An analysis of the current situation indicates that the Polish food industry is in a critical transitional phase, in which a lack of preparation for implementing the requirements of the AI Act may result in drastic financial sanctions. Although Regulation (EU) 2024/1689 of the European Parliament and of the Council, known as the Artificial Intelligence Act (AI Act), entered into force on August 1, 2024, the prevailing perception among entrepreneurs in Poland is that no real changes have occurred in the area of AI.
The Dynamics of AI Act Implementation: Why the Market Does Not Notice the Changes
The widespread impression that “nothing has changed” results from the regulation’s gradual application mechanism. The EU legislature adopted a strategy under which the most dangerous practices are eliminated immediately, while requirements for systems supporting production or logistics are introduced slowly.
The following points show the stages of implementing provisions that directly affect the operation of food enterprises in Poland.
| Date | Stage | Practical consequence |
|---|---|---|
| August 1, 2024 | Entry into force of the regulation | Formal start of adaptation processes in the EU |
| February 2, 2025 | Prohibition of unacceptable-risk practices | Requirement to withdraw manipulative and biometric systems |
| February 2, 2025 | Obligation to build competence (AI Literacy) | Requirement to train employees in the safe use of AI |
| August 2, 2025 | Management of GPAI (general-purpose AI) models | New standards for providers of tools such as ChatGPT |
| August 2, 2025 | Establishment of supervisory authorities and a system of penalties | Member states’ readiness to impose administrative sanctions |
| August 2, 2026 | Full applicability to high-risk systems (Annex III) | Documentation and audit obligations for AI in HR and logistics |
| August 2, 2027 | AI systems as components of regulated products | Certification of production machinery with embedded artificial intelligence |
Certification of Production Machinery with Embedded Artificial Intelligence
The provisions become fully applicable to sales systems now, in 2026, but since February 2025 companies have been required to ensure that employees possess an appropriate level of knowledge about AI (Article 4). Failure to observe this provision may be verified during an inspection by the Labor Inspectorate or the newly planned Commission for the Development and Security of Artificial Intelligence (KRiBSI). This is an advisory or parliamentary body concerned with supporting AI development and supervising its safe implementation. It analyzes technological, social, and legal risks associated with the use of artificial-intelligence systems and develops regulatory recommendations, including in the context of implementing provisions such as the AI Act.
There is no need to panic: this commission is still only at the legislative-concept stage. It is a planned body that is to be established in the future; it does not yet formally exist or conduct inspections in practice. This does not mean that this article can be put aside until later. History has shown that such authorities can appear very quickly and pose a real threat to our peace of mind.
Risk Architecture in the Food Industry
Poland’s food industry, characterized by a high degree of automation and complex supply chains, is a natural field for implementing AI systems. The AI Act divides these systems into four risk categories, each carrying different consequences for a food producer.
Under Article 6 and Annex III, AI systems become “high risk” when they affect physical safety, critical infrastructure, or workers’ rights. The following systems in a Polish production plant may be deemed noncompliant with the AI Act:
- Recruitment and personnel-management systems. Automated filtering of job applications, systems assessing employee performance on meat-cutting lines, or algorithms monitoring employee behavior for the purpose of awarding bonuses.
- Critical infrastructure and logistics. AI managing traffic in high-bay warehouses (AGV systems) or optimizing the cold chain, where an algorithmic error may lead to large-scale food spoilage and a threat to public health.
- Machinery safety components. Intelligent sensors in packaging or cutting machinery intended to detect a person’s presence and stop the process in an emergency.
Such systems must expect requirements to maintain detailed technical documentation, retain system logs for a specified period, and ensure continuous human supervision over algorithmic outputs.
Shadow AI: The Hidden Revolution and Its Dangers
Shadow AI refers to employees’ use of artificial-intelligence tools without the formal consent, knowledge, or supervision of the IT department. It is a direct evolution of the long-known phenomenon of Shadow IT, but carries a significantly greater risk to data integrity and legal compliance.
In the Polish food industry, pressure to optimize costs and working time leads office employees and technologists to reach for generally available language models such as ChatGPT, Claude, and Gemini, as well as simple image generators, treating them as free private tools that improve productivity.
Mechanisms Behind the Emergence of Shadow AI
The phenomenon is driven by three main factors:
- Ease of access. Most powerful AI tools are available through a smartphone browser, making restrictions on company computers ineffective.
- Lack of official tools. When a company delays implementing secure enterprise versions of AI, employees search for solutions themselves in order to meet increasing management pressure.
- Low risk awareness. Employees often do not understand that by entering data into a chat window they “feed” a public model with data that may become available to competitors.
Shadow AI in Practice: Examples from the Food Industry and Office Work
To understand the threat fully, one should analyze specific situations in a food company—situations from office life.
A technologist pastes the complete chemical composition of a proprietary spice mixture into a public chatbot and asks it to find a cheaper substitute for one preservative that will not change the product’s pH. The unique recipe, a trade secret, is thereby transferred to an external provider’s servers.
A financial analyst copies data from the profit-and-loss (P&L) statement of a particular product line into a free AI tool, requesting a profitability forecast for the next quarter. Confidential margin data become part of a training dataset.
Another employee, this time a lawyer, uses AI to summarize an agreement with a key raw-material supplier. The employee uploads a scan containing contractual penalties, supply volumes, and the personal data of the parties’ representatives, thereby breaching the NDA and GDPR.
A production-planning manager uses an unauthorized AI plug-in for Excel that downloads historical fresh-seafood sales data and combines them with a weather forecast. The plug-in has permission to read the entire network drive, creating a security vulnerability for hackers.
An executive assistant uses AI to transcribe a recording from a confidential meeting concerning a planned merger with a smaller processor. The recording is processed in the cloud on a server with an unknown security level.
A programmer maintaining the plant’s ERP system uses AI to repair an error in code responsible for product-batch traceability. The programmer pastes fragments of source code into a bot, risking disclosure of vulnerabilities in system security.
A quality inspector uses AI to generate a report from a hygiene audit. The AI “hallucinates,” changing information that Listeria was detected in one sample into a statement about “marginal environmental contamination.” This reduces management’s vigilance and leads to the release of a dangerous batch of goods.
An occupational health-and-safety coordinator asks AI to prepare safe-working instructions for a new autoclave. AI creates instructions that sound professional but state an incorrect critical pressure for that model, creating a risk of explosion.
The last two examples entail criminal-law consequences and directly create a risk of imprisonment. Explaining matters as AI mistakes only worsens the defendants’ position.
The marketing department uses AI to generate product images—for example, juicy fruit on juice packaging—that do not reflect the actual composition. Failure to mark them as an “AI-generated image” breaches the AI Act’s transparency requirements and may be considered misleading to consumers.
Consequences of a Lack of Supervision: A KRiBSI Inspection Scenario
The Commission for the Development and Security of Artificial Intelligence does not exist. The planned deadline for the Council of Ministers to adopt the draft is the first quarter of 2026, but there is no information concerning the date on which the project will be implemented.1 We therefore have time.
Many Polish food companies base their strategy on giving employees freedom in the hope of increasing innovation. The AI Act, however, provides for strict verification mechanisms that will eventually begin to be enforced.
According to Polish draft legislation, KRiBSI will be an independent authority with broad inspection powers. An inspection procedure may look as follows:
- System audit. Inspectors may demand access to source code, logs, and technical documentation for every AI system considered high risk.
- Verification of competence. An inspection may examine whether the company fulfilled its AI Literacy obligation—that is, whether employees know which tools they may use and understand the limits of the technology.
- Examination of Shadow AI. Tools monitoring network traffic may reveal that employees transmit company data to unapproved public models, which will be classified as a lack of an adequate risk-management system.
Financial and Operational Sanctions
A lack of preparation for inspection may result in administrative fines which, for large enterprises, are calculated as a percentage of annual turnover.
| Type of infringement | Maximum fine (EUR) | Maximum fine (% of turnover) |
|---|---|---|
| Use of prohibited practices (for example, manipulation) | 35,000,000 | 7% |
| Failure to comply with requirements for high-risk AI | 15,000,000 | 3% |
| Providing incomplete or incorrect information to authorities | 7,500,000 | 1% |
In addition to financial penalties, the supervisory authority has the right to order the immediate withdrawal of an AI system from the market or the cessation of its use. If AI is integrated into a production line, this may mean shutting down the plant for many days.
The Myth of Safety in Large Corporations
Large food-sector companies in Poland often display an attitude that can be called “safety through ignorance.” It rests on the false assumption that their scale of operations, legal departments, and the absence of AI penalties to date protect them from risk. Reality is different.
Dispersed responsibility. Shadow AI silos arise more easily in large structures. While the marketing department “plays” with AI, the management board may believe the company is safe even though legal risk is already increasing.
Responsibility for suppliers. Giants often purchase ready-made solutions from startups. The AI Act obliges the deployer—the large company—to verify that the supplier has fulfilled the regulation’s requirements. Purchasing a “black box” without CE certification directly exposes the company to a fine. One can see that, for its own convenience, the commission may inspect certificates rather than undertake the difficult task of digging through algorithmic code.
The PoC (Proof of Concept) trap. Many companies test AI through pilot programs. The AI Act does not exempt systems in a testing phase if they affect real processes or natural persons’ data. It is unknown whether verification will also concern projects at the “paper deliberation” stage.
For listed companies, an AI Act fine is not merely a cost, but a powerful blow to ESG ratings and investor confidence. Information about “unethical artificial intelligence” in food production may trigger a consumer boycott.
Large companies are more visible to regulators. Seeking to establish market standards, KRiBSI will first turn toward industry leaders and treat them as an example for the entire sector. It is easy to see that well-known, wealthy brands will be first in line. There will inevitably be spectacular exemplary penalties. Every authority—especially a new one—must earn “respect.” It is worth recalling that when GDPR or the Road Transport Inspectorate (ITD) were introduced, reports of enormous exemplary fines shook the market.
Compliance Management: How to Survive an AI Act Audit
Preparing for the full requirements to enter into force in 2026 requires food companies to take systematic action. Compliance with the AI Act is not a one-time event, but a continuous process. This process will certainly last more than a dozen months. Are we sure we have that much time?
Elements of an AI Management System
Companies should implement a model based on the following pillars:
- Central register of AI systems. Documentation of every tool used, its purpose, data source, and risk classification.
- FRIA (Fundamental Rights Impact Assessment). Mandatory for high-risk systems. It must assess how AI affects privacy, nondiscrimination, and employee safety.
- Human-oversight procedures. Designation of specific people responsible for verifying AI outputs and provision of tools allowing them to “switch off” the system in the event of failure.
- Data-cleaning principles. Ensuring that training data are representative and free from errors—which, in the food industry, means taking account of such factors as variation in raw materials across different seasons.
Key Conclusions for Management
AI Literacy is today’s priority. The training obligation under Article 4 is the easiest point for inspectors to verify. Remember: training is a relatively inexpensive method of building the first effective line of defense.
Shadow AI is a real legal threat. Employees’ uncontrolled use of free tools is a simple route to leaking trade secrets and violating the AI Act.
I would begin by introducing, “on paper,” a prohibition on using AI tools at work. This will be a difficult argument to overcome during any inspection.
Ignorance is costly. Because of their market exposure, large food companies will be the first objects of KRiBSI inspections. A lack of certification for systems embedded in production lines after 2027 will prevent products from being sold on the EU market. Here I would count on cooperation with solution providers. They, too, must remember these certificates. Without them, they will not sell their devices.
Ethics and transparency build value. Labeling AI-generated content and ensuring that algorithms do not discriminate against employees will become part of competitive advantage in relationships with retail chains. This is also fairly simple to implement. If a company clearly identifies which product descriptions, graphics, and recommendations are generated by AI, it demonstrates that it operates transparently and does not manipulate the recipient, in accordance with the AI Act.
Enterprises should immediately move from a model of accidental experiments with AI to a model of organized AI risk management—AI Governance. Only this approach will enable the safe use of artificial intelligence’s potential in optimizing food production while avoiding penalties that may threaten the organization’s continued existence.
Waiting for the “first penalties imposed on competitors” may prove to be a belated strategy, because the AI Act’s sanction system is designed to punish years of neglect in building supervisory structures severely. Do we still have time merely to observe the phenomenon?
1 Source cited in the original article: https://www.gov.pl/web/premier/projekt-ustawy-o-systemach-sztucznej-inteligencji
Wojciech Moszczyński
Wojciech Moszczyński—a graduate of the Department of Econometrics and Statistics at Nicolaus Copernicus University in Toruń; a specialist in econometrics, finance, data science, and management accounting. He specializes in optimizing production and logistics processes. He conducts research into the development and application of artificial intelligence. For years, he has been involved in popularizing machine learning and data science in business communities.
