GLACIS·EU AI Act series·IT Italy·EU timeline checked August 2026

The EU AI Act in Italy: Law 132/2025 and the current high-risk dates.

Italy enacted Law 132/2025, layering AgID, ACN, Garante, and sector regulators on top of the directly applicable EU AI Act. This page gives General Counsel, CCO, CISO, and DPO teams a working view, updated for the AI Omnibus now in force and the current 2027 and 2028 high-risk dates.

Talk to us Read the full EU AI Act guide →
General Counsel CCO CISO DPO
Feb 2025
Prohibited practices in force
Aug 2025
GPAI obligations live; AgID and ACN designated
10 Oct 2025
Law 132/2025 enters into force, the first national AI law in the EU
Oct 2026
Italy implementing decrees due; AI Omnibus dates now enacted
Status reviewed 26 August 2026

Italy’s Law 132/2025 (Legge 23 settembre 2025, n. 132) entered into force on 10 October 2025. It complements the EU AI Act with national provisions for healthcare, employment, public administration, justice, copyright and institutional responsibilities; the two regimes must be analyzed together.[1][2][10]

After the May 2026 provisional agreement, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028.

Italy’s implementing decrees, which will provide technical standards and detailed guidance, are due within 12 months of Law 132/2025 entering force, i.e. by 10 October 2026. That national deadline precedes the December 2027 and August 2028 EU high-risk dates described above; operators should track both the Italian measures and directly applicable EU obligations.

Executive summary

Law 132/2025 (Legge sull’intelligenza artificiale) was passed by the Senate on 17 September 2025, signed on 23 September 2025, and entered into force on 10 October 2025. It relies on EU AI Act definitions while adding national institutional and sector provisions, including healthcare, employment, public administration, justice, copyright, and criminal-law measures. Those provisions require their own analysis.[1][2]

Italy’s governance model is a triangle: AgID (Agenzia per l’Italia Digitale) is the notifying authority responsible for conformity-assessment-body accreditation; ACN (Agenzia per la Cybersicurezza Nazionale) is the market surveillance authority and EU single point of contact; Garante retains all GDPR oversight over AI-related data processing. Sector regulators (Bank of Italy, CONSOB, IVASS) supervise AI in banking, securities and insurance.[3]

The practical position after the Omnibus: classify each system, map it to the applicable 2 December 2027 or 2 August 2028 high-risk date, identify AgID, ACN, Garante, or a sector regulator as applicable, and track Italy’s implementing decrees. Other AI Act provisions retain their own dates.

Italy’s implementation status

Law No. 132 (Legge 23 settembre 2025, n. 132) was signed on 23 September 2025 after final Senate approval on 17 September 2025 and entered into force on 10 October 2025. It is national legislation that complements the directly applicable EU AI Act.[1][2][10]

Key characteristics of Law 132/2025

CharacteristicDetail
Complementary frameworkRelies entirely on EU AI Act definitions; does not impose obligations beyond the EU framework.
Core principlesEstablishes transparency, proportionality, security, data protection and non-discrimination as foundational principles.
Human autonomyPreserves human decision-making autonomy as a central tenet across all AI applications.
Sector-specific guidanceDetailed provisions for healthcare, employment, public administration and justice.
Implementing decreesTechnical standards and detailed guidance due within 12 months, i.e. by 10 October 2026.
Regulatory integration

Italy’s approach combines the EU AI Act with GDPR, the NIS2 Directive and existing sector-specific rules. Configured GLACIS paths can add scoped operational evidence about selected control decisions to a wider assurance case; those records do not themselves establish compliance with any of these regimes.[6]

National competent authorities: AgID, ACN, Garante

Article 20 of Law 132/2025 establishes Italy’s governance triangle: AgID notifying authority, ACN market surveillance, and Garante GDPR remit. Sector regulators (Bank of Italy, CONSOB, IVASS) supervise AI in their domains.[3]

AuthorityRoleDetail
AgID (Agenzia per l’Italia Digitale)Notifying authorityPromotion of AI development and adoption; notification, assessment and accreditation of conformity-assessment bodies; monitoring accredited notified bodies; national AI standards and guidelines.
ACN (Agenzia per la Cybersicurezza Nazionale)Market surveillance and EU liaisonMarket surveillance and inspections; EU single point of contact with the AI Office; enforcement and sanctions; cybersecurity oversight for AI systems.
Garante (per la protezione dei dati personali)GDPR data protectionRetains all GDPR oversight over AI-related personal-data processing. AI processing personal data faces dual compliance: AI Act (ACN) and GDPR (Garante).
Bank of ItalyBanking and payment-systems AISector market surveillance for banking AI.
CONSOBSecurities and investment AISector market surveillance for capital-markets AI.
IVASSInsurance-sector AISector market surveillance for insurance AI.
Independence question

The European Commission’s detailed opinion C(2024)7814 emphasised that national supervising authorities must enjoy full functional and operational independence. Assigning pivotal AI governance to governmental agencies (AgID, ACN) rather than independent administrative authorities has raised institutional-independence questions that may be addressed in the October 2026 implementing decrees.[3]

Implementation timeline and Omnibus framing

Italian organizations track two frameworks: the directly applicable EU AI Act and Law 132/2025 plus its implementing measures. Regulation (EU) 2026/1744 is now in force and sets the current Annex III and Annex I product-embedded high-risk dates.[12]

DateMilestoneNotes for Italy
Aug 2024EU AI Act entry into forceDirectly applicable across the EU.
Feb 2025Prohibited practices in forceArticle 5 prohibitions apply; check the current ACN and EU authority materials for live enforcement status.
Aug 2025National authorities designated; GPAI obligations liveAgID and ACN established; the Commission maintains a live GPAI Code signatory register rather than a fixed provider count.
10 Oct 2025Law 132/2025 enters into forceFirst national AI law in the EU. Sector-specific guidance for healthcare, employment, public administration and justice.
Jul 2026AI Omnibus enters into forceRegulation (EU) 2026/1744 applies from 27 July.
Oct 2026Italy implementing decrees dueTechnical standards and detailed guidance under Law 132/2025.
Dec 2027Annex III high-risk obligationsRelevant duties apply from 2 December.
Aug 2028Annex I product-embedded high-risk obligationsRelevant duties apply from 2 August.
Working baseline

Italy’s implementing decrees are due 10 October 2026. Separately, relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028. Track national measures without treating them as substitutes for EU-level requirements.

Italian national AI strategy

The Strategia Italiana per l’Intelligenza Artificiale 2024–2026 was published by AgID in July 2024, days after the EU AI Act’s publication. A 14-member expert committee developed the strategy as the policy context within which Law 132/2025 operates. It explicitly prioritizes anthropocentric and sustainable AI, aligning with the EU AI Act’s fundamental-rights protections and Italy’s emphasis on human decision-making autonomy.[4]

PillarDetail
Research and innovation€500 million allocated in 2024 for 150 new AI professorships, AI research infrastructure and public-private research collaboration.
Public administrationAI adoption for service-delivery efficiency; national pilot projects with scalability focus; streamlined administrative processes.
Enterprise supportSME-focused AI adoption programs; financial incentives and training; manufacturing and production optimization.
Education and trainingAI literacy across educational levels; workforce reskilling; Ministry of Education AI guidelines.

High-risk AI in Italian markets

Annex III applies uniformly across the EU, but Italy’s economic profile shifts which categories matter most: a manufacturing-led, SME-dominated industrial base; a strong healthcare sector with public-private hybrid delivery; large banks supervised by Bank of Italy, CONSOB and IVASS; and a recognisable fashion and luxury-goods sector.

SectorTypical applications
Manufacturing and industryArticle 6(1) can apply where AI is a product or safety component covered by Annex I machinery law and the product requires third-party conformity assessment. Annex III point 4 separately lists specified worker recruitment, task-allocation and monitoring uses. Quality control or predictive maintenance is not automatically high-risk from the label alone.
Healthcare (sanità)Law 132/2025 permits AI as a support tool but bars discriminatory use or AI deciding access to treatment. Medical-device AI requires Article 6(1) analysis, including the third-party conformity trigger; emergency healthcare triage may fall within Annex III point 5(d). Diagnostic or treatment-support labels alone do not settle classification.
Banking and financial servicesSupervised by Bank of Italy, CONSOB and IVASS. Annex III lists natural-person creditworthiness or credit scoring in point 5(b), excluding financial-fraud detection, and life-and-health insurance risk assessment or pricing for natural persons in point 5(c). Loan approval and insurance generally are not standalone categories.
Fashion and luxury goodsSpecified recruitment, selection, promotion, termination, task-allocation, monitoring and evaluation uses can fall within Annex III point 4. Marketing and design tools require their own Article 50 or other analysis; not all AI-generated content is a deepfake.
Public administration (pubblica amministrazione)Law 132/2025 includes specific provisions. High-risk: AI for benefits eligibility, immigration processing, public-service access; justice-sector AI for case research (under judicial authority oversight). National-security exemption applies to AI for defense and security.
Build the evidence trail

GLACIS can create signed operational records for selected events and control decisions. They may support review alongside the wider evidence set for Articles 9 to 15, but do not establish ACN or Garante acceptance, complete coverage, control effectiveness or compliance.

Talk to us

Article 12 logging requirements

Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. In Italy, implementation also intersects with GDPR and the Garante’s oversight where logs contain personal data.

LayerWhat must be captured
TraceabilityLogging capabilities ensure traceability of AI system functioning across the lifecycle.
Appropriate levelLogging depth proportionate to the intended purpose of the high-risk system.
System-specific eventsEvents relevant to risk identification and post-market monitoring. Article 12(3)’s specific fields for period of use, reference database, input data leading to a match and human verification apply to covered remote biometric identification systems.
Integrity and retentionThe Regulation does not generally prescribe cryptography or tamper-evident storage. Apply proportionate integrity controls and determine retention from the applicable provider, deployer and sector rules.

Italy-specific logging considerations

  • GDPR integration: log data containing personal information triggers GDPR. Apply data-minimization; log only what is necessary for traceability.
  • Garante prior consultation: conduct a DPIA where GDPR Article 35 applies. Consult the Garante under Article 36 only if the DPIA identifies residual high risk that the controller cannot mitigate; this is not a blanket AI notification requirement.
  • Sector retention: banking (Bank of Italy), insurance (IVASS) and healthcare may impose retention windows beyond the AI Act baseline.
  • ACN access: as market surveillance authority, ACN may request access to logs during inspections; logs must be available and interpretable.

Sector-specific requirements

Law 132/2025 provides detailed guidance for AI deployment in healthcare, employment and the protection of minors:

SectorRequirements under Law 132/2025
Healthcare (sanità)AI permitted as a support tool for clinical decision-making; AI cannot be used to discriminate or decide access to treatment; human clinicians remain responsible for all final treatment decisions; medical AI devices require CE marking under MDR.
Employment (lavoro)Employers must inform workers about AI systems used in the workplace; appropriate training is required; Article 12 of Law 132/2025 establishes a National Observatory for AI employment-impact monitoring.
Minors (minori)Under 14: parental consent required for AI access and related data processing. Ages 14 to 18: minors may consent if information is easily accessible and comprehensible. Aligns with GDPR Article 8 and Italian data-protection law.

Garante coordination

The Garante per la protezione dei dati personali retains all authority over personal-data processing underlying AI activities. Under Law 132/2025 the AI Act framework operates alongside GDPR, not as a replacement.[6]

AreaDetail
DPIA and prior consultationConduct a DPIA where GDPR Article 35 applies. Prior consultation with the Garante under Article 36 is required only where the DPIA shows residual high risk that the controller cannot mitigate; the authority then has up to eight weeks for written advice, extendable by six weeks for complexity.
Research processingResearch does not receive a blanket “no consent” or notification rule merely because AI is involved. Determine the legal basis, special-category-data condition, ethics requirements, safeguards and any Garante procedure for the specific research and institution.
GDPR principlesAll of these apply to AI data processing: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.
Dual compliance

The AI Act and GDPR can both apply where their separate scope tests are met. The competent authority and potential penalties depend on the operator, system and processing. GDPR Article 22 requires its own analysis for qualifying solely automated decisions with legal or similarly significant effects; “high-risk” under the AI Act is not the trigger.

Conformity assessment pathway

AgID is Italy’s notifying authority, responsible for accrediting conformity-assessment bodies. The pathway depends on the system’s classification:

PathwayDetail
Internal control (most high-risk)Provider self-assessment supported by: technical documentation per Annex IV; quality management system; post-market monitoring plan; EU declaration of conformity; CE marking affixation. Cost is internal resourcing.
Conditional notified-body involvementFor Annex III point 1 biometric systems, Article 43(1) permits internal control or notified-body assessment when applicable standards are fully used, and requires the Annex VII route in the conditions listed there. Annex I products follow the conformity route under their sector legislation. Timing and fees depend on the system, route, and eligible body.

Organisations whose Article 43 or sector-law pathway requires third-party assessment should verify the current notifying authority and eligible bodies in official Italian and EU registers. This page does not imply that any named body is designated for the particular system.

Enforcement and penalties

ACN is named as a principal Italian market-surveillance authority, with AgID and sector authorities holding other roles. This page does not claim that a search found every enforcement action; teams should check the current authority registers and sector-specific route. EU AI Act penalties apply on their own terms, while separate GDPR exposure may arise where personal data is involved.

ViolationMaximum fineEnforcing authority
Prohibited AI practices€35,000,000 or 7% global revenueACN
High-risk non-compliance€15,000,000 or 3% global revenueACN; sector regulators
GPAI model non-compliance€15,000,000 or 3% global revenueACN; EU AI Office
Article 50 transparency violations€15,000,000 or 3% global revenueACN; competent sector authority
GDPR violations (AI-related)€20,000,000 or 4% global revenueGarante
Stacking penalties

ACN (AI Act) and Garante (GDPR) penalties can stack. An AI system that processes personal data in violation of both frameworks faces potential fines under each. SME proportionality principles apply, but the ceilings remain substantial.

Compliance roadmap for Italian organizations

The roadmap below should be scheduled against 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Italy’s implementing measures sit alongside, not in place of, the EU requirements.

PhaseDetail
01. AI inventory and Italian contextCatalogue all AI systems across your Italian operations. Classify each intended use under Article 6 and Annex III. Identify sector overlays and map the relevant authorities. Flag personal-data processing for GDPR analysis rather than assuming notification is required.
02. GDPR integrationFor AI processing personal data: verify legal basis, transparency, privacy by design, security and DPIA obligations. Seek Garante prior consultation only where GDPR Article 36 applies, and assess Article 22 for qualifying solely automated decisions.
03. Risk management under Article 9Stand up continuous risk management per Article 9. Identify foreseeable risks in the Italian deployment context. Implement mitigation aligned with Italy’s human-centric principles. Integrate with ISO 42001 or NIST AI RMF where relevant.
04. Article 12 loggingDeploy automatic event logging across the lifecycle at a level appropriate to intended purpose. Apply Article 12(3)’s specific fields only where covered remote biometric identification is in scope. Use proportionate access, integrity and retention controls; signed records are an optional integrity measure, not proof of effectiveness or compliance.
05. Conformity and documentationPrepare Annex IV technical documentation and the applicable Article 17 quality-management system. Determine the internal-control or notified-body pathway and current body availability early; timing depends on classification, product law, scope, and capacity. Prepare the EU declaration of conformity and CE marking where required.
06. Post-market monitoring (Ongoing)Track performance and incidents. Article 73 serious-incident reporting to ACN within the 15-day deadline. Maintain living documentation. Monitor AgID and ACN announcements for implementing decrees (due October 2026). Coordinate with sector regulators.
Critical timing insight

Italy’s implementing decrees are due by 10 October 2026, within 12 months of Law 132/2025 entering force. Build against the EU-level requirements and adapt national procedures as the Italian measures emerge.

FAQ

Who is the national competent authority for the EU AI Act in Italy?

Italy has a triangle: AgID (notifying authority for conformity-assessment-body accreditation); ACN (market surveillance authority and EU single point of contact, responsible for enforcement, inspections and sanctions); and Garante (GDPR oversight for AI-related personal-data processing). Sector regulators (Bank of Italy, CONSOB, IVASS) supervise AI in their respective domains.

Does Law 132/2025 create new compliance obligations beyond the EU AI Act?

No. Law 132/2025 was explicitly designed to complement the EU AI Act without imposing additional obligations. It relies entirely on EU AI Act definitions and provides sector-specific guidance (healthcare, employment, public administration, justice) rather than new requirements. The law’s value is in clarifying how EU requirements apply in the Italian context and establishing the national governance structure.

How does the Garante interact with AI Act enforcement?

The Garante retains its GDPR powers where AI activities process personal data. The AI Act and GDPR can both apply, but they have different scopes and triggers. A DPIA is required where Article 35 applies; prior consultation with the Garante is required under Article 36 only when residual high risk cannot be mitigated. GDPR gives the supervisory authority up to eight weeks to provide written advice, extendable by six weeks for complexity.

When are Italy’s implementing decrees expected?

By 10 October 2026, within 12 months of Law 132/2025 entering force. The decrees address specifics left undefined in the framework law; organizations should continue mapping EU-level requirements directly.

How does Italy support SMEs with AI compliance?

The AI Strategy 2024–2026 prioritizes support for SMEs, which form the backbone of Italian industry. The strategy includes financial incentives, training programs and collaborative research initiatives. Proportionality principles in enforcement provide some relief for smaller organizations, though compliance obligations remain.

Can I use AI for employment decisions in Italy?

Yes, with significant requirements. AI for recruitment, task allocation, performance monitoring, promotion or termination decisions is high-risk under Annex III §4. Law 132/2025 requires employers to inform workers about AI systems and ensure appropriate training. The National Observatory monitors employment impact. Human oversight per Article 14 is mandatory.

References

  1. Cleary Gottlieb. “Italy Adopts the First National AI Law in Europe Complementing the EU AI Act.” October 2025. clearygottlieb.com
  2. A&O Shearman. “Law No. 132: Italy’s Leadership in National AI Regulation.” October 2025. aoshearman.com
  3. Linklaters. “Italy — A Pioneering National Framework to Complement the EU AI Act.” September 2025. linklaters.com
  4. AgID. “The Italian Strategy for Artificial Intelligence 2024–2026.” July 2024. agid.gov.it
  5. European Union. “Regulation (EU) 2024/1689.” OJEU, 12 July 2024. EUR-Lex
  6. Hogan Lovells. “Italy’s AI Law: the Good, the Bad… and the Actual Substance.” October 2025. hoganlovells.com
  7. Jones Day. “Italy Leads the Way in Shaping National AI Legislation Within the EU.” October 2025. jonesday.com
  8. White & Case. “AI Watch: Global Regulatory Tracker — Italy.” Updated 2025–2026. whitecase.com
  9. EU Artificial Intelligence Act. “Overview of All AI Act National Implementation Plans.” Updated 2026. artificialintelligenceact.eu
  10. IAPP. “Italy Becomes First EU Member State to Pass an AI Law.” October 2025. iapp.org
  11. European Parliament. “AI Act: deal on simplification measures, ban on nudifier apps.” 27 April 2026. europarl.europa.eu

Make supervision reviewable

EU AI Act evidence from runtime coverage on your highest-risk workflow.

Glacis can preserve signed, scoped records from configured control paths and map fields to selected requirements. Those artifacts do not prove correct execution or compliance. Relevant Annex III high-risk obligations apply from 2 December 2027 under the AI Omnibus now in force.

Talk to us Talk to us

Related guides

Full EU AI Act guideRisk categories, Articles 9 to 15 in detail, GPAI obligations, conformity-assessment paths, Omnibus status.
EU AI Act in SpainAESIA, the December 2025 guidance pack, the regulatory sandbox, draft national AI law.
EU AI Act in GermanyBundestag-adopted KI-MIG, proposed BNetzA and KoKIVO roles, BaFin overlay, and current-status caveat.
ISO 42001 guideAI management system standard.
AI risk assessmentArticle 9 implementation guide.