps demonstrate compliance on transparency, copyright and the safety of models with systemic risk [9]. It is not a certificate and does not shift responsibility away from the provider.

AI literacy after the change to article 4

Since 2 February 2025 providers and deployers have had to take measures supporting the development of AI literacy among their staff and other people dealing with the operation or use of systems on their behalf. After the 2026 amendment, article 4 does not require guaranteeing a particular or "sufficient" level in every individual. The measures are to be matched to those people's knowledge, experience, education and training, and to the context in which the system is used [10].

The law imposes no certificate, no annual training and no "AI officer" post. Good, proportionate practice nevertheless includes:

  • inventorying the tools and the people who use them;
  • distinguishing roles: ordinary user, person verifying output, administrator, builder or integrator;
  • covering the limitations of the specific tool, hallucinations, bias, protection of data and secrets, copyright, safe prompting and how to escalate errors;
  • keeping an internal record of activity, participants and updates, even though the AI Act requires no special certificate;
  • strengthening the programme after a change of model, use, affected groups or risk profile - not merely by the calendar.

Simply telling staff to read the manual may not be enough. On the other hand a small office using a tool for editing text does not need the programme appropriate to a team deploying AI in recruitment or diagnostics.

Supervision in Poland and regulatory sandboxes

It is no longer accurate to say that the Polish authority "is yet to be chosen". The act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026 item 1003) was promulgated on 27 July and entered into force in substance on 11 August 2026. Some provisions - including articles 8 to 18 and chapters 3 to 5, 8 and 9 - start to apply on 28 October 2026 [11].

The act designates the Commission for the Development and Security of Artificial Intelligence as the market surveillance authority and single point of contact. Its tasks include supervising compliance with the AI Act and the national statute, conducting proceedings, information activity, issuing individual opinions, and creating and running regulatory sandboxes. For certain products and sectors, competence remains linked to the existing authorities under sectoral law.

A regulatory sandbox is a controlled environment for developing, training, validating or testing an innovative system under the supervision of a competent authority. Participation is meant to increase legal certainty and ease market entry, but it does not suspend the AI Act, the GDPR or liability for damage. At least one national sandbox is to be operational by 2 August 2027; the amendment also allowed for a Union-level sandbox.

Enforcement and penalties

The level of a fine is not automatic. The authority takes into account, among other things, the nature, gravity and duration of the infringement, its effects, intent or negligence, remedial action, cooperation and the size of the entity. The maximum ceilings in article 99 are:

  • EUR 35 million or 7 per cent of total worldwide annual turnover for the preceding year - for infringing the prohibitions in article 5; for an undertaking the higher figure applies;
  • EUR 15 million or 3 per cent of turnover - for infringing specified obligations of operators and notified bodies, including deployer obligations under article 26 and transparency under article 50;
  • EUR 7.5 million or 1 per cent of turnover - for supplying incorrect, incomplete or misleading information to notified bodies or competent authorities in response to a request.

For small and medium enterprises, including start-ups, the maximum fine is capped by the lower of the relevant fixed and percentage figures. The Digital Omnibus extended some of those reliefs to small mid-cap companies, though not for the highest ceiling covering prohibited practices. GPAI providers fall under article 101: the Commission may impose up to EUR 15 million or 3 per cent of worldwide turnover, whichever is higher. The enforcement framework operated by the AI Office and national authorities has been in operation since August 2026 [12].

The AI Act, the GDPR, NIS2 and standards

The GDPR

The AI Act creates no legal basis for processing personal data and does not replace the GDPR. An organisation has to establish a basis under article 6 of the GDPR independently, and for special categories a condition under article 9 as well. A data protection impact assessment is required where the planned processing is likely to result in a high risk to rights and freedoms - not automatically for every AI project. Article 22 of the GDPR concerns decisions based solely on automated processing which produce legal effects or similarly significantly affect a person, with the exceptions and safeguards provided [13].

NIS2 and cybersecurity

NIS2 applies only where the organisation and its services fall within the scope of that directive or of the national transposing law. Not every model provider, and not every company using cloud, is automatically a NIS2 entity. Where the regimes overlap, managing vulnerabilities, incidents, the supply chain and continuity can support the robustness and cybersecurity requirements of the AI Act, but compliance with one does not prove compliance with the other.

ISO/IEC 42001 and harmonised standards

ISO/IEC 42001:2023 sets requirements for an AI management system and can bring order to policies, roles, impact assessment and improvement [14]. Certification to that standard is not required by the AI Act and does not by itself give a presumption of conformity with the regulation.

A presumption of conformity with specified requirements can follow from voluntary application of a European harmonised standard, but only once its reference has been published in the Official Journal of the EU. Those two events have to be kept apart: publication of a standard by CEN-CENELEC and citation of it by the Commission in the Official Journal are separate steps, and only the second has legal effect.

On 12 July 2026 CEN-CENELEC published EN 18286:2026 "Artificial intelligence - Quality management system for EU AI Act regulatory purposes", the first European standard created for the AI Act. It is no longer a draft prEN [16]. As at 24 August 2026 its reference has not yet been published in the Official Journal, so applying it does not give a presumption of conformity under article 40; work on the remaining standards from the Commission's standardisation request continues [15]. Implementing EN 18286 can therefore tidy up a quality management system and shorten the later road to compliance, but for now it is a business decision rather than a legal shortcut.

Checklist: what an organisation should do now

  1. Build an inventory. Record the system name, provider, version, business owner, purpose, users, input data and recipients of the output.
  2. Check the definition. Separate AI systems from ordinary deterministic automation.
  3. Establish the role. For each use, determine whether the organisation is a deployer, provider, importer or distributor, and whether changes shift the provider's obligations onto it.
  4. Rule out prohibited practices. Document the analysis of the current prohibitions and plan a check of the two new ones before 2 December 2026.
  5. Assess high risk. Check both routes under article 6 and the specific entries in annexes I and III; do not classify on the strength of an industry name alone.
  6. Implement article 50. Determine who provides the information about interacting with AI, the technical marking of content, and disclosure of deepfakes or text on public matters.
  7. Develop competence. Match measures to roles, tools, data, uses and affected people; keep evidence of what was done.
  8. Join the analysis to the GDPR. Check legal bases, minimisation, transfers, retention, contracts, article 22 and whether an impact assessment is needed.
  9. Manage providers. Obtain instructions, limitations, information about logs, security, data, model changes and sub-processors, and agree incident handling.
  10. Prepare human oversight. Define genuine authority to challenge, halt or reverse an output, and test it.
  11. Set the incident path. Connect user reports, security, data protection, compliance and the provider contact.
  12. Keep the assessment current. Repeat it after a change of model, purpose, data, integration, affected groups or law - not just once a year.

Frequently asked questions

Does the whole AI Act apply from 2 August 2026?

Most provisions apply from that date, but not all. The requirements for high-risk systems under annex III were postponed to 2 December 2027, and for systems linked to products under annex I to 2 August 2028. The two new prohibitions start to apply on 2 December 2026.

Is a company using ChatGPT or Copilot covered by the AI Act?

If the organisation uses such a system under its own authority in a professional capacity, it is as a rule a deployer. It must observe the prohibitions and take measures supporting staff competence. Further obligations depend on the use. Merely using an off-the-shelf tool does not make a company a GPAI model provider and does not automatically mean high risk.

Does every piece of AI-assisted material have to be labelled?

No. The provider of a generative system is responsible for the technical, machine-readable marking of outputs within the scope of article 50(2). A publisher has separate obligations chiefly for deepfakes and for texts on matters of public interest; for such texts there is an exception covering human review or editorial control combined with responsibility for publication.

Does an ordinary website chatbot need registration in the EU database?

An ordinary informational chatbot does not become a high-risk system for that reason and is as a rule not subject to the registration applying to such systems. From 2 August 2026, however, a person should know they are communicating with AI unless that is obvious. If the system serves another, high-risk purpose, the whole case is assessed under article 6 and the annexes, and the registration obligations are assigned to the appropriate role.

Does AI literacy mean a mandatory annual certificate?

No. After the amendment, article 4 requires measures supporting the development of competence, matched to staff knowledge and the context of use. It imposes no particular level, certificate or single training format. Internal documentation of what was done is nevertheless sensible evidence that the obligation was discharged properly.

Who supervises the AI Act in Poland?

The act of 3 July 2026 designates the Commission for the Development and Security of Artificial Intelligence as the market surveillance authority and single point of contact. At EU level the AI Office supervises GPAI providers and certain systems within its competence. In regulated sectors the relevant sectoral authorities also retain a role.

Does ISO/IEC 42001 confirm AI Act compliance?

Not automatically. The standard can support an AI management system, but a certificate does not replace classifying the system, the conformity assessment or discharging specific obligations. A presumption of conformity comes only from an appropriate harmonised standard whose reference has been published in the Official Journal, and only within the scope of that reference.

What are the maximum penalties?

For prohibited practices: up to EUR 35 million or 7 per cent of worldwide turnover. For certain other infringements: up to EUR 15 million or 3 per cent. For incorrect, incomplete or misleading information supplied in response to a request: up to EUR 7.5 million or 1 per cent. Lower ceilings apply to small and medium enterprises, and the actual fine has to be proportionate to the specific infringement.

Need consulting in this area?

A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.

Bibliography and sources

Sources as at 24 August 2026. The basis is the text of the law and official material from the institutions responsible for applying it. Commission guidance is auxiliary; what binds is the text of the legal acts and the interpretation of the competent courts.

  1. [1]prawo UEParlament Europejski i Rada UE. Rozporządzenie (UE) 2024/1689 - tekst skonsolidowany na 27 lipca 2026 r. · EUR-Lex
  2. [2]prawo UEParlament Europejski i Rada UE (2026). Rozporządzenie (UE) 2026/1744 - Digital Omnibus on AI · EUR-Lex
  3. [3]wytyczneKomisja Europejska (2025, aktualizacja 2026). Guidelines on the definition of an artificial intelligence system · Shaping Europe's digital future
  4. [4]informacja urzędowaKomisja Europejska (aktualizacja 3 sierpnia 2026). AI Act - regulatory framework for AI · Shaping Europe's digital future
  5. [5]wytyczneKomisja Europejska (2025). Guidelines on prohibited artificial intelligence practices · Shaping Europe's digital future
  6. [6]projekt wytycznychKomisja Europejska (2026). Draft guidelines on the classification of high-risk AI systems · Shaping Europe's digital future
  7. [7]wytyczneKomisja Europejska (2026). Guidelines on transparency obligations for providers and deployers of AI systems · Shaping Europe's digital future
  8. [8]wytyczneKomisja Europejska (2025, aktualizacja 2026). Guidelines for providers of general-purpose AI models · Shaping Europe's digital future
  9. [9]kodeksKomisja Europejska i AI Board (2025-2026). General-Purpose AI Code of Practice · Shaping Europe's digital future
  10. [10]Q&AKomisja Europejska (aktualizacja 2026). AI Literacy - Questions & Answers · Shaping Europe's digital future
  11. [11]prawo polskieSejm RP (2026). Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji, Dz.U. 2026 poz. 1003 · ELI / Dziennik Ustaw
  12. [12]informacja urzędowaKomisja Europejska (aktualizacja 24 sierpnia 2026). The enforcement framework of the AI Act · Shaping Europe's digital future
  13. [13]prawo UEParlament Europejski i Rada UE (2016). Rozporządzenie (UE) 2016/679 (RODO) · EUR-Lex
  14. [14]normaISO/IEC (2023). ISO/IEC 42001:2023 - Artificial intelligence management system · ISO
  15. [15]normalizacjaKomisja Europejska (aktualizacja 3 sierpnia 2026). Standardisation of the AI Act · Shaping Europe's digital future
  16. [16]normaCEN-CENELEC (2026). EN 18286:2026 - Artificial intelligence - Quality management system for EU AI Act regulatory purposes, opublikowana 12 lipca 2026 r. · CEN-CENELEC
4crypto.eu