Solari SolutionsIT

Articles · Consultingdraft

The AI Act for those who use artificial intelligence, not for those who produce it

Published · by Dario Solari · 5 min read

The European regulation is written mainly for those who develop artificial intelligence systems. For a company that uses them the obligations are few and precise. What they are, from when they apply, and what the Italian law adds.

The European regulation on artificial intelligence, Regulation (EU) 2024/1689, known as the AI Act, is the first general law on the subject in the world. It was amended in 2026 by the so-called Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026), which moved some deadlines and rewrote some articles. What follows is the regulation as it stands today.

A regulation built on risk

The AI Act does not regulate artificial intelligence in general: it regulates its uses, according to the risk they carry. There are four levels.

Prohibited practices. Some uses are forbidden: for example, systems that manipulate people to their detriment or that classify them according to their social behaviour. The ban has applied since 2 February 2025.

High-risk systems. These are the uses listed in Annex III of the regulation: recruitment, creditworthiness assessment, education, access to essential services, and others. For these, extensive obligations apply, both for those who produce them and for those who use them: human oversight, logs, monitoring. Their entry into application has been postponed from 2 August 2026 to 2 December 2027.

Transparency obligations. Anyone who puts a person in contact with an artificial intelligence system must tell them so; artificially generated content that could be mistaken for real must be labelled. These obligations, laid down in Article 50, have applied since 2 August 2026 and have not been postponed.

Minimal risk. Everything else, that is, the great majority of uses in a company, carries no specific obligations beyond the literacy obligation discussed below.

Two roles: those who produce and those who use

The regulation distinguishes the provider, which develops a system and places it on the market, from the deployer (in the Italian text, utilizzatore), which uses it in its own business. A company that adopts an assistant to write, summarise or search its own documents is a deployer. Most of the AI Act's obligations concern providers.

A useful clarification for those who customise a model: adapting an open model to one's own documents does not turn the company into a provider of a general-purpose AI model. According to the Commission's guidelines, this happens only if the additional training exceeds one third of the computing power used for the original model, a threshold far beyond any company customisation.

What applies to a company that uses artificial intelligence

For a deployer that does not fall within the high-risk uses, the obligations are three.

1. AI literacy (Article 4), since 2 February 2025. The company must adopt measures to promote knowledge of artificial intelligence among the people who use it, in proportion to the context. After the Digital Omnibus the provision no longer requires a "sufficient" level, nor does it guarantee an outcome for every individual, but the obligation remains. Documented training is the most direct way to comply with it.

2. Transparency (Article 50), since 2 August 2026. If a customer talks to an automated assistant, they must know it. If the company publishes artificially generated text, images or audio that could be mistaken for real, it must say so. For tools used only internally, among colleagues, the obligation does not arise.

3. Care with high-risk uses, from 2 December 2027. Using artificial intelligence to select candidates, evaluate employees or decide on credit brings the company into the high-risk regime, with obligations of human oversight, logging of operations and monitoring. For most companies the simplest choice is not to use it for these purposes, or to prepare in good time.

What the Italian law adds

Italian law no. 132 of 23 September 2025, in force since 10 October 2025, sits alongside the European regulation with some rules of its own.

  • Intellectual professions (Article 13). Artificial intelligence may be used only for instrumental and supporting activities; the professional's intellectual work must prevail. The professional must inform the client about the systems used, in clear, simple and comprehensive language.
  • Employment (Article 11). The employer must inform workers when artificial intelligence is used in hiring, in managing or in monitoring their work.
  • Authorities. The Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN) are the competent national authorities.

What does not change

The AI Act comes on top of the GDPR; it does not replace it. The company remains the controller of the data it enters into any system: it must have a legal basis, keep the record of processing activities, inform the data subjects, protect the data (Article 32) and, for high-risk processing, assess its impact.

A system installed on the company's premises, which does not transmit data outside, simplifies part of these duties: no transfer to third countries, no external provider processing the data, an easier answer to customers who ask where their documents end up. It does not remove the others. An internal machine that is not updated and has no access control can be less secure than a well-run external service.

A list to begin with

  1. Take stock of the artificial intelligence tools already in use, including the free ones used by individuals.
  2. Organise and document staff training (Article 4).
  3. Check where customers encounter an automated system and inform them (Article 50).
  4. Check that no use falls within Annex III; if one does, plan ahead of December 2027.
  5. For professionals, update the information given to clients in accordance with Article 13 of Italian law 132/2025.
  6. Decide which data may leave the company and which may not, and choose the tools accordingly.

Sources

  • Regulation (EU) 2024/1689 (AI Act), arts. 4, 5, 26, 50 and Annex III.
  • Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026.
  • European Commission, Guidelines on the obligations of general-purpose AI providers, FAQ.
  • Italian law no. 132 of 23 September 2025, arts. 11 and 13.
  • Regulation (EU) 2016/679 (GDPR), arts. 30, 32 and 35.