act · Effective Jan 1, 2025
IT regulates AI through Legge n.132 del 23 settembre 2025 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale.
Legge n.132 del 23 settembre 2025 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
As of early 2026, Italy has transitioned from a strategy-led approach to a comprehensive, legally binding regulatory framework for artificial intelligence. The cornerstone of this regime is Law No. 132 of September 23, 2025 (Legge 23 settembre 2025, n. 132), which serves as the primary national statute for AI development, adoption, and oversight. This legislation was designed to operate in strict harmony with the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689), while addressing specific Italian priorities such as data sovereignty, the protection of minors, and the integration of AI within the public administration (PA). Italy’s regulatory philosophy is explicitly 'anthropocentric,' a term codified in national law to ensure that AI systems remain under human control and respect fundamental rights, non-discrimination, and transparency. This approach is deeply rooted in the Italian constitutional tradition, which emphasizes the dignity of the person and the protection of labor. The Italian government has viewed AI not merely as a technical tool but as a transformative force that requires a strong ethical and legal foundation to prevent the erosion of democratic values. This transition was accelerated by the National Recovery and Resilience Plan (PNRR), which allocated significant resources to digital transformation, positioning AI as a central pillar of Italy's future economic competitiveness. Italy’s journey toward AI regulation was marked by early, proactive interventions, most notably the 2023 temporary limitation of ChatGPT by the Italian Data Protection Authority (Garante). This event signaled Italy's commitment to rigorous data protection standards in the age of generative AI and served as a catalyst for the broader legislative debate. Today, the landscape is characterized by a multi-layered governance structure involving the Presidency of the Council, the Agency for Digital Italy (AgID), and the National Cybersecurity Agency (ACN). The national strategy (2024-2026) complements this legal framework by focusing on the 'Data Valley' vision, leveraging Italy's high-performance computing (HPC) infrastructure—such as the Leonardo supercomputer hosted at Cineca—to support small and medium-sized enterprises (SMEs) and public sector innovation. This infrastructure is seen as a strategic asset, ensuring that Italy can develop and train large-scale AI models locally, reducing dependence on non-EU technology providers and fostering a domestic ecosystem of AI excellence.
Regulatory approach
Italy employs a hybrid regulatory approach that combines horizontal, cross-sectoral mandates with specific sectoral rules. The horizontal layer is provided by Law 132/2025, which establishes the general principles of transparency, accountability, and risk management applicable to all AI providers and deployers. This law adopts the EU AI Act’s risk-based classification system, distinguishing between prohibited practices, high-risk systems, and general-purpose AI models. However, Italy has added unique national layers, such as the requirement for public administrations to host AI systems on servers located within the national territory to preserve strategic autonomy and security. This 'localization' requirement is a key differentiator of the Italian model, reflecting a broader European trend toward digital sovereignty. The Italian approach also emphasizes the 'human-in-the-loop' principle, mandating that for any AI system used in critical decision-making, there must be a clear path for human intervention and override. This is particularly relevant in the context of administrative acts, where the right to a human-led review is considered a fundamental procedural safeguard. The sectoral layer is highly developed in the areas of public administration, healthcare, and labor. For the public sector, the AgID 'Linee guida' (Guidelines) provide a prescriptive operational framework for procurement and deployment, emphasizing auditability and human oversight. These guidelines require public bodies to conduct thorough impact assessments before deploying AI, focusing on potential biases and the impact on vulnerable populations. In healthcare, Italian law mandates that AI serve only as clinical decision support, ensuring that final medical decisions are always made by a human professional. This risk-based approach is further supported by 'soft law' instruments, such as the Three-Year ICT Plan (Piano Triennale), which provides public bodies with templates, checklists, and sandboxes for safe experimentation before full-scale deployment. These sandboxes are designed to allow for 'controlled innovation,' where companies can test new algorithms in a real-world environment under the watchful eye of regulators, ensuring that safety and ethical standards are met from the design phase. The Italian governance model for AI is decentralized but highly coordinated, reflecting the complexity of the technology. The Presidency of the Council of Ministers, through the Department for Digital Transformation, leads the national strategy and inter-ministerial coordination. However, the technical and enforcement powers are primarily split between two agencies: the Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN). AgID is responsible for the promotion of innovation, the management of notification procedures for high-risk systems, and the accreditation of conformity-assessment bodies. It acts as the primary interface for public administrations looking to adopt AI solutions, providing technical assistance and ensuring that AI systems are interoperable with existing digital infrastructures. AgID also maintains the national registry of high-risk AI systems, providing a level of transparency that is central to the Italian regulatory philosophy. Conversely, the National Cybersecurity Agency (ACN) serves as the market surveillance authority. Its mandate includes conducting inspections, monitoring the technical robustness of AI models, and ensuring that AI systems do not introduce systemic vulnerabilities into national critical infrastructure. ACN’s role is particularly critical in the context of 'dual-use' AI technologies that could have implications for national security. Additionally, the Italian Data Protection Authority (Garante per la protezione dei dati personali) remains a central actor, exercising its powers under the GDPR to oversee how AI systems process personal data. The Garante has the power to block AI systems that do not comply with privacy-by-design principles. Sectoral regulators, such as the Bank of Italy and CONSOB, retain oversight for AI applications within the financial and insurance markets, ensuring that AI-driven trading or credit scoring complies with existing financial stability rules and consumer protection laws. This multi-agency approach ensures that AI is regulated from multiple perspectives: innovation, security, privacy, and financial stability.
Enforcement & penalties
Enforcement in Italy involves a combination of administrative fines and new criminal sanctions, creating a comprehensive deterrent framework. Under Law 132/2025, administrative penalties for non-compliance with the EU AI Act’s requirements (such as deploying prohibited AI systems or failing to meet high-risk documentation standards) are aligned with the significant fines set at the EU level, which can reach up to €35 million or 7% of global annual turnover. ACN has the power to issue corrective orders, suspend the use of non-compliant systems, and impose daily penalty payments for non-compliance with its directives. These administrative measures are designed to ensure rapid compliance and to remove dangerous or non-compliant products from the market before they can cause widespread harm. The enforcement process is also designed to be transparent, with ACN required to publish summaries of its enforcement actions to inform the public and other market participants. A distinctive feature of the Italian regime is the introduction of specific criminal provisions in the Penal Code. Article 612-quater of the Italian Penal Code now criminalizes the illicit dissemination of AI-generated or altered content (deepfakes) that causes unjust damage to individuals, punishable by 1 to 5 years of imprisonment. This measure was introduced in response to the growing threat of AI-enabled harassment and disinformation. Furthermore, Law 132/2025 introduces aggravating circumstances for traditional crimes—such as market manipulation, fraud, or defamation—when they are committed using AI systems. These measures reflect the Italian legislature's intent to deter the use of AI for social harm and to ensure that the technology is not used to circumvent existing legal protections. By integrating AI-specific crimes into the Penal Code, Italy has sent a clear message that the misuse of advanced technology will be met with the full force of the law, ensuring that the 'digital' world is subject to the same ethical and legal standards as the physical one.
Data protection
The data protection framework for AI in Italy is anchored in the EU General Data Protection Regulation (GDPR) and the national Data Protection Code (Legislative Decree 196/2003). The Garante has been exceptionally active in interpreting how these laws apply to AI training and deployment. In May 2024, the Garante issued Provvedimento n. 329, which provides specific guidance on 'web scraping' for AI training. This note emphasizes that site operators must implement technical and organizational measures—such as robots.txt updates, rate limiting, and CAPTCHAs—to protect personal data from indiscriminate harvesting by AI bots. The Garante has also emphasized the importance of the 'legal basis' for processing, arguing that 'legitimate interest' cannot be used as a blanket justification for the mass collection of personal data for AI training without adequate safeguards and opt-out mechanisms for data subjects. Furthermore, Law 132/2025 reinforces data sovereignty by requiring that AI systems used by public administrations for sensitive functions (such as justice or social benefits) must host their data on national or 'qualified' cloud infrastructures, such as the Polo Strategico Nazionale (PSN). This ensures that the data of Italian citizens remains subject to Italian and EU jurisdiction and is protected against unauthorized access by third-country authorities. The Garante also requires mandatory Data Protection Impact Assessments (DPIAs) for any AI system that involves large-scale profiling or the processing of sensitive 'special category' data. These DPIAs must specifically address the risks of algorithmic bias and the potential for discriminatory outcomes. The Italian framework thus creates a high bar for data protection, ensuring that the development of AI does not come at the expense of individual privacy or the security of national data assets.
Sector-specific rules
Italy has established clear 'red lines' and specific requirements for AI in high-stakes sectors to protect fundamental rights. In the Public Administration, AI use is governed by AgID’s 2025 guidelines, which mandate that any automated decision-making process must include a 'human-in-the-loop' mechanism. This ensures that citizens can always contest an AI-generated decision and receive a human-led review. The guidelines also require that the algorithms used by public bodies be 'explainable,' meaning that the logic behind a decision must be understandable to both the administrator and the citizen. In the labor market, Law 132/2025 requires employers to provide transparent information to workers and unions regarding the use of AI for recruitment, performance evaluation, or workplace monitoring. It strictly prohibits AI-driven surveillance that infringes on worker dignity or that uses biometric data for emotional recognition in the workplace. In the healthcare sector, the law clarifies that AI systems are tools for clinical decision support and cannot replace the professional judgment of medical practitioners. There are strict requirements for the transparency of algorithms used in diagnostics to ensure that doctors understand the logic behind an AI recommendation and can identify potential errors. In the justice system, AI is permitted only for administrative and research tasks; its use for judicial decision-making or 'predictive justice' is heavily restricted to prevent biases from affecting the right to a fair trial. These sectoral rules are designed to prevent the 'black box' effect in areas where human rights and safety are most at risk. By providing clear, sector-specific guidance, Italy aims to foster trust in AI among both professionals and the general public, ensuring that the technology is seen as a helpful assistant rather than a mysterious or threatening force.
International alignment
Italy’s AI framework is a model of international alignment, primarily centered on the EU AI Act. Law 132/2025 explicitly states that national measures must be interpreted in conformity with Regulation (EU) 2024/1689. This ensures that Italian companies can operate seamlessly across the European Digital Single Market without facing conflicting national requirements. Italy has also been a proactive participant in the G7, using its 2024 presidency to promote the 'Hiroshima AI Process' and the 'Apulia AI Hub for Sustainable Development.' These initiatives aim to create global consensus on AI ethics and to bridge the digital divide between the Global North and South, emphasizing the need for inclusive AI that benefits all of humanity. Italy has also championed the concept of 'AI for Peace,' advocating for international norms to prevent the use of AI in autonomous weapon systems. Beyond the EU, Italy adheres to the OECD Council Recommendation on Artificial Intelligence and participates in the Council of Europe’s efforts to draft a framework convention on AI and human rights. The Italian strategy emphasizes 'technological sovereignty,' but it does so through partnerships with EU neighbors and by supporting the development of a 'European AI ecosystem.' This includes aligning national standards for AI testing and certification with those developed by CEN/CENELEC at the European level, ensuring that Italian AI products can move freely within the Digital Single Market. Italy also participates in the 'AI Alliance,' a multi-stakeholder forum that brings together industry, academia, and civil society to discuss the future of AI governance. This international engagement ensures that Italy remains at the forefront of the global AI debate, contributing its unique perspective on the importance of human-centric technology.
What's next
The regulatory landscape in Italy is expected to evolve rapidly through 2026 as the Government exercises the delegated powers granted by Law 132/2025. Over the next 12 months, a series of Legislative Decrees (decreti legislativi) will be issued to define the precise technical standards for conformity assessments, the specific thresholds for 'high-risk' systems in the national context, and the procedural rules for the newly established AI sandboxes. These sandboxes will allow companies to test innovative AI solutions under the supervision of AgID and ACN before they are brought to market, providing a safe space for experimentation. The government is also expected to launch a national 'AI Literacy' campaign to ensure that citizens and workers have the skills necessary to navigate an AI-driven economy. This will include funding for university research centers and vocational training programs focused on AI ethics and technical development. Additionally, the Italian government is expected to update the National AI Strategy in late 2026 to account for advancements in quantum computing and its intersection with AI. There is also ongoing legislative debate regarding the 'Right to Explanation' for AI-driven decisions in the private sector, which could lead to further amendments to the Consumer Code. As the EU AI Act becomes fully applicable in August 2026, Italy will likely focus on refining its market surveillance mechanisms and ensuring that the dual-agency model between AgID and ACN operates efficiently without creating bureaucratic overlap for businesses. The goal is to create a regulatory environment that is both rigorous and agile, capable of keeping pace with the rapid development of AI technology while providing the legal certainty that businesses need to invest and innovate. Future developments will also likely focus on the environmental impact of AI, with potential regulations requiring transparency regarding the energy consumption of large-scale AI models.
act · Effective Jan 1, 2025
act · Effective Jan 1, 2025
guideline · Effective Jan 1, 2025
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
regulation · Effective Jan 1, 2023
policy · Effective Jan 1, 2022
policy · Effective Jan 1, 2021
policy · Effective Jan 1, 2021
enforcement
Promotion of digital innovation and PA transformation. National AI authority for notification and accreditation.
enforcement
National authority for cybersecurity and AI market surveillance.
data_protection
Supervision of personal data protection and privacy compliance.
advisory
Strategic coordination of national digital and AI policies.
Apr 28, 2026 · news
Communications Regulatory Authority files request to European Commission to evaluate Google's AI services over alleged systemic risks to publishers and AI-generated misinformation risks
Open source →Apr 20, 2026 · enforcement_action
Competition Authority concludes investigation into Nova over failure to disclose AI hallucination risks following commitments to improve user information
Open source →Mar 2, 2026 · news
Italy proposes governance model on AI and work
Open source →Feb 20, 2026 · international_agreement
Italy, India, Kenya sign landmark AI cooperation agreement to advance development in Africa
Open source →Jan 18, 2026 · international_agreement
South Korea and Italy agree to strengthen cooperation in AI, chips
Open source →Jan 7, 2026 · news
Garante issues warning relating to deepfake risks of Grok, ChatGPT, Clothoff and other similar services
Open source →Nov 25, 2025 · enforcement_action
Italy antitrust watchdog may curb Meta as WhatsApp AI probe widens
Open source →Oct 9, 2025 · law_amended
Italy's AI bill enters into force
Open source →Sep 30, 2025 · news
Italian DPA temporarily restricts deepfake nude app ClothOff from processing of Italian personal data
Open source →Sep 16, 2025 · law_amended
Italy finally approves AI bill, covering privacy, oversight and child access
Open source →Sep 16, 2025 · guideline_issued
Data protection authorities adopted joint statement on building trustworthy data governance frameworks to encourage development of innovative and privacy-protecting AI
Open source →Jul 29, 2025 · news
Italy Competition Authority investigates into Meta's integration of Meta AI in WhatsApp
Open source →May 22, 2025 · law_amended
Italian government moves to drop data localization rule in national Al law
Open source →May 18, 2025 · enforcement_action
Garante fines AI company Replika's developer $5.6 million
Open source →Mar 19, 2025 · law_amended
Italy Senate passes AI bill
Open source →Feb 23, 2025 · news
UAE and Italy sign MoU on data centres and AI
Open source →Jan 29, 2025 · news
Garante blocks DeepSeek
Open source →Jan 28, 2025 · news
Garante seeks information from DeepSeek on data protection
Open source →Dec 22, 2024 · guideline_issued
G7 Digital & Tech Working Group finalises reporting framework for advanced AI systems
Open source →Dec 19, 2024 · enforcement_action
Italian DPA hands down EUR 15 million fine on OpenAI
Open source →Dec 1, 2024 · news
Italian Competition Authority launches consultation on pricing algorithms in passenger air transport
Open source →Nov 26, 2024 · news
Italian Garante issues interim ruling on GEDI Gruppo x OpenAI deal
Open source →Sep 25, 2024 · news
Italy DPA monitors OpenAI's agreements with publishers
Open source →Jun 20, 2024 · news
Consumer organisations file privacy complaint to Italian Garante over Linkedin's use of user data for AI training
Open source →May 20, 2024 · international_agreement
Seoul Declaration for Safe, Innovative and Inclusive AI signed
Open source →Apr 22, 2024 · guideline_issued
Italy's cabinet outlines framework, investment for AI
Open source →Apr 22, 2024 · law_amended
Digital Italy Agency and the National Cybersecurity Agency to supervise AI regulation in Italy
Open source →Apr 9, 2024 · news
Italy considers tougher penalties for AI-related crimes
Open source →Mar 29, 2024 · news
Garante issues guidance to protect personal data from web scraping
Open source →Mar 11, 2024 · law_amended
Italy to set up AI fund of 1 billion euros, PM says
Open source →Mar 7, 2024 · news
Garante investigates OpenAI's AI model Sora
Open source →Jan 28, 2024 · law_amended
Garante notifies breaches of privacy law to OpenAI
Open source →Jan 25, 2024 · enforcement_action
Garante fines first city for privacy breaches in use of AI
Open source →Nov 22, 2023 · news
Garante looks into online data gathering to train AI
Open source →Nov 18, 2023 · law_amended
France, Germany, Italy push for 'mandatory self-regulation' for foundation models in EU's AI law
Open source →May 21, 2023 · news
Garante to launch broad review of AI platforms
Open source →