AI Legal landscape – how does the European Union regulate artificial intelligence?
AI Legal landscape – how does the European Union regulate artificial intelligence?
The growing scale of artificial intelligence applications and the emergence of new legal and social challenges have led to the adoption by the EU of the first comprehensive regulations governing AI. They are contained in Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, wider known as the AI Act. The vast majority of these provisions will become applicable as early as 2 August 2026. For most professional entities, this means the necessity to adapt the way of using AI systems to the new legal requirements, especially since the AI Act also provides for severe penalties for the infringement of its provisions.
In this article, the solutions adopted in the AI Act will be generally discussed, including basic definitions, the scope of application of the Regulation, obligations imposed on providers and users of AI systems, and the system of supervision over compliance with the new regulations.
What role does the AI Act play?
EU bodies recognized the need to regulate AI as some of the first public institutions in the world. The direction of the future legal framework was already outlined in 2020 within the EC White Paper on artificial intelligence. It indicated the direction of regulation, which was reflected in Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence. This Regulation determines, among others, the division of AI tools based on the degree of risk, prohibited practices, and obligations imposed on providers and users of AI models and systems. The AI Act also harmonises the procedure of AI technology governance at the Union and national levels, and determines the penalties that face entities failing to comply with the regulations.
The AI Act applies in stages. From February 2025, provisions concerning prohibited practices and introductory provisions (Chapters I and II) apply, and from August 2025, part of the regulations concerning general-purpose AI models and institutional supervision (Article 78 and Chapters III Section 4, V, VII, and XII with the exclusion of Article 101). The vast majority of the provisions will become applicable from 2 August 2026, however, recently enacted amendments to the AI Act postpone the entry into force of the provisions concerning high-risk systems (until 2 December 2027 and 2 August 2028, depending on the specificity of the system).
Also very significant remains the so-called Union soft law, which means documents explaining the ways of applying the AI Act. In the case of such a new and dynamically developing field as artificial intelligence, knowledge of Union codes and guidelines takes on a special significance. For example, the EC Guidelines on the definition of an AI system allow for a better understanding of which tools the AI Act regulates. For the obligation to label content, the Commission has provided not only Guidelines, but also a Code of Conduct, which is intended to make it easier for providers and those using AI to ensure compliance with the provisions. In practice, most of the obligations provided for in the Act have been supplemented by guidelines or Codes of Conduct. These documents, although they are not of a binding nature, in practice help in the interpretation of the AI Act provisions.
However, it must be remembered that to many situations related to the use of AI, other legal acts will apply in parallel. In particular, this concerns provisions in the field of copyright and personal data protection. A good example is also Article 4 of the DSM Directive 2019/790 establishing the „text and data mining” exception, which providers of AI models use to train models on copyright-protected works.
Who and what does the AI Act concern?
The AI Act determines both the material scope, meaning which technologies the regulation covers, and the personal scope, meaning who is obliged to comply with its provisions. Regulation (EU) 2024/1689 contains as many as 68 definitions due to the broad scope of the concept of artificial intelligence.
One of the key concepts is the definition of an AI system contained in Article 3(1) of the AI Act. According to it, an AI system is a machine-based system, possessing a certain degree of autonomy and adaptability, which on the basis of input data generates outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This definition is of fundamental importance for the application of the AI Act, which is why the European Commission published Guidelines on its interpretation.
However, a definition of an AI model will not be found in the Act. For the purposes of understanding AI tools, an AI model should be viewed as a technical component trained on data, which can be used in one or multiple AI systems. On the other hand, the concept of a general-purpose AI model is defined – these are models capable of performing a wide range of tasks and possible to integrate with many different systems or applications.
The circle of entities covered by the provisions has been specified in the collective concept of operators (Article 3(8) of the AI Act), which includes providers, deployers, product manufacturers, authorised representatives, importers, and distributors. Some of the AI Act obligations concern all operators, while others are directed straight to some of the mentioned entities.
From the perspective of most entrepreneurs, the most important will be the provisions referring directly or indirectly to deployers. These are natural or legal persons, public authorities, agencies, or other bodies using an AI system under their control. In the case of entities responsible for making AI systems available on the market, the AI Act distinguishes the role played by the provider (who develops or commissions the development of an AI system and places it on the market or puts it into service under its own name or trademark), the importer (who places on the Union market a system originating from a third country), and the distributor (who makes such a system available on the Union market).
The personal scope of the AI Act is therefore very broad and includes most entities using or making available AI systems. Equally broad is the material scope of the AI Act, which covers practically all the newest AI systems – from chatbots serving customers, through tools analyzing business data, up to generative AI systems creating texts, images, audio, and video materials.
Scope of obligations – division according to the degree of threat
The greatest novelty of the AI Act is the division of artificial intelligence systems according to the risk level. The scope of obligations that Regulation (EU) 2024/1689 imposes on providers and deployers of AI systems will depend on the risk category. The AI Act distinguishes four basic categories: general-purpose AI models (Chapter V), general-purpose AI models with systemic risk (Chapter V), high-risk AI systems (Chapter III), and prohibited AI practices (Chapter II).
The least rigorous obligations concern general-purpose AI models. Their providers are obliged, first and foremost, to maintain technical documentation, ensure compliance with copyright laws, and cooperate with the European Commission and competent authorities. In the case of models posing a systemic risk, the catalogue of obligations has been expanded to include systemic risk management, reporting of serious incidents, and ensuring an appropriate level of cybersecurity.
A separate chapter of the AI Act is dedicated to high-risk AI systems. High-risk AI systems can be divided into systems integrated with specific products listed in Annex I of the AI Act (including radio, dangerous toys, lifts) and standalone systems indicated in Annex III of the AI Act, meaning those used, among others, in biometrics, critical infrastructure, education, employment, and justice.
Extensive obligations have been imposed on high-risk AI systems regarding human oversight of the system, monitoring the system’s operation, reporting malfunctions, keeping logs, and conducting a fundamental rights impact assessment of the AI system.
Since February 2025, the most restrictive provisions regarding prohibited AI practices have been in force. They include, among others, systems applying subliminal or manipulative techniques, exploiting psychological vulnerabilities of persons (e.g. due to age, specific social situation), and those analyzing personal or personality traits leading to unfavourable treatment (so-called social scoring). Infringement of these provisions can lead to the imposition of an exceptionally high penalty, reaching as much as EUR 35,000,000 or 7% of the enterprise’s annual turnover.
Apart from obligations dependent on the level of risk, the AI Act also provides for a range of general requirements. From the perspective of most entities using AI, two of them are of particular importance: the obligation to develop AI literacy among staff (Article 4 of the AI Act) and transparency obligations, including the labelling of AI-generated content (Article 50 of the AI Act).
Article 4 of the AI Act formally applies from 2 February 2025, however, its wording and sense have been changed by the amendments provided for in the Regulation of the EP and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards simplifying the implementation of harmonised rules on artificial intelligence, known as the Digital Omnibus on AI. The amended provision will impose on providers and deployers an obligation to take measures aimed at supporting the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. This obligation is less restrictive than the previous one, which required ensuring the aforementioned literacy among employees. The scope of these measures should moreover be adapted to the experience, education, and knowledge of the employees – in practice, this obligation can be fulfilled, among others, through training, but also e-learning platforms or educational programs.
Moving on to transparency obligations, the provisions concerning the labelling of content generated or manipulated by AI, including content of a „deepfake” nature, require the greatest attention. This refers to AI-generated or manipulated images, audio, or video content that authentically or truthfully resembles existing persons, places, objects, or events.
In the draft Guidelines of the European Commission on the implementation of transparency obligations in relation to certain AI systems under Article 50 of the AI Act, the exact meaning of this definition has been further specified. The Commission indicates that for a given content to be considered a deepfake, it is irrelevant whether it actually misleads the recipients. Consequently, the obligation to label may also apply to materials that faithfully replicate reality. For example, a realistic image of a beverage can generated by AI will constitute a deepfake, even if it is indistinguishable from the actual product. For entities obliged to comply with Article 50 of the AI Act, the Code of Practice on transparency of AI-generated content will also be of importance. It determines the methods an entity can apply in order to ensure compliance with the regulations, including the proper way of labelling AI content.
Which authorities supervise the enforcement of the AI Act?
The AI Act creates mechanisms of control at both the Union and national levels. Article 64 of the AI Act establishes the EU AI Office, which, among others, monitors the effective implementation and enforcement of the obligations resulting from the AI Act, supports the development of codes of practice, and cooperates with the competent national authorities. At the national level, the AI Act imposes in Article 70 an obligation to designate at least one notifying authority and at least one market surveillance authority in each Member State.
In Poland, the implementation of Article 70 is addressed by the Act on Artificial Intelligence Systems, passed by the Sejm and awaiting the President’s signature. According to the provisions of the Act, the competences of the notifying authority will be vested in the Minister responsible for computerisation. He will be responsible for the development and application of the procedures necessary for the assessment, designation, and notification of conformity assessment bodies, and for their monitoring. Conformity assessment will be the process of demonstrating whether the requirements set out in Chapter III Section 2 in relation to a high-risk AI system have been met.
The market surveillance authority in Poland will be the Commission for the Development and Safety of Artificial Intelligence (KRiBSI). It exercises, in particular, market surveillance over high-risk systems (Article 74(3) of the AI Act), supports and monitors development in the area of AI research and application, and also issues rulings and decisions in cases concerning infringements of the AI Act. The Act clarifies that the Commission also has powers to impose administrative fines under the rules of Chapter XII of the AI Act.
What penalties does the AI Act provide for?
The AI Act provides for very high administrative fines for infringement of its provisions. Their amount depends on the type of infringement and can be specified as a fixed amount or a percentage of the total annual worldwide turnover of the enterprise.
The highest penalties, reaching EUR 35 million or 7% of turnover, are threatened for using prohibited AI practices. In turn, for the infringement of obligations related to the use of high-risk AI systems or the labelling of AI-generated content, entities may be imposed fines up to 15 million or 3% of turnover.
From the perspective of entrepreneurs, provisions concerning AI systems used in employment are of particular importance. These include, among others, solutions used in recruitment and selection of candidates, as well as AI systems supporting decision-making that affects the terms of employment relationships, such as promotions, termination of contracts, or employee performance evaluation.
Apart from the indicated penalties, it must be kept in mind that the Act on Artificial Intelligence Systems grants the national market surveillance authority (KRiBSI) competence to impose administrative fines also for non-compliance with other provisions of the AI Act. This concerns, among others, infringements of the obligation to take measures to ensure an appropriate level of AI literacy specified in Article 4 of the AI Act.
Practice in Member States
The AI Act constitutes the foundation of EU AI regulations, however, Member States are increasingly eager to decide to regulate certain legal issues on their own. A good example is Denmark, which is working on strengthening protection against deepfakes by extending protection similar to copyright to the digital use of image and voice. The aim of these changes is to provide natural persons with more effective tools to counteract the unauthorized use of their face or voice.
In Italy, on the other hand, a framework Act on AI was adopted, which provides, among others, for separate penalization of the illegal distribution of deepfakes, threatened with imprisonment from one to five years. A different direction has been taken in France, where in April 2026 the Senate adopted a draft Bill introducing a presumption of the use of protected works by providers of AI models and systems if the circumstances make such use probable. Although the draft has not yet been enacted, it may in the future affect disputes regarding copyright through a partial reversal of the burden of proof.
Soon, Poland will also join the states regulating AI in their own legal system. The Act on Artificial Intelligence Systems, awaiting the President’s signature, in the first place satisfies the requirements provided for by the AI Act by establishing the notifying authority (the Minister competent for computerisation) and the market surveillance authority (KRiBSI). The most important tasks related to issuing decisions and imposing fines belong to the latter authority. An interesting solution provided for in the Act is also the institution of the so-called settlement, enabling a reduction of the fine in exchange for cooperation with KRiBSI and the disclosure of the circumstances of the infringement.
Summary
The AI Act constitutes the first comprehensive system of artificial intelligence regulation in the world, however, it does not function in isolation from other provisions of law. Its application will require taking into account not only the AI Act itself, but also the case law, guidelines, and codes of the European Commission, as well as national regulations adopted by Member States. This means that entrepreneurs utilizing AI systems should monitor not only changes in the AI Act, but also the development of the practice of supervisory authorities and courts, which in the coming years will play a key role in the interpretation of new obligations.
Key legal acts:
- Acts and documents at the Union level:
-
- Regulation (EU) 2024/1689 of the European Parliament and of the Council – AI Act, https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
-
- Regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) – https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX:52025PC0836
-
- European Commission White Paper of 2020 – „White Paper on Artificial Intelligence: A European approach to excellence and trust”, https://commission.europa.eu/system/files/2020-02/commission-white-paper-artificial-intelligence-feb2020_en.pdf
-
- General-Purpose AI Code of Practice, https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
-
- European Commission Guidelines on the definition of an AI system, https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application
-
- European Commission Guidelines on prohibited AI practices, https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act
-
- European Commission Guidelines for providers of general-purpose AI models, https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models
-
- European Commission Code of Practice on transparency of AI-generated content, https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
-
- Draft European Commission Guidelines on the implementation of transparency obligations in relation to certain artificial intelligence systems under Article 50 of the Artificial Intelligence Act, https://digital-strategy.ec.europa.eu/pl/library/draft-guidelines-implementation-transparency-obligations-certain-ai-systems-under-article-50-ai-act
- National acts and initiatives of Member States
-
- Denmark – draft plans for protection against deepfakes through the right to voice and image, https://kum.dk/aktuelt/nyheder/bred-aftale-om-deepfakes-giver-alle-ret-til-egen-krop-og-egen-stemme
-
- Italy – Act No. 132/2025 concerning artificial intelligence, https://www.gazzettaufficiale.it/atto/serie_generale/caricaDettaglioAtto/originario?atto.codiceRedazionale=25G00143&atto.dataPubblicazioneGazzetta=2025-09-25
-
- France – draft Act on the presumption of the use of cultural content by AI providers, https://www.senat.fr/leg/ppl25-220.html
-
- Poland – draft Act on Artificial Intelligence Systems, https://legislacja.rcl.gov.pl/projekt/12390551
Zobacz też:
AI Legal landscape – jak Unia Europejska reguluje sztuczną inteligencję?
Tytuł: AI Legal landscape – jak Unia Europejska reguluje sztuczną inteligencję? Rosnąca skala zastosowań sztucznej inteligencji i pojawienie się nowych wyzwań prawnych oraz społecznych doprowadziły do przyjęcia przez UE pierwszych kompleksowych przepisów...
Przegląd orzecznictwa TSUE od 6.07 do 10.07.2026
Wyrok – 09/07/2026 – Anne Frank Fonds, Sprawa C‑788/24 – Sprawa dotyczyła pytań prejudycjalnych odnoszących się do pojęcia „publicznego udostępniania” w rozumieniu art. 3 ust. 1 Dyrektywy 2001/29 oraz do oceny skuteczności geoblokady jako środka technologicznego w...
Przegląd orzecznictwa TSUE od 29.06 do 03.07.2026
Attilah przeciwko EUIPO – Bella Tawziaa II i Groupe Bellakhdar, Sprawa T‑654/24 – Sprawa dotyczyła postępowania o unieważnienie unijnego znaku towarowego z powodu zgłoszenia dokonanego w złej wierze na podstawie art. 52 ust. 1 lit. b Rozporządzenia nr 207/2009. –...



