With Regulation (EU) 2024/1689 — the so-called AI Act — the European Union has adopted the first comprehensive body of rules on artificial intelligence. It is not a rule for developers alone: it concerns, and above all, the businesses that merely use AI — to select staff, profile customers, automate decisions or generate content. It is therefore worth framing what the AI Act provides, to whom it applies, what obligations it introduces, within what deadlines and with what penalties — without alarmism, but aware that compliance must be built in good time.
What the AI Act is and to whom it applies
The AI Act, published in the Official Journal of the European Union on 12 July 2024 and in force since 1 August 2024, governs the development, the placing on the market and the use of artificial-intelligence systems in the Union. It addresses a range of actors: providers (those who develop or place an AI system on the market), deployers or professional users (those who use it in their activity), as well as importers and distributors. Its reach is extraterritorial: the Regulation also applies to operators established outside the Union where the system’s output is used within the Union.
The risk-based approach
The logic of the AI Act is to scale obligations according to the risk a system poses to people’s rights and safety. Four levels are distinguished:
- Unacceptable risk — the practices prohibited by Article 5: among others, social scoring, manipulative or subliminal techniques, the mass scraping of facial images for facial recognition, emotion recognition in the workplace and in schools.
- High risk — the systems listed in the annexes (including AI for staff recruitment and management, access to credit and essential services, education, justice, critical infrastructure, biometrics): permitted, but subject to strict obligations.
- Limited risk — subject only to transparency obligations (Article 50): the user must be informed that they are interacting with an AI (think of a chatbot), and synthetic content, including deepfakes, must be labelled as such.
- Minimal risk — the great majority of systems, freely usable.
What obligations for businesses
For high-risk systems the Regulation requires, on the provider, an articulated compliance system: a risk-management system, data-governance requirements for the training data, technical documentation and event logging, transparency towards users, human oversight, adequate levels of accuracy, robustness and cybersecurity, as well as the conformity assessment and CE marking.
The deployer — the business that uses the system — has its own obligations: to use it in accordance with the instructions, to ensure human oversight by competent staff, to monitor its operation and, in certain cases, to carry out a fundamental-rights impact assessment. Even those who “merely use” AI, then, have precise responsibilities.
The timeline
Application is gradual. The original timeline has been revised by the “Digital Omnibus” package, approved by the European Parliament on 16 June 2026 and, definitively, by the Council of the EU on 29 June 2026: the amending regulation, now in the course of publication in the Official Journal of the European Union, has postponed the deadlines for high-risk systems. The updated timeline:
- 2 February 2025: prohibition of unacceptable-risk practices (Article 5) and AI-literacy obligations;
- 2 August 2025: obligations for general-purpose AI models (GPAI) and the start of governance;
- 2 August 2026: transparency obligations (Article 50) — recognisable chatbots and the labelling of synthetic content, with a transitional window until 2 December 2026 for the technical marking of systems already on the market — together with the designation of the national authorities and the start of the penalty regime;
- 2 December 2027: obligations for “standalone” high-risk systems (Annex III), the deadline thus postponed by the Digital Omnibus;
- 2 August 2028: obligations for high-risk systems embedded in regulated products (Annex I).
The postponement therefore concerns high-risk systems only: in August 2026 transparency, national authorities and penalties take effect in any event. The references of the amending regulation should be cited as soon as it is published in the Official Journal.
The penalties
Article 99 sets penalties across several bands: up to 35 million euros or 7% of total worldwide annual turnover for prohibited practices (Article 5); up to 15 million or 3% for breaches of the other obligations (providers, deployers, transparency); up to 7.5 million or 1% for false or misleading information supplied to the authorities. For SMEs and start-ups, the lower of the fixed amount and the percentage applies.
The AI Act and the GDPR: two regimes that add up
The AI Act does not replace the GDPR: it sits alongside it. Any AI system that processes personal data remains fully subject to the data-protection Regulation — from the legal basis to the information notice, to the right not to be subject to automated decisions (Article 22 GDPR). For many businesses the first test of AI will not be the AI Act, whose application is gradual, but the GDPR, already fully operational.
The Italian layer: Law 132/2025
Alongside the EU Regulation comes Law No 132 of 23 September 2025, in force since 10 October 2025: Italy’s first national law on artificial intelligence. It entrusts governance to AgID and ACN (the national digital and cybersecurity agencies), imposes transparency obligations towards workers on the use of AI systems, lays down rules for the intellectual professions and healthcare, and introduces a new criminal offence for the harmful dissemination of deepfakes. Italian businesses must consider it together with the AI Act.
What the case law says
The AI Act, in gradual application, does not yet have its own body of enforcement decisions. The framework already in force, however, is the GDPR, on which the Garante has intervened precisely on the algorithmic systems used to manage workers — an area the AI Act classifies as high-risk.
By injunction order of 10 June 2021 (doc. web no. 9675440) the Garante fined Foodinho, of the Glovo group, 2.6 million euros for the algorithmic management of about nineteen thousand riders: the order-allocation system and the reputational score penalised couriers according to non-transparent criteria, without adequate safeguards as to the accuracy of the data or the right to human intervention. By a later decision of 13 November 2024 (doc. web no. 10074601) the Authority returned to the same company, imposing a fine of 5 million euros and requiring, among other things, that decisions taken by the algorithm be verified by suitably trained staff. These are, in essence, the same safeguards — transparency, accuracy, human oversight, non-discrimination — that the AI Act imposes, in strengthened form, on high-risk systems.
Getting to grips with the AI Act in good time — mapping the systems used, classifying their risk, putting the required measures in place — is the way to turn an obligation into a competitive advantage. It is a path closely interwoven with GDPR compliance and with the broader corporate-compliance picture.
Frequently asked questions
Does the AI Act apply to my company? Yes, if it develops, places on the market or uses AI systems. The intensity of the obligations depends on the system’s risk level; for many everyday uses it is minimal, but not nil.
When does the AI Act become mandatory? It has been in force since 1 August 2024; the prohibitions apply from 2 February 2025, the transparency obligations from 2 August 2026, and the obligations on high-risk systems — following the postponement enacted by the Digital Omnibus — from 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
Does using ChatGPT or generative AI in the company fall under the AI Act? Often these are minimal-risk uses, with light obligations (mainly transparency); the GDPR, however, always applies to the personal data processed.
This article is for informational purposes and reflects the rules in force as at the date of publication; it does not replace an assessment of the specific case.
This article is for general information only and is not legal advice on any specific case. Content reviewed by Giuseppe Foti, legal consultant — last checked on July 15, 2026.