AI Act

EU Regulation 2024/1689 (AI Act) is the first comprehensive AI law worldwide. It adopts a risk-based approach: prohibited practices (subliminal manipulation, social scoring, public-space biometric identification), high-risk systems (employment, credit, education, critical infrastructure, justice), GPAI models (general-purpose) with stricter rules for models with systemic risk, and limited/minimal-risk systems subject only to transparency.

Timeline: February 2025 (prohibited practices), August 2025 (GPAI + governance), August 2026 (high-risk Annex III), August 2027 (Annex I). Sanctions reach up to EUR 35 million or 7% of global turnover.

LX20 supports Italian businesses with AI portfolio mapping by risk level, compliance for high-risk systems (quality management, data governance, logs, conformity assessment, CE marking), contracting with GPAI vendors, DPIA and the interaction with GDPR and the Data Act.

Related practices

Frequently asked questions

Does the AI Act apply to SMEs?

Yes, but with simplified regimes: national sandboxes at reduced cost, documentation templates and priority queues at notified bodies.

When does it apply?

In force from 1 August 2024. Staggered application: 2025 (prohibited + GPAI), 2026 (high-risk Annex III), 2027 (Annex I).

What is a high-risk system?

An AI system used in sensitive areas (employment, credit, education, justice, critical infrastructure, biometrics) or as a safety component of regulated products (Annex I).

What is a GPAI with systemic risk?

A general-purpose foundation model trained with > 10^25 FLOP compute or designated by the Commission: enhanced obligations on evaluation, mitigation and cyber.

Must I appoint an AI compliance officer?

Not nominally required, but high-risk systems demand a quality management system with clear responsibilities.

Do AI Act and GDPR overlap?

No, they are complementary. The AI Act governs the AI product; GDPR governs personal-data processing. High-risk systems require a DPIA.

What are the sanctions?

Up to EUR 35m or 7% of global turnover (prohibited); EUR 15m or 3% (high-risk); EUR 7.5m or 1.5% (incorrect information).

Can I use ChatGPT at work?

Yes, but you need internal policies on transparency, input data, output review and vendor contracts (DPA + GPAI addendum).

What is an AI sandbox?

A regulated environment by AgID/MIMIT to test high-risk AI systems before market launch, with structured dialogue with the regulator.

EU Reg. 2024/1689, GPAI, high-risk AI systems, AI Office, AI sandbox

LX20
Caricamento…