The EU AI Act in Poland

How Regulation (EU) 2024/1689 applies in Poland, and the 8 AI instruments Poland has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Poland’s own AI instruments

8 records tracked for Poland, beyond the EU-level Act above.

National authority in Poland

Named in Poland’s own records, not inferred.

Per Poland - AI Systems Regulation (DAISPXX/2024)

Per Poland - Data Management Act

Per Poland - Digital Transformation Strategy

Per Poland - Open Data Re-use Act (1641/2021)

Per Poland - AI Development Policy (Resolution No. 196/2020)

Per Poland - AI Development Roadmap

Per Poland - AI Development Strategy

Per Poland - National AI Strategy (2018)

Penalties in Poland

As stated in Poland’s own records.

Per Poland - AI Systems Regulation (DAISPXX/2024)

  • Administrative fines proportionate to the severity of the violation, aligned with the EU Regulation's scales (including potential reference to fines up to amounts comparable to EU maxima for serious infringements).
  • Corrective measures: suspension of system operation, product recalls, market withdrawals, temporary bans on placing systems on the market.
  • Mitigation procedures including requirements to implement remedies within set deadlines; failure to comply may lead to escalated fines.
  • Publication of non‑compliance decisions and corrective actions, subject to confidentiality protections.
  • In specific cases, referral to criminal prosecution where national criminal law standards for intentional or grossly negligent conduct are met.

Per Poland - Data Management Act

  • Administrative fines up to EUR 50,000 for failure to notify/register as a data intermediation provider (amounts expressed in euro-equivalents in the Draft).
  • Administrative fines up to EUR 500,000 for material breaches of intermediary obligations or unlawful transfers of non-personal data to third countries.
  • Administrative fines up to EUR 5,000 for registered organisations of data altruism breaching registration conditions.
  • Orders to suspend, restrict or cease services where serious or repeated breaches occur.
  • Compulsory production of documents and data for enforcement purposes and administrative enforcement of monetary penalties.

Per Poland - Digital Transformation Strategy

  • The strategy itself does not establish standalone fines; rather it conditions eligibility for specific national and EU funding on compliance with recommended standards.
  • Non‑compliance by public entities may lead to suspension of allocated program funding, requirement to implement corrective action plans, or administrative measures under applicable sectoral laws.
  • Where sectoral regulations exist (e.g., personal data breaches subject to GDPR/UODO enforcement), entities remain liable under those laws and may face penalties imposed by the competent authority.
  • Procurement non-conformity can trigger contractual remedies, withholding of payments, or re-tendering obligations as provided in public procurement rules.
  • Recommended future regulatory acts inspired by the strategy may create direct enforcement and penalty regimes for specific digital practices (to be enacted separately).

Per Poland - Open Data Re-use Act (1641/2021)

  • The Act emphasizes administrative remedies and judicial review under Polish administrative law rather than introducing new criminal sanctions.
  • Enforcement can include administrative orders to publish or correct datasets and legal challenges in administrative courts for refusals to provide information.
  • Failure to comply may lead to supervisory measures by competent ministries and potential liability under general civil, administrative or data-protection frameworks (including remedies and fines under GDPR where applicable).
  • Sector-specific secondary regulations may specify additional compliance mechanisms or administrative consequences (e.g., fee regulation for museums).
  • Remedies for harmed parties or wrongful reuse are governed by general liability law; the Act does not primarily create bespoke punitive fines within its text.

Per Poland - AI Development Policy (Resolution No. 196/2020)

  • The Policy itself does not set new penalties or sanctions; enforcement and penalties are left to existing sectoral laws and to future legislation that may be introduced to implement regulatory obligations.
  • Non-compliance with the Policy’s recommended actions may be addressed through administrative oversight, procurement sanctions (where procurement rules apply) or future statutory instruments aligned with EU rules.

Per Poland - AI Development Roadmap

  • None: the Roadmap itself is a strategic, non‑binding instrument and does not establish penalties. Enforcement and penalties (where applicable) are handled through sectoral laws, procurement rules and later binding regulations.

Per Poland - AI Development Strategy

  • No unique penalties included in the memorandum itself (non‑binding declaration).
  • Legal or administrative consequences for non‑compliance with existing laws (e.g. GDPR, sectoral safety rules) remain applicable where relevant.
  • Compliance and enforcement rely on administrative oversight, funding conditionality and reputational accountability rather than sanctions embedded in the memorandum.

Per Poland - National AI Strategy (2018)

  • The assumptions document does not impose new administrative sanctions or criminal penalties.
  • Non-compliance with requirements referenced in the strategy (e.g., GDPR) is subject to existing enforcement mechanisms and penalties under applicable law.
  • Sectoral breaches during pilots may give rise to contractual remedies, civil liability or administrative penalties under sector-specific regulations.
  • Public procurement violations remain subject to standard procurement oversight and corrective procedures.

Poland overview

The full picture of AI regulation in Poland, beyond just the EU AI Act.

Poland AI regulation overview →