The rules

AI Act: supervision and transparency obligations come into force on 2 August

Fines may be imposed for breaches. However, under the Digital Omnibus, the implementation of the requirements for high-risk systems has been postponed until 2027 and 2028

InfiniteFlow - stock.adobe.com

5' min read

Translated by AI
Versione italiana

5' min read

Translated by AI
Versione italiana

Next Sunday was supposed to be the date of the ‘big bang’ for European artificial intelligence. 2 August 2026 was, in fact, the date set for the general implementation of the AI Act (EU Regulation 2024/1689), with the introduction of obligations for high-risk systems.

The Digital Omnibus, which was finally approved by the EU Council on 29 June, has, however, revised the timetable: the rules for Annex III systems, used in sensitive areas such as staff recruitment, credit, education and biometrics, have been postponed to 2 December 2027; those for AI integrated into Annex I products, such as medical devices and machinery, to 2 August 2028. Publication in the Official Journal of the European Union is expected by July.

Loading...

But the postponement does not mean ‘business as usual’: from 2 August, in fact, the supervisory authorities will begin their work, the transparency requirements will come into force, and the European Commission will be able to fine large models.

And the first test for businesses and firms is a requirement that has been in force for a year and a half: training.

Training

Literacy checks may be introduced

Article 4 of the AI Act requires those who develop artificial intelligence systems (providers) and those who use them under their own authority (the deployers: in practice, anyone who uses artificial intelligence for professional purposes) to ensure that staff have an adequate level of of AI literacy commensurate with their role, the context of use and the risks involved.

The requirement has been in force since 2 February 2025, but so far there has been no supervisory authority: it is from 2 August 2026 that the national supervisory authorities will become operational and will be able to verify compliance.

The Digital Omnibus has now softened the wording: providers and deployers of AI systems are no longer required to adopt ‘measures to ensure’ a sufficient level of staff literacy, as provided for in the AI Act, but rather ‘measures aimed at supporting the development’ of staff literacy. And a breach of the new obligation will not result in a direct financial penalty.

The significance of this obligation, however, lies elsewhere: in the event of damage, a dispute or an inspection, documented training is the organisation’s primary evidence of due diligence. It is therefore necessary to have a traceable plan that maps out who uses which systems, provides for different modules based on role and risk, records activities and is updated over time.

Transparency

Obligation to declare chatbots and deepfakes

Loading...

The transparency obligations set out in Article 50 of the AI Act remain in force until 2 August 2026.

From next Sunday, providers of artificial intelligence systems that interact with people must make their artificial nature recognisable , so that users are aware that they are speaking to a chatbot, unless this is already obvious.

Furthermore, anyone using emotion recognition systems or biometric categorisation systems must inform the data subjects. And anyone using AI to create deepfakes or to generate texts published to inform the public on matters of public interest must declare this.

The only relaxation granted by the Digital Omnibus concerns watermarking, that is, the machine-readable marking of synthetic content generated by artificial intelligence: the obligation to adopt this measure has in fact been postponed by four months, to 2 December 2026, for systems already on the market.

The new ban on the use of artificial intelligence introduced by the Digital Omnibus will also come into force on 2 December 2026: systems that generate non-consensual intimate images (so-called nudifiers) or child sexual abuse material, unless adequate technical safeguards are in place.

Large models

Sanctioning powers come into effect

Providers of artificial intelligence modelsfor general purposes (GPIs, which form the basis of the main chatbots) must comply with documentation, transparency and copyright obligations from 2 August 2025.

What will change from 2 August 2026 is the ability to enforce these rights: the European Commission, through the AI Office, will be able to request information, assess models, impose corrective measures and fines of up to 15 million euros or 3 per cent of annual global turnover (35 million or 7 per cent for prohibited practices).

Enforcement of large models therefore follows Brussels’ guidelines; the rest of the oversight falls to the national authorities, and this is where the work in Italia begins.

Implementation

New offences and ‘231’ liabilities in Italia

The Italian framework is already in place: oversight lies with the National Cybersecurity Agency, with the Data Protection Authority, the Bank of Italy, Consob and Ivass responsible for their respective sectors. On 10 June, the Council of Ministers gave its preliminary approval to the two implementing decrees that complete the framework: the first concerns the powers of the authorities, sanctions, pilot schemes, training and employment; the second relates to the use of AI in policing and civil and criminal liability.

The direction is clear, and it lies within criminal law. The debut is being preparedof Article 437-bis of the Criminal Code, which punishes those who fail to implement security measures on high-risk AI systems, thereby creating a real danger to people. Furthermore, AI-related offences are being included in the catalogue of corporate liability, governed by Legislative Decree 231/2001, which exposes the company to its own penalties when the offence is committed in its interest: these include the new Article 437-bis and the unlawful deepfake (Article 612-quater of the Criminal Code), an offence from 2025 onwards. For companies, the message is clear: the 231 organisational models must be updated to address AI-related risks.

Consultancy

How to make the most of the time you’ve saved

For those who support businesses, the time saved through these postponements should be put to good use. First step: carry out a survey of the AI systems in use and classify them by risk. The Omnibus Directive confirms a key rule: if the supplier (the party placing the system on the market) considers that a system used in the areas covered by Annex III is not high-risk, because it has no significant effects on health, safety or rights, they must document their self-assessment and, when that regime comes into force at the end of 2027, register it in the European database of high-risk systems, which is largely public. Therefore, only the self-assessment of those invoking the exemption is recorded: a position on which the authorities can base their inspections. This same register serves to ensure compliance with transparency obligations and to prepare the documentation that the high-risk regime will require from customers.

The calendar

The combined provisions of the AI Act and the Digital Omnibus set out the new dates for the full entry into force of the artificial intelligence regulations.

 2 February 2025

The requirement for staff to undergo training on AI comes into force on this date.

2 August 2026

Supervisory authorities are now able to verify compliance with the staff training requirement. Transparency requirements apply regarding chatbots and deepfakes.

The Commission may impose fines of up to €15 million or 3 per cent of annual global turnover on suppliers of GPai models .

2 December 2026

The requirement for watermarking comes into force for systems already on the market. AI systems that generate non-consensual intimate images are now illegalnudifier) are now illegal.

2 December 2027

This is the new date from which the obligations relating to high-risk AI systems set out in Annex III to the AI Act (such as recruitment, credit, education and biometrics) will apply.

2 August 2028

These requirements also apply to AI systems integrated into Annex I products (such as medical devices and machinery).

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti