The EU AI Act in Italy

How Regulation (EU) 2024/1689 applies in Italy, and the 12 AI instruments Italy has of its own.

The EU AI Act

In Force (Amended)RegulationEntered into force 1 Aug 2024

The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.

Key dates

  • 1 Aug 2024Entry into Force of the AI Act
  • 2 Feb 2025Prohibited AI practices and AI literacy obligations apply
  • 2 Aug 2025Governance rules and obligations for General-Purpose AI (GPAI) models apply
  • 27 Jul 2026Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
  • 2 Dec 2026Watermarking obligations on AI-generated content apply
  • 2 Aug 2027Obligations for high-risk AI systems included in Annex I of the AI Act apply
Read the full EU AI Act record →

Italy’s own AI instruments

12 records tracked for Italy, beyond the EU-level Act above.

National authority in Italy

Named in Italy’s own records, not inferred.

Per Italy - AI Adoption Guidelines

Per Italy - AI Regulation (n.132/2025)

Per Italy - National AI Law (132/2025)

  • Agenzia per l'Italia Digitale (AgID)Designated national authority for promotion, notification management, accreditation and conformity assessment of AI systems; co‑manager of experimentation spaces and technical guidance.
  • Agenzia per la Cybersicurezza Nazionale (ACN)Designated national authority for market surveillance, inspections and cybersecurity oversight of AI systems; single contact point to EU institutions for market surveillance matters.
  • Banca d'ItaliaSectoral market supervisor for AI systems used by credit and banking institutions (oversight role in financial sector compliance).
  • CONSOBMarket supervisor for securities markets; oversight where AI is used to affect market behaviour and enforcement coordinator for financial sector rules.
  • IVASSInsurance market supervisor with competence on AI applications in insurance underwriting and claims processing.
  • Garante per la protezione dei dati personaliData protection supervisory authority retaining competence on GDPR matters and DPIAs related to AI.

Per Italy - Digital Transformation Plan

Per Italy - Web Scraping Guidance (329/2024)

Per Italy - Temporary Order Against ChatGPT

Per Italy - Digital Transformation Strategy

Per Italy - National AI Strategy

Penalties in Italy

As stated in Italy’s own records.

Per Italy - AI Adoption Guidelines

  • The draft itself does not create new criminal penalties; however, non-compliance with underlying binding law (EU AI Act, GDPR) remains subject to statutory administrative fines and corrective orders by competent authorities.
  • Potential administrative fines under the EU AI Act and GDPR enforced by the relevant national authorities (including the Data Protection Authority) for breaches linked to AI deployments.
  • Contractual remedies, including termination, penalties and indemnities, where procurement or supplier agreements require compliance and suppliers fail to meet obligations.
  • Internal administrative or disciplinary measures for PA officials in case of gross negligence or systemic failure to follow mandatory legal requirements.
  • Procurement sanctions (e.g., exclusion from future public contracts) for suppliers that do not meet contractually specified AI compliance obligations.

Per Italy - AI Regulation (n.132/2025)

  • Administrative sanctions for regulatory non‑compliance and omissions as defined by the law and subsequent decrees (sanctions to be detailed in implementing measures).
  • Criminal offenses and penalties for illicit acts involving AI (including new or adapted crimes such as illicit dissemination of AI‑generated audiovisual content — deepfakes — and aggravated penalties where omission of safety measures causes concrete danger or harm).
  • Aggravating circumstances for corporate or market manipulation offenses committed using AI tools and adjustments to existing penal provisions where AI is instrumental in committing offenses.
  • Possible administrative measures (e.g., suspension orders, corrective measures, mandatory audits) imposed by competent authorities.
  • Liability for damages following civil liability rules, subject to clarifications and criteria to be specified by delegated legislation.

Per Italy - National AI Law (132/2025)

  • Criminal offence: Art. 612‑quater c.p. – illicit dissemination of AI‑generated or altered images, video or audio causing unjust damage (imprisonment 1–5 years) with procedural rules on complaint/ex officio prosecution in specified cases.
  • Administrative fines and corrective measures for non‑compliance with notification, documentation, cybersecurity and transparency obligations (amounts to be specified in delegated decrees).
  • Market surveillance remedies (withdrawal, suspension, recall) and sanctions for placing non‑conforming AI systems on the market; enforcement by ACN and sectoral supervisors.
  • Penal or administrative sanctions for omissions in safety measures where omissions cause concrete danger to life, public or state security (delegated legislative detail forthcoming).
  • Professional sanctions and contractual remedies (including contract termination, liability for damages) under civil law where AI misuse causes harm.

Per Italy - Digital Transformation Plan

  • The Plan itself does not establish criminal penalties; however, administrative consequences may follow from non‑compliance (e.g., reduction in funding eligibility or limited access to central procurement frameworks).
  • Systemic or repeated governance failures may be subject to administrative review and audits (including by Corte dei Conti) with potential managerial or financial repercussions under existing public administration accountability rules.
  • Non-adherence to procurement or reporting rules may result in ineligibility for certain centrally managed procurement agreements or financing mechanisms.

Per Italy - Web Scraping Guidance (329/2024)

  • The Provvedimento is advisory, but unlawful processing detected by supervisory procedures may give rise to corrective measures under the GDPR, including warnings, orders to bring processing into compliance, and administrative fines under Article 83 GDPR (up to €20 million or 4% of annual global turnover).
  • Civil liability to data subjects (compensation under Article 82 GDPR) may arise where processing causes material or non-material damage.
  • National penalties and remedies under Italian implementing law (d.lgs. 196/2003, as amended) may also apply.
  • Reputational and contractual consequences for controllers and processors that fail to implement proportionate protections are likely.

Per Italy - Temporary Order Against ChatGPT

  • Potential administrative fines under GDPR Article 83 up to amounts provided for relevant infringements, including reference to Article 83(5)(e) for failure to comply with supervisory requests.
  • Enforcement measures under GDPR Article 58 including temporary or definitive limitations, bans on processing, and orders to bring processing operations into compliance.
  • Judicial review rights preserved: parties subject to the provvedimento may bring opposition before national ordinary courts within the terms specified in the measure.
  • Publication of enforcement orders and other reputational and operational measures available to the supervisory authority.

Per Italy - Digital Transformation Strategy

  • Suspension, reduction or clawback of PNRR funding for failure to meet contractual milestones or deliverables.
  • Administrative sanctions and corrective orders under public procurement and public administration accountability frameworks.
  • Remedial measures and mandatory security upgrades ordered by ACN for non‑compliant cybersecurity postures.
  • Denial of qualification for cloud/ICT procurement processes where providers or implementations fail to meet required technical/security standards.
  • Typical judicial and administrative remedies for misuse of public funds or breach of procurement and transparency obligations.

Per Italy - National AI Strategy

  • The Programme is strategic and does not impose specific administrative fines within its text; enforcement is effected through conditionality of funding and programmatic oversight.
  • Non‑compliance with funding conditions can lead to suspension, clawback or reallocation of grants.
  • Liability for harms remains governed by sectoral laws and existing civil liability frameworks; the Programme anticipates future alignment with EU rules that may add sanctions for regulated AI systems.
  • Where public procurement rules are breached in Programme-backed calls, standard procurement remedies and sanctions apply under relevant public procurement law.

Italy overview

The full picture of AI regulation in Italy, beyond just the EU AI Act.

Italy AI regulation overview →