Compliance and data security
The two biggest barriers to AI projects in Polish companies are unclear regulation and worry about data — not cost. Below is where the law stands today and what you get from us in writing. If something is missing here, tell us: we'll fill the gap before the meeting, not after.
Where an email-handling agent sits in the AI Act
An agent that reads enquiries, classifies them and drafts replies is a limited-risk system. It needs no conformity assessment, no registration in the EU database and no Annex IV technical documentation. The obligations for high-risk systems under Annex III have been pushed by Regulation 2026/1744 from August 2026 to 2 December 2027 — this is the misunderstanding that most often makes legal teams put projects on hold.
Caveat: the classification depends on the use case. Point the agent at recruitment, creditworthiness assessment or another Annex III use, and it moves into the high-risk regime. That's why we write the intended purpose into the contract, along with the rule that changing it triggers a fresh analysis.
What applies, and from when
- from 2 February 2025Prohibited practices (Art. 5) and AI literacy (Art. 4)
- from 2 August 2026Transparency obligations (Art. 50) — users must know they are talking to AI
- from 11 August 2026The Polish AI Systems Act (Journal of Laws 2026, item 1003)
- from 28 October 2026Inspections, proceedings and penalties — the authority is KRiBSI
- from 2 December 2027High-risk systems under Annex III (moved from 2026)
What this means for you in practice
You disclose that it's AI
Article 50 requires the recipient to know they are dealing with an AI system. We build this into the wording of the replies — zero cost, and it settles the question.
Your team gets a short training
Article 4 requires you to maintain AI literacy among the people operating the system. Training is part of the implementation, and under the PARP FERS programme it is sometimes funded separately.
We complete the UODO checklist
On 6 August 2026 UODO, Poland's data protection authority, published its preliminary question lists, including a 26-question version for companies using off-the-shelf AI tools. We fill it in with you before the implementation, separately for each process, and leave it behind as accountability documentation.
We check whether a DPIA is needed
Processing customer correspondence usually requires a data protection impact assessment (Article 35 GDPR). We settle that during the audit, not after go-live.
Where the data lives
There are two models to choose from, and the decision is made before the pilot, not during it. First: the data stays in your infrastructure, and only the fragments the model needs ever leave it. Second: processing in an EU region of your choice, with a provider holding the right certifications. In both cases we limit the agent's access to a single process, and every action it takes is logged.
- Company data is not used to train models — we put that in the contract, we don't just say it.
- A data processing agreement (DPA) with defined data categories and retention periods.
- Agent permissions based on the roles you already have — no new access paths.
- The agent's full decision history, available for review and audit.
A question that isn't covered here?
During the audit we go through compliance as concretely as we go through the numbers. If your legal team has a list of questions, send it in advance — we'll answer in writing.
Let's start with a conversation
30 minutes, one process and a first estimate of the time and money you can win back. No system access, no commitment. We reply within 24 hours.