Analysis of the draft law on artificial intelligence systems adopted by the Council of Ministers
31 March 2026 · Reading time: approx. 12 minutes
31 March 2026. The Council of Ministers adopts the draft law on artificial intelligence systems. Prime Minister Donald Tusk says it plainly: "Poland is one of the first countries in Europe to have prepared AI regulation." And he is right. Of the 27 EU member states, only 9 had designated their national AI supervisory authorities by early 2026. Two-thirds of Europe still lacks a ready model.
You have not read the draft law. I understand -- it runs over 80 pages. I have. I am breaking it down so you know what is actually changing.
First, the context, so you understand why this matters
The AI Act, as an EU regulation, has been directly applicable in all member states since 1 August 2024. In theory, it does not require "implementation" in the sense of transposition into national law, because EU regulations apply automatically. But here a critical problem emerges.
The regulation itself does not work without enforcement infrastructure. For the AI Act to have teeth, each member state must separately: designate a national AI market surveillance authority, establish control procedures, handle citizen complaints, and launch regulatory sandboxes for testing innovation. Without this, the AI Act is like law without police. The rules exist, but nobody enforces them.
The deadline for appointing a supervisory authority expired on 2 August 2025. Poland missed the deadline for the institution itself, but the draft law is now ready and is heading to the Sejm. This is still one of the faster moves across the entire EU.
KRiBSI: a new institution built from scratch
Poland is creating something that almost no one else in Europe has: the Commission for the Development and Safety of Artificial Intelligence, abbreviated KRiBSI.
This is not a rebrand of an existing office. It is not UOKiK "with a new name" or UODO "with expanded competences." It is an entirely new institution built from scratch -- an approach that is exceptional across the entire European Union. For comparison: France split AI supervision competences among 14 different bodies. Germany went with a distributed model based on existing sectoral regulators. Poland opted for a single decision-making centre and full centralisation.
Why does this matter? Because in a distributed model, the question always arises of who is actually responsible for a given decision. When a bank's AI system discriminates against borrowers, does the financial regulator, the data regulator, or the AI regulator handle it? In Poland, the answer will be straightforward: KRiBSI.
The Chair of the Commission is appointed by the Prime Minister through an open and competitive recruitment process. Its members include deputy chairs, the President of UOKiK, the President of UKE, a representative of KNF, and a representative of KRRiT. The President of UODO is separately responsible for AI systems used by security services. This is a deliberate design choice to avoid mixing oversight of commercial AI with oversight of AI in state hands.
What about the budget? The original proposal from the Ministry of Digital Affairs envisaged a fully independent agency with its own legal personality and a budget of PLN 448 million over 10 years. The Ministry of Finance said no. Ultimately, KRiBSI receives PLN 278 million over 10 years, operates under the Ministry of Digital Affairs, and is expected to reach 70 specialists by 2027. This is a compromise that raises questions about the Commission's actual independence, but was necessary to push the project through.
What KRiBSI actually does
The Commission's scope of competence is broad. KRiBSI conducts market surveillance -- checking whether specific AI systems meet AI Act requirements. It handles citizen complaints when a bank's AI system, an insurance platform, or a recruitment system has malfunctioned to their detriment. It issues authorisations for placing high-risk systems on the market, receives reports of serious incidents, and supervises regulatory sandboxes.
An important point worth remembering: KRiBSI can initiate proceedings ex officio. It does not have to wait for a complaint. If the Commission receives a signal of a possible violation from the media, industry reports, or an anonymous tip, it can launch proceedings on its own. This is the model of an active regulator, not a passive body waiting for paperwork from a lawyer.
KRiBSI also issues opinions on draft legislation and government documents concerning AI, and cooperates with the EU AI Office and corresponding authorities in other member states. In practice, this means that Polish regulations will be calibrated with what the rest of Europe is doing, rather than developed in a vacuum.
Regulatory sandbox: how to test AI without risking a penalty
One of the most practical elements of the entire law. Deputy Minister Standerski called it "the first such solution in the EU that enables testing before full market entry."
The mechanism is simple. Before you release your AI system onto the market, you can test it in a controlled regulatory environment. For the duration of the test, you face no penalties for violating national or EU rules, even if your system is not yet fully compliant. This is a fundamental shift in approach: instead of "do everything perfectly first, then enter the market," Poland is saying "enter the sandbox, test, adjust, and then move forward."
For SMEs, the sandbox is free of charge. Large companies pay a nominal administrative fee. The infrastructure is centralised and properly secured, and the Polish Centre for Accreditation can issue certification upon completion of the process. The entire Chapter 8 of the law is dedicated to supporting innovation -- a signal that the legislator genuinely wanted this element to work, rather than be a dead-letter provision.
Individual opinions: a binding answer instead of guesswork
This is something the AI Act does not explicitly require. Poland added it on its own initiative, and it is one of the most practical elements of the entire regulation.
The mechanism works as follows: your company officially asks KRiBSI "does our AI system qualify as high-risk?" The Commission analyses the case, responds, and that response is binding. Binding not only for KRiBSI itself, but for all state bodies and organisational units relevant to the given enterprise.
In the context of the AI Act, this is genuinely significant. Classifying a system as "high-risk" triggers a series of obligations: full technical documentation, a risk management system, training data quality requirements, human oversight mechanisms, and mandatory registration in the EU database. A mistaken self-classification can result in a multi-million-euro fine. The ability to ask the regulator and receive an official answer is real protection against such a scenario.
In most EU countries, companies must resort to external lawyers specialising in the AI Act or simply guess. This is a concrete advantage of the Polish approach.
Sanctions: how much you can lose and for what
KRiBSI imposes penalties by administrative decision; the funds go to the state budget. The scale is non-trivial.
For violations of the prohibited AI practices under Article 5 of the AI Act -- social scoring, real-time biometrics in public spaces, subliminal manipulation, or systems for assessing emotional vulnerability -- the penalty is up to EUR 35 million or 7% of global annual turnover, whichever is higher. For other AI Act violations, which will apply from 2 August 2026, the maximum penalty is EUR 15 million or 3% of turnover. Euro amounts are converted at the NBP exchange rate as of 28 January each year.
Beyond financial penalties, KRiBSI has an entire spectrum of tools at its disposal. It can issue a warning with a remedial order, including an order to block access to the system. For lesser irregularities, it may issue post-inspection recommendations instead of a penalty. In cases of direct and serious risk to health, safety, or fundamental rights, it can order the withdrawal of a system from the market through an expedited procedure with immediate enforceability. The latter is a particularly powerful instrument, because the decision is enforceable immediately, before the company has a chance to appeal.
When imposing a penalty, the Commission must take into account the nature and gravity of the infringement, its duration, the degree of fault, and prior violations. A reduction of 10-50% is possible if certain conditions are met.
Procedures: what the proceedings look like
Penalty proceedings are single-instance. An appeal against a KRiBSI decision lies with the Regional Court in Warsaw, specifically the Court of Competition and Consumer Protection (SOKiK). The choice of SOKiK is not accidental -- this court already has established experience in cases involving market supervision and digital technologies.
There is also the option of a settlement with KRiBSI to negotiate the penalty amount. If a company fails to comply with the terms of the settlement, the Commission resumes the original proceedings. This mechanism is well known in competition law and works well in practice: the regulator wants the violation remedied quickly, the company wants the penalty reduced. The settlement serves both sides.
AI in security services: a separate oversight track
This is a sensitive topic that is worth understanding precisely. High-risk AI systems used for law enforcement, border control, and the administration of justice do not fall under KRiBSI. Oversight of these systems is exercised by the President of UODO, who is simultaneously a member of the Commission.
This separation is deliberate. The rationale is simple: AI systems of the Police, Border Guard, and State Protection Service operate on personal data in a particularly sensitive manner, often in the context of fundamental rights, and it is logical for oversight to be exercised by an authority with experience in data protection rather than a newly created institution. The Ministry of Digital Affairs meanwhile firmly maintains that the provisions will fully cover the activities of these services and that there will be no blanket exemption for them.
Social Council: who watches the regulator
An advisory-consultative body is being established alongside KRiBSI: the Social Council for Artificial Intelligence. It consists of 9 to 15 members selected from nominations by the Commissioner for Human Rights, chambers of commerce, trade unions, universities, and NGOs.
Candidates must have expertise in at least one of the following areas: AI and machine learning, IT and cybersecurity, law of new technologies, or human rights. The term lasts 2 years -- deliberately short so that the composition keeps pace with the speed of technological change. The positions are unpaid, and the Council's opinions are publicly available online.
In theory, this is a tool for keeping the regulator in touch with reality. In practice, the effectiveness of such bodies depends on how seriously the regulator itself treats their voice. We shall see.
Citizens' rights: what ordinary people stand to gain
If an AI system rejects your credit application or removes you from a platform based on an automated decision, you can file a complaint with KRiBSI. The Commission will look under the hood of the system and check whether it operated in compliance with the law. The law also restricts the possibility of making decisions that produce legal effects solely in an automated manner, without human involvement.
All KRiBSI decisions will be publicly available, and the Commission publishes an annual report by 31 March featuring examples of best practices in AI deployment by enterprises. This is a soft-influence mechanism that in practice can shape industry standards more effectively than penalties.
What this means for you as a builder
If you are building an AI product in Poland and have 2 August 2026 in your calendar, here is what you need to do now.
Start with an inventory. Every AI system in your company must be classified according to the AI Act risk categories: prohibited (outright ban), high-risk (full compliance regime), limited risk (transparency requirements), or minimal risk (no special obligations). This is not a task for an outside lawyer -- it is a task for the founding team, because only you know how the system actually works.
If you are building something in a grey area and are unsure of the classification, you have two options. First: the regulatory sandbox, free for SMEs, where you test without risk of penalty. Second: an individual opinion from KRiBSI, a binding answer from the regulator before you go to market. Use both. This is not the time for guesswork when the potential penalty reaches EUR 35 million.
For high-risk systems, you face: technical documentation, a risk management system, data governance, human oversight mechanisms, and registration in the EU database. This takes months of work. You have fewer than four.
Where Poland stands relative to the rest of Europe
Only 9 of 27 EU member states had designated national AI supervisory authorities by early 2026. Another 10 are in the process; more than two-thirds of countries do not yet have a ready model. Poland is the only country in the entire EU building a new, centralised institution from scratch as the sole AI oversight body.
The Oxford Blavatnik School of Government, in a March 2026 analysis, identified the KRiBSI model as an interesting case of a centralised approach to AI Act enforcement in the EU, noting the uniqueness of the decision to build a new institution rather than relying on existing regulators. Poland also established formal cooperation with Lithuania on AI in January 2026, pointing to regional ambitions in this area.
The draft now heads to the Sejm. Parliamentary amendments are possible. The direction, however, is set. The law must be ready before 2 August 2026, when the full AI Act provisions for high-risk systems come into force.
You have fewer than four months.
Note from the author: FOTOhub is ready
As CEO of FOTOhub.app, I welcome this direction. The AI regulations Poland is now adopting are something I have been waiting for and preparing for.
FOTOhub is a Polish creative platform for generating images, video, voice, and audio. We operate in the limited/minimal risk category under the AI Act, which means no obligation for formal certification or registration in EU databases. We do not make decisions that affect users' lives. We generate creative content.
But we have done more than the minimum. We are developing our own AI models within FOTOcore, our internal orchestrator and AI engine powering the entire platform. We train on our own datasets and on public datasets from users who have given their consent. By default, this is turned off -- opt-in, not opt-out. Every piece of content generated by FOTOhub passes through FOTOcore's control pipeline before reaching the user. AI-generated content is labelled in accordance with the requirements of Article 50 of the AI Act.
Once KRiBSI is operational and individual opinions can be submitted, we will file ours formally. To have it in black and white.
Polish AI regulation is not a threat to FOTOhub. It is an opportunity to build in a country that understands AI needs rules but cannot stifle innovation. And that is exactly what Polish AI startups need.
Article based on the draft law on artificial intelligence systems (UC71) adopted by the Council of Ministers on 31 March 2026, prepared by the Ministry of Digital Affairs under the leadership of Minister Krzysztof Gawkowski and Secretary of State Dariusz Standerski.
Sources (14 items)
- "Rzad wreszcie przyjal projekt ustawy wdrazajacej AI Act", Rzeczpospolita, 31.03.2026
- "Rzad przyjal ustawe o systemach sztucznej inteligencji", CyberDefence24, 31.03.2026
- "Building a Centralised National AI Authority", Interface-eu.org, 2026
- "The AI Act's enforcement gap: what Poland's new regulator reveals about Europe's challenge", Oxford Blavatnik School of Government, March 2026
- "Rewolucja w regulacji: wchodzi w zycie Akt o AI", Portal sztucznej inteligencji Gov.pl, 01.08.2024
- "AI Act 2026: Nowe obowiazki dla wysokiego ryzyka AI", Dudkowiak.pl, 2026
- "Projekt ustawy o systemach sztucznej inteligencji", Gov.pl, 31.03.2026
- "Rzad dogadal sie ws. AI. Nowe prawo na stole", Do Rzeczy, 2026
- "Ministerstwo Cyfryzacji pokazalo nowa wersje ustawy o sztucznej inteligencji", Rzeczpospolita, 2026
- "Menedzerowie jednak nie zaplaca kar za AI. Jest nowy projekt ustawy", Gazeta Prawna, 2026
- "Beda kary za zle uzywanie sztucznej inteligencji. Rzad zdecydowal", Business Insider Polska, 31.03.2026
- "Projekt ustawy o systemach AI nie zwalnia Policji z nowych obowiazkow", Fundacja Panoptykon, 2026
- "Projekt ustawy o systemach sztucznej inteligencji w Polsce", GlobalCodeMaster, 2026
- "Polska i Litwa zaciesniaja wspolprace w zakresie sztucznej inteligencji", Gov.pl/Cyfryzacja, January 2026
