News

/ Taxes and Law in Poland

AI Act transparency obligations from 2 August 2026: what must companies in Poland implement?

AI Act transparency obligations from 2 August 2026: what must companies in Poland implement?

/
Date27 Jul 2026
/
Stay up to date Add us as a preferred source on Google
Add

From 2 August 2026, businesses operating in Poland will have to comply with key AI Act transparency obligations concerning chatbots, emotion recognition, biometric categorisation, deepfakes and certain AI-generated publications. Not every text, image or video created with AI will require a visible label. Companies should identify their AI use cases, define approval and labelling rules, document human review and clarify responsibilities with agencies and contractors. Non-compliance may result in fines of up to EUR 15 million or 3% of worldwide annual turnover.

From 2 August 2026, the key AI Act transparency obligations set out in Article 50 will apply to companies operating in Poland. Businesses will have to inform users when they interact with certain AI systems, disclose the use of emotion recognition and biometric categorisation systems, and label specified deepfakes and texts concerning matters of public interest.

The obligation will not automatically cover every text, photograph or video produced with the assistance of AI. The type of material, the extent of the system’s intervention, the realism of the content and the purpose of publication will determine whether disclosure is required.

Providers of systems generating images, text, audio or video will generally have to ensure that outputs are marked in a machine-readable format. A limited transitional period until 2 December 2026 applies to relevant systems placed on the market before 2 August 2026. Companies using these systems may nevertheless be responsible for visibly labelling published deepfakes and certain AI-generated texts.

Before 2 August, businesses should establish where AI is being used, who approves AI-assisted materials, when labelling is required and how human review is documented. A breach of the transparency obligations may result in a fine of up to EUR 15 million or 3% of the company’s total worldwide annual turnover.


What changes under the AI Act from 2 August 2026?

From 2 August 2026, transparency obligations will apply in four principal areas: direct interaction between people and AI, technical marking of synthetic content, emotion recognition and biometric categorisation systems, and the publication of deepfakes and certain AI-generated texts.

These obligations arise from Article 50 of Regulation (EU) 2024/1689 of the European Parliament and of the Council. They are intended to reduce the risk of misleading recipients, impersonating other people and distributing materials whose artificial origin is difficult to identify.

Use of AIObligation from 2 August 2026Responsible party
Chatbot or virtual assistantInform the user that they are interacting with an AI system, unless this is obviousSystem provider
Text, image, video or audio generatorTechnically mark the output as generated or manipulated by AISystem provider
Emotion recognition or biometric categorisation systemInform the individuals exposed to the systemSystem deployer
Image, video or audio constituting a deepfakeClearly disclose that the material was generated or manipulated by AISystem deployer
Text concerning a matter of public interestDisclose the use of AI unless the human review and editorial responsibility exemption appliesSystem deployer

For most businesses, the most relevant requirements will concern chatbots and AI-generated materials. They may apply both to content produced internally and to materials commissioned from marketing agencies, designers, freelancers and other external providers.

Article 50
AI Act transparency obligations from 2 August 2026
Four key AI transparency obligations
From this date, providers and deployers of AI systems used in Poland will be subject to specific transparency obligations concerning chatbots, emotion recognition, biometric categorisation, deepfakes and certain AI-generated texts.
01
Chatbots & virtual assistants
Obligation on: system provider
Inform the user that they are interacting with an AI system, unless this is obvious — no later than the start of the interaction.
Example disclosure
“You are speaking with a virtual assistant powered by artificial intelligence.”
02
Deepfakes & synthetic media
Obligation on: system deployer
Clearly disclose AI-generated or manipulated images, audio or video that resemble real or plausibly existing persons, objects, places or events and may falsely appear authentic.
Example
This may include realistic product or property visualisations that recipients could mistake for authentic photographs.
03
Emotion recognition & biometric categorisation
Obligation on: system deployer
Inform individuals who are exposed to an emotion recognition or biometric categorisation system.
Key principle
The information must be provided no later than the person’s first exposure to the system.
04
Texts on matters of public interest
Obligation on: system deployer
Disclose the use of AI when publishing texts intended to inform the public about matters of public interest, such as legal, tax, economic, health or security issues relevant to public debate.
Exemption
Not required where the content has undergone genuine human review or editorial control and a natural or legal person holds editorial responsibility.
Maximum administrative fine
Up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year
For undertakings, whichever is higher. For SMEs, the lower statutory maximum applies. The maximum fine is not imposed automatically and depends on the circumstances of the infringement.
What to do before 2 August 2026
Not every AI output needs a label — companies using AI need a clear compliance process
1
Identify
Map where AI is used across marketing, sales, customer service, HR, communications, IT and cooperation with agencies.
2
Classify
Determine which uses require user information, a visible label, or documented human review.
3
Assign responsibility
Define who approves content, adds labels, retains metadata and is responsible for publication.

Must a chatbot disclose that it is powered by artificial intelligence?

Yes, where a user may not realise that they are interacting with an AI system. The information must be provided no later than the beginning of the interaction.

The obligation may apply to:

  • website chatbots;
  • virtual customer assistants;
  • bots conducting preliminary recruitment interviews;
  • automated advisers operating through messaging platforms;
  • voice-based telephone support systems;
  • avatars that communicate directly with users.

A disclosure is not required where it is obvious to a reasonably well-informed, circumspect and observant person that they are interacting with a machine. In practice, however, companies should not base their entire compliance process on the assumption that the artificial nature of a tool is sufficiently apparent.

A prudent solution is to display a short notice such as:

You are speaking with a virtual assistant powered by artificial intelligence.”

The notice should be visible before the conversation begins or included directly in the first message. It should not be hidden exclusively in the terms of service or privacy policy. Article 50 requires the information to be communicated clearly, in a distinguishable manner and in accordance with accessibility requirements.


Which AI-generated content must be labelled?

The visible labelling obligation for companies deploying AI primarily concerns images, audio recordings and videos constituting deepfakes, as well as certain texts published to inform the public about matters of public interest.

The AI Act defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

The rules are therefore not limited to videos impersonating politicians or public figures. They may also cover advertising and business materials where realistic objects, people or situations are presented in a way that could be perceived as genuine.


Must every AI-generated image be labelled?

Not every image generated using AI will be subject to a disclosure obligation. The key questions are whether the material resembles an existing person, object, place, entity or event — or something that can plausibly exist or could plausibly have existed — and whether it may falsely appear to be authentic or truthful.

The risk will be greater where materials are used as:

  • product photographs in online stores;
  • property visualisations;
  • images of employees or customers;
  • illustrations presenting the results of a service;
  • materials documenting a fictional event;
  • advertisements presenting a non-existent situation as real;
  • investment or development visualisations that do not reflect the actual design.

One example is a realistic apartment visualisation in which AI has generated the furniture, the view from the window or elements of the interior. Where recipients may believe they are viewing an actual photograph of the property being offered, the material should be assessed for a potential labelling obligation.

A clearly fantastical illustration, icon or abstract graphic that recipients would not regard as documentation of the real world may be assessed differently. The mere use of an image generator does not in itself determine that disclosure is required.


Must AI-enhanced photographs be labelled?

Minor technical corrections to a photograph should not automatically trigger a labelling obligation. The obligation may arise where AI materially changes the content or meaning of the image.

Article 50(2) provides an exception from the provider’s machine-readable marking obligation where a system performs an assistive function for standard editing or does not substantially alter the input data or its meaning. For the company publishing the material, the key issue is whether the final result constitutes a deepfake and may falsely appear authentic or truthful.

Standard technical editing may include:

  • improving sharpness;
  • reducing noise;
  • correcting white balance;
  • adjusting exposure;
  • making minor colour corrections;
  • automatically removing technical imperfections.

Removing or adding a person, changing a product’s appearance, generating a new background or placing an object in a location where it was never present should be assessed differently.

The practical question should therefore not be limited to “Was AI used?” It should be: “Did AI change the reality presented in the material in a way that could affect the recipient’s decision?”


Must AI-generated text be labelled?

Not every text produced with AI will automatically require disclosure. Article 50 covers AI-generated or manipulated texts published for the purpose of informing the public about matters of public interest.

Matters of public interest may include law, taxation, politics, the economy, public health, security or environmental protection where the issue is relevant to the public or forms — or may form — a meaningful subject of public debate. However, not every legal, tax or business publication will automatically satisfy this condition.

A standard product description, email, internal instruction or working meeting summary will not require a label solely because generative AI was used in its preparation.

The AI Act provides an exemption where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication.

A company relying on this exemption should be able to demonstrate:

  1. who reviewed the content;
  2. the scope of the review;
  3. whether the facts, sources and legal basis were checked;
  4. who approved the final version;
  5. who holds responsibility for publication.

Automatically generating a text, reading it superficially and publishing it without genuine substantive verification may not be sufficient to rely on the exemption. Purely formal checks, such as spell-checking or grammatical correction, are not regarded as human review or editorial control.

Newsletter getsix® Information Service
Stay a step ahead of the changes
Tax, labour law, HR and payroll in Poland — the key updates delivered to your inbox before they take effect.
Tax, labour law, HR and payroll in Poland — key updates delivered to your inbox.
Subscribe  →

How should AI-generated content be labelled?

A label should be clear, visible, accessible to the recipient and presented no later than the first exposure to the material. The AI Act does not prescribe one mandatory statement for every type of content.

The form of disclosure should be adapted to the content and the publication channel.

Type of contentExample disclosure
Realistic image“Image generated using artificial intelligence”
Materially altered photograph“This photograph has been modified using AI”
VideoNotice at the beginning of the video and in its description
Synthetic voice“This recording contains an AI-generated voice”
Chatbot“You are speaking with a virtual assistant powered by AI”
Deepfake“This material has been artificially generated or manipulated”
Text concerning public-interest mattersNotice displayed directly with the publication or in an editorial note

The disclosure should accurately reflect how the technology was used. Where AI generated only the voice, the company should not claim that the entire video was created using artificial intelligence.

A vague statement that material was prepared using modern technologies will also be insufficient. Recipients should be able to understand which element was generated or materially modified.

For artistic, satirical, fictional or creative content, the disclosure may be presented in a manner that does not impair the display or enjoyment of the work. This does not, however, provide a complete exemption from disclosure.


How do a provider’s duties differ from a company’s duties as a deployer?

A system provider is primarily responsible for the technical marking of content. A company using the tool as a deployer may be responsible for providing a clear disclosure that is visible to the recipient. These are separate obligations.

A provider of a system generating text, images, video or audio should ensure that the output is marked in a machine-readable format and can be detected as artificially generated or manipulated.

Technical solutions may include:

  • metadata;
  • watermarks;
  • file provenance information;
  • cryptographic solutions;
  • mechanisms enabling the automated detection of synthetic content.

A company publishing the material should not remove this information during editing, exporting, compression or file transfers.

At the same time, retaining technical metadata alone may not be sufficient where Article 50 requires information that can be understood by a person. Recipients should not have to use specialist software to determine the origin of the material.


Who is responsible for labelling content: the company or the marketing agency?

The identity of the system deployer is not determined solely by who physically operates the AI tool. It also depends on whose authority, responsibility and control the system is used under and on whose behalf it is operated.

Where an agency or freelancer uses AI on behalf of a company, in accordance with the company’s instructions and under its responsibility and control, the company may remain the deployer. Where the agency acts independently, in its own name and under its own control, the agency may itself be the deployer. The allocation of responsibilities should be clearly defined in the contract.

In practice, a brand should not assume that all responsibility automatically rests with the contractor. Publishing misleading material may also create risks under consumer law, unfair competition rules, copyright law, image rights or the contract concluded with the agency.

The contract with the contractor should specify:

  • whether the contractor may use generative AI;
  • which systems may be used;
  • who determines whether the material requires a label;
  • who adds the label;
  • whether metadata must be retained;
  • who approves the content before publication;
  • who is responsible for incorrect labelling;
  • how the parties will respond after a breach is identified.

Can a company voluntarily label all AI-generated content?

A company may adopt a standard that is broader than the minimum requirements of the AI Act. This can simplify internal procedures and reduce the risk of employees incorrectly classifying particular materials.

However, labelling every item indiscriminately may also cause problems. Where the same label is applied to all materials regardless of AI’s actual role, recipients may stop paying attention to it.

A better approach may be to establish several levels of disclosure, for example:

  • “Content generated by AI”;
  • “Content partially generated by AI”;
  • “Content materially modified using AI”;
  • “Text prepared with AI assistance and subject to editorial review”.

This approach provides recipients with information that accurately reflects how the technology was used.


How should companies in Poland prepare for the new obligations?

Before 2 August 2026, companies should inventory their AI use cases, establish content-classification rules and appoint people responsible for approving AI-assisted materials.

1. How can the company identify all AI use cases?

The assessment should not be limited to officially purchased systems. Employees may use publicly available tools to create graphics, edit texts, prepare presentations or generate voices.

The inventory should cover at least:

  • marketing;
  • sales;
  • customer service;
  • recruitment and HR;
  • internal communications;
  • legal departments;
  • procurement;
  • IT;
  • agencies and subcontractors.

2. How should AI use cases be classified by obligation?

Companies should distinguish between systems that:

  • communicate with customers;
  • generate content;
  • modify photographs and recordings;
  • recognise emotions;
  • use biometric data;
  • produce publications concerning matters of public interest.

Each category is subject to different rules and may require a different disclosure.

3. What should an AI content-assessment matrix include?

The person approving a material should answer several basic questions:

  1. Did AI generate or materially modify the material?
  2. Does the content resemble a real person, object, place or event?
  3. Could the recipient regard it as authentic?
  4. Does the material inform the public about a matter of public interest?
  5. Has it been reviewed by a person?
  6. Who holds editorial responsibility?
  7. Has the technical provenance information been retained?

4. How should standard AI labels be prepared?

The company should prepare approved statements for the formats it uses most frequently. Employees should not have to create a new disclosure independently each time.

The internal standard should specify:

  • the wording of the disclosure;
  • where it must be placed;
  • its minimum visibility;
  • when it must be displayed;
  • accessibility requirements;
  • how the disclosure should be documented.

5. How should the publication-control process work?

AI-generated materials should not pass directly from an AI tool to a public communication channel.

The process should include:

  • substantive review;
  • a legal review in higher-risk cases, supported where necessary by legal services in Poland;
  • verification of copyright and image rights;
  • assessment of the labelling obligation;
  • approval of the final version;
  • retention of a copy of the published material.

6. How should contracts and internal policies be updated?

The company’s AI policy should explain when employees may use generative tools and what information they must provide to the person responsible for approving publication.

Contracts with contractors should require them to disclose:

  • the tool used;
  • the extent of AI involvement;
  • the elements generated or modified;
  • the safeguards applied;
  • the technical markings retained.

7. How should human review be documented?

Documentation does not have to involve preparing an extensive formal report for every social media post. It should nevertheless make it possible to establish who reviewed the content and who approved its publication.

Evidence may consist of an entry in a content management system, an approval record, a comment in a project-management tool or retained correspondence.


Should companies follow the EU Code of Practice?

Adherence to the Code of Practice is voluntary, but it may make it easier to demonstrate compliance with AI-generated content labelling obligations.

The Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026. It contains separate commitments for system providers and organisations deploying AI.

On 8 July 2026, the European Commission concluded that the Code adequately covers the obligations arising under Article 50(2), (4) and (5). Adherence does not, however, constitute conclusive evidence of full compliance. A company remains responsible for correctly implementing the relevant measures.

A business that does not sign the Code may implement its own measures. It must nevertheless be prepared to demonstrate that those measures are adequate and effective.


What penalties apply for breaching the transparency obligations?

A breach of the obligations under Article 50 may result in an administrative fine of up to EUR 15 million or up to 3% of the company’s total worldwide annual turnover for the preceding financial year, whichever is higher.

For small and medium-sized enterprises, the maximum fine is determined by the lower of the fixed monetary amount and the turnover-based percentage.

When determining the sanction, the authority should consider factors including:

  • the nature and duration of the infringement;
  • the number of people affected;
  • the damage caused;
  • the size of the company;
  • whether the infringement was intentional or negligent;
  • the level of cooperation with the authority;
  • the organisational and technical measures implemented;
  • the actions taken to mitigate the consequences.

The maximum fine will not automatically be imposed for every missing label. However, an absence of procedures, repeated infringements or the deliberate publication of misleading materials may increase the risk of sanctions.


What do the AI Act obligations mean for foreign companies operating in Poland?

Foreign companies should verify whether their global AI policies also cover the way content is created and published by their Polish subsidiary, branch or local team.

Risks may arise where:

  • the parent company supplies ready-made materials without information about AI use;
  • the local team modifies global campaigns;
  • an external agency generates materials without the company’s knowledge;
  • different subsidiaries apply inconsistent labels;
  • metadata is removed during translation, export or file conversion;
  • responsibility for publication on the Polish market has not been assigned.

A central policy should therefore be supplemented by a local approval process, a register of AI tools and rules governing cooperation with agencies and subcontractors operating in Poland.


On 24 July 2026, the President of Poland signed the Act on Artificial Intelligence Systems, establishing the national framework for supervising compliance with the AI Act. The legislation provides for the creation of the Commission for the Development and Security of Artificial Intelligence, which will be responsible, among other matters, for market surveillance, conducting inspections and proceedings, and enforcing the applicable AI rules. The President’s signature does not mean that the Commission has already begun operating. The Act must first enter into force, and the new authority must be formally appointed in accordance with the procedure laid down in the legislation.


Summary

From 2 August 2026, the obligations arising under Article 50 of the AI Act will become part of companies’ day-to-day management of content and communications in Poland.

Businesses should review, in particular, their chatbots, generated images, product and property visualisations, synthetic voices, video materials and publications concerning matters of public interest. Not every item created using AI will require a label. Companies must nevertheless have a process that identifies materials subject to disclosure, assigns responsibility and retains evidence of appropriate human review.

If you have any questions regarding this topic or if you are in need for any additional information – please do not hesitate to contact us:

Ask a question »

CUSTOMER RELATIONSHIPS DEPARTMENT

ELŻBIETA<br/>NARON - GROCHALSKA

ELŻBIETA
NARON-GROCHALSKA

Head of Customer Relationships
Department / Senior Manager
getsix® Group
pl en de

***

This publication is non-binding information and serves for general information purposes. The information provided does not constitute legal, tax or management advice and does not replace individual advice. Despite careful processing, all information in this publication is provided without any guarantee for the accuracy, up-to-date nature or completeness of the information. The information in this publication is not suitable as the sole basis for action and cannot replace actual advice in individual cases. The liability of the authors or getsix® are excluded. We kindly ask you to contact us directly for a binding consultation if required. The content of this publication iis the intellectual property of getsix® or its partner companies and is protected by copyright. Users of this information may download, print and copy the contents of the publication exclusively for their own purposes.

Our Recommendations

Our Memberships

Our Certification

Wojskowe Centrum Normalizacji Jakości I KodyfikacjiTÜV NORDTÜV RHEINLAND

Our Partnerships

Competencies