---
title: "EU AI Act: compliance guide for deployers (2026) | Volcanic Minds"
description: "EU AI Act, Digital Omnibus and Law 132/2025: what applies to deployers from August 2, 2026 and why high-risk duties move to 2027-2028."
url: "https://volcanicminds.com/en/eu-ai-act"
lang: "en"
type: "first_level_page"
updated: "2026-09-02"
alternate: "https://volcanicminds.com/eu-ai-act"
---

# EU AI Act: why compliance is a code problem, not a paperwork problem

From August 2, 2026 transparency, governance, penalties and the powers of national authorities apply, while the Digital Omnibus moves the obligations on high-risk systems to 2027-2028. Italy - with Law 132/2025 already in force and implementing decrees on the way - is building a regime of criminal and corporate liability for those releasing AI systems without oversight.

## The August 2, 2026 deadline and the Italian path to compliance

The AI Act is already partially in effect. EU Regulation 2024/1689, as amended by EU Regulation 2026/1744.

The prohibitions apply from February 2025. From August 2, 2026 transparency, governance, penalties and the powers of national authorities apply, while the obligations for high-risk systems move to December 2, 2027 for Annex III and August 2, 2028 for Annex I, under Regulation (EU) 2026/1744 (the Digital Omnibus), in force since July 27, 2026.

A common misconception is that the regulation only affects those who _create_ the base models (OpenAI, Anthropic). The reality is different: the Regulation directly affects **deployers** - that is, those who _use_ an AI system under their own responsibility in business processes (Art. 3(4)). They are required to ensure human oversight, logging, and compliant use (Art. 26).

## How to apply it in our case

In Italy, the framework should be read on two levels.

### Already in force.

Law 132/2025 (in force since October 10, 2025) has _directly_ introduced new criminal offenses related to AI, including the crime of unlawful dissemination of content generated or altered with AI (art. 612-quater c.p., deepfake) and a common aggravating factor for crimes committed through Artificial Intelligence systems (art. 61 no. 11-decies c.p.).

### On the way.

On June 10, 2026, the Council of Ministers approved _in preliminary review_ (Press Release no. 177) two draft implementing decrees, government acts no. 418 and no. 421. As of September 2026 they are still under parliamentary review and have not been published in the Official Gazette: the deadline for adoption is October 2026. The drafts assign oversight to two authorities: AgID as the notification authority, ACN as the market supervision and data security authority.

## What the draft decrees are about to put on the table

### A new crime (proposed art. 437-bis c.p.)

Failure to implement security measures in high-risk AI systems, where the omission of technical barriers or human oversight leads to a **concrete danger** for people or public safety. Criminal liability is not "automatic for top management": it falls on those who actually failed to put in place the required measures, with intent or gross negligence.

### Extension of D.Lgs. 231/2001 (proposed art. 25-vicies)

The offense could become a predicate crime for _corporate administrative liability_, with financial and prohibitive sanctions: this is where the risk affects the company as an entity.

### Automated workplace decisions

The drafts prohibit entrusting _solely_ to an algorithm the decisions on hiring, dismissal, and disciplinary measures, reserving the final decision to a human being; for dismissals made in violation, nullity is expressly provided.

⚠️ **Status of the process (updated September 2026)**

As of September 2, 2026 the two drafts (government acts no. 418 and no. 421) are still under parliamentary review and have not been published in the Official Gazette. The points therefore come from decrees **in preliminary review**, **not yet in force**. The information reflects the regulatory status at the indicated date, does not replace legal advice and we will update it once the final texts are published in the Official Gazette.

## The "easy" compliance bluff

Our position is clear

True AI Act compliance is not about filling in a PDF or purchasing a compliance dashboard license. The list of theoretical obligations must be transformed into practical actions which the IT team must translate and implement to avoid penalties.

And the AI Act's penalties are progressive: up to **3% of global turnover or €15M** for obligations on providers and deployers, up to **7% or €35M** for those adopting prohibited practices. Every non-architectural shortcut is a debt that comes due at an ACN inspection.

Compliance with the AI Act is not an _after-the-fact_ administrative activity. It is a **non-functional requirement of the architecture**. It must be anticipated and written into the code, otherwise — without architecture — it’s technical-regulatory debt.

## We'll help you implement the law.

Compliance by Design

### Guardrail Engineering (Art. 15 - accuracy, robustness, cybersecurity.)

Deterministic validation systems upstream and downstream of LLM calls, to drastically reduce the risk of agents hallucinating data, deviating from policies or producing non-compliant output.

### LLM Observability & immutable tracking (Art. 12 - record-keeping).

Runtime control plans that record every operation performed by agent systems immutably — context, tokens, decision steps, result — so that in the event of an audit (AgID/ACN), the company can provide intact, traceable, and explainable logs (explainability).

### Human-in-the-Loop Architectures (Art. 14 - human oversight.)

UX and logic engineered so high-risk decisions prepared by AI require formal validation from a qualified operator, recorded in compliance with Art. 26.

### Data sovereignty and proprietary code (No vendor lock-in.)

100% proprietary solutions for the client, on private/on-premise infrastructure and controlled open-source models. By design, no data leaves externally or is sent to third parties.

## Do you want to know where you're really exposed?

With a **free analysis**, we map your AI systems to the 4 pillars - Guardrails, Observability, Human-in-the-Loop, Data Sovereignty - and deliver your top priority gaps with respect to AI Act obligations. No strings attached.

## We've already done it

Our AI Auditing use case

Not theory. In our portfolio is the Advanced Auditing Agentic AI Platform: a multi-tenant system designed to conduct complex audits, manage the knowledge base in a controlled way and mitigate hallucinations. In practice, all knowledge remains federated and the AI cannot leave the boundaries of the designed domain. The harness is not just good engineering practice: it's a fundamental requirement.

## Some clarifications to help you understand what’s happening

Questions about the EU AI Act

### Who is a "deployer" under the AI Act?

The natural or legal person who _uses_ an AI system under their authority in the course of their professional activity (Art. 3(4)) - distinct from the provider who develops it and the distributor who makes it available.

### What changes on August 2, 2026?

The transparency obligations, the governance framework, the penalty regime and the powers of national authorities take effect. The obligations for high-risk systems, instead, have been postponed by Regulation (EU) 2026/1744 (the Digital Omnibus): December 2, 2027 for Annex III systems, August 2, 2028 for Annex I systems. Prohibitions are already active from February 2025; obligations on GPAI models from August 2025.

### What penalties does a company face?

Three levels: up to €35M/7% of turnover for prohibited practices; €15M/3% for violation of other obligations; €7.5M/1% for incorrect information to authorities.

### Is the Italian regulation already in force?

Law 132/2025 is (since October 10, 2025). The implementing decrees introducing the new AI safety offense and 231 liability are still drafts under parliamentary review (checked September 2026), not yet law.

### Which official documents and institutional sources do you refer to?

Transparency is one of our values: every legal statement in the text has been drawn from a source in the following list.

However, **we encourage you to check** directly from the source for correct interpretation, for any changes and updates, or for incorrect interpretations. The importance and understanding of these topics is vital, so for further details consult professionals.

1. **Regulation (EU) 2024/1689 (AI Act)** - [eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689)
1. **Regulation (EU) 2026/1744 (Digital Omnibus)** - [eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1744)
1. **Law 23 September 2025, no. 132** - [gazzettaufficiale.it](https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00143/sg)
1. **Press release of the Council of Ministers no. 177 (10 June 2026)** - [governo.it](https://www.governo.it/it/articolo/comunicato-stampa-del-consiglio-dei-ministri-n-177/32050)
1. **AI Act - European Commission** - [digital-strategy.ec.europa.eu | Digital Strategy](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)
1. **European AI approach - European Commission** - [digital-strategy.ec.europa.eu | EU Approach AI](digital-strategy.ec.europa.eu)

[Frequently Asked Questions]

**_Disclaime**r_

_Informational and engineering-focused content. The information reflects the regulatory status at the date of update (see the sources listed in the FAQ on this page for more details) and does not represent legal advice. The content of this page, however thoroughly checked, may contain errors or incorrect interpretations. For actual evaluations and/or specific cases talk to a qualified professional, or call us and we’ll involve one toget_her.

**_Last update: September 2026**._

## Want to discover the real impact of our solutions?

Don’t leave your AI compliance up to chance or a typical 80-page PDF. The adoption of AI must not be slowed down by bureaucracy, turned into an additional cost, or become a legal gamble: we build agentic systems that are stable, secure, and compliant from the first line of code. Clear ideas, clear business.
