Poland has a national AI statute. The Act of 3 July 2026 on artificial intelligence systems was published at Dz.U. 2026 poz. 1003 on 27 July 2026 and entered into force on 11 August 2026. Its enforcement machinery, including inspections, proceedings, fines and the criminal provisions, switches on separately on 28 October 2026. The Act creates KRiBSI as Poland's market surveillance authority and single point of contact, and gives operators something unusual and genuinely useful: a right to request a binding individual opinion from the regulator. Alongside it, the EU AI Act applies directly, on the timetable as amended by the Digital Omnibus. This guide sets out both layers and what an operator should do between now and late October.
Key takeaways
- Poland has an enacted national AI statute: the Act of 3 July 2026 on artificial intelligence systems, Dz.U. 2026 poz. 1003, in force since 11 August 2026. Its inspection, procedure, settlement, fine and criminal chapters apply from 28 October 2026.
- KRiBSI, the Commission for the Development and Safety of Artificial Intelligence, is created by Article 125(1) and designated by Article 5 as the market surveillance authority under Article 70(1) of the EU AI Act and the single point of contact under Article 70(2). It is not yet staffed: the Sejm, with Senate consent, must appoint its Chair within two months of entry into force, and it must hold its first sitting within three months.
- Articles 8 to 14 create a binding individual opinion. Any operator can ask KRiBSI whether a system is within scope or how a duty applies, and receive an answer within 30 days, or 60 in complex cases, that binds KRiBSI and other state bodies. This is the most practically valuable instrument in the Act.
- Polish fines are not a separate ceiling. Article 104(1) applies the amounts in Chapter XII of Regulation (EU) 2024/1689, converted to zloty at the National Bank of Poland average rate published on 28 January of the relevant year. The Act adds misdemeanour liability for obstructing an inspection or ignoring a Commission decision.
- Under the EU AI Act, Article 5 prohibitions have applied since 2 February 2025, GPAI provider obligations and the Chapter XII penalty regime since 2 August 2025, and Article 50 transparency obligations since 2 August 2026. Annex III high-risk obligations, including Article 26 deployer duties, now apply from 2 December 2027, and Annex I obligations from 2 August 2028, under Regulation (EU) 2026/1744.
How Poland got here, and why the sequence matters
Poland did not meet the EU AI Act's 2 August 2025 deadline for designating national competent authorities. Its bill reached the Sejm as government print 2443 on 9 April 2026, had its first reading on 29 April, passed third reading on 11 June, went to the Senate on 25 June, returned for the Sejm to resolve the Senate's amendments on 3 July, was signed by the President on 24 July and published on 27 July. It entered into force on 11 August 2026, nine days after the Article 50 transparency obligations began to apply across the EU.
That lateness had no effect on what operators owed in the interim. Regulation (EU) 2024/1689 applies uniformly whether or not a Member State has designated anyone. What the sequence does affect is who an operator talks to, and when. The commission that will conduct Poland's first domestic enforcement inquiries now exists in law, has budget limits set by Article 126, and has a statutory composition, but has no appointed members. The Act's own timetable acknowledges this by holding the enforcement chapters back to 28 October 2026.
The Act on artificial intelligence systems and KRiBSI
The Act is Poland's vehicle for satisfying the EU AI Act's Article 70 requirement to designate national market surveillance and notifying authorities. It goes further by creating a dedicated body rather than distributing supervision across existing regulators without a central point.
Article 125(1) creates the Komisja Rozwoju i Bezpieczenstwa Sztucznej Inteligencji, KRiBSI, the Commission for the Development and Safety of Artificial Intelligence. Article 5(1) makes it the market surveillance authority within the meaning of Article 70(1) of the Regulation, and Article 5(2) makes it the single point of contact under Article 70(2). Article 19(1) sets its composition: a Chair, two Deputy Chairs, and four members designated respectively by the President of the Office of Competition and Consumer Protection (UOKiK), the Polish Financial Supervision Authority (KNF), the National Broadcasting Council (KRRiT), and the President of the Office of Electronic Communications (UKE). Sectoral expertise is built into the body rather than left beside it.
What is outstanding is staffing, not existence. Article 125(2) requires the Sejm, with the consent of the Senate, to appoint the Chair within two months of entry into force. Article 125(3) requires the first sitting within three months. On the Act's own commencement date those deadlines fall in October and November 2026. Until the Chair is appointed, an operator cannot direct a compliance inquiry to KRiBSI and expect an answer.
The notifying authority is separate. Under Chapter 6 the minister responsible for informatisation, the Minister of Digital Affairs, is the notifying authority, with the Polish Centre for Accreditation handling accreditation of conformity assessment bodies.
Article 2 carves out national defence, the special services operating under the ABW, AW, SKW and SWW statutes, and defined research and development. Oversight of the special services' own AI use sits with the Prime Minister or the Minister Coordinator of Special Services, not with KRiBSI.
The binding individual opinion, and why it is the point
Articles 8 to 14 of the Act create an instrument that has no direct equivalent in the Regulation. An operator can apply to KRiBSI for an individual opinion (opinia indywidualna) on how the rules apply to its situation. KRiBSI must answer within 30 days, extendable to 60 in complex cases. The opinion binds KRiBSI and other state bodies. The fee is refundable in defined circumstances, and the opinion has no effect if the application contained a false declaration.
For an operator facing a genuine classification question, whether a particular agent is a high-risk system under Annex III, whether a workflow crosses the Article 50 disclosure threshold, this converts an open legal risk into a written answer the state cannot later disown. It is worth building the internal process to use it before KRiBSI is busy. Note that these articles are among those that only commence on 28 October 2026.
UODO, KNF and the other regulators: what the Act actually gives them
The Urzad Ochrony Danych Osobowych, Poland's data protection authority, is not designated as a market surveillance authority anywhere in the Act. Its role is cooperation. Article 20(1)(3) has it cooperate with KRiBSI on Article 57(10) matters, Article 92 has its President provide positions to KRiBSI and to regulatory sandbox participants, Article 32(2)(3) gives it one seat on the recruitment panel for Deputy Chairs, and Article 123 inserts a new Article 59a into the Polish Data Protection Act requiring the President of the Office to cooperate with KRiBSI. UODO's own comments on the bill, published on 23 April 2026, complained that the cooperation rules were imprecise and that it had no voting right on the Commission.
That does not make UODO irrelevant. Its GDPR powers apply directly and immediately to any AI system that processes personal data, entirely independent of AI Act designation. An AI system used for credit scoring, recruitment screening or biometric identification engages UODO's jurisdiction today. On 6 August 2026 UODO published a set of four practical checklists under the title "Zanim wdrozysz narzedzie AI, sprawdz czy jest ono zgodne z zasadami RODO", one version of which also flags AI Act duties including risk classification and the fundamental rights impact assessment. That is the current UODO material on AI, and it is a more useful starting point than any general profiling guidance.
For financial institutions the more consequential allocation is in the Regulation itself. Article 74(6) of Regulation (EU) 2024/1689 makes the financial supervision authority the market surveillance authority for high-risk AI systems placed on the market or used by regulated financial institutions, where the use is directly connected to the financial service. Article 121 of the Polish Act inserts a new Article 17h into the Act on financial market supervision requiring KNF and KRiBSI to cooperate and exchange information. A Polish bank or insurer deploying a high-risk AI system therefore answers to KNF on that system, not to KRiBSI in the first instance.
Separately, Article 74(8) of the Regulation requires Member States to designate data protection authorities, or authorities designated under Articles 41 to 44 of Directive (EU) 2016/680, as market surveillance authorities for Annex III point 1 systems used in law enforcement, border management, justice and democracy, and for Annex III points 6, 7 and 8. This is a category rule about law enforcement and fundamental rights, not a general personal data rule, and an earlier version of this guide misdescribed it as Article 70(2).
UOKiK retains its consumer protection powers over AI systems that interact directly with consumers, including chatbots and recommendation systems, through its existing unfair commercial practices framework. UKE regulates AI within telecommunications services and KRRiT within its media remit. Each also seats a member on KRiBSI.
What the EU AI Act requires in Poland, and when
Regulation (EU) 2024/1689 is directly applicable law in every EU Member State without requiring national transposition. Its obligations arrive in stages, and the stages changed in July 2026. The Digital Omnibus on AI was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, six days before the original high-risk deadline. It moved the Annex III stand-alone high-risk obligations, including the Article 26 deployer duties, from 2 August 2026 to 2 December 2027, and the Annex I obligations for high-risk AI embedded in regulated products to 2 August 2028.
What was not deferred still applies. The Article 5 prohibitions have been enforceable since 2 February 2025, although the new prohibitions the Omnibus inserted, covering child sexual abuse material and non-consensual intimate imagery, apply from 2 December 2026. The general-purpose AI provider obligations have applied since 2 August 2025, as has the whole of Chapter XII, which contains the Article 99 penalty regime. The Article 50 transparency obligations, which reach any operator running a chatbot or generating synthetic media, have applied since 2 August 2026, with a transitional period to 2 December 2026 for machine-readable marking under Article 50(2) by generative systems already on the market. By 2 August 2027 each Member State must operate at least one AI regulatory sandbox. High-risk systems intended for use by public authorities have until 2 August 2030.
The substantive Article 26 standard is settled even though its deadline has moved: deployers of high-risk AI systems must use the system in accordance with the provider's instructions, assign human oversight to individuals with the necessary competence, monitor the system's operation, and keep the logs the system automatically generates. The deferral is a change of date, not of content, and the documentation takes as long to build either way.
For a full explanation of how the EU AI Act applies as directly effective law, see the EU AI Act extraterritorial reach guide and the EU AI Act Member State transposition tracker.
Penalty exposure for Polish operators
Article 99 of the EU AI Act sets the ceilings, and Poland adopts them rather than inventing its own. Article 99(3) sets EUR 35,000,000 or 7 per cent of total worldwide annual turnover for the Article 5 prohibited practices. Article 99(4) sets EUR 15,000,000 or 3 per cent for the other operator obligations, including the provider duties in Article 16 and the deployer duties in Article 26. Article 99(5) sets EUR 7,500,000 or 1 per cent for supplying incorrect, incomplete or misleading information. In each case the higher of the two figures applies, except that under Article 99(6) an SME or start-up faces the lower of the two.
Article 104(1) of the Polish Act has KRiBSI impose administrative fines in the cases, amounts and conditions set out in Chapter XII of the Regulation. Article 104(4) converts the euro figures into zloty at the average National Bank of Poland exchange rate published on 28 January of the relevant year. Fines are paid to the state budget under Article 106, with deferral and instalments available.
The Act also builds in routes to reduce exposure. Chapter 5 allows a settlement, under which KRiBSI may lower a fine. Article 107 permits a further reduction of at least 10 per cent where the operator implements the actions set out in a prior warning and the breach caused no harm. Appeals against KRiBSI fine decisions go to the Sad Okregowy w Warszawie sitting as the competition and consumer protection court, through a new division of the Civil Procedure Code for AI cases, with a fixed fee of PLN 1,000 for an appeal and PLN 500 for a complaint against a ruling.
Beyond administrative fines, Articles 112 to 114 create misdemeanour liability. Obstructing an inspection, or failing to comply with a KRiBSI decision under Article 63(2), is punishable by restriction of liberty or a fine, including for individuals acting on behalf of a legal entity. All of this commences on 28 October 2026.
Separately and concurrently, where an AI system processes personal data unlawfully, UODO can impose administrative fines under the GDPR framework of up to EUR 20 million or 4 per cent of worldwide annual turnover. The two regimes address different legal wrongs even where the facts overlap.
Insurance and liability considerations for AI operators in Poland
The market for AI-specific liability insurance available to Polish operators mirrors the broader European market rather than developing a distinct domestic character. Munich Re's aiSure product and Armilla's Lloyd's-backed AI coverage are accessible to Polish enterprises through the same European broker channels available elsewhere in the EU. As with other jurisdictions, these carriers assess governance documentation quality as part of underwriting, meaning a Polish operator with a well-documented Article 26 operator file and UODO-compliant data governance is positioned for better coverage terms than one without.
Separately, the revised EU Product Liability Directive, Directive (EU) 2024/2853, was published in the Official Journal on 18 November 2024 and entered into force on 8 December 2024. It treats software, including AI systems, as a product for strict liability purposes. Member States must transpose it by 9 December 2026, on which date Directive 85/374/EEC is repealed. It is a directive, not a regulation, so it takes effect in Poland through Polish transposing legislation; no such Polish act had been located in the official register at the date of this verification pass.
What operators in Poland should do now
Poland now has both a domestic AI statute and the directly applicable Regulation. KRiBSI's incomplete formation does not reduce a Polish operator's obligations under either. The following steps represent the practical compliance priorities.
First, deal with what is already enforceable rather than what is deferred. Article 50 transparency obligations have applied since 2 August 2026: any conversational agent must disclose that it is an AI system, and synthetic audio, image, video and certain published text must be marked. Article 4 AI literacy remains an obligation on providers and deployers, though the Omnibus removed the mandated level, so the practical duty is to train the people who operate your systems well enough that human oversight is real. Then build and maintain the Article 26 operator file against the 2 December 2027 date rather than treating the deferral as a reason to stop: a current risk record, a human oversight assignment with named individuals of adequate competence, a logging schedule consistent with what the AI system generates automatically, and an incident protocol.
Second, assess UODO applicability to every AI system that processes personal data. Confirm a lawful basis for each processing activity, and where the AI system makes or substantially informs a consequential decision about a person, review UODO's guidance on automated decision-making and implement appropriate transparency and human review mechanisms consistent with GDPR Article 22.
Third, identify which existing sectoral regulator, KNF, UOKiK, UKE, or KRRiT, most closely corresponds to your deployment context, and review any AI-relevant guidance that regulator has already published under its existing powers, since that guidance reflects the most concrete compliance expectation currently enforceable in Poland outside the EU AI Act itself.
Fourth, read the Act on Artificial Intelligence Systems itself at Dz.U. 2026 poz. 1003 and diarise 28 October 2026, when its penalty provisions begin to apply, and watch for KRiBSI's constitution. A governance file built to EU AI Act and GDPR standard is very likely to satisfy the bulk of KRiBSI's domestic requirements, since the Act is designed to implement rather than diverge from the EU framework, but the domestic procedural obligations should be read from the statute rather than assumed from the Regulation.
Frequently asked questions
Does Poland have a standalone AI law in 2026?
Yes. The Act on Artificial Intelligence Systems of 3 July 2026 was published at Dz.U. 2026 poz. 1003 and entered into force on 11 August 2026. Its penalty provisions apply from 28 October 2026. It designates KRiBSI as Poland's market surveillance authority under Article 70 of the EU AI Act.
What is KRiBSI and has it been formally established?
KRiBSI, the Commission for the Development and Safety of Artificial Intelligence, is the body created by the Act on Artificial Intelligence Systems to serve as Poland's primary market surveillance authority, drawing on UOKiK, KNF, UKE, and KRRiT. As of 17 August 2026 it has not yet been constituted and cannot yet receive compliance inquiries, although the Act creating it is in force.
What is UODO's role in AI governance in Poland?
UODO, Poland's data protection authority, already has enforcement powers over AI systems that process personal data under the GDPR and its Polish implementing law. The Polish Act gives it a cooperation role with KRiBSI rather than designating it as a market surveillance authority. Under Article 74(8) of the EU AI Act, Member States must designate data protection authorities as market surveillance authorities for the Annex III law enforcement, border, justice and democracy categories. UODO is the most concrete near-term contact for Polish operators pending KRiBSI's establishment, and published four practical AI checklists on 6 August 2026.
Which EU AI Act obligations apply in Poland now?
Article 5 prohibitions since 2 February 2025, general-purpose AI provider obligations since 2 August 2025, and Article 50 transparency obligations since 2 August 2026. Annex III high-risk obligations, including the Article 26 deployer duties, now apply from 2 December 2027, and Annex I obligations from 2 August 2028, under Regulation (EU) 2026/1744, the Digital Omnibus, in force since 27 July 2026.
What penalties apply to AI operators in Poland?
Article 99 of the EU AI Act sets ceilings of EUR 35 million or 7 per cent of worldwide annual turnover for prohibited practices, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for misleading information, whichever is higher in each case. UODO can separately impose GDPR fines up to EUR 20 million or 4 per cent of worldwide annual turnover. The domestic penalty provisions of the Act on Artificial Intelligence Systems apply from 28 October 2026 and should be read from the published text of the Act.
How does Poland's approach compare to other EU Member States?
Poland chose a single dedicated commission rather than a distributed model. Ireland, by contrast, designated fifteen national competent authorities from existing sectoral regulators on 16 September 2025 and added a coordinating AI Office. Poland missed the EU AI Act's 2 August 2025 designation deadline and legislated in July 2026. A Member State by Member State designation picture is maintained on the transposition tracker rather than summarised here, because the position changes month to month.
References
- Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji, Dz.U. 2026 poz. 1003, published 27 July 2026, in force 11 August 2026, enforcement chapters in force 28 October 2026 (Article 127). dziennikustaw.gov.pl and api.sejm.gov.pl.
- Same Act, Article 5 (KRiBSI as market surveillance authority and single point of contact), Article 19(1) (composition), Articles 8 to 14 (binding individual opinions), Articles 104, 106 and 107 (fines, budget, reduction), Articles 109, 115 and 120 (appeals and fees), Articles 112 to 114 (misdemeanours), Articles 125 and 126 (creation, appointment deadlines, budget limits), Article 2 (scope carve-outs).
- Sejm legislative record, government print 2443, tenth term: submitted 9 April 2026, first reading 29 April 2026, passed 11 June 2026, Senate position 25 June 2026, Sejm resolution of Senate amendments and transmission to the President 3 July 2026, signed 24 July 2026. api.sejm.gov.pl.
- Urzad Ochrony Danych Osobowych (UODO). "Zanim wdrozysz narzedzie AI, sprawdz czy jest ono zgodne z zasadami RODO", four checklists, 6 August 2026. uodo.gov.pl. UODO comments on the bill, 23 April 2026.
- Uchwala nr 196 Rady Ministrow z dnia 28 grudnia 2020 r. w sprawie ustanowienia "Polityki dla rozwoju sztucznej inteligencji w Polsce od roku 2020", Monitor Polski 2021 poz. 23, in force 13 January 2021.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). Official Journal of the European Union, 12 July 2024. Articles 16 and 26 (provider and deployer obligations), 70 (national competent authorities), 74(6) and 74(8) (market surveillance for financial institutions and for law enforcement and fundamental rights categories), 99(3) to 99(6) (penalties), 113 (application dates).
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), published in the Official Journal 24 July 2026, in force 27 July 2026. Amends Article 113 so that Chapter III Sections 1 to 3 apply from 2 December 2027 for Annex III and 2 August 2028 for Annex I.
- Directive (EU) 2024/2853 on liability for defective products, Official Journal 18 November 2024, in force 8 December 2024, transposition deadline 9 December 2026, repealing Directive 85/374/EEC from that date.
- Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal). Cited for the principle that an operator cannot disclaim responsibility for its automated system's representations to customers.
- Munich Re, aiSure AI performance insurance product. Munich Reinsurance Company.
- Armilla, a Lloyd's of London coverholder offering affirmative AI liability and performance cover.