LEGAL ALERT: AI Act – What Businesses Need to Know Before August 2, 2026

Dear Sir or Madam,

For many months, 2 August 2026 was regarded as the deadline for the full application of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, known as the AI Act. However, this situation has changed due to the so-called Digital Omnibus for AI – a regulation amending the AI Act as part of the EU’s simplification package (Omnibus VII), which was finally adopted by the Council of the EU on 29 June 2026, following approval by the European Parliament on 16 June 2026, with publication in the Official Journal of the EU expected before 2 August. In practice, the most onerous obligations have been postponed by a dozen or so months; however, some provisions will come into force on 2 August 2026 without any changes. You can read below about exactly what is coming into force, who it applies to, and what the further timetable looks like.

Who is affected by the AI Act?

The AI Act is primarily aimed at providers of AI systems and at entities using these systems – including those outside the European Union, provided that the outputs of the system are used within the EU. Importantly, the transparency obligations coming into force on 2 August 2026 also apply to businesses that do not develop AI themselves but merely use off-the-shelf tools – in particular chatbots and generative AI used to create marketing, graphic or audio content.

What has the Omnibus Directive changed?

The Digital Omnibus does not alter the core principles of the AI Act – the risk-based approach, the catalogue of prohibited practices and the regime for general-purpose AI (GPAI) models remain in place. However, the amendment, which comes into force on 27 July 2026, postpones the application of the most onerous obligations, namely the provisions concerning high-risk AI systems.

This postponement covers the areas most relevant to the majority of business clients, including: recruitment and staff management, credit scoring, education, biometric identification and critical infrastructure. However, this is a deferral, not a waiver of the obligations, so it is worth using the time gained to prepare, as compliance assessment and proper implementation may take up to several months.

What comes into force on 2 August 2026?

The key element that comes into force on 2 August 2026 without any deferral is the transparency obligations set out in Article 50 of the AI Act (paragraphs 1, 3 and 4). In practice, these mean:

  • Disclosure of interactions with AI – entities providing chatbots and conversational assistants must inform users that they are conversing with an artificial intelligence system, not a human;
  • Labelling synthetic content and deepfakes – any entity using AI to generate or manipulate images, audio, video or text is obliged to clearly and explicitly disclose that the content was created or modified using AI;
  • Disclosure regarding emotion recognition and biometric categorisation – individuals subject to such analysis must be informed in advance, in accordance with the GDPR.

What does the full timetable look like?

It is worth organising your calendar, as the AI Act is being implemented in stages, and the Digital Omnibus has only amended part of it:

  • 2 February 2025 (in force) – prohibited practices (Article 5) and the obligation to develop AI literacy;
  • 2 August 2025 (in force) – obligations for general-purpose AI (GPAI) models, as well as the supervisory framework and provisions on penalties;
  • 2 August 2026 – transparency obligations under Article 50; the obligation for providers to automatically label synthetic content (Article 50(2)) for new systems;
  • 2 December 2026 – labelling of AI-generated content for systems placed on the market before 2 August 2026 (transitional period) and a new prohibition under Article 5 concerning systems generating CSAM and non-consensual intimate images (so-called ‘deepnude’ and ‘nudifier’ applications);
  • 2 August 2027 – deadline for Member States to establish testing environments for AI systems;
  • 2 December 2027 – obligations for high-risk systems listed in Annex III (stand-alone);
  • 2 August 2028 – obligations for high-risk systems listed in Annex I (embedded in products).

The Act on AI Systems

At the same time, the national Act on Artificial Intelligence Systems was finalised, designed to ensure the implementation of the AI Act in Poland. The Sejm passed it on 11 June 2026, the Senate adopted it on 25 June 2026, and on 24 July 2026 the Act was signed by the President of the Republic of Poland. The market supervisory body will be the Commission for the Development and Safety of Artificial Intelligence (KRiBSI) – a specialised, central body authorised, amongst other things, to carry out inspections, impose sanctions, withdraw systems from the market and issue binding individual opinions, providing businesses with certainty regarding the legality of planned implementations.

It should be borne in mind, however, that KRiBSI will not be fully operational as of 2 August 2026 – the appointment of its chairperson is part of a procedure lasting several months, involving the Sejm and the Senate, which will be initiated once the Act comes into force. This does not, however, alter the legal situation for businesses: as an EU regulation, the AI Act is directly applicable, regardless of the pace of domestic work or the composition of the supervisory body.

What penalties are in store?

Severe penalties are provided for breaches of the AI Act. The maximum fine – in the case of prohibited practices – may amount to €35 million or 7 per cent of global annual turnover, whichever is higher. By way of comparison, this threshold is higher than the maximum penalties provided for under the GDPR. However, the Polish legislator has introduced an interesting provision for cooperating entities, allowing for a reduction in the penalty of up to 90 per cent. Therefore, even in the event of an error, appropriate preparation and conduct can significantly improve an organisation’s legal position.

What does this mean for your organisation?

Despite the deferral of obligations for high-risk systems, we recommend that you take preparatory steps now, in particular:

Carry out an inventory of all AI tools and systems in use – both internal and those provided by third parties;

Classify systems according to the AI Act categories;

Implement transparency mechanisms by 2 August 2026 – including notifications regarding interactions with chatbots and labelling of AI-generated content;

Use the time gained to develop compliance documentation and processes for high-risk systems, rather than postponing them until 2027.

Summary

The Digital Omnibus for AI – effective from 27 July 2026 – has provided businesses with some relief regarding the most demanding obligations for high-risk systems, postponing them to 2027 and 2028. However, 2 August 2026 remains a key compliance deadline – on this date, the transparency obligations under Article 50 come into force, which in practice affect many companies using chatbots or generative AI. A properly planned preparatory process allows these requirements to be treated not as a burden, but as part of a structured corporate governance framework for AI.

If you are interested in an analysis of the AI Act’s impact on your business, or require support in classifying the systems you use and implementing transparency obligations, we are at your disposal.

Kind regards

KONTAKT

Magdalena Patryas Partner, Katowice

E: magdalena.patryas@pl.Andersen.com
T: +48 32 731 68 84
M: +48 502 392 419

Kamil Kozioł Senior Manager, Katowice

E: kamil.koziol@pl.Andersen.com
T: +48 32 731 68 50

Contact form

    News