Italy - AI Regulation (n.132/2025)

Parliamentary bill n.1146 - Provisions and delegations to the Government regarding artificial intelligence

Disegno di legge n.1146 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Italy

RAI-IT-NA-DDLNDXX-2025
Effective: October 10, 2025
In Force(In Force)
ActGovernance and OversightRisk ManagementCybersecurity and Model Security
Export PDF

Italy's Disegno di legge n.1146 (approved as Law n.132/2025) establishes national principles, sectoral rules and delegations to the Government for implementing measures on artificial intelligence, aligned with the EU AI Act. It sets a risk-based, anthropocentric framework covering public sector use, health, work, accessibility and new penal provisions concerning AI-enabled harms. (senato.it)

Summary

Disegno di legge n.1146 (approved and enacted as Law 23 September 2025, n.132) creates Italy's first comprehensive national statute addressing artificial intelligence by setting high-level principles, sectoral rules and delegations to the Government for secondary legislation and technical standards. The law declares an 'anthropocentric' approach that prioritizes human autonomy, non-discrimination, transparency, data protection and cybersecurity, and requires that national measures be interpreted in conformity with Regulation (EU) 2024/1689 (the EU AI Act). It includes targeted provisions for healthcare, disability, public administration, labour and the justice system, and requires additional safeguards where AI systems process sensitive data or affect fundamental rights. The statute also mandates that certain public sector AI systems be hosted on servers located within the national territory to preserve data sovereignty and security. For minors, the law provides specific consent rules (parental consent for children under 14 and special information/consent rules for 14–17 year olds). The law includes delegations to the Government to adopt implementing decrees within 12 months, and provides for enhanced oversight and cooperation among national authorities (including the Presidency of the Council, AgID, the National Cybersecurity Agency and the Data Protection Authority). Finally, the law introduces new criminal provisions and aggravating circumstances for harmful uses of AI (including provisions addressing the illicit dissemination of AI-generated audiovisual content and adjustments to corporate and market-manipulation offenses when committed through AI). The parliamentary dossier and texts are published on the Senate and Chamber websites and the law was published in the Gazzetta Ufficiale; entry into force followed the vacatio legis and occurred on 10 October 2025. ([documenti.camera.it](https://documenti.camera.it/leg19/pdl/xhtml/leg.19.pdl.camera.2316.19PDL0135060.html))

Full article

Read full text ↗

Overview

The parliamentary initiative S.1146 (printed Senato n.1146 / Camera n.2316) and its final consolidated form S.1146‑B set out a national legislative framework for artificial intelligence in Italy. The law (enacted as Legge 23 September 2025, n.132) contains 28 articles grouped into six Capi (Principles and purposes; Sectoral provisions; National strategy and authorities; User protections and copyright; Penal provisions; Financial and final provisions) and is expressly to be applied in coherence with the EU AI Act (Regulation (EU) 2024/1689). The statute enshrines an anthropocentric vision of AI, combines rights-protective principles with economic development objectives and delegates detailed measures to Government decrees to be adopted under the mandate provided. Official parliamentary documentation and the approved text are available from the Senate and Chamber of Deputies and the final law was published in the Gazzetta Ufficiale. For the primary sources, see the parliamentary dossier and the published law. Senate dossier (S.1146), Chamber text (C.2316) and Gazzetta Ufficiale (publication & rettifica).

Definitions

The law adopts the terminology of the EU AI Act: "AI system", "AI model" and similar expressions are defined by reference to the definitions in Regulation (EU) 2024/1689. The statute supplements this approach with national clarifications such as a broad definition of "data" (including audio/visual recordings) and specific references to "models for general-purpose use". Where the national text is silent, the EU regulation's definitions apply. The statute also distinguishes public sector uses, sectoral applications (health, work, justice, education) and explicitly excludes national security and defence activities from its scope while preserving constitutional protections.

Governance and Institutional Framework

The law establishes a multi‑actor governance architecture and delegates powers to the Government to adopt implementing decrees. It envisions coordination among central administrations (including the Presidency of the Council), ministerial competences for sectoral rules (Health; Labour; Justice; Economy; Enterprises), and oversight roles for independent authorities. The Agency for the Italian Digital Agenda (AgID) and the national Data Protection Authority (Garante per la protezione dei dati personali) are referenced for technical standards and prior consultation in cases involving sensitive processing. The law gives a role to the Agenzia per la Cybersicurezza Nazionale (ACN) in defining cybersecurity requirements for AI systems and to institutions responsible for economic policy for measures supporting national competitiveness and technological sovereignty. The statute also mandates the creation or strengthening of observatories and inter‑ministerial committees to monitor deployment and to coordinate the delegated rule‑making process. See the Chamber and Senate texts for institutional assignments and the Government's delegation clauses. Chamber approved text, Senate 1146-B dossier (approved).

Key Focus Areas

The statute focuses on a set of priority areas: (1) fundamental rights protection (privacy, non‑discrimination, freedom of expression), (2) data governance and data quality for training models, (3) cybersecurity across the AI lifecycle, (4) sectoral regimes for health, disability support and public administration use, (5) labour and workplace protections (transparent information to workers, safeguards against unfair automated decisions), (6) accessibility requirements for persons with disabilities, and (7) intellectual property and liability adaptations for AI‑generated or AI‑assisted works. In the public sector the law requires localization of servers for systems used by public bodies (a national sovereignty/data security measure) and mandates explicit human oversight mechanisms where decisions materially affect citizens’ rights or public interests. The statute addresses minors by requiring parental consent under specified thresholds and clear information obligations. It also includes penal measures for serious abuses (e.g., illicit dissemination of deepfakes) and authorises the Government to define additional criminal and administrative sanctions as part of delegated measures. These themes reflect a hybrid approach that merges rights‑based governance with industrial policy and cybersecurity priorities.

Implementation Framework

Implementation is primarily delegated to the Government via decrees to be adopted within the timeframe established by the law (commonly 12 months), which will specify technical standards, thresholds, conformity assessment processes, registration duties, and the precise division of responsibilities among authorities. Decrees are expected to detail: criteria for identifying high‑risk systems within the national context, model‑level measures for general‑purpose models, procedures for conformity assessment and voluntary certification, specific cybersecurity controls for systems used in critical sectors, and administrative rules for procurement and public administration deployment. The law also contemplates budgetary provisions and funds to support public initiatives, research and the establishment of national observatories and training programs. Implementation will require coordinated rule‑making across ministries and consultation with the independent authorities referenced in the text.

Monitoring and Evaluation

The law requires ongoing monitoring by designated national bodies, the establishment of observatories and periodic reporting to Parliament and to the Presidency of the Council. Monitoring covers impacts on employment, public services, health outcomes, accessibility, privacy and safety incidents. The national observatory mechanism is expected to aggregate data and issue recommendations; delegated decrees will specify reporting formats, incident notification timelines and metrics for evaluation. The text provides for cooperation with the EU network of authorities under the AI Act and envisages alignment with European reporting systems and incident repositories.

Penalties, Liability, and Appeals

The statute contains administrative and penal provisions: administrative sanctions and oversight measures are foreseen for regulatory non‑compliance, while penal provisions introduce new or adapted crimes (including provisions addressing illicit dissemination of AI‑generated content and aggravating circumstances where omission of required security measures creates concrete danger to life or public safety). The law also asks the Government to clarify criteria for criminal and corporate liability tied to the development, deployment and omission of safety measures for AI systems. It preserves judicial remedies and administrative appeal routes while mandating cooperation between enforcement bodies and independent authorities in sanctioning and corrective actions. For precise edictal wording and penalties refer to the published law and parliamentary texts.

Relationship to Other Instruments

The law expressly operates in coherence with the EU AI Act (Regulation (EU) 2024/1689), the GDPR and national data protection legislation, existing cybersecurity frameworks (including directives transposed nationally), and sector‑specific rules (healthcare, labour law, public procurement). It also intersects with copyright and civil liability regimes; the statute foresees specific references to adaptation of intellectual property rules for AI‑generated content and delegates to the Government the power to adjust civil and administrative liability frameworks. The law thus acts as a national integrative layer—aligning domestic policy with EU rules while introducing context‑specific measures for Italy’s public sector and priority domains.

International Alignment

The statute is drafted to align with the EU AI Act and EU data protection law, and it foresees coordination with EU bodies and other Member States' competent authorities. By anchoring many definitions and minimum obligations to the AI Act, Italy aims to preserve regulatory harmonisation while adopting national measures to protect sovereignty and public interests. The law anticipates participation in EU networks, information exchanges and possible bilateral cooperation on standards, certification and enforcement. Italy signals intent to remain consistent with European policy while supporting national industrial policy objectives.

Implementation Timeline

DateEvent
20 May 2024Bill presented to Parliament (original initiative).
20 March 2025Senate approval (S.1146) and transmission to the Chamber.
25 June 2025Chamber approval with amendments (C.2316) and retransmission.
17 September 2025Final approval in Senate (S.1146‑B) and signature as law.
23 September 2025Promulgation date (Law text dated).
25 September 2025Publication in the Gazzetta Ufficiale (GU n.223).
10 October 2025Entry into force (end of vacatio legis).

Sources and References

SourceType
Senate dossier (S.1146)Primary Source
Camera text (C.2316)Primary Source
Senate dossier and 1146-B (final documents and PDFs)Primary Source
Approved DDL PDF (Senate PDF: 1146‑B)Primary Source
Gazzetta Ufficiale (publication & rettifica)Primary Source

Requirements for a company

What an organisation has to do under Italy - AI Regulation (n.132/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

15
  • Comply with cybersecurity requirements defined by ACN for AI systems.Providers and deployers of AI systems.
  • Implement cybersecurity measures across the entire AI system lifecycle.Providers and deployers of AI systems.
  • Localize servers for AI systems used by public bodies within Italy.Public bodies using AI systems.
  • Mandate explicit human oversight for AI decisions materially affecting rights or public interests.Deployers of AI systems in the public sector.
  • Obtain parental consent for AI system use by minors under specified thresholds.Providers and deployers of AI systems interacting with minors.
  • Do not illicitly disseminate AI-generated content, such as deepfakes.Any person.
  • +9 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Italy - AI Regulation (n.132/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers and deployers of AI systems.Comply with cybersecurity requirements defined by ACN for AI systems.
The law gives a role to the Agenzia per la Cybersicurezza Nazionale (ACN) in defining cybersecurity requirements for AI systems.
Before placing AI systems on the market or deploying them.Critical
2Providers and deployers of AI systems.Implement cybersecurity measures across the entire AI system lifecycle.
cybersecurity across the AI lifecycle
Continuously throughout the AI system lifecycle.Critical
3Public bodies using AI systems.Localize servers for AI systems used by public bodies within Italy.
the law requires localization of servers for systems used by public bodies
Before deploying AI systems in the public sector.Critical
4Deployers of AI systems in the public sector.Mandate explicit human oversight for AI decisions materially affecting rights or public interests.
mandates explicit human oversight mechanisms where decisions materially affect citizens’ rights or public interests.
Before deploying AI systems affecting rights or public interests.Critical
5Providers and deployers of AI systems interacting with minors.Obtain parental consent for AI system use by minors under specified thresholds.
requiring parental consent under specified thresholds and clear information obligations.
Before allowing AI use by minors.Critical
6Any person.Do not illicitly disseminate AI-generated content, such as deepfakes.
penal measures for serious abuses (e.g., illicit dissemination of deepfakes)
Always.Critical
7Providers and deployers of AI systems.Map AI systems and identify high-risk uses according to national criteria.Before placing AI systems on the market or deploying them.Critical
8Providers of AI systems and public bodies.Adopt a risk management system and conduct Data Protection Impact Assessments (DPIAs).Before placing AI systems on the market or deploying them.Critical
9Providers of AI models.Ensure data governance and quality for training AI models.
data governance and data quality for training models
Before training AI models.Important
10Entities processing sensitive data with AI systems.Consult the Garante for data protection in cases involving sensitive processing.
prior consultation in cases involving sensitive processing.
Before processing sensitive data.Important
11Employers using AI systems in the workplace.Provide transparent information to workers about AI system use in the workplace.
transparent information to workers
Before deploying AI systems affecting workers.Important
12Employers using AI systems in the workplace.Implement safeguards against unfair automated decisions affecting workers.
safeguards against unfair automated decisions
Before deploying AI systems affecting workers.Important
13Providers and deployers of AI systems.Ensure AI systems meet accessibility requirements for persons with disabilities.
accessibility requirements for persons with disabilities
Before placing AI systems on the market or deploying them.Important
14Providers and deployers of AI systems interacting with minors.Provide clear information about AI systems to minors and their parents.
clear information obligations
Before allowing AI use by minors.Important
15Providers, importers, and distributors of AI systems.Register required information in national registries as specified by decrees.
registration duties
As per future decrees.Important

© Regulations.AI · updated on 13-Jun-2026