On 10 June 2026, the Italian Council of Ministers approved, at a preliminary stage, two draft legislative decrees on artificial intelligence.

The first draft concerns the powers of national authorities, supervision, sanctions, testing environments and training, and also contains provisions relating to employment.

The second draft regulates the use of artificial intelligence systems in policing and introduces provisions on civil and criminal liability.

It should be made clear from the outset that these are not yet final texts. The drafts have been approved at a preliminary stage and must complete the required procedure, with possible amendments before final approval and publication in the Official Gazette.

This initiative falls within the framework of Law No. 132 of 23 September 2025, which sets out provisions and delegates powers to the Government regarding artificial intelligence, and of EU Regulation 2024/1689, namely the AI Act. The rationale is to align the national legal system with the European framework, not to create a parallel or alternative Italian regime.

Executive summary

The package approved by the Government confirms that Italian AI regulation is entering a more operational phase.

The most significant areas are:

  • national governance of the AI Act, with a central role for AgID and ACN;
  • supervision, inspection powers and sanctions;
  • sandboxes and regulatory experimentation;
  • AI in work processes and in decisions affecting workers;
  • training and AI literacy;
  • use of AI by the police, with specific regulations for biometrics and facial recognition;
  • civil liability, access to evidence and presumption of causation;
  • criminal liability and potential impact on 231 models; and
  • protection of data, algorithms and training methods as trade secrets, where the conditions apply.

AI is not treated as an isolated technology, but as an organisational and decision-making infrastructure requiring governance, documentation, controls, internal accountability and appropriate contracts.

1. National governance: AgID, ACN and sectoral authorities

According to the first draft decree, the national authorities for artificial intelligence are AgID and ACN.

AgID acts as the national notification authority, with powers relating to notification procedures and conformity assessment bodies. ACN, on the other hand, plays a central role in market surveillance for AI systems and is designated as the single point of contact.

The role of sectoral authorities remains unchanged, particularly in the banking, financial and insurance sectors. The draft decree identifies the Bank of Italy, CONSOB and IVASS as the competent authorities in their respective fields, in addition to the Data Protection Authority within the limits of its relevant remit.

For regulated firms, this is a key point. AI compliance will not be merely an internal policy matter, nor solely a privacy issue. Depending on the circumstances, it may involve ACN, AgID, the Data Protection Authority, the Bank of Italy, IVASS, CONSOB and other competent authorities.

2. Sanctions: alignment with the AI Act, but with a national framework

The first draft decree provides for a structured system of sanctions, coordinated with the AI Act.

For the most serious violations, relating to practices prohibited by Article 5 of the AI Act, the penalty may reach up to €35 million or, if higher, up to 7% of the total annual global turnover of the previous financial year. Lower thresholds are also provided for other categories of obligations, including those of providers, deployers, notified bodies, transparency and reporting to the authorities.

The penalty figure is significant, but it is not the most important aspect. The real issue for businesses will be the ability to demonstrate an effective control system: classification of AI systems, AI Act roles, technical documentation, logging, human oversight, risk management, incident management, post-deployment monitoring and change control.

Looking ahead, organisations will need to be able to demonstrate not only that they have ‘an AI policy’, but that they have verifiable processes for acquiring, developing, using, modifying and decommissioning AI systems.

3. Work: an end to exclusively automated decisions

One of the most significant aspects concerns employment.

The first draft decree stipulates that, in decision-making processes concerning the employment relationship, employers using AI systems must ensure that decisions relating to the establishment, modification or termination of the relationship, including disciplinary measures, are not taken solely on the basis of automated processing.

The final decision must be reserved for a natural person exercising effective and independent authority.

The employee would also be entitled, upon request and through human intervention, to receive a comprehensible explanation of the decision, including an indication of any impact the AI system had on the decision-making process and the main parameters considered. The draft also provides for the nullity of any dismissal issued in breach of the prohibition on exclusively automated decisions.

This may affect recruitment systems, candidate screening, workforce management, performance management, internal scoring, automated scheduling, people analytics, disciplinary systems and tools for monitoring or assessing productivity.

The issue will not be merely formal. It will not suffice to state that ‘the final decision is human’ if, in practice, the system’s output substantially determines or influences the decision. Companies will have to document the role of human intervention, the possibility of challenging the decision, the main decision-making logic, anti-discrimination safeguards and information obligations.

4. Health and safety at work

The first draft decree also introduces an explicit link between AI and health and safety in the workplace.

The use of AI systems that affect the organisation of work, production rates, the manner in which work is performed, or decision-making processes relevant to safety should be assessed as part of the risk assessment under Legislative Decree 81/2008.

Employers should also ensure that information and training are provided on the specific risks associated with the use of AI systems and on the prevention and protection measures adopted.

This profile may be particularly relevant for logistics, manufacturing, retail, digital platforms, healthcare, financial services, contact centres and organisations that use AI tools to optimise shifts, workloads, operational priorities or performance monitoring.

5. Training, AI literacy, universities, professions and the public administration

The first draft decree devotes a significant section to training. Measures are envisaged for schools, teacher training, adult literacy, professional retraining, public administration, universities, research bodies, AFAM, ITS Academy, the administration of justice, professions and healthcare.

These provisions reflect Article 4 of the AI Act, which require providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and other persons operating or using AI systems on their behalf.

Training should therefore not be treated as a generic course on AI. It will need to be tailored to specific roles: board and management, legal, compliance, privacy, risk, procurement, HR, IT, cybersecurity, data science, business owners and end users.

The content must vary depending on the type of AI system used, the level of risk, the business process involved and the people affected by the outputs.

6. Police, biometrics and facial recognition

The second draft decree governs the use of AI by the police.

The approach is to permit the use of AI systems as support tools, with qualified human oversight, traceability and respect for fundamental rights. For high-risk systems, human oversight must be effective and compliant with the AI Act.

The most sensitive provision concerns real-time remote biometric identification in public places or places open to the public. The decree permits this only for limited purposes, such as preventing specific threats or searching for missing persons or victims of certain crimes.

Biometric matching must be carried out against appropriate reference databases, and the decree prohibits the use of biometric databases populated, in whole or in part, through non-targeted scraping or created in breach of data protection legislation.

Procedural, temporal and territorial limits are provided for. Authorisation must relate to a specific event or the time strictly necessary, in any case not exceeding fifteen days, with possible justified extensions.

In the event of non-compliance with the conditions, use must be discontinued, the data and outputs must be deleted, and the results may not be used.

In criminal proceedings, the framework provides for the involvement of the public prosecutor and the judge for preliminary investigations. The public prosecutor requests authorisation from the judge for preliminary investigations, who issues a reasoned decree; emergency procedures with subsequent validation are provided for.

For technology providers, this is not merely a public sector issue. Those who develop or supply biometric solutions, video analytics, identity verification, cybersecurity, law enforcement technology or data analytics platforms must carefully assess the intended purpose, context of use, contractual limitations, audits, logging, accountability and prohibited use clauses.

7. Criminal liability and 231 models

The second draft decree introduces a new criminal offence relating to the failure to adopt security measures in AI systems and the unlawful alteration of systems.

The offence concerns, in particular, high-risk AI systems and conduct such as design, training, production, placing on the market or professional use in the absence of appropriate technical measures to prevent malfunctions or alterations, or in the absence of human supervision, where this results in a concrete danger to life, personal safety, public safety or national security.

The draft also provides for the inclusion in Legislative Decree 231/2001 of offences related to the use of AI systems, including the new Article 437-bis of the Criminal Code; the draft also refers to Article 612-quater of the Criminal Code, which will be assessed separately in the final text.

This is a point of great significance for businesses. If confirmed in the final text, AI governance could also become a 231 issue, at least for organisations that develop, train, place on the market or professionally use high-risk AI systems.

Organisational models should therefore include safeguards regarding security, human oversight, change control, testing, logging, incident management and the traceability of technical decisions.

8. Civil liability: access to evidence and presumption of causation

In civil matters, the second draft decree does not appear to introduce a generalised strict liability regime for AI.

The approach taken is different: strengthening the injured party’s means of proof, access to relevant documentation, and a relative presumption of causation in the event of a breach of obligations under the AI Act.

In particular, the court may order the production of evidence relating to the operation of the AI system, including logs, risk management system documentation, technical documentation and information regarding parameters and methods of human supervision.

The framework also provides safeguards for trade secrets and confidential information.

There is also a presumption of a causal link where the harm results from a breach of one or more obligations under the AI Act, subject to proof to the contrary. The AI system’s compliance with the obligations of the AI Act, even if certified, does not in itself exclude the defendant’s liability.

For businesses, this reinforces the importance of documentation. The practical question becomes: in the event of a dispute, are we able to produce logs, risk assessments, technical documentation, user instructions, evidence of human oversight, tests, change logs and governance decisions?

9. Insurance and direct action

The second draft decree also contains provisions on direct action against an insurance company.

Anyone intending to bring a claim for compensation could ask the party deemed liable whether there is insurance cover for civil liability relating to the damage. If cover exists, the injured party would have a direct claim against the insurer up to the limit of the policy.

This aspect is relevant not only for litigation but also for the structuring of insurance programmes. Companies should verify whether and how AI risks are covered by cyber, professional indemnity, product liability, D&O, E&O or other policies, and whether there are specific exclusions relating to algorithms, models, automated outputs, high-risk systems or non-compliant use.

10. Data, algorithms and training methods as trade secrets

A particularly interesting aspect for technology companies, developers, AI providers and industrial groups is the provision relating to the Industrial Property Code.

The second draft decree provides that, among the business information and technical-industrial know-how eligible for protection as trade secrets, data, algorithms and mathematical methods for training AI systems may also be included, provided the legal requirements are met.

In particular, this refers to model architectures, optimisation functions, training procedures and configurations, and other technical and computational elements instrumental to the development of AI systems.

If confirmed, this provision could have significant implications for AI development contracts, licensing, technology outsourcing, research partnerships, joint development, data sharing, procurement and M&A due diligence.

Protection will not be automatic: the standard requirements for trade secrets will still apply, including confidentiality, the economic value derived from confidentiality, and the adoption of reasonable measures to maintain it.

11. Operational implications for businesses

Even before final approval, businesses should start working on certain priority areas.

The first is mapping AI systems. Many organisations do not yet have a reliable inventory of the AI systems in use, including tools embedded in third-party software, HR platforms, CRM, cybersecurity, analytics, procurement, document automation, customer service and generative tools used by employees.

The second is the classification of systems. A distinction must be made between prohibited practices, high-risk systems, systems subject to transparency obligations, general-purpose AI and tools with lower risk. This classification must be documented and updated over time.

The third is technology procurement. AI contracts should not be treated as standard software or SaaS contracts. Clauses are required covering the role of the AI Act, intended purpose, technical documentation, user instructions, data, output, IP, logging, audits, cybersecurity, incident management, system modification, retraining, fine-tuning, subcontractors, cooperation with authorities and allocation of liability.

The fourth is internal governance. Legal, compliance, privacy, cyber, procurement, HR, risk, IT and business owners must have clearly defined roles. AI governance cannot be left solely to IT or the innovation function.

The fifth is the workplace. Tools affecting recruitment, assessment, performance, disciplinary measures, dismissal, work organisation or safety must be subject to a specific review.

The sixth is evidential documentation. Future AI risk management will also depend on the ability to produce evidence: logs, risk assessments, tests, validations, human oversight, instructions, data checks, change logs, incident reports and governance decisions.

The seventh is training. AI literacy must be practical, tailored to specific roles and linked to the systems actually used by the organisation.

Conclusion

The Government has launched the national implementation phase of the AI Act. The decrees are not yet final, but they clearly indicate the direction of Italian regulation: AI must be governed through an integrated system of compliance, cybersecurity, data protection, supplier oversight, internal accountability, training, documentation and traceability.

For businesses, the issue is not merely ‘being compliant’ when the decrees come into force. The issue is being prepared, including knowing where AI is used, by whom, with which suppliers, in which processes, with what data, with what impact on people, with what human supervision, with what documentary evidence and with what contractual allocation of responsibilities.

For more information on AI and its effects across the globe, you can view our new campaign Algorithm to Advantage – making AI clarity your competitive advantage.