AI Act: The Complete Guide for Italian Companies

Everything Italian companies need to know about Regulation (EU) 2024/1689: deadlines, obligations, penalties and a practical path to compliance.

Download the guide as a PDF

The full version, to save and read at your own pace or pass on to your team.

Updated July 202614 min read

What the AI Act Is (Regulation EU 2024/1689)

The AI Act (Regulation EU 2024/1689) is the world's first legislation to comprehensively regulate artificial intelligence. Approved by the European Parliament on 13 March 2024, it entered into force on 1 August 2024 and applies to all EU member states, including Italy, with no need for national transposition.

The regulation takes a risk-based approach: the more an AI system could endanger people's fundamental rights, the stricter the obligations for whoever develops and whoever uses it. The distinction between "provider" (whoever develops the system) and "deployer" (whoever uses it in a business context) is central: a company that integrates ChatGPT into its processes is a deployer and has specific obligations.

For Italian companies, the AI Act is a structural change. Anyone who today uses AI tools without a governance and compliance framework will have to comply by precise deadlines, on pain of penalties reaching up to 7% of global turnover. But the AI Act is not just a cost: it is the chance to structure AI use in a way that is effective, safe and competitive.

Application Timeline: The Key Deadlines

The AI Act does not come into force all at once. The European legislator has set a 36-month transition period, with staggered deadlines. For an Italian company, planning is essential: anyone who waits until the last moment risks being out of compliance with active penalties.

The first critical deadline was 2 February 2025, when the absolute ban on unacceptable-risk AI systems took effect (social scoring, subliminal manipulation, mass biometric surveillance). The second deadline is 2 August 2025, with the application of the obligations for general-purpose AI (GPAI) models, which directly concerns anyone running LLMs such as GPT, Claude or Gemini in production.

For companies using high-risk systems, the operational deadline is 2 December 2027, after the postponement decided with the Digital Omnibus package approved by the European Parliament on 16 June 2026: from that date the full Annex III obligations will take effect: technical documentation, conformity assessment, registration in the European database and post-market monitoring. Companies therefore have just over 4 months to complete compliance.

DeadlineWhat takes effectWho is affected
1 August 2024The regulation enters into forceAll EU operators
2 February 2025Ban on unacceptable-risk systemsAll providers and deployers
2 August 2025Obligations for GPAI and general-purpose AI modelsFoundation model providers and deployers
2 December 2027 (Digital Omnibus postponement)Full obligations for high-risk systems (Annex III)Providers and deployers of high-risk systems
2 August 2028 (Digital Omnibus postponement)Obligations for high-risk systems embedded in regulated productsAll economic operators

The Four Risk Levels of the AI Act

The core of the AI Act is classification by risk level. Every AI system must be assessed and placed in one of four categories. The category determines the regulatory obligations, the documentation required and the penalties in case of non-compliance.

The four levels are: unacceptable risk (prohibited), high risk (stringent obligations), limited risk (transparency obligations) and minimal risk (no specific obligations). Most AI systems used by Italian companies fall into the last two categories, but checking is essential: a customer service chatbot might be limited risk, but an AI system that evaluates job candidates is high risk.

For a detailed guide on how to classify your company's AI systems, see our guide to AI risk classification. Yellow Tech has already supported more than 500 organizations in analyzing and classifying their AI systems according to AI Act categories.

Obligations for Italian Companies

Obligations vary depending on the company's role (provider or deployer) and the risk level of the AI system used. For most Italian companies, which are deployers of AI systems developed by third parties (OpenAI, Anthropic, Google, Microsoft), the main obligations concern the responsible and documented use of these tools.

For high-risk systems, deployers must: use the system in line with the provider's instructions, ensure human oversight of decision-making processes, keep the logs generated by the system for at least 6 months, inform affected people that they are subject to an AI system, and carry out a fundamental rights impact assessment (FRIA) before deployment.

For limited-risk systems, the main obligation is transparency: users must know they are interacting with an AI system. This applies to chatbots, text-generation systems, deepfakes and synthetic content. A company that uses an AI chatbot on its website must clearly state that the answers are generated by artificial intelligence.

  • Drafting a corporate AI Policy - the document that sets the rules and limits for AI use in the company (full guide here)
  • AI system register - mapping of all AI systems in use, with risk classification
  • Staff training - Art. 4 of the AI Act requires AI literacy for every employee who uses AI systems
  • Impact assessment (FRIA) - mandatory for high-risk systems before deployment
  • Continuous monitoring - human oversight and periodic audits of production systems
  • Incident management - procedures for reporting serious malfunctions to the competent authorities

Penalties: What Non-Compliance Costs

The AI Act provides for a three-tier penalty system, calibrated on the severity of the violation and the company's turnover. The penalties are among the highest in the European regulatory landscape, comparable only to those of the GDPR.

The first tier concerns the use of prohibited AI systems (unacceptable risk): the penalty reaches up to 35 million euros or 7% of annual global turnover, whichever is higher. For a company with 50 million in turnover, that means a potential fine of 3.5 million euros.

The second tier concerns violations of the obligations for high-risk systems: up to 15 million euros or 3% of global turnover. The third tier, for false or incomplete information given to the authorities, provides for penalties of up to 7.5 million euros or 1% of turnover.

For SMEs and startups, the regulation provides for proportional and reduced penalties. But the reputational risk goes beyond the fine: an AI Act non-compliance investigation can damage business relationships and participation in public tenders. Prevention, through a structured AI governance framework, is the most effective investment.

How to Prepare: The Yellow Tech Path

AI Act compliance requires a structured approach that brings together legal, technical and organizational aspects. Yellow Tech has developed a 5-phase path specifically for Italian companies, based on experience gained with more than 500 organizations and 300+ AI agents in production.

Phase 1 (Assessment) consists of mapping every AI system in use, from the Microsoft Copilot suite to custom chatbots and production AI agents. Each system is classified by risk level according to AI Act criteria. We have catalogued hundreds of AI systems in client companies over the past year.

Phase 2 (Gap Analysis) compares the current state against the regulatory obligations. For each high-risk system we assess: technical documentation, human oversight procedures, log management, user transparency and impact assessment. The result is a prioritized roadmap with effort and timeline for each intervention.

Phase 3 (Implementation) includes drafting the corporate AI Policy, configuring monitoring systems, preparing compliance documentation and integrating with existing GDPR processes.

Phase 4 (Training) is legally mandatory: Art. 4 of the AI Act requires every employee working with AI systems to have an adequate level of AI literacy. We have trained more than 20,000 people in Italy on this topic, with programs ranging from 2-hour executive sessions to complete AI Upskilling paths.

Phase 5 (Continuous monitoring) includes periodic audits, documentation updates and reviews of the risk classification. The AI Act is not a one-off requirement: it needs a governance system that is alive and kept up to date. To start your compliance path, contact us for a free assessment.

Frequently asked questions

The AI Act has already been in force since 1 August 2024. The bans on unacceptable-risk systems apply from 2 February 2025. Obligations for GPAI models from 2 August 2025. The full obligations for high-risk systems take effect from 2 December 2027, after the postponement decided with the Digital Omnibus package. Yellow Tech has already supported more than 500 Italian organizations with regulatory compliance, with a team of 30+ dedicated specialists.

Penalties reach up to 35 million euros or 7% of global turnover for using prohibited systems, up to 15 million or 3% for violations of the high-risk obligations, and up to 7.5 million or 1% for false information. Proportional reductions apply for SMEs. Yellow Tech offers compliance paths that start from the assessment and cover every phase through to continuous monitoring.

Yes. If your company uses ChatGPT, Microsoft Copilot, Claude, Gemini or any other AI system in a work setting, the AI Act applies. The company is classified as a "deployer" and has specific obligations, including staff AI literacy (Art. 4) and transparency toward users. Yellow Tech has trained more than 20,000 people in 500+ organizations on the compliant use of AI tools.

The classification is based on Annex III of the AI Act, which lists the categories of high-risk systems (biometrics, critical infrastructure, education, employment, credit, justice, migration). Yellow Tech uses a proprietary framework that maps every corporate AI system to the Annex III criteria and produces a classified register, with 300+ systems already analyzed for its clients.

The cost depends on the complexity of the organization and the number of AI systems in use, which is why we always start from a tailored quote. A typical path includes an initial assessment with risk classification, followed by a complete compliance path (gap analysis, AI policy, training, monitoring). The average CSAT among Yellow Tech clients is 98%.

Related guides

Want to see how AI can help your company?