Legal Landscapes: Poland- TMT

Agata Szeliga, Marta Kupczak-Strzelecka, Sylwia Macura-Targosz, Maciej Gil, Michał Kalinowski, Alicja Maciążka

Partner, Senior Counsel, Senior Counsel, Senior Associate, Associate, Associate, Soltysinski Kawecki & Szlezak


1. What is the current legal landscape for your practice area in your jurisdiction? 

Poland’s TMT sector is undergoing a period of significant regulatory change, as EU-level digital legislation converges with newly enacted national laws on cybersecurity and artificial intelligence.

Cybersecurity – NIS2 transposition

Poland transposed the NIS2 Directive (‘NIS2’) by amending the Act on the National Cybersecurity System, the amendment having been in force since 3 April 2026. Essential and important entities that will not be entered ex officio, are now required to self-identify until 3 October 2026 in a new registry, and until 3 April 2027 implement all other obligations, including formal information security management system, update their incident reporting procedures, and manage cybersecurity risk across their supply chains.

Artificial intelligence – the national implementing legislation

The core provisions of the Act on Artificial Intelligence Systems (‘Polish Act on AI’) apply as of 11 August 2026, while the rules governing individual opinions, inspections, proceedings, settlements, administrative penalties and criminal liability will come into force on 28 October 2026.

The Act establishes the enforcement machinery for the directly applicable EU AI Act and does not introduce new substantive obligations of its own. It creates the Commission for the Development and Safety of Artificial Intelligence (KRiBSI), which will be responsible for market surveillance and enforcement of both the EU AI Act and the domestic rules, and will serve as Poland’s national contact point. The chair is appointed by the Sejm (the lower house of the Polish parliament) with the consent of the Senate (the upper house) for a five-year term, and is joined by two deputies appointed by the chair for a five-year term from among candidates selected through an open and competitive recruitment process, and members nominated by the Office of Competition and Consumer Protection (UOKiK), the Polish Financial Supervision Authority (KNF), the National Broadcasting Council (KRRiT) and the Office of Electronic Communications (UKE).

As regards its powers, KRiBSI will be able to conduct compliance audits and may order the withdrawal of a non-compliant AI system from the market or restrict its use. Any individual or organisation will be entitled to lodge a complaint with KRiBSI concerning an AI system believed to breach the AI Act or Polish law. Two features merit particular attention: businesses may request a binding individual opinion from KRiBSI on the classification of their AI system prior to its commercial launch, the public version of which will be published afterwards and the Act establishes a legal basis for regulatory sandboxes, allowing certain regulatory requirements to be temporarily suspended within a controlled test environment.

Digital platforms

Poland has not yet enacted the domestic legislation required to designate a national Digital Services Coordinator and competent authorities, or to lay down administrative fines, civil liability rules and enforcement procedures for breaches of the DSA. While the DSA is directly applicable and does not require transposition, it does require enabling national legislation to give effect to its institutional and procedural framework.

A government bill amending the Act on the Provision of Electronic Services was adopted by parliament, but was vetoed by the President of the Republic of Poland on 9 January 2026 on the grounds that it introduced ‘administrative censorship’ and conferred excessive powers on the President of UKE (Office of Electronic Communications) without sufficient guarantees of institutional independence.

Following the veto, revised draft legislation was published, split into two separate bills: one enabling the police, prosecutors and the National Revenue Administration to apply for the blocking of illegal online content, and a second designating the President of UKE as the Digital Services Coordinator.

Implementing legislation for the Data Act in Poland.

The EU Data Act entered into force on 11 January 2024 and has been directly applicable since 12 September 2025, but its full operation in Poland still depends on a national law covering matters left to member states, such as the designation of competent authorities, a data coordinator, dispute-resolution procedures and penalties. A draft law on fair access to data and its use was published for public consultation in November 2025, and as of mid-2026 it is still being processed within government, meaning implementation has lagged well behind the Regulation’s direct applicability.

The latest available draft designates the President of UKE as the competent authority under Article 37(1) of the Data Act, as the body responsible for certifying alternative dispute-resolution bodies under Article 10(5), and as the data coordinator under Article 37(2). The President of the Office for Personal Data Protection (‘UODO’) does not hold supervisory competence under the draft; instead, the President of UKE may request the President of the UODO to provide an opinion on matters falling within the scope of Article 37(3) of the Data Act – that is, where enforcement of the Regulation intersects with personal-data protection. On penalties, the draft proposes fines of up to PLN 100,000, or up to 4% of annual turnover for businesses.

2. What three essential pieces of advice would you give to clients involved in your practice area matters?

Advice No 1 – Keep close eye on consumers protection regulations

The Polish Competition Authority has recently been extremely active in the Polish market, especially in e-commerce area, adopting a very strict and formalistic approach and challenging practices which have been adopted by the market for a long time, e.g. changing prices of online and subscription services under a so-called opt-out mechanism, meaning that a user who does not terminate the contract is deemed to have accepted the changes.

The PCA’s activity focuses on the most important aspects of providing online services, such as price presentation, advertising practices, influencer marketing, complaints resolution procedures, and changes to existing platform and services functionalities. We may also expect it to be very active in the field of proper labelling of AI-generated or AI-modified content.

In addition to monetary fines of up to 10% of the trader’s worldwide turnover for each identified infringement of consumer protection regulations, the PCA may also order the trader to compensate consumers (e.g. by way of refund of undue payments or provision of a discount), the costs of which may be significant and even more severe than the monetary fine.

The practice of strengthening consumer protection is also clearly visible in other European markets. In conjunction with EU activities in this area of law, it is to be expected that regulations concerning consumer protection in the digital market, broadly understood, will constitute a key element in ensuring the legal certainty of business operations. Given the absence of harmonised regulations at the EU level and the law-making practice of regulatory authorities, ongoing monitoring of the regulatory landscape in relevant jurisdictions is crucial.

Advice No 2 – Implement AI governance in your organisation

The number of individuals utilising AI tools has grown rapidly in recent years. AI-based tools have become an essential working instrument for many professionals, while also permeating their personal lives. Numerous studies demonstrate that the use of AI tools enhances both the quality and the efficiency of work.

For these reasons, the use of AI tools by employees within an organisation should become standard practice. Attempts to impose blanket prohibitions in this regard are unlikely to prove effective and will merely drive the use of such tools without the employer’s knowledge and in the absence of appropriate internal procedures.

It is therefore essential that organisations implement robust internal procedures, commonly known as AI governance.

Three key areas of risk associated with the use of AI tools within an organisation may be identified: (i) data security, (ii) regulatory compliance, and (iii) over-reliance on AI and loss of capabilities.

Ensuring the security of data processed by AI systems remains a matter of paramount importance, particularly for regulated entities such as banks and for entities with access to especially sensitive data, such as healthcare providers or tech companies. Anonymisation does not, however, constitute a universally viable solution, as it may render the tool in question ineffective for its intended purpose. Accordingly, the selection of a reliable provider, the implementation of appropriate contractual safeguards, and the conduct of an internal assessment and classification of the sensitivity of specific categories of data remain of critical importance.

The use of AI-based tools is subject to an increasingly complex regulatory environment, encompassing, among other instruments, the AI Act, the GDPR, the Data Act and the NIS2 Directive. Regulatory compliance in the field of AI accordingly represents one of the principal challenges facing all organisations, and particularly those that are simultaneously subject to sector-specific regulatory requirements such as banking or medical sector. A central dimension of this challenge is the question of liability, both vis-à-vis public authorities empowered to impose significant monetary fines and vis-à-vis business partners entitled to seek compensation under contractual provisions. With the high level of shadow AI within organizations, the reasonable AI governance rules could substantially mitigate those risks.

Excessive reliance on AI systems gives rise to two serious consequences: first, the risk of error resulting from the use of outputs that have not been independently verified; and second, the risk of a gradual erosion of the user’s and organisation own knowledge and skills where such user routinely delegates tasks exclusively to AI tools, particularly without verifying the results produced. 

Advice No 3 – Take care of your cybersecurity

In recent years, cybersecurity has become not only one of the regulatory areas that businesses must take into account but mainly the business one. Cybersecurity risks are by no means confined to companies operating in the IT sector. Today, virtually every enterprise or organisation may be affected by cybersecurity incidents.

The emergence of AI tools and the ability to create new scams has only accelerated the ‘arms race’ between malicious actors and the developers of solutions designed to safeguard the digital environment.

Cybersecurity is not solely a matter of appropriate software and the configuration of the digital environment and its supporting infrastructure; it equally encompasses procedural and legal requirements. This is further evidenced by the imposition of a range of new obligations on numerous entities in connection with the adoption and transposition of NIS2. Cybersecurity will undoubtedly constitute one of the key legal and technological challenges in the years ahead, and it is therefore essential that it be accorded particular attention.

3. What are the greatest threats and opportunities in your practice area law in the next 12 months?

Threats:

Implementation of the Electronic Communications Law (‘PKE’): 2026 is the second year of the PKE being in force and will bring numerous implementing regulations, including rules on complaints handling, service quality indicators and facilities for persons with disabilities. Telecommunications undertakings should expect continued increases of compliance costs relating to subscriber documentation, complaint handling, reporting to UKE, invoicing, national e-invoicing and obligations connected with national defence and state security.

Growing cybersecurity and operational resilience obligations: NIS2 implementation, combined with sector-specific network security requirements, may create overlapping duties and additional compliance costs.

Uncertainty linked to EU reform – the Digital Networks Act (‘DNA’): on 21 January 2026, the European Commission published its proposal for the Digital Networks Act, intended to replace the European Electronic Communications Code. The proposal envisages, among other things, a single cross-border authorisation procedure (a ‘Single Passport’), harmonised and, in principle, indefinite or extended spectrum reservations, a single EU-level authorisation regime for satellite services, and a voluntary conciliation mechanism for disputes in place of mandatory ‘fair share’ contributions from large platforms. Replacing directives with a directly applicable regulation could mean far-reaching centralisation of powers currently held by Member States which has already prompted opposition from some Member States, and the legislative process creates a risk of prolonged uncertainty as to the eventual shape of the national regulatory framework and a possible need to change the recently implemented PKE again.

Opportunities:

Eventual harmonisation and simplification: the DNA and PKE may, over time, reduce barriers to market entry, facilitate cross-border services and increase legal predictability for investors.

Longer and more stable spectrum reservations, alongside measures supporting spectrum sharing, should improve investment planning for next-generation networks.

New service segments: the proposed EU-level authorisation regime for satellite services, together with the growth of virtualised and cloud-based services, may help operators diversify into satellite connectivity, managed services and cloud-integrated solutions.

Greater customer trust: new PKE consumer standards on offer transparency, complaints handling and prepaid refunds may become a competitive advantage for operators that implement them effectively.

AI-driven growth and investment: with the Polish Act on AI now in force and KRiBSI up and running, businesses have a clear domestic enforcement framework, giving genuine first-mover advantage to those who invest now rather than wait out the uncertainty. Early adopters that implement robust AI governance, secure a binding individual opinion from KRiBSI on the classification of their systems, or make use of regulatory sandboxes will be well placed to bring compliant AI solutions to market ahead of their competitors. This advantage is reinforced by the EU’s own funding priorities, which are channelling substantial investment into both AI tools and the underlying hardware and compute infrastructure, opening up opportunities for Polish businesses across the entire AI value chain.

4. How do you ensure high client satisfaction levels are maintained by your practice?

In a practice area as dynamic as TMT, client satisfaction is no longer secured by simply staying ahead of the regulatory curve; that is now baseline expectation. Our role has evolved accordingly. We do not merely advise on the law as it stands, but help clients understand how regulation, technology and business implementation interact in practice. This requires us to combine strategic regulatory advice with sophisticated technology-contracting expertise and practical implementation support, particularly in matters that are central to Poland’s digital transformation.

In practice, this means that our work goes beyond legal analysis of AI, cloud, data protection, cybersecurity, outsourcing and telecommunication rules. We support clients in translating complex regulatory requirements into workable governance structures, contractual frameworks, internal policies and implementation roadmaps. Many of these projects also require sensitive engagement with regulators, major enterprises and public-sector stakeholders, where legal advice must be aligned with the client’s strategic objectives, commercial constraints and operational reality. We therefore focus on giving clients not only a clear view of their legal obligations, but also a practical path for managing regulatory change as a planned business process rather than as a recurring source of disruption.

5. What technological advancements are reshaping your practice area law and how can clients benefit from them?

The continuing rise of remote advocacy

From a client perspective, legal services are becoming increasingly accessible as secure, cloud-based collaboration platforms remove geography from the lawyer-client relationship. By 2026, dedicated client portals have evolved beyond video calls and document repositories into shared matter workspaces, in which clients and legal teams can exchange and review documents, co-author drafts, monitor tasks and decisions, and work from the same matter record in real time.

Remote advocacy builds upon the same infrastructure. Cloud-based workspaces support negotiations and document exchange. These technologies enable continuous cross-border collaboration throughout the entire lifecycle of a matter.

AI-assisted legal practice

Legal AI is reshaping the whole legal practice by providing a new form of professional assistance, not by replacing the lawyer (or the ‘lawyers-to-be’, students). Our team uses AI solutions, including AI agents dedicated for lawyers as well creates its own workflows to speed up and improve our work. We are also able to support the client’s legal departments in their AI transformation. In particular, we carry out trainings for legal teams on potential use of AI. We also co-authored the first Polish recommendations on use of AI by lawyers – the “AI in the work of an attorney-at-law” which was prepared in 2025 in collaboration with Microsoft and the Polish National Council of Attorneys at Law.

Digital incident response

Technology is also transforming the management of data breaches and cybersecurity incidents, particularly where a single event may engage several notification regimes, supervisory authorities and statutory deadlines. Digital incident-response platforms can create a controlled source of information, allocate responsibilities, map established facts against jurisdiction-specific requirements and preserve an audit trail as the understanding of the incident develops. For clients, this does not mean that notification decisions are delegated to software; it means that those decisions can be made on the basis of information that is structured, consistent and capable of being updated across jurisdictions without repeatedly reconstructing the same factual record.