AI Act: transparency obligations applicable from 2 August
Artificial Intelligence
As from 2 August 2026, the transparency obligations under Article 50 of Regulation (EU) 2024/1689 (the “AI Act”) will apply. The framework covers systems that interact with natural persons, generative systems, emotion recognition, biometric categorisation and deepfake content.
Providers must inform users when they are interacting with an AI system, unless this is obvious to a reasonably well-informed person. For generative systems, audio, video, image and text outputs must be marked in a machine-readable and detectable manner, through effective and interoperable solutions.
As regards deployers, Article 50 requires them to inform persons exposed to emotion recognition or biometric categorisation and to ensure that deepfakes are identifiable as such. Texts on matters of public interest generated or manipulated by AI must be disclosed as such, unless they are subject to editorial review or editorial control with responsibility being assumed for them.
The relevant notice must be clear and distinguishable, no later than upon first interaction or first exposure, and infringements may result in fines of up to EUR 15 million or 3% of worldwide annual turnover.
Providers and deployers must therefore immediately map roles, use cases and touchpoints, distinguishing between information obligations and technical marking measures. To support this activity, the Commission has adopted dedicated guidelines, a Code of Practice on Transparency of AI-Generated Content and a set of EU labelling icons.
Data brokers and legitimate interest: the Garante fines Lusha EUR 2 million
Data Protection
By decision No. 542 of 14 July 2026, the Italian Data Protection Authority fined Lusha Systems Inc. EUR 2 million. The company operates a platform that collects, enriches and makes available professional contact data from public sources, third-party providers and digital integrations.
The GDPR was held to apply pursuant to Article 3(2), notwithstanding the absence of an establishment in the European Union, in light of the collection, monitoring and continuous updating of information relating to data subjects in the European territory.
Reliance on legitimate interest to communicate data to clients for their own commercial or promotional purposes was challenged, since the mere public availability of the data does not make large-scale systematic collection, enrichment and commercialisation reasonably foreseeable. The balancing exercise takes into account expectations, scale and impacts.
The Garante therefore found breaches of data minimisation and data protection by design. Integrations with email and calendar systems collected excessive and unnecessary information, including headers, participants and titles. The filters did not prevent the inclusion of contact details relating to public officials. The privacy notices were difficult to find, incomplete and available only in English.
In addition to the fine, the authority ordered a prohibition on further processing of data relating to data subjects in Italy collected without an appropriate legal basis and ordered their erasure. This case is a reminder that data brokers must document sources, purposes, legal bases, expectations and controls separately throughout the entire data supply chain.
E-commerce and promotional countdowns: the AGCM fines Deghi EUR 2 million
Consumer protection
By decision of 23 June 2026, the Italian Competition Authority fined Deghi S.p.A. EUR 2 million for an unfair commercial practice on its e-commerce website.
The objection concerned the use of countdown timers associated with offers presented as available for a limited period only. Upon expiry, the promotion was reintroduced on the same terms with a new timer, thereby creating artificial urgency capable of accelerating the purchase decision.
The conduct therefore falls within Article 23(1)(g) of the Italian Consumer Code, under which it is always misleading to state, contrary to the truth, that a product is available on particular terms only for a very limited time so as to procure an immediate decision.
On this point, the AGCM also rejected the argument that there had been a single continuous extension of the offer. Such continuity had not been communicated clearly, and the timer appeared to have been manually renewed across a large part of the catalogue.
The AGCM also found that the discount had been calculated on the full list price rather than on the lowest price applied during the previous 30 days, pursuant to Article 17-bis.
The case confirms that compliance also depends on the design of the offer. Interface, duration and messaging must not unduly influence consumer choice, and any scarcity claims and reference prices must reflect actual and verifiable conditions.
Intellectual property in the European Union: the EUIPO 2025 results and the new examination guidelines
Intellectual property
The EUIPO has published its Consolidated Annual Activity Report 2025, reporting more than 327,000 new applications for European Union trade marks and EU designs, a historic record.
As regards trade marks, filings by EU applicants remain predominant, with Italy among the most active jurisdictions. As regards EU designs (“EUD”, Regulation (EU) 2024/2822), filings from third countries exceeded those from the EU for the first time. In 2025, the EUIPO also extended its activities to geographical indications for craft and industrial products pursuant to Regulation (EU) 2023/2411.
The update to the 2026 Guidelines for Examination, adopted by decision EX-26-09 of 30 June 2026 and effective from 1 July, reflects the evolution of practice.
The main developments concern design representation requirements, which must already be sufficiently clear for the purposes of obtaining a filing date. As regards trade marks, the changes concern the treatment of geographical indications, the comparison of word signs, and the distinctive character of simple elements, such as single letters, as well as issues relating to opposition proceedings and prior rights.
In view of the increase in applications, some practical suggestions remain valid before filing: availability, distinctive character, goods and services coverage, and consistency of representation should be verified, integrating registration into the strategy for protection and exploitation of the asset.
Focus
Security for prize promotions: a mere formality or a compliance lever?
The security required under Presidential Decree No. 430 of 26 October 2001 is not a merely formal step. It safeguards the delivery of prizes and affects the structure, costs and timetable of the campaign. The ministerial FAQs distinguish between prize operations…
Italy and the space economy: Law No. 89/2025 as an industrial policy tool
Law No. 89 of 13 June 2025 introduced the first organic Italian framework for space activities, combining authorisation, oversight and industrial policy instruments. Operators must demonstrate technical and professional capability, as well as the security and resilience of infrastructure…
Tracking pixels in emails: the Garante’s guidelines on transparency and consent
By decision No. 284 of 17 April 2026, the Italian Data Protection Authority treated the use of tracking pixels in emails as access to terminal equipment governed by Article 122 of the Italian Privacy Code. Notice is required for every type of message…