A sporting director drops three player profiles into an AI tool and asks which transfer is best. An administrator uploads a contract to have it summarised. Marketing generates a match preview. A physiotherapist wants to combine an athlete's test results with their injury history. HR uses an algorithm to sort applications for a new role.
In each case we say: "we use artificial intelligence".
In terms of organisational risk and law, these are five completely different situations.
And that is where the problem starts.
Many sports organisations are trying to answer the question: "Can we use ChatGPT and other AI tools?"
That is the wrong question.
The right one is:
"What do we use AI for, what data do we give it, who is affected by its output, who takes the final decision and who is accountable for it?"
Since 2 August 2026 the answer is no longer only a matter of good technology management. It has become part of an organisation's compliance with the European AI Act. That does not mean every club needs an AI officer, a two-hundred-page policy or a ban on generative AI.
Quite the opposite.
The worst response to the AI Act would be to block the technology out of fear of regulation. The second worst would be to let everyone use it with no rules at all.
A mature organisation does something in between.
It knows where it uses AI, what for, what risk follows and where a human must stay in charge.
The argument
For sport, the AI Act is first a test of management maturity and only second a legal problem.
A club or federation that cannot say today where its staff use artificial intelligence cannot assess the risk that follows from it.
The best policy drafted by a law firm will not help.
You cannot manage what the organisation cannot see.
Legal status and nature of this material. This text is informational and does not constitute legal advice. It describes the state of play as of 10 August 2026, including the AI Omnibus package that entered into force on 27 July 2026. Classifying a specific system always requires individual legal analysis.
What actually happened on 2 August 2026
A lot of confusion has built up around this date, so it is worth being precise. On 2 August 2026 most of the AI Act started to apply, the Article 50 transparency obligations came into effect and enforcement of already applicable rules began. It is not the date from which all high-risk requirements apply. That was changed by the AI Omnibus package, which entered into force on 27 July 2026 and postponed some deadlines.
The timeline reflects the official implementation schedule published by the European Commission's AI Act Service Desk after the AI Omnibus entered into force. Source links are listed at the end of the article.
For a club, the practical conclusion differs from the headlines. Postponing high-risk deadlines is not an exemption from thinking — it is time to prepare. What already applies concerns the most everyday matters: prohibited practices, staff competence and content transparency.
The AI Act is not a law about ChatGPT
The most common misreading in sports organisations is to equate the AI Act with regulation of popular chatbots. The regulation governs AI systems by risk and by the role of the entity, not by brand popularity. Four distinctions matter for a club, association or academy.
First, the role. A provider develops a system and places it on the market under its own name. A deployer uses it in the course of its activity. A club is almost always a deployer — unless it rolls out someone else's tool under its own brand or substantially modifies it. It may then take on provider obligations, which is easily forgotten in joint projects with a technology partner.
Second, the risk category. Some practices are prohibited. Some uses qualify as high risk, including systems used in employment and worker management, and in education and vocational training. Many back-office tools fall into neither category but are subject to transparency obligations if they generate content or interact with people.
Third, parallel regulation. The AI Act does not replace the GDPR. If a prompt contains a player's name, an injury description or a fan's contact details, that is processing of personal data with all the consequences. The European Data Protection Board addressed this interface between AI models and data protection in Opinion 28/2024.
Fourth, the object of regulation. The law is not interested in whether a tool is fashionable. It is interested in what data goes in, what output comes out and what decision about a person is taken on that basis.
The five situations from the opening — what to do about them
1. The sporting director and a player list in a prompt
This is the most common real incident in clubs. Players' personal data goes into an external system, often together with character assessments, family information or contract situations. The risk is not that the model will "steal" the list. It is that the club has no legal basis for the processing, does not know where the data is stored and cannot document who entered it and when. The fix is simple and does not mean giving up the tool: work with pseudonyms and player codes, keep substantive assessment in the scouting system, and use the AI assistant for document structure rather than as a store of knowledge about people. We write more about data discipline in sport in our analysis of biometric data in sport .
2. Administration and a scanned sponsorship contract
A sponsorship contract usually contains a confidentiality clause, the details of the people representing the parties and the financial terms. Uploading it to a free tool with no processing agreement and no knowledge of whether input data feeds model training is both a contractual risk and a risk to the partner relationship. A practical rule: confidential documents are processed only in tools approved by the organisation, in a version with training on customer data switched off and with a signed data processing agreement.
3. Marketing and an unlabelled image using a player's likeness
Three regimes meet here: the Article 50 transparency obligations, image rights and the player's contract. Since 2 August 2026 the obligations on synthetic content and deepfakes apply, and on 20 July 2026 the European Commission published guidelines on Article 50. For a club this means a concrete editorial procedure: label machine-generated content, prohibit synthetic reproduction of voice or likeness without consent, and add a checkpoint to publication approval. It is the cheapest change on the list and the one that protects reputation fastest.
4. The physiotherapist and a specific player's injury notes
Health data is a special category of data. Typing it into a general consumer assistant is a risk that no time saving justifies. This is not about keeping the medical staff away from technology — it is about using tools designed for medical data, on an established legal basis and after a data protection impact assessment.
5. HR and automated rejection of candidates
This is the one case of the five that points directly at the high-risk category: systems used in recruitment and worker management are listed in Annex III. Rules for that category start to apply on 2 December 2027, but a club has no reason to wait. Automatic rejection of an application without human involvement is a discrimination and reputational risk regardless of the implementation calendar. The minimum today: the system may sort and suggest, a person decides, and the criteria are written down before recruitment starts.
Shadow AI: personal accounts and the question nobody asked
The biggest problem for sports organisations is not which AI tools they use officially. It is which tools staff use unofficially, on personal accounts and phones, after hours, to make a press conference or a licensing deadline. This is called shadow AI, and sport is fertile ground for it: seasonality, time pressure, small back offices, many volunteers and people on short contracts.
Shadow AI has three consequences. The organisation does not know what data has left its environment. There is no trace of how a document sent to a federation or sponsor was produced. And it cannot demonstrate compliance, because it does not know its own factual situation. A punitive response usually makes things worse — staff stop admitting they use the tools and the risk grows.
The effective order is the reverse: first an information amnesty and an honest inventory with no disciplinary consequences, then access to an approved tool in its business version, then a data rule, and only at the end enforcement. Staff do not bypass rules out of disloyalty. They bypass them because nobody gave them a legitimate path that works just as fast. It is the same mechanism we described in knowledge management in a sports club : knowledge and tools circulate outside the system until the system is more convenient than the workaround.
Do staff have to be trained in AI?
Yes — and it is not a recommendation but an obligation. Article 4 of the AI Act requires providers and deployers to ensure a sufficient level of AI literacy among staff operating the systems. It has applied since 2 February 2025. The European Commission maintains an official Q&A on AI literacy.
The provision requires no certificates or multi-day courses. It requires proportionality: a person generating social-media graphics needs different competence than a person using a recruitment support tool. In practice, short and concrete training covering four things works well: what the model is and cannot do, what data may be entered, how to spot a model error and who takes the final decision. The last point matters most culturally — if nobody in the organisation owns the decision, AI is not the problem but a convenient alibi. We write more about the competence gap in Polish sport in our article on the role of education in sport .
The BRAMKA AI model
The name is deliberate: "bramka" means a gate in Polish (and a goal in football). A gate is not a wall — you walk through it. The point is controlled entry, not prohibition.
B for Base of use
An organisation's first document should not be an AI policy. It should be an AI use case register. One table. Tool. Department. User. Purpose. Type of data. Influence on decisions. Recipient of the output. Responsible person. That is enough to see more within days than months of AI strategy discussions produce. Some boards discover for the first time that artificial intelligence is already in use across the organisation. Nobody had named it before.
R for Risk
Not every use of AI needs the same process. A model suggesting a post headline should not go through the same procedure as an algorithm recommending job candidates. The simplest management filter has four questions: does the AI work on personal or confidential data? Does its output affect a specific person? Can the output cause a material sporting, financial or legal effect? Can a human realistically verify the result? The more "yes" answers, the higher the level of control.
A for Authorisation
"Staff may use AI" is not a policy. "Staff may not use AI" is not a policy either. An organisation should clearly identify approved tools and the categories of information that may be processed in them. A public press release, a draft internal presentation, an unpublished sponsorship offer, a transfer contract and a player's medical file must be treated very differently. Authorisation does not mean blocking innovation. It means staff do not have to work out for themselves each time whether they have crossed a line. A good policy removes uncertainty.
M for Meaningful human oversight
The most dangerous sentence in an organisation using AI may become: "that is what the system showed". AI can prepare an analysis, flag anomalies, compare data and draft a recommendation. But the greater the impact of a decision on a person, a budget or the organisation, the more precisely you must define who may challenge the output and who signs off. Human-in-the-loop cannot be decoration. If a person approves 200 recommendations a day with no real ability to assess them, they are formally in the process but not actually in control.
K for Knowledge
Not everyone needs to know how a transformer is built. Everyone should know where the competence of the tool they use ends. A communications officer should understand hallucinations, fact-checking, content rights and publication rules. Someone working with player data should understand data protection and the system's limits. A manager should be able to judge whether AI supports a decision or has started to replace it. A board should understand the organisational risk. That is AI literacy — not prompt craft.
A for Auditability
Six months later it should be possible to answer: "why did we take this decision and what role did AI play in it?" Not every situation requires archiving every prompt — that would be as absurd as printing every email. But in materially risky processes an organisation should keep enough of a decision trail to establish which system was used, what data it received, who verified the output and who took the decision. That is not bureaucracy. It is organisational memory. And without memory there is no accountability.
Text diagram (also available to screen readers): Base of use → Risk → Authorisation → Meaningful human oversight → Knowledge → Auditability . The cycle repeats for every new tool and every material change of use.
The 30-second test before sending a prompt
The BRAMKA AI model is for the organisation. An individual employee needs a shortcut that fits in their head before they hit enter. Four questions:
- Would I send this information to an external consultant if I did not yet know the terms of our contract with them?
- Would I be comfortable if my manager, a lawyer or an auditor saw this prompt tomorrow?
- Will the AI output influence a decision about a specific person?
- Can I verify the accuracy of the answer myself?
If the answer to the first two is "no", or to the last one "I don't know", the task should be stopped and sent for verification. Simple rules often work better than forty pages of policy.
What to require from an AI vendor
A club takes on most of the risk when it signs the contract, not when it uses the tool. The list below is the minimum worth asking about before purchase — including when the tool comes as part of a sponsorship package or a free pilot.
A 30-day plan for a club or federation
The plan assumes the reality of an organisation where nobody works on AI full time and the board has a few hours a month for it in total.
After thirty days an organisation is not "AI Act compliant" — compliance is not a one-off state. But it is in a position where the board knows where AI works in the club, who is responsible for it and what data leaves the organisation. That is more than most organisations in Polish sport have today.
The biggest mistake: compliance theatre
The sector's most likely response to the AI Act is not breaking the law but compliance theatre. It looks like this: a club buys a template AI policy, uploads it to the intranet, collects staff signatures confirming they have read it and closes the topic. The AI system register is created once and never updated. Training happens as a 40-slide deck sent by email. Nobody changes how they work.
Compliance theatre is worse than doing nothing, because it creates an illusion of safety. The board believes the matter is closed and stops asking. Meanwhile the real situation — personal accounts, data in external systems, unlabelled content — remains untouched. In an inspection or an incident, a signed policy is not evidence of compliance. The evidence is a register somebody actually maintains and decisions that can be reconstructed.
The distinguishing test is simple: if after adopting an AI policy not a single person changed how they do their job, there was no implementation.
Where criticism of the AI Act is justified
Honesty requires acknowledging that some criticism of the regulation is well founded. First, the cost of compliance is disproportionate — for a club with two administrative staff the same obligations weigh far more than for a federation with a legal department. Second, interpretative uncertainty is real: the fact that deadlines were moved by the AI Omnibus package shows the rules of the game changed while organisations were preparing.
Third, there is a risk of the opposite effect. An overly restrictive internal policy does not remove AI from the organisation — it pushes it into the grey zone of personal accounts, where control is zero. Fourth, in amateur sport and small clubs the real problem is not artificial intelligence but the lack of basic data hygiene: shared mailboxes, passwords on sticky notes, documents on private drives.
The conclusion is not "let's wait". It is: match the scale of the response to the scale of the organisation. For a small club the answer is one page of rules and a list of two approved tools, not an AI risk management system.
Should every club already have an AI policy?
Not every club needs a document called an "AI policy". Every club where anyone uses AI tools for work needs three things: knowledge of which tools these are, a rule on data and a named responsible person. If those three fit on a single page, that is a sufficient AI policy for an organisation of that size.
An extensive document makes sense where scale demands it: in a federation, in a club with an academy and a developed HR function, in an organisation processing players' medical data, in an operator of a venue with security systems. The criterion is not ambition but the number and sensitivity of use cases. Exactly as in the governance of sports organisations : a document with no owner and no review cycle is not a management mechanism, only an annex.
Frequently asked questions
Strategic conclusion
The AI Act asks sports organisations a question that has always been difficult in sport: who actually takes decisions, and on what basis. Artificial intelligence only accelerates the consequences of how an organisation is managed. In a club with a clear division of responsibility, AI becomes a tool that speeds up work. In a club without it, AI becomes one more place where nobody knows who decided.
That is why the first step is neither a legal audit nor a system purchase. The first step is an honest list of the tools the organisation already uses — including those the board does not know about. Everything else, the BRAMKA AI model included, is only a way of organising that list. Clubs and federations that go through this now will not be catching up in December 2027. They will be updating something that already works.