<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AI Governance - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/ai-governance/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/ai-governance/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Mon, 05 Oct 2026 09:55:27 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>A Human in the Loop, Data under Control. The GDPR and the AI Act in Implementation Practice</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/ai-act-and-gdpr-ai-governance-compliance/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/ai-act-and-gdpr-ai-governance-compliance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 05 Oct 2026 09:55:26 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[algorithmic bias]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Data Protection Law]]></category>
		<category><![CDATA[DPIA]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[FRIA]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[high-risk AI]]></category>
		<category><![CDATA[Human Oversight]]></category>
		<category><![CDATA[large language models]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Machine Learning]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[PRIVACY]]></category>
		<category><![CDATA[workplace AI]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8947</guid>

					<description><![CDATA[<p>Publication date: October 05, 2026 Implementing artificial intelligence in an organisation does not begin with choosing a tool, but with answering the question of who we are in the AI value chain and what we are responsible for. This article sets out the relationship between the GDPR and the AI Act: from the roles of [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/ai-act-and-gdpr-ai-governance-compliance/">A Human in the Loop, Data under Control. The GDPR and the AI Act in Implementation Practice</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: October 05, 2026</strong></mark></p>



<p>Implementing artificial intelligence in an organisation does not begin with choosing a tool, but with answering the question of who we are in the AI value chain and what we are responsible for. This article sets out the relationship between the GDPR and the AI Act: from the roles of provider, deployer and controller, through algorithmic risks, the limits of lawfulness in the workplace and the rights of individuals, to the DPIA, the FRIA and the AI Governance model. It reflects the legal position following the entry into force of the Polish Act on Artificial Intelligence Systems and the postponement of the AI Act application dates by Regulation (EU) 2026/1744.</p>



<span id="more-8947"></span>



<h2 class="wp-block-heading"><strong>Introduction</strong></h2>



<p>Rapid technological progress and the widespread deployment of systems based on artificial intelligence are permanently reshaping the landscape of modern economic and social life. The use of machine learning algorithms and large language models in professional processes opens up unprecedented opportunities for optimisation, allowing the automation of tasks that previously required prolonged human effort. This technological efficiency, however, brings significant ethical and legal challenges and calls into question existing standards of privacy protection. In an era of such profound digital transformation, the key task is to develop a regulatory framework that balances the drive for innovation against the imperative of protecting fundamental rights. It must be remembered that AI systems, despite their apparent infallibility, operate on data that may be erroneous, biased or out of date. As a result, algorithm-based decision-making processes directly affect the legal and personal situation of natural persons, which creates a need to define precisely who is responsible for the outcome of the technology.</p>



<p>Regardless of how advanced AI tools become, the paradigm of human oversight must remain the fundamental principle of safe implementation. A human being cannot be reduced to a mere recipient of output data; they must perform an active supervisory function and act as a guarantor of reliability and safety when the algorithm fails. The AI Act<a href="#_ftn1" id="_ftnref1">[1]</a> establishes rigorous procedures and imposes specific restrictions on providers, deployers and other links in the artificial intelligence value chain. In relation to the GDPR<a href="#_ftn2" id="_ftnref2">[2]</a>, the AI Act is complementary: it does not repeal existing data protection principles but refines them in a technological context. The AI Act adds an additional layer of product-related and ethical obligations, ensuring that algorithms are used with respect for the rights and freedoms of the individual. Much of this framework already applies: the prohibitions in Article 5 AI Act have applied since 2 February 2025 and the transparency obligations in Article 50 AI Act since 2 August 2026, while Regulation (EU) 2026/1744 (the so-called Digital Omnibus on AI) has postponed the application of the obligations for stand-alone high-risk systems listed in Annex III to 2 December 2027. In Poland, the national framework is set out in the Act of 3 July 2026 on Artificial Intelligence Systems (Journal of Laws, item 1003), which established the Commission for the Development and Safety of Artificial Intelligence (KRiBSI) as the market surveillance authority.</p>



<h2 class="wp-block-heading"><strong>1st         Who Is Who in the AI Ecosystem: Provider, Deployer, Controller</strong></h2>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>a)    Provider or Deployer? The Answer Determines the Scope of Liability</strong></h3>



<p>Defining an organisation&#8217;s role in the artificial intelligence ecosystem is of key importance for determining its legal obligations precisely. It must be established whether a given entity acts as the provider of an AI system or is merely a deployer of a ready-made technological solution. Under Article 3(3) AI Act, a provider is a natural or legal person, public authority, agency or other body that develops an AI system (or a general-purpose AI model) or has it developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. The provider&#8217;s principal task is therefore to create the technology and ensure its compliance with rigorous safety and data quality requirements before the commercialisation stage. Most organisations using AI systems will not act as providers but as deployers. This distinction is fundamental to risk analysis: while the provider is responsible for the architecture and the training process (compliance of the “product”), the deployer is responsible for how the system is operated, for instructions to employees and for the lawfulness of the data entered into the model during the inference phase.</p>



<p>Under Article 3(4) AI Act, a deployer may be a natural or legal person, public authority, agency or other body that uses an AI system under its authority. These features clearly distinguish the provider of an AI system from an entity that merely uses the supplied system and exercises authority over it. In addition, an entity using artificial intelligence systems may acquire the status of a controller of personal data once it meets the definitional criteria set out in Article 4(7) GDPR. A controller is therefore a natural or legal person, public authority or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. It should be stressed that an AI system itself has no legal personality, and responsibility for its actions rests with the entity that decides on its deployment and operating parameters. Data processing in this context takes place through operations or sets of operations performed on personal data by automated means, which falls within the broad definition in Article 4(2) GDPR. These processes include, in particular, the collection, recording, adaptation, consultation and use of data by algorithms in order to generate results (<em>output</em>). In the case of AI systems, this processing is highly automated and is usually aimed at optimising and increasing the operational efficiency of information processes, which places a particular duty on the controller to keep control over every stage of the data life cycle.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>b)    When an AI System Becomes a High-Risk System</strong></h3>



<p>Under the system adopted in the AI Act, the correct classification of artificial intelligence systems is of key importance for organisations, since solutions classified as high-risk systems are subject to the most stringent legal regime. An AI system acquires that status if it meets the conditions set out in Article 6(1) AI Act (this concerns systems that are products, or safety components of products, subject to EU certification) or if it is expressly listed in Annex III to the Regulation. That catalogue covers areas of critical importance for fundamental rights, such as biometrics and the categorisation of persons, the management of critical infrastructure, and education and vocational training. Particular attention should be paid to employment and workers management, access to essential public and commercial services, and systems used in law enforcement, migration management and the administration of justice. Classifying a technology in this category obliges the controller not only to ensure high-quality data and human oversight in accordance with the AI Act, but also to comply strictly with the GDPR, which in most cases will include carrying out a full data protection impact assessment (DPIA).</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>c)     Transparency, Instructions for Use and Human Oversight: Obligations in Practice</strong></h2>



<p>Providers must ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the persons concerned are informed that they are interacting with an AI system (Article 50(1) AI Act). High-risk AI systems must also be designed and developed in accordance with the principle of transparency of their operation (Article 13 AI Act), which enables deployers to interpret the system&#8217;s output and use it appropriately. It is also essential to attach instructions for use in an appropriate format, containing complete and comprehensible information for deployers. While AI systems are in use, it must be possible for natural persons to oversee the system (Article 14 AI Act) in order to prevent risks to health, safety or fundamental rights.</p>



<p>Deployers of high-risk AI systems must implement appropriate technical and organisational measures to ensure that they use such systems in accordance with the instructions for use supplied by the provider (Article 26(1) AI Act). Under Article 26(11) AI Act, deployers of the high-risk AI systems referred to in Annex III that make decisions, or assist in making decisions, related to natural persons must fulfil their information obligation before actually using the high-risk AI system, by clearly informing those persons that such technology is being used in relation to them.</p>



<p>In order to give full effect to the requirements of the AI Act, deployers are also obliged to assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary organisational support. Under Article 14(2) of the Regulation, “<em>human oversight shall aim to prevent or minimise the risks to health, safety or fundamental rights (…)</em>”. Article 14(4), in turn, requires providers to deliver a high-risk AI system to the deployer in such a way as to enable the natural persons to whom human oversight is assigned, among other things, “<em>to remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias), in particular for high-risk AI systems used to provide information or recommendations for decisions to be taken by natural persons</em>”.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>d)    Training and Inference: Where the Data Risk Hides in Language Models</strong></h2>



<p>The foundation of large language models (LLMs) is the processing of vast quantities of data, enabling the generation of text and the performance of advanced natural-language tasks. As tools belonging to generative artificial intelligence, these models operate on the basis of the statistical prediction of successive tokens (words or parts of words) in response to instructions entered by the user, known as prompts. In market and corporate practice, the most common are the GPT series models (OpenAI), implemented in solutions such as ChatGPT and Microsoft Copilot, as well as the Llama family of models (Meta), DeepSeek and the Polish projects Bielik and PLLuM. From a data protection perspective, the key distinction is between the two fundamental phases of a model&#8217;s operation: training and inference.</p>



<p><strong>Training phase</strong></p>



<p>In this phase, the substantive “intelligence” of the model is created. The process is based on the analysis of enormous data sets (Big Data) in order to detect statistical correlations between tokens. It should be emphasised that an LLM does not interpret content cognitively (in the human sense) but calculates the probability of the next element in a sequence. The data is often obtained through the mass collection of content from the open internet (web scraping). From the GDPR perspective, this is the most controversial stage, because the controller of personal data (usually the provider of the system) must demonstrate a specific legal basis and purpose for the processing (Article 6 GDPR). At this stage the provider becomes responsible for the quality of the data sets. Under Article 10 AI Act, training data sets must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the intended purpose of the system.</p>



<p><strong>Inference phase</strong></p>



<p>The inference phase is the operational stage in which the trained model generates answers to specific user queries (prompts), using the statistical weights developed during training. In this phase the model does not, as a rule, “learn” in real time but processes the information supplied to it at a given moment. From the perspective of an organisation deploying an AI system, this is the area of the highest legal risk. The key problem is employees entering customer data, personal information or trade secrets into queries sent to an external model. Such conduct constitutes a transfer of data to the provider&#8217;s servers, which often involves a transfer outside the European Economic Area (EEA). In this scenario the organisation acquires the status of a deployer within the meaning of Article 3(4) AI Act. Under Article 4(7) GDPR, the organisation, as the controller of its employees&#8217; and customers&#8217; data, bears full responsibility for the content of the information that reaches the AI system. So while the training phase remains the domain of large technology corporations (providers), the inference phase is the area in which every business bears direct responsibility for the security and lawfulness of the prompts it generates.</p>



<h2 class="wp-block-heading"><strong>2nd    Bias, Hidden Scoring and Explainability: Algorithmic Risks under Article 5 GDPR and Article 10 AI Act</strong></h2>



<p>The practical implementation of artificial intelligence systems in socially sensitive areas, such as the recruitment of employees or the assessment of creditworthiness, requires the systematic management of the risk of algorithmic error. The key challenge is to ensure the explainability of AI and to combat effectively the phenomenon of bias, which can lead to the discrimination of entire social groups. The foundation for counteracting these risks under data protection law is the set of principles expressed in Article 5(1) GDPR. Under the principle of transparency (point (a)), the organisation must be able to explain to the data subject the logic behind an autonomous decision of the algorithm. The principle of data minimisation (point (c)), in turn, requires the information collected to be limited to what is necessary for the purpose, which prevents models from being fed with redundant data or data that has no objective bearing on the result of the analysis. In this context, the prohibition of so-called hidden scoring takes on particular significance; this means an AI system covertly assessing, for example, job candidates by assigning them points without ensuring adequate transparency of the process. The controller, as the employer, is obliged under Article 13(2)(f) GDPR to provide the data subject with information about the existence of automated decision-making, including profiling (referred to in Article 22(1) and (4)), and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.</p>



<p>AI systems frequently rely on profiling mechanisms, that is, the automated processing of personal data consisting of the use of that data to evaluate certain aspects of a natural person, in particular their competence, expected work performance or other characteristics relevant to the purpose for which the AI tool is used. Under Article 22(1) GDPR, “<em>the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her</em>”, unless the decision is necessary for entering into or performing a contract, is authorised by Union or Member State law, or is based on the data subject&#8217;s explicit consent (Article 22(2) GDPR). Profiling as such is not prohibited in principle, but its use is subject to significant restrictions, particularly where it leads to decisions with significant effects on the person being profiled. In practice, this means that special care must be taken in designing and using AI tools, particularly with regard to the risk of bias. These systems learn from historical data, which may lead to the replication of earlier decision patterns and to unintended discrimination, for example on grounds of age, state of health or other personal characteristics. It is therefore essential to ensure transparency of the systems&#8217; operation, adequate human oversight and the ability to verify and challenge the results generated by AI.</p>



<p>Relying solely on the rules contained in the GDPR is not enough, however, when confronted with deep neural networks, which is why a key role is played by Article 10 AI Act, which governs data and data governance in high-risk AI systems. That provision imposes rigorous obligations on providers to examine and verify training, validation and testing data. These data sets must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the specific geographical, behavioural or functional setting in which the system is to operate. This requirement directly compels organisations to apply procedures for detecting and neutralising hidden bias (bias mitigation). For example, a recruitment algorithm trained on the historical data of a company in which mainly men were promoted may classify the female gender as a negative feature; Article 10 AI Act requires such anomalies to be actively monitored and corrected at the design stage and through continuous oversight of the system&#8217;s operation.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>3rd      Can an Employer Require the Use of AI? The Limits of Lawfulness in the Workplace</strong></h2>



<p>Assessing the lawfulness of deploying artificial intelligence systems in the workplace requires a precise delineation of the boundary between the employer&#8217;s managerial prerogatives and the fundamental rights of employees. Whether an employee can be required to use AI tools depends on the nature of the tool and the extent of its intrusion into the employee&#8217;s privacy. While issuing a work instruction to use AI as simple support in daily duties falls within the law, the deployment of monitoring, evaluation or biometric systems encounters strict legal barriers. The legal basis for deploying standard algorithms that optimise work processes is most often Article 6(1)(f) GDPR, that is, the legitimate interest of the controller (the employer). Its application is conditional, however, on passing the so-called balancing test, which must show that the employer&#8217;s economic or organisational interests do not override the autonomy, rights and freedoms of the persons employed. In the case of high-risk AI tools, the balancing test will generally be harder to pass, and legitimate interest alone may prove insufficient, particularly where the processing leads to decisions of the kind referred to in Article 22 GDPR.</p>



<p>The situation becomes radically more complicated where an AI system requires the processing of biometric data in order to operate (for example, facial recognition systems used to record working time or to analyse an employee&#8217;s emotions). Biometric data belong to the special categories of data whose processing is, as a rule, prohibited under Article 9(1) GDPR. For an employer to use such data lawfully, one of the exceptional conditions in Article 9(2) GDPR must be met; in the reality of Polish labour law this most often requires the employee&#8217;s explicit and fully voluntary consent (subject to the requirements of Article 22¹ᵇ of the Labour Code) or a specific legal provision imposing such an obligation on safety grounds. The employee&#8217;s lack of genuine freedom of choice in the relationship with the employer makes such consent extremely difficult to defend before the supervisory authorities.</p>



<p>The ultimate barrier to the implementation of high-risk algorithmic AI systems is Article 5 AI Act, which introduces a categorical list of practices prohibited in the European Union. On that basis it is unlawful to deploy AI systems used for so-called <em>social scoring</em> (the point-based classification of citizens or employees on the basis of their social behaviour), as well as systems that carry out biometric categorisation in order to infer sensitive characteristics (for example political opinions or sexual orientation). Moreover, in the context of employment relationships, the AI Act prohibits the use of emotion recognition systems in the workplace (Article 5(1)(f) AI Act), except for systems put in place for medical or safety reasons, which in practice closes the door to employers algorithmically testing the mood or stress levels of their staff. These prohibitions have applied since 2 February 2025, and Regulation (EU) 2026/1744 extends their catalogue from 2 December 2026.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>4th       Individuals versus the Algorithm: Erasure, Human Intervention, Transparency</strong></h2>



<p>The informational and technological asymmetry between the individual and the entities deploying artificial intelligence systems requires effective instruments of legal protection. The greatest controversy in this area currently surrounds the exercise of rights of an erasure nature. Enforcing the right to be forgotten under Article 17 GDPR encounters a fundamental technical barrier in the form of the so-called “memory” of generative models and neural networks. In traditional databases, deleting information means erasing a specific record. In the case of AI models, input data becomes irreversibly integrated into the structure of the model&#8217;s mathematical weights during the training process. Reversing that state, described in the literature as machine unlearning, is a complex and costly process and often simply impossible without retraining the model in its entirety. This creates a deep conflict between the individual&#8217;s right to demand the erasure of their data and the architecture of modern technologies.</p>



<p>Another key safeguard is Article 22 GDPR, which lays down a general prohibition on subjecting natural persons to decisions based solely on automated processing, including profiling, which produce legal effects concerning them or similarly significantly affect them. This provision gives the individual the right to obtain human intervention (<em>human-in-the-loop</em>), to express their own point of view and to contest a decision taken by an algorithm (for example, an automated refusal of credit or rejection of a job application). Supervisory authorities&#8217; guidelines and the case law of the CJEU (including the judgment of 7 December 2023 in Case C-634/21 SCHUFA Holding) indicate that human involvement in the decision-making process may not be fictitious or token; a manager or analyst must have a real ability to change the verdict generated by the AI. These guarantees are complemented, at the level of direct interaction with the technology, by the information obligations arising from Article 50 AI Act, applicable since 2 August 2026. That provision imposes strict operational transparency requirements on providers and deployers of artificial intelligence systems. Under it, every natural person interacting with an AI system, such as a chatbot or voice assistant, must be clearly and promptly informed of that fact, unless this is obvious from the context of use. Equally strict obligations apply to the labelling of synthetically generated content, including so-called deepfakes. Deployers of AI systems that generate or manipulate images, audio or video content in such a way that it closely resembles authentic persons or events are legally required to disclose that the content has been artificially generated. The purpose of this regulation is to protect the cognitive autonomy of the individual and to counter mass disinformation.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>5th       Four Risk Tiers and a New Supervisory Map: KRiBSI alongside the President of the Personal Data Protection Office</strong></h2>



<p>A key element of the EU strategy for regulating artificial intelligence is the risk-based approach, which directly determines the scope of the legal obligations imposed on organisations. The Artificial Intelligence Act introduces a rigid division of systems into four categories: prohibited practices (posing an unacceptable risk to fundamental rights), high-risk systems, limited-risk systems (mainly subject to information obligations) and minimal-risk systems. From the operational perspective of businesses and public institutions, the most important category is that of high-risk systems, whose definition and classification mechanism are governed by Article 6 AI Act. That provision refers directly to Annex III to the AI Act, which contains a closed catalogue of critical areas, including workers management and access to employment (HR), education and vocational training, as well as law enforcement and the management of critical infrastructure. Implementing AI tools in these sectors triggers a strict legal regime, including the need to implement a risk management system, ensure high-quality data and provide human oversight. Under Regulation (EU) 2026/1744, these obligations will apply to stand-alone systems listed in Annex III from 2 December 2027 and to systems embedded in products covered by Annex I from 2 August 2028; the postponement does not, however, change the scope of the requirements but merely gives organisations time to implement them.</p>



<p>From the perspective of mapping risk within an organisation, this classification has profound consequences under data protection law. The Act of 3 July 2026 on Artificial Intelligence Systems entrusted market surveillance to the Commission for the Development and Safety of Artificial Intelligence (KRiBSI), which from 28 October 2026 acquires full powers of inspection and the power to impose the fines provided for in the AI Act. This does not, however, exclude the President of the Personal Data Protection Office (PUODO). Under Article 74(8) AI Act, in respect of the high-risk AI systems listed in Annex III, point 1 (biometrics, in so far as used for law enforcement, migration and the administration of justice), point 6 (law enforcement), point 7 (migration and asylum) and point 8 (administration of justice and democratic processes), market surveillance is linked to the data protection authorities, and the PUODO consistently emphasised, already in its comments on the draft act, that any processing of personal data in AI systems remains within its competence under the GDPR. This means that a compliance audit cannot be limited to a standard data protection impact assessment (DPIA). The organisation must take account of a dual supervision model in which KRiBSI verifies the system&#8217;s compliance with the AI Act, while the data protection authority retains full investigative and corrective powers in respect of the processing of personal data, including the data used to build the model. Ignoring this dual competence at the system design stage (<em>privacy and compliance by design</em>) exposes controllers to a serious risk of financial penalties and administrative sanctions in the form of an order to shut down the algorithm immediately.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>6th       DPIA and FRIA: from a Document in a Drawer to a Dialogue with the Regulator</strong></h2>



<p>Because of their systemic and often unpredictable impact on privacy, the deployment of advanced artificial intelligence systems in most cases automatically triggers an obligation to carry out a data protection impact assessment. Under Article 35 GDPR, that assessment (Data Protection Impact Assessment, DPIA) is mandatory whenever processing using new technologies is likely to result in a high risk to the rights or freedoms of natural persons, which, in the context of recruitment or credit-assessment algorithms (mentioned above in relation to the principles of minimisation and transparency in Article 5 GDPR), is an operational standard. The contemporary AI legal regime, however, dramatically extends that obligation. Under Article 27 AI Act, public bodies and private entities providing public services, as well as deployers of the high-risk AI systems referred to in Annex III, point 5(b) and (c), are required to carry out a rigorous fundamental rights impact assessment (FRIA). The entities referred to in Annex III, point 5(b) and (c) AI Act are those using high-risk AI systems to evaluate the creditworthiness of natural persons or establish their credit score, and systems used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. This mechanism cannot operate in isolation from the GDPR; in practice, the FRIA becomes an integral, deeper extension of the classic DPIA, requiring the organisation to examine the impact of the algorithm not only on privacy but also on human dignity, non-discrimination and the right to a fair trial, that is, the impact on the fundamental rights of the persons in relation to whom the AI systems are used.</p>



<p>The traditional approach, in which the DPIA was merely an internal, static corporate document filed away in a drawer, is becoming a thing of the past when confronted with Article 57(10) AI Act, which governs so-called regulatory sandboxes. These sandboxes, which are controlled testing environments for innovative AI solutions, redefine the relationship between the controller and the supervisory authority. An organisation that decides to participate in a regulatory sandbox is legally obliged to cooperate closely and transparently with the authority operating the sandbox (in Poland, KRiBSI) and, in so far as the system under test processes personal data, also with the President of the Personal Data Protection Office (Article 57(10) AI Act). In this new model of cooperation, the DPIA process evolves into a tool for a dynamic, multilateral dialogue with the state authority. The results of the risk analysis are consulted on an ongoing basis, which makes it possible to eliminate algorithmic bias under the regulator&#8217;s eye before the system is commercialised. Such a compliance model not only minimises the risk of severe financial penalties but also makes it possible to build AI systems that are safe and transparent from the stage of their technological incubation.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>7th       AI Governance: How to Implement AI in an Organisation and Be Able to Prove It</strong></h2>



<p>Effective management of artificial intelligence systems within an organisation requires a multi-level oversight model (AI Governance<a href="#_ftn3" id="_ftnref3">[3]</a>) that combines technical protective measures with a systematic assessment of legal risk. The foundation for designing safe algorithms is formed by the principles of data protection by design and by default, codified in Article 25 GDPR. They oblige the organisation to take privacy protection and data minimisation into account at the earliest stage of creating the architecture of the AI model, and also when selecting training data and model parameters. Article 32 GDPR, in turn, which lays down the principle of security of processing, takes on an entirely new technological dimension in the world of autonomous systems. Classic IT safeguards (such as encryption or access control) are no longer sufficient against the specific vulnerabilities of neural networks. Ensuring the integrity and confidentiality of data requires controllers to actively harden models against a new generation of cyberattacks, including <em>adversarial attacks</em><a href="#_ftn4" id="_ftnref4">[4]</a>, attempts to poison training data sets (<em>data poisoning</em>) and model inversion techniques aimed at extracting the personal data used to build the model.</p>



<p>The formal tool for verifying these safeguards and estimating the risks to natural persons remains the data protection impact assessment (DPIA) carried out under Article 35 GDPR. Because of the informational asymmetry and intrusiveness of AI models, however, this assessment ceases to be merely an internal, static document and becomes a platform for continuous monitoring. For artificial intelligence systems classified as high-risk solutions, the traditional DPIA must be integrated with the new, strict obligation under Article 27 AI Act: the fundamental rights impact assessment (FRIA). Only the synergy of the technical resilience of the model with a transparently conducted DPIA/FRIA procedure enables an organisation to demonstrate compliance and lawfully keep an AI system in commercial use.</p>



<h1 class="wp-block-heading"><strong>Summary and Conclusions</strong></h1>



<p>The analysis shows that the implementation of artificial intelligence systems, including advanced large language models (LLMs), redefines existing standards of privacy protection and requires organisations to build entirely new governance structures. The key to ensuring the lawfulness of data processing is the precise identification of the entity&#8217;s role in the AI ecosystem. The distinction between the provider, responsible for the training phase and the quality of the product data, and the deployer, which as controller bears full responsibility for the inference phase and the content of the prompts entered, is the starting point for effectively mapping regulatory risk under the GDPR and the Artificial Intelligence Act.</p>



<p>The main challenge for modern organisations is the management of specific algorithmic risks, such as the lack of explainability of machine decisions and hidden bias, which in sensitive areas such as recruitment or credit assessment may lead to the replication of discriminatory social patterns. Traditional data protection principles, in particular the principles of transparency and minimisation, gain strong support from Article 10 AI Act. That provision revolutionises compliance processes by imposing strict requirements for the verification of training data, with the aim of actively neutralising bias at the system design stage. Furthermore, the right to be forgotten (Article 17 GDPR) encounters a technological barrier in the form of the mathematical memory of neural networks, which means that the exercise of individuals&#8217; rights against the algorithm requires advanced procedures such as machine unlearning, and the unconditional guarantee of real rather than merely token human oversight (<em>human-in-the-loop</em>).</p>



<p>Equally important is the categorisation of systems by level of risk. Classifying AI tools as high-risk (for example in the employment sector or financial scoring) triggers strict information obligations and absolute prohibitions of impermissible practices, which include emotion recognition systems in the workplace and biometric profiling to infer sensitive characteristics. In this context, the classic data protection impact assessment (DPIA) is evolving: for high-risk systems it must be integrated with the fundamental rights impact assessment (FRIA) under Article 27 AI Act. In addition, the analysis of institutional roles points to a model of supervision shared between the newly established Commission for the Development and Safety of Artificial Intelligence (KRiBSI) and the President of the Personal Data Protection Office (PUODO), which retains full competence wherever an AI system processes personal data, while risk assessment processes cease to be static documents and become part of a dynamic dialogue with the regulator, including within regulatory sandboxes.</p>



<p>Consequently, the lawful and ethical use of artificial intelligence in modern business is not possible without a comprehensive oversight model: <em>AI Governance</em>. Traditional IT security measures must be extended to include mechanisms that harden models against a new generation of cyberattacks, such as <em>adversarial</em> attacks and <em>data poisoning</em>. The synergy of the principles of <em>privacy by design</em> and <em>privacy by default</em> with the rigorous procedures of the AI Act and the GDPR leads to the conclusion that the EU legal framework does not block innovation but civilises the process of digital transformation. It guarantees that technological development takes place within the limits of the law, with respect for the personhood and cognitive autonomy of the human being.</p>



<h2 class="wp-block-heading"><strong>Bibliography</strong></h2>



<h2 class="wp-block-heading"><strong>Legislation</strong></h2>



<ol class="wp-block-list">
<li>Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, as amended) – hereinafter: GDPR</li>



<li>Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance) (OJ L, 2024/1689, 12.7.2024) – hereinafter: AI Act</li>



<li>Act of 26 June 1974 – Labour Code (consolidated text: Journal of Laws of 2025, item 277, as amended).</li>
</ol>



<h2 class="wp-block-heading"><strong>Online Sources</strong></h2>



<ul class="wp-block-list">
<li>Letter of [date] issued by the President of the Personal Data Protection Office, ref. DOL.401.354.2024, <em>Comments of the PUODO on the draft Act on Artificial Intelligence Systems</em>, www.uodo.gov.pl.</li>



<li>Wolters Kluwer: “<em>Przetwarzanie danych osobowych na podstawie prawnie uzasadnionego interesu administratora</em>” [Processing of personal data on the basis of the controller&#8217;s legitimate interest], 12.12.2025, available online: https://www.lex.pl/test-rownowagi-rodo,43864.html</li>



<li>European Parliamentary Research Service (EPRS): <em>Artificial Intelligence Act: State of play and implementation challenges, European Parliamentary Research Service (EPRS) At a Glance Briefing</em>, Brussels 2026, [online], available at: https://www.europarl.europa.eu/RegData/etudes/ATAG/2026/785673/EPRS_ATA(2026)785673_EN.pdf (accessed: 29.05.2026).</li>



<li>Biznes Myśli: <em>Fine-tuning LLM – fakty i mity. Jak skutecznie dotrenować duży model językowy</em> [Fine-tuning LLMs – facts and myths. How to fine-tune a large language model effectively], [online], available at: https://biznesmysli.pl/fine-tuning-llm-fakty-i-mity/ (accessed: 29.05.2026).</li>



<li>LegalGeek: <em>AI Act vs RODO. Jak sztuczna inteligencja wpływa na ochronę danych osobowych</em> [AI Act vs GDPR. How artificial intelligence affects personal data protection], Legal Knowledge Portal for Business, [online], available at: https://legalgeek.pl/blog/ai-act-vs-rodo/ (accessed: 29.05.2026).</li>



<li>Wikipedia (the free encyclopedia): <em>Duży model językowy</em> [Large language model], [online], available at: https://pl.wikipedia.org/wiki/Du%C5%BCy_model_j%C4%99zykowy (accessed: 29.05.2026).</li>



<li>Data Science Robię: <em>AI Governance – co to takiego i dlaczego jest teraz kluczowe?</em> [AI Governance – what is it and why is it now key?], [online], available at: https://www.datasciencerobie.pl/ai-governance-co-to-takiego/ (accessed: 02.06.2026).</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p><a href="#_ftnref1" id="_ftn1">[1]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance) (OJ L, 2024/1689, 12.7.2024) – hereinafter: AI Act</p>



<p><a href="#_ftnref2" id="_ftn2">[2]</a> Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, as amended) – hereinafter: GDPR</p>



<p><a href="#_ftnref3" id="_ftn3">[3]</a> Data Science Robię: AI Governance – co to takiego i dlaczego jest teraz kluczowe? [AI Governance – what is it and why is it now key?], [online], available at: https://www.datasciencerobie.pl/ai-governance-co-to-takiego/ (accessed: 02.06.2026).</p>



<p><a id="_ftn4" href="#_ftnref4">[4]</a> adversarial attacks – the deliberate manipulation of input data in order to deceive the algorithm.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/ai-act-and-gdpr-ai-governance-compliance/">A Human in the Loop, Data under Control. The GDPR and the AI Act in Implementation Practice</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/ai-act-and-gdpr-ai-governance-compliance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 11:29:19 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[algorithmic decision-making]]></category>
		<category><![CDATA[algorithmic transparency]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[automated moderation]]></category>
		<category><![CDATA[Central Eastern Europe legal services]]></category>
		<category><![CDATA[compliance by design]]></category>
		<category><![CDATA[consumer protection law]]></category>
		<category><![CDATA[consumer reviews verification]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[digital platforms]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[e-commerce regulation]]></category>
		<category><![CDATA[European Union Law]]></category>
		<category><![CDATA[fake reviews]]></category>
		<category><![CDATA[fake reviews in e-commerce]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[international legal cooperation]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[marketplace regulation]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[online consumer protection]]></category>
		<category><![CDATA[online marketplaces]]></category>
		<category><![CDATA[online reputation management]]></category>
		<category><![CDATA[platform liability]]></category>
		<category><![CDATA[Poland technology law]]></category>
		<category><![CDATA[Polish e-commerce law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[review authenticity]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[unfair commercial practices]]></category>
		<category><![CDATA[uokik]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8830</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 10, 2026</mark></strong></p>



<p>The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer experience, misleads the recipient, directly influencing their decision-making process. Legally, a fake review is considered not only a completely false message, but also one that, by omitting important facts or manipulating context, creates a false impression of the quality of a product or the reliability of a seller. This practice is classified as unfair commercial activity if its nature causes or is likely to cause the average consumer to make a transactional decision they would not otherwise make, thus violating the fundamental principles of fair dealing.</p>



<span id="more-8830"></span>



<p>The typology of activities considered unfair rests on several fundamental pillars, the most blatant of which is direct fabrication. This involves posting or commissioning the creation of false recommendations from specialized external entities, such as marketing agencies, which directly violates regulations on combating unfair market practices. Another mechanism is selective manipulation, in which a business intentionally manages the visibility of reviews by removing, concealing, or delaying the publication of negative reviews while favoring positive ones. Such action distorts the image of actual customer satisfaction and is considered misleading regarding the essential characteristics of a product or service. An equally significant aspect is feigned verification, i.e., declaring that reviews come from real buyers without implementing proportionate and reasonable steps to verify their authenticity, which constitutes a direct violation of the disclosure obligations imposed by the Omnibus Directive.</p>



<p>Contemporary market practices have also evolved more subtle forms of manipulation, such as astroturfing, which involves creating artificial social support through employees or store owners posing as independent consumers. These activities often involve the manipulation of user profiles, where images generated by artificial intelligence algorithms are used to authenticate fictitious accounts, creating false social proof. Each of these practices, regardless of their technological sophistication, is subject to strict scrutiny by competition and consumer protection authorities.</p>



<p><strong>The role of the President of the Office of Competition and Consumer Protection and the responsibility of management boards</strong></p>



<p>The President of the Polish Office of Competition and Consumer Protection (UOKiK) serves as a central regulator in the legal system, endowed with rigorous powers to counteract violations of collective consumer interests. The main disciplinary instrument at the authority&#8217;s disposal is an administrative fine, which can be imposed in the amount of 10% of the turnover achieved by the entrepreneur in the financial year preceding the year of issuance of the decision. The amount of the fine is not determined arbitrarily, but rather results from precisely defined criteria, which include, above all, the scale of the violation, its duration, and the degree of intentionality of the perpetrator. Importantly, this fine is intended to serve not only a repressive function but, above all, a preventive and deterrent one, discouraging other market participants from engaging in similar unfair practices involving the manipulation of reviews or misleading as to the authenticity of reviews.</p>



<p>The enforcement procedure in consumer matters is designed to ensure high effectiveness of supervisory activities. A business subject to a sanction is obligated to settle the fine within 14 days of the decision becoming final, which directly contributes to the state budget. A crucial procedural element is the prejudicial nature of the decisions of the President of the Office of Competition and Consumer Protection (UOKiK), which means that the authority&#8217;s findings regarding violations of the law are binding on common courts in compensation cases brought by injured customers. This legal structure significantly facilitates consumers in pursuing civil claims, as they do not have to prove the illegality of the store&#8217;s actions, focusing solely on demonstrating the damage suffered. The office&#8217;s activity in recent years, reflected in numerous proceedings against e-commerce leaders, confirms that protecting the transparency of reviews has become a regulatory priority, translating into real and severe financial consequences for violators.</p>



<p>The contemporary model of liability in consumer protection law departs from a concept focused solely on the business entity, shifting the burden of sanctions also to individuals who actually manage the enterprise. The President of the Office of Competition and Consumer Protection (UOKiK) has the authority to impose a personal fine of up to PLN 2,000,000 on a manager. This liability is triggered by demonstrating that the manager has intentionally allowed – through their actions or conscious omissions – the company to violate collective consumer interests. In case law, the degree of management involvement in decision-making processes regarding marketing and communications is crucial. This liability may therefore affect a management board member who approves a budget for obtaining reviews from external opinion farms or ignores the lack of implementation of verification procedures under the Omnibus Directive, despite being aware of such deficiencies.</p>



<p>It should be emphasized that the responsibility of managers is autonomous and independent of any penalty imposed directly on the entrepreneur. This is intended to provide a strong incentive for management to build internal compliance structures and actively oversee the entity&#8217;s operational ethics. In the era of digitalization of trade, where algorithms and automation of marketing processes can generate violations on a massive scale, the personal financial risk of managers is intended to compel prioritizing compliance as the foundation of business strategy. Therefore, the systemic fight against false reviews is implemented not only through sanctions against corporate structures but also by disciplining those who actually shape companies&#8217; market policies. This, according to the legislature, is intended to ensure long-term improvement in integrity standards in electronic trading.</p>



<p><strong>The Omnibus Directive and the blacklist of market practices</strong></p>



<p>The implementation of the Omnibus Directive into the Polish legal system significantly redefined transparency standards in e-commerce, introducing mechanisms that directly address the systemic manipulation of consumer reviews. A key instrument in this regard is the so-called blacklist of market practices, which constitutes a catalog of behaviors considered unfair in all circumstances, eliminating the need for supervisory authorities to conduct a case-by-case analysis of the consequences of a given action. Classifying these market torts as unfair practices aims to eliminate evidentiary difficulties, as their mere existence exaggerates the entrepreneur&#8217;s wrongdoing. This legal framework not only strengthens the consumer&#8217;s position but, above all, simplifies the evidentiary process, making the fight against e-commerce abuse more effective and predictable for market participants. The foundation of the new regulations is an absolute prohibition on manipulating the verification and authenticity of product recommendations, which imposes an active obligation on sellers to implement procedures to verify the origin of reviews.</p>



<p>Under the current wording of the regulations, it is considered an unfair market practice for a trader to claim that product reviews were posted by consumers who actually used or purchased the product, in situations where reasonable and proportionate steps were not taken to verify their authenticity. This practice violates the consumer&#8217;s right to reliable information, which is essential for making an informed decision about purchasing the product, and violating it constitutes conduct contrary to good practice. The law prohibits not only posting completely false reviews, but also commissioning third parties to create them, or transferring recommendations between products with different parameters, which is referred to as review hijacking. Other offenses listed in the catalog are treated equally severely, such as using false quality certificates without appropriate authorization or using surreptitious advertising, which involves using editorial content to promote a product without clearly identifying the paid nature of the communication. Aggressive techniques are also considered particularly burdensome, including mass spamming and forced selling, which involves demanding payment for products delivered to the consumer without their prior order.</p>



<p>The blacklist also eliminates techniques <strong>such as bait advertising and direct persuasion of children to purchase</strong>, which aims to protect the integrity of the consumer decision-making process from manipulation. This protection of minors stems from their particular vulnerability to advertising messages and their inability to critically assess the persuasive nature of commercial offers. Expanding the list to include a ban on posting or commissioning another person to post false reviews for the purpose of promoting products significantly complements the system, preventing brands from using agencies that fabricate social evidence. It is emphasized that any form of distortion of the actual image of a product&#8217;s popularity constitutes a violation of the collective interests of consumers, which entitles the President of the Office of Competition and Consumer Protection (UOKiK) to intervene under public law as soon as a threat to the interests of all market users arises.</p>



<p>A particularly significant and painful consequence of these unfair techniques for entrepreneurs is a specific civil law sanction in the form of an extended right of withdrawal from the contract. If an e-store engages in practices listed in the prohibited catalog or fails to comply with information obligations regarding review verification, the statutory return period granted to the buyers is extended from 14 days to a full 12 months. This mechanism is a direct consequence of the assumption that, in the absence of reliable information, the consumer could not have expressed a fully informed intention to purchase, which suspends the running of standard mandatory deadlines. Systematic combating of review fraud and the use of black market practices is therefore becoming not only a matter of business ethics but the foundation of legal security and stability for every entity operating in the e-commerce sector. Neglect in transparency can lead to mass claims for refunds, posing a real threat to the operational liquidity of the company.</p>



<p><strong>Manipulation Architecture and Platform Obligations under the Digital Services Act (DSA)</strong></p>



<p>The phenomenon known as dark patterns constitutes a sophisticated form of interference in the user&#8217;s decision-making process, based on the deliberate use of interface architecture to distort their autonomy of will. Manipulative design patterns are not merely a manifestation of aggressive marketing, but a systematic designer&#8217;s action aimed at inducing a specific cognitive bias in the consumer, which ultimately leads to a purchase decision they would not have made in conditions of full transparency. The psychological foundation of these actions is the use of heuristics, i.e., simplified rules of reasoning and automatic thinking, which in the fast-paced environment of e-commerce transactions make the user susceptible to subliminal suggestions. This phenomenon has evolved from simple forms of persuasion to advanced interface manipulation, where the line between inducement and fraud is deliberately blurred to maximize conversion at the expense of the interests of the weaker party in the legal relationship.</p>



<p>A particularly significant area of application of these practices is the system for <strong>presenting reviews and suggesting their authenticity</strong>, where manipulation takes the form of so-called interface interference. Businesses often employ patterns involving selective content display, which in practice means deliberately hiding negative reviews on subsequent pages of the website while simultaneously highlighting only enthusiastic reviews on the product&#8217;s home page. This practice violates the model of the average consumer, who has the right to expect that the image presented of a product&#8217;s popularity and quality is reliable and has not been subjected to arbitrary filtering. Manipulation in the sphere of social evidence also includes fabricating popularity indicators, such as false messages about the number of people viewing a given product at a given time or false offer duration counters, which create an artificial sense of scarcity in the user and pressure them to immediately close the transaction. Under the Polish Act on Combating Unfair Market Practices, these activities may be classified as misleading because they distort the actual market conditions, preventing a rational comparison of offers.</p>



<p>Another dimension of manipulation is the technique known as confirmation shaming, which in the sphere of opinion writing involves the use of evaluative and emotional language to coerce users into specific behaviors, for example, through unsubscribe buttons suggesting a lack of consumer awareness. These practices are closely related to the &#8220;<strong>roach motel model</strong>”, where the process of issuing a favorable review is simplified to the maximum extent, while editing, reporting an error, or deleting content requires navigating a complex subpage structure, which is intended to discourage users from correcting false information. In the legal context, such procedural barriers are considered burdensome impediments that violate good practice and the principle of commercial fairness. An analysis of case law and the positions of supervisory authorities indicates that an interface that deliberately hinders users from exercising their rights or changing their minds loses its neutrality and becomes a tool for harming consumer interests.</p>



<p>A fundamental change in the regulatory sphere was brought about by the entry into force of the <strong>EU Digital Services Act (DSA), which, in Article 25, explicitly prohibits online platform providers from designing, organizing, and operating interfaces in a way that misleads or manipulates service users</strong>. This regulation is overarching and complements the existing consumer protection framework by introducing a direct obligation to maintain neutrality in choice architecture and prohibiting structures that significantly impede users&#8217; ability to make free and informed decisions. Violation of this prohibition entails not only civil law risks but also severe administrative sanctions, which can amount to a significant percentage of the business&#8217;s global turnover.</p>



<p>In the sphere of law enforcement, the key role is played by the model design of the average consumer, who is observant and cautious but lacks specialized knowledge of the psychological mechanisms used in interface design. This protection is preventative and abstract in nature, meaning the President of the Office of Competition and Consumer Protection (UOKiK) can intervene in situations where the mere existence of a manipulative pattern poses a real risk of distorting market behavior, without having to wait for measurable financial damage to a specific individual. Effectively combating dark patterns requires businesses not only to comply with the law but, above all, to shift to a design model focused on reliability, where all product information, including opinions, is presented free from coercive mechanisms. Ultimately, interface transparency is becoming a prerequisite for maintaining trust in the digital economy, and the use of sophisticated forms of manipulation is perceived as highly harmful to society, subject to strict assessment in light of the principles of social coexistence.</p>



<p><strong>New obligations for marketplaces regarding moderation and transparency</strong></p>



<p>The entry into force of Regulation 2022/2065, known as the Digital Services Act (DSA), represents a fundamental shift in the liability paradigm for intermediary service providers, particularly marketplaces. This regulation shifts the emphasis from passive content hosting to active oversight of the transparency and security of the digital system, introducing rigorous operational standards aimed at eliminating illegal content while respecting users&#8217; fundamental rights. A key pillar of this reform is the formalization of moderation processes, which until now were often subject to arbitrary internal platform decisions and are now subject to strict procedural rigors contained in the notice-and-action mechanism. Under the DSA, each platform is required to provide easily accessible and user-friendly tools for identifying potentially illegal content, including fake reviews or infringing offers. The mere receipt of a report obliges the provider to promptly and objectively address it.</p>



<p>The evolution of moderation obligations is inextricably linked to the <strong>requirement for transparency in decisions</strong>, which is achieved through the justification mechanism provided for in the EU regulation. When a marketplace decides to remove content, limit its visibility, or suspend a user&#8217;s account, the user is absolutely obligated to provide clear and specific reasons for such action, which is intended to prevent abuse by blocking reliable reviews that are unfavorable to the seller. This system is complemented by a<strong> mandatory internal complaint handling system</strong>, which allows users to appeal moderation decisions free of charge within a period of at least six months. <strong>This constitutes an important procedural guarantee and allows for the correction of potential algorithmic errors</strong>. It is indicated that such a legal framework is necessary to counteract the fragmentation of consumer protection, which previously relied primarily on general national clauses that were unsuitable for the scale of operations of global digital entities.</p>



<p>A significant innovation introduced specifically for trading platforms is the &#8220;Know Your Business Customer&#8221; (KYBC) principle, regulated in the chapter on marketplace transparency. These entities are charged with collecting and verifying information about traders offering their products through their interfaces, including registration data, payment account numbers, and declarations of commitment to offer goods in compliance with EU law. This mechanism aims to eliminate the phenomenon of anonymous sellers, who often promote defective products using fabricated reviews and, after raising capital, disappear from the market, avoiding legal liability. The platform is obligated to suspend services for sellers who fail to submit the required documents, making the marketplace an active guardian of the legality of trade, rather than merely a passive intermediary in trade.</p>



<p>The scope of transparency obligations extends beyond relationships with individual users to include public reporting through the periodic publication of transparency reports. These documents must include detailed data on the number of orders received from national authorities, statistics on content moderation initiated by the platform itself, and information on the use of automated tools in verification processes. For very large online platforms, these rigors are even stricter, including the obligation to conduct annual audits and systemic risk assessments, including analysis of the interface&#8217;s vulnerability to manipulation that could negatively impact public safety or consumer protection. The systemic fight against disinformation and unfair market practices is therefore anchored in the full transparency of operational processes, which allows supervisory authorities to continuously monitor the effectiveness of implemented security measures.</p>



<p>Supervision of compliance with these obligations is based on a new institutional architecture, in which national digital services coordinators, working closely with the European Commission, play a central role. The enforcement system for the adopted regulations is based on fines of up to 6% of a provider&#8217;s global turnover, which compels compliance with specific cybersecurity standards. This control system is designed to ensure that marketplaces not only implement the required procedures but also apply them reliably and uniformly across the European Union, which is crucial for building consumer confidence in cross-border trade. The introduction of these standards ends the phase of full regulatory freedom for platforms, imposing on them real responsibility for shaping the environment in which the modern exchange of goods and services takes place.</p>



<h2 class="wp-block-heading"><strong>Technological verification mechanisms and modern operating models</strong></h2>



<p><strong>Authenticity Suggestion and Pressure Mechanisms</strong></p>



<p>The evolution of digital market oversight has led to the development of mechanisms in which traditional legal instruments are increasingly being replaced by algorithmic jurisdictions based on advanced artificial intelligence systems. The phenomenon known as AI exclusion is a modern form of sanction that, for e-commerce entities, can prove more severe than traditional financial penalties imposed by administrative bodies. The foundation of this process is the integration of data on the credibility of reviews directly with positioning parameters in ranking systems, which means that transparency is no longer merely an ethical obligation but a condition for the technical visibility of an offer. Recommendation algorithms operating within platforms such as Google and Amazon constantly analyze behavioral and linguistic patterns to identify anomalies suggesting manipulation of social evidence. These systems are currently capable of recognizing the structure of texts generated by LLM language models, which are characterized by a specific repetition of phrases and a lack of emotional details typical of authentic consumer experiences. An additional risk factor subject to automatic verification is the so-called review growth rate, where a sudden jump in the number of positive ratings without correlation with actual website traffic or sales volume is interpreted by AI as a warning signal initiating restrictive procedures.</p>



<p>The consequences of an online store being classified by AI systems as posing a high risk of manipulation are immediate and often irreversible in the short term. This mechanism, known in market practice as <strong>shadow banning or de-indexing</strong>, leads to a drastic decline in visibility in search results and the blocking of offers in advertising systems, effectively cutting the entrepreneur off from key customer acquisition channels. Under the provisions of the Digital Services Act, providers of very large online platforms are required to maintain particular transparency regarding the parameters used in recommendation systems. Article 27 of the aforementioned regulation requires platforms to clearly define in their regulations the key parameters determining information ranking, which aims to limit <strong>algorithmic arbitrage</strong> and enable entrepreneurs to understand the reasons for a potential decline in their market exposure. It is worth noting that modern risk assessment systems may be classified as high-risk systems within the meaning of the Artificial Intelligence Regulation, which imposes strict requirements on their creators regarding human oversight and the prevention of <strong>algorithmic discrimination</strong>.</p>



<p>In parallel to restrictive systems, a paradigm known as agentic commerce is developing, in which purchasing processes are carried out by autonomous AI assistants acting directly on behalf of the consumer. In this model, traditional product reviews cease to serve as persuasive texts for humans and become raw input data for machines that filter the market in search of offers with the highest level of verified trust. A key element of this new commerce architecture is the so-called trust layer, built on protocols such as the Universal Commerce Protocol promoted by Google or the Agentic Commerce Protocol developed by OpenAI. These systems are guided not only by price or availability of goods but above all by the certified credibility of the seller&#8217;s data, automatically rejecting offers from entities that lack a clear digital traceability of their recommendations. The collaboration of AI assistants with secure payment systems, such as the Agent Payments Protocol, creates a closed ecosystem in which offers at risk of manipulation are excluded at the initial algorithmic selection stage, before they are even presented to the user.</p>



<p>In the era of agent-based commerce, the role of modern shopping assistants is becoming dominant, forcing businesses to redefine their credibility-building strategies. The Context Protocol model and other open-source solutions enable the exchange of context between various AI models and commerce systems, allowing information about unfair practices by a single store to be instantly shared across the entire assistant network. The doctrine suggests that this systematic approach to eliminating abuse is a natural response to the technological ease of fabricating content online. For an e-commerce store, losing its trustworthy status in the eyes of Google or OpenAI algorithms means the modern equivalent of server shutdown, as AI assistants, protecting the interests of their users, will systematically bypass offers that generate manipulative signals. Thus, the fight for authenticity is no longer a mere compliance issue but an existential foundation in the new, automated e-commerce environment, where barriers to entry into the trust layer are becoming increasingly difficult for entities employing pressure mechanisms and suggesting false authenticity.</p>



<p><strong>Compliance as a Service and the Digital Feedback Path</strong></p>



<p>The rapid evolution of the e-commerce market and the increasing professionalization of unfair market practices have forced entrepreneurs to abandon a reactive reputation management model in favor of proactively building a digital immune system. The scale of the challenge facing modern e-commerce is illustrated by analyses of the systematic erosion of trust in the digital sector, pointing to the prevalence of fake reviews and consumer concerns about the mass implementation of generative artificial intelligence for opinion fabrication. This state of affairs creates decision paralysis, where an overabundance of unreliable information, instead of supporting the purchasing process, becomes an insurmountable barrier.</p>



<p>The economic impact of the lack of reliable content verification is directly measurable and translates into tangible operational losses for businesses. The literature emphasizes that exposure to manipulated reviews drastically reduces purchase intentions and brand trust, generating measurable financial losses. The information vacuum filled with false enthusiasm also leads to a phenomenon known as post-purchase dissonance, in which a product that fails to meet expectations is returned to the seller as a complaint or contract withdrawal. Consequently, the lack of investment in transparent review processes generates hidden logistical and operational costs that, in the long run, may outweigh the gains achieved through the temporary increase in conversions driven by manipulation.</p>



<p>In response to increasing regulatory rigor, including the Omnibus Directive, the Digital Services Act (DSA), and the AI Act framework, an operational model known as <strong>Compliance as a Service (CaaS)</strong> has emerged in market practice. It involves fully outsourcing compliance processes to specialized technology providers who take over the burden of monitoring and verifying content in accordance with current regulations. CaaS allows for the automation of data oversight, which is essential in an environment where the volume of incoming reviews precludes manual oversight without risking accusations of disproportionality. In this approach, compliance ceases to be merely an administrative cost and becomes a component of a strategy for building brand value by guaranteeing the authenticity of every customer touchpoint.</p>



<p>The foundation of the Compliance as a Service model is the maintenance of clean data and the generation of an indisputable digital trace of the review&#8217;s provenance. Every published review should be accompanied by a log containing metadata regarding the specific transaction, a unique order number, and delivery status, creating auditable proof of authenticity that can be presented during inspections by supervisory authorities such as the President of the Office of Competition and Consumer Protection. This digital reconstruction of the review process provides the most effective legal shield for businesses, eliminating the risk of allegations of unfair market practices. In the era of algorithmic jurisdiction, where ranking systems favor content supported by digital evidence, having a certified trace of data provenance is becoming a prerequisite for maintaining the market visibility of an offer.</p>



<p>Parallel to technical verification, modern review management systems integrate mediation mechanisms that allow for the amicable resolution of disputes before they are publicly expressed. Market experience suggests that implementing structured review processes allows for the amicable resolution of a significant portion of consumer disputes, effectively preventing the publication of negative reviews resulting from logistical errors. This approach aligns with the principles of reliability and good market practices, building customer relationships based on dialogue rather than solely on the one-way transmission of ratings.</p>



<p>Transaction verification is now becoming the market standard, replacing open, abuse-prone review sections with a system of unique invitations sent only after a purchase is completed. The literature emphasizes that restricting the review process to those who actually purchased the product is the simplest and most effective way to comply with the obligations imposed by the Omnibus Directive. This not only minimizes the risk of severe financial penalties, but above all, provides AI shopping assistants with reliable input data, which, in the new agent-based commerce paradigm, will determine the viability of each entity in the e-commerce ecosystem.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>KG Legal Contributes to techUK’s Tech &#038; Innovation Focus Week 2026: Agentic AI, Governance and Responsible Adoption</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 12:46:40 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Risk Management]]></category>
		<category><![CDATA[Autonomous AI Systems]]></category>
		<category><![CDATA[Public Sector AI]]></category>
		<category><![CDATA[Responsible AI]]></category>
		<category><![CDATA[UK AI Regulation]]></category>
		<category><![CDATA[UK GDPR]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8798</guid>

					<description><![CDATA[<p>Publication date: June 2, 2026 We are pleased to announce that KG Legal Kiełtyka Gładkowski contributes to techUK’s annual Tech &#38; Innovation Focus Week, taking place from 15–19 June 2026. The initiative brings together industry leaders, technology experts and innovators to discuss the transformative technologies shaping the future of the UK economy. LINK: https://www.techuk.org/resource/call-for-contributions-techuk-s-2026-tech-innovation-focus-week.html For [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/">KG Legal Contributes to techUK’s Tech &#038; Innovation Focus Week 2026: Agentic AI, Governance and Responsible Adoption</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>Publication date: June 2, 2026</strong></p>



<p>We are pleased to announce that KG Legal Kiełtyka Gładkowski contributes to techUK’s annual Tech &amp; Innovation Focus Week, taking place from 15–19 June 2026. The initiative brings together industry leaders, technology experts and innovators to discuss the transformative technologies shaping the future of the UK economy.</p>



<p>LINK: <a href="https://www.techuk.org/resource/call-for-contributions-techuk-s-2026-tech-innovation-focus-week.html" target="_blank" rel="noreferrer noopener">https://www.techuk.org/resource/call-for-contributions-techuk-s-2026-tech-innovation-focus-week.html</a></p>



<span id="more-8798"></span>



<p>For this year&#8217;s focus week, we submitted a contribution under the Agentic AI theme, exploring both the opportunities and challenges associated with the deployment of increasingly autonomous AI systems across public and private sectors.</p>



<p>Drawing on our experience at the intersection of technology, law and regulatory compliance, our article examines how organisations can move beyond experimentation and implement AI agents in a practical, secure and accountable manner. Particular attention is given to the role of Agentic AI in the public sector, where intelligent automation has the potential to improve administrative efficiency, service delivery and decision-support processes.</p>



<p>The article goes beyond the discussion of technological capabilities alone. It highlights the legal and governance frameworks that are essential for responsible AI adoption, including UK GDPR compliance, AI governance structures, accountability mechanisms and regulatory obligations that organisations must address when deploying AI-driven systems.</p>



<p>We also discuss the growing importance of internationally recognised standards and frameworks, including ISO/IEC 42001 and the NIST AI Risk Management Framework, which provide organisations with practical tools for managing AI-related risks and building trustworthy systems.</p>



<p>A central theme of our contribution is the importance of data security, auditability, traceability and meaningful human oversight. As AI agents become increasingly capable of taking actions autonomously and interacting with multiple digital environments, organisations need robust governance mechanisms to ensure transparency, control and accountability.</p>



<p>In our view, the future of Agentic AI depends not only on technological innovation but also on the ability to balance innovation with responsibility. Sustainable adoption requires practical governance frameworks that enable organisations to realise the benefits of AI while maintaining trust, compliance and effective risk management.</p>



<p>We are delighted to contribute to this important conversation and look forward to supporting organisations as they navigate the evolving legal and regulatory landscape surrounding AI technologies.</p>



<p>KG Legal Kiełtyka Gładkowski</p>



<p>Technology, AI &amp; Digital Regulation Practice Group</p>



<p><em>See the full text of the contribution here:</em></p>



<h2 class="wp-block-heading"><strong>Agentic AI in the UK: Unlocking Sectoral Opportunities While Building the Foundations for Responsible Adoption</strong></h2>



<p>Artificial intelligence is entering a new phase of development. While recent years have been dominated by generative AI systems capable of producing text, images, and code, the next wave of innovation is increasingly focused on agentic AI &#8211; systems that can plan, reason, take actions, and interact with digital tools to achieve defined objectives with varying degrees of autonomy. Rather than merely responding to prompts, AI agents can execute multi-step tasks, coordinate workflows, and support decision-making processes across organisations.</p>



<p>For the United Kingdom, agentic AI represents a significant opportunity to improve productivity, strengthen public services, and enhance competitiveness across strategically important sectors. However, the successful deployment of these technologies at scale will depend not only on technological progress but also on the development of appropriate governance frameworks, organisational capabilities, and regulatory safeguards.</p>



<p>One of the most promising areas for adoption is <strong>the public sector</strong>. Government departments, local authorities, and public agencies manage large volumes of administrative processes that are often repetitive, time-consuming, and highly procedural. Agentic AI systems could support public servants by processing applications, managing case files, drafting correspondence, coordinating information across departments, and responding to routine citizen enquiries. In healthcare, AI agents could assist with patient triage, clinical documentation, appointment scheduling, and care coordination, helping to reduce administrative burdens and allowing healthcare professionals to focus on activities that require human expertise and judgement. At a time when public services face increasing demand and resource constraints, such efficiencies could have a meaningful impact on service delivery.</p>



<p>The financial and professional services sector, one of the UK&#8217;s most important economic strengths, also presents substantial opportunities. Banks, insurers, law firms, accounting practices, and consulting businesses rely heavily on information-intensive workflows that are often governed by detailed regulatory requirements. Agentic AI could automate compliance monitoring, support anti-money laundering investigations, review contracts, process insurance claims, conduct due diligence exercises, and assist with regulatory reporting. By reducing the time spent on routine analysis and documentation, organisations could improve operational efficiency while enabling skilled professionals to focus on higher-value strategic work.</p>



<p>Significant potential also exists in life sciences and healthcare innovation. Drug discovery, clinical research, pharmacovigilance, and regulatory compliance involve complex processes requiring the analysis and management of vast amounts of information. AI agents could help researchers identify relevant scientific literature, support clinical trial management, monitor safety data, and streamline documentation requirements. Given the UK&#8217;s strong research institutions and established life sciences ecosystem, agentic AI could contribute to both improved healthcare outcomes and economic growth.</p>



<p>Beyond knowledge-intensive industries, agentic systems could support manufacturing, infrastructure, transport, and energy. Applications may include predictive maintenance, supply chain optimisation, resource allocation, operational planning, and infrastructure monitoring. In the energy sector, AI agents could assist in balancing increasingly complex electricity networks, improving efficiency and supporting the integration of renewable energy sources. As the UK continues to modernise critical infrastructure and pursue net-zero objectives, intelligent automation may become an increasingly valuable tool.</p>



<p>While the opportunities are substantial, the widespread adoption of agentic AI will depend on overcoming a range of technical and organisational challenges. Autonomous systems must be reliable, secure, and capable of operating within clearly defined boundaries. Organisations will need robust mechanisms for evaluating agent performance, monitoring behaviour, identifying failures, and ensuring that human oversight remains available when necessary. The quality, accessibility, and interoperability of data will also be critical, as AI agents are only as effective as the information and systems with which they interact.</p>



<p>However, technology alone will not determine success. Many organisations continue to view AI as a standalone innovation initiative rather than a catalyst for broader transformation. Effective adoption will require the redesign of workflows, investment in workforce skills, and the establishment of clear governance structures. Employees must understand how AI systems operate, where their limitations lie, and when human intervention is required. Equally important is the allocation of responsibility for decisions made or influenced by AI systems. As autonomy increases, organisations must ensure that accountability remains clearly defined.</p>



<p>These governance considerations are becoming increasingly important as agentic AI systems move from experimentation to operational deployment. Although the UK has generally adopted a flexible and innovation-oriented approach to AI regulation, organisations deploying AI agents are already subject to a range of existing legal and regulatory obligations.</p>



<p>Unlike the European Union, which has introduced a dedicated regulatory framework through the EU AI Act, the United Kingdom has largely favoured a principles-based approach that relies on existing regulators and legal frameworks. This means that organisations deploying AI agents must consider how established laws apply to new technological capabilities rather than expecting a single comprehensive AI statute to provide all the answers.</p>



<p>Data protection law is particularly relevant where agentic systems process personal information. Under the UK GDPR and the Data Protection Act 2018, organisations must ensure lawful processing, transparency, accountability, and appropriate safeguards for automated decision-making. As AI agents increasingly influence decisions affecting individuals, issues such as explainability, fairness, and meaningful human oversight become more significant. Depending on the sector and use case, organisations may also need to consider obligations arising under consumer protection law, financial services regulation, employment law, equality legislation, cyber security requirements, and professional conduct rules.</p>



<p>Alongside formal regulation, an increasingly influential body of soft law is shaping expectations around responsible AI deployment. Guidance issued by the Information Commissioner&#8217;s Office (ICO), the Alan Turing Institute, the Centre for Data Ethics and Innovation (CDEI), and government bodies has helped establish practical principles relating to transparency, fairness, accountability, and human-centred design. While these instruments do not carry the same legal force as legislation, they are increasingly used as benchmarks by regulators, procurement authorities, and stakeholders when assessing whether organisations have deployed AI responsibly.</p>



<p>International standards are also beginning to play an important role. Frameworks such as ISO/IEC 42001, the first international management system standard specifically designed for AI governance, provide organisations with structured approaches to managing AI-related risks and responsibilities. Similarly, the NIST AI Risk Management Framework has emerged as an influential reference point for identifying, assessing, and mitigating risks throughout the AI lifecycle. Together, these frameworks are contributing to the development of a common governance language that may facilitate trust, interoperability, and regulatory compliance across jurisdictions.</p>



<p>For agentic AI specifically, governance challenges are amplified by the ability of systems to take actions, access external tools, and interact with multiple digital environments. Organisations will therefore need mechanisms that support auditability, traceability, incident management, and human escalation. Comprehensive logging, approval workflows, access controls, and continuous monitoring are likely to become essential features of responsible deployment. In practice, successful adoption may depend as much on governance design as on technical capability.</p>



<p>Ultimately, the UK&#8217;s opportunity lies not simply in adopting more AI, but in deploying increasingly capable systems in ways that generate measurable economic and societal value. The greatest benefits are likely to emerge where agentic AI is embedded within complex, high-volume workflows across both public and private sectors. Yet sustainable adoption will require more than innovation alone. It will depend on a careful balance between technological ambition, organisational readiness, and robust governance. Those organisations that invest early in accountability, risk management, and trust-building measures are likely to be best positioned to capture the benefits of agentic AI while navigating an increasingly complex regulatory and ethical landscape.</p>



<p>Prepared by KG LEGAL KIELTYKA GLADKOWSKI, iSTART1</p>
<p> </p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/">KG Legal Contributes to techUK’s Tech &#038; Innovation Focus Week 2026: Agentic AI, Governance and Responsible Adoption</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
