The AI ​​Act is now in effect. Is your company using AI? Check if you’re at risk of a fine of up to €35 million

From August 2, 2026, further provisions of the EU AI Act regulation entered into force throughout the European Union, including Poland. These are not full obligations for high-risk systems yet – these have been postponed to 2027 and 2028. However, specific transparency requirements now apply: you must inform users that they are talking to a bot, label AI-generated content and disclose deepfakes. Violation of these rules carries penalties of up to EUR 35 million or 7% of the company’s global annual turnover – depending on the type of offense.

If your company uses ChatGPT, Copilot, image generators, a website chatbot, or any AI tool in marketing, customer service, or HR, this article is for you.

What exactly changed on August 2, 2026?

Much confusion has arisen around this date, as in the summer of 2026, EU institutions adopted the Digital Omnibus, which postponed some deadlines. Many companies interpreted this as a sign that there was still time, so the matter could be postponed. Unfortunately, this situation becomes more complicated.

In fact, on August 2, 2026, the following entered into force:

  • Transparency obligations under section 50 of the AI ​​Act – apply to every entity (not only AI providers, but also companies that use such tools) and include, among others, informing users about interactions with chatbots, marking content generated or modified by AI, and mandatory disclosure of deepfakes.
  • Real market surveillance (Chapter IX of the Regulation) – from this date on, national supervisory authorities can carry out inspections and actually enforce the regulations, and not just monitor the situation.
  • Penalties for general purpose AI model providers (GPAI) – The European Commission has gained the ability to impose financial sanctions on providers of large language models that breach their obligations.

What was actually postponed was the full implementation of obligations for the so-called high-risk systems – more about this later in the article. In other words: you didn’t get an extra year to completely ignore the topic, just extra time to adapt a specific, narrower category of systems.

Does the AI ​​Act apply to my company?

The short answer: probably yes, if you use AI tools in any way with customers, employees or use them in decision-making processes.

The regulation distinguishes two main roles:

  • Provider – the company that creates or develops an AI system and introduces it to the market. It has the most responsibilities: full technical documentation, registration in an EU database, and risk management systems.
  • Deployer (applying entity) – a company that uses a ready-made AI tool in its business. This applies to the vast majority of Polish SMEs. If you use ChatGPT Enterprise, Claude or Copilot to automate internal processes, you do not formally have vendor responsibilities, but you do have deployer responsibilities – you must, for example, document how and why you use a given tool.

Practical examples that apply to small and medium-sized businesses

  • Do you have a customer service chatbot on your website? You need to inform the user that they are talking to a machine and not a human.
  • Do you publish AI-generated graphics or videos on social media? In certain cases, you must mark them as synthetic content.
  • Do you use AI for CV pre-selection or employee evaluation? This may already fall into the area of ​​high-risk systems – here the obligations are much broader.
  • Do you use tools to analyze customer emotions or biometric recognition? Some of these uses may even be prohibited.

What are the real penalties for non-compliance with the AI ​​Act?

The level of sanctions depends on the type of violation. The AI ​​Act provides for three penalty thresholds:

Type of violation Maximum penalty
Use of prohibited AI practices (Article 5) €35 million or 7% of the company’s global annual turnover (whichever is greater)
Violation of other obligations, including those relating to high-risk systems and GPAI models 15 million euros or 3% of the company’s global annual turnover
Providing incorrect, incomplete or misleading information to supervisory authorities 7.5 million euros or 1% of the company’s global annual turnover

For small and medium-sized enterprises and startups, the regulation provides for some relaxation – in their case, the lower of the two indicated values ​​(fixed amount or percentage of turnover) is taken into account, and not automatically the higher one. This does not mean, however, that SMEs are exempt from obligations – just that the scale of penalties is more proportional to the size of the business.

High Risk Systems – Do I Really Have More Time?

This is where the most confusion is. Digital Omnibus has postponed the application of the rules on high-risk systems to two new dates:

  • December 2, 2027 – for systems from Annex III (including recruitment, creditworthiness assessment, education, some applications in public administration).
  • August 2, 2028 – for Annex I systems, i.e. products regulated by other regulations (e.g. machinery, medical equipment, automotive).

This sounds like a comfortable amount of time, but AI Act lawyers reiterate one thing: this is no reason to postpone preparations. Classifying the systems your company uses, assessing risks, documenting them, and training those responsible for overseeing AI is a process that realistically takes months—and regulators will begin to monitor compliance precisely when the deadlines pass, not before.

Moreover, in Poland the national supervisory authority already has a name and a legal basis, but it is not yet operational. On July 24, 2026, the President signed the Act on Artificial Intelligence Systems, which establishes the Commission for the Development and Security of Artificial Intelligence (KRiBSI) ​​- the target national supervisory authority for the AI ​​market. In reality, however, the Commission will only start operating in November 2026, because the act gives the Sejm two months to appoint a chairman and three months to assemble the entire composition. For several months, a situation arises in which the regulations are already in force, but the body responsible for enforcing them in Poland is still being organized. However, this does not release companies from obligations arising directly from the EU regulation, which applies regardless of the pace of building the national supervision infrastructure.

Full AI Act implementation calendar

To avoid further confusion, it is worth having the entire schedule in one place:

This schedule clearly shows that the AI ​​Act is a process spread over years, not one event. Companies that organize the topic of AI internally now will avoid the rush of catching up with each subsequent deadline.

What to do now? A practical checklist.

Instead of waiting for an inspection, it is worth going through a simple process of organizing the AI ​​topic in the company over the next few months:

  1. Map all AI systems used in the organization – not only official tools, but also the so-called shadow AI, i.e. applications used by individual employees without the knowledge of the IT department.
  2. Determine whether you are a provider or a deployer for each of these systems – this determines the scope of your responsibilities.
  3. Check if you generate or publish content marked as AI-powered – especially in marketing, customer communications, and social media.
  4. Verify that none of your systems fall into the category of prohibited practices – pay particular attention to employee emotion analysis and biometric categorization.
  5. Assess whether any of your systems may be considered high risk – if so, start building documentation now, even though the hard deadline is a long way off.
  6. Prepare an internal AI use policy – ​​a simple document regulating which tools can be used, for what purposes, and with what supervision.

How SOFTIQ can help

At SOFTIQ, we implement AI tools in companies of all sizes on a daily basis – from the automation of individual processes to full AI-based systems, such as the SOFTIQ AI tool: Przetargi.io. We understand precisely where questions about compliance with the AI ​​Act lie in practice: which tools count as high-risk systems, how to document how AI is used within a company, and how to design implementations so that they don’t need to be modified later to meet new regulatory requirements. If you’re wondering whether your current AI implementations are compliant, now is a good time to check before the regulator does it for you.

Frequently asked questions about the AI ​​Act

1. Does the AI ​​Act apply to small businesses or only large corporations?

Applies to all entities operating in the EU that use AI systems – regardless of size. However, small and medium-sized companies have more favorable rules for calculating financial penalties than large corporations.

2. Does the mere use of ChatGPT or Claude in a company require compliance with AI Act obligations?

Yes, within the scope of the deployer’s responsibilities – the entity using the ready-made tool. Among other things, you must know what you’re using the tool for and inform users or customers about it in specific situations.

3. Since when do penalties for non-compliance with the AI ​​Act actually apply?

The legal framework for penalties became fully operational on August 2, 2026, with the launch of market surveillance. For high-risk schemes, full enforcement will only begin after the extended deadlines of December 2, 2027 and August 2, 2028.

4. Who supervises compliance with the AI ​​Act in Poland?

Ultimately, the Commission for the Development and Security of Artificial Intelligence (KRiBSI), established by an act signed by the president on July 24, 2026. However, the commission is not to actually start operating until November 2026, so the regulations will be in force for several months before the body responsible for enforcing them in Poland is launched.

5. What are the consequences of not labeling AI-generated content?

Breaches of the transparency obligations under Article 50 of the AI ​​Act fall under the second tier of penalties – up to €15 million or 3% of the company’s global annual turnover, whichever is higher.

Article current as of August 2026. The provisions of the AI ​​Act and the timetable for their implementation may be subject to further changes – before making business decisions, it is worth consulting a lawyer specializing in new technologies law.

Share

Read also

The AI ​​Act is now in effect. Is your company using AI? Check if you’re at risk of a fine of up to €35 million

As of August 2, 2026, the AI ​​Act imposes new obligations and penalties of up to €35 million. Find out

5 biggest challenges slowing down the implementation of AI in companies

Learn about the 5 most serious challenges faced by companies interested in implementing AI tools in their operations and the

10 Key benefits of building MVP (Minimum Viable Product) version of your custom software

By creating custom software in the MVP (Minimum Viable Product) model, you can verify your initial business assumptions and gather

If you want to know more about our latest projects, subscribe to the SOFTIQ newsletter.