Italy - AI Regulation (n.132/2025)
Parliamentary bill n.1146 - Provisions and delegations to the Government regarding artificial intelligence
Disegno di legge n.1146 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale
Italy
RAI-IT-NA-DDLNDXX-2025Italy's Disegno di legge n.1146 (approved as Law n.132/2025) establishes national principles, sectoral rules and delegations to the Government for implementing measures on artificial intelligence, aligned with the EU AI Act. It sets a risk-based, anthropocentric framework covering public sector use, health, work, accessibility and new penal provisions concerning AI-enabled harms. (senato.it)
Summary
Disegno di legge n.1146 (approved and enacted as Law 23 September 2025, n.132) creates Italy's first comprehensive national statute addressing artificial intelligence by setting high-level principles, sectoral rules and delegations to the Government for secondary legislation and technical standards. The law declares an 'anthropocentric' approach that prioritizes human autonomy, non-discrimination, transparency, data protection and cybersecurity, and requires that national measures be interpreted in conformity with Regulation (EU) 2024/1689 (the EU AI Act). It includes targeted provisions for healthcare, disability, public administration, labour and the justice system, and requires additional safeguards where AI systems process sensitive data or affect fundamental rights. The statute also mandates that certain public sector AI systems be hosted on servers located within the national territory to preserve data sovereignty and security. For minors, the law provides specific consent rules (parental consent for children under 14 and special information/consent rules for 14–17 year olds). The law includes delegations to the Government to adopt implementing decrees within 12 months, and provides for enhanced oversight and cooperation among national authorities (including the Presidency of the Council, AgID, the National Cybersecurity Agency and the Data Protection Authority). Finally, the law introduces new criminal provisions and aggravating circumstances for harmful uses of AI (including provisions addressing the illicit dissemination of AI-generated audiovisual content and adjustments to corporate and market-manipulation offenses when committed through AI). The parliamentary dossier and texts are published on the Senate and Chamber websites and the law was published in the Gazzetta Ufficiale; entry into force followed the vacatio legis and occurred on 10 October 2025. ([documenti.camera.it](https://documenti.camera.it/leg19/pdl/xhtml/leg.19.pdl.camera.2316.19PDL0135060.html))
Full article
Read full text ↗Overview
The parliamentary initiative S.1146 (printed Senato n.1146 / Camera n.2316) and its final consolidated form S.1146‑B set out a national legislative framework for artificial intelligence in Italy. The law (enacted as Legge 23 September 2025, n.132) contains 28 articles grouped into six Capi (Principles and purposes; Sectoral provisions; National strategy and authorities; User protections and copyright; Penal provisions; Financial and final provisions) and is expressly to be applied in coherence with the EU AI Act (Regulation (EU) 2024/1689). The statute enshrines an anthropocentric vision of AI, combines rights-protective principles with economic development objectives and delegates detailed measures to Government decrees to be adopted under the mandate provided. Official parliamentary documentation and the approved text are available from the Senate and Chamber of Deputies and the final law was published in the Gazzetta Ufficiale. For the primary sources, see the parliamentary dossier and the published law. Senate dossier (S.1146), Chamber text (C.2316) and Gazzetta Ufficiale (publication & rettifica).
Definitions
The law adopts the terminology of the EU AI Act: "AI system", "AI model" and similar expressions are defined by reference to the definitions in Regulation (EU) 2024/1689. The statute supplements this approach with national clarifications such as a broad definition of "data" (including audio/visual recordings) and specific references to "models for general-purpose use". Where the national text is silent, the EU regulation's definitions apply. The statute also distinguishes public sector uses, sectoral applications (health, work, justice, education) and explicitly excludes national security and defence activities from its scope while preserving constitutional protections.
Governance and Institutional Framework
The law establishes a multi‑actor governance architecture and delegates powers to the Government to adopt implementing decrees. It envisions coordination among central administrations (including the Presidency of the Council), ministerial competences for sectoral rules (Health; Labour; Justice; Economy; Enterprises), and oversight roles for independent authorities. The Agency for the Italian Digital Agenda (AgID) and the national Data Protection Authority (Garante per la protezione dei dati personali) are referenced for technical standards and prior consultation in cases involving sensitive processing. The law gives a role to the Agenzia per la Cybersicurezza Nazionale (ACN) in defining cybersecurity requirements for AI systems and to institutions responsible for economic policy for measures supporting national competitiveness and technological sovereignty. The statute also mandates the creation or strengthening of observatories and inter‑ministerial committees to monitor deployment and to coordinate the delegated rule‑making process. See the Chamber and Senate texts for institutional assignments and the Government's delegation clauses. Chamber approved text, Senate 1146-B dossier (approved).
Key Focus Areas
The statute focuses on a set of priority areas: (1) fundamental rights protection (privacy, non‑discrimination, freedom of expression), (2) data governance and data quality for training models, (3) cybersecurity across the AI lifecycle, (4) sectoral regimes for health, disability support and public administration use, (5) labour and workplace protections (transparent information to workers, safeguards against unfair automated decisions), (6) accessibility requirements for persons with disabilities, and (7) intellectual property and liability adaptations for AI‑generated or AI‑assisted works. In the public sector the law requires localization of servers for systems used by public bodies (a national sovereignty/data security measure) and mandates explicit human oversight mechanisms where decisions materially affect citizens’ rights or public interests. The statute addresses minors by requiring parental consent under specified thresholds and clear information obligations. It also includes penal measures for serious abuses (e.g., illicit dissemination of deepfakes) and authorises the Government to define additional criminal and administrative sanctions as part of delegated measures. These themes reflect a hybrid approach that merges rights‑based governance with industrial policy and cybersecurity priorities.
Implementation Framework
Implementation is primarily delegated to the Government via decrees to be adopted within the timeframe established by the law (commonly 12 months), which will specify technical standards, thresholds, conformity assessment processes, registration duties, and the precise division of responsibilities among authorities. Decrees are expected to detail: criteria for identifying high‑risk systems within the national context, model‑level measures for general‑purpose models, procedures for conformity assessment and voluntary certification, specific cybersecurity controls for systems used in critical sectors, and administrative rules for procurement and public administration deployment. The law also contemplates budgetary provisions and funds to support public initiatives, research and the establishment of national observatories and training programs. Implementation will require coordinated rule‑making across ministries and consultation with the independent authorities referenced in the text.
Monitoring and Evaluation
The law requires ongoing monitoring by designated national bodies, the establishment of observatories and periodic reporting to Parliament and to the Presidency of the Council. Monitoring covers impacts on employment, public services, health outcomes, accessibility, privacy and safety incidents. The national observatory mechanism is expected to aggregate data and issue recommendations; delegated decrees will specify reporting formats, incident notification timelines and metrics for evaluation. The text provides for cooperation with the EU network of authorities under the AI Act and envisages alignment with European reporting systems and incident repositories.
Penalties, Liability, and Appeals
The statute contains administrative and penal provisions: administrative sanctions and oversight measures are foreseen for regulatory non‑compliance, while penal provisions introduce new or adapted crimes (including provisions addressing illicit dissemination of AI‑generated content and aggravating circumstances where omission of required security measures creates concrete danger to life or public safety). The law also asks the Government to clarify criteria for criminal and corporate liability tied to the development, deployment and omission of safety measures for AI systems. It preserves judicial remedies and administrative appeal routes while mandating cooperation between enforcement bodies and independent authorities in sanctioning and corrective actions. For precise edictal wording and penalties refer to the published law and parliamentary texts.
Relationship to Other Instruments
The law expressly operates in coherence with the EU AI Act (Regulation (EU) 2024/1689), the GDPR and national data protection legislation, existing cybersecurity frameworks (including directives transposed nationally), and sector‑specific rules (healthcare, labour law, public procurement). It also intersects with copyright and civil liability regimes; the statute foresees specific references to adaptation of intellectual property rules for AI‑generated content and delegates to the Government the power to adjust civil and administrative liability frameworks. The law thus acts as a national integrative layer—aligning domestic policy with EU rules while introducing context‑specific measures for Italy’s public sector and priority domains.
International Alignment
The statute is drafted to align with the EU AI Act and EU data protection law, and it foresees coordination with EU bodies and other Member States' competent authorities. By anchoring many definitions and minimum obligations to the AI Act, Italy aims to preserve regulatory harmonisation while adopting national measures to protect sovereignty and public interests. The law anticipates participation in EU networks, information exchanges and possible bilateral cooperation on standards, certification and enforcement. Italy signals intent to remain consistent with European policy while supporting national industrial policy objectives.
Implementation Timeline
| Date | Event |
|---|---|
| 20 May 2024 | Bill presented to Parliament (original initiative). |
| 20 March 2025 | Senate approval (S.1146) and transmission to the Chamber. |
| 25 June 2025 | Chamber approval with amendments (C.2316) and retransmission. |
| 17 September 2025 | Final approval in Senate (S.1146‑B) and signature as law. |
| 23 September 2025 | Promulgation date (Law text dated). |
| 25 September 2025 | Publication in the Gazzetta Ufficiale (GU n.223). |
| 10 October 2025 | Entry into force (end of vacatio legis). |
Sources and References
| Source | Type |
|---|---|
| Senate dossier (S.1146) | Primary Source |
| Camera text (C.2316) | Primary Source |
| Senate dossier and 1146-B (final documents and PDFs) | Primary Source |
| Approved DDL PDF (Senate PDF: 1146‑B) | Primary Source |
| Gazzetta Ufficiale (publication & rettifica) | Primary Source |
Requirements for a company
What an organisation has to do under Italy - AI Regulation (n.132/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
15- Comply with cybersecurity requirements defined by ACN for AI systems.Providers and deployers of AI systems.
- Implement cybersecurity measures across the entire AI system lifecycle.Providers and deployers of AI systems.
- Localize servers for AI systems used by public bodies within Italy.Public bodies using AI systems.
- Mandate explicit human oversight for AI decisions materially affecting rights or public interests.Deployers of AI systems in the public sector.
- Obtain parental consent for AI system use by minors under specified thresholds.Providers and deployers of AI systems interacting with minors.
- Do not illicitly disseminate AI-generated content, such as deepfakes.Any person.
- +9 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Italy - AI Regulation (n.132/2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers and deployers of AI systems. | Comply with cybersecurity requirements defined by ACN for AI systems. “The law gives a role to the Agenzia per la Cybersicurezza Nazionale (ACN) in defining cybersecurity requirements for AI systems.” | Before placing AI systems on the market or deploying them. | — | Critical |
| 2 | Providers and deployers of AI systems. | Implement cybersecurity measures across the entire AI system lifecycle. “cybersecurity across the AI lifecycle” | Continuously throughout the AI system lifecycle. | — | Critical |
| 3 | Public bodies using AI systems. | Localize servers for AI systems used by public bodies within Italy. “the law requires localization of servers for systems used by public bodies” | Before deploying AI systems in the public sector. | — | Critical |
| 4 | Deployers of AI systems in the public sector. | Mandate explicit human oversight for AI decisions materially affecting rights or public interests. “mandates explicit human oversight mechanisms where decisions materially affect citizens’ rights or public interests.” | Before deploying AI systems affecting rights or public interests. | — | Critical |
| 5 | Providers and deployers of AI systems interacting with minors. | Obtain parental consent for AI system use by minors under specified thresholds. “requiring parental consent under specified thresholds and clear information obligations.” | Before allowing AI use by minors. | — | Critical |
| 6 | Any person. | Do not illicitly disseminate AI-generated content, such as deepfakes. “penal measures for serious abuses (e.g., illicit dissemination of deepfakes)” | Always. | — | Critical |
| 7 | Providers and deployers of AI systems. | Map AI systems and identify high-risk uses according to national criteria. | Before placing AI systems on the market or deploying them. | — | Critical |
| 8 | Providers of AI systems and public bodies. | Adopt a risk management system and conduct Data Protection Impact Assessments (DPIAs). | Before placing AI systems on the market or deploying them. | — | Critical |
| 9 | Providers of AI models. | Ensure data governance and quality for training AI models. “data governance and data quality for training models” | Before training AI models. | — | Important |
| 10 | Entities processing sensitive data with AI systems. | Consult the Garante for data protection in cases involving sensitive processing. “prior consultation in cases involving sensitive processing.” | Before processing sensitive data. | — | Important |
| 11 | Employers using AI systems in the workplace. | Provide transparent information to workers about AI system use in the workplace. “transparent information to workers” | Before deploying AI systems affecting workers. | — | Important |
| 12 | Employers using AI systems in the workplace. | Implement safeguards against unfair automated decisions affecting workers. “safeguards against unfair automated decisions” | Before deploying AI systems affecting workers. | — | Important |
| 13 | Providers and deployers of AI systems. | Ensure AI systems meet accessibility requirements for persons with disabilities. “accessibility requirements for persons with disabilities” | Before placing AI systems on the market or deploying them. | — | Important |
| 14 | Providers and deployers of AI systems interacting with minors. | Provide clear information about AI systems to minors and their parents. “clear information obligations” | Before allowing AI use by minors. | — | Important |
| 15 | Providers, importers, and distributors of AI systems. | Register required information in national registries as specified by decrees. “registration duties” | As per future decrees. | — | Important |
Related Regulations
Legge n.132 del 23 settembre 2025 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale (National Law on Artificial Intelligence)
Italy96% similar
Italy AI Regulation Overview
Italy93% similar
Bozza - Linee guida per l'adozione dell'Intelligenza Artificiale nella Pubblica Amministrazione (AgID draft guidelines on AI adoption in the PA)
Italy91% similar
Programma Strategico per l'Intelligenza Artificiale (Strategic Programme on Artificial Intelligence) 2022-2024
Italy90% similar
226 of 2025 - Artificial Intelligence Regulations, 2025 (Legal Notice)
Malta90% similar
© Regulations.AI · updated on 13-Jun-2026