The EU AI Act in Poland
How Regulation (EU) 2024/1689 applies in Poland, and the 8 AI instruments Poland has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Poland’s own AI instruments
8 records tracked for Poland, beyond the EU-level Act above.
Poland - AI Systems Regulation (DAISPXX/2024)
Poland · 2024
Poland - Data Management Act
Poland · 2024
Poland - Digital Transformation Strategy
Poland · 2024
Poland - Open Data Re-use Act (1641/2021)
Poland · 2021 · 8 Dec 2021
Poland - AI Development Policy (Resolution No. 196/2020)
Poland · 2020 · 28 Dec 2020
Poland - AI Development Roadmap
Poland · 2019 · 22 Jan 2019
Poland - AI Development Strategy
Poland · 2019 · 26 Feb 2019
Poland - National AI Strategy (2018)
Poland · 2018 · 9 Nov 2018
National authority in Poland
Named in Poland’s own records, not inferred.
Per Poland - AI Systems Regulation (DAISPXX/2024)
- Ministry of Digital Affairs (Ministerstwo Cyfryzacji) — Policy lead and sponsor of the draft; coordinates interministerial consultations and national implementation.
- Commission for AI Development and Safety (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji - KRiBSI) — Proposed central market surveillance and enforcement body for AI systems, national single point of contact for EU cooperation.
- Rządowe Centrum Legislacji (RCL) — Official publishing and legislative procedure platform where the draft and supporting documents are hosted.
- Government Legislative Council (Rada Legislacyjna) — Advisory body that published an expert opinion on the draft (25 Oct 2024).
- Personal Data Protection Office (Urząd Ochrony Danych Osobowych — UODO) — Cooperating authority on GDPR and data protection issues where AI systems process personal data.
Per Poland - Data Management Act
- President of the Personal Data Protection Office (Prezes UODO) — Competent supervisory authority for registration, oversight and enforcement regarding data intermediation services and organisations of data altruism; issues decisions and penalties.
- President of Statistics Poland (Prezes GUS) — Designated provider of technical assistance to public-sector bodies for secure re-use of protected datasets (pseudonymisation, secure environments, data structuring).
- Ministry of Digitalisation (Ministerstwo Cyfryzacji) — Operates the single information point for users; coordinates public consultation and publishes guidance and templates; central policy sponsor of the Draft.
Per Poland - Digital Transformation Strategy
- Ministry of Digitalisation (Ministerstwo Cyfryzacji) — Lead coordinator, publisher of the draft strategy and primary implementing authority for national digitalisation governance.
- President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych - UODO) — Data protection oversight for personal data processing under GDPR and national law; advisory role on data governance measures.
- NASK – Research and Academic Computer Network (Naukowa i Akademicka Sieć Komputerowa) — Technical and cybersecurity partner; operates national CERT and research infrastructure supporting secure digital services.
- Government Centre for Security (Rządowe Centrum Bezpieczeństwa - RCB) — Coordination on national resilience and crisis response relating to cyber incidents and national emergency planning.
Per Poland - Open Data Re-use Act (1641/2021)
- Minister competent for informatization (minister właściwy do spraw informatyzacji) — Administrator of the national data portal; responsible for technical standards, portal operation and coordination with obligated entities.
- Council of Ministers (Rada Ministrów) — Adopts implementing regulations, including the Rozporządzenie Rady Ministrów on the national data portal and other secondary legislation.
Per Poland - AI Development Policy (Resolution No. 196/2020)
- Council of Ministers (Rada Ministrów) — Adoption and overarching political decision-making; resolution sponsor.
- Ministry of Digital Affairs (Ministerstwo Cyfryzacji) / Ministry responsible for digital affairs — Lead coordinating ministry for policy drafting, consultations and initial implementation oversight; host of the national AI portal.
- GovTech Polska — Facilitate public procurement pilots, GovTech initiatives and public-sector deployment of AI.
Per Poland - AI Development Roadmap
- Ministry of Development and Technology (Ministerstwo Rozwoju i Technologii) — Convenor and facilitator of the original roadmap conference and stakeholder coordination in 2019.
- Ministry of Digital Affairs / Ministry of Digitization (Ministerstwo Cyfryzacji) — Lead on digital policy and subsequent national AI policy coordination; host of AI portal and follow‑on policy activities.
Per Poland - AI Development Strategy
- Ministry of Digitization (Ministerstwo Cyfryzacji / gov.pl AI portal) — Primary coordinator for policy drafting, public consultations and inter‑ministerial AI coordination.
- Ministry of Entrepreneurship and Technology (Ministerstwo Przedsiębiorczości i Technologii / successor bodies on gov.pl) — Co‑signatory ministry — economic and industry policy, support for business and innovation.
- Ministry of Science and Higher Education (Ministerstwo Nauki i Szkolnictwa Wyższego) — Responsible for research policy, university cooperation, and training/skills initiatives.
- Ministry of Investment and Development (Ministerstwo Inwestycji i Rozwoju) — Investment and development planning signatory; coordinates investment and regional development aspects.
Per Poland - National AI Strategy (2018)
- Ministry of Digital Affairs (Ministerstwo Cyfryzacji) — Primary coordinator and convener for the national AI assumptions and Plan of Activities (2018–2019).
- President of the Personal Data Protection Office (UODO) / Data protection regulator (Poland) — Enforcement of GDPR obligations applicable to processing of personal data in AI projects.
Penalties in Poland
As stated in Poland’s own records.
Per Poland - AI Systems Regulation (DAISPXX/2024)
- Administrative fines proportionate to the severity of the violation, aligned with the EU Regulation's scales (including potential reference to fines up to amounts comparable to EU maxima for serious infringements).
- Corrective measures: suspension of system operation, product recalls, market withdrawals, temporary bans on placing systems on the market.
- Mitigation procedures including requirements to implement remedies within set deadlines; failure to comply may lead to escalated fines.
- Publication of non‑compliance decisions and corrective actions, subject to confidentiality protections.
- In specific cases, referral to criminal prosecution where national criminal law standards for intentional or grossly negligent conduct are met.
Per Poland - Data Management Act
- Administrative fines up to EUR 50,000 for failure to notify/register as a data intermediation provider (amounts expressed in euro-equivalents in the Draft).
- Administrative fines up to EUR 500,000 for material breaches of intermediary obligations or unlawful transfers of non-personal data to third countries.
- Administrative fines up to EUR 5,000 for registered organisations of data altruism breaching registration conditions.
- Orders to suspend, restrict or cease services where serious or repeated breaches occur.
- Compulsory production of documents and data for enforcement purposes and administrative enforcement of monetary penalties.
Per Poland - Digital Transformation Strategy
- The strategy itself does not establish standalone fines; rather it conditions eligibility for specific national and EU funding on compliance with recommended standards.
- Non‑compliance by public entities may lead to suspension of allocated program funding, requirement to implement corrective action plans, or administrative measures under applicable sectoral laws.
- Where sectoral regulations exist (e.g., personal data breaches subject to GDPR/UODO enforcement), entities remain liable under those laws and may face penalties imposed by the competent authority.
- Procurement non-conformity can trigger contractual remedies, withholding of payments, or re-tendering obligations as provided in public procurement rules.
- Recommended future regulatory acts inspired by the strategy may create direct enforcement and penalty regimes for specific digital practices (to be enacted separately).
Per Poland - Open Data Re-use Act (1641/2021)
- The Act emphasizes administrative remedies and judicial review under Polish administrative law rather than introducing new criminal sanctions.
- Enforcement can include administrative orders to publish or correct datasets and legal challenges in administrative courts for refusals to provide information.
- Failure to comply may lead to supervisory measures by competent ministries and potential liability under general civil, administrative or data-protection frameworks (including remedies and fines under GDPR where applicable).
- Sector-specific secondary regulations may specify additional compliance mechanisms or administrative consequences (e.g., fee regulation for museums).
- Remedies for harmed parties or wrongful reuse are governed by general liability law; the Act does not primarily create bespoke punitive fines within its text.
Per Poland - AI Development Policy (Resolution No. 196/2020)
- The Policy itself does not set new penalties or sanctions; enforcement and penalties are left to existing sectoral laws and to future legislation that may be introduced to implement regulatory obligations.
- Non-compliance with the Policy’s recommended actions may be addressed through administrative oversight, procurement sanctions (where procurement rules apply) or future statutory instruments aligned with EU rules.
Per Poland - AI Development Roadmap
- None: the Roadmap itself is a strategic, non‑binding instrument and does not establish penalties. Enforcement and penalties (where applicable) are handled through sectoral laws, procurement rules and later binding regulations.
Per Poland - AI Development Strategy
- No unique penalties included in the memorandum itself (non‑binding declaration).
- Legal or administrative consequences for non‑compliance with existing laws (e.g. GDPR, sectoral safety rules) remain applicable where relevant.
- Compliance and enforcement rely on administrative oversight, funding conditionality and reputational accountability rather than sanctions embedded in the memorandum.
Per Poland - National AI Strategy (2018)
- The assumptions document does not impose new administrative sanctions or criminal penalties.
- Non-compliance with requirements referenced in the strategy (e.g., GDPR) is subject to existing enforcement mechanisms and penalties under applicable law.
- Sectoral breaches during pilots may give rise to contractual remedies, civil liability or administrative penalties under sector-specific regulations.
- Public procurement violations remain subject to standard procurement oversight and corrective procedures.
Poland overview
The full picture of AI regulation in Poland, beyond just the EU AI Act.
Poland AI regulation overview →