AI Act · Italy
EU AI Act enforcement in Italy
Italy put AI supervision with its cybersecurity agency and then did something no other member state has done: it made AI misuse a crime.
Everywhere else in this series the question is what the fine will be. Italy added a second question.
Law No. 132 of 23 September 2025, published on 25 September and in force from 10 October 2025, is the first dedicated national AI statute in the Union. It designates the supervisors, and it also amends the criminal code.
Who holds what
| Body | Role |
|---|---|
| ACN — National Cybersecurity Agency | Market surveillance authority. Inspection and sanctioning powers. Single point of contact with the EU institutions |
| AgID — Digital Italy Agency | Promotes AI development; notifies and assesses conformity assessment bodies; monitors compliance |
| Banca d'Italia, CONSOB, IVASS | Banking, securities and insurance keep oversight in their own domains |
| Special committee, Presidency of the Council of Ministers | Coordination at government level |
| Ministries by delegation | Decrees governing AI in named sectors — health and justice among them |
The split is worth reading carefully. AgID handles the notifying side — the machinery of conformity assessment. ACN does the enforcing, and ACN is a cybersecurity agency.
That is a fifth kind of regulator, and the series now has the full set. Germany routes to an engineering regulator, France and the Netherlands to their privacy authorities, Ireland to an employment body for workplace practices, Spain to a purpose-built AI agency, and Italy to a cybersecurity agency. Each arrives with a different first question. A privacy regulator asks what the individual was told. An engineering regulator asks whether the system meets spec. A cybersecurity agency asks who could reach it, what it was allowed to do, and what the logs show.
The part with no equivalent anywhere else
Law 132/2025 makes three changes to Italian criminal law.
1 · Disseminating AI-altered media
A new Article 612-quater creates an offence of publishing AI-altered images, video or audio likely to mislead as to their authenticity, punishable by one to five years' imprisonment.
2 · Text and data mining against an opt-out
Amendments to Article 171 criminalise unauthorised text and data mining that breaches rightsholders' reserved rights. Training-data provenance stops being purely a licensing question in Italy.
3 · The aggravating circumstance, which reaches furthest
Article 61, no. 11-decies adds a general aggravating circumstance: where an AI system facilitated the offence, the penalty increases by up to a third. It is drafted generally rather than as a list of AI-specific crimes. Fraud and identity theft are the examples usually given.
Read that third one as an organisation, not as a lawyer. It does not create a compliance obligation you can map to a control. It changes the consequences of misconduct that happens to run through an automated system — and the more of your operations run through agents, the larger the surface it touches. A fraud committed by a person using a tool your organisation built and did not monitor is still that person's crime. But the sentencing exposure moves, and the question of what the system was permitted to do, and who was watching, moves with it.
From 30 September 2026: the decree that reaches deployers
Law 132/2025 delegated the detail to the government. Two legislative decrees followed — preliminary approval on 10 June 2026, final approval on 4 August 2026 — and the first to reach the Official Gazette changes the picture above. Legislative Decree 160 of 9 September 2026 was published on 15 September and applies from 30 September 2026.
It adds Article 437-bis to the Criminal Code: failing to adopt adequate security measures, or to provide human oversight, for a high-risk AI system — across design, training, production, placing on the market and professional use. It requires a concrete danger, not a paperwork gap.
| Conduct | Penalty |
|---|---|
| Omitted safety measures or oversight, endangering individual life or safety | 1–5 years' imprisonment |
| The same, endangering public safety or state security | 2–8 years |
| Unlawful alteration of a high-risk system | 2–6 years; 3–10 where public safety is endangered |
| Gross negligence rather than intent | Reduced by one-third to one-sixth |
“Professional use” is what makes this a deployer's problem and not only a provider's. The three changes above concern misuse. This one concerns neglect: running a high-risk system without the oversight the Act requires can, where it puts someone in concrete danger, be a crime.
The company, not only the individual
The decree makes Article 437-bis a predicate offence under Legislative Decree 231/2001, Italy's corporate liability regime, at 600 to 1,000 quotas, and does the same for the Article 612-quater deepfake offence at 200 to 700 quotas. The defence is the usual 231 one: a company that adopted and effectively implemented an organisational, management and control model addressing the risk can avoid liability. A model can only cover systems somebody has listed.
And damage is easier to prove
- Disclosure. Courts can order production of logs, risk management documentation, technical files and human oversight records, and draw adverse inferences from an unjustified refusal.
- Presumed causation. Where damage follows a breach of an AI Act obligation, the causal link is presumed unless the defendant proves otherwise.
- Direct action against the insurer, within policy limits.
The same decree requires judicial authorisation, for at most fifteen days at a time, before police use real-time biometric identification.
What the law asks in specific sectors
| Sector | Rule |
|---|---|
| Employment | AI must be safe, reliable, transparent and non-discriminatory. It may not replace human performance or undermine worker dignity. Workers have the right to know when AI systems are in use. A monitoring observatory was established. Under the implementing decrees, a dismissal decided solely by automated processing is void |
| Healthcare | The physician keeps final therapeutic authority. Patients must be informed of AI involvement, including the logic and benefits of an AI-assisted diagnosis. AGENAS is to run a support platform issuing non-binding recommendations |
| Public administration | AI is limited to decision support. The human official remains accountable for the decision |
| Justice | Legislative Decree 160/2026 governs police use of AI: human review of outputs, and judicial authorisation for real-time biometric identification |
Commentary disagrees on whether this amounts to obligations beyond the AI Act. One reading is that the sectoral provisions largely restate principles the Regulation already carries, and the law is complementary rather than additive. The criminal provisions are a different matter: they are criminal law, a separate instrument from the Act's administrative regime, and nothing in the Regulation produces them.
The workplace disclosure duty is the one most likely to bite a deployer in practice. Workers have a right to know when AI is in use — a positive duty on the employer, owed to the workforce, not a filing owed to a regulator.
Where Italy stands
| Item | Position |
|---|---|
| Article 70 designation | Complete — one of nine member states |
| Instrument | Law No. 132 of 23 September 2025; published 25 September; in force 10 October 2025 |
| Distinction | First dedicated national AI statute in the Union |
| Market surveillance | ACN — National Cybersecurity Agency |
| Notifying authority | AgID |
| Single point of contact | ACN |
| Implementing decrees | Final approval 4 August 2026; Legislative Decree 160/2026 applies from 30 September 2026 |
| Criminal exposure | Deepfake dissemination 1–5 years; TDM against opt-out; + up to one third on any offence facilitated by AI; from 30 September, Article 437-bis for omitted safety measures or oversight on high-risk AI |
| Corporate liability | Articles 437-bis and 612-quater added to Legislative Decree 231/2001 |
| High-risk obligations apply | 2 December 2027 (stand-alone) · 2 August 2028 (embedded) |
| Prohibitions in force since | 2 February 2025 |
What an Italian deployer should do now
- Prepare for a security regulator's questions, not a lawyer's. ACN enforces, and it comes from cyber defence. Expect access paths, permissions, authentication and logs to be the substance of an inspection, rather than a conformity file reviewed on paper.
- Add AI to your 231 model before 30 September. The corporate defence depends on a model that was adopted and effectively implemented before anything went wrong, and it can only cover the systems and agents you have enumerated.
- Treat human oversight as evidence, not intent. Italian courts can now order oversight records and presume causation where an AI Act breach caused damage. Oversight that happened but left no record is hard to prove.
- Tell your workforce. The right to know that AI is in use is a positive duty owed to workers. It is satisfied by disclosure, which is cheap, and breached by silence, which is not.
- Know where your training data came from. The Article 171 amendments put text and data mining against a reserved right into criminal territory. Provenance becomes something to be able to demonstrate.
- Do not treat the aggravating circumstance as somebody else's problem. It does not require an AI-specific crime. The practical defence is the ordinary one — an agent that can only do what it was meant to do, and a record showing what it did.
- Start the six-month log retention now. Article 26 requires deployers to keep system logs for at least six months. Logs not kept cannot be reconstructed, so the system needs to be running correctly by roughly mid-2027 to have a compliant record on day one. In Italy that record has a second audience.
Questions
Who enforces the EU AI Act in Italy?
Two national bodies under Law No. 132/2025. The National Cybersecurity Agency, ACN, is the market surveillance authority with inspection and sanctioning powers and the single point of contact with the EU institutions. The Digital Italy Agency, AgID, promotes AI development, notifies and assesses conformity assessment bodies, and monitors compliance. Banking, financial and insurance regulators keep oversight in their own domains, and a special committee sits within the Presidency of the Council of Ministers.
What makes Italy different from other member states?
Criminal law. Italy is the only member state in this series where using AI can be a crime rather than only an administrative breach. Law 132/2025 created an offence for disseminating AI-altered media likely to mislead as to authenticity, carrying one to five years' imprisonment, criminalised text and data mining that breaches opt-out rights, and — the provision with the widest reach — added a general aggravating circumstance that increases the penalty for any offence by up to a third when an AI system helped commit it.
Can failing to oversee an AI system be a crime in Italy?
From 30 September 2026, yes, for high-risk systems where it creates a concrete danger. Legislative Decree 160/2026 adds Article 437-bis to the Criminal Code, covering failure to adopt adequate security measures or human oversight across design, training, production, placing on the market and professional use. Penalties run from one to five years where individual safety is endangered and two to eight years where public safety is. It is also a predicate offence for corporate liability under Legislative Decree 231/2001, where a company can defend itself with an effectively implemented control model.
Does the aggravating circumstance apply to ordinary business crime?
It is drafted generally, applying where an AI system facilitated the offence rather than being limited to a list of AI-specific crimes. Fraud and identity theft are the examples most commonly cited. An organisation should read it as changing the consequences of misconduct that happens to run through an automated system, not as a separate AI offence it can scope out of.
What does Italy require in employment and healthcare?
In employment, AI must be safe, reliable, transparent and non-discriminatory, it may not replace human performance or undermine worker dignity, and workers have the right to know when AI systems are in use. In healthcare, the physician keeps final therapeutic authority and patients must be informed of AI involvement, including the logic and benefits of an AI-assisted diagnosis. In public administration, AI is limited to decision support and the human official stays accountable.
Has Italy completed its Article 70 designation?
Yes. Italy is among the nine member states that completed designation, and it did so through a full national statute rather than an instrument — Law No. 132/2025, published 25 September 2025 and in force from 10 October 2025, the first dedicated national AI law in the Union.
Related
Agent Trust Cloud
We publish this because the deployer side of the AI Act is widely misread, and Italy is misread as simply the country that legislated first. The consequential part is who enforces and with what. A cybersecurity agency inspecting an AI estate asks what each system could reach and what the logs show — which is the question we exist to answer. Agent Trust Cloud is building a control plane for AI agents — identity, policy, evidence. The platform is in development and is not sold as a subscription today; what is available now is a fixed-scope assessment of the agents and machine identities you already have.