policy · Effective Jan 1, 2025
PL regulates AI through Policy for the Development of Artificial Intelligence in Poland to 2030.
Policy for the Development of Artificial Intelligence in Poland to 2030 · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Poland has adopted a proactive and structured approach to the regulation of artificial intelligence, evolving from early strategic roadmaps in 2019 to a comprehensive legislative and institutional framework designed to operationalize the European Union’s AI Act. The country’s regulatory philosophy is centered on the dual objectives of fostering a competitive, high-growth AI ecosystem while ensuring the highest levels of safety, transparency, and respect for fundamental rights. This approach is articulated in the flagship "Policy for the Development of Artificial Intelligence in Poland to 2030," which envisions Poland becoming one of the top 20 AI-ready countries globally. The policy emphasizes the development of national computing infrastructure, the creation of "AI HUB Poland" for public sector adoption, and the support of open-source models to ensure technological sovereignty. The maturity of Poland's AI landscape is evidenced by its integrated governance model, which involves multiple ministries and specialized regulators. The Ministry of Digital Affairs (Ministerstwo Cyfryzacji) serves as the central coordinating body, ensuring that AI development aligns with broader national digitalization strategies, such as the "Strategy for the Digitization of Poland to 2035." By 2026, Poland has moved beyond mere policy declarations into the enforcement phase, with the "Draft Act on Artificial Intelligence Systems" providing the legal basis for market surveillance and the imposition of administrative penalties. This legislative maturity reflects a shift from a "soft law" advisory environment to a "hard law" compliance environment, particularly for high-risk AI systems deployed in critical sectors like healthcare, finance, and public administration. The government has also recognized that AI is not merely a technological shift but a fundamental economic and social transformation. Consequently, the regulatory landscape has been meticulously crafted to provide a stable environment for investment while safeguarding the democratic values that underpin the Polish state. The goal is not just compliance but the creation of a "sovereign AI" capability that reduces dependence on non-European providers.
Regulatory approach
Poland utilizes a hybrid regulatory approach that combines horizontal, risk-based legislation with targeted sectoral guidelines. The primary horizontal instrument is the Draft Act on Artificial Intelligence Systems, which mirrors the EU AI Act’s classification of AI systems into prohibited, high-risk, and low-risk categories. This act serves as the procedural bridge, filling national gaps in the EU framework by defining the specific powers of Polish oversight bodies, establishing national registration procedures for high-risk systems, and setting out the rules for regulatory sandboxes. This horizontal layer ensures a baseline of safety and accountability across all industries, preventing a fragmented regulatory environment that could stifle cross-sectoral innovation. In addition to horizontal laws, Poland increasingly relies on sectoral "soft law" and technical standards to manage domain-specific risks. For instance, the Ministry of Digital Affairs and the AI HUB Poland initiative provide specialized guidance for AI use in public administration, focusing on procurement standards and ethical impact assessments. Similarly, the financial and healthcare sectors are subject to additional oversight from their respective regulators (such as the KNF for finance), who integrate AI considerations into existing prudential and safety frameworks. This approach allows for flexibility, enabling regulators to issue rapid guidance on emerging technologies like generative AI and deepfakes while maintaining the stability of a permanent, statutory legal foundation. The Polish regulatory approach is characterized by its "risk-based" and "pro-innovation" dualism. Rather than imposing a one-size-fits-all regulatory burden, Poland has adopted the EU's classification system, which focuses oversight on systems that pose the highest risk to safety and fundamental rights. This approach allows developers of low-risk AI, such as spam filters or AI-enabled video games, to innovate with minimal administrative interference. However, for high-risk systems—such as those used in recruitment, credit scoring, or law enforcement—the regulatory requirements are stringent. These include mandatory risk management systems, high-quality data governance, and detailed technical documentation. A unique feature of the Polish approach is the emphasis on "technological sovereignty." The government actively supports the development of local AI models and infrastructure to ensure that Poland is not solely dependent on external technology providers. The governance of AI in Poland is characterized by a multi-layered institutional architecture. At the apex is the Ministry of Digital Affairs (Ministerstwo Cyfryzacji), which is responsible for national AI policy, international representation, and the overall coordination of digital transformation. The Ministry manages the AI HUB Poland platform, which serves as a technical and advisory resource for both public and private stakeholders. Under the proposed AI Systems Act, a new collegiate body, the Commission for AI Development and Safety (KRiBSI), is designated as the national market surveillance authority. KRiBSI is tasked with monitoring compliance, managing the national registry of high-risk AI systems, and acting as the single point of contact for the European AI Board. Complementing these AI-specific bodies are established regulators with expanded mandates. The Office for Personal Data Protection (UODO) plays a critical role in overseeing the data-intensive aspects of AI, ensuring that model training and deployment comply with the GDPR and the Data Governance Act. UODO has the power to conduct audits and issue opinions on high-risk AI impact assessments. Additionally, the President of Statistics Poland (GUS) provides technical assistance for data re-use, while sectoral regulators like the Polish Financial Supervision Authority (KNF) monitor AI applications within the banking and insurance sectors to ensure financial stability and consumer protection. The governance of AI in Poland is a multi-institutional effort, reflecting the cross-cutting nature of the technology. Within the Ministry of Digital Affairs, the "Department of Artificial Intelligence" focuses on the technical and ethical aspects of AI deployment. KRiBSI is a collegiate body, meaning it draws expertise from various government departments and independent experts, ensuring a balanced perspective on AI oversight. Its powers are extensive, ranging from the ability to conduct on-site inspections of AI developers to the power to order the immediate cessation of a non-compliant AI system. This distributed governance model ensures that each aspect of AI—from data privacy to financial risk—is overseen by the most qualified authority, while the Ministry of Digital Affairs provides the necessary high-level coordination.
Enforcement & penalties
Enforcement in the Polish AI framework is designed to be rigorous and escalatory, closely aligning with the penalty structures defined in the EU AI Act. The Draft Act on Artificial Intelligence Systems empowers the Commission for AI Development and Safety (KRiBSI) to impose significant administrative fines for non-compliance. For the use of prohibited AI practices—such as social scoring or unauthorized biometric identification—fines can reach up to €35 million or 7% of a company’s total global annual turnover, whichever is higher. For breaches related to high-risk AI system obligations, including failures in risk management or technical documentation, penalties are capped at €15 million or 3% of turnover. Smaller infractions, such as providing misleading information to regulators, carry lower but still substantial fines. Beyond financial penalties, the enforcement regime includes a variety of corrective measures. KRiBSI and other competent authorities have the power to order the immediate withdrawal of an AI system from the market, mandate the suspension of its operation, or require specific technical modifications to bring the system into compliance. The Draft Act also outlines a clear appeals process, allowing entities to challenge administrative decisions before the administrative courts. This ensures a system of checks and balances, where enforcement actions must be reasoned, proportionate, and subject to judicial review, thereby maintaining legal certainty for AI developers and deployers operating in the Polish market. The enforcement philosophy emphasizes "compliance through cooperation" for first-time or minor offenders. KRiBSI has the authority to issue "warnings" and "compliance orders" before resorting to financial penalties. This allows companies to rectify issues without facing immediate financial ruin, which is particularly important for startups and SMEs. The enforcement regime also includes "periodic penalty payments," which are daily fines designed to compel a company to comply with a specific order, such as providing access to a system's source code for an audit. This comprehensive set of tools ensures that the Polish government can effectively manage the risks associated with AI while maintaining a fair and predictable business environment.
Data protection
Data protection is the bedrock of Poland's AI regulatory environment, with the General Data Protection Regulation (GDPR) serving as the primary legal standard for all AI systems involving personal data. The Polish Office for Personal Data Protection (UODO) has been vocal in emphasizing that AI development must not circumvent privacy-by-design and privacy-by-default principles. Under the Draft Act on Data Management, Poland has further strengthened this framework by transposing the EU Data Governance Act. This introduces strict neutrality requirements for data intermediaries, ensuring that personal and non-personal data can be shared for AI training without being exploited by the intermediaries themselves. The framework also addresses the unique challenges of "data altruism" and the re-use of protected public sector information. The 2021 Act on Open Data facilitates the flow of high-value datasets to AI researchers, while the Data Management Act provides a secure legal pathway for using commercially sensitive or IP-protected data under controlled conditions. This is supported by the President of Statistics Poland (GUS), who provides the technical infrastructure—such as secure processing environments and pseudonymization tools—to ensure that data used for AI innovation remains protected. This dual focus on data availability and data security aims to build public trust in AI systems while providing the high-quality data necessary for accurate model performance. UODO has issued specific guidance on "AI and Employee Monitoring," a major concern in the Polish labor market. The Data Management Act also introduces the concept of "Data Altruism Organizations," which are non-profits that manage data for the public good, such as medical research. To ensure that this does not lead to privacy breaches, the "President of Statistics Poland" (GUS) provides advanced pseudonymization and anonymization tools. This allows AI researchers to access large-scale datasets without compromising the identity of individual citizens. The framework also addresses the "right to an explanation" for individuals affected by automated decisions, ensuring that AI systems are not "black boxes" but are instead transparent and accountable.
Sector-specific rules
While horizontal laws provide the general framework, Poland has developed specific rules for high-impact sectors. In Healthcare, the Strategy for the Digitization of Poland to 2035 sets a target for AI-assisted diagnostics to be available for 100 different disease units. This is supported by specific medical data sharing protocols and clinical validation requirements for AI-driven medical devices. The Ministry of Health and the National Health Fund (NFZ) work alongside AI HUB Poland to ensure that healthcare AI is explainable and does not introduce biases into patient treatment plans. These rules emphasize human oversight, requiring that AI tools serve as decision-support systems rather than autonomous diagnostic agents. In the Financial Sector, the Polish Financial Supervision Authority (KNF) has integrated AI oversight into its broader digital finance agenda. Financial institutions using AI for credit scoring, fraud detection, or algorithmic trading must comply with strict transparency and auditability standards to prevent systemic risk and discriminatory outcomes. Similarly, in Public Administration, the AI HUB Poland initiative has established procurement guidelines that require vendors to provide detailed documentation on model training and bias mitigation. These sectoral rules are designed to ensure that the most sensitive applications of AI are governed by experts who understand the specific technical and ethical nuances of those domains. In the energy sector, AI is being used to manage the transition to renewable energy. The "Energy Law" is being updated to include provisions for AI-driven grid management. In cybersecurity, the "National Cybersecurity System" now includes AI-based threat detection as a requirement for "operators of essential services." Other sectors, such as transportation, are also seeing the emergence of AI-specific rules. For example, the "Road Traffic Act" is being adapted to accommodate the testing of autonomous vehicles. These sector-specific rules ensure that the general principles of AI safety and ethics are applied in a way that makes sense for the unique challenges of each industry.
International alignment
Poland’s AI strategy is fundamentally European in its orientation. The country has been an active participant in the negotiation and subsequent implementation of the EU AI Act, ensuring that its national laws are fully interoperable with the Union’s single market requirements. This alignment extends to the adoption of European technical standards for AI safety and cybersecurity. Poland also adheres to the OECD Recommendation on Artificial Intelligence, embedding principles of inclusive growth, human-centric values, and transparency into its national policies. This international consistency is intended to make Poland an attractive destination for global investment, as companies can rely on a regulatory environment that is familiar and compliant with international best practices. Furthermore, Poland actively participates in international research and infrastructure initiatives, such as the EuroHPC Joint Undertaking and the Global Partnership on Artificial Intelligence (GPAI). The national "Policy for the Development of AI to 2030" explicitly calls for the promotion of Polish AI actors on the international stage and the alignment of national standards with those of the UN and OECD. By positioning itself as a bridge between the technical capabilities of Central and Eastern Europe and the regulatory standards of the EU, Poland seeks to influence the global discourse on trustworthy AI while securing its place in the global digital economy. Poland also plays a key role in regional cooperation, particularly within the "Visegrád Group" (V4) and the "Three Seas Initiative." These platforms allow Poland to coordinate its digital policies with its neighbors, creating a more unified and powerful voice in international discussions on AI governance. By aligning its national standards with international best practices, Poland is positioning itself as a reliable and attractive partner for global AI investment. This international alignment also extends to cybersecurity, where Poland works closely with its NATO allies to develop AI-driven tools for defending critical infrastructure against cyber threats.
What's next
The next few years will see the finalization and full operationalization of Poland's AI legislative package. The most significant pending development is the formal enactment of the Act on Artificial Intelligence Systems, which will trigger the establishment of the Commission for AI Development and Safety (KRiBSI). Once the act is in force, the government is expected to launch the first national regulatory sandboxes, providing a controlled environment for companies to test innovative AI solutions under the supervision of regulators. These sandboxes will be critical for small and medium-sized enterprises (SMEs) seeking to navigate the complexities of high-risk AI compliance. Additionally, the Policy for the Development of Artificial Intelligence in Poland to 2030 is expected to move from its current draft status to full implementation, unlocking significant funding for national computing centers and AI research grants. The Ministry of Digital Affairs is also expected to issue further guidance on the use of Generative AI and Foundation Models, particularly regarding copyright protections for creators and the prevention of deepfake-related disinformation. As the EU AI Act’s various deadlines approach, Poland will continue to refine its administrative procedures, ensuring that its national registry and conformity assessment bodies are fully functional to support the next generation of AI innovation. Another major development is the "AI for Education" initiative, which aims to integrate AI literacy into the national school curriculum by 2026. The government is also working on the "National AI Language Model" (PLLuM), a project designed to create a large language model that is specifically optimized for the Polish language and culture. This project is seen as a key component of Poland's "technological sovereignty," as it will reduce the country's dependence on foreign generative AI models. In the realm of data, the full implementation of the "Data Management Act" will see the creation of a national registry for "Data Altruism Organizations," facilitating the flow of data for public interest research.
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2024
central_coordinator
Central coordination of AI policy and digital strategy.
enforcement
National market surveillance authority for AI systems.
data_protection
Supervision of personal data processing and data altruism.
advisory
Technical support for public sector data re-use.
Apr 22, 2026 · law_amended
President of Personal Data Protection Office submits opinion on proposal for Act on Artificial Intelligence systems
Open source →Mar 3, 2026 · news
Deputy President of the Personal Data Protection Office speaks on the role of AI in local governments
Open source →Dec 30, 2025 · enforcement_action
Poland urges EU to probe TikTok over AI-generated content suspected to come from Russia
Open source →Sep 17, 2025 · law_amended
Personal Data Protection Office's proposal to introduce law to address dissemination of harmful deepfake content
Open source →Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
Sources:
act · Effective Jan 1, 2021
policy · Effective Jan 1, 2020
policy · Effective Jan 1, 2019
policy · Effective Jan 1, 2019
Feb 5, 2025 · news
UODO adopts guidance cautioning against use of DeepSeek
Open source →Oct 30, 2024 · law_amended
Poland designates three public bodies to enforce protections of fundamental rights related to high-risk AI systems under the EU AI Act
Open source →Oct 15, 2024 · law_amended
Poland unveils draft law implementing EU AI Act
Open source →Oct 7, 2024 · law_amended
Polish government preparing AI regulations for use in specific industries
Open source →Oct 2, 2024 · international_agreement
US and Poland sign Memorandum of Understanding on cybersecurity and emerging technology cooperation
Open source →