WILIŃSKI LEGAL

AI & Cybersecurity

Technology changes faster than internal procedures. A legal problem often begins before management even learns that a new tool is being used or that an incident has occurred.

We support organisations with the legal aspects of artificial intelligence, cybersecurity, KSC/NIS2 and technology-risk management. We do not replace the IT team — we focus on accountability, decisions, procedures and legal obligations.

Practice leadership

The AI & Cybersecurity practice is led by attorney Tomasz Wiliński

The practice combines technology law with management accountability, compliance and crisis management. The objective is not to create documents for their own sake, but to prepare the organisation for decisions that will genuinely need to be made.

Who we support

Technology law from the management-decision perspective

Management boards

Accountability, oversight, post-incident decisions, risk acceptance and organisational readiness.

Legal and compliance teams

Policies, registers, roles, escalation procedures and compliant use of AI.

IT and security teams

Translating a technical incident into legal obligations, organisational decisions and communication.

Organisations deploying AI

Rules for tool use, confidentiality, data, copyright and human oversight.

Products

Services that deliver a concrete result

Incident-readiness review

Assessment of roles, procedures, decision paths and communication. Result: a list of gaps, priorities and an action plan for management.

KSC/NIS2 legal audit

Assessment of the organisation's obligations, accountability and documentation, together with an adaptation plan.

AI Use Policy

Rules for permitted use, data classification, human control, confidentiality and employee accountability.

AI Governance

Review of how AI is used in the organisation, allocation of roles, approval procedures and documentation of decisions.

Board training

A practical workshop: what management is responsible for, what it should know and which questions it should ask technical teams.

Incident response

Support in assessing obligations, communication, documenting decisions and coordinating with IT and people responsible for data.

How we work

Facts first, documentation second

01

Map of use and risk

We establish where technology is actually being used and who makes the relevant decisions.

02

Legal obligations

We assess the regulations and accountability framework applicable to the organisation.

03

Gaps

We identify what is missing organisationally, legally or in the documentation.

04

Implementation

We prepare procedures and materials that employees and management can realistically use.

Frequently asked questions

Does the firm perform technical cybersecurity audits?

No. We focus on the legal and organisational layer, accountability and procedures. Where needed, we work with the client's technical specialists or external experts.

Is an AI policy enough?

Not if the organisation does not know where and how AI is being used. The document should reflect the real model of tool use and allocation of responsibility.

When should an incident-response procedure be prepared?

Before an incident occurs. After an attack, time is consumed by operational decisions, so roles, contacts and escalation paths should be established in advance.

Insights

Materials for management boards

Cyber

What management should do before a cyber incident

The most important decisions should be made while everything is still working.

AI

Can employees use AI for company documents?

Risks involving confidentiality, personal data and trade secrets.

Governance

An AI policy is only the beginning

How to assign roles and control the use of tools within the organisation.

Cybersecurity and responsible AI use begin before the problem, not after it.