This page does not constitute legal advice. It is a checklist of what we review during every implementation and the documentation we prepare in case of an audit or complaint. For high-risk systems and medical data, we work alongside the client's legal counsel.
Everything hinges on one distinction. A provider builds an AI system and places it on the market. A deployer uses it in its business operations.
A company that implements a third-party chatbot or uses an AI model via API is a deployer. Its obligations are more limited, but it remains responsible for how the system operates within its processes.
Key dates for companies using AI
- in forceMandatory staff AI literacy (Art. 4) and prohibited practices under Art. 5, including workplace emotion recognition and social scoring.
- in forceTransparency (Art. 50): chatbots, voicebots, and assistants interacting with humans must disclose they are AI; synthetic content and deepfakes must be labeled. From this date, member states enforce regulations and impose penalties.
- in forceThe Act of July 3, 2026 on Artificial Intelligence Systems (Journal of Laws 2026, item 1003) enters into force. It establishes the Commission for the Development and Security of Artificial Intelligence (KRiBSI) at the Ministry of Digital Affairs.
- upcomingProvisions of the Act on inspections, proceedings, and penalties take effect. From this date, a client, employee, or competitor can file a complaint with KRiBSI regarding an AI system in a company.
- upcomingObligations for standalone high-risk systems under Annex III (including recruitment, employee evaluation, credit scoring, education). Deadline postponed from August 2, 2026 by the Digital Omnibus, published in the Official Journal of the EU on July 24, 2026.
- upcomingObligations for AI embedded in products covered by separate regulations (Annex I): machinery, medical devices, vehicles.

Five deployer obligations we check
AI literacy (Article 4)
Documented training activities tailored to risk and role: syllabus, attendee list, materials. There is no single mandatory course or certificate. What matters is proving after an incident that the people using the tool knew what was permitted and what was not.
Transparency disclosures (Article 50)
Every chatbot, voicebot, and assistant interacting with a customer or employee must state that it is AI. Generated content, including images and video, is labelled. This also applies to website bots and automated inbox replies.
Prohibited practices (Article 5)
Emotion recognition in the workplace and education, social scoring, subliminal manipulation. Rare in small and medium-sized enterprises, but recruitment tools and employee monitoring touch on this boundary.
GDPR for every external API
Model provider recorded in the processing register, data processing agreement signed, and cross-border transfers outside the EEA verified. Plus a decision on whether a data protection impact assessment (DPIA) is required, for example for customer profiling or employee monitoring.
High risk from December 2027
If a system impacts recruitment, employee evaluation, credit scoring, or education, deployer obligations apply from 2 December 2027: human oversight, log retention, informing employees. Build the register of such systems now, as it defines which rules apply.

Penalties
For prohibited practices, the AI Act sets fines up to 35 million EUR or 7% of annual worldwide turnover. For breaches of other obligations, including transparency, up to 15 million EUR or 3%. For small and medium-sized enterprises, the ceiling is the lower of the two amounts.
In Poland, inspections and fines are handled by KRiBSI under the Artificial Intelligence Systems Act. Provisions regarding penalties take effect on 28 October 2026.
In practice, documented training and an AI usage policy are the first things a regulator or opposing party requests in any AI-related dispute. Having no documentation is worse than having imperfect documentation.

What we prepare during implementation
AI acceptable use policy
What data can be pasted into tools, what cannot; which tools are approved; who approves new ones; consequences of circumvention.
Company AI system inventory
Name, provider, data types, business purpose, system owner, risk classification. A single table showing which regulations apply to each system.
Documented training (Article 4)
Curriculum tailored to roles, attendee list, materials, brief assessment. AI and automation training qualifies for funding from Baza Usług Rozwojowych, up to 83% of costs according to PARP data.
Read moreDisclosure copy (Article 50)
On your website, in bots, in automated reply footers, alongside generated assets. We use them ourselves: the generated content page on hexart.pl is an example.
Read moreGDPR records of processing activities and data processing agreement template
For every third-party model provider used in the implementation. If data cannot leave your company, an on-premise model on your own server is the alternative.
Read moreIncident response procedure
Who shuts down the system, who notifies clients, who logs events, within what timeframe. A single page that can be read at 7:00.

Legal status as of September 5, 2026. Sources: AI Act (EU Regulation 2024/1689), Digital Omnibus Regulation, and the Polish Act of July 3, 2026 on Artificial Intelligence Systems (Journal of Laws 2026, item 1003). This page does not replace legal advice.
Questions and answers
Frequently asked questions
Does a chatbot on our website have to disclose that it is AI?
Yes. Since August 2, 2026, Article 50 of the AI Act requires systems interacting with humans to disclose that they are AI, unless obvious from the context. This applies to website chatbots, voicebots, and automated inbox replies sent to customers.
Do we have to train employees on AI?
Yes. Since February 2, 2025, Article 4 of the AI Act requires AI literacy for staff, tailored to their role and risk level. There is no single mandatory course. Documented measures matter: training plan, attendee list, materials. National authorities enforce this from August 3, 2026.
Can an employee use ChatGPT for work?
Yes, provided the company defines what data can be pasted and from which account. Personal data, contracts, and HR matters should not enter the tool without a data processing agreement and a record in the register of processing activities. A one-page AI usage policy is sufficient, not a twenty-page rulebook.
Does this apply to a fifteen-person company?
Yes. Articles 4 and 50 have no company size threshold. For SMEs, the difference lies in penalties: the lower of the two amounts applies. The scope of documentation depends on risk. A company that drafts proposals with an AI assistant only needs a usage policy, a tool register, and a brief training session.
What changes on October 28, 2026?
Provisions of the Polish Act on Artificial Intelligence Systems concerning inspections, proceedings, and penalties take effect. From this date, a client, employee, or competitor can submit a complaint to KRiBSI regarding an AI system deployed in a company. The Act itself applies from August 11, 2026.
Other paths
What next
We want to startWhere to start AI implementation in a companyWhich process to pick first, how to measure it, and how to tell it has paid off.
We built it ourselvesReview of an AI implementation you built yourselfAn agent set up in Claude Code, n8n, or Make works until it does not. We check what happens when it stops.
GrantsAI implementation grants for companies in 2026PARP, KPO, FENG: which programs, what thresholds, and what we prepare for the application to make it submission-ready.- GeneratorImplementation plan in nine questionsIndustry, size, process, data, systems. In response, you receive recommendations, stages, cost benchmarks, responsibilities, and grants. Every item cites a source.
No-obligation call
One-day compliance audit
System register, usage policy, disclosure copy, and training plan. We start with 30 minutes: what you have, who uses it, and what data it contains.
