Artificial intelligence has become a common tool used by entrepreneurs, employers, and public institutions. AI systems now support applications such as document analysis, recruitment, marketing, customer service, and decision-making. At the same time, employees are increasingly using publicly available generative AI tools independently.
However, the development of this technology has created new threats. The European Union responded with the AI Act – Regulation (EU) 2024/1689 on Artificial Intelligence. Its goal is to establish rules for the safe use of AI while protecting health, safety, and fundamental rights. The regulation entered into force on August 1, 2024, with its individual provisions being applied in phases.
The greater the risk, the greater the responsibilities
The AI Act is based on a risk-based approach. The scope of obligations depends primarily on how a specific AI system is used and the risks it may pose.
The use of AI to improve the style of messages should be assessed differently than a system used to evaluate candidates in the recruitment process or influencing access to certain benefits or services.
The most far-reaching regulation is the prohibited practices in AI, as defined in Article 5 of the regulation. These include, among others, certain uses of manipulative techniques, exploiting the particular vulnerabilities of certain individuals, certain forms of social scoring, and certain uses of biometrics and emotion recognition.
Special requirements also apply to high-risk systems. The AI Act imposes extensive obligations on them, including documentation, transparency, event logging, system monitoring, and ensuring effective human oversight.
Risks associated with the use of AI
One of the most common problems is AI hallucination. The system can generate a response that appears credible even though it contains false information. In professional practice, this can lead to incorrect document analysis, the preparation of an inappropriate recommendation, or the citation of a nonexistent source.
Another threat is the lack of transparency. Users aren't always able to determine why the system generated a specific result. This is especially important when a decision about another person is based on it. AI systems can also replicate existing biases and lead to unjustified discrimination against specific individuals or groups.
Significant risks also arise with personal and confidential information. An employee could submit a document containing customer or employee data, trade secrets, or other sensitive information to an external AI tool.
So-called shadow AI, or the use of AI tools by employees without the organization's knowledge or control, is also becoming a problem. Entrepreneurs may then be unaware of the systems being used in their business and the information being transferred to them.
How to prepare an organization?
The first step should be to determine which AI systems the organization actually uses, for what purposes, and what information is transferred to them. Then, responsibilities related to specific applications should be defined.
In practice, it is advisable to create rules for the use of AI, define the tools permitted for use, inventory the systems used and provide a supervision mechanism.
AI literacy, meaning ensuring the appropriate level of competence of those using AI, is also of particular importance. Employees should be familiar with the system's limitations, understand the need to verify its results, and know what information they should not provide to a given tool. The obligation to take appropriate measures in this regard applies from February 2, 2025.
When using an external system, a contract with the provider is also important. In particular, rules regarding data processing, system security, and data handling after termination should be established.
AI Act and other regulations
The AI Act does not operate in isolation from other laws. The same event may be subject to multiple legal regimes.
For example, if an employee submits a document containing a client's personal data to an external AI tool, the situation should also be assessed under the GDPR. Where appropriate, regulations regarding cybersecurity, labor law, or trade secrets may also apply. Therefore, compliance with the AI Act does not automatically imply compliance with other regulations.
Commission and compliance control
The national system for overseeing compliance with the AI Act was established in the Act of July 3, 2026, on Artificial Intelligence Systems. One of its key elements is the Artificial Intelligence Development and Security Commission, which is empowered to oversee the application of the regulations.
The Act provides, among other things, for the possibility of conducting audits. Their purpose is to verify whether the audited entity is complying with applicable regulations. During the audit, it is possible to examine documentation, request information and explanations, and verify the actual use of AI systems.
The audit may therefore cover not only documentation relating to the system itself, but also contracts with suppliers, adopted procedures, the manner of preparing employees and the implementation of the required human supervision.
If any irregularities are found, the Commission may issue post-audit recommendations specifying the method and deadline for their removal.
Infringement proceedings should be distinguished from inspections. Their purpose is to determine whether a violation of the AI Act or the Act has occurred and what the consequences should be. Proceedings may also be initiated based on information about a possible violation obtained independently of a prior inspection.
Importantly, the provisions of the Polish act on inspections and infringement proceedings enter into force on October 28, 2026. Therefore, there is little time left before the new oversight mechanisms are launched. This is the final moment for businesses and institutions to streamline their AI use policies, identify the systems they use and the associated risks, review procedures and contracts with suppliers, and prepare employees. These actions should aim not only to formally meet the requirements but also to create a truly functioning AI compliance system.
High penalties for violating the AI Act
The AI Act provides for significant administrative fines. For violations of the prohibited practices specified in Article 5, the maximum fine can be €35 million, or in the case of a company, up to 7% of its total global annual turnover from the previous financial year, in accordance with the rules set out in the regulation.
For breaches of a number of other obligations, the maximum level of sanctions is EUR 15 million or 3% of the global annual turnover, while for providing incorrect, incomplete or misleading information to the competent authorities – EUR 7.5 million or 1% of the turnover.
However, the level of sanctions depends on the circumstances of the specific case, including the nature, gravity, and duration of the violation. According to the regulations, the sanction must be effective, proportionate, and dissuasive.
What does this mean for entrepreneurs and institutions?
The AI Act doesn't mean abandoning artificial intelligence. However, it does require that its use be done consciously, in a controlled manner, and with due regard for the risks associated with a specific application.
For entrepreneurs and institutions, a good starting point is to analyze how AI is used, verify the tools used and contracts with their suppliers, define internal rules and properly prepare employees.
In the event of an audit, it will be important not only to have the appropriate documents, but also to be able to demonstrate that the organization actually identifies risks related to AI, controls the use of systems and responds to any irregularities found.
Implementing appropriate solutions allows not only to reduce the risk of liability, but above all to safely use the opportunities offered by artificial intelligence.
This article is for informational purposes only and does not constitute legal advice
Legal status as of October 6 , 2026
Author:
Series editor:
