How should a company operate in the era of new AI obligations?
by ecommerce legal on Aug 18, 2026
In just a few years, artificial intelligence has gone from a technological curiosity to an almost daily tool in businesses. Companies use it to generate marketing content, graphics, and product descriptions, automate customer service, analyze documents, prepare meeting summaries, support recruitment, create product recommendations, and leverage language models to work with internal data.
However, in many organizations, this development occurred from the bottom up. First, an employee created an account in a popular AI tool, then the entire department used it, and only at a later stage did the company begin to wonder what data was going into the system, who approved its use, and what legal obligations arose from such a process.
The AI Act changes the significance of these questions. The use of artificial intelligence is no longer solely a technological or operational decision. In certain cases, it becomes a regulated area that requires establishing the entrepreneur's role, assessing how the AI system is used, ensuring appropriate transparency, developing staff competencies, and – in more advanced cases – preparing a much broader compliance system.
Therefore, legal support for the AI Act should not consist solely of preparing a single set of regulations for AI use. The starting point must be to determine where AI actually exists in the organization, what it is used for, and what consequences its operation entails.
What is the AI Act?
The AI Act, or Regulation (EU) 2024/1689 of the European Parliament and of the Council, establishes common rules for the European Union regarding the development, placement on the market, and use of artificial intelligence systems.
The regulation does not assume that all artificial intelligence is equally dangerous. The foundation of the AI Act is a risk-based approach. The greater the potential impact of a specific AI application on safety, human rights, or the situation of a specific person, the more far-reaching the regulatory obligations.
This means that a system used to filter spam will not be evaluated in the same way as a solution making decisions in the recruitment process. Similarly, a simple text generator used by the marketing department does not automatically create the same obligations as a system used to assess an individual's creditworthiness.
The first mistake made by entrepreneurs is therefore asking: "Do we use AI?" From a legal perspective, the more important question is: "What kind of AI do we use, what do we use it for, and what role do we play in relation to this system?"
Does the AI Act apply to an ordinary company that only uses AI tools?
Yes. The AI Act is not a regulation aimed solely at manufacturers of language models, technology companies, or startups creating their own algorithms.
The regulation distinguishes several categories of entities. A provider is, as a rule, an entity that develops an AI system or commissions its development and places it on the market or puts it into service under its own name or trademark. A "deployer," i.e., an entity using an AI system, is a natural or legal person or public authority, agency, or other body that uses an AI system under its control for purposes other than purely personal or non-professional activity. The regulation also covers, among others, importers and distributors.
In practice, this means that an enterprise does not have to create its own artificial intelligence model for the AI Act to be relevant to it.
An online store using an AI chatbot may be a deployer of the system. A company using artificial intelligence in the recruitment process may also be subject to appropriate obligations. The same applies to an organization generating visual materials with AI, automating customer contact, or implementing solutions that analyze user behavior.
However, the scope of obligations will vary. This is precisely why a lawyer dealing with the AI Act should not begin the analysis by preparing a ready-made package of documents, but by determining the entrepreneur's role in relation to individual tools and their uses.
The AI Act doesn't start with documentation. It starts with a map of AI usage
In many companies, management does not have full information about where artificial intelligence is used. Marketing uses one text generator, the graphics department uses another tool, sales automates meeting transcriptions, HR analyzes CVs, and administrative staff send documents to publicly available language models.
Each of these processes can carry different risks.
Therefore, the first element of proper implementation should be a register or map of AI systems used. This approach is also indicated in current studies on preparing organizations for the AI Act - alongside an AI use policy, documenting risk assessment, and defining individuals responsible for oversight.
The register should not end with the name of the tool. From a compliance perspective, what matters is which department uses it, for what purpose, what data is entered into it, what results it generates, whether the AI output is subject to human control, whether it influences decisions concerning a specific person, and whether the client or employee has direct contact with the system.
Only such a picture allows determining which regulations actually apply.
Risk categories in the AI Act – why is the way AI is used more important than the tool's name?
The AI Act is based on differentiating applications by risk. In simplified terms, one can speak of prohibited practices, high-risk systems, systems subject to specific transparency obligations, and solutions for which the AI Act does not provide such an extensive regime.
However, the key is that it is primarily the use case of the system that is classified, not the technology brand itself. The same model can be used to write a product description, analyze a document, or as an element of a much more advanced system making decisions about people. The regulatory significance of each of these scenarios will be different. A use-case-based approach is one of the central tenets of the AI Act.
Practices deemed unacceptable by the regulation are prohibited. Some of these provisions have been applicable since February 2, 2025. They concern, among other things, certain forms of manipulation of human behavior, exploitation of particular vulnerabilities of certain individuals, or prohibited social scoring.
A much more extensive system of obligations has been provided for high-risk systems. This group may include, among others, certain solutions used in recruitment and employee management, in education, in creditworthiness assessment, in some areas of biometrics, critical infrastructure, or access to essential services.
However, a significant change occurred in 2026. As a result of the adoption of the AI Omnibus, the application date for the most important obligations concerning high-risk systems has been postponed. For systems classified as high-risk on the basis of Article 6(2) and Annex III, the essential date has been set for December 2, 2027, while for high-risk systems that are components of certain products covered by harmonized EU legislation, it is August 2, 2028.
However, the postponement of deadlines does not mean that businesses should postpone their AI analysis until 2027. If a company is already using a solution in recruitment, employee assessment, or another potentially high-risk area, today's decision regarding supplier selection, integration methods, and data flow can determine how costly later adjustments will be.
What changed since August 2, 2026?
August 2, 2026, was a significant moment in the AI Act timeline. From this date, further parts of the regulation began to apply, and new transparency obligations were enforced.
For many businesses, transparency will be the most visible effect of the new regulations.
If an AI system is designed to interact directly with a human, its provider should ensure a solution that allows informing the person that they are interacting with an AI system, unless this is obvious to a well-informed and attentive recipient in the given circumstances. In practice, this applies, for example, to many customer service chatbots.
Special obligations also apply to synthetic content. Providers of systems generating artificial text, image, audio, or video have obligations regarding marking the results in a machine-readable format that allows detecting their artificial origin. At the same time, AI deployers have separate obligations regarding the disclosure of AI use, e.g., in the case of deepfakes and certain textual content concerning matters of public interest.
This distinction is important. The slogan "from August 2, every AI-generated material must be marked" would be an oversimplification. The obligation depends on the type of content, the entrepreneur's role, and the specific way it is used.
Product photos, graphics, and deepfakes - does every material prepared with AI need to be marked?
This question is particularly important for e-commerce, as generative artificial intelligence is already widely used in creating photo backgrounds, product arrangements, visualizations of product variants, and advertising materials.
The AI Act defines a deepfake as an AI-generated or manipulated image, audio, or video material that resembles existing persons, objects, places, entities, or events and can falsely appear authentic or real. If the material meets this definition, the deployer of the system is obliged to disclose that the content has been artificially generated or manipulated.
However, this does not mean that every retouch made using AI automatically becomes a deepfake. The AI Act itself provides an exception to the technical marking obligation for systems that serve an auxiliary function in standard editing or those that do not significantly change the input data or its meaning.
For an online store, the scale of interference is therefore important. Automatic exposure correction is one thing, and creating a product visualization in a non-existent setting in a way that could be perceived as a real photo is another. The boundary should be assessed taking into account the specific material, the way it is published, and what idea of the product the consumer might get.
At this point, AI Act legal support should also be combined with an analysis of consumer law and rules regarding the fair presentation of products. Even if a given material does not meet the technical definition of a deepfake, the way AI is used still cannot mislead the consumer about the characteristics of the offered goods.
AI in customer service - a chatbot is not just a technological issue
Another area where businesses will relatively quickly encounter the AI Act is customer service.
If a customer initiates a conversation with a system that looks and responds like a human, they should know that there is artificial intelligence on the other side, if this fact is not obvious from the circumstances. The information should be conveyed clearly and no later than at the first interaction or exposure to the system.
However, the company's obligations do not end there.
A chatbot often receives information from the customer regarding an order, email address, complaint, payment, product issue, or other data that allows identifying a specific person. In such a case, the project cannot be analyzed solely in terms of the AI Act. It becomes necessary to also check the rules for processing personal data, the relationship with the technology provider, the scope of information transferred, retention periods, and security.
Therefore, a good AI Act lawyer should analyze the system not as an isolated tool, but as an element of the entire process. The privacy policy may require updating, but updating the document itself will not be sufficient if the internal use of the tool remains unorganized.
AI Act and GDPR - why does compliance with one regulation not mean compliance with the other?
The AI Act does not replace the GDPR.
This is one of the most important principles when implementing AI tools in a company. A system may be correctly classified under the AI Act, while the way it is fed data may violate personal data protection regulations. Analogously, compliance of the process with the GDPR does not guarantee fulfillment of obligations arising from the AI Act.
The problem is particularly evident with publicly available generative models. An employee may paste a list of clients, a fragment of correspondence, a contract, a candidate's CV, or complaint data into the tool without first considering whether the organization has approved such processing and what rules stem from the agreement with the solution provider.
From the company's perspective, a joint analysis of at least three layers is therefore needed: the AI Act, data protection, and the contractual terms of using a specific system. Depending on the application, labor law, consumer law, trade secrets, or copyright regulations may also apply. Deloitte also points out that the AI Act should be analyzed as part of a broader EU digital regulatory landscape, and not as a closed, standalone legal act.
Employee competencies in AI – an existing obligation
One of the less spectacular but very practical elements of the AI Act are the obligations regarding AI competencies.
Article 4 of the regulation requires providers and deployers of AI systems to take measures to support the development of competencies of personnel and other persons involved in the operation and use of AI systems on their behalf. The scope of such measures should take into account technical knowledge, experience, education, the context of technology use, and the individuals who may be affected by the system.
In practice, this does not mean conducting a single identical training for all employees.
A person using a text generator to prepare a draft post needs a different level of knowledge than an HR employee using AI in the recruitment process, and yet another than a person responsible for implementing a customer service system.
A well-prepared AI literacy program should stem from a real map of AI use. This ensures that training does not become a theoretical obligation, but part of a system that reduces operational risk.
AI policy in the company – a document or a real system of action?
With the increasing interest in the AI Act, many companies have started creating internal "AI policies." The document itself can be a good starting point, but its value depends on whether it describes a process that actually functions within the organization.
The policy should answer practical questions. Can an employee independently create an account in an AI tool? What data should not be entered into public models? Who approves a new tool? Do AI effects need to be verified by a human? How do we handle materials generated for clients? When should the application be consulted with the person responsible for compliance or data protection?
Without such rules, a company may have a formal document, while at the same time having no control over the actual use of AI.
Therefore, AI Act legal support should include not only the preparation of the policy, but also its correlation with the tools register, the process of approving new solutions, purchasing rules, information security, and employee training. In current studies on the AI Act, managing AI as part of a broader compliance system is indicated as a practical direction for preparing organizations.
AI in recruitment and employee management – an area requiring special attention
One example that well illustrates the logic of the AI Act is recruitment.
Annex III of the regulation covers certain AI systems intended for recruiting or selecting natural persons, including solutions used to analyze and filter applications or evaluate candidates. The catalog also includes certain systems used to make decisions regarding employment conditions, promotions, termination of cooperation, task assignment, and employee monitoring and evaluation.
This does not mean that every assistance from ChatGPT in writing a recruitment announcement automatically creates a high-risk system. The actual function of the system and the impact of its operation on a human being are significant.
However, if AI begins to select candidates, assign them scoring, or recommend with whom the entrepreneur should continue the process, the legal situation is completely different.
Although the most important obligations regarding this high-risk category have been postponed until December 2, 2027, an entrepreneur currently planning to purchase such a system should take future requirements into account already when choosing a supplier and negotiating the contract.
Contracts with AI providers – compliance begins before purchase
One of the more often overlooked elements of artificial intelligence implementation are contractual terms.
Companies often analyze a tool's functionality and price, but only after they start using it do they check where data is stored, whether the vendor uses the entered information to further train the model, what the liability for system availability looks like, and what rights the entrepreneur has to the generated content.
For critical business processes, such an approach is risky.
A legal analysis of the tool should take place before its implementation. The more a system impacts customers, employees, or key business decisions, the more important are the provisions regarding data, security, technical documentation, system functionality changes, parties' liability, and access to information needed later to demonstrate compliance.
This is also where an AI Act lawyer can be relevant even before any reporting obligation arises. A poorly structured relationship with a vendor can mean that the company does not have the information needed to properly assess the system or manage its risks.
What should a company do to prepare for the AI Act?
Organizational preparation can be structured into three consecutive stages:
-
Identify AI and establish roles. The company should inventory the systems used, their providers, users, types of data processed, and purposes of use, and then determine its role under the AI Act.
-
Assess risks and obligations. Each significant use case should be classified in terms of prohibited practices, potential high risk, transparency requirements, GDPR, consumer rights, labor law, intellectual property, and information security.
-
Implement operational solutions. The final stage involves preparing necessary communications, procedures, internal policies, and agreements, developing employee competencies, defining responsibilities, and creating a mechanism for regular review of the systems used.
The most important thing is to maintain this sequence. A company that starts by writing an AI policy without determining how the technology is actually used may produce a document completely detached from reality.
What does an AI Act compliance audit look like?
An AI Act audit should not be limited to asking whether the company uses ChatGPT.
A proper analysis covers the entire AI usage cycle: from technology selection and purchase, through data input into the system, its operation and human oversight, to the AI-generated output and its impact on the customer, employee, or other person.
For example, a marketing department might generate product graphics. In such a case, the nature of AI intervention and the way content is used must be assessed. A customer service department might use a chatbot – this introduces the issue of transparency and data flow. HR might use a tool to analyze candidates – this could lead to a high-risk classification. Management might use a model to analyze documents containing trade secrets.
Thus, a single enterprise can simultaneously have several systems belonging to entirely different regulatory categories.
This is precisely why AI Act legal support must be a process, not a single document.
Penalties for AI Act violations
The AI Act foresees high maximum levels of administrative fines.
For violations of prohibited practices under Article 5, the penalty can be up to 35 million euros or – in the case of an undertaking – up to 7% of its total annual worldwide turnover for the preceding financial year, whichever is higher according to the regulation's rules. For violations of a range of other obligations, including transparency obligations under Article 50, a maximum of 15 million euros or 3% of turnover is provided. For supplying incorrect, incomplete, or misleading information to competent authorities, the maximum threshold is 7.5 million euros or 1% of turnover. For SMEs, the regulation provides for the application of the lower of the relevant monetary and percentage thresholds.
Such values do not, of course, mean that every violation will result in the maximum penalty. When assessing sanctions, the circumstances of the specific case are important, and penalties must be effective, proportionate, and dissuasive. This does not change the fact that the scale of potential liability means that AI management should not be left solely to the informal decisions of individual employees.
AI Act in Poland – who will supervise businesses?
The AI Act itself is a European Union regulation, and thus directly applicable. However, Poland needed national regulations regarding the organization of supervision, procedures, and institutions responsible for applying the provisions.
The Act of July 3, 2026, on Artificial Intelligence Systems, came into force on August 11, 2026. Among other things, it establishes the framework for the functioning of the Polish supervision system and the Commission for the Development and Security of Artificial Intelligence (KRiBSI).
KRiBSI is to be an independent body supervising the application of AI regulations in Poland. The Ministry of Digitization indicates that the Commission will, among other things, consider reports of irregularities in the operation of AI systems, support the development of regulatory sandboxes, and issue individual opinions. The Chairperson of the Commission is to be appointed within two months of the Act's entry into force, and the entire Commission within three months; according to information from the Ministry, this means it will begin operations in November 2026.
For entrepreneurs, this is a significant change. The AI Act ceases to function solely as a European legal act discussed in the context of future regulations. A national infrastructure for its supervision and enforcement is being established.
AI Act lawyer - when does a company truly need support?
Not every company using a simple AI tool needs a multi-month implementation project. At the same time, the scale of obligations cannot be assessed solely based on the size of the enterprise.
A small online store might use a chatbot, automatically generate product photos, and transmit customer data to external tools. A large organization, on the other hand, might only use AI internally for preparing draft document summaries.
It is the use case, not the company's turnover, that reveals the true scale of the problem.
An AI Act lawyer is especially needed when the company cannot unambiguously determine its role, uses multiple tools across different departments, AI impacts customers or employees, personal or confidential data enters the systems, the organization develops its own solution, or implements a system that might fall into a high-risk category.
However, the role of a lawyer should not be to block technology. Properly prepared AI Act legal support should help differentiate applications that genuinely require extensive safeguards from those where simpler organizational solutions suffice.
The goal is to create an AI usage model that allows the company to develop automation without building legal risks that no one had previously identified.
AI Act legal support and e-commerce
In e-commerce, the problem is particularly multidimensional. Artificial intelligence is increasingly present simultaneously in marketing, product presentation, customer service, user behavior analysis, recommendations, personalization, content creation, and internal team work.
Therefore, implementing the AI Act in an online store cannot be limited to adding one paragraph to the privacy policy.
It is necessary to check whether the customer knows when they are interacting with AI, what data they are providing to the chatbot, how generated photos and content are used, under what rules AI tools process user information, and whether automation affects decision-making regarding specific individuals.
At the same time, the documentation must reflect the actual process. Regulations, privacy policies, and a chatbot message will not solve the problem if employees continue to send customer data to public models without established rules.
In this area, therefore, the combination of law, technology, and operational practice is particularly important—exactly as with other e-commerce regulations.
The most common mistake: companies only analyze officially implemented systems
Organizations are increasingly experiencing a phenomenon known as shadow AI. Employees begin using artificial intelligence tools without formal implementation, often using their own accounts or free versions of services.
Management might therefore be convinced that the company "does not yet use AI," while the technology is already being used for daily work in several departments.
Such situations are particularly problematic because the organization does not control what data enters the systems and under what conditions it is processed.
Therefore, an AI audit should cover not only tools purchased by IT or listed in the software register. It should also examine the actual practices of employees.
Only then is it possible to prepare a procedure that corresponds to reality.
Can a company simply ban the use of AI?
Technically, an enterprise can restrict the use of certain tools. In practice, a complete ban often does not solve the problem.
If AI genuinely increases employee efficiency, too broad a ban can lead to the use of technology being moved outside official channels. The company then loses visibility and control over the process.
A more mature solution is to define which tools may be used, for what purposes, with what data, and with what level of human control.
AI governance should therefore support the safe use of technology, rather than merely impose prohibitions. This is where legal regulations, information security, and business needs should be combined into one process.
Should every company have an AI policy?
The AI Act does not introduce a single universal provision requiring every entrepreneur to create a document titled "AI Policy."
However, this does not mean that internal rules are not needed.
If many people in an organization use AI, customer or employee data enters the systems, or the tools are important for business processes, documented rules become a practical way to manage risk and demonstrate that the company has not left the use of artificial intelligence to chance.
The scope of documentation should be proportionate to the company's activities. A small store using a few standard tools will need a different solution than an organization building its own AI systems or applying algorithms in HR processes.
Does using ChatGPT automatically mean falling under the AI Act?
Simply using a popular generative model in professional activities means that an enterprise may be an operator of an AI system within the meaning of the regulation. However, this does not automatically entail an extensive set of obligations typical for high-risk systems.
The way it is used matters.
If an employee uses the model to prepare a draft article title, the situation is different from integrating the model into a process that automatically evaluates job candidates.
Therefore, the analysis should concern the application, not merely the fact of having an account with a specific service.
Does AI-generated content always need to be marked?
No.
The AI Act foresees specific transparency obligations, but their scope depends on the type of system, the content, and the role of the entrepreneur. The obligations of a provider of a generative system regarding the machine-readable marking of its outputs are different from the obligation of an AI system operator regarding the disclosure of specific deepfakes. Different rules also apply to texts published to inform the public about matters of public interest.
Therefore, automatically marking everything with "created with AI" is not a universal principle for all content directly derived from the AI Act.
On the other hand, a lack of any analysis can lead to missing an obligation where marking is indeed required.
Does the AI Act restrict the ability to use artificial intelligence?
The fundamental premise of the regulation is not to prohibit businesses from using artificial intelligence.
The AI Act establishes a system where the scope of restrictions and obligations depends on the risk of a particular application. Most everyday applications of the technology are not prohibited. Problems arise when the system enters areas considered particularly sensitive, or when the company fails to fulfill its obligations related to its application.
Therefore, compliance should answer the question, "how to use AI legally?" rather than "how to stop using AI?"
AI Act legal support - what can cooperation with ecommerce.legal look like?
Adapting a company to the AI Act should correspond to its actual operating model.
At ecommerce.legal, we start the analysis by examining how artificial intelligence is used within the organization. We check processes, tools, the entrepreneur's roles, data flow, and areas where AI's operation can affect customers, employees, or other individuals.
Based on this, it is possible to determine which obligations truly apply and which elements need to be organized. Depending on the project, AI Act legal support may include auditing existing solutions, classifying systems, preparing policies and procedures, analyzing transparency, verifying GDPR documentation and vendor contracts, and supporting the implementation of new systems.
This approach helps avoid two extremes. The first is ignoring regulations because the company "only uses off-the-shelf tools." The second is creating an extensive documentation system where the nature of AI application does not justify it.
AI Act - summary
Artificial intelligence is already part of normal business operations. That's why the AI Act is not just a regulation for tech companies.
For most organizations, the first task should not be to look for a ready-made AI policy template, but to gain knowledge about where and how artificial intelligence is actually used. Only on this basis can the roles resulting from the regulation, the risk level of individual applications, transparency obligations, and the relationship of the AI Act with GDPR, labor law, consumer rights, or intellectual property be established.
As of August 2, 2026, significant transparency requirements, among others, will apply. At the same time, following changes introduced by the AI Omnibus, the most important obligations concerning high-risk systems will be applied later – from December 2, 2027, and August 2, 2028, respectively.
Poland also has its own law organizing the national AI supervision system, which came into force on August 11, 2026.
This is a good time for companies to transition from spontaneous use of artificial intelligence to conscious management of it. The sooner processes, responsibilities, and rules for using AI are organized, the easier it will be to implement subsequent solutions without having to fix the entire system only when an audit or a problem with a specific application arises.
If your company already uses artificial intelligence tools or plans wider implementation, the ecommerce.legal team can analyze the current AI usage model, determine the obligations arising from the AI Act, and prepare appropriate legal and organizational solutions.