A new obligation: banks must admit you are talking to a machine
Since 2 August 2026, Poland — like the rest of the European Union — has been subject to a new phase of the EU's artificial intelligence regulation, the AI Act. For an ordinary bank customer, this translates into one concrete change: if you type into a chat with an 'advisor' or call a hotline and a voice answers, the financial institution is now required to clearly and immediately tell you that you are talking to a bot, not a human. It sounds like a minor detail, but in practice it changes how banks communicate with customers — and, as it turns out, Poland itself is not entirely ready to police the rule.
What exactly changed on 2 August
The new rules cover so-called transparency obligations for AI systems that interact directly with people. In practice this means chatbots on banking websites and apps, voicebots on phone lines, avatars in video chats, and any automated system 'pretending' to be a human consultant. From now on, such a system must reveal its nature from the very first contact — not after the customer's third question, and not only when explicitly asked 'am I talking to a bot?'. Institutions that ignore this can face genuinely painful fines — depending on the scale of the violation, up to 15 million euros, and in extreme cases up to 35 million euros or a corresponding percentage of the company's global turnover.
Deepfakes under scrutiny
The second pillar of the new rules concerns content generated or modified by artificial intelligence — images, audio recordings, videos. Anyone who publishes such material professionally (and a bank publishing an advert with a synthetic narrator's voice certainly falls into that category) must label it in a way that is both machine-readable and immediately visible to the recipient, not hidden somewhere in the file's metadata. This matters in the context of increasingly common fraud attempts using fabricated voices or images — the new law doesn't eliminate such attempts, but it at least draws a hard, penalty-backed line in Poland between what's legal and what isn't.
What this means for your wallet and your safety
For a bank customer, this change has two practical dimensions. First, more certainty during everyday contact with the bank. If you call about a complaint or ask about an offer's terms, you will know for sure whether you're speaking with a machine or a human — which matters, for instance, when the matter is complicated and you'd rather be transferred straight to a consultant. Second, the new rules make it harder (though not impossible) to impersonate a bank using a fabricated voice or video, which is one of the increasingly popular tools in fraudsters' hands.
This is also a good moment to recall a simple rule: no new law replaces common sense when choosing the institution you trust with your money. Before opening a new personal account, instead of clicking a link in an unverified message, check an independent personal account comparison and verify the offer at its source. The same applies to bigger decisions — if you're considering a cash loan or a long-term commitment such as a mortgage, use the bank's official channels and trusted comparison services, not messaging apps or ads whose authenticity is hard to verify.
The problem: the law is in force, but there's no watchdog yet
Here begins the less optimistic part of this story. Although the rules formally took effect on 2 August, the Polish body meant to enforce them — the Commission for the Development and Security of Artificial Intelligence (KRiBSI) — is not actually operating yet. Its establishment is allowed three months from the entry into force of the national AI systems act, meaning it will realistically start functioning only in autumn, likely November. Until then, the transparency obligation formally exists, but Poland has no institution actively monitoring compliance or issuing penalties for breaches.
What the financial sector says
The financial community, including the Polish Financial Enterprises Association, is already commenting on the new rules, noting that the future supervisory commission will also include representatives of the Polish Financial Supervision Authority — so the banking sector will have a voice in how these rules are enforced. That's good news for the future, but it doesn't change the fact that for the coming months, responsibility for vigilance rests largely on the banks themselves (which are, after all, regulated institutions with good reason to take the new obligations seriously) and on customers, who shouldn't assume that every new regulation instantly translates into real-world enforcement.
What you should do right now
The new rules are a step in the right direction, but not a reason to lower your guard. Treat them as an additional safeguard, not the only one. In practice this means: keep logging into your banking only through the official app or website, don't automatically trust voice or video recordings even when they sound convincing, and ask directly when you're unsure who — or what — you're talking to; you now have that right written explicitly into law. If you're planning to switch banks, open a new savings account, or set up a term deposit for your savings in the coming months, do it through verified, independent comparison sources rather than a link sent in a message from an 'advisor' whose identity you have no way to verify.
Bottom line: since 2 August, banks in Poland must openly disclose when you're talking to a bot and label AI-generated content, under threat of multimillion-euro fines. The catch is that the national watchdog meant to enforce this won't really be up and running until autumn. Until then, your own vigilance and reliance on verified, official channels remain the best protection — and when choosing the banking product itself, as always, base your decision on a careful comparison rather than the first ad you happen to see.