Free Phishing Test
REGULACJE PRAWNE

AI Act and GDPR in Practice: Did 2025 Expose the Illusion of Security in Polish Organizations?

30-jan-2026 3 minutes read

The analysis of incidents reported to the President of the Personal Data Protection Office (PUODO) in 2025 paints a disturbing picture: over 22,400 reported personal data protection breaches are a signal that the current risk management models are becoming ineffective. Moreover, the CERT Polska team handled over 250,000 security incidents in 2025 (over 600,000 reports, of which approximately 250,000 were identified as incidents). This is more than twice as high as in 2024.

In the era of full implementation of the AI Act (Regulation on Artificial Intelligence) and the evolution of threats, cybersecurity is no longer the domain of IT departments and is becoming a key element of the legal responsibility of management boards.

Risk modeling in the light of Art. 15 AI Act

Although many organizations use AI systems that do not qualify as high-risk systems, it isArt. 15 AI Actsets today the standards of “due diligence” in risk analysis. According to this provision, systems should be resistant to:

  • Adversarial attacks (adversarial attacks)
  • Data poisoning
  • Input data manipulation (prompt injection). 

In legal practice, we increasingly recommend the use of the Art. 15 AI Act framework as an element of a data protection impact assessment (DPIA). The 2025 incidents showed that the unauthorized use of intelligent assistants to transcribe meetings without participants’ consent is not only a violation of privacy, but a potential legal tort. 

Identity as a legal parameter (Art. 32 GDPR)

The statistics are ruthless: 1/3 of breaches last year resulted from credential compromise. From the point of view of the data controller (ADO), the failure to implement multi-factor authentication (MFA) in 2025 may be interpreted as afailure to comply with the obligation to implement appropriate technical measuresin accordance with Art. 32 of the GDPR. 

The example of a doctor impersonated in order to obtain prescriptions for opioids shows that the legal consequences of a violation go beyond administrative fines – civil liability for personal injury is involved. 

AI Act checklist for CISOs for 2026:
High-risk AI systems

Security by Design – from code to compliance

“Security is not a function, but a consequence of decisions made when writing code.” This statement is strongly supported by thePrivacy by Designprinciple (Art. 25 GDPR). More than 75% of IT incidents that constituted data breaches resulted from application errors (e.g. SQL Injection). For a lawyer, this means that a compliance audit must include not only documentation (policies, registers), but also verification of software development processes and regular code reviews. 

HR verification challenges: NIS-2 and UKSC

The amendment to the Act on the National Cybersecurity System (UKSC) and theNIS-2guidelines introduce new rigors for personnel verification. It is worth paying attention to Implementing Regulation 2024/20690, which in point 10.2 suggests verifying the background of employees in certain cases. 

However, there is an important coincidence with labor law. The Provincial Administrative Court’s judgment (II SA/Wa 190/22) sets the limits of the admissibility of monitoring employees’ activity on social media. Administrators must balance the obligation to ensure security and protect employee privacy. 

Summary

2025 proved that “it doesn’t take a big hole to sink a ship – just one that no one knows about.” Effective data protection in 2026 requires abandoning “paper compliance” in favor of real vulnerability management and incorporating cybersecurity into the organization’s KPI structure. 

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579