I've already written a dedicated article on the PUIA and the specific obligations for special education. Here I widen the lens: what happens when the same regulation enters a business, and how to hold schools and SMEs together under the same method — because the mistake I see most often, in both contexts, is the same: waiting for someone else to write the perfect policy before moving.
The contradiction that stalls everyone
On paper the AI Act promises three things: protecting people's rights, system safety, ethical innovation. In practice, whoever has to apply it — a school principal, an SME owner, an HR manager — mostly sees the other side: forms to fill out, a "risk-based" approach that's proportionate in theory but leaves real ambiguity in practice about what actually counts as "high-risk," and the fear of falling behind competitors operating outside the EU without these constraints.
This tension is real, not laziness from those who have to apply the rule. But it has a dangerous practical consequence: while waiting for total clarity, obligations already in force get ignored. And some have been in force for a year and a half.
What's already mandatory, today, for anyone using AI
Since February 2, 2025, Article 4 of the AI Act has been applicable: the obligation of AI literacy for the staff of anyone who provides or uses AI systems. It doesn't only apply to high-risk systems — it applies to anyone, school or business, letting staff use AI without a minimum of training on what's happening behind the tool. It's the most-ignored obligation I come across, because it doesn't make headlines the way "high-risk" systems do, but it's already checkable today.
What kicks in from August 2, 2026
As of this week, two important blocks become fully applicable:
- Obligations on high-risk systems (Annex III). For schools: systems that assess or guide students. For SMEs: this includes, among others, AI systems used for staff recruitment and evaluation — one of the most common uses and one of the least recognized as "high-risk" by those adopting it.
- Transparency obligations (Art. 50). Anyone using a chatbot for customer service must say so clearly. Synthetic content — text, images, audio, video generated or altered with AI and shared publicly — must be labeled as such. This applies to a school's website just as much as to an SME's marketing content.
For schools: not just special education
In the article dedicated to the PUIA I covered the special-needs area in depth. But the institutional AI plan, implementing Ministerial Decree 166/2025, covers the whole school: from the acceptable-use policy to appointing an internal AI officer, to training modules for all staff — not just those working in special education. Whoever writes the PUIA rarely has practical examples to draw on, and that's where an outside audit shortens the timeline.
For SMEs: where to look first
In most SMEs I've worked with, the problem isn't lack of will — it's not knowing where to start. Three concrete points:
- Map what you're already using. Chatbots on the website, content-generation tools, CV-screening software, assistants built into company tools: there are almost always more than the owner thinks, often introduced by individual employees without a structured adoption process.
- Classify the risk before writing any policy. Not everything is "high-risk" — but some common uses (staff selection, customer scoring) are, and need to be treated differently from an FAQ chatbot.
- Train the people who use these tools every day. The AI literacy obligation (Art. 4) is the fastest starting point and already in force — and in practice it alone reduces much of the operational risk, before any formal document exists.
The right question isn't "are we compliant?" — it's "do we actually know what we're already using?" The second always comes before the first, and almost nobody asks it.
Where to start without waiting for the perfect policy
The method I use is the same for schools and SMEs, applied to different contexts: an initial audit that maps the tools already in use, separates what's already mandatory from what kicks in in August 2026, and produces a proportionate training and documentation plan — not red tape for its own sake, but a way to use AI with less risk and more real results.
Conclusion
The AI Act's contradictions — protection versus red tape, safety versus uncertainty — aren't solved by waiting for a clearer version of the rule. They're addressed by mapping what's actually being used, today, and acting on the points that matter most. The rest gets built afterward, with more clarity and less rush.