Italy’s implementation status
Law No. 132 (Legge 23 settembre 2025, n. 132) was signed on 23 September 2025 after final Senate approval on 17 September 2025 and entered into force on 10 October 2025. It is national legislation that complements the directly applicable EU AI Act.[1][2][10]
Key characteristics of Law 132/2025
| Characteristic | Detail |
|---|---|
| Complementary framework | Relies entirely on EU AI Act definitions; does not impose obligations beyond the EU framework. |
| Core principles | Establishes transparency, proportionality, security, data protection and non-discrimination as foundational principles. |
| Human autonomy | Preserves human decision-making autonomy as a central tenet across all AI applications. |
| Sector-specific guidance | Detailed provisions for healthcare, employment, public administration and justice. |
| Implementing decrees | Technical standards and detailed guidance due within 12 months, i.e. by 10 October 2026. |
Italy’s approach combines the EU AI Act with GDPR, the NIS2 Directive and existing sector-specific rules. Configured GLACIS paths can add scoped operational evidence about selected control decisions to a wider assurance case; those records do not themselves establish compliance with any of these regimes.[6]
National competent authorities: AgID, ACN, Garante
Article 20 of Law 132/2025 establishes Italy’s governance triangle: AgID notifying authority, ACN market surveillance, and Garante GDPR remit. Sector regulators (Bank of Italy, CONSOB, IVASS) supervise AI in their domains.[3]
| Authority | Role | Detail |
|---|---|---|
| AgID (Agenzia per l’Italia Digitale) | Notifying authority | Promotion of AI development and adoption; notification, assessment and accreditation of conformity-assessment bodies; monitoring accredited notified bodies; national AI standards and guidelines. |
| ACN (Agenzia per la Cybersicurezza Nazionale) | Market surveillance and EU liaison | Market surveillance and inspections; EU single point of contact with the AI Office; enforcement and sanctions; cybersecurity oversight for AI systems. |
| Garante (per la protezione dei dati personali) | GDPR data protection | Retains all GDPR oversight over AI-related personal-data processing. AI processing personal data faces dual compliance: AI Act (ACN) and GDPR (Garante). |
| Bank of Italy | Banking and payment-systems AI | Sector market surveillance for banking AI. |
| CONSOB | Securities and investment AI | Sector market surveillance for capital-markets AI. |
| IVASS | Insurance-sector AI | Sector market surveillance for insurance AI. |
The European Commission’s detailed opinion C(2024)7814 emphasised that national supervising authorities must enjoy full functional and operational independence. Assigning pivotal AI governance to governmental agencies (AgID, ACN) rather than independent administrative authorities has raised institutional-independence questions that may be addressed in the October 2026 implementing decrees.[3]
Implementation timeline and Omnibus framing
Italian organizations track two frameworks: the directly applicable EU AI Act and Law 132/2025 plus its implementing measures. Regulation (EU) 2026/1744 is now in force and sets the current Annex III and Annex I product-embedded high-risk dates.[12]
| Date | Milestone | Notes for Italy |
|---|---|---|
| Aug 2024 | EU AI Act entry into force | Directly applicable across the EU. |
| Feb 2025 | Prohibited practices in force | Article 5 prohibitions apply; check the current ACN and EU authority materials for live enforcement status. |
| Aug 2025 | National authorities designated; GPAI obligations live | AgID and ACN established; the Commission maintains a live GPAI Code signatory register rather than a fixed provider count. |
| 10 Oct 2025 | Law 132/2025 enters into force | First national AI law in the EU. Sector-specific guidance for healthcare, employment, public administration and justice. |
| Jul 2026 | AI Omnibus enters into force | Regulation (EU) 2026/1744 applies from 27 July. |
| Oct 2026 | Italy implementing decrees due | Technical standards and detailed guidance under Law 132/2025. |
| Dec 2027 | Annex III high-risk obligations | Relevant duties apply from 2 December. |
| Aug 2028 | Annex I product-embedded high-risk obligations | Relevant duties apply from 2 August. |
Italy’s implementing decrees are due 10 October 2026. Separately, relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028. Track national measures without treating them as substitutes for EU-level requirements.
Italian national AI strategy
The Strategia Italiana per l’Intelligenza Artificiale 2024–2026 was published by AgID in July 2024, days after the EU AI Act’s publication. A 14-member expert committee developed the strategy as the policy context within which Law 132/2025 operates. It explicitly prioritizes anthropocentric and sustainable AI, aligning with the EU AI Act’s fundamental-rights protections and Italy’s emphasis on human decision-making autonomy.[4]
| Pillar | Detail |
|---|---|
| Research and innovation | €500 million allocated in 2024 for 150 new AI professorships, AI research infrastructure and public-private research collaboration. |
| Public administration | AI adoption for service-delivery efficiency; national pilot projects with scalability focus; streamlined administrative processes. |
| Enterprise support | SME-focused AI adoption programs; financial incentives and training; manufacturing and production optimization. |
| Education and training | AI literacy across educational levels; workforce reskilling; Ministry of Education AI guidelines. |
High-risk AI in Italian markets
Annex III applies uniformly across the EU, but Italy’s economic profile shifts which categories matter most: a manufacturing-led, SME-dominated industrial base; a strong healthcare sector with public-private hybrid delivery; large banks supervised by Bank of Italy, CONSOB and IVASS; and a recognisable fashion and luxury-goods sector.
| Sector | Typical applications |
|---|---|
| Manufacturing and industry | Article 6(1) can apply where AI is a product or safety component covered by Annex I machinery law and the product requires third-party conformity assessment. Annex III point 4 separately lists specified worker recruitment, task-allocation and monitoring uses. Quality control or predictive maintenance is not automatically high-risk from the label alone. |
| Healthcare (sanità) | Law 132/2025 permits AI as a support tool but bars discriminatory use or AI deciding access to treatment. Medical-device AI requires Article 6(1) analysis, including the third-party conformity trigger; emergency healthcare triage may fall within Annex III point 5(d). Diagnostic or treatment-support labels alone do not settle classification. |
| Banking and financial services | Supervised by Bank of Italy, CONSOB and IVASS. Annex III lists natural-person creditworthiness or credit scoring in point 5(b), excluding financial-fraud detection, and life-and-health insurance risk assessment or pricing for natural persons in point 5(c). Loan approval and insurance generally are not standalone categories. |
| Fashion and luxury goods | Specified recruitment, selection, promotion, termination, task-allocation, monitoring and evaluation uses can fall within Annex III point 4. Marketing and design tools require their own Article 50 or other analysis; not all AI-generated content is a deepfake. |
| Public administration (pubblica amministrazione) | Law 132/2025 includes specific provisions. High-risk: AI for benefits eligibility, immigration processing, public-service access; justice-sector AI for case research (under judicial authority oversight). National-security exemption applies to AI for defense and security. |
GLACIS can create signed operational records for selected events and control decisions. They may support review alongside the wider evidence set for Articles 9 to 15, but do not establish ACN or Garante acceptance, complete coverage, control effectiveness or compliance.
Article 12 logging requirements
Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. In Italy, implementation also intersects with GDPR and the Garante’s oversight where logs contain personal data.
| Layer | What must be captured |
|---|---|
| Traceability | Logging capabilities ensure traceability of AI system functioning across the lifecycle. |
| Appropriate level | Logging depth proportionate to the intended purpose of the high-risk system. |
| System-specific events | Events relevant to risk identification and post-market monitoring. Article 12(3)’s specific fields for period of use, reference database, input data leading to a match and human verification apply to covered remote biometric identification systems. |
| Integrity and retention | The Regulation does not generally prescribe cryptography or tamper-evident storage. Apply proportionate integrity controls and determine retention from the applicable provider, deployer and sector rules. |
Italy-specific logging considerations
- GDPR integration: log data containing personal information triggers GDPR. Apply data-minimization; log only what is necessary for traceability.
- Garante prior consultation: conduct a DPIA where GDPR Article 35 applies. Consult the Garante under Article 36 only if the DPIA identifies residual high risk that the controller cannot mitigate; this is not a blanket AI notification requirement.
- Sector retention: banking (Bank of Italy), insurance (IVASS) and healthcare may impose retention windows beyond the AI Act baseline.
- ACN access: as market surveillance authority, ACN may request access to logs during inspections; logs must be available and interpretable.
Sector-specific requirements
Law 132/2025 provides detailed guidance for AI deployment in healthcare, employment and the protection of minors:
| Sector | Requirements under Law 132/2025 |
|---|---|
| Healthcare (sanità) | AI permitted as a support tool for clinical decision-making; AI cannot be used to discriminate or decide access to treatment; human clinicians remain responsible for all final treatment decisions; medical AI devices require CE marking under MDR. |
| Employment (lavoro) | Employers must inform workers about AI systems used in the workplace; appropriate training is required; Article 12 of Law 132/2025 establishes a National Observatory for AI employment-impact monitoring. |
| Minors (minori) | Under 14: parental consent required for AI access and related data processing. Ages 14 to 18: minors may consent if information is easily accessible and comprehensible. Aligns with GDPR Article 8 and Italian data-protection law. |
Garante coordination
The Garante per la protezione dei dati personali retains all authority over personal-data processing underlying AI activities. Under Law 132/2025 the AI Act framework operates alongside GDPR, not as a replacement.[6]
| Area | Detail |
|---|---|
| DPIA and prior consultation | Conduct a DPIA where GDPR Article 35 applies. Prior consultation with the Garante under Article 36 is required only where the DPIA shows residual high risk that the controller cannot mitigate; the authority then has up to eight weeks for written advice, extendable by six weeks for complexity. |
| Research processing | Research does not receive a blanket “no consent” or notification rule merely because AI is involved. Determine the legal basis, special-category-data condition, ethics requirements, safeguards and any Garante procedure for the specific research and institution. |
| GDPR principles | All of these apply to AI data processing: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. |
The AI Act and GDPR can both apply where their separate scope tests are met. The competent authority and potential penalties depend on the operator, system and processing. GDPR Article 22 requires its own analysis for qualifying solely automated decisions with legal or similarly significant effects; “high-risk” under the AI Act is not the trigger.
Conformity assessment pathway
AgID is Italy’s notifying authority, responsible for accrediting conformity-assessment bodies. The pathway depends on the system’s classification:
| Pathway | Detail |
|---|---|
| Internal control (most high-risk) | Provider self-assessment supported by: technical documentation per Annex IV; quality management system; post-market monitoring plan; EU declaration of conformity; CE marking affixation. Cost is internal resourcing. |
| Conditional notified-body involvement | For Annex III point 1 biometric systems, Article 43(1) permits internal control or notified-body assessment when applicable standards are fully used, and requires the Annex VII route in the conditions listed there. Annex I products follow the conformity route under their sector legislation. Timing and fees depend on the system, route, and eligible body. |
Organisations whose Article 43 or sector-law pathway requires third-party assessment should verify the current notifying authority and eligible bodies in official Italian and EU registers. This page does not imply that any named body is designated for the particular system.
Enforcement and penalties
ACN is named as a principal Italian market-surveillance authority, with AgID and sector authorities holding other roles. This page does not claim that a search found every enforcement action; teams should check the current authority registers and sector-specific route. EU AI Act penalties apply on their own terms, while separate GDPR exposure may arise where personal data is involved.
| Violation | Maximum fine | Enforcing authority |
|---|---|---|
| Prohibited AI practices | €35,000,000 or 7% global revenue | ACN |
| High-risk non-compliance | €15,000,000 or 3% global revenue | ACN; sector regulators |
| GPAI model non-compliance | €15,000,000 or 3% global revenue | ACN; EU AI Office |
| Article 50 transparency violations | €15,000,000 or 3% global revenue | ACN; competent sector authority |
| GDPR violations (AI-related) | €20,000,000 or 4% global revenue | Garante |
ACN (AI Act) and Garante (GDPR) penalties can stack. An AI system that processes personal data in violation of both frameworks faces potential fines under each. SME proportionality principles apply, but the ceilings remain substantial.
Compliance roadmap for Italian organizations
The roadmap below should be scheduled against 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Italy’s implementing measures sit alongside, not in place of, the EU requirements.
| Phase | Detail |
|---|---|
| 01. AI inventory and Italian context | Catalogue all AI systems across your Italian operations. Classify each intended use under Article 6 and Annex III. Identify sector overlays and map the relevant authorities. Flag personal-data processing for GDPR analysis rather than assuming notification is required. |
| 02. GDPR integration | For AI processing personal data: verify legal basis, transparency, privacy by design, security and DPIA obligations. Seek Garante prior consultation only where GDPR Article 36 applies, and assess Article 22 for qualifying solely automated decisions. |
| 03. Risk management under Article 9 | Stand up continuous risk management per Article 9. Identify foreseeable risks in the Italian deployment context. Implement mitigation aligned with Italy’s human-centric principles. Integrate with ISO 42001 or NIST AI RMF where relevant. |
| 04. Article 12 logging | Deploy automatic event logging across the lifecycle at a level appropriate to intended purpose. Apply Article 12(3)’s specific fields only where covered remote biometric identification is in scope. Use proportionate access, integrity and retention controls; signed records are an optional integrity measure, not proof of effectiveness or compliance. |
| 05. Conformity and documentation | Prepare Annex IV technical documentation and the applicable Article 17 quality-management system. Determine the internal-control or notified-body pathway and current body availability early; timing depends on classification, product law, scope, and capacity. Prepare the EU declaration of conformity and CE marking where required. |
| 06. Post-market monitoring (Ongoing) | Track performance and incidents. Article 73 serious-incident reporting to ACN within the 15-day deadline. Maintain living documentation. Monitor AgID and ACN announcements for implementing decrees (due October 2026). Coordinate with sector regulators. |
Italy’s implementing decrees are due by 10 October 2026, within 12 months of Law 132/2025 entering force. Build against the EU-level requirements and adapt national procedures as the Italian measures emerge.
FAQ
Who is the national competent authority for the EU AI Act in Italy?
Italy has a triangle: AgID (notifying authority for conformity-assessment-body accreditation); ACN (market surveillance authority and EU single point of contact, responsible for enforcement, inspections and sanctions); and Garante (GDPR oversight for AI-related personal-data processing). Sector regulators (Bank of Italy, CONSOB, IVASS) supervise AI in their respective domains.
Does Law 132/2025 create new compliance obligations beyond the EU AI Act?
No. Law 132/2025 was explicitly designed to complement the EU AI Act without imposing additional obligations. It relies entirely on EU AI Act definitions and provides sector-specific guidance (healthcare, employment, public administration, justice) rather than new requirements. The law’s value is in clarifying how EU requirements apply in the Italian context and establishing the national governance structure.
How does the Garante interact with AI Act enforcement?
The Garante retains its GDPR powers where AI activities process personal data. The AI Act and GDPR can both apply, but they have different scopes and triggers. A DPIA is required where Article 35 applies; prior consultation with the Garante is required under Article 36 only when residual high risk cannot be mitigated. GDPR gives the supervisory authority up to eight weeks to provide written advice, extendable by six weeks for complexity.
When are Italy’s implementing decrees expected?
By 10 October 2026, within 12 months of Law 132/2025 entering force. The decrees address specifics left undefined in the framework law; organizations should continue mapping EU-level requirements directly.
How does Italy support SMEs with AI compliance?
The AI Strategy 2024–2026 prioritizes support for SMEs, which form the backbone of Italian industry. The strategy includes financial incentives, training programs and collaborative research initiatives. Proportionality principles in enforcement provide some relief for smaller organizations, though compliance obligations remain.
Can I use AI for employment decisions in Italy?
Yes, with significant requirements. AI for recruitment, task allocation, performance monitoring, promotion or termination decisions is high-risk under Annex III §4. Law 132/2025 requires employers to inform workers about AI systems and ensure appropriate training. The National Observatory monitors employment impact. Human oversight per Article 14 is mandatory.
References
- Cleary Gottlieb. “Italy Adopts the First National AI Law in Europe Complementing the EU AI Act.” October 2025. clearygottlieb.com
- A&O Shearman. “Law No. 132: Italy’s Leadership in National AI Regulation.” October 2025. aoshearman.com
- Linklaters. “Italy — A Pioneering National Framework to Complement the EU AI Act.” September 2025. linklaters.com
- AgID. “The Italian Strategy for Artificial Intelligence 2024–2026.” July 2024. agid.gov.it
- European Union. “Regulation (EU) 2024/1689.” OJEU, 12 July 2024. EUR-Lex
- Hogan Lovells. “Italy’s AI Law: the Good, the Bad… and the Actual Substance.” October 2025. hoganlovells.com
- Jones Day. “Italy Leads the Way in Shaping National AI Legislation Within the EU.” October 2025. jonesday.com
- White & Case. “AI Watch: Global Regulatory Tracker — Italy.” Updated 2025–2026. whitecase.com
- EU Artificial Intelligence Act. “Overview of All AI Act National Implementation Plans.” Updated 2026. artificialintelligenceact.eu
- IAPP. “Italy Becomes First EU Member State to Pass an AI Law.” October 2025. iapp.org
- European Parliament. “AI Act: deal on simplification measures, ban on nudifier apps.” 27 April 2026. europarl.europa.eu