AI Act introduces transparency obligations. We explain what changed on August 2

From a simple prompt in a chatbot conversation to AI embedded in corporate systems. Regardless of where artificial intelligence is “hidden”, new EU rules require companies to disclose its use. Experts explain the challenges businesses will face.

Zdaniem ekspertów szeroka adopcja chmury w naszym kraju nie oznacza bynajmniej, że polskie firmy wykorzystują jej potencjał w maksymalnym stopniu. Fot. Getty Images
AI specialists will have the greatest employment opportunities in IT companies. Photo: Getty Images
Loading the Elevenlabs Text to Speech AudioNative Player...

Do Polish entrepreneurs know whether, and how, artificial intelligence is being used in their companies? The AI Act – the European Union’s Artificial Intelligence Act (2024/1689) – will force businesses to conduct internal audits. On August 2, another part of the regulation came into effect, including transparency obligations for AI systems and rules governing general-purpose AI models.

The principle appears simple: customers or potential users must know when they are interacting with a person and human work, and when they are dealing with a bot and the output of technology. This includes both the obligation to disclose that a conversation or written exchange is taking place with a bot and the requirement to inform recipients that, for example, an advertisement for a service was created by technology rather than being a photograph of an actual hair salon.

First, however, we examine how Polish businesses – from small companies to market giants – are using AI.

Do companies know they are using AI? “Sometimes it gets out of control”

“The answer depends on how we define artificial intelligence. In many small and medium-sized companies in Poland, there is still a lack of knowledge, resources and funding. There are no clearly defined standards for using AI because there are no dedicated teams responsible for such implementations, as there are in the largest companies. Some business owners have no idea that their employees are using tools such as ChatGPT. If we do not invest in education and training, the consequences of so-called shadow AI could be costly,” says Joanna Plona, CEO of WeNet Group.

The way companies use AI – including cases where the lack of awareness itself is the problem – is described in the latest “Labour Market Barometer” by Gi Group Holding. According to the study, 42.2% of companies say they use automation and artificial intelligence, with the highest adoption rates in trade and services. The figure could be even higher if it included organisations that are unaware of AI being embedded in tools such as Outlook, Teams, HR systems, CRMs or marketing platforms.

Experts argue, however, that knowing who uses AI within a company and how they use it is no longer simply good practice – it is becoming an obligation. The AI Act will require businesses to carry out numerous internal audits.

“The biggest challenge for businesses will not be implementing the AI Act, but determining where artificial intelligence is already operating within the organisation. In many companies, employees started using AI from the bottom up, and today no one has a complete picture of how it is being used. Yet this type of audit should be the starting point for preparing for the new obligations,” says Dr Judyta Latymowicz, partner at LEGALLY.SMART law firm.

AI Act. What changed on August 2?

August 2 marked an important milestone in the fight against deepfakes. From that date, any content – video or image – showing a person in a way that has been manipulated by AI must be labelled. The European Commission has even prepared proposed icons for this purpose, which can be used (although they are not mandatory) on recordings or images. What matters is that the label is visible and unambiguous. Exceptions include, for example, artistic works, where the disclosure may appear in end credits or in the description of the material.

Transparency requirements also apply to interactions with chatbots, virtual assistants and automated customer service systems. From August 2, people using an AI system should be clearly informed that they are interacting with a machine.

“When we call a helpline, a chatbot usually introduces itself as a virtual assistant. Under the law, we should apply the same principle to other channels, such as text-based chats. Users should also know when they are dealing with, for example, a deepfake. To me, this is as natural as disclosing sponsored partnerships or labelling photographs taken by a photographer or sourced from a stock library. Here, the ‘author’ is artificial intelligence,” comments Joanna Plona.

Importantly, companies that fail to comply with transparency requirements face penalties. As a general rule, the maximum fine amounts to EUR 15 million or 3% of global annual turnover.

“Broad adoption, shallow use of AI”

To understand how Polish businesses are using AI, we spoke with experts who provide companies with artificial intelligence-based solutions. Marcin Dąbrowski, co-creator and project lead of Obywatel Bielik at Bielik AI, explains that there are two scenarios on the Polish market.

AI adoption may be a bottom-up initiative, either with or without managers’ oversight – as in the case of shadow AI described above. It may also result from a carefully planned implementation process for a specific technology.

“The first scenario is far more common, although it is the least visible in statistics. If an employee uses AI independently, management often has no idea. Yet it is management that participates in surveys. The scale itself also varies significantly depending on the source. According to, for example, Statistics Poland (GUS) or Eurostat, around 9% of Polish companies use AI, while the latest report by PARP and Jagiellonian University puts the figure at 23%. Both numbers are accurate; they simply refer to different segments of the economy. GUS covers all industries, while PARP deliberately selected twelve sectors with the greatest implementation potential. And that is the more interesting figure, because even in areas where artificial intelligence makes the most sense, fewer than one in four companies are using it,” explains the expert.

Karol Drążek, IT director at Mindbox, adds that in Polish business AI has “broad applications but shallow use”.

“This happens because many employees are effectively using artificial intelligence without their employers being aware of it. AI is embedded even in the simplest documents. The barrier to entry is virtually zero, which is why employee training is needed,” says the expert.

He adds that companies often do not consider who they are entrusting with their corporate data. When using global large language models, they frequently fail to configure settings in a way that limits data processing.

“In the face of the AI Act, as with previous regulatory reforms, many companies are starting work at the last minute. Only at the final stage do they audit AI tools and prepare the necessary documentation. However, I am confident that this reform will ultimately become a formality for businesses, and they will manage it just as they managed GDPR,” adds the expert.

AI bot on the front line: why companies are turning to artificial intelligence

A WeNet expert points out that companies are not afraid to invest in AI when they can see the benefits it delivers. Our interviewee cites WeNet AI Assistant as an example.

“We sold more than 1,700 subscriptions to this solution within two months. The tool collects information from a potential customer in order to prepare an offer for them. There is no need for customers to leave their contact details and wait for a call, for example, from a furniture store. The virtual assistant knows the store’s offering. Once the customer provides the required information, it can prepare an offer on its own. This is an example of how AI can be effectively used in the services sector,” the expert adds.

Bots serving as the first point of contact are also increasingly being introduced by banks, medical facilities and other service providers.

“They relieve employees from handling repetitive inquiries about appointment availability, pricing or doctors’ schedules.

Another application of AI is working with documents and knowledge. I am referring here to internal search engines, contract and legal document analysis, summaries and retrieval-augmented generation (RAG). In legal tech, such systems can automatically verify whether cited court rulings actually support the conclusions generated. In public administration, tools can automatically identify prohibited clauses in standard contract templates before any formal proceedings are initiated,” says Marcin Dąbrowski.

As he explains, when it comes to Bielik, companies primarily use the model in areas where the quality of the Polish language and the ability to process sensitive data in a local environment — rather than in the cloud — are crucial. It is data security and the accuracy of responses that give local language models an advantage over global technology giants.

Business does not want to fall victim to its own regulation

Our interviewees do not hide the fact that establishing rules governing AI is a necessity. However, they unanimously stress that it is important to strike the right balance — one that protects the interests of users, whose data must also be safeguarded online, while recognizing the needs of businesses for which AI has become a permanent element of building competitiveness.

“This is a step in the right direction. We are being flooded with deepfake images and videos. A ban on nudification will also help clean the internet of inappropriate content. We need to quickly block the risks associated with AI. At the same time, I have serious concerns that we could become victims of our own regulation — that we might create barriers restricting technology imports and investment,” concludes Karol Drążek, IT director at Mindbox.

Główne wnioski

  1. In the face of the AI Act, many companies will need to begin not with deploying new tools, but with determining where artificial intelligence is already being used. The challenge is so-called shadow AI — employees are using chatbots and AI-powered features in their daily work, often without their employers’ knowledge. This is compounded by AI solutions embedded in popular software such as Outlook, Teams, HR systems, CRM platforms and marketing tools. For many companies, the first step toward compliance with the AI Act will therefore be an internal audit to identify the solutions currently in use and assess the risks associated with them.
  2. The new regulations do not prohibit the use of artificial intelligence, nor do they impose obligations on every company using AI. They do, however, introduce the principle that in certain situations users should know when they are interacting with an AI system or with content generated or manipulated using AI. This applies, among other things, to chatbots and deepfakes.
  3. Experts agree that artificial intelligence is moving beyond the experimental stage and becoming a tool that supports sales, customer service, document analysis and information retrieval. At the same time, the importance of secure data processing, appropriate employee training and establishing clear rules for AI use within organizations is growing. In practice, success will not be determined simply by implementing cutting-edge solutions, but by the ability to use them consciously and responsibly.