Sunday, September 6, 2026

News

UODO Report: Nearly Half of Polish Institutions Still Not Using AI

PolicyPatryk Raba

A new report from Poland's data protection authority UODO finds that 42.7 percent of surveyed organizations do not use artificial intelligence at all, while nearly 96 percent feel unprepared to apply GDPR in the context of AI.

Contents
  1. Who actually uses AI
  2. A systemic GDPR problem
  3. The barriers aren't technological
  4. What UODO proposes

UODO (Poland's Personal Data Protection Office) has published a strategic report showing that Polish institutions are adopting artificial intelligence far more slowly and chaotically than the prevailing AI-boom narrative would suggest. The study covered nearly 500 organizations, mostly from the public sector, and revealed a gap between declared and actual use of the technology.

The report is titled "Strategic Report: A Study of Organizations' Needs Regarding the Use of Artificial Intelligence and Personal Data Protection" and was produced under the Social Expert Team at the President of UODO, specifically its working group on artificial intelligence. The authors are Maria Drabczyk, president of the Digital Centre Foundation, and Dr. habil. Dominik Lubasz, an attorney.

Who actually uses AI

The data show that only 16.7 percent of surveyed organizations have AI integrated into their daily work. Another 16.3 percent say they are interested but don't know where to start, while about 40 percent are at the pilot, testing, or implementation-planning stage. The remaining 42.7 percent do not use AI at all.

Where AI is already in use, it most often serves to automate administrative processes (41.2 percent of responses), analyze data and forecast (31 percent), handle customers or petitioners (28 percent), and support research and development work (28.2 percent). Service personalization appeared in only 11.1 percent of responses, showing that Polish institutions treat AI mainly as a tool for easing bureaucratic burden rather than for building new products.

A systemic GDPR problem

The most troubling finding concerns compliance with personal data protection rules. Nearly 96 percent of organizations rate themselves as unprepared or uncertain about applying GDPR in the context of AI. On top of that, 41 percent of respondents either see no connection between building their own AI systems and processing personal data, or are unable to judge it.

The data we obtained in the study clearly indicate that we are dealing with a systemic problem - Dr. habil. Dominik Lubasz, attorney, co-author of the UODO report

The report's authors highlight a phenomenon known as "shadow AI", meaning employees' uncontrolled use of tools such as ChatGPT without their employer's knowledge or consent. In practice, this means personal data ends up in external systems without any legal assessment, and the actual scale of AI use within organizations is larger than official declarations suggest.

The actual scale of AI use is probably far greater than what the surveyed organizations' declarations would suggest - Dr. habil. Dominik Lubasz, co-author of the UODO report

The barriers aren't technological

Among the obstacles to AI adoption, respondents most often cited a lack of suitable data for training models, a lack of support from superior units, ethical or reputational concerns, and complicated AI regulations. The report's authors stress that these are organizational and regulatory barriers, not technical limitations of the tools themselves.

Respondents rated practical, sector-specific guidelines as the most valuable form of support, giving them 4.57 points on a five-point scale. They value concrete, ready-to-use solutions more highly than general training or abstract strategic declarations.

Respondents rated practical guidelines highest among all forms of support, at 4.57 on a five-point scale - Dr. habil. Dominik Lubasz, co-author of the UODO strategic report

What UODO proposes

The report recommends creating sector-specific "AI Compliance Starter" packages, data protection impact assessment (DPIA) templates for specific AI use cases, decision maps, and risk repositories. The authors stress that different sectors, such as education, healthcare, or local government, face different problems and need separate support tracks rather than one universal set of guidelines.

For Polish employers, especially in the public sector, the report is a signal that deploying AI without a parallel assessment of personal data protection risk can carry serious legal consequences. The shadow AI phenomenon means that even organizations that declare no AI deployments may already be processing personal data through tools employees use without formal approval.

UODO says the report's findings will be used to prepare sector-specific guidelines and support materials for public and private institutions. For now, though, as the study shows, most organizations in Poland have neither an AI implementation strategy nor mechanisms to check compliance with data protection rules, which, amid growing pressure to digitize, could become a real legal problem in the coming months.

Share: