POLAND Law and Practice Contributed by: Barbara Kiełtyka, Jakub Gładkowski and Małgorzata Kiełtyka, Kieltyka Gladkowski KG Legal
ties should be implemented based on a formal post- market monitoring plan. The AI Act does not explicitly regulate updates and changes to algorithms after their initial approval. How - ever, the previously described principle regarding the post-market monitoring system (Article 72 (2)) can be used for this purpose. The purpose of this process is to assess whether the system – including updates – continues to meet the requirements of the AI Act. Under Article 73, providers of high-risk AI systems placed on the EU market are required to report serious incidents to the market surveillance authorities of the Member State where the incident occurred. In Poland, the authority responsible for oversight will likely be the Commission for the Development and Security of Artificial Intelligence. 3.4 Enforcement Actions Poland does not yet have specific national regula - tions on AI, other than the EU AI Act. In Poland, the main authority responsible for the MDR and IVDR is the President of the Office for Registration of Medici - nal Products, who has statutory powers to inspect and classify products, impose penalties and suspend trade. The Chief Pharmaceutical Inspectorate also exercises supervisory authority. Poland has not yet designated national market sur - veillance authorities for the MDR and IVDR. Authori - ties designated under these three regulations will be obligated to co-operate, and co-ordination activities at the EU level will typically be supported by the EU Product Compliance Network. Under Article 99 (1) of the AI Act, financial penalties may be imposed for non-compliance, depending on the type of violation. The penalties must be effective, proportionate, and dissuasive. They must take into account the interests of SMEs, including start-ups, and their economic situation. For violations of the prohibitions on specific AI practices, effective from 2 February 2025, penalties will apply from 2 August 2025, and will amount to up to EUR35 million or 7% of global annual turnover, whichever is higher.
Your suggestion is good: “inspect and classify prod - ucts, impose penalties and suspend trade”
4. Liability and Risk in Healthcare AI 4.1 Liability Framework The European Commission withdrew the proposed Artificial Intelligence Liability Directive, which aimed to facilitate compensation claims by introducing a presumption of a causal link in specific situations involving high-risk AI systems. Hence, the national provisions of the Polish Civil Code will be applicable. Under the AI Act, any natural or legal person who influ - ences the operation of AI is liable for any damage caused by it. The regulation uses the concept of an operator in this context, which can be either: • a front-end operator (an entity that controls the risks associated with the operation of an AI system and derives benefits from it); or • a back-end operator (an entity that provides the data, support and technology necessary for the solution to function). Liability for medical errors, traditionally understood, concerns actions or omissions that contradict current medical knowledge and lead to patient harm. Depend - ing on the circumstances, this liability may rest with a doctor, hospital or insurer. However, liability for AI errors is questionable from a legal perspective, as AI lacks legal personality. The supply chain for AI products includes program - mers, device manufacturers, component suppliers, distributors and, ultimately, users. Liability for damages resulting from the provision of AI services depends on the cause of the damage. If the service provider is at fault, it is liable under general principles, whereas if none of the entities involved in providing the service are at fault, we can investigate the potential fault of other entities, such as sellers. Liability for a product deemed unsafe is based on strict liability. Liability for AI products used in medicine
96
CHAMBERS.COM
Powered by FlippingBook