Illustration generated by AI (GPT Image 2 model on the FOTOhub.app platform). Disclosed in line with Article 50 of the AI Act.
On July 24, 2026, President Karol Nawrocki signed the Act on Artificial Intelligence Systems, wrapping up more than a year of legislative work and, in the same stroke, creating an institution that, starting in November 2026, will decide whether Polish companies building AI-powered products can sleep soundly or should already be rethinking their compliance architecture. That institution is called the Committee for the Development and Safety of Artificial Intelligence, known by its Polish acronym KRiBSI, and while the name reads like just another bureaucratic construct destined to fade from public memory as quickly as it appeared, its actual powers are broad enough that every founder building an AI-driven product should spend the next hour understanding what KRiBSI really is, and just as importantly, what it isn't.
Let's start with the institutional basics, because in this case the devil is in the constitutional details, not just the substance of the rules themselves. KRiBSI is designed as an independent collegial body, administratively serviced by the Ministry of Digital Affairs, which in practice means the Committee won't be a standalone agency with its own budget and full operational autonomy, but a body embedded inside the ministry's structure, even if formally independent in its decision-making. That setup has drawn skepticism from technology-law specialists from the outset, who point out that having the same ministry responsible for the country's digitalization policy also run the administrative machinery of the market-surveillance authority for AI raises legitimate questions about KRiBSI's real institutional independence, especially in cases where economic-growth interests might collide with the demands of strict oversight. Deputy Digital Affairs Minister Dariusz Standerski justified the arrangement on budgetary grounds, noting that folding the Committee's administrative operations into the existing ministerial structure would save as much as PLN 23 million a year compared to standing up a fully independent agency. That's the first paradox worth sitting with: the regulator tasked with checking whether your AI product is safe and lawful will also be, functionally, part of the very same state apparatus responsible for promoting AI-driven growth in the Polish economy.
The Committee will be led by a chairperson appointed by the Sejm with the Senate's consent for a five-year term, and its membership will also include two deputy chairs plus four representatives nominated by key regulatory institutions of the state: the President of the Office of Competition and Consumer Protection, the President of the Office of Electronic Communications, the Polish Financial Supervision Authority, and the National Broadcasting Council. That composition isn't accidental, and it says a great deal about how lawmakers envision the real flashpoints of conflict around AI systems. The presence of a UOKiK representative signals that the regulator treats algorithmic consumer practices, dynamic pricing or manipulative interface design among them, as a genuine enforcement priority. The presence of a KNF representative points to particular attention being paid to AI systems used in the financial sector, credit scoring and automated risk decisions by banks chief among them. And the presence of a broadcasting-authority representative suggests deepfakes, synthetic content, and their impact on media are being treated as a serious, standalone risk area rather than an afterthought. A Social Council for Artificial Intelligence will also operate alongside the Committee in an advisory capacity, though without any decision-making powers of its own.
The timeline for the institution's actual launch is already public, and it's worth committing to memory, since it marks the real moment KRiBSI starts operating, rather than merely existing on paper. The law provides that within two months of taking effect, the Sejm, with Senate consent, will appoint the Committee's chair, and within a further three months, the chair is obligated to convene the first session. As Deputy Minister Standerski confirmed directly to Rzeczpospolita, that means the chair should be selected in October 2026, with the Committee actually becoming operational in November 2026. That's the date every founder mapping out their compliance timeline needs to circle: roughly four months from the law's signing to the point where the institution starts genuinely accepting complaints, running inspections, and issuing rulings.
What KRiBSI actually is: a national market-surveillance authority, not another advisory office
Formally, under Article 5(1) of the Act on AI Systems, the Committee is the market surveillance authority for AI systems within the meaning of Article 70(1) of the EU AI Act, and under Article 5(2) it simultaneously serves as Poland's single point of contact with EU institutions. That resolves one of the most persistent ambiguities that dogged the AI Act's rollout across the entire European Union: every member state was required to designate a national AI market-surveillance authority by August 2, 2025, and Poland spent well over a year falling short of that deadline until the Act on AI Systems was finally passed. In other words, KRiBSI isn't some optional add-on to the legal system; it's a component the EU regulation itself demanded, and its absence for more than a year represented a real, formal gap in Poland's AI oversight architecture.
The Committee's duties, laid out in Article 6 of the Act, cover exercising the powers of a market-surveillance authority and monitoring compliance with the AI Act on Polish territory. In practice, that translates into four main areas of activity worth unpacking individually, since each one carries different operational consequences for a company building an AI product.
The first area is market oversight and compliance auditing. KRiBSI will be able to open inspections at companies and institutions deploying AI systems, examine those systems' compliance with the EU AI Act's requirements, issue administrative decisions and rulings, and, in extreme cases, impose administrative sanctions. Crucially, during the parliamentary process, lawmakers dropped the power originally proposed for KRiBSI to order a system withdrawn from the market or to compel the removal of specific components, a meaningful softening compared to earlier drafts of the bill and to the version described as recently as April 2026, when government communications still pointed to market withdrawal as one of the Committee's core enforcement tools. That's a substantive, practical difference from the industry's earlier fears: the final version of the law doesn't hand KRiBSI a nuclear option in the form of forced product removal, though the Committee retains full authority to levy administrative fines and open formal proceedings.
The second area covers investigative powers, and this is the area that demands the most precise understanding from tech companies, since it concerns a real procedure an organization could actually face. According to an analysis based on the text of the law passed on July 3, 2026, and published in the Journal of Laws under item 1003, KRiBSI inspections are conducted remotely, with the Committee giving the inspected entity seven days' notice, after which the company has anywhere from fourteen to thirty days to respond, depending on the stage of the procedure. The scope of what the Committee can demand from an inspected entity is broad, and includes access to IT systems, electronic correspondence, and, critically for companies relying on third-party cloud infrastructure, access to data stored in another provider's cloud, to the extent the inspected entity itself has access to that data, under Article 52(1)(1) of the Act. That comes paired with an active duty to cooperate on the part of the inspected entity, under Article 52(2), meaning a company can't just passively wait out the procedure; it has to proactively provide information and access on the Committee's request. A physical, in-person visit by inspectors is the exception to the default remote-inspection rule, reserved for cases involving a suspected genuine threat to life, health, or citizens' fundamental rights.
The third area is receiving and handling complaints from citizens, businesses, and institutions concerning how AI systems operate, including erroneous automated decisions, cases of discrimination, violations of fundamental rights, or the use of banned practices such as social scoring. The Committee will maintain a registry of these complaints and take action when it identifies irregularities, and government materials specifically flag bank decisions perceived by customers as unfair or discriminatory as an area of particular interest, meaning the financial sector, which relies heavily on AI for credit scoring and automated risk assessment, should expect closer-than-average scrutiny from the regulator.
The fourth area, and probably the most consequential one from the perspective of startups and tech companies trying to build genuinely innovative AI solutions, covers ecosystem-support mechanisms: creating and managing regulatory sandboxes, issuing individual opinions, and running educational and awareness initiatives. A regulatory sandbox is the mechanism through which selected entities capable of contributing to AI development can obtain KRiBSI's approval to test new technologies in a controlled environment, with some flexibility around certain provisions, ahead of full commercial rollout. An individual opinion, meanwhile, is the instrument that lets a company request a binding interpretation from the Committee on whether a specific, planned or already-implemented solution complies with the AI Act, intended to give companies legal certainty before they sink resources into deploying a given system. For any founder wondering whether it's worth using, the answer is simple: this is the only formal mechanism that lets you secure regulatory certainty before investing months of engineering work into a product that could later turn out to be non-compliant.
What KRiBSI means in practice for a company building an AI product
The first, most immediately practical consequence of KRiBSI's creation concerns the very structure of legal accountability. Until now, Polish companies building AI systems operated in a kind of institutional limbo: the AI Act applied directly as EU law, but no national authority existed to approach for a binding interpretation, and none was actually running compliance inspections on Polish soil. That situation is ending. Starting in November 2026, there will be a specific address for complaints, a specific authority running inspections, and a specific institution a company will need to demonstrate compliance to if proceedings are ever opened.
The second consequence concerns the operational calendar for any company working with high-risk AI systems as defined by the EU regulation, a category that includes systems used in education, critical infrastructure, hiring processes, and migration management, among others. The Committee will be able to grant approvals for such systems, meaning companies operating in these sectors now face an additional, formal administrative step on their path to market that didn't functionally exist before, even though it was theoretically already required under the AI Act itself.
The third consequence, one that gets far too little attention in public debate around the law, concerns the real scope of KRiBSI's inspection demands on cloud infrastructure. The fact that the Committee can demand access to data stored in a third party's cloud, to the extent the inspected company itself has access to that data, means access-management policy within a company's cloud architecture becomes directly relevant to compliance, not merely to information security. Companies running multi-tenant setups, where access to customer data is contractually restricted, should already be examining whether and to what extent that access could fall within the scope of a regulator's inspection request.
The fourth consequence concerns the sheer speed the inspection procedure demands. Response windows of fourteen, twenty-one, and thirty days across successive stages aren't generous, particularly for smaller companies without a dedicated compliance function or legal department. That means companies building AI products should already have, at minimum, baseline technical documentation for their systems in place: a description of implemented safeguards, a risk register, and a record of design decisions, so that if an inspection notice arrives, that documentation doesn't have to be assembled from scratch under a very tight deadline.
Why this matters beyond the letter of the law
KRiBSI is, in a sense, a live test of whether Poland can build a regulatory institution that protects citizens without smothering technological innovation before it's had a chance to generate any economic value at all. The Committee's composition, drawing in representatives from competition authorities, financial supervision, media, and telecommunications regulators, suggests real ambition to cover a broad spectrum of AI applications, from bank credit scoring to synthetic media content to consumer practices in e-commerce. At the same time, housing the Committee's administrative operations inside the Ministry of Digital Affairs, justified on budgetary grounds, raises genuine questions about how independently this body will be able to act in situations where the country's economic-growth interests and the demands of strict citizen protection pull in opposite directions.
For Poland's startup ecosystem, what will matter most is how the Committee actually uses its two most business-friendly instruments, regulatory sandboxes and individual opinions, in its first months of operation. If KRiBSI treats these mechanisms as genuine tools for supporting innovation rather than bureaucratic formalities burdened by months of waiting, they could become a real competitive differentiator for the Polish AI market relative to other EU countries still dragging their feet on standing up their own market-surveillance authorities. If, instead, these mechanisms prove difficult to access, overloaded, or excessively formalized in practice, KRiBSI could quickly earn a reputation as yet another institution that talks about supporting innovation while, in practice, mostly adding a documentation burden onto companies that already have plenty of challenges just trying to build their product.
November 2026, when the Committee actually becomes operational, is the moment these questions stop being theoretical. Until then, every company building an AI product in Poland has a clearly defined, limited window to get its documentation in order, rethink its compliance architecture, and, if it operates in the high-risk systems space, seriously consider using a regulatory sandbox before KRiBSI starts running inspections in earnest.
Sources (14)
- Chancellery of the Prime Minister, "Draft Act on Artificial Intelligence Systems", www.gov.pl
- Ministry of Digital Affairs, "Act on AI Systems - Safe AI Development in Poland", www.gov.pl
- Rzeczpospolita, "Sejm passes AI law. AI Committee and regulatory sandboxes", www.rp.pl
- Traple Konarski Podrecki & Partners, "The Committee for the Development and Safety of AI under the Digital Affairs Ministry", www.traple.pl
- TVN24, "Government prepares AI oversight in Poland. Committee approves draft", tvn24.pl
- Gazeta Prawna, "The AI Committee will be an independent body, administratively serviced within the Ministry", www.gazetaprawna.pl
- Rzeczpospolita, "Poland's AI committee to begin work in November", www.rp.pl
- ITwiz, "Sejm passes AI law. Poland implements the AI Act and creates a new oversight body", itwiz.pl
- AI Bez Obaw, "AI Systems Act 2026: KRiBSI and inspections", aibezobaw.pl
- Forsal.pl, "Poland establishes a new AI oversight body", forsal.pl
- Legalis, "Who will oversee AI in Poland?", legalis.pl
- Maćura Law Firm, "AI Systems Act signed. KRiBSI to begin market oversight", www.kancelariamacura.pl
- Mam Startup, "Poland will have a new algorithm sheriff", mamstartup.pl
- Prawo.pl, "President signs the Act on AI Systems", www.prawo.pl
