DEV Community

Cover image for AI Act Italia: Imprese, 2 Agosto è Vicino!
Gian Paolo
Gian Paolo

Posted on • Originally published at gp69-ai.vercel.app

AI Act Italia: Imprese, 2 Agosto è Vicino!

Il risveglio brusco dell'IA: Ehi, la data è qui!

The summer lull is officially over. For Italian businesses, August 2nd wasn't just another day on the calendar; it was the day the theoretical became tangible. It was the starting pistol for a two-year marathon that many companies haven't even started training for. The AI Act, the European Union's comprehensive regulation on artificial intelligence, has now entered into force, and its cascading deadlines are no longer a distant concern.

This is the rude awakening. The casual experimentation with AI tools—the marketing team using a generative model for ad copy, the HR department testing an algorithm to screen CVs—is now subject to a legal framework. While the full application of the law is 24 months away, the clock is ticking on several crucial milestones that arrive much sooner.

Think of it as a series of gates, each closing at a specific time. The first gate, concerning AI systems deemed to pose an "unacceptable risk," slams shut in just six months. These systems, such as those used for social scoring by public authorities or manipulative techniques, will be outright banned. Most businesses won't be developing these, but they must ensure they aren't inadvertently using them through third-party vendors.

The next, more relevant gate for a vast number of companies closes in 12 months. This one concerns generative AI. Any business using models to create text, images, video, or audio that is made public will have a clear obligation: transparency. You will have to ensure the output is clearly marked as artificially generated. That chatbot on your website? That AI-generated image in your social media campaign? They will need a label. The era of passing off machine-made content as human is officially on a countdown.

The biggest deadline looms on the horizon: August 2, 2026. By this date, all other obligations, especially for high-risk AI systems, must be met. According to reporting on the new rules, this includes complex requirements like conformity assessments and CE marking, similar to what's required for physical products like toys or electronics [Entro 2 agosto 2026: Marcatura e Codice AI generativa - Actainfo].

What does this mean for a typical Italian enterprise today? It means the work must start now. The first step is no longer optional: conduct a full inventory of all AI systems in use. Where is AI operating in your business? Is it a high-risk application, like in recruitment or credit scoring? Or is it a limited-risk tool, like a generative AI model?

For years, the adoption of AI has been a mad dash for advantage. Now, it's a calculated race for compliance. The two-year runway is not a grace period; it's an implementation period. The rude awakening of August 2nd isn't about a penalty or a fine. It’s the jarring realization that the future of AI regulation has arrived, and the time to prepare for it was yesterday.

Non solo "alto rischio": Le sfumature dell'AI Act che toccano tutti

While the headlines have understandably focused on the strict regulations for "high-risk" AI systems, many Italian businesses might be breathing a sigh of relief, thinking the AI Act doesn't concern them. This would be a mistake. A crucial, and much broader, part of the regulation is designed to impact nearly every company that uses modern digital tools: the rules on transparency.

These obligations are not about systems that make life-or-death decisions. They are about the everyday AI that is already woven into marketing, customer service, and content creation. The core principle is simple: people have the right to know when they are interacting with an AI or viewing AI-generated content.

Consider a typical e-commerce business. It might use a generative AI tool to create attractive images for its social media feed or to write compelling product descriptions. Under the AI Act, this activity now comes with new responsibilities. Any AI-generated audio, image, video, or text content—often called deepfakes, but the term applies more broadly—must be clearly labeled as artificially created or manipulated. That friendly chatbot on the company website? It must explicitly inform users they are not speaking with a human.

This isn't a minor suggestion; it's a fundamental shift. The era of seamlessly blending AI-generated content with human-created material without disclosure is ending. For businesses, this means processes must change. A marketing team that uses an AI to generate a blog post will need to ensure it's labeled. A customer service department deploying a new virtual assistant must build a clear disclaimer into its very first interaction.

These rules address the rise of General-Purpose AI (GPAI) models, the engines behind tools like ChatGPT and Midjourney. While the developers of these powerful models have their own significant obligations, the companies that deploy them are also on the hook for transparency with the end-user. As outlined in a recent analysis, many tech giants are already aligning with a voluntary Code of Practice for Generative AI in anticipation of the Act's full force.

The clock is ticking. The deadline for these transparency and labeling requirements to become fully enforceable is August 2, 2026. This may seem distant, but it requires businesses to begin auditing their tools and workflows now. Identifying every touchpoint where AI interacts with a customer or generates public content is the first step. The second is building the technical and procedural mechanisms for clear and consistent labeling.

Ultimately, these rules are about maintaining trust in the digital ecosystem. The AI Act ensures that as artificial intelligence becomes more capable and widespread, its presence is acknowledged, not hidden. For any business, big or small, transparency is no longer just good practice—it's the law.

Dal codice al caso d'uso: Cosa cambia davvero per la tua azienda?

The most significant change coming with the AI Act isn't buried in lines of code; it's found in your business plan. With the two-year adaptation period officially kicking off on August 2nd, the focus for companies is shifting dramatically from the technology itself to its specific application. The law isn't asking "What algorithm are you using?" but rather, "What are you using it for?"

This is the core of the new risk-based approach. An AI model is not inherently "high-risk" or "low-risk." Its classification, and the mountain of compliance obligations that comes with it, depends entirely on its deployment context—the use case.

Consider a practical example: your company's hiring process. You decide to implement an AI tool to help manage the flood of applications.

If you use the AI simply to scan CVs for specific keywords (like "Python" or "project management") and then group them for a human recruiter to review, the system likely falls into a minimal or limited risk category. Your main obligation would be transparency—letting candidates know an AI is involved in the process.

But what if you use that same underlying technology to automatically score, rank, and shortlist candidates, or even to reject them without human oversight? The moment the AI's output directly influences someone's access to employment, the system is classified as high-risk. This triggers a host of stringent requirements: rigorous testing, detailed documentation, human oversight mechanisms, and robust data governance. The technology didn't change, but its application did, and with it, your legal responsibility.

This distinction is now paramount for every business leader. As Sky TG24 reports, all operators have two years to adapt to these new European rules, and understanding your specific use cases is the first and most critical step in that journey. You can no longer simply purchase an "AI solution" and hand it off to the IT department. Compliance is now a strategic function that must involve legal, operations, and management from the very beginning.

This applies even to general-purpose AI, like the large language models powering chatbots and content creation tools. If your marketing team uses a generative AI to create a blog post, the rules are straightforward: the output must be clearly labeled as artificially generated. If your customer service deploys a chatbot, you must inform users they are interacting with a machine. The principle remains the same: context and application determine the rules of engagement. The era of treating AI as a black box is over. For your business, the future of compliance begins with a simple question about how you intend to use it.

Marcatura, dati, trasparenza: Le nuove parole chiave della conformità

For companies in Italy navigating the new landscape of artificial intelligence, a new vocabulary is taking hold. The words are simple—marking, data, and transparency—but their implications are profound. These are no longer abstract concepts for ethics papers; they are the concrete pillars of compliance under the EU AI Act, which has now officially begun its phased rollout.

The most visible change will be in how AI systems and their outputs are presented to the world. The era of unlabeled, opaque AI-generated content is officially ending. For systems classified as "high-risk," such as those used in critical infrastructure or medical devices, a mandatory CE marking will be required, similar to the one seen on many physical products. This mark will certify that the system has undergone a rigorous conformity assessment before being placed on the market.

For generative AI, the rules are just as clear. Any text, image, or audio created by an AI must be clearly labeled as artificially generated. This means the marketing images your company creates with a text-to-image model or the product descriptions written by a large language model must be identifiable as such. The goal is to prevent deception and ensure users know when they are interacting with synthetic media. According to one analysis, providers of general-purpose AI models have a clear deadline to meet these obligations, including drawing up technical documentation and complying with EU copyright law, by August 2, 2026.

Beneath this surface-level marking lies a deeper requirement concerning data. Providers of foundational models, the engines behind many generative AI tools, now have a significant homework assignment: they must compile and make publicly available a detailed summary of the data used to train their models. This strikes at the heart of the "black box" problem, forcing a new level of accountability regarding copyrighted material and potential biases baked into the training data. For any business using these tools, understanding the provenance of the model's training data will become a key part of their own due diligence.

All these requirements funnel into the central principle of transparency. It’s about more than just labels. The Act mandates that when people interact with an AI system, such as a customer service chatbot, they must be informed that they are not communicating with a human. Consider a simple e-commerce site. If a visitor asks a question in the chat window, a disclaimer like "You are speaking with an AI assistant" is no longer just good practice; it is a legal necessity. As highlighted by observers, this new framework fundamentally alters the responsibilities for anyone developing, deploying, or simply using artificial intelligence in their business operations.

While the full slate of rules will come into effect over the next 24 months, the transition period has begun. For Italian businesses, the time to audit their AI usage, review contracts with technology providers, and update user-facing interfaces is now. These new keywords aren't just about avoiding fines; they represent a new social contract for AI, and compliance is the price of admission.

Oltre la scadenza: Investire oggi per non pagare domani

While the August 2nd date looms large on the calendar, it marks a starting line, not a finish line. For Italian companies, this is the beginning of a phased implementation, with different obligations activating over the next 24 months. The bans on prohibited AI practices, such as social scoring by public authorities, will take effect first, in about six months. Other, more complex requirements for high-risk systems will follow. The full scope of the regulation, including crucial rules for generative AI, won't be fully enforceable until August 2026.

This staggered timeline presents a dangerous illusion of having plenty of time. Treating compliance as a distant problem to be solved in 2026 is a significant strategic error. The real work of adapting to the AI Act cannot be done in a last-minute rush. It requires a fundamental shift in how organizations develop, procure, and deploy artificial intelligence systems. Waiting means accumulating technical and regulatory debt that will be far more expensive to pay down the line.

The alternative is to act now. Companies using or developing generative AI, for example, can already align with the voluntary Codes of Practice. This isn't just about ticking a box; it's about building trust and future-proofing operations. As detailed in a recent analysis, these codes offer a clear pathway to demonstrate due diligence and responsible innovation ahead of legal mandates AI Generativa e Code of Practice europeo: cosa cambia per le imprese - Namirial Corporate.

Proactive measures go beyond codes of conduct. The immediate priority for any business is to conduct a thorough inventory of all AI systems in use. Where did this model come from? What data was it trained on? What is its intended purpose? This internal audit is the essential first step to classifying systems according to the Act's risk-based tiers. A chatbot for customer service scheduling carries a different weight than an algorithm used in hiring or credit scoring. Understanding this distinction is the core of the regulation.

Ultimately, this isn't just about avoiding hefty fines. It’s about market positioning. Companies that integrate transparency, accountability, and fairness into their AI lifecycle from the outset will build more robust products and earn greater consumer trust. Those who wait will be forced to retrofit compliance onto opaque, potentially biased systems—a process that is not only costly but sometimes impossible. The choice, then, is between architecting for the future or patching up the past.

Sources

Top comments (0)