Poland - AI Systems Regulation (DAISPXX/2024)

Draft Act on Artificial Intelligence Systems

Projekt ustawy o systemach sztucznej inteligencji

Poland

RAI-PL-NA-DAISPXX-2024
Draft(Being written or scoped)
BillGovernance and OversightConformity Assessment and RegistrationMarket Surveillance
Export PDF

The Draft Act on Artificial Intelligence Systems is a Polish government bill designed to implement and complement the EU AI Regulation (Regulation (EU) 2024/1689) at the national level. It creates a national supervisory architecture (including a proposed Commission for AI Development and Safety), sets conformity, registration and market surveillance rules for AI systems, and aligns enforcement and sanctions with the EU framework while adding national procedural and institutional detail.

Overview

The Draft Act on Artificial Intelligence Systems is a national implementing measure prepared to facilitate and operationalize the EU AI Regulation (Regulation (EU) 2024/1689) in Poland. It was prepared by the Ministry of Digital Affairs and first published on 16 October 2024 on the Rządowe Centrum Legislacji platform; a revised version following public consultations was published on 11 February 2025. The draft focuses on establishing a national oversight architecture, setting conformity assessment and registration rules for high‑risk AI systems, and defining enforcement powers and penalties at the national level. For the official draft and its supporting documents see the RCL project page: RCL - Draft Act on AI Systems (Projekt) and the Ministry information page: Ministry of Digital Affairs - Project (Feb 11, 2025).

Definitions

The draft adopts and cross‑references many definitions from the EU AI Regulation, including categories such as "model AI of general purpose", "provider", "user/deployer", "high‑risk AI system", and "prohibited AI practice". It supplements EU definitions where necessary for national procedural rules (for instance, defining national registration formats, responsible contact points, and the national approach to conformity assessment). Key definitional clarifications are used to set boundaries for when national authorities exercise oversight and how the national register of high‑risk systems is to be maintained.

Governance and Institutional Framework

The draft contemplates the creation or formal designation of a new collegiate supervisory body — the Commission for AI Development and Safety (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji, KRiBSI) — to act as Poland's central market surveillance and enforcement authority for AI systems. KRiBSI's proposed composition includes representatives of relevant sectoral supervisors (e.g., health, transport, financial supervision) and expert members; the aim is to consolidate market surveillance, provide a national single point of contact for the European AI Board, and coordinate investigations and cross‑sector responses. The Ministry of Digital Affairs is responsible for administering policy, submitting the draft through the RCL process, and coordinating interministerial consultations. The draft also prescribes mechanisms for cooperation with other national authorities — including the Personal Data Protection Office (UODO) on data protection matters and sectoral regulators for domain‑specific controls — and sets out the Commission’s powers to order corrective measures, suspend system operation, require documentation, and levy administrative fines. For ministry statements and background, see Ministry - AI Act implementation.

Key Focus Areas

The draft addresses a set of priority regulatory areas consistent with the EU risk‑based approach: (1) prohibited AI systems and practices — the draft mirrors EU prohibitions for high‑risk abuses (such as certain biometric identification uses and social scoring practices); (2) high‑risk systems — obligations on providers and deployers to perform conformity assessment, implement risk management systems, maintain technical documentation and logs, carry out human oversight and post‑market monitoring; (3) transparency and disclosure — requirements that enable affected persons to understand when AI is being used in decision‑making or content generation; (4) data protection and privacy — explicit cross‑references to GDPR obligations and coordination with the Data Protection Authority for impact assessments; (5) cybersecurity and model security — mandatory baseline security controls, vulnerability management and supply‑chain considerations; (6) market surveillance and conformity assessment — national procedures for registering high‑risk systems and verifying compliance through notified bodies or national assessment schemes; and (7) innovation‑oriented measures — regulatory sandboxes, simplified procedures for certain test environments, and provisions to support research while respecting the EU derogations for bona fide research and testing. The draft also strengthens provisions for incident reporting and cooperation with EU and Member State authorities to respond to cross‑border risks.

Implementation Framework

Implementation relies on a multi‑pillar regulatory architecture: (a) primary obligations on providers and deployers (risk management, DPIAs, technical documentation, record keeping); (b) a national registry for high‑risk systems linked to EU registries; (c) a conformity assessment and notification regime that uses both internal checks and third‑party assessment where required; (d) market surveillance and enforcement powers for the Commission and cooperating authorities; and (e) special procedural rules for innovation tools such as sandboxes and authorisation mechanisms for certain uses. The draft sets timelines for transitional arrangements to align with EU deadlines (notably provisions referenced to the EU Regulation's entry into force dates), and specifies administrative procedures for inspections, requests for information, and appeals.

Monitoring and Evaluation

The draft requires national authorities to monitor compliance, publish periodic reports on market surveillance activities, and share information with the European AI Board. It includes mandatory post‑market monitoring by providers (incident reporting and corrective actions) and obliges the Commission to maintain a national register and to publish summaries of enforcement actions subject to confidentiality rules. The draft also envisages evaluation mechanisms to review regulatory effectiveness after specified timeframes and to coordinate with EU evaluations of the AI Regulation.

Penalties, Liability, and Appeals

Sanctions in the draft follow the EU approach: administrative fines for infringements (with references to the European AI Regulation’s scale), corrective orders (recalls, suspension, market withdrawal), and mandatory remedial measures. The draft distinguishes between administrative enforcement and criminal liability, reserving criminal sanctions for clearly defined intentional or negligent conduct where domestic criminal law applies. The bill also sets out administrative procedural guarantees, including rights of defence, timelines for appeals and judicial review routes, and mechanisms for mitigating sanctions where prompt remediation occurs.

Relationship to Other Instruments

The draft is expressly designed to operate in tandem with the EU AI Regulation (Regulation (EU) 2024/1689) and cross‑references key definitions and provisions. It also coordinates with the General Data Protection Regulation (GDPR) on data protection, national sectoral laws (health, transport, finance), and the national cybersecurity framework. The Government Legislative Council’s opinion recommended close textual alignment with the EU text where definitions are shared and advised harmonisation between art. 88 of the draft and EU timelines (see Rada Legislacyjna opinion of 25 October 2024: Rada Legislacyjna - Opinion (25 Oct 2024)).

International Alignment

The draft is explicitly framed to implement EU law consistently and to enable Poland to meet its obligations under the EU AI Regulation, including cooperation through the European AI Board and cross‑border enforcement. It also recognizes the need for alignment with international best practices on AI safety, model governance, and cybersecurity. The national provisions are therefore tailored to avoid fragmentation while permitting national procedural detail needed for enforcement and market surveillance.

Implementation Timeline

EventDate / Note
Initial publication of draft on RCL2024-10-16 (RCL publication of the draft)
Government Legislative Council opinion2024-10-25 (opinion published)
Revised draft after consultations2025-02-11 (Ministry published updated draft)
EU AI Regulation earliest applicable provisions2025-02-02 (some EU rules begin application)
Main EU AI Regulation application date2026-08-02 (principal provisions of the EU Regulation apply)
Expected national parliamentary and procedural stepsSubject to interministerial agreement, public consultations and parliamentary timetable (dates to be determined)

Compliance Checklist

Action for Providers/DeployersEvidence / Documentation
Identify if system is prohibited/high‑riskClassification memo, DPIA
Complete conformity assessmentConformity certificate / internal verification records
Register high‑risk systemsRegistration record in national/EU register
Implement risk management systemRisk management policy, logs, testing reports
Maintain technical documentation and logsTechnical dossier, version history, incident logs
Ensure cybersecurity and model securitySecurity assessments, patch and update records
Report serious incidentsIncident reports submitted to authority within required timeframe
Support inspections and provide dataDesignated contact point and requested documents

Sources and References

SourceType
Rządowe Centrum Legislacji — Draft Act on Artificial Intelligence Systems (project entry)Primary Source
Ministry of Digital Affairs — Project (11 Feb 2025 announcement)Primary Source
Government Legislative Council — Opinion (25 Oct 2024)Primary Source
Plain English

This Polish draft law sets up the national framework for Artificial Intelligence systems, applying to companies and individuals who develop or use AI in Poland, to implement and enforce the broader European Union AI Regulation. It aims to operationalize the EU's comprehensive AI rules within Poland, primarily targeting 'providers' (developers) and 'deployers' (users) of AI systems. The law focuses heavily on 'high-risk AI systems' and prohibits certain AI practices that pose unacceptable risks, such as some biometric identification uses and social scoring. If you develop or use high-risk AI, you must: - Perform a conformity assessment and implement risk management systems to ensure safety and ethical standards. - Maintain comprehensive technical documentation, logs, and ensure human oversight. - Continuously monitor your system after it's on the market and register it in a new national registry. To oversee these requirements, the draft proposes creating a new national body, the Commission for AI Development and Safety (KRiBSI). This Commission will be Poland's central authority for market surveillance and enforcement, working with other national regulators like the Personal Data Protection Office. It will have powers to order corrective measures, suspend AI system operations, demand documentation, and issue administrative fines. While the Polish law is still a draft, it's designed to align with the EU AI Regulation, which begins applying some provisions in February 2025, with the main rules taking effect in August 2026. Therefore, businesses should prepare based on these EU timelines. Penalties for non-compliance can be substantial, mirroring the EU framework, with administrative fines and potential criminal liability for serious, intentional breaches. A key practical point is that even though the Polish law's final effective date is unknown, the underlying EU obligations are firm and approaching, meaning preparation is critical now.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Poland - AI Systems Regulation (DAISPXX/2024). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market or deploying

    Applies to: Providers and deployers of AI systems.

    the draft mirrors EU prohibitions for high‑risk abuses (such as certain biometric identification uses and social scoring practices)
  2. #2CriticalBefore placing on market or deploying

    Applies to: Providers and deployers of high-risk AI systems.

    obligations on providers and deployers to perform conformity assessment
  3. #3CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    national procedures for registering high‑risk systems linked to EU registries
  4. #4CriticalBefore placing on market and continuously

    Applies to: Providers and deployers of high-risk AI systems.

    implement risk management systems
  5. #5CriticalBefore placing on market and continuously

    Applies to: Providers and deployers of AI systems.

    mandatory baseline security controls, vulnerability management and supply‑chain considerations
  6. #6CriticalContinuously

    Applies to: Providers and deployers of AI systems processing personal data.

    explicit cross‑references to GDPR obligations and coordination with the Data Protection Authority
  7. #7CriticalWithin required timeframe

    Applies to: Providers of AI systems.

    strengthens provisions for incident reporting
  8. #8ImportantContinuously

    Applies to: Providers and deployers of high-risk AI systems.

    maintain technical documentation and logs
  9. #9ImportantContinuously

    Applies to: Providers and deployers of high-risk AI systems.

    carry out human oversight
  10. #10ImportantContinuously after placing on market

    Applies to: Providers of high-risk AI systems.

    mandatory post‑market monitoring by providers (incident reporting and corrective actions)
  11. #11ImportantContinuously

    Applies to: Providers and deployers of AI systems.

    transparency and disclosure — requirements that enable affected persons to understand when AI is being used
  12. #12ImportantUpon request

    Applies to: Providers and deployers of AI systems.

    cooperation with EU and Member State authorities to respond to cross‑border risks.

© Regulations.AI — created on 13-Jun-2026