01 What actually started on 2 August, and what didn’t
On 2 August 2026 a block of the AI Act became applicable, and the Italian press covered it thoroughly: the transparency obligations of article 50, which require anyone deploying chatbots, voice assistants or synthetic content to make clear that what the user is dealing with was generated or manipulated by a machine. From the same date the national penalty regime became operational, with ceilings that reach 15 million euros or 3% of worldwide annual turnover.
Less well covered is what did not start. A later amendment to the Regulation’s timetable pushed the obligations for high-risk systems back: to 2 December 2027 for the stand-alone systems of Annex III, which include recruitment, credit and education, and to 2 August 2028 for systems embedded in regulated products. So the part most companies were bracing for is now more than a year away.
The practical conclusion most Italian SMEs have drawn from this coverage is reasonable and wrong: none of it applies to us, we do not sell chatbots and we do not run high-risk systems. The first half is usually true. The second half skips an article that has been binding since before any of this.
02 The word that applies to you is “deployer”
The Regulation splits the world into roles, and the two that matter here are provider and deployer. A provider develops an AI system, or has one developed, and places it on the market under its own name. That is not you.
Article 3(4) defines a deployer as “a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity”.
Read the exception carefully, because it is the whole thing. Personal non-professional use is outside. Your sales assistant summarising a technical datasheet with a chatbot on Tuesday afternoon is not doing anything personal and non-professional. They are doing their job, on your instructions, under your authority. That makes the company a deployer, and it makes it a deployer whether or not anyone ever signed a purchase order, opened a project or told the owner.
You do not become a deployer by buying something. You become one because someone in your company is already using it to work.
03 The obligation that has been in force since February 2025
Article 4 of the AI Act is three lines long and applies, under the Regulation’s own timetable, from 2 February 2025. In the original:
“Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.”
In plain terms: if people work with AI systems on your behalf, you have to take measures so that they know what they are doing with them. Not a certification. Not a course from an approved provider. Measures, proportionate to who the people are and to what the systems are used for. The wording is deliberately soft, and it is still an obligation.
Note who it binds. Not providers only. Providers and deployers. Which, given the definition above, is most Italian companies with more than a handful of office staff, as of eighteen months ago.
04 The Italian paradox this collides with
In our piece on personal AI and company memory we used two figures that only make sense together. 47% of Italian workers use AI at work, and of those only 19% do so exclusively with company-provided tools. Meanwhile 83.6% of Italian companies have adopted no AI technology at all.
Those are the same offices. The technology arrived through individual curiosity rather than through procurement, which is a perfectly Italian way for a technology to arrive, and it produces a specific legal oddity: a large number of companies now carry an obligation about a practice they have never formally acknowledged exists.
The obligation is not to stop it. Nothing in the Regulation says staff cannot use AI. The obligation is to ensure they are competent to use it, which is impossible to satisfy for a practice you are pretending is not happening. You cannot train people on tools you have not admitted are in the building, and you certainly cannot demonstrate that you did.
05 There is no fine for this, and that is the awkward part
Here is where a lot of what was written this week is imprecise, and where it is worth being exact. Article 99 lists the provisions whose breach triggers administrative fines: article 5 on prohibited practices at the top of the scale, then articles 16, 22, 23, 24, 26, 31, 33, 34 and 50 in the 15 million or 3% band, then incorrect or incomplete information at the bottom. Article 4 is not on the list. There is no dedicated European fine for failing to ensure AI literacy.
That should not be read as “so it does not matter”, for three reasons.
- It is still a binding obligation. Article 99(1) requires Member States to lay down rules on penalties for infringements of the Regulation, effective, proportionate and dissuasive, taking into account the interests of SMEs. The absence of a dedicated ceiling is not an exemption.
- Italy has appointed who checks. Law 132/2025 designates AgID and the National Cybersecurity Agency as the national AI authorities, with market surveillance, inspection and sanctioning functions sitting with ACN, alongside the unchanged competences of the Bank of Italy, Consob, IVASS, the data protection authority and AGCOM in their own fields.
- It shows up long before an inspection does. Obligations without a headline fine tend to surface in the ordinary places first: in a customer’s supplier questionnaire, in a due diligence, in an insurance policy, in the contractual representations a larger client asks a smaller supplier to sign. That is where “can you demonstrate what you did” gets asked, and demonstrating requires having done something on purpose.
06 What a normal company can actually do about it
The proportionality in the article’s wording, “to their best extent”, and the explicit consideration of SME interests in article 99(1), point at a small and honest set of measures rather than a compliance project. For a company of forty to two hundred people, this is what it looks like:
- Ask, without consequences, who is using what. The first obstacle is that people will not say, because they assume they are breaking a rule. Say plainly that they are not in trouble. You cannot govern a practice you cannot see, and the map costs one honest conversation per team.
- Write down what may and may not go into an outside tool. One page. Customer data, drawings, price lists, personal data of employees: the categories, and where the line is. This is the single measure with the highest ratio of protection to effort.
- Give people a company route that is better than the personal one. A prohibition that leaves people worse off gets ignored quietly. The only enforcement that works is being more useful than the alternative.
- Do the training with your own material, not with a generic course. Article 4 asks for literacy in the context the systems are used in. A slide deck about what a large language model is satisfies nobody; twenty examples of real questions from your own work, with what a good answer and a bad answer look like, satisfies both the obligation and the people attending.
- Keep a trace. Dates, who attended, what the policy said and when it changed. Unglamorous, and it is the only difference between having complied and being able to say so.
None of this is expensive, and none of it needs a consultant. What it needs is the decision to treat something that is already happening as something the company does on purpose, which is the same decision that turns scattered personal accounts into a shared company memory. The compliance requirement and the operational one point in the same direction here, which does not happen often enough to waste.
07 Note on sources
This article is not legal advice. It reports what the articles say and what has been officially designated in Italy. A concrete assessment needs a professional who has seen how your company actually works.
- Articles quoted are 3(3), 3(4), 4 and 99 of Regulation (EU) 2024/1689. Article 4 applies from 2 February 2025 under the Regulation’s own timetable. Translations into Italian in this piece are ours and the English wording is quoted alongside.
- The central claim, that article 4 does not appear among the provisions fined under article 99, was verified paragraph by paragraph against the text of article 99.
- What became applicable on 2 August 2026 and the postponement of the high-risk obligations to 2 December 2027 and 2 August 2028 are reported from concurring specialist and general Italian press of 30 July to 2 August 2026. We did not verify the amending regulation on EUR-Lex, so we do not cite it by number, and none of the reasoning in this article depends on those dates.
- The Italian framework is Law 132/2025, which designates AgID and ACN as national AI authorities, reported from concurring sources.
- The adoption figures come from Istat and the Politecnico di Milano observatory, verified in our 4 August 2026 article on personal AI and company memory.
One caution about this piece specifically. This is fast-moving law, and a good part of what circulated in the days around 2 August was imprecise in both directions, describing either obligations that were postponed or fines that do not exist. If you are reading this some time after publication, check the dates against the current text before acting on any of it.
Sources
- Regulation (EU) 2024/1689 (AI Act), articles 3, 4, 50, 99 and 113.
- Legge 23 settembre 2025, n. 132, on artificial intelligence (designation of AgID and ACN as national authorities).
- Italian specialist and general press on the obligations applicable from 2 August 2026 (Agenda Digitale, Il Sole 24 Ore, Il Fatto Quotidiano, Sky TG24), 30 July to 2 August 2026.
- Istat and Osservatorio Artificial Intelligence, Politecnico di Milano, as verified in ekory, Personal ChatGPT is not your company’s memory, August 2026.