Do you already know who’s writing to you? The AI Act comes into full force on August 2nd

27 Jul , 2026 - Notizie

Do you already know who’s writing to you? The AI Act comes into full force on August 2nd

Draft 1 — FinGreenTech S.r.l. Società Benefit

From August 2, 2026, the European Union’s Artificial Intelligence Regulation — Regulation (EU) 2024/1689, better known as the AI Act — becomes fully applicable. Behind the technical language lies a principle anyone can grasp immediately: from that date, everyone has the right to know, clearly and explicitly, whether what they’re reading, hearing, or watching was made by a person or a machine.

For businesses, even the smallest ones, this is no minor detail. It’s the moment artificial intelligence stops being a grey area and becomes a regulated field, with precise obligations and real penalties.

A path announced two years ago

August 2nd doesn’t come out of nowhere. The AI Act entered into force on August 1, 2024, and its application has been rolling out in stages ever since. Since February 2, 2025, practices posing an “unacceptable risk” — such as social scoring or mass surveillance — have been banned, and the AI literacy obligation (Article 4) is already in force: anyone who puts artificial intelligence in their staff’s hands must make sure they can use it responsibly. Since August 2, 2025, the rules on general-purpose AI models, European governance, and the penalty framework have applied.

August 2, 2026 is the real turning point: from this date, the rest of the regulation applies — the package of obligations that reaches the widest group of subjects. Further deadlines will follow between 2027 and 2030 for high-risk systems embedded in regulated products and for systems already on the market, but for the vast majority of businesses, the countdown ends now.

The heart of the change: Article 50 and transparency

The most immediate impact on businesses comes from the transparency obligations set out in Article 50. And on this deadline, it’s not worth hoping for extensions: while the Digital Omnibus package has reshuffled some of the regulation’s timelines, August 2, 2026 has stayed fixed. The European Commission has in fact published its final guidelines to help providers and users apply these obligations in practice — a clear sign that the waiting period is over.

The obligations can be summed up in four rules.

1. Chatbots must identify themselves. If your business uses a virtual assistant, a customer-support chatbot, a voice system for bookings, or an automated tool for first commercial contact, that system must be designed so the user immediately and unambiguously understands they’re talking to a machine. The only exception is when the artificial nature is already obvious from context. In practice: screens, welcome messages, voice responses, and customer journeys all need reviewing.

2. Synthetic content must be marked. Text, images, audio, and video generated by AI must be identifiable as artificial, marked in a machine-readable format, as far as technically feasible. For systems already on the market before August 2, 2026, there’s an extra grace period: the recently approved Digital Omnibus package pushes the deadline out to December 2nd. Anyone integrating content-generation tools would do well to ask their vendors now what kind of marking they offer and how well it survives later edits.

3. Deepfakes must be labelled. Anyone using systems that create or alter images, audio, or video with a realistic effect must disclose that the content was artificially generated or manipulated. Clearly artistic, satirical, or creative works remain exempt.

4. AI-generated information must be disclosed. If you publish text produced by AI to inform the public on matters of general interest, the use of AI must be made explicit — unless the content has gone through human editorial review, with a person taking responsibility for it. The goal isn’t to slow down the technology, but to build a clear chain of accountability: who approves, who checks, who answers for it.

One idea runs through all four rules: transparency isn’t a label you stick onto a finished product. It’s a requirement to build in from the system’s design stage — transparency by design — much like what happened with privacy under the GDPR. Anyone choosing or integrating an AI tool today should be evaluating it on this basis too.

The fifth obligation nobody talks about: emotion recognition and biometrics

There’s one requirement that gets left out of most summaries. Anyone deploying emotion-recognition or biometric-categorisation systems — for marketing, retail, events, or private security, for instance — must inform the people exposed to them about how these tools work, and data processing must fully comply with European data-protection rules. This is an issue that directly affects shops, workplaces, and public-facing services, often without whoever adopted the technology even realising it.

“But I don’t build AI”: why this affects you too

A common misconception is thinking the AI Act only concerns those who build artificial intelligence systems. The regulation distinguishes between providers (those who develop and place systems on the market) and deployers (those who use AI systems in their own operations). The small business that switched on the chatbot bundled into its management software, that generates images for social media, or that uses a voice assistant for bookings falls within scope as a deployer — even without writing a single line of code. Different obligations, but obligations nonetheless.

Penalties — and more than just penalties

Violations of the transparency obligations can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher, with proportionate thresholds for SMEs and startups. But reducing the risk to fines would be the wrong way to look at it: accountability for AI use is already a reality, as shown by the first cases of Italian professionals sanctioned for filing documents containing AI-generated errors. The real question isn’t “how much am I risking in fines,” but “can I stand behind what my tools produce?”

The real problem isn’t the fines: it’s the missing map

Compliance readiness in Italy is moving at two speeds. Larger, more structured organisations have already mapped out the systems they use, adopted internal policies, and set up controls. Many small businesses and professionals, on the other hand, don’t even have an inventory yet of the AI tools they use every day — often because AI arrived “sideways,” embedded inside software and services already in use.

And that’s the real point: you can’t bring into compliance something you haven’t even brought into focus yet.

Where to start

The first step doesn’t require an elaborate consulting engagement. It requires a method:

  1. Take stock of the AI tools actually in use across the business, including those embedded in third-party software.
  2. Classify them: which ones interact with people? Which generate content? Which process biometric or emotional data?
  3. Check which Article 50 obligations apply to each one.
  4. Adjust interfaces, notices, disclaimers, and markings, working with vendors as needed.
  5. Formalise an internal AI-use policy: who can use what, for which purposes, with what controls and approvals.
  6. Train your people: AI literacy isn’t optional — it’s already been a requirement since February 2025.

From there, compliance becomes a manageable process — not an emergency.

Our approach

As a Benefit Corporation, at FinGreenTech we believe technology should be adopted responsibly and transparently — which is exactly the spirit behind the AI Act. That’s why we always start by mapping things out: understanding which systems you use, where AI enters your processes, and what needs to be disclosed. If you want to reach August 2nd knowing exactly where you stand, the first consultation is free.


Leave a Reply

Your email address will not be published. Required fields are marked *