Poland has not enacted a standalone AI statute as of August 2026. Its domestic AI governance rests on a draft Act on Artificial Intelligence Systems that would establish a dedicated commission, KRiBSI, but that bill has not completed legislative passage. In the interim, the Personal Data Protection Office (UODO) and Poland's existing sectoral regulators supervise AI-related activity under their current powers. The EU AI Act's high-risk operator provisions entered into application across the EU on 2 August 2026, meaning Polish operators now carry the full weight of Article 26 deployer obligations and Article 99 penalty exposure regardless of whether KRiBSI has been formally constituted. This guide explains each layer and what operators should do now that enforcement is live.
Key takeaways
- Poland has no enacted standalone AI statute as of August 2026. The Ministry of Digital Affairs published a draft Act on Artificial Intelligence Systems in June 2025, proposing KRiBSI as the primary market surveillance authority, but the bill remains in the legislative process.
- KRiBSI, as drafted, would draw representatives from UOKiK, KNF, UKE, and KRRiT into a single coordinating commission. It has not been formally constituted and has no current enforcement powers, because the underlying Act has not passed.
- UODO, Poland's data protection authority, already has enforcement powers over AI systems that process personal data under the GDPR and its Polish implementing law, and is the most likely near-term contact for Polish operators pending KRiBSI's establishment.
- The EU AI Act's Article 9 through 17 provider obligations, Article 26 deployer obligations, and Article 99 penalties entered into application on 2 August 2026 across the EU, including Poland. This happened regardless of Poland's incomplete national designation, placing Poland alongside Germany, France, and the Netherlands as large Member States that entered enforcement without a fully constituted national authority.
- An operator file built to EU AI Act Article 26 standard, combined with UODO-compliant data governance, is the most defensible position available to a Polish operator today, and it will satisfy the bulk of KRiBSI's likely future requirements once the domestic Act is enacted.
The Polish AI regulatory landscape in brief
Poland is the sixth-largest economy in the European Union and has one of the region's fastest-growing technology sectors, with a substantial concentration of AI development activity in Warsaw, Kraków, and Wrocław. The Polish government has treated AI policy as a strategic priority since publishing its first national AI development policy in 2020, but that early strategic engagement has not yet translated into enacted AI-specific legislation. As of August 2026, the operative architecture in Poland is a draft national implementing act that has not passed, a data protection authority with established powers that predate the AI Act, and direct application of the EU AI Act itself as Regulation law.
This is a materially different position from Member States such as Italy, Ireland, Finland, Hungary, Lithuania, Malta, and Cyprus, which had completed formal Article 70 designation before the EU AI Act's operator provisions took effect on 2 August 2026. Poland sits instead alongside Germany, France, and the Netherlands: large, economically significant Member States that entered enforcement of the operator provisions without a fully constituted national authority in place. For operators, the practical consequence is not that obligations are lighter. The Regulation applies uniformly regardless of national designation status. The practical consequence is uncertainty about which body will conduct the first enforcement inquiries, and a corresponding need to build compliance documentation that is defensible to whichever authority eventually exercises jurisdiction.
The draft Act on Artificial Intelligence Systems and KRiBSI
Poland's Ministry of Digital Affairs published a draft Act on Artificial Intelligence Systems (ustawa o systemach sztucznej inteligencji) in June 2025, following an earlier 2024 concept paper. The draft Act is Poland's vehicle for satisfying the EU AI Act's Article 70 requirement to designate national market surveillance and notifying authorities, and it goes further by proposing a dedicated coordinating body rather than distributing supervision across existing regulators without a central point.
The centrepiece of the draft is the Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji, or KRiBSI (the Commission for the Development and Safety of Artificial Intelligence). As proposed, KRiBSI would function as the primary market surveillance authority and single point of contact with the European Commission and the AI Office, while incorporating sectoral expertise by drawing representatives from Poland's existing regulators: the Office of Competition and Consumer Protection (UOKiK) for consumer-facing AI and market conduct, the Polish Financial Supervision Authority (KNF) for AI used in financial services, the Office of Electronic Communications (UKE) for telecommunications-sector AI, and the National Broadcasting Council (KRRiT) for AI used in media and broadcasting contexts.
This model is structurally similar to Ireland's distributed approach, which drew fifteen national competent authorities from existing sectoral regulators, but Poland's draft creates a single commission rather than leaving the sectoral bodies to operate independently. The intended benefit is a coherent single point of contact for operators and for the Commission, avoiding the fragmentation that has complicated implementation in Member States pursuing a fully distributed model. The drawback, evident as of August 2026, is that a dedicated commission requires a specific legislative act to exist, and that act has not yet passed, whereas a distributed model can in principle activate more quickly by repurposing regulators that already exist.
As of August 2026, KRiBSI has not been formally constituted. It has no members, no budget allocation confirmed through enacted legislation, and no operative enforcement powers. Operators in Poland cannot direct compliance inquiries to KRiBSI because it does not yet function as a body capable of receiving them.
UODO: the practical near-term contact
The Urząd Ochrony Danych Osobowych, Poland's data protection authority, is not new and does not depend on the draft AI Act for its powers. UODO has supervised the processing of personal data in Poland under the GDPR and the Polish Act on the Protection of Personal Data since 2018, with a well-established enforcement track record including administrative fines against both public and private sector data controllers.
For AI operators, UODO's relevance rests on two grounds. First, its existing GDPR powers apply directly and immediately to any AI system that processes personal data, entirely independent of AI Act designation status. An AI system used for credit scoring, recruitment screening, biometric identification, or any other function involving personal data engages UODO's jurisdiction today, regardless of whether KRiBSI ever comes into existence. Second, under Article 70(2) of the EU AI Act, Member States are expected to designate data protection authorities as market surveillance authorities specifically for AI systems used in the high-risk categories most closely tied to personal data, including biometric identification systems and several of the employment and financial services use cases listed in Annex III. Even once KRiBSI is formally established, UODO is likely to retain a parallel role for these categories, following the same pattern seen in Italy, where the Garante retains its GDPR-linked Article 70(2) role alongside the National Cybersecurity Agency's general market surveillance function.
For a Polish operator assessing where to direct compliance engagement today, UODO is the most concrete and immediately actionable answer for any AI system that touches personal data. UODO has published general guidance on automated decision-making and profiling under GDPR Article 22 that, while not AI Act-specific, sets out expectations for transparency, human review, and data subject rights that substantially overlap with the AI Act's Article 14 human oversight and Article 13 transparency requirements for high-risk systems.
Sector regulators with existing AI-relevant powers
Beyond UODO, several of Poland's existing sectoral regulators, the same bodies proposed for representation within KRiBSI, already exercise powers relevant to AI deployments in their sectors, independent of the draft Act's passage.
The Polish Financial Supervision Authority (KNF) supervises banks, insurers, and investment firms, and has issued guidance addressing model risk management for algorithmic and AI-driven systems used in credit decisioning, fraud detection, and insurance underwriting. Financial institutions deploying AI agents for these functions are subject to KNF's existing supervisory expectations on model validation, explainability, and audit trail maintenance, independent of the AI Act's separate high-risk classification for credit-scoring systems under Annex III.
The Office of Competition and Consumer Protection (UOKiK) has consumer protection powers relevant to AI systems that interact directly with consumers, including AI chatbots and recommendation systems. UOKiK's existing unfair commercial practices enforcement framework applies to misleading or deceptive AI-generated representations made to consumers, in a manner analogous to the Moffatt v. Air Canada finding that an operator cannot disclaim responsibility for its automated system's representations to customers.
The Office of Electronic Communications (UKE) regulates AI use within telecommunications services, including automated customer service systems and network management AI, while the National Broadcasting Council (KRRiT) has begun addressing AI-generated content and deepfake disclosure within its media regulation remit.
EU AI Act enforcement is now live in Poland
The most significant development for Polish operators as of this publication is not domestic. Regulation (EU) 2024/1689 is directly applicable law in every EU Member State without requiring national transposition, and its high-risk operator provisions entered into application on 2 August 2026. The Digital Omnibus proposal to defer these obligations to 2 December 2027 was not formally adopted and published in the Official Journal before that date, so the original deadline stood. This means that from 2 August 2026, the full set of provider obligations under Articles 9 through 17, the deployer obligations under Article 26, the transparency obligations under Article 50, and the penalty regime under Article 99 apply directly to operators in Poland, exactly as they apply in every other Member State, regardless of KRiBSI's incomplete formation.
This creates a specific and immediate compliance position for Polish operators. The substantive legal standard is not in doubt and does not wait for domestic legislation: Article 26 requires deployers of high-risk AI systems to use the system in accordance with the provider's instructions, assign human oversight to individuals with the necessary competence, monitor the system's operation, and keep logs the system automatically generates. What is genuinely unresolved in Poland is which specific national body will conduct the first enforcement inquiries against a non-compliant operator. Until KRiBSI is constituted, the most probable interim answer is UODO for AI systems involving personal data, and the relevant sectoral regulator (KNF, UOKiK, UKE, or KRRiT) for AI systems within their existing domains, consistent with the pattern observed across other undesignated Member States including France and the Netherlands.
For a full explanation of how the EU AI Act applies as directly effective law and how enforcement is structured across Member States with incomplete national designation, see the EU AI Act extraterritorial reach guide and the EU AI Act Member State transposition tracker on agentliability.eu, which tracks designation status across all 27 Member States including Poland.
Penalty exposure for Polish operators
Two separate penalty regimes apply to Polish operators today, and a third is pending enactment. Under Article 99(2) of the EU AI Act, deployer and provider obligation violations for high-risk systems carry a penalty ceiling of EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. This applies directly as Regulation law and does not depend on KRiBSI's formation, since enforcement in the interim falls to whichever body, most likely UODO or the relevant sectoral regulator, exercises oversight in the specific use case.
Separately, where an AI system processes personal data unlawfully, UODO can impose administrative fines under the GDPR framework of up to EUR 20 million or 4 percent of worldwide annual turnover. These two regimes can apply concurrently to the same underlying AI deployment if it both qualifies as high-risk under the AI Act and involves unlawful personal data processing, since the two frameworks address different legal wrongs even where the facts overlap.
Poland's draft Act on AI Systems, once enacted, would add a domestic penalty structure and formalise KRiBSI's specific enforcement powers, but as of August 2026 this third layer remains prospective. Operators should not wait for its enactment to build compliance documentation, since the EU-level and UODO exposures are already live and unaffected by the domestic Act's legislative status.
Insurance and liability considerations for AI operators in Poland
The market for AI-specific liability insurance available to Polish operators mirrors the broader European market rather than developing a distinct domestic character. Munich Re's aiSure product, Armilla's Lloyd's-backed AI coverage, and the newer SME-focused entrants HSB and Testudo are accessible to Polish enterprises through the same European broker channels available elsewhere in the EU. As with other jurisdictions, these carriers assess governance documentation quality as part of underwriting, meaning a Polish operator with a well-documented Article 26 operator file and UODO-compliant data governance is positioned for better coverage terms than one without.
Separately, the revised EU Product Liability Directive (Directive 2024/2853), which applies from December 2026 and treats AI software as a product for strict liability purposes, will apply in Poland on the same terms as the rest of the EU once its implementation deadline arrives, independent of the domestic AI Act's status.
What operators in Poland should do now
The absence of enacted domestic AI legislation does not mean Poland is a low-governance environment, and the passing of the 2 August 2026 EU deadline without a fully constituted national authority does not reduce a Polish operator's obligations. The following steps represent the practical compliance priorities.
First, build and maintain the Article 26 operator file now that the deadline has passed rather than treating it as preparatory work. This means a current risk record, a human oversight assignment with named individuals of adequate competence, a logging schedule consistent with what the AI system generates automatically, and an incident protocol. This documentation is required under EU law directly and is not contingent on KRiBSI's formation.
Second, assess UODO applicability to every AI system that processes personal data. Confirm a lawful basis for each processing activity, and where the AI system makes or substantially informs a consequential decision about a person, review UODO's guidance on automated decision-making and implement appropriate transparency and human review mechanisms consistent with GDPR Article 22.
Third, identify which existing sectoral regulator, KNF, UOKiK, UKE, or KRRiT, most closely corresponds to your deployment context, and review any AI-relevant guidance that regulator has already published under its existing powers, since that guidance reflects the most concrete compliance expectation currently enforceable in Poland outside the EU AI Act itself.
Fourth, monitor the legislative progress of the draft Act on Artificial Intelligence Systems and KRiBSI's eventual constitution, but do not treat the Act's incomplete status as a reason to delay compliance work that is already legally required under the EU AI Act and GDPR. A governance file built to EU AI Act and GDPR standard today is very likely to satisfy the bulk of KRiBSI's eventual domestic requirements once the Act passes, since the draft is explicitly designed to implement rather than diverge from the EU framework.
Frequently asked questions
Does Poland have a standalone AI law in 2026?
No. As of August 2026, Poland has not enacted a standalone AI statute. The Ministry of Digital Affairs published a draft Act on Artificial Intelligence Systems in June 2025, which would establish KRiBSI as the primary market surveillance authority, but the bill had not completed parliamentary passage as of the EU AI Act's operator provisions taking effect on 2 August 2026. UODO and existing sectoral regulators are the practical points of contact in the meantime.
What is KRiBSI and has it been formally established?
KRiBSI, the Commission for the Development and Safety of Artificial Intelligence, is the body proposed under Poland's draft Act on AI Systems to serve as the country's primary market surveillance authority. As drafted, it would include representatives from UOKiK, KNF, UKE, and KRRiT. As of August 2026, KRiBSI has not been formally constituted because the underlying Act has not completed legislative passage, and it does not yet have operative enforcement powers.
What is UODO's role in AI governance in Poland?
UODO, Poland's data protection authority, already has enforcement powers over AI systems that process personal data under the GDPR and its Polish implementing law. Under Article 70(2) of the EU AI Act, data protection authorities are also expected to serve as market surveillance authorities for AI systems in specific high-risk categories involving personal data. UODO is the most likely near-term enforcement contact for Polish operators pending KRiBSI's formal establishment.
Are Polish operators subject to EU AI Act enforcement now that the deadline has passed?
Yes. Regulation (EU) 2024/1689 is directly applicable law in Poland without requiring national transposition. The Article 9 through 17 provider obligations, the Article 26 deployer obligations, and the Article 99 penalty regime entered into application on 2 August 2026 across the entire EU, including Poland, regardless of whether KRiBSI has been formally constituted.
What penalties apply to AI operators in Poland?
For high-risk AI systems, Article 99(2) sets a penalty ceiling of EUR 15 million or 3 percent of worldwide annual turnover. This applies directly in Poland as Regulation law. UODO can separately impose administrative fines under the GDPR framework, up to EUR 20 million or 4 percent of worldwide annual turnover, for AI systems that process personal data unlawfully. A domestic penalty structure under the draft Act on AI Systems remains pending enactment.
How does Poland's approach compare to other EU Member States?
Poland's position resembles the majority of EU Member States as of August 2026: a draft implementing act exists but formal legislative passage and Commission notification remain incomplete. This places Poland alongside Germany, France, and the Netherlands, three of the EU's largest economies that entered EU AI Act enforcement on 2 August 2026 without a fully designated national authority. Only a minority of Member States, including Italy, Ireland, Finland, Hungary, Lithuania, Malta, and Cyprus, had completed formal designation before the deadline.
References
- Ministry of Digital Affairs, Republic of Poland. Draft Act on Artificial Intelligence Systems (projekt ustawy o systemach sztucznej inteligencji), published for consultation June 2025.
- Proposed Commission for the Development and Safety of Artificial Intelligence (KRiBSI), as set out in the draft Act on AI Systems, June 2025 revision.
- Urząd Ochrony Danych Osobowych (UODO). Guidance on automated decision-making and profiling under GDPR Article 22.
- Regulation (EU) 2016/679 (GDPR), Article 22, and the Polish Act on the Protection of Personal Data implementing it.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). Official Journal of the European Union, 12 July 2024. Articles 9-17 (provider obligations), 26 (deployer obligations), 70 (national competent authorities), 99 (penalties).
- Komisja Nadzoru Finansowego (KNF). Guidance on model risk management for algorithmic systems in financial services.
- Urząd Ochrony Konkurencji i Konsumentów (UOKiK). Unfair commercial practices enforcement framework as applied to automated consumer-facing systems.
- Directive (EU) 2024/2853 on liability for defective products (Product Liability Directive), entered into force 9 December 2024, applicable from December 2026.
- Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal). Cited for the principle that an operator cannot disclaim responsibility for its automated system's representations to customers.
- EU AI Act Member State transposition status, tracked at agentliability.eu, including Poland's designation status relative to other Member States as of August 2026.
- Munich Re, aiSure AI performance insurance product. Munich Reinsurance Company.
- Armilla AI, AI performance guarantees and underwriting. Armilla AI Inc.