![]() |
2026 is the year in which artificial intelligence, from a regulatory standpoint, stops being frontier territory. With the general application of the AI Act set for 2 August and Italian legislation fully operative since autumn 2025, public and private organisations now face a layered set of rules, structured across several levels and still set to evolve in the coming months through delegated decrees. Understanding how to navigate this landscape is no longer an academic exercise for specialist lawyers: it is a necessary condition for anyone within a company who decides to adopt an AI system - from a customer-service chatbot to a tool supporting recruitment decisions. This article seeks to bring order to the picture, reconstructing the regulatory architecture in its entirety: where the rules come from, who must comply with them, how AI systems are classified by risk, which specific obligations apply to sectors such as employment, healthcare, public administration and justice, and - above all - what an organisation should already have done to avoid exposure to penalties. Three levels of rules that speak to one another.The first building block is Regulation (EU) 2024/1689, better known as the AI Act, which entered into force on 1 August 2024: the first comprehensive European framework on artificial intelligence, designed to apply to both the public and private sectors, with the sole exception of systems intended exclusively for military, defence or pure scientific research purposes. Built on this European foundation is Law 132/2025, which entered into force on 10 October 2025: the first comprehensive intervention by the Italian legislature in this field. It is important to grasp one technical but decisive point - Italian law expressly describes itself as complementary, not additive, to the European regulation: it does not introduce new obligations for AI systems and general-purpose AI models beyond those already set out in the AI Act, and its provisions must be read consistently with it. The third, often underestimated, level is the GDPR, which continues to apply in full whenever an AI system processes personal data - a scenario that is anything but marginal, covering in practice the majority of corporate uses of AI. Completing the picture is the Digital Omnibus on AI (Regulation (EU) 2026/1744), which amended certain exceptions under the AI Act by postponing the application of the provisions on high-risk systems - a sign that the regulatory framework, substantial as it already is, remains in motion. Who must comply with the rules: not just AI developers.A common misconception is to think the AI Act only concerns those who produce the technology. In reality, the regulation carefully distinguishes roles along the entire value chain: the provider, who develops the system to place it on the market; the deployer, i.e. the organisation that uses the system in its own activities - the vast majority of Italian companies fall into this category; and importers and distributors, who also bear specific obligations. Each role carries different responsibilities, and it is precisely the role held that determines which concrete obligations an organisation must meet. The risk pyramid: the heart of the system.The organising principle of the entire framework is the risk-based approach: the greater an AI system's potential impact on people's rights and safety, the stricter the obligations. At the top sit prohibited practices: manipulation of human behaviour through subliminal techniques, social-scoring systems run by public authorities, indiscriminate real-time biometric identification in public spaces, and exploitation of the vulnerabilities of fragile categories of people. These prohibitions are already fully in force: they have applied since 2 February 2025. Immediately below sits high risk, a category covering particularly sensitive sectors: critical infrastructure (energy, transport, communications), education, human-resources management, access to essential services such as healthcare, credit and insurance, policing and justice, border control, and the management of democratic processes. Anyone deploying systems in these areas must guarantee stringent requirements of accuracy, transparency, human oversight, data governance and cybersecurity, in addition to registration in a dedicated EU database. This is a point worth dwelling on for those working in human resources: CV-screening tools or performance-evaluation systems potentially fall within this tier. A third level concerns limited risk: chatbots and virtual assistants, for which transparency obligations towards users apply. The relevant provision, Article 50 of the AI Act, becomes applicable precisely on 2 August 2026 and requires that anyone designing such systems do so in a way that ensures the user always knows they are interacting with artificial intelligence. Finally, a separate set of rules applies to general-purpose AI (GPAI) models - the large language models that today power many corporate tools - subject to obligations of technical documentation, transparency towards downstream integrators, and registration, under the supervision of the European Commission's AI Office. The Italian principles and the (already active) duty to train people.Italian law adds to the risk-based logic a catalogue of cross-cutting principles - transparency, proportionality, security, data protection, confidentiality, accuracy, non-discrimination, gender equality, sustainability - that must guide every activity of AI research, development and use. Two elements deserve particular attention: respect for human decision-making autonomy, with guaranteed oversight and the ability to intervene, and cybersecurity as a precondition throughout the entire life cycle of the systems. There is also an obligation many organisations risk underestimating, precisely because it does not involve buying new technology but investing in skills: AI literacy. Already in force since 2 February 2025, Article 4 of the AI Act requires anyone who develops or uses AI systems to ensure, as far as possible, a sufficient level of AI literacy among their staff - not just those who design the systems, but anyone who uses them on the organisation's behalf. In practical terms, this obligation is closely intertwined with workplace-safety law and GDPR rules, outlining an integrated training system that companies should already have set in motion. Sector-specific rules: employment, healthcare, public administration, professions, justice.It is in the sector-specific rules that Italian law shows its most concrete face. In employment relationships, AI must be used to improve working conditions and protect workers' psychophysical integrity, with respect for dignity, confidentiality and non-discrimination. Employers must inform workers of the use of AI systems, and such tools may never give rise to discrimination based on sex, age, ethnic origin, religious belief, sexual orientation or political opinion. In healthcare, AI systems remain a support to prevention, diagnosis and treatment processes: the final decision always rests with the medical professional. Patients have the right to be informed of the use of these technologies, and the systems must be periodically checked to minimise the risk of error - a framework that will also be implemented through a national health-AI platform managed by AGENAS. In public administration, a clear and significant principle applies: AI has a purely instrumental function, and responsibility for administrative decisions always rests with the person who adopts them, not with the system that supported them. The regulated professions too - law, notarial practice, medicine, engineering - are required to confine AI use to support activities, with the professional's own intellectual work remaining predominant, and with obligations of transparent disclosure to the client. In judicial activity, finally, every decision on the interpretation of the law and the assessment of evidence remains reserved to the judge: AI may assist, but never replace. When AI decides alone: the role of the GDPR.Whenever an AI system makes decisions based solely on automated processing - including profiling - that produce legal effects significantly affecting a person, Article 22 of the GDPR comes into play. The data subject has the right not to be subject to such a decision, save for specific exceptions, and in any event the data controller must guarantee effective human intervention, the possibility to express one's point of view and to contest the decision. The AI Act and Italian law confirm and reinforce these safeguards, definitively welding together privacy and AI regulation. Who supervises: AgID and ACN.On the governance front, Italian law designates two national authorities for artificial intelligence: AgID (the Agency for Digital Italy), responsible for promoting innovation and for notification, assessment and accreditation procedures, and ACN (the National Cybersecurity Agency), responsible for supervision and inspection and sanctioning activities. The respective powers of the Bank of Italy, CONSOB and IVASS remain unaffected within their own areas of competence. Penalties: amounts that can seriously weigh on the balance sheet.The AI Act's penalty regime is graduated by severity. Prohibited practices can cost up to €35 million or, for undertakings, up to 7% of total worldwide annual turnover if higher; breaches relating to high-risk systems reach up to €15 million or 3% of turnover; providing false or misleading information to the authorities can cost up to €7.5 million or 1% of turnover. Reduced measures are envisaged for SMEs and start-ups, so as not to discourage innovation. On the criminal-law front, Italian law has already introduced a specific offence for the non-consensual distribution of deepfakes - images, videos or voices falsified through AI - punishable by one to five years' imprisonment, alongside an aggravating factor for market-manipulation offences committed through artificial-intelligence systems. On the civil-liability front, liability for damage caused by AI is moving towards an accountability-based model, with presumptions of causation in favour of the injured party in cases involving high-risk systems - an evolution that goes beyond the traditional fault-based scheme and which will be set out in detail in the delegated decrees expected by October 2026. What to do, today.In light of this framework, for an Italian organisation the question is no longer "whether" to comply, but "how far behind" it already is with respect to obligations that are already fully in force. Already active, with a concrete risk of sanctions, are:
As has been shown, the framework is not static: by October 2026 the delegated legislative decrees completing Italy's implementation of the AI Act are expected, and the European timetable sets further deadlines through to 2030 for high-risk systems. Staying up to date, more than a formal compliance exercise, is now a structural component of corporate risk management. This article is for information and educational purposes only and does not constitute legal advice. Copyright Leexè 2026 | riproduzione riservata |
AI, ICT
Artificial intelligence in business: the complete map of rules every organisation must know in 2026.
Area of expertise
Related articles
