Italy has written artificial intelligence into its criminal code and its corporate liability regime, publishing on 15 September 2026 a legislative decree that creates a new offence for failing to secure or supervise high-risk AI systems and exposes companies to financial and interdictive sanctions when those systems are involved in wrongdoing.
In Short
Italy passed a law that makes it a crime to skip the safety checks and the human supervision required for the riskiest kinds of AI, with prison sentences attached when the failure endangers people. The same law lets prosecutors go after the company, not just the individual, and one of the penalties a company can receive is a ban on advertising its own products. If you work with AI systems in Italy, the records you keep about testing, monitoring and who was supervising what now matter in a courtroom rather than just in an audit.
A new article in the criminal code
The instrument is Legislative Decree of 9 September 2026, no. 160, signed by President Sergio Mattarella and countersigned by Prime Minister Giorgia Meloni together with the ministers for European affairs, the interior, justice, foreign affairs, defence and economy. It appeared in Gazzetta Ufficiale no. 214 of 15 September 2026. The published text carries a currency notation of 30 September 2026, consistent with the fifteen-day interval that normally separates publication from entry into force for Italian legislative decrees.
According to the decree's preamble, the measure adapts national law to Regulation (EU) 2024/1689 in two distinct areas: the use of AI systems by police forces, and civil and criminal liability. It draws its authority from Article 24 of Law no. 132 of 23 September 2025, Italy's framework AI statute. The procedural record set out in the preamble is unusually detailed: a preliminary Council of Ministers deliberation on 10 June 2026, an opinion from the data protection authority, an opinion from the Conferenza unificata delivered on 20 July 2026, opinions from the competent parliamentary committees of both chambers, and a final Council of Ministers deliberation on 4 August 2026.
Article 12 inserts a new Article 437-bis into the criminal code, headed in the original as covering the omitted adoption of security measures in artificial intelligence systems and the unlawful alteration of those systems. The construction is layered. Anyone who fails to adopt the technical security measures prescribed for the design, training, production or placing on the market of high-risk AI systems, measures suitable to prevent malfunctions or alterations in how those systems operate, or who fails to adopt human oversight measures, faces one to five years of imprisonment where the omission produces a danger to life or to public or individual safety. Where the conduct produces a danger to State security, the range rises to two to eight years.
The second paragraph addresses a different act. Altering a high-risk AI system, outside the cases covered by the first paragraph, carries two to six years where danger to life or public or individual safety follows, and three to ten years where the danger touches "la sicurezza dello Stato." That ten-year ceiling is the highest figure in the provision, and it attaches to tampering rather than to negligence.
Two further clauses narrow and widen the offence at once. Where the first-paragraph conduct is committed through gross negligence, the penalty is reduced by between one third and one sixth. And a professional user of a high-risk AI system who intentionally omits human oversight measures is punished under the first paragraph. That last sentence is the one that reaches beyond developers. Deployers, not only providers, sit inside the offence.
Entity liability and the advertising prohibition
Article 15 amends Legislative Decree no. 231 of 8 June 2001, the statute that governs the administrative liability of legal persons in Italy, by inserting a new Article 25-vicies covering offences committed using AI systems. For the new Article 437-bis offence, the entity faces a pecuniary sanction of between 600 and 1,000 quote. For the offence under Article 612-quater of the criminal code, which concerns the unlawful dissemination of AI-generated or altered content, the range is 200 to 700 quote.
Under Article 10 of the 2001 decree, a single quota ranges from 258 to 1,549 euros, placing the theoretical outer limit of the higher band somewhere close to 1.5 million euros before any of the non-monetary measures are considered. Those non-monetary measures are where the advertising consequence sits. Article 25-vicies applies the interdictive sanctionslisted at Article 9(2), letters b), c), d) and e) of the 2001 decree: suspension or revocation of the authorisations, licences or concessions connected to the offence; a prohibition on contracting with public administration; exclusion from and revocation of benefits, financing, contributions and subsidies; and a prohibition on advertising goods or services. Letter a), the outright interdiction from carrying on the activity, is not among them. Under the 2001 framework, interdictive sanctions run from a minimum of three months to a maximum of two years.
The practical shape of this is narrow but sharp. An entity that benefits from the unlawful dissemination of AI-generated or altered content can, on top of a fine, lose the ability to advertise for a defined period. Italy's data protection authority had already tested the boundaries of synthetic media in a commercial setting when it ordered Mediaset to stop broadcasting deepfake segments featuring the journalist Enrico Mentana, a decision reached without a fine and on principles predating the AI Act. The criminal and corporate track now runs alongside that administrative one.
Giulio Coraggio, a partner at DLA Piper and head of its intellectual property and technology practice, described the change on LinkedIn as bringing AI-related offences within entity liability, with the consequence that an AI incident can develop into an investigation touching both individual criminal liability and corporate liability. Framing the defence problem, he asked "what evidence can the company produce when an investigation starts?"
Civil litigation: disclosure, presumption, and the insurer
The decree's second liability chapter may prove more consequential for ordinary commercial operators than the criminal one, because it applies to any AI system rather than only high-risk ones.
Article 16 states that the evidence provisions apply to damages actions, contractual and non-contractual alike, for harm caused in the use of an AI system. Where a natural person acting outside any business, commercial, artisanal or professional activity brings the claim, the court of that person's residence or domicile is also competent, adding a consumer forum to the ordinary rules of jurisdiction.
Article 17 sets out an access-to-evidence mechanism. On application by the party alleging harm, the judge orders the other party, or a third party holding the material, to produce evidence specifically relevant to how the AI system functioned, provided the applicant presents facts making the claim plausible, including on the link between the system's output and the alleged damage. The decree enumerates what falls within scope: the logs required by Article 12 of Regulation (EU) 2024/1689; documentation of the risk management system under Article 9; relevant information in the technical documentation under Article 11; and information on the parameters and methods of human oversight under Article 14. The order must stay limited to what is necessary and proportionate, and the judge weighs the interests of all parties with particular regard to trade secrets and confidential information, applying Article 121-ter of the industrial property code where disclosure risks exposure.
Failure to comply carries teeth. A party that does not comply without justification exposes itself to adverse inferences under Article 116 of the code of civil procedure, and where the non-compliance concerns the documentation listed above, the judge, having weighed all other evidence, treats the facts alleged by the applicant as admitted. A third party that fails to comply faces a pecuniary penalty of between 1,500 and 10,000 euros.
Article 18 states the presumption of causation in a single line: where damage derives from the breach of one or more obligations under Regulation (EU) 2024/1689, the causal link between breach and damage is presumed, subject to contrary proof. Article 19 closes the obvious escape route, providing that conformity with the AI Act, including where certified under Chapter III, Section 5 of the regulation, does not by itself exclude the defendant's liability.
Article 20 adds a direct action against insurers. A prospective claimant may first ask the party they consider responsible whether civil liability cover exists for the damage in question; the request is not a condition of admissibility, but the recipient must state within thirty days whether such a contract exists, its particulars, and the name of the insurer. Omitted or incomplete replies again permit adverse inferences. The injured party then holds a direct claim against the insurer within the policy limits, with contractual defences predating the loss remaining enforceable and the insurer retaining recourse against its insured.
Policing, biometrics and the fifteen-day clock
The first title of the decree governs how Italian police forces may research, develop, train, test and deploy AI. Article 3 requires qualified human review of automated outputs before they are used in acts affecting a person's legal position, with the review carried out by personnel identified through each force's internal procedures and documented so as to be traceable. Article 6 obliges each force to run AI courses at its training institutes, listing five minimum learning outcomes that include knowledge of the limits, biases and errors of AI systems with specific attention to biometric recognition and predictive analysis, and awareness of cybersecurity risks in line with guidance from the national cybersecurity agency.
Article 8 governs real-time remote biometric identification in public spaces, permitted for the prevention purposes at Article 5(1)(h)(ii) of the AI Act and for locating missing persons or victims of kidnapping, human trafficking or sexual exploitation. Use requires a request from a questore, a provincial commander of the Carabinieri or the Guardia di Finanza, or the head of a central service, addressed to the public prosecutor at the district capital's tribunal, specifying purpose, expected duration, territorial area, persons concerned, reference databases and the technologies employed. Authorisation attaches to a specific event or to the time strictly necessary, capped at fifteen days and renewable by reasoned decree for successive fifteen-day periods. In urgent cases the system may be started on the authority of the questore or the named commanders, following communication to the prosecutor that may be oral; the written request must follow within twenty-four hours, and the prosecutor decides within a further twenty-four. Where the conditions or deadlines are missed, or authorisation is refused, use stops immediately, the data and outputs are deleted, and the results cannot be used.
The reference database rules are tighter still. Comparison runs only against a database built specifically for each authorised use, containing only biometric data pertinent to that purpose, deleted when the authorisation expires and structured so that comparison sets cannot accumulate across authorisations. Databases fed wholly or partly by "scraping non mirato," which Article 2 defines as the automated, indiscriminate, large-scale extraction of facial images from the internet or CCTV footage in order to create or expand facial recognition databases, are prohibited outright. That definition tracks the practice at issue in the European litigation over PimEyes, where the privacy group noyb sued the Hamburg data protection authority over its handling of the case.
Article 9 requires a fundamental rights impact assessment under Article 27 of the AI Act and a data protection impact assessment under the Italian transposition of Directive (EU) 2016/680, automatic and unmodifiable log files retained for five years, and notification to the Garante after use. That notification requires prior clearance from the competent judicial authority, which may defer it for up to three months on specific secrecy grounds, renewable once.
Cameras at venues, and a seven-day window
Article 10 covers a scenario with direct commercial reach: video surveillance systems augmented with AI-driven retrospective facial recognition. Activation must follow image acquisition by an interval long enough that the operation does not amount to real-time remote biometric identification. To run retrospective recognition against a person under targeted search as a suspect, the public prosecutor must seek authorisation from the preliminary investigations judge within forty-eight hours of the system being started, and the judge rules within a further forty-eight hours. Authorisation is not required where the technology is used solely after an offence, for the initial identification of a potential suspect, on the basis of objective and verifiable elements directly connected to the offence.
The venue provisions are specific. Where criteria set by ministerial decree apply, the systems process face images of people entering places or events with particular public order requirements, without processing the corresponding biometric data at that stage. Images are stored locally in a reference database, alongside personal details and, where seating is assigned, the seat identifier, both captured by electronic scanning of access tickets. Only after an offence does activation trigger biometric processing of the locally held images for retrospective comparison. The controller is the Ministry of the Interior's Department of Public Security. Data held in that reference database is retained for seven days from collection and deleted automatically afterwards. Access logs are kept for five years. No decision producing negative legal effects may rest solely on a facial recognition result, and untargeted use, disconnected from any offence or proceeding, is prohibited in all cases.
Installation and maintenance may be carried out by venue operators, event organisers or promoters, or whoever controls the structures where events take place, at no new cost to public finances. Those systems are then granted on free loan to the questura, which acquires complete and exclusive availability of them.
Research, sandboxes and the transition
Article 4 allows police forces to collaborate with universities, research bodies and public and private entities on AI research projects, subject to contractual clauses excluding the sharing of sensitive operational data and barring partners from acquiring or using systems trained for policing, except where synthetic data or masked or pseudonymised real data is involved. Intellectual property, industrial property and economic exploitation rights over research results, derived models, training data and software must be expressly allocated, and ownership of models trained on sensitive operational data rests with the police forces in all cases.
Article 5 establishes the national legal basis, under Article 59(2) of the AI Act, for processing personal data, including criminal offence data and the special category data referenced at Article 3(37) of the regulation, within regulatory sandboxes where necessary for policing purposes.
Article 21 sets the transition. AI systems that are the subject of contracts, under development or testing, or already in use for policing purposes when the decree enters into force must be brought into line with Chapter II of Title I within one year. For provisions whose application depends on the AI Act itself, the regulation's own timetable governs.
Why this matters for the marketing community
The immediate relevance is not that most advertising technology is high-risk under Annex III. Very little of it is. The relevance lies in three narrower places.
First, Article 25-vicies attaches corporate exposure to the dissemination of AI-generated or altered content, and among the available sanctions is a prohibition on advertising goods or services for a period of up to two years. Synthetic creative is no longer only a disclosure question governed by transparency rules. The European Commission's Article 50 framework, including the free labelling icons it published ahead of the August 2026 deadline, addresses whether content is marked. The Italian decree addresses what happens to the entity when the content itself is unlawful.
Second, the civil chapter applies to any AI system, not only high-risk ones. Article 18's presumption of causation converts an AI Act compliance failure into a litigation liability by default, and Article 17 makes logs, risk management documentation, technical documentation and human oversight parameters producible in an Italian civil court, with the alleged facts treated as admitted where a party cannot produce them. The record-keeping burden that the AI Act frames as an administrative duty now carries evidentiary weight in private disputes, and the burden falls on organisations whose AI vendors hold the underlying material.
Third, the definition of a professional user in Article 437-bis reaches deployers who intentionally skip human oversight. Italy's data protection authority has already applied the AI Act's prohibited practices to a commercial product, warning a startup over a Slack and Teams plug-in that inferred employee stress levels in one of the first European actions to invoke the regulation alongside the GDPR. The criminal track sits above that, with a different evidentiary standard and a different consequence.
The timing carries its own significance. The EU's own high-risk obligations under Annex III have moved: Council and Parliament negotiators agreed in May 2026 to push those deadlines to 2 December 2027, after an earlier round of talks collapsed in late April and after Parliament committees had voted 101 to 9 in March 2026 for fixed calendar dates. Italy is legislating national criminal and civil consequences while the harmonised compliance obligations those consequences reference remain more than a year from full application. Denmark completed its national implementation first, in May 2025, designating three authorities. Italy's approach differs in kind rather than in speed: it attaches prison terms and entity liability rather than only supervisory architecture.
For agencies and brands operating in the Italian market, the assessment sits alongside the sector picture that IAB Italia set out in its April 2026 AI white paper, which positioned 2026 as the year AI moved from pilots into stable production workflows. Production deployment and criminal liability arrived in the same calendar year.
Timeline
- 1 August 2024: Regulation (EU) 2024/1689, the AI Act, enters into force
- 2 February 2025: AI Act prohibitions on unacceptable practices begin to apply
- 8 May 2025: Denmark becomes the first member state to adopt national implementing legislation
- 2 August 2025: Obligations for general-purpose AI model providers begin to apply
- 23 September 2025: Italy enacts Law no. 132, the national AI framework statute containing the delegation at Article 24
- 12 March 2026: The European Commission publishes a draft implementing regulation on investigating and fining general-purpose AI model providers
- 18 March 2026: Parliament committees vote 101-9 to replace flexible deadlines with fixed dates
- 13 April 2026: IAB Italia publishes its AI white paper on the Italian marketing sector
- Late April 2026: Digital Omnibus trilogue talks on the AI Act collapse
- 7 May 2026: Council and Parliament agree fixed high-risk deadlines of 2 December 2027 and 2 August 2028
- 14 May 2026: Italy's Garante issues a formal warning over an AI workplace stress-inference plug-in
- 10 June 2026: Italian Council of Ministers adopts the preliminary deliberation on the decree
- 20 July 2026: The Conferenza unificata delivers its opinion
- 4 August 2026: Italian Council of Ministers adopts the final deliberation
- 7 August 2026: Italy's data protection authority orders Mediaset to halt deepfake segments featuring a named journalist
- 9 September 2026: Legislative Decree no. 160 is signed in Rome
- 15 September 2026: The decree is published in Gazzetta Ufficiale no. 214
- 30 September 2026: Date carried on the published text as the currency reference
- 2 December 2027: Scheduled application of AI Act high-risk obligations under Annex III
Related PPC Land coverage
- EU AI Act gets its first real haircut - high-risk deadlines pushed to 2027 - The 7 May 2026 provisional agreement fixing 2 December 2027 and 2 August 2028 as the new compliance dates for high-risk systems.
- Brussels AI Act talks collapse - but the August 2026 deadline holds - The breakdown of Digital Omnibus negotiations and the uncertainty it left over national compliance planning.
- EU Parliament committee backs AI Act delay with fixed 2027 deadline - The March 2026 committee vote that replaced a Commission-triggered mechanism with calendar dates.
- Italy warns AI startup: Slack stress-detection plug-in may violate two EU laws - One of the first European enforcement actions invoking the GDPR and the AI Act together against a commercial product.
- Mediaset faces 30-day deadline after Italy bans Mentana deepfakes - The Garante decision on synthetic doubles of a real journalist, decided without a fine and on pre-AI Act principles.
- IAB Italia's AI white paper maps the future of marketing in Italy - The trade body's April 2026 assessment of AI moving into production workflows across Italian marketing.
- Council of Europe unveils AI discrimination playbook for regulators - Guidance for equality bodies on the AI Act, including the record of Denmark completing national implementation first.
- noyb sues Hamburg DPA as PimEyes keeps scanning faces unhindered - European litigation over facial recognition databases assembled from images collected at scale.
- EU publishes free AI labelling icons ahead of August 2026 deadline - The Article 50(4) transparency icons and the penalty exposure attached to unlabelled synthetic content.
- EU draft reveals how Brussels will probe and fine AI model providers - The Commission's procedural rules for investigations and fines at the supranational level.
- AI Office gains 5% daily penalty power over Google and Meta AI systems - The enforcement architecture sitting above national implementation.
- Italian court kills OpenAI's €15M fine - and it wasn't even close - How an Italian enforcement decision against an AI provider was annulled on jurisdictional grounds.
Summary
Who: The Italian state, acting through a legislative decree signed by President Sergio Mattarella and countersigned by Prime Minister Giorgia Meloni and six ministers. The obligations reach designers, trainers, producers and importers of high-risk AI systems, professional users of those systems, legal entities that benefit from the covered offences, Italian police forces, and venue and event operators that install augmented video surveillance.
What: Legislative Decree no. 160 of 9 September 2026, adapting Italian law to Regulation (EU) 2024/1689. It creates criminal code Article 437-bis, with one to five years for omitting security or human oversight measures where danger to life or safety follows, two to eight where State security is endangered, and two to six or three to ten years for altering a high-risk system. It inserts Article 25-vicies into the corporate liability decree, setting pecuniary sanctions of 600 to 1,000 quote and 200 to 700 quote and applying four interdictive sanctions including a prohibition on advertising goods or services. It adds criminal procedure Article 359-ter on real-time biometric identification, and a civil chapter establishing evidence disclosure, a presumption of causation, and direct action against insurers.
When: Signed 9 September 2026 and published in Gazzetta Ufficiale no. 214 on 15 September 2026, with the published text carrying a currency date of 30 September 2026. Existing police AI systems have one year from entry into force to be brought into conformity.
Where: Italy, with effects reaching any organisation deploying AI systems in the Italian market or facing civil claims before Italian courts. Biometric provisions apply in public spaces and in venues hosting events with particular public order requirements.
Why: The decree converts obligations that the AI Act frames administratively into criminal exposure for individuals, entity liability for companies, and evidentiary burdens in civil proceedings. For the marketing sector, the operative consequences are the advertising prohibition available as a sanction where an entity benefits from unlawful dissemination of AI-generated content, and the presumption of causation that attaches to any AI Act breach causing damage.
Discussion