FOTC
  • Products
    • Google Workspace
    • Google Cloud
    • Google hardware
    • Zendesk
    • Pipedrive
    • Worksmile
    • Workvivo
  • Services
        • Google Workspace
          • Google AI
          • Migration
          • Technical support
          • Management
        • Google Cloud
          • Cloud engineering as a service
          • Path to the cloud
          • Landing Zone
          • Cost audit
          • Google Cloud Care
  • Training
    • Google Gemini
    • Google Workspace fundamentals
    • Advanced Google Workspace
    • Google Workspace for administrators
  • Customers
  • Company
    • About us
    • Partner Program
    • Careers
    • Blog
Contact
ro pl hu en
  • Privacy policy

Home > Blog > Business > AI Act in 2026 – New Timeline, Real Risks, and Obligations for Polish Companies

AI Act in 2026 – New Timeline, Real Risks, and Obligations for Polish Companies

20 July 2026| Sebastian Górski

Table of contents

  • What is the AI Act?
  • Four Risk Levels Under the AI Act – Where Does Your Company Stand?
  • New AI Act Implementation Timeline – What Does the AI Omnibus Package Mean in Practice?
    • Updated Calendar for AI Act Implementation
  • Strictly Enforced Obligations – Here and Now
    • Building Staff Competence (Art. 4)
    • Absolute Ban on Prohibited Practices (Art. 5)
  • Unofficial Software and the Legal Division of Roles
    • Example 1 – Change of Intended Purpose (e.g., in HR)
    • Example 2 – Deep Technical Modification (Fine-Tuning) in the Financial Sector
    • What Does This Role Shift Mean for a Company in Practice?
  • Penalty for Ignorance: Real Financial Risks
  • How to Safely Implement Artificial Intelligence in a Company
  • AI Act Preparation Roadmap for 2026
  • Safe Artificial Intelligence Implementation with FOTC
  • Frequently Asked Questions (FAQ)
    • Does the AI Act apply to small and medium-sized enterprises (SMEs)?
    • How does the AI Act differ from the GDPR?
    • When must a company inform a customer that they are talking to a bot?

In an average Polish company employing up to 200 people, staff unofficially use at least a dozen different artificial intelligence tools, while executive management typically knows about only three. The lack of control over information flow creates a dangerous legal loophole. Although the AI Omnibus regulatory package adopted in June 2026 pushed back some implementation deadlines for the AI Act, key requirements and strict financial penalties apply strictly right now.

The following article organizes the schedule of changes, explains the risks associated with unverified software, and highlights specific steps to protect your organization from fines reaching up to €35 million.

What is the AI Act?

The AI Act is a comprehensive regulatory framework for artificial intelligence developed and adopted by the European Parliament and the Council of the European Union. It classifies AI systems based on the level of risk they pose. The regulation introduces strict safety and transparency rules, imposing specific obligations on every organization that designs, supplies, or uses algorithms within the European Union market. What does this mean in practice for an average company in Poland?

The regulation focuses on full responsibility for the context and manner in which AI tools are used. A key pillar of the new rules is the necessity of maintaining continuous oversight over processes that utilize artificial intelligence solutions. Companies must anticipate severe financial penalties not only for using prohibited tools, but primarily for lacking appropriate internal procedures and documented staff knowledge regarding the systems operated.

Four Risk Levels Under the AI Act – Where Does Your Company Stand?

The regulation does not assess the technology itself, but rather the context of its use and its impact on human rights and safety. Depending on this, the AI Act divides tools into four categories:

Risk Level AI ACT #2Examples of Corporate Use AI ACT #2Main Legal and Organizational Obligations AI ACT #2
1. UnacceptableEmployee emotion recognition, social scoring, subliminal manipulationTotal ban on use starting February 2, 2025
2. HighAI in recruitment and employee evaluation, credit scoring, health insurance pricingRegistration in the EU database, audits, data management, mandatory human oversight
3. LimitedSales chatbots, marketing content generators, graphic material generatorsObligation to inform users they are talking to AI and content marking/watermarking (Art. 50)
4. MinimalSpellcheck assistants, anti-spam filters, internal process analyticsNo requirements under the AI Act (only Art. 4 training requirement and general GDPR apply)

New AI Act Implementation Timeline – What Does the AI Omnibus Package Mean in Practice?

For many months, the business sector across the entire European Union treated August 2, 2026, as the moment high-risk artificial intelligence systems would become fully regulated. However, this timeline underwent a fundamental shift. In mid-2026, the European Parliament and the Council of the EU approved a package of amendments known as the Digital Omnibus on AI.

Updated Calendar for AI Act Implementation

Entry into Force Date AI ACT #2Legal Provision or Requirement AI ACT #2Formal Status AI ACT #2
August 1, 2024Initial entry into force of the EU AI Act regulationIn force
February 2, 2025Ban on prohibited practices (Art. 5) and requirement for personnel literacy/competence building (Art. 4)In force
August 2, 2025Rules and obligations for providers of general-purpose AI modelsIn force
August 2026Launch of national supervisory authorities and commencement of direct inspections and enforcementCurrent stage
December 2, 2026Obligation for digital marking of AI-generated content and transparency rules (Art. 50)In implementation
December 2, 2027Obligations for standalone high-risk systems under Annex III (e.g., credit scoring, insurance risk assessment, recruitment and evaluation systems)Postponed (AI Omnibus)
August 2, 2028Obligations for AI systems that serve as product safety componentsPostponed (AI Omnibus)

Strictly Enforced Obligations – Here and Now

The delay of deadlines under the Omnibus package did not cover the entire regulation. Two pillars of the regulations have had legal effect since February 2, 2025, and these are what businesses must focus on first.

Building Staff Competence (Art. 4)

This provision requires employers to ensure that personnel operating artificial intelligence tools possess adequate knowledge. Employees must understand how algorithms work, the principles of data input, and the risks associated with machine-made decisions. The EU legislature does not view this requirement as a one-time training session; competence building must become a permanent element of internal company procedures.

Starting August 2026, newly established supervisory bodies will begin official audits. Documented lack of training and procedures required by Article 4 will be treated as an aggravating circumstance when imposing financial penalties.

Absolute Ban on Prohibited Practices (Art. 5)

Since early 2025, the deployment and use of AI systems designed for socially harmful actions has been prohibited across the entire European Union. The ban includes solutions utilizing subliminal manipulation, inducing unconscious behavioral changes in people, and so-called social scoring (evaluating trustworthiness based on everyday behavior). The rules also ban the use of tools for analyzing employee emotions in the workplace and real-time remote biometric identification in public spaces.

Unofficial Software and the Legal Division of Roles

Employees using free, publicly available content generators or plugins without the IT department’s knowledge (so-called Shadow AI) poses a massive operational threat. Inputting confidential financial documents, customer databases, or commercial contracts into unauthorized assistants creates an immediate risk of data leaks, GDPR violations, and breaches of trade secrets.

From a legal supervision perspective, it makes no difference whether a given technology was officially purchased by executive management or launched independently by an employee.

At the same time, the AI Act precisely distinguishes legal responsibility depending on the role an entity plays in the technological ecosystem. Two primary roles are identified:

  • Deployer: An organization that uses an off-the-shelf AI tool provided by an external vendor in its operations (for example, software for automatically calculating creditworthiness or a system supporting recruitment).
  • Provider: An entity that designs, develops, and places an AI system on the market under its own name or trademark.

However, there is a formal trap. An organization that purchases off-the-shelf software from an external firm and subsequently makes substantial modifications or changes its intended purpose ceases to be merely a deployer under the regulation. It automatically assumes full legal and financial responsibility assigned to a provider.

Two very specific examples illustrate situations where an organization shifts from a deployer to a provider:

Example 1 – Change of Intended Purpose (e.g., in HR)

A company that purchases a license for a general LLM model / text assistant created and intended for simple office tasks (e.g., drafting job descriptions or editing emails) assumes the role of a deployer.

However, if the internal HR department integrates this model with its databases and modifies it to automatically analyze, score, and rank candidate resumes during recruitment, the organization changes the technology’s original purpose. This is because recruitment and candidate selection are classified as high-risk areas under the AI Act. In the eyes of the law, this company becomes a provider of a high-risk system.

Example 2 – Deep Technical Modification (Fine-Tuning) in the Financial Sector

A bank or lending institution buys ready-made analytical software from an external IT company. Subsequently, the internal IT team performs a substantial modification (fine-tuning) by training the model on its own unique historical databases and altering the scoring algorithms.

As a result of this modification, the system begins making or directly determining credit approval decisions independently. Due to deep interference with the algorithm’s operation, the software vendor is no longer liable for its final output—the bank assumes full legal and financial responsibility as a provider.

What Does This Role Shift Mean for a Company in Practice?

Assuming the role of a provider means the organization cannot limit itself to following user manuals. At its own expense, it must create and maintain complete technical documentation and a risk management system, conduct a formal conformity assessment, and register the system in the EU database pursuant to Article 49 of the AI Act.

Penalty for Ignorance: Real Financial Risks

Violating the requirements of the EU Artificial Intelligence Act incurs severe penalties. The amount directly depends on the severity of the offense and the company’s annual turnover from the preceding financial year:

  • Providing false or misleading information to supervisory authorities: Fines reach up to €7.5 million or up to 1% of annual turnover.
  • Violating deployer or provider obligations for high-risk systems and lack of transparency: Fines reach up to €15 million or up to 3% of global turnover.
  • Using prohibited AI practices (Art. 5): Fines reach up to €35 million or up to 7% of total worldwide annual turnover.

Business owners must remember that these figures represent ceilings, not automatically calculated amounts. When evaluating an offense, supervisory authorities consider the scale of negligence, duration of the violation, prior cooperation, and whether the company made genuine attempts to document compliance procedures.

Beyond monetary fines, market surveillance authorities have the power to order the immediate cessation of a tool’s use within an organization. Added to this are reputational damage and the risk of individual civil damages claims filed by employees or clients.

How to Safely Implement Artificial Intelligence in a Company

The solution to Shadow AI issues is not an absolute ban on new technologies, but rather creating a secure, audited work environment.

An example of a structured approach is implementing Google Workspace with Gemini assistant. Data entered by employees into the system is not used to train public AI models nor shared with third parties. Information processing complies with European data protection standards, featuring transparent access privilege distribution within the organization.

In parallel, an organizational governance structure must be established. Representatives from legal, IT, finance, and HR departments should jointly establish rules for approving new tools.

For processes impacting people, ensuring human oversight (human-in-the-loop) is critical. Machine-generated recommendations—such as candidate evaluations or service pricing—must be verified by a designated employee who makes the final decision.

AI Act Preparation Roadmap for 2026

Effectively aligning a company with AI Act requirements requires executing several organizational steps in sequence:

  1. Conduct a full software inventory. Document all tools utilizing AI algorithms across all business units—with special attention to applications deployed independently by employees (Shadow AI).
  2. Verify active processes. Audit company activities against practices prohibited under Article 5 (e.g., workplace emotion recognition, subliminal manipulation).
  3. Launch a competence enhancement program (Art. 4). Organize and document ongoing AI safety training cycles for all staff.
  4. Assess company role and scope of model modifications. Determine whether the organization operates strictly as a deployer or—through deep modifications or fine-tuning of general-purpose models—assumes provider obligations.
  5. Analyze vendor contracts. Review and update agreements regarding liability clauses, input data quality, technical documentation, and incident reporting procedures.
  6. Implement internal AI policy and human oversight procedures. Establish protocols for personnel verification of algorithmic decisions (Human in the Loop), confidential data protection, and digital marking of synthetic content (Art. 50).
  7. Register systems and schedule annual audits. Submit high-risk systems to the official EU database (under Art. 49) and set a timetable for regular compliance reviews.

Safe Artificial Intelligence Implementation with FOTC

Preparing a company for legal requirements does not mean foregoing innovation. The team of experts at FOTC supports organizations at every stage of safe technology adaptation:

  1. Deploy and configure a closed Google Workspace ecosystem with Gemini assistant, ensuring total data confidentiality.
  2. Help conduct software inventories, highlight security gaps, and eliminate risks associated with unofficial tools.
  3. Train teams on the safe use of digital assistants, fulfilling the formal competence-building mandate under Article 4.

Fill out the contact form on our website to schedule a free consultation with an FOTC advisor.

Frequently Asked Questions (FAQ)

Does the AI Act apply to small and medium-sized enterprises (SMEs)?

Yes. Applicability under the regulation is determined by the intended purpose of the AI system and its impact on people, not company size or capital. A small recruitment agency using algorithms to evaluate candidates is subject to the requirements to the exact same extent as a large corporation.

How does the AI Act differ from the GDPR?

GDPR focuses on protecting personal data and individual privacy. The AI Act, on the other hand, regulates the safe design, deployment, and use of artificial intelligence systems themselves, focusing on technical risk minimization and fundamental rights protection.

When must a company inform a customer that they are talking to a bot?

The disclosure obligation under Article 50 arises immediately upon the first interaction. A virtual advisor or online store chatbot must clearly inform the customer of its synthetic nature at the very start of the conversation. Burying this information in the website terms and conditions is insufficient.

This Page Contains:
Table of contents
What is the AI Act?
Four Risk Levels Under the AI Act – Where Does Your Company Stand?
New AI Act Implementation Timeline – What Does the AI Omnibus Package Mean in Practice?
Strictly Enforced Obligations – Here and Now
Unofficial Software and the Legal Division of Roles
Penalty for Ignorance: Real Financial Risks
How to Safely Implement Artificial Intelligence in a Company
AI Act Preparation Roadmap for 2026
Safe Artificial Intelligence Implementation with FOTC
Frequently Asked Questions (FAQ)

Join top players benefitting from the cloud

Use FOTC's 10 years of experience in cloud management.

Find out more
Services
  • Cloud Infrastructure Strategy Roadmap
  • Landing Zone
  • Training
Products
  • Google Workspace
  • Google Cloud
  • Google Workspace for Education
Industry
  • Education
  • Gaming
  • Government
  • Healthcare
  • Retail
  • Small and medium businesses
Knowledge
  • Blog
  • Case Studies
  • NIS2 directive
Company
  • About us
  • Career
  • Contact
  • Partner program
  • Google Workspace Support
  • Privacy Policy
  • Regulations
Copyright © 2014 – 2026 Fly On The Cloud sp. z o.o. KRS: 0000500884, NIP: 8971797086, REGON: 022370270