Italy AI Regulation Overview

Italy AI Regulation Overview

Italy

RAI-IT-NA-SUMMARY-2026
Governance and OversightData Protection and PrivacyEnforcement and Penalties
Export PDF

Tracked instruments in Italy

8 instruments tracked — 5 In Force, 1 Draft, 1 Adopted, 1 Superseded. Built directly from our records, so — unlike the article below — it cannot go stale.

InstrumentTypeStatusYearEffective
Italy - AI Adoption GuidelinesGuidelineDraft2025—
Italy - AI Regulation (n.132/2025)ActIn Force202510 Oct 2025
Italy - National AI Law (132/2025)ActIn Force202510 Oct 2025
Italy - Digital Transformation PlanPolicyIn Force202412 Feb 2024
Italy - Web Scraping Guidance (329/2024)GuidelineIn Force20247 Jun 2024
Italy - Temporary Order Against ChatGPTRegulationIn Force202311 Apr 2023
Italy - Digital Transformation StrategyPolicyAdopted202115 Mar 2021
Italy - National AI StrategyPolicySuperseded202124 Nov 2021

Italy regulates artificial intelligence through Legge n. 132/2025, aligning national governance with the EU AI Act. Key oversight is shared between AgID, ACN, and the Garante, establishing anthropocentric design principles, sector rules, public administration guidelines, and penal provisions for AI misuse.

Full article

Overview

Italy's regulatory framework for artificial intelligence has evolved into a comprehensive, national statutory system built upon European legal foundations and dedicated national legislation. The primary legislative backbone is Legge 23 September 2025, n.132 (promulgated following parliamentary proceedings under DDL S.1146/C.2316), which entered into force on 10 October 2025. This statute establishes core principles, sectoral requirements, governance mandates, and criminal penalties while operating in explicit conformity with Regulation (EU) 2024/1689 (the EU AI Act).

Complementing primary legislation, Italy's framework features executive policies and institutional guidance across the public sector and data protection domains. Key policy instruments include the Three-Year ICT Plan for the Public Administration (Piano Triennale per l'Informatica nella Pubblica Amministrazione 2024–2026), the National Digital Strategy (Italia Digitale 2026), AgID's draft guidelines on AI adoption in public bodies (Bozza Linee guida PA 2025), and supervisory enforcement decisions by the Data Protection Authority (Garante per la protezione dei dati personali). Together, these measures establish an anthropocentric regulatory approach prioritizing human dignity, fundamental rights, cybersecurity, and national data sovereignty.

Regulatory Approach

Italy combines binding horizontal statutory legislation with sector-specific mandates and soft-law administrative guidance. Legge n.132/2025 codifies fundamental statutory principles—such as human-centricity (anthropocentrism), transparency, non-discrimination, proportionality, and security—while authorizing the Government to adopt implementing decrees (decreti legislativi and decreti ministeriali) for technical execution, thresholds, and administrative procedures.

The national regime mirrors the EU AI Act's risk-based architecture, superimposing additional national requirements for high-risk applications, public administration adoption, and data governance. Public sector deployments face strict operational criteria, including mandatory human oversight for decisions affecting citizens' rights, server localization within national territory for sovereign security, and systematic risk and data protection impact assessments. Additionally, proactive soft-law guidance from AgID and the Garante provides modular toolkits and technical standards for continuous risk management and compliance monitoring.

Key AI Legislation

Italy's AI statutory and regulatory landscape comprises primary statutes, public administration plans, regulatory decisions, and strategic policy frameworks:

  • Legge 23 settembre 2025, n.132 (Disposizioni e deleghe al Governo in materia di intelligenza artificiale): Italy's baseline national statute on AI (originating as DDL n.1146). It sets high-level anthropocentric principles, designates AgID and ACN as primary AI authorities, introduces new criminal offenses (including Art. 612-quater c.p. on illicit deepfake dissemination), mandates server localization for public sector systems, and delegates detailed rule-making to the Government.
  • Piano Triennale per l'Informatica nella Pubblica Amministrazione 2024–2026: National strategic and operational blueprint issued by AgID and the Department for Digital Transformation, establishing operational directives, procurement standards, and risk-based AI tools for public bodies.
  • Bozza Linee guida per l'adozione dell'Intelligenza Artificiale nella Pubblica Amministrazione (2025): Draft AgID guidelines providing lifecycle governance, procurement clauses, model cards, and risk classification flowcharts for public sector deployers.
  • Garante Provvedimento n.114 (11 April 2023) & Provvedimento n.329 (20 May 2024): Enforcement and guidance measures issued by the Data Protection Authority regarding generative AI systems, addressing emergency limitations on ChatGPT, age verification, consent legal bases, and technical countermeasures against unauthorized web scraping for model training.
  • Italia Digitale 2026 & Programma Strategico per l'AI 2022–2024: National strategic policy blueprints embedding AI development into recovery investments (PNRR), digital infrastructure expansion, and national research initiatives.

Governance & Enforcement Bodies

Legge n.132/2025 establishes a multi-layered governance architecture led by the Presidency of the Council of Ministers (structure for innovation and digital transition), which oversees national AI strategy, interministerial direction, and policy coordination. Operational supervision and technical execution are shared between two designated primary national AI authorities: the Agenzia per l'Italia Digitale (AgID) and the Agenzia per la Cybersicurezza Nazionale (ACN).

AgID is tasked with innovation promotion, sandbox environments, notification management, technical standards, and the accreditation of conformity-assessment bodies. ACN serves as the national market surveillance and inspection authority, holding powers over cybersecurity oversight, technical inspections, and compliance enforcement. Specialized sector supervisory authorities—including the Garante per la protezione dei dati personali for data privacy, alongside Banca d'Italia, CONSOB, and IVASS for financial and insurance markets—maintain their existing statutory jurisdiction in conjunction with the primary AI authorities.

Penalties & Enforcement

Enforcement of AI rules in Italy relies on a dual track of statutory criminal offenses and administrative sanction mechanisms. Under Legge n.132/2025, criminal provisions are established for harmful abuses, notably introducing Article 612-quater of the Penal Code (c.p.), which criminalizes the illicit dissemination of AI-generated or altered audio, visual, or audiovisual content (deepfakes) causing unjust damage, punishable by 1 to 5 years of imprisonment. The law further adjusts existing offenses regarding market manipulation, financial misstatements, and corporate crimes when committed through AI technologies.

Administrative enforcement and market surveillance are conducted by ACN, AgID, and sectoral regulators. Under delegated powers, the framework provides for administrative fines, corrective orders, system suspensions, and non-conformity penalties. Furthermore, data processing breaches committed during AI training or deployment remain fully subject to GDPR enforcement mechanisms by the Garante, including corrective orders and administrative fines up to 20 million EUR or 4% of total global annual turnover under GDPR Article 83.

Data Protection Framework

Data protection serves as a foundational pillar of Italy's AI regulatory architecture, governed by the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and the national Data Protection Code (d.lgs. 196/2003 as amended). The Garante per la protezione dei dati personali plays a highly active role in enforcing privacy requirements against AI developers and deployers, demanding explicit legal bases for training data collection, data subject opt-out tools, and mandatory Data Protection Impact Assessments (DPIAs).

National legislation introduces specific data sovereignty and protection constraints. Legge n.132/2025 requires that public sector AI processing systems processing sensitive data be hosted on servers located within national territory to safeguard security and sovereignty. Additionally, Garante Provvedimento n.329 outlines guidance for data controllers to combat unauthorized web scraping for AI model training, recommending technical rate-limiting, CAPTCHAs, API gating, and contractual prohibitions. Special statutory age-consent safeguards also govern minors' interaction with AI platforms.

Sector-Specific Rules

Italian AI regulation establishes dedicated provisions across key public and private sectors. In healthcare, Legge n.132/2025 regulates AI used as clinical decision support, mandating explicit patient information and mandatory human oversight over AI-driven diagnoses or treatment plans. In the public administration, AgID guidelines and the Piano Triennale require formal risk classification, algorithmic transparency, auditability, and human intervention before final decisions affecting citizens' legal rights are executed.

In employment and workplace settings, the law enforces worker transparency rules, limiting automated employee monitoring and prohibiting unfair automated profiling in hiring, performance evaluation, or workplace management. Within financial markets, Legge n.132/2025 updates market abuse regulations and financial disclosure requirements, subjecting AI systems operated by financial institutions to joint oversight by Banca d'Italia, CONSOB, and IVASS. Copyright law is also updated to require clear disclosure of AI assistance in creative works.

International Alignment

Italy's national AI regulatory architecture is directly integrated with European Union legislation and international frameworks. Legge n.132/2025 explicitly mandates that all national provisions and secondary decrees be interpreted and applied in full conformity with Regulation (EU) 2024/1689 (the EU AI Act). The national risk classification, provider-deployer obligations, and conformity assessment schemes align directly with the European harmonized standards.

Furthermore, Italian regulatory bodies actively participate in European and international policy coordination. The Garante participates in the European Data Protection Board (EDPB) task forces on generative AI, while national strategies explicitly incorporate principles from the OECD AI Principles and the EU Digital Decade 2030 objectives. National market surveillance structures under ACN and AgID are structured to interface directly with the European AI Board and EU incident reporting repositories.

Future Developments

The Italian AI regulatory landscape will undergo significant operational expansion through delegated legislative decrees (decreti legislativi) authorized under Legge n.132/2025. Over the 12 months following enactment, the Government is mandated to issue detailed secondary legislation establishing precise sanctioning scales, accreditation criteria for conformity bodies, procedures for market surveillance, and national extensions for high-risk system classifications.

Additional near-term developments include the formalization of AgID's public administration AI guidelines following public consultation, the deployment of regulatory sandboxes and testing environments for SMEs and public bodies, and the publication of updated biennial national AI strategy documents by the Presidency of the Council. Authorities will also finalize technical standards for public sector server localization and age-verification mechanisms for online platforms.

Enforcement Bodies

AgencyMandateKey PowersWebsite
Agenzia per l'Italia Digitale (AgID)Designated national authority for AI promotion, public administration digital transformation, technical standards, notification management, and accreditation of conformity-assessment bodies.Issues technical guidelines, manages notification and accreditation of conformity bodies, monitors PA digital transition, and provides operational toolkits.
Agenzia per la Cybersicurezza Nazionale (ACN)Designated national authority for AI market surveillance, cybersecurity oversight, and national cyber resilience.Conducts market surveillance, technical inspections, cybersecurity audits, and enforces compliance and corrective measures.
Garante per la protezione dei dati personali (Garante)Independent national supervisory authority for data protection and privacy under GDPR and national law.Conducts investigations, issues emergency processing limitations, imposes administrative fines under GDPR, and sets privacy directives for AI training and web scraping.
Presidenza del Consiglio dei Ministri (Dipartimento per la Trasformazione Digitale)Central government body responsible for leading national AI strategy, interministerial policy coordination, and digital transformation goals.Prepares biennial national AI strategy, coordinates interministerial actions, and oversees PNRR digital transformation targets.
Banca d'Italia / CONSOB / IVASSSectoral financial and insurance market supervisory authorities.Supervise AI application within banking, financial markets, and insurance services under sectoral statutes.

Real enforcement actions

13 entries recorded · ~€5.6M in fines

Public enforcement actions where regulators cited Italy AI Regulation Overview. Helps you see how the law is actually applied in practice.

  1. FineJul 9, 2026

    Garante per la protezione dei dati personali vs Character Technologies Inc.

    €158K
    Fine

    The Garante per la protezione dei dati personali fined Character Technologies Inc. €158,000 for data protection violations, including inadequate privacy notices and issues with child protection and age verification in its generative AI service. The authority also ordered further corrective measures.

    Source ↗
  2. FineJul 3, 2026

    Garante per la protezione dei dati personali v Character Technologies, Inc.

    Garante per la protezione dei dati personali

    €158K
    Fine

    On 3 July 2026 the Italian data protection authority fined Character Technologies, Inc. (Character.AI) €158,000 and imposed binding corrective measures (Registro dei provvedimenti n. 487). The procedure, opened on 26 January 2026, found breaches of GDPR Articles 12-14 on transparency (privacy policy available only in English after the Italian launch), Articles 14 and 21 on processing user data for LLM pre-training without adequate disclosure or a workable opt-out, Articles 24-25 on inadequate age-verification measures, Articles 5 and 35 on the late adoption of a data protection impact assessment, and Article 27 on the late designation of an EU representative. Character must implement working age verification, effectively block re-registration by barred minors, make minors' profiles private by default, and report compliance within 120 days.

    Source ↗
  3. InvestigationJun 3, 2026

    Garante per la protezione dei dati personali vs Centro Nazionale Opere Salesiane — Scuola (CNOS-Scuola)

    On 3 June 2026 the Garante privacy sent a request for information to the Centro Nazionale Opere Salesiane — Scuola after learning that Salesian schools had begun a structured trial of generative AI systems involving more than 1,600 teachers and nearly 29,000 students. The Authority gave 20 days to supply the pre-launch assessments, the processing methods for pupils' and staff data, the list of participating institutes, the technology suppliers and any data protection impact assessment, noting the high risks to those involved and the presence of automated decision-making, and recalling that data protection law applies equally to public and private bodies.

    Source ↗
  4. InvestigationMay 14, 2026

    IL GARANTE PER LA PROTEZIONE DEI DATI PERSONALI vs Myndoor S.r.l.

    The Italian Data Protection Authority investigated Myndoor S.r.l.'s AI-powered sentiment analysis plug-in for employee stress evaluation. The investigation concluded that Myndoor acts as the data controller and that the system, after adjustments, processes data pseudonymously or anonymously, providing only aggregated reports to employers under strict conditions.

    Source ↗
  5. Enforcement orderFeb 26, 2026

    Garante per la protezione dei dati personali vs Depac Societa Cooperativa Sociale

    The Garante sanctioned Depac for unlawfully processing employees' biometric data via a facial-recognition system without an adequate legal basis, proper notice or an impact assessment, in breach of the GDPR.

    Source ↗
  6. FineJan 29, 2026

    Garante per la protezione dei dati personali (Garante Privacy) vs eCampus

    Sector: Education

    €50K
    Fine

    The Garante fined eCampus €50,000 for GDPR violations related to its use of a facial recognition system to verify student attendance during online lessons. The authority found issues with invalid consent, lack of a proper legal basis for processing biometric data, and breaches of data protection principles.

    Source ↗
  7. Enforcement orderOct 1, 2025

    Garante per la protezione dei dati personali (Garante Privacy) vs Clothoff app

    Sector: Deepfake App

    The Garante ordered an immediate stop to the Clothoff app, which uses artificial intelligence to 'undress' people in images. The authority cited serious violations of personal data protection principles.

    Source ↗
  8. InvestigationSep 11, 2025

    Garante per la protezione dei dati personali vs SEA - Milan Linate Airport operator

    The Garante opened an information request to airport operator SEA regarding the facial-recognition systems deployed at Milan Linate Airport, scrutinising the lawful basis and safeguards for the biometric processing of passengers.

    Source ↗
  9. Enforcement orderJan 30, 2025

    Garante per la protezione dei dati personali (Garante Privacy) vs Hangzhou DeepSeek Artificial Intelligence, Beijing DeepSeek Artificial Intelligence

    Sector: Generative AI

    The Garante imposed an urgent and immediate definitive limitation on the processing of Italian users' personal data by the companies behind the DeepSeek chatbot service. This action was due to insufficient responses regarding data collection, storage in China, and overall GDPR compliance.

    Source ↗
  10. FineJun 6, 2024

    Garante per la protezione dei dati personali vs Cappello Giovanni & Figli S.r.l.

    €120K
    Fine

    The Garante fined a company EUR 120,000 and banned its X-Face 380 facial-recognition system for employee attendance control, holding there is no legal basis for biometric processing for this purpose and that it breached minimisation and proportionality.

    Source ↗
  11. Service ban / suspensionFeb 2, 2023

    Garante per la protezione dei dati personali vs Luka Inc. (Replika chatbot)

    The Garante imposed an immediate temporary limitation on processing of Italian users' data by the AI chatbot Replika, finding no legal basis and no age-verification mechanism, posing risks to minors and emotionally vulnerable people.

    Source ↗
  12. FineJul 22, 2021

    Garante per la protezione dei dati personali vs Deliveroo Italy S.r.l.

    €2.5M
    Fine

    The Garante fined Deliveroo Italy EUR 2.5 million for unlawfully processing data of about 8,000 riders, citing lack of transparency in the order-assignment and shift-booking algorithms and excessive geolocation monitoring.

    Source ↗
  13. FineJul 5, 2021

    Garante per la protezione dei dati personali vs Foodinho S.r.l. (Glovo)

    €2.6M
    Fine

    The Garante fined Foodinho EUR 2.6 million for unlawful processing of rider data, finding it failed to ensure the accuracy and fairness of the algorithms rating riders and assigning orders, with no safeguards against discriminatory automated decisions.

    Source ↗

© Regulations.AI using Gemini 3.6 Flash · updated on 13 Sep 2026