Company · Updated 15 September 2026

AI
Act.

What the European regulation on artificial intelligence provides, when it applies and what it means for the research, products and work of FISIT S.r.l., which operates under the Analytiko brand.

The regulation.

Regulation (EU) 2024/1689, known as the AI Act, lays down common rules for artificial intelligence systems placed on the market, put into service or used in the European Union. It entered into force on 1 August 2024 and applies in stages.

The rules are proportionate to risk. Some practices are prohibited. High-risk systems, for example those used in education, recruitment or with biometric data, must meet requirements on data, documentation, human oversight and accuracy. Other uses carry transparency obligations, and general-purpose AI models have rules of their own.

Obligations depend on the role. The provider develops a system and places it on the market under its own name; the deployer uses it under its own authority. A company that integrates a model developed by others into its own product is the provider of the system, while the obligations on the model remain with those who developed it.

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, in force since 27 July 2026, changed the timeline and some obligations, including the one on AI literacy.

Timeline.

  1. Entry into force

    Published on 12 July 2024, the regulation enters into force twenty days later.

    In force
  2. Prohibited practices and AI literacy

    The prohibitions in Article 5 and Article 4 on AI literacy apply.

    Applies
  3. General-purpose models and governance

    Obligations for providers of general-purpose AI models, supervisory authorities and penalties.

    Applies
  4. General application

    The general part of the regulation applies, including the transparency obligations in Article 50. The rules on high-risk systems have been postponed.

    Applies
  5. Synthetic content and new prohibitions

    Deadline for marking synthetic content from systems placed on the market before 2 August 2026. The prohibitions added in 2026 on realistic intimate content generated without consent and on child sexual abuse material apply.

    Upcoming
  6. High risk: Annex III

    Requirements for high-risk systems in the areas listed in Annex III, including biometrics, education, employment and access to essential services.

    Upcoming
  7. High risk: products

    Requirements for high-risk systems embedded in products covered by the legislation listed in Annex I, such as machinery, toys and medical devices.

    Upcoming

In Italy.

Law no. 132 of 23 September 2025, in force since 10 October 2025, complements the European framework with national provisions. It designates the Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN) as national authorities for artificial intelligence, without prejudice to the powers of the Bank of Italy, CONSOB and IVASS. It contains rules on the use of AI at work and in the intellectual professions, on copyright and on consent by minors, and creates the offence of unlawful dissemination of content generated or altered with AI systems (Article 612-quater of the Italian Criminal Code).

On 4 August 2026 the Council of Ministers gave final approval to two implementing legislative decrees. As of 15 September 2026 they have not yet been published in the Official Gazette.

What it
means
for us.

Four areas of our work on which the regulation has different effects.

  1. 01

    Research

    The regulation does not apply to systems developed and put into service for the sole purpose of scientific research and development (Article 2(6)), nor to research, testing and development activities before a system is placed on the market (Article 2(8)). Testing in real-world conditions is not covered by this exclusion. Other rules, starting with the GDPR, still apply.

    Phase 1 of MNEMOS is entirely in simulation and falls within this scope. Later phases involve physiological signals, which the Commission's guidelines treat as biometric data. For this reason, before any phase with participants we check how the system is classified against the prohibitions in Article 5 and the high-risk cases in Annex III, including emotion recognition, which is prohibited in workplaces and educational institutions.

    ReferencesArticles 2, 3 and 5 and Annex III of Regulation (EU) 2024/1689; Commission guidelines on prohibited practices (2025). MNEMOS progress.

  2. 02

    Products

    MurphFin and Cryterio integrate general-purpose AI models developed by third parties. For these systems FISIT is the provider; obligations on the models, such as the documentation to be given to those who integrate them, remain with their developers.

    If a function falls within the high-risk cases in Annex III, for example assessing the creditworthiness of natural persons, the obligations change: new functions are therefore assessed before release. Where a product interacts with people or generates text and images, the transparency obligations in Article 50 apply from 2 August 2026.

    ReferencesArticles 3, 25, 50 and 53 of Regulation (EU) 2024/1689.

  3. 03

    Recruitment

    In our selection processes an AI model can suggest an indicative score for open answers to a questionnaire. It receives only the text of the question and of the answer, and the final score is given by a person, as described in the Privacy Policy.

    Annex III, point 4, lists among high-risk systems those intended to evaluate candidates. The related obligations apply from 2 December 2027: by that date this function will be reviewed against those requirements.

    ReferencesAnnex III, point 4(a), and Article 6 of Regulation (EU) 2024/1689; Article 22 GDPR. Privacy Policy.

  4. 04

    Internal use

    We also use AI tools in our daily work, under two rules set in the Code of conduct: we do not enter confidential client, partner or research data into third-party services, and every output of a model is checked by a person.

    Article 4, as amended by the Omnibus, requires providers and deployers to take measures to support the AI literacy of their staff and of anyone operating the systems on their behalf, taking account of skills and context of use. The obligation applies to us too.

    ReferencesArticle 4 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. Code of conduct · Ethical principles.

Sources.

This page summarises the legal framework and how we apply it. It does not replace the text of the rules or legal advice.