Italy - National AI Law (132/2025)
Law No. 132 of September 23, 2025 - Provisions and Delegations to the Government on Artificial Intelligence
Legge n.132 del 23 settembre 2025 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale
Italy
RAI-IT-NA-LND2SXX-2025Legge n.132/2025 establishes a national framework for the development, deployment and governance of artificial intelligence in Italy, aligning domestic policy with the EU AI Act (Reg. 2024/1689). It defines principles (anthropocentric, transparent, safe), designates AgID and the National Cybersecurity Agency (ACN) as national authorities, introduces sectoral rules (health, labour, finance), and adds new criminal and administrative measures including a specific offence for illicit dissemination of AI-generated/altered content (deepfakes).
Summary
Legge 23 September 2025, n.132 is Italy's comprehensive national act on artificial intelligence, published in Gazzetta Ufficiale (GU n.223, 25 September 2025) and entering into force on 10 October 2025. The law establishes principles and objectives for research, experimentation, development, adoption and use of AI systems, emphasizing human-centric (anthropocentric) application, protection of fundamental rights, data protection and cybersecurity. It expressly interprets and applies in conformity with the EU AI Act (Regulation (EU) 2024/1689), while adding national governance structures, sectoral rules, enforcement mechanisms and penal provisions adapted to Italy's legal and institutional context.
Key institutional arrangements include designation of the Agenzia per l'Italia Digitale (AgID) and the Agenzia per la Cybersicurezza Nazionale (ACN) as the national authorities for AI, with AgID responsible for promotion, notification and conformity-assessment procedures and ACN responsible for market surveillance, inspections and cybersecurity oversight. The Presidency of the Council (through the competent structure for innovation and digital transition) leads national strategy and coordination; a Committee for coordination and a Committee of interministerial direction are provided to align ministerial action and monitor implementation. The law provides delegations to the Government to adopt technical and implementing decrees (decreti legislativi and decreti ministeriali) to specify conformity assessment, accreditation, notification processes, thresholds, sanctions and procedural details.
Sector provisions cover healthcare (AI as clinical decision support with mandatory human oversight and patient information), employment (rules for AI use in recruitment, performance evaluation and workplace monitoring), public administration (rules for procurement, adoption and experimentation), copyright (treatment of works created with AI and obligations to disclose AI use), and financial markets (adjustments to offences such as market manipulation and disclosure obligations where AI is used). The law introduces new criminal provisions, notably Art. 612-quater c.p. criminalising illicit dissemination of AI-generated or altered images, video or audio that causes unjust damage to a person (punishable by 1–5 years' imprisonment, with procedural rules for complaints and public-interest prosecutions). It also directs legislative action to clarify criminal and administrative liability linked to omissions in safety measures for AI systems that pose concrete danger to life, public safety or national security.
Compliance obligations set out documentation, record-keeping, risk assessments, testing and human oversight requirements, registration/notification (as aligned with the EU regime), and obligations on providers, deployers and professional users. Market surveillance, conformity assessment and accreditation schemes will be implemented jointly by AgID and ACN, with supervisory roles reserved for sectoral supervisors (Banca d'Italia, CONSOB, IVASS) where applicable. Administrative fines, corrective measures and criminal sanctions are provided; delegated measures will define precise sanctioning ranges and procedural rules.
The law represents Italy's attempt to combine alignment with EU harmonised rules with national priorities (innovation support, industrial policy, strategic autonomy and sectoral specificity). It creates a detailed implementation roadmap (biennial national AI strategy, delegated decrees, experimental sandboxes) and resources for promotion, monitoring and enforcement. Primary official sources include the Gazzetta Ufficiale publication of the law and explanatory materials from AgID and parliamentary documentation.
Full article
Read full text ↗Overview
Legge 23 September 2025, n.132 "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" is the national statute establishing Italy's domestic framework for artificial intelligence. Published in the Gazzetta Ufficiale - Legge 23 settembre 2025, n. 132, the law enters into force on 10 October 2025 and is explicitly designed to operate in conformity with the European AI Act (Regulation (EU) 2024/1689). It codifies principles (anthropocentrism, transparency, proportionality, security, non‑discrimination), delegates implementing powers to the Government and sets up a governance architecture led by the Presidency of the Council with technical roles for AgID and the National Cybersecurity Agency (ACN). The law covers sectoral rules (healthcare, labour, public administration, finance), conformity assessment, market surveillance, penal offences for misuse of AI (including a new deepfake offence), and provisions on data, copyright and user protection. For an authoritative summary by the designated promotion agency, see AgID - AI.
Definitions
The law adopts and references the AI-related definitions used by EU Regulation 2024/1689 and clarifies national-specific terms. Key defined concepts include: "system of artificial intelligence" (broadly covering models, algorithms, software and associated data pipelines); "provider" (natural or legal person who develops and places an AI system on the market or puts it into service); "user" and "professional user" (entities deploying or employing AI in the course of economic activity); "high-risk AI systems" (as per EU lists and national extensions); "deployment" and "use"; and procedural terms such as "notification", "conformity assessment" and "market surveillance". The law also defines unlawful dissemination of AI-generated or altered content for penal purposes and clarifies terms for criminal imputability connected to AI-driven processes.
Governance and Institutional Framework
Article 19–21 create a layered governance architecture. The Presidency of the Council (structure for innovation and digital transition) prepares and updates the national AI strategy, to be approved biennially by the interministerial committee. The Act designates the Agenzia per l'Italia Digitale (AgID) and the Agenzia per la Cybersicurezza Nazionale (ACN) as the national authorities for AI (Art. 20). AgID is tasked with promotion, innovation facilitation, notification management and accreditation of conformity-assessment bodies. ACN is designated as the market surveillance and inspection authority, with powers for cybersecurity oversight, inspections and sanctions. Sectoral supervisors (Banca d'Italia, CONSOB, IVASS) retain market oversight powers for financial/insurance sectors. A coordinating committee of director generals from AgID, ACN and the Presidency of the Council ensures operational alignment; a wider ministerial committee ensures policy direction (including defence, research, health, and economy ministries). The law also mandates collaboration with the Data Protection Authority and the Communications Authority where their competences intersect.
Key Focus Areas
The statute addresses multiple substantive domains: (1) fundamental rights and non-discrimination – requiring impact assessments and safeguards where AI affects rights; (2) data governance and privacy – alignment with GDPR and specific obligations for datasets used to train models deployed in Italy; (3) safety, testing and conformity – mandatory risk assessment, documentation and technical testing for high‑risk systems, with accreditation of conformity assessors carried out under AgID supervision; (4) transparency and disclosure – obligations to label synthetic content and to inform users when AI supports decision‑making, especially in healthcare and employment; (5) employment and workplace use – specific provisions require information to workers about AI use and protections limiting surveillance and unjustified automated profiling; (6) public administration and procurement – guidelines and rules for experimentation and procurement emphasizing interoperability, accessibility and auditability; (7) copyright and creative works – rules clarifying attribution, authorship and rights where AI substantially contributes to creative outputs; (8) market and financial integrity – adjustments to market abuse provisions where AI is used to influence markets; and (9) criminal law – introduction of Art. 612‑quater (illicit dissemination of AI‑generated or altered content) and directives to clarify criminal/administrative liability linked to safety omissions.
Implementation Framework
The Act delegates to the Government a program of implementing decrees to define: the lists and thresholds of high‑risk systems appropriate for Italy; detailed procedures for notification and conformity assessment; accreditation criteria for conformity assessors; sanctions and fines scales; procedural rules for inspections; sectoral rules for healthcare platforms and financial services; and funding and incentive schemes for research and SMEs. It requires the Presidency of the Council to publish a biennial national AI strategy and funds targeted initiatives (including experimentation sandboxes and competency programs). AgID and ACN must coordinate issuance of technical guidelines and linee guida, and create joint testbeds for compliance testing. The delegated measures will also specify registration and record‑keeping formats, and the interplay with national cybersecurity obligations and the NIS2 regime.
Monitoring and Evaluation
The law sets monitoring duties: AgID and ACN must produce annual monitoring reports on strategy implementation, market compliance and risks; results are transmitted to Parliament. The statute provides for metrics and monitoring targets (adoption projects, research investments, cybersecurity incidents) and requires the Presidency to evaluate socio‑economic impacts. It mandates sample audits, systematic market surveillance on high‑risk systems and a public register (to be implemented) of certain AI systems placed on the market or put into service. The Act links monitoring outputs to funding, research incentives and updates to the national strategy.
Penalties, Liability, and Appeals
The law establishes a mixed sanctioning regime. Administrative fines, corrective measures (recall, suspension, withdrawal) and public remediation orders will be available for regulatory breaches and are to be quantified in forthcoming delegated decrees. On the criminal side, Art. 612‑quater c.p. criminalises the illicit dissemination of images, video or audio falsified or altered by AI causing unjust damage, punishable with imprisonment (1–5 years) and initiated by complaint or ex officio in specified situations. The Act also mandates legislative clarification on imputability for crimes/administrative offences committed via AI, and contemplates liability for omission or failure to adopt safety measures where such omissions create concrete danger to life, public safety or national security. Affected parties retain administrative and judicial appeal routes; procedural details for sanctions and appeal bodies will be specified in implementing measures.
Relationship to Other Instruments
The statute is explicitly designed to be consistent with and complementary to: Regulation (EU) 2024/1689 (AI Act), GDPR (Regulation (EU) 2016/679), NIS2 and other sectoral EU rules, the Italian Data Protection Code and existing sectoral legislation for health, finance and labour. It modifies or interacts with the Civil Code, the Penal Code, the Testo Unico della Finanza and public procurement rules where necessary. The law also references existing national strategies (Italian AI Strategy and AgID guidance) and creates a path for delegated acts to coordinate domestic regulatory instruments.
International Alignment
While implementing a national approach, Legge n.132/2025 seeks alignment with EU harmonisation under the AI Act and with international standards on AI safety, cybersecurity and human rights. The law designates national contact points (AgID as notification authority and ACN as market surveillance and single contact point to EU institutions) to ensure coordination with EU bodies and cross‑border enforcement. It encourages participation in international testbeds, standards bodies and research cooperation, and foresees adaptation of national lists of high‑risk systems to EU delegated acts and globally recognised standards.
Implementation Timeline
| Milestone | Deadline / Date |
|---|---|
| Publication in Gazzetta Ufficiale | 2025-09-25 |
| Entry into force (vacatio legis expired) | 2025-10-10 |
| Biennial National AI Strategy first update due | Within 24 months of entry into force (by 2027-10-10) |
| Government delegated decrees (conformity, sanctions, thresholds) | Staged; implementing decree schedule set by Law (see articles delegating powers) — expected 2025–2026 |
| Establishment of joint AgID–ACN testbeds and public register | To be defined in implementing acts; monitoring reports annually |
Sources and References
| Source | Type |
|---|---|
| Gazzetta Ufficiale — Legge 23 settembre 2025, n. 132 (Atto completo) | Primary Source |
| AgID — Intelligence Artificial pages and guidance | Primary Source (Agency) |
| Parliamentary dossier and preparatory documents (Camera dei Deputati) | Primary Source |
Requirements for a company
What an organisation has to do under Italy - National AI Law (132/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
14- Do not illicitly disseminate AI-generated or altered content causing unjust damage.Any person.
- Conduct impact assessments and implement safeguards where AI affects fundamental rights.Providers and deployers of AI systems affecting fundamental rights.
- Comply with GDPR and specific obligations for datasets used to train AI models deployed in Italy.Providers and deployers of AI systems using training datasets in Italy.
- Conduct mandatory risk assessment for high-risk AI systems.Providers of high-risk AI systems.
- Maintain comprehensive documentation for high-risk AI systems.Providers of high-risk AI systems.
- Perform technical testing for high-risk AI systems.Providers of high-risk AI systems.
- +8 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Italy - National AI Law (132/2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Any person. | Do not illicitly disseminate AI-generated or altered content causing unjust damage. “Art. 612‑quater (illicit dissemination of AI‑generated or altered content)” | Oct 10, 2025 | Art. 612‑quater | Critical |
| 2 | Providers and deployers of AI systems affecting fundamental rights. | Conduct impact assessments and implement safeguards where AI affects fundamental rights. “requiring impact assessments and safeguards where AI affects rights” | Before placing on market | Key Focus Areas (1) | Critical |
| 3 | Providers and deployers of AI systems using training datasets in Italy. | Comply with GDPR and specific obligations for datasets used to train AI models deployed in Italy. “alignment with GDPR and specific obligations for datasets used to train models deployed in Italy” | Before placing on market | Key Focus Areas (2) | Critical |
| 4 | Providers of high-risk AI systems. | Conduct mandatory risk assessment for high-risk AI systems. “mandatory risk assessment... for high‑risk systems” | Before placing on market | Key Focus Areas (3) | Critical |
| 5 | Providers of high-risk AI systems. | Maintain comprehensive documentation for high-risk AI systems. “documentation and technical testing for high‑risk systems” | Before placing on market | Key Focus Areas (3) | Critical |
| 6 | Providers of high-risk AI systems. | Perform technical testing for high-risk AI systems. “technical testing for high‑risk systems” | Before placing on market | Key Focus Areas (3) | Critical |
| 7 | Providers and publishers of AI-generated materials. | Label AI-generated synthetic content. “obligations to label synthetic content” | Before dissemination | Key Focus Areas (4) | Critical |
| 8 | Providers and deployers of AI systems. | Adopt safety measures to prevent concrete danger to life, public safety, or national security from AI systems. “liability for omission or failure to adopt safety measures where such omissions create concrete danger” | Before placing on market | Key Focus Areas (9) | Critical |
| 9 | Providers and operators of AI systems. | Comply with national cybersecurity obligations and the NIS2 regime. “interplay with national cybersecurity obligations and the NIS2 regime” | Oct 10, 2025 | Implementation Framework | Critical |
| 10 | Deployers of AI systems supporting decision-making. | Inform users when AI supports decision-making, especially in healthcare and employment. “inform users when AI supports decision‑making, especially in healthcare and employment” | Before putting into service | Key Focus Areas (4) | Important |
| 11 | Employers deploying AI in the workplace. | Inform workers about AI use in the workplace. “require information to workers about AI use” | Before deploying AI in the workplace | Key Focus Areas (5) | Important |
| 12 | Employers deploying AI in the workplace. | Implement protections limiting AI surveillance and unjustified automated profiling of workers. “protections limiting surveillance and unjustified automated profiling” | Before deploying AI in the workplace | Key Focus Areas (5) | Important |
| 13 | Public administration entities procuring AI systems. | Emphasize interoperability, accessibility, and auditability in public AI procurement. “emphasizing interoperability, accessibility and auditability” | When procuring AI systems | Key Focus Areas (6) | Important |
| 14 | Providers of certain AI systems. | Register certain AI systems placed on the Italian market or put into service. “public register (to be implemented) of certain AI systems placed on the market or put into service” | To be defined in implementing acts | Implementation Framework | Important |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026