The AI Act in practice: challenges and opportunities for the development of artificial intelligence in the EU

26 July 2024 | Knowledge, News, The Right Focus

On 12 July 2024, just over three years after work began, the AI Act, i.e. the Regulation laying down harmonised rules on artificial intelligence, was published in the Official Journal of the European Union. The Regulation will enter into force 20 days after this date and will be fully applicable from 2 August 2026. This means that providers and users of artificial intelligence will soon face a number of new obligations.

We look at how to prepare for this effectively.

How to prepare your business for the AI Act

Before embarking on large-scale implementations, every company should consider what systems it uses, if any, and what its role is in relation to them.

This is because the extent of your responsibilities will depend on the type of system and on whether you are the system’s provider, just a user, or perhaps you use it with appropriate modifications.

EN Broszura AI 3

Classification of systems

The AI Act classifies AI systems according to their level of risk:

  • Solutions deemed to pose unacceptable risk, such as those using subliminal techniques or social scoring based on behaviour or personal characteristics, are prohibited.
  • High-risk systems, such as those using biometric data or used for employee recruitment, will be allowed after meeting additional requirements, including, without limitation:
    • Monitoring system performance
    • Ensuring that input data is relevant and representative
    • Compliance with registration obligations
  • Limited-risk systems, such as chatbots or technologies that manipulate audiovisual content – it will be necessary to inform users that they are dealing with artificial intelligence systems
  • Minimal-risk systems, such as spam filters, will be free to use, although, as with all AI systems, providers and deployers should take measures to ensure that their staff and others responsible for the systems have a sufficient level of AI literacy

In addition, the AI Act also singles out general-purpose AI models, such as tools like ChatGPT.

Defining your role

In order to adequately prepare for the AI Act, the first step is to map and identify the processes. This will enable you to determine whether you are dealing with an AI system and to verify its technical standards.

You will then need to classify the system according to the risk categories mentioned above and define your role, i.e. whether you are a supplier or a deployer, whether you are modifying the system, and to identify your specific responsibilities.

The next step will be to develop appropriate procedures and documentation, including:

  • Policy on the use of AI systems
  • Technical documentation on the technologies used
  • Risk management mechanisms
  • Procedures for dealing with customers or recipients of the system

Preparation for action

As part of your operational preparation to meet your obligations under the AI Act, it is advisable to:

  • Carry out an AIRA (AI Risk Assessment) process and designate a structure responsible for managing AI, monitoring risks and ensuring compliance, as well as implementing appropriate internal policies
  • Assess the AI systems in use and analyse the associated risks (e.g. discrimination, data breaches) and compliance gaps
  • Ensure that appropriate cybersecurity standards are in place
  • Protect the organisation against potential incidents, including developing appropriate patterns for preventing, responding to and reporting incidents to the relevant authorities
  • Establish good practices for example in terms of staff preparation or customer information standards.
  • If using technology provided by an external provider – also assess the provider using the AI Vendor risk assessment matrix or other methodology
  • In addition, in the case of high-risk system providers, it is also important to consider:
  • Ensuring that the system meets the requirements of the AI Act
  • Implementing a quality management system
  • Properly labelling of the AI system
  • Conducting conformity assessment and preparing a statement of conformity
  • Fulfilling registration obligations and obligations towards supervisory authorities

Reporting obligations

The AI Act requires providers of high-risk artificial intelligence systems to report serious incidents.

Serious incidents are those that directly or indirectly lead, could have led or are likely to lead to the death of a person or serious harm to a person’s health, harm to property or the environment, or serious and irreversible disruption of the management and operation of critical infrastructure.

Incident prevention and response mechanisms should therefore be developed.

In addition, it is important to remember that compliance with the obligations under the AI Act will often overlap with the requirements of other regulations, such as the GDPR, DORA, DMA, DSA, or regulations on copyright protection, among others.

The AI Act also provides for the establishment of the AI Office to supervise certain systems, support the development of certain standards and enforce rules set at EU level.

In addition, each Member State should establish its own competent authority for AI matters or delegate such powers to an existing body. In Poland, this role will be fulfilled by the newly established Commission for Artificial Intelligence Supervision, according to the Ministry of Digital Affairs.

The AI Act – a summary

In summary, by imposing obligations on providers and users of AI-based solutions, the AI Act will affect not so much BigTechs as all businesses using AI.

It is predicted that within the next two years, almost 80 per cent of businesses will be using AI-based systems and will therefore fall under the AI Act to some extent.

This will require the implementation of appropriate policies, procedures and comprehensive AI Governance, as well as securing the aspect of using AI-based solutions provided by third parties.

It is therefore advisable to make the appropriate organisational and technical preparations now and to ensure compliance with the new regulations.

Any questions? Contact us

Latest Knowledge

Announcement of Income Tax Reform

On 19 August, during a press conference, the Prime Minister announced a package of tax changes planned for next year. According to the announcement, the reform is intended, on the one hand, to ease the burden on the middle class and, on the other, to shift a greater fiscal burden onto the wealthiest individuals and the largest companies. We take a look at the proposals included in the announced package and explain what they might mean for taxpayers.

Family foundations and the tax authorities: what draft bill UD447 proposes and why this is not the end of the troubles

Family foundations were intended to provide entrepreneurs with a stable framework for intergenerational wealth management. Yet not even four years have passed since the first such foundations were established, and the rules governing their taxation are set to be changed once again. This is because the scale of interest and the practical problems uncovered have overwhelmed the drafters of the legislation, as best illustrated by the figures – 927 applications for individual tax rulings and 77 opinions issued from the Head of the National Revenue Administration. This does not, however, mean that family foundations are being used on a massive scale for aggressive tax optimisation. A significant proportion of the queries concerned simply how to correctly apply the complex regulations.

NIS2 and the National Cybersecurity System Act in transport: what you need to do before October 2026

The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.

Family foundations: the government has done the maths and presented the bill

Three years. That’s how long we’ve been waiting for what the Council of Ministers had seen in the data from the outset – and has now disclosed in its review of the Family Foundation Act. The document not only diagnoses the problems, but also previews substantial changes to rules that founders and their advisers treated as settled and stable. And therein lies a problem that goes far beyond tax matters. If the rules of the game are changed while the game is being played, there can be neither planning stability nor trust in the law. It is no coincidence that one of the greatest concerns among entrepreneurs considering setting up a foundation is not the level of taxation, but the stability of the legal framework – which today is once again being called into question.

What the new swiss franc act means for banks

We now have a new Act on Special Measures for the Adjudication of Cases Concerning Loan Agreements Denominated in or Indexed to the Swiss Franc. The provisions come into force 14 days after publication. So now is a good time to look at what lies ahead and what banks should be doing today.

New draft Pay Transparency Act – what has changed since December 2025?

A second version of the draft act on strengthening the application of the right to equal pay for equal work or work of equal value between men and women has now been published. It refines procedures and deadlines and introduces a new supervisory body. We have already discussed the changes affecting the recruitment stage and the three pillars of the forthcoming pay transparency framework, noting that Poland will miss the EU transposition deadline of 7 June 2026. Now, we take a closer look at the further changes, new developments and risks that have emerged in the latest, April version of the draft.

Payment Services Regulation (PSR) – between consumer protection and due diligence

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

Contact us:

Natalia Kotłowska-Wochna

Natalia Kotłowska-Wochna

Attorney-at-Law / Partner/ New Tech, IP, Trade & Logistics Practice Group / Head of New Tech M&A

+48 606 689 185

n.kotlowska@kochanski.pl