The AI Act in practice: challenges and opportunities for the development of artificial intelligence in the EU

26 July 2024 | Knowledge, News, The Right Focus

On 12 July 2024, just over three years after work began, the AI Act, i.e. the Regulation laying down harmonised rules on artificial intelligence, was published in the Official Journal of the European Union. The Regulation will enter into force 20 days after this date and will be fully applicable from 2 August 2026. This means that providers and users of artificial intelligence will soon face a number of new obligations.

We look at how to prepare for this effectively.

How to prepare your business for the AI Act

Before embarking on large-scale implementations, every company should consider what systems it uses, if any, and what its role is in relation to them.

This is because the extent of your responsibilities will depend on the type of system and on whether you are the system’s provider, just a user, or perhaps you use it with appropriate modifications.

EN Broszura AI 3

Classification of systems

The AI Act classifies AI systems according to their level of risk:

  • Solutions deemed to pose unacceptable risk, such as those using subliminal techniques or social scoring based on behaviour or personal characteristics, are prohibited.
  • High-risk systems, such as those using biometric data or used for employee recruitment, will be allowed after meeting additional requirements, including, without limitation:
    • Monitoring system performance
    • Ensuring that input data is relevant and representative
    • Compliance with registration obligations
  • Limited-risk systems, such as chatbots or technologies that manipulate audiovisual content – it will be necessary to inform users that they are dealing with artificial intelligence systems
  • Minimal-risk systems, such as spam filters, will be free to use, although, as with all AI systems, providers and deployers should take measures to ensure that their staff and others responsible for the systems have a sufficient level of AI literacy

In addition, the AI Act also singles out general-purpose AI models, such as tools like ChatGPT.

Defining your role

In order to adequately prepare for the AI Act, the first step is to map and identify the processes. This will enable you to determine whether you are dealing with an AI system and to verify its technical standards.

You will then need to classify the system according to the risk categories mentioned above and define your role, i.e. whether you are a supplier or a deployer, whether you are modifying the system, and to identify your specific responsibilities.

The next step will be to develop appropriate procedures and documentation, including:

  • Policy on the use of AI systems
  • Technical documentation on the technologies used
  • Risk management mechanisms
  • Procedures for dealing with customers or recipients of the system

Preparation for action

As part of your operational preparation to meet your obligations under the AI Act, it is advisable to:

  • Carry out an AIRA (AI Risk Assessment) process and designate a structure responsible for managing AI, monitoring risks and ensuring compliance, as well as implementing appropriate internal policies
  • Assess the AI systems in use and analyse the associated risks (e.g. discrimination, data breaches) and compliance gaps
  • Ensure that appropriate cybersecurity standards are in place
  • Protect the organisation against potential incidents, including developing appropriate patterns for preventing, responding to and reporting incidents to the relevant authorities
  • Establish good practices for example in terms of staff preparation or customer information standards.
  • If using technology provided by an external provider – also assess the provider using the AI Vendor risk assessment matrix or other methodology
  • In addition, in the case of high-risk system providers, it is also important to consider:
  • Ensuring that the system meets the requirements of the AI Act
  • Implementing a quality management system
  • Properly labelling of the AI system
  • Conducting conformity assessment and preparing a statement of conformity
  • Fulfilling registration obligations and obligations towards supervisory authorities

Reporting obligations

The AI Act requires providers of high-risk artificial intelligence systems to report serious incidents.

Serious incidents are those that directly or indirectly lead, could have led or are likely to lead to the death of a person or serious harm to a person’s health, harm to property or the environment, or serious and irreversible disruption of the management and operation of critical infrastructure.

Incident prevention and response mechanisms should therefore be developed.

In addition, it is important to remember that compliance with the obligations under the AI Act will often overlap with the requirements of other regulations, such as the GDPR, DORA, DMA, DSA, or regulations on copyright protection, among others.

The AI Act also provides for the establishment of the AI Office to supervise certain systems, support the development of certain standards and enforce rules set at EU level.

In addition, each Member State should establish its own competent authority for AI matters or delegate such powers to an existing body. In Poland, this role will be fulfilled by the newly established Commission for Artificial Intelligence Supervision, according to the Ministry of Digital Affairs.

The AI Act – a summary

In summary, by imposing obligations on providers and users of AI-based solutions, the AI Act will affect not so much BigTechs as all businesses using AI.

It is predicted that within the next two years, almost 80 per cent of businesses will be using AI-based systems and will therefore fall under the AI Act to some extent.

This will require the implementation of appropriate policies, procedures and comprehensive AI Governance, as well as securing the aspect of using AI-based solutions provided by third parties.

It is therefore advisable to make the appropriate organisational and technical preparations now and to ensure compliance with the new regulations.

Any questions? Contact us

Latest Knowledge

Banking in 2026: technology, regulation and the new market landscape

The year 2026 will see the banking sector undergo its most dynamic transformation in a decade. The trends identified in Accenture’s Top Banking Trends FY26 report suggest that the sector is entering a phase in which technology and regulation will be inseparable, driving all aspects of change. However, it is regulation that determines the boundaries, pace and manner of implementation for new solutions. We take a look at what else the experts are focusing on.

The new National Cybersecurity System

The amendment to the Act on the National Cybersecurity System (UKSC) is one of the most significant regulatory reforms in recent years. Its main objective is to align Polish law with Directive (EU) 2022/2555 of the European Parliament and of the Council. The directive, also known as NIS2, substantially raises digital security requirements across the Union. The Polish Act on the National Cybersecurity System has undergone a thorough overhaul, covering more organisations (with estimates suggesting nearly 40,000 entities), introducing more demanding obligations, statutory personal liability for management board members, and even more stringent rules for imposing financial penalties. In the case of the most serious violations, these penalties can reach 100 million PLN.

‘Made in Europe’ is no longer just a slogan. It is becoming law

Until recently, ‘Made in Europe’ was just a label. While it was useful for marketing purposes, it lacked any hard, normative content. This may soon change. On 4 March, the European Commission published a proposal for the Industrial Accelerator Act, stipulating that, from 2027 onwards, the Union origin of components will be a prerequisite for participating in renewable energy auctions, accessing public funding, and for being eligible to participate in public procurement procedures. The slogan ‘Buy European’ could become a concrete instrument for supporting local production and controlling foreign investment.

Non-obvious cases of transferring an establishment to a new employer

The transfer of all or part of an establishment (zakład pracy) is a special concept in labour law relating to changes in ownership. Put simply, it is the automatic transfer of all the rights and obligations of the employer from one entity to another, without the need for any additional actions or consents from the parties involved. However, this must be preceded by the fulfilment of a range of informing obligations by both the new and former employers. Let’s take a look at what the process should involve.

Protecting yourself against tax risks in the deposit-return system

The deposit-return system has been in place since October 2025, raising significant tax concerns from the outset. Although the regulations came into force, it was unclear for a long time how to apply them in practice. Some of the regulations needed clarification, some solutions were missing and the published explanations did not cover all the key issues. Consequently, the market began to develop its own operating standards.

Banking sector overview | Banking today and tomorrow | March 2026

On 12 February 2026, the Court of Justice of the European Union (CJEU) issued a judgment concerning the use of the WIBOR index in loan agreements. The CJEU judges confirmed that, in consumer cases, courts cannot examine the correctness of the WIBOR calculation. The banks had correctly informed their clients about the reference rate in accordance with national and EU law.

The issue of the National Labour Inspectorate reform has resurfaced

A new draft law proposing changes to the way the National Labour Inspectorate operates has been submitted to the Sejm. During its first reading on 25 February, the draft was not rejected and was therefore referred to the Social Policy and Family Committee for further consideration. Despite the concerns and controversies raised so far, including by businesses, the legislature continues to pursue the thorough modernisation of Poland’s employment model, which involves increased supervision of the labour market and curbing the abuse of civil law contracts. In this article, we will take a look at the proposals included in the new draft and explain what they mean for businesses.

Contact us:

Natalia Kotłowska-Wochna

Natalia Kotłowska-Wochna

Attorney-at-Law / Partner/ New Tech, IP, Trade & Logistics Practice Group / Head of New Tech M&A

+48 606 689 185

n.kotlowska@kochanski.pl