AI act: the new european rules on artificial intelligence

Following the approval of the final text of the Artificial Intelligence Act (AI Act) by the Committee of Permanent Representatives (Coreper) of the Member States on February 2, the regulation that will govern artificial intelligence (AI) throughout the European Union is now close to enactment.
The final vote is expected to take place on April 24, 2024, followed by publication in the Official Journal of the European Union and a gradual entry into force of its provisions over the next two years.
The AI Act will be the first regulation on AI at such a broad level and will introduce a set of obligations that will affect both those who develop and those who implement AI systems. This includes companies and organizations that, although not operating in the tech development sector, will increasingly integrate third-party AI systems into their business activities.
This is therefore a good time, now that we are nearing the finish line, to take a quick look at how the new European AI framework is structured.
Risk-Based Protection
Following an approach similar to the General Data Protection Regulation (GDPR) for personal and sensitive data protection, the EU has decided to align the level of safeguards for citizens—and thus the level of obligations imposed on AI users—with the risk level posed by each AI system and/or its use.
The AI Act defines three risk levels, each associated with different regulatory requirements:
- Minimal Risk: Most AI systems currently in use fall into this category and can continue to be developed and used under existing legislation without additional legal obligations.
Providers of such systems may voluntarily choose to comply with requirements to qualify their AI as trustworthy and to follow voluntary codes of conduct modeled after the requirements that will be mandatory for high-risk or high-impact AI systems.
- High Risk: These are AI systems that could potentially negatively affect people’s safety or fundamental rights. They will be subject to the AI Act’s requirements, including a risk management system, data governance, technical documentation, record-keeping, transparency and user information, human oversight, accuracy and robustness, cybersecurity, a conformity assessment before market placement, and registration in a public database.
- Unacceptable Risk: These are AI systems used for particularly harmful purposes that contravene EU values and will therefore be banned.
Prohibited uses of AI include: social scoring, exploiting individuals’ vulnerabilities, subliminal techniques, real-time remote biometric identification (except in specific cases), biometric categorization to infer race, political views, sexual orientation, etc., predictive policing, emotion recognition in the workplace (except in specific cases), and indiscriminate facial image scraping.
Additionally, two other types of risks are identified:
- Transparency Risk: Specific transparency obligations will apply to certain AI systems where there is a risk of manipulating users, so that users are aware they are interacting with an AI system.
- Systemic Risks: These derive from general-purpose AI models, especially high-powered generative AI systems (with computational power exceeding 10^25 FLOPS, such as ChatGPT), which are widely used for many tasks. Their misuse or errors could affect large numbers of people and are therefore considered high-impact AI systems.
Providers of such models must comply with transparency obligations, adopt policies to protect copyright during AI training, assess and mitigate risks, report serious incidents, conduct cutting-edge testing and evaluation, ensure system cybersecurity, and disclose energy consumption.
In short, different risk levels and types entail varying degrees of citizen protection, ranging from outright bans on AI systems that would violate fundamental rights to simpler transparency and risk management obligations, intended to prevent citizens from unknowingly interacting with AI or suffering harm such as data loss, misuse, or financial damage due to AI implementation.
Company Obligations
In this upcoming regulatory framework, what must companies do?
For the use of low-risk AI systems, there will be no specific obligations, although adherence to best practices for responsible AI use—reflecting the requirements for high-risk AI—will be encouraged.
There will likely be direct and indirect incentives to move in this direction, such as making adherence to these best practices a condition for access to public resources, or the market rewarding companies that demonstrate higher user care.
In the case of high-impact general-purpose AI (such as ChatGPT), transparency obligations toward users and customers will be key, to ensure that individuals are aware that some or all of their interaction with the company is managed by AI.
For both general-purpose high-impact and high-risk AI systems, companies will also be required to implement risk analysis and management systems, similar to the impact assessments already required under privacy law for personal data processing.
The FRIA
Just as data controllers must draft a DPIA (Data Protection Impact Assessment) under privacy law, those who use high-risk or high-impact AI systems in their business activities must draft a FRIA (Fundamental Rights Impact Assessment).
This AI impact assessment must include:
- Implementation Description: A detailed explanation of the process(es) in which the high-risk or high-impact AI system will be used.
- Duration and Frequency: Specification of how long and how often the system will be used.
- Affected Categories or Groups: Identification of the categories of individuals and/or groups that may be affected by the AI system.
- Specific Harm Risks: Description of potential risks associated with the system's use that could harm the identified individuals or groups.
- Human Oversight Measures: Detailed description of the human supervision measures that will be implemented.
- Remedial Measures: Description of actions that will be taken to address consequences if the identified risks materialize.
For those who have already drafted a DPIA, these points will appear familiar, as the FRIA follows the same principles and steps but is adapted to AI processes.
This means that companies already subject to GDPR’s strictest requirements will be at an advantage thanks to their acquired know-how.
On the other hand, companies that do not handle personal data—or do so without needing a DPIA—but use AI systems classified as high-risk or high-impact by the new regulation will need to learn how to draft a solid FRIA from scratch. We strongly recommend seeking professional support rather than attempting it alone.
The risk of going it alone is ending up with an impact assessment that fails to meet compliance requirements during audits, resulting in penalties.
Penalties
The AI Act establishes three levels of penalties depending on the specific regulatory breaches:
- Up to €30,000,000 or 6% of total annual global turnover (whichever is higher) for violations of Article 5 (banned uses of AI) or Article 10 (rules on the datasets used to train high-risk AI systems);
- Up to €20,000,000 or 4% of global turnover for non-compliance with other obligations under the AI Act (articles other than 5 and 10);
- Up to €10,000,000 or 2% of global turnover for providing incorrect, incomplete, or misleading information to notified bodies or national authorities.
It’s clear that penalties can be significant—even for breaches of internal documentation and oversight obligations concerning AI-related processes.
Companies already using or planning to use AI in their operations should begin evaluating now the compliance requirements applicable to their chosen systems and business processes, and prepare to be fully compliant when the monitoring bodies appointed by EU Member States begin conducting inspections.
At RUP Legal & Consulting, we are available to support you in assessing your situation and helping you be fully prepared for the entry into force of the AI Act.
Right to be Forgotten: Do you want to remove data or news about yourself from the Internet? Here’s how
Nowadays, due to the widespread use of the internet and social media, personal data and information spread rapidly and effectively.
But what happens when the person concerned does not want news about them to circulate online uncontrollably, because, for example, they believe it harms their image?
To respond to this need, Article 17 of the GDPR provides for and regulates the so-called right to be forgotten, which gives the data subject the right to request the deletion of content concerning them.
Let’s see when and how this right can be exercised.
Conditions for Exercising the Right to Be Forgotten
The cases in which the right to be forgotten can be exercised, as outlined in Article 17 of the GDPR, are as follows:
- a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- b) the data subject withdraws the consent on which the processing is based;
- c) the data subject objects to the processing;
- d) the personal data have been unlawfully processed;
- e) the personal data must be erased to comply with a legal obligation;
- f) the personal data were collected in relation to the offer of information society services referred to in Article 8(1).
The Right to Report (Freedom of Expression and Information)
The right to be forgotten is not an absolute right. It must be balanced with other rights, above all the right to report, i.e., the right to publish information relating to facts and events of public interest or that take place in public.
This principle is explicitly stated in Article 17 of the GDPR (paragraph 3), which provides that the right to erasure does not apply when processing is necessary for: “…the exercise of the right of freedom of expression and information…”
In such cases, therefore, personal data and information related to an individual may be lawfully published.
Naturally, after a certain period of time, even accurate information may lose its relevance to the public interest.
When this happens, the information must be removed in order to fully restore the right to privacy and reputation of the persons concerned.
If the data controller does not act voluntarily, the data subject may request the deletion of the content.
Other Exceptions
In addition to what is provided for the right to report, paragraph 3 of Article 17 of the GDPR outlines other exceptions to the right to be forgotten. This right cannot be exercised when the data must be processed:
- a) to comply with a legal obligation (e.g., laws that require data to be retained for a specific period);
- b) for reasons of public interest in the area of public health;
- c) for archiving purposes in the public interest, scientific or historical research, or statistical purposes;
- d) for the establishment, exercise, or defense of legal claims.
How to Exercise the Right to Be Forgotten
When one of the conditions provided by Article 17 of the GDPR is met, the data subject may request the deletion of content and related data directly from the data controller who published the material.
The data controller must proceed with the deletion without delay and free of charge.
As an alternative to deletion, the data controller may opt to anonymize the data.
In this case, the data are not deleted but are processed in such a way that it is no longer possible to identify the data subject.
De-indexing
In addition to requesting deletion from the data controller, the data subject may request de-indexing of relevant web pages by search engines.
In this case, the content is not removed, but search engines make it harder to find. As a result, users will have more difficulty finding the news through an online search.
The request must be made by filling out the specific forms provided online and must include the relevant reasons and required documentation.
Cartabia Reform and the Right to Be Forgotten of the Accused
The issue has recently been addressed in the context of justice reform with an amendment to Article 1, paragraph 25, of Law No. 134/2021. This introduced a specific procedure for exercising the right to be forgotten by a defendant who has been acquitted, declared not liable to stand trial, or whose case has been dismissed.
In particular, the individual concerned may request de-indexing of content containing their personal data. This de-indexing may also be preventive, meaning the person may request that all articles written from the time of the ruling onward that refer to the defendant not be indexed.
If a request is submitted, the clerk’s office of the judge who issued the ruling will include a note referencing Article 17 of the GDPR at the bottom of the document.
Do you need to recover a debt? Here's how to do it in a few steps
Have you sold a good or provided a service and your client hasn’t paid?
Attempts to amicably resolve the dispute have failed? In such cases, it's essential to know how to act in order to protect your interests and recover the amounts owed as quickly as possible.
Notice of Default
The first step to recover your credit is to place the debtor in default.
This is done by sending the debtor a notice via certified email (PEC) or registered mail with return receipt, demanding payment of the amounts due within a specific period, typically not exceeding 15 days.
If the deadline expires without payment, you may initiate legal proceedings to recover the debt.
Application for an Injunction Order
If the notice of default is unsuccessful, you can proceed with forced debt recovery.
To do so, you need an enforceable title, such as a court ruling or an injunction order (“decreto ingiuntivo”).
The most common and fastest method of debt recovery is to file an application for an injunction order.
Once the application is filed, the judge may:
- grant the request and order the debtor to pay,
- reject the application, or
- request additional documentation.
If the injunction order is issued, it must be served to the debtor within 60 days, otherwise it will become ineffective.
The debtor may contest the injunction by filing an objection within 40 days of receiving the notice.
This objection must be filed through a writ of summons before the same court that issued the injunction, which will lead to a standard court proceeding.
Writ of Payment (Precetto)
If the debtor does not object to the injunction order within 40 days of service, the creditor may request the court to make the injunction order enforceable.
Based on the now enforceable decree, the creditor may then draft a writ of payment (“atto di precetto”).
This document warns the debtor to pay within at least 10 days, failing which enforcement proceedings will begin.
Provisionally Enforceable Injunction Order
When the credit is based on promissory notes, bank checks, cashier’s checks, stock exchange settlement certificates, or notarial/public documents, the judge may declare the injunction order provisionally enforceable immediately upon issuance.
This means the creditor may immediately proceed to serve the writ of payment and the injunction order, without waiting for the 40-day term.
The judge may also grant provisional enforceability if a delay would cause serious harm (e.g., risk of debtor bankruptcy or asset concealment), or if the creditor submits signed documentation proving the claim (such as a written acknowledgment of debt).
Enforcement (Pignoramento)
After at least 10 days from service of the writ of payment, you can proceed with forced enforcement against the debtor.
The writ becomes ineffective if enforcement is not initiated within 90 days of service.
The enforcement can be carried out using three types of seizure:
- Movable property seizure (pignoramento mobiliare),
- Real estate foreclosure (pignoramento immobiliare),
- Third-party garnishment (pignoramento presso terzi).
Beware of Statutes of Limitations
If a right is not exercised for an extended period, it may become time-barred, meaning it is extinguished by statute.
In that case, the debtor is no longer legally obliged to pay, and the creditor can no longer claim the debt.
Rights are subject to specific limitation periods defined by law. The general limitation period is 10 years, but there are many exceptions (for example, claims arising from shipping and transport contracts expire in one year).
It is therefore crucial to act promptly to recover your receivables, with the support of experienced professionals like those at Rup Legal and Consulting.
Start-up and innovative SMEs: new incentives and tax benefits for 2024
Are you an aspiring entrepreneur looking to launch your start-up in 2024?
Starting a new business can be an exciting adventure, but it’s important to navigate the complex world of entrepreneurship with awareness. Laying strong legal foundations can save you time and money in the long run.
Here are some key tips to help you avoid complicated or unpleasant situations.
- Choose the legal structure that best suits your needs
Each legal form comes with specific features and implications from a legal, fiscal, and operational standpoint.
Take the time to assess and choose the most appropriate one for your goals.
For instance, if you want to protect your personal assets, it’s advisable to establish a limited liability company, which ensures full financial autonomy—meaning the company’s assets are separate from the personal assets of its shareholders.
- Pay attention to what you include in your articles of incorporation
Finding the right partners is no easy task. They must share your work ethic and your vision when it comes to investments and business decisions.
But what happens when one partner wants to leave the company? What are they entitled to? Under what conditions? And what if they want to sell their shares to a third party?
These are tough questions, but it’s much easier to face them in advance by inserting clear and detailed provisions in the articles of incorporation.
- Protect yourself contractually against missed payments
Unfortunately, it can happen that some clients will use your products or services and then refuse to pay.
A clear and precise contract will help you recover your money—and the related interest—more effectively.
- Keep your documentation in order
Documentation is key. Sign contracts with your suppliers, clients, and employees. Don’t rely on a handshake if you want to protect your business.
Also, take the time to organize and regularly update your documents. This will be a great asset as your company grows.
- Protect your intellectual property
Intellectual property is often a company’s most valuable asset—the very thing that makes your product or service unique.
Protect it by registering trademarks and patents, and safeguard confidential information with NDAs (Non-Disclosure Agreements).
- Be prepared for employee-related issues
Unfortunately, you may sometimes need to deal with employee problems.
Make sure you have well-drafted employment contracts with non-compete and confidentiality clauses. Keep signed copies on file and formally document any disciplinary actions.
Being precise and diligent from the beginning will save you a lot of time and money later on.
- Set up a privacy management system
Data protection has become a top priority, especially with the rise in cyberattacks and data breaches.
You need a company privacy policy to manage personal data properly. Without one, you could face severe penalties.
- Don’t do it all alone
If you have doubts, consult your trusted legal advisor—and if you don’t have one yet, make sure to find a lawyer who can guide you on your entrepreneurial journey.
Even if at first it may seem like an unnecessary expense, good legal advice—like the kind offered by RUP Legal and Consulting—can save you significant time and money in the future.
E-commerce and consumer protection: how to comply with legal obligations
Advertising is the soul of commerce, and part of that soul has always been made up of prize contests.
We are used to seeing large companies, even multinationals, periodically launch contests offering branded merchandise linked to their products and services (e.g., coffee mugs for biscuit brands) or entirely different, sometimes luxurious items such as cars, cruises, or silverware.
This is because a well-designed prize contest can benefit even large companies already investing heavily in extensive marketing campaigns—and it is easy to see how it could positively affect the sales of medium and small businesses, especially those operating primarily or exclusively online. Particularly given how easy the Internet makes organizing such contests.
In short, if your business includes e-commerce, the chance to use your digital sales and promotional channels to launch a prize contest that attracts new customers and builds loyalty among existing ones should not be overlooked. Even something simple and quick—like a selfie contest featuring your product and a specific tag—can bring more traffic, better indexing, and new potential sales.
Prize Contests: A Regulated Activity
Before jumping in, however, it is crucial to understand that prize contests in Italy are governed by a specific regulation: Presidential Decree (DPR) 430/2001. The Ministry of Productive Activities (now called the Ministry of Enterprises and Made in Italy) is authorized to ensure that contests held in Italy comply with this regulation.
Violation of the rules can result in significant administrative penalties.
To help you start off on the right foot, this article offers essential information on the legal framework governing prize contests. In any case, before launching a prize contest, it is advisable to seek specialized legal advice from professionals, such as the experts at RUP Legal & Consulting.
Prize Contests vs. Reward Programs
The first thing to know is that the law distinguishes between "prize contests" and "reward programs."
A prize contest is any competition in which the awarding of prizes is determined either by chance (random drawing by any means) or by the contestants' skill or ability—objectively assessed—in predicting an event, answering questions, completing tasks, or being the first to meet certain criteria outlined in the rules.
In other words, a prize contest may rely entirely on chance (a draw), partially on chance (e.g., predicting a future event), or entirely on skill (e.g., answering quiz questions, building a model airplane out of cans, or submitting a selfie with a product).
A reward program, on the other hand, grants prizes based on the purchase of one or more products or services and the presentation of proof of purchase. Sometimes the reward is not a prize but a discount on a product or service offered by the organizer.
Think of the typical supermarket loyalty programs, where purchases earn stickers or points, and collecting a certain number entitles the customer to a prize or a discount—as in the well-known "Esselunga Catalog."
In the rest of this article, we will use the term "promotion" or "promotional contest" to refer to both prize contests and reward programs.
Duration of Promotional Contests
Promotions—whether prize contests or reward programs—have a legally established maximum duration. This protects both organizers and participants, preventing organizers from being bound by promises made years earlier.
The maximum duration is:
- One year for prize contests
- Five years for reward programs
The longer time frame for reward programs reflects their purpose: to reward long-term customer loyalty, which naturally requires more time.
Prize contests, by contrast, are intended to be faster in execution and conclusion.
Who Can Participate in Promotions
Promotions can target both final consumers (whether or not they are current customers) and other stakeholders in your business operations, such as retailers, intermediaries, distributors, collaborators, and employees.
Thus, promotions can be used not only to acquire and retain customers, but also to motivate and engage those who help sell or support your products or services.
Who Can Organize a Promotional Contest
According to the law, prize contests can be organized by manufacturers or commercial enterprises that produce or distribute the products or services being promoted. "Promoted" here refers to the items being advertised through the contest—not the prizes themselves, which may come from third parties (e.g., a soda brand offering game consoles as prizes).
Foreign companies can also launch promotions in Italy, provided they have an official representative based in the country.
Participation Costs
Participation in a promotional contest must be free, aside from necessary expenses such as postage or phone charges.
In 2001, this rule mainly applied to phone-in contests or mail-in proof-of-purchase submissions. Today, it extends to things like internet access costs to interact with an online contest.
In any case, organizers cannot impose any additional entry fees, direct or indirect.
It is also forbidden to increase the price of the promoted product or service to offset the cost of the prize, as this would misrepresent the prize's true value. The prize value must always be clearly stated in the official contest rules.
Location of Promotional Activities
Promotional contest activities must take place in Italy, except for product packaging operations that may occur abroad.
This clause aims to ensure that organizers don't conduct contests offshore to avoid Italian regulations. However, in online contexts—where websites and servers may be hosted abroad—there is some flexibility.
What matters is that decisive actions (e.g., winner selection, point tallying, prize distribution) occur in Italy. If communications are sent to foreign servers but the operations are handled domestically, the law is considered respected.
We recommend using software that operates on Italian servers and ensures transparency, especially for automated promotions (e.g., via SaaS).
Eligible Prizes
Cash prizes are not allowed. Nor are investment-related items like public/private bonds, company shares, mutual fund units, or life insurance policies.
Instead, you may offer:
- Goods
- Services
- Price discounts
- Non-nominal vouchers (e.g., transferable gift cards)
Prizes must have a clear and stated monetary value.
That’s why TV shows use gold tokens (which can be resold) rather than cash—gold is a way to skirt the cash prize ban while staying compliant.
Acceptable prizes also include lottery tickets or pre-filled betting slips, effectively letting winners try their luck in state-authorized games.
Artistic, literary, or scientific contests that award cash are exempt from DPR 430/2001—as long as their goal is producing creative or intellectual works. This is why awards like the Premio Strega are allowed to offer monetary prizes.
Security Deposit
To guarantee delivery of the prizes, the organizer must deposit a bond with the Ministry:
- 100% of the prize value for prize contests
- 20% for reward programs
If the prize value is uncertain, it is estimated based on similar contests or projected product sales.
The bond can be released only after a year, provided there are no irregularities or undelivered prizes.
Administrative Requirements
Per Article 10 of DPR 430/2001:
For prize contests:
- Submit a notice to the Ministry, including the contest rules and proof of bond payment.
- Notify the Ministry of any rule changes.
For reward programs:
- Self-certify the rules via a notarized statement from the company’s legal representative.
- Keep a copy of the rules at the company's legal address for the contest duration plus 12 months.
- Apply the same for any amendments.
Changes to deadlines must be communicated with the same or equivalent visibility as the original rules.
Prizes not claimed must be donated to non-profit organizations with social utility.
Prohibited Promotions
The law bans promotions that:
- Violate legal regulations
- Undermine fairness or transparency
- Attempt to bypass the state monopoly on gambling
- Distort competition or market dynamics (under EU law)
- Promote products with advertising restrictions
Promotions for restricted goods/services are allowed only after meeting authorization or notification requirements.
Winner Selection
In prize contests, every stage of prize awarding must be supervised by a notary or consumer protection official from the local Chamber of Commerce.
If using technical tools (e.g., software), an expert must certify the system’s compliance.
These officials also verify bond payments and prize donations, and issue a report.
The Ministry may conduct random checks to ensure compliance.
Rules and Publicity
The contest rules must be available to participants and include all mandatory information: organizer, duration, area of operation, how it works, prize nature/value, delivery timing, and recipient of unclaimed prizes.
Promotional materials must include or link to these rules. If they do not, they must at least state the contest duration, participation terms, and total prize value.
If full info isn’t provided, the materials must direct users to where the rules can be read.
Conclusion
Running a prize contest or reward program is a valuable way to promote your business. While not overly complicated, it does require compliance with detailed rules to protect both participants and public institutions.
To ensure smooth execution and full compliance, seek legal support from experienced consultants—like the lawyers at RUP Legal & Consulting—who can help draft legally sound rules and safeguard your interests.






