AI Act Postponed to 2027-2028: Why Italian SMEs Must Not Stand Still After the Omnibus Agreement of 7 May
Ai Consulting Digital

AI Act Postponed to 2027-2028: Why Italian SMEs Must Not Stand Still After the Omnibus Agreement of 7 May

On 7 May 2026 the EU Council and the European Parliament moved the obligations on high-risk AI systems to December 2027. But in Italy Law 132/2025 remains in force, the ACN is watching and watermarking arrives in December. What really changes for those already using AI tools in their processes.

A126 Team 9 min read

News that looks like good news

On the morning of 7 May 2026, at 4:30 am, the EU Council and the European Parliament closed a six-month negotiation on the Omnibus package dedicated to the AI Act. The outcome, published a few hours later, was a collective sigh of relief for many companies: the most feared deadlines have been postponed by years. The obligations on high-risk AI systems under Annex III, due to kick in on 2 August 2026, slip to 2 December 2027. Those for AI built into regulated products under Annex I move to 2 August 2028. The only near-term deadline that remains is the watermarking of AI-generated content, put back by just four months to 2 December 2026.

For large enterprises with structured legal teams, the postponement is simply an organisational relief. For Italian SMEs the situation is more complicated than the headlines make it look. Because while Europe brakes, Italy has already accelerated: Law 132 of 10 October 2025, approved ahead of European enforcement, introduced national requirements on artificial intelligence that go beyond those of the AI Act, and which remain binding regardless of what happens in Brussels.

The result is a picture many entrepreneurs have not yet brought into focus: a partly overlapping dual regime, a national supervisory authority already active, some near-term deadlines that remain, and a hidden tax in the form of repeated consultancy and projects redone several times. Understanding what the postponement really means for those using AI tools in their business processes is the key issue of the coming weeks.

What has been postponed and what hasn’t

The Omnibus package of 7 May intervenes surgically on three deadlines. The most important is 2 August 2026, the date on which the full obligations would have kicked in for AI systems classified as “high-risk” under Annex III: recruitment software, credit scoring systems, AI used in product safety, healthcare, critical infrastructure, justice. These obligations include conformity assessment, the CE marking, detailed technical documentation, qualified human oversight, registration in European databases. It’s the heaviest regulatory block in the entire regulation, and the one that generated the most anxiety among Italian companies.

The second deadline moved concerns AI systems built into regulated products under Annex I (machinery, medical devices, toys, vehicles). These obligations too have been postponed by two years, to 2 August 2028.

The third deadline, on the watermarking of AI-generated content, has instead been moved by only a few months, from 2 August to 2 December 2026.

What the Omnibus package did not touch is equally important. The AI literacy obligation under Article 4 has been in force since 2 February 2025: any company using AI systems must ensure its staff have a “sufficient level of literacy” regarding the risks and the correct uses. The bans on unacceptable-risk AI practices (indiscriminate biometric recognition, social scoring, subliminal manipulation) have been active since the same 2 February 2025. The rules on general-purpose AI models have been operational since 2 August 2025. The penalties provided for under Article 99 — up to 35 million euros or 7% of global turnover for the most serious infringements — remain around the corner for the parts of the regulation already applicable.

What “watermarking” means and why it’s the most urgent deadline

The term watermarking translates literally as “filigrana”, like the one on banknotes. Applied to artificial intelligence, it refers to a system for recognisably marking every piece of AI-generated content, so that whoever sees or reads it can tell it was created not by a person but by a machine. It’s the European regulatory response to the risk of deepfakes, fake reviews, synthetic advertising images passed off as real photographs, journalistic articles written by AI without declaring it.

Watermarking works on two levels that must be provided for together. The first is the visible watermark, the one the user sees directly: a caption beneath an AI-generated photo, a disclaimer at the foot of an article written with AI support, a notice before an interaction with a chatbot declaring that there’s an automated system on the other side, not a person. The second is the invisible watermark, or machine-readable: hidden metadata inside the file that the user can’t see with the naked eye, but which other software, search engines or social platforms recognise automatically. An image generated by Midjourney, for example, today already contains invisible metadata declaring its artificial origin.

For an Italian SME this obligation touches all content generated with AI tools: marketing text (blog posts, product descriptions, sales emails, social posts), promotional images created with generators such as Midjourney or DALL-E, corporate videos made with tools such as Sora, synthetic voiceovers, and chatbots published on the website. From December 2026 each of these pieces of content will have to be labelled in a compliant way. The penalties for failing to be transparent reach up to 15 million euros or 3% of global turnover.

The critical point is that watermarking isn’t solved by writing “created with AI” by hand beneath a post. To be compliant you need technical automation: a system that inserts the hidden metadata into the generated files, a register tracking which content was produced, by which tool and when, uniform labelling across all company channels (website, social media, newsletter), and integration with the website’s CMS and with publishing tools. An SME that publishes even just fifty social posts a month and twenty marketing emails cannot label them manually: it needs a structured technical workflow.

This is the only near-term deadline left after the Omnibus package, and probably the least discussed in the specialist media. For companies doing digital marketing, e-commerce or customer management with AI support, December 2026 is much closer than it seems.

The Italian scenario: Law 132/2025 changes the picture

The part many entrepreneurs have not yet absorbed is that Italy isn’t waiting for Europe. On 10 October 2025 Law 132/2025 was published, transposing and specifying the AI Act in the Italian context by introducing additional national elements. Three things matter in particular: the law designates the ACN (National Cybersecurity Agency) as the national supervisory authority; it introduces specific transparency obligations for public administration; and it requires qualified human oversight in healthcare and justice, as well as impact assessments for all AI systems used in public decision-making processes.

The ACN is already fully operational as the competent authority. In the event of an inspection or report, it’s to the ACN that you answer. The fact that the European obligations on high-risk have been postponed doesn’t move the Italian requirements by a single day; they remain binding. An Italian company working for the public administration or in critical sectors therefore finds itself under active national supervision while the European one goes into stand-by.

The figures on AI adoption in Italy make the picture even more relevant. According to ISTAT 2025 data, 16.4% of Italian companies with at least ten employees already use at least one artificial intelligence technology, a growth of 8.2% on 2024. Among SMEs the figure is 15.7%, against 53.1% for large enterprises. Most of these companies use AI in ways that nonetheless require compliance: ChatGPT to generate sales emails, Microsoft Copilot built into the Office suite, chatbots on websites, order-management automations, predictive analytics systems. None of these uses is exempt from the obligations of literacy, transparency towards users and risk management.

The three traps of the postponement for Italian SMEs

The Omnibus package, presented as a common-sense measure to avoid an unsustainable burden, contains three traps that hit SMEs particularly hard.

The first trap is the illusion of time gained. An SME thinking today “we’ve got two more years” is underestimating the complexity of the compliance work. Mapping the AI systems in use, classifying them by risk, identifying the role (provider or deployer), preparing the technical documentation, training staff: for a company with standard AI use we’re talking about six to ten weeks of consultancy work plus internal time. Postponing means many SMEs will reach 2027 having done nothing, and will find themselves in the same urgent situation they were in today.

The second trap is the moving target. An SME that had launched a compliance programme for the original August 2026 deadline now finds itself with a project under way, consultancy costs already incurred, processes already modified. The postponement doesn’t cancel these investments, but it suspends them in limbo. The companies that started in good time are now wondering whether to continue at full speed or slow down, knowing the deadlines could be overturned yet again if the political wind changed once more. It’s a hidden tax that weighs far more heavily on SMEs than on large enterprises.

The third trap concerns the overlap with Italian legislation. Law 132/2025 remains binding, watermarking arrives in December 2026, AI literacy is already mandatory. An Italian SME thinking “the postponement applies to me” while neglecting these points risks penalties even in the short term. Fines for failing to train staff can already be imposed. Those for failing to label AI content will kick in in December. Those for failing to meet the Italian obligations are already in force.

What to do now, concretely

The operational approach for an Italian SME changes little compared with before 7 May. What changes is the calendar, not the substance of the work. There are five concrete steps worth tackling by summer 2026, regardless of the postponements.

The first step is mapping the AI systems in use. An SME almost always uses more AI tools than it thinks: ChatGPT for marketing, Copilot in Office, Make or Zapier automations with AI components, chatbots on the website, supplier scoring systems, document recognition, machine translation. Without a clear inventory, no conformity assessment is possible.

The second step is classifying each system by risk. Most of the tools used by SMEs fall into the minimal- or limited-risk categories, where the obligations are light. But some specific uses (automated recruitment, customer scoring, predictive systems that affect significant decisions) can fall into the high-risk category, even when the software is bought from third parties.

The third step is identifying the role: provider (whoever develops or significantly modifies an AI system) or deployer (whoever uses it). Most Italian SMEs are deployers. The trap is substantial fine-tuning: if an SME customises an AI model with its own data in a deep way, it risks being reclassified as a provider, with far heavier documentary obligations. This step requires joint legal and technical assessment.

The fourth step is staff AI literacy, an obligation already active since February 2025. There’s no need to train all employees as AI experts: what’s needed is to ensure a basic level of awareness of the risks, of the correct use of the tools, and of the data that must not be entered into public generative systems. For an SME with 20-50 employees this work typically wraps up in two to four hours of structured training.

The fifth step is technical preparation for the December 2026 watermarking. As explained above, a formal declaration isn’t enough: you need a system that inserts the hidden metadata, tracks content generation, ensures uniform labelling across all channels and integrates with the company CMS. It’s probably the most urgent point, and the one Italian SMEs are least prepared for.

At A126 Web Technologies we support Italian SMEs through these five steps with an integrated approach spanning technical mapping of the systems, configuration of the integrations needed for compliance (watermarking, AI interaction logs, systems to track automated generations) and ongoing operational support. AI Act compliance isn’t just a legal matter: it requires technical skills ranging from tool configuration to data-flow management.

The reputational and commercial risk few consider

Beyond the direct penalties, the European postponement doesn’t cancel a side effect already under way: the demand for AI Act compliance is becoming a contractual prerequisite in business-to-business relationships, especially towards enterprise clients. An SME supplying a large Italian or European company increasingly finds itself having to demonstrate compliance with AI Act requirements in order to stay in the supply chain, even before the official deadlines. The postponement doesn’t stop this dynamic — if anything the opposite: large companies keep demanding guarantees from suppliers, and those who can’t provide them lose opportunities.

The same goes for reputation with end customers. The penalty decisions published by European and Italian authorities create immediate reputational effects. The retention of log files, the documentation of algorithmic choices, transparency towards users are not just formal obligations: they are credibility assets in the market.

If you’re using AI tools in your processes and want to understand what concretely changes for your company after the postponement of 7 May, get in touch for a free consultation: together we’ll analyse your current exposure, build the map of the AI systems in use, and define a compliance path sized to your scale, integrated with the Italian deadlines already in force and with the December 2026 watermarking.

A126 Web TechnologiesBespoke digital solutions for Italian SMEs.

Share this article