The dual track: AI Act and Law 132/2025 for SMEs
Why an Italian SME must comply with both regimes — European and national — and how to oversee them with a single governance.
In short: yes. Regulation (EU) 2024/1689 is directly applicable in Italy with no national transposition and follows a risk-based approach. The question is not “do I develop AI?” but “what is my role and which risk class does the system I use fall into?”. Most SMEs are deployers (users). Below are the facts verified against EUR-Lex, then our reading.
The facts · fields 1–10
01 · Name
“Regulation of the European Parliament and of the Council, of 13 June 2024, laying down harmonised rules on artificial intelligence and amending a number of regulations and directives”. Common short name: AI Act (or AI Regulation / RIA).
EUR-Lex · ELI reg/2024/1689
02 · Type of source
An EU legislative act of general application, adopted by the European Parliament and the Council under the ordinary legislative procedure.
EUR-Lex · Reg. (EU) 2024/1689
03 · Nature
As an EU regulation (Art. 288 TFEU) it is binding in its entirety and directly applicable in every Member State, with no need for national transposition. It is not soft law: it lays down legal obligations and a penalty regime.
Art. 288 TFEU + the text of the Regulation on EUR-Lex
04 · Subject matter
It establishes a harmonised legal framework for the placing on the market, putting into service and use of AI systems in the EU, following a risk-based approach: unacceptable risk → prohibited; high risk → stringent obligations; limited risk → transparency obligations; minimal risk → unrestricted. It includes specific rules for general-purpose AI models (GPAI).
EUR-Lex · Reg. (EU) 2024/1689
05 · Who it applies to
Personal scope: providers, professional deployers/users (deployers), importers and distributors of AI systems, as well as product manufacturers. Territorial scope is extraterritorial: it also applies to entities established outside the EU when the system is placed on the EU market or when the output produced is used within the Union.
EUR-Lex · Reg. (EU) 2024/1689 (Art. 2 — scope)
06 · Key dates
Entry into force (the 20th day after publication in the OJEU of 12 July 2024).
The general provisions (Chapter I), the prohibitions on unacceptable-risk practices (Art. 5) and the AI literacy obligation (Art. 4) apply.
Rules on GPAI models and governance (designation of national authorities and the penalty regime, Chapter XII / Art. 99).
Obligations for “stand-alone” high-risk systems (Annex III).
Obligations for high-risk systems integrated into regulated products (Annex I).
The original text of Art. 113 set 2 August 2026 (Annex III) and 2 August 2027 (Annex I). The “Digital Omnibus” simplification package replaced those deadlines with fixed, postponed dates (2 Dec 2027 / 2 Aug 2028), no longer conditional on the availability of harmonised standards. The same package also introduced a new prohibited practice under Art. 5 (generation of non-consensual intimate images — so-called “nudifiers” — and synthetic child sexual abuse material), with a transitional regime until 2 December 2026 — ⚠️ [to verify] the exact wording and scope of that prohibition against the text published in the OJEU.
Council of the EU, press release 29/06/2026 · European Parliament 16/06/2026 · Reg. (EU) 2024/1689, Art. 113
07 · Competent authorities
EUR-Lex · Reg. (EU) 2024/1689 (Chapter VII — Governance)
08 · Status
The application timetable was amended by the “Digital Omnibus” package, definitively approved by the European Parliament (16 June 2026) and the Council of the EU (29 June 2026); as at the date of this card, publication in the OJEU and the entry into force of the amendments are ⚠️ [being finalised — verify publication]. The high-risk application dates indicated above (2 Dec 2027 / 2 Aug 2028) are those of the timetable currently in force.
EUR-Lex · Reg. (EU) 2024/1689, Art. 113
09 · Relationship with other rules
EUR-Lex · Reg. (EU) 2024/1689 (interface clauses with the GDPR)
10 · Official source
Primary source to cite: EUR-Lex, ELI identifier. Published in the OJEU, L series of 12 July 2024.
Open the official source on EUR-Lex
Primary source · EUR-Lex (ELI reg/2024/1689)
Fields 11–12 · our own synthesis
Positioning note (NomotecnIA): NomotecnIA provides orientation and readiness activities towards compliance. NomotecnIA is not a notified body and does not issue AI Act conformity certifications.
Further reading
Why an Italian SME must comply with both regimes — European and national — and how to oversee them with a single governance.
How the voluntary standard builds the governance backbone that the AI Act requires anyway. A bridge, not a shortcut.
The “without prejudice to the GDPR” clause and the two cumulative tracks: complying with the AI Act does not exempt you from data-protection compliance.
From the rule to your business
The AI Entry Assessment brings the Regulation down to your reality: a map of your systems, risk classification, gap analysis and a prioritised roadmap — with no duplicated obligations.