AI & Intellectual Property 2026

Last Updated September 02, 2026

Italy

Law and Practice

Authors



ICT Legal Consulting (ICTLC) is an international law firm providing strategic legal and regulatory support across privacy, data protection, IP and TMT law – with a strong focus on the normative and operational aspects of cybersecurity. The firm assists organisations in designing and implementing governance, compliance and security frameworks that meet the highest international standards. With over 80 professionals and an active network in more than 65 jurisdictions, ICTLC combines global co-ordination with local insight. Through its sister company ICT Cyber Consulting, the firm offers integrated cybersecurity services, including legal/technical risk assessments, resilience planning and alignment with frameworks such as NIS2, DORA and the Cyber Resilience Act. ICTLC’s multidisciplinary expertise enables clients to navigate complex digital regulations and strengthen trust, compliance and resilience across their global operations.

Italy has not adopted a standalone AI-specific IP regime. AI and IP issues are governed by the Italian Copyright Law (Law No 633/1941), the Industrial Property Code (Legislative Decree No 30/2005), the DSM Directive as implemented by Legislative Decree No 177/2021, the AI Act (Regulation (EU) 2024/1689) and, more recently, Law No 132/2025, which represents a first step in the regulation of AI Law No 132/2025 does not create new IP rights for AI but complements the existing framework. In copyright, it confirms that protection extends to AI-assisted works only where they result from human intellectual creation and expressly clarifies that the copyright rules on text and data mining also apply to AI systems. It also introduces criminal sanctions for unlawful text and data mining in breach of Articles 70-ter and 70-quater of the Italian Copyright Law, including where carried out through AI systems.

By contrast, no AI-specific provisions have been introduced for patents, designs or trade marks. AI-assisted inventions therefore remain subject to the ordinary principles of Italian and European patent law, including the requirement that the inventor be a natural person.

Rules on model transparency, copyright-compliance policies and training-data governance derive primarily from the AI Act rather than Italian IP legislation. Accordingly, the current framework largely adapts traditional IP rules to AI technologies instead of creating a separate AI-specific IP regime.

Italy’s AI and IP framework is primarily influenced by EU law and international IP treaties. The Berne Convention, TRIPS Agreement, WIPO Copyright Treaty and WIPO Performances and Phonograms Treaty underpin copyright protection, while AI-related patent issues are influenced by the European Patent Convention (EPC) and the Patent Cooperation Treaty (PCT).

At the EU level, the InfoSoc Directive (Directive 2001/29), Database Directive (Directive 96/9/EC), DSM Directive (Directive 2019/790) and the AI Act provide the main framework for copyright, text and data mining and AI regulation, as implemented in Italy.

Soft-law instruments, such as the OECD AI Principles, UNESCO Recommendation on the Ethics of Artificial Intelligence and WIPO initiatives, may influence policy developments but are not binding. Foreign judgments are not binding on Italian courts, while CJEU case law is binding for EU IP law interpretation.

No special rules apply to foreign rights-holders or AI developers: they generally benefit from the same protection and are subject to the same rules as Italian operators where EU or Italian law applies.

Italian law does not provide specific IP definitions for AI systems, generative AI, foundation models, general-purpose AI models, training data, model weights, prompts or AI-generated outputs. These concepts are primarily addressed through EU law, particularly the AI Act, while their IP treatment remains governed by existing copyright, database, patent, trade-secret and contractual rules.

The AI Act introduces definitions and obligations for certain categories of AI systems, including general-purpose AI models. It does not, however, create new IP rights or modify the substantive scope of copyright or patent protection. The protection of AI-related assets or outputs depends on the requirements of the relevant IP regime.

Autonomous or agentic AI systems are not subject to a separate IP regime. Their ability to plan tasks, select tools, retrieve information, make API calls or generate outputs with limited human intervention does not, by itself, affect the application of existing IP rules. The practical assessment remains focused on issues such as human involvement originality, authorship, ownership, infringement and control over the system.

Where terminology differs between AI regulation and IP law, regulatory classifications do not automatically determine IP protection or liability.

Italian law does not provide for specialised courts or administrative bodies exclusively dedicated to AI-related intellectual property disputes. AI-related IP matters are therefore handled by the same bodies responsible for general IP law.

Civil IP disputes fall within the jurisdiction of the Specialised Business Courts (Sezioni Specializzate in Materia di Impresa), which hear cases concerning copyright, patents, trade marks, designs, trade secrets and related unfair competition claims.

Certain administrative authorities may also have a role where AI intersects with regulated areas. In particular, AGCOM has powers concerning online copyright enforcement, while other authorities, such as the Italian Data Protection Authority, may intervene where AI systems raise data protection issues.

At EU level, the AI Act introduces specific supervisory mechanisms, including oversight by the European Commission and the AI Office for general-purpose AI models, without changing the allocation of jurisdiction for IP disputes.

Italy has not adopted specific procedural rules or examination guidelines for AI-related IP rights. Such issues continue to be assessed under the ordinary rules applicable to the relevant IP right. Current developments mainly concern EU-level initiatives, including the AI Act and related guidance on transparency, documentation and copyright compliance for AI model providers.

Italian law does not recognise a single IP right protecting an AI system as a whole. Protection depends on the nature of each component and the applicable IP regime.

Source code, object code and preparatory design materials may be protected as computer programs under copyright law, which protects the expression of software but not ideas, functionality or algorithms (see CJEU, SAS Institute v World Programming, C-406/10). AI-related inventions may be patentable where they provide a technical solution to a technical problem, while algorithms and mathematical methods remain excluded as such.

Training datasets, fine-tuning materials and evaluation benchmarks may benefit from copyright or, where the requirements are met, sui generis database protection. Documentation, APIs and interfaces may also be protected where they satisfy ordinary originality requirements.

Model architectures, weights, parameters, embeddings, prompts, agent workflows, tool configurations, memory systems and orchestration layers are not subject to a specific IP regime. They are typically protected through trade secrets, confidentiality obligations and contracts, although copyright or patent protection may apply in specific circumstances.

The same principles apply to autonomous or agentic AI systems: their degree of autonomy does not create a separate IP regime and protection remains assessed component by component.

Under Italian Copyright Law (as amended by Law No 132/2025), AI software is protected under the ordinary rules applicable to computer programs and other copyrighted works. Copyright protection extends to AI-assisted works, provided that the AI’s contribution is ancillary and the works reflect a sufficient human creative contribution; purely AI-generated materials are generally not protected.

Computer programs are protected under Article 2(8) of the Italian Copyright Law, implementing Directive 2009/24/EC. Protection may cover source code, object code and preparatory design materials, as well as related documentation, provided that they constitute the author’s own intellectual creation. In the AI context, this may include software implementing the model, interfaces, technical documentation, architecture descriptions, prompt libraries and system instructions, where they reflect original creative choices in their expression or structure.

As discussed in 2.1 Protectable Elements of AI Systems, the position is less certain for model architectures, model weights, parameters and intermediate computational artefacts. Copyright may protect the original expression describing an architecture, but not the underlying technical concept, while weights, parameters and similar computational elements are generally more likely to be protected, if at all, through trade secrets, confidentiality obligations or contractual arrangements.

The main limitation remains the distinction between expression and functionality: copyright protects the expression of software and related materials, but not ideas, algorithms, mathematical concepts, methods of operation or technical functionality. The Court of Justice of the European Union (CJEU) has confirmed this principle.

Under Italian law, AI-related inventions developed by a model creator are assessed under the ordinary patentability requirements applicable to inventions generally. No AI-specific patent regime exists. Patent protection may be available where the invention constitutes a technical solution to a technical problem and satisfies the requirements of novelty, inventive step and industrial applicability.

Consistent with European patent principles, computer programs, algorithms and mathematical methods are not patentable as such. However, machine-learning models, neural networks or AI-based systems may be patent-eligible where their implementation produces a further technical effect or a practical technical application.

Patent applications must disclose the invention sufficiently to enable the skilled person to carry it out. The disclosure requirements do not generally require publication of training datasets or proprietary training methods unless necessary to reproduce the claimed invention. Claim drafting must therefore focus on the technical contribution rather than the AI model or algorithm in the abstract.

The treatment of AI inventions does not differ from ordinary patent protection: the same substantive requirements apply. However, AI-related inventions may raise specific issues concerning technical effect, claim scope and disclosure.

Under Italian law, AI models and related assets may be protected as trade secrets or confidential information under the ordinary rules applicable to undisclosed business information. No AI-specific trade-secret regime exists. The relevant framework is set out in Articles 98 and 99 of the Italian Industrial Property Code, implementing Directive (EU) 2016/943.

Protection requires that information is not generally known or readily accessible, has commercial value because of its secrecy and is subject to reasonable measures to preserve confidentiality. These requirements apply to AI-related assets in the same way as to traditional know-how.

Depending on the circumstances, protected assets may include model weights and parameters, proprietary datasets, fine-tuning methods, system instructions, deployment configurations, agent workflows, tool permissions, memory stores and operational know-how. Typical safeguards include confidentiality obligations, access restrictions, encryption, secure storage, logging, internal policies and governance measures.

Transparency, audit and regulatory obligations may create practical tensions but do not generally eliminate trade-secret protection. The AI Act recognises the need to protect confidential information and does not require public disclosure of proprietary models, datasets or deployment know-how. Disclosure may therefore be limited to regulators or authorised parties where required.

Under Italian law, AI datasets and related assets are not subject to a specific protection regime. They are protected, where applicable, under the ordinary rules governing copyright, database rights, trade secrets, contracts and, in some cases, unfair competition. The framework does not differ from that applying to databases generally.

Copyright may protect datasets, corpora, annotation frameworks and similar collections where their selection or arrangement reflects the author’s own intellectual creation, but not the underlying data or information. AI datasets may also qualify for the sui generis database right under Articles 102-bis and 102-ter of the Italian Copyright Law, which requires substantial investment in obtaining, verifying or presenting the contents, rather than originality. Consistently with CJEU case law, investment in creating data is not sufficient.

Datasets, benchmarks, annotations, labels, embeddings and synthetic datasets may therefore benefit from overlapping protection, including confidentiality and contractual restrictions. Licence terms, access controls and no-training clauses are commonly used to regulate their use.

Italian law provides a framework of partial legal certainty regarding the use of copyright-protected works for AI development. The applicable regime is primarily based on the implementation of the DSM Directive into the Italian Copyright Law, through Articles 70-ter and 70-quater, recently complemented by Article 70-septies introduced by Law No 132/2025. As discussed in 3.2 Text and Data Mining and Other Exceptions, activities such as copying, scraping, downloading, ingesting or tokenising protected works may constitute acts of reproduction or extraction falling within the exclusive rights of copyright holders. Their lawfulness therefore depends on whether they are authorised by licence or fall within the statutory text and data mining (TDM) exceptions.

There is a reasonable degree of legal certainty that analytical uses carried out during the development and evaluation of AI systems (including training, fine-tuning, benchmarking and safety testing) may benefit from the TDM regime, provided that its statutory conditions are satisfied. Article 70-septies confirms that these provisions also apply where such activities are carried out through AI systems.

However, significant uncertainties remain. The principal unresolved issue is whether the training of foundation models and large language models falls entirely within the scope of the TDM exceptions. Likewise, the legality of web scraping depends on lawful access to the relevant content and compliance with any effective reservation of rights, while the application of the TDM regime to proprietary datasets, licensed databases and contractually restricted materials continues to raise practical questions.

Further uncertainty surrounds retrieval-augmented generation (RAG), agentic retrieval and tool-mediated access. Italian law does not provide AI-specific rules for these techniques. Instead, their legality is evaluated under standard copyright principles, taking into account the particular acts of reproduction, extraction, public communication or database use carried out by the system.

Most of these issues are expected to be clarified through judicial interpretation rather than further legislative reform. In particular, the pending reference before the Court of Justice of the European Union in Case C-250/25, concerning the relationship between large language model training and the DSM text and data mining regime, is expected to provide important guidance. Given that the Italian provisions directly implement the DSM Directive, the CJEU’s interpretation will be decisive for the future application of Italian copyright law to AI training activities.

Italy does not recognise a general fair use doctrine. AI training and development are therefore assessed under the specific exceptions provided by the Italian Copyright Law, principally those implementing the DSM Directive.

The main exceptions are the TDM exceptions under Articles 70-ter and 70-quater, as clarified by Article 70-septies, which expressly confirms that reproductions and extractions carried out through AI systems, including generative AI, remain subject to those provisions. Other exceptions (eg, temporary copying, research, education, quotation and uses by cultural heritage institutions) may apply in specific circumstances but generally play a complementary role.

The key distinction is between research and commercial uses. Article 70-ter permits TDM by research organisations and cultural heritage institutions with lawful access to the relevant materials. Article 70-quater also applies to commercial AI development, provided that the developer has lawful access and the rightsholder has not reserved its rights through the DSM Directive opt-out mechanism.

Accordingly, the principal area of legal certainty is that AI-related analytical activities may benefit from the TDM exceptions where their statutory conditions are met. By contrast, significant uncertainty remains as to their application to the training of foundation models and large language models, as well as to issues such as web scraping, the interaction between contractual restrictions and the TDM regime and the legal effect of technical opt-out mechanisms.

No Italian court has yet resolved these issues. However, the pending proceedings before the Court of Rome (RTI S.p.A. and Medusa Film S.p.A. v Perplexity AI) and the cited case pending before the CJEU in Case C-250/25 are expected to provide important guidance on the scope of the TDM exceptions in the context of AI training.

Italy has no specific licensing regime for AI training. In practice, developers rely on a combination of voluntary licences, existing contractual arrangements, open-content licences and, where the applicable conditions are met, the TDM exceptions implemented under the DSM Directive (see 3.2 Text and Data Mining and Other Exceptions). The choice between licensing and reliance on the statutory exceptions depends on the nature of the content and the intended use.

Voluntary licensing remains the prevailing commercial model. AI developers increasingly enter into direct agreements with publishers, content providers and other rightsholders, while remuneration, attribution and permitted AI uses are generally determined by contract.

Open-source and Creative Commons licensed content also play an important role, subject to the applicable licence terms.

Italy does not currently provide a collective or extended collective licensing regime, compulsory licensing scheme or statutory remuneration mechanism specifically for AI training. Although the orphan works and out-of-commerce works regimes exist under EU and Italian copyright law, they are not designed to facilitate commercial AI training. Likewise, data trusts have not yet developed into a significant mechanism for licensing training content in the Italian market.

Under Italian law, rights reservations and opt-outs are recognised under Article 4 of the DSM Directive. Accordingly, commercial TDM may be carried out only where rights holders have not expressly reserved their rights. Following the introduction of Article 70-septies of the Italian Copyright Law by Law No 132/2025, this framework also applies to AI systems relying on the commercial TDM exception.

Italian law does not prescribe a specific format for rights reservations. Opt-outs may therefore be expressed through contractual terms, website notices, metadata or other machine-readable means. However, no uniform technical standard currently determines how such notices must be implemented or recognised. Their effectiveness therefore depends on industry practices and emerging European standards on rights management information and content credentials.

Licensing registers and similar rights-management tools may support ownership verification and rights clearance but do not have an autonomous legal effect under Italian Copyright Law; their relevance derives from the underlying rights and contractual arrangements.

Italian law does not specifically regulate cases where AI agents autonomously browse, retrieve content or use external tools. The use of autonomous systems does not change the applicable copyright rules. Where a valid opt-out exists, an AI developer may not rely on the TDM exception merely because an agent failed to detect or comply with the reservation. Compliance will likely depend on adopting appropriate technical and organisational measures.

Uncertainty remains regarding the technical standards for machine-readable notices and how responsibility is allocated when AI systems fail to recognise them.

Italian law does not impose a general obligation to document every stage of AI model development. Documentation requirements derive primarily from the AI Act, together with Italian Copyright Law, data protection legislation and general accountability principles.

In practice, developers are expected to maintain records demonstrating the lawful origin of training data, compliance with rights reservations and opt-outs, dataset governance and, where relevant, filtering and removal procedures. Although Italian law does not specifically regulate documentation relating to deduplication or synthetic data, maintaining appropriate records is regarded as an important compliance measure.

For agentic AI systems, no AI-specific rules require retaining logs relating to tool calls, browsing activities, API access, retrieval or autonomous actions. Nevertheless, maintaining adequate audit trails is increasingly considered good governance practice, particularly for allocating responsibility where autonomous systems interact with third-party content. Further practical considerations on agentic AI governance are discussed in the Trends & Developments chapter.

Italian law also contains no AI-specific conflict-of-law rules for distributed AI development. Where datasets, servers, developers or users are located in different jurisdictions, questions concerning the place of copying or infringement are determined under the ordinary rules of private international law and the applicable EU framework, taking into account where the relevant infringing acts occurred.

Italian law does not provide an AI-specific test for direct IP infringement. Accordingly, liability is assessed under the ordinary rules governing the relevant IP right, considering the acts performed during the training, fine-tuning, evaluation, deployment or operation of the AI system.

In copyright cases, the claimant must establish ownership (or entitlement to enforce the relevant rights), identify the protected work or other subject matter and prove that the defendant carried out one or more acts falling within the exclusive rights conferred by the Italian Copyright Law, such as reproduction, adaptation, extraction, communication to the public or other restricted acts. Where the alleged infringement concerns AI training, the claimant must generally show that protected content was copied, ingested or otherwise used without authorisation and that no statutory exception (including the text and data mining exceptions) or licence applies.

The fact that the relevant acts are performed automatically by an AI model, autonomous agent or tool-using system does not, in itself, preclude liability. The assessment remains focused on the conduct of the developer or provider responsible for the design, deployment or operation of the system, applying the ordinary principles of causation and attribution.

In practice, the principal evidential challenge is demonstrating that protected works were actually used during model development, particularly where training datasets are not publicly disclosed. In this respect, the transparency obligations introduced by the AI Act may facilitate access to relevant evidence but do not alter the substantive conditions for establishing infringement.

No Italian judgment has yet resolved these issues. However, the pending proceeding cited at 3.2 Text and Data Mining and Other Exceptions is expected to provide important guidance on AI training, the application of the TDM exceptions and the evidential burden in AI-related copyright disputes.

Italian law does not specifically regulate the legal status of model weights, parameters, embeddings, caches or other internal model artefacts. Their treatment is therefore assessed under the ordinary rules governing copyright and database rights.

Whether such elements constitute infringing copies or extracted parts of protected works depends on whether they embody or reproduce protectable expression or, in the case of databases, a substantial part of protected contents.

Italian law does not currently provide a specific legal qualification for internal model representations.

Likewise, Italian courts have not yet addressed the legal significance of memorisation or “regurgitation” by AI systems. Where an AI output reproduces protected expression or a substantial part of a protected database ordinary infringement principles are likely to apply. By contrast, whether internal memorisation alone, without an infringing output, constitutes infringement remains unresolved.

To date, neither Italian courts nor the CJEU have established specific tests for model weights, memorisation, regurgitation, substantial similarity or de minimis copying in the AI context. These issues remain among the main areas of legal uncertainty, pending future judicial guidance.

Italian law does not provide a specific regime governing secondary liability of AI model providers for IP infringements committed by users, downstream deployers or autonomous AI agents. Liability is therefore assessed under the ordinary rules of the relevant IP right and general principles of civil liability.

A model provider is not liable merely because its model can generate infringing outputs. Liability depends on the provider’s own conduct, including whether it authorised, induced, knowingly facilitated or materially contributed to the infringing activity and on the degree of control retained over the system or its use. The same principles apply where the allegedly infringing acts are performed automatically by downstream applications, autonomous agents or tool-using systems.

The allocation of responsibility may also be influenced by the respective roles of providers, deployers and users under the AI Act. Although the AI Act does not harmonise IP liability, its governance, transparency and compliance obligations may be relevant when assessing each actor’s conduct.

Safe-harbour protections remain limited. The Digital Services Act applies only to qualifying intermediary services and does not provide a general exemption for AI model providers. Likewise, the Intellectual Property Enforcement Directive (Directive 2004/48) harmonises enforcement mechanisms but does not establish AI-specific rules on secondary liability.

No Italian court has yet defined the circumstances in which an AI model provider may incur indirect liability for IP infringements committed by users or autonomous systems. Accordingly, the allocation of responsibility remains highly fact-specific and will depend on the provider’s knowledge, degree of control, contractual arrangements and role in the infringing activity.

Italian law does not provide a specific regime governing the use of trade secrets or confidential information in AI systems. Claims arising from the use of confidential materials for training, fine-tuning, prompting, retrieval, memory, tool use or evaluation are therefore assessed under the ordinary rules on trade secrets, contractual confidentiality and civil liability.

Where information qualifies as a trade secret under Articles 98 and 99 of the Italian Industrial Property Code, liability may arise from its unlawful acquisition, use or disclosure, including through incorporation into training datasets or retrieval systems. Contractual claims may also arise where AI systems are used in breach of confidentiality obligations, NDAs or access restrictions.

Risks also arise where a model reproduces, infers or reveals confidential information, including through agentic retrieval or tool calls. Liability will depend on the source of the information, applicable obligations, attribution of the disclosure and the governance measures adopted by the relevant actors.

No Italian court has yet specifically addressed trade secret misappropriation or confidentiality breaches in the AI context. These issues are therefore expected to be resolved by applying existing principles, informed by emerging AI governance obligations.

As discussed in 3.2 Text and Data Mining and Other Exceptions, Italian law does not recognise a general fair use doctrine. AI developers and model providers must therefore rely on the ordinary defences available under Italian and EU IP law.

The principal copyright defence is compliance with the statutory TDM exceptions under Articles 70-ter and 70-quater of the Italian Copyright Law, provided their conditions are satisfied. Defendants may also rely on licences (including open-content licences), implied authorisation, public-domain status or the absence of protectable subject matter. Other substantive defences include the lack of reproduction of protected expression or of a substantial part of a database, as well as independent creation.

Procedural defences include limitation periods, lack of standing, failure to establish ownership or infringement and, where appropriate, abuse of rights. Competition law arguments may also arise in exceptional cases.

As noted in 4.3 Secondary, Authorisation and Intermediary Liability, EU safe harbour regimes apply only to qualifying intermediary service providers and do not provide a general exemption for AI model providers. Likewise, the AI Act does not introduce new IP defences but operates alongside the existing copyright and industrial property framework. To date, Italian courts have not recognised AI-specific defences beyond the ordinary principles of IP law.

Italian law does not provide a specific infringement test for AI-generated outputs. Copyright infringement is therefore assessed under the ordinary principles of the Italian Copyright Law and EU copyright law, focusing on whether the output reproduces all or a substantial and recognisable part of the protected expression of a pre-existing work.

Outputs that are substantially similar to training works may infringe copyright where they reproduce protected expressive elements rather than unprotected ideas, facts or styles. Likewise, outputs generated from prompts or reference images may be infringing if they reproduce protected expression contained in those inputs without authorisation.

By contrast, the imitation of an artistic style, genre, voice or creative technique does not, in itself, constitute copyright infringement, since Italian Copyright Law protects the expression of a work rather than an author’s style. However, depending on the circumstances, such conduct may raise issues under unfair competition, trade mark, personality or related rights, particularly where it creates confusion, exploits another person’s reputation or reproduces protected performances or sound recordings.

To date, no Italian court has established AI-specific criteria for assessing copyright infringement by AI-generated outputs and applying traditional copyright principles to generative AI remains an evolving area of law.

Italian law does not provide a specific liability regime for AI users or deployers. Liability is therefore assessed under the ordinary rules applicable to the relevant IP right. The absence of intent does not, by itself, exclude liability where AI-generated content infringes third-party rights.

Liability depends on the user’s or deployer’s conduct, including the nature of the prompts, the publication or commercialisation of outputs, the level of human review and the foreseeability of infringement. Incidental similarities remain subject to a case-by-case assessment under ordinary copyright principles.

The same approach applies to agentic AI systems: autonomous execution does not automatically remove responsibility from those configuring, deploying or controlling the system. Liability will depend on factors such as human oversight, foreseeability and safeguards implemented.

Provider terms may allocate contractual risk but do not exclude liability towards third-party right holders. AI Act governance requirements may be relevant in assessing the adoption of reasonable safeguards, but they do not harmonise IP liability.

Italian law does not provide AI-specific rules on trade marks or unfair competition. AI-generated content is therefore assessed under the ordinary rules of the Italian Industrial Property Code, EU trade mark law and the general principles on unfair competition.

AI outputs incorporating third-party trade marks, logos or other distinctive signs may infringe trade mark rights where they are used in the course of trade and create a likelihood of confusion, suggest a commercial connection with the rights holder or, in the case of reputed marks, take unfair advantage of or dilute their distinctive character or reputation.

The same principles apply to AI-generated content reproducing product get-up, packaging, brand identity or other distinctive commercial features, which may also give rise to design or unfair competition claims where the relevant legal requirements are met.

The unauthorised commercial use of names, images, voices or other celebrity indicia may also engage trade mark protection, personality rights or unfair competition rules, particularly where it falsely suggests endorsement or commercial association.

The AI Act’s transparency obligations do not alter the substantive assessment of trade mark infringement or unfair competition, which remains governed by the ordinary principles of Italian and EU law.

Italian law does not provide an AI-specific regime for technical IP infringement. AI-generated product designs, software code, technical documentation, manufacturing parameters, chemical or biological candidates and processes are therefore assessed under the ordinary rules governing patents, designs, copyright and trade secrets.

Infringement risks may arise both from using protected third-party materials as inputs and from exploiting AI-generated outputs. Where an output reproduces protected software code or designs or implements a product or process falling within the scope of a third party’s patent claims ordinary infringement principles apply.

The use of AI does not alter the legal assessment. Direct infringement may arise where protected subject matter is made, used, offered, marketed or otherwise exploited without the rights holder’s authorisation. Indirect infringement may also arise where AI-generated instructions, components or technical information knowingly facilitate the implementation of a patented invention by third parties, subject to the conditions laid down by the Italian Industrial Property Code.

To date, no Italian legislation or case law establishes AI-specific criteria for assessing infringement of technical IP rights. The ordinary principles of Italian and EU IP law therefore continue to apply.

Italian law does not establish a specific liability regime for autonomous AI systems or AI agents. Liability is therefore assessed under the ordinary rules governing the relevant IP right, regardless of whether a person performs the infringing act directly or an AI system performs it autonomously.

Where an AI system scrapes or retrieves third-party content, accesses software tools or APIs, generates code or other protected material, publishes outputs or makes autonomous product or design choices, the key question remains whether the underlying conduct infringes copyright, patent, trade mark, design, trade secret or other IP rights and to whom that conduct is legally attributable.

In practice, liability will depend on factors such as the degree of human control, the system’s configuration, the foreseeability of the infringing conduct and the governance measures implemented by the provider or deployer. The risk increases where an AI agent is intentionally configured to access, reproduce or publish protected content without authorisation.

Although the AI Act does not harmonise IP liability, its governance, monitoring and human oversight obligations reinforce the expectation that providers and deployers implement appropriate safeguards, particularly where AI agents autonomously retrieve, process or publish third-party content. For further considerations on agentic AI governance, see the Trends & Developments chapter.

Article 1 of the Italian Copyright Act, as amended by Law No 132/2025 (see 2.2 Copyright in Software and Model-Related Materials), confirms that works created with the assistance of AI may benefit from copyright protection where they result from the author’s intellectual creation. AI assistance does not exclude protection, but copyright depends on a sufficient human creative contribution.

In the absence of consolidated case law, the assessment remains case-specific under ordinary copyright principles. Given the low originality threshold, protection does not require absolute novelty or artistic merit, but the work must reflect free and creative choices attributable to a human author.

A mere prompt or generic instruction is unlikely to be sufficient. Human authorship may arise from iterative prompt development, selection and arrangement of outputs, substantive editing, the use and transformation of reference materials or the integration of AI-generated elements with original content, where these choices reflect the author’s creative expression.

The same applies to agentic AI systems. Prompt chaining, prompt decomposition, meta-prompting, autonomous planning or automated selection of intermediate outputs do not automatically prevent protection, but increasing system autonomy makes it more important to demonstrate retained human creative control over the conception, direction and final selection of the work.

AI-generated works receive no copyright protection in the absence of human intellectual work. AI’s contribution must be secondary to the creative effort of the human mind (see 6.1 Human Authorship and Copyright Protection). No separate sui generis right currently exists for AI-generated creative works.

Italian law contains no AI-specific rules on joint authorship, derivative works or adaptations. Accordingly, these issues are governed by the ordinary principles of the Italian Copyright Law, interpreted in light of EU copyright law.

Joint authorship arises only where two or more natural persons each make an original creative contribution to the final work. Co-authors generally own the copyright jointly, while ownership shares and exploitation rights are determined by agreement or, failing that, by the applicable statutory rules. In the context of AI-assisted creation, whether prompt engineering, editing, selection or other human interventions are sufficient to establish co-authorship must be assessed on a case-by-case basis, depending on whether they reflect the author’s own intellectual creation.

Likewise, where an AI output constitutes a recognisable adaptation or transformation of a protected work, the authorisation of the relevant rightsholder will generally be required unless a statutory exception applies. Whether AI-generated content infringes third-party rights depends on the extent to which it reproduces protected expressive elements rather than merely drawing inspiration from existing works. Given the absence of AI-specific rules or case law, contractual allocation of rights remains particularly important where multiple contributors or AI tools are involved.

Italian law does not impose a general obligation to disclose the use of AI when applying for or enforcing IP rights. Any disclosure requirements depend on the ordinary rules governing the relevant IP right.

In copyright, no registration system exists. Where authorship is disputed, however, the claimant may need to demonstrate a sufficient human creative contribution for copyright protection to subsist (see 2.2 Copyright in Software and Model-Related Materials).

Likewise, Italian and EU trade mark and design law do not require applicants to disclose AI involvement. Protection is assessed under the ordinary substantive requirements, regardless of the tools used.

In patent law, the inventor designated in the application must be a natural person (see 2.3 Patent Protection for AI Technologies). Applicants must also comply with the ordinary disclosure requirements, including providing a sufficiently clear and complete description of the invention (which may require explaining the use of AI to enable a person skilled in the art to reproduce the invention).

Separate transparency obligations may arise under the AI Act.

Italian law does not permit an AI system to be designated as an inventor or co-inventor. Consistently with the EPC and the case law of the European Patent Office (EPO), inventorship may be attributed only to a natural person. AI is therefore regarded as a tool assisting the inventive process rather than as a legal subject capable of generating patent rights.

Accordingly, the use of AI does not preclude patent protection, provided that the claimed invention remains attributable to human inventive activity. Although no specific statutory threshold exists for AI-assisted inventions, a human contribution is required to identify the technical problem, direct or validate the inventive process and recognise the technical solution ultimately claimed. The fact that an AI system proposes experiments, selects parameters or generates candidate solutions does not, in itself, affect inventorship where the human researcher retains effective control over the inventive concept.

The same principles apply to increasingly autonomous AI systems. The greater the autonomy exercised by the AI during the research process, the more important it becomes to demonstrate that the inventive contribution reflected in the patent claims remains the result of human intellectual activity.

Ownership of AI-assisted inventions is determined under the ordinary rules of the Italian Industrial Property Code. In the case of employee inventions, the right to obtain the patent is allocated according to the statutory regime governing inventions made in the course of employment, while the inventor retains the moral right to be recognised as such. For contractors, researchers and collaborators, entitlement depends on the applicable contractual arrangements, subject to any special statutory rules governing inventions made within universities, public research institutions and research hospitals.

Italian patent law contains no AI-specific rules on inventive step or novelty. Accordingly, AI-assisted inventions are assessed under the ordinary principles of the Italian Industrial Property Code, interpreted consistently with the European Patent Convention and EPO practice.

The availability of AI tools does not, in itself, alter the legal standards governing inventive step, the notional skilled person or common general knowledge. However, AI may affect the factual assessment of these requirements, particularly where it enables faster identification of prior art or assists in developing technical solutions. Likewise, AI-assisted inventions must still satisfy the ordinary requirement of sufficient disclosure, enabling the skilled person to carry out the invention without undue burden.

AI-generated disclosures, synthetic datasets and automatically generated technical documents are assessed under the ordinary rules on prior art. Where such materials are publicly available before the filing date and disclose the relevant technical teaching, they may form part of the state of the art regardless of whether humans or AI generated them. No AI-specific rules currently govern their treatment as prior art under Italian law.

Under Italian and EU law, AI-generated or AI-assisted designs may be protected through registered or unregistered design rights, copyright (where originality requirements are met), trade marks (for distinctive signs) and unfair competition law.

Unlike copyright, design protection does not require proof of human authorship. AI-generated designs may therefore be registered provided they satisfy the ordinary requirements of novelty and individual character. Features dictated solely by technical function are excluded from protection and the use of AI is generally irrelevant to the registrability assessment.

These principles apply to product configurations, graphical user interfaces (GUIs), icons, avatars, digital characters and the visual appearance of virtual goods. Design rights protect only visual appearance, while software functionality and source code remain subject to copyright or other applicable IP regimes.

AI systems cannot own IP rights. Ownership generally belongs to the applicant, the employer where the design is created in the course of employment or the person or entity acquiring the rights by contract or assignment.

Trade dress may also be protected under trade mark law or unfair competition rules, provided the applicable legal requirements are satisfied.

Italian and EU law do not prohibit registering trade marks created with AI assistance. AI-generated names, logos, slogans, sounds, motion marks and other brand assets may be registered provided they satisfy the ordinary requirements for protection, including distinctiveness, lawfulness and the absence of conflicts with earlier rights.

AI systems cannot own trade mark rights. Ownership belongs to the natural or legal person filing the application and using the sign in the course of trade or to the person or entity entitled under the applicable contractual arrangements.

When AI is used to generate brand assets, it is advisable to verify the AI provider’s contractual terms regarding ownership and use of the generated content. Clearance searches also remain essential to identify prior trade marks and reduce the risk of confusion or infringement.

The use of AI does not alter the substantive conditions for trade mark registration or ownership under Italian or EU law.

Italian law contains no AI-specific rules on moral rights. Accordingly, AI-assisted works are governed by the ordinary principles of the Italian Copyright Law.

Authors retain their inalienable moral rights, including the right to be identified as the author of the work and to object to any distortion or modification prejudicial to their honour or reputation. These rights continue to apply where AI is used as a creative tool.

Italian law does not recognise an exclusive right over an author’s artistic style. Accordingly, the imitation of a living creator’s style by an AI system does not, in itself, constitute copyright infringement. Liability will instead depend on whether the output reproduces protectable expression from existing works or infringes other rights, such as personality rights, unfair competition or trade mark rights, depending on the circumstances.

Likewise, Italy does not impose a general obligation to disclose AI involvement in the creation of works. However, the transparency obligations introduced by the AI Act may require certain AI-generated or AI-manipulated content to be appropriately disclosed. While these obligations pursue regulatory rather than copyright objectives, they may help reduce disputes concerning false attribution and the origin of synthetic content.

Italian law does not recognise a standalone right of publicity comparable to some common law jurisdictions.

Protection against unauthorised AI generation or use of a person’s name, image, likeness, voice or digital replica derives from a combination of personality rights, IP rights, data protection and, where applicable, unfair competition law.

Personality rights under Articles 6–10 of the Italian Civil Code and Articles 96–97 of the Italian Copyright Law provide the main protection, regulating the use and dissemination of a person’s name and image and may apply to AI-generated content involving identifiable individuals.

Additional protection may arise from trade marks, performers’ rights, unfair competition rules and misleading association claims where identity has commercial value. AI processing of images, voices or biometric data may also trigger GDPR obligations, as well as the violations indicated in 5.1 Copyright Infringement in Outputs.

Protection therefore relies on multiple legal regimes rather than a single AI-specific or publicity right.

As noted in 1.4 Courts, IP Offices and Regulators, the AI Act complements rather than replaces existing IP law. Accordingly, Italy has not established dedicated courts or tribunals for AI-related IP disputes, which remain subject to the ordinary jurisdiction applicable to the relevant IP right.

Copyright, patent, trade mark, design, trade secret and related unfair competition claims fall within the jurisdiction of the Specialised Business Courts (Sezioni Specializzate in Materia di Impresa). AGCOM (Italian Communications Regulatory Authority) also retains its existing administrative powers to enforce copyright online, including removing or disabling/restricting access to infringing content.

By contrast, disputes concerning compliance with the AI Act fall within the competence of the authorities designated under that Regulation. At EU level, the European Commission and the AI Office exercise supervisory powers, particularly in relation to general-purpose AI models. National competent authorities are responsible for enforcement within their respective sectors.

No AI-specific IP tribunal or alternative dispute resolution mechanism currently exists in Italy.

Under Italian law, parties to AI and IP disputes may rely on the ordinary rules of evidence under the Italian Code of Civil Procedure, together with the specific evidentiary measures available under the Italian Industrial Property Code and the Italian Copyright Law. In particular, courts may order disclosure (ie ordine di esibizione) of relevant evidence held by the opposing party and, in IP proceedings, grant certain measures, including on an interim basis, where the applicable statutory requirements are met. These measures can extend to AI-related evidence, including training datasets, source code, model documentation and technical logs.

Courts must balance the need for disclosure with the protection of confidential information and trade secrets. They may therefore restrict access to sensitive materials through confidentiality clubs or other protective measures, including limited disclosure, redactions and access confined to the judge, court-appointed experts and designated advisers.

While the AI Act does not introduce specific rules on evidence, its documentation, logging and transparency obligations may facilitate access to relevant technical information in subsequent litigation.

Under Italian law, courts may grant both interim and final injunctions to prevent or bring to an end infringement of IP rights.

Interim relief is available where the claimant establishes a prima facie case (fumus boni iuris) and a risk of irreparable harm (periculum in mora), pursuant to the Italian Industrial Property Code, the Italian Copyright Law and the Italian Code of Civil Procedure.

Although Italian law does not provide AI-specific injunctions, existing remedies are sufficiently broad to address AI-related infringements. Depending on the circumstances, courts may order the cessation of infringing activities, including:

  • the training, deployment or distribution of AI systems;
  • preserve evidence;
  • require the removal of unlawfully used protected works from datasets; or
  • require the implementation of technical measures (such as filters or other safeguards) necessary to prevent continuing infringement.

Likewise, where proportionate and technically justified, courts may order measures affecting the operation of AI systems, including the suspension of autonomous functions, restrictions on the use of specific tools or functionalities or other measures necessary to prevent further infringements. Following a finding of infringement, courts may also order corrective measures, including the withdrawal of infringing products from the market, destruction or assignment of infringing materials and publication of the judgment.

As no AI-specific remedies currently exist, the scope of any injunction will ultimately be determined by the traditional principles of effectiveness, necessity and proportionality.

Under Italian law, AI-related IP disputes are subject to the ordinary remedies provided by the Italian Industrial Property Code, the Italian Copyright Law and the Italian Civil Code. No AI-specific remedies currently exist.

A successful claimant may obtain compensation for economic and non-economic harm, calculated by reference to the losses suffered, the infringer’s profits and, where appropriate, a reasonable royalty. Courts may also order disgorgement of profits to prevent unjust enrichment.

Italian law does not provide for statutory or punitive damages.

Available non-monetary remedies include injunctions, seizure, withdrawal from the market, destruction or assignment of infringing goods and publication of the judgment. While there are no specific retraining or model-deletion remedies, courts may impose proportionate measures to stop the infringement, including removing unlawfully used materials from controlled datasets.

IP remedies are territorial. Cross-border disputes are governed by EU rules on jurisdiction and applicable law, while recognition and enforcement of foreign judgments follow applicable EU instruments or Italian private international law.

As discussed in 3.3 Licensing of Training Content, Italian law does not provide a standard licensing framework or mandatory contractual terms for using copyright-protected content, data or databases in AI training, fine-tuning, evaluation or retrieval-augmented generation (RAG). Contractual arrangements primarily govern these matters.

AI licences typically address the scope of permitted uses, covered models or services, duration, territory, exclusivity, remuneration, attribution, audit rights, deletion obligations, sublicensing restrictions and the parties’ respective rights over AI-generated outputs and their downstream exploitation.

For AI agents and autonomous retrieval systems, licences may also include specific provisions on logging, access to external tools and data sources, tool permissions and restrictions on autonomous retrieval, use or publication of third-party content. Such provisions reflect contractual risk allocation and emerging market practice rather than specific statutory requirements under Italian law.

No comprehensive reform creating a standalone AI-specific IP regime is currently expected in Italy. Future developments are likely to focus on clarifying the application of existing copyright, patent, trade secret and database rules to generative AI and agentic systems, rather than introducing new IP rights.

Key developments include the implementation of Law No 132/2025, the progressive application of the AI Act (particularly the obligations applicable to GPAI models) and future CJEU case law on AI training and the scope of the DSM text-and-data-mining exceptions.

Further legislative developments may also arise from implementing other EU instruments, including the revised Product Liability Directive (Directive 2024/285).

In practice, AI developers are expected to face increasing obligations relating to documentation, transparency, copyright compliance and governance, while right holders should benefit from improved enforcement tools and greater transparency regarding the use of protected content for AI development.

Italy participates in the international harmonisation of AI and IP primarily through the European Union and its implementation of EU legislation, including the AI Act and the DSM Directive.

It also contributes to discussions within WIPO, the Council of Europe, the OECD and UNESCO.

Italy follows the EU’s human-centred approach, preserving traditional IP principles, including human authorship and the existing copyright framework.

The main divergences from other major jurisdictions concern AI training, particularly the EU TDM regime and the absence of a broad US-style fair use doctrine.

ICT Legal Consulting

Via Borgonuovo 12
20121, Milan
Italy

+39 028 424 7194

+39 027 005 121 01

info@ictlc.com www.ictlc.com
Author Business Card

Trends and Developments


Authors



ICT Legal Consulting (ICTLC) is an international law firm providing strategic legal and regulatory support across privacy, data protection, IP and TMT law – with a strong focus on the normative and operational aspects of cybersecurity. The firm assists organisations in designing and implementing governance, compliance and security frameworks that meet the highest international standards. With over 80 professionals and an active network in more than 65 jurisdictions, ICTLC combines global co-ordination with local insight. Through its sister company ICT Cyber Consulting, the firm offers integrated cybersecurity services, including legal/technical risk assessments, resilience planning and alignment with frameworks such as NIS2, DORA and the Cyber Resilience Act. ICTLC’s multidisciplinary expertise enables clients to navigate complex digital regulations and strengthen trust, compliance and resilience across their global operations.

The Architecture of Agentic AI: Why Technology and Legal Risk Are Becoming Increasingly Intertwined

Over the past two years, advising multinational companies deploying AI across sectors such as healthcare, life sciences, technology and manufacturing, we have observed a significant evolution in the legal issues arising from AI adoption. Early projects primarily involved large language models (LLMs) used as decision-support or content-generation tools, with legal analysis focusing on training datasets, ownership of AI-generated outputs and compliance with the emerging European regulatory framework.

Today, the landscape has changed considerably. Organisations are increasingly deploying Agentic AI systems capable not only of generating content but also of autonomously planning tasks, retrieving information, developing software, interacting with enterprise applications and third-party digital environments, invoking external tools through APIs and executing complex workflows with limited human intervention. AI is therefore evolving from a passive assistant into an autonomous actor capable of pursuing predefined objectives across multiple digital systems.

Our experience advising multinational clients shows that this technological evolution is also reshaping legal priorities. The focus is shifting from compliance with AI and data protection rules to the strategic governance, protection and commercial exploitation of IP assets generated by or used within AI systems, while ensuring such systems do not infringe third-party intellectual property rights.

In this context, the evolution of AI toward agentic models is surfacing legal questions that both build upon traditional generative AI themes and introduce entirely new challenges.

This include, on the one side, assessing which elements inherent to the agentic nature of these AI systems (eg orchestration layers) may qualify for IP protection and, on the other, examining the IP implications of their increasing autonomy, particularly as regards ownership of outputs and potential risks to third-party and enterprise IP, resulting from their continuous access to, processing of and learning from enterprise information. Hence, understanding the technical architecture of Agentic AI is no longer a purely technological exercise. Each functional component of an autonomous agent may give rise to distinct legal issues, as discussed below. Appreciating how these components interact is therefore essential to assessing IP risks, allocating contractual responsibility and designing governance mechanisms capable of supporting the lawful deployment of Agentic AI within the Italian and broader European market.

In fact, unless these issues are expressly addressed in contracts with AI providers, companies may lose effective control over the use, management and exploitation of their IP assets. These issues are not confined to a single industry; they are surfacing transversally across diverse industrial sectors in Italy. We see significant trends especially in these sectors:

  • healthcare – where agentic capabilities are being developed for general administrative tasks, electronic health record management and, crucially, to support clinical and diagnostic activities for hospital staff;
  • urban transportation – within projects aimed at monitoring network status in real-time, identifying the root causes of delays by autonomously proposing alternative routes; and
  • manufacturing and logistics – improving supply chain resilience and optimising production workflows through autonomous agents that can react to environmental changes without constant human intervention.

Defining the New Actors: AI Agents and Agentic AI Systems

The category of Agentic AI can be subdivided into different levels of sophistication: from AI agents, which are autonomous, decision-making systems powered by AI, that are deployed to perform specific functions; to more sophisticated Agentic AI systems and multi-agent systems, capable of operating with a higher degree of autonomy to achieve a broader set of goals, essentially acting as an “AI agent manager”, which deploys, coordinates and manages multiple specialised agents without requiring human approval at each stage.

Rather than producing a single output, the agent may plan intermediate tasks, retrieve information from multiple sources, invoke external software tools, interact with enterprise applications through APIs, retain contextual information in memory and, where authorised, execute actions or publish outputs without requiring human intervention at every stage.

From a legal perspective, deploying autonomous agents significantly expands both the number of interactions with third-party IP and the range of actors potentially involved in the AI value chain. Whereas conventional generative AI primarily raises questions concerning the lawful use of training data and the ownership of AI-generated/AI-assisted outputs, Agentic AI introduces a continuous operational layer in which protected materials may be accessed, processed, combined or reproduced throughout the execution of the agent’s tasks, regardless of the level of human supervision, if any.

The Liability Trap: Autonomy vs Responsibility

A critical point to understand is that greater agent autonomy increases, rather than reduces, the deployer’s liability. AI agents might autonomously access protected third-party content or inadvertently share sensitive corporate assets (such as trade secrets) with external systems. Likewise, AI agents can autonomously define sub-goals and orchestrate multiple tools and APIs. The further an agent acts from its original human instruction, the more complex it becomes to attribute legal authorship to Agentic AI outputs and allocate liability for its specific actions.

Under Italian law, there is no separate liability regime for infringing acts carried out autonomously by an AI agent. Whether an AI agent autonomously scrapes third-party content, generates infringing code or makes a design choice that violates a patent, the legal assessment follows the standard rules governing the relevant IP right.

In practice, liability will depend on the degree of human control and the foreseeability of the agent’s actions. The risk is highest when an agent is configured to access protected content without oversight. While Regulation EU 2024/1689 (the EU AI Act) does not create new IP rights, it places heavy governance obligations on deployers (Article 26), requiring effective monitoring and human oversight.

The key features of Agentic AI and the implications for IP rights

Understanding the architecture of Agentic AI therefore becomes essential to identifying where legal risks arise in respect of IP rights. In practice, an autonomous agent typically comprises several interconnected functional layers, each raising different legal considerations.

Agentic AI shifts the focus of IP protection from the models themselves to the systems that make them act. The planning and orchestration layer determines how the agent decomposes complex objectives into individual tasks and when to consult external resources. It determines the circumstances in which the system will interact with protected content and therefore plays a crucial role in the overall governance of the AI system.

These assets often derive their value from secrecy. Therefore, trade secret law and robust contractual confidentiality are often more effective than copyright or patents for protecting Agentic AI’s orchestration (especially if it is difficult to prove that a human made a creative contribution, given the autonomy of the AI agent).

The retrieval layer, including Retrieval-Augmented Generation (RAG), allows the agent to access internal knowledge repositories, enterprise databases, scientific publications or publicly available online materials in real time. Unlike model training, retrieval generally does not incorporate external content permanently into the model. Nevertheless, autonomous consultation of copyright-protected works, databases or licensed digital resources may still engage copyright, database rights, contractual restrictions governing access or, where confidential repositories are involved, trade secret protection. Therefore, particular attention should be paid not only to the lawfulness of the initial training dataset, but also to the provenance and permitted use of the information continuously retrieved during the agent’s operational life.

A further layer concerns the integration of external tools and APIs. Modern agents increasingly perform tasks by interacting directly with third-party software environments, cloud platforms or enterprise applications rather than generating content in isolation. Depending on the permissions granted, an agent may execute searches, download documents, query proprietary databases, access customer relationship management systems or trigger actions within business software. These functionalities increase the likelihood that the agent will interact with content or software protected by IP rights or subject to contractual licence restrictions. Therefore, from a legal standpoint, the relevant issue extends to whether the agent’s autonomous interactions remain within the scope of the permissions granted by the relevant right holders or contractual counterparties.

Another increasingly significant component is the agent’s memory architecture. Long-term memory enables the system to retain contextual information across multiple interactions, improving efficiency and reducing repetitive tasks. At the same time, persistent memory may result in the storage or subsequent retrieval of copyright-protected materials, confidential business information or trade secrets beyond the purposes originally envisaged. Although Italian courts have not yet addressed these issues specifically in the context of Agentic AI, existing principles governing copyright, confidentiality and trade secret protection provide the analytical framework within which such questions are likely to be assessed.

Finally, autonomous AI agents increasingly operate within governance frameworks that include human approval mechanisms, logging systems and audit trails. These components, often perceived as purely technical safeguards, are becoming equally significant from a legal perspective. Under the EU AI Act, providers and, in certain circumstances, deployers must implement governance measures that ensure appropriate human oversight, transparency and accountability. In practice, comprehensive logging of retrieval activities, tool invocations, API calls and autonomous decisions not only supports compliance with the EU AI Act but may also prove essential in demonstrating the provenance of generated outputs, allocating contractual responsibility between providers and customers and establishing evidence in potential IP disputes.

These architectural features explain why the legal analysis of Agentic AI can no longer be confined to questions of mere model development or training. The principal source of legal exposure increasingly lies in the agent’s autonomous interaction with the digital environment in which it operates. For organisations entering the Italian or European market, governance therefore extends well beyond regulatory compliance: it requires a holistic approach that combines IP due diligence, contractual risk allocation and technical controls that ensure autonomous systems remain legally and operationally accountable throughout their lifecycle.

Ownership and Authorship of Agentic AI Outputs under the Italian Legal Framework

The core of the IP challenge lies in the “anthropocentric” nature of our legal systems. AI systems cannot hold IP rights under EU or Italian law; human authorship and inventorship remain legally mandatory.

Under Italian principles, we can identify three critical areas for determining protectability:

  • minimum creativity threshold – Italian case law requires only a minimal degree of creativity (the work must reflect the author’s personality and involve a minimal degree of subjectivity);
  • input and prompts – simple, generic commands are insufficient for protection; however, a series of detailed, iterative prompts that express specific stylistic choices and involve active selection and refining may demonstrate the necessary creative effort; and
  • selection and editing – human decisions made after an output is generated, such as selecting specific modules, modifying them or creatively aggregating them with other content, constitute a creative contribution that can secure copyright.

This creates a friction point as agents become more autonomous. Article 1 of the Italian Copyright Law (Law No 633/1941), as recently amended by Law No. 132/2025, clarifies that copyright protection applies to works created with the aid of AI tools, provided they constitute the result of the author’s intellectual work. Therefore, proof of a human creative contribution is indispensable and is assessed on a case-by-case basis.

The peculiarities of “vibe coding”

This issue is particularly acute in software development through “vibe coding”. In this approach, a user describes an objective in natural language and the Agentic AI system handles the actual coding independently, selecting languages, researching components and writing the source code.

If the human provides only the idea (the “vibe”) and the AI handles the creative implementation, no copyright typically arises, since abstract ideas are not protected under copyright law; only their creative expression is. Pure vibe coding risks creating a “copyright vacuum” where competitors can copy the resulting software with no legal recourse. To retain protection, companies must adopt a model of controlled or responsible AI-assisted development, where experienced developers perform significant refactoring and quality control.

Agentic AI, Training Data and Third-Party IP Rights

The use of protected works for training remains highly debated in Italy and Agentic AI is no exception. The legal framework is primarily governed by the text and data mining (TDM) exceptions (Articles 70-ter and 70-quater of the Italian Copyright Law), as outlined below.

  • Commercial TDM (Article 70-quater): Allows reproductions and extractions for commercial AI development, provided the developer has lawful access and the right holders have not opted out.
  • Opt-outs: Right holders can reserve their rights through machine-readable means. If an AI agent autonomously scrapes a site and fails to detect a valid opt-out, the developer may still be liable.
  • New clarifications (Article 70-septies): Recently introduced to confirm that the TDM regime expressly applies to generative AI systems.

Uncertainty remains regarding the long-term retention of training corpora and the application of these rules to specialised techniques like retrieval-augmented generation (RAG), where content is retrieved and reproduced dynamically during the system’s operation.

Verifying the Adequacy of the Contractual Structure of Agreements with AI Vendors in the Context of Agentic AI

Contracts with Agentic AI providers are a key instrument for ensuring that enterprises maintain full control over their IP assets while also complying with the EU AI Act and other regulatory frameworks.

This is particularly evident in the healthcare software sector, which provides one of the clearest illustrations of how Agentic AI is reshaping the legal risk landscape. Unlike conventional generative AI applications, autonomous agents deployed in healthcare rarely operate on a single dataset or perform isolated tasks. Instead, they increasingly function as orchestration tools that can interact with multiple digital environments simultaneously, including scientific publications, proprietary clinical databases, electronic health records, medical device software, internal standard operating procedures, regulatory documentation and enterprise knowledge repositories.

This interconnected environment significantly expands the legal issues that organisations must address before deploying autonomous agents in production.

The autonomous retrieval of scientific and technical information illustrates these issues well. Healthcare agents increasingly consult medical literature, clinical guidelines and specialised databases in real time, requiring organisations to consider any applicable copyright, database-right or contractual restrictions.

Similar concerns arise when autonomous agents access internal repositories containing regulatory, technical or research documentation. Here, the key issue is often protecting trade secrets and confidential information, as persistent memory and autonomous reasoning may expose protected know-how or customer data beyond the scope of authorised access. Under Italian law, these risks are assessed under the ordinary rules on trade secrets, confidentiality and contractual obligations, regardless of whether a human or an AI system performs the activity.

The same applies to product development. As Agentic AI increasingly supports software engineering, medical device design and manufacturing organisations should assess not only ownership of AI-assisted outputs but also the provenance of the information on which the agent relied in generating them.

Added to this complexity are the challenges of EU AI Act compliance, the potential classification of an AI system as “high-risk,” and regulatory aspects related to medical device regulations, cybersecurity and the protection of patients’ personal data.

The specific characteristics of Agentic AI, including those related to the protection of IP rights, necessarily affect the contractual agreements organisations enter into with providers of Agentic AI tools; these agreements must adapt to the technicalities of such tools to address the issues highlighted above.

It is therefore essential to examine the definitions and clauses contained in the AI vendor agreements relating to agentic AI architectures to ensure the following aspects are addressed in a manner that adequately protects the enterprise.

  • The methods and purposes for which the Agentic AI platform uses the enterprise’s and its customers’ data and related IP assets (including input data, contextual data, logs, traces, reasoning outputs, retrieval artifacts and similar information); such data may be used solely to provide the contracted services and must not be used to train or improve the agentic platform and/or for the benefit of other users. Customer-specific data or other artefacts (eg, configurations, prompts, retrieval configurations, embeddings, agent skills orchestration patterns or workflow settings) must remain exclusive to the enterprise’s environment and use case, with an express prohibition on their reuse for the benefit of other users in the absence of a specific written agreement.
  • The assignment of rights to outputs generated by the AI agent platform.
  • Any interaction between the orchestration logic of the Agentic AI platform and the enterprise’s systems. For instance, the architecture, workflows, decision-making rules and overall orchestration of the enterprise’s platform prior to its integration with the Agentic AI platform may contain the enterprise’s IP rights and should not be made available to the Agentic AI platform without express consent.
  • AI tool contracts should provide for adequate indemnifications by the vendor if their model violates third-party IP or if they misuse the customer’s data.
  • Definitions, scope and service warranties: if the service is defined as a set of tasks performed by agents, the delegation of authority (what the agent can do) and policy guardrails (mandatory triggers for human approval) should be expressly defined. The AI vendor must guarantee that AI agents shall comply with the defined guardrails and authority limits.

It will also be necessary to assess whether existing contractual commitments to clients are consistent with the licence terms proposed by AI vendors and identify any potential conflicts before deployment. If an enterprise’s agreement with customers assigns full IP ownership to the client, but the AI vendor agreements grant only a license to use outputs, this misalignment should be addressed. The same applies to transparency obligations vis-à-vis clients (mandatory under Article 50 of the EU AI Act, enforceable from 2 August 2026): Agentic AI provider terms should permit disclosure of Agentic AI usage. Where inconsistencies arise, enterprises should either renegotiate the AI vendor’s IP provisions or avoid using AI in the relevant engagements, as the potential legal and commercial consequences of conflicting contractual obligations are likely to outweigh any operational efficiencies.

Actionable Governance: Human-in-the-Loop as Infrastructure

Meeting legal standards for IP and compliance requires a deployment architecture that makes human control technically verifiable, as governance cannot be treated as a formal requirement embedded in a policy.

Technical-legal controls should include:

  • checkpoints – documenting human architectural decisions before an AI agent runs to provide evidence for potential patent or copyright claims;
  • immutable action logs – recording every tool call, API request and file write in an append-only store to comply with audit trail requirements under the EU AI Act (Article 12) and obtain a factual record for liability assessment;
  • approval human gates – integrating hard human gates in the deployment pipeline, so ensuring that autonomous code cannot be deployed in production without human review; and
  • real-time override – under the EU AI Act (Article 14), assigned human overseers must have a practical and accessible means to halt or override the agent’s execution loop in real-time.

Conclusion: A Strategic Approach to AI and IP

The evolution toward increasingly autonomous systems requires a synergistic integration of regulatory, contractual and IP competencies.

Organisations entering the Italian and wider European markets should approach Agentic AI not simply as a technological innovation but as a governance challenge and a strategic and competitive factor.

Effective deployment therefore requires a multidisciplinary governance strategy. IP compliance can no longer be considered in isolation; it must be integrated with contractual risk allocation, data protection, cybersecurity, technical safeguards and regulatory oversight throughout the entire operational lifecycle of the autonomous system. This reflects the increasingly interconnected legal landscape in which Agentic AI operates, where a single autonomous decision may simultaneously engage IP rights, confidential information, personal data, cybersecurity obligations and sector-specific regulatory requirements.

The questions surrounding technologies that learn, act and evolve are no longer speculative; they are already shaping procurement and contract negotiations. Organisations operating in the Italian and European markets are moving beyond a compliance-driven approach, focused on the EU AI Act, privacy and governance, towards a more strategic focus on the ownership, protection and commercial exploitation of IP assets generated by or used within AI systems. As Agentic AI continues to evolve organisations best positioned to innovate securely and maintain a competitive advantage will ensure autonomous systems remain transparent, accountable and effectively governed, while retaining effective control over their IP assets.

ICT Legal Consulting

Via Borgonuovo 12
20121, Milan
Italy

+39 028 424 7194

+39 027 005 121 01

info@ictlc.com www.ictlc.com
Author Business Card

Law and Practice

Authors



ICT Legal Consulting (ICTLC) is an international law firm providing strategic legal and regulatory support across privacy, data protection, IP and TMT law – with a strong focus on the normative and operational aspects of cybersecurity. The firm assists organisations in designing and implementing governance, compliance and security frameworks that meet the highest international standards. With over 80 professionals and an active network in more than 65 jurisdictions, ICTLC combines global co-ordination with local insight. Through its sister company ICT Cyber Consulting, the firm offers integrated cybersecurity services, including legal/technical risk assessments, resilience planning and alignment with frameworks such as NIS2, DORA and the Cyber Resilience Act. ICTLC’s multidisciplinary expertise enables clients to navigate complex digital regulations and strengthen trust, compliance and resilience across their global operations.

Trends and Developments

Authors



ICT Legal Consulting (ICTLC) is an international law firm providing strategic legal and regulatory support across privacy, data protection, IP and TMT law – with a strong focus on the normative and operational aspects of cybersecurity. The firm assists organisations in designing and implementing governance, compliance and security frameworks that meet the highest international standards. With over 80 professionals and an active network in more than 65 jurisdictions, ICTLC combines global co-ordination with local insight. Through its sister company ICT Cyber Consulting, the firm offers integrated cybersecurity services, including legal/technical risk assessments, resilience planning and alignment with frameworks such as NIS2, DORA and the Cyber Resilience Act. ICTLC’s multidisciplinary expertise enables clients to navigate complex digital regulations and strengthen trust, compliance and resilience across their global operations.

Compare law and practice by selecting locations and topic(s)

{{searchBoxHeader}}

Select Topic(s)

loading ...
{{topic.title}}

Please select at least one chapter and one topic to use the compare functionality.