Hundreds of articles have been written in Poland about the EU AI Act. About who will actually enforce it here, almost nothing. And that is the part starting soonest.

On 28 October 2026 the provisions giving the Polish supervisory authority real powers take effect: inspections, proceedings and penalties. Here is what is worth knowing in advance.

Who KRiBSI is

The Commission for AI Development and Safety, established by the Act of 3 July 2026 on artificial intelligence systems, published in the Journal of Laws on 27 July under item 1003.

It is a collegial body, not a single-official agency. Its members include representatives of institutions that already supervise their respective markets: the Office of Competition and Consumer Protection, the Polish Financial Supervision Authority, the National Broadcasting Council and the Office of Electronic Communications.

That design says something useful about what to expect. KRiBSI is not starting from zero. Its members have run proceedings on unfair market practices, financial supervision and data protection. The procedural experience is already in place; what was missing was a legal basis for a new area.

The calendar

  • 11 August 2026 - the main body of the Act took effect: provisions on the organisation of supervision, notified bodies and innovation-support measures, including the regulatory sandbox.
  • October 2026 - deadline for appointing the chair of the Commission, two months after the Act entered into force.
  • 28 October 2026 - provisions take effect on inspections, proceedings before the authority, settlements reducing sanctions and financial penalties, as well as on individual opinions and clarifications.
  • November 2026 - deadline for the full Commission to be constituted, three months after entry into force.

Until 28 October the Commission carries out no inspections and imposes no penalties. That does not mean the obligations are suspended. The AI Act is an EU regulation with direct effect, whether or not the national authority has finished organising itself. The Polish Act governs the supervisory procedure only.

The thing worth knowing early

Discussion of AI supervision is dominated by the image of an inspection: an official arrives, asks for documents, issues a decision. That image is incomplete, and reassuring in the wrong way.

The Act opens the ability to complain about how an AI system operates to anyone, employees included. In practice that means proceedings may begin not with a decision by the authority, but with one person who concluded that something affected them.

A candidate whose CV was rejected by an automated screen. An employee assessed by a system whose rules nobody explained to them. A customer refused a service by an algorithm. These are real people with a real reason to write, and they need neither a lawyer nor a fee.

A board reading "inspection" thinks "someday, maybe, not us". The same board reading "a job applicant can file a complaint" starts thinking about its own recruitment. The second thought is closer to how this is likely to play out.

What it means for an ordinary company

If you use AI in standard ways, the risk of an inspection on the authority's own initiative is low. An authority with limited resources starts with the cases that come to it, and with the organisations of greatest impact.

But three things are worth having in order before anyone asks.

Know what you use. An AI tool register is not an AI Act requirement for an ordinary deployer, but without one you cannot answer any question about how you use AI. If a complaint concerns a tool nobody in the company knew was running, the situation deteriorates faster than the underlying breach would justify.

Have evidence of training. The literacy obligation has applied since February 2025, and after July's change of wording what counts is what you can show: training delivered, dates, acknowledgements.

Check recruitment and performance evaluation. This is the most common place where a company unknowingly enters the high-risk category, and at the same time the area most likely to generate a complaint from a specific person.

The regulatory sandbox

The Act also provides the legal basis for a regulatory sandbox: a mechanism for companies that want to test AI solutions in a controlled environment, with the authority's support and without the risk that a first mistake ends in a fine.

For companies building their own AI systems this is genuinely valuable. For those that only use AI it is a curiosity, but worth knowing it exists.

What to do this quarter

There are two and a half months until the end of October. Enough to put the basics in order, and not enough if you start in October.

  • List the AI tools used across the organisation, including those bought by individual departments.
  • Check whether any use case involves decisions about people: recruitment, evaluation, access to services.
  • Train your team and keep the documentation.
  • Check that your chatbot and AI-generated content are marked in line with Article 50.

Not sure where to start? The AI Ready Check is a free three-minute preliminary diagnosis showing which obligations may apply to your organisation.

Sources

  1. Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003) - establishment of KRiBSI, inspection procedure, proceedings and penalties: dziennikustaw.gov.pl
  2. Polish Ministry of Digital Affairs - The AI Systems Act: safe development of artificial intelligence in Poland: gov.pl
  3. Regulation (EU) 2024/1689 (AI Act) - Article 74 (market surveillance), Article 85 (right to lodge a complaint), Article 99 (penalties): eur-lex.europa.eu

This article was written with the help of artificial intelligence and reviewed before publication by the author, who takes editorial responsibility for it.