The EU AI Act: Navigating New Regulations Amidst Enforcement Delays
Poland has officially stepped into the era governed by the European Union’s groundbreaking AI Act. However, the nation finds itself in a peculiar legislative limbo. Specific provisions concerning the labeling of AI-generated content came into effect on August 2nd, yet the critical body tasked with penalizing violations remains merely a concept on paper. This delay raises significant questions about compliance, accountability, and the immediate future of AI governance in the country.
Understanding the EU AI Act’s Core Principles
The EU AI Act stands as a pioneering regulatory framework designed to ensure the safe and ethical development and deployment of artificial intelligence systems across the European Union. Its primary objective is to differentiate obligations for entities using AI systems based on their potential risk levels – from minimal to unacceptable risks.
A crucial milestone occurred when the first wave of provisions under the AI Act began to apply. Specifically, transparency obligations related to the use of generative artificial intelligence and the mandatory labeling of such content came into force on August 2nd. The broader “first wave” of compliance for various aspects is slated to fully apply by August 2, 2026, marking a significant transition period for businesses and public administrations.
Poland’s Legislative Gap: An Enforcement Body on Hold
In anticipation of the AI Act, Poland enacted its own Artificial Intelligence Systems Act. This national legislation aims not only to transpose the EU regulation but also to establish a dedicated national supervisory authority: the Commission for the Development and Security of Artificial Intelligence (KRiBSI). KRiBSI is intended to be the linchpin for overseeing compliance and enforcing the new AI regulations within Poland.
Despite these legislative steps and the entry into force of certain AI Act provisions, KRiBSI has yet to commence its operations. This operational delay leaves a critical gap in enforcement, where companies and institutions are expected to adhere to new regulations without a clear national body to guide, monitor, or sanction them.
Penalties Under the AI Act: A Tiered System
The AI Act introduces a robust, multi-tiered system of financial penalties designed to deter non-compliance. These penalties feature very high maximum thresholds, reflecting the EU’s commitment to serious enforcement:
- Up to €35 million or 7% of global annual turnover (whichever is higher) for violations concerning prohibited AI practices. These include egregious uses such as certain forms of biometric identification, manipulative behavioral techniques, or social scoring.
- Up to €15 million or 3% of global annual turnover (whichever is higher) for infringements related to obligations for high-risk AI systems and transparency rules. This category notably includes violations of Article 50, which mandates the clear labeling of AI-generated content, the transparent use of chatbots, and the identification of emotion recognition systems and deepfakes.
- Up to €7.5 million or 1% of global annual turnover (whichever is higher) for providing authorities with false or misleading information.
It’s important to note that lower penalty caps are foreseen for EU institutions (e.g., up to €1.5 million for prohibited practices). Furthermore, the Act allows for potentially more lenient approaches for Small and Medium-sized Enterprises (SMEs) and startups, although the specifics will ultimately depend on the practical application by national enforcement bodies.
For industries heavily reliant on generative AI—such as media platforms and technology companies—Article 50 is particularly relevant. Non-compliance could involve:
- Failing to mark deepfakes that depict real individuals or events, potentially misleading the public. For more information on this, see: AI-Generated Fake News, Disinformation, and the EU Report Threat.
- Omitting clear disclosure about the use of chatbots when interacting with consumers, hindering transparency. The potential risks of such interactions are further explored here: AI Chatbot Risks: Violence and Mental Health Warning.
- Not informing users that the content they are engaging with has been generated by an AI model.
The Dilemma of Retroactive Enforcement
With no operational national enforcement body, a critical question arises: will the law apply retroactively? Businesses and institutions in Poland are currently in a precarious position, tasked with adapting to EU requirements without clear guidance on who will hold them accountable, or when.
Legal opinions on this matter are divided:
- Some legal experts argue that KRiBSI, once it finally becomes operational (potentially not until 2027), should not impose penalties for events that occurred before its formal establishment. This perspective emphasizes the principle of legal certainty and the need for a functioning authority to oversee compliance.
- Conversely, other legal scholars contend that the obligations stipulated by the AI Act are directly binding, implying that the state’s delay in establishing an enforcement body does not negate these duties. They suggest that sanctions could still be applied for violations that clearly contradict the EU’s transparency standards, irrespective of KRiBSI’s operational status.
Moreover, it’s worth noting that other existing institutions can already address certain AI-related abuses. For instance, the Polish Data Protection Office (UODO) can leverage provisions from the General Data Protection Regulation (GDPR) to intervene in cases involving personal data protection within AI systems.
The EU AI Act is a pioneering regulation designed to ensure that AI systems used within the European Union are safe, ethical, and trustworthy. It categorizes AI systems by risk level, imposing stricter rules on higher-risk applications to protect fundamental rights and safety.
Under Article 50 of the AI Act, developers and deployers of generative AI systems must ensure users are informed when they interact with AI-generated content. This includes clearly labeling deepfakes, disclosing the use of chatbots, and notifying users that content has been created by an AI model.
The delay creates uncertainty for companies. While they are legally obligated to comply with the AI Act’s provisions, the absence of an active national enforcement body (KRiBSI) means there’s no clear authority to provide guidance, conduct audits, or impose penalties. This leaves businesses without a direct point of contact for compliance questions and creates ambiguity regarding the timing and scope of potential enforcement actions for current non-compliance.
Source: WNP, RP, Ministry of Digital Affairs, europa.eu. Opening photo: Gemini