Italy - National AI Law (132/2025)

Law No. 132 of September 23, 2025 - Provisions and Delegations to the Government on Artificial Intelligence

Legge n.132 del 23 settembre 2025 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Italy

RAI-IT-NA-LND2SXX-2025
Effective: October 10, 2025
In Force(In Force)
ActGovernance and OversightConformity Assessment and RegistrationEnforcement and Penalties
Export PDF

Legge n.132/2025 establishes a national framework for the development, deployment and governance of artificial intelligence in Italy, aligning domestic policy with the EU AI Act (Reg. 2024/1689). It defines principles (anthropocentric, transparent, safe), designates AgID and the National Cybersecurity Agency (ACN) as national authorities, introduces sectoral rules (health, labour, finance), and adds new criminal and administrative measures including a specific offence for illicit dissemination of AI-generated/altered content (deepfakes).

Summary

Legge 23 September 2025, n.132 is Italy's comprehensive national act on artificial intelligence, published in Gazzetta Ufficiale (GU n.223, 25 September 2025) and entering into force on 10 October 2025. The law establishes principles and objectives for research, experimentation, development, adoption and use of AI systems, emphasizing human-centric (anthropocentric) application, protection of fundamental rights, data protection and cybersecurity. It expressly interprets and applies in conformity with the EU AI Act (Regulation (EU) 2024/1689), while adding national governance structures, sectoral rules, enforcement mechanisms and penal provisions adapted to Italy's legal and institutional context.

Key institutional arrangements include designation of the Agenzia per l'Italia Digitale (AgID) and the Agenzia per la Cybersicurezza Nazionale (ACN) as the national authorities for AI, with AgID responsible for promotion, notification and conformity-assessment procedures and ACN responsible for market surveillance, inspections and cybersecurity oversight. The Presidency of the Council (through the competent structure for innovation and digital transition) leads national strategy and coordination; a Committee for coordination and a Committee of interministerial direction are provided to align ministerial action and monitor implementation. The law provides delegations to the Government to adopt technical and implementing decrees (decreti legislativi and decreti ministeriali) to specify conformity assessment, accreditation, notification processes, thresholds, sanctions and procedural details.

Sector provisions cover healthcare (AI as clinical decision support with mandatory human oversight and patient information), employment (rules for AI use in recruitment, performance evaluation and workplace monitoring), public administration (rules for procurement, adoption and experimentation), copyright (treatment of works created with AI and obligations to disclose AI use), and financial markets (adjustments to offences such as market manipulation and disclosure obligations where AI is used). The law introduces new criminal provisions, notably Art. 612-quater c.p. criminalising illicit dissemination of AI-generated or altered images, video or audio that causes unjust damage to a person (punishable by 1–5 years' imprisonment, with procedural rules for complaints and public-interest prosecutions). It also directs legislative action to clarify criminal and administrative liability linked to omissions in safety measures for AI systems that pose concrete danger to life, public safety or national security.

Compliance obligations set out documentation, record-keeping, risk assessments, testing and human oversight requirements, registration/notification (as aligned with the EU regime), and obligations on providers, deployers and professional users. Market surveillance, conformity assessment and accreditation schemes will be implemented jointly by AgID and ACN, with supervisory roles reserved for sectoral supervisors (Banca d'Italia, CONSOB, IVASS) where applicable. Administrative fines, corrective measures and criminal sanctions are provided; delegated measures will define precise sanctioning ranges and procedural rules.

The law represents Italy's attempt to combine alignment with EU harmonised rules with national priorities (innovation support, industrial policy, strategic autonomy and sectoral specificity). It creates a detailed implementation roadmap (biennial national AI strategy, delegated decrees, experimental sandboxes) and resources for promotion, monitoring and enforcement. Primary official sources include the Gazzetta Ufficiale publication of the law and explanatory materials from AgID and parliamentary documentation.

Full article

Read full text ↗

Overview

Legge 23 September 2025, n.132 "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" is the national statute establishing Italy's domestic framework for artificial intelligence. Published in the Gazzetta Ufficiale - Legge 23 settembre 2025, n. 132, the law enters into force on 10 October 2025 and is explicitly designed to operate in conformity with the European AI Act (Regulation (EU) 2024/1689). It codifies principles (anthropocentrism, transparency, proportionality, security, non‑discrimination), delegates implementing powers to the Government and sets up a governance architecture led by the Presidency of the Council with technical roles for AgID and the National Cybersecurity Agency (ACN). The law covers sectoral rules (healthcare, labour, public administration, finance), conformity assessment, market surveillance, penal offences for misuse of AI (including a new deepfake offence), and provisions on data, copyright and user protection. For an authoritative summary by the designated promotion agency, see AgID - AI.

Definitions

The law adopts and references the AI-related definitions used by EU Regulation 2024/1689 and clarifies national-specific terms. Key defined concepts include: "system of artificial intelligence" (broadly covering models, algorithms, software and associated data pipelines); "provider" (natural or legal person who develops and places an AI system on the market or puts it into service); "user" and "professional user" (entities deploying or employing AI in the course of economic activity); "high-risk AI systems" (as per EU lists and national extensions); "deployment" and "use"; and procedural terms such as "notification", "conformity assessment" and "market surveillance". The law also defines unlawful dissemination of AI-generated or altered content for penal purposes and clarifies terms for criminal imputability connected to AI-driven processes.

Governance and Institutional Framework

Article 19–21 create a layered governance architecture. The Presidency of the Council (structure for innovation and digital transition) prepares and updates the national AI strategy, to be approved biennially by the interministerial committee. The Act designates the Agenzia per l'Italia Digitale (AgID) and the Agenzia per la Cybersicurezza Nazionale (ACN) as the national authorities for AI (Art. 20). AgID is tasked with promotion, innovation facilitation, notification management and accreditation of conformity-assessment bodies. ACN is designated as the market surveillance and inspection authority, with powers for cybersecurity oversight, inspections and sanctions. Sectoral supervisors (Banca d'Italia, CONSOB, IVASS) retain market oversight powers for financial/insurance sectors. A coordinating committee of director generals from AgID, ACN and the Presidency of the Council ensures operational alignment; a wider ministerial committee ensures policy direction (including defence, research, health, and economy ministries). The law also mandates collaboration with the Data Protection Authority and the Communications Authority where their competences intersect.

Key Focus Areas

The statute addresses multiple substantive domains: (1) fundamental rights and non-discrimination – requiring impact assessments and safeguards where AI affects rights; (2) data governance and privacy – alignment with GDPR and specific obligations for datasets used to train models deployed in Italy; (3) safety, testing and conformity – mandatory risk assessment, documentation and technical testing for high‑risk systems, with accreditation of conformity assessors carried out under AgID supervision; (4) transparency and disclosure – obligations to label synthetic content and to inform users when AI supports decision‑making, especially in healthcare and employment; (5) employment and workplace use – specific provisions require information to workers about AI use and protections limiting surveillance and unjustified automated profiling; (6) public administration and procurement – guidelines and rules for experimentation and procurement emphasizing interoperability, accessibility and auditability; (7) copyright and creative works – rules clarifying attribution, authorship and rights where AI substantially contributes to creative outputs; (8) market and financial integrity – adjustments to market abuse provisions where AI is used to influence markets; and (9) criminal law – introduction of Art. 612‑quater (illicit dissemination of AI‑generated or altered content) and directives to clarify criminal/administrative liability linked to safety omissions.

Implementation Framework

The Act delegates to the Government a program of implementing decrees to define: the lists and thresholds of high‑risk systems appropriate for Italy; detailed procedures for notification and conformity assessment; accreditation criteria for conformity assessors; sanctions and fines scales; procedural rules for inspections; sectoral rules for healthcare platforms and financial services; and funding and incentive schemes for research and SMEs. It requires the Presidency of the Council to publish a biennial national AI strategy and funds targeted initiatives (including experimentation sandboxes and competency programs). AgID and ACN must coordinate issuance of technical guidelines and linee guida, and create joint testbeds for compliance testing. The delegated measures will also specify registration and record‑keeping formats, and the interplay with national cybersecurity obligations and the NIS2 regime.

Monitoring and Evaluation

The law sets monitoring duties: AgID and ACN must produce annual monitoring reports on strategy implementation, market compliance and risks; results are transmitted to Parliament. The statute provides for metrics and monitoring targets (adoption projects, research investments, cybersecurity incidents) and requires the Presidency to evaluate socio‑economic impacts. It mandates sample audits, systematic market surveillance on high‑risk systems and a public register (to be implemented) of certain AI systems placed on the market or put into service. The Act links monitoring outputs to funding, research incentives and updates to the national strategy.

Penalties, Liability, and Appeals

The law establishes a mixed sanctioning regime. Administrative fines, corrective measures (recall, suspension, withdrawal) and public remediation orders will be available for regulatory breaches and are to be quantified in forthcoming delegated decrees. On the criminal side, Art. 612‑quater c.p. criminalises the illicit dissemination of images, video or audio falsified or altered by AI causing unjust damage, punishable with imprisonment (1–5 years) and initiated by complaint or ex officio in specified situations. The Act also mandates legislative clarification on imputability for crimes/administrative offences committed via AI, and contemplates liability for omission or failure to adopt safety measures where such omissions create concrete danger to life, public safety or national security. Affected parties retain administrative and judicial appeal routes; procedural details for sanctions and appeal bodies will be specified in implementing measures.

Relationship to Other Instruments

The statute is explicitly designed to be consistent with and complementary to: Regulation (EU) 2024/1689 (AI Act), GDPR (Regulation (EU) 2016/679), NIS2 and other sectoral EU rules, the Italian Data Protection Code and existing sectoral legislation for health, finance and labour. It modifies or interacts with the Civil Code, the Penal Code, the Testo Unico della Finanza and public procurement rules where necessary. The law also references existing national strategies (Italian AI Strategy and AgID guidance) and creates a path for delegated acts to coordinate domestic regulatory instruments.

International Alignment

While implementing a national approach, Legge n.132/2025 seeks alignment with EU harmonisation under the AI Act and with international standards on AI safety, cybersecurity and human rights. The law designates national contact points (AgID as notification authority and ACN as market surveillance and single contact point to EU institutions) to ensure coordination with EU bodies and cross‑border enforcement. It encourages participation in international testbeds, standards bodies and research cooperation, and foresees adaptation of national lists of high‑risk systems to EU delegated acts and globally recognised standards.

Implementation Timeline

MilestoneDeadline / Date
Publication in Gazzetta Ufficiale2025-09-25
Entry into force (vacatio legis expired)2025-10-10
Biennial National AI Strategy first update dueWithin 24 months of entry into force (by 2027-10-10)
Government delegated decrees (conformity, sanctions, thresholds)Staged; implementing decree schedule set by Law (see articles delegating powers) — expected 2025–2026
Establishment of joint AgID–ACN testbeds and public registerTo be defined in implementing acts; monitoring reports annually

Sources and References

SourceType
Gazzetta Ufficiale — Legge 23 settembre 2025, n. 132 (Atto completo)Primary Source
AgID — Intelligence Artificial pages and guidancePrimary Source (Agency)
Parliamentary dossier and preparatory documents (Camera dei Deputati)Primary Source

Requirements for a company

What an organisation has to do under Italy - National AI Law (132/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

14
  • Do not illicitly disseminate AI-generated or altered content causing unjust damage.Any person.
  • Conduct impact assessments and implement safeguards where AI affects fundamental rights.Providers and deployers of AI systems affecting fundamental rights.
  • Comply with GDPR and specific obligations for datasets used to train AI models deployed in Italy.Providers and deployers of AI systems using training datasets in Italy.
  • Conduct mandatory risk assessment for high-risk AI systems.Providers of high-risk AI systems.
  • Maintain comprehensive documentation for high-risk AI systems.Providers of high-risk AI systems.
  • Perform technical testing for high-risk AI systems.Providers of high-risk AI systems.
  • +8 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Italy - National AI Law (132/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Any person.Do not illicitly disseminate AI-generated or altered content causing unjust damage.
Art. 612‑quater (illicit dissemination of AI‑generated or altered content)
Oct 10, 2025Art. 612‑quaterCritical
2Providers and deployers of AI systems affecting fundamental rights.Conduct impact assessments and implement safeguards where AI affects fundamental rights.
requiring impact assessments and safeguards where AI affects rights
Before placing on marketKey Focus Areas (1)Critical
3Providers and deployers of AI systems using training datasets in Italy.Comply with GDPR and specific obligations for datasets used to train AI models deployed in Italy.
alignment with GDPR and specific obligations for datasets used to train models deployed in Italy
Before placing on marketKey Focus Areas (2)Critical
4Providers of high-risk AI systems.Conduct mandatory risk assessment for high-risk AI systems.
mandatory risk assessment... for high‑risk systems
Before placing on marketKey Focus Areas (3)Critical
5Providers of high-risk AI systems.Maintain comprehensive documentation for high-risk AI systems.
documentation and technical testing for high‑risk systems
Before placing on marketKey Focus Areas (3)Critical
6Providers of high-risk AI systems.Perform technical testing for high-risk AI systems.
technical testing for high‑risk systems
Before placing on marketKey Focus Areas (3)Critical
7Providers and publishers of AI-generated materials.Label AI-generated synthetic content.
obligations to label synthetic content
Before disseminationKey Focus Areas (4)Critical
8Providers and deployers of AI systems.Adopt safety measures to prevent concrete danger to life, public safety, or national security from AI systems.
liability for omission or failure to adopt safety measures where such omissions create concrete danger
Before placing on marketKey Focus Areas (9)Critical
9Providers and operators of AI systems.Comply with national cybersecurity obligations and the NIS2 regime.
interplay with national cybersecurity obligations and the NIS2 regime
Oct 10, 2025Implementation FrameworkCritical
10Deployers of AI systems supporting decision-making.Inform users when AI supports decision-making, especially in healthcare and employment.
inform users when AI supports decision‑making, especially in healthcare and employment
Before putting into serviceKey Focus Areas (4)Important
11Employers deploying AI in the workplace.Inform workers about AI use in the workplace.
require information to workers about AI use
Before deploying AI in the workplaceKey Focus Areas (5)Important
12Employers deploying AI in the workplace.Implement protections limiting AI surveillance and unjustified automated profiling of workers.
protections limiting surveillance and unjustified automated profiling
Before deploying AI in the workplaceKey Focus Areas (5)Important
13Public administration entities procuring AI systems.Emphasize interoperability, accessibility, and auditability in public AI procurement.
emphasizing interoperability, accessibility and auditability
When procuring AI systemsKey Focus Areas (6)Important
14Providers of certain AI systems.Register certain AI systems placed on the Italian market or put into service.
public register (to be implemented) of certain AI systems placed on the market or put into service
To be defined in implementing actsImplementation FrameworkImportant

© Regulations.AI · updated on 13-Jun-2026