GLI – AI, Machine Learning & Big Data 2026: The Polish perspective on artificial intelligence law

14 May 2026 | Knowledge, News

Global Legal Insights (GLI) is a series of international publications by the Global Legal Group (GLG), authored by legal practitioners from around the world. It offers an up-to-date and highly practical guide to the applicable regulatory landscape, complemented by expert commentary on specific areas of law across different jurisdictions. In short: legislation and actionable know-how in one place.

We co-authored this year’s eighth edition of the volume dedicated to artificial intelligence, machine learning and big data, in which we analyse the key legal aspects of the development and deployment of AI systems in the Polish context.

Trends: Poland on the path to digital maturity

We have reached an advanced stage of digital transformation, with a marked acceleration in the adoption of AI solutions across both the private sector and public administration.

This gives rise to a number of challenges, which can be grouped into four key categories:

  • Personal data protection
  • Liability for algorithmic decisions
  • Automation of HR processes
  • Intellectual property rights in AI-generated content

Poland does not yet have a standalone statute dedicated exclusively to artificial intelligence. AI-related activities are currently governed by the directly applicable EU AI Act and by horizontal legislation such as the GDPR, the Civil Code, copyright law and cybersecurity regulations.

The draft AI law addresses, inter alia:

  • Market surveillance in accordance with the EU AI Act
  • Procedures concerning infringements
  • Accreditation and notification of conformity assessment bodies
  • Reporting of serious incidents
  • Measures to support innovation
  • Administrative penalties

The draft does not address matters relating to defence and national security, nor fundamental research that does not involve real-world testing or placing on the market.

The absence of dedicated AI legislation means, however, that liability, including for infringements of individual rights, is based solely on an interpretative extension of general principles of law.

Centralised supervision: a model that sets Poland apart within the EU

As regards supervision, unlike the majority of EU countries, which entrust oversight to existing regulators, Poland is establishing a new body – the Commission for the Development and Safety of Artificial Intelligence (KRiBSI) – which is to serve as the sole national market surveillance authority and the single point of contact with the EU. The draft act also provides for regulatory sandboxes, allowing temporary derogations from documentation requirements. Participation in these is free of charge for, inter alia, SMEs.

The key date for all those deploying AI systems is 2 August 2026 – the deadline for compliance with the EU AI Act. From that date, the principal obligations applicable to high-risk systems will take effect.

Poland’s ‘AI roadmap’

A detailed analysis of these issues, together with an overview of the current regulatory landscape, can be found in the Polish jurisdiction chapter of the Global Legal Insights guide. Its authors – Monika Maćkowska-Morytz, Robert Brodzik, Jarosław Fejdasz and Wiktoria Ostrowidzka – have examined, among other things:

  • Generative AI and foundation models
  • AI in the workplace
  • Key considerations for the implementation of AI into business
  • Liability
  • Algorithmic discrimination and bias

As a large market with a growing demand for AI, Poland faces extensive EU regulatory requirements alongside notable institutional gaps at the national level.

Chief among the concerns is the lack of full harmonisation between the AI Act and the GDPR, so in the absence of unified national compliance methodologies, companies are left to navigate both regimes in parallel.

In the medium term, the market is expected to consolidate, and AI system audits will become a standard feature of due diligence investigations.

The experience of GDPR implementation clearly demonstrates that regulatory ambition must be backed by an effective supervisory apparatus. Without that, harmonisation will remain more of an aspiration than reality.

The Polish jurisdiction chapter is available here.

Questions? Contact us

Latest Knowledge

Announcement of Income Tax Reform

On 19 August, during a press conference, the Prime Minister announced a package of tax changes planned for next year. According to the announcement, the reform is intended, on the one hand, to ease the burden on the middle class and, on the other, to shift a greater fiscal burden onto the wealthiest individuals and the largest companies. We take a look at the proposals included in the announced package and explain what they might mean for taxpayers.

Family foundations and the tax authorities: what draft bill UD447 proposes and why this is not the end of the troubles

Family foundations were intended to provide entrepreneurs with a stable framework for intergenerational wealth management. Yet not even four years have passed since the first such foundations were established, and the rules governing their taxation are set to be changed once again. This is because the scale of interest and the practical problems uncovered have overwhelmed the drafters of the legislation, as best illustrated by the figures – 927 applications for individual tax rulings and 77 opinions issued from the Head of the National Revenue Administration. This does not, however, mean that family foundations are being used on a massive scale for aggressive tax optimisation. A significant proportion of the queries concerned simply how to correctly apply the complex regulations.

NIS2 and the National Cybersecurity System Act in transport: what you need to do before October 2026

The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.

Family foundations: the government has done the maths and presented the bill

Three years. That’s how long we’ve been waiting for what the Council of Ministers had seen in the data from the outset – and has now disclosed in its review of the Family Foundation Act. The document not only diagnoses the problems, but also previews substantial changes to rules that founders and their advisers treated as settled and stable. And therein lies a problem that goes far beyond tax matters. If the rules of the game are changed while the game is being played, there can be neither planning stability nor trust in the law. It is no coincidence that one of the greatest concerns among entrepreneurs considering setting up a foundation is not the level of taxation, but the stability of the legal framework – which today is once again being called into question.

What the new swiss franc act means for banks

We now have a new Act on Special Measures for the Adjudication of Cases Concerning Loan Agreements Denominated in or Indexed to the Swiss Franc. The provisions come into force 14 days after publication. So now is a good time to look at what lies ahead and what banks should be doing today.

New draft Pay Transparency Act – what has changed since December 2025?

A second version of the draft act on strengthening the application of the right to equal pay for equal work or work of equal value between men and women has now been published. It refines procedures and deadlines and introduces a new supervisory body. We have already discussed the changes affecting the recruitment stage and the three pillars of the forthcoming pay transparency framework, noting that Poland will miss the EU transposition deadline of 7 June 2026. Now, we take a closer look at the further changes, new developments and risks that have emerged in the latest, April version of the draft.

Payment Services Regulation (PSR) – between consumer protection and due diligence

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

Contact us:

Monika Maćkowska-Morytz

Monika Maćkowska-Morytz

Advocate / Partner / NewTech / Head of the Personal Data Protection & Cybersecurity Practice

+48 660 765 918

m.mackowska-morytz@kochanski.pl

Robert Brodzik

Robert Brodzik

Advocate / Counsel / NewTech / Data Protection and Cybersecurity

+48 532 206 479

r.brodzik@kochanski.pl

Jarosław Fejdasz

Jarosław Fejdasz

Advocate / Senior Associate / NewTech M&A / Intellectual Property / Personal Data Protection and Cybersecurity

+48 788 474 759

j.fejdasz@kochanski.pl