AI Act: The Delay Everyone Is Talking About Isn’t the One That Affects You
Over the past few weeks, a very convenient version of events has been circulating: the AI Act has been delayed, so there’s plenty of time to prepare.
It’s an interpretation that has the advantage of being simple—and the disadvantage of being wrong where it matters most.
On August 2, 2026, the European Artificial Intelligence Act entered its general application phase.
Some obligations have indeed been postponed.
Others—the ones that affect most businesses—are already in force, together with the supervisory authorities and the enforcement regime behind them.
So it’s worth understanding exactly where the line is drawn.
What Is the AI Act, Technically?
The AI Act is Regulation (EU) 2024/1689.
The word regulation is important because it means the law applies directly in every EU Member State without requiring national implementing legislation.
There is no separate Italian version of the AI Act, and there never will be.
It is the world’s first comprehensive legal framework dedicated specifically to artificial intelligence.
Its logic often confuses people approaching it for the first time.
The regulation doesn’t primarily regulate technology.
It regulates risk.
It doesn’t ask which model you use.
It asks what you do with it.
There are four levels of risk.
At the top are prohibited AI practices, including social scoring, manipulative techniques, and emotion recognition in the workplace. These have been banned since February 2, 2025, with no transition period.
Next come high-risk AI systems, including those used for:
- recruitment;
- credit scoring;
- biometrics;
- education;
- justice;
- critical infrastructure;
- medical devices.
Then comes limited risk, where the obligation is primarily informational: disclosure.
Finally, there is minimal risk, where no specific obligations apply.
There is, however, another distinction that matters even more in practice.
Provider and Deployer Are Not the Same Thing
The AI Act distinguishes between the company that develops an AI system and the organization that uses it.
The developer is the provider.
The user is the deployer.
This distinction is often underestimated.
Deployers have their own legal obligations.
You don’t need to build AI models to fall under the AI Act.
You simply need to use them.
A recruitment agency screening CVs with third-party software is a deployer.
An e-commerce business using an AI chatbot is a deployer.
A marketing agency producing AI-generated content is a deployer.
If your company concluded, “We don’t build AI,” it was probably answering the wrong question.
The Timeline After the Digital Omnibus
The timeline changed in mid-2026, creating much of today’s confusion.
The European Commission proposed the Digital Omnibus on November 19, 2025.
The European Parliament adopted it on June 16, 2026.
The Council gave final approval on June 29.
The legislation was signed on July 8.
The stated reason was practical:
the harmonized standards and conformity tools for high-risk AI systems simply weren’t ready.
This is how the timeline now looks.
- Prohibited AI practices and AI literacy obligations: February 2, 2025
- Obligations for general-purpose AI models: August 2, 2025
- General application, transparency obligations, supervisory authorities, and enforcement: August 2, 2026
- Standalone Annex III high-risk systems: December 2, 2027
- High-risk AI embedded within regulated products such as medical devices, machinery, and toys: August 2, 2028
The delay therefore concerns the most demanding part of the regulation.
It also happens to concern the smallest number of businesses.
If your company doesn’t perform credit scoring, biometric identification, or manufacture regulated medical products, you’ve effectively gained sixteen months on obligations that probably weren’t relevant to you anyway.
What Actually Took Effect on August 2
Article 50 of the AI Act remained exactly where it always was.
The European Commission explicitly confirmed this.
Article 50 introduces four transparency obligations.
Providers of AI systems that interact directly with people must ensure users know they’re interacting with AI, unless that fact is already obvious from the context.
A clear notice at the beginning of the interaction is generally sufficient.
Organizations using AI to create deepfakes must disclose that fact.
Organizations publishing AI-generated text intended to inform the public about matters of public interest must disclose that AI was used.
Organizations using emotion recognition or biometric categorization systems must inform the affected individuals.
Only one transparency requirement has been postponed.
The machine-readable watermarking requirement now applies from December 2, 2026, for both existing and newly marketed systems.
The same date also introduces two additional prohibitions created by the Digital Omnibus:
- AI systems generating non-consensual intimate images;
- AI-generated child sexual abuse material.
These prohibitions apply both to providers and to deployers.
The Penalties—And How They Should Be Read
Article 99 establishes three levels of administrative fines.
Each fine is calculated as whichever is higher between a fixed amount and a percentage of worldwide annual turnover.
- Up to €35 million or 7% of global annual turnover for prohibited AI practices under Article 5.
- Up to €15 million or 3% for breaches of other obligations, including transparency.
- Up to €7.5 million or 1% for supplying incorrect, incomplete, or misleading information to supervisory authorities.
For SMEs and startups, paragraph 6 reverses the calculation.
The lower value between the fixed amount and the percentage applies.
That remains a significant financial risk.
One clarification is worth making.
The €35 million headline is widely quoted but often misunderstood.
That highest tier concerns prohibited practices.
If your business isn’t carrying out social scoring or monitoring employees’ emotions, that probably isn’t your category.
The transparency obligations are.
The Italian Framework
Italy added a national layer through Law No. 132 of September 23, 2025, which entered into force on October 10, 2025.
Article 20 designates:
- the Agency for Digital Italy (AgID) as the notifying authority;
- the National Cybersecurity Agency (ACN) as the market surveillance authority, responsible for inspections and enforcement.
The Italian Data Protection Authority continues overseeing all matters involving personal data.
Sector regulators—including the Bank of Italy, CONSOB, and IVASS—retain their existing responsibilities.
In practice, most AI systems process personal data.
That means companies often operate under two parallel regulatory frameworks:
the AI Act and the GDPR.
The legislation also expands Italy’s Legislative Decree 231 organizational liability framework, introducing governance responsibilities that did not previously exist.
The Most Likely Risk Isn’t the Fine
This deserves to be stated clearly.
Most discussions focus entirely on penalties.
The probability that a medium-sized company will receive an inspection in the next twelve months is relatively low.
The probability that a business customer will ask for an AI Act compliance statement before signing a contract is considerably higher—and increasing every quarter.
Failing to provide that documentation doesn’t result in an administrative fine.
It results in a contract that never gets signed.
There is also reputational risk.
Enforcement decisions are public.
Civil liability is another consideration.
If someone suffers harm because of a non-compliant AI system, demonstrating regulatory non-compliance makes proving liability substantially easier.
Where to Start
The first step doesn’t require consultants.
It can begin today.
Then classify each system according to its risk level.
Identify which ones fall under Article 50.
Update policies and disclosures accordingly.
Assign responsibilities to specific individuals.
It’s tedious work.
That’s precisely why many organizations postpone it.
But when the first request eventually arrives—from a regulator, or far more likely from a client—that inventory becomes the first document everyone asks for.
And it’s the only one you can’t realistically assemble in a week.
One final question.
Does the chatbot on your website clearly tell visitors they’re speaking with AI?



