SERVICES · AI ACT
AI Act: establishing your role, obligations and scope of preparation
I help establish the role an organization holds under the AI Act. I separate the obligations that already apply from those that require preparation. The starting point is the actual state of affairs: the places where artificial intelligence is already at work.
Over 20 years of practice · Legal and technological perspective · Work in Polish and English
WHAT ALREADY APPLIES AND WHAT COMES NEXT
from 2 February 2025
Prohibited practices and AI literacy
Applies to every organization that uses AI.
from 2 August 2026
Transparency obligations towards individuals
Informing people about contact with a system and about artificially generated content.
from 2 December 2026
requires action
Two new prohibitions and labelling of content in older systems
Also applies to systems made available earlier.
The postponement of deadlines covered only the requirements for high-risk systems. The remaining provisions apply unchanged.
ENTRY SITUATIONS
When support is needed
There is no inventory of use cases
AI tools entered the organization by different routes and nobody keeps a record of them.
The tool was built inside the organization
A team built an assistant or a classifier on a general-purpose model.
AI supports decisions about people
Systems operate in recruitment, employee assessment or client qualification.
The question came from outside
A client, insurer or auditor asks about compliance with the AI Act.
Content is produced automatically
The organization publishes material generated or processed by AI.
A deployment is planned
The project is due to start before the dates from which high-risk requirements apply.
TIMELINE
The postponement did not cover the whole regulation
In July 2026 the European Union changed the timeline for applying the AI Act. The postponement concerns the requirements and obligations relating to high-risk systems. The remaining provisions apply unchanged.
An organization using off-the-shelf tools therefore faces the opposite of the common message. Part of the obligations already applies. The deferral bought time to prepare for the rest.
2 February 2025
Prohibited practices and AI literacy
in force
2 August 2025
General-purpose models, supervision and penalties
in force
2 August 2026
Transparency obligations towards individuals
Informing people about interaction with an AI system and labelling artificially generated content.
in force now
2 December 2026
Two new prohibitions and labelling of content in older systems
Also applies to systems made available earlier.
requires action
2 December 2027
Requirements for high-risk systems from Annex III
preparation
2 August 2028
Requirements for high-risk systems from Annex I
preparation
In Poland the application of the regulation is supervised by the Commission for the Development and Security of Artificial Intelligence, established by the Act on artificial intelligence systems.
STARTING POINT
Who the organization is under the AI Act
This question determines the scope of obligations.
The line between these roles is thinner than it looks at first glance
MOST COMMON ROLE
Deployer
Uses an AI system in its own activity. Where the system is high-risk, it is responsible for using it in accordance with the instructions for use and for assigning human oversight to people with the necessary competence and authority — the obligations in Article 26, which apply from 2 December 2027 or 2 August 2028. Regardless of how the system is classified, the transparency duties towards individuals in Article 50 apply.
A deployer is considered to be a provider of a high-risk AI system in the three situations set out in Article 25(1):
Own name or trademark
The organization makes a high-risk system already on the market available under its own brand.
Substantial modification of the system
A high-risk system already placed on the market is substantially modified.
Change of intended purpose
A system that was not a high-risk system is used in a way that makes it one.
BROADER ROLE
Provider
Places a system on the market or puts it into service under its own name. The scope of its obligations is considerably broader and includes conformity assessment.
The third case applies to many organizations today. A team that built an internal tool on a general-purpose model and directed it at supporting decisions about candidates may have changed the organization’s role without a board decision.
The regulation does not ask whether an organization „works with AI”. It asks about its role in relation to a specific system.
1
Establishing the role is the first step
2
It determines the scope of further work
HOW IT RUNS
How the cooperation works
STAGE 1
Diagnostic call
We establish what the organization already uses and where the need came from.
STAGE 2
Review of use cases
Conversations with process owners and a review of tools and contracts.
STAGE 3
Qualification and gaps
Role, risk category and the difference between the current and the required state.
STAGE 4
Plan and implementation
Priorities, task owners and deadlines matched to the timeline of the regulation.
STAGE 5
Maintenance
Review of new deployments and updates to the register and documentation.
SCOPE OF SUPPORT
What the cooperation covers
Register of AI use cases
We establish where AI is already at work – including tools built in-house and AI features in software bought for another purpose.
Qualification of role and risk level
For each use case we establish the organization’s role and the system’s category, from prohibited practices to high risk.
Transparency towards individuals
We check where the organization must inform people about interaction with a system or about artificially generated content.
Human oversight
We establish who exercises oversight and whether they can stop the system – it is a role, not an entry in a policy.
Contracts and the supply chain
We check whether contracts with tool suppliers give the organization the information and documentation it needs to meet its own obligations.
Documentation and evidence
We put in order the records showing how decisions on deployment and oversight were made – the organization answers clients and auditors with that same material.
FORMS OF COOPERATION
Cooperation options
The scope is matched to the point the organization is at today. Each option can be closed or extended into the next one.
1
First step
Review of AI use cases and qualification
For an organization that does not yet have a picture of the situation.
Result: a list of use cases, the organization’s role established for each of them, and a report with priorities for the board.
2
Putting order in place
Organizing AI governance
For an organization after qualification. Covers the rules for using AI, keeping the register and the model of human oversight. Requirements towards suppliers come with it.
Result: a plan of preparation for the dates from which requirements for high-risk systems apply.
3
Ongoing cooperation
Standing advisory support
For an organization deploying AI on a continuous basis.
Result: assessment of new deployments before launch, updates to the register and responses to changes in the law and to questions from outside.
What the board gains
1
A picture of the situation
It is known where AI operates and who is responsible for it.
2
A settled role
The organization knows whether it acts as a deployer or as a provider.
3
Separated deadlines
It is clear what requires action now and what should be planned.
4
Workable oversight
It is known who can halt a system and on what basis.
5
A basis for deployment decisions
New AI projects go through assessment before launch.
6
Material for questions from outside
An answer for a client or an auditor rests on documents.
Division of roles in the cooperation
LabLogic
Runs the review and qualification, formulates recommendations and coordinates the work.
The organization
Takes decisions, provides information about processes and indicates task owners.
Tool suppliers
Provide technical documentation, instructions and the information needed for assessment.
WHO DELIVERS IT
Knowledge that comes from practice
Over twenty years of work in technology, data protection and cybersecurity. Combining the legal, organizational and technological perspectives makes it possible to assess an AI tool both from the side of the provision and from the side of the deployment. The cooperation is conducted in Polish and in English.
DIRECT CONTACT WITH THE EXPERT
Michał Rutkowski
LabLogic — support and acting as DPO, preparation for NIS2 and the local law KSC, incident response, audits and training.
Frequently asked questions
Does the AI Act apply to us if we only use off-the-shelf tools?
Yes. The regulation also imposes obligations on organizations that merely deploy AI systems. Their scope depends on what a given system is used for.
We heard the deadlines were postponed. Is there anything to do now?
The postponement covered the requirements for high-risk systems. Prohibited practices, the obligation to support AI literacy and the transparency obligations apply regardless of it.
When does an organization using AI become its provider?
When it makes the system available under its own name, substantially modifies it, or uses it in a way that turns it into a high-risk system. The last case happens with tools built in-house.
Does an AI tool in recruitment always mean a high-risk system?
Not always. What decides is the system’s intended purpose and the way it is used, not its mere presence in the recruitment process. That is why qualification is carried out for a specific use case.
Is a data protection impact assessment enough instead of a fundamental rights impact assessment?
It does not replace it, but it connects with it. If the obligation has already been met in the data protection impact assessment, its relevant parts can be included in the fundamental rights impact assessment.
Who supervises the application of the AI Act in Poland?
The Commission for the Development and Security of Artificial Intelligence, established by the Act on artificial intelligence systems. It cooperates with the authorities competent in the remaining areas, including the data protection authority.
Related services
The obligations under the AI Act meet three areas in which an organization usually already has its own rules.
SERVICE
Data protection
Many AI use cases process personal data, so GDPR obligations apply in parallel. Information received from the system’s supplier is used in the data protection impact assessment.
SERVICE
Cybersecurity
Organizations covered by NIS2 and the local law on the national cybersecurity system also assess AI tools as part of the supply chain.
SERVICE
Staff competence
The regulation requires measures supporting AI literacy among the people who use these systems. Scope and format are matched to roles.
Related materials
Questions that keep coming back during a first review of AI use cases — with answers read from the consolidated text of the regulation.
KNOWLEDGE BASE
When does an organization using AI become the provider of the system?
Three circumstances from Article 25(1) and the contractual reservation that settles the outcome.
KNOWLEDGE BASE
What should a register of AI use cases contain?
The regulation does not require a register. It imposes obligations for which a central inventory is a practical and evidentially strong tool.
KNOWLEDGE BASE
Who is responsible for the transparency obligations under the AI Act?
Four obligations from Article 50 divided between the provider and the deployer.
FIRST STEP
Book a diagnostic call
Let us start by establishing where artificial intelligence works in your organization today and in what role the organization stands towards it. The conversation makes it possible to name the first sensible step before you decide on the scope of work.
This material is general and informational. It does not constitute individual legal advice or a recommendation for a specific organization. The scope of obligations should be assessed with that organization’s situation in mind. Legal status: August 2026.
REQUEST A CALL
The controller of the data provided in the form is Michał Rutkowski, trading as LabLogic Consulting. I use the data to handle the enquiry and to prepare a reply or an offer. Details are set out in the Privacy Policy.