In many companies, AI has already arrived through an employee’s browser rather than an IT project. Someone opens a personal account to draft a proposal or summarise a long customer email. The board’s first task is to understand which tools are used, what data they receive and who owns the decision.
This English overview accompanies the full Polish article. The four original supporting documents are in Polish. The proposed data classes, pilot design and 90-day plan are practical suggestions, not research findings.
Microsoft and LinkedIn’s 2024 Work Trend Index found that 78% of people using AI at work brought their own tools, rising to 80% in small and medium-sized companies. The survey covered 31,000 knowledge workers in 31 countries; it is not a representative sample of Polish businesses.
Where companies stand
Eurostat reports that 19.95% of EU enterprises with at least ten people employed used AI in 2025. Adoption differed by size: 17% of small enterprises, 30.36% of medium-sized enterprises and 55.03% of large enterprises. Poland’s figure was 8.36%.
Polish studies use different definitions and samples. Figures from GUS, the Ministry of Development and Technology and the Polish Economic Institute should therefore not be combined into a single comparable series. A company’s own inventory is more useful for deciding what needs to change tomorrow.
Among businesses already using AI, Eurostat identifies marketing and sales, as well as administration and management, as common application areas. These can provide a starting point for a pilot, provided data sensitivity and review requirements are understood first.
Rules: six decisions to make
1. Name one accountable owner. Someone must be authorised to approve a tool, refuse an unsuitable use and answer employees’ questions. In a smaller business this may be the owner or operations director; in a larger company, the CIO or another appointed leader. They need access to management and a clear understanding of company information.
2. Inventory existing use before issuing a ban. Ask which tools employees use, for which tasks, with which data, on personal or business accounts, and what support they need. An anonymous initial survey can help reveal use that would otherwise remain invisible.
3. Define simple data classes. The following is the author’s proposed starting point, not a regulatory classification:
- Green: public content, used in approved tools.
- Yellow: internal documents without personal data, used only through approved business accounts.
- Red: customer or employee personal data, trade secrets, source code, customer contracts and financial information. Require an explicit decision and a risk assessment before use.
The classification does not replace a GDPR assessment or determine a system’s AI Act risk category. A marketing draft and a recruitment scoring tool may have very different implications.
4. Approve tools and use managed business accounts. Check whether the provider trains models on submitted information, where data is stored, how long it is retained and what happens when an employee leaves. Private accounts reduce the organisation’s control. Business subscriptions still require careful review of terms and settings.
5. Keep a human accountable for the output. A person sending a proposal, calculation or customer reply must check the result. Responsibility does not disappear because software drafted the message.
6. Develop AI literacy. Article 4 has applied since 2 February 2025. Regulation (EU) 2026/1744 amended the wording to require measures supporting the development of staff AI literacy. A practical session using company rules and examples can be a starting point; what is appropriate depends on the people, tasks and systems involved. Keep a record of the measures taken.
Initial governance work does not necessarily require a large IT project. It does require time for an inventory, contract review, data assessment and training. The cost depends on the business, rather than licences alone.
Risks that deserve attention
Data exposure
The article discusses Samsung’s reported 2023 restrictions after sensitive source code was submitted to ChatGPT. The operational lesson is to establish clear rules before employees upload information the company cannot afford to disclose.
IBM’s 2025 Cost of a Data Breach report examined 600 organisations that had experienced a breach. High levels of shadow AI were associated with an average additional breach cost of USD 670,000 compared with low or no shadow AI. These are global figures for breached organisations, not a prediction of the cost facing a small Polish company.
Incorrect answers and accountability
In Moffatt v. Air Canada, the British Columbia Civil Resolution Tribunal held the airline responsible for incorrect information supplied by its chatbot. A correct policy elsewhere on the website did not resolve the problem. Customer-facing output needs appropriate controls and a route to human assistance.
Personal data
UODO has published initial questions to consider before creating or using AI systems, including material for smaller organisations using ready-made tools. The questions support an assessment; they are not a binding interpretation or a substitute for a complete analysis. Consider purpose, data categories, legal basis, retention, recipients and the consequences for individuals.
Integrations and agents
OWASP’s 2025 list for large language model applications includes prompt injection, sensitive information disclosure and excessive agency. An early agent should have the minimum functions and permissions needed. Read-only access is a safer starting point than permission to write to financial systems.
Gartner’s June 2025 forecast that more than 40% of agentic AI projects would be cancelled by the end of 2027 is a forecast, not an observed cancellation rate. Increasing costs, unclear value and weak risk controls are reasons to define decision criteria before a pilot starts.
Legal timetable
The AI Omnibus entered into force on 27 July 2026. The European Commission gives 2 December 2027 as the application date for the Annex III high-risk rules and 2 August 2028 for high-risk AI embedded in regulated products. Prohibitions and AI literacy provisions have applied since February 2025; general-purpose model rules started applying in August 2025.
Transparency requirements under Article 50 depend on the application and content concerned. Do not assume that every document drafted with AI is subject to the same labelling requirement. Assess applicable duties and exceptions for the actual use case.
Poland’s Act of 3 July 2026 on AI systems entered into force on 11 August 2026, with specified provisions entering into force on 28 October 2026. Use the official legislation and obtain advice for the company’s situation. A tool used to draft marketing copy and one used to assess candidates are not equivalent risk cases.
First deployments: measure before scaling
Productivity depends on the task
Research on customer support by Brynjolfsson, Li and Raymond found improvements from an AI assistant, especially for less experienced workers. METR’s early-2025 randomised study of experienced open-source developers found that participants took 19% longer with AI, despite believing it had made them faster. Its later update also discusses difficulties in measuring current effects.
Neither result predicts what will happen in your company. The studies differ in task, tools and population. They make one practical point: users’ impressions are insufficient evidence of business value.
Choose a bounded first task
A useful first task is frequent, uses approved lower-sensitivity data, has a human reviewing the output and has a measurable baseline. Possible candidates include drafts of standard sales responses, summaries of approved meeting notes, first drafts of product descriptions or classification of support requests.
Avoid beginning with candidate or employee assessment, an unsupervised customer-facing chatbot or an agent allowed to write to accounting and banking systems. These introduce consequences that exceed the scope of a simple productivity experiment.
Design the pilot before starting
- One task, 5–15 users and a proposed period of 6–8 weeks.
- A baseline for completion time, corrections and complaints.
- An agreed budget including staff time, not just subscriptions.
- Success and stopping criteria recorded before results are available.
- A weekly review of errors and changes needed in the instructions.
These numbers are a suggested design, not research findings. A hypothetical 40-person company might pilot one proposal type with five salespeople. It could require a 25% reduction in preparation time without an increase in customer-requested corrections. Set thresholds using the company’s own economics; do not copy an example without checking it.
A proposed 90-day plan
| Weeks | Work | Output |
|---|---|---|
| 1–2 | Appoint an owner, survey existing use and inventory tools | AI tools register |
| 3–4 | Agree data classes, approve tools, introduce the policy and train users | Policy and approved tool list |
| 5–6 | Select the pilot task and measure the baseline | Pilot worksheet |
| 7–12 | Run the pilot and review errors each week | Measured pilot results |
| 13 | Decide whether to scale, improve or stop | Recorded decision |
Downloadable materials
The three PDFs and editable XLSX workbook below are the author’s original Polish templates. Adapt them to the company. Illustrative values in the pilot worksheet are hypothetical.
The materials are not legal advice. Have the policy reviewed before implementation, particularly where personal data or regulated activities are involved.
AI use policy
Rules, data classes and responsibilities. 3 pages; Polish.
Download PDF ↓AI tools register and risk assessment
Editable workbook with instructions, register, summary and scoring; Polish.
Download XLSX ↓AI vendor assessment checklist
Data, contracts, security and privacy questions. 3 pages; Polish.
Download PDF ↓AI pilot worksheet
Hypothesis, baseline, budget and decision criteria. 2 pages; Polish.
Download PDF ↓