A Warsaw-based software company launches a customer-facing chatbot in spring 2026. The product team assumes that because the system "just answers questions," no special disclosure is required. Six months later, the company receives a formal inquiry from the Polish supervisory authority. The inquiry cites missing transparency notices, absent human-oversight mechanisms, and inadequate documentation. The company now faces potential fines and a product redesign. That scenario is not hypothetical – it reflects the compliance gap that dozens of Polish AI providers are discovering right now.
The EU AI Act imposes direct transparency obligations on providers of AI systems placed on the Polish market, with the most demanding requirements applying to high-risk systems and general-purpose AI models. Providers must supply users with clear information about the system's capabilities and limitations, maintain technical documentation, and implement human-oversight measures before deployment. Non-compliance can trigger administrative fines reaching EUR 15 million or 3% of global annual turnover, whichever is higher.
This guide walks through the step-by-step compliance procedure, maps obligations by risk tier, identifies the three most common mistakes Polish providers make, and closes with a practical checklist. Three business scenarios – a manufacturing integrator, an IT product company, and a foreign investor entering Poland – illustrate how the rules apply in practice.
How does the AI Act classify systems, and why does classification matter?
Classification determines your entire compliance burden. The AI Act uses a four-tier risk pyramid: unacceptable risk (banned outright), high risk (the heaviest obligations), limited risk (transparency duties only), and minimal risk (no mandatory obligations). Getting the tier wrong – in either direction – is expensive. Under-classification exposes a provider to enforcement; over-classification wastes resources on unnecessary documentation.
High-risk systems listed in the AI Act's annexes include AI used in critical infrastructure, employment decisions, credit scoring, and certain medical devices. In Poland, the Urząd Ochrony Danych Osobowych (Personal Data Protection Office, UODO) and the future national market surveillance authority will share oversight responsibilities. The Office of Competition and Consumer Protection (UOKiK) retains jurisdiction where AI systems interact with consumers. Providers must identify the correct supervisory body before filing any documentation – the wrong addressee causes delays of up to 90 days.
Limited-risk systems carry a narrower but still mandatory set of transparency duties. Any AI system that interacts with natural persons must disclose its non-human nature, unless the human already knows. Deepfake content must be labelled. Emotion-recognition systems must notify the persons being assessed. These obligations apply from the first day the system is made available on the Polish market – there is no grace period for disclosure duties at this tier.
- Verify whether your system appears on the high-risk annexes before assuming limited-risk status.
- Check whether the system processes biometric data – that triggers additional scrutiny under Rozporządzenie o Ochronie Danych Osobowych (General Data Protection Regulation, GDPR Poland overlay).
- Identify the correct national supervisory body for your sector.
- Document the classification decision and the reasoning behind it.
One practical pointer: the classification is not a one-time exercise. If you update the model materially – retraining on new data, adding a new modality, or expanding the intended purpose – the classification must be reviewed. Polish market surveillance guidance treats a significant model update as equivalent to placing a new system on the market.
What are the core transparency obligations for high-risk AI systems?
High-risk AI providers face the most detailed transparency regime. Three elements are non-negotiable: a technical information package for the supervisory authority, a plain-language information notice for deployers and end-users, and an ongoing logging mechanism that captures system outputs for at least six months. Missing any one element constitutes a standalone infringement.
The technical information package must describe the system's intended purpose, the training data categories used, performance metrics, known limitations, and the human-oversight measures built into the design. The package must be drafted before the system is placed on the market – not after. In practice, Polish providers often finalise the package within 60 to 90 days of starting compliance work, which means the process should begin at the product design stage, not at launch.
We secured a favourable supervisory outcome for an IT product company in the Mazowieckie region (spring 2026). The client had launched a high-risk recruitment screening tool without completing the technical documentation. We restructured the documentation package, implemented the required human-review layer, and submitted a voluntary disclosure to the relevant authority within 30 days. The authority closed the inquiry without imposing a financial penalty.
The plain-language notice must reach both the deployer – the business buying or integrating your system – and, where technically feasible, the end-user. The notice must cover what the system does, what it cannot do, when a human must be involved, and how to contact the provider. In cross-border situations, Polish law requires the notice in Polish. An English-only notice does not satisfy the obligation, even if the deployer is a multinational.
For a tailored strategy on AI Act documentation packages, reach out to info@kordeckipartners.com.
How does the step-by-step compliance procedure work in Poland?
The procedure has five stages, each with a defined output. Skipping a stage does not save time – it creates a documentation gap that the supervisory authority will identify during any audit. The total timeline from scoping to market placement typically runs 90 to 150 days for a high-risk system, and 30 to 45 days for a limited-risk system.
Stage 1 – Classification and scoping (weeks 1–3). Map every AI component in the product. Assign a preliminary risk tier. Identify the intended purpose and the user population. Document the decision with legal reasoning. At this stage, many providers discover that a product they considered a single system is in fact two separate systems with different risk tiers – a common finding for manufacturing integrators building AI into production line monitoring.
Stage 2 – Gap analysis (weeks 3–6). Compare current technical documentation, logging practices, and user notices against the AI Act requirements. Assign a red/amber/green status to each requirement. The gap analysis output becomes the basis for the remediation project plan. Budget at least PLN 40,000 to PLN 120,000 for external legal and technical support at this stage, depending on system complexity.
Stage 3 – Remediation (weeks 6–12). Draft or update the technical information package. Build the logging mechanism. Prepare user notices in Polish and any other required languages. Implement the human-oversight layer. This is the most resource-intensive stage. For general-purpose AI models, the provider must also register in the EU database maintained by the European AI Office – registration is a condition of lawful deployment, not an optional step.
Stage 4 – Internal review and sign-off (weeks 12–14). Legal, technical, and product teams review all outputs. A conformity assessment is completed. For certain high-risk systems, a third-party conformity assessment body must be involved – this adds four to eight weeks and costs that vary by assessor.
Stage 5 – Market placement and ongoing monitoring (from week 14). The system goes live with all documentation in place. The provider must monitor performance against the metrics declared in the technical package and update documentation when material changes occur. Post-market monitoring is not optional; the AI Act treats it as a continuous obligation, not a one-off exercise.
What mistakes do Polish AI providers most commonly make?
Three mistakes account for the majority of enforcement inquiries seen in the Polish market. Each is avoidable with early legal involvement. Each also carries the risk of an irreversible consequence – a public supervisory decision that cannot be expunged from the record, regardless of subsequent remediation.
Mistake 1 – Treating transparency as a marketing question, not a legal one. Providers draft user notices in their marketing team without legal review. The result is a notice that reads well but omits mandatory elements – specifically, the description of human-oversight mechanisms and the contact details for the provider's EU representative. The supervisory authority does not accept post-hoc corrections as a defence; personal liability of the responsible manager can arise where the omission was deliberate.
Mistake 2 – Ignoring the GDPR Poland overlay. AI systems that process personal data must comply with both the AI Act and GDPR simultaneously. The interaction is not always obvious. For example, the AI Act's logging requirement – retaining outputs for six months – must be reconciled with GDPR data minimisation principles. Providers who implement logging without a lawful basis under GDPR create a second infringement risk while trying to fix the first. Our article on data transfer from Poland to Ukraine illustrates how overlapping regulatory frameworks require coordinated legal analysis.
Mistake 3 – Assuming that a foreign provider's EU compliance covers Poland. A German or Dutch parent company that has completed AI Act compliance in its home jurisdiction has not automatically satisfied Polish requirements. Polish market surveillance authorities will apply Polish procedural rules. Notices must be in Polish. The local deployer must receive documentation in Polish. Where the foreign provider has no Polish establishment, it must appoint an EU representative – and that representative's details must appear in the user notice and in the EU database registration.
We obtained a full compliance sign-off for a foreign investor's AI subsidiary in Lower Silesia (autumn 2025). The parent had completed German compliance documentation but had not localised it for Poland. We translated and adapted the full package, registered the system in the EU database, and appointed the firm as EU representative. The system was on the Polish market within 45 days of instruction.
To receive an expert assessment of your AI Act compliance position, contact info@kordeckipartners.com.
How do three business scenarios illustrate the obligations in practice?
Abstract rules become clearer through concrete situations. The three scenarios below cover the most common provider profiles in the Polish market. Each scenario identifies the risk tier, the key obligations, and the critical timeline pressure.
Scenario A – Manufacturing integrator. A Silesian manufacturer integrates an AI-based quality-control vision system into its production line. The system makes automated decisions about product rejection. This system falls within the high-risk category because it operates in a safety-relevant context. The manufacturer, acting as both provider and deployer, must complete the full technical documentation package and implement a human-review mechanism for every rejection decision above a defined confidence threshold. The timeline for compliance is 90 days from the decision to deploy. Delays beyond that point risk placing a non-compliant system on the market.
Scenario B – IT product company. A Warsaw-based software house builds a general-purpose AI assistant and licences it to Polish businesses. The assistant does not fall in the high-risk annexes, but it interacts with natural persons and therefore carries limited-risk transparency obligations. The provider must disclose the AI nature of the system in every user interaction, maintain a register of deployers, and ensure that each deployer has received the plain-language information notice. The IP lawyer Warsaw practices that advise such companies frequently flag that licensing agreements must be updated to allocate compliance responsibilities between provider and deployer – a contractual gap that creates joint liability risk.
Scenario C – Foreign investor. A US-based AI company wants to place a predictive analytics product on the Polish market through a local distribution agreement. The distributor is not the provider under the AI Act – the US company is. It must appoint an EU representative, register in the EU database, and supply documentation in Polish to the distributor. DORA compliance may also be relevant if the product is used by regulated financial institutions. For cross-border data flows involved in the product's operation, the mechanisms described in our guide on data transfer from Poland to Cyprus provide a useful structural parallel. The foreign investor scenario is where trademark and IP lawyer Warsaw expertise intersects with AI regulation – the product's technical documentation must reference any IP protections and licensing terms that affect the system's permitted uses.
A note on environmental due diligence: where AI systems are integrated into real estate or infrastructure projects, the compliance perimeter may extend to matters covered by our analysis of environmental due diligence for Polish real estate, particularly where AI-driven systems monitor or control physical assets subject to environmental permits.
Frequently asked questions
Q: How long does the AI Act compliance process take for a limited-risk system in Poland?
A: For a limited-risk system, the core compliance work – classification, drafting the transparency notice in Polish, and implementing the disclosure mechanism – typically takes 30 to 45 days with dedicated legal and technical support. The timeline extends if the system also processes personal data under GDPR, because a data protection impact assessment may be required in parallel. Providers should not wait for enforcement inquiries to begin; the transparency disclosure obligation applies from the first day of market availability.
Q: Is it a common misconception that open-source AI models are exempt from AI Act transparency obligations?
A: Yes – this is one of the most frequent misunderstandings among Polish providers. The AI Act does provide a limited exemption for certain open-source model releases, but it does not cover providers who integrate an open-source model into a product placed on the market. If you are deploying a product built on an open-source foundation model, you are the provider for AI Act purposes and carry the full transparency obligations for your system's risk tier. The open-source origin of the underlying model does not transfer or reduce your obligations.
Q: What are the costs of AI Act compliance for a small Polish AI company?
A: Costs vary significantly by system complexity and risk tier. For a limited-risk system, expect external legal and technical costs in the range of PLN 15,000 to PLN 40,000 for the initial compliance project. High-risk systems requiring third-party conformity assessments can cost PLN 80,000 to PLN 250,000 or more, depending on the assessor and the system's technical complexity. Ongoing annual monitoring costs are additional. These figures assume no enforcement action – a supervisory inquiry adds legal defence costs that frequently exceed the original compliance investment, which is why proactive compliance is the more economical path.
What to prepare: compliance checklist
- Written classification decision with supporting legal reasoning and risk-tier assignment.
- Technical information package covering intended purpose, training data categories, performance metrics, and known limitations.
- Plain-language user notice in Polish, including human-oversight contact details and EU representative information.
- Logging mechanism retaining system outputs for at least six months, with a documented GDPR lawful basis for retention.
- EU database registration (for high-risk and general-purpose AI models) and appointment of an EU representative if the provider has no Polish or EU establishment.
Specific circumstances require specific analysis. A compliance checklist identifies what is needed; it does not replace the legal assessment of whether your system meets each requirement. Gaps discovered during a supervisory audit – rather than during internal review – precludes the voluntary disclosure pathway that can avoid financial penalties.
To discuss how AI Act transparency obligations apply to your system, email info@kordeckipartners.com.
KORDECKI & Partners is a law firm based in Warsaw and Krakow, advising business clients across 30 jurisdictions. Our team combines expertise in Polish and international law with a practical approach to AI regulation, IP, and technology law. We work with Polish entrepreneurs, foreign investors, and in-house legal teams navigating the AI Act, DORA compliance, GDPR Poland requirements, and related obligations. To discuss your situation, contact info@kordeckipartners.com.
Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. KORDECKI & Partners assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@kordeckipartners.com.