Security

AI Act: what it is and what companies should do (practical deployer guide)

5 min read
AI Act: what it is and what companies should do (practical deployer guide)

The AI Act is not a general ban on artificial intelligence: it is an EU risk-based regulation, with different obligations for those who supply systems and those who use them professionally. For most Italian SMEs the operational point is this: if you use AI in processes (including commercial tools), you are typically a deployer and need to be able to show transparency, literacy, and control.

This is general information, not legal advice. Dates and duties should be checked on your concrete case with a qualified professional.

What the AI Act is, in one useful sentence

The AI Act is Regulation (EU) 2024/1689: harmonised rules on artificial intelligence in the European Union. It classifies uses by risk level and ties obligations to that risk.

The European Commission summarises it as a risk-based approach, with bans on unacceptable practices, stricter duties for high-risk systems, transparency duties for certain uses (e.g. chatbots and synthetic content), and few extra rules for minimal risk. The official overview is on the Regulatory framework for AI page.

Which deadlines matter now (August 2026)

Not all deadlines are the same. According to the Commission:

  • from 2 February 2025, bans on prohibited practices and AI literacy obligations apply (Art. 4);
  • from 2 August 2025, governance rules and obligations for GPAI (general-purpose AI) models apply;
  • from 2 August 2026, enforcement and transparency obligations relevant to chatbots and AI-generated or altered content start (Commission press release, 31 July 2026);
  • obligations for high-risk systems in Annex III were moved to 2 December 2027, and those for systems embedded in regulated products (Annex I) to 2 August 2028, following the simplification package (“AI Omnibus”) described by the Commission.

Operational summary: August 2026 is not “all high-risk obligations at once.” It is the moment when transparency and enforcement become concrete.

What companies that use AI should do (deployer role)

In the AI Act, a provider develops and places a system on the market (or puts it into service under its own name). A deployer uses an AI system under its authority in a professional context (Art. 3, points 3 and 4).

If your SME uses ChatGPT, Copilot, an internal document assistant, or a ticket agent, in most cases you are a deployer. You are not “outside the rules”: you are inside, with proportionate obligations.

Practical steps we recommend operationally (not as an exhaustive legal list):

  1. Inventory: which AI tools you use, for which processes, with which data.
  2. Rough risk classification: generic support use vs decisions about people (HR, credit, access to services).
  3. Transparency: if a chatbot talks to customers or users, it must be clear they are interacting with an AI system, not a person (Art. 50 / August 2026 enforcement).
  4. Literacy: train people who use AI at work (already applicable since February 2025).
  5. Ownership: who is accountable for output quality and escalation.
  6. Data: GDPR alignment on what can be uploaded and where.

Zendata works on the operational piece: usable, traceable, governed systems—not as a substitute for legal advice.

High-risk systems: when to worry in earnest

High risk is not “any AI in the company.” The Commission lists sensitive use cases, including (examples): safety components in critical infrastructure, education and exam scoring, recruitment and worker management, credit scoring and access to essential services, biometrics in certain contexts, justice and migration. Details and updated list: official AI Act page.

If you use AI only for email drafts, internal search, or document summarisation with human oversight, you are in a different scenario from automated candidate ranking. The distinction matters: it avoids useless panic and delays where preparation is actually needed.

FAQ

Does the AI Act ban ChatGPT at work?
No. It does not introduce a general ban. It introduces differentiated obligations and, for certain uses, transparency and responsibility.

Are SMEs exempt?
Not automatically. The regulation includes support measures and simplifications for SMEs/start-ups, but professional use is in scope. Assess the concrete case.

What changed on 2 August 2026?
According to the Commission, enforcement and transparency obligations on AI interaction and certain generated/altered content start. Annex III high-risk obligations remain on a later horizon (December 2027, subject to further updates).

Do we need a lawyer, or is an AI vendor enough?
You need operational clarity and, on relevant legal points, professional advice. A technical vendor does not replace a legal assessment.

Sources

Dig deeper in the series

If you want to map the AI tools in use and understand, operationally, what to put in order first (transparency, literacy, ownership, data), we can do it on a concrete perimeter. Write to info@zendata.it or visit zendata.it.

Pietro Ciattaglia, CEO of Zendata AI, Rome