Italy - AI Adoption Guidelines

Draft Guidelines for the Adoption of Artificial Intelligence in Public Administration

Bozza - Linee guida per l'adozione dell'Intelligenza Artificiale nella Pubblica Amministrazione

Italy

RAI-IT-NA-BLGPLXX-2025
Draft(Being written or scoped)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

A draft (Bozza V.1.0, 14 Feb 2025) of the Italian national guidelines prepared by the Agency for Digital Italy (AgID) to support adoption, procurement and development of AI systems by public administrations. The document aligns PA practice with the EU AI Act, GDPR and national plans, setting governance, risk-assessment, transparency and security expectations while explicitly restricting certain uses (e.g., social scoring and real-time biometric identification) in line with EU rules.

Summary

Context and purpose: In February 2025 AgID published a draft of national "Linee guida per l'adozione dell'Intelligenza Artificiale nella Pubblica Amministrazione" (Bozza V.1.0, 14.02.2025) and initiated a public consultation running 18 February–20 March 2025. The guidelines are issued under the mandate of the 2024–2026 Triennial Plan for IT in the Public Administration (Piano Triennale per l'Informatica nella PA) and follow the procedure set out by article 71 of the Italian Code of Digital Administration (CAD). The draft provides an operational framework for Italian public administrations (central, regional, local and agencies) to adopt, procure, develop and manage AI systems while ensuring legal compliance, protection of fundamental rights and organizational readiness.

Scope and alignment: The Bozza addresses the full AI systems lifecycle (design, procurement, deployment, operation, monitoring and decommissioning) and defines roles and responsibilities across the chain of value (PA as deployer, procuring units, solution providers and maintainers). The draft explicitly references and aligns with EU law—most notably the European Artificial Intelligence Act—and with EU and national data protection law (GDPR) and national cybersecurity and procurement frameworks. It also situates itself within Italy's digital transformation strategy by linking with the DPCM 12 January 2024 Plan and the national AI strategy processes.

Governance and requirements: The guidelines propose a governance model for PAs that includes: internal AI governance bodies (AI steering committees or referees), mandatory risk classification and assessment procedures, privacy and security impact assessments (including Data Protection Impact Assessments where required by GDPR), transparency and documentation requirements (model cards, data sheets, record-keeping of decisions), and staff training and digital skills programs. They prescribe pre-deployment testing, continuous monitoring, incident response processes and model maintenance obligations. Conformity, documentation and traceability are emphasised to support accountability and audits.

Use restrictions and risk approach: The draft mirrors the AI Act’s risk-based approach: it forbids or strongly restricts uses already prohibited or tightly regulated at EU level (e.g., social scoring, manipulative profiling of citizens, certain remote biometric identification in public spaces except narrow national security exceptions). It identifies categories of high-risk public-sector uses requiring higher assurance and conformity measures (e.g., employment and social benefits allocation, justice and law enforcement, critical infrastructure, healthcare decisions). For such uses the draft requires formal conformity assessment, more stringent testing, explainability measures and human oversight provisions.

Operational guidance and tools: To reduce implementation friction, the document is accompanied by annexed "tools" and templates (risk assessment templates, procurement clauses, model evaluation checklists, contractual clauses for suppliers and sample documentation formats). AgID signals these instruments are intended to be living artefacts that can be updated more frequently than the main text. The draft also describes the role of AgID and other national authorities (data protection authority, sectoral regulators and the national cybersecurity agency) in supporting, monitoring and advising PAs.

Enforcement and legal effect: As a draft guideline, the Bozza itself is not a law but it is designed to ensure compliance with binding EU and national obligations. Non-compliance with mandatory obligations under the AI Act or GDPR remains enforceable by statutory regulators; the guidelines aim to translate those obligations into PA-appropriate operational practices. The draft points to potential administrative or disciplinary consequences for PAs or officials in case of systemic breaches and highlights interaction with procurement rules and contract remedies.

Consultation and next steps: AgID adopted the Determinazione n.17/2025 (17 Feb 2025) to launch consultation. The consultation period closed 20 March 2025 and comments were collected via the Forum Italia platform. The document is expected to be updated following consultation feedback and integrated into the Triennial Plan implementation. AgID also held explanatory webinars and made slide materials and recorded sessions available to stakeholders.

Full article

Read full text ↗

Overview

The AgID draft "Linee guida per l'adozione dell'Intelligenza Artificiale nella Pubblica Amministrazione" (Bozza V.1.0, 14 Feb 2025) sets out operational guidance for Italian public administrations to harness AI in delivering public services while protecting rights and ensuring legal compliance. The draft was published for public consultation by Determinazione n.17/2025 (consultation open 18 February–20 March 2025) and is anchored to the Piano Triennale per l'Informatica nella Pubblica Amministrazione 2024–2026. The document mirrors the EU risk-based approach under the EU Artificial Intelligence Act and integrates obligations under the GDPR, national procurement and cybersecurity rules. It aims to provide PAs with policies, templates and a lifecycle framework for procurement, deployment, testing and monitoring of AI systems, and to flag prohibited or highly restricted uses in line with EU prohibitions (for example social scoring and pervasive biometric surveillance).

Definitions

The draft defines core terms to ensure common understanding across PAs: "AI system" (broad functional definition consistent with the AI Act); "provider" (entity making an AI system available on the market or putting it into service); "deploying administration" or "deployer" (PA that uses the AI system to achieve public functions); "high-risk system" (uses that substantially affect rights, health, safety or access to essential public services); "model lifecycle" (from design and dataset curation to decommissioning); and governance terms such as "AI steward", "AI steering committee" and "record of processing and decisions". These definitions aim for alignment with EU terminology to facilitate interoperability and compliance.

Governance and Institutional Framework

The draft prescribes internal governance structures inside PAs: formation of an AI governance body (e.g., an AI Steering Committee or a designated AI Responsible Officer), clear allocation of responsibilities across procurement, legal, data protection and ICT/security units, and processes to involve sectoral regulators where needed. AgID positions itself as a central support and coordination point—providing templates, running training, hosting "environments for experimentation" and curating technical and ethical guidance. The document also identifies coordination needs with the national Data Protection Authority (Garante), the national cybersecurity authority and sectoral regulators (e.g., Ministry of Health for healthcare AI) and references the AgID transparency and determination pages for the consultation materials (Determination n.17/2025 and AgID AI area).

Key Focus Areas

The draft concentrates on several intersecting themes: (1) risk-based classification and assessment—requiring PAs to evaluate potential impacts on rights, safety and fairness before procurement or deployment; (2) transparency and documentation—obliging detailed records (model cards, documentation of training data provenance, decision logs) to enable audits and explainability; (3) data protection and privacy—embedding DPIA integration and minimisation principles consistent with the GDPR; (4) cybersecurity and model security—requiring technical safeguards against data poisoning, model theft and adversarial manipulation and referencing national cyber guidance; (5) human oversight—ensuring that final decisions with legal or significant effects on citizens include appropriate human review; (6) procurement and contractual clauses—incorporating compliance, audit and liability terms into supplier contracts; and (7) skills and organisational preparedness—recommending training plans and dedicated operational roles. The draft highlights prohibited or restricted uses consistent with EU rules (e.g., social scoring and most forms of real-time remote biometric identification).

Implementation Framework

Operationally, the guidelines provide PAs with procedural steps, templates and annexed tools for implementation: a) an initial screening and risk classification flowchart; b) detailed DPIA and AI impact assessment templates; c) procurement clauses and model contractual language for suppliers (including requirements for access to documentation and logs); d) pre-deployment testing protocols and acceptance criteria; e) post-deployment monitoring plans with KPIs and incident reporting routes; and f) decommissioning checklists to manage model retirement and data retention. AgID signals that the annexed "tools" are modular and will be updated more frequently than the main text to reflect technological or normative changes.

Monitoring and Evaluation

The draft requires continuous monitoring and periodic re-evaluation of deployed systems, including automated telemetry on key performance indicators (accuracy, fairness metrics, drift detection) and scheduled audits. It suggests establishing incident reporting and remediation procedures, logging and retention policies sufficient for technical forensic analysis, and mechanisms for citizens to request human review or lodge complaints. AgID envisages coordination with national supervisory authorities for systemic issues and information sharing via designated national channels. Monitoring also includes periodic review of contracts and supplier compliance.

Penalties, Liability, and Appeals

While the Bozza itself is a non-binding guidance instrument, it clarifies how compliance with mandatory EU and national obligations should be operationalised within PAs. It points out that violations of binding law (for example the AI Act or GDPR) remain subject to statutory sanctions (administrative fines and corrective measures by competent authorities) and that non-compliance can also trigger procurement remedies, contractual sanctions and internal administrative or disciplinary measures. The draft recommends clear internal appeals processes for citizens and staff affected by automated decisions and creates a procedural link to sectoral appeal bodies and the national Data Protection Authority for privacy-related disputes.

Relationship to Other Instruments

The document is explicitly designed to complement and operationalise higher-level instruments: the EU Artificial Intelligence Act (risk-based obligations and prohibited practices), the GDPR (privacy and DPIA obligations), the DPCM Piano Triennale 2024–2026 (strategic priorities for PA digitalisation) and national procurement and cybersecurity frameworks. It also cross-references instruments prepared by sectoral regulators (e.g., health, justice, finance) and invites PAs to align sectoral deployments with any additional sector-specific rules or technical standards.

International Alignment

The draft references the EU AI Act and encourages alignment with EU-level conformity, standardisation (CEN-CENELEC activities), and the evolving work of the European AI Office. It also recommends that PAs follow internationally recognised technical best practices for security and testing and to monitor international developments in AI regulation to maintain interoperability and legal consistency. AgID positions the guidelines as compatible with EU-wide supervisory frameworks and anticipates cooperation with the national contact points emerging from EU implementation mechanisms.

Implementation Timeline

MilestoneDate
Draft version date (Bozza V.1.0)2025-02-14
Adoption (Determina AGID n.17/2025)2025-02-17
Publication & start of public consultation2025-02-18
End of consultation2025-03-20
Expected update following consultationTo be determined (post-consultation)

Sources and References

SourceType
AgID - AI area (consultation notice)Primary Source
Determination n.17/2025 (AgID transparency portal)Primary Source
AgID - Linee guida (Allegato PDF - Bozza V.1.0)Primary Source
European Commission - AI Act (overview)Primary/Context
EUR-Lex - GDPR (Regulation (EU) 2016/679)Primary/Context

Requirements for a company

What an organisation has to do under Italy - AI Adoption Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

13
  • Prohibit or restrict AI systems for social scoring and real-time remote biometric identification.Italian public administrations
  • Evaluate potential impacts of AI systems on rights, safety, and fairness.Italian public administrations
  • Integrate Data Protection Impact Assessments (DPIA) and apply data minimisation principles.Italian public administrations
  • Ensure appropriate human review for final decisions with legal or significant effects on citizens.Italian public administrations deploying AI systems
  • Form an AI governance body or designate an AI Responsible Officer.Italian public administrations
  • Clearly allocate responsibilities for AI across procurement, legal, data protection, and ICT/security units.Italian public administrations
  • +7 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Develop training plans and dedicated operational roles for AI systems.Italian public administrations

Should not do

0

Nothing in this category.

Who must do what

The obligations under Italy - AI Adoption Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Italian public administrationsProhibit or restrict AI systems for social scoring and real-time remote biometric identification.
explicitly restricting certain uses (e.g., social scoring and real-time biometric identification) in line with EU rules.
Before placing on marketCritical
2Italian public administrationsEvaluate potential impacts of AI systems on rights, safety, and fairness.
requiring PAs to evaluate potential impacts on rights, safety and fairness before procurement or deployment
Before procurement or deploymentCritical
3Italian public administrationsIntegrate Data Protection Impact Assessments (DPIA) and apply data minimisation principles.
embedding DPIA integration and minimisation principles consistent with the GDPR
Before deploymentCritical
4Italian public administrations deploying AI systemsEnsure appropriate human review for final decisions with legal or significant effects on citizens.
ensuring that final decisions with legal or significant effects on citizens include appropriate human review
Before deploymentCritical
5Italian public administrationsForm an AI governance body or designate an AI Responsible Officer.
formation of an AI governance body (e.g., an AI Steering Committee or a designated AI Responsible Officer)
Important
6Italian public administrationsClearly allocate responsibilities for AI across procurement, legal, data protection, and ICT/security units.
clear allocation of responsibilities across procurement, legal, data protection and ICT/security units
Important
7Italian public administrations deploying AI systemsMaintain detailed records including model cards, training data provenance, and decision logs.
obliging detailed records (model cards, documentation of training data provenance, decision logs) to enable audits and explainability
Before deployment and continuouslyImportant
8Italian public administrations deploying AI systemsImplement technical safeguards against data poisoning, model theft, and adversarial manipulation.
requiring technical safeguards against data poisoning, model theft and adversarial manipulation
Before deploymentImportant
9Italian public administrations procuring AI systemsIncorporate compliance, audit, and liability terms into AI system supplier contracts.
incorporating compliance, audit and liability terms into supplier contracts
Before contract signingImportant
10Italian public administrations deploying AI systemsConduct pre-deployment testing protocols and acceptance criteria for AI systems.
pre-deployment testing protocols and acceptance criteria
Before deploymentImportant
11Italian public administrations deploying AI systemsContinuously monitor and periodically re-evaluate deployed AI systems.
requires continuous monitoring and periodic re-evaluation of deployed systems
OngoingImportant
12Italian public administrations deploying AI systemsEstablish incident reporting and remediation procedures for AI systems.
It suggests establishing incident reporting and remediation procedures
Before deploymentImportant
13Italian public administrations deploying AI systemsProvide mechanisms for citizens to request human review or lodge complaints.
mechanisms for citizens to request human review or lodge complaints
Before deploymentImportant
14Italian public administrationsDevelop training plans and dedicated operational roles for AI systems.
recommending training plans and dedicated operational roles
Recommended

© Regulations.AI · updated on 13-Jun-2026