91ÌÒÉ«

Dr Piotr C. Sosnowski: Regulations vs Reality – Will Companies Meet EU Requirements in Time?

EU regulations are becoming a part of everyday business operations. Legal acts such as the CSRD, NIS2, DORA and the AI Act have either already entered into force or will do so in the coming years. This means a considerable compliance burden for Polish enterprises. The CSRD, which replaces the earlier NFRD Directive, requires structured ESG (Environment, Society, Governance) reporting and control of non-financial data. NIS2 raises the bar for cybersecurity across numerous sectors. DORA introduces uniform rules on digital operational resilience in the financial sector. The AI Act is the world's first comprehensive regulation governing the use of artificial intelligence. Its primary objective is to ensure that AI systems are safe, transparent and compliant with human rights and EU values – much as the GDPR does in relation to personal data. Dr Piotr C. Sosnowski from the Faculty of Management, 91ÌÒÉ« dicusses the topic.

Opublikowano: 14 July 2026

Piotr Sosnowski

  • Regulations and implementation timelines
    CSRD (Corporate Sustainability Reporting Directive) – EU: reporting from 2025 (for the 2024 financial year); additional groups covered progressively until 2029
  • NIS2 (Network and Information Systems 2 Directive) – EU: in force since 2023; Poland: early 2026
  • DORA (Digital Operational Resilience Act) – EU: full application from 17 January 2025
  • AI Act (Artificial Intelligence Act) – EU: in force since 2024; key obligations applicable between 2025 and 2027

Compliance with EU requirements is not only an obligation but also an opportunity to strengthen a company's market position. ESG reporting under the CSRD, along with compliance with NIS2 and DORA requirements. It helps build trust among customers and investors, who increasingly expect responsibility and security from their business partners. Companies operating in accordance with regulatory requirements are perceived as less risky, which facilitates access to financing and may provide a competitive advantage. At the same time, implementing standards ahead of mandatory deadlines minimises the risk of penalties and reputational damage.


Failure to comply with EU regulations carries both financial and reputational risks. Enterprises that ignore obligations resulting from the CSRD, NIS2, DORA or the AI Act may face administrative penalties. A lack of transparency in ESG reporting reduces credibility in the eyes of investors, making access to financing more difficult and potentially leading to customer losses. Non-compliance with cybersecurity regulations increases the risk of incidents that may disrupt operations and result in data loss. In the longer term, a lack of compliance entails not only the risk of penalties but also the loss of competitive advantage and reputation, the rebuilding of which can be both costly and time-consuming.


The question is whether Polish enterprises will be able to develop and implement measures enabling them to comply with these standards without harming their business operations. From an operational management perspective, following several principles familiar to the vast majority of managers may prove helpful.
 

The first is the allocation of responsibility for processes. If it is not clear who owns a particular risk, no one is actually managing it. Assigning ownership of risks enables, among other things, process mapping using BPMN (Business Process Model and Notation) diagrams and the development of Standard Operating Procedures (SOPs). This makes it possible to determine who is responsible for each stage of a process.


The second principle is the implementation of appropriate process measurement systems. If we cannot monitor our activities, we are unable to measure progress in implementing improvement measures. Developing and introducing metrics and Key Performance Indicators (KPIs) makes it possible to assess the effectiveness of actions, identify areas requiring improvement and respond quickly to deviations from established objectives.


The third principle is repeatability. If management reviews are not conducted regularly, the system loses its effectiveness. Ensuring compliance with regulatory requirements can be treated either as an implementation project or as BAU (Business As Usual) – an element of everyday operational activity that does not disappear once implementation is complete and to which organisations must continuously adapt.


EU regulations such as the CSRD, NIS2, DORA and the AI Act are becoming an integral part of doing business in Poland and across the European Union. Their implementation requires not only process adjustments but also a change in the approach to risk management and reporting. Compliance with these requirements creates opportunities to build customer and investor trust, improve operational efficiency and achieve a competitive advantage. Conversely, non-compliance is associated with the risk of penalties, reputational damage and restricted access to financing. It is therefore essential that companies treat regulatory compliance as a component of their day-to-day operations, one that supports stable growth and the security of business activities in the long term.

 

Source: Dr Piotr C. Sosnowski, Department of Logistics, Faculty of Management, Faculty of Management

Edit:

Published: Agnieszka Wołowiec

91ÌÒÉ«

 

Narutowicza 68, 90-136 LODZ

fax: 00 48 42/665 57 71, 00 48 42/635 40 43

NIP: 724 000 32 43

© 2009-2026, 91ÌÒÉ«