Specializations
Artificial Intelligence (AI)
We advise on the legal and regulatory aspects of implementing artificial intelligence systems.
Artificial intelligence is increasingly used in key business processes, including customer risk assessment, scoring, fraud prevention, AML, customer service, complaint automation, marketing, HR and data analytics. For many businesses, AI is no longer a technological experiment but an integral part of their core operations.
However, implementing an AI system requires not only a technological assessment, but also a legal and regulatory analysis. It is crucial to determine whether a given solution falls within the scope of AI regulations, whether it may qualify as a high-risk AI system, what obligations apply to the provider or deployer of the system, and how to properly secure data, documentation, liability and relationships with technology providers.
We support businesses in designing, implementing and using AI systems in compliance with regulatory requirements and business realities. We advise in particular entities operating in the FinTech, LendTech, payment services, AML, crypto-assets and e-commerce sectors, as well as ICT providers serving the financial industry.
We help clients classify AI systems, assess regulatory risks, prepare documentation for high-risk AI systems, conduct DPIA and FRIA assessments, develop AI governance policies, negotiate agreements with AI and ICT providers, and represent clients in dealings with supervisory authorities.
Based on Polish and European regulations concerning artificial intelligence, personal data protection, cybersecurity, ICT outsourcing, financial services and consumer protection, we provide comprehensive legal support for the implementation and use of AI systems.
Our advisory services include in particular analysis of the following regulations and areas:
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act);
- the proposed Polish Act on Artificial Intelligence Systems, particularly in relation to supervision, inspections, penalties, individual opinions and relations with authorities;
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the Polish Personal Data Protection Act of 10 May 2018;
- Regulation (EU) 2022/2554 of the European Parliament and of the Council (DORA);
the Polish National Cybersecurity System Act of 5 July 2018 and regulations implementing the NIS2 Directive; - the Polish Payment Services Act of 19 August 2011;
the Polish Anti-Money Laundering and Counter-Terrorist Financing Act of 1 March 2018; - the Polish Consumer Credit Act of 12 May 2011;
- Regulation (EU) 2023/1114 of the European Parliament and of the Council (MiCA);
the Polish Act on the Provision of Electronic Services of 18 July 2002; - Regulation (EU) 2022/2065 of the European Parliament and of the Council (DSA), where AI systems are used in digital services, platforms, marketplaces or communication with users.
We support clients both at the concept and design stage of AI systems, as well as during implementation, commercial launch, ongoing monitoring and interactions with supervisory authorities.
- Does a given solution qualify as an AI system under applicable regulations?
- Can an AI system be classified as a high-risk AI system?
- What obligations apply to an AI system provider?
- What obligations apply to an entity using an AI system?
- Does AI implementation require additional documentation?
- Is a DPIA required for a given AI system?
- Is a FRIA required for a given AI system?
- How can AI be lawfully used in scoring, AML, fraud detection or customer service?
- How should the use of ChatGPT, Copilot or other GenAI tools by employees be regulated?
- What provisions should be included in an agreement with an AI system provider?
- Who is liable for malfunctioning or incorrect operation of an AI system?
- How should human oversight over AI systems be ensured?
- What information must be provided to customers or users of the system?
- How should an organisation prepare for an inspection or inquiry from a supervisory authority?
- Is it worth applying for an individual opinion regarding the application of AI regulations?
- Classification of AI systems from a regulatory perspective.
- Assessment of whether an AI system qualifies as high-risk.
- Determining the client’s role within the AI value chain, including provider, deployer, importer or distributor status.
- Preparation and verification of documentation for high-risk AI systems.
- Development of AI risk management procedures.
- Preparation of AI governance policies.
- Development of internal rules for the use of GenAI tools by employees.
- Conducting DPIAs for AI implementations involving personal data processing.
- Conducting FRIAs, i.e. assessments of the impact of AI systems on fundamental rights.
- Legal analysis of AI systems used in scoring, AML, fraud detection, KYC, customer service, HR and marketing.
- Verification of information obligations towards customers, users and employees.
- Analysis and negotiation of agreements with AI and ICT providers.
- Drafting clauses regarding liability, audits, documentation, data, cybersecurity, IP, SLAs and exit plans.
- Advising on DORA, ICT outsourcing and cybersecurity risks related to AI implementation.
- Preparation of applications for individual opinions concerning the application of AI regulations.
- Preparation of legal opinions, responses to regulatory inquiries, and representation in proceedings and inspections.
- Training for management boards, legal departments, compliance teams, DPOs, IT teams, product owners and employees using AI tools.
We advise businesses that develop, implement or use artificial intelligence systems in their operations. We particularly support entities operating in regulated sectors, where AI implementation involves not only technological risks, but also regulatory obligations, data protection requirements, interactions with supervisory authorities and liability towards customers.
We support in particular:
- fintech companies;
- banks and financial institutions;
- domestic and small payment institutions;
- electronic money institutions;
- lending institutions and LendTech entities;
- providers of AML, KYC, fraud detection and scoring services;
- ICT providers and software houses serving the financial sector;
- CASPs and entities operating in the crypto-assets market;
- e-commerce platforms and digital service providers;
- organisations implementing GenAI tools internally.
We continuously monitor the development of AI regulations in Poland and the European Union, as well as the practices of supervisory authorities. Thanks to our experience in advising regulated entities, we help clients implement AI solutions in a practical, secure and business-oriented manner.
Monika Macura