Our Expert in Italy
No results available
Italy is developing one of Europe’s more consequential national approaches to holding providers, deployers and corporations accountable for artificial intelligence failures. The legal landscape combines directly-applicable EU rules, chiefly Regulation (EU) 2024/1689, the EU Artificial Intelligence Act (the “AI Act”), with Italy’s own legislative initiatives on AI, including Law No. 132 of 23 September 2024 on the National Cybersecurity Agency and, most significantly, the Italian AI law approved by Parliament in 2025 (Law No. 132/2025 on artificial intelligence). For anyone building, deploying, insuring or litigating around high-risk AI in Italy, the practical stakes are immediate. This guide explains the direction of travel, who is exposed, and the concrete steps to take now.
Because AI legislation is evolving rapidly at both EU and national level, readers should verify the precise text and commencement dates of any specific measure with official sources before acting.
Who should read this: companies supplying or using high-risk AI systems in Italy, insurers and brokers, in-house counsel, compliance officers, senior product managers and litigators.
Italy’s AI framework operates across criminal, civil and insurance law simultaneously, drawing on a combination of directly-applicable EU rules and national implementing measures. The principal building blocks that practitioners should understand are:
The national provisions sit directly on top of the EU AI Act (available on EUR-Lex), which supplies the core definitions that Italian law borrows and enforces domestically.
Understanding exposure begins with the actor definitions imported from the EU AI Act. Italian law does not invent a new taxonomy; it enforces the one already familiar to compliance teams operating under EU harmonised rules.
The central scoping concept is the high-risk AI system. The AI Act designates categories of high-risk systems through its annexes, capturing uses such as certain law-enforcement tools, critical-infrastructure management, and safety components of products such as medical devices. The most important compliance question for any Italian business is deceptively simple but analytically demanding: does any AI we build or deploy fall within a high-risk category, and what obligations attach to it?
Because the AI Act is an EU instrument, the exposure is cross-border. A provider established elsewhere in the EU that places a high-risk system on the Italian market, or whose system causes damage in Italy, may find itself facing Italian civil claims and, where individuals are implicated, Italian legal process. Multinationals cannot treat Italian AI compliance as a purely local concern.
Historically, prosecutors seeking to hold individuals accountable for AI-related harm in Italy have had to fit conduct into existing offences, for example negligence, endangerment, or offences concerning the safety of workplaces and products. Italy’s national AI law introduces AI-specific criminal provisions, including offences concerning the unlawful dissemination of AI-generated or manipulated content (such as deepfakes) and aggravating circumstances where AI is used to commit certain crimes. The precise scope, wording and penalties of these provisions should be verified against the consolidated text published on Normattiva.
Where an AI safety failure endangers life or safety, individual criminal exposure may arise under general Criminal Code offences depending on the facts, the mental element (intent or negligence), and the causal link between the conduct and the harm. The practical evidential burden typically centres on documentary evidence of what oversight and security measures were, or were not, in place. Businesses should not assume that AI-related conduct is beyond the reach of existing criminal law simply because a bespoke offence may not squarely apply.
Legislative Decree 231/2001 establishes the administrative liability of entities arising from certain crimes committed in their interest or to their advantage. Where an AI-related offence falls within the 231 catalogue of predicate offences, a company can be sanctioned in its own right, unless it can show it had adopted and effectively implemented an adequate organisational and management model (modello organizzativo) and appointed a supervisory body (organismo di vigilanza).
Sanctions under Decree 231 operate through a quota system, under which the court fixes the number of quotas and then the monetary value of each quota according to the entity’s economic condition, within the ranges set by the applicable provisions. Beyond fines, the 231 framework allows for interdictory or disqualification measures, which can include restrictions on carrying out the activity, suspension of authorisations, and prohibitions on contracting with public administration. For many businesses the reputational and operational impact of a disqualification measure outweighs the fine.
The practical consequence is clear: existing Decree 231 compliance programmes should be reviewed to address AI-related risks and any AI-relevant predicate offences. That means revised risk assessments covering high-risk AI, dedicated protocols for security and human oversight, clear reporting lines, and evidence that the organisational model is genuinely operative rather than a paper exercise. Boards should treat significant developments in AI criminal law as a trigger for a formal review of the entire 231 model, not merely a bolt-on clause.
Civil liability for AI harm is where day-to-day litigation is most likely to arise. Italian civil claims are governed by the Civil Code and product-liability rules, and are increasingly shaped by EU-level developments on AI and product liability. The revised EU Product Liability Directive (Directive (EU) 2024/2853), which member states must transpose into national law, expressly brings software and AI systems within the scope of product liability and introduces evidentiary tools that affect AI claims. The precise Italian transposition and its commencement should be verified with official sources.
A perennial obstacle for victims of AI harm is informational asymmetry: the injured party rarely understands how the system reached the decision or produced the output that caused loss. EU instruments and evolving national rules increasingly empower courts to order disclosure of relevant evidence about how a high-risk AI system functioned, potentially extending to documentation on the system’s design, its operational logic, and relevant logs. To obtain such an order a claimant must generally advance a plausible claim and demonstrate the relevance and proportionality of the material sought.
Any such disclosure power is typically coupled with protective measures. Courts can impose redaction, confidentiality arrangements and protective orders to safeguard trade secrets and confidential information, balancing the claimant’s evidential need against the defendant’s legitimate commercial interests. In practice, litigants should expect early, sharply contested applications over the scope of disclosure and the adequacy of protective conditions.
Proving causation in AI cases is difficult because the technical chain from fault to injury is often opaque. EU product-liability reform introduces rebuttable presumptions designed to ease this burden in defined circumstances, for example where a defendant fails to comply with a disclosure order, or where the technical complexity makes it excessively difficult for the claimant to prove defectiveness or causation. Where such a presumption applies, the defendant may rebut it by adducing sufficient evidence, for example by demonstrating an alternative cause or showing the harm would have occurred regardless.
Consider three illustrative scenarios. In an automated-driving safety failure, a claimant able to point to a relevant breach may benefit from an evidential presumption, prompting the manufacturer to prove the incident arose from an independent cause. In a case involving a police-use identification system, disclosure and presumption mechanisms may assist a claimant otherwise locked out of the system’s inner workings. In a medical-device misdiagnosis, a patient may be assisted where the device provider breached a governance obligation. In each case the burden-shift can be decisive, and contemporaneous evidence of compliance becomes the defendant’s most valuable asset.
Defendants sometimes assume that certification of conformity with the AI Act provides immunity. That assumption is unsafe. Compliance with the AI Act’s harmonised requirements is important evidence in a defendant’s favour, it demonstrates that a provider met the applicable requirements and undertook the required assessments, but it does not, of itself, necessarily exclude civil liability. A system can be compliant on paper and still fail in operation, still be deployed outside its intended purpose, or still cause harm through inadequate oversight in the field. The message for providers and deployers is that documentation must extend beyond the certificate to the entire lifecycle of design, deployment, monitoring and human oversight.
| Issue | Traditional position | Direction of travel under EU/Italian AI rules |
|---|---|---|
| Criminal exposure for lack of oversight | General negligence/endangerment offences | AI-specific offences and aggravations under national AI law, plus continued general offences |
| Corporate liability (Decree 231) | Existing catalogue of predicate offences | Potential extension to AI-related offences; models should be reviewed accordingly |
| Causation in civil claims | Standard civil burden of proof | Rebuttable presumptions in defined circumstances under EU product-liability reform |
| Disclosure of AI functioning | Challenging; protective orders ad hoc | Court-ordered disclosure of relevant evidence, subject to protection of trade secrets |
| Insurance access | Contract and Civil Code rules | Growing emphasis on cover for AI risk; verify sector-specific requirements |
The insurance dimension of AI liability affects both claims handling and underwriting. Italian insurance is supervised by IVASS (Istituto per la Vigilanza sulle Assicurazioni), and general rules on liability insurance, disclosure and, in defined statutory contexts, direct action against insurers are found in the Civil Code and the Insurance Code (Codice delle Assicurazioni Private).
Underwriters and brokers should map whether AI-caused losses fall within general liability, professional indemnity, product liability or cyber wordings, and should address the risk of gaps and overlaps between these lines. Policy wording may need tailored AI liability extensions, clearer definitions of covered AI risks, and exclusions calibrated to the evolving legal landscape.
Direct action against an insurer by an injured party is available in Italian law in specific statutory contexts (for example compulsory motor liability insurance); whether it is available in a given AI dispute depends on the applicable rules and policy. Insurers should nonetheless anticipate earlier involvement in AI disputes, prepare notification flows geared to prompt information requests, reassess reserving assumptions for AI exposures, and consider subrogation strategies across complex AI supply chains. Insurers operating in Italy should also monitor supervisory expectations from IVASS on transparency and claims conduct.
AI liability rewards early, technically literate litigation planning on both sides of a dispute.
Claimants should move quickly to seek disclosure of the system’s operational logic, oversight records and logs before they can be lost or overwritten. Establishing a breach of a specific AI Act or safety obligation is often the key to unlocking evidential presumptions, so pleadings should identify the precise obligation allegedly breached. Expert evidence remains essential, to demonstrate the breach and to counter the defendant’s rebuttal evidence. Early clarity on the defendant’s insurance position helps assess the ability to satisfy any judgment and informs settlement strategy.
Defendants should preserve model artefacts, oversight logs and conformity evidence from the moment a claim is intimated, because these are precisely the materials that rebut presumptions and evidence compliance. Rebuttal will typically rest on documentary proof that required security measures and human oversight were in place, that the system operated within its intended purpose, and that the harm arose from an independent cause. Where disclosure threatens trade secrets, defendants should invoke the available protective measures rather than resist disclosure outright. Cross-border disputes add complexity: evidence located in other jurisdictions, differing forensic standards, and the interaction of Italian procedure with EU cooperation mechanisms all require early coordination between legal and technical teams.
The following consolidated checklist translates the framework into action. Responsibilities and deadlines should be assigned for each item, with board-level sponsorship given the criminal and corporate stakes.
Providers carry the design-stage burden. Priority actions are rigorous documentation of security-by-design and human-oversight features, retention of conformity evidence, secure and auditable logging, and contractual clarity with deployers on responsibilities after the system leaves the provider’s control. Because compliance is not an automatic safe harbour, providers should document the full lifecycle rather than resting on a certificate alone.
Deployers must operate systems within their intended purpose, maintain meaningful human oversight, and keep records of oversight interventions. Where deployment involves personal data, deployers should align AI governance with data-protection obligations, drawing on Garante and EDPB guidance on the interaction between the AI Act and the GDPR.
Insurers and brokers should map coverage for AI-caused losses across product lines, prepare response processes for information requests and potential direct claims, and revisit wordings and reserving for AI exposures.
Italy’s AI liability rules are a national complement to the EU AI Act. The AI Act supplies the harmonised obligations and the definition of high-risk systems; national law adds Italian criminal, corporate and civil consequences for their breach, and Italy has enacted its own national AI legislation. This layering means that a single set of AI Act obligations can generate very different national liability outcomes across the EU. Some member states may rely primarily on civil and administrative mechanisms, while Italy has moved to introduce AI-specific criminal provisions and to apply corporate liability under Decree 231/2001 to relevant offences.
For businesses operating across borders, the practical takeaway is that AI Act compliance is necessary but not sufficient: national liability rules must be assessed jurisdiction by jurisdiction. Divergence in criminalisation and corporate liability is likely to become a live comparative issue. Where AI systems process personal data, controllers should continue to consult EDPB and Garante guidance to ensure GDPR obligations and AI Act obligations are met coherently rather than in isolation. For organisations that need broader support, our Italy data protection lawyers and the Data Protection practice area resources provide further orientation, alongside the In-house vs external DPO in Italy, legal guide.
Italy’s evolving AI liability framework significantly raises the stakes for anyone building, deploying or insuring high-risk AI in the country. With potential criminal exposure, corporate liability through Decree 231, evolving civil rules on disclosure and causation, and growing scrutiny of insurance arrangements, the window for preparation is narrow. The priorities are clear: inventory high-risk systems, document security and oversight, refresh Decree 231 programmes, and review insurance and supply contracts. Because the consequences can reach both individuals and organisations, businesses should not wait for a claim to test the framework.
Where any uncertainty exists about exposure, disclosure obligations or litigation strategy, seek early advice from a data-protection lawyer in Italy and verify the precise text and commencement of any measure against official sources. If you need to prepare for litigation risk, our Hire a litigation lawyer in Italy, checklist is a useful starting point.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Susanna Greggio at GTA Studio Legale, a member of the Global Law Experts network.
posted 19 minutes ago
posted 38 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message