Poland

Poland

Law Over Borders Comparative Guide: Artificial Intelligence Law Guide

29 Sep 2026
Artificial Intelligence Law Guide Artificial Intelligence Law Guide

Poland’s artificial intelligence (AI) market is transitioning from early experimentation to broader commercial and institutional deployment. The domestic ecosystem is supported by a strong technology talent base, a sizeable digital services sector, growing business demand for automation and data-driven tools, and increasing public-sector interest in AI-enabled services.

From a legislative perspective, Poland does not yet have a mature body of AI-specific domestic law comparable to a standalone national AI code. The Polish AI legal environment is currently driven primarily by EU law, especially the EU Artificial Intelligence Act (“EU AI Act”), as well as by generally applicable Polish laws in areas such as civil liability, criminal law, consumer protection, competition, intellectual property, employment, data protection, cybersecurity and sector-specific regulation. Poland-specific issues therefore often arise not from AI-specific legislation, but from domestic legal features that affect AI deployment in practice, such as the scope of Polish consumer protection rules, including certain protections afforded to sole proprietors acting outside the professional character of a given transaction.

The main legislative development to monitor is the Polish Act on AI Systems, intended to support the domestic application and enforcement of the EU AI Act. The key institutional element is the planned establishment of the Commission for the Development and Safety of Artificial Intelligence (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji) as the core Polish AI supervisory authority.

There is currently no AI-specific constitutional framework in Poland. AI systems are assessed under the general constitutional and human rights framework applicable to public authorities, private actors and regulated sectors. In practice, the most relevant issues are likely to arise where AI affects privacy, personal data, equality and non-discrimination, freedom of expression, consumer rights, employment, access to services, due process or access to justice.

Poland is also subject to the broader international and European human rights framework. The key instruments relevant to AI include:

  • Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law; the Convention has been signed by the EU.
  • International Covenant on Civil and Political Rights;
  • International Covenant on Economic, Social and Cultural Rights;
  • European Convention on Human Rights; and
  • Charter of Fundamental Rights of the European Union;

These instruments do not create a Poland-specific AI regime, but they provide the fundamental rights baseline against which AI use may be assessed. In particular, AI use may engage rights to privacy and data protection, equality and non-discrimination, freedom of expression and information, effective remedy, fair trial, workers’ rights and protection of vulnerable groups.

Polish law does not currently provide for a separate AI-specific intellectual property (IP) regime. AI-related issues are therefore assessed under the general IP framework, including patent law, copyright law, trade secrets law, unfair competition law and contractual arrangements.

There are no material Poland-specific AI patent rules. Patent protection is governed primarily by the Industrial Property Law.

Pure AI algorithms, models or software “as such” are unlikely to be patentable, because Polish patent law excludes computer programs from the concept of patentable inventions. However, an AI component may form part of a broader patentable technical invention, for example where AI is embedded in an electro-mechanical device and the claimed invention satisfies the general patentability criteria.

There are no material Poland-specific copyright rules dedicated to AI-generated works. Copyright protection is governed by the Act on Copyright and Related Rights. Under Polish law, a protected work must be a fixed manifestation of creative activity of individual character. As copyright is linked to human creativity, purely AI-generated output should not, in itself, qualify as a copyright-protected work.

This does not exclude protection where a human subsequently makes creative changes to AI-generated material or creatively selects, arranges or combines AI-generated elements. In such cases, protection should extend only to the human creative contribution, that is the modified or creatively arranged output, not to the AI-generated material as such. A prompt may also be protected as a literary work if it independently meets the statutory originality threshold, although short, functional or technical prompts will often not do so.

Trade secrets are protected in Poland under the Act on Combating Unfair Competition. A trade secret covers technical, technological, organisational or other business information with economic value that is not generally known or easily accessible to persons normally dealing with such information, provided that the holder has taken reasonable steps to keep it confidential.

The unlawful acquisition, disclosure or use of another party’s trade secrets constitutes an act of unfair competition. Such breaches may also give rise to criminal liability. This is directly relevant to AI because model weights, training datasets, prompts, system architecture, source code, evaluation methods, business workflows, customer data and internal AI governance materials may all qualify as trade secrets if properly protected.

In practice, trade secrets, confidential information and know-how are typically protected through non-disclosure agreements (NDAs), confidentiality clauses in framework agreements, project agreements and/or cooperation arrangements. In AI projects, these provisions should expressly cover the use of protected information in AI tools and workflows, including restrictions on uploading confidential information, client data, proprietary datasets, source code or non-public technical materials to public or third-party AI systems, unless the relevant confidentiality, data security and permitted-use terms have been verified and contractually accepted.

Poland does not yet have a developed body of final, reported AI-specific IP judgments. The most notable pending matter concerns alleged AI voice cloning of Polish voice-over artist Jarosław Łukomski. According to public reporting, Mikrofonika (the company that represents the artist in these proceedings) filed a claim against JFC POLSKA before the Regional Court in Warsaw alleging that JFC POLSKA used an AI-generated imitation of Łukomski’s voice in advertising without Łukomski’s or Mikrofonika’s knowledge. Public reports indicate that the claimants seek, among other remedies, PLN 50,000 as compensation for non-pecuniary harm, PLN 102,000 for unjust enrichment, an apology and cessation of the alleged infringements. Public reporting indicates that the proceedings are ongoing; therefore, the final legal reasoning and practical impact remain to be monitored.

Poland, as an EU Member State, applies the General Data Protection Regulation (GDPR) as the core legal framework for personal data processing. There is no separate Poland-specific general data law dedicated to AI training or AI development. Therefore, where AI-related data use involves personal data, the key issue is compliance with the GDPR, including the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

For AI training purposes, the controller must identify an appropriate legal basis for processing. Depending on the use case, this may include consent or processing necessary for the performance of a contract, where the relevant processing is genuinely necessary. Legitimate interests may also be considered, but this requires a balancing test. If special categories of data are processed, additional GDPR conditions must also be met. AI training or deployment may also require a data protection impact assessment if a particular type of processing is likely, given its nature, scope, context, and purposes, to result in a high risk to the rights or freedoms of natural persons.

The relevant GDPR assessment must be made case by case, taking into account the specific dataset, data subjects, purpose, source of data, model architecture, risks and safeguards.

The principal data protection regulation applicable in Poland is the General Data Protection Regulation. The Polish supervisory authority (Data Protection Authority) is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).

The GDPR is supplemented in Poland by the Act on Personal Data Protection. The Polish Act is not a separate substantive data protection code replacing the GDPR. It primarily operationalises the GDPR in the Polish legal order and regulates institutional, procedural and enforcement matters, including certification and codes of conduct, the national supervisory authority, proceedings concerning infringements, inspections, European administrative cooperation, civil liability, criminal liability and administrative fines (values arising from the GDPR).

Poland has adopted the Act on Open Data and Re-use of Public Sector Information, which implements the EU Directive on open data and the reuse of public sector information.

As a general rule, public sector information is made available or provided for re-use free of charge, subject to statutory exceptions. Fees may apply, for example, where preparation or provision of information in the manner or format requested requires additional costs. Re-use may also be restricted where required by law, including due to personal data protection, privacy, trade secrets, intellectual property rights or other legally protected secrets.

In Poland, biometric data is primarily regulated under the GDPR and is treated as a special category of personal data. This means that processing is generally prohibited unless the applicable GDPR conditions are met, including in particular the relevant Article 9 GDPR conditions.

Voice data and facial images are not automatically special-category biometric data in every context. However, where they are resulting from specific technical processing and are processed for the purpose of unambiguously identifying a natural person, they will generally qualify as biometric data and attract the higher GDPR standard. This is particularly relevant for facial recognition, voice recognition, speaker identification and biometric access control.

Poland does not currently have a general AI-specific domestic statute addressing algorithmic bias or AI-driven discrimination as a distinct legal category. AI-related bias and discrimination risks are therefore assessed under generally applicable rules.

Employment is a key practical area. The Polish Labour Code provides for equal rights of employees performing the same duties and prohibits any direct or indirect discrimination in employment, including on grounds such as sex, age, disability, race, religion, nationality, political beliefs, trade union membership, ethnic origin, belief, sexual orientation, fixed-term or indefinite-term employment, and full-time or part-time employment. These rules may apply where AI tools are used in recruitment, candidate screening, work allocation, employee monitoring, performance assessment, promotion, remuneration or termination processes.

Poland also has the Act on the Implementation of Certain EU Provisions on Equal Treatment. It is not AI-specific, but it may be relevant where AI-supported processes affect, for example, vocational training, access to or performance of business or professional activity, membership in professional or employment-related organisations, social security, healthcare, education, or publicly offered services, goods, rights or energy.

Poland does not currently impose general AI-specific domestic technology infrastructure requirements. In particular, there is no general requirement to host AI systems, training datasets, model weights or computing infrastructure in Poland. Cloud-based and cross-border AI deployments are generally possible, subject to applicable cybersecurity, data protection, confidentiality, outsourcing, sectoral and contractual requirements.

Technology infrastructure obligations may nevertheless arise under general or sector-specific cybersecurity and resilience regimes. The key domestic framework is the Act on the National Cybersecurity System, as amended in connection with the Polish implementation of NIS 2. The Act defines the organisation of the national cybersecurity system, the tasks and obligations of entities forming part of that system, the rules of supervision and control, the scope of the Polish Cybersecurity Strategy, and the national plan for responding to large-scale cybersecurity incidents and crisis situations. Its purpose is to ensure cybersecurity at national level, including uninterrupted provision of services by key and important entities, by achieving an appropriate level of security of information systems used to provide those services and by ensuring incident handling.

For AI businesses, the key point is that Polish infrastructure-related obligations will usually not apply because a system is AI-based as such, but because the provider, deployer, customer, infrastructure or use case falls within a regulated category. This may be the case, for example, where AI is deployed in public administration, financial services, healthcare, energy, telecommunications, and digital services.

Poland does not currently have AI-specific domestic rules on algorithmic collusion, AI-driven dark patterns or other AI-specific anti-competitive conduct. However, the use of AI may fall within the general Polish and EU competition law framework if it facilitates or implements conduct that would otherwise qualify as anti-competitive, such as price fixing, market sharing, limiting market access or abuse of dominance. The fact that a practice is performed or supported by an algorithm or AI system does not change the legal test: the assessment will focus on whether the conduct has as its object or effect the restriction of competition or constitutes an abuse of dominance.

AI-related market conduct may qualify as an act of unfair competition under the Act on Combating Unfair Competition or as an unfair commercial practice under the Act on Counteracting Unfair Commercial Practices. Under Polish law, an act of unfair competition is an act contrary to law or good practice, if it threatens or infringes the interest of another entrepreneur or customer. An unfair commercial practice is a market practice used by an entrepreneur towards consumers which is contrary to good practice and materially distorts or may materially distort the economic behaviour of the average consumer before, during or after concluding a contract concerning a product.

The main regulatory risk is potential intervention by the President of the Office of Competition and Consumer Protection (Prezes Urzędu Ochrony Konkurencji i Konsumentów, UOKiK). If AI-enabled conduct infringes collective consumer interests, UOKiK may impose administrative fines on the entrepreneur and, in certain cases, on management-level individuals. UOKiK may also review consumer contract terms and assess whether they contain prohibited abusive clauses.

The key Polish statute is the Act on Competition and Consumer Protection. It covers, in particular, restrictive practices, practices infringing collective consumer interests, prohibited clauses in consumer contracts and anti-competitive concentrations, where such conduct has or may have effects in Poland.

For AI businesses, there is no separate Polish antitrust test for AI. The relevant assessment will depend on the function and market impact of the AI system.

Polish law does not recognise AI agents as having legal personality, legal capacity or capacity to perform legal acts in their own name. Similarly, an AI agent cannot itself act as an attorney-in-fact or legal representative.

This does not mean that actions executed through AI agents are legally irrelevant. If a user deploys an AI agent to negotiate, place an order, accept terms, conclude a transaction or otherwise interact with a counterparty, the legal effects will generally be assessed as effects attributable to the person or entity using the AI agent. In practice, the key issues will be, for example, consumer protection, the terms governing the use of the relevant AI agent, and contractual allocation of responsibility for errors or unauthorised actions performed through the AI agent.

There are currently no Poland-specific sectoral regulations dedicated specifically to “agentic AI” as a distinct legal category.

Agentic AI may nevertheless fall within general sectoral regulatory frameworks, depending on the relevant use case, product or service. This assessment would not usually be based on the fact that the AI is “agentic” as such, but rather on whether the AI system itself, or the product or service in which it is embedded, qualifies under existing sector-specific rules. This may be relevant, for example, in regulated areas such as financial services, healthcare, transportation, cybersecurity, consumer-facing digital services or defence.

Polish law does not currently provide for a separate AI-specific product liability regime. AI-related liability is therefore assessed under general civil liability, product liability, product safety and consumer protection rules, depending on the nature of the AI system and the relevant harm.

Polish law does not currently contain a single AI-specific product liability regime. Existing liability rules apply depending on the role of the AI system, the contractual setup, the type of harm and whether the AI is embedded in a physical product.

As a starting point, the Polish Civil Code provides for general tort liability.

AI may also be relevant under Polish consumer law. The Act on Consumer Rights does not create a general AI product liability regime. This is relevant for B2C contracts. The related conformity rules are addressed in Section 8.2, below.

The Act on Supervision of General Product Safety implements the EU General Product Safety Regulation (GPSR). It applies to products within the scope of the GPSR, that is products placed or made available on the consumer market. In practical terms, this framework will usually be relevant to AI where AI is embedded in, or functionally connected with, a physical consumer product (this particular product will be subject to this regime). Standalone AI software or AI-as-a-service will not usually be treated as a product under this product-safety framework. The President of the Office of Competition and Consumer Protection is the authority competent for supervision of general product safety, while regional Trade Inspection authorities are competent for product safety inspections.

Under the Polish Civil Code, liability for damage caused by a dangerous product is generally structured as a strict/risk-based liability regime. A producer acting within the scope of its business is liable for damage caused to any person by a dangerous product, irrespective of fault.

A product is a movable item, even if incorporated into another item; animals and electricity are also treated as products. Accordingly, under the current Civil Code framework, standalone AI software, SaaS or an AI model as such will not always fit within the statutory product definition. The regime is most relevant where AI is embedded in, or forms part of, a movable product, for example a device, machine, vehicle, robot or other AI-enabled hardware.

A product is dangerous if it does not provide the safety that may reasonably be expected, taking into account its normal use. The assessment is made by reference to the circumstances existing at the time the product was placed on the market. A product is not considered dangerous merely because a similar improved product was placed on the market later.

The injured party must establish the damage and an adequate causal link between the dangerous nature of the product and the harm suffered. The regime may cover personal injury and damage to property, although property damage is subject to statutory limitations.

A separate strict/risk-based regime may also arise under the statutory warranty for defects (rękojmia) in the Polish Civil Code. Under this regime, the seller is liable to the buyer if the sold item has a defect (i.e. if it is not in conformity with the contract). In an AI context, this regime will primarily be relevant where the subject matter of the sale is a tangible item, such as an AI-powered device or another movable product incorporating AI functionality.

This regime is mainly relevant to B2B/non-consumer sales, because consumer-facing rules on conformity of goods, goods with digital elements, digital content and digital services are now addressed separately under the Act on Consumer Rights. Polish law also extends certain consumer-type protections to natural persons conducting sole business activity.

In B2B sales, statutory warranty is often contractually excluded or limited. The Civil Code allows the parties to extend, limit or exclude warranty liability, although an exclusion or limitation is ineffective if the seller fraudulently concealed the defect. In sales between entrepreneurs, the buyer may also lose warranty rights if it fails to inspect the item in the time and manner customary for items of that type and to notify the seller of the defect without delay; if the defect becomes apparent only later, notification must be made without delay after it is discovered.

Accordingly, while statutory warranty may be relevant to AI-enabled products sold in B2B transactions, in practice its role will often depend on the contract. AI supply, implementation and technology B2B contracts should therefore expressly regulate conformity criteria, acceptance testing, maintenance, updates, defects, remedies, exclusions and liability caps.

A further strict/quasi-strict regime applies under the Act on Consumer Rights in B2C relations. For these purposes, certain consumer protections also apply to a natural person conducting sole business activity where the contract is directly connected with that person’s business but is not of a professional nature for that person.

Consumer conformity regimes may be highly relevant for AI-enabled consumer products and digital AI services, but the precise assessment will depend on the structure of the relevant offering. The above is only a high-level overview and does not exhaust all statutory requirements or specific conditions applicable to goods, goods with digital elements, digital content and digital services. For specific AI deployments, the statutory conformity criteria, update obligations, consumer information duties, remedies, complaint-handling rules and rules on unilateral changes should be verified in detail and reflected in consumer-facing terms, product information, update policies, complaints procedures and other consumer communications.

As noted in Section 8.1, above, the Act on Supervision of General Product Safety is only relevant to AI in specific cases.

In the context of AI-related products, inspections may include requests for documents, technical specifications, data or information necessary to assess whether the product is safe and compliant, including access to embedded software where necessary for that assessment.

Where there are justified circumstances indicating that a product presents a serious risk and immediate action is necessary to protect consumers’ health or life, the President of UOKiK may prohibit, by immediately enforceable decision, making the product available on the market, offering it or presenting it until the proceedings are completed.

There are currently no known final, reported Polish cases, settlements or clearly established litigation trends concerning AI product liability as such.

AI-related disputes in Poland are more likely, at this stage, to arise in adjacent areas such as personal rights, image or voice imitation, copyright, data protection, unfair competition, consumer protection or contractual liability. However, these should not yet be treated as AI product liability precedents. The position may evolve as AI systems become more frequently embedded in consumer products, medical devices, vehicles, industrial systems or other regulated products, and as the new EU product liability framework (i.e. Directive 2024/2853 on liability for defective products) is implemented in Poland

The key domestic legislative development is the proposed Act on Artificial Intelligence Systems.

The draft Act provides for the organisation and operation of the Polish AI market supervision framework. Its main elements include the designation of the Commission for the Development and Safety of Artificial Intelligence (Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji) as the Polish AI market surveillance authority, rules on proceedings concerning infringements of the AI Act and the Polish Act, accreditation and notification of conformity assessment bodies, administrative fines, supervisory controls, individual opinions and general explanations, regulatory sandboxes, and measures supporting the development of AI systems in Poland.

The bill is currently subject to the ordinary Polish parliamentary legislative process. The next steps include work in the Sejm, including committee review, followed by the Senate stage and Presidential review. The legislative intention appears to be adoption in 2026; however, the final timing remains uncertain and will depend on the progress of parliamentary work and the President’s position, including the possibility of a veto or referral for constitutional review. The draft itself proposes that the Act enter into force 14 days after promulgation, subject to narrow statutory exceptions.

Poland’s main government strategy document is the Policy for the Development of Artificial Intelligence in Poland until 2030, prepared by the Ministry of Digital Affairs. The document sets out the government’s strategic direction for building a coordinated, trustworthy AI ecosystem supporting economic growth and social wellbeing.

The strategy focuses on AI infrastructure, access to data, open-source models, skills, public-sector implementation, business adoption and trustworthy AI. It expressly refers to the development of national AI infrastructure, including AI factories and participation in the AI gigafactory programme, support for open data and Polish open-source models, including PLLuM and Bielik, and AI deployment in public administration and business.

Can we use AI in this project?

In most ordinary business use cases, yes — provided that the use case has been properly cleared. Polish law does not impose a general prohibition on using AI in business operations. The first step is to identify what type of AI system is intended to be used and for what purpose. If the use case falls within a prohibited AI practice under the EU AI Act, it should not be implemented.

For non-prohibited AI use cases, the assessment should focus on contractual and organisational constraints. In particular, it should be verified whether the agreement with the client, customer, supplier or other counterparty prohibits AI use, restricts the use of third-party tools, imposes confidentiality or data-security obligations, or requires prior notice, consent or disclosure.

The organisation’s internal policies should also be checked. Some companies restrict or prohibit the use of public AI tools for specific categories of data, projects or business functions. In practice, AI use should be approved for the relevant project scope, data category and tool type before deployment, especially where confidential information, personal data, client materials, source code, regulated activities or consumer-facing outputs are involved.

Do we need to label AI-generated content?

There is no general Polish-law obligation to label every item of AI-generated content. However, labelling may be legally required, or at least strongly advisable, depending on the type of content and the use case.

The clearest case is deepfake content under the EU AI Act. A “deep fake” means an AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. Deployers of AI systems that generate or manipulate image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated.

Labelling or disclosure obligations may also arise under other regimes. For example, AI-generated product reviews should not be presented as consumer reviews if they are not genuine consumer opinions. Similarly, AI-generated summaries or rankings of consumer reviews should be designed and described so that consumers are not misled; in practice, it is often advisable to state that the summary was generated by AI. Depending on the facts, Polish consumer protection, unfair competition, advertising or sector-specific rules may also require transparency, even where the content is not a deepfake.

Can we use client data, business data or copyrighted materials to train or fine-tune AI?

Only after verifying the legal basis and contractual rights. For personal data, GDPR requirements must be assessed, including the legal basis, transparency, purpose limitation, data minimisation, security and, where relevant, DPIA requirements. For confidential information, trade secrets, know-how, source code, client data or proprietary datasets, the starting point is the NDA, framework agreement, project agreement or applicable internal policy.

For copyrighted materials, it is necessary to verify whether the relevant licence, assignment or other contractual basis covers AI-related uses, such as training, fine-tuning, text and data mining, creation of datasets, use in prompts or generation of synthetic content. In Poland, copyright agreements should also properly address the relevant fields of exploitation, because transfer or licensing of economic copyrights requires specification of the fields of exploitation covered by the agreement.

It should also be checked whether the intended use may rely on a statutory copyright exception, including text and data mining, where applicable. This assessment should include whether the possibility of invoking such permitted use has been duly excluded in cases where the relevant exception permits such exclusion (e.g. opt out from text data mining (TDM)). In addition, some materials may fall outside copyright protection or be freely usable because they are in the public domain (taking into account the author’s moral rights, which do not expire) or are not protected by copyright, for example certain official materials such as legislative texts. However, this should be assessed carefully, as editorial versions, databases, translations or compilations may still be protected.

Publicly available content should not be treated as automatically free for AI training or fine-tuning. Even where copyright does not prevent use, confidentiality, database rights, terms of service, personal data protection, trade secrets, contractual restrictions or sector-specific duties may still apply

Who is liable if AI produces an unlawful output or causes harm?

The AI system itself is not a legal person and does not bear liability. Liability will generally be assessed by reference to the natural or legal person that develops, deploys, integrates, sells, operates, configures or uses the AI system. The use of AI does not, as such, create a liability shield for the business using it.

Polish law does not currently provide for a separate AI-specific liability regime. Depending on the facts, exposure may arise under general tort liability, contractual liability, consumer protection, product liability, product safety, data protection, IP, unfair competition, personal rights or sector-specific regulation. The relevant analysis will depend on the role of the AI system, the contractual setup, the type of harm, the affected party and whether the AI is supplied as a standalone tool, a service, digital content or as part of a physical or regulated product.

For example, if AI causes harm because of negligent use, general tort fault-based liability may be relevant. If the issue arises in an AI implementation, liability will usually be assessed under the relevant contract, including the scope of obligations, performance parameters, standard of care, disclaimers, liability caps and causation.

Criminal liability may also be relevant where the conduct involving the AI output constitutes a criminal offence under generally applicable Polish criminal law. This may be the case, for example, where a user intentionally uses AI-generated content or an AI-generated action to commit an offence, facilitate unlawful conduct, impersonate another person, defraud a counterparty, disclose protected information or otherwise cause legally relevant harm. If AI operates at the initiative of a user, and the user subsequently relies on or disseminates an unlawful output, the user’s own liability may need to be assessed independently.

From a risk-management perspective, contracts should clearly allocate responsibility for AI outputs, data quality, testing, human oversight, prohibited uses, security, incident response, third-party claims, regulatory compliance and limitations of liability. Internal AI governance should define who may approve AI use cases, who is responsible for monitoring outputs, when human review is required and how incidents or harmful outputs should be handled.

Can an AI agent enter into contracts or take legally binding actions on our behalf?

Not in its own name. Polish law does not recognise AI agents as having legal personality, legal capacity or capacity to perform legal acts independently. An AI agent also cannot itself act as an attorney-in-fact or legal representative.

That does not mean that actions performed through an AI agent are legally irrelevant. If a company deploys an AI agent to negotiate, place an order, accept terms, conclude a transaction, send confirmations, make bookings or otherwise interact with a counterparty, the legal effects will generally be assessed as attributable to the person or entity using the AI agent.

In practice, the key issues are whether the AI agent acted within the intended scope of use, whether the counterparty could reasonably rely on the interaction, what the applicable platform or tool terms provide, and how responsibility for erroneous or unauthorised actions is allocated contractually. Consumer protection rules may also be relevant where the AI agent interacts with consumers.

There are currently no Poland-specific sectoral regulations dedicated specifically to “agentic AI” as a separate legal category. However, agentic AI may fall within existing sectoral frameworks depending on the relevant use case, product or service. This is not because the AI is “agentic” as such, but because the AI system itself, or the product or service in which it is embedded, may qualify under existing rules, for example in financial services, healthcare, transportation, cybersecurity, consumer-facing digital services or defence.