[codicts-css-switcher id=”346″]

Global Law Experts Logo
poland chooses single centralised ai regulator

Poland Chooses a Single Centralised AI Regulator As Most of Europe Splits AI Act Enforcement Across Sectors

By Global Law Experts
– posted 1 hour ago

This article explains Poland’s decision to centralise AI Act enforcement in a single national authority, compares that approach with other Member States, and provides practical next steps and a checklist for counsel operating across the EU.

Poland chooses single centralised AI regulator status at a moment when most of the European Union is moving in the opposite direction. As the EU AI Act moves from statute to supervised reality across 2026, the practical question for cross-border operators is no longer only what the rules require but who will hold the file in each Member State. Poland’s answer is unusually clear: a single, dedicated body, the Commission for the Development and Safety of Artificial Intelligence, known by its Polish acronym KRiBSI, designated as the national authority for AI Act supervision.

That contrasts with the sectoral, distributed enforcement models emerging in much of Europe, and it changes how in-house and external counsel should map notifications, investigations and inspections for AI systems placed on the Polish market.

Executive summary: what Poland’s centralised choice means for counsel

Poland chooses single centralised AI regulator as its structural response to the EU AI Act, concentrating AI-specific supervision in one institution rather than dispersing it across finance, health, transport and other sectoral supervisors. For companies used to navigating a patchwork of regulators, this offers something rare: a single, predictable domestic point of contact for AI-related supervision in one of Europe’s largest markets.

Many Member States are taking a different route. Rather than build a new central body, they are layering AI Act supervision onto existing sectoral regulators, so that the authority responsible for a given AI system depends on the sector in which it is deployed. The result is a more fragmented enforcement architecture in which the same product may face different supervisors, different technical cultures and different response times depending on where and how it is used.

The immediate operational question for multinational legal teams is therefore not primarily about substantive obligations, those flow from the EU AI Act itself and are broadly uniform, but about enforcement geography. Which authority will investigate a complaint about your high-risk system in Poland, and how does that differ from Germany, Denmark or Finland? Understanding that map is now a near-term compliance priority, and Poland’s centralised model is a clear reference point for how a single-regulator approach works in practice.

Quick primer: the EU AI Act, roles and timelines

The EU AI Act (Regulation (EU) 2024/1689) is the Union’s horizontal framework for artificial intelligence, adopting a risk-based structure that scales obligations to the potential harm a system may cause. It applies across sectors and, like other EU product-safety-style regimes, relies on national authorities to supervise the market while EU-level bodies coordinate consistency. The European Commission’s regulatory framework page sets out the scope, obligations and enforcement mechanisms that Member States must give effect to domestically. The Regulation entered into force in 2024, with its obligations applying in stages across the subsequent transition periods.

Core definitions that matter to enforcement

Three concepts drive most enforcement questions:

  • High-risk systems. These are AI systems that the Act treats as capable of significant impact on health, safety or fundamental rights. They carry the heaviest compliance burden, conformity assessment, technical documentation, risk management, logging and human oversight, and are a primary focus of market surveillance.
  • Provider. The entity that develops an AI system, or has it developed, and places it on the market or puts it into service under its own name or trademark. Providers bear the bulk of pre-market obligations.
  • Deployer. The entity using an AI system under its authority in a professional context. Deployers carry operational obligations, including appropriate use, monitoring and, for certain systems, transparency toward affected individuals.

Enforcement architecture under the AI Act

The Act relies on two national roles that recur throughout this analysis. The market surveillance authority supervises AI systems on the market, investigates non-compliance, requests documentation and can order corrective measures. The notifying authority is responsible for the designation and oversight of the conformity assessment bodies that verify high-risk systems. Member States must designate these authorities and ensure they cooperate, both domestically and with EU-level structures, such as the European Artificial Intelligence Board and the Commission’s AI Office, that promote consistent application across the internal market. Because each Member State designates its own authorities, the identity of the responsible regulator is a jurisdiction-by-jurisdiction question, precisely the fragmentation that Poland’s single-regulator model seeks to avoid at home.

Poland’s implementing law and KRiBSI: what the statute does

Poland’s implementing legislation establishes KRiBSI, the Commission for the Development and Safety of Artificial Intelligence, and designates it as the national authority for AI Act supervision. The Sejm passed Poland’s Act on artificial intelligence in 2026, following a drafting process that ran through late 2025 and early 2026. Rather than distribute AI supervision across the existing constellation of sectoral regulators, the Polish approach concentrates primary supervisory functions in this dedicated body. That is the essence of why Poland chooses single centralised AI regulator status: one institution is intended to hold the file for AI Act supervision across the Polish market.

Counsel should confirm the final numbering, structure and commencement provisions against the enacted text as published in the Dziennik Ustaw (the Polish Journal of Laws).

KRiBSI, powers, remit and organisational placement

As the designated authority, KRiBSI is expected to carry the core supervisory toolkit contemplated by the AI Act: receiving and investigating complaints, requesting technical documentation and logs, examining conformity, and ordering corrective or restrictive measures where systems do not comply. Concentrating these powers in a single commission is designed to build specialist institutional capacity for AI supervision rather than spreading thin expertise across many bodies. Independent policy analysis of the Polish model has framed this centralisation as a deliberate attempt to close the “enforcement gap” that arises when regulators lack the dedicated resources and technical depth to supervise complex AI systems.

Interaction with sectoral regulators

Centralisation does not mean isolation. AI systems are deployed in regulated sectors, banking, health, energy, transport, where sectoral regulators hold deep domain knowledge and their own supervisory mandates. Poland’s model therefore contemplates cooperation between KRiBSI and these sectoral bodies, so that AI-specific supervision sits alongside, rather than displaces, sector-specific supervision. In practice, this is the pressure point counsel should watch: the effectiveness of a single AI regulator depends heavily on how cleanly it coordinates with sectoral supervisors, how information is shared, and how jurisdictional overlaps are resolved. Where Poland chooses single centralised AI regulator arrangements, the coordination mechanisms, cooperation agreements, referral protocols and information-sharing channels, become the operational backbone of the system.

Timeline for designation and when enforcement begins

The direction of travel is set, but counsel should treat the precise operational start date and the full suite of guidance as matters to confirm against the enacted text and KRiBSI’s own communications. Poland has also been associated with proposals, floated at EU level, concerning the phasing of the penalty regime for high-risk AI systems, reflecting a broader European debate about whether newly established authorities and newly regulated businesses need more transition time before financial sanctions bite. The final implementing law text and regulator guidance remain the authoritative reference for exact timelines, and legal teams should verify these rather than rely on early summaries.

How other Member States are implementing enforcement

The significance of Poland’s choice becomes clearer against the wider European picture. Many Member States are not building a single AI regulator. Instead, they are assigning AI Act supervision to existing sectoral or national authorities, meaning the responsible supervisor depends on the sector or context in which an AI system operates. This distributed approach leverages existing regulatory capacity but produces a more complex enforcement map for operators.

Centralised versus sectoral, the split across Europe

By mid-2026, the state of implementation across the Union was uneven. A number of Member States had national AI implementing measures already in force, while others were still moving legislation through their parliaments. Only a limited group had designated both their market surveillance and notifying authorities, indicating that designation of the responsible regulators was still incomplete across much of the Union at that point. For cross-border operators, this means that in several jurisdictions the practical question of “who holds the file” did not yet have a settled answer. Counsel should verify the current position for each Member State against official national sources rather than rely on general summaries.

Notable national examples

  • Germany. Germany advanced its national implementing measures through its legislative process during 2026. Its approach reflects the more distributed European tendency, building on existing supervisory structures, rather than the single-body centralisation Poland has chosen. Counsel should confirm the current designation of the responsible German authorities before relying on it.
  • Denmark and Finland. Both have been reported among the Member States moving ahead on national AI implementation, each fitting within the broader pattern of building on existing institutional structures rather than creating a dedicated central AI regulator on the Polish model. The precise designated authorities should be verified against official national sources.

The practical takeaway is a mapping exercise. For each Member State where a company places or deploys AI systems, counsel must identify: whether a national implementing law is in force; which body is the designated market surveillance authority; which is the notifying authority; and how those bodies coordinate with sectoral regulators. In a centralised jurisdiction, that map has one clear node. In a sectoral jurisdiction, it may have several, and the correct node depends on the use case.

Comparison table: centralised (Poland/KRiBSI) versus sectoral enforcement

The table below sets out the operational differences between Poland’s centralised model and the sectoral approach adopted across much of the EU. These are structural characteristics rather than value judgements; each model carries trade-offs for operators.

Feature Centralised (Poland: KRiBSI) Sectoral (many Member States)
Point of contact for operators Single dedicated authority for AI supervision Multiple authorities depending on sector and use case
Speed and consistency of decisions Potential for consistent AI-specific decisions from one body Risk of divergent approaches across regulators
Sector-specific technical knowledge Concentrated AI expertise; relies on cooperation for sector depth Deep sector knowledge held by existing supervisors
Administrative burden on operator Lower, one relationship to manage domestically Higher, multiple relationships and touchpoints
Notification path for high-risk systems Coordinated through the central authority Depends on designated authority per sector
Coordination with EU bodies Single national interlocutor for EU-level cooperation Coordination distributed across several national bodies
Appeal and judicial review pathways Channelled through the central authority’s decisions Varies by which regulator issued the decision
Likely resource constraints Capacity concentrated but must scale to full market Spread across bodies with competing priorities

For operators, the centralised model reduces the domestic coordination burden: there is one authority to engage, one channel for notifications and information requests, and a single locus for supervisory decisions. That predictability is valuable for compliance planning and for building a stable regulatory relationship.

The sectoral model, by contrast, brings deep domain expertise, a health regulator understands clinical context, a financial supervisor understands systemic risk, but at the cost of complexity. The same AI system used across sectors may face more than one supervisor, and consistency across those supervisors is not guaranteed. Where Poland chooses single centralised AI regulator supervision, that fragmentation risk is internalised and managed through inter-agency cooperation rather than exported to the operator.

Neither model is inherently superior; the difference matters most for how legal teams allocate resources. A centralised jurisdiction rewards investment in one strong regulatory relationship; a sectoral jurisdiction demands a broader, use-case-driven mapping of responsible authorities.

Practical checklist for cross-border counsel and compliance teams

The following prioritised checklist translates the enforcement architecture into concrete actions. It is structured by time horizon so that legal and compliance teams can sequence work sensibly.

Notification and registry actions: what to file where

  • Immediate (first 30 days). Confirm, against the enacted Polish implementing law, that KRiBSI is the designated authority and identify the notifying authority relevant to any planned high-risk products. For every other Member State in scope, confirm whether the responsible authority has been designated and, if not, note the open question and monitor for updates.
  • Short term (1–3 months). Amend notification templates to reflect the correct authority in each jurisdiction, identify a local technical contact who can respond to information requests, and map the notification path for high-risk systems country by country.
  • Medium term (3–12 months). Test the information-request process, internally rehearse how quickly the organisation can produce technical documentation and logs, and confirm that the correct point of contact receives regulator correspondence without delay.

Audit and documentation checklist for high-risk systems

  • Maintain complete, up-to-date technical documentation for each high-risk system, in a form that can be produced promptly on request.
  • Ensure logging and record-keeping meet the Act’s requirements and are retained for the required periods.
  • Preserve conformity assessment evidence and the identity of the body that performed it.
  • Document risk-management measures, human oversight arrangements and post-market monitoring.
  • Update the data protection officer and information security lead on incident escalation paths, given the overlap between AI supervision and data protection obligations.

Engagement plan with national regulators and KRiBSI

  • Open a dialogue with the designated authority, in Poland, KRiBSI, before an incident forces one. Early engagement builds a constructive relationship and clarifies expectations.
  • In sectoral jurisdictions, identify each relevant supervisor by use case and understand how they coordinate on AI matters.
  • Prepare legal readiness for supervisory inspections: know the authority’s powers, the scope of documents it may request, and the deadlines for response.
  • Develop a remediation and dispute strategy in advance, including the correct appeal and judicial review routes for decisions of the responsible authority, and a plan for coordinating a response across affected Member States where a single product faces action in more than one jurisdiction.

Because Poland chooses single centralised AI regulator supervision, the engagement plan for the Polish market is comparatively streamlined, one authority, one relationship. The complexity lies in reconciling that with sectoral jurisdictions elsewhere in the group’s footprint.

Enforcement timeline, penalties and likely near-term scenarios

The EU AI Act provides for a graduated administrative penalty regime, with the most serious infringements attracting the highest sanctions. Enforcement is administered nationally by the designated authorities, subject to the procedural safeguards of the relevant Member State.

Penalty regime and administrative process

In Poland, penalty administration falls within the remit of the centralised authority, giving operators a single domestic locus for both supervision and sanction. Poland has been linked to proposals concerning the phasing of penalties, reflecting a wider European conversation about transition time for new regulators and regulated entities alike. Counsel should confirm the exact penalty timeline and the applicable maximum amounts against the final implementing law and any KRiBSI guidance rather than relying on early commentary, as the applicable dates and any transitional relief are matters for the enacted text.

Likely priority sectors and triggers for investigations

New authorities and sectoral supervisors alike tend to concentrate early enforcement where the stakes are highest and public interest is clearest. Commentators expect early attention to focus on areas such as public procurement, healthcare and critical infrastructure, where high-risk AI systems intersect directly with safety and fundamental rights. Likely investigation triggers include complaints from affected individuals, serious incidents, and gaps in conformity documentation surfaced during routine supervision. The likely practical effect of a centralised model is that priority-setting is coordinated within a single body, whereas in sectoral systems enforcement priorities may vary by regulator.

What multinational groups should ask their local counsel now

To build an accurate pan-EU enforcement map, corporate legal teams should send a consistent set of questions to local counsel in each Member State where AI systems are placed or deployed. Standardising the questions makes the answers comparable across jurisdictions.

Minimum information to request from local counsel

  • Is the national implementing law in force, and where is the authoritative text?
  • Which body is the designated market surveillance authority, and which is the notifying authority?
  • Is enforcement centralised in one body or distributed across sectoral regulators, and if distributed, which regulator supervises our specific use cases?
  • What are the notification requirements and the correct channel for high-risk systems?
  • What are the penalty timelines and any transitional measures?
  • What are the appeal and judicial review routes against decisions of the responsible authority?

Conclusion and next steps

Poland chooses single centralised AI regulator supervision at a time when much of Europe is dispersing AI Act enforcement across sectoral bodies, and that divergence is the practical story counsel must act on. For the Polish market, the immediate answer to “who holds the file” is clear: KRiBSI. Elsewhere, the answer depends on jurisdiction, sector and the state of national implementation. The task now is to build an accurate enforcement map, align notification and documentation workflows to the responsible authority in each country, and open constructive dialogue with regulators before an incident forces the conversation. Global Law Experts supports cross-border teams with jurisdictional briefings and regulator-readiness reviews to turn this fragmented enforcement landscape into a manageable compliance plan.

Sources

  1. European Commission, Regulatory framework on AI
  2. Blavatnik School of Government, University of Oxford, The AI Act’s enforcement gap
  3. Interface EU, Building a Centralised National AI Authority (Poland)
  4. Sejm of the Republic of Poland
  5. EUR-Lex, Regulation (EU) 2024/1689 (Artificial Intelligence Act)
  6. European Data Protection Board (EDPB)

FAQs

Who will enforce the EU AI Act in Poland?
KRiBSI, the Commission for the Development and Safety of Artificial Intelligence, is designated as the national authority for AI Act supervision under Poland’s implementing law. Sectoral authorities are expected to cooperate, but KRiBSI holds the primary supervisory functions. This is the practical meaning of the fact that Poland chooses single centralised AI regulator supervision rather than a distributed model.
No. The substantive obligations flow from the EU AI Act itself and are broadly uniform across Member States. Poland’s national law sets the institutional arrangements for enforcement, designating the responsible authority, and may address national procedural and transitional measures, but it does not rewrite the Act’s core requirements.
Check the national designation and any official notification guidance for each Member State. In Poland, notifications and supervisory interactions are coordinated through the centralised authority, KRiBSI. In sectoral jurisdictions, the responsible authority depends on the sector and use case, so the correct contact must be confirmed country by country.
Poland has been associated with proposals to phase the penalty regime, reflecting a broader European debate about transition time. The exact timelines should be confirmed against the final implementing law text and KRiBSI guidance rather than early summaries, as any transitional relief is a matter for the enacted statute.
Map the designated authorities in each Member State, confirm the local counsel position on who holds the file, update notification and documentation workflows to reflect the correct authority, and open a dialogue with the designated regulator. Because Poland chooses single centralised AI regulator supervision, the Polish leg of that map is comparatively straightforward, the complexity lies in reconciling it with sectoral jurisdictions.
legal due diligence companies saudi arabia
By Faisal A. Siddiqui

posted 30 minutes ago

new saudi companies lawkey changes founders
By Faisal A. Siddiqui

posted 32 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Poland Chooses a Single Centralised AI Regulator As Most of Europe Splits AI Act Enforcement Across Sectors

Send welcome message

Custom Message