EU AI Act amendment and LLM security responsibilities
Adoption of generative AI in Italian companies is accelerating, with the ISTAT report forecasting that 16.4% of firms employing at least ten staff will use Large Language Models (LLMs) in decision‑making and data management by 2025 – more than three times the 2023 level. The rapid rollout brings security challenges such as data‑poisoning during training and prompt‑injection attacks in production. Responsibility for these risks is distributed among the model vendor, the system integrator and the client, creating a “shared‑responsibility” gap that hampers clear liability when incidents occur.
At the same time, the European Parliament has passed a targeted amendment to the AI Act as part of the Digital Omnibus VII package. The changes postpone key compliance dates for high‑risk AI systems to December 2027 (or August 2028 for AI embedded in regulated products) and delay the labeling requirement for AI‑generated content to December 2026. The amendment also introduces a ban on “nudifier” AI systems and tightens definitions of safety components, aiming to give businesses more time to meet risk‑based obligations while enhancing transparency and fundamental‑rights protection.