The AI Act already applies. The part that concerns you is smaller than it looks.
On 2 August 2026 Article 50 of the European Regulation on artificial intelligence became applicable. Since that day a great many Italian businesses have been using tools that fall within scope without knowing they are inside a scope. The useful part lies in a distinction of role that almost nobody explains, and that reduces a small business's obligations to four things.
You aren't an AI provider, you are a user. The regulation calls whoever uses a system developed by others a deployer. The obligations of those who use are far fewer than those of whoever builds and places on the market.
The main obligation is to say there is an AI involved. When a person talks to it, when content is generated or manipulated, when a voice or a face is synthetic.
It applies to systems already in use, not just new ones. The article applies regardless of when the system was placed on the market. Only content marking, and only for pre-existing systems, is postponed to 2 December 2026.
There is also an Italian law, and it is about workers. Law 132/2025 requires informing workers before introducing an AI system into a process, and keeping a person able to correct it.
This piece sits alongside the glossary of AI and automation and the AI transparency page, where Itria states which systems it uses and how. It is written for whoever runs a business, and it ends where a lawyer's work begins.
What kicked in on 2 August
The AI Act didn't come into force all at once. It arrives in stages, and on 2 August 2026 it was the turn of Article 50, the one on transparency. It is the article that concerns the largest number of ordinary businesses, because it doesn't talk about high-risk systems or biometric recognition in the street. It talks about one thing only: when a person is dealing with an artificial intelligence, they must be able to know it.
It applies to all systems within scope, regardless of the date on which they were placed on the market.
That line is the surprising part. There is no grandfathering for the chatbot installed on the website in 2024. If it is within scope today, today it has to be declared. The only extension concerns the technical marking of generated content, the machine-readable kind, and only for systems already present before 2 August: for those the deadline is 2 December 2026. All the article's other obligations apply straight away.
The distinction that changes everything: who provides and who uses
This is where most conversations that start with “so now we have to do AI compliance” fall down. The regulation distinguishes two roles, and treats them very differently.
The provider is whoever develops an artificial intelligence system and places it on the market under their own name. The bulk of the regulation weighs on them: technical documentation, conformity assessment, risk management, registration.
The deployer, that is, the user, is whoever takes one of those systems and uses it in their own business. A company that puts an assistant on its website, generates texts with a model, has calls transcribed. In almost every case, an Italian SME sits here. And the deployer's obligations under Article 50 are essentially information obligations.
It isn't a loophole and it isn't a technicality. It is the architecture of the regulation: the weight is on whoever builds the tool, transparency is on whoever points it at a person.
There are six roles, however, not two, and one of them is inherited without signing anything: whoever puts their own brand on a high-risk system becomes its provider. The complete map is on the page about who the AI Act applies to and in what role, and the classification of systems on the one about risk levels.
The three cases that really affect a small business
The scope of Article 50 is broader, but for a services business, a producer or a hospitality business it almost always comes down to three situations.
| Situation | What is needed | Where people go wrong |
|---|---|---|
| Direct interactionchatbot, assistant, auto-responder | The person must know they are talking to a system, and must know it before talking to it, not after. A clear line at the start is enough. |
The assistant with a person's name and a smiling photo. The more human it seems, the stricter the obligation. |
| Generated contenttexts, images, audio | Machine-readable marking when the content is generated or manipulated, and a visible disclosure when it is published to inform the public on matters of public interest without human review. |
Believing it covers every product sheet. A sheet reread and approved by a person doesn't count as content published without editorial control. |
| Synthetic voice and facedeepfake, cloned voice | It must be disclosed on the content. It applies even when the cloned voice is yours and you authorised it yourselves. |
The promotional video with a generated voice and no note. It is the most visible case and the one a competitor reports first. |
The Italian law, and it concerns those who work with you
On top of the European regulation Italy has added its own rule: Law No 132 of 23 September 2025, in force since 10 October 2025. The part that affects an employer lies in internal processes, not in the relationship with the customer.
It asks for three things, and they are reasonable. Inform workers before introducing an AI system into a process, explaining what it is for and what data it processes. Keep a person able to check and correct every decision taken or suggested by the system. Keep a documented record, that is, know which systems are running, where, and who is responsible for them.
Whoever has already built their automations with a human step at the sensitive points finds half the work done. Whoever let an agent write to customers on its own, on the other hand, has a problem that isn't only about the rule.
The law also does five other things the European regulation doesn't, from copyright to a new offence in the criminal code: they are collected on the page about Law 132/2025 on artificial intelligence. On the relationship with data protection there is the page on AI Act and GDPR.
The penalties, without scaremongering
Breach of the transparency obligations sits in the middle band of the penalty regime: up to €15 million or 3% of worldwide annual turnover, whichever is higher. The figure circulates widely and serves mainly to sell courses.
We add the part almost nobody cites: for small and medium-sized enterprises the lower of the two amounts applies, not the higher. It remains a figure nobody wants to see, and it remains very far from the ordinary case of a company that forgot a line under the chatbot. The realistic risk for an SME isn't the fine. It is the customer discovering on their own that they were talking to a machine. The three bands, the criteria used to reach a figure and who can apply them in Italy are on the page about AI Act penalties.
AI Act obligations, company by company
The European Commission sums up Article 50 in one line: «Article 50 of the AI Act applies as from 2 August 2026». The obligations that follow from it are four, and they don't all fall on the same party: two concern whoever provides the system, two whoever uses it.
| Obligation | Who it concerns | From when |
|---|---|---|
| Say it is an AIdirect interaction | The provider of the system, who must design it so that the person is informed they are interacting with an artificial intelligence system. An SME using a third-party assistant inherits it already compliant, and only has to not hide it. |
2 August 2026 |
| Mark synthetic contentmachine-readable format | The provider of the system that generates or manipulates text, images, audio or video, who must make them marked and detectable as artificial. |
2 August 2026, with a window until 2 December 2026 for systems placed on the market before August |
| Inform those exposedemotions and biometrics | Whoever uses emotion recognition or biometric categorisation systems, who must inform the people exposed about how they work. |
2 August 2026 |
| Disclose deepfakesmanipulated content | Whoever uses the system to produce manipulated content, who must disclose it clearly and distinguishably, at the latest at the first exposure. |
2 August 2026 |
For most small Italian businesses the count ends here: they use third-party tools, so the third and fourth rows count, and the first only insofar as it mustn't be hidden. The two provider rows concern whoever builds the system, not whoever buys it.
It also applies to those outside the Union: the same source specifies that providers established or located outside the European Union are subject to the provisions of the AI Act if the output of their system is used in the Union.
The four things to sort out
Setting theory aside, the compliance work of a small business using third-party tools comes down to four steps. None requires a consultant to get started.
| Step | What you do | What it costs |
|---|---|---|
| 01 · The listhalf a day | Write down which AI systems run in the company, who activated them, what data they work on and where that data sits. |
A spreadsheet. It is also the document Law 132/2025 asks you to be able to show. |
| 02 · The disclosuresan afternoon | A line under every automated point of contact, and a note on generated content where needed. |
Text. The real cost is deciding how to say it without sounding like a legal notice. |
| 03 · The public pagea day | A page that states the systems in use, their purpose and where the data sits. In this form it isn't mandatory, and it is the cheapest way to show that the rest has been done. |
See ours, which is written exactly like that. |
| 04 · The human stepongoing | On every automated process that touches a customer, money or an outgoing communication, a person approves before it goes out. |
Zero, if the system was designed that way. A lot, if it has to be redone afterwards. |
There is a fifth point that doesn't appear in this list because it doesn't come from Article 50: Article 4 requires attention to the skills of those who use the systems, and it applies from 2 February 2025. The detail is on the page about the AI literacy training obligation.
The dates, in order
2 February 2025, Chapters I and II apply: the obligation to take care of the skills of those who use the systems, in Article 4, and the prohibitions in Article 5. 10 October 2025, Law 132/2025 comes into force and with it the obligations towards workers. 2 August 2026, Article 50 becomes applicable, for all systems within scope regardless of when they were placed on the market.
2 December 2026, the extension on content marking alone expires for systems that existed before August, and on the same day two new prohibited practices added to Article 5 become applicable. 10 October 2026, on the other hand, an Italian date expires: the delegation in Article 24 of Law 132/2025 for the decrees assigning penalty powers.
The dates for high-risk systems have been moved. Regulation (EU) 2026/1744 of 24 July 2026 rewrote Article 113 and moved Chapter III, sections 1, 2 and 3, to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I systems. The postponement doesn't touch the prohibitions, literacy or transparency, so a small business hasn't gained time on anything that concerns it. The full picture is in the updated calendar of AI Act deadlines.
Frequently asked questions
Does the AI Act also concern small businesses?
Yes, but almost never in the role people fear. Whoever uses ChatGPT, an assistant on their website or a text generator is a deployer, not a provider. The deployer's obligations come down, in most cases, to saying clearly when there is an AI involved.
What kicked in on 2 August 2026?
Article 50 of Regulation (EU) 2024/1689, that is, the transparency obligations, for all systems within scope regardless of the date they were placed on the market. For systems already present, only the marking obligation is postponed to 2 December 2026.
Do I have to declare that a text on my website was written with AI?
The obligation concerns generated or manipulated content published to inform the public on matters of public interest without human review or editorial control. A product sheet reread and approved by a person doesn't fall within it. Declaring it anyway remains the choice that costs less than an argument.
What are the penalties for an SME?
Up to €15 million or 3% of worldwide annual turnover, with a clarification that matters: for small and medium-sized enterprises the lower of the two amounts applies, not the higher.
Does Italian Law 132/2025 add anything?
Yes, and it concerns workers: inform them before introducing an AI system into a process, ensure that a person can check and correct the system's decisions, and keep a documented record.
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex, Article 50.
- Transparency obligations under Article 50 of the AI Act, European Commission, for the date of application, the four obligations and the window until 2 December 2026 for systems placed on the market before 2 August 2026. Page opened on 6 September 2026, last update stated 24 July 2026.
- Art. 50 AI Act, transparency becomes operational, Agenda Digitale, on applicability regardless of the date of placing on the market and on the marking extension.
- Law No 132 of 23 September 2025, provisions on artificial intelligence, Italian Official Gazette No 223 of 25 September 2025, in force since 10 October 2025.
- Regulation (EU) 2026/1744, the digital omnibus on AI, published on 24 July 2026, for the postponement of the high-risk system dates and the two new prohibited practices applicable from 2 December 2026.
This article is an operational overview, not a legal opinion. On specific situations, and in particular on organisational models and employment relationships, the answer comes from a professional who looks at your company.
Which of the four obligations really concerns you.
If you have an assistant that replies to customers, or a system that prepares texts that go out in your name, working out which of the four points concerns you takes fifteen minutes. If none of them does, we tell you, and that is the end of it.