August and September 2026 are shaping companies’ technology agendas. New obligations relating to artificial intelligence and cybersecurity are coming into force, whilst at the same time planning for next year’s budgets is getting underway. The common thread running through these processes is the growing importance of accountability: it is becoming increasingly difficult to justify technology on the basis of innovation alone. It must have a demonstrable impact on results, costs or risk.
The economic climate favours investment, but not profligacy. The National Bank of Poland’s July forecast projects Polish GDP growth of 3.7 per cent in 2026. The European Commission forecasts 3.5 per cent, with a slowdown to 2.8 per cent in 2027. The favourable economic climate allows for the financing of modernisation, but the prospect of weaker growth heightens the importance of the quality of decisions taken today.
AI is moving from the accessibility phase to the accountability phase
From 2 August, further provisions of the AI Act will come into force, including transparency requirements concerning selected interactive systems, AI-generated content and deepfakes. The regulation does not halt the commercial use of artificial intelligence. However, it changes the conditions under which it can be safely scaled up.
For businesses, this means that the value of implementation increasingly depends on an understanding of the entire process, rather than solely on the quality of the model. The origin of the data, the ability to verify the result, the way the recipient is informed, and accountability for incorrect recommendations are all becoming increasingly important. The closer a system is to a customer, an employee or a critical business decision, the greater the costs of uncontrolled use become.
This is particularly significant in Poland. In 2025, 20 per cent of businesses in the European Union were using AI technology, but only 8.4 per cent in Poland. Among large companies in the EU, the figure stood at 55 per cent. Poland’s adoption gap is creating pressure to accelerate adoption, particularly in organisations competing with international players.
However, the pace of implementation alone does not solve the problem. A model that generates meeting summaries has a different risk profile to a system supporting recruitment, customer assessment or complaint handling. Treating all AI projects as a single category leads either to excessive caution or to an underestimation of risk.
Consequently, the economics of AI are becoming increasingly intertwined with the architecture of accountability. Projects with a measurable impact on process time, sales, quality or service costs are easier to justify and develop. Solutions without a defined outcome remain merely a demonstration of the technology’s capabilities, even when they attract user interest.
The main change, therefore, is not the emergence of new models. It is the shift from the question ‘Does AI work?’ to the question ‘Can the company use it safely and profitably on a larger scale?’.
Cybersecurity is becoming part of product quality
From 11 September, manufacturers of software and devices containing digital components will be required to report actively exploited vulnerabilities and serious incidents. The remainder of the Cyber Resilience Act will come into force later, but the September deadline is already linking product security with operational processes and reporting.
For technology companies, the consequence is a narrowing of the gap between the security department and the business. A vulnerability can simultaneously affect service continuity, customer relations, legal liability and product reputation. What matters, therefore, is not only the number of security measures, but also the ability to quickly determine the scale of the problem and its significance for users.
In this context, cybersecurity is no longer merely a cost associated with protecting infrastructure. It is increasingly becoming a component of product quality and a prerequisite for maintaining revenue.
The cloud is gaining a realistic exit price
From 12 January 2027, the Data Act will abolish charges for switching data processing service providers, including data transfer fees. The regulation limits one of the financial mechanisms of vendor lock-in, but does not eliminate technological dependencies.
Migration costs may still arise from application architecture, proprietary formats, a lack of expertise, or the time required to recreate the environment. The value of cloud flexibility therefore depends less on a declared multi-cloud strategy and more on whether switching providers is actually feasible.
Technology is subject to the same rules as other investments
The AI Act, the Cyber Resilience Act and the Data Act cover different areas, but lead to a similar conclusion. Technology is becoming more measurable, contractually defined and linked to business accountability.
The advantage may lie not in the largest number of projects launched, but in the ability to select those that can be scaled without an uncontrolled increase in costs and risk. In the 2027 budgets, the mere promise of innovation will carry less weight. Greater importance will be attached to measurable results, operational resilience and the ability to change direction when a project fails to meet its objectives.

