Services • AI Act

AI Act: establishing your role, obligations and scope of preparation

I help establish the role an organisation holds under the AI Act. I separate the obligations that already apply from those that require preparation. The starting point is the facts: the places where artificial intelligence is already at work.

Over 20 years of practice • Legal and technological perspective • Work in Polish and English

What already applies

since 2 February 2025

Prohibited practices and AI literacy

Applies to every organisation that uses AI.

since 2 August 2026

Transparency obligations towards individuals

Informing people about contact with a system and about artificially generated content.

The postponement covered only the requirements for high-risk systems. The remaining provisions apply unchanged.

Timeline

The postponement did not cover the whole regulation

In July 2026 the EU changed the timeline for applying the AI Act. The postponement concerns the requirements and obligations relating to high-risk systems. The remaining provisions apply unchanged.

An organisation that uses off-the-shelf tools therefore faces the opposite of the common message. Some obligations already apply. The deferral bought time to prepare for the rest.

2 February 2025

Prohibited practices and AI literacy

in force

2 August 2025

General-purpose models, supervision and penalties

in force

2 August 2026

Transparency obligations towards individuals

Informing people about interaction with an AI system and labelling artificially generated content.

in force now

2 December 2026

Two new prohibitions and labelling of content in legacy systems

This also covers systems made available earlier.

action required

2 December 2027

Requirements for high-risk systems under Annex III

preparation

2 August 2028

Requirements for high-risk systems under Annex I

preparation

In Poland, supervision over the application of the regulation rests with the Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (the Commission for the Development and Security of Artificial Intelligence), established under the Polish Act on Artificial Intelligence Systems.

When it comes up

When support is needed

No inventory of use cases

AI tools entered the organisation through different routes and nobody keeps a record of them.

The tool was built in-house

A team built an assistant or a classifier on a general-purpose model.

AI supports decisions about people

Systems are used in recruitment, employee assessment or client qualification.

The question came from outside

A client, insurer or auditor asks about AI Act compliance.

Content is generated automatically

The organisation publishes material generated or processed by AI.

A deployment is planned

The project is due to start before the dates on which the high-risk requirements apply.

Starting point

What the organisation is under the AI Act

This question determines the scope of obligations. The regulation does not ask whether an organisation “works with AI”. It asks about the role it holds towards a specific system.

Most common role

Deployer

Uses an AI system in its own activity. Its responsibilities include using the system in accordance with the instructions, assigning human oversight to people with the appropriate competence and authority, and informing individuals in the cases set out in the regulation.

Broader role

Provider

Places a system on the market or puts it into service under its own name. Its obligations are considerably broader and include conformity assessment.

The line between these roles is thinner than it looks at first sight

The regulation treats a deployer as a provider in three situations:

1

Own name or trade mark

The organisation makes the system available under its own brand.

2

Substantial modification

A high-risk system already placed on the market is substantially modified.

3

Change of intended purpose

A system that was not high-risk is used in a way that makes it one.

The third case applies to many organisations today. A team that built an internal tool on a general-purpose model and pointed it at supporting decisions about candidates may have changed the organisation’s role without any board decision. Establishing the role is the first step. The scope of everything that follows depends on it.

Scope of support

What the work covers

AI use-case register

We establish where AI systems are already at work, who introduced them and on what basis. The register also covers tools built in-house and AI features in software the organisation bought for another purpose.

Role and risk qualification

For each use case we establish the organisation’s role and the category the system falls into. The regulation distinguishes prohibited practices and high-risk systems.

Transparency towards individuals

We check where the organisation must inform people about interaction with a system or about artificially generated content.

Human oversight

Oversight is a role, not a statement in a policy. We establish who exercises it, what authority they have and whether they are able to stop the system.

Contracts and the supply chain

We review the terms of cooperation with tool vendors for the information, documentation and support the organisation needs to meet its own obligations.

Documentation and evidence

We put in order the records showing how the organisation made its decisions on deployment and oversight. The same material answers questions from clients and auditors.

Ways of working

Ways we can work together

We match the scope to where the organisation is today. Each option can be closed or extended into the next one.

First step

Review of AI use cases and qualification

For an organisation that does not yet have a picture of the situation.

Result: a list of use cases, the organisation’s role towards each of them and a report with priorities for the board.

Putting order in

Establishing AI governance

For an organisation after qualification. It covers the rules for using AI, keeping the register and the model of human oversight, along with the requirements towards vendors.

Result: a plan of preparations for the dates on which the high-risk requirements apply.

Ongoing support

Standing advisory support

For an organisation that deploys AI continuously.

Result: assessment of new deployments before launch, updates to the register and responses to changes in the law and questions from outside.

How it runs

How we work together

STAGE 1

Diagnostic call

We establish what the organisation already uses and where the need came from.

STAGE 2

Review of use cases

Conversations with process owners and a review of tools and contracts.

STAGE 3

Qualification and gaps

The role, the risk category and the difference between the current and the required state.

STAGE 4

Plan and implementation

Priorities, task owners and deadlines matched to the timeline of the regulation.

STAGE 5

Maintenance

Review of new deployments and updates to the register and documentation.

What the board gains

A picture of the situation. It is clear where AI is running and who is accountable for it.

A settled role. The organisation knows whether it acts as a deployer or as a provider.

Separated deadlines. It is visible what needs action now and what should be planned.

A basis for deployment decisions. New AI projects are assessed before launch.

Material for questions from outside. The answer for a client or an auditor rests on documents.

LabLogic

Runs the review and qualification, formulates recommendations and coordinates the work.

The organisation

Makes the decisions, provides information about its processes and appoints task owners.

Tool vendors

Provide technical documentation, instructions and the information needed for the assessment.

Context

Where this meets other obligations

Data protection

Many AI use cases process personal data, so GDPR obligations apply in parallel. Information received from the system provider is used in the data protection impact assessment, and parts of that assessment can be incorporated into the fundamental rights impact assessment.

external DPO support →

Cybersecurity

Organisations covered by NIS2 and the Polish Act on the National Cybersecurity System (KSC) also assess AI tools as part of the supply chain.

NIS2 and KSC readiness →

Staff competence

The regulation requires measures supporting AI literacy among the people who use these systems. The scope and format are matched to roles.

training matched to roles →

Who runs the work

Knowledge that comes from practice

Over twenty years of work in technology, data protection and cybersecurity. Combining legal, organisational and technological perspectives makes it possible to assess an AI tool from the side of the provision and from the side of the deployment at the same time. Work is carried out in Polish and English.

Direct contact with the expert

Michał Rutkowski

LabLogic — support for and performance of the DPO role, NIS2 and KSC readiness, incident response, audits and training.

M.Rutkowski@LabLogic.pl

Frequently asked questions

Does the AI Act apply to us if we only use off-the-shelf tools?

Yes. The regulation also places obligations on organisations that merely deploy AI systems. Their scope depends on what the system is used for.

We heard the deadlines were postponed. Is there anything to do now?

The postponement covered the requirements for high-risk systems. Prohibited practices, the AI literacy obligation and the transparency obligations apply regardless of it.

When does an organisation using AI become its provider?

When it makes the system available under its own name, substantially modifies it, or uses it in a way that makes it a high-risk system. The last case happens with tools built in-house.

Does an AI tool in recruitment always mean a high-risk system?

Not always. What decides is the intended purpose of the system and the way it is used, not its mere presence in the recruitment process. That is why qualification is carried out for a specific use case.

Is a data protection impact assessment enough instead of a fundamental rights impact assessment?

It does not replace it, but it connects with it. Where the obligation has already been met in the data protection impact assessment, the relevant parts of it can be incorporated into the fundamental rights impact assessment.

Who supervises the application of the AI Act in Poland?

The Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji (the Commission for the Development and Security of Artificial Intelligence), established under the Act on Artificial Intelligence Systems. It cooperates with the authorities competent in other areas, including the data protection authority.

Book a diagnostic call

Let us start by establishing where artificial intelligence works in your organisation today and what role your organisation holds towards it. The call makes it possible to name the first sensible step before you decide on the scope of the work.

Prefer to write straight away? M.Rutkowski@LabLogic.pl

This material is general and informational. It is not individual legal advice or a recommendation for any specific organisation. The scope of obligations should be assessed in the light of that organisation’s circumstances.

Legal status: August 2026

Scroll to Top