AI Act · Obligations in force

The AI Act delay does not apply to your company

The European regulation on artificial intelligence has applied since 2 August 2026 in the part that reaches almost every business. What slipped to 2027 concerns one specific category of systems, which most companies neither build nor own.

For some weeks now I have heard the same sentence repeated in meetings: the AI Act has been postponed to 2027, we will come back to it next year. That is not the case, and the misunderstanding comes from a true piece of news read badly.

The regulation has been in force since 1 August 2024, but it does not apply all at once: it comes into operation in blocks, and the largest block became applicable on 2 August 2026. The Digital Omnibus on artificial intelligence — Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026 — moved one precise part of those blocks forward, the part on high-risk systems, and left where they stood the prohibitions, the transparency obligations and the power of the authorities to impose penalties.

For most companies, which buy artificial intelligence rather than build it, the postponement moved exactly the part that did not concern them.

The delay covered one thing only.

Moved forward
  • High-risk systems under Annex III2 December 2027. These are the systems that decide, or help decide, about a person: recruitment, allocation of tasks, creditworthiness assessment, access to essential services.
  • High-risk AI embedded in already regulated products2 August 2028. Systems acting as safety components in machinery, medical devices and other products subject to European harmonisation. The postponement aligns the two regimes: the Machinery Regulation (EU) 2023/1230 applies from 20 January 2027.
  • High-risk systems intended for public authorities2 August 2030.
  • Marking of generative content already on the market before 2 August 20262 December 2026.
  • Regulatory sandboxes (Article 57 of the AI Act) → 2 August 2027. This is the deadline by which Member States must establish at least one: it concerns them, not you, and nothing prevents them starting earlier. The Digital Omnibus also provides for an EU-level sandbox run by the AI Office, with priority access for small and medium-sized enterprises.
Unchanged
  • Prohibitions under Article 5 of the AI Act — applicable since 2 February 2025
  • Obligations on general-purpose AI models — since 2 August 2025
  • Transparency obligations under Article 50 of the AI Act — since 2 August 2026
  • National penalty regimes — since 2 August 2026

The full timeline is in the chronology on the home page.

One clarification about 2 December 2026, because that date tends to be read only as a postponement falling due. From that day two new prohibitions also arrive, which did not exist before: nudification applications, which generate nude images of real people without their consent, and systems that produce child sexual abuse material. The Digital Omnibus did not only push deadlines back: in places it tightened.

There is a practical reason not to read the delay as a pause. Building the inventory of systems, renegotiating supplier contracts and training staff usually takes twelve to eighteen months. A company that starts now works at ordinary cost; a company that starts in the autumn of 2027 works in emergency mode, and emergencies have a different price list.

If you only use AI, the obligations are already yours.

Almost no small or medium-sized company develops artificial intelligence systems. The vast majority use them, and that is what the regulation calls a deployer: a party using someone else's system in the course of its own professional activity. It is a lighter role than the provider's. It is not an empty one.

Article 50 of Regulation (EU) 2024/1689 — the AI Act — distributes four transparency obligations between provider and deployer, and the distinction matters, because it settles who pays if something is missing.

Two obligations are directly yours.

Biometrics and emotion recognition. A company using an emotion recognition system or a biometric categorisation system must inform the people exposed to it, and must do so at the latest at the time of first exposure. This covers biometric access gates, security systems that classify people entering a site, and tools that measure operator attention. The processing of the data remains subject to the GDPR in parallel.

Deepfakes and texts on matters of public interest. Whoever generates or manipulates images, audio or video amounting to a deepfake must disclose it. The same applies to AI-generated text published to inform the public on matters of general interest, unless the content has undergone human review and someone takes editorial responsibility for it.

Two fall on the provider, but land on you all the same.

Disclosure of the interaction. A system intended to interact with people must be designed so that whoever talks to it knows they are talking to a machine. The obligation is the provider's, but the chatbot is on your website and the switchboard answers in your name: if the notice is missing, you are the first to take the reputational damage, and the authority's request for clarification arrives at your address. This is a matter for the contract, not for good faith.

Marking of content. Text, images, audio and video generated or manipulated by artificial intelligence must be marked in a machine-readable format. Here too the obligation belongs to whoever supplies the system. But if you put your own brand on that system, the obligation becomes entirely yours: that is the point of the next section.

A note on AI literacy.

The Digital Omnibus rewrote Article 4 of the AI Act, and it is worth being precise about what changed: the obligation has not been abolished, its intensity has been lowered. Previously a company had to ensure an adequate level of AI literacy among its staff; today it must take measures to support the development of that literacy, proportionate to the risks of the systems used and to the characteristics of the organisation, without having to guarantee a given level for each individual. Those measures need not be a training course: operating instructions, internal policies, exercises and periodic updates all count. The relief, however, concerns the formal requirement, not the consequences: if an incident arises from an employee's improper use of a tool, the absence of instructions and of documented training is the first thing to be raised against the company, and not only under the AI Act.

You can become a provider without noticing.

Article 25 of the AI Act contains the provision that, in a year of conversations, I have seen surprise company leadership most often. A deploying company automatically takes on the role and the responsibilities of the provider if it does one of these three things:

  1. It puts its own brand or name on an artificial intelligence system already on the market.
  2. It substantially modifies the intended purpose of a system. The example I use most often: computer vision software bought for quality control on the line, redirected to measuring the productivity of the operators. Same software, different purpose, different legal role.
  3. It makes substantial modifications to a high-risk system.

In all three cases it is no longer possible to point back at the manufacturer. Documentary conformity, risk assessment and technical control of the system become a burden to be demonstrated in your own name, with documentation the company generally does not have and is not equipped to produce.

The most frequent case is the first, and it is almost always unintentional: a conversational assistant bought from a third party, renamed after the company and put on the website. Nobody decided to change legal role. It happened anyway.

Who supervises, and what a mistake costs.

The penalties under Article 99 of the AI Act are organised in three bands.

Penalty bands under Article 99 of the AI Act
Infringement Maximum
Prohibited practices (Article 5 of the AI Act) EUR 35 million or 7% of total worldwide annual turnover
Obligations of providers and deployers, including the transparency duties of Article 50 EUR 15 million or 3%
False or misleading information supplied to the authorities EUR 7.5 million or 1%

The higher of the two figures applies. For small and medium-sized enterprises and for start-ups the regulation provides the opposite criterion: the lower figure applies.

One clarification usually missing from alarmist summaries. The EUR 35 million concerns prohibited practices — behavioural manipulation, social scoring, untargeted scraping of facial images — which an ordinary business does not engage in. The band that actually concerns a deployer is the second. It is still a serious figure, but it is a different figure, and confusing the two does not help anyone decide.

Who supervises, in Italy.

Italian Law no. 132 of 23 September 2025 allocated competences among several authorities: AgID, the Agency for Digital Italy, is the notifying authority for conformity assessment bodies; the National Cybersecurity Agency is the market surveillance authority; the Italian data protection authority and the sectoral authorities — the Bank of Italy, Consob, IVASS — keep their own competences in their respective fields.

The next Italian deadline is close: on 10 October 2026 the deadline expires for the implementing decrees under Law 132/2025, which will define how supervision works in practice.

The involvement of the cybersecurity agency has a consequence worth recording straight away: controls on artificial intelligence will intertwine with those on network security, the NIS2 Directive included. Treating the AI Act as an isolated file, or as an appendix to privacy, means preparing for the wrong inspection.

The GDPR and the AI Act are not the same file.

This is the confusion I see most often, and it produces two opposite mistakes: those who think they are covered because they did the GDPR, and those who redo from scratch work they already had.

The two regulations protect different people. The GDPR protects the person whose data are processed, and its assessment instrument is the DPIA (Article 35 of Regulation (EU) 2016/679). The AI Act protects the person affected by a machine's decision — even where their data are not in play — and its instrument is the FRIA, the fundamental rights impact assessment under Article 27 of the AI Act.

The FRIA does not apply to every high-risk system: it is required of bodies governed by public law, of private entities providing public services, and of those deploying the Annex III systems concerning creditworthiness and life and health insurance.

A practical consequence follows: the record of processing activities and the inventory of artificial intelligence systems are two distinct documents, related but not interchangeable. The first starts from the data, the second from the systems. Keeping only one leaves a side uncovered.

A recent case. By decision no. 487 of 3 July 2026 the Italian data protection authority fined Character Technologies Inc., the company operating Character.AI, EUR 158,000: an inadequate privacy notice, an impact assessment carried out late, and late designation of the representative in the Union. The company was also ordered to take corrective measures on age verification and on the confidentiality of minors' profiles.

The figure is worth looking at. One hundred and fifty-eight thousand euro is not a headline fine, and that is precisely the point: for a company that does not engage in prohibited practices, the real risk is not of the order of magnitude of the statutory maxima. It is of the order of magnitude of a compliance project done badly.

On the reforms under discussion. The amendments proposed to the GDPR in the so-called Digital Omnibus on data are still going through the European legislative process and are not law in force: proposed by the Commission in November 2025, they have been in inter-institutional negotiation since the spring of 2026. The artificial intelligence branch reached the end of the road; the data branch did not. They should not be used to justify decisions taken today.

What to do over the next twelve months.

Four steps, in the order in which they should be taken.

Build the inventory. Record every artificial intelligence tool in use, shadow AI included: translators, extensions installed in the CRM, generative assistants switched on by individual departments without going through IT. In my experience the real number is between two and five times what the company expects.

Qualify the role, system by system. For each tool, establish whether the company acts as a deployer or falls into one of the three cases under Article 25 of the AI Act that turn it into a provider.

Classify the risk. Identify which systems fall within the high-risk category of Annex III to the AI Act, and tie them to the 2 December 2027 deadline with a plan that starts today.

Set up governance and contracts. An internal policy on the use of these tools, training plans proportionate to the risk and — the point most often neglected — renegotiation of supplier contracts, to obtain access to technical documentation and cooperation in the event of an inspection. A contract signed before 2024 almost certainly contains none of this.

Six questions to ask around a table.

Before looking for a consultant, the leadership should try to answer these six questions. They measure organisational exposure, not legal exposure.

  1. How many artificial intelligence systems are in use in the company today, including those embedded in software bought for something else?
  2. For each of them, are we a deployer or a provider?
  3. Are the people who interact with our automated systems — customers, candidates, employees — told that they are talking to a machine?
  4. Is there a named person responsible for the compliance of these systems?
  5. Do our supplier contracts guarantee us access to technical documentation and their assistance in the event of an inspection?
  6. Have the people using these tools received instructions for use, clear limits and documented training?

If more than two answers are missing, the immediate priority is not a legal one: it is organisational.

Ugo Bruno Gambardella
Ugo Bruno Gambardella

Avvocato (Italian lawyer). He works on AI Act and AI governance, data protection and the DPO function, Legislative Decree 231/2001 compliance models and internal controls. Track record.

Sources

Legal position as at 22 August 2026, verified against the primary sources listed above. This note is published for general information and does not constitute advice on a specific case.

All notes The AI Act timeline