PL·EU AI Act series·Poland implementation·EU timeline checked August 2026
The EU AI Act in Poland: national implementation law enacted.
Poland enacted the Act of 3 July 2026 on AI systems (Dz.U. 2026 poz. 1003). The law establishes the national supervision, conformity, and sandbox framework, including KRiBSI. Appointments, operating procedures, and live filing routes should be checked against current official notices.
The Act of 3 July 2026 on AI systems was enacted, signed, and published as Dz.U. 2026 poz. 1003. It replaces the draft-status account previously shown on this page and establishes the national institutional framework, including KRiBSI.
Earlier UODO comments concerned draft legislation and should not be presented as the current allocation. Confirm the final statutory role, current appointments, operational capacity, and competent route for a specific system from the enacted text and current Polish authority notices.
Who supervises what in Poland
The enacted law establishes Poland’s national AI Act institutional framework, including KRiBSI, while existing regulators retain powers under their own laws. The competent authority, notifying authority, Article 77 body, and sector route for a specific system should be confirmed from the final text and current official designations.
| Authority | Mandate | EU AI Act role (reviewed August 2026) |
|---|---|---|
| KRiBSI | Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji | Established under the enacted 2026 law within Poland’s national AI Act implementation framework. Confirm current appointments, procedures, and operational notices before naming a live filing route. |
| Ministry of Digital Affairs (MC) | Ministerstwo Cyfryzacji | National digital-policy and implementation role under the enacted framework. Confirm the current notifying-authority and operational-support allocation from the final text and official notices. |
| UODO | Urząd Ochrony Danych Osobowych (data protection authority) | Retains its GDPR powers where AI systems process personal data. Confirm any AI Act role from the enacted law and current Article 77 and authority notices rather than relying on the superseded draft debate. |
| KNF | Komisja Nadzoru Finansowego (financial supervision authority) | Existing financial-supervision powers may overlap with AI Act duties. Confirm whether KRiBSI, KNF, or another body is competent for the specific system and obligation. |
| URPL | Urząd Rejestracji Produktów Leczniczych (medicines, devices, biocidal products office) | Healthcare AI sectoral regulator; medical-device conformity overlap (MDR/IVDR). |
| PIP | Państwowa Inspekcja Pracy (national labour inspectorate) | Workplace AI: emotion-recognition prohibition, worker monitoring; Article 77 fundamental-rights body. |
| RPO | Rzecznik Praw Obywatelskich (Ombudsperson) | Article 77 fundamental-rights body; non-discrimination supervision on AI-affected decisions. |
| RPP | Rzecznik Praw Pacjenta (Patient Rights Ombudsperson) | Article 77 fundamental-rights body in healthcare; clinical-AI patient-impact supervision. |
UODO commented on earlier drafts, but those comments do not establish the allocation under the enacted Act. Where personal data is processed, UODO’s GDPR powers remain relevant; the competent AI Act route should be confirmed from the final law and current authority notices.
Polish sector overlays
The substantive obligations in Articles 9 to 15 apply EU-wide. Poland’s enacted law supplies the national institutional layer. The exact competent route depends on the system, operator role, product and sector law, and current implementation notices; the combinations below are issues to check, not a definitive jurisdictional allocation.
| Sector | Polish regulators on top of the AI Act |
|---|---|
| Healthcare AI | Check the applicable medical-device, reimbursement, personal-data, patient-rights, and interoperability regimes separately. Confirm the current AI Act competent route for the specific product and use. |
| Financial services | KNF on conduct, prudential, and AML; UODO on customer-data lawful basis. Anti-fraud models continue under existing CRR/MiFID frameworks. |
| IT services and outsourcing | Poland’s strong IT outsourcing sector means many domestic providers face provider obligations under Article 16 even when the deployer sits in another member state. Cross-border conformity-assessment coordination is the main complexity. |
| Manufacturing | Product-embedded AI may require Article 6(1), Annex I, and sector product-safety analysis. Annex III(2) is limited to the critical-infrastructure uses and conditions listed there, not industrial systems generally. |
| Public administration | Check AI Act operator duties, GDPR supervision where personal data is processed, and the current Article 77 fundamental-rights designations. Do not infer a single horizontal authority for every issue. |
| Workplace AI | PIP holds the prohibited-practice line on emotion recognition and biometric categorization in workplaces; works-council co-determination under the Labour Code applies in parallel. |
Regulatory sandbox
The enacted 2026 law addresses Poland’s national AI regulatory-sandbox framework. Confirm current eligibility, application procedures, participating authorities, and opening dates from KRiBSI or the Ministry of Digital Affairs. Existing sector innovation programs should not be described as AI Act sandboxes without a current primary source establishing that status.
References
- European Union. Regulation (EU) 2024/1689 (EU AI Act). EUR-Lex 32024R1689.
- Blavatnik School of Government, Oxford. AI Act’s enforcement gap: what Poland’s new regulator reveals about Europe’s challenge. bsg.ox.ac.uk.
- Poland. Act of 3 July 2026 on AI systems, Dz.U. 2026 poz. 1003. ISAP official record.
- Sejm. Legislative history for the Act on AI systems. Official proceeding record.
- Technology’s Legal Edge. State of the Act: EU AI Act implementation in key Member States, November 2025. technologyslegaledge.com.
- European Parliament. AI Act delayed application; ban on nudifier apps, March 2026. europarl.europa.eu.
Build the evidence trail
Polish operators: selected control records for the wider evidence trail.
For configured paths, GLACIS can add signed, scoped records of selected control decisions to the provider or deployer’s wider documentation and Article 12 logging design. The records do not replace technical documentation, establish compliance, or imply acceptance by KRiBSI, KNF, UODO, or a notified body.
Start where AI already acts. We’ll map the intended controls, operational decision points, and evidence gaps.