Avv. Jawad Asmahi – Lawyer in Italy and Spain, expert in AI Law, Privacy and Technology Law
Artificial intelligence is no longer a subject for futurists: today it is a central tool in corporate decision-making processes, in customer services, in human resources management, in finance, in healthcare. For this reason, the European legislator has decided to regulate its use in a systematic and binding way with the AI Act, the first Regulation in the world entirely dedicated to the responsible and safe use of artificial intelligence.
The text was finally approved in 2024, entered into force in 2025 and will become fully applicable in August 2026. During this time, companies must adapt to the new compliance obligations.
Who does the Regulation apply to?
The Regulation applies to those who:
- develops AI systems (even outside the EU, if marketed in Europe);
- integrates them into its own products or services (e.g. an AI-powered CRM);
- uses them for operational purposes (e.g. CV screening, customer profiling, credit scoring).
It is therefore the registered office of the company is irrelevant: what matters is whether the AI is intended for the European market or has an impact on people in the EU.
Risk categories: the heart of the system
The Regulation classifies AI systems into four categories based on the level of risk to fundamental rights:
❌ Prohibited systems (unacceptable risk)
These are technologies that violate human dignity or fundamental rights, such as:
- social classification of people (such as “social credit score”),
- real-time biometric identification in public spaces (with exceptions),
- subliminal manipulation of behavior.
⚠️ High risk systems
They are allowed, but only if they comply with stringent requirements for security, transparency and human control. This includes:
- AI used in healthcare (e.g. automated diagnosis),
- justice and jurisprudence (e.g. predictive systems),
- finance and credit (e.g. credit assessment),
- work environment (e.g. automatic personnel selection systems),
- critical infrastructure, transportation, education, surveillance.
ℹ️ Limited risk systems
They require transparency towards the user, such as chatbots, virtual assistants or generative software (e.g. images, texts, audio generated by AI). The user must know that he is interacting with a machine.
✅ Low or zero risk systems
They are free from constraints, but it is still advisable to adopt good practices to avoid indirect compliance risks (e.g. data protection, cybersecurity).
Main obligations for businesses
Anyone who develops or uses systems high risk will have to fulfill a series of documentary and technical obligations, including:
- Risk assessment ex ante and constant updates;
- Technical documentation detailed information on how the system works;
- Data traceability used for training and validation;
- Human supervision automated processes;
- Registration in the European database of AI systems;
- Management of complaints and malfunction reports.
For companies that integrate “off-the-shelf” AI, careful consideration will still be necessary compliance check with shared responsibility with the supplier (co-responsibility).
Sanctions and responsibilities
The Regulation provides for sanctions very high, similar in structure to those of the GDPR:
- until 35 million euros or 7% of the global annual turnover, for the use of prohibited systems;
- until 15 million euros or 3% of turnover, for violations of obligations on high-risk systems;
- until 7.5 million euros for misleading or incomplete communications.
Furthermore, in case of damage caused by faulty AI systems, the new European framework on civil liability for damage caused by AI, the implementation of which is underway.
How to Prepare: Compliance Is Not Just an Obligation
Complying with the AI Act is a process that involves multiple business functions, not just the IT department. An integrated approach is needed between:
- legal (for regulatory analysis and preparation of documentation),
- technician (for the implementation of the requirements in the system),
- organizational (for internal training and risk management).
A well-structured compliance can become a competitive advantage: transparency, accountability and compliance are today decisive factors for accessing regulated markets, European tenders, technological partnerships and ESG investments.
Turning to industry experts allows the companies involved to comply with the required compliance, avoiding the sanctions provided for by the AI Act and providing a service to customers in compliance with European regulations.