As of today, August 2, 2026, the EU's Artificial Intelligence Act (AI Act) applies across the European Union, Poland included. Except what's taking effect is not quite what was being announced a month ago. Five days before this date, the EU postponed the heaviest obligations to 2027 and 2028. What remains in force today, however, affects a far wider group of companies than high-risk systems.
Below, we break it down: what applies from today, what has been deferred, where the Polish implementing act stands, and what to check in your organisation this week. Back in May we wrote about what to expect before this date - what follows is the current legal state as of today.
The short version: what changes on August 2, 2026
As of today, the transparency obligations under Article 50 of the AI Act apply. That means informing people that they are interacting with an AI system, labelling synthetic content, disclosing deepfakes, and informing people about emotion recognition and biometric categorisation.
Obligations for standalone high-risk systems under Annex III (recruitment, credit scoring, education, access to essential services) were postponed to December 2, 2027. AI systems embedded in products under Annex I have until August 2, 2028.
The Polish Act on artificial intelligence systems was published in the Journal of Laws on July 27, 2026, and essentially enters into force on August 11. The new supervisory authority, KRiBSI, is expected to start operating in November 2026. This has no bearing on companies' obligations, since the AI Act applies directly, regardless of the state of national law.
Where does this date come from
The AI Act, Regulation (EU) 2024/1689, entered into force on August 1, 2024. Its application was staggered across several stages. Since February 2, 2025, the prohibited practices under Article 5 and the AI competence obligation under Article 4 have applied. Since August 2, 2025, the rules on general-purpose AI (GPAI) models, governance frameworks and penalty provisions have applied. August 2, 2026 is the date of general application of the regulation - the point at which, by default, everything not carved out under a separate deadline starts to apply.
And that list of carve-outs grew at the end of July.
The Digital Omnibus: the plot twist from July 27
On July 27, 2026, Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, entered into force. It was adopted on July 8 and published in the EU Official Journal on July 24. It amends Article 113 of the AI Act and pushes back the application deadlines for high-risk system obligations.
The new timeline:
- December 2, 2027: obligations for standalone high-risk systems qualified under Article 6(2) in conjunction with Annex III. That covers employment, education, critical infrastructure, access to essential services, migration, law enforcement, and the administration of justice.
- August 2, 2028: obligations for AI that is a component of products covered by EU harmonisation legislation under Annex I, including medical devices, toys and aviation equipment.
- August 2, 2027: deadline for member states to establish at least one AI regulatory sandbox.
The reason for the postponement is mundane. The harmonised standards, without which conformity assessment of a high-risk system is essentially guesswork, were not ready in time. It's hard to enforce compliance with a standard that doesn't exist yet.
Along the way, the amendment also added new prohibited practices to Article 5: systems that generate or manipulate intimate images of people without their consent, and material depicting the sexual abuse of minors. Providers of such systems have until December 2, 2026 to implement technical safeguards.
What actually takes effect today: Article 50
The Digital Omnibus left the transparency obligations untouched. As of August 2, 2026, Article 50 of the AI Act applies, and this is the provision that affects the most companies, because it doesn't require having any sophisticated system in place. A chatbot on a website or an image from a generator is enough.
Disclosing contact with AI
Providers of systems designed for direct interaction with people must ensure the person knows they are communicating with an AI system. This covers customer-service chatbots, voicebots and voice assistants. The obligation drops away where it is obvious to a reasonably well-informed, observant and circumspect person, given the context. In practice: if you have a chat widget on your site powered by a model, the user should learn that at the start of the conversation, not fifteen minutes in.
Labelling synthetic content
Providers of systems generating image, audio, video or text must mark the system's outputs in a way that makes it possible to detect that they were AI-generated or manipulated. The marking must be machine-readable - metadata or a watermark, not just a caption under the image.
This is an obligation on the tool provider, not on every end user. There is no blanket requirement to label every email drafted with a model's help. Nor does the obligation apply where AI performs a purely assistive editing function and does not substantially alter the material, for instance in ordinary proofreading or quality improvement.
There is one buffer here. The machine-readable labelling requirement under Article 50(2) applies from December 2, 2026 to systems placed on the market before August 2, 2026. Systems entering the market from today must comply with it immediately. The remaining Article 50 obligations have no transition period.
Deepfakes and realistic synthetic content
Here, the obligation falls on the deployer, i.e. the company publishing the material. If you use AI to generate an image, audio or video constituting a deepfake, you must disclose that the content was artificially generated or manipulated. The definition in Article 3(60) is broad: content resembling existing persons, objects, places or events that a recipient could mistake for authentic.
For works that are evidently artistic, creative, satirical or fictional, the obligation is limited to disclosing the existence of such content in a way that does not spoil the enjoyment of the work.
A separate rule applies to AI-generated texts published to inform the public on matters of public interest. You must disclose that the text was artificially generated, unless it has undergone human review or editorial control and someone bears editorial responsibility for the publication.
Emotion recognition and biometric categorisation
Deployers of emotion-recognition or biometric-categorisation systems must inform the people affected and ensure GDPR compliance. This is a rarer but real scenario in call centres, recruitment and access control.
Provider or deployer: it's not the same thing
The most common mistake in AI Act conversations is assuming the rules only apply to "tech companies." The AI Act splits the roles. The provider is responsible for the system's design and labelling mechanisms. The deployer - an ordinary company using a ready-made tool - is responsible for disclosing deepfakes, informing people about emotion recognition, and for how it actually uses the system.
A provider's assurance that "the tool is AI Act compliant" doesn't remove your own obligations. This applies to marketing agencies publishing realistic visualisations, shops running a chatbot, companies recording an AI voiceover for video content, and law firms publishing content prepared with a model.
AI literacy after the changes: the obligation stays, the bar drops
The Digital Omnibus changed the wording of Article 4. Previously, providers and deployers had to ensure, to the extent possible, an adequate level of AI competence among staff. Now they must take measures to support the development of that competence, and the provision explicitly clarifies that this does not mean guaranteeing a specific level of knowledge for a specific person.
An obligation of result became an obligation of diligent effort. The obligation hasn't disappeared and hasn't been deferred. What changed is how it will be assessed. In practice, a complete absence of training will rarely be a standalone basis for a penalty, but it looks very bad in the file as an aggravating circumstance when an authority is examining something else. Documented AI literacy training and an internal attendance register are the cheapest insurance policy available here.
Penalties
Breaching the Article 50 transparency obligations is subject to an administrative fine under Article 99(4) of the AI Act: up to EUR 15 million or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
For prohibited practices under Article 5, the ceiling is EUR 35 million or 7% of turnover. For supplying false or misleading information to supervisory authorities: EUR 7.5 million or 1.5%. For the full breakdown of thresholds and what determines the size of a fine, see our article EU AI Act fines and penalties.
These are statutory ceilings, not price lists. The size of a fine depends on the nature, gravity and duration of the infringement and on the remedial action taken. For most Polish companies, the real cost won't be the maximum fine - it will be the moment a major client or contracting party demands evidence of due diligence in a tender, and the company has nothing to show.
As of today, the European Commission can also impose fines on general-purpose AI model providers under Article 101, which had previously been excluded from application.
The Polish angle: the Act and KRiBSI
The domestic implementation process wrapped up in the final days of July. The Sejm passed the Act on artificial intelligence systems on July 3, 2026, adopting 24 of the Senate's 25 amendments. The President signed it on July 24, and it was published in the Journal of Laws on July 27. The first provisions, on setting up a unit within the Ministry of Digital Affairs to service the new authority, entered into force on July 28. The rest of the Act takes effect on August 11, 2026.
The Act establishes the Committee for AI Development and Security (KRiBSI) as the national market surveillance authority under the AI Act. The Committee will conduct inspections and proceedings, handle complaints from citizens and businesses, impose administrative fines, issue individual opinions, and set up regulatory sandboxes. It will be led by a chair appointed by the Sejm with Senate consent for a five-year term, with deputies and representatives nominated by, among others, the President of the Office of Competition and Consumer Protection (UOKiK) and the National Broadcasting Council.
Organisational timeline: the chair is to be appointed within two months of the Act entering into force, i.e. by October 2026, and the full Committee within three months, i.e. by November.
It's tempting to conclude that since the authority doesn't exist yet, neither do the obligations. That's wrong. The AI Act is an EU regulation and applies directly. The Article 50 obligations arise today, regardless of when KRiBSI is constituted. The national Act governs who enforces these obligations and how - not whether they exist at all. Breaches that occur before November don't disappear once the Committee is appointed.
All the key dates in one place
- February 2, 2025: prohibited practices (Article 5) and the AI competence obligation (Article 4)
- August 2, 2025: general-purpose AI (GPAI) models, governance frameworks, penalty provisions
- July 27, 2026: the Digital Omnibus on AI, Regulation (EU) 2026/1744, enters into force
- July 28, 2026: first provisions of the Polish Act on AI systems
- August 2, 2026: transparency obligations (Article 50), Commission fines for GPAI providers (Article 101)
- August 11, 2026: the main body of the Polish Act on AI systems enters into force
- November 2026: KRiBSI expected to start operating
- December 2, 2026: end of the transition period for machine-readable content labelling
- August 2, 2027: deadline for establishing regulatory sandboxes
- December 2, 2027: obligations for high-risk systems under Article 6(2) (Annex III)
- August 2, 2028: obligations for high-risk systems under Article 6(1) (Annex I)
What to do this week
You don't need an implementation project for this. You need a review.
- List the AI tools used in your company. Who, where, for what, on what data. Without an AI system register, any further analysis is guesswork.
- Check your chatbot and voicebot. Does the notice that you're talking to AI appear at the start of the conversation, and is it clear?
- Review your marketing materials from recent months. Realistic images, video, AI voiceovers, depictions of people. If any content could be mistaken for authentic, it needs disclosure.
- Set a rule for content published on your website and social media. Who reviews texts prepared with a model, and who bears editorial responsibility for them.
- Check your contracts with AI tool vendors. Who is responsible for machine-readable labelling, and who bears the cost if it turns out the tool doesn't do it.
- Classify the systems that will fall into the high-risk category in December 2027. Recruitment, employee evaluation, scoring, qualification for services. The deadline is distant, but classification still takes several weeks.
- Write down your internal rules for using generative AI and start a training register. That's your evidence base under Article 4.
- Decide who in the company receives reports about an AI system malfunctioning and what happens to them next.
The postponement for high-risk obligations gives sixteen months of runway. The history of GDPR implementation suggests how that kind of runway usually gets used. Whoever treats this time as a window to get processes in order, rather than a reason to shelve the topic, will simply be ready come December 2027.
Frequently asked questions
Has the AI Act applied in the EU since August 2, 2026?
Yes, but not in full. From this date, the transparency obligations under Article 50 apply. Prohibited practices and the AI literacy obligation have applied since February 2025, and general-purpose AI model rules since August 2025. Obligations for high-risk systems were postponed to December 2027 and August 2028.
Do I have to label every text written with the help of ChatGPT?
No. The machine-readable labelling obligation rests with the provider of the generative tool. As a company, you must disclose deepfakes and AI-generated texts published to inform the public on matters of public interest, unless the text has undergone human review and someone bears editorial responsibility for it.
Does a chatbot on my website have to disclose that it is AI?
Yes, unless this is obvious from the context to a reasonably well-informed, observant and circumspect person. In practice, it is safer to assume it is not obvious and add a clear message at the start of the conversation.
Does a private individual have to label AI content on their profile?
Article 50 obligations apply to professional and business activity. A private individual posting content on their own account, outside a professional context, is not subject to these requirements.
I have an AI recruitment tool. What do I need to do by August 2, 2026?
Nothing under the high-risk rules, since that deadline was postponed to December 2, 2027. Today, transparency obligations apply if the tool interacts directly with candidates or analyses emotions. It is worth starting classification and documentation now, as that is the longest part of the preparation.
What penalties apply for breaching transparency obligations?
Up to EUR 15 million or up to 3% of total worldwide annual turnover, whichever is higher. For prohibited practices, the ceiling is EUR 35 million or 7% of turnover.
What is KRiBSI and when does it start operating?
The Committee for AI Development and Security (KRiBSI) is the Polish AI market surveillance authority, established by the Act on AI systems. The chair is to be appointed in October 2026, with the full Committee in November. Until then, obligations arising directly from the AI Act still apply.
Is AI literacy still mandatory?
Yes. The Digital Omnibus softened the wording of Article 4 from ensuring an adequate level of AI competence to taking measures to support its development, but it did not remove or defer the obligation. Documented training remains the simplest way to demonstrate an organisation is meeting it.
Does the AI Act apply to small companies and sole traders?
Yes. The regulation has no size threshold. Obligations depend on which AI systems you use and in what role, not on headcount.
How AI TrustCERT helps
The list in this article looks simple on paper. The trouble usually starts at item three, when it turns out nobody in the company actually knows how many AI tools their teams use, and last year's training was never logged anywhere.
The AI TrustCERT training programme includes courses on AI literacy, AI risk management and AI governance, each ending in an exam and a completion certificate. The platform for documenting compliance - a register of the AI tools you use, ready-to-adopt policies, and an incident-reporting path - is included in the training licence, ready to launch in 1-7 days.
If you want to see where your organisation stands, start with the free AI Ready Check - 3 minutes, no commitment.
Summary
August 2, 2026 is not the day the AI Act "fully enters into force" - that description was accurate a month ago. It's the day the transparency obligations take effect, reaching a far wider group of companies than the high-risk systems whose deadlines were pushed to 2027 and 2028.
Whoever can already say today where AI is used in their organisation, whether their chatbot identifies itself, and who's responsible for content prepared with a model, is already further along than most companies waiting for "final guidance."
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), EUR-Lex
- Regulation (EU) 2026/1744 of the European Parliament and of the Council (Digital Omnibus on AI), EU Official Journal, July 24, 2026
- Act on artificial intelligence systems, Journal of Laws, July 27, 2026
- Ministry of Digital Affairs communication on the signing of the Act on AI systems, gov.pl
- Analysis by the National Chamber of Legal Advisers, "AI Act after the changes," July 27, 2026
This article was written with the help of artificial intelligence and reviewed before publication by the author, who takes editorial responsibility for it.