Warto wiedzieć
Źródła, na których opieram to, co mówię
Nie proszę, żebyś wierzył mi na słowo. Poniżej badania, przepisy i własne pomiary — wszystko z linkami do oryginałów, żebyś mógł sprawdzić sam, zanim ze mną porozmawiasz.
Stan na 5 października 2026 r.
Worth knowing
The sources behind what I tell you
I'm not asking you to take my word for it. Below are studies, regulations and my own measurements — all linked to the originals, so you can check for yourself before we talk.
As of 5 October 2026.
Porównanie kart graficznych do lokalnego AI
Dla firm, które przechodzą do fazy II i wybierają kartę graficzną do własnego serwera.
Zanim kupisz kartę graficzną do fazy II — wyniki porównawcze na Qwen3.8-27B i Qwen3.8-Flash-Next 177B
local-ai.company · pomiary 24 września – 4 października 2026 · Qwen3.8-27B i Qwen3.8-Flash-NextTen sam budżet tokenów na czterech działających instalacjach: Qwen3.8-27B na RTX 3090, na Intel Arc Pro B70 i na czterech RTX 3090 w jednej maszynie (w pełnej precyzji BF16) — oraz te same cztery RTX 3090 z nowym modelem Qwen3.8-Flash-Next 177B, który na każdy token liczy tylko ok. 6 mld parametrów. Przy dokumencie 189 tys. tokenów Flash-Next generuje 140 tok/s, a 27B na tych samych kartach — 9.
Pojedyncza RTX 3090 (4 500 zł) przy limicie 180 W daje łącznie 46–50 tok/s i ta liczba nie rośnie między trzema a ośmioma osobami; przy limicie 220 W, jeśli wytrzyma go zasilacz komputera — około 70 tok/s. Na stronie są też pobór mocy, rachunek za prąd i koszt sprzętu na jeden token na sekundę.
To porównanie działających instalacji, a nie samego krzemu w identycznych warunkach — konfiguracje różnią się kwantyzacją i silnikiem inferencji.
Zobacz wynikiAgenci od gigantów: dostęp do naszych dokumentów i tokeny, które właśnie podrożały dwukrotnie
YouTube · Sharbel A. · „OpenAI Just Launched Dots. Here's The Truth About It.” · po angielsku · 12 minFilm porównuje nowych „zawsze włączonych” agentów: dots od OpenAI (DevDay, 29 września 2026), Muse od Meta (8 września), Grok Bot od SpaceXAI, czyli połączonych SpaceX, xAI i Cursora (11 sierpnia), oraz otwartego Hermes Agent. Agenci gigantów pracują na komputerach w chmurze dostawcy, logują się do Twojej poczty, kalendarza i aplikacji i działają dalej, gdy zamkniesz laptopa.
Wynika z tego, że giganci technologiczni owszem dadzą nam agentów u siebie — takich, którzy mogą robić wszystko i mają dostęp do naszych dokumentów, co już samo w sobie budzi niepokój. Do tego taki agent pracuje bez przerwy i w tle zużywa bardzo dużo tokenów. A tokeny właśnie podrożały dwukrotnie: od 30 października w planie ChatGPT Pro za 200 USD limit Codex i ChatGPT Work spada z 20-krotności planu Plus do 10-krotności — ta sama cena za połowę pracy. Nowy plan kosztuje 500 USD miesięcznie.
Comparing graphics cards for local AI
For companies moving to Phase II and choosing a graphics card for their own server.
Before you buy a GPU for Phase II — comparative results on Qwen3.8-27B and Qwen3.8-Flash-Next 177B
local-ai.company · measured 24 September – 4 October 2026 · Qwen3.8-27B and Qwen3.8-Flash-NextThe same token budget on four working installations: Qwen3.8-27B on an RTX 3090, on an Intel Arc Pro B70 and on four RTX 3090s in one machine (at full BF16 precision) — plus the same four RTX 3090s running the new Qwen3.8-Flash-Next 177B, which computes only about 6 billion parameters per token. On a 189k-token document Flash-Next generates 140 tok/s; 27B on the same cards, 9.
A single RTX 3090 (€1,050) capped at 180 W delivers 46–50 tok/s in total, and that figure does not grow between three and eight users; at a 220 W cap, if the computer's power supply can take it — about 70 tok/s. The page also covers power draw, the electricity bill and hardware cost per token per second.
This compares working installations, not bare silicon under identical conditions — the configurations differ in quantisation and inference engine.
See the resultsAgents from the tech giants: access to our documents, and tokens that just doubled in price
YouTube · Sharbel A. · “OpenAI Just Launched Dots. Here's The Truth About It.” · 12 minThe video compares the new “always-on” agents: dots from OpenAI (DevDay, 29 September 2026), Muse from Meta (8 September), Grok Bot from SpaceXAI — the merged SpaceX, xAI and Cursor (11 August) — and the open-source Hermes Agent. The giants' agents run on computers in the provider's cloud, sign into your e-mail, calendar and apps, and keep working after you close the laptop.
The takeaway: the tech giants will indeed give us agents on their own platforms that can do anything and have access to our documents — which is unsettling in itself. On top of that, such an agent works non-stop and burns a lot of tokens in the background. And those tokens have just doubled in price: from 30 October, the Codex and ChatGPT Work allowance in the $200 ChatGPT Pro plan drops from 20 times the Plus plan to 10 times — the same price for half the work. A new plan costs $500 a month.
Co naprawdę dzieje się w firmach
Punkt wyjścia całej oferty: pracownicy już używają AI, tylko nie tego, które im dałeś.
Pracownicy nie rezygnują z AI, nawet gdy firma tego zakazuje
Infor.pl (Kadry) · 15 września 2026 · na podstawie raportu „Cyberportret polskiego biznesu 2026” (ESET i DAGMA Bezpieczeństwo IT)Badanie ARC Rynek i Opinia z marca 2026 r., przeprowadzone przez internet na próbie 1026 osób pracujących przy komputerze co najmniej trzy dni w tygodniu. Pokazuje skalę zjawiska nazywanego shadow AI — korzystania z narzędzi AI poza wiedzą i kontrolą pracodawcy.
Pracownicy
Firmy
Autorzy zalecają jasne zasady zamiast samych zakazów, szkolenia z ryzyk, bezpieczne narzędzia z licencją i kontrolę przepływu danych. To pokrywa się z tym, co powtarzam na konsultacjach: zakaz nie działa, bo nie usuwa powodu. Działa dopiero danie ludziom narzędzia, które jest równie wygodne i jednocześnie dozwolone.
Przeczytaj artykułWhat is really happening in companies
The starting point of the whole offer: your staff already use AI — just not the one you gave them.
Employees don't give up AI, even when the company bans it
Infor.pl (Kadry) · 15 September 2026 · in Polish · based on the report “Cyberportret polskiego biznesu 2026” (ESET and DAGMA Bezpieczeństwo IT)An online survey by ARC Rynek i Opinia from March 2026, among 1,026 people in Poland who work at a computer at least three days a week. It shows the scale of what is called shadow AI — using AI tools without the employer's knowledge or control.
Employees
Companies
The authors recommend clear rules rather than bans alone, training on the risks, secure licensed tools and control over data flows. That matches what I say in every consultation: a ban doesn't work because it doesn't remove the reason. What works is giving people a tool that is just as convenient and also permitted.
Read the article (in Polish)Na początek: nie potrzebujesz wszystkiego naraz
Ta strona zbiera sporo pojęć i przepisów. Nie musisz znać ich wszystkich, żeby podjąć dobrą decyzję.
Najpierw proces, potem technologia
Zaczynamy od analizy, czego firma naprawdę potrzebuje — od procesu, który dziś boli. Sprzęt i model dobiera się do niego, nie odwrotnie.
Dwie drogi, często mylone
Wspomaganie pracowników: ludzie pracują szybciej, a system odpowiada na pytania, streszcza i szuka w dokumentach. Agenci AI w zespole: system sam wykonuje zadania, ma dostęp do narzędzi i pracuje w tle. To inna architektura, inny sprzęt, inne ryzyka i inne obowiązki z AI Act — warto wiedzieć, którą drogę się wybiera, zanim się cokolwiek kupi.
Najważniejsza jest kontrola nad danymi
Model, interfejs i sprzęt można wymienić. Danych, które raz wypłynęły, cofnąć się nie da.
First things first: you don't need everything at once
This page collects a lot of concepts and regulations. You don't need to master them all to make a good decision.
Process first, technology second
We start by working out what the company actually needs — beginning with the process that hurts today. Hardware and model are chosen to fit it, not the other way round.
Two paths that are often confused
Assisting employees: people work faster while the system answers questions, summarises and searches documents. AI agents on the team: the system carries out tasks on its own, with access to tools, in the background. Different architecture, different hardware, different risks and different AI Act duties — worth knowing which path you are taking before you buy anything.
Control over data comes first
The model, the interface and the hardware can all be replaced. Data that has leaked cannot be called back.
Region UE to nie to samo co jurysdykcja UE
Dostawcy chmurowi coraz częściej obiecują, że dane „zostaną w Europie”. Warto rozumieć, co taka obietnica zmienia, a czego nie.
OpenRouter rozdziela ruch: eu.openrouter.ai i us.openrouter.ai
OpenRouter · dokumentacja i blog · region UE od października 2025, region USA od 9 września 2026OpenRouter to pośrednik, przez którego firmy wysyłają zapytania do kilkuset modeli wielu dostawców. Uruchomił dwa osobne adresy regionalne. Zapytanie wysłane na adres europejski jest odszyfrowywane w UE i trafia wyłącznie do dostawców działających w UE. Jeśli żaden z nich nie obsługuje wybranego modelu, zapytanie kończy się błędem, zamiast wyjechać poza region. Funkcja jest dostępna w planach Business i Enterprise.
To dobry krok, ale dotyczy miejsca przetwarzania, a nie tego, czyje prawo obowiązuje firmę, która przetwarza. OpenRouter, Inc. to spółka amerykańska, a w sierpniu 2026 r. Stripe — również firma z USA — ogłosił, że ją przejmuje. Dokumentacja regionów mówi o zapytaniach i odpowiedziach. Nie obejmuje wprost danych konta ani rozliczeń. Polityka prywatności OpenRouter przewiduje natomiast ujawnianie danych na zgodne z prawem żądania organów publicznych.
Co prawo USA pozwala zrobić z danymi — niezależnie od adresu serwera
Kodeks Stanów Zjednoczonych (U.S. Code) · stan na wrzesień 2026-
CLOUD Act
18 U.S.C. § 2713 · 2018Dostawca podlegający prawu USA musi wydać dane, które ma w posiadaniu lub pod kontrolą, bez względu na to, czy serwer stoi w Stanach, czy w Europie. Do treści zwykle potrzebny jest nakaz sądu — ale amerykańskiego, nie europejskiego. Sąd może jednocześnie zakazać dostawcy informowania kogokolwiek, także klienta, tzw. gag order (18 U.S.C. § 2705(b)).
-
FISA, sekcja 702
50 U.S.C. § 1881aNadzór wymierzony w osoby spoza USA — czyli także w klientów z Europy. Nie ma nakazu na konkretną osobę: sąd FISA raz w roku zatwierdza ogólne certyfikaty, a dostawca dostaje polecenie współpracy z obowiązkiem zachowania tajemnicy. Ustawowa podstawa programu wygasła 12 czerwca 2026 r., ale certyfikaty zatwierdzone w marcu 2026 r. pozwalają prowadzić go do marca 2027 r. Kongres rozmawia o odnowieniu.
-
National Security Letters
18 U.S.C. § 2709FBI wydaje je samo, bez udziału sądu. Dotyczą danych o abonencie i rejestrów połączeń, a nie treści. Zwykle idzie z nimi zakaz ujawnienia, że żądanie w ogóle padło. Sąd bada takie pismo dopiero wtedy, gdy dostawca je zaskarży.
Dlaczego to nie jest teoria: przekazywanie danych do USA wisi na jednym porozumieniu
Trybunał UE i TSUE · stan na wrzesień 2026Przekazywanie danych osobowych do USA opiera się dziś na porozumieniu EU-U.S. Data Privacy Framework z 2023 r. Trybunał UE utrzymał je 3 września 2025 r., ale 31 października 2025 r. wniesiono odwołanie do TSUE i sprawa wciąż czeka na rozstrzygnięcie. Dwa poprzednie porozumienia — Safe Harbor w 2015 r. i Privacy Shield w 2020 r. — TSUE unieważnił właśnie z powodu zakresu amerykańskiego nadzoru.
Jeśli TSUE podważy także to porozumienie, firmy korzystające z amerykańskich usług znów staną przed pytaniem, na jakiej podstawie przekazują dane.
An EU region is not the same as EU jurisdiction
Cloud providers increasingly promise that data “stays in Europe”. It is worth understanding what that promise changes — and what it doesn't.
OpenRouter splits its traffic: eu.openrouter.ai and us.openrouter.ai
OpenRouter · docs and blog · EU region since October 2025, US region since 9 September 2026OpenRouter is a gateway through which companies send requests to hundreds of models from many providers. It now runs two separate regional addresses. A request sent to the European address is decrypted inside the EU and routed only to providers operating in the EU. If none of them serves the chosen model, the request fails instead of leaving the region. The feature is available on the Business and Enterprise plans.
That is a good step, but it concerns where processing happens, not whose law governs the company doing it. OpenRouter, Inc. is a US company, and in August 2026 Stripe — also a US company — announced it would acquire it. The regional documentation covers prompts and completions; it does not expressly cover account or billing data. OpenRouter's privacy policy, meanwhile, provides for disclosing data in response to lawful requests from public authorities.
What US law allows with data — wherever the server stands
United States Code · as of September 2026-
CLOUD Act
18 U.S.C. § 2713 · 2018A provider subject to US law must hand over data in its possession, custody or control, whether the server is in the United States or in Europe. Content usually requires a warrant — but from a US court, not a European one. The court can also forbid the provider from telling anyone, including the customer — a so-called gag order (18 U.S.C. § 2705(b)).
-
FISA Section 702
50 U.S.C. § 1881aSurveillance aimed at people outside the US — which includes customers in Europe. There is no warrant for a specific person: the FISA court approves general certifications once a year, and the provider receives a directive to assist, with a duty of secrecy. The statutory authority lapsed on 12 June 2026, but certifications approved in March 2026 allow the programme to run until March 2027. Congress is discussing renewal.
-
National Security Letters
18 U.S.C. § 2709Issued by the FBI itself, with no court involved. They cover subscriber information and connection records, not content, and usually come with a ban on revealing that the request was ever made. A court looks at such a letter only if the provider challenges it.
Why this isn't theoretical: data transfers to the US hang on a single framework
EU General Court and Court of Justice · as of September 2026Transfers of personal data to the US currently rely on the 2023 EU-U.S. Data Privacy Framework. The EU General Court upheld it on 3 September 2025, but an appeal to the Court of Justice was lodged on 31 October 2025 and is still pending. The two previous frameworks — Safe Harbor in 2015 and Privacy Shield in 2020 — were struck down by the Court of Justice precisely because of the scope of US surveillance.
If the Court of Justice undermines this framework as well, companies relying on US services will once again face the question of what legal basis they have for transferring data.
Przepisy, które Cię dotyczą
Oryginały, nie streszczenia. Warto mieć je pod ręką, zanim ktokolwiek zacznie Ci sprzedawać „zgodność”.
UODO: zanim wdrożysz narzędzie AI, sprawdź, czy jest zgodne z RODO
Urząd Ochrony Danych Osobowych · listy pytań · aktualizacja 6 sierpnia 2026Prezes UODO udostępnia gotowe listy pytań do samodzielnego sprawdzenia narzędzia AI przed wdrożeniem — w czterech wersjach: dla firm budujących lub dotrenowujących własne modele, dla MŚP korzystających z gotowych narzędzi, dla sektora publicznego i rozszerzoną, obejmującą także AI Act. Wypełnioną listę warto zachować: jest dowodem, że sprawdziłeś te kwestie przed uruchomieniem, czyli realizacją zasady rozliczalności.
Według wersji dla MŚP więcej niż trzy odpowiedzi „nie” oznaczają, że przed dalszym korzystaniem z narzędzia trzeba skonsultować się ze specjalistą. Ta sama lista zastrzega, że nie wystarcza, gdy w grę wchodzą dane wrażliwe albo dane trafiają poza EOG — wtedy trzeba sięgnąć po wersję rozszerzoną.
AI Act — rozporządzenie (UE) 2024/1689, pełny tekst po polsku
EUR-Lex · oficjalne źródło prawa UniiNajważniejsze dla firmy wdrażającej AI: art. 4 o kompetencjach personelu, art. 5 o praktykach zakazanych, art. 50 o obowiązku informowania użytkownika, że rozmawia z systemem AI, oraz załącznik III wyznaczający obszary wysokiego ryzyka — w tym rekrutację i ocenę pracowników.
Uwaga na role: kupując narzędzie, stajesz się podmiotem stosującym. Jeśli złożysz własne środowisko i opatrzysz je nazwą swojej firmy, w świetle rozporządzenia stajesz się dostawcą systemu AI, z pełnym zestawem obowiązków.
Otwórz tekst rozporządzeniaRegulations that apply to you
The originals, not summaries. Worth having to hand before anyone starts selling you “compliance”.
Polish data protection authority (UODO): check an AI tool against the GDPR before you deploy it
Personal Data Protection Office · checklists in Polish · updated 6 August 2026The President of UODO publishes ready-made checklists for vetting an AI tool yourself before deployment, in four versions: for organisations building or fine-tuning their own models, for SMEs using off-the-shelf tools, for the public sector, and an extended version that also covers the AI Act. Keep the completed list: it is evidence that you looked into these issues before going live — accountability in practice.
According to the SME version, more than three “no” answers mean you should consult a specialist before continuing to use the tool. The same list warns that it is not enough where sensitive data is involved or data leaves the EEA — in that case the extended version is needed.
The AI Act — Regulation (EU) 2024/1689, full text
EUR-Lex · the official source of EU lawMost relevant for a company deploying AI: Article 4 on staff AI literacy, Article 5 on prohibited practices, Article 50 on telling users they are dealing with an AI system, and Annex III listing high-risk areas — including recruitment and employee evaluation.
Watch the roles: when you buy a tool, you become a deployer. If you assemble your own environment and put your company's name on it, under the regulation you become a provider of an AI system, with the full set of obligations.
Open the regulationWłasne pomiary
Zamiast zrzutów ekranu i obietnic — liczby z mojego sprzętu, razem z tym, czego nie udało się zmierzyć.
Firmowy RAG z rerankerem — co potrafi i ile to trwa
local-ai.company · pomiary z sierpnia i września 2026Jak baza wiedzy odpowiada z Twoich dokumentów ze wskazaniem źródła, dlaczego drugi model — reranker — sprawdza trafność każdego znalezionego fragmentu, jak rozdzielone są dane pracowników i co zmienia karta graficzna.
W liczbach: około 1,3 s na wyszukiwanie z rerankingiem na karcie 12 GB, 90% pytań kontrolnych z właściwym dokumentem w pierwszej piątce wyników i 32 automatyczne testy separacji danych przed każdą zmianą.
Zobacz podstronęMy own measurements
Instead of screenshots and promises — numbers from my own hardware, including what could not be measured.
Company RAG with a reranker — what it does and how long it takes
local-ai.company · measured August and September 2026How the knowledge base answers from your own documents and names the source, why a second model — the reranker — checks the relevance of every retrieved excerpt, how employees' data is kept apart, and what difference a graphics card makes.
In numbers: about 1.3 s per search with reranking on a 12 GB card, 90% of control questions with the right document in the top five results, and 32 automated data-separation tests before every change.
See the pageTo wszystko i tak trzeba przełożyć na Twoją firmę
Na konsultacji przechodzimy przez to, co z tej strony dotyczy właśnie Ciebie: jakie dane, jakie procesy, jaki sprzęt i jakie obowiązki.
Umów konsultacjęAll of this still has to be applied to your company
In a consultation we go through what on this page actually applies to you: which data, which processes, which hardware and which obligations.
Book a consultation