The AI Act applies in stages, and the deadlines moved in 2026. See how Kancelaria Prawna Skarbiec helps your company meet the new legal requirements for artificial intelligence.
The AI Act: what it means for businesses
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages. In July 2026 the calendar was amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), which postponed the requirements for high-risk systems. As the law stands today:
- the bans on prohibited practices have applied since 2 February 2025; two further prohibitions, covering AI-generated non-consensual intimate imagery and child sexual abuse material, apply from 2 December 2026;
- the requirements for general-purpose AI models have applied since 2 August 2025;
- the transparency obligations under Article 50 (informing users that they are interacting with an AI system, marking AI-generated or manipulated content) apply from 2 August 2026, and generative systems placed on the market before that date have until 2 December 2026 to implement machine-readable marking;
- the requirements for high-risk systems listed in Annex III (recruitment, creditworthiness assessment, education, critical infrastructure and other listed uses) apply from 2 December 2027, and for AI embedded in products covered by EU product safety legislation (Annex I) from 2 August 2028.
The postponement changes the dates, not the substance. For most companies the pressing questions are not the high-risk requirements at all, but the transparency duties, the prohibited practices, the AI literacy of staff, and the contractual and data protection issues raised by the AI tools already in daily use. Adaptation should therefore begin now. A systematic approach spreads the cost and the organisational effort over time and reduces the business risk that the new rules create.

Who is covered by the AI Act?
Check whether your company falls under the new rules.
The AI Act reaches a wide circle of organisations involved in developing, distributing and using artificial intelligence systems. It addresses five categories of operators: providers, who develop AI systems and place them on the market; deployers, who use AI systems in the course of their business; importers and distributors, who bring AI systems into the EU and supply them onward; manufacturers of products that integrate AI systems; and authorised representatives acting on behalf of providers established outside the Union. The Regulation applies not only to operators established in the EU, but also to organisations outside the Union that offer AI systems in the EU or whose systems produce output that is used in the EU. Outside its scope remain AI systems used exclusively for military and national security purposes, activity limited to scientific research and development, open-source solutions (with limitations, in particular for high-risk systems and general-purpose models) and purely personal, non-professional use.
AI Act implementation: our services
Comprehensive support in implementing the requirements of the AI Act, provided by Kancelaria Prawna Skarbiec.
Regulatory sandboxes
We help you use regulatory sandboxes, which allow innovative AI solutions to be tested in a safe environment under the supervision of the regulator.
AI systems audit
We carry out a complete inventory and analysis of the AI systems used in your organisation and classify each of them by risk level under the AI Act.
Documentation
We prepare every document the AI Act requires, including the register of AI systems and the monitoring procedures.
Oversight and monitoring
We help you implement effective human oversight of AI systems and procedures for responding to anomalies and irregularities.
Staff training
We train management and the staff responsible for AI systems, building the competences your organisation needs and meeting the AI literacy duty under Article 4 of the Regulation.
Negotiations with AI suppliers
We analyse and negotiate contracts with suppliers of AI systems, securing a clear allocation of responsibility and compliance with the new rules.
Regulatory sandboxes: what are they?
A regulatory sandbox is a controlled testing environment set up by a regulator, in which companies and innovators can test new products, services or business models with certain temporary regulatory concessions, but under the regulator’s supervision. Under Article 57 of the AI Act, each Member State must have at least one AI regulatory sandbox operational at national level; following the July 2026 amendment, the deadline is 2 August 2027.
In the context of the AI Act, a regulatory sandbox makes it possible to:
- test innovative AI solutions in real or near-real conditions;
- experiment with new technologies without the full regulatory requirements applying immediately;
- open a dialogue between innovators and regulators at an early stage of product development;
- gather experience that can help adjust the rules.
Regulatory sandboxes under the AI Act allow:
- faster market entry for innovations;
- verification of compliance in a controlled environment;
- a better understanding of the potential risks of new technologies;
- less legal uncertainty for companies developing new AI solutions.
Categories of AI systems: risk levels
At the heart of the AI Act is a classification of AI systems by risk level. Learn the categories and the requirements the Regulation attaches to each of them.
The Regulation prohibits outright the use of systems deemed unacceptable, such as behavioural manipulation techniques or mass biometric surveillance in public spaces. Particularly strict requirements apply to high-risk systems, used among other things in recruitment, education and healthcare. These systems require a detailed conformity assessment, comprehensive technical documentation and continuous monitoring.
For most companies, however, the rules that matter are those on limited-risk systems such as chatbots and generative tools. Here the user must be told that they are interacting with an AI system, and AI-generated or manipulated content, including deepfakes, must be marked. Adapting to the new requirements calls for real investment in monitoring, documentation and staff training, but in the longer term the changes can bring measurable business benefits: greater client trust and new market opportunities.
Ask a lawyer
Tell us which AI tools your company uses, in which processes and for whose benefit. The answers determine whether the matter is a transparency duty, a high-risk classification, a supplier contract or a data protection question, and in what order to address them. Artificial intelligence is one of the areas of our practice in crypto and new technologies; we also compile materials on the law of artificial intelligence at prawo-ai-legal.pl/en/.
Legal status as at 21 September 2026. The text takes account of Regulation (EU) 2026/1744, in force since 27 July 2026.

