Diritto al Digitale
Diritto al Digitale is the must-listen podcast on innovation law, brought to you by Giulio Coraggio, data and technology lawyer at the global law firm DLA Piper. Each episode explores the cutting-edge legal challenges shaping our digital world—from data privacy and artificial intelligence to the Internet of Things, outsourcing, e-commerce, and intellectual property.
Join us as we illuminate the legal frameworks behind today’s breakthroughs and provide insider insights on how innovation is transforming the future of business and society.
You can contact us at the details available on dlapiper.com
Diritto al Digitale
The EU AI Act from 2 August 2026: what actually applies and what to report to the board
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The Digital Omnibus has postponed the obligations on high-risk AI systems, but it has not modified the general date of application of the AI Act. As a consequence, as of the 2nd of August 2026, the enforcement powers on general purpose AI models, the transparency obligations under Article 50 and the entire sanctioning framework become fully enforceable.
In this episode of Diritto al Digitale, Giulio Coraggio, technology and data lawyer of the global law firm DLA Piper, reviews what is actually applicable as of today, the operational implications of the requalification from deployer into provider, what Regulation (EU) 2026/1744 has postponed to December 2027 and August 2028, and why the actual obstacle to compliance is not the legal text, but the absence of an allocated accountability. With a concrete five-point board paper for in-house legal functions.
📌 You can find our contacts 👉 www.dlapiper.com
Let's imagine that on Monday morning you receive a request for information from a supervisor at word, not an inspection, an email of three lines. Please provide a list of artificial intelligence systems used by your organization indicated. For each of them, the purpose, the owner, and the role performed by your company under the regulation. How much time would you need in order to reply? In my experience, the honest answer that I receive from Inhouse Link of Council is the following. I do not know because I'm not even aware of how many systems are in place. As of today, that in aid is possible. In this episode, we shall discuss the date of the 2nd of August 2026 and the misunderstanding growing around it. What becomes actually applicable under the UAI Act? What has been postponed because of the digital omnibus package? And above all, the operational implications for those who, within companies, have to translate all of this into decisions. I'm addressing in particular those of you who work in house since you are most likely the ones who have already flagged this issue internally and who now have to put it back on the agenda. On the 27th of July, the regulation 2026-1744, the so-called Digital Omnibus OAI, entered into force, amending the UAI Act just a few days before its main date of application. The intervention follows the so-called Draghi Report and the debate on European overregulation. The purpose was to simplify. The outcome for anyone who has to build a compliance plan is considerably more articulated. The point to be fixed is the following, and I would suggest to use it literally when you discuss the matter internally. The digital omnibus has postponed the obligations relating to high-risk AI systems. It has not, however, modified the general data application of the UAI Act, which remains the 2nd of August 2026. Both statements are true at the same time, and the mistake that I see spreading, including memoranda circulated by advisors, is the improper summary according to which the AAI Act has been postponed. This is not the case. Let's enter into the merit. As of the 2nd of August 2026, three matters change. Firstly, the enforcement powers of general purpose AI models. The EU Commission and the UAI office obtain the power to investigate and sanction the providers of general purpose AI systems with fines up to 15 million euro or 3% of the worldwide turnover. The substantive obligations applied already since August 2026. What is activated today is, however, is the sanctioning apparatus. Second point, the transparency obligations under Article 50 of the UAI Act become enforceable. I shall come back to them later, since they affect the largest number of organizations and even individuals. Thirdly, the whole sanctioning framework becomes operational, and national market surveillance authorities may enforce all the provisions already enforced. This includes also Article 5 on prohibited practices and Article 4 on AI literacy, applicable since February 2025, but so far without a fully active enforcement mechanism. It's now sufficient to adopt measures aimed at supporting its development, without guaranteeing a specific level. This is a real simplification, but not a repeal, and documenting the training initiatives remains the easiest manner to evidence compliance. In my view, Article 50 is the most underestimated obligation of this phase. For a structural reason, it does not presuppose a high-risk system, and therefore it remains outside the classification exercise that has absorbed most of the work of the last months. Let me summarize its scope, since this is a checklist that you may circulate to the business already from today. Those who provide systems intended to interact with natural persons shall ensure that the artificial network, the artificial network of the system is recognizable. Unless evident from the content, support, chatbots, voice agents, virtual assistants, and avatars shall have this kind of disclosure. Synthetic contents shall be labeled. AI-generated texts published in order to inform the public on matters of general interest shall be declared as such unless a natural person assumes the editorial responsibility. And those deploying emotion recognition of biometric or biometric categorization shall inform the individuals concerned. Two operational remarks, however. The machine readable marking under the second paragraph does not apply to the systems already placed on the market before today, for which the deadline is the 2nd of December 2026. On the contrary, the information towards individuals is enforceable immediately. The second remark is the argument that they usually raise with CFOs. What we are dealing with the least expensive compliance measure of the entire UAI Act. A line of text within an interface to defend before a board the failure to adopt a measure whose cost is one day of development is a position in which I would not like to be. This might remove from the high-risk perimeter more systems than one would expect. Therefore, it's advisable to review the classification performed before July. In any case, the postponement does not represent a relief. The technical documentation, the fundamental rights impact assessments, and the requalification of agreement of the agreements with suppliers require between 6 and 12 months of work. Moreover, the inventory that you shall need in December 2027 is exactly the one that an authority might request a very easier. And here I come to the reason for which I wanted to record this episode. In my experience, obstacle is almost never the text of the regulation. You are familiar with the text, the obstacle is that with organizations, AI compliance does not belong to anyone. Either it's spread among legal, IT, security, procurement, marketing, and the business lines, with each of them assuming that somebody else will be dealing with it. Or, and this is the more insidious variant, since it has the appearance of a solution, it's entirely allocated to the IT department, which maps the systems and implements the controls. An essential contribution. But it is not the function equipped in order to determine whether a used case falls under Annex 3, whether a fine-tuning has led to a requalification, or whether a disclosure under Article 50 is legally adequate. There are legal qualifications taken by default by individuals who have never received such mandate. I've also mentioned two arguments that I assume you have already heard since I hear them constantly. First one, but these systems are used by everyone. This is the most frequent objection and also the weakest. The circumstance that a tool is widely adopted does not say anything about how the same is actually used within your organization, on which the data has been trained and which function is performed. Moreover, the widespread breach of an obligation does not consider the justification. On the contrary, it increases the likelihood of an intervention by the authority, and at that stage, somebody should beat the first case. Second argument is more subtle. A number of organizations select the tool with considerable rigor, due diligence on the supplier, negotiated agreement, preliminary assessment, and then they do not monitor anymore how the system is used within your organization. The system is introduced for a given purpose and then six months later it's serving a different one. Nobody has taken such decision. Compliance is not assessed on the basis of the purchase agreement, it's assessed on the basis of the actual use. And that the actual use within a considerable number of organizations is not monitored by anyone. If this description sounds familiar, the issue is not yours, but the solution passes through you, since you are the only function having visibility both on the legal risks and on the decisions making process. Let me conclude with that. Very pragmatically, I would suggest to include in a board paper due in the coming weeks. Number one, the inventory of AI systems in use, including shadow AI, the purpose, the owner, and the role performed by the organization. Everything else depends on it, as well as your ability to reply to a request from an authority. 2. The formal allocation of the responsibility, an AI committee with a defined mandate, an escalation path, and a minutes decisions involving legal, IT compliance, audits, UAD, and the business. We have dedicated a specific episode of this podcast to this uh establishment. Number three, the assessment under article 5 and 50, which has the closest deadline and the lowest cost. So we're talking about the labeling, the disclaimers that need to be present when an AI system is interacting with an individual. Number four, the assessment of the potential re-qualifications that means of the exercise on the projects of the last year. So re-qualification between a deployer and a provider. Number five, the launch of the high-risk work stream to be justified before the board on the basis of the time required rather than the deadline. And above all, please document the decisions taken during an inspection, a dated record of what has been assessed and of why a given option has not been pursued is worth considerably more than an impeccable policy that nobody has applied. The question that I would raise before any board of directors and that I suggest you do raise yourself is a very short one. Is there anyone with a name or and a surname accountable for AI compliance within this organization? If the answer requires more than a moment, that is the first item of the agenda. So just to conclude, the 2nd of August 2026 is not the compliance cliff that the market was expecting. It's the moment in which the enforcement begins in relation to the obligations that have been silently accumulating since February 2023. For organizations, having an accountable function, the matter is manageable, and under several aspects, it represents a competitive advantage towards clients and partners that are beginning to request at the contractual stage. For the others, the postponement to December 2027 shall pass exactly in the same manner as the last 18 months.com. Thank you for listening. Arrivederci