AI Act transparency obligations in force since 2 August 2026

Artificial intelligence belongs in a business only when someone can account for how it works.

I help companies putting AI into their value chain do it in a way that is documented and defensible. Twenty years of corporate law applied to a technology the law has only just finished regulating.

Ugo Bruno Gambardella Corporate legal & compliance · Based in Potenza, Italy · Remote across Europe

Why now

The timetable is not yours to set.

The European AI Regulation has entered its application phase. Some deadlines have passed, part of the framework has been pushed further out, and Italy is drafting its own implementing rules. Here is where things actually stand.

  1. Done

    Entry into force Regulation (EU) 2024/1689 becomes part of the European legal order.

  2. Done

    Prohibitions and AI literacy Prohibited practices take effect, alongside the duty to ensure an adequate level of AI literacy among staff who use these systems.

  3. Done

    General-purpose models Obligations for GPAI model providers, European governance structures and designation of national authorities.

  4. In force

    Transparency and penalties Article 50 transparency obligations apply, together with the national penalty regime and Commission fines on general-purpose model providers.

  5. Next

    Italian implementing decrees Deadline for the delegated decrees under Italian Law 132/2025. Supervision is split between AgID and the National Cybersecurity Agency.

  6. Postponed

    High risk, Annex III Obligations for high-risk systems listed in Annex III, moved back by the Digital Omnibus.

  7. Later

    High risk inside products Systems embedded in products already governed by sectoral safety legislation, such as machinery and medical devices.

A postponement is not a pause. The Digital Omnibus, adopted by the European Parliament on 16 June 2026 and by the Council on 29 June, moved back only the high-risk obligations. Everything else already applies. And since building a system inventory, renegotiating supplier contracts and training staff normally takes twelve to eighteen months, the time gained is working time, not waiting time.

Services

Four ways into your processes.

Project-based engagements with a defined scope and a specific set of deliverables. No open-ended retainers, and no report that ends up in a drawer.

Innovation and digital transformation

I support the introduction of new technology into production and administrative processes: who does what, with which tool, under whose responsibility, and leaving which documentary trail.

  • Process mapping and identification of control points
  • Redesign of roles, delegations and internal procedures
  • Documentation that withstands audit and inspection
  • Support for certification and public funding routes

AI Act readiness and AI governance

From an inventory of what the company already uses to an internal policy people can actually follow. The point is not to slow adoption down; it is to make adoption demonstrable.

  • Inventory of AI systems and of the roles held in each
  • Risk classification and gap analysis
  • Internal usage policy and transparency duties
  • Contract clauses for suppliers and integrators

Data protection, GDPR and the DPO function

AI multiplies personal data processing and changes its nature. I put the data protection framework back in order and, where useful, take on the data protection officer function on an outsourced basis.

  • Records of processing and impact assessments
  • Appointments, instructions and processor agreements
  • Breach procedure and incident handling
  • Outsourced, ongoing DPO function

Decree 231 model and supervisory body

Italian corporate criminal liability now reaches cyber and environmental offences. I build or update the organisational model and can serve on the supervisory body — relevant to any group with an Italian subsidiary.

  • Risk assessment on predicate offences
  • Drafting and updating of the organisational model
  • Protocols, reporting flows and whistleblowing channel
  • Membership of the supervisory body

Method

Three phases, with an end date.

I know what the person signing the engagement is afraid of: a project that widens, drags on and produces nothing anyone can use. So each phase has an estimated duration and a recognisable deliverable.

Assessment

Where you actually are, not where the procedures say you are. Interviews with the people responsible, review of the systems in use, reading of contracts already signed. It closes with a report listing the gaps by severity and by cost to close.

Build

The part that produces usable documents: policies, registers, appointments, contract clauses, notices, protocols. Written to be applied by the people doing the work, not to survive one inspection and then be forgotten.

Oversight

Compliance is a habit rather than a state. Periodic checks, training for the people using the tools, updates when the rules change — on an agreed schedule rather than on call.

Track record

Twenty years across courtrooms, factories and customs offices.

I did not come to compliance through theory. I negotiated a joint venture in China, handled health accreditation for export markets, and spent six years overseeing process compliance inside logistics hubs that never stop. That is where you learn what a badly written procedure really costs.

  1. 2019 — 2025

    Operations, quality and process compliance

    H&F S.p.A. — four Amazon hubs · contractual title: Administrative Assistant

    Operational management of technical infrastructure across four sites, supervision of process compliance, quality control and reporting, coordination of operational teams.

  2. 2017 — 2019

    Operations and process control

    ELPE S.p.A. — Amazon site, Pomezia · contractual title: Administrative Assistant

    Technical infrastructure of the site, support to operational activities on the compliance side, quality control of service delivery.

  3. 2015 — 2016

    International Project Coordinator

    CCIC-Boja Information Technology — Hangzhou, China

    Coordination of a multicultural team of more than fifty professionals on a public–private project, liaising with university, customs, institutional and banking stakeholders in Zhejiang province.

  4. 2014 — 2015

    International Project Manager · due diligence and joint venture

    Zhejiang Pingroup — Shanghai, China

    Legal and organisational management of the establishment of an Italian–Chinese joint venture: due diligence, international negotiation, coordination of professionals and stakeholders.

  5. 2012 — 2014

    Advisor and international development

    S.I.S.MA. S.r.l.

    Documentary compliance and relations with certification bodies. Support in obtaining HACCP certification and FDA accreditation for export to the United States and Canada.

  6. 2000 — 2014

    Independent professional practice

    Rome and Tallinn, Estonia

    Commercial and employment law, contract drafting, arbitration and litigation. Admitted to the Tallinn Bar Association; retained counsel to the Italian Embassy in Estonia. Inspection of public works contracts for the release of European funding.

  7. 1988 — 1993

    Assistant Officer, civil service

    Presidency of the Council of Ministers, Italy

    Handling of confidential administrative matters under strict procedures and binding confidentiality obligations.

Education

Qualifications

  • 2025 — 2026 Second-level University Master’s in artificial intelligence, digital teaching and new technologies for inclusive processes in progress University of Basilicata. Expected completion December 2026. The programme covers the new European DigComp 3.0 framework, published by the Commission’s Joint Research Centre in November 2025, which weaves artificial intelligence through all twenty-one digital competences.
  • 1994 — 2000 Degree in Law Sapienza University of Rome.
  • 2005 Qualified to practise law in Italy Professional qualification obtained in 2005.
  • Courses Decree 231/2001, GDPR and cybersecurity Corporate conduct, Regulation (EU) 2016/679, specialist information security training.
  • Certified DigComp 2.2 EDO Initiative, Italian Ministry of Labour and Social Policies.
  • Languages Italian native · English B2 One-year course at the City College of San Francisco.

Areas of work

What I am called in for

  • AIAI Act and AI governance Inventory, risk classification, usage policy, transparency duties, supplier obligations.
  • DataPrivacy and data protection GDPR, records of processing, impact assessments, breach handling, outsourced DPO function.
  • 231Corporate liability Organisational model, risk assessment on predicate offences, supervisory body.
  • GovernanceStructures and controls Delegations, procedures, reporting flows, documentary audit, due diligence.
  • ProcessQuality and operational compliance Process control, reporting, certification, inspection readiness.
  • Cross-borderInternational operations Joint ventures, negotiation, export accreditation, coordination of multicultural teams.

Frequent questions

The objections I hear most often.

Straight answers rather than sales copy. If one of these is close to your situation, it is probably worth a conversation.

My company only uses ChatGPT. Does the AI Act apply to us?

Yes, in the role of deployer. An organisation that uses an AI system in the course of its business carries its own obligations, separate from those of the provider: telling people when they are interacting with an AI system, ensuring an adequate level of AI literacy among the staff who use it, and keeping the underlying data processing compliant with the GDPR. Light obligations if addressed early; expensive ones if addressed after an inspection.

High-risk obligations have been postponed. Can we wait?

The postponement concerns only high-risk systems, which now apply from 2 December 2027 and 2 August 2028. Transparency duties, the ban on prohibited practices, the AI literacy requirement and the penalty regime already apply in full. Beyond that, building an inventory, renegotiating supplier contracts and training staff normally takes twelve to eighteen months: the time gained is working time, not waiting time.

Can the Data Protection Officer be external to the company?

Yes. Article 37(6) of the GDPR expressly allows the data protection officer to be a member of staff or to fulfil the tasks under a service contract. An external appointment removes the conflict of interest with operational roles, which is the substantive requirement of the function and the most common ground on which internal appointments are challenged.

What is Decree 231/2001, and does it reach foreign groups?

Italian Legislative Decree 231/2001 introduced administrative liability of the entity for certain criminal offences committed in its interest or to its advantage. It applies to companies operating in Italy, including Italian subsidiaries of foreign groups. Adopting and effectively implementing an organisational and management model is the only route to exemption from that liability — and a model adopted after the fact produces no effect at all.

How long does an AI Act readiness assessment take?

Three to six weeks for a mid-sized organisation. The first step is an inventory of the AI systems actually in use, which almost always returns a higher number than expected because it captures tools adopted by individual departments without central approval. Risk classification, gap analysis and a prioritised action plan with assigned ownership follow.

Do you work with companies outside Italy?

Yes. The AI Act and the GDPR are EU regulations applying uniformly across member states, and both have extraterritorial reach: they bind providers established outside the Union where the output of the system is used within it. I have worked in Estonia, in China and on accreditation routes for export to the United States and Canada. Meetings are held in English or Italian.

Contact

The first conversation is free.

Thirty minutes to understand where you stand and whether I can be useful. If the answer is no, I will say so straight away and point you towards who to look for instead.

The details you provide are used only to reply to you. They are not used for marketing and are never passed to third parties.