KSeF, NIS2, AI Act and Labour Law: Compliance Is Becoming a Board-Level Job

KSeF, NIS2, AI Act and Labour Law: Compliance Is Becoming a Board-Level Job
View on original source
Category: Business
Share
Archive
Like
Companies in Poland are simultaneously implementing KSeF, new cybersecurity obligations, the AI Act, PPWR and changes to labour law. Each regulation may have a different internal owner, but the combined risk ultimately meets in one place: at company and board level. Regulatory change is increasingly becoming a permanent management process rather than a sequence of one-off compliance projects. A few years ago, a major legal change could usually be treated as a project. A company appointed responsible people, changed procedures and systems, trained staff and eventually closed the implementation phase. Today there is often no point at which an organisation can say it has finished adapting and returned to normal. Continuous regulatory implementation has become the normal state. Finance teams are stabilising Poland's National e-Invoicing System, KSeF. IT and compliance departments are implementing requirements under the amended National Cybersecurity System Act, which transposes NIS2. Marketing and HR are assessing the use of artificial intelligence under the AI Act. Production, procurement and logistics are dealing with the Packaging and Packaging Waste Regulation, while HR departments are also adjusting to changes in labour inspections, mobbing and discrimination rules and the upcoming pay-transparency framework. Each project can have a logical owner. KSeF may sit with the CFO, NIS2 with the CISO or IT director, AI with compliance and technology teams, PPWR with production or environmental compliance, and employment law with HR. The problem is that a business does not carry five isolated regulatory risks. It carries one combined risk created by five parallel implementation programmes. If each department manages only its own fragment, management can easily develop a false sense of control. Finance reports that KSeF is implemented. IT says NIS2 work is under way. HR is preparing policies. Marketing is mapping AI tools. Production is reviewing packaging. From the board's perspective, everything may appear to be 'in progress'. But 'in progress' is not a risk-management category. KSeF shows how regulation becomes operational KSeF is no longer merely a future legal project for most businesses. Its implementation has required changes to accounting systems, access rights, fallback procedures, document flows and cooperation with contractors. That makes it an operating-model issue, not only a tax or accounting issue. The cybersecurity framework goes even further. Poland's amendment to the National Cybersecurity System Act entered into force on 3 April 2026. For key and important entities, it introduced organisational obligations related to information-security management, incident response and risk governance. Management bodies are expected to approve risk-management measures and oversee implementation. Cybersecurity responsibility therefore moves beyond the technical IT layer and into corporate governance. AI use must first be mapped The AI Act creates a different challenge: companies first need to determine where artificial intelligence is actually being used. The answer is not limited to products explicitly sold as 'AI systems'. AI functions may be embedded in HR software, marketing platforms, sales tools, analytics packages and customer-service systems. Some AI Act obligations already apply, including requirements concerning staff AI literacy and, from August, selected transparency duties. At the same time, implementation dates for some high-risk system requirements have shifted. This illustrates why compliance cannot be treated as a one-time legal update. Organisations need a process for managing rules that themselves change over time. Packaging and labour law add further layers The EU's Packaging and Packaging Waste Regulation has applied since 12 August 2026, although individual obligations have their own transition periods. Companies must translate the regulation into decisions about products, packaging, suppliers, logistics and sales models. Employment regulation is also generating parallel work. Since 8 July, Poland's National Labour Inspectorate has had new tools relating to civil-law contracts used in circumstances that may resemble employment relationships. From 5 November, rules on mobbing and discrimination are changing, while employers are also preparing for full implementation of EU pay-transparency requirements. Boards need a regulatory map Management does not need to interpret every article of PPWR, configure KSeF or review network logs. Its role is to build a system in which specialists identify risk, responsible owners manage implementation and issues requiring a management decision reach the appropriate level. A practical regulatory map should show which major regulations apply to the company, what obligations they create, who owns each workstream, upcoming deadlines, implementation status and the most important unresolved risks. It should also capture dependencies between rules. An AI system used in recruitment may simultaneously trigger AI Act, labour-law, data-protection and anti-discrimination issues. A cyber incident may create obligations under the cybersecurity act, GDPR, customer contracts and sector rules. A packaging change required by PPWR can affect suppliers, labelling, marketing and the economics of the entire supply chain. Documentation is part of governance The ability to prove how management responded to risk is becoming increasingly important. If a regulator, auditor, shareholder or court asks two years later how the board handled a particular issue, a written policy may not be enough. Relevant questions may include when management learned about the risk, what audit results it received, what recommendations were made, whether resources were allocated and whether implementation was later checked. This means modern corporate governance increasingly requires not only reasonable action, but also evidence that reasonable action occurred. The biggest mistake in today's accumulation of regulation may therefore be broader than failure to implement one procedure. It may be the absence of a system that allows the board to know what the company has not yet implemented. The key management question is no longer simply: 'Are we compliant?' It is: 'Do we have a system that tells us where we are not yet compliant, who is responsible for fixing it, and when management needs to know?' Source: ManagerPlus.

(0)Comments

 

A note on cookies

Newshunt uses essential cookies to keep you signed in and to remember your language and country, so the site works the way you expect. With your permission, we'd also like to use analytics cookies to understand how people use Newshunt and improve it over time.

Accepting only affects analytics. To learn more, view our Privacy Policy or Terms & Conditions.