EU AI Act Forces Companies to Review How Employees Use Artificial Intelligence

LAWEU AI Act Forces Companies to Review How Employees Use Artificial Intelligence
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

New requirements introduced as part of the European Union’s AI Act took effect on 2 August 2026, creating additional responsibilities for businesses that provide or use artificial intelligence systems.

The rules cover issues including transparency, disclosure of interactions with AI, machine-readable marking of synthetic content and the labelling of deepfakes and certain AI-generated publications.

According to legal experts, the new requirements, together with the obligations that will apply to high-risk systems from December 2027, will force companies to change the way they approach artificial intelligence. One of their most urgent tasks will be to identify and regulate how employees already use AI tools across the organisation.

“On 2 August, the main body of obligations under the EU AI Act became applicable. The transparency requirements are likely to affect the largest number of businesses, as they concern, among other things, the proper identification of interactions with artificial intelligence and certain AI-generated materials,” Michał Jeleń of the LEGALLY.SMART law firm told the Newseria news agency.

Article 50 of the AI Act establishes transparency obligations for providers and deployers of certain artificial intelligence systems, including interactive and generative AI tools, emotion-recognition systems, biometric categorisation technologies and deepfakes.

Not every AI-assisted publication requires the same label

The rules distinguish between the responsibilities of AI system providers and those of organisations that deploy these systems.

Providers of generative AI systems must ensure that synthetic or manipulated text, audio, images and video are marked in a machine-readable format so that they can be detected as AI-generated. Certain exceptions apply, including standard editing functions, source code, machine-to-machine outputs and some closed industrial uses.

Businesses and other professional users publishing material are subject to a separate disclosure obligation. They must clearly label image, audio or video content that constitutes a deepfake. They must also disclose the use of AI in text published to inform the public about matters of public interest when the material has not undergone meaningful human review or editorial control.

“When content such as an image, audio recording or video is generated or materially manipulated by AI, it must be possible to identify its artificial origin,” Jeleń explained.

“For example, a company may record a genuine video but add a voice generated by artificial intelligence. Depending on how the material is created and presented, the provider may have to embed a machine-readable mark, while the organisation publishing it may also have to provide a visible disclosure if the material qualifies as a deepfake.”

The distinction is important. The AI Act does not impose an identical visible labelling obligation on every image, recording or video produced with any degree of AI assistance.

Providers are primarily responsible for technical, machine-readable marking. Deployers are responsible for visible or audible disclosure when they publish deepfakes and certain AI-generated texts concerning matters of public interest.

People must also be informed when they are exposed to emotion-recognition or biometric categorisation systems. Companies providing chatbots, AI agents and similar interactive systems must ensure that people know they are interacting with artificial intelligence unless this is already obvious from the context.

Satirical and artistic content is not completely exempt

The rules also cover deepfakes, meaning AI-generated or manipulated images, audio or video that resemble existing people, objects, places, entities or events and could falsely appear authentic.

For clearly artistic, fictional, satirical or creative works, the disclosure may be presented in a way that does not interfere with the enjoyment of the work. This is therefore a more flexible form of disclosure rather than a complete exemption from the transparency requirement.

AI-generated or manipulated text intended to inform the public about political, economic, financial, scientific, cultural, health or other matters of public interest must also be labelled.

However, the disclosure is not required when the publication has undergone substantive human review or editorial control and a natural or legal person assumes editorial responsibility for it.

A superficial check of spelling, grammar or formatting is not sufficient. The review must involve an informed examination of the substance of the publication, including fact-checking and assessment of the reliability of its sources.

“The labelling requirement also applies to text generated by artificial intelligence, but disclosure may not be necessary if the material undergoes thorough human review and someone accepts editorial responsibility for it,” Jeleń said.

Article 50 applies from 2 August 2026. A limited transitional period applies to the machine-readable marking of outputs produced by systems already placed on the market before that date. Providers of those systems have until 2 December 2026 to comply with the marking and detection obligation. Content generated before 2 August does not have to be labelled retroactively.

High-risk AI requirements postponed until December 2027

Rules governing certain high-risk AI systems were originally expected to become applicable earlier. Following the adoption of the AI Omnibus, the requirements for high-risk systems covered by Annex III of the AI Act will apply from 2 December 2027.

These include systems used for certain purposes in recruitment, employee management, education, access to essential services, creditworthiness assessment, law enforcement, migration and biometric applications.

A separate deadline of 2 August 2028 applies to high-risk AI incorporated into regulated physical products such as machinery, toys and lifts. The AI Omnibus entered into force on 27 July 2026.

“The obligations apply both to providers of high-risk systems and to deployers — the customers and organisations that use those systems in practice,” Jeleń explained.

“High-risk systems are specialised solutions used in sensitive areas such as human resources, healthcare and financial services. The group of providers may be relatively limited, as it will largely include major AI companies and businesses that develop their own systems or significantly modify existing products.”

The number of organisations deploying these systems will be considerably larger.

Companies must follow the provider’s instructions

Deployers of high-risk AI systems will generally be required to use them in accordance with the instructions supplied by the provider, monitor their operation and respond to identified risks or serious incidents.

They will also have to appoint appropriately trained people to provide effective human oversight. When an organisation supplies input data, the data must be relevant and sufficiently representative of the intended use of the system.

“To limit the risk of liability, organisations should use high-risk systems only in accordance with the provider’s instructions,” Jeleń said.

“This can be compared to the off-label use of medicinal products. When a doctor uses a product outside its authorised instructions, responsibility for that decision may shift towards the doctor. Similarly, an organisation that substantially changes or misuses a high-risk AI system may assume responsibilities normally associated with its provider.”

Before high-risk systems can be placed on the EU market, providers will have to meet detailed requirements relating to risk management, data quality, technical documentation, traceability, transparency, accuracy, robustness, cybersecurity and human oversight.

Providers will also be required to conduct conformity assessments and register relevant systems in the EU database.

Businesses should audit their AI systems and contracts

Companies using high-risk solutions should begin preparing well before the December 2027 deadline.

“Organisations should audit the systems they use,” Jeleń said. “They need to verify whether the solutions are properly assessed, safe and registered where required.”

“They should also address matters such as vulnerabilities, security updates, incident handling and the division of responsibility in service-level agreements, implementation agreements and other contracts with technology providers.”

Such an audit should establish:

  • which AI systems are being used;
  • who introduced and controls them;
  • what data is processed;
  • whether they affect decisions concerning individuals;
  • whether they fall into a high-risk category;
  • whether meaningful human oversight is available;
  • how errors, incidents and complaints are handled;
  • and whether contracts clearly allocate responsibility between providers and deployers.

Recruitment systems face particularly strict scrutiny

The obligations will have a major impact on HR departments, which have rapidly automated recruitment and workforce-management processes in recent years.

According to the HR Tech Changer 2025 report prepared by the Polish HR Forum, 53% of surveyed HR professionals regularly use AI-based solutions. These technologies are frequently applied to candidate sourcing, recruitment, applicant screening, competency assessment and candidate-database management.

AI systems used to place targeted job advertisements, analyse and filter job applications, evaluate candidates or make decisions affecting employment conditions may be classified as high-risk.

“Decisions made or supported by AI in recruitment not only place these systems in the high-risk category but also create additional due-diligence requirements,” Jeleń said.

The same may apply in financial services and insurance. AI systems used to assess the creditworthiness of individuals or evaluate and price risks in life and health insurance can qualify as high-risk.

Medical AI may also fall within the high-risk framework, particularly when it forms part of a regulated medical device or supports diagnosis and treatment decisions.

“In healthcare, these systems will often have to be used under strong supervision by a doctor or another authorised professional. In some circumstances, using AI for a particular purpose may not be appropriate at all,” Jeleń added.

More than four in ten Polish companies already use AI or automation

The Polish Labour Market Barometer 2026, prepared by Gi Group Holding, shows that 42.2% of surveyed Polish companies use automation or AI solutions.

Most implementations remain limited to selected parts of the organisation rather than covering the entire business. Only 12.2% of employers say they use such technologies extensively, while 30% use them in selected areas and see further room for development.

Extensive adoption is most frequently reported by large companies, at 14.1%, compared with 11.8% of medium-sized businesses and 10.6% of small companies.

Artificial intelligence is already used across almost every corporate function, from HR, marketing, sales and customer service to legal, financial and administrative departments.

According to LEGALLY.SMART experts, the latest stage of the AI Act means that artificial intelligence can no longer be treated exclusively as an IT issue. It is becoming a matter of corporate strategy, risk management and legal compliance.

Many companies do not know which AI tools employees use

One of the most significant challenges will be identifying where and how AI is already being used within an organisation.

In many companies, employees began using publicly available AI tools independently, without central approval, formal policies or the knowledge of IT and compliance departments. As a result, senior management may not have a complete picture of which systems are processing corporate, personal or confidential information.

“Following the introduction of the next set of AI Act requirements, companies will have to significantly change their approach to artificial intelligence tools,” Jeleń said.

“They will need to support the development of employees’ AI literacy, analyse the tools used in the organisation and prepare a list of approved systems, as well as tools that employees are not permitted to use.”

The AI literacy obligation has applied since February 2025. Following amendments introduced through the AI Omnibus, providers and deployers remain required to take measures supporting the AI literacy of employees and other people using AI on their behalf, although they do not have to guarantee a formally defined level of knowledge for every individual.

The appropriate measures depend on the systems being used, the risks involved and the employees’ responsibilities. They may include training, internal guidance, practical instructions and role-specific compliance procedures.

Companies need internal AI policies

Businesses should introduce clear procedures covering the permitted and prohibited uses of artificial intelligence.

These policies should address:

  • personal data protection;
  • confidentiality and trade secrets;
  • intellectual property;
  • verification of AI-generated information;
  • approved and prohibited applications;
  • human oversight;
  • record-keeping;
  • incident reporting;
  • security updates;
  • and responsibility for final decisions.

Employees should know which information may be entered into external AI tools, when AI-generated results require additional verification and who must approve the use of AI in sensitive business processes.

In Jeleń’s assessment, responsibility for non-compliance ultimately rests with the organisation. Depending on the nature of the violation and the applicable national rules, members of the management board may also face personal legal consequences.

AI Act fines can reach EUR 35 million

The most serious violations of the AI Act, including the use of prohibited AI practices, can result in administrative fines of up to EUR 35 million or 7% of the company’s total worldwide annual turnover from the preceding financial year, whichever is higher.

Violations of other obligations, including transparency requirements and rules governing high-risk systems, can result in fines of up to EUR 15 million or 3% of worldwide annual turnover.

Providing incorrect, incomplete or misleading information to the relevant authorities may attract penalties of up to EUR 7.5 million or 1% of global annual turnover.

For SMEs, the applicable maximum is generally the lower of the fixed monetary amount and the percentage of annual turnover. For larger businesses, the higher amount applies.

“For breaches of transparency obligations or the requirements applying to high-risk systems, penalties can reach 3% of turnover or EUR 15 million,” Jeleń said.

“The regulation provides a degree of proportionality for SMEs, which should generally be subject to the lower rather than the higher of the two maximum thresholds.”

The new stage of AI Act implementation therefore represents much more than an obligation to add labels to selected content.

For companies, it marks the beginning of a broader process of identifying artificial intelligence systems, controlling the tools used by employees, reviewing technology contracts and integrating AI risk into corporate governance.

Check out our other content
Related Articles
The Latest Articles