PL·EU AI Act series·Poland implementation·EU timeline checked August 2026

The EU AI Act in Poland: national implementation law enacted.

Poland enacted the Act of 3 July 2026 on AI systems (Dz.U. 2026 poz. 1003). The law establishes the national supervision, conformity, and sandbox framework, including KRiBSI. Appointments, operating procedures, and live filing routes should be checked against current official notices.

Talk to us All-EU material in the main guide →
Compliance lead DPO General Counsel CISO
Jul 2025
UODO publishes critique of advisory-only role
Aug 2025
GPAI obligations live; Polish authority designation slips
Jul 2026
Poland enacts and publishes its AI-systems implementation law
Dec 2027
Relevant Annex III high-risk obligations apply under the AI Omnibus in force since 27 July 2026
Status reviewed 26 August 2026 · Poland

The Act of 3 July 2026 on AI systems was enacted, signed, and published as Dz.U. 2026 poz. 1003. It replaces the draft-status account previously shown on this page and establishes the national institutional framework, including KRiBSI.

Earlier UODO comments concerned draft legislation and should not be presented as the current allocation. Confirm the final statutory role, current appointments, operational capacity, and competent route for a specific system from the enacted text and current Polish authority notices.

Who supervises what in Poland

The enacted law establishes Poland’s national AI Act institutional framework, including KRiBSI, while existing regulators retain powers under their own laws. The competent authority, notifying authority, Article 77 body, and sector route for a specific system should be confirmed from the final text and current official designations.

AuthorityMandateEU AI Act role (reviewed August 2026)
KRiBSI Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji Established under the enacted 2026 law within Poland’s national AI Act implementation framework. Confirm current appointments, procedures, and operational notices before naming a live filing route.
Ministry of Digital Affairs (MC) Ministerstwo Cyfryzacji National digital-policy and implementation role under the enacted framework. Confirm the current notifying-authority and operational-support allocation from the final text and official notices.
UODO Urząd Ochrony Danych Osobowych (data protection authority) Retains its GDPR powers where AI systems process personal data. Confirm any AI Act role from the enacted law and current Article 77 and authority notices rather than relying on the superseded draft debate.
KNF Komisja Nadzoru Finansowego (financial supervision authority) Existing financial-supervision powers may overlap with AI Act duties. Confirm whether KRiBSI, KNF, or another body is competent for the specific system and obligation.
URPL Urząd Rejestracji Produktów Leczniczych (medicines, devices, biocidal products office) Healthcare AI sectoral regulator; medical-device conformity overlap (MDR/IVDR).
PIP Państwowa Inspekcja Pracy (national labour inspectorate) Workplace AI: emotion-recognition prohibition, worker monitoring; Article 77 fundamental-rights body.
RPO Rzecznik Praw Obywatelskich (Ombudsperson) Article 77 fundamental-rights body; non-discrimination supervision on AI-affected decisions.
RPP Rzecznik Praw Pacjenta (Patient Rights Ombudsperson) Article 77 fundamental-rights body in healthcare; clinical-AI patient-impact supervision.
Final-law check

UODO commented on earlier drafts, but those comments do not establish the allocation under the enacted Act. Where personal data is processed, UODO’s GDPR powers remain relevant; the competent AI Act route should be confirmed from the final law and current authority notices.

Polish sector overlays

The substantive obligations in Articles 9 to 15 apply EU-wide. Poland’s enacted law supplies the national institutional layer. The exact competent route depends on the system, operator role, product and sector law, and current implementation notices; the combinations below are issues to check, not a definitive jurisdictional allocation.

SectorPolish regulators on top of the AI Act
Healthcare AICheck the applicable medical-device, reimbursement, personal-data, patient-rights, and interoperability regimes separately. Confirm the current AI Act competent route for the specific product and use.
Financial servicesKNF on conduct, prudential, and AML; UODO on customer-data lawful basis. Anti-fraud models continue under existing CRR/MiFID frameworks.
IT services and outsourcingPoland’s strong IT outsourcing sector means many domestic providers face provider obligations under Article 16 even when the deployer sits in another member state. Cross-border conformity-assessment coordination is the main complexity.
ManufacturingProduct-embedded AI may require Article 6(1), Annex I, and sector product-safety analysis. Annex III(2) is limited to the critical-infrastructure uses and conditions listed there, not industrial systems generally.
Public administrationCheck AI Act operator duties, GDPR supervision where personal data is processed, and the current Article 77 fundamental-rights designations. Do not infer a single horizontal authority for every issue.
Workplace AIPIP holds the prohibited-practice line on emotion recognition and biometric categorization in workplaces; works-council co-determination under the Labour Code applies in parallel.

Regulatory sandbox

The enacted 2026 law addresses Poland’s national AI regulatory-sandbox framework. Confirm current eligibility, application procedures, participating authorities, and opening dates from KRiBSI or the Ministry of Digital Affairs. Existing sector innovation programs should not be described as AI Act sandboxes without a current primary source establishing that status.

Articles 9 to 15, conformity assessment, GPAI, penalties

These obligations apply EU-wide and are not Poland-specific. To keep this page focused on locality, the in-depth treatment of Articles 9 to 15, the conformity-assessment workflow, GPAI provider duties, and the Article 99 penalty structure is maintained on the main guide.

One timing note reaches every member state, Poland included: Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028. Other AI Act provisions retain their own dates.

↑ For all-EU material, see the main guide

TopicAnchor on the main guide
Articles 9 to 15 explainerguide-eu-ai-act#requirements-by-category
Article 12 logging requirementsguide-eu-ai-act#requirements-by-category
Conformity-assessment workflowguide-eu-ai-act#compliance-roadmap
GPAI obligations and Code of Practiceguide-eu-ai-act#gpai-requirements
Article 99 penalty structureguide-eu-ai-act#penalties-enforcement
Member-state implementation tableguide-eu-ai-act#member-states

References

  1. European Union. Regulation (EU) 2024/1689 (EU AI Act). EUR-Lex 32024R1689.
  2. Blavatnik School of Government, Oxford. AI Act’s enforcement gap: what Poland’s new regulator reveals about Europe’s challenge. bsg.ox.ac.uk.
  3. Poland. Act of 3 July 2026 on AI systems, Dz.U. 2026 poz. 1003. ISAP official record.
  4. Sejm. Legislative history for the Act on AI systems. Official proceeding record.
  5. Technology’s Legal Edge. State of the Act: EU AI Act implementation in key Member States, November 2025. technologyslegaledge.com.
  6. European Parliament. AI Act delayed application; ban on nudifier apps, March 2026. europarl.europa.eu.

Build the evidence trail

Polish operators: selected control records for the wider evidence trail.

For configured paths, GLACIS can add signed, scoped records of selected control decisions to the provider or deployer’s wider documentation and Article 12 logging design. The records do not replace technical documentation, establish compliance, or imply acceptance by KRiBSI, KNF, UODO, or a notified body.

Talk to us See an evidence pack →

Start where AI already acts. We’ll map the intended controls, operational decision points, and evidence gaps.