ISHIGHRISK AI
Analysis

What does Italy's AI law add to the EU AI Act?

Italy's AI law names ACN and AgID as AI Act authorities. Since 30 September 2026, failing to oversee high-risk AI can be a crime under Decree 160/2026.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Italy's AI law is Law 23 September 2025 n. 132, in force since 10 October 2025, which makes the Agenzia per la cybersicurezza nazionale (ACN) the AI Act market surveillance authority and single point of contact and the Agenzia per l'Italia digitale (AgID) the notifying authority, with Banca d'Italia, CONSOB and IVASS for financial entities. Legislative Decree 9 September 2026 n. 160, in force since 30 September 2026, adds Article 437-bis to the penal code, punishing failure to adopt safety or human oversight measures in high-risk AI systems with one to five years' imprisonment where danger to life or safety results, plus corporate liability and a presumption of causation in civil claims. The second decree, on authority powers and Article 99 fines, was approved by the Council of Ministers on 4 August 2026 but had not appeared in any Gazzetta Ufficiale general series issue up to 3 October 2026.

Italy's AI law is two texts, with a third still pending

Since 30 September 2026, a person who fails to adopt the safety or human oversight measures provided for a high-risk AI system can face a criminal charge in Italy where danger to life or safety results, and the company behind them an administrative sanction under Legislative Decree 231/2001, not only an AI Act fine. That is the sharpest consequence of Italy's AI law, and it comes from the second of two texts, not the first.

The first is Law 23 September 2025 n. 132, "Disposizioni e deleghe al Governo in materia di intelligenza artificiale", published in Gazzetta Ufficiale general series n. 223 of 25 September 2025 and in force since 10 October 2025. It sets national principles and sector rules, designates the AI Act authorities and creates new offences. Article 24 then delegates the Government to adapt Italian law to Regulation (EU) 2024/1689 by legislative decree within twelve months of entry into force.

The second is Legislative Decree 9 September 2026 n. 160, published in Gazzetta Ufficiale general series n. 214 of 15 September 2026 and in force since 30 September 2026. Adopted under Article 24(1), (2)(h), (3) and (5) of Law 132/2025, it governs AI use by the police and the civil and criminal liability that attaches to AI systems.

A third text is announced but not law. The Council of Ministers' press release n. 185 records that on 4 August 2026 it gave final approval to two decrees, Decree 160/2026 and a second on "poteri delle autorità nazionali" and AI in training, professions, work, health and public administration. That second decree does not appear in any Gazzetta Ufficiale general series issue or ordinary supplement published from 5 August to 3 October 2026, so nothing below relies on its content.

30 Sep 2026 Legislative Decree 160/2026 in force: Article 437-bis c.p., Article 359-ter c.p.p. and the civil liability rules apply.

Who enforces the AI Act in Italy

Article 20(1) of Law 132/2025 designates two national authorities for AI: AgID, the Agenzia per l'Italia digitale, and ACN, the Agenzia per la cybersicurezza nazionale. Article 20(2) then assigns the AI Act roles under Article 70: "l'AgID è designata quale autorità di notifica ai sensi dell'articolo 70 del medesimo regolamento e l'ACN è designata quale autorità di vigilanza del mercato e punto di contatto unico con le istituzioni dell'Unione europea".

Authority Role Source
ACN Market surveillance authority, including inspection and sanctioning activity, and single point of contact Art 20(1)(b) and 20(2) Law 132/2025, Art 70 AI Act
AgID Notifying authority: notification, assessment, accreditation and monitoring of conformity assessment bodies; promotion of AI innovation Art 20(1)(a) and 20(2) Law 132/2025, Art 28 and 70 AI Act
Banca d'Italia, CONSOB, IVASS Market surveillance for financial entities Art 20(1) and 20(2) Law 132/2025, Art 74(6) AI Act
Garante per la protezione dei dati personali, AGCOM Existing powers preserved, AGCOM as Digital Services Coordinator Art 20(4) Law 132/2025

Article 20(1)(c) gives AgID and ACN joint responsibility for regulatory sandboxes. The cross-border picture, including Italy's place among the Member States with a final designation on the Commission's list, is on the national authorities tracker, and the comparable German regime is set out in the KI-MIG article.

Law 132/2025 does not itself give ACN its full toolkit. Article 24(2)(a) and (m) delegate the inspection powers, and Article 24(2)(d) the power to impose "le sanzioni e le altre misure amministrative previste dall'articolo 99". The press release describes the unpublished second decree as setting that governance and a graduated sanctions regime "con limiti massimi inferiori a quelli previsti dal regolamento europeo".

Article 437-bis: the new high-risk AI offence

Article 12 of Decree 160/2026 inserts Article 437-bis into the penal code, headed "Omessa adozione di misure di sicurezza nei sistemi di intelligenza artificiale e alterazione illecita dei sistemi". It implements the criterion in Article 24(5)(b) of Law 132/2025.

Paragraph Who Conduct Condition Penalty
First "Chiunque", anyone Fails to adopt the technical safety measures provided for the design, training, production or placing on the market of high-risk AI systems that are suitable to prevent malfunction or alteration, or fails to adopt human oversight measures Danger to life or public or individual safety results 1 to 5 years' imprisonment
First Anyone The same Danger to State security results 2 to 8 years
Second Anyone, outside the first-paragraph cases and unless a more serious offence applies Alters high-risk AI systems Danger to life or public or individual safety results 2 to 6 years
Second Anyone The same Danger to State security results 3 to 10 years
Third Anyone A first-paragraph offence committed with gross negligence ("colpa grave") As for the first paragraph "la pena è ridotta da un terzo a un sesto"
Fourth The professional user of high-risk AI systems Intentionally omits human oversight measures Danger to life or safety, or to State security The first-paragraph penalties

Three features decide whether a given system is exposed. First, the offence is tied to high-risk systems. Article 11 of the Decree applies the definitions in Article 3 of the AI Act, and the AI Act's test for what is high-risk is the classification under Article 6 with Annexes I and III, so that is the gateway. The high-risk systems guide and what high-risk means set out that test, and the triage classifier runs it.

Second, the omission alone is not the crime. Each paragraph requires that danger to life, to public or individual safety, or to State security "derivi" from the conduct. A missing control that creates no such danger falls outside it, though it may still be an AI Act breach.

Third, the measures are those "previste" for high-risk systems, which points back to the AI Act's own requirements, chiefly human oversight under Article 14 and accuracy, robustness and cybersecurity under Article 15. Article 437-bis contains no commencement rule of its own linked to the AI Act's high-risk application dates, which the Digital Omnibus moved to 2 December 2027 and 2 August 2028, as the AI Act timeline shows. Which measures are "provided for" at a given date is therefore a question to put to Italian counsel before relying on the later dates.

The fourth paragraph reaches the user side. "Utilizzatore professionale" is not a term defined in Article 3 of the AI Act, but it maps closely onto the deployer, which Article 26(2) requires to "assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support". Only intentional omission is caught there; the gross negligence variant in the third paragraph refers to the first paragraph alone. The split between the two roles is explained in provider or deployer.

Corporate liability and civil claims

Article 15 of Decree 160/2026 adds Article 25-vicies to Legislative Decree 231/2001, Italy's regime of administrative liability of entities for crimes committed in their interest or to their advantage. An entity faces a pecuniary sanction of 600 to 1,000 quotas for Article 437-bis and 200 to 700 quotas for the deepfake offence in Article 612-quater, and in both cases the disqualification sanctions in Article 9(2)(b) to (e) of Decree 231/2001.

The civil rules in Articles 16 to 20 change the litigation position of anyone harmed by an AI system:

  • Disclosure, Article 17. In a damages claim for harm caused in using an AI system, the court can order the other party or a third party to produce evidence on how the system worked, expressly including the Article 12 logs, the Article 9 risk management documentation, the relevant Article 11 technical documentation and the Article 14 human oversight information. Where that documentation is withheld without justification, the court, having weighed the other evidence, "ritiene come ammessi i fatti allegati dall'istante", treats the claimant's alleged facts as admitted. A third party that fails to comply can be fined 1,500 to 10,000 euro.
  • Presumed causation, Article 18. Where damage derives from breach of one or more AI Act obligations, "il nesso di causalità tra la violazione e il danno è presunto, salvo prova contraria".
  • Certification is not a defence, Article 19. Conformity with the AI Act, "anche se certificata", does not in itself exclude the defendant's liability.
  • Consumer forum and insurer, Articles 16(4) and 20. A natural person suing outside any business or professional activity can also sue where they reside or are domiciled, and any injured party has a direct action against the defendant's liability insurer within the sums insured.

Article 16(3) keeps Article 82 GDPR and the national transposition of the Product Liability Directive (EU) 2024/2853 in place alongside these rules. See also the AI Act and the GDPR.

Biometric identification by the police

Article 5(1)(h) of the AI Act prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to three narrow exceptions, and Article 5(5) lets a Member State permit those exceptions only by laying down "in their national law the necessary detailed rules" for authorisation. Italy has now done so, which is why the prohibited practices analysis reads differently for Italian law enforcement than for Member States that have not legislated.

Article 13 of Decree 160/2026 inserts Article 359-ter into the code of criminal procedure. Real-time identification can be authorised for suspects of Annex II offences punishable with a maximum of at least four years, for fugitives, and for specific victims of abduction, trafficking or sexual exploitation. The preliminary investigations judge authorises it by reasoned decree, for a defined area and named persons, for no more than fifteen days at a time, and only after the Article 5(2) assessments. Biometric databases fed by untargeted scraping are banned outright, and results obtained outside those rules cannot be used.

Article 8 of the Decree covers the preventive and missing-person uses, authorised by the public prosecutor, and Article 9 requires a prior Article 27 fundamental rights impact assessment and, after use, notification to the Garante under Article 5(4). Article 10 governs post-event facial recognition: the public prosecutor must ask the preliminary investigations judge to authorise it within 48 hours of start-up, except for the initial identification of a potential suspect that Article 26(10) of the AI Act exempts from authorisation.

What Law 132/2025 adds beyond the AI Act

Much of Law 132/2025 sits outside the AI Act's product safety logic and applies whatever the risk class.

  • Minors, Article 4(4). Access to AI technologies by children under fourteen, and the related data processing, requires the consent of whoever holds parental responsibility. From fourteen the minor can consent to the processing, provided the information is easily accessible and understandable.
  • Work, Article 11(2). Employers must inform workers of the use of AI in the cases and manner set by Article 1-bis of Legislative Decree 152/1997, which covers fully automated decision-making or monitoring systems.
  • Intellectual professions, Article 13. AI may be used only for "attività strumentali e di supporto", with intellectual work prevailing, and the professional must tell the client which AI systems are used "con linguaggio chiaro, semplice ed esaustivo".
  • Copyright, Article 25. Article 1 of the copyright law, Law 633/1941, now protects works of "human" intellect, including those created with AI tools "purché costituenti risultato del lavoro intellettuale dell'autore". A new Article 70-septies confirms that reproductions and extractions from lawfully accessible works for text and data mining by AI models and systems are permitted in accordance with the existing exceptions in Articles 70-ter and 70-quater.

Article 26 then amends the criminal law. It adds a general aggravating circumstance in Article 61 n. 11-undecies of the penal code for offences committed through AI that acted as an insidious means, hindered defence or aggravated the consequences. It creates Article 612-quater, punishing the non-consensual dissemination of AI-falsified or altered images, video or voices "idonei a indurre in inganno sulla loro genuinità" that causes unjust harm, with one to five years, prosecuted on complaint unless linked to an offence prosecuted ex officio or committed against an incapable person or a public authority. It raises the penalties for market rigging under Article 2637 of the civil code and market manipulation under Article 185 of the Consolidated Law on Finance to two to seven years where AI is used, and adds unlawful text and data mining to the copyright offences in Article 171. The disclosure duties for deepfakes under the AI Act itself are covered in the deepfake disclosure rules.

How Italian criminal law sits alongside the AI Act

The AI Act is a regulation and applies directly. It sets the obligations, but it does not punish anyone itself: Article 99(1) requires Member States to "lay down the rules on penalties and other enforcement measures" and to make them "effective, proportionate and dissuasive". The administrative fines, with their ceilings of up to 35,000,000 euro or 7 percent of worldwide turnover, are set out on the penalties page.

Italy has layered its own criminal and civil law on top of that frame rather than inside it. The Article 437-bis offence and the Article 612-quater offence are national crimes with national penalties, prosecuted by Italian prosecutors before Italian criminal courts, and they do not replace the Article 99 fines, for which Article 20(1)(b) of Law 132/2025 makes ACN responsible. The same conduct, a missing human oversight measure on a high-risk system, can therefore carry three exposures in Italy: an administrative fine under Article 99(4), a criminal charge under Article 437-bis where danger results, and a civil claim in which Article 18 presumes causation from the breach. A Decree 231 sanction on the company can sit on top of the individual charge.

The practical difference is who carries the risk. Article 99 fines land on the operator. Article 437-bis is addressed to "chiunque", so it can reach the individual whose omission created the danger.

What to check if you operate in Italy

This is triage, not advice on Italian criminal law.

  1. Is any system high-risk under Article 6? If not, Article 437-bis does not reach it. The Article 17 disclosure rules and the Article 18 presumption are not limited to high-risk systems, and Articles 4, 11 and 13 of Law 132/2025 and Article 612-quater of the penal code may still apply.
  2. For each high-risk system, who in Italy is the professional user? Check that Article 26(2) oversight is assigned to named people with the competence and authority to intervene, because intentional omission there is now a crime where danger results.
  3. Can you produce the Article 9, 11, 12 and 14 documentation on demand? In an Italian damages claim, failing to produce it can mean the claimant's facts are treated as admitted.
  4. Does your Decree 231 model cover AI? Article 25-vicies makes Article 437-bis and 612-quater predicate offences.
  5. Watch for the second decree. Until it is published, the procedure and national amounts for Article 99 fines in Italy are not fixed in law.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What is the Italian AI law?

It is Law 23 September 2025 n. 132, "Disposizioni e deleghe al Governo in materia di intelligenza artificiale", published in Gazzetta Ufficiale general series n. 223 of 25 September 2025 and in force since 10 October 2025. It sets national principles, sector rules, designates the AI Act authorities in Article 20 and, in Article 24, delegates the Government to adapt Italian law to Regulation (EU) 2024/1689 by legislative decree. Legislative Decree n. 160 of 9 September 2026 was adopted under Article 24(1), (2)(h), (3) and (5) of that law.

Who is the AI Act regulator in Italy?

ACN, the national cybersecurity agency, is the market surveillance authority and single point of contact under Article 20(2) of Law 132/2025, and AgID is the notifying authority that designates and monitors conformity assessment bodies. Banca d'Italia, CONSOB and IVASS keep the market surveillance role for financial entities provided for in Article 74(6) of the AI Act, and Article 20(4) preserves the powers of the Garante per la protezione dei dati personali and of AGCOM as Digital Services Coordinator.

Is it a crime in Italy not to put human oversight on a high-risk AI system?

It can be, since 30 September 2026. Article 437-bis of the penal code, inserted by Article 12 of Legislative Decree 160/2026, punishes anyone who fails to adopt the technical safety measures provided for high-risk AI systems, or fails to adopt human oversight measures, with one to five years' imprisonment where danger to life or public or individual safety results, and two to eight years where danger to State security results. A professional user who intentionally omits human oversight faces the same penalties. The offence requires that danger to result; an omission alone is not enough.

Is creating or sharing a deepfake a crime in Italy?

Sharing one can be. Article 612-quater of the penal code, inserted by Article 26 of Law 132/2025, punishes anyone who causes unjust harm to a person by transferring, publishing or otherwise disseminating, without consent, AI-falsified or altered images, video or voices capable of deceiving as to their genuineness, with one to five years' imprisonment. It is prosecuted on the victim's complaint, except in the cases the article lists. This sits alongside, not in place of, the AI Act's Article 50(4) disclosure duty on deployers.

What AI Act fines apply in Italy?

The ceilings in Article 99 of the AI Act, up to 35,000,000 euro or 7 percent of worldwide annual turnover for prohibited practices, apply directly, but Article 99(1) leaves the rules on imposing them to national law. Article 24(2)(d) of Law 132/2025 delegates that to the Government, and the decree implementing it was approved on 4 August 2026 but had not appeared in any Gazzetta Ufficiale general series issue up to 3 October 2026. Its final text, including the lower national maximums the Government announced, cannot be relied on until it is published.

Do children need parental consent to use AI in Italy?

Under 14, yes. Article 4(4) of Law 132/2025 provides that access to AI technologies by minors under fourteen, and the resulting processing of personal data, requires the consent of whoever holds parental responsibility. A minor aged fourteen to seventeen can consent to the related data processing, provided the information about it is easily accessible and understandable.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 5 October 2026. Final classification for ambiguous cases needs qualified counsel.