EU Regulation · source: EUR-Lex

Does the AI Act apply also to those who use AI, not only to those who develop it?

In short: yes. Regulation (EU) 2024/1689 is directly applicable in Italy with no national transposition and follows a risk-based approach. The question is not “do I develop AI?” but “what is my role and which risk class does the system I use fall into?”. Most SMEs are deployers (users). Below are the facts verified against EUR-Lex, then our reading.

The facts · fields 1–10

What the official source says.

Verified against EUR-Lex

01 · Name

Regulation (EU) 2024/1689 — AI Act

“Regulation of the European Parliament and of the Council, of 13 June 2024, laying down harmonised rules on artificial intelligence and amending a number of regulations and directives”. Common short name: AI Act (or AI Regulation / RIA).

EUR-Lex · ELI reg/2024/1689

02 · Type of source

Regulation of the European Union

An EU legislative act of general application, adopted by the European Parliament and the Council under the ordinary legislative procedure.

EUR-Lex · Reg. (EU) 2024/1689

03 · Nature

Binding and directly applicable

As an EU regulation (Art. 288 TFEU) it is binding in its entirety and directly applicable in every Member State, with no need for national transposition. It is not soft law: it lays down legal obligations and a penalty regime.

Art. 288 TFEU + the text of the Regulation on EUR-Lex

04 · Subject matter

A harmonised framework, risk-based approach

It establishes a harmonised legal framework for the placing on the market, putting into service and use of AI systems in the EU, following a risk-based approach: unacceptable risk → prohibited; high risk → stringent obligations; limited risk → transparency obligations; minimal risk → unrestricted. It includes specific rules for general-purpose AI models (GPAI).

EUR-Lex · Reg. (EU) 2024/1689

05 · Who it applies to

Providers, deployers, importers, distributors — with extraterritorial effect

Personal scope: providers, professional deployers/users (deployers), importers and distributors of AI systems, as well as product manufacturers. Territorial scope is extraterritorial: it also applies to entities established outside the EU when the system is placed on the EU market or when the output produced is used within the Union.

EUR-Lex · Reg. (EU) 2024/1689 (Art. 2 — scope)

06 · Key dates

Staggered application

  1. Entry into force (the 20th day after publication in the OJEU of 12 July 2024).

  2. The general provisions (Chapter I), the prohibitions on unacceptable-risk practices (Art. 5) and the AI literacy obligation (Art. 4) apply.

  3. Rules on GPAI models and governance (designation of national authorities and the penalty regime, Chapter XII / Art. 99).

  4. Obligations for “stand-alone” high-risk systems (Annex III).

  5. Obligations for high-risk systems integrated into regulated products (Annex I).

The original text of Art. 113 set 2 August 2026 (Annex III) and 2 August 2027 (Annex I). The “Digital Omnibus” simplification package replaced those deadlines with fixed, postponed dates (2 Dec 2027 / 2 Aug 2028), no longer conditional on the availability of harmonised standards. The same package also introduced a new prohibited practice under Art. 5 (generation of non-consensual intimate images — so-called “nudifiers” — and synthetic child sexual abuse material), with a transitional regime until 2 December 2026 — ⚠️ [to verify] the exact wording and scope of that prohibition against the text published in the OJEU.

Council of the EU, press release 29/06/2026 · European Parliament 16/06/2026 · Reg. (EU) 2024/1689, Art. 113

07 · Competent authorities

AI Office and AI Board at EU level; national authorities

  • European AI Office (AI Office) within the European Commission — supervision of GPAI.
  • European Artificial Intelligence Board (AI Board).
  • At national level each Member State designates its own competent authorities (notification + market surveillance). For Italy the designation is made by Law 132/2025 (AgID and ACN — see the dedicated card).

EUR-Lex · Reg. (EU) 2024/1689 (Chapter VII — Governance)

08 · Status

In force since 1 August 2024, timetable being updated

The application timetable was amended by the “Digital Omnibus” package, definitively approved by the European Parliament (16 June 2026) and the Council of the EU (29 June 2026); as at the date of this card, publication in the OJEU and the entry into force of the amendments are ⚠️ [being finalised — verify publication]. The high-risk application dates indicated above (2 Dec 2027 / 2 Aug 2028) are those of the timetable currently in force.

EUR-Lex · Reg. (EU) 2024/1689, Art. 113

09 · Relationship with other rules

It adds to Law 132/2025; it operates “without prejudice to” the GDPR

  • ↔ Law 132/2025 (Italy): the Italian national law adds to the AI Act, it does not replace it; it designates its national authorities and adapts the domestic legal order.
  • ↔ GDPR (Reg. EU 2016/679): the AI Act applies “without prejudice to” the GDPR; the processing of personal data remains governed by data-protection law, which operates in parallel.
  • ↔ ISO/IEC 42001: a voluntary standard (AI Management System). It is not law, but adopting a compliant management system can support the demonstration of compliance and the internal governance required by the AI Act.

EUR-Lex · Reg. (EU) 2024/1689 (interface clauses with the GDPR)

10 · Official source

EUR-Lex — ELI identifier

Primary source to cite: EUR-Lex, ELI identifier. Published in the OJEU, L series of 12 July 2024.

Open the official source on EUR-Lex

Primary source · EUR-Lex (ELI reg/2024/1689)

NomotecnIA reading · interpretation, not source

Fields 11–12 · our own synthesis

Our reading for an SME.

Summary

  • The AI Act is a directly effective regulation: an Italian SME is required to comply with it even without any national act of transposition.
  • The operational question is not “do I develop AI?” but “what is my role and which risk class does the system I use fall into?”. Most SMEs are deployers (users), not providers: the heaviest obligations (high risk) fall mainly on providers, but the deployer still has duties of its own.
  • The first deadlines are already in effect: prohibitions (Art. 5) and AI literacy (Art. 4) since 2 February 2025. AI literacy is a cross-cutting obligation often underestimated by SMEs.
  • The critical juncture for high risk is now 2 December 2027 (Annex III); for AI integrated into products, 2 August 2028.
  • The extraterritorial scope (output used in the EU) makes the Regulation relevant also to non-EU providers in the SME's value chain.

Practical obligations for a deployer / SME

  1. Map the AI systems used in the business and classify their risk (prohibited / high / limited / minimal).
  2. Check the prohibitions (Art. 5): immediately rule out prohibited uses (e.g. social scoring, emotion recognition in the workplace in the prohibited cases).
  3. AI literacy (Art. 4): ensure an adequate level of competence among the staff who use the AI systems — documented training.
  4. For high-risk systems where you are a deployer: use the system in accordance with the provider's instructions, ensure human oversight, keep the logs, inform the workers concerned.
  5. Transparency (Art. 50): inform users when they interact with an AI (e.g. a chatbot) and label synthetic/deepfake content.
  6. Put in place internal governance and a register of AI systems; consider the voluntary adoption of ISO/IEC 42001 as a readiness framework.

Positioning note (NomotecnIA): NomotecnIA provides orientation and readiness activities towards compliance. NomotecnIA is not a notified body and does not issue AI Act conformity certifications.

Further reading

The articles that cite this rule.

Editorial Observatory · dated

Meta · fields 13–15

Revision, disclaimer, changelog, author and sources

Last updated · 2026-07-10

Disclaimer

This content is for information and general orientation purposes only; it does not constitute legal advice or an attestation of conformity. For any assessment the official source (EUR-Lex) always prevails. NomotecnIA is not a notified body.

  • #AIAct
  • #RegolamentoUE
  • #IntelligenzaArtificiale
  • #RiskBased
  • #GPAI
  • #Compliance
  • #GDPR
  • #ISO42001
  • #PMI

Changelog

Revision history

  1. 2026-07-06

    First publication — research verified against the official source and editorial review (CCO).

  2. 2026-07-10

    Editorial enrichment — added Further reading, credited author and list of sources; updated the “Digital Omnibus” timetable.

Author

Matteo Colacchio

CEO · AI Governance, NomotecnIA

Author profile →

LinkedIn: to be linked

Official sources

Where we verified

  • EUR-Lex (ELI) — Regulation (EU) 2024/1689 (AI Act): eur-lex.europa.eu/eli/reg/2024/1689primary source.
  • Council of the EU — press release of 29 June 2026 (“Digital Omnibus” package); European Parliament, 16 June 2026 — cited in fields 6 and 8 for the timetable update (publication in the OJEU being verified).
  • System reference: Art. 288 TFEU (directly applicable nature of the EU regulation).

Official source · EUR-Lex

From the rule to your business

Which AI Act obligations actually apply to your SME?

The AI Entry Assessment brings the Regulation down to your reality: a map of your systems, risk classification, gap analysis and a prioritised roadmap — with no duplicated obligations.