AI Act 2026: The Complete Compliance Guide for Italian Companies

Deadlines, transparency obligations, the fines under Article 99 and a roadmap of 7 actions to be ready by 2 August 2026, with the AI Omnibus and Law 132/2025 (Italy’s national AI law) included.

Download the guide as a PDF

The full version, to save and read at your own pace or pass on to your team.

Updated June 202615 min read

The AI Act in 2026, in Brief

On 2 August 2026 the AI Act, Regulation (EU) 2024/1689, becomes fully applicable across the European Union. The transparency obligations of Article 50 take effect, while the prohibited practices and AI literacy have been in force since 2 February 2025. Fines reach up to 35 million euros or 7% of worldwide turnover. This guide explains what to do, by when and in what order of priority.

What the AI Act Is: Regulation (EU) 2024/1689 in Brief

The AI Act is the European regulation on artificial intelligence, published in the Official Journal of the European Union on 12 July 2024 and in force since 1 August 2024, as the European Commission reports. Because it is a regulation, it applies directly in Italy with no need for national transposition. It covers anyone who develops, distributes or uses AI systems on the European market.

The point many CEOs underestimate is exactly this: the AI Act also applies to companies that merely use artificial intelligence. If your company runs a chatbot for customer care, a CV screening system or a predictive analytics tool, you are a "deployer" and you have specific obligations. The regulation takes a risk-based approach: the more a system can affect people’s rights and safety, the stricter the requirements.

In practice the regulation distinguishes between prohibited practices (Article 5), high-risk AI systems (with the use cases listed in the annexes, from biometrics to employment, from education to critical infrastructure, all the way to systems embedded in regulated products such as medical devices, machinery and vehicles), systems subject to transparency obligations (Article 50) and general-purpose AI models, the so-called GPAI such as large language models.

For an Italian company the picture is completed by Law no. 132/2025, the national artificial intelligence law we come to further on, and by the penalty regime of Article 99, which deserves a chapter of its own.

The AI Act Timeline: Every Deadline From 2025 to 2028

The AI Act applies in stages. The prohibited practices and the AI literacy obligation took effect on 2 February 2025, the rules on GPAI models on 2 August 2025, and general application arrives on 2 August 2026. For high-risk AI systems the deadlines were revised by the proposed AI Omnibus, with a horizon stretching to 2028.

Here is the full calendar, reconstructed from European Commission sources and the analysis by Vega Engineering. The correct reading is simple: most of the obligations that affect an Italian SME are already in force or take effect in 2026. Anyone waiting for the "full operation" of 2 August 2026 to start moving is already late on two fronts, prohibited practices and training, both active since February 2025.

DateWhat takes effect
2 February 2025Ban on prohibited AI practices (Art. 5) and AI literacy obligation (Art. 4)
2 August 2025Rules on GPAI models, institutional governance, penalty regime
2 August 2026General application of the regulation and transparency obligations (Art. 50)
2 August 2027End of the transition period for AI models already on the market before 2 August 2025
2 August 2028High-risk AI systems embedded in regulated products (Annex I: medical devices, machinery, vehicles), following the AI Omnibus extension

What Changes on 2 August 2026 for Italian Companies

2 August 2026 marks the general application of Regulation (EU) 2024/1689. From that date the regulatory framework is fully operational and the transparency obligations of Article 50 become applicable, which closely affect anyone using chatbots, AI-generated content or systems that interact with people. Here is what that means in practice for a mid-sized Italian company.

First, transparency. Article 50 requires you to inform people when they are interacting with an artificial intelligence system and when content has been artificially generated or manipulated. If your website has a virtual assistant, the user has to know they are talking to a machine. If you publish synthetic content, adequate labeling is needed.

Second, full operation of the regulation means that from that moment the entire framework, including the powers of the supervisory authorities, is active. In Italy, as we will see, supervision falls to ACN (Italy’s National Cybersecurity Agency), with inspection and sanctioning powers.

Third, the deadlines that have already passed remain fully valid. The prohibitions in Article 5 have been in force since 2 February 2025, together with the AI literacy obligation in Article 4: staff who use AI systems must have an adequate level of literacy in artificial intelligence. This is a training obligation that many Italian companies are still ignoring.

One important caveat, also flagged by Agenda Digitale in its analysis of the Digital Omnibus: the European simplification proposal does not touch the 2 August 2026 date for transparency, prohibited practices and AI literacy. That deadline stays fully operational. The postponements concern only high-risk AI systems, as we explain in the section on the AI Omnibus.

AI Act Penalties: Article 99 and What Your Company Risks

Article 99 of Regulation (EU) 2024/1689 sets three tiers of penalties. They run from 7.5 million euros for false information supplied to the authorities up to 35 million euros, or 7% of worldwide annual turnover, for prohibited practices. For SMEs and startups a proportionality principle applies and reduces the exposure.

Here is the detail, as reconstructed from the analyses by Vega Engineering and DAgostino Lex:

ViolationMaximum penalty
Prohibited AI practices (Art. 5)35 million euros or 7% of worldwide annual turnover, whichever is higher
Other obligations under the regulation15 million euros or 3% of worldwide annual turnover, whichever is higher
False or misleading information supplied to the authorities7.5 million euros or 1% of worldwide annual turnover, whichever is higher

Penalties and SMEs: How the Proportionality Principle Works

There is one element every SME founder needs to know: for SMEs and startups the lower of the fixed amount and the percentage of turnover applies. It is the proportionality principle set out in the regulation. For a company with a few million in turnover the maximum exposure is therefore calculated on the percentage, with figures far smaller than the absolute ceilings.

Read this mitigation the right way, though. Even 3% of annual turnover, added to the reputational damage and to the shutdown of a system on which the company has built operating processes, is a risk no board can ignore. Compliance pays off on purely economic grounds too.

AI Omnibus: What Actually Slips and What Stays Confirmed

The AI Omnibus is the simplification proposal adopted by the European Commission on 17 November 2025, on which the European Parliament adopted its negotiating position during the second plenary session of March 2026 and on which a political agreement was reached on 7 May 2026. It pushes back only the deadlines for high-risk AI systems.

The new dates set out in the agreement, according to the reconstructions by The Integrity Times and Agenda Digitale, are two:

  • Annex III (biometrics, education, employment, critical infrastructure and other high-risk use cases): new deadline of 2 December 2027
  • Annex I (AI systems embedded in regulated products such as medical devices, machinery and vehicles): new deadline of 2 August 2028

The Two Clarifications Not to Miss on the AI Omnibus

The first: at the time of our checks the final text of the amending regulation did not yet appear to have been formally published in the Official Journal. The political agreement is there; the formal publication needs watching.

The second, and more important still: the 2 August 2026 date stays fully operational for the transparency obligations of Article 50, for the prohibited practices and for AI literacy. Reading the AI Omnibus as a general postponement of the AI Act is a mistake that can prove expensive. Only the obligations on high-risk AI systems slip, and everything else runs on the original calendar.

Why did the Commission propose the extension? One of the official reasons is the delay in harmonized technical standards. The standards drawn up by CEN-CENELEC JTC21, which should guide the implementation of the high-risk requirements, are behind schedule: the first, prEN 18286 on AI-related quality management systems, closed its enquiry stage only in January 2026 and the full package is expected in the fourth quarter of 2026, as reported by SendApp and Agenda Digitale. Without harmonized standards, demonstrating conformity for high-risk AI systems is objectively harder, and Europe has taken note.

Italy’s AI Law: What Law 132/2025 Provides

Italy passed Law no. 132 of 23 September 2025, in force since 10 October 2025. According to the Department for Digital Transformation it is the first national legal framework in Europe aligned with the AI Act. It designates AgID (the Agency for Digital Italy) and ACN as the competent authorities and activates an investment program worth 1 billion euros.

The authorities in charge are settled. The law assigns the roles to two agencies: AgID handles promotion, notifications and the accreditation of conformity assessment bodies; ACN, for its part, has supervisory duties along with inspection and sanctioning powers. In plain terms: once the AI Act is fully applied, checks in Italy will run through ACN. Knowing who supervises helps you work out how to prepare.

There are resources for those who invest. The law activates an investment program worth 1 billion euros for startups and SMEs in artificial intelligence, cybersecurity and emerging technologies, as announced by the Department for Digital Transformation. For an SME weighing up AI projects, the message from the legislator is clear: compliance goes together with investment, and public instruments are there to support it.

The national and European frameworks have to be read together. Italy’s law moves inside the perimeter of the AI Act. A serious compliance strategy starts from the European regulation and then checks the national aspects, from the competent authorities to the funding opportunities, inside a structured AI governance framework.

Compliance Roadmap: The 7 Actions to Complete Before 2 August 2026

Preparing for the AI Act comes down to a handful of essential steps: map the AI systems in use, classify them by risk, remove prohibited practices, train staff, set up transparency, assign internal responsibilities and keep watch on how the rules evolve. Here is the sequence we recommend to the CEOs of Italian SMEs.

  • 1. Take stock of every AI system in the company. Including the "hidden" ones: the AI module in the CRM, the marketing automation tool, the plugin that writes sales emails. Without an inventory there is no compliance. It is step zero, and in our experience it is the one that holds the most surprises.
  • 2. Classify every system against the categories in the regulation. For each system, ask: does it fall among the prohibited practices in Article 5? Is it a high-risk use case from the annexes? Does it fall under the transparency obligations of Article 50? The classification determines which obligations and deadlines apply.
  • 3. Check right away that there are no prohibited practices. The ban has been in force since 2 February 2025 and carries the highest penalty tier under Article 99, up to 35 million euros or 7% of worldwide turnover. It is the absolute priority.
  • 4. Launch an AI literacy program. Article 4 requires an adequate level of AI literacy for staff who use these systems, and it too has been in force since 2 February 2025. Documented training, with attendance records, is also the proof of your diligence if you are inspected.
  • 5. Prepare the transparency measures for 2 August 2026. Chatbot notices, labeling of AI-generated content, clear communication to users. It is the central deadline of 2026 and the AI Omnibus does not move it.
  • 6. Assign internal roles and responsibilities. You need someone accountable for AI governance, even in an SME. Someone has to keep the inventory, keep an eye on suppliers and update the assessments when a system changes, starting from a written corporate AI policy. AI compliance is a continuous process, and a checklist filled in once is not enough.
  • 7. Track regulatory developments and technical standards. The formal publication of the AI Omnibus in the Official Journal, the CEN-CENELEC standards expected in the fourth quarter of 2026, the operational guidance from AgID and ACN. If your systems fall into the high-risk bracket, the new 2027 and 2028 deadlines give you valuable time: use it to adapt with method instead of putting things off.

Who Is Involved: Providers, Deployers and Suppliers

The AI Act separates roles along the value chain: whoever develops an AI system and places it on the market carries the broadest obligations, while whoever uses it in a professional setting still has responsibilities of their own, from transparency to staff training. No company that uses AI can consider itself outside the perimeter. One piece of advice that cuts across everything: document it all. Inventory, classifications, training delivered, notices published. In an inspection, being able to show a structured path is the difference between a manageable finding and a fine.

For an Italian SME the most frequent case is that of the deployer: the company buys or subscribes to AI tools developed by third parties. Obligations exist in this scenario too. The AI literacy duty in Article 4 concerns your staff, the transparency notices in Article 50 concern your customers, and the ban on the practices in Article 5 concerns the use you make of the tools, regardless of who developed them.

This also shifts attention onto supplier management. Before adopting a new AI tool it is worth asking for documentation on conformity, working out which risk category it falls into and setting adequate contractual clauses. A supplier who can answer AI Act questions precisely today is a supplier to build on. One who plays the topic down is a risk you are bringing in-house.

A final point on GPAI models: the rules on general-purpose AI models have been in force since 2 August 2025 and mainly concern the companies that develop them. For anyone integrating them into products or processes, the priority is to check how the model provider handles its own obligations and what that means for the chain of responsibility.

Want to Be Ready by 2 August 2026?

Yellow Tech works alongside Italian companies on the path to AI Act compliance: assessment of the systems in use, risk classification, AI literacy training for staff and continuous governance. Every project starts from an analysis of your situation and a tailored quote. Contact us for an initial consultation and we will define the roadmap to conformity together.

Frequently asked questions

It is Regulation (EU) 2024/1689 on artificial intelligence, published in the Official Journal of the EU on 12 July 2024 and in force since 1 August 2024, which governs the development and use of AI systems with a risk-based approach.

The regulation has been in force since 1 August 2024 and applies in stages. General application starts on 2 August 2026, while prohibited practices and AI literacy have been operational since 2 February 2025 and the rules on GPAI since 2 August 2025.

No. The AI Omnibus moves only the deadlines for high-risk AI systems, to 2 December 2027 for Annex III and 2 August 2028 for Annex I. Transparency, prohibited practices and AI literacy stay on the original calendar.

Yes. Anyone who uses AI systems in a professional setting is a deployer and has obligations of their own, starting with staff AI literacy (Art. 4) and the transparency obligations (Art. 50) applicable from 2 August 2026.

Article 99 provides for up to 35 million euros or 7% of worldwide turnover for prohibited practices, 15 million or 3% for other obligations, and 7.5 million or 1% for false information supplied to the authorities.

No. For SMEs and startups the lower of the fixed amount and the percentage of turnover applies, under the proportionality principle set out in the regulation.

Law 132/2025, in force since 10 October 2025, is the first national framework in Europe aligned with the AI Act. It designates AgID and ACN as the competent authorities and activates an investment program worth 1 billion euros for startups and SMEs.

Supervision, inspections and sanctioning powers fall to ACN, Italy’s National Cybersecurity Agency. AgID handles promotion, notifications and the accreditation of conformity assessment bodies.

Article 4 of the regulation requires staff who use AI systems to have an adequate level of literacy in artificial intelligence. The obligation has been in force since 2 February 2025.

They are the use cases listed in the annexes to the regulation: Annex III covers areas such as biometrics, education, employment and critical infrastructure, while Annex I covers systems embedded in regulated products such as medical devices, machinery and vehicles.

They are general-purpose AI models, such as large language models. The rules covering them have applied since 2 August 2025, with a transition period until 2 August 2027 for models already on the market before 2 August 2025.

The harmonized CEN-CENELEC standards will guide how conformity is demonstrated for high-risk AI systems. The first, prEN 18286, closed its enquiry stage in January 2026 and the full package is expected in the fourth quarter of 2026. The delay is among the official reasons for the extension proposed by the Commission.

From an inventory of the AI systems in use and their classification by risk. Priorities, obligations and applicable deadlines all follow from there.

Related guides

Want to see how AI can help your company?