91桃色

Is AI Above the Law? Interview with Prof. Dominik Lubasz

This year, a new research centre was established at the Faculty of Law and Administration of the 91桃色: CLAIRE 鈥 Centre for LegalTech and AI Research. What exactly does it do? What are its plans and what has it achieved so far? These questions are answered by dr hab. Dominik Lubasz, Associate Professor at the 91桃色, Head of CLAIRE.

Opublikowano: 05 August 2026
a portrait photo of dr hab. Dominik Lubasz, Associate Professor at the 91桃色

Let us begin with the question from the title. Is artificial intelligence above the law?

dr hab. Dominik Lubasz, Associate Professor at the 91桃色*: No, and it never has been. Even if the AI Act did not exist, AI systems would still operate within the framework of the GDPR, anti-discrimination law, product liability law, consumer law and administrative procedure. There is no provision exempting anyone from these obligations simply because a decision was prepared by a model.

The more difficult question is a different one. Does a person affected by a decision made with the involvement of an algorithm have a genuine opportunity to challenge it: to find out that an algorithm was used, to understand the reasons behind the decision and to have it reviewed by someone empowered to change it? This is no longer a legislative question. It is a question about the legitimacy of power.

And what about the law itself? In 2024, the AI Act, a European Union regulation governing the development, deployment and use of artificial intelligence systems, entered into force. How is this regulation performing today, given the pace of technological development?

Let me begin with a correction, because this question contains a misunderstanding that is often repeated in public debate. Regulation 2024/1689 entered into force on 1 August 2024, but entry into force is not the same as application. The prohibitions of certain practices have applied since February 2025, the provisions concerning general-purpose models since August 2025, while the most challenging part, namely the requirements for high-risk systems, was due to start applying on 2 August 2026.

Here something happened that is, in itself, a research subject. Regulation 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July. The obligations concerning standalone high-risk systems under Annex III were postponed until 2 December 2027, while those concerning AI embedded in regulated products under Annex I were postponed until 2 August 2028. The reason is not ideological but administrative: harmonised standards were not in place, Member States were delayed in designating supervisory authorities, and notified bodies were lacking. The European Union effectively acknowledged that its own legislative timetable had outpaced its implementation capacity.

The postponement covered three sections of Chapter III, not the entire regulation. 2 August 2026 remains the date from which the Act applies, together with the transparency obligations under Article 50, including the obligation to inform a person that they are interacting with a machine. A new prohibition was also introduced: from 2 December 2026 it will be prohibited to place on the market or use systems intended to generate intimate images of identifiable individuals without their consent or material depicting child sexual abuse. This is the first tightening of the Act since its adoption.

The honest answer, therefore, is this: we do not yet know how the AI Act performs in practice, because its most significant provisions are not yet being applied. However, we do know where the challenge of regulatory law in relation to technology lies. It lies in the operationalisation of legal norms, not in their content.

What is CLAIRE 鈥 Centre for LegalTech and AI Research?

CLAIRE is a research centre of the Faculty of Law and Administration, 91桃色. It operates on a self-financing basis through grants and international projects and does not burden the Faculty鈥檚 budget.

The Centre is built on two pillars. The first, and indeed the central research question around which I established it, concerns the legality and legitimacy of algorithmic power in the European legal order. We are interested in the constitutional limits of decision-making automation, trust as a normative rather than a marketing category, the risk-based approach as a framework of legality, and ex ante accountability together with procedural control over machine-made decisions.

The second pillar is LegalTech, although we treat it not as a set of tools but as a subject of regulation. Where does the boundary of permissible automation of legal activities lie? Who is responsible when an AI tool generates an incorrect legal analysis? What happens to professional secrecy when client files are submitted to a language model? These are not hypothetical questions. According to the Future Ready Lawyer study (Wolters Kluwer, 2024), 76% of lawyers working in in-house legal departments and 68% of lawyers in law firms use generative AI at least once a week. LexisNexis reported that AI usage among lawyers in the United Kingdom rose from 11% in 2023 to 41% in 2024. The transformation of the legal profession is already taking place, largely without sufficient deontological reflection.

The Centre鈥檚 Scientific Board comprises sixteen researchers from the 91桃色, the University of Wroc艂aw, the University of Gda艅sk, the University of Silesia, the Institute of Law Studies of the Polish Academy of Sciences, Kozminski University, SWPS University, Kujawy and Pomorze University, as well as the University of Salerno.

Within the Faculty, CLAIRE does not replace any existing initiative. It complements the AI Hub and is intended to serve as a platform connecting Lodz Cyber Hub, AI for Justice Lab, AI Work Team, and the Centre for Personal Data Protection and Information Management. It also provides legal expertise to the University鈥檚 Generative AI Team at the 91桃色.

What are the first initiatives undertaken by the Centre?

Although the Centre was formally established in May, the projects that form its foundation had already been underway. For this reason, I submitted the proposal to establish it relatively soon after joining the University.

The most important event was the inaugural BRIDGE symposium, held at our Faculty on 29鈥30 April 2026. Twenty-eight speakers from Poland, Germany and European institutions took part in it.

At the same time, my monograph GDPR for AI: A Legal Framework for Trustworthy Artificial Intelligence through Data Protection by Design was published by Kluwer Law International. It is an attempt to treat the GDPR as a fully-fledged instrument for regulating AI systems rather than merely an obstacle to their development. A commentary on the AI Act, prepared by a team of authors from several academic centres, is currently in editorial preparation.

In addition, the Centre has entered the phase of building an international consortium, which I will discuss in a moment. It also continues its cooperation with public administration, primarily through the expert group advising the President of the Personal Data Protection Office, as well as with legal self-government bodies on matters relating to digital transformation and the use of Polish language models.

What are CLAIRE鈥檚 plans for the coming academic year?

There are three priorities, in order of importance

First, BRIDGE. This is the bilateral research initiative Bilateral Research Initiative on Data and the Governance of Emerging Technologies, which I lead jointly with prof. Boris Paal from the Technical University of Munich. Its premise is simple: the two strongest traditions of data protection within continental Europe should discuss the European model of data and AI regulation together, without erasing their differences.

BRIDGE consists of two stages. The first, diagnostic stage took place in 艁贸d藕 under the title 鈥淒iagnosis: Status Quo & Questions鈥. Five panels, twenty-eight participants, English as the working language, the Chatham House Rule, and a discussion-based rather than presentation-based format. We invited not only academia but also supervisory authorities, the European Commission, business representatives, NGOs and practitioners because the question we posed concerns the entire regulatory model: How far can European governance of data and AI be redesigned in the name of innovation and competitiveness without undermining trust?

This question did not emerge in a vacuum. The Letta and Draghi reports, the simplification agenda and, finally, the Digital Omnibus all suggest, when read together, that the regulatory achievements of the last decade are regarded as a problem to be solved rather than an accomplishment to be defended. BRIDGE was not convened either to confirm or reject that narrative. It was convened to test it.

The second stage will take place in Munich this autumn and will focus on solutions: workshops, working groups and a policy recommendation document. The outcome of both meetings will be a report and a joint research agenda, ultimately leading to a permanent bilateral cooperation structure rather than a one-off conference.

Second, a grant application. We are building a transatlantic consortium for a Trans-Atlantic Platform call, with the 91桃色 serving as lead institution and partners from Germany and Latin America. The topic is how regulatory choices concerning AI in the justice system influence citizens鈥 actual access to courts and their trust in the administration of justice. The full proposal will be submitted this autumn.

Third, teaching and seminars. I would like the Centre to establish a regular research seminar involving doctoral students because that is the only way to ensure that, in five years鈥 time, the Faculty will have scholars who understand these issues from within rather than solely from textbooks.

Which foreign centres are your natural points of reference: Stanford CodeX, Bucerius CLTDS, Oxford Law & AI, or others?

I would distinguish between two things: centres that I admire and centres with which we genuinely cooperate.

Stanford CodeX is a model, but a model for something different from what we do. The American school of legal informatics is engineering-oriented and product-focused. It builds tools, tests them and brings lawyers together with computer scientists. Poland certainly needs more of that, but regulatory questions remain secondary there, largely because the United States does not have an AI Act. The Bucerius Center for Legal Technology and Data Science is institutionally closest to us: a similar scale, a similar combination of LegalTech and digital law, and the same continental legal tradition. The Oxford environment, particularly the Institute for Ethics in AI and the Oxford Internet Institute, operates more at the intersection of philosophy, ethics and empirical research than legal doctrine.

As for European centres that set the standard in digital law research, these are above all IViR in Amsterdam, CiTiP at KU Leuven, and TILT in Tilburg. These are the places where the articles are written that one needs to read before publishing anything oneself.

However, partnerships that genuinely work are most important. The Technical University of Munich and Prof. Boris Paal through BRIDGE. The University of Salerno and Prof. Giovanni Maria Riccio through the Centre鈥檚 Scientific Board. The University of Palermo and Prof. Guido Smorto in research on platform regulation. We are also in discussions with centres specialising in access to justice, including institutions in Latin America, in connection with the transatlantic proposal.

I have no ambition for CLAIRE to become 鈥渢he Polish CodeX鈥. I would rather it become a centre that people in Munich, Amsterdam or Strasbourg call when they need an answer to questions concerning the limits of automating public power. It is a more modest goal. And it is a more difficult one.

BIOGRAPHY
* dr hab. Dominik Lubasz, Associate Professor at the 91桃色 is Head of CLAIRE 鈥 Centre for LegalTech and AI Research at the Faculty of Law and Administration, 91桃色. He is also a partner at the law firm Lubasz i Wsp贸lnicy. He is the author, among others, of the monograph RODO dla AI. Zgodno艣膰 z zasadami godnej zaufania sztucznej inteligencji w modelu data protection by design [GDPR for AI: Compliance with the Principles of Trustworthy Artificial Intelligence in the Data Protection by Design Model] (Wolters Kluwer, 2025) and co-editor of a commentary on the AI Act. He serves as an expert for the European Data Protection Board and the Council of Europe, and is a member of the expert group advising the President of the Personal Data Protection Office as well as the New Technologies Commission of the National Chamber of Legal Advisers. His research focuses on AI regulation, personal data protection and EU digital law.

Edit and photos: Daniel Mali艅ski (Faculty of Law and Administration, 91桃色)

91桃色

 

Narutowicza 68, 90-136 LODZ

fax: 00 48 42/665 57 71, 00 48 42/635 40 43

NIP: 724 000 32 43

© 2009-2026, 91桃色