Artificial Intelligence 2026

Last Updated May 21, 2026

Italy

Law and Practice

Authors



Chiomenti is an independent law firm of approximately 450 professionals with offices in Rome, Milan, London, Brussels and New York. Over 75 years of activity, Chiomenti has developed an extensive network of international relationships and provides its clients with the services and advice of over 450 professionals whose experience and expertise cover multiple economic sectors and geographic areas. Chiomenti has structured its services and assistance in practice areas with a particular focus on transactions and matters of importance and special relevance for its clients, putting its independence and legal expertise at the disposal of companies and institutions, and successfully innovating its leadership at the top of the legal services market. Assistance is carried out in full integration with the different professional areas in which the firm is divided, in order to address and manage various profiles of interest in transactions with a multidisciplinary and integrated approach, focusing on collaboration, internationality and technological innovation as factors of acceleration in its leadership.

Overview

Italy adopted Law No. 132 of 23 September 2025 (the AI Law), which complements Regulation (EU) 2024/1689 (the AI Act) by designating national competent authorities, introducing sector-specific rules, and establishing AI-related criminal offences. The Italian data protection authority (Garante per la Protezione dei Dati Personali, the DPA) retains supervisory competences over AI systems processing personal data. General background law provisions remain essential for matters not specifically addressed by AI-specific legislation.

Contract Law

Neither EU nor Italian law specifically addresses AI-related contract formation. The AI Act does not harmonise contract law, though its transparency and information obligations on providers and deployers (Articles 13, 25-26) will influence contractual risk allocation in the AI supply chain. At national level, the Civil Code contains no AI-specific provisions; general principles on offer, acceptance, capacity, and agency would apply by analogy. Where agentic AI autonomously concludes transactions, novel questions arise as to which party bears contractual liability. Italian courts have not yet ruled on this issue, and scholarly commentary remains limited. Possible frameworks include agency principles (mandato, Articles 1703 et seq. Civil Code), apparent authority (rappresentanza apparente), or forms of objective or risk-based liability of the deploying entity, but no settled doctrine has emerged.

Tort and Product Liability

EU law is reshaping product liability but does not fully harmonise non-contractual liability for AI. The Product Liability Directive (EU) 2024/2853 (the PLD), to be transposed by 9 December 2026, explicitly includes software and AI systems within its scope, removes the EUR 500 damages threshold, and introduces disclosure obligations to facilitate claimants’ access to evidence. The proposed AI Liability Directive, which would have introduced rebuttable presumptions of causation, was withdrawn by the Commission in February 2025 (see Section 10.2 for details). At national level, absent sector-specific rules, fault-based liability under Article 2043 Civil Code would apply to AI-caused harm, requiring proof of wrongful conduct, damage, and causation. Italian courts have not yet addressed AI-specific tort claims, and establishing fault and causation may prove challenging given model opacity. Scholarly commentary has explored whether strict or aggravated liability regimes-such as Article 2050 (dangerous activities) or Article 2051 (liability for things in custody)-could apply by analogy, but these provisions do not seem to readily accommodate AI’s distinctive features, and no settled interpretive approach has emerged.

Privacy and Data Protection

The deployment of AI systems is subject to the general EU and Italian data protection framework – notably the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) and Legislative Decree No. 196/2003, as further amended and supplemented (the Italian Privacy Code) – whenever personal data is processed, irrespective of whether the system is predictive, generative, or agentic. Controllers and processors must comply with core principles (Article 5 GDPR), identify a lawful basis (Articles 6–9), and implement data protection by design and by default (Article 25). Key issues include profiling and large-scale analytics (predictive AI), lawful training data sourcing and output risks (generative AI), and automated decision-making under Article 22 (agentic AI). High-risk uses generally require a data protection impact assessment (Article 35). Overall, GDPR and national law remain the primary regimes governing personal data processing alongside the AI Act.

Intellectual Property

Italian copyright law (Law No. 633/1941, Legge sul Diritto d’Autore, the LDA) requires human authorship under Article 1, as amended by the AI Law (Article 25), which now expressly protects works created “with the aid of AI tools” only where they constitute “the result of the author’s intellectual work.” Purely AI-generated works without substantial human creative input are not protected. The TDM exception (Article 70-ter LDA, implementing Article 4 of Directive (EU) 2019/790, the DSM Directive) permits reproduction for text and data mining, subject to an opt-out mechanism for commercial uses; the AI Law adds Article 70-septies LDA specifically addressing TDM for AI training (see 3.6Data, Information or Content Laws for detailed analysis). Patent protection follows Legislative Decree No. 30/2005 (Codice della Proprietà Industriale, the CPI); AI cannot be named inventor per European Patent Office practice and a similar requirement could be derived at national level from Article 62 CPI (moral right to be recognised as author of the invention, which vests in the inventor and specified heirs), and Article 63 CPI (entitlement to the patent is vested in the inventor of the patent), both of which presuppose the inventor is a natural person. For comprehensive analysis of IP issues, see 16 Intellectual Property.

Employment

In employment, Article 4 of Law No. 300/1970 (Statuto dei Lavoratori, the Workers’ Statute) prohibits remote monitoring, requiring trade union or labour inspectorate authorisation to implement tools which could trigger the possibility of remote monitoring of employees. Legislative Decree No. 104/2022 (the Transparency Decree) mandates disclosure of automated decision-making systems in employment. The AI Law (Articles 11-12) reinforces worker protections, requiring that AI use in the workplace respects dignity and ensures human oversight for consequential decisions.

Consumer Protection

The Consumer Code (Legislative Decree No. 206/2005, the Consumer Code) does not contain AI-specific provisions. However, the Italian competition authority (Autorità Garante della Concorrenza e del Mercato, AGCM) recently applied its general unfair commercial practices rules (Articles 20-22 Consumer Code) to AI services. In a recent proceeding against DeepSeek and other providers (settled with commitments), AGCM held that failure to clearly inform users about “hallucination” risks - ie, the possibility of inaccurate or fabricated outputs - constitutes an omission of material information essential for informed consumer decision-making, even where the service is provided free of charge (see 4.1 Precedent-Setting Judicial Decisions for details on this decision).

Criminal Law

The AI Law introduced AI-specific criminal provisions, including an aggravating circumstance for offences committed using AI systems (Article 61, para. 11-undecies Criminal Code) and a new standalone offence for unlawful dissemination of AI-generated content harmful to a person’s image (Article 612-quater Criminal Code). The AI Law also introduced enhanced penalties for market manipulation committed by means of AI, and added a new criminal offence to the LDA (Article 171, para. 1, let. a-ter) punishing unlawful text and data mining in violation of Articles 70-ter and 70-quater, including via AI systems. Deepfake intimate imagery remains punishable under Article 612-ter (revenge porn). For analysis of deepfake regulation, see 12.3 Deepfakes and Synthetic Media.

A 2025 Confindustria Report (L’Intelligenza Artificiale per il Sistema Italia) mapped over 200 use cases across 76 companies, with healthcare, manufacturing and sustainable mobility as key sectors. Operations-related applications predominate, followed by corporate/HR and customer service. Generative AI accounts for 46% of the market (Osservatorio Artificial Intelligence del Politecnico di Milano, 2025). ISTAT (Imprese e ICT 2025) cites lack of digital skills and high implementation costs as main adoption barriers.

Italy is a major beneficiary of the EU Recovery and Resilience Facility (Regulation (EU) 2021/241) – so-called PNRR funding. According to a report by Fondazione Leonardo ETS (L’Italia nell’era dell’IA, edited by Luciano Floridi and Micaela Lovecchio, March 2026), key AI-related allocations include:

  • the FAIR (Future Artificial Intelligence Research) extended partnership, funded by the Ministry of University and Research with over EUR100 million, creating a network of research bodies, universities, and corporate partners organised into thematic spokes; and
  • the IT4LIA AI Factory project, with a total investment of several hundred million euros co-financed by the Italian Government and the EuroHPC Joint Undertaking (Regulation (EU) 2021/1173), aimed at deploying exascale computing infrastructure.

Additionally, the AI Law (Article 23) authorises investments of up to EUR1 billion in companies operating in AI, cybersecurity, and enabling technologies, including quantum computing. These investments are to be made through equity and quasi-equity instruments managed by CDP Venture Capital SGR, with governance participation by the Presidency of the Council of Ministers and ACN (Agenzia per la Cybersicurezza Nazionale).

As the first EU Member State to adopt comprehensive national legislation on AI, the AI Law positions Italy as a first mover. It facilitates the application of the AI Act in the Italian legal order and reflects a precautionary, risk-based and human-centric approach (see 3.2 Jurisdictional Law for implementation details and 5.1 Regulatory Agencies for competent authorities).

The AI Law establishes sector-specific rules for AI use in healthcare, public administration, employment, intellectual professions and judicial activities (see 7 AI and the State to 12 Specific Legal Issues With AI for detailed sectoral analysis).

In the IP and personality rights realm, the AI Law introduces provisions on copyright and AI, confirming that TDM exceptions apply to AI training subject to the opt-out mechanism, and requiring human authorship for copyright protection of AI-assisted works (see 3.6 Data, Information or Content Laws and 16 Intellectual Property for IP analysis). For pending legislative proposals addressing deepfakes and algorithmic platforms, see 3.7 Proposed AI-Specific Legislation and Regulations.

In the area of data protection, both the Italian legislature and the DPA tend to adopt a precautionary approach, broadly consistent with the positions articulated at EU level by the European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB).

The AI Law incorporates the AI Act classification of AI systems by reference, applying across the full AI lifecycle. Its distinctive feature is a sector-specific approach, imposing context-based requirements and limitations in sensitive domains such as justice, healthcare, employment, and public administration (see 4 Case Law, 5 AI Regulatory Oversight, 6 Standard-Setting Bodies, 7 AI and the State, 11 Agentic AI Systems and Autonomous Decision-Making and 12 Specific Legal Issues With AI).

The law establishes a governance and monitoring framework, designating the Presidency of the Council of Ministers as the co-ordinating authority (see 3.3 Jurisdictional Directives), and mandates the adoption of a periodically updated national AI strategy.

The law also promotes regulatory sandboxes for AI (see 3.4 EU AI Act) and introduces specific provisions on copyright (see 3.6 Data, Information or Content Laws and 16.2 AI as Inventor/Author) and AI-related criminal offences (see 1.1 General Legal Background).

Italy is developing a soft-law framework to guide AI adoption across key sectors. In March 2026, AgID launched a public consultation on draft guidelines which ended on 11 April 2026. Following the consultation, two sets of guidelines were adopted through Resolution No. 43/2026. The guidelines concern, respectively, the development of AI systems in the public sector and the procurement of AI solutions by public administrations.

The guidelines on the development of AI systems in the public sector provide a strategic framework for designing new AI-based systems. They address key principles such as transparency, accountability, human oversight, and non-discrimination. They also connect these principles with the operational framework of procurement, ensuring coherence and continuity across the entire AI lifecycle within the public sector.

The guidelines on the procurement of AI systems in the public sector complement the development guidelines and establish a methodological and operational framework to support public authorities in the acquisition, management, and monitoring of AI solutions. They introduce operational tools and criteria to strengthen the capacity of public administrations to design and manage complex tenders, ensuring compliance with the AI Act requirements for high-risk AI systems used in public services. Furthermore, the Ministry of Labour and Social Policies, through Ministerial Decree No. 180/2025, has issued guidelines promoting the responsible use of AI in the workplace, with a focus on employee protection, transparency, accountability, non-discrimination, regulatory compliance, and sustainable innovation. Lastly, the Ministry of Education has adopted Ministerial Decree No. 166/2025, introducing guidance to support the informed integration of AI tools in schools. These measures aim to enhance teaching and administrative processes, while addressing ethical and data protection risks through a set of technical, ethical, and regulatory safeguards.

As noted in 3.1 General Approach to AI-Specific Legislation, Italy adopted the AI Law further and to give effect to the AI Act. The law is aligned with the risk-based approach and draws upon the categories, concepts, and actors defined in the AI Act. Article 1(2) of the AI Law explicitly provides that its provisions shall apply and be interpreted in accordance with the AI Act. Article 2(1) refers to the notions of “AI systems” and “AI models” as defined, respectively, in Articles 3(1) and 3(63) of the AI Act. Moreover, paragraph 2 establishes that for any notions not expressly defined therein, the definitions in the AI Act shall apply.

In addition to introducing sector-specific provisions – concerning, among others, the use of AI by public administrations, in the workplace (see 1.1 General Legal Background), in intellectual professions, and in healthcare – the AI Law fulfils the obligation imposed on member states by Article 70 of the AI Act to designate the national competent authorities in the field of AI. The law also includes measures to strengthen cybersecurity in AI systems.

By designating AgID as the notifying authority and market surveillance authority for non-high-risk AI systems, and ACN as the market surveillance authority for high-risk AI systems and for general-purpose AI models, the Italian legislator has entrusted existing agencies with the relevant powers (unlike other jurisdictions, such as Spain, which have established ad-hoc AI authorities). In accordance with Article 74(6) of the AI Act, the Bank of Italy, CONSOB (Commissione Nazionale per le Società e la Borsa), and IVASS (Istituto per la Vigilanza sulle Assicurazioni) act as market surveillance authorities for AI systems used in the financial services sector. For a comprehensive overview of all competent authorities, see 5.1 Regulatory Agencies.

Moreover, while designating the competent AI authorities, Article 20 of the AI Law applies without prejudice to the powers and competences of the DPA and the Italian Communications Authority (Autorità per le Garanzie nelle Comunicazioni, AGCOM), with the latter acting as the digital services coordinator for Italy under Regulation (EU) 2022/2065 (the DSA).

Article 24 of the AI Law contains a delegation of power to the government for the adoption of legislative decrees necessary to facilitate the application and enforcement of the AI Act. In particular, such decrees will:

  • empower the competent authorities to effectively perform their notifying and supervisory functions;
  • adapt existing sectoral legislation (including financial services) to ensure full compliance with the AI Act;
  • establish specific rules for the use of AI in sensitive areas, such as law enforcement;
  • introduce the applicable sanctions regime; and
  • promote AI training and awareness programmes for the general public, professionals, and sectoral operators. Universities and research institutions are expected to contribute to the development and use of regulatory sandboxes in cooperation with industry.

Not relevant in this jurisdiction.

Copyright and TDM Exceptions

The Italian TDM framework builds on the DSM Directive. Article 70-ter LDA (transposing Article 3 DSM Directive) permits TDM for scientific research by research organisations and cultural heritage institutions with lawful access. This exception is mandatory, non-waivable, and royalty-free.

Article 70-quater LDA (transposing Article 4 DSM Directive) establishes a broader TDM exception for any person with lawful access, including for commercial AI training, subject to an opt-out mechanism. Unlike the DSM Directive, the Italian transposition does not specify how rightholders must express their reservation. Under Article 4(3) DSM Directive and Recital 18, reservations for online content must be machine-readable (eg, metadata, robots.txt). The AI Act reinforces this: Article 53(1)(c) requires general-purpose AI (GPAI) model providers to implement policies to identify and comply with rights and reservations using “state-of-the-art technologies”, which Recital 106 specifies may include watermarking.

Article 25 of the AI Law introduces Article 70-septies LDA, confirming that TDM exceptions apply to AI model training (including generative AI), subject to the opt-out for commercial uses. See 16.3 Copyright and AI Training Data for detailed analysis of copyright issues, licensing frameworks and pending litigation.

Database Rights and Sui Generis Protection

The sui generis database right under Directive 96/9/EC protects databases showing substantial investment in obtaining, verifying or presenting their contents. Article 4(1) DSM Directive extends the TDM exception to the sui generis right. Article 70-quater LDA does not expressly mention it but refers to “database owners”; the extension should apply by consistent interpretation. Debate remains whether large-scale extraction for AI training exceeds proportionality limits, particularly when entire databases are ingested for model development.

Data Protection

On data protection, while there is no AI-specific legal basis for processing under the Italian Privacy Code, the DPA has consistently applied core GDPR principles (lawfulness, transparency, purpose limitation, data minimisation) when assessing generative AI services, including via remediation orders directed at LLM deployments.

Web scraping remains legally fraught where personal data is collected or reused for AI training without a lawful basis and adequate notice. Recent DPA interventions – such as the 2022 EUR20 million fine on Clearview AI for unlawful web scraping (including biometric and geolocation data), and 2024 guidance on protecting personal data from web scraping – confirm that “publicly available” does not equate to “free to scrape”.

Finally, Italy lacks a dedicated statutory framework for synthetic data, whose use is generally assessed under the GDPR (anonymisation v pseudonymisation), and the DPA’s risk-based approach. However, the AI Law has introduced the possibility for the National Agency for Regional Health Services (AGENAS) to issue and update guidelines on anonymisation and synthetic data creation for AI research in the health sector.

At the time of writing, some legislative proposals addressing AI-specific issues are pending before the Italian Parliament. 

  • Bill No. 1644 on the protection of personal identity in the use of AI technologies, which addresses deepfake-related threats. The bill establishes individuals’ exclusive rights over their name, image, voice, and facial expressions, prohibits the unauthorised reproduction, imitation, simulation, or dissemination of a person’s identity through AI without explicit consent, and introduces a presumption of harm for violations. Sanctions range from EUR10,000 to 100,000, with criminal penalties (six months to three years imprisonment) in cases of intent or recidivism. The bill also mandates clear disclosure of AI-generated audiovisual content and requires digital platforms to implement reporting and rapid blocking mechanisms.
  • Bill No. 1859 on the regulation of social media algorithms, which shifts the focus from content moderation to the design of platforms. This proposal introduces a duty of care for algorithmic systems, liability with a reversed burden of proof (modelled on Article 2050 of the Civil Code), and prohibitions on addictive design practices (e.g., infinite scroll, autoplay, variable reinforcement notifications). It also establishes non-profiling as the default rule, with proactive protections for minors and increased sanctions (up to 4% of global turnover) for manipulative practices affecting electoral processes. AGCOM is designated as the competent authority. These proposals are still under parliamentary review and have not yet been passed or enacted.

Moreover, Article 16 of the AI Law empowers the government to adopt implementing decrees regulating the use of data, algorithms, and mathematical methods for AI training (in line with the EU AI Act and without adding further obligations). Similarly, and more generally, Article 24 of the same law delegates to the Italian government the power to adopt decrees to ensure full implementation of the EU AI Act in Italy (including adapting existing sectoral legislation, defining sanctions and liability regimes, regulating unlawful and high-risk AI systems, and establishing rules for AI use in sensitive contexts such as criminal investigations).

Italy’s body of truly precedent-setting AI case law is still developing; however, certain judicial decisions on algorithmic systems already articulate principles that will probably shape disputes across IP, privacy, liability and labour.

Intellectual Property

In the IP realm, while Italian courts have not yet ruled on AI training and copyright infringement, the first significant case is now pending: RTI and Medusa Film v Perplexity AI (Court of Rome, filed December 2025). The Mediaset subsidiaries allege that Perplexity systematically used copyrighted audiovisual content (films, TV programmes) to train its LLM without authorisation, invoking violations of Articles 1, 2, 45, and 78-ter LDA. The claimants seek an injunction, damages and daily penalties for future violations. The case is the first Italian lawsuit targeting AI training on audiovisual works and will likely test the interplay between the TDM exception and the opt-out mechanism. No decision has yet been rendered.

On the related question of copyright protection for algorithmically generated works, the Supreme Court of Cassation touched upon the issue in Cass. civ. Sez. I, 16 January 2023, No. 1107 (a fractal image used as set design for the Sanremo Festival): in that case, well ahead of the AI Law and the recent amendments to the LDA, the Court noted that using software to generate an image is compatible with the elaboration of a work of authorship with a degree of creativity that would only need to be scrutinised with greater rigour (see 16.2 AI as Inventor/Author for further analysis).

Two recent precautionary orders issued in 2026 provide early indications of how Italian courts may approach AI-related IP and liability issues. In Court of Milan, 23 April 2026, the court addressed alleged copyright violations involving digital renders (photorealistic images) allegedly used to train an AI system. While the proceeding was dismissed for lack of ongoing harm (the defendant had removed all contested content and committed to a penalty for future violations), the court nonetheless found that the infringing use was “evident” for purposes of allocating costs under the virtual succumbence criterion. The claimant had argued that the defendant’s conduct – downloading renders and using them to train an AI system to generate derivative images reproducing the same distinctive elements (perspective, angles, lighting) – violated the exclusive rights of reproduction (Article 13 LDA) and elaboration (Article 18 LDA). Although the court did not formally rule on the merits, this framing suggests that Italian courts may treat AI training on protected works as engaging both reproduction and elaboration rights where outputs substantially reproduce original elements.

In Court of Pistoia, 19 March 2026, the court granted precautionary relief against a competitor for unfair competition through parasitic advertising, including the use of keyword advertising referencing a rival’s celebrity testimonials. Notably, the defendant argued that the infringing blog content had been “generated by an automated text generation system based on artificial intelligence” without direct human intervention or conscious editorial intent. The court expressly rejected this defence, holding that AI systems are “at least for now, not capable of taking any initiative” autonomously, and therefore the entrepreneur remains liable for content generated through AI tools deployed in its business. This ruling establishes an early judicial position that reliance on AI does not excuse liability for unlawful outputs – a principle likely to inform future disputes over AI-generated content in advertising, marketing and beyond.

Consumer Protection

The AGCM closed three investigations against DeepSeek (case PS12942, decision of 16 December 2025), Mistral (case PS12968, decision of 17 February 2026) and NOVA AI (case PS12973, decision of 21 April 2026) by accepting commitments, without any finding of infringement. The proceedings arose from concerns that users were not adequately informed about the risk of so-called hallucinations, including at key stages such as first access, use of the chat interface and pre-contractual disclosures. The commitments focused on enhancing transparency towards users, including by ensuring that relevant information on hallucinations is provided in Italian. In particular, the companies introduced permanent disclaimers within their interfaces (websites and apps), including directly below chat windows, alerting users to the risk of hallucinations and linking to further information. They also strengthened pre-contractual disclosures (eg, in their terms and conditions), with explicit warnings on the limits of reliability of AI-generated content and the need for users to verify outputs. DeepSeek’s commitments went further by implementing targeted technical interventions to mitigate hallucinations, including improved filtering of training data, the use of specialised datasets and reinforcement learning techniques to reduce unreliable outputs, and the integration of real-time, authoritative information sources.

Data Protection

Supreme Court of Cassation No. 28358/2023 clarifies that consent-based profiling is valid only if the underlying algorithm is described unambiguously, without requiring disclosure of weightings or source code.

Italy’s most developed AI case law lies in the labour/platform-work space, where algorithmic management is treated as a substantive mode of organising work. In Court of Milan, Labour Section, No. 1018 of 20 April 2022 (Deliveroo Italia), the algorithmic system for order allocation and reputational scoring was deemed indicative of hetero-direction leading to the re-classification of the relationship as subordinate employment. The ruling suggests that where algorithms govern access to work and embed sanctions/rewards, courts may recharacterise job relationships or intensify employer duties. At Supreme Court level, the Court of Cassation decision of 22 September 2023 (in the Foodinho/rider context) confirmed that algorithmic governance is central to assessing discrimination and transparency toward workers.

For AI case law in the public-law sphere, see Section 7.2 Judicial Decisions.

Article 20 of the AI Law designates ACN and AgID as the national competent authorities for AI pursuant to Article 70 of the AI Act. ACN is designated as the market surveillance authority, responsible for supervision (including inspections and sanctions), and as the single point of contact with EU institutions; it is also tasked with promoting AI development in relation to cybersecurity. AgID is designated as the notifying authority, responsible for promoting AI innovation and development, and for defining procedures for the notification, assessment, accreditation and monitoring of conformity assessment bodies. The AI Law also provides that Bank of Italy, CONSOB and IVASS are responsible for market surveillance over AI systems in financial services pursuant to Article 74(6) of the AI Act.

The designation of ACN and AgID is expressly stated to be without prejudice to the competences of other authorities: the DPA retains its supervisory competences over AI systems processing personal data under the GDPR (Article 20(4) AI Law), and AGCOM retains its competences, including as digital services coordinator under the DSA with authority over AI systems in media and recommendation algorithms (Article 20(4) AI Law). AGCM is not expressly designated under the AI Law but retains its general competences, inter alia over unfair commercial practices (Articles 20-22 Consumer Code), which might extend to AI-related services, as demonstrated by its recent enforcement initiatives (see 4.1 Precedent-Setting Judicial Decisions).

Soft law issued by regulators, while not formally binding, often sets the practical compliance baseline for AI deployments.

As concerns AgID guidelines, as well as guidelines from government agencies, see 3.3 Jurisdictional Directives.

Where personal data is processed, a central role is played by the DPA, which has used general guidance, sector-specific “rulebooks”, and consultative opinions to operationalise GDPR principles and the Italian Privacy Code. An example is the DPA’s guidance of 20 May 2024 on measures to mitigate web scraping of personal data published online. Although framed as “non-binding measures” under the accountability principle, it provides a concrete control catalogue (eg, reserved areas, traffic monitoring, and technical anti-bot countermeasures), directly relevant for organisations training or fine-tuning AI models on web datasets.

The DPA has also issued opinions on draft measures and programmes involving AI/machine learning (ML), including:

  • Bank of Italy ML initiatives for complaints handling;
  • Ministry of Health rules on Electronic Health Records and the Health Data Ecosystem; and
  • the Ministry of Education and Merit’s decree and guidelines on introducing AI in schools.

In healthcare, the DPA has published structured “decalogue” guidance for AI-enabled national health services, translating legality, fairness, human oversight and security requirements into operational governance. Finally, the DPA has provided indications on AI uses in sensitive areas, such as smart assistants or deepfakes (especially in connection to cyberbullying, fake news, revenge porn and other cybercrimes).

Italy’s AI enforcement to date has been driven primarily by the DPA, leveraging the GDPR and the Italian Privacy Code to address perceived gaps as the AI Law beds in. A clear trend is the use of urgent/interim powers (including temporary processing bans) alongside fines, particularly where foundation-model providers rely on large-scale data collection and opaque training pipelines. The flagship case remains the DPA’s 2023 action against OpenAI’s ChatGPT: an urgent order imposed an immediate restriction on processing Italian users’ data (prompting geoblocking), followed by conditional measures to lift the ban and, ultimately, a final fine in December 2024, later successfully challenged by OpenAI before the Court of Rome. Similar concerns (with a focus on minors’ protection) informed the DPA’s actions against Luka Inc’s Replika (2023-2025), culminating in requirements to strengthen age-gating and privacy documentation (including Italian-language notices and clearer positions on retention and extra-EEA transfers).

Italian enforcement has also targeted biometric AI: in the 2022 Clearview AI decision, the DPA sanctioned the creation and use of facial-recognition profiles built from mass web-scraped images and ordered cessation of processing and erasure of data relating to individuals in Italy. Beyond foundation models and biometrics, in 2025 the DPA sanctioned AI-enabled surveillance (Municipality of Trento) for lack of legal basis for special-category/criminal-offence data, inadequate anonymisation, missing data protection impact assessments (DPIA), and deficient transparency, and imposed a EUR5 million penalty on Foodinho for algorithmic management in the platform economy, focusing on automated decision-making safeguards and the right to human intervention. Recent actions further show scrutiny of AI training/data-sharing arrangements (publisher–LLM content sharing) and health-data uses for AI training (Menarini Silicon Biosystems, 2025).

On the consumer protection front, AGCM has also taken action against generative AI providers: in 2025-2026, the authority closed proceedings against DeepSeek, Mistral and NOVA AI by accepting commitments requiring enhanced transparency on hallucination risks (see 4.1 Precedent-Setting Judicial Decisions).

In Italy, AI standard-setting emerges from a multi-layered ecosystem of legislative, regulatory, and technical sources. Alongside formal legislation (notably the AI Law, establishing a governance and accountability framework for AI systems and requiring demonstrable risk management, traceability, and audit-ready controls), key institutional actors shape operational expectations, including UNI (Ente Italiano di Normazione) and CEI (Comitato Elettrotecnico Italiano), as well as regulators such as AgID, ACN, and the DPA, and ministerial initiatives. Although largely soft-law, such instruments materially influence compliance, particularly in high-impact sectors (public procurement, employment, and education), as reflected in ministerial guidelines on AI use in workplaces and schools (see 3.3 Jurisdictional Directives), and in the Italian DPA’s decisions on AI-driven data processing, including generative AI services. Collectively, these measures operate as de facto standards, shaping market expectations and bridging AI Act requirements with national practice.

International standards such as ISO/IEC 42001 (AI management systems), ISO/IEC 23894 (AI risk management) and ISO/IEC 22989 (AI terminology), alongside IEEE frameworks and the NIST AI Risk Management Framework, are increasingly used in Italy as practical benchmarks for governance and risk management. While not legally binding, they are widely regarded as state-of-the-art indicators and relied upon to evidence diligence in the AI design, development and deployment. In practice, Italian and multinational companies are progressively incorporating these standards into internal compliance structures, supplier due diligence processes and contractual arrangements, particularly in anticipation of AI Act conformity assessment. This is especially relevant for high-risk systems, where adherence to recognised standards can help substantiate controls on risk management, data governance, transparency and human oversight. Although generally consistent with EU law, including the GDPR and applicable cybersecurity requirements, these frameworks are not applied mechanically but require calibration to align with interpretative guidance from Italian authorities, including the DPA, as well as sector-specific regulatory expectations.

Italian public administrations are increasingly deploying AI systems across administrative processes, under the Italian Strategy for Artificial Intelligence 2024–2026, prioritising research, talent, and measurable public service improvements. Accordingly, AI adoption is primarily aimed at enhancing efficiency, service provision, and risk management and compliance.

Applications remain largely “assistive”, including machine learning tools for welfare fraud detection (notably within INPS, the National Institute for Social Security), and natural language processing for document classification and case management. The most advanced uses are in tax administration: the Revenue Agency employs automated tools for VAT and income tax controls, pre-filed returns, and SME risk-scoring, supported by digitised invoicing and receipts. Parliament has authorised AI for tax risk analysis subject to GDPR compliance and human oversight, and the Revenue Agency is developing AI-enabled assessment engines correlating registry and financial data, including graph-based VAT fraud detection tools.

More generally, Article 14 of the AI Law regulates AI use by public administrations to enhance efficiency, accelerate procedures, and improve services, requiring systems to remain supportive and traceable, with final decision-making authority and accountability vested in human officials, alongside appropriate organisational and training measures. Additionally, Article 5(1)(d) of the AI Law requires e-procurement platforms to favour suppliers whose AI solutions ensure data localisation and processing within Italian data centres, with domestic disaster recovery and business continuity measures, significantly impacting data sovereignty in AI public procurement.

Italian case law on AI use by government agencies and public administrations has developed primarily in the administrative courts, crystallising enforceable constraints on algorithmic decisions. In its 2019 landmark judgment (Consiglio di Stato, Sez. VI, 8 April 2019, No. 2270), the Council of State accepted that algorithmic tools may support administrative efficiency, provided that the underlying rule is fully “knowable” in a reinforced transparency sense: stakeholders must understand authorship, design choices, relevant data inputs, and prioritisation logic, enabling legality and rationality to be tested. This line has been reaffirmed and refined, with the Council of State stressing that IT tools cannot depart from legal criteria and that the administration retains verification and accountability, including in discretionary contexts.

Courts have also linked transparency to access obligations: Consiglio di Stato, Sez. IV, 4 June 2025, No. 4857 distinguishes algorithmic decisions from decision-support tools and addresses access to source code and datasets in light of transparency and procurement rules favouring traceability and open solutions. In parallel, the Italian Supreme Court of Cassation (Corte di Cassazione, Sez. I, No. 28358/2023) has addressed “algorithmic opacity” through a data-protection lens: valid consent requires intelligible information on data processing within an algorithm, without disclosure of the mathematical code.

In Italy, AI in national security and defence sits at the intersection of:

  • sector-specific security laws;
  • cybersecurity rules for critical functions and infrastructure; and
  • data-protection constraints on State use of personal data-intensive technologies. 

A defining feature is Italy’s preservation of a distinct regulatory space for “security of the Republic” and defence functions, while reaffirming constitutional and fundamental-rights guardrails. At legislative level, the AI Law excludes activities for national security (intelligence bodies under Law No. 124/2007), national defence (Armed Forces), and certain cybersecurity/resilience functions linked to the national cybersecurity architecture under Decree-Law No. 82/2021 (as converted). At the same time, the law provides that these excluded activities must still comply with constitutional rights and principles of proportionality, security and human oversight. AI research and development may fall under the National Cybersecurity Perimeter (Perimetro di sicurezza nazionale cibernetica) introduced by Decree-Law No. 105/2019 (as converted), which imposes risk analysis, security measures and incident reporting obligations for entities and assets deemed critical to national security. Furthermore, specific categories of IT goods and services provided to public administrations or entities within the National Cybersecurity Perimeter and used in a context related to the protection of strategic national interests are subject to essential cybersecurity requirements. Finally, where AI entails biometric or large-scale analytics for public security, data protection enforcement remains a material constraint.

Regulatory Framework for General-Purpose AI Models

The AI Act introduces a dedicated regulatory framework for GPAI models, including LLMs, image generators and other foundation models. Chapter V of the AI Act establishes tiered obligations based on whether a model presents systemic risks. All GPAI model providers must maintain technical documentation, provide information to downstream AI system providers, comply with EU copyright law and publish a sufficiently detailed summary of training content. GPAI models with systemic risks - identified by reference to cumulative compute thresholds or Commission designation - face additional obligations including model evaluation, adversarial testing, incident reporting and cybersecurity measures.

Copyright Issues in Training and Outputs

Generative AI raises distinctive copyright challenges at both the input and output stages. Training large models on copyrighted works involves acts of reproduction that require either rightholder authorisation or reliance on a statutory exception, such as TDM under Articles 3-4 of the DSM Directive (transposed in Italy as Articles 70-ter and 70-quater LDA). However, significant doctrinal debate exists as to whether the TDM exception - designed for analytical extraction - is conceptually suited to generative AI training aimed at learning and reproducing expressive qualities. At the output stage, generated content that reproduces or substantially resembles protected works may constitute infringement. For detailed analysis, see 16 Intellectual Property.

Data Protection Considerations

As regards data protection issues, while useful guidance has been provided at the European level by the 2025 EDPB Report on AI Privacy Risks & Mitigations – Large Language Models (LLMs), the Italian DPA has also taken enforcement action against certain LLM providers (see 17 Data Protection).

Liability for Harmful or Infringing Outputs

Generative AI outputs may cause harm through various mechanisms:

  • factual inaccuracies (hallucinations);
  • defamatory statements;
  • privacy violations; or
  • IP infringement.

Liability allocation depends on the specific facts and applicable legal regime. Under general tort principles, both providers and users may bear responsibility depending on their knowledge, control and the foreseeability of harm. For detailed analysis of liability frameworks, see 10 Liability for AI. For AI in legal practice and hallucination risks, see 9.1 AI in the Legal Profession and Ethical Considerations.

Transparency Requirements

The AI Act imposes transparency obligations at multiple levels. Article 50 requires that AI systems designed to interact with natural persons disclose that the user is interacting with an AI system. Providers of AI systems that generate synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable format as artificially generated or manipulated. GPAI model providers must publish summaries of training content and maintain technical documentation. The GPAI Code of Practice provides further guidance on implementing these transparency requirements, including specifications for watermarking and content authenticity standards.

The AI Law directly regulates the use of AI in intellectual professions, including the legal one: Article 13 restricts AI to “instrumental and support activities”, requiring the predominance of the professional’s intellectual work, and imposes a prior written disclosure obligation to clients. The Italian National Bar Council (CNF) issued a standard-form notice.

Hallucinations and Early Case Law

Italian courts have begun addressing negligent reliance on AI-generated content. In TAR Lombardia-Milano, no. 3348/2025 (21 October 2025), the court referred an attorney to the Milan Bar for disciplinary proceedings after he cited entirely irrelevant case law sourced through AI tools, invoking Article 88 Italian Code of Civil Procedure (duty of loyalty) and the Milan Bar’s Charter on AI use by lawyers. The Court of Florence, Business Section (14 March 2025) addressed AI-linked negligence involving the use of ChatGPT to generate fabricated Supreme Court citations in pleadings, though without imposing aggravated costs under Article 96 Italian Code of Civil Procedure due to the absence of bad faith on the part of the lawyer. A further notable example is the Court of Siracusa decision of 20 February 2026 (no. 338), in which the claimant cited four purported Supreme Court precedents to support its legal arguments. On examination, the court found that the quoted passages did not match any actual judgments: the cited authorities were either irrelevant to the matter or entirely fabricated. The court held that the uncritical use of generative AI tools without verifying outputs against primary sources constituted gross negligence, applying Article 96 Italian Code of Civil Procedure (aggravated procedural liability), ordering payment of about EUR15,000 to the opposing party and imposing a further EUR2,000 fine in favour of the Treasury (Cassa delle ammende).

Unauthorised Practice, Confidentiality and Ethics

Article 13 of the AI Law implicitly draws the boundary against unauthorised practice: AI may only perform support tasks, and the professional’s intellectual contribution must remain predominant. Client confidentiality (Article 13 of the Italian Bar Code of Conduct) and GDPR apply to cloud-based AI tools. The Italian ethical framework rests on three pillars:

  • human oversight (Article 13 AI Law);
  • mandatory prior disclosure to clients; and
  • continued application of existing ethical rules (competence, diligence, independence, confidentiality).

Lastly, the Ministry of Justice has established an Observatory on AI in judicial activity (D.M. 10 July 2024).

Italian Liability Framework for AI

Italian law applies several liability regimes to AI-caused harm. As mentioned, the new PLD (see 1.1 General Legal Background) explicitly covers software and AI and must be transposed into national law by December 2026. Fault-based liability under Article 2043 Civil Code requires proof of wrongful conduct, damage and causation, which may be challenging in case of a lack of transparency/asymmetry of information. There is debate whether strict liability provisions (Article 2050 for dangerous activities; Article 2051 for things in custody) could apply by analogy, but no settled approach has emerged. Vicarious liability (Article 2049) may extend to AI acting within deployment scope, although its application depends on qualifying the AI system within an organisational relationship comparable to that of an employee or agent. For AI-generated content liability, the DSA’s intermediary regime also applies to the extent AI systems or models are provided as intermediary services, but does not generally govern liability for all AI-generated outputs as such.

Evidentiary Challenges and Forthcoming Reforms

AI opacity makes it difficult to establish causation or identify defects. The revised PLD introduces disclosure mechanisms and burden-shifting where technical complexity makes proof excessively difficult. Critically, Article 24(5)(d) of the AI Law delegates to the government the task of regulating burden-of-proof allocation in AI civil liability cases, taking into account AI Act risk classifications - a distinctive Italian measure that may yield AI-specific procedural rules.

The question of liability for AI was initially expected to be harmonised EU-wide through the proposed 2022 Directive on non-contractual civil liability for AI (the AI Liability Directive). However, in February 2025, the European Commission withdrew the proposal due to the lack of foreseeable agreement among member states. The withdrawal followed a lack of political agreement among member states, alongside concerns from industry stakeholders that an additional liability regime could overlap with the AI Act and create unnecessary complexity. While the European Commission may consider a revised proposal or an alternative approach in the future, liability relating to AI needs, for now, to be addressed under existing legislation and general principles, as outlined in 10.1 General Theories of Liability.

Agentic AI systems are not yet subject to a dedicated Italian legal regime and are not recognised in Italy as legal persons capable of contracting or acting independently. Their governance relies on Italian civil law principles, EU digital regulation, and the AI Act.

Under Italian contract law (Civil Code, Arts. 1321 et seq.) and agency principles, AI actions can be attributed to the deploying principal as AI lacks legal personality, liability and contractual effects are assigned in principle to the deploying human or legal entity, based on risk allocation and controls. The AI Act introduces layered governance: for high-risk systems, it requires human oversight, ensuring monitoring, override or interruption of autonomous multi-step agentic processes, and mandates logging/traceability for auditability, reconstruction and ex post explainability in multi-agent environments. In regulated sectors (such as employment, credit scoring, critical infrastructure, law enforcement) such systems are typically high-risk, triggering conformity assessments, risk management, and strict data governance obligations.

Although multi-agent systems are not separately regulated, the AI Act’s provider–deployer allocation and lifecycle governance extend accountability across organisational boundaries, avoiding accountability gaps. From a public-law perspective, Italian administrative case law requires auditability and transparency of automated decision-making; this approach will most likely also inform multi-agent, cross-organisational accountability and escalation paths.

Liability Allocation in Italy

The AI Act distinguishes providers (primary responsible for design, testing, compliance) from deployers (responsible for use, human oversight, incident reporting). This regulatory allocation informs civil liability analysis, though the AI Act does not create private rights of action. In Italy, Article 14 of the AI Law reinforces human accountability: in public administration, the natural person remains solely responsible for administrative acts and decisions taken with AI support; a similar principle applies in the context of intellectual professions under Article 13. Existing strict liability provisions (Articles 2050-2051 Civil Code) may apply, though their adaptation to AI remains doctrinally unsettled and untested in court. For discussion of general liability theories, see 10.1 General Theories of Liability.

Evidentiary and Multi-Agent Challenges

AI opacity complicates causation proof; the AI Act’s logging requirements (Article 12) may partially assist. Article 24(5)(d) of the AI Law mandates government regulation of burden-of-proof allocation in AI liability cases. For multi-agent systems, joint and several liability principles may apply where cascading failures cause indivisible harm; the AI Act’s lifecycle governance provides a basis for accountability even in distributed architectures, although practical allocation among multiple actors remains likely to be highly fact-specific. For discussion of evidentiary challenges, see 10.1 General Theories of Liability.

Italian fairness obligations in AI are not defined through a single statutory concept of bias, but instead derive from a multilayered framework combining constitutional equality principles, administrative law constraints on automated decision-making, and, where personal data is processed, GDPR requirements of lawfulness, transparency, data minimisation, and safeguards.

In the public sector, these principles have been progressively shaped by case law. The Council of State (No. 2270 of 2019, see also 7.2 Judicial Decisions) recognised algorithmic tools for efficiency, with safeguards of intelligibility, accessibility, consistency with administrative discretion, and judicial review. The DPA operationalised algorithmic fairness through an accountability-based approach, requiring model reliability, reduced opacity, continuous testing, and corrective measures in case of discriminatory risks. This is reflected in sectoral guidance (eg, the “Decalogue” on AI in healthcare) and enforcement, including the 2024 Foodinho case on algorithmic scoring, human intervention and contestation of automated decisions.

Against this background, the AI Act introduces a harmonised framework for high-risk systems, requiring risk management, data governance, and training data quality controls to mitigate discriminatory outcomes, framing bias as systemic distortions in data or outputs causing unequal treatment. Bias mitigation is partly anticipatory under the AI Act but grounded in GDPR accountability. Liability rests on a combination of civil law, sectoral anti-discrimination rules, and GDPR enforcement, alongside algorithmic impact assessments, auditing, and explainability aligned with EU ethical guidelines and ISO/IEC standards.

Enforcement will intensify significantly under the AI Act, with enhanced supervisory powers and significant sanctions for systemic bias or unfair automated decision-making.

Biometric AI systems in Italy are governed mainly by the GDPR, as supplemented by the Italian Privacy Code and DPA guidance. Biometric data for unique identification qualifies as under “special categories of personal data” under Article 9 GDPR, and is subject to a general prohibition on processing unless a strict exception applies, such as explicit consent or substantial public interest. The DPA has historically adopted a restrictive stance, often suspending or limiting public surveillance deployments and treating facial recognition as a particularly high-risk use case. Such systems require a legal basis, together with strict necessity and proportionality assessment, and strong safeguards. Enforcement practice, including the DPA’s Clearview AI (2022) and Municipality of Trento (2024) cases, confirms heightened scrutiny of biometric and AI surveillance, focusing on unlawful scraping, DPIAs, transparency, and processing of sensitive or criminal data.

Consent remains a fragile legal basis for biometric processing, particularly in employment or public services due to power imbalance, therefore compliance typically relies on legal obligation or public interest, supported by strong technical and organisational safeguards. Accuracy and bias risks must be managed through testing, validation, and meaningful human oversight to meet GDPR accuracy and accountability requirements, particularly where outputs affect legal or similarly significant decisions.

The EU AI Act adds a risk-based regime for biometrics, defining emotion recognition and biometric categorisation systems, prohibiting certain intrusive uses (including in workplaces and education), and restricting sensitive attribute interference. Remote biometric identification is high risk and subject to strict requirements, including a general ban on real-time use in publicly accessible spaces for law enforcement, subject to limited exceptions.

Italian Framework for Deepfakes and Synthetic Media

The AI Act (Article 50) requires disclosure of AI-generated or manipulated content through machine-readable marking; the DSA imposes notice-and-action obligations on platforms hosting illegal deepfakes. In Italy, Article 26 of the AI Law introduces a new criminal offence (Article 612-quater Criminal Code): disseminating-without consent-AI-falsified images, videos or voices apt to deceive is punishable by one to five years’ imprisonment. An aggravating circumstance (Article 61, para. 11-undecies) applies when AI is used as an insidious means (see 1.1 General Legal Background for criminal law provisions). Pre-existing protections remain relevant: Article 10 Civil Code (right to image), Articles 96-97 LDA (portrait consent), and defamation/privacy remedies extend by analogy to deepfakes. For transparency requirements under the AI Act, see 12.4 Transparency and Disclosure.

Pending Legislation: Bill 1644

Bill 1644, inspired by Denmark’s 2024 law, proposes comprehensive identity protection:

  • an exclusive right over name, image, voice and facial expression (Article 1);
  • prohibition of AI reproduction without explicit consent - even for satire if dignity is harmed (Article 2);
  • presumption of harm (Article 3);
  • mandatory disclosure of synthetic content and platform rapid-blocking mechanisms (Article 4); and
  • penalties of EUR10,000-100,000 plus imprisonment (six months to three years) for violations, extending to providers of deepfake tools lacking traceability (Article 6).

For discussion of other pending AI legislation, see 3.7 Proposed AI-Specific Legislation and Regulations.

The AI Act imposes disclosure obligations at multiple levels.

  • Article 50 requires deployers to inform individuals when they interact with AI systems (chatbot disclosure) and to label AI-generated or manipulated synthetic content (see 12.3 Deepfakes and Synthetic Media for deepfake-specific rules).
  • Article 50(3) mandates that emotion-recognition and biometric-categorisation systems inform affected individuals (see 12.2 Biometric Technologies and Emotion Recognition).
  • Article 53 requires providers of GPAI models to publish a sufficiently detailed summary of training data and adopt copyright-compliance policies.

Against this backdrop, the AI Law implements complementary national requirements: Article 3 mandates transparency, explainability and human oversight in AI systems; Article 4 requires clear, simple communications on data processing and AI-related risks; Article 13 obliges professionals using AI to inform clients in clear language; Article 14 requires public administrations to ensure traceability and intelligibility of AI use; and Article 7(3) grants patients in healthcare a right to be informed about AI deployment.

In this context, the AGCM’s December 2025 DeepSeek decision illustrates an early enforcement example: the Authority required Italian-language disclaimers warning of hallucination risks in chatbot interfaces, registration pages and sensitive-topic outputs, establishing a practical benchmark for AI disclosure in consumer-facing applications. For details on this decision, see 4.1 Precedent-Setting Judicial Decisions.

In Italy, Article 5(d) of the AI Law directs public e-procurement platforms to favour AI solutions that guarantee data localisation and processing in domestic data centres and implement disaster recovery and business continuity in national facilities, thereby embedding data-sovereignty criteria into public-sector AI contracting. For public administrations, the AgID draft Procurement Guidelines provide a detailed operational framework, framed within the Public Contracts Code and NIS2/cybersecurity obligations.

Consistent with the EU AI Act’s value-chain approach (Articles 25-26), in Italy the AgID draft Procurement Guidelines reinforce these concepts with specific requirements for public-sector AI acquisitions, like:

  • traceability of data flows and model changes throughout the contract lifecycle;
  • clauses ensuring the PA retains effective control over the system and the ability to intervene in case of criticalities;
  • continuous monitoring of supplier compliance; and
  • planning for transition/dismissal to preserve data restitution and operational continuity.

These guidelines also emphasise that risk assessment must cover technological, organisational, economic and reputational dimensions.

Article 11 of the AI Law provides that AI must be deployed to improve working conditions, protect workers' psychophysical integrity, and enhance both productivity and quality of work, in conformity with EU law. The use of AI in the workplace must be safe, reliable, transparent, and must not conflict with human dignity or violate personal data privacy. Employers or principals are required to inform workers about the use of AI in accordance with Article 1-bis of Legislative Decree No. 152/1997. Furthermore, Article 11 mandates that AI in employment contexts must guarantee respect for workers' inviolable rights without discrimination based on sex, age, ethnic origin, religious beliefs, sexual orientation, political opinions, or personal, social and economic conditions. For background law on employment, see 1.1 General Legal Background.

Legislative Decree No. 104/2022 (Transparency Decree) imposes on employers a duty to inform employees about the use of automated decision-making systems that significantly affect working conditions, hiring, task allocation, or termination.

Article 12 of the AI Law establishes the Observatory on the Adoption of Artificial Intelligence Systems in the World of Work within the Ministry of Labour and Social Policies. The Observatory is tasked with defining a strategy for AI use in the workplace, monitoring its impact on the labour market, identifying sectors most affected by AI, and promoting training for both workers and employers on artificial intelligence matters.

Case law wise, Italian courts had, in fact, already addressed algorithmic management in the context of platform work; notably, the Court of Bologna (31 December 2020) found Deliveroo’s algorithm indirectly discriminatory, as it penalised riders absent from shifts regardless of whether the absence was due to strike action or illness.

Historically, Article 4 of Law No. 300/1970 (Workers’ Statute) prohibits remote monitoring of workers, requiring prior agreement with trade unions or authorisation from the labour inspectorate before deploying surveillance or control systems which may also indirectly or potentially trigger remote control (see 1.1 General Legal Background). The AI Law reinforces these protections with Articles 11-12 as well as Ministerial Decree No. 180/2025 as outlined above.

Pursuant to Recital 118 AI Act, insofar as AI systems or models are embedded into designated very large online platforms (VLOPs) or very large online search engines (VLOSEs), they are subject to the risk-management framework provided in the DSA. Consequently, the corresponding obligations of the AI Act should be presumed to be fulfilled, unless significant systemic risks not covered by the DSA emerge and are identified.

Furthermore, according to Recital 119 AI Act, AI systems may be provided as intermediary services or part thereof that fall under the scope of the DSA, for example to provide online search engines.

Article 15 of Law-Decree No. 123 of 15 September 2023 (converted into Law No. 159 of 13 November 2023) has designated AGCOM as the national digital service coordinator under Article 49 DSA.

To date, no enforcement action has been publicly announced or undertaken by AGCOM concerning the obligations under the DSA with respect to AI systems or models integrated into VLOPs or VLOSEs or provided as intermediary services or part thereof. At EU level, the Commission has recently announced that it will assess the possible designation of ChatGPT online search functionality under the DSA.

AI Governance and the TUF Reform

Italy has recently enacted Legislative Decree No. 47 of 27 March 2026 (the TUF Reform Decree), in force since 29 April 2026, which introduces for the first time within the Consolidated Financial Act (Testo Unico della Finanza, TUF) the explicit definitions of (i) artificial intelligence systems (by reference to Article 3(1) of the AI Act), and (ii) IT risks – ie, any reasonably identifiable circumstance relating to the use of IT and network systems which, if materialised, could compromise the security of such systems, any dependent tools or processes, operations and processes, or the provision of services, causing adverse effects in the digital or physical environment.

Furthermore, the TUF Reform Decree amends Article 123-bis of the TUF (governing the corporate governance report) by requiring listed companies to disclose: (i) where adopted, a description of the company’s policies on the use and monitoring of new technologies, in particular AI systems, within administrative, organisational and accounting structures; and (ii) where adopted, a description of the policies for managing and monitoring IT risks, including cybersecurity risks and risks arising from the integration of new technologies into administrative, organisational and accounting structures.

AI-Driven Credit Decision Making

Legislative Decree No. 212/2025 of 31 December 2025, implementing the Consumer Credit Directive 2 (Directive (EU) 2023/2225), introduced within the Consolidated Banking Act (Testo Unico Bancario, TUB) new rules for AI-driven credit decisions. Where a creditworthiness assessment relies, even partially, on automated data processing, the consumer has the right to: obtain a clear explanation of the assessment logic and its effects on the decision; express their opinion to the lender; and request a review with human intervention.

The lender must inform the consumer of these rights before initiating the automated processing of their personal data for creditworthiness purposes. These rights complement the protections under GDPR (see 17 Data Protection) and the AI Act's high-risk classification of credit scoring systems.

Regulatory Expectations

In April 2026, the Bank of Italy’s Senior Deputy Governor, during a speech presenting the joint OECD/Bank of Italy report on “AI in Italian Financial Markets”, outlined three priority areas:

  • strengthening AI governance (with boards taking direct ownership of AI strategies and risk frameworks);
  • integrating AI-specific scenarios into operational resilience testing under the DORA framework; and
  • moving from experimentation to structured integration of AI into business processes.

Particular emphasis was placed on managing third-party dependencies, which can propagate risk across the system in ways that are difficult to detect.

No information has been provided in this jurisdiction.

No information has been provided in this jurisdiction.

No information has been provided in this jurisdiction.

No information has been provided in this jurisdiction.

The Italian AI Law and Amendments to the Copyright Act

Italy is the first EU member state to adopt a comprehensive national AI law. Article 25 of the AI Law amended the LDA (Article 1) to expressly require that protected works be works of “human” creation, while clarifying that works created with the assistance of AI tools may be protected “provided they constitute the result of the author’s intellectual work”. The new Article 70-septies LDA confirms that the TDM exceptions (Articles 70-ter and 70-quater) apply to text and data extraction through AI models, including generative AI (see 3.6 Data, Information or Content Laws for detailed TDM analysis).

Patent and Copyright Protection

Under Italian and European patent law, AI algorithms are excluded from patentability as such, but technical applications producing concrete technical effects may qualify. Software code implementing AI systems may be protected as a literary work under the LDA, provided it meets the originality threshold. Datasets may benefit from sui generis database protection (Articles 102-bis and 102-ter LDA). Trade secrets protection for model weights and training methodologies is also available under Articles 98-99 CPI.

Human Authorship Requirement under Italian Law

Under Italian law, neither patent nor copyright systems recognise AI as a legal subject. The CPI requires inventors to be natural persons; the LDA attributes authorship exclusively to natural persons. The AI Law codified this by amending Article 1 LDA to require that protected works be works of “human” ingenuity (see 1.1 General Legal Background for the legislative framework). At the same time, Article 1 now expressly provides that works created with AI assistance may be protected “provided they constitute the result of the author’s intellectual work”. To this end, factors such as iterative prompt refinement, output selection and substantial post-editing may establish the requisite human contribution. Works generated entirely by AI without qualifying human contribution fall outside copyright and moral rights protection.

Italian Case Law

No Italian case law has yet interpreted the AI Law’s new human authorship requirement, given its recent entry into force (October 2025). However, prior case law on algorithmically generated works offers relevant guidance. In Cass. civ. Sez. I, 16 January 2023, No. 1107, the Supreme Court considered a fractal image created using mathematical software - not AI in the contemporary sense, but an automated process. The Court declared the ground inadmissible as a new issue raised for the first time in cassation. However, it noted that the use of software to generate an image is “compatible with the elaboration of a work of authorship with a degree of creativity that would only need to be scrutinised with greater rigour” and that “a factual assessment would have been necessary to verify whether and to what extent the use of the tool had absorbed the creative elaboration of the artist who used it.” This reasoning suggests Italian courts will focus on whether the human exercised sufficient creative control over the automated process, rather than categorically excluding software-assisted works (see also 4.1 Precedent-Setting Judicial Decisions for pending litigation on AI training, RTI/Medusa v Perplexity).

Copyright Infringement and TDM Exceptions under Italian Law

Training AI models on copyrighted works might involve acts of reproduction within the meaning of Article 2 InfoSoc Directive. Italy transposed the TDM exceptions through Articles 70-ter (research organisations) and 70-quater (commercial use, subject to opt-out) LDA. The new Article 70-septies, introduced by the AI Law, expressly confirms that reproductions and extractions for TDM through AI models, including generative AI, are permitted in accordance with Articles 70-ter and 70-quater, subject to the Berne Convention (see 3.6 Data, Information or Content Laws for the opt-out mechanism analysis). As mentioned above, Italian law leaves the choice of technical mechanism to rightholders, creating uncertainty about what constitutes a valid and enforceable opt-out. The GPAI Code of Practice might fill this gap by endorsing protocols “already consolidated in web crawling practice”, but its voluntary nature and “best efforts” clauses have drawn criticism as insufficiently binding.

On the other side, the key concern remains the absence of independent verification that AI developers effectively exclude opted-out content. This is compounded by: (i) the limited granularity of transparency obligations under Article 53 AI Act, which requires only a “sufficiently detailed summary” of training data rather than work-by-work disclosure; and (ii) the lack of formal requirements for exercising the opt-out in Italian law.

Licensing and Collective Management

While at global level commercial AI developers are increasingly entering licensing agreements with content owners and Collective Management Organisations (CMOs), who are exploring collective licensing mechanisms. At the time of writing there is only one notable case in the Italian landscape: Musixmatch, an Italian-based lyrics and music data company, entered AI licensing agreements with three major music publishers (Sony Music Publishing, Universal Music Publishing Group, and Warner Chappell Music) gaining access to catalogues of over 15 million musical works to develop analytical and non-generative AI services, with compensation flowing to publishers and songwriters (2025).

No Italian CMO has, at the time of writing, publicly announced it concluded a formal licensing agreement for AI training. However, several have taken preparatory steps. SIAE (the main authors and publishers’ CMO) has exercised a collective opt-out from TDM, reserving reproduction rights for its entire repertoire, and has amended its standard licences to expressly exclude TDM/AI training uses. SCF (neighbouring rights for major labels) has revised its mandate agreement to exclude AI-generated recordings from protection and is reassessing policies in light of the majors’ deals with AI platforms (Udio, Suno). Industry associations (FIEG, for newspaper publishers, and AIE, book publishers) have advocated for simplified opt-out mechanisms, shared licensing models, fair compensation, and declared insertion of explicit TDM/AI reservation clauses in their publications. Other performers’ CMOs (Nuovo IMAIE, LEA, Itsright) have not yet publicly adopted specific measures.

AI-Related IP Litigation in Italy

The only IP/copyright litigation brought in Italy at the time of writing and concerning the use of protected works for AI training is RTI SpA and Medusa Film SpA v Perplexity AI Inc., filed on 3 December 2025 before the Civil Court of Rome. The claimants allege that Perplexity scraped and reproduced their audiovisual content without authorisation to train its “Sonar” LLM, invoking Articles 1, 2, 45, and 78-ter LDA as well as the three-step test under the Berne Convention, and seek injunctive relief and damages (see 4.1 Precedent-Setting Judicial Decisions for further discussion).

AI-Generated Works Under Italian Copyright Law

Under Italian and EU copyright law, works generated entirely by AI without meaningful human creative input do not qualify for protection. The AI Law codified this by amending Article 1 LDA to require “human” ingenuity (see 16.1 IP Protection for AI Assets).

Human-AI Collaborative Works and Ownership

Where humans interact meaningfully with AI – eg, through iterative prompt refinement, output selection, substantial editing or integration with original content - the resulting work may qualify for protection. As discussed in 16.2 AI as Inventor/Author, the AI Law amended the LDA to permit protection for AI-assisted works “provided they constitute the result of the author’s intellectual work”. Ownership vests in the natural person who made the qualifying creative contribution.

Moral Rights

For AI-assisted works qualifying for protection, the human author retains moral rights under Italian law, including the right of attribution and integrity (Articles 20-24 LDA). These rights are personal and inalienable. Works generated entirely by AI without qualifying human contribution fall outside moral rights protection, as there is no author in whom such rights could vest.

Italian law does not contain specific provisions on foundation models, open-source AI licensing, derivative works, fine-tuning rights, or model merging/distillation. The applicable framework is the EU AI Act: Article 2(12) which exempts AI systems released under free and open-source licences from certain obligations (unless high-risk), and Article 53(2) which grants GPAI providers transparency exemptions where model parameters, architecture and usage information are publicly available. GPAI models with systemic risks remain fully regulated regardless of licensing model.

Personal data processing for AI training under Italian law requires strict compliance with GDPR and the Italian Privacy Code.

Lawful basis remains a critical issue. The DPA’s ChatGPT orders (March–April 2023) confirmed that large-scale data collection for training must rely on a valid legal basis, while later scrutiny of GEDI Gruppo Editoriale data-sharing with a major LLM provider has cast doubt on the suitability of legitimate interests in this context. A more specific framework has emerged under Article 8 of the AI Law, which recognises certain AI-driven scientific research in healthcare as a substantial public interest task under Article 9(2)(g) GDPR, subject to conditions such as non-identifiability and prior DPA notification.

Purpose limitation and data minimisation are also key constraints. The DPA’s 2025 decision fining Menarini Silicon Biosystems SpA identified, inter alia, unclear purposes and retention periods in AI health-data training. Similarly, the 2024 warning to GEDI emphasised that data subjects could not reasonably expect journalistic archive data to be repurposed for AI training.

On data minimisation, the Italian tax administration’s approach (exclusion of data falling under Articles 9 and 10 GDPR from automated risk analysis) remains a benchmark.

Data subject rights (including access, erasure and objection) remain fully applicable, albeit difficult to operationalise in trained models. In the ChatGPT case, the DPA required mechanisms for correction or deletion of outputs as a condition for lifting its temporary ban.

Processing of special category data is generally prohibited absent specific derogations. In a 2024 decision against the Municipality of Trento, the DPA sanctioned AI surveillance involving Articles 9 and 10 GDPR data without adequate legal bases and sufficient anonymisation safeguards. 

Anonymisation and pseudonymisation are strictly interpreted by the Italian DPA; ineffective techniques may still trigger GDPR applicability, as shown in the 2023 Thin Srl case, where allegedly anonymised health data remained identifiable. The 2023 “Decalogue” on AI in healthcare further stresses data accuracy, robustness of anonymisation, and documentation of training metrics and data quality assessments.

Finally, accountability requires documentation, bias monitoring and privacy-by-design, reinforced by the AI Law and DPA guidance, including the AI healthcare Decalogue and 2024 web scraping guidance.

AI deployment in Italy is governed by a layered framework (inclusive of the GDPR, the Italian Privacy Code, and the AI Law) imposing strict requirements on lawful bases, transparency, and data subject rights.

Italian DPA enforcement shows that each personal data processing by AI must rely on a clearly identified legal basis. In the 2023-2025 Replika chatbot case, the DPA challenged the controller’s reliance on contractual necessity, including as regards the processing of children’s data. Similarly, in its 2024 warning to GEDI Gruppo Editoriale, the DPA scrutinised the use of legitimate interests for the transfer of personal data to an LLM provider, finding that insufficient transparency and unclear role allocation undermined the asserted legal basis.

Transparency is a central enforcement focus in AI-driven processing and has been repeatedly addressed in DPA enforcement actions, including those concerning Menarini Silicon Biosystems SpA, Replika, and the 2024 Foodinho case.

Data subject rights are also strongly protected. In particular, the DPA has consistently stressed the right to obtain human intervention and to contest automated decisions. In the 2024 Foodinho decision, the DPA found that two algorithmic systems had been deployed without implementing GDPR safeguards for automated decision-making, including riders’ rights to human intervention, to express their point of view, and to challenge algorithmic outcomes. The Italian Supreme Court of Cassation (Judgment No. 28358 of 10 October 2023) further clarified that, for consent to be valid, the underlying algorithm must be described in an intelligible manner.

Children’s data is subject to enhanced safeguards under the AI Law, which requires parental consent for access to AI technologies or related processing by children under 14, and clear, accessible information for older minors. Enforcement actions, including the Replika case, addressed the absence of effective age-verification mechanisms and risks posed to minors by AI chatbots.

Finally, data retention in AI systems is under increasing scrutiny, with recent decisions (including Menarini Silicon Biosystems and Replika) criticising unclear retention periods and requiring greater transparency on storage practices and data transfers in AI contexts.

Italian data governance requirements for AI systems are shaped also by GDPR, the Italian Privacy Code, DPA guidance, and the AI Law.

Data protection impact assessments under Article 35 GDPR are typically a key requirement for AI processing, consistently emphasised by the DPA, including in its Decalogue for AI in healthcare, the 2024 Municipality of Trento decision, and Opinion No. 276/2022 on the tax administration’s use of ML for risk assessment.

The principle of data protection by design and by default is equally fundamental; it has been repeatedly addressed by the DPA (including in the Decalogue and the 2024 web scraping guidance), and further strengthened by the AI Law requiring data quality, security, transparency, and ongoing, proportionate monitoring.

Controller-processor relationships in AI supply chains are particularly critical, requiring clear allocation of roles and responsibilities, robust due diligence, and auditable oversight of providers. In this respect, the DPA’s 2024 warning to GEDI Gruppo Editoriale highlighted risks of unclear processing roles and ineffective data subject rights where an LLM provider acts as an independent controller.

Finally, cross-border data transfers for AI training and deployment must comply with GDPR Chapter V and EDPB guidance. The 2022 Clearview AI decision confirms that large-scale web scraping cannot circumvent EU transfer rules. The 2025 Replika decision required clarification of international transfers in privacy policies, reflecting scrutiny of transfers of Italian users’ personal data to countries lacking an adequate level of protection.

In July 2025, AGCM opened proceedings against Meta concerning the integration of Meta AI into WhatsApp (Case A576). The investigation was expanded in November 2025 to address WhatsApp’s new Business Solution Terms barring rival AI chatbot providers from the platform. In December 2025, AGCM adopted interim measures ordering Meta to suspend the contested policy. The authority expressed concerns that control over a dominant messaging platform could be leveraged to exclude AI competitors, representing one of Italy’s first formal antitrust investigations at the intersection of AI services and platform dominance. The European Commission subsequently opened parallel proceedings on the same conduct.

Also in December, AGCM closed proceedings against DeepSeek (Case PS12942), accepting commitments from the Chinese platform. Though formally a consumer protection matter (see 4.1 Precedent-Setting Judicial Decisions for details), this illustrates the authority’s willingness to scrutinise AI service providers. The proceeding addressed LLM hallucinations and resulted in commitments requiring enhanced user disclosure of AI output limitations, demonstrating how existing unfair commercial practice rules under the Consumer Code can effectively regulate AI services.

Cybersecurity requirements applicable to AI systems stem primarily from EU and national frameworks, rather than AI-specific legislation. Key instruments include the NIS2 Directive (Directive (EU) 2022/2555), the National Cybersecurity Perimeter regime (Decree-Law No. 105/2019), and ACN technical guidance. AI systems are not regulated as a standalone category but fall within broader network and information systems used by essential and important entities. Although AI-specific threats are not expressly regulated in Italy, they are indirectly covered by NIS2 obligations requiring the implementation of proportionate technical and organisational measures to manage cybersecurity risks and incident reporting. Such obligations apply where incidents significantly impact service continuity or integrity, and must be notified to competent authorities and CSIRT Italia within the statutory deadlines, regardless of AI use. 

NIS2 also expressly addresses supply chain security, requiring risk assessments and management of suppliers and ICT/AI-related third parties, including cloud and software providers, through appropriate contractual, technical and organisational safeguards to ensure resilience. It further covers vulnerability management and disclosure, also relevant to AI tools.

Finally, AI use in cybersecurity defence is not specifically regulated but permitted, provided compliance with cybersecurity, data protection, and accountability requirements, including appropriate governance, oversight, and auditability.

In Italy, the ESG dimensions of AI are addressed through the AI Law and related soft-law instruments, encompassing environmental sustainability, non-discrimination, and governance principles.

Article 3 of the AI Law includes sustainability among core principles. The AgID draft Guidelines for AI Development in PA require energy efficiency, computational proportionality, and sustainability criteria across the AI stack. Article 3 also enshrines non-discrimination, transparency, explainability, and human oversight. Article 11 mandates that workplace AI be safe, transparent, protect worker dignity, ensure human oversight, and prohibit discrimination (see 14 Employment). Article 12 establishes the Observatory on AI in the Workplace.

In Italy, AI governance frameworks are shaped by the interplay between the AI Act and national implementing legislation. The AI Law designates ACN and AgID as the competent authorities responsible for AI oversight (see 5.1 Regulatory Agencies), while sector-specific regulators (Bank of Italy, CONSOB, IVASS) retain market surveillance powers for financial services AI. The AgID Guidelines on AI Development and Procurement (though still a draft, see 3.3 Jurisdictional Directives) will provide operational guidance for public administrations, requiring risk management systems, fundamental rights impact assessments (FRIAs), human oversight mechanisms, and transparent documentation throughout the AI lifecycle. For certain deployers of high-risk AI systems (eg, in financial and insurance services), Article 27 of the AI Act mandates FRIAs, which can be integrated with existing GDPR Data Protection Impact Assessments.

Chiomenti

Via Giuseppe Verdi 4
20121
Milano
Italy

+39 02 72157 1

chiomenti.net
Author Business Card

Trends and Developments


Authors



Chiomenti is an independent law firm of approximately 450 professionals with offices in Rome, Milan, London, Brussels and New York. Over 75 years of activity, Chiomenti has developed an extensive network of international relationships and provides its clients with the services and advice of over 450 professionals whose experience and expertise cover multiple economic sectors and geographic areas. Chiomenti has structured its services and assistance in practice areas with a particular focus on transactions and matters of importance and special relevance for its clients, putting its independence and legal expertise at the disposal of companies and institutions, and successfully innovating its leadership at the top of the legal services market. Assistance is carried out in full integration with the different professional areas in which the firm is divided, in order to address and manage various profiles of interest in transactions with a multidisciplinary and integrated approach, focusing on collaboration, internationality and technological innovation as factors of acceleration in its leadership.

Generative AI and Copyright: Who Owns the Output?

Companies Called Upon to Reorganise Their Creative Processes

The Italian and European Landscape at a Turning Point

Introduction: a simple question; an answer still up in the air

When a creative agency uses Midjourney to generate images for an advertising campaign, or when an architectural firm uses AI to develop the visual concepts for a project, the question is always the same: who owns what the AI has produced? And furthermore, can what has been generated be protected?

The answer, in 2026, is not yet definitive. But the direction that European case law is taking is clear, and Italy – with a comprehensive AI law approved first in the entire European Union – offers a privileged vantage point on how the law is gearing up to respond.

This article focuses on a specific issue of great practical relevance for anyone using generative AI tools in a professional or commercial context: the protectability of the output – that is, the possibility of claiming intellectual property rights over content like text, images, code, or music produced by generative artificial intelligence systems.

The picture that emerges is one of a market that has moved much faster than the law, and of a legal system that is catching up, albeit by resorting to conceptual categories that predate the advent of generative AI by decades.

The Italian context: an accelerating market; a regulatory leadership to be consolidated

Before addressing the legal issues in detail, it is useful to understand the scale of the phenomenon in the Italian market, as this is the context in which intellectual property issues will arise with increasing frequency.

According to the report ‘Italy in the Age of AI’, presented to the Chamber of Deputies in March 2026 by Luciano Floridi on behalf of the Leonardo ETS Foundation – the first systematic mapping of the Italian AI ecosystem – the national artificial intelligence market reached EUR1.2 billion in 2024, representing 58% growth compared to the previous year. Adoption in companies with at least ten employees doubled in a year, rising from 8.2% to 16.4%. In large enterprises, the adoption rate reached 53.1%.

These figures, whilst significant, nevertheless conceal a structural gap: SMEs, which form the backbone of Italian industry, have an adoption rate of just 15.7%, well below the European average. Furthermore, only 19.9% of Italian citizens used generative AI tools in 2025, among the lowest figures in the EU.

The regulatory data, however, is of greatest interest to an international legal audience: with Law No. 132 of 23 September 2025, which came into force on 10 October 2025, Italy became the first Member State of the European Union to adopt a comprehensive framework on artificial intelligence, effectively anticipating the application of the European AI Act. This is a first that has political and symbolic value, but which, as remains to be seen, still awaits the implementation phase to translate into legal certainty.

Law 132/2025: what it says about AI outputs

The Italian AI law is a framework law: it establishes principles, identifies authorities, and delegates to the government the adoption of implementing decrees within 12 months. It does not resolve the thorniest issues, but it points the way forward.

On the issue of interest here – the protectability of output – the most relevant text is contained in Chapter IV, which amends the Copyright Act (Law 633/1941) by extending protection to works of human ingenuity ‘even where created with the aid of artificial intelligence tools, provided they constitute the result of the author’s intellectual work’.

The Italian legislature’s choice is therefore clear in its theoretical approach: AI is a tool, and does not in itself possess authorial capacity. The work is eligible for protection if and to the extent that it reflects the intellectual work of a human author. What matters is not the means by which the work was produced, but the presence of an identifiable human creative contribution.

This approach is consistent with Italian and European legal tradition, and is precisely the criterion that European courts are applying to AI-generated content in their first rulings on the subject.

However, crucial questions remain open: the implementing decrees, at the time of writing, have not yet been issued. The law itself delegates to the government the task of regulating ‘cases of unlawful creation and use of AI systems’ and of bringing national legislation into line with the AI Act. Until these decrees are enacted, the legal certainty promised by the law remains partly unfulfilled.

The foundations: Italian and European doctrine on creative contribution

To understand how the courts are addressing the issue of the protectability of AI output, it is essential to start with the established doctrine and case law on copyright that predates the advent of generative AI by a considerable margin. The same standards that case law has developed over the decades for every other category of work apply to AI output.

The European framework: CJEU doctrine

Since 2009, the Court of Justice of the European Union (CJEU) has established a uniform standard of originality applicable to all categories of works, known as ‘own intellectual creation’ – ‘the author’s own intellectual creation’.

The starting point is the Infopaq judgment (C-5/08, 2009), in which the CJEU extended to all works within the meaning of the InfoSoc Directive the standard of originality previously harmonised only for software, databases and photographs. The principle: a work is original if it is the result of the author’s ‘free and creative choices’, through which they imprint their own ‘personal touch’.

The Painer judgment (C-145/10, 2011) is particularly significant for the topic of AI because it concerned photographic portraits – ie, images produced with the aid of a machine. The CJEU ruled that the photographer must be able to make ‘free and creative choices in various ways and at various stages of production’ – during the preparatory phase, at the moment the photograph is taken, and in the final selection. The use of a camera does not preclude protection, but it does not guarantee it: what matters is the creative freedom exercised by the human author.

In the Football Dataco case (C-604/10, 2012), the CJEU definitively closed the door on the Anglo-Saxon ‘skill and labour’ doctrine: investment and effort, on their own, are not sufficient. The European standard requires a ‘creative’ element distinct from mere technical effort. As we shall see, this aspect is fundamental when discussing the protectability of the output of generative AI.

The established principle can be summarised as follows: a work is protectable if, and only if, it reflects the personality of its author through free and creative choices; where technical constraints, rules or other influences leave no room for creative freedom, the necessary originality is lacking.

The Italian context: the Court of Cassation

The case law of the Italian Court of Cassation has developed, independently but in line with European case law, its own doctrine on creative contribution, with certain specific characteristics.

The key principle has been established for decades and was most recently reaffirmed in Order No. 1107/2023: copyright protection requires originality and creativity, ‘consisting not in the idea underlying its creation, but in the form of its expression, provided that the work reflects the personality of its author, manifesting their free and creative choices’.

A fundamental corollary of the Italian approach is the minimum threshold of creativity: creativity cannot be ruled out merely because the work consists of simple ideas and concepts that are already part of the common intellectual heritage. As the Court of Cassation stated in judgment no. 22118/2015, ‘minimal creativity and modest artistic value’ are sufficient. The threshold is low – but it must nevertheless involve a human and personal contribution.

Case law has further clarified this concept in specific sectors. The Court of Florence, for example, in the field of architecture, has stated that ‘where the creation of the work is determined by the rigid application of rules, constraints or technical concepts, without any scope for the author’s creative freedom, then the requirement of creativity is not met’. This is a formula which recurs when discussing the issues raised by generative AI.

Case law on AI output: European judgments and a Chinese case

The global landscape: a negative consensus with one exception

Before examining the European judgments, it is useful to outline the global picture. To date, there is no decision in any Western or European jurisdiction that recognises AI output as a work protected by copyright. In the United States, the principle of human authorship has been reaffirmed at the highest levels: in March 2026, the Supreme Court denied certiorari in the case of Thaler v Perlmutter, upholding the decision of the US Court of Appeals for the District of Columbia Circuit which excludes the copyrightability of works created autonomously by AI. The US Copyright Office is equally firm: no protection for purely AI-generated output. The point, however, is what is meant by ‘AI-generated’.

The only global exception comes from China. On 27 November 2023, the Beijing Court recognised copyright protection for an image generated using Stable Diffusion in the case of Li Yunkai v Liu Yuanchun. The claimant had selected over 150 prompts, arranged them in order and set specific parameters, continuing to make adjustments until the final result was achieved. The Court held that this intellectual investment in the prompting process was sufficient to reflect the claimant’s ‘personalised expression’, attributing authorship of the work to him.

The Chinese decision stands alone and is not without its critics. Nor is the approach consistent in subsequent Chinese case law. It remains, however, the only precedent in the world in which a court has answered in the affirmative to the question: can AI output be a work protected by copyright?

The three European judgments

In Europe, the line of case law on the copyrightability of AI output currently comprises three decisions on the merits, all dating from after 2024 and all leaning towards a negative conclusion, albeit with significant nuances and openings.

First judgment: Prague Municipal Court (2024)S.Š. v Taubel Legal, case no. 13/2023

This is the first European ruling ever on the subject. The claimant had generated an image using DALL-E with a simple prompt (‘create a visual representation of two parties signing a commercial contract in a law firm in Prague, show only the hands’), published it on their website, and found it being used without consent by a rival law firm.

The Prague Court denied protection: an AI-generated image cannot, in principle, be protected by copyright as it is not the result of the creative activity of a natural person. The prompt itself, the Court added, can be equated with a theme or an idea, neither of which is protectable.

But the door has not been closed entirely: the Court suggested that, had the instructions provided to the AI tool demonstrated ‘the originality of the human author’, the outcome might have been different.

Second judgment: Amtsgericht München – Munich District Court (13 February 2026)Case No. 142 C 9786/25

This judgment directly addresses the issue of elaborate prompting: the claimant had created three logos using a text-to-image AI system, and argued that his iterative and detailed prompting – including a 1,700-character instruction for a single logo – constituted a ‘personal intellectual creation’ within the meaning of Section 2(2) of German copyright law. The unauthorised use of the logos by a third party had prompted the claimant to take legal action to seek a declaration of copyright infringement.

The Court dismissed the appeal, denying copyright protection to all three images. The key principle: copyright protection depends on whether the final output objectively reflects the personality of the human creator and their free creative choices. Even an extensive 1,700-character prompt proved insufficient, because the human input did not demonstrably determine the specific expressive elements of the final design. The length of the prompt is not enough: what matters is whether the process involved free creative choices regarding the expressive elements, not merely descriptive or technical instructions.

Third ruling: OLG Düsseldorf – Düsseldorf Court of Appeal (2 April 2026) Case No. I-20 W 2/26

The most recent judgment is probably the most significant. A photographer specialising in underwater photographs of dogs had discovered that a former collaborator had uploaded one of her photos into AI software, generated a derivative image and published it on their own website. She had sought an injunction; the Landgericht had dismissed it; she had appealed.

The Higher Regional Court of Düsseldorf upheld the rejection, but – and this is the most interesting aspect of the judgment – it corrected the legal reasoning of the lower court, developing its argument on two distinct levels.

On the first level – the protectability of the AI-generated image – the OLG clarified that protection is theoretically possible if the output reflects the human author’s personality through free creative choices. Such choices may manifest themselves through individual settings in the programming of the generative process, an iterative process of selection among generated variants, or subsequent interventions on the output. The decisive factor is that the prompting expresses the author’s creative abilities through free and specific choices regarding the visual elements – not merely generic instructions, even if numerous. Anyone wishing to claim protection bears the burden of documenting and demonstrating in concrete terms which creative decisions they have made. In the specific case, the defendant – who had invoked the nature of the AI image as a derivative work – had provided no indication of their own creative choices, and the Court denied the work’s protected status.

On the second point – the infringement of the copyright in the original photograph – the Higher Regional Court applied the very recent judgment of the CJEU of 4 December 2025 (Mio and Konektra, Cases C-580/23 and C-795/23) and concluded that there was no infringement because the similarities between the original photograph and the AI image concerned exclusively the subject matter – a dog underwater grasping a red toy – which is not protectable. The protected expressive elements of the photograph (the specific perspective, the blurring of the dog’s body, the dynamic composition) had not been reproduced in the AI output, which had a cartoon-like quality and depicted the dog in its entirety in a completely different manner.

A first Italian signal: Tribunale di Milano (23 April 2026) Order in urgent proceedings, R.G. n. 8040/2026

A noteworthy development comes from Italy itself, very close in time to the Düsseldorf ruling. On 23 April 2026, the specialised IP section of the Tribunale di Milano issued an order in urgent proceedings (procedimento cautelare) involving facts that bear a striking resemblance to the Düsseldorf case.

Before examining its content, one methodological caveat is essential for any international reader: the decision was issued in the context of cognizione sommaria – summary proceedings designed to grant interim relief quickly, without a full examination of the merits. As a structural matter, such orders do not lend themselves to the kind of in-depth legal reasoning that characterises full judgments on the merits. The legal grounds underlying the court's findings were stated but not fully developed. The precedential value of the order should be assessed with this limitation firmly in mind.

With that caveat, the facts and the court's reaction are significant. A Dutch company specialising in photorealistic digital renders for the automotive industry had licensed its images to an Italian company for use on its websites. Following the Italian company's failure to pay the licence fees, the Dutch licensor suspended the service and disabled access to the platform. The Italian company, however, continued to use the renders – and went further: it modified them using AI software, using at least 122 renders as a training dataset to generate new ‘derivative’ images that reproduced the perspectives, lighting and reflections of the originals.

The Dutch company brought urgent proceedings, arguing that the local downloading of the renders to feed the AI system constituted unlawful reproduction under Article 13 of the Italian Copyright Act (legge sul diritto d'autore, l.d.a.), while the generation of AI ‘derivative’ outputs replicating the essential features of the originals constituted an unauthorised creative elaboration under Article 18 l.d.a. A claim in unfair competition under Article 2598(3) of the Civil Code was also advanced.

The Court of Milan ultimately dismissed the application – but on procedural grounds, not on the merits. The Italian company had removed all contested images from its web channels and social media, and had unilaterally undertaken to pay a penalty of EUR1,000 for each future breach. The court held that this conduct eliminated the periculum in mora (urgency) required for interim relief to be granted.

However – and this is the passage that has attracted attention – the court expressly stated, albeit without developing the legal reasoning, that the infringing use by the Italian company of the AI-generated images derived from the Dutch company's renders appeared evident. This framing suggests that Italian courts may treat AI training on protected works as engaging both reproduction and elaboration rights where outputs substantially reproduce original elements. For the first time, an Italian court has apparently taken a clear position on the question of third-party rights infringement through AI-generated derivative works – even if that position was stated in terms as peremptory as they were legally unelaborated.

The Milan order is therefore a signal rather than a settled precedent. It shows that Italian courts are willing to look at AI-generated derivative outputs through the lens of existing copyright law – specifically the law on unauthorised elaboration – and to reach conclusions adverse to the party that used protected works as AI training data without authorisation. Whether this approach will be confirmed and fully reasoned in proceedings on the merits remains to be seen.

Is a sort of presumption of non-protectability of the output taking hold?

Taken together, the aforementioned decisions outline an approach consistent with the established case law of the CJEU and the Italian courts on the requirement of creative contribution.

AI is not and cannot be an author. This point is undisputed in all three judgments and reflects the global consensus. AI is a tool, not a legal entity. This is also the underlying approach of Law No. 132 of 23 September 2025 on AI.

Another established point appears to be that a prompt does not automatically equate to authorship. This is a point from which, for the time being, the courts do not move, although it is a point debated in doctrine. According to the judges, the quantity and length of the instructions are not decisive. What matters is whether those instructions specifically determined the expressive elements of the output, expressing the creative personality of the human author. A 1,700-character prompt describing expected results without controlling specific visual elements is no more protectable than a twenty-word prompt.

All three European judgments recognise, in principle, the possibility of protection, provided that the individual claiming protection is able to demonstrate a decisive creative influence on the final output – not merely descriptive or technical. In effect, a sort of presumption is emerging in favour of the non-protectability of AI-generated output, or, at the very least, the establishment of a strict burden of proof to the contrary on those claiming copyright protection. Anyone wishing to claim authorship of an AI output must document the creative process: the prompts used, the iterations, the choices made in selecting variants, and subsequent interventions on the output.

The Düsseldorf and Milan cases, also proved that the use of protected works as training data to generate derivative outputs is a terrain of increasing risk. The Milan case adds an important perspective compared to the German rulings: the problem does not only concern the protectability of AI outputs produced by the user, but also – and perhaps even more urgently – the risk that those outputs infringe the rights of third parties on the works used to train the model. A risk that, as the Court of Milan has hinted, the Italian judges do not seem willing to ignore.

The practical implications are significant: anyone unable to reconstruct the creative process and provide this type of evidence cannot rely on copyright protection. For companies and professionals using generative AI tools, the emerging picture has immediate consequences.

Anyone producing content with the aid of AI and intending to claim intellectual property rights over it must be able to demonstrate that those outputs reflect their specific creative choices regarding the expressive elements. This requires documenting the process:

  • retaining the prompts used along with their subsequent versions;
  • recording the choices made when selecting between variants; and
  • keeping track of modifications made to the raw output.

Employment, agency and supply contracts must be updated to explicitly regulate ownership of AI outputs, as well as procedures for monitoring and reporting on production processes. In the absence of this documentation, AI-generated content risks being unprotected and freely usable by third parties.

Another advantage of monitoring and recording the creative process is the possibility of demonstrating that the output does not reproduce or reprocess protected expressive elements of pre-existing works without authorisation.

Conclusions

The question of whether AI outputs can be protected is not a technical problem awaiting a technological solution. It is a fundamental legal issue that strikes at the very heart of copyright: what does ‘creating’ mean? What makes a work the product of human ingenuity?

The response from the European courts is that authorship is not measured in terms of effort, time or the length of the prompts, but in terms of the creative freedom exercised by the human author over the expressive elements of the work. This is the same response given by the CJEU in Infopaq and Painer, and by the Italian Court of Cassation in dozens of judgments: creativity is not absolute novelty, it is not effort, and it is not the quantity of work. It is the author’s personality that is reflected in the form of the work through free choices.

Applied to generative AI, this principle poses a concrete challenge: the prompting process – even when elaborate and iterative – rarely transparently documents the user’s specific creative choices regarding the expressive elements of the output. The machine interprets, generates, proposes; the human guides, selects, modifies. But the line between ‘tool that executes’ and ‘machine that creates’ is still to be drawn, case by case.

For those working in Italy, the message is twofold. In a country that has chosen to take a leading role in this debate, being the first in Europe to adopt a comprehensive law on AI, the practical rule is simple: document, document, document. The creative process leading to an AI output is, today, the only available evidence of the human authorship that process claims.

***

Key References

  • Law No. 132 of 23 September 2025, "Provisions and powers delegated to the Government regarding artificial intelligence"
  • Leonardo ETS Foundation / Luciano Floridi, ‘Italy in the AI era. Growth, challenges and prospects of an ongoing revolution’ (March 2026)
  • CJEU, Infopaq, C-5/08 (2009)
  • CJEU, Painer, C-145/10 (2011)
  • CJEU, Football Dataco, C-604/10 (2012)
  • CJEU, Mio and Konektra, C-580/23 and C-795/23 (4 December 2025)
  • Court of Cassation, Order No 1107/2023
  • Prague Municipal Court, S.Š. v Taubel Legal, Case No. 13/2023 (2024)
  • Munich Local Court, Case No. 142 C 9786/25 (13 February 2026)
  • Higher Regional Court of Düsseldorf, Case No. I-20 W 2/26 (2 April 2026)
  • Beijing Internet Court, Li Yunkai v Liu Yuanchun (27 November 2023)
  • Court of Milan (23 April 2026) Order in urgent proceedings, R.G. n. 8040/2026
Chiomenti

Chiomenti, Via Giuseppe Verdi 4
20121 Milano
Italy

+39 02 72157 1

www.chiomenti.net
Author Business Card

Law and Practice

Authors



Chiomenti is an independent law firm of approximately 450 professionals with offices in Rome, Milan, London, Brussels and New York. Over 75 years of activity, Chiomenti has developed an extensive network of international relationships and provides its clients with the services and advice of over 450 professionals whose experience and expertise cover multiple economic sectors and geographic areas. Chiomenti has structured its services and assistance in practice areas with a particular focus on transactions and matters of importance and special relevance for its clients, putting its independence and legal expertise at the disposal of companies and institutions, and successfully innovating its leadership at the top of the legal services market. Assistance is carried out in full integration with the different professional areas in which the firm is divided, in order to address and manage various profiles of interest in transactions with a multidisciplinary and integrated approach, focusing on collaboration, internationality and technological innovation as factors of acceleration in its leadership.

Trends and Developments

Authors



Chiomenti is an independent law firm of approximately 450 professionals with offices in Rome, Milan, London, Brussels and New York. Over 75 years of activity, Chiomenti has developed an extensive network of international relationships and provides its clients with the services and advice of over 450 professionals whose experience and expertise cover multiple economic sectors and geographic areas. Chiomenti has structured its services and assistance in practice areas with a particular focus on transactions and matters of importance and special relevance for its clients, putting its independence and legal expertise at the disposal of companies and institutions, and successfully innovating its leadership at the top of the legal services market. Assistance is carried out in full integration with the different professional areas in which the firm is divided, in order to address and manage various profiles of interest in transactions with a multidisciplinary and integrated approach, focusing on collaboration, internationality and technological innovation as factors of acceleration in its leadership.

Compare law and practice by selecting locations and topic(s)

{{searchBoxHeader}}

Select Topic(s)

loading ...
{{topic.title}}

Please select at least one chapter and one topic to use the compare functionality.