News
Polish Public Agencies Don't Know Which Systems Fall Under the EU AI Act

A report from Watchdog Polska shows that public institutions interpret the EU AI Act's definition of artificial intelligence in wildly inconsistent ways, just months before full enforcement begins on August 2, 2026.
Contents
The Zakład Ubezpieczeń Społecznych (ZUS, Poland's social insurance institution) uses a predictive model to assess sick leave claims, assigning each one a risk score, yet the agency does not consider this an artificial intelligence system. The Agencja Bezpieczeństwa Wewnętrznego (ABW, Poland's Internal Security Agency) refuses to answer any questions at all, arguing that merely admitting to AI use would reveal its operational methods. Two municipal offices denied using AI, even though they had issued administrative decisions citing fabricated legal provisions, a telltale sign of generative language models at work.
A definition that doesn't work
Article 3(1) of the EU's AI regulation defines an AI system as a mechanism that operates with a degree of autonomy, is capable of adapting after deployment, and infers how to generate outputs such as predictions, content, recommendations, or decisions that affect physical or virtual environments. The definition covers both generative chatbots like ChatGPT and Claude and the predictive models and scoring tools that public administration has used for years.
Watchdog Polska's report finds that agencies interpret this provision in wildly different ways. Some institutions classify plain OCR software that reads text from scanned documents as an AI system, others count only content-generating applications like ChatGPT as AI, and still others refuse to disclose advanced analytical models, claiming their solutions don't meet the regulation's definition.
Specific cases
ZUS uses a predictive system that analyzes medical certificates and assigns each sick-leave claim a score for likely irregularities. Despite relying on predictive-analytics techniques, the institution does not classify this mechanism as an AI system covered by the regulation, and so it has not implemented the required safeguards, such as risk classification or a fundamental-rights impact assessment.
The STIR system (Szybkie Informowanie o Ryzyku, or Rapid Risk Reporting), run by Poland's National Revenue Administration, analyzes the risk of banking fraud and calculates the indicators that determine whether an account gets frozen. The system's functions suggest it relies on AI technology, but the Ministry of Finance and the clearing house that operates it have disclosed only the bare minimum, citing operational secrecy. The ABW took the same approach, refusing to disclose any details about the tools it uses.
The local government paradox
The starkest example of the problem comes from two municipalities that, in response to Watchdog Polska's questions, formally denied using AI at all, even as they issued administrative decisions bearing the hallmarks of generative language models, including citations to legal provisions that don't exist. It shows that civil servants are reaching for tools like ChatGPT in their daily work without their superiors' knowledge and without any check on the quality of the generated content.
Every entity has to assess for itself whether a given system meets the definition in Article 3(1), including determining its role as a provider or a deployer, which is what determines the scope of its obligations - Paweł Dymek, lawyer, Głowacki i Wspólnicy law firm
Arguments over definitions can become a pretext for avoiding transparency. Institutions claim that a tool isn't an AI system, that using it is optional, or that a human makes the final decision - Michał Zemełka, Watchdog Polska
The penalties for concealment
The regulation gives supervisory authorities real leverage. Article 80 of the AI Act allows them to intervene when an institution deliberately understates its system's risk level, and Article 99 provides for steep financial penalties for ignoring orders to come into compliance, if a review finds that a high-risk system was operating without the required safeguards.
Watchdog Polska recommends adopting a single, operational definition of AI for public administration, based on a system's actual function and its impact on citizens rather than on the operator's own say-so. The organization also proposes creating a public, central registry of AI applications used by government agencies, along with an independent mechanism for quickly reviewing refusals to disclose information.
Why it matters for Poland
With full entry into force of the AI Act on August 2, 2026, drawing near, the report shows that a large share of public administration cannot even inventory which AI tools it uses. Without that inventory, it's hard to see how agencies can meaningfully implement the transparency, risk-assessment, and high-risk-system oversight obligations the regulation imposes on public institutions.
The problem extends beyond large central institutions to small municipalities, where awareness of the obligations under the EU regulation is even lower. Among smaller local governments, the share of units with any internal AI usage rules at all falls below one percent, meaning that in practice civil servants are operating with no guidance whatsoever.
