This article explains Poland’s decision to centralise AI Act enforcement in a single national authority, compares that approach with other Member States, and provides practical next steps and a checklist for counsel operating across the EU.
Poland chooses single centralised AI regulator status at a moment when most of the European Union is moving in the opposite direction. As the EU AI Act moves from statute to supervised reality across 2026, the practical question for cross-border operators is no longer only what the rules require but who will hold the file in each Member State. Poland’s answer is unusually clear: a single, dedicated body, the Commission for the Development and Safety of Artificial Intelligence, known by its Polish acronym KRiBSI, designated as the national authority for AI Act supervision.
That contrasts with the sectoral, distributed enforcement models emerging in much of Europe, and it changes how in-house and external counsel should map notifications, investigations and inspections for AI systems placed on the Polish market.
Poland chooses single centralised AI regulator as its structural response to the EU AI Act, concentrating AI-specific supervision in one institution rather than dispersing it across finance, health, transport and other sectoral supervisors. For companies used to navigating a patchwork of regulators, this offers something rare: a single, predictable domestic point of contact for AI-related supervision in one of Europe’s largest markets.
Many Member States are taking a different route. Rather than build a new central body, they are layering AI Act supervision onto existing sectoral regulators, so that the authority responsible for a given AI system depends on the sector in which it is deployed. The result is a more fragmented enforcement architecture in which the same product may face different supervisors, different technical cultures and different response times depending on where and how it is used.
The immediate operational question for multinational legal teams is therefore not primarily about substantive obligations, those flow from the EU AI Act itself and are broadly uniform, but about enforcement geography. Which authority will investigate a complaint about your high-risk system in Poland, and how does that differ from Germany, Denmark or Finland? Understanding that map is now a near-term compliance priority, and Poland’s centralised model is a clear reference point for how a single-regulator approach works in practice.
The EU AI Act (Regulation (EU) 2024/1689) is the Union’s horizontal framework for artificial intelligence, adopting a risk-based structure that scales obligations to the potential harm a system may cause. It applies across sectors and, like other EU product-safety-style regimes, relies on national authorities to supervise the market while EU-level bodies coordinate consistency. The European Commission’s regulatory framework page sets out the scope, obligations and enforcement mechanisms that Member States must give effect to domestically. The Regulation entered into force in 2024, with its obligations applying in stages across the subsequent transition periods.
Three concepts drive most enforcement questions:
The Act relies on two national roles that recur throughout this analysis. The market surveillance authority supervises AI systems on the market, investigates non-compliance, requests documentation and can order corrective measures. The notifying authority is responsible for the designation and oversight of the conformity assessment bodies that verify high-risk systems. Member States must designate these authorities and ensure they cooperate, both domestically and with EU-level structures, such as the European Artificial Intelligence Board and the Commission’s AI Office, that promote consistent application across the internal market. Because each Member State designates its own authorities, the identity of the responsible regulator is a jurisdiction-by-jurisdiction question, precisely the fragmentation that Poland’s single-regulator model seeks to avoid at home.
Poland’s implementing legislation establishes KRiBSI, the Commission for the Development and Safety of Artificial Intelligence, and designates it as the national authority for AI Act supervision. The Sejm passed Poland’s Act on artificial intelligence in 2026, following a drafting process that ran through late 2025 and early 2026. Rather than distribute AI supervision across the existing constellation of sectoral regulators, the Polish approach concentrates primary supervisory functions in this dedicated body. That is the essence of why Poland chooses single centralised AI regulator status: one institution is intended to hold the file for AI Act supervision across the Polish market.
Counsel should confirm the final numbering, structure and commencement provisions against the enacted text as published in the Dziennik Ustaw (the Polish Journal of Laws).
As the designated authority, KRiBSI is expected to carry the core supervisory toolkit contemplated by the AI Act: receiving and investigating complaints, requesting technical documentation and logs, examining conformity, and ordering corrective or restrictive measures where systems do not comply. Concentrating these powers in a single commission is designed to build specialist institutional capacity for AI supervision rather than spreading thin expertise across many bodies. Independent policy analysis of the Polish model has framed this centralisation as a deliberate attempt to close the “enforcement gap” that arises when regulators lack the dedicated resources and technical depth to supervise complex AI systems.
Centralisation does not mean isolation. AI systems are deployed in regulated sectors, banking, health, energy, transport, where sectoral regulators hold deep domain knowledge and their own supervisory mandates. Poland’s model therefore contemplates cooperation between KRiBSI and these sectoral bodies, so that AI-specific supervision sits alongside, rather than displaces, sector-specific supervision. In practice, this is the pressure point counsel should watch: the effectiveness of a single AI regulator depends heavily on how cleanly it coordinates with sectoral supervisors, how information is shared, and how jurisdictional overlaps are resolved. Where Poland chooses single centralised AI regulator arrangements, the coordination mechanisms, cooperation agreements, referral protocols and information-sharing channels, become the operational backbone of the system.
The direction of travel is set, but counsel should treat the precise operational start date and the full suite of guidance as matters to confirm against the enacted text and KRiBSI’s own communications. Poland has also been associated with proposals, floated at EU level, concerning the phasing of the penalty regime for high-risk AI systems, reflecting a broader European debate about whether newly established authorities and newly regulated businesses need more transition time before financial sanctions bite. The final implementing law text and regulator guidance remain the authoritative reference for exact timelines, and legal teams should verify these rather than rely on early summaries.
The significance of Poland’s choice becomes clearer against the wider European picture. Many Member States are not building a single AI regulator. Instead, they are assigning AI Act supervision to existing sectoral or national authorities, meaning the responsible supervisor depends on the sector or context in which an AI system operates. This distributed approach leverages existing regulatory capacity but produces a more complex enforcement map for operators.
By mid-2026, the state of implementation across the Union was uneven. A number of Member States had national AI implementing measures already in force, while others were still moving legislation through their parliaments. Only a limited group had designated both their market surveillance and notifying authorities, indicating that designation of the responsible regulators was still incomplete across much of the Union at that point. For cross-border operators, this means that in several jurisdictions the practical question of “who holds the file” did not yet have a settled answer. Counsel should verify the current position for each Member State against official national sources rather than rely on general summaries.
The practical takeaway is a mapping exercise. For each Member State where a company places or deploys AI systems, counsel must identify: whether a national implementing law is in force; which body is the designated market surveillance authority; which is the notifying authority; and how those bodies coordinate with sectoral regulators. In a centralised jurisdiction, that map has one clear node. In a sectoral jurisdiction, it may have several, and the correct node depends on the use case.
The table below sets out the operational differences between Poland’s centralised model and the sectoral approach adopted across much of the EU. These are structural characteristics rather than value judgements; each model carries trade-offs for operators.
| Feature | Centralised (Poland: KRiBSI) | Sectoral (many Member States) |
|---|---|---|
| Point of contact for operators | Single dedicated authority for AI supervision | Multiple authorities depending on sector and use case |
| Speed and consistency of decisions | Potential for consistent AI-specific decisions from one body | Risk of divergent approaches across regulators |
| Sector-specific technical knowledge | Concentrated AI expertise; relies on cooperation for sector depth | Deep sector knowledge held by existing supervisors |
| Administrative burden on operator | Lower, one relationship to manage domestically | Higher, multiple relationships and touchpoints |
| Notification path for high-risk systems | Coordinated through the central authority | Depends on designated authority per sector |
| Coordination with EU bodies | Single national interlocutor for EU-level cooperation | Coordination distributed across several national bodies |
| Appeal and judicial review pathways | Channelled through the central authority’s decisions | Varies by which regulator issued the decision |
| Likely resource constraints | Capacity concentrated but must scale to full market | Spread across bodies with competing priorities |
For operators, the centralised model reduces the domestic coordination burden: there is one authority to engage, one channel for notifications and information requests, and a single locus for supervisory decisions. That predictability is valuable for compliance planning and for building a stable regulatory relationship.
The sectoral model, by contrast, brings deep domain expertise, a health regulator understands clinical context, a financial supervisor understands systemic risk, but at the cost of complexity. The same AI system used across sectors may face more than one supervisor, and consistency across those supervisors is not guaranteed. Where Poland chooses single centralised AI regulator supervision, that fragmentation risk is internalised and managed through inter-agency cooperation rather than exported to the operator.
Neither model is inherently superior; the difference matters most for how legal teams allocate resources. A centralised jurisdiction rewards investment in one strong regulatory relationship; a sectoral jurisdiction demands a broader, use-case-driven mapping of responsible authorities.
The following prioritised checklist translates the enforcement architecture into concrete actions. It is structured by time horizon so that legal and compliance teams can sequence work sensibly.
Because Poland chooses single centralised AI regulator supervision, the engagement plan for the Polish market is comparatively streamlined, one authority, one relationship. The complexity lies in reconciling that with sectoral jurisdictions elsewhere in the group’s footprint.
The EU AI Act provides for a graduated administrative penalty regime, with the most serious infringements attracting the highest sanctions. Enforcement is administered nationally by the designated authorities, subject to the procedural safeguards of the relevant Member State.
In Poland, penalty administration falls within the remit of the centralised authority, giving operators a single domestic locus for both supervision and sanction. Poland has been linked to proposals concerning the phasing of penalties, reflecting a wider European conversation about transition time for new regulators and regulated entities alike. Counsel should confirm the exact penalty timeline and the applicable maximum amounts against the final implementing law and any KRiBSI guidance rather than relying on early commentary, as the applicable dates and any transitional relief are matters for the enacted text.
New authorities and sectoral supervisors alike tend to concentrate early enforcement where the stakes are highest and public interest is clearest. Commentators expect early attention to focus on areas such as public procurement, healthcare and critical infrastructure, where high-risk AI systems intersect directly with safety and fundamental rights. Likely investigation triggers include complaints from affected individuals, serious incidents, and gaps in conformity documentation surfaced during routine supervision. The likely practical effect of a centralised model is that priority-setting is coordinated within a single body, whereas in sectoral systems enforcement priorities may vary by regulator.
To build an accurate pan-EU enforcement map, corporate legal teams should send a consistent set of questions to local counsel in each Member State where AI systems are placed or deployed. Standardising the questions makes the answers comparable across jurisdictions.
Poland chooses single centralised AI regulator supervision at a time when much of Europe is dispersing AI Act enforcement across sectoral bodies, and that divergence is the practical story counsel must act on. For the Polish market, the immediate answer to “who holds the file” is clear: KRiBSI. Elsewhere, the answer depends on jurisdiction, sector and the state of national implementation. The task now is to build an accurate enforcement map, align notification and documentation workflows to the responsible authority in each country, and open constructive dialogue with regulators before an incident forces the conversation. Global Law Experts supports cross-border teams with jurisdictional briefings and regulator-readiness reviews to turn this fragmented enforcement landscape into a manageable compliance plan.
posted 7 minutes ago
posted 22 minutes ago
posted 38 minutes ago
posted 47 minutes ago
posted 52 minutes ago
posted 52 minutes ago
posted 58 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
No results available
Find the right Legal Expert for your business
Send welcome message