Based on this framework, the Act imposes differentiated obligations on providers and
deployers of AI systems. High-risk systems are subject to the most stringent and
comprehensive regulatory requirements, reflecting their potential impact on safety and
fundamental rights. Limited-risk systems, by contrast, are primarily associated with
transparency obligations. These include requirements to inform users when they are
interacting with AI-generated content, thereby addressing potential informational
asymmetries and enhancing user trust. Minimal-risk systems, such as spam filters and
other widely used applications, are generally permitted with minimal regulatory
intervention, subject only to voluntary best-practice measures aimed at ensuring safety
and reliability.
At the most restrictive end of the spectrum, Chapter 2 prohibits AI systems classified as
posing unacceptable risks. These systems are deemed incompatible with EU values as
they may undermine human dignity, violate fundamental rights, or manipulate human
behavior, and are therefore prohibited in principle under Article 5, with only narrow
exceptions such as law enforcement or counter-terrorism contexts (Jeon, 2024). Chapter
3 (Articles 6–49) regulates high-risk AI systems in detail, allowing their use only under
strict compliance conditions. Providers must meet extensive requirements regarding data
governance, documentation, transparency, human oversight, and risk management,
ensuring a high level of accountability prior to market deployment.
Annexes 1 and 3 further specify the criteria for identifying high-risk systems. In general,
AI systems subject to existing EU product safety legislation are classified as high risk,
requiring conformity assessments, often conducted by third parties, to ensure compliance
with regulatory standards (Lee, S. Y., 2023; Mökander, J., et al., 2022). In addition,
systems used in sensitive areas such as biometric identification, critical infrastructure,
public services, and law enforcement are also included in the high-risk category and are
subject to rigorous pre-market controls.
In contrast to the EU framework, Italy has recently adopted a more enforcement-
intensive and human-centered approach through its national AI legislation. While the EU
AI Act primarily establishes a harmonized regulatory architecture based on risk
classification and compliance obligations, the Italian AI law complements this structure
by introducing stronger deterrent mechanisms at the domestic level. Notably, it
incorporates criminal liability provisions for the misuse of AI systems, including penalties
for the malicious use of AI that endangers individuals or interferes with democratic
processes. It also mandates explicit watermarking of synthetic content such as deepfakes
and imposes significant administrative fines for non-compliance. Furthermore, Italy
places stronger emphasis on direct state supervision, including parental consent
requirements for minors and centralized oversight by national agencies such as the
Digital Italy Agency (AgID) and the National Cybersecurity Agency (ACN). In this respect,
while the EU framework is primarily preventive and harmonized in nature, the Italian
approach is more punitive and enforcement-oriented, reflecting a stricter interpretation
of “digital humanism.”
Overall, the EU risk-based approach represents a systematic and preventive model of AI
governance aimed at embedding European values—such as human dignity, safety, and