ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI information
Italy's AI Act Implementation Decree Takes Effect: High-Risk AI Failures Can Now Mean Criminal Liability

Italy's AI Act Implementation Decree Takes Effect: High-Risk AI Failures Can Now Mean Criminal Liability

AI information • Admin • • 3 views

Italy's domestic implementing decree for the EU AI Act officially took effect on September 30, 2026. It is one of the first member-state implementations of the EU Artificial Intelligence Act with real teeth: it doesn't just regulate how police use AI — it writes inadequate safety measures for high-risk AI into criminal law for the first time.

The decree's full name is a mouthful — Legislative Decree No. 160 of September 9, 2026, published in Official Gazette No. 214 on September 15, effective September 30. Its job is to translate the parts of the EU AI Act (Regulation 2024/1689) left to member states into Italian domestic law. It regulates three main things:

1. Police use of AI now has rules

Title I of the decree specifically governs the use of AI systems by police authorities: it must stay consistent with the EU AI Act and Italy's Law No. 132 of 2025, respecting four principles — proportionality, non-discrimination, human oversight, and transparency. The most controversial areas, facial recognition and remote biometric identification, fall within scope — Italy's existing S.A.R.I. automatic image-recognition system (which searches fingerprint databases via facial matching to identify suspects) is explicitly brought under management. Existing systems get a one-year transition: within 12 months of the effective date, police must bring systems in use into compliance.

2. A new criminal offense: safety failures in high-risk AI can mean prison

The decree inserts a new Article 437-bis into the Italian Criminal Code, titled "failure to adopt safety measures for artificial intelligence systems and unlawful tampering with systems." Two categories of conduct become criminal: failing to adopt required technical safety or human-oversight measures for high-risk AI systems where that creates a concrete danger to life or personal safety, and unlawfully tampering with high-risk AI systems. In other words, AI safety moves from "best practice" to "legal obligation" — when something goes wrong, it's no longer just about paying damages.

3. Corporate liability expands: the Decree 231 compliance checklist grows

The decree also amends Italy's Legislative Decree 231/2001 — the country's corporate administrative liability regime — adding the new AI-safety offenses to the catalog of predicate crimes triggering company liability. That means companies operating in Italy must review not only the technical compliance of their AI systems, but also whether organizational safeguards, human-oversight mechanisms, documentation, and internal compliance models (Modello 231) keep pace. Several Italian law firms are already telling clients: this isn't an IT-department matter; it's a board matter.

From "regulating models" to "assigning responsibility": the focus of AI governance is changing

The decree's signaling value outweighs its text. For the past two years, global AI regulation has fixated on "how powerful the model is": compute thresholds, evaluation reports, red-teaming — and both sides of the Atlantic are tightening. The US FTC just opened a sweeping probe into frontier labs including Anthropic and OpenAI; Italy goes further still, writing AI safety directly into criminal law. Police using facial recognition need authorization and time limits; companies using high-risk AI need safety measures and human oversight — fall short and face criminal liability.

It has practical meaning for Chinese companies too. Italy is in the fast lane of EU AI Act implementation, and its implementing rules will likely become a template for other member states. Companies with European operations using high-risk AI systems — industrial quality inspection, hiring screening, biometrics, for example — should start auditing now: are safety-measure documents complete, is the human-oversight chain intact, is the compliance model updated. The EU's AI governance is moving off the paper and into fines and courtrooms.

Recommended Tools

More