[codicts-css-switcher id=”346″]

Global Law Experts Logo
italys ai liability framework

Italy's AI Liability Framework: How the AI Act and National Law Affect Criminal, Civil and Insurance Exposure

By Global Law Experts
– posted 2 hours ago

Italy is developing one of Europe’s more consequential national approaches to holding providers, deployers and corporations accountable for artificial intelligence failures. The legal landscape combines directly-applicable EU rules, chiefly Regulation (EU) 2024/1689, the EU Artificial Intelligence Act (the “AI Act”), with Italy’s own legislative initiatives on AI, including Law No. 132 of 23 September 2024 on the National Cybersecurity Agency and, most significantly, the Italian AI law approved by Parliament in 2025 (Law No. 132/2025 on artificial intelligence). For anyone building, deploying, insuring or litigating around high-risk AI in Italy, the practical stakes are immediate. This guide explains the direction of travel, who is exposed, and the concrete steps to take now.

Because AI legislation is evolving rapidly at both EU and national level, readers should verify the precise text and commencement dates of any specific measure with official sources before acting.

Who should read this: companies supplying or using high-risk AI systems in Italy, insurers and brokers, in-house counsel, compliance officers, senior product managers and litigators.

Statutory snapshot: what Italy’s AI liability landscape involves

Italy’s AI framework operates across criminal, civil and insurance law simultaneously, drawing on a combination of directly-applicable EU rules and national implementing measures. The principal building blocks that practitioners should understand are:

  • The EU AI Act (Regulation (EU) 2024/1689). Directly applicable in Italy, it supplies the definitions of provider, deployer and high-risk AI system, and imposes the harmonised obligations whose breach can trigger national liability. Its provisions apply on a staggered timetable running through 2025 to 2027.
  • Italian national AI law. Italy’s national law on artificial intelligence (Law No. 132/2025), which introduces national principles, sector rules and, in relevant respects, changes to criminal provisions concerning the misuse of AI systems.
  • Legislative Decree No. 231/2001. The Italian regime of administrative liability of entities arising from crimes, which can be engaged where AI-related offences are added to its catalogue of predicate offences.
  • The Italian Civil Code and product-liability rules, which govern civil claims for damage, alongside evolving EU-level proposals on AI and product liability.
  • The GDPR (Regulation (EU) 2016/679) and Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018, which govern personal data processed by AI systems and are enforced by the Garante per la protezione dei dati personali.

The national provisions sit directly on top of the EU AI Act (available on EUR-Lex), which supplies the core definitions that Italian law borrows and enforces domestically.

Who is exposed under Italy’s AI framework

Understanding exposure begins with the actor definitions imported from the EU AI Act. Italian law does not invent a new taxonomy; it enforces the one already familiar to compliance teams operating under EU harmonised rules.

  • Providers. Entities that develop an AI system, or have one developed, and place it on the market or put it into service under their own name or trademark. Providers bear the heaviest design-stage obligations around risk management, security measures and human oversight.
  • Deployers. Entities using an AI system under their authority in a professional context. Deployers are responsible for operating the system within its intended purpose and maintaining oversight in real-world use.
  • Users and operators. Individuals within an organisation who interact with, supervise or intervene in the system’s operation, including designated human overseers whose decisions can become evidentially significant.
  • Public authorities. Bodies deploying AI in sensitive contexts, notably policing and law enforcement, where the AI Act imposes stringent constraints or prohibitions.

The central scoping concept is the high-risk AI system. The AI Act designates categories of high-risk systems through its annexes, capturing uses such as certain law-enforcement tools, critical-infrastructure management, and safety components of products such as medical devices. The most important compliance question for any Italian business is deceptively simple but analytically demanding: does any AI we build or deploy fall within a high-risk category, and what obligations attach to it?

Because the AI Act is an EU instrument, the exposure is cross-border. A provider established elsewhere in the EU that places a high-risk system on the Italian market, or whose system causes damage in Italy, may find itself facing Italian civil claims and, where individuals are implicated, Italian legal process. Multinationals cannot treat Italian AI compliance as a purely local concern.

Criminal exposure for AI-related harm

Historically, prosecutors seeking to hold individuals accountable for AI-related harm in Italy have had to fit conduct into existing offences, for example negligence, endangerment, or offences concerning the safety of workplaces and products. Italy’s national AI law introduces AI-specific criminal provisions, including offences concerning the unlawful dissemination of AI-generated or manipulated content (such as deepfakes) and aggravating circumstances where AI is used to commit certain crimes. The precise scope, wording and penalties of these provisions should be verified against the consolidated text published on Normattiva.

General principles of individual liability

Where an AI safety failure endangers life or safety, individual criminal exposure may arise under general Criminal Code offences depending on the facts, the mental element (intent or negligence), and the causal link between the conduct and the harm. The practical evidential burden typically centres on documentary evidence of what oversight and security measures were, or were not, in place. Businesses should not assume that AI-related conduct is beyond the reach of existing criminal law simply because a bespoke offence may not squarely apply.

Corporate liability under Legislative Decree 231/2001

Legislative Decree 231/2001 establishes the administrative liability of entities arising from certain crimes committed in their interest or to their advantage. Where an AI-related offence falls within the 231 catalogue of predicate offences, a company can be sanctioned in its own right, unless it can show it had adopted and effectively implemented an adequate organisational and management model (modello organizzativo) and appointed a supervisory body (organismo di vigilanza).

Sanctions under Decree 231 operate through a quota system, under which the court fixes the number of quotas and then the monetary value of each quota according to the entity’s economic condition, within the ranges set by the applicable provisions. Beyond fines, the 231 framework allows for interdictory or disqualification measures, which can include restrictions on carrying out the activity, suspension of authorisations, and prohibitions on contracting with public administration. For many businesses the reputational and operational impact of a disqualification measure outweighs the fine.

The practical consequence is clear: existing Decree 231 compliance programmes should be reviewed to address AI-related risks and any AI-relevant predicate offences. That means revised risk assessments covering high-risk AI, dedicated protocols for security and human oversight, clear reporting lines, and evidence that the organisational model is genuinely operative rather than a paper exercise. Boards should treat significant developments in AI criminal law as a trigger for a formal review of the entire 231 model, not merely a bolt-on clause.

Civil liability: disclosure, causation and conformity

Civil liability for AI harm is where day-to-day litigation is most likely to arise. Italian civil claims are governed by the Civil Code and product-liability rules, and are increasingly shaped by EU-level developments on AI and product liability. The revised EU Product Liability Directive (Directive (EU) 2024/2853), which member states must transpose into national law, expressly brings software and AI systems within the scope of product liability and introduces evidentiary tools that affect AI claims. The precise Italian transposition and its commencement should be verified with official sources.

Disclosure of evidence about AI functioning

A perennial obstacle for victims of AI harm is informational asymmetry: the injured party rarely understands how the system reached the decision or produced the output that caused loss. EU instruments and evolving national rules increasingly empower courts to order disclosure of relevant evidence about how a high-risk AI system functioned, potentially extending to documentation on the system’s design, its operational logic, and relevant logs. To obtain such an order a claimant must generally advance a plausible claim and demonstrate the relevance and proportionality of the material sought.

Any such disclosure power is typically coupled with protective measures. Courts can impose redaction, confidentiality arrangements and protective orders to safeguard trade secrets and confidential information, balancing the claimant’s evidential need against the defendant’s legitimate commercial interests. In practice, litigants should expect early, sharply contested applications over the scope of disclosure and the adequacy of protective conditions.

Causation and the shifting evidential landscape

Proving causation in AI cases is difficult because the technical chain from fault to injury is often opaque. EU product-liability reform introduces rebuttable presumptions designed to ease this burden in defined circumstances, for example where a defendant fails to comply with a disclosure order, or where the technical complexity makes it excessively difficult for the claimant to prove defectiveness or causation. Where such a presumption applies, the defendant may rebut it by adducing sufficient evidence, for example by demonstrating an alternative cause or showing the harm would have occurred regardless.

Consider three illustrative scenarios. In an automated-driving safety failure, a claimant able to point to a relevant breach may benefit from an evidential presumption, prompting the manufacturer to prove the incident arose from an independent cause. In a case involving a police-use identification system, disclosure and presumption mechanisms may assist a claimant otherwise locked out of the system’s inner workings. In a medical-device misdiagnosis, a patient may be assisted where the device provider breached a governance obligation. In each case the burden-shift can be decisive, and contemporaneous evidence of compliance becomes the defendant’s most valuable asset.

Conformity is not an automatic safe harbour

Defendants sometimes assume that certification of conformity with the AI Act provides immunity. That assumption is unsafe. Compliance with the AI Act’s harmonised requirements is important evidence in a defendant’s favour, it demonstrates that a provider met the applicable requirements and undertook the required assessments, but it does not, of itself, necessarily exclude civil liability. A system can be compliant on paper and still fail in operation, still be deployed outside its intended purpose, or still cause harm through inadequate oversight in the field. The message for providers and deployers is that documentation must extend beyond the certificate to the entire lifecycle of design, deployment, monitoring and human oversight.

Issue Traditional position Direction of travel under EU/Italian AI rules
Criminal exposure for lack of oversight General negligence/endangerment offences AI-specific offences and aggravations under national AI law, plus continued general offences
Corporate liability (Decree 231) Existing catalogue of predicate offences Potential extension to AI-related offences; models should be reviewed accordingly
Causation in civil claims Standard civil burden of proof Rebuttable presumptions in defined circumstances under EU product-liability reform
Disclosure of AI functioning Challenging; protective orders ad hoc Court-ordered disclosure of relevant evidence, subject to protection of trade secrets
Insurance access Contract and Civil Code rules Growing emphasis on cover for AI risk; verify sector-specific requirements

Insurance considerations for AI risk in Italy

The insurance dimension of AI liability affects both claims handling and underwriting. Italian insurance is supervised by IVASS (Istituto per la Vigilanza sulle Assicurazioni), and general rules on liability insurance, disclosure and, in defined statutory contexts, direct action against insurers are found in the Civil Code and the Insurance Code (Codice delle Assicurazioni Private).

Coverage mapping

Underwriters and brokers should map whether AI-caused losses fall within general liability, professional indemnity, product liability or cyber wordings, and should address the risk of gaps and overlaps between these lines. Policy wording may need tailored AI liability extensions, clearer definitions of covered AI risks, and exclusions calibrated to the evolving legal landscape.

Claims handling and direct action

Direct action against an insurer by an injured party is available in Italian law in specific statutory contexts (for example compulsory motor liability insurance); whether it is available in a given AI dispute depends on the applicable rules and policy. Insurers should nonetheless anticipate earlier involvement in AI disputes, prepare notification flows geared to prompt information requests, reassess reserving assumptions for AI exposures, and consider subrogation strategies across complex AI supply chains. Insurers operating in Italy should also monitor supervisory expectations from IVASS on transparency and claims conduct.

Litigation and evidence strategy

AI liability rewards early, technically literate litigation planning on both sides of a dispute.

Claimant tactics

Claimants should move quickly to seek disclosure of the system’s operational logic, oversight records and logs before they can be lost or overwritten. Establishing a breach of a specific AI Act or safety obligation is often the key to unlocking evidential presumptions, so pleadings should identify the precise obligation allegedly breached. Expert evidence remains essential, to demonstrate the breach and to counter the defendant’s rebuttal evidence. Early clarity on the defendant’s insurance position helps assess the ability to satisfy any judgment and informs settlement strategy.

Defendant tactics

Defendants should preserve model artefacts, oversight logs and conformity evidence from the moment a claim is intimated, because these are precisely the materials that rebut presumptions and evidence compliance. Rebuttal will typically rest on documentary proof that required security measures and human oversight were in place, that the system operated within its intended purpose, and that the harm arose from an independent cause. Where disclosure threatens trade secrets, defendants should invoke the available protective measures rather than resist disclosure outright. Cross-border disputes add complexity: evidence located in other jurisdictions, differing forensic standards, and the interaction of Italian procedure with EU cooperation mechanisms all require early coordination between legal and technical teams.

Compliance and risk-management steps: a 10-point checklist

The following consolidated checklist translates the framework into action. Responsibilities and deadlines should be assigned for each item, with board-level sponsorship given the criminal and corporate stakes.

  1. Map high-risk AI systems. Build an inventory and risk register identifying which systems fall within AI Act high-risk categories.
  2. Document security and oversight. Capture evidence of the technical security measures and human oversight arrangements for each high-risk system.
  3. Review Decree 231 programmes. Reflect AI-related risks in internal protocols, revise risk assessments and confirm the organisational model is operative.
  4. Review supplier contracts. Amend indemnities and provisions on model access, log retention and liability allocation across the AI supply chain.
  5. Reassess insurance. Review liability programmes and seek tailored AI liability cover where gaps exist.
  6. Establish evidence-preservation processes. Implement robust logging standards and retention rules to support both defence and compliance.
  7. Commission independent audits. Deploy red-teaming and third-party assessment of high-risk systems.
  8. Train overseers and staff. Instruct human overseers and operational teams, and retain records of oversight decisions.
  9. Build an incident-response playbook. Integrate legal and technical response for AI failures, including disclosure and notification workflows.
  10. Seek early legal advice. Engage counsel on disclosure requests, criminal exposure and litigation strategy before a dispute crystallises.

For providers and designers

Providers carry the design-stage burden. Priority actions are rigorous documentation of security-by-design and human-oversight features, retention of conformity evidence, secure and auditable logging, and contractual clarity with deployers on responsibilities after the system leaves the provider’s control. Because compliance is not an automatic safe harbour, providers should document the full lifecycle rather than resting on a certificate alone.

For deployers and controllers

Deployers must operate systems within their intended purpose, maintain meaningful human oversight, and keep records of oversight interventions. Where deployment involves personal data, deployers should align AI governance with data-protection obligations, drawing on Garante and EDPB guidance on the interaction between the AI Act and the GDPR.

For insurers and brokers

Insurers and brokers should map coverage for AI-caused losses across product lines, prepare response processes for information requests and potential direct claims, and revisit wordings and reserving for AI exposures.

Cross-border and EU context

Italy’s AI liability rules are a national complement to the EU AI Act. The AI Act supplies the harmonised obligations and the definition of high-risk systems; national law adds Italian criminal, corporate and civil consequences for their breach, and Italy has enacted its own national AI legislation. This layering means that a single set of AI Act obligations can generate very different national liability outcomes across the EU. Some member states may rely primarily on civil and administrative mechanisms, while Italy has moved to introduce AI-specific criminal provisions and to apply corporate liability under Decree 231/2001 to relevant offences.

For businesses operating across borders, the practical takeaway is that AI Act compliance is necessary but not sufficient: national liability rules must be assessed jurisdiction by jurisdiction. Divergence in criminalisation and corporate liability is likely to become a live comparative issue. Where AI systems process personal data, controllers should continue to consult EDPB and Garante guidance to ensure GDPR obligations and AI Act obligations are met coherently rather than in isolation. For organisations that need broader support, our Italy data protection lawyers and the Data Protection practice area resources provide further orientation, alongside the In-house vs external DPO in Italy, legal guide.

Conclusion: immediate next steps

Italy’s evolving AI liability framework significantly raises the stakes for anyone building, deploying or insuring high-risk AI in the country. With potential criminal exposure, corporate liability through Decree 231, evolving civil rules on disclosure and causation, and growing scrutiny of insurance arrangements, the window for preparation is narrow. The priorities are clear: inventory high-risk systems, document security and oversight, refresh Decree 231 programmes, and review insurance and supply contracts. Because the consequences can reach both individuals and organisations, businesses should not wait for a claim to test the framework.

Where any uncertainty exists about exposure, disclosure obligations or litigation strategy, seek early advice from a data-protection lawyer in Italy and verify the precise text and commencement of any measure against official sources. If you need to prepare for litigation risk, our Hire a litigation lawyer in Italy, checklist is a useful starting point.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Susanna Greggio at GTA Studio Legale, a member of the Global Law Experts network.

Sources

  1. Gazzetta Ufficiale della Repubblica Italiana
  2. EUR-Lex, European Union law (AI Act; Product Liability Directive)
  3. Normattiva, Italian consolidated legislation
  4. Garante per la protezione dei dati personali
  5. IVASS, Istituto per la Vigilanza sulle Assicurazioni
  6. Ministero della Giustizia
  7. European Data Protection Board (EDPB)

FAQs

What are the main sources of AI liability law in Italy?
The key sources are the directly-applicable EU AI Act (Regulation (EU) 2024/1689), Italy’s national law on artificial intelligence (Law No. 132/2025), Legislative Decree No. 231/2001 on corporate liability, the Italian Civil Code and product-liability rules (including the transposition of the revised EU Product Liability Directive (EU) 2024/2853), and, for personal data, the GDPR and Legislative Decree No. 196/2003 as amended by Legislative Decree No. 101/2018. Because these rules are evolving, verify the current text and commencement of any specific provision with official sources.
Yes. Depending on the facts, individuals may face liability under existing Criminal Code offences (such as negligence or endangerment) and under AI-specific provisions introduced by Italy’s national AI law. Liability generally requires proof of the relevant mental element and a causal link between the conduct and the harm.
EU product-liability reform introduces rebuttable presumptions to ease the claimant’s burden in defined circumstances, for example where technical complexity makes proof excessively difficult or where a defendant fails to comply with a disclosure order. A defendant can rebut such a presumption with sufficient evidence that the alleged breach did not cause the damage.
Not automatically. Compliance with the AI Act’s requirements is important evidence in a defendant’s favour, but it does not, of itself, necessarily exclude civil liability where the system nonetheless caused harm, for example through operation outside its intended purpose or inadequate oversight in the field.
Direct action against an insurer is available in Italian law in specific statutory contexts (such as compulsory motor liability insurance). Whether it is available in a given AI dispute depends on the applicable rules and the relevant policy, so specific advice should be sought.
Businesses should map their high-risk AI systems, document security and human-oversight measures, review Decree 231 compliance programmes to reflect AI-related risks, and review insurance cover and supply-chain contracts to allocate liability and prepare for potential disclosure requests.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Italy's AI Liability Framework: How the AI Act and National Law Affect Criminal, Civil and Insurance Exposure

Send welcome message

Custom Message