SERVICES · AI ACT

AI Act: establishing your role, obligations and scope of preparation

I help establish the role an organization holds under the AI Act. I separate the obligations that already apply from those that require preparation. The starting point is the actual state of affairs: the places where artificial intelligence is already at work.

Over 20 years of practice · Legal and technological perspective · Work in Polish and English

WHAT ALREADY APPLIES AND WHAT COMES NEXT

from 2 February 2025

Prohibited practices and AI literacy

Applies to every organization that uses AI.

from 2 August 2026

Transparency obligations towards individuals

Informing people about contact with a system and about artificially generated content.

from 2 December 2026

requires action

Two new prohibitions and labelling of content in older systems

Also applies to systems made available earlier.

The postponement of deadlines covered only the requirements for high-risk systems. The remaining provisions apply unchanged.

ENTRY SITUATIONS

When support is needed

There is no inventory of use cases

AI tools entered the organization by different routes and nobody keeps a record of them.

The tool was built inside the organization

A team built an assistant or a classifier on a general-purpose model.

AI supports decisions about people

Systems operate in recruitment, employee assessment or client qualification.

The question came from outside

A client, insurer or auditor asks about compliance with the AI Act.

Content is produced automatically

The organization publishes material generated or processed by AI.

A deployment is planned

The project is due to start before the dates from which high-risk requirements apply.

TIMELINE

The postponement did not cover the whole regulation

In July 2026 the European Union changed the timeline for applying the AI Act. The postponement concerns the requirements and obligations relating to high-risk systems. The remaining provisions apply unchanged.

An organization using off-the-shelf tools therefore faces the opposite of the common message. Part of the obligations already applies. The deferral bought time to prepare for the rest.

2 February 2025

Prohibited practices and AI literacy

in force

2 August 2025

General-purpose models, supervision and penalties

in force

2 August 2026

Transparency obligations towards individuals

Informing people about interaction with an AI system and labelling artificially generated content.

in force now

2 December 2026

Two new prohibitions and labelling of content in older systems

Also applies to systems made available earlier.

requires action

2 December 2027

Requirements for high-risk systems from Annex III

preparation

2 August 2028

Requirements for high-risk systems from Annex I

preparation

In Poland the application of the regulation is supervised by the Commission for the Development and Security of Artificial Intelligence, established by the Act on artificial intelligence systems.

STARTING POINT

Who the organization is under the AI Act

This question determines the scope of obligations.

The line between these roles is thinner than it looks at first glance

MOST COMMON ROLE

Deployer

Uses an AI system in its own activity. Where the system is high-risk, it is responsible for using it in accordance with the instructions for use and for assigning human oversight to people with the necessary competence and authority — the obligations in Article 26, which apply from 2 December 2027 or 2 August 2028. Regardless of how the system is classified, the transparency duties towards individuals in Article 50 apply.

A deployer is considered to be a provider of a high-risk AI system in the three situations set out in Article 25(1):

Own name or trademark

The organization makes a high-risk system already on the market available under its own brand.

Substantial modification of the system

A high-risk system already placed on the market is substantially modified.

Change of intended purpose

A system that was not a high-risk system is used in a way that makes it one.

BROADER ROLE

Provider

Places a system on the market or puts it into service under its own name. The scope of its obligations is considerably broader and includes conformity assessment.

The third case applies to many organizations today. A team that built an internal tool on a general-purpose model and directed it at supporting decisions about candidates may have changed the organization’s role without a board decision.

The regulation does not ask whether an organization „works with AI”. It asks about its role in relation to a specific system.

1

Establishing the role is the first step

2

It determines the scope of further work

HOW IT RUNS

How the cooperation works

STAGE 1

Diagnostic call

We establish what the organization already uses and where the need came from.

STAGE 2

Review of use cases

Conversations with process owners and a review of tools and contracts.

STAGE 3

Qualification and gaps

Role, risk category and the difference between the current and the required state.

STAGE 4

Plan and implementation

Priorities, task owners and deadlines matched to the timeline of the regulation.

STAGE 5

Maintenance

Review of new deployments and updates to the register and documentation.

SCOPE OF SUPPORT

What the cooperation covers

Register of AI use cases

We establish where AI is already at work – including tools built in-house and AI features in software bought for another purpose.

Qualification of role and risk level

For each use case we establish the organization’s role and the system’s category, from prohibited practices to high risk.

Transparency towards individuals

We check where the organization must inform people about interaction with a system or about artificially generated content.

Human oversight

We establish who exercises oversight and whether they can stop the system – it is a role, not an entry in a policy.

Contracts and the supply chain

We check whether contracts with tool suppliers give the organization the information and documentation it needs to meet its own obligations.

Documentation and evidence

We put in order the records showing how decisions on deployment and oversight were made – the organization answers clients and auditors with that same material.

FORMS OF COOPERATION

Cooperation options

The scope is matched to the point the organization is at today. Each option can be closed or extended into the next one.

1

First step

Review of AI use cases and qualification

For an organization that does not yet have a picture of the situation.

Result: a list of use cases, the organization’s role established for each of them, and a report with priorities for the board.

2

Putting order in place

Organizing AI governance

For an organization after qualification. Covers the rules for using AI, keeping the register and the model of human oversight. Requirements towards suppliers come with it.

Result: a plan of preparation for the dates from which requirements for high-risk systems apply.

3

Ongoing cooperation

Standing advisory support

For an organization deploying AI on a continuous basis.

Result: assessment of new deployments before launch, updates to the register and responses to changes in the law and to questions from outside.

What the board gains

1

A picture of the situation

It is known where AI operates and who is responsible for it.

2

A settled role

The organization knows whether it acts as a deployer or as a provider.

3

Separated deadlines

It is clear what requires action now and what should be planned.

4

Workable oversight

It is known who can halt a system and on what basis.

5

A basis for deployment decisions

New AI projects go through assessment before launch.

6

Material for questions from outside

An answer for a client or an auditor rests on documents.

Division of roles in the cooperation

LabLogic

Runs the review and qualification, formulates recommendations and coordinates the work.

The organization

Takes decisions, provides information about processes and indicates task owners.

Tool suppliers

Provide technical documentation, instructions and the information needed for assessment.

WHO DELIVERS IT

Knowledge that comes from practice

Over twenty years of work in technology, data protection and cybersecurity. Combining the legal, organizational and technological perspectives makes it possible to assess an AI tool both from the side of the provision and from the side of the deployment. The cooperation is conducted in Polish and in English.

DIRECT CONTACT WITH THE EXPERT

Michał Rutkowski

LabLogic — support and acting as DPO, preparation for NIS2 and the local law KSC, incident response, audits and training.

M.Rutkowski@LabLogic.pl

Frequently asked questions

Does the AI Act apply to us if we only use off-the-shelf tools?

Yes. The regulation also imposes obligations on organizations that merely deploy AI systems. Their scope depends on what a given system is used for.

We heard the deadlines were postponed. Is there anything to do now?

The postponement covered the requirements for high-risk systems. Prohibited practices, the obligation to support AI literacy and the transparency obligations apply regardless of it.

When does an organization using AI become its provider?

When it makes the system available under its own name, substantially modifies it, or uses it in a way that turns it into a high-risk system. The last case happens with tools built in-house.

Does an AI tool in recruitment always mean a high-risk system?

Not always. What decides is the system’s intended purpose and the way it is used, not its mere presence in the recruitment process. That is why qualification is carried out for a specific use case.

Is a data protection impact assessment enough instead of a fundamental rights impact assessment?

It does not replace it, but it connects with it. If the obligation has already been met in the data protection impact assessment, its relevant parts can be included in the fundamental rights impact assessment.

Who supervises the application of the AI Act in Poland?

The Commission for the Development and Security of Artificial Intelligence, established by the Act on artificial intelligence systems. It cooperates with the authorities competent in the remaining areas, including the data protection authority.

Related services

The obligations under the AI Act meet three areas in which an organization usually already has its own rules.

SERVICE

Data protection

Many AI use cases process personal data, so GDPR obligations apply in parallel. Information received from the system’s supplier is used in the data protection impact assessment.

See DPO support →

SERVICE

Cybersecurity

Organizations covered by NIS2 and the local law on the national cybersecurity system also assess AI tools as part of the supply chain.

See NIS2 and KSC preparation →

SERVICE

Staff competence

The regulation requires measures supporting AI literacy among the people who use these systems. Scope and format are matched to roles.

See training matched to roles →

Related materials

Questions that keep coming back during a first review of AI use cases — with answers read from the consolidated text of the regulation.

KNOWLEDGE BASE

When does an organization using AI become the provider of the system?

Three circumstances from Article 25(1) and the contractual reservation that settles the outcome.

Read →

KNOWLEDGE BASE

What should a register of AI use cases contain?

The regulation does not require a register. It imposes obligations for which a central inventory is a practical and evidentially strong tool.

Read →

KNOWLEDGE BASE

Who is responsible for the transparency obligations under the AI Act?

Four obligations from Article 50 divided between the provider and the deployer.

Read →

FIRST STEP

Book a diagnostic call

Let us start by establishing where artificial intelligence works in your organization today and in what role the organization stands towards it. The conversation makes it possible to name the first sensible step before you decide on the scope of work.

This material is general and informational. It does not constitute individual legal advice or a recommendation for a specific organization. The scope of obligations should be assessed with that organization’s situation in mind. Legal status: August 2026.

REQUEST A CALL

The controller of the data provided in the form is Michał Rutkowski, trading as LabLogic Consulting. I use the data to handle the enquiry and to prepare a reply or an offer. Details are set out in the Privacy Policy.

Scroll to Top