AI in Italy: new rules introduced on criminal, civil and corporate liability
Published on 18 September 2026
New Italian legislation creates criminal liability for AI failures, extends corporate liability under Legislative Decree 231/2001, and eases the path to civil damages claims
On 15 September 2026, Legislative Decree No. 160/2026 was published in the Official Gazette. The measure constitutes a first set of provisions implementing the delegations granted under Law No. 132/2025 ("Provisions and delegations to the Government on artificial intelligence") and will apply from 30 September 2026.
The decree introduces significant developments in the AI space that will affect businesses and professionals. In particular, new rules are introduced in relation to: (i) criminal liability; (ii) corporate liability under Legislative Decree No. 231/2001; and (iii) civil liability, all in connection with the use of AI systems.
New rules on criminal liability
The decree introduces into the Italian Criminal Code new Article 437-bis, headed "Failure to adopt security measures in artificial intelligence systems and unlawful alteration of systems".
The offences punishable under the new provision are as follows:
- Failure to adopt security measures (paragraph 1): anyone who fails to adopt the technical security measures required for the design, training, production and placing on the market of high-risk AI systems, measures intended to prevent malfunctions or alterations in functioning, or who fails to adopt human oversight measures, where such failure gives rise to a danger to life or to public or individual safety, is punishable by imprisonment from one to five years. The penalty is increased (imprisonment from two to eight years) where the failure gives rise to a danger to state security.
- Unlawful alteration of AI systems (paragraph 2): anyone who alters high-risk AI systems, where the act gives rise to a danger to life or to public or individual safety, is punishable by imprisonment from two to six years. Here too, the penalty is increased (imprisonment from three to ten years) where the act gives rise to a danger to state security.
- Offence specific to professional users (paragraph 4): a professional user of high-risk AI systems who intentionally fails to adopt human oversight measures, where such failure gives rise to a danger to life or to public or individual safety, or to state security, is punishable by the same custodial sentences provided under paragraph 1 above.
The conduct described under paragraph 1 (failure to adopt security measures) is punishable even where committed through gross negligence. The scope of criminal liability therefore extends beyond intentional wrongdoing: those who design, produce or place high-risk AI systems on the market without adequately ensuring security and human oversight are exposed to criminal consequences even in the absence of criminal intent.
New rules on corporate liability
The decree introduces into Legislative Decree No. 231/2001 new Article 25-vicies, extending the administrative liability of corporate entities to offences committed in connection with the use of AI systems.
The new predicate offences are:
- the offence of failure to adopt security measures and unlawful alteration of AI systems (new Article 437-bis of the Criminal Code, as described above), carrying a financial penalty of between 600 and 1,000 units;
- the offence of unlawful dissemination of content generated or altered using AI systems (Article 612-quater of the Criminal Code, commonly referred to as "deepfake"), carrying a financial penalty of between 200 and 700 units.
In both cases, in addition to financial penalties, certain disqualification sanctions may be applied to the entity, including: prohibition from contracting with public authorities, exclusion from grants, financing and contributions, and prohibition from advertising goods or services.
The introduction of new Article 25-vicies requires a review of the organisational and management models adopted pursuant to Legislative Decree No. 231/2001, which will need to include specific protocols for the prevention of the new predicate offences connected with the use of AI systems.
New rules on civil liability
The decree introduces a series of instruments in favour of those who have suffered harm from the use of AI systems, with a significant impact on the procedural balance in damages claims.
Access to evidence: the court's fact-finding powers
In claims for damages (whether contractual or tortious) arising from the use of AI systems, the court may, at the request of the injured party, order the disclosure of evidence relating to the functioning of the system, provided that the applicant has produced elements sufficient to render the claim plausible.
The disclosure order may cover, in particular: log records (Article 12 AI Act), documentation on the risk management system (Article 9 AI Act), technical documentation (Article 11 AI Act), and information on the parameters and methods of human oversight (Article 14 AI Act).
Failure to comply with the disclosure order without justification entitles the court to draw adverse inferences against the non-compliant party. Where the order is directed at a third party, non-compliance without justification results in the imposition of a financial penalty of between €1,500 and €10,000.
Those who develop, produce or deploy AI systems must carefully retain all technical documentation required under the AI Act. In the event of litigation, such documentation may be obtained by the court at the request of the injured party.
Presumption of causation
Where the damage results from a breach of one or more obligations under the AI Act, the causal link between the breach and the damage is presumed, subject to proof to the contrary by the defendant.
Non-compliance with the AI Act carries a significant procedural consequence: the burden falls on the defendant to prove that the damage was not caused by the use of the AI system in breach of the AI Act.
Compliance certification does not exclude liability
Compliance of an AI system with the obligations under the AI Act, even where certified in accordance with the procedures provided for by the AI Act, does not in itself exclude the civil liability of the defendant.
Obtaining a compliance certificate is not sufficient to be shielded from damages claims. The certification may be taken into account by the court in the course of proceedings, but it does not constitute an automatic defence.
Direct action against an insurer
The injured party has a direct right of action for compensation against the insurance company providing liability insurance to the alleged wrongdoer, up to the policy limit.
Before bringing a claim, the injured party may query the alleged wrongdoer as to whether they hold liability insurance: the queried party has 30 days to respond, indicating the details of the policy and the name of the insurer. Failure to respond, or an incomplete response, may be taken into account by the court as evidence against the non-responding party.
The introduction of the direct right of action broadens the injured party's prospects of recovering compensation. For businesses that develop or use AI systems, it is essential to review the adequacy of their liability insurance coverage in light of the new scenarios introduced by the legislation.
Consumer jurisdiction and concurrence with other liability regimes
Where the injured party is a natural person acting for purposes outside their trade or profession, the court of the place of residence or domicile of the injured party also has jurisdiction.
The provisions on compensation under the General Data Protection Regulation (GDPR) and the national implementing measures for Directive (EU) 2024/2853 on liability for defective products remain fully applicable; the injured party may invoke the different regimes cumulatively, where the respective conditions are met.
The alternative jurisdictional rule strengthens the procedural position of the injured consumer. The concurrence with other liability regimes further broadens the options available to those who have suffered harm from AI systems.