Skip to content
TrustList
News

Poland's finance ministry sets AI rules and bars vendors training on its data

Editorial

By TrustList Editorial

An order dated 30 September covers the ministry, tax offices and customs. It requires a central register of AI uses, staff training before use, and monthly sessions of a new AI council.

About Poland's finance ministry sets AI rules and bars vendors training on its data

Poland's finance ministry sets AI rules and bars vendors training on its data

2 October 2026: Poland's Ministry of Finance has put in force an AI development policy that governs how the ministry and its subordinate bodies design, buy and use AI tools. Dziennik Gazeta Prawna reports that the order is dated 30 September and took effect that week.

Not yet independently verified. We could not open the ministry order itself, so the details come from ITwiz and the opening of the Gazeta Prawna report. We will add the official text when we find it. We will update this when it can be confirmed, and remove this note.

Gazeta Prawna gives the start date as 2 October 2026. It covers more than the ministry itself: tax administration chambers, tax and customs offices, the National Revenue Information service (KIS), the ministry's IT centre, the National School of Taxation, the Polish Economic Institute and the Polish Audit Oversight Agency are all named by ITwiz. The policy applies whether a tool is built in-house, bought from a supplier or consumed as a service, and it counts AI components inside larger IT systems.

The part most relevant to suppliers is the contract rule. ITwiz reports that agreements with technology firms should contain an explicit ban on using the ministry's data to train, tune or improve the vendor's own systems. The ministry also says it will prefer solutions developed in Poland or the EU when they meet its functional, security and efficiency needs, while still allowing global suppliers. Solutions running in its own infrastructure, or in environments with comparable security and full control over data processing, are to come first.

Every AI use has to be approved by the director of the unit responsible for AI, on top of the ordinary checks for any IT system. Each one is entered in two registers: the register of IT systems and a new Central Register of AI Uses. A proof-of-concept test may come first, and running systems face periodic audits by people independent of those who built or operate them. The audits look for deviations from stated behaviour and falling output quality.

A new AI Council, drawn from tax-administration IT, data protection, information security, IT development and data analysis, will give opinions on proposals, proof-of-concept results and audits. It is to meet remotely at least once a month.

Decisions stay with people. The policy rules out automatic decisions with legal or practical effect unless an authorised employee has verified the result and signed it off, and it provides for explanations of how an AI tool influenced a case and for objections or appeals under the relevant rules. Staff must complete training on the ministry's learning platform before they use AI, and must be told clearly when they are dealing with an AI-based tool.

Detailed operating rules are to follow in a separate document, the AI RF Regulations, which ITwiz says will classify initiatives and set the project and approval procedure.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy