Artificial intelligence in European companies is entering a new phase. The AI Act — the world’s first comprehensive legal framework regulating the use of artificial intelligence — is being implemented gradually, with another important set of rules taking effect on 2 August 2026.
Although companies using high-risk systems, including solutions applied in recruitment and employee management, have until 2 December 2027 to comply with all the requirements, it would be a mistake to assume that preparations can be postponed. Companies should already be organising the way they use AI, improving employees’ skills and preparing for the next stages of the regulation’s implementation.
On 24 July, Poland’s Artificial Intelligence Systems Act was signed into law. The legislation determines how the EU AI Act will operate in Poland. Without these national provisions, enforcing the new obligations would be practically impossible.
“This is an important step in the development of artificial intelligence in Poland. It is not only about supporting new technologies, but also about improving our understanding and oversight of AI systems,” said Krzysztof Gawkowski, Poland’s Minister of Digital Affairs.
“These regulations create favourable conditions for the development of artificial intelligence while also increasing the safety of its users,” the Deputy Prime Minister added.
The AI Act has been in force since August 2024, but its provisions are being applied in stages. From 2 August 2026, new requirements will take effect in areas including the transparency of AI systems, the obligation to ensure that people using artificial intelligence have an appropriate level of competence, rules governing general-purpose AI models and provisions concerning supervision and enforcement of the regulation.
Deepfakes Under Scrutiny: New Online Transparency Rules
What will this mean in practice?
From the beginning of August, organisations will be required, among other things, to disclose when a particular image, video or audio recording has been generated using artificial intelligence.
The new rules primarily concern so-called deepfakes. They do not prohibit the publication of such materials, but require them to be clearly labelled. This will allow audiences to recognise that the content has been created or altered by AI.
According to European Commission guidance, the obligation applies to organisations using AI systems, including companies, public institutions and agencies that control how those systems are deployed.
This marks a clear shift: EU regulations are no longer merely setting the direction of future change, but are becoming part of the everyday operations of companies and organisations.
A Faulty AI Decision? A New Commission Will Handle User Complaints
The new Polish law also establishes institutions responsible for supervising compliance and introduces measures intended to support the development of AI technologies.
The Commission for the Development and Security of Artificial Intelligence will be able to receive complaints concerning the operation of AI systems.
These may include situations in which an algorithm makes an incorrect or discriminatory decision, for example when assessing a person’s creditworthiness, or when an AI-based tool fails to perform in line with the capabilities declared by its provider.
In the case of systems posing a risk to life or health, the Commission will be able to order their withdrawal from the market.
The Commission will also be responsible for issuing individual opinions for businesses. This will allow companies to obtain an assessment of whether a particular solution complies with the law before introducing it.
“The first months of the Commission’s operation will be extremely important for building businesses’ confidence in the new system,” said Eliza Turkiewicz, Director of the Digital Market Department at the Lewiatan Confederation.
“From the outset, the Commission should operate efficiently and predictably and remain open to dialogue. It will also be important to recruit experts who understand both the legislation and the practical ways in which AI systems are used.”
This is particularly important for employers and HR companies, which will become subject to high-risk system requirements in December 2027, during the next stage of the AI Act’s implementation.
These requirements will apply to systems used in areas such as recruitment and CV screening.
The extended timetable for the full implementation of the AI Act gives the HR sector more time to adapt to the new rules and renegotiate agreements with software providers in order to ensure that systems are secure and compliant.
Recruitment Under Particular Scrutiny: 68% of Organisations Have Experienced AI-Related Data Leaks
According to a 2025 Metomic report cited by Security Magazine, 68% of companies have experienced security incidents in which employees shared sensitive information with AI tools such as ChatGPT.
Analyses cited by hcamag.com, an industry website focused on human resources management, indicate that HR data was found in 82% of the data breaches examined, making it an attractive target for AI-assisted attacks.
It is therefore no coincidence that the European Commission, in its “Navigating the AI Act” questions and answers section, stated that AI-based solutions used for certain HR functions may be classified as high-risk systems.
This applies to tools used for employee management and access to self-employment, including systems that target job advertisements, analyse and filter applications, or evaluate candidates.
Organisations using such solutions must comply with AI Act requirements concerning transparency, human oversight, data quality, cybersecurity and the ability to explain how a particular recommendation or decision was reached.
In HR, Decisions Always Affect People
“HR is not marketing. It is a specific area of every company’s operations that primarily deals with people,” said Grzegorz Sadziak, Cloud Solution Architect and cybersecurity expert at Supremo.
“Artificial intelligence in HR does not merely analyse processes or results. It has a direct impact on people — their careers, income, self-esteem and future lives.
“That is precisely why the requirements relating to cybersecurity and data protection must be particularly stringent in this area.”
Compliance with the AI Act Is a Shared Responsibility
The obligation to provide information is also important in this context.
In its “Navigating the AI Act” guidance, the European Commission emphasises that if a high-risk system is used in the workplace, the organisation must inform employees and their representatives in advance.
If the system is intended to make or support decisions concerning an individual, that person must also be informed.
The AI Act also provides for a right to obtain an explanation when the output of a high-risk system has been used in making a decision that produces legal effects.
AI May Recommend, but It Should Not Make the Final Decision
For this reason, the EU AI Act strengthens the principle of human oversight over technology.
The European Commission explains that a company using a high-risk system must appoint one or more people capable of overseeing it, monitoring how it operates and responding to identified risks.
“The AI Act is a moment for companies comparable to the introduction of the GDPR. The period of experimenting with AI without clear rules is coming to an end,” said Kamil Jankowski, Director of Marketing and Communications at Gi Group Holding.
“This is particularly important for HR departments because AI is increasingly being used to support recruitment, candidate assessment and workforce management.
“Companies that prepare early will gain not only a regulatory advantage, but also a reputational one.”
Artificial intelligence can support recruiters by organising information, analysing skills and preparing recommendations, but it should not take over the role of the person responsible for the final decision.
“A well-designed process should use artificial intelligence to support analysis while still leaving room for assessing context, nuances and factors that the system is unable to interpret correctly,” said Zuzanna Spaltenstein-Kotas, data protection and compliance expert at Gi Group Holding.
Violations of the AI Act, including breaches of transparency requirements, may result in fines of up to EUR 15 million or 3% of a company’s total worldwide annual turnover, whichever amount is higher.
Source: ManagerPlus.pl





