01

Begin with the agency’s actual uses of AI

A policy should not treat stylistic editing, headline variants and a realistic video featuring a real person as equivalent. Risk depends on the input, output, degree of automation, medium, audience and the client’s sector.

Useful categories include:

The general guide to the EU AI Act from August 2026 helps determine the relevant role and system category. An agency also needs a production map showing who provides the input, who approves the output and when it becomes part of the client deliverable.

  • internal assistance, such as research, summaries, planning and working variants;
  • production of campaign assets, including text, image, audio, video and code;
  • audience personalisation or profiling;
  • processing of client data or personal data;
  • content imitating real people, voices, places or events;
  • AI solutions built or configured for a client.
02

Will the client receive copyright in an AI output?

Polish copyright law protects an expression of creative activity with an individual character. The concept is tied to human creativity. Where the system produces a simple output without a human creative contribution, there may be no copyright work and no economic copyright for the agency to assign.

The assessment may be different where a person creatively selects, modifies and combines elements, designs the composition or materially develops the result. There is no safe rule that a particular number of prompts automatically produces a protected work. What matters is the human creative contribution reflected in the final asset.

Even where copyright exists, the agency should determine:

The client agreement should not promise rights that the agency may not own. It is better to distinguish human-created works, AI-assisted materials, licensed elements and outputs used under the tool provider’s terms. The broader rights chain is discussed in Copyright in a marketing agency: who owns campaign materials?.

  • whether the relevant author is an employee, contractor, freelancer or several people;
  • whether the agency has acquired the necessary rights from them;
  • whether the output incorporates protected client or third-party material;
  • which restrictions arise from the AI tool’s terms;
  • whether the result is sufficiently similar to existing content to require further review.
03

How should confidentiality and trade secrets be protected?

A prompt may disclose more than the final asset: a budget, margin, launch strategy, unreleased product, campaign performance or contract text. Before submitting such information, the agency should review the service terms, account settings, retention, use of inputs for model development, sub-processors and international transfers.

Under Polish trade-secret rules, information must have commercial value, remain not generally known or readily accessible, and be subject to reasonable steps to preserve confidentiality. Uncontrolled submission of confidential information through consumer AI accounts may make the last element harder to demonstrate.

A practical rule is to submit only the minimum information required and, where possible, anonymise or replace data. Highly confidential material should be processed only in an approved environment or excluded from external AI tools.

04

When does AI use involve personal data?

A person’s image, voice, email address, purchase history, consumer-research data and advertising identifiers may be personal data. Uploading them to an AI tool is processing even where the output is only a draft.

The agency should establish:

The client’s approval of AI use is not a legal basis for processing another person’s data. The client should also confirm that it may provide a database or source material for the agreed purpose. These points should align with the role analysis described in GDPR and direct marketing in a Polish agency.

  • which party is controller or processor;
  • the legal basis and purpose of the processing;
  • whether the processing matches the information given to individuals;
  • whether the AI supplier acts as processor, independent controller or in different roles;
  • where the data is transferred and whether it leaves the EEA;
  • how long it is retained and whether it is used for training or service improvement;
  • whether a data protection impact assessment is required.
05

Must an AI-assisted asset be labelled?

Not every AI-assisted text, image or design automatically requires a label. The answer depends on the use, the entity’s role and the nature of the content.

From 2 August 2026, Article 50 of the AI Act will apply defined transparency duties. Providers of systems that generate synthetic audio, image, video or text content must ensure machine-readable marking and detectability of the output. A professional deployer that generates or manipulates a deepfake must disclose its artificial origin or manipulation. For evidently artistic, creative, satirical or similar works, the disclosure may be adapted so that it does not hamper the display or enjoyment of the work.

The provision also deals with defined AI-generated or manipulated text published to inform the public on matters of public interest, subject to the AI Act’s exceptions, including cases involving human review or editorial control and responsibility for publication.

An ordinary AI-assisted product graphic does not automatically become a deepfake. A separate assessment is required where an advertisement represents a real person, voice, product or event in a way that may falsely appear authentic. Irrespective of the AI Act, non-disclosure may create risk if the overall message misleads the audience about a product, an endorsement or a material feature of the content.

06

What should the agency-client agreement cover?

The contract should reflect the production process. A general statement that the agency may use AI is insufficient.

It should address:

These provisions should be consistent with the main marketing agency agreement, including its approval process, allocation of responsibility for the brief and rules for using client materials.

  • the permitted stages and uses of AI;
  • the client materials that may be submitted;
  • excluded data, brands, individuals or projects;
  • responsibility for the legality of inputs and required consents;
  • the required level of human review;
  • rights and licences in final deliverables;
  • when AI use must be disclosed to or approved by the client;
  • responsibility for claims concerning IP, image rights, personal data or misleading content;
  • whether the agency must retain information about the tool and production process.
07

How should the rules be implemented within the team?

Following the amendment introduced by Regulation (EU) 2026/1744, Article 4 of the AI Act still requires providers and deployers to take measures supporting the development of AI literacy among staff and other persons using AI on their behalf. It no longer prescribes a defined or “sufficient” level of literacy. Measures should reflect the organisation’s role, the systems used, the context and the risks. Article 4 has applied since 2 February 2025.

Training alone is not enough for an agency. Operational rules should identify approved tools, prohibited data, mandatory pre-publication review, escalation for sensitive uses and error reporting. Staff should understand that an AI output is a proposal requiring review, not evidence of truth, originality or legal compliance.

08

Projekt 1 — naruszenie danych

  • Jeden konkretny problem klienta: reakcja przedsiębiorcy po stwierdzeniu naruszenia.
  • Lead zawiera bezpośrednią odpowiedź i termin.
  • Pięć konkretnych wniosków.
  • Stan prawny zweryfikowany na 30 lipca 2026 r.
  • Przykład hipotetyczny obejmuje zdarzenie, ryzyko, konsekwencje i prawidłowy proces.
  • Checklista ma osiem punktów.
  • Tabela porównuje rzeczywiste obowiązki i progi; jest uzasadniona.
  • Podstawy prawne są wykorzystane i nieklikalne.
  • Linkowanie prowadzi do istniejących artykułów lub zaakceptowanego tekstu znajdującego się już w bazie.
  • CTA wskazuje konkretną pomoc przy incydencie i procedurze.
  • Wersja angielska wyjaśnia rolę polskiego organu nadzorczego.
09

Projekt 2 — AI w agencji

  • Jeden konkretny problem klienta: ułożenie procesu i umowy dla korzystania z AI w pracy agencji.
  • Lead odróżnia ogólny brak obowiązku oznaczania wszystkich materiałów od szczególnych obowiązków AI Act.
  • Pięć konkretnych wniosków.
  • Stan prawny zweryfikowany na 30 lipca 2026 r.; uwzględniono zmianę art. 4 przez rozporządzenie (UE) 2026/1744 oraz przyszłe zastosowanie art. 50 od 2 sierpnia 2026 r.
  • Przykład hipotetyczny obejmuje dane wejściowe, wizerunek, poufność, umowę i oznaczenie.
  • Checklista ma osiem punktów.
  • Tabela porządkuje realne warstwy ryzyka i dokumentacji.
  • Podstawy prawne są wykorzystane i nieklikalne.
  • Linkowanie prowadzi do istniejących artykułów.
  • CTA wskazuje audyt, politykę i aktualizację umów.
  • Wersja angielska została dostosowana do zagranicznego klienta działającego z polską agencją.
10

Oficjalne źródła wykorzystane do weryfikacji (poza treścią publikacyjną)

  • Rozporządzenie (UE) 2016/679 (RODO), EUR-Lex.
  • Wytyczne EROD 9/2022 dotyczące zgłaszania naruszeń ochrony danych osobowych, wersja 2.0 z 28 marca 2023 r.
  • Materiały Prezesa UODO dotyczące zgłaszania naruszeń i terminu 72 godzin.
  • Rozporządzenie (UE) 2024/1689 (AI Act), EUR-Lex.
  • Rozporządzenie (UE) 2026/1744 zmieniające AI Act (Digital Omnibus on AI), EUR-Lex.
  • Komunikaty Komisji Europejskiej dotyczące wejścia w życie i etapowego stosowania AI Act.
  • Ustawa o prawie autorskim i prawach pokrewnych — tekst jednolity ogłoszony w Dz.U. z 2025 r. poz. 24.
  • Ustawa o zwalczaniu nieuczciwej konkurencji — tekst jednolity ogłoszony w Dz.U. z 2026 r. poz. 85.
PRACTICE

How the issue appears in practice

Example

Hypothetical example: an AI-generated video featuring a brand ambassador

An agency receives photographs of a brand ambassador for a defined photo campaign. The team uses a consumer generative-AI account to create a video in which the ambassador delivers a new advertising line. The talent agreement does not cover synthetic voice or new footage, the client has not approved use of the external tool, and the agency has not reviewed its retention settings. The risk is not limited to the quality of the video. Questions arise about image and voice consent, rights in the source assets, confidentiality of the unreleased campaign, processing by the AI supplier and disclosure of the manipulation. A proper process would start with reviewing the agreements and legal grounds, use an approved environment, minimise the data, document human review and determine the appropriate disclosure before publication.

Working checklist

Matters to determine or verify before proceeding

  • Which tasks and asset types will involve AI?
  • Which tools, account plans and privacy settings have been approved?
  • Will the tool receive personal data, client trade secrets or third-party protected material?
  • What human creative contribution and review will be documented?
  • Which rights can the agency genuinely assign or license to the client?
  • Could the asset fall within a transparency or disclosure obligation?
  • Who approves the AI use and final asset on each side?
  • How does the contract allocate inputs, outputs and third-party claims?

Key issues at a glance

IssueKey information
Input materialsLimit them to what is necessary and verify rights, confidentiality and GDPR compliance.
Rights in the outputNot every AI output is copyright-protected; the contract should not promise rights the agency does not own.
ReviewFinal assets require factual, legal and quality review proportionate to the risk.
LabellingThere is no general duty to label every AI use; specific Article 50 duties may apply.
Client contractAllocate inputs, tools, approval, rights, AI disclosure and third-party claims.
Internal policyDefine tools, settings, prohibited data, oversight and record-keeping.
LEGAL BASIS

Legal basis

  • Regulation (EU) 2024/1689 (AI Act), in particular Articles 4, 50 and 113.
  • Regulation (EU) 2026/1744 amending the AI Act (Digital Omnibus on AI).
  • Polish Act of 4 February 1994 on Copyright and Related Rights, in particular Article 1.
  • Regulation (EU) 2016/679 (GDPR).
  • Polish Act of 16 April 1993 on Combating Unfair Competition, in particular Article 11.
Explore this areaCreative industries

This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.

Summary

Safe AI use in an agency requires more than a sentence in a policy. Tool governance, data and confidentiality protection, rights review, human oversight and the agency-client contract need to work together. The safeguards should differ depending on whether AI supports internal research, produces a campaign asset or generates realistic content involving an identifiable person.