ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI compliance
Italy's New AI Rules Take Effect September 30: Up to 5 Years in Prison for Missing Safety Measures on High-Risk AI

Italy's New AI Rules Take Effect September 30: Up to 5 Years in Prison for Missing Safety Measures on High-Risk AI

AI compliance • Admin • • 2 views

Italy's new AI rules have written compliance failures into the criminal code. Legislative Decree No. 160 of 9 September 2026, published in Gazzetta Ufficiale No. 214 on 15 September 2026, takes effect on 30 September 2026 — and its most striking provision is a new Article 437-bis in the Italian Criminal Code: anyone who designs, trains, produces, places on the market, or professionally uses a high-risk AI system without adopting technical measures to prevent malfunctions or tampering, or without implementing human oversight measures, faces up to five years' imprisonment once the omission creates a concrete danger to life or individual safety. It is the first law in Europe to make AI governance failures a criminal offence.

What happened: a criminal provision taking effect on 30 September

On 10 June 2026 the Italian government gave preliminary approval to two draft legislative decrees implementing the EU AI Act; the final texts were approved on 4 August 2026, signed by the President on 9 September, and published in Gazzetta Ufficiale No. 214 on 15 September. Under the usual fifteen-day interval between publication and entry into force for Italian legislative decrees, the decree's effective date is 30 September 2026.

The decree's job is to align Italian law with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). The EU Act itself sets no criminal penalties, leaving member states to decide whether and how to use criminal law — Italy is the first to actually do it, building an AI-era omission offence on the model of workplace-safety crimes.

Who it covers: high-risk AI systems only, but a long chain

A boundary worth drawing first, to avoid misreading: the offence does not apply to all AI. It covers only high-risk AI systems as defined by the EU AI Act (the categories in Articles 6 and 7 — systems used in hiring, credit, education, medical triage, and similar settings).

The conduct chain spans five stages: design, training, production, placing on the market, and professional use. Everyone from model developers to enterprise buyers of these systems is in scope. Territorially, any company developing, deploying, or commercialising high-risk AI systems on the Italian market must comply, including the Italian operations of multinationals. At EU level, enforcement inspections under the AI Act are already underway — EU AI Act enforcement moves into practice: hiring and credit-scoring AI inspected first. Italy has now added criminal teeth at the other end of enforcement.

What conduct is criminal: two omissions, plus one act of tampering

Article 437-bis is built around omissions:

First, failing to adopt technical measures capable of preventing malfunctions or alterations in how the system operates. This maps to Article 9 of the AI Act (risk management systems) and Article 15 (accuracy, robustness, and cybersecurity) — for example, a medical AI giving wrong diagnostic recommendations because of defective training data, or model parameters being poisoned or modified without authorisation, where the company could have taken technical precautions.

Second, failing to implement human oversight measures. This maps to Article 14 of the AI Act: high-risk systems must be effectively overseen by natural persons, through measures built into the system by the provider or implemented by the deployer as instructed by the provider. Paragraph 4 of the new article specifically targets professional users who intentionally fail to implement human oversight.

The third is an active offence: paragraph 2 punishes outsiders who tamper with the operation of a high-risk AI system — data poisoning attacks or unauthorised changes to model parameters — with a base sentence of two to six years.

The threshold: "concrete danger" required — ordinary technical errors don't count

The decisive qualifier is "concrete danger": the offence is committed only where the omission genuinely creates, in the specific circumstances, a danger to life or individual safety — carrying one to five years' imprisonment. Where the danger reaches public safety or the security of the State, the range rises to two to eight years. Aggravated tampering follows the same logic, up to three to ten years.

Where the omission is committed through gross negligence rather than intent, the sentence is reduced by one third to one sixth. The design is deliberate: lawmakers do not want every technical deviation in court, only governance failures that clearly depart from the duty of care and genuinely risk life and safety.

Not just individuals: companies face liability too

The decree also brings Article 437-bis within the scope of Italy's corporate liability framework, Legislative Decree No. 231 of 2001. Companies themselves can be held liable: fines calculated in units, in bands of 600 to 1,000 and 200 to 700 units, plus disqualification-style sanctions — including a ban on advertising goods or services, which hurts AI companies that live on customer acquisition more than any fine.

The direct compliance takeaway: records of testing, monitoring, and who was supervising what are no longer just audit material — they are evidence that can speak in court. What was done, and to what extent, cannot be reconstructed afterwards.

Doing AI business in Italy: three things to fix now

First, translate the obligation lists in AI Act Articles 9 (risk management), 14 (human oversight), and 15 (accuracy and cybersecurity) into executable internal processes and checkpoints — not just policy documents.

Second, clarify who does what along the supply chain: which oversight measures the provider built in, which the deployer implemented — both in writing, so no one points fingers after an incident.

Third, the decree is not only about criminal law: it also covers rules for police use of AI systems and a civil-liability chapter (evidence disclosure, a presumption of causation, direct action against insurers). Companies operating in Italy should review all of these together, not just the criminal provisions.

Recommended Tools

More