The EU AI Act in Italy
How Regulation (EU) 2024/1689 applies in Italy, and the 12 AI instruments Italy has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Italy’s own AI instruments
12 records tracked for Italy, beyond the EU-level Act above.
Italy - AI Adoption Guidelines
Italy · 2025
Italy - AI Regulation (n.132/2025)
Italy · 2025 · 10 Oct 2025
Italy - National AI Law (132/2025)
Italy · 2025 · 10 Oct 2025
Italy - Digital Transformation Plan
Italy · 2024 · 12 Feb 2024
Italy - Lombardy - AI Strategy
Italy · 2024 · 16 Apr 2024
Italy - Web Scraping Guidance (329/2024)
Italy · 2024 · 7 Jun 2024
Italy - Temporary Order Against ChatGPT
Italy · 2023 · 11 Apr 2023
Italy - Emilia-Romagna - AI Regional Hub
Italy · 2022 · 1 Jan 2022
Italy - Digital Transformation Strategy
Italy · 2021 · 15 Mar 2021
Italy - National AI Strategy
Italy · 2021 · 24 Nov 2021
Emilia-Romagna AI Regulation Summary
Italy
Lombardy AI Regulation Summary
Italy
National authority in Italy
Named in Italy’s own records, not inferred.
Per Italy - AI Adoption Guidelines
- Agenzia per l'Italia Digitale (AgID) — Author and coordinator of guidelines; provides templates, training and support; manages consultation process.
- Garante per la protezione dei dati personali (Italian Data Protection Authority) — Supervisory authority for compliance with data protection obligations and DPIAs related to AI systems processing personal data.
- National cybersecurity authority / relevant cybersecurity bodies — Provide guidance and standards for cybersecurity and model security measures applicable to AI systems in the PA.
Per Italy - AI Regulation (n.132/2025)
- Presidency of the Council of Ministers (Presidenza del Consiglio dei Ministri) — Overall coordination, lead in implementing delegated powers; chairing inter‑ministerial coordination.
- Agenzia per l'Italia Digitale (AgID) — Technical standards, digital public procurement guidance, IT architecture and interoperability for PA AI systems.
- Agenzia per la Cybersicurezza Nazionale (ACN) — Define cybersecurity requirements, support incident response, oversee resilience for critical AI systems used by public bodies.
- Garante per la protezione dei dati personali (Italian Data Protection Authority) — Oversight for data protection compliance, consultation on sensitive processing and DPIA requirements, enforcement of GDPR‑related obligations.
- Ministry of Health (Ministero della Salute) — Sectoral rules and oversight for AI uses in healthcare and health data processing.
- Ministry of Labour and Social Policies (Ministero del Lavoro e delle Politiche Sociali) — Oversight of workplace and labour uses of AI and establishment of national observatory functions in labour context.
Per Italy - National AI Law (132/2025)
- Agenzia per l'Italia Digitale (AgID) — Designated national authority for promotion, notification management, accreditation and conformity assessment of AI systems; co‑manager of experimentation spaces and technical guidance.
- Agenzia per la Cybersicurezza Nazionale (ACN) — Designated national authority for market surveillance, inspections and cybersecurity oversight of AI systems; single contact point to EU institutions for market surveillance matters.
- Banca d'Italia — Sectoral market supervisor for AI systems used by credit and banking institutions (oversight role in financial sector compliance).
- CONSOB — Market supervisor for securities markets; oversight where AI is used to affect market behaviour and enforcement coordinator for financial sector rules.
- IVASS — Insurance market supervisor with competence on AI applications in insurance underwriting and claims processing.
- Garante per la protezione dei dati personali — Data protection supervisory authority retaining competence on GDPR matters and DPIAs related to AI.
Per Italy - Digital Transformation Plan
- Agenzia per l'Italia Digitale (AGID) — Primary coordinator, guideline issuer, monitor and technical authority for the Three‑Year ICT Plan.
- Dipartimento per la Trasformazione Digitale - Presidenza del Consiglio dei Ministri — Strategic coordination with AGID; participates in governance and inter-institutional coordination.
- Corte dei Conti — Audit and review authority for public administration use of funds and conformity review for the Plan where required.
- Consip S.p.A. — Central purchasing body that operates strategic procurement frameworks aligned with Plan indicators.
Per Italy - Web Scraping Guidance (329/2024)
- Garante per la protezione dei dati personali — National supervisory authority for data protection in Italy (issuer of the Provvedimento and responsible for enforcement and guidance)
Per Italy - Temporary Order Against ChatGPT
- Garante per la protezione dei dati personali — Primary supervisory authority issuing the provvedimento and overseeing enforcement under GDPR in Italy
Per Italy - Digital Transformation Strategy
- Dipartimento per la trasformazione digitale (Presidency of the Council of Ministers) — Policy coordination, PNRR milestone oversight and operational leadership for the strategy
- Agenzia per l'Italia Digitale (AgID) — Technical standards, interoperability, identity management (SPID/CIE), guidance for PA implementations
- Agenzia per la Cybersicurezza Nazionale (ACN) — National cybersecurity authority responsible for cyber resilience, minimum security levels and inspections
- Minister for Technological Innovation and Digital Transition — Political leadership and strategic direction for national digital policy
Per Italy - National AI Strategy
- Ministry for Technological Innovation and Digital Transition (MID) / Department for Digital Transformation — Lead coordinator for GovTech, data infrastructure, and digital transition; host of Programme materials and Secretariat for working group.
- Ministry of University and Research (MUR) — Co-author and lead for research, PhD funding and academic partnerships.
- Ministry of Economic Development (MISE) — Co-author and lead for industrial policy, support to startups, and measures to promote AI adoption in industry.
- Comitato Interministeriale per la Transizione Digitale (CITD) — Interministerial committee hosting the permanent working group and providing cross-government oversight.
Penalties in Italy
As stated in Italy’s own records.
Per Italy - AI Adoption Guidelines
- The draft itself does not create new criminal penalties; however, non-compliance with underlying binding law (EU AI Act, GDPR) remains subject to statutory administrative fines and corrective orders by competent authorities.
- Potential administrative fines under the EU AI Act and GDPR enforced by the relevant national authorities (including the Data Protection Authority) for breaches linked to AI deployments.
- Contractual remedies, including termination, penalties and indemnities, where procurement or supplier agreements require compliance and suppliers fail to meet obligations.
- Internal administrative or disciplinary measures for PA officials in case of gross negligence or systemic failure to follow mandatory legal requirements.
- Procurement sanctions (e.g., exclusion from future public contracts) for suppliers that do not meet contractually specified AI compliance obligations.
Per Italy - AI Regulation (n.132/2025)
- Administrative sanctions for regulatory non‑compliance and omissions as defined by the law and subsequent decrees (sanctions to be detailed in implementing measures).
- Criminal offenses and penalties for illicit acts involving AI (including new or adapted crimes such as illicit dissemination of AI‑generated audiovisual content — deepfakes — and aggravated penalties where omission of safety measures causes concrete danger or harm).
- Aggravating circumstances for corporate or market manipulation offenses committed using AI tools and adjustments to existing penal provisions where AI is instrumental in committing offenses.
- Possible administrative measures (e.g., suspension orders, corrective measures, mandatory audits) imposed by competent authorities.
- Liability for damages following civil liability rules, subject to clarifications and criteria to be specified by delegated legislation.
Per Italy - National AI Law (132/2025)
- Criminal offence: Art. 612‑quater c.p. – illicit dissemination of AI‑generated or altered images, video or audio causing unjust damage (imprisonment 1–5 years) with procedural rules on complaint/ex officio prosecution in specified cases.
- Administrative fines and corrective measures for non‑compliance with notification, documentation, cybersecurity and transparency obligations (amounts to be specified in delegated decrees).
- Market surveillance remedies (withdrawal, suspension, recall) and sanctions for placing non‑conforming AI systems on the market; enforcement by ACN and sectoral supervisors.
- Penal or administrative sanctions for omissions in safety measures where omissions cause concrete danger to life, public or state security (delegated legislative detail forthcoming).
- Professional sanctions and contractual remedies (including contract termination, liability for damages) under civil law where AI misuse causes harm.
Per Italy - Digital Transformation Plan
- The Plan itself does not establish criminal penalties; however, administrative consequences may follow from non‑compliance (e.g., reduction in funding eligibility or limited access to central procurement frameworks).
- Systemic or repeated governance failures may be subject to administrative review and audits (including by Corte dei Conti) with potential managerial or financial repercussions under existing public administration accountability rules.
- Non-adherence to procurement or reporting rules may result in ineligibility for certain centrally managed procurement agreements or financing mechanisms.
Per Italy - Web Scraping Guidance (329/2024)
- The Provvedimento is advisory, but unlawful processing detected by supervisory procedures may give rise to corrective measures under the GDPR, including warnings, orders to bring processing into compliance, and administrative fines under Article 83 GDPR (up to €20 million or 4% of annual global turnover).
- Civil liability to data subjects (compensation under Article 82 GDPR) may arise where processing causes material or non-material damage.
- National penalties and remedies under Italian implementing law (d.lgs. 196/2003, as amended) may also apply.
- Reputational and contractual consequences for controllers and processors that fail to implement proportionate protections are likely.
Per Italy - Temporary Order Against ChatGPT
- Potential administrative fines under GDPR Article 83 up to amounts provided for relevant infringements, including reference to Article 83(5)(e) for failure to comply with supervisory requests.
- Enforcement measures under GDPR Article 58 including temporary or definitive limitations, bans on processing, and orders to bring processing operations into compliance.
- Judicial review rights preserved: parties subject to the provvedimento may bring opposition before national ordinary courts within the terms specified in the measure.
- Publication of enforcement orders and other reputational and operational measures available to the supervisory authority.
Per Italy - Digital Transformation Strategy
- Suspension, reduction or clawback of PNRR funding for failure to meet contractual milestones or deliverables.
- Administrative sanctions and corrective orders under public procurement and public administration accountability frameworks.
- Remedial measures and mandatory security upgrades ordered by ACN for non‑compliant cybersecurity postures.
- Denial of qualification for cloud/ICT procurement processes where providers or implementations fail to meet required technical/security standards.
- Typical judicial and administrative remedies for misuse of public funds or breach of procurement and transparency obligations.
Per Italy - National AI Strategy
- The Programme is strategic and does not impose specific administrative fines within its text; enforcement is effected through conditionality of funding and programmatic oversight.
- Non‑compliance with funding conditions can lead to suspension, clawback or reallocation of grants.
- Liability for harms remains governed by sectoral laws and existing civil liability frameworks; the Programme anticipates future alignment with EU rules that may add sanctions for regulated AI systems.
- Where public procurement rules are breached in Programme-backed calls, standard procurement remedies and sanctions apply under relevant public procurement law.
Italy overview
The full picture of AI regulation in Italy, beyond just the EU AI Act.
Italy AI regulation overview →