AI Act Compliance in Brief
AI Act compliance means bringing the artificial intelligence systems your company uses into line with Regulation (EU) 2024/1689, in force since 1 August 2024. In practice, you need to classify your AI systems by risk level, meet the deadlines set out in the regulation and prepare for transparency and governance obligations. This guide gives you an operational checklist in 10 steps and links to our complete guide to the AI Act 2026.
What the AI Act Is and Why It Concerns Your SME Too
The AI Act is Regulation (EU) 2024/1689, published in the Official Journal of the European Union on 12 July 2024 and in force since 1 August 2024, as Cybersecurity360 and Digitalic report. It is not a directive that each state has to transpose. It is a regulation directly applicable in all 27 EU countries, with extraterritorial reach: it also applies to those who sell AI products on the European market from abroad.
This point matters a great deal for Italian SMEs. There is no need to wait for a national transposition law. The European text already applies today, and its rules take effect in stages, on a precise calendar. According to Digitalic, the extraterritorial reach extends the obligations to non-EU providers that place AI systems on the European market too, so an Italian company that integrates tools from an American vendor still falls within the scope of the regulation.
Many business owners think the AI Act only concerns the big labs that build models. That is not the case. The regulation classifies systems by use and risk, not by the size of whoever develops them. An SME that uses CV-screening software, a credit-scoring system or a customer-facing chatbot falls within its scope. That is why the first question to ask is not "are we big enough to be involved", but "which AI systems do we use and which risk category do they fall into".
The Four Risk Categories in Brief
The AI Act works on a pyramid logic. The higher the risk to people's rights, the stricter the obligations.
- Unacceptable risk: prohibited practices (Art. 5), such as certain forms of manipulation or social scoring.
- High risk: systems listed in the annexes to the regulation, for example in employment, credit or healthcare.
- Limited risk: systems subject mainly to transparency obligations, such as chatbots and generated content.
- Minimal risk: most common applications, with no specific obligations.
The AI Act Deadlines, Updated for 2026
The AI Act deadlines follow the calendar set out in Article 113 of Regulation (EU) 2024/1689 and could be partly postponed by the Digital Omnibus package, currently going through final adoption. Some obligations have already been in force since 2025, while the heavier ones on high-risk systems would be pushed back to between late 2027 and 2028. The postponement does not cancel anything, it only moves the dates.
Here is the full picture, based on data from Vega Engineering and Cyberness, updated with the Digital Omnibus development reported by AI4Business and Tom's Hardware Italia.
| Date | Obligation |
|---|---|
| 2 February 2025 | Ban on unacceptable-risk AI systems (Art. 5), already in force |
| 2 August 2025 | Rules for GPAI models, general-purpose AI, already in force |
| 2 August 2026 | Transparency obligations, national governance and the first rules on high-risk systems |
| 2 December 2027 | Annex III high-risk systems, postponement proposed by the Digital Omnibus |
| 2 August 2028 | Annex I high-risk systems, products subject to sector regulations such as medical devices and vehicles |
What Has Changed With the Digital Omnibus
On 26 March 2026 the European Parliament approved its negotiating position on the Digital Omnibus package with 569 votes in favor, 45 against and 23 abstentions, as AI4Business and Tom's Hardware Italia document. At the time of writing a provisional agreement between Parliament and Council dates from 7 May 2026, but the legal-linguistic revision, the final formal approval and publication in the EU Official Journal are still pending: the new deadlines are therefore not yet formally binding. Once formally adopted, the measure would postpone the deadlines for high-risk systems: those under Annex III would move to 2 December 2027, those under Annex I to 2 August 2028.
The message for companies is clear. The postponement gives more time to get organized, but it does not remove the obligations. Anyone who reads the delay as a green light to put off every activity risks being unprepared when the deadlines arrive. Preparing serious technical documentation, a risk management system and internal governance takes months, not weeks. The time gained is better spent building than waiting.
AI Act Penalties: What You Really Risk
AI Act penalties are among the highest in European law and follow Articles 99 and 101 of Regulation (EU) 2024/1689. For prohibited practices they reach up to 35 million euros or 7% of worldwide annual turnover. For SMEs and startups, though, the regulation provides a safeguard: the lower of the fixed amount and the percentage applies.
Here is the detail of the maximum amounts, according to iSimply and INSIC.
| Type of violation | Maximum penalty |
|---|---|
| Prohibited practices (Art. 5) | €35,000,000 or 7% of worldwide annual turnover, whichever is higher |
| Other obligations, including high-risk systems | €15,000,000 or 3% of worldwide annual turnover |
| False information to the authorities | €7,500,000 or 1% of turnover |
| SMEs and startups | The lower of the fixed amount and the percentage applies |
The Proportionality Clause for SMEs
The SME clause matters. For a small company with modest turnover, 3% of turnover is almost always lower than 15 million euros, so the penalty is calculated on the percentage. It remains, all the same, a figure that can put a company in difficulty. The point is not just the theoretical maximum amount, but the principle: the AI Act sets out a real, enforceable penalty regime, run by national authorities. Treating it as a formality is a misjudgment.
AI Act Compliance Checklist: The 10 Operational Steps
The AI Act compliance checklist starts with mapping the AI systems used in the company and goes all the way to defining internal governance. The goal is to know what you use, which risk category it falls into, which obligations apply to you and who is responsible for keeping up with them over time. Here are the ten essential steps to follow in order.
- Inventory of AI systems. List every artificial intelligence tool used in the company, whether developed in-house or bought from external providers. Include chatbots, scoring systems, automation tools, predictive analytics software.
- Risk classification. For each system, determine the category: unacceptable, high, limited or minimal. This step decides every obligation that follows (see our guide to risk classification).
- Check on prohibitions. Make sure no system falls under the prohibited practices in Art. 5, already in force since 2 February 2025.
- Role definition. Establish whether you are the provider, deployer, importer or distributor of each system. Obligations change depending on the role.
- Technical documentation. For high-risk systems, prepare the required documentation: system description, training data, how it works, risk management measures.
- Transparency toward users. For limited-risk systems, such as chatbots, make sure users know they are interacting with an AI and that generated content is recognizable as such.
- Managing GPAI models. If you use general-purpose models, check compliance with the rules in force since 2 August 2025.
- Human oversight. Define how a person can step in and check high-risk systems, in line with the principles of the regulation.
- Internal governance. Appoint someone responsible, define monitoring and update procedures, train staff on the correct use of AI tools (see AI governance and compliance).
- Continuous monitoring. Compliance is not a one-off event. Plan periodic reviews, especially ahead of the 2026, 2027 and 2028 deadlines.
Common Mistakes to Avoid
In our day-to-day work with companies we see a few mistakes come up again and again. The first is thinking that tools bought from external providers are "the provider's problem". That is not the case: as a deployer you have obligations of your own, for example on transparency and oversight. The second mistake is ignoring tools adopted by individual departments without going through IT, so-called shadow AI. If marketing uses a content generator and HR a screening tool, both need to be mapped. The third mistake is putting everything off to 2027 because of the postponement. The time is there to build, and building well takes months.
Who Should Worry Most: Roles and Responsibilities
The AI Act assigns different obligations depending on the role a company plays in relation to the AI system. A company can be a provider, deployer, importer or distributor, and often holds more than one role at the same time. Understanding your own position is essential, because it determines which requirements actually fall on you and which fall on other players in the chain.
Let's look at a few practical examples for Italian SMEs.
- A company that develops its own AI system. It is the provider. It carries the broadest obligations on documentation, risk management and conformity.
- A company that uses third-party AI software. It is the deployer. It must ensure compliant use, human oversight and transparency toward the people affected.
- A company that imports an AI system from outside the EU. It is the importer. It must check that the non-EU provider has met its obligations, bearing in mind the extraterritorial reach of the regulation noted by Digitalic.
- A company that resells AI systems. It is the distributor. It must make sure the products it distributes are conformant.
How to Prepare for the 2026 Deadlines and Beyond
Preparing for the AI Act means starting the mapping now, even though the heavier deadlines are expected to be postponed to 2027 and 2028. The rules on prohibitions, GPAI models and transparency are already in force or will be in 2026. Building a solid base today reduces the work and the risk when the obligations on high-risk systems arrive.
A reasonable path for an SME unfolds across three time horizons.
Right away (by 2026). Complete the inventory of AI systems and the risk classification. Check that no tool falls under prohibited practices. Sort out the transparency of chatbots and generated content. Appoint a first internal owner.
Medium term (toward 2 December 2027). Prepare the technical documentation for Annex III high-risk systems. Put risk management and human oversight processes in place. Train staff.
Long term (toward 2 August 2028). Tackle the Annex I high-risk systems, the ones tied to products subject to sector regulations such as medical devices and vehicles. Integrate AI compliance with the other product-level requirements.
| Horizon | Priority | Goal |
|---|---|---|
| Right away | Inventory, classification, prohibitions, transparency | Know what you use and remove immediate risks |
| Medium term | Documentation and governance for Annex III | Be ready for 2 December 2027 |
| Long term | Annex I systems | Sector-product conformity by 2 August 2028 |
Talk to Us About Your AI Act Compliance
If you want to understand where your company stands with respect to the AI Act and which priorities to tackle first, the Yellow Tech team offers dedicated advice with a tailored quote. Book a first call to assess your situation together and build your compliance roadmap.
Frequently asked questions
It is Regulation (EU) 2024/1689, published in the EU Official Journal on 12 July 2024 and in force since 1 August 2024. It governs the development and use of artificial intelligence systems in the European Union, classifying them by risk level.
Yes. The regulation applies based on the use and risk of the AI systems, not on the size of the company. An SME that uses chatbots, scoring systems or screening tools falls within its scope.
The ban on unacceptable-risk practices has been in force since 2 February 2025 and the rules on GPAI models since 2 August 2025. The obligations on high-risk systems are expected to be postponed to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), under the Digital Omnibus text still going through final adoption.
It is the package on which the European Parliament approved its negotiating position on 26 March 2026 with 569 votes in favor, 45 against and 23 abstentions. It aims to postpone the deadlines for high-risk systems. At present there is a provisional Parliament-Council agreement dated 7 May 2026, but the legal-linguistic revision, the final formal approval and publication in the EU Official Journal are still pending: the new deadlines are therefore not yet formally binding. The postponement, once adopted, would push back the obligations without removing them.
Up to 35 million euros or 7% of worldwide annual turnover for prohibited practices, up to 15 million or 3% for other obligations, up to 7.5 million or 1% for false information given to the authorities, according to iSimply and INSIC.
The regulation provides that for SMEs and startups the lower of the fixed amount and the percentage of turnover applies. It remains, all the same, a real penalty regime not to be underestimated.
Yes. The regulation has extraterritorial reach, as Digitalic notes. It also applies to non-EU entities that place AI systems on the European market.
No. It is not a directive, it is a regulation directly applicable in all 27 EU countries. Its rules already apply without needing an Italian transposition law.
It is the role of whoever uses an AI system developed by someone else. Most Italian SMEs fall here. The deployer must ensure compliant use, human oversight and transparency toward the people affected.
They are general-purpose AI models. The rules covering them have been in force since 2 August 2025 and impose specific obligations on whoever develops and makes them available.
From the inventory of the AI systems used in the company and their classification by risk level. Every obligation that follows depends on this initial mapping.
No. Several obligations are already in force and preparing the documentation and governance takes months. The time gained should be used to build a solid base, not to delay.
Related guides
- AI Act 2026: The Complete Compliance Guide for Italian Companies
- AI Act: The Complete Guide for Italian Companies
- AI Risk Classification Under the AI Act
- AI Governance and Compliance: A Framework for Companies
- How to Write a Corporate AI Policy: Guide and Template
- AI Consulting in Italy: The Complete Guide for Businesses
Want to see how AI can help your company?
