Documents aligned with the way the product actually works.
In technology, material risk often sits in the gap between the document and the working product. These materials cover development, implementation, sale, maintenance, scaling and exit.
Practical questions
Where should the analysis begin?
01Who owns the code and data?
02How do acceptance and the SLA work?
03Does the sales journey meet consumer requirements?
Allowing a team to use AI does not create a safe workflow. An agency needs approved tools and data rules, human review, a clear rights chain and an accurate allocation of responsibility with the client.
The CRA reporting regime starts before most other requirements under the Regulation. Businesses marketing software or hardware under their own name should map their products, reporting thresholds, escalation routes and supplier obligations before 11 September 2026.
A DPA is required where a supplier processes personal data on a company’s behalf and for its purposes. Access to data alone is not enough; the parties’ roles must first be classified correctly.
Businesses in sectors covered by Poland’s amended Cybersecurity Act must assess their own status. For some entities, registration is due by 3 October 2026.
EU rules envisage an easy-to-find, two-step online withdrawal function. Poland has not completed implementation, so a seller’s current obligations also depend on the consumer markets it targets.
Paying for software does not automatically transfer rights to the code. The agreement should cover chain of title, exploitation rights, open source, repositories, acceptance and exit arrangements.
The special representation rule in Article 210 of the Polish Commercial Companies Code, shareholder resolutions, proxy scope and practical signing risks.
A business does not have to certify every AI tool merely because 2 August 2026 has passed. It must classify use cases, implement applicable disclosures, support AI literacy and prepare a roadmap for high-risk systems.