This note is a technical reminder, not legal advice. Dates must be confirmed against the official sources and with a lawyer.
| When | What | Applies to |
|---|---|---|
| 2 August 2026 | AI Act, transparency obligations (Art. 50), with a grace period for marking | those who publish AI content or systems |
| 11 September 2026 | Cyber Resilience Act: reporting of actively exploited vulnerabilities and severe incidents | manufacturers of products with digital elements |
| 31 October 2026 | NIS2 Italy: adoption of baseline security measures for entities notified in 2025 | essential and important entities |
| 2 December 2026 | AI Act: machine-readable marking of AI-generated content and new prohibitions | those who generate content with AI |
| 11 December 2027 | Cyber Resilience Act: obligations for open source software stewards | open source stewards |
| 2 December 2027 | AI Act: high-risk systems in Annex III | recruitment, credit, education and others |
| 2 August 2028 | AI Act: high risk as a safety component of regulated products (Annex I) | medical devices, machinery, toys |
Sources and level of certainty
- AI Act: the “Digital Omnibus” regulation was published in the Official Journal of the EU on 24 July 2026 and has been in force since 27 July 2026. Secondary source: White & Case.
- Cyber Resilience Act: official portal of the European Commission, reporting obligations. It provides for an early warning within 24 hours, a notification within 72 hours and a final report.
- NIS2 in Italy (Legislative Decree 138/2024): the 31 October 2026 date comes from secondary sources (IusPrivacy); the ACN pages could not be accessed at the time of verification. Check the Agency’s website.
What this means in practice for architecture
- Inventory of systems, dependencies and versions (the basis of all three regulations).
- Logs and notifications: centralised logs and a procedure that allows an incident to be notified within 24 hours.
- Access control and backups that have been tested.
- For AI: documentation of data, models and controls; marking of generated content.
An assessment can translate these requirements into technical controls and priorities.