STATE OF PLAY — AI
AI Act state of play
The AI Act does not start all at once, and the distinction that matters is between AI in your processes (what you use in the business) and AI in your product (what you embed in a machine or a device). Here is where it stands: the dates that matter, the status of the harmonised standards and of the Italian authorities. A page kept up to date — for the detailed operational timeline see the guide the AI Act deadlines.
Last updated: 26 August 2026
What is happening now
CEN-CENELEC harmonised standards (JTC 21)
These are the standards that will grant a presumption of conformity with the high-risk requirements. Committee JTC 21 is working on the Commission’s standardisation request: teams designing AI to embed in a product should track them, since they will become the common language of compliance — just like the product standards for the CRA.
Art. 40Commission guidelines on high-risk classification
The Commission must publish practical guidelines on applying Article 6, with concrete examples of what is and is not high-risk. For an industrial manufacturer this is the tool that will clear up the borderline cases: is an AI component in a machine always a "safety component"? The actual publication date is to be confirmed.
Art. 6(5) · Art. 96Italian national authorities designated
Italy’s national AI law (Law 132/2025) assigns the roles the AI Act requires to AgID (notifying authority) and ACN (market-surveillance authority). This is the institutional reference an Italian company will deal with for notifications, controls and notified bodies.
Art. 70 · L. 132/2025AI regulatory sandboxes
Each Member State must have at least one regulatory sandbox operational by 2 August 2026: a controlled environment to develop and test innovative AI systems under the authority’s guidance. For an industrial SME it is a channel to validate high-risk AI solutions before placing them on the market.
Art. 57The dates that matter
1 August 2024
The regulation enters into force
The AI Act is in force, but almost no obligation applies straight away: application is staggered over several years. The dates below are when the obligations actually begin to bite.
Art. 1132 February 2025
Prohibited practices and the AI literacy duty
Prohibited practices (Art. 5) are outlawed and the AI literacy duty (Art. 4) is already live: anyone developing or using AI systems must ensure an adequate level of competence in the people who operate them. This is not a 2027 deadline — it is already today, and it also covers AI used in-house.
Art. 4, 52 August 2025
GPAI models, governance and penalties
The obligations for general-purpose AI (GPAI) models, the governance framework, the notifying authorities and the penalty regime apply. For an industrial manufacturer this matters mostly upstream: if you integrate a third-party GPAI model into your product, its transparency and documentation duties flow into your chain too.
Art. 113(b) · Capi V, VII, XII2 August 2026
AI in your processes: Annex III high-risk
Most of the regulation applies, including the obligations for the high-risk systems listed in Annex III (Art. 6(2)). This is the AI you use in your processes, not in your product: recruitment, worker management, access to essential services. A manufacturer is exposed here even without selling any AI — simply from how it uses AI internally.
What you must have done
Map where you use AI in your internal processes and check whether it falls under Annex III (recruitment and worker management, access to essential services). For high-risk systems: risk management, data governance, human oversight, technical documentation and registration. You are exposed by how you use AI in the business, even without selling it.
What to expect next: 2 August 2027: the Article 6(1) high-risk tier — AI embedded in the product.
Art. 113 · Art. 6(2) · Allegato III ↗2 August 2027
AI in your product: Article 6(1) high-risk
The Article 6(1) obligations kick in: an AI system is high-risk when it is a safety component of — or is itself — a product covered by the Annex I harmonisation legislation (Machinery Regulation, RED, medical devices and others) and subject to third-party conformity assessment. This is the pivotal date for anyone embedding AI in a machine or a device: it hooks onto the CE marking you already know. The same date also applies to GPAI models placed on the market before August 2025, which must come into compliance.
What you must have done
If you embed AI as a safety component in a product already subject to CE marking (Machinery Regulation, RED, medical devices): treat it as a high-risk function within your existing conformity assessment — risk-management system, data and traceability, human oversight, robustness and cybersecurity, technical documentation. It hooks onto the CE route you already follow; it is not a separate track.
What to expect next: The publication of the harmonised standards (JTC 21) that will grant a presumption of conformity, and the Commission’s guidelines on the Article 6 borderline cases.
Art. 6(1) · Art. 111(3) · Allegato I ↗2 August 2030
Legacy public-sector systems must comply
High-risk systems already in use by public bodies before the deadlines must be brought into compliance. It concerns the public sector above all, but marks the point where legacy systems too come into scope: worth keeping in mind for public-sector supply.
Art. 111(2)An editorial reconstruction for information only, current as of the date shown: not advice and not an official source. Always verify dates and statuses against Regulation (EU) 2024/1689 and the sources of the Commission, the AI Office and the Italian authorities (AgID, ACN).
Not sure where to start?
45 free minutes to map your regulatory exposure and know what you must have done for each deadline.
Book the Regulatory Spark