Contributed By Chiomenti
Overview
Italy adopted Law No. 132 of 23 September 2025 (the AI Law), which complements Regulation (EU) 2024/1689 (the AI Act) by designating national competent authorities, introducing sector-specific rules, and establishing AI-related criminal offences. The Italian data protection authority (Garante per la Protezione dei Dati Personali, the DPA) retains supervisory competences over AI systems processing personal data. General background law provisions remain essential for matters not specifically addressed by AI-specific legislation.
Contract Law
Neither EU nor Italian law specifically addresses AI-related contract formation. The AI Act does not harmonise contract law, though its transparency and information obligations on providers and deployers (Articles 13, 25-26) will influence contractual risk allocation in the AI supply chain. At national level, the Civil Code contains no AI-specific provisions; general principles on offer, acceptance, capacity, and agency would apply by analogy. Where agentic AI autonomously concludes transactions, novel questions arise as to which party bears contractual liability. Italian courts have not yet ruled on this issue, and scholarly commentary remains limited. Possible frameworks include agency principles (mandato, Articles 1703 et seq. Civil Code), apparent authority (rappresentanza apparente), or forms of objective or risk-based liability of the deploying entity, but no settled doctrine has emerged.
Tort and Product Liability
EU law is reshaping product liability but does not fully harmonise non-contractual liability for AI. The Product Liability Directive (EU) 2024/2853 (the PLD), to be transposed by 9 December 2026, explicitly includes software and AI systems within its scope, removes the EUR 500 damages threshold, and introduces disclosure obligations to facilitate claimants’ access to evidence. The proposed AI Liability Directive, which would have introduced rebuttable presumptions of causation, was withdrawn by the Commission in February 2025 (see Section 10.2 for details). At national level, absent sector-specific rules, fault-based liability under Article 2043 Civil Code would apply to AI-caused harm, requiring proof of wrongful conduct, damage, and causation. Italian courts have not yet addressed AI-specific tort claims, and establishing fault and causation may prove challenging given model opacity. Scholarly commentary has explored whether strict or aggravated liability regimes-such as Article 2050 (dangerous activities) or Article 2051 (liability for things in custody)-could apply by analogy, but these provisions do not seem to readily accommodate AI’s distinctive features, and no settled interpretive approach has emerged.
Privacy and Data Protection
The deployment of AI systems is subject to the general EU and Italian data protection framework – notably the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) and Legislative Decree No. 196/2003, as further amended and supplemented (the Italian Privacy Code) – whenever personal data is processed, irrespective of whether the system is predictive, generative, or agentic. Controllers and processors must comply with core principles (Article 5 GDPR), identify a lawful basis (Articles 6–9), and implement data protection by design and by default (Article 25). Key issues include profiling and large-scale analytics (predictive AI), lawful training data sourcing and output risks (generative AI), and automated decision-making under Article 22 (agentic AI). High-risk uses generally require a data protection impact assessment (Article 35). Overall, GDPR and national law remain the primary regimes governing personal data processing alongside the AI Act.
Intellectual Property
Italian copyright law (Law No. 633/1941, Legge sul Diritto d’Autore, the LDA) requires human authorship under Article 1, as amended by the AI Law (Article 25), which now expressly protects works created “with the aid of AI tools” only where they constitute “the result of the author’s intellectual work.” Purely AI-generated works without substantial human creative input are not protected. The TDM exception (Article 70-ter LDA, implementing Article 4 of Directive (EU) 2019/790, the DSM Directive) permits reproduction for text and data mining, subject to an opt-out mechanism for commercial uses; the AI Law adds Article 70-septies LDA specifically addressing TDM for AI training (see 3.6Data, Information or Content Laws for detailed analysis). Patent protection follows Legislative Decree No. 30/2005 (Codice della Proprietà Industriale, the CPI); AI cannot be named inventor per European Patent Office practice and a similar requirement could be derived at national level from Article 62 CPI (moral right to be recognised as author of the invention, which vests in the inventor and specified heirs), and Article 63 CPI (entitlement to the patent is vested in the inventor of the patent), both of which presuppose the inventor is a natural person. For comprehensive analysis of IP issues, see 16 Intellectual Property.
Employment
In employment, Article 4 of Law No. 300/1970 (Statuto dei Lavoratori, the Workers’ Statute) prohibits remote monitoring, requiring trade union or labour inspectorate authorisation to implement tools which could trigger the possibility of remote monitoring of employees. Legislative Decree No. 104/2022 (the Transparency Decree) mandates disclosure of automated decision-making systems in employment. The AI Law (Articles 11-12) reinforces worker protections, requiring that AI use in the workplace respects dignity and ensures human oversight for consequential decisions.
Consumer Protection
The Consumer Code (Legislative Decree No. 206/2005, the Consumer Code) does not contain AI-specific provisions. However, the Italian competition authority (Autorità Garante della Concorrenza e del Mercato, AGCM) recently applied its general unfair commercial practices rules (Articles 20-22 Consumer Code) to AI services. In a recent proceeding against DeepSeek and other providers (settled with commitments), AGCM held that failure to clearly inform users about “hallucination” risks - ie, the possibility of inaccurate or fabricated outputs - constitutes an omission of material information essential for informed consumer decision-making, even where the service is provided free of charge (see 4.1 Precedent-Setting Judicial Decisions for details on this decision).
Criminal Law
The AI Law introduced AI-specific criminal provisions, including an aggravating circumstance for offences committed using AI systems (Article 61, para. 11-undecies Criminal Code) and a new standalone offence for unlawful dissemination of AI-generated content harmful to a person’s image (Article 612-quater Criminal Code). The AI Law also introduced enhanced penalties for market manipulation committed by means of AI, and added a new criminal offence to the LDA (Article 171, para. 1, let. a-ter) punishing unlawful text and data mining in violation of Articles 70-ter and 70-quater, including via AI systems. Deepfake intimate imagery remains punishable under Article 612-ter (revenge porn). For analysis of deepfake regulation, see 12.3 Deepfakes and Synthetic Media.
A 2025 Confindustria Report (L’Intelligenza Artificiale per il Sistema Italia) mapped over 200 use cases across 76 companies, with healthcare, manufacturing and sustainable mobility as key sectors. Operations-related applications predominate, followed by corporate/HR and customer service. Generative AI accounts for 46% of the market (Osservatorio Artificial Intelligence del Politecnico di Milano, 2025). ISTAT (Imprese e ICT 2025) cites lack of digital skills and high implementation costs as main adoption barriers.
Italy is a major beneficiary of the EU Recovery and Resilience Facility (Regulation (EU) 2021/241) – so-called PNRR funding. According to a report by Fondazione Leonardo ETS (L’Italia nell’era dell’IA, edited by Luciano Floridi and Micaela Lovecchio, March 2026), key AI-related allocations include:
Additionally, the AI Law (Article 23) authorises investments of up to EUR1 billion in companies operating in AI, cybersecurity, and enabling technologies, including quantum computing. These investments are to be made through equity and quasi-equity instruments managed by CDP Venture Capital SGR, with governance participation by the Presidency of the Council of Ministers and ACN (Agenzia per la Cybersicurezza Nazionale).
As the first EU Member State to adopt comprehensive national legislation on AI, the AI Law positions Italy as a first mover. It facilitates the application of the AI Act in the Italian legal order and reflects a precautionary, risk-based and human-centric approach (see 3.2 Jurisdictional Law for implementation details and 5.1 Regulatory Agencies for competent authorities).
The AI Law establishes sector-specific rules for AI use in healthcare, public administration, employment, intellectual professions and judicial activities (see 7 AI and the State to 12 Specific Legal Issues With AI for detailed sectoral analysis).
In the IP and personality rights realm, the AI Law introduces provisions on copyright and AI, confirming that TDM exceptions apply to AI training subject to the opt-out mechanism, and requiring human authorship for copyright protection of AI-assisted works (see 3.6 Data, Information or Content Laws and 16 Intellectual Property for IP analysis). For pending legislative proposals addressing deepfakes and algorithmic platforms, see 3.7 Proposed AI-Specific Legislation and Regulations.
In the area of data protection, both the Italian legislature and the DPA tend to adopt a precautionary approach, broadly consistent with the positions articulated at EU level by the European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB).
The AI Law incorporates the AI Act classification of AI systems by reference, applying across the full AI lifecycle. Its distinctive feature is a sector-specific approach, imposing context-based requirements and limitations in sensitive domains such as justice, healthcare, employment, and public administration (see 4 Case Law, 5 AI Regulatory Oversight, 6 Standard-Setting Bodies, 7 AI and the State, 11 Agentic AI Systems and Autonomous Decision-Making and 12 Specific Legal Issues With AI).
The law establishes a governance and monitoring framework, designating the Presidency of the Council of Ministers as the co-ordinating authority (see 3.3 Jurisdictional Directives), and mandates the adoption of a periodically updated national AI strategy.
The law also promotes regulatory sandboxes for AI (see 3.4 EU AI Act) and introduces specific provisions on copyright (see 3.6 Data, Information or Content Laws and 16.2 AI as Inventor/Author) and AI-related criminal offences (see 1.1 General Legal Background).
Italy is developing a soft-law framework to guide AI adoption across key sectors. In March 2026, AgID launched a public consultation on draft guidelines which ended on 11 April 2026. Following the consultation, two sets of guidelines were adopted through Resolution No. 43/2026. The guidelines concern, respectively, the development of AI systems in the public sector and the procurement of AI solutions by public administrations.
The guidelines on the development of AI systems in the public sector provide a strategic framework for designing new AI-based systems. They address key principles such as transparency, accountability, human oversight, and non-discrimination. They also connect these principles with the operational framework of procurement, ensuring coherence and continuity across the entire AI lifecycle within the public sector.
The guidelines on the procurement of AI systems in the public sector complement the development guidelines and establish a methodological and operational framework to support public authorities in the acquisition, management, and monitoring of AI solutions. They introduce operational tools and criteria to strengthen the capacity of public administrations to design and manage complex tenders, ensuring compliance with the AI Act requirements for high-risk AI systems used in public services. Furthermore, the Ministry of Labour and Social Policies, through Ministerial Decree No. 180/2025, has issued guidelines promoting the responsible use of AI in the workplace, with a focus on employee protection, transparency, accountability, non-discrimination, regulatory compliance, and sustainable innovation. Lastly, the Ministry of Education has adopted Ministerial Decree No. 166/2025, introducing guidance to support the informed integration of AI tools in schools. These measures aim to enhance teaching and administrative processes, while addressing ethical and data protection risks through a set of technical, ethical, and regulatory safeguards.
As noted in 3.1 General Approach to AI-Specific Legislation, Italy adopted the AI Law further and to give effect to the AI Act. The law is aligned with the risk-based approach and draws upon the categories, concepts, and actors defined in the AI Act. Article 1(2) of the AI Law explicitly provides that its provisions shall apply and be interpreted in accordance with the AI Act. Article 2(1) refers to the notions of “AI systems” and “AI models” as defined, respectively, in Articles 3(1) and 3(63) of the AI Act. Moreover, paragraph 2 establishes that for any notions not expressly defined therein, the definitions in the AI Act shall apply.
In addition to introducing sector-specific provisions – concerning, among others, the use of AI by public administrations, in the workplace (see 1.1 General Legal Background), in intellectual professions, and in healthcare – the AI Law fulfils the obligation imposed on member states by Article 70 of the AI Act to designate the national competent authorities in the field of AI. The law also includes measures to strengthen cybersecurity in AI systems.
By designating AgID as the notifying authority and market surveillance authority for non-high-risk AI systems, and ACN as the market surveillance authority for high-risk AI systems and for general-purpose AI models, the Italian legislator has entrusted existing agencies with the relevant powers (unlike other jurisdictions, such as Spain, which have established ad-hoc AI authorities). In accordance with Article 74(6) of the AI Act, the Bank of Italy, CONSOB (Commissione Nazionale per le Società e la Borsa), and IVASS (Istituto per la Vigilanza sulle Assicurazioni) act as market surveillance authorities for AI systems used in the financial services sector. For a comprehensive overview of all competent authorities, see 5.1 Regulatory Agencies.
Moreover, while designating the competent AI authorities, Article 20 of the AI Law applies without prejudice to the powers and competences of the DPA and the Italian Communications Authority (Autorità per le Garanzie nelle Comunicazioni, AGCOM), with the latter acting as the digital services coordinator for Italy under Regulation (EU) 2022/2065 (the DSA).
Article 24 of the AI Law contains a delegation of power to the government for the adoption of legislative decrees necessary to facilitate the application and enforcement of the AI Act. In particular, such decrees will:
Not relevant in this jurisdiction.
Copyright and TDM Exceptions
The Italian TDM framework builds on the DSM Directive. Article 70-ter LDA (transposing Article 3 DSM Directive) permits TDM for scientific research by research organisations and cultural heritage institutions with lawful access. This exception is mandatory, non-waivable, and royalty-free.
Article 70-quater LDA (transposing Article 4 DSM Directive) establishes a broader TDM exception for any person with lawful access, including for commercial AI training, subject to an opt-out mechanism. Unlike the DSM Directive, the Italian transposition does not specify how rightholders must express their reservation. Under Article 4(3) DSM Directive and Recital 18, reservations for online content must be machine-readable (eg, metadata, robots.txt). The AI Act reinforces this: Article 53(1)(c) requires general-purpose AI (GPAI) model providers to implement policies to identify and comply with rights and reservations using “state-of-the-art technologies”, which Recital 106 specifies may include watermarking.
Article 25 of the AI Law introduces Article 70-septies LDA, confirming that TDM exceptions apply to AI model training (including generative AI), subject to the opt-out for commercial uses. See 16.3 Copyright and AI Training Data for detailed analysis of copyright issues, licensing frameworks and pending litigation.
Database Rights and Sui Generis Protection
The sui generis database right under Directive 96/9/EC protects databases showing substantial investment in obtaining, verifying or presenting their contents. Article 4(1) DSM Directive extends the TDM exception to the sui generis right. Article 70-quater LDA does not expressly mention it but refers to “database owners”; the extension should apply by consistent interpretation. Debate remains whether large-scale extraction for AI training exceeds proportionality limits, particularly when entire databases are ingested for model development.
Data Protection
On data protection, while there is no AI-specific legal basis for processing under the Italian Privacy Code, the DPA has consistently applied core GDPR principles (lawfulness, transparency, purpose limitation, data minimisation) when assessing generative AI services, including via remediation orders directed at LLM deployments.
Web scraping remains legally fraught where personal data is collected or reused for AI training without a lawful basis and adequate notice. Recent DPA interventions – such as the 2022 EUR20 million fine on Clearview AI for unlawful web scraping (including biometric and geolocation data), and 2024 guidance on protecting personal data from web scraping – confirm that “publicly available” does not equate to “free to scrape”.
Finally, Italy lacks a dedicated statutory framework for synthetic data, whose use is generally assessed under the GDPR (anonymisation v pseudonymisation), and the DPA’s risk-based approach. However, the AI Law has introduced the possibility for the National Agency for Regional Health Services (AGENAS) to issue and update guidelines on anonymisation and synthetic data creation for AI research in the health sector.
At the time of writing, some legislative proposals addressing AI-specific issues are pending before the Italian Parliament.
Moreover, Article 16 of the AI Law empowers the government to adopt implementing decrees regulating the use of data, algorithms, and mathematical methods for AI training (in line with the EU AI Act and without adding further obligations). Similarly, and more generally, Article 24 of the same law delegates to the Italian government the power to adopt decrees to ensure full implementation of the EU AI Act in Italy (including adapting existing sectoral legislation, defining sanctions and liability regimes, regulating unlawful and high-risk AI systems, and establishing rules for AI use in sensitive contexts such as criminal investigations).
Italy’s body of truly precedent-setting AI case law is still developing; however, certain judicial decisions on algorithmic systems already articulate principles that will probably shape disputes across IP, privacy, liability and labour.
Intellectual Property
In the IP realm, while Italian courts have not yet ruled on AI training and copyright infringement, the first significant case is now pending: RTI and Medusa Film v Perplexity AI (Court of Rome, filed December 2025). The Mediaset subsidiaries allege that Perplexity systematically used copyrighted audiovisual content (films, TV programmes) to train its LLM without authorisation, invoking violations of Articles 1, 2, 45, and 78-ter LDA. The claimants seek an injunction, damages and daily penalties for future violations. The case is the first Italian lawsuit targeting AI training on audiovisual works and will likely test the interplay between the TDM exception and the opt-out mechanism. No decision has yet been rendered.
On the related question of copyright protection for algorithmically generated works, the Supreme Court of Cassation touched upon the issue in Cass. civ. Sez. I, 16 January 2023, No. 1107 (a fractal image used as set design for the Sanremo Festival): in that case, well ahead of the AI Law and the recent amendments to the LDA, the Court noted that using software to generate an image is compatible with the elaboration of a work of authorship with a degree of creativity that would only need to be scrutinised with greater rigour (see 16.2 AI as Inventor/Author for further analysis).
Two recent precautionary orders issued in 2026 provide early indications of how Italian courts may approach AI-related IP and liability issues. In Court of Milan, 23 April 2026, the court addressed alleged copyright violations involving digital renders (photorealistic images) allegedly used to train an AI system. While the proceeding was dismissed for lack of ongoing harm (the defendant had removed all contested content and committed to a penalty for future violations), the court nonetheless found that the infringing use was “evident” for purposes of allocating costs under the virtual succumbence criterion. The claimant had argued that the defendant’s conduct – downloading renders and using them to train an AI system to generate derivative images reproducing the same distinctive elements (perspective, angles, lighting) – violated the exclusive rights of reproduction (Article 13 LDA) and elaboration (Article 18 LDA). Although the court did not formally rule on the merits, this framing suggests that Italian courts may treat AI training on protected works as engaging both reproduction and elaboration rights where outputs substantially reproduce original elements.
In Court of Pistoia, 19 March 2026, the court granted precautionary relief against a competitor for unfair competition through parasitic advertising, including the use of keyword advertising referencing a rival’s celebrity testimonials. Notably, the defendant argued that the infringing blog content had been “generated by an automated text generation system based on artificial intelligence” without direct human intervention or conscious editorial intent. The court expressly rejected this defence, holding that AI systems are “at least for now, not capable of taking any initiative” autonomously, and therefore the entrepreneur remains liable for content generated through AI tools deployed in its business. This ruling establishes an early judicial position that reliance on AI does not excuse liability for unlawful outputs – a principle likely to inform future disputes over AI-generated content in advertising, marketing and beyond.
Consumer Protection
The AGCM closed three investigations against DeepSeek (case PS12942, decision of 16 December 2025), Mistral (case PS12968, decision of 17 February 2026) and NOVA AI (case PS12973, decision of 21 April 2026) by accepting commitments, without any finding of infringement. The proceedings arose from concerns that users were not adequately informed about the risk of so-called hallucinations, including at key stages such as first access, use of the chat interface and pre-contractual disclosures. The commitments focused on enhancing transparency towards users, including by ensuring that relevant information on hallucinations is provided in Italian. In particular, the companies introduced permanent disclaimers within their interfaces (websites and apps), including directly below chat windows, alerting users to the risk of hallucinations and linking to further information. They also strengthened pre-contractual disclosures (eg, in their terms and conditions), with explicit warnings on the limits of reliability of AI-generated content and the need for users to verify outputs. DeepSeek’s commitments went further by implementing targeted technical interventions to mitigate hallucinations, including improved filtering of training data, the use of specialised datasets and reinforcement learning techniques to reduce unreliable outputs, and the integration of real-time, authoritative information sources.
Data Protection
Supreme Court of Cassation No. 28358/2023 clarifies that consent-based profiling is valid only if the underlying algorithm is described unambiguously, without requiring disclosure of weightings or source code.
Italy’s most developed AI case law lies in the labour/platform-work space, where algorithmic management is treated as a substantive mode of organising work. In Court of Milan, Labour Section, No. 1018 of 20 April 2022 (Deliveroo Italia), the algorithmic system for order allocation and reputational scoring was deemed indicative of hetero-direction leading to the re-classification of the relationship as subordinate employment. The ruling suggests that where algorithms govern access to work and embed sanctions/rewards, courts may recharacterise job relationships or intensify employer duties. At Supreme Court level, the Court of Cassation decision of 22 September 2023 (in the Foodinho/rider context) confirmed that algorithmic governance is central to assessing discrimination and transparency toward workers.
For AI case law in the public-law sphere, see Section 7.2 Judicial Decisions.
Article 20 of the AI Law designates ACN and AgID as the national competent authorities for AI pursuant to Article 70 of the AI Act. ACN is designated as the market surveillance authority, responsible for supervision (including inspections and sanctions), and as the single point of contact with EU institutions; it is also tasked with promoting AI development in relation to cybersecurity. AgID is designated as the notifying authority, responsible for promoting AI innovation and development, and for defining procedures for the notification, assessment, accreditation and monitoring of conformity assessment bodies. The AI Law also provides that Bank of Italy, CONSOB and IVASS are responsible for market surveillance over AI systems in financial services pursuant to Article 74(6) of the AI Act.
The designation of ACN and AgID is expressly stated to be without prejudice to the competences of other authorities: the DPA retains its supervisory competences over AI systems processing personal data under the GDPR (Article 20(4) AI Law), and AGCOM retains its competences, including as digital services coordinator under the DSA with authority over AI systems in media and recommendation algorithms (Article 20(4) AI Law). AGCM is not expressly designated under the AI Law but retains its general competences, inter alia over unfair commercial practices (Articles 20-22 Consumer Code), which might extend to AI-related services, as demonstrated by its recent enforcement initiatives (see 4.1 Precedent-Setting Judicial Decisions).
Soft law issued by regulators, while not formally binding, often sets the practical compliance baseline for AI deployments.
As concerns AgID guidelines, as well as guidelines from government agencies, see 3.3 Jurisdictional Directives.
Where personal data is processed, a central role is played by the DPA, which has used general guidance, sector-specific “rulebooks”, and consultative opinions to operationalise GDPR principles and the Italian Privacy Code. An example is the DPA’s guidance of 20 May 2024 on measures to mitigate web scraping of personal data published online. Although framed as “non-binding measures” under the accountability principle, it provides a concrete control catalogue (eg, reserved areas, traffic monitoring, and technical anti-bot countermeasures), directly relevant for organisations training or fine-tuning AI models on web datasets.
The DPA has also issued opinions on draft measures and programmes involving AI/machine learning (ML), including:
In healthcare, the DPA has published structured “decalogue” guidance for AI-enabled national health services, translating legality, fairness, human oversight and security requirements into operational governance. Finally, the DPA has provided indications on AI uses in sensitive areas, such as smart assistants or deepfakes (especially in connection to cyberbullying, fake news, revenge porn and other cybercrimes).
Italy’s AI enforcement to date has been driven primarily by the DPA, leveraging the GDPR and the Italian Privacy Code to address perceived gaps as the AI Law beds in. A clear trend is the use of urgent/interim powers (including temporary processing bans) alongside fines, particularly where foundation-model providers rely on large-scale data collection and opaque training pipelines. The flagship case remains the DPA’s 2023 action against OpenAI’s ChatGPT: an urgent order imposed an immediate restriction on processing Italian users’ data (prompting geoblocking), followed by conditional measures to lift the ban and, ultimately, a final fine in December 2024, later successfully challenged by OpenAI before the Court of Rome. Similar concerns (with a focus on minors’ protection) informed the DPA’s actions against Luka Inc’s Replika (2023-2025), culminating in requirements to strengthen age-gating and privacy documentation (including Italian-language notices and clearer positions on retention and extra-EEA transfers).
Italian enforcement has also targeted biometric AI: in the 2022 Clearview AI decision, the DPA sanctioned the creation and use of facial-recognition profiles built from mass web-scraped images and ordered cessation of processing and erasure of data relating to individuals in Italy. Beyond foundation models and biometrics, in 2025 the DPA sanctioned AI-enabled surveillance (Municipality of Trento) for lack of legal basis for special-category/criminal-offence data, inadequate anonymisation, missing data protection impact assessments (DPIA), and deficient transparency, and imposed a EUR5 million penalty on Foodinho for algorithmic management in the platform economy, focusing on automated decision-making safeguards and the right to human intervention. Recent actions further show scrutiny of AI training/data-sharing arrangements (publisher–LLM content sharing) and health-data uses for AI training (Menarini Silicon Biosystems, 2025).
On the consumer protection front, AGCM has also taken action against generative AI providers: in 2025-2026, the authority closed proceedings against DeepSeek, Mistral and NOVA AI by accepting commitments requiring enhanced transparency on hallucination risks (see 4.1 Precedent-Setting Judicial Decisions).
In Italy, AI standard-setting emerges from a multi-layered ecosystem of legislative, regulatory, and technical sources. Alongside formal legislation (notably the AI Law, establishing a governance and accountability framework for AI systems and requiring demonstrable risk management, traceability, and audit-ready controls), key institutional actors shape operational expectations, including UNI (Ente Italiano di Normazione) and CEI (Comitato Elettrotecnico Italiano), as well as regulators such as AgID, ACN, and the DPA, and ministerial initiatives. Although largely soft-law, such instruments materially influence compliance, particularly in high-impact sectors (public procurement, employment, and education), as reflected in ministerial guidelines on AI use in workplaces and schools (see 3.3 Jurisdictional Directives), and in the Italian DPA’s decisions on AI-driven data processing, including generative AI services. Collectively, these measures operate as de facto standards, shaping market expectations and bridging AI Act requirements with national practice.
International standards such as ISO/IEC 42001 (AI management systems), ISO/IEC 23894 (AI risk management) and ISO/IEC 22989 (AI terminology), alongside IEEE frameworks and the NIST AI Risk Management Framework, are increasingly used in Italy as practical benchmarks for governance and risk management. While not legally binding, they are widely regarded as state-of-the-art indicators and relied upon to evidence diligence in the AI design, development and deployment. In practice, Italian and multinational companies are progressively incorporating these standards into internal compliance structures, supplier due diligence processes and contractual arrangements, particularly in anticipation of AI Act conformity assessment. This is especially relevant for high-risk systems, where adherence to recognised standards can help substantiate controls on risk management, data governance, transparency and human oversight. Although generally consistent with EU law, including the GDPR and applicable cybersecurity requirements, these frameworks are not applied mechanically but require calibration to align with interpretative guidance from Italian authorities, including the DPA, as well as sector-specific regulatory expectations.
Italian public administrations are increasingly deploying AI systems across administrative processes, under the Italian Strategy for Artificial Intelligence 2024–2026, prioritising research, talent, and measurable public service improvements. Accordingly, AI adoption is primarily aimed at enhancing efficiency, service provision, and risk management and compliance.
Applications remain largely “assistive”, including machine learning tools for welfare fraud detection (notably within INPS, the National Institute for Social Security), and natural language processing for document classification and case management. The most advanced uses are in tax administration: the Revenue Agency employs automated tools for VAT and income tax controls, pre-filed returns, and SME risk-scoring, supported by digitised invoicing and receipts. Parliament has authorised AI for tax risk analysis subject to GDPR compliance and human oversight, and the Revenue Agency is developing AI-enabled assessment engines correlating registry and financial data, including graph-based VAT fraud detection tools.
More generally, Article 14 of the AI Law regulates AI use by public administrations to enhance efficiency, accelerate procedures, and improve services, requiring systems to remain supportive and traceable, with final decision-making authority and accountability vested in human officials, alongside appropriate organisational and training measures. Additionally, Article 5(1)(d) of the AI Law requires e-procurement platforms to favour suppliers whose AI solutions ensure data localisation and processing within Italian data centres, with domestic disaster recovery and business continuity measures, significantly impacting data sovereignty in AI public procurement.
Italian case law on AI use by government agencies and public administrations has developed primarily in the administrative courts, crystallising enforceable constraints on algorithmic decisions. In its 2019 landmark judgment (Consiglio di Stato, Sez. VI, 8 April 2019, No. 2270), the Council of State accepted that algorithmic tools may support administrative efficiency, provided that the underlying rule is fully “knowable” in a reinforced transparency sense: stakeholders must understand authorship, design choices, relevant data inputs, and prioritisation logic, enabling legality and rationality to be tested. This line has been reaffirmed and refined, with the Council of State stressing that IT tools cannot depart from legal criteria and that the administration retains verification and accountability, including in discretionary contexts.
Courts have also linked transparency to access obligations: Consiglio di Stato, Sez. IV, 4 June 2025, No. 4857 distinguishes algorithmic decisions from decision-support tools and addresses access to source code and datasets in light of transparency and procurement rules favouring traceability and open solutions. In parallel, the Italian Supreme Court of Cassation (Corte di Cassazione, Sez. I, No. 28358/2023) has addressed “algorithmic opacity” through a data-protection lens: valid consent requires intelligible information on data processing within an algorithm, without disclosure of the mathematical code.
In Italy, AI in national security and defence sits at the intersection of:
A defining feature is Italy’s preservation of a distinct regulatory space for “security of the Republic” and defence functions, while reaffirming constitutional and fundamental-rights guardrails. At legislative level, the AI Law excludes activities for national security (intelligence bodies under Law No. 124/2007), national defence (Armed Forces), and certain cybersecurity/resilience functions linked to the national cybersecurity architecture under Decree-Law No. 82/2021 (as converted). At the same time, the law provides that these excluded activities must still comply with constitutional rights and principles of proportionality, security and human oversight. AI research and development may fall under the National Cybersecurity Perimeter (Perimetro di sicurezza nazionale cibernetica) introduced by Decree-Law No. 105/2019 (as converted), which imposes risk analysis, security measures and incident reporting obligations for entities and assets deemed critical to national security. Furthermore, specific categories of IT goods and services provided to public administrations or entities within the National Cybersecurity Perimeter and used in a context related to the protection of strategic national interests are subject to essential cybersecurity requirements. Finally, where AI entails biometric or large-scale analytics for public security, data protection enforcement remains a material constraint.
Regulatory Framework for General-Purpose AI Models
The AI Act introduces a dedicated regulatory framework for GPAI models, including LLMs, image generators and other foundation models. Chapter V of the AI Act establishes tiered obligations based on whether a model presents systemic risks. All GPAI model providers must maintain technical documentation, provide information to downstream AI system providers, comply with EU copyright law and publish a sufficiently detailed summary of training content. GPAI models with systemic risks - identified by reference to cumulative compute thresholds or Commission designation - face additional obligations including model evaluation, adversarial testing, incident reporting and cybersecurity measures.
Copyright Issues in Training and Outputs
Generative AI raises distinctive copyright challenges at both the input and output stages. Training large models on copyrighted works involves acts of reproduction that require either rightholder authorisation or reliance on a statutory exception, such as TDM under Articles 3-4 of the DSM Directive (transposed in Italy as Articles 70-ter and 70-quater LDA). However, significant doctrinal debate exists as to whether the TDM exception - designed for analytical extraction - is conceptually suited to generative AI training aimed at learning and reproducing expressive qualities. At the output stage, generated content that reproduces or substantially resembles protected works may constitute infringement. For detailed analysis, see 16 Intellectual Property.
Data Protection Considerations
As regards data protection issues, while useful guidance has been provided at the European level by the 2025 EDPB Report on AI Privacy Risks & Mitigations – Large Language Models (LLMs), the Italian DPA has also taken enforcement action against certain LLM providers (see 17 Data Protection).
Liability for Harmful or Infringing Outputs
Generative AI outputs may cause harm through various mechanisms:
Liability allocation depends on the specific facts and applicable legal regime. Under general tort principles, both providers and users may bear responsibility depending on their knowledge, control and the foreseeability of harm. For detailed analysis of liability frameworks, see 10 Liability for AI. For AI in legal practice and hallucination risks, see 9.1 AI in the Legal Profession and Ethical Considerations.
Transparency Requirements
The AI Act imposes transparency obligations at multiple levels. Article 50 requires that AI systems designed to interact with natural persons disclose that the user is interacting with an AI system. Providers of AI systems that generate synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable format as artificially generated or manipulated. GPAI model providers must publish summaries of training content and maintain technical documentation. The GPAI Code of Practice provides further guidance on implementing these transparency requirements, including specifications for watermarking and content authenticity standards.
The AI Law directly regulates the use of AI in intellectual professions, including the legal one: Article 13 restricts AI to “instrumental and support activities”, requiring the predominance of the professional’s intellectual work, and imposes a prior written disclosure obligation to clients. The Italian National Bar Council (CNF) issued a standard-form notice.
Hallucinations and Early Case Law
Italian courts have begun addressing negligent reliance on AI-generated content. In TAR Lombardia-Milano, no. 3348/2025 (21 October 2025), the court referred an attorney to the Milan Bar for disciplinary proceedings after he cited entirely irrelevant case law sourced through AI tools, invoking Article 88 Italian Code of Civil Procedure (duty of loyalty) and the Milan Bar’s Charter on AI use by lawyers. The Court of Florence, Business Section (14 March 2025) addressed AI-linked negligence involving the use of ChatGPT to generate fabricated Supreme Court citations in pleadings, though without imposing aggravated costs under Article 96 Italian Code of Civil Procedure due to the absence of bad faith on the part of the lawyer. A further notable example is the Court of Siracusa decision of 20 February 2026 (no. 338), in which the claimant cited four purported Supreme Court precedents to support its legal arguments. On examination, the court found that the quoted passages did not match any actual judgments: the cited authorities were either irrelevant to the matter or entirely fabricated. The court held that the uncritical use of generative AI tools without verifying outputs against primary sources constituted gross negligence, applying Article 96 Italian Code of Civil Procedure (aggravated procedural liability), ordering payment of about EUR15,000 to the opposing party and imposing a further EUR2,000 fine in favour of the Treasury (Cassa delle ammende).
Unauthorised Practice, Confidentiality and Ethics
Article 13 of the AI Law implicitly draws the boundary against unauthorised practice: AI may only perform support tasks, and the professional’s intellectual contribution must remain predominant. Client confidentiality (Article 13 of the Italian Bar Code of Conduct) and GDPR apply to cloud-based AI tools. The Italian ethical framework rests on three pillars:
Lastly, the Ministry of Justice has established an Observatory on AI in judicial activity (D.M. 10 July 2024).
Italian Liability Framework for AI
Italian law applies several liability regimes to AI-caused harm. As mentioned, the new PLD (see 1.1 General Legal Background) explicitly covers software and AI and must be transposed into national law by December 2026. Fault-based liability under Article 2043 Civil Code requires proof of wrongful conduct, damage and causation, which may be challenging in case of a lack of transparency/asymmetry of information. There is debate whether strict liability provisions (Article 2050 for dangerous activities; Article 2051 for things in custody) could apply by analogy, but no settled approach has emerged. Vicarious liability (Article 2049) may extend to AI acting within deployment scope, although its application depends on qualifying the AI system within an organisational relationship comparable to that of an employee or agent. For AI-generated content liability, the DSA’s intermediary regime also applies to the extent AI systems or models are provided as intermediary services, but does not generally govern liability for all AI-generated outputs as such.
Evidentiary Challenges and Forthcoming Reforms
AI opacity makes it difficult to establish causation or identify defects. The revised PLD introduces disclosure mechanisms and burden-shifting where technical complexity makes proof excessively difficult. Critically, Article 24(5)(d) of the AI Law delegates to the government the task of regulating burden-of-proof allocation in AI civil liability cases, taking into account AI Act risk classifications - a distinctive Italian measure that may yield AI-specific procedural rules.
The question of liability for AI was initially expected to be harmonised EU-wide through the proposed 2022 Directive on non-contractual civil liability for AI (the AI Liability Directive). However, in February 2025, the European Commission withdrew the proposal due to the lack of foreseeable agreement among member states. The withdrawal followed a lack of political agreement among member states, alongside concerns from industry stakeholders that an additional liability regime could overlap with the AI Act and create unnecessary complexity. While the European Commission may consider a revised proposal or an alternative approach in the future, liability relating to AI needs, for now, to be addressed under existing legislation and general principles, as outlined in 10.1 General Theories of Liability.
Agentic AI systems are not yet subject to a dedicated Italian legal regime and are not recognised in Italy as legal persons capable of contracting or acting independently. Their governance relies on Italian civil law principles, EU digital regulation, and the AI Act.
Under Italian contract law (Civil Code, Arts. 1321 et seq.) and agency principles, AI actions can be attributed to the deploying principal as AI lacks legal personality, liability and contractual effects are assigned in principle to the deploying human or legal entity, based on risk allocation and controls. The AI Act introduces layered governance: for high-risk systems, it requires human oversight, ensuring monitoring, override or interruption of autonomous multi-step agentic processes, and mandates logging/traceability for auditability, reconstruction and ex post explainability in multi-agent environments. In regulated sectors (such as employment, credit scoring, critical infrastructure, law enforcement) such systems are typically high-risk, triggering conformity assessments, risk management, and strict data governance obligations.
Although multi-agent systems are not separately regulated, the AI Act’s provider–deployer allocation and lifecycle governance extend accountability across organisational boundaries, avoiding accountability gaps. From a public-law perspective, Italian administrative case law requires auditability and transparency of automated decision-making; this approach will most likely also inform multi-agent, cross-organisational accountability and escalation paths.
Liability Allocation in Italy
The AI Act distinguishes providers (primary responsible for design, testing, compliance) from deployers (responsible for use, human oversight, incident reporting). This regulatory allocation informs civil liability analysis, though the AI Act does not create private rights of action. In Italy, Article 14 of the AI Law reinforces human accountability: in public administration, the natural person remains solely responsible for administrative acts and decisions taken with AI support; a similar principle applies in the context of intellectual professions under Article 13. Existing strict liability provisions (Articles 2050-2051 Civil Code) may apply, though their adaptation to AI remains doctrinally unsettled and untested in court. For discussion of general liability theories, see 10.1 General Theories of Liability.
Evidentiary and Multi-Agent Challenges
AI opacity complicates causation proof; the AI Act’s logging requirements (Article 12) may partially assist. Article 24(5)(d) of the AI Law mandates government regulation of burden-of-proof allocation in AI liability cases. For multi-agent systems, joint and several liability principles may apply where cascading failures cause indivisible harm; the AI Act’s lifecycle governance provides a basis for accountability even in distributed architectures, although practical allocation among multiple actors remains likely to be highly fact-specific. For discussion of evidentiary challenges, see 10.1 General Theories of Liability.
Italian fairness obligations in AI are not defined through a single statutory concept of bias, but instead derive from a multilayered framework combining constitutional equality principles, administrative law constraints on automated decision-making, and, where personal data is processed, GDPR requirements of lawfulness, transparency, data minimisation, and safeguards.
In the public sector, these principles have been progressively shaped by case law. The Council of State (No. 2270 of 2019, see also 7.2 Judicial Decisions) recognised algorithmic tools for efficiency, with safeguards of intelligibility, accessibility, consistency with administrative discretion, and judicial review. The DPA operationalised algorithmic fairness through an accountability-based approach, requiring model reliability, reduced opacity, continuous testing, and corrective measures in case of discriminatory risks. This is reflected in sectoral guidance (eg, the “Decalogue” on AI in healthcare) and enforcement, including the 2024 Foodinho case on algorithmic scoring, human intervention and contestation of automated decisions.
Against this background, the AI Act introduces a harmonised framework for high-risk systems, requiring risk management, data governance, and training data quality controls to mitigate discriminatory outcomes, framing bias as systemic distortions in data or outputs causing unequal treatment. Bias mitigation is partly anticipatory under the AI Act but grounded in GDPR accountability. Liability rests on a combination of civil law, sectoral anti-discrimination rules, and GDPR enforcement, alongside algorithmic impact assessments, auditing, and explainability aligned with EU ethical guidelines and ISO/IEC standards.
Enforcement will intensify significantly under the AI Act, with enhanced supervisory powers and significant sanctions for systemic bias or unfair automated decision-making.
Biometric AI systems in Italy are governed mainly by the GDPR, as supplemented by the Italian Privacy Code and DPA guidance. Biometric data for unique identification qualifies as under “special categories of personal data” under Article 9 GDPR, and is subject to a general prohibition on processing unless a strict exception applies, such as explicit consent or substantial public interest. The DPA has historically adopted a restrictive stance, often suspending or limiting public surveillance deployments and treating facial recognition as a particularly high-risk use case. Such systems require a legal basis, together with strict necessity and proportionality assessment, and strong safeguards. Enforcement practice, including the DPA’s Clearview AI (2022) and Municipality of Trento (2024) cases, confirms heightened scrutiny of biometric and AI surveillance, focusing on unlawful scraping, DPIAs, transparency, and processing of sensitive or criminal data.
Consent remains a fragile legal basis for biometric processing, particularly in employment or public services due to power imbalance, therefore compliance typically relies on legal obligation or public interest, supported by strong technical and organisational safeguards. Accuracy and bias risks must be managed through testing, validation, and meaningful human oversight to meet GDPR accuracy and accountability requirements, particularly where outputs affect legal or similarly significant decisions.
The EU AI Act adds a risk-based regime for biometrics, defining emotion recognition and biometric categorisation systems, prohibiting certain intrusive uses (including in workplaces and education), and restricting sensitive attribute interference. Remote biometric identification is high risk and subject to strict requirements, including a general ban on real-time use in publicly accessible spaces for law enforcement, subject to limited exceptions.
Italian Framework for Deepfakes and Synthetic Media
The AI Act (Article 50) requires disclosure of AI-generated or manipulated content through machine-readable marking; the DSA imposes notice-and-action obligations on platforms hosting illegal deepfakes. In Italy, Article 26 of the AI Law introduces a new criminal offence (Article 612-quater Criminal Code): disseminating-without consent-AI-falsified images, videos or voices apt to deceive is punishable by one to five years’ imprisonment. An aggravating circumstance (Article 61, para. 11-undecies) applies when AI is used as an insidious means (see 1.1 General Legal Background for criminal law provisions). Pre-existing protections remain relevant: Article 10 Civil Code (right to image), Articles 96-97 LDA (portrait consent), and defamation/privacy remedies extend by analogy to deepfakes. For transparency requirements under the AI Act, see 12.4 Transparency and Disclosure.
Pending Legislation: Bill 1644
Bill 1644, inspired by Denmark’s 2024 law, proposes comprehensive identity protection:
For discussion of other pending AI legislation, see 3.7 Proposed AI-Specific Legislation and Regulations.
The AI Act imposes disclosure obligations at multiple levels.
Against this backdrop, the AI Law implements complementary national requirements: Article 3 mandates transparency, explainability and human oversight in AI systems; Article 4 requires clear, simple communications on data processing and AI-related risks; Article 13 obliges professionals using AI to inform clients in clear language; Article 14 requires public administrations to ensure traceability and intelligibility of AI use; and Article 7(3) grants patients in healthcare a right to be informed about AI deployment.
In this context, the AGCM’s December 2025 DeepSeek decision illustrates an early enforcement example: the Authority required Italian-language disclaimers warning of hallucination risks in chatbot interfaces, registration pages and sensitive-topic outputs, establishing a practical benchmark for AI disclosure in consumer-facing applications. For details on this decision, see 4.1 Precedent-Setting Judicial Decisions.
In Italy, Article 5(d) of the AI Law directs public e-procurement platforms to favour AI solutions that guarantee data localisation and processing in domestic data centres and implement disaster recovery and business continuity in national facilities, thereby embedding data-sovereignty criteria into public-sector AI contracting. For public administrations, the AgID draft Procurement Guidelines provide a detailed operational framework, framed within the Public Contracts Code and NIS2/cybersecurity obligations.
Consistent with the EU AI Act’s value-chain approach (Articles 25-26), in Italy the AgID draft Procurement Guidelines reinforce these concepts with specific requirements for public-sector AI acquisitions, like:
These guidelines also emphasise that risk assessment must cover technological, organisational, economic and reputational dimensions.
Article 11 of the AI Law provides that AI must be deployed to improve working conditions, protect workers' psychophysical integrity, and enhance both productivity and quality of work, in conformity with EU law. The use of AI in the workplace must be safe, reliable, transparent, and must not conflict with human dignity or violate personal data privacy. Employers or principals are required to inform workers about the use of AI in accordance with Article 1-bis of Legislative Decree No. 152/1997. Furthermore, Article 11 mandates that AI in employment contexts must guarantee respect for workers' inviolable rights without discrimination based on sex, age, ethnic origin, religious beliefs, sexual orientation, political opinions, or personal, social and economic conditions. For background law on employment, see 1.1 General Legal Background.
Legislative Decree No. 104/2022 (Transparency Decree) imposes on employers a duty to inform employees about the use of automated decision-making systems that significantly affect working conditions, hiring, task allocation, or termination.
Article 12 of the AI Law establishes the Observatory on the Adoption of Artificial Intelligence Systems in the World of Work within the Ministry of Labour and Social Policies. The Observatory is tasked with defining a strategy for AI use in the workplace, monitoring its impact on the labour market, identifying sectors most affected by AI, and promoting training for both workers and employers on artificial intelligence matters.
Case law wise, Italian courts had, in fact, already addressed algorithmic management in the context of platform work; notably, the Court of Bologna (31 December 2020) found Deliveroo’s algorithm indirectly discriminatory, as it penalised riders absent from shifts regardless of whether the absence was due to strike action or illness.
Historically, Article 4 of Law No. 300/1970 (Workers’ Statute) prohibits remote monitoring of workers, requiring prior agreement with trade unions or authorisation from the labour inspectorate before deploying surveillance or control systems which may also indirectly or potentially trigger remote control (see 1.1 General Legal Background). The AI Law reinforces these protections with Articles 11-12 as well as Ministerial Decree No. 180/2025 as outlined above.
Pursuant to Recital 118 AI Act, insofar as AI systems or models are embedded into designated very large online platforms (VLOPs) or very large online search engines (VLOSEs), they are subject to the risk-management framework provided in the DSA. Consequently, the corresponding obligations of the AI Act should be presumed to be fulfilled, unless significant systemic risks not covered by the DSA emerge and are identified.
Furthermore, according to Recital 119 AI Act, AI systems may be provided as intermediary services or part thereof that fall under the scope of the DSA, for example to provide online search engines.
Article 15 of Law-Decree No. 123 of 15 September 2023 (converted into Law No. 159 of 13 November 2023) has designated AGCOM as the national digital service coordinator under Article 49 DSA.
To date, no enforcement action has been publicly announced or undertaken by AGCOM concerning the obligations under the DSA with respect to AI systems or models integrated into VLOPs or VLOSEs or provided as intermediary services or part thereof. At EU level, the Commission has recently announced that it will assess the possible designation of ChatGPT online search functionality under the DSA.
AI Governance and the TUF Reform
Italy has recently enacted Legislative Decree No. 47 of 27 March 2026 (the TUF Reform Decree), in force since 29 April 2026, which introduces for the first time within the Consolidated Financial Act (Testo Unico della Finanza, TUF) the explicit definitions of (i) artificial intelligence systems (by reference to Article 3(1) of the AI Act), and (ii) IT risks – ie, any reasonably identifiable circumstance relating to the use of IT and network systems which, if materialised, could compromise the security of such systems, any dependent tools or processes, operations and processes, or the provision of services, causing adverse effects in the digital or physical environment.
Furthermore, the TUF Reform Decree amends Article 123-bis of the TUF (governing the corporate governance report) by requiring listed companies to disclose: (i) where adopted, a description of the company’s policies on the use and monitoring of new technologies, in particular AI systems, within administrative, organisational and accounting structures; and (ii) where adopted, a description of the policies for managing and monitoring IT risks, including cybersecurity risks and risks arising from the integration of new technologies into administrative, organisational and accounting structures.
AI-Driven Credit Decision Making
Legislative Decree No. 212/2025 of 31 December 2025, implementing the Consumer Credit Directive 2 (Directive (EU) 2023/2225), introduced within the Consolidated Banking Act (Testo Unico Bancario, TUB) new rules for AI-driven credit decisions. Where a creditworthiness assessment relies, even partially, on automated data processing, the consumer has the right to: obtain a clear explanation of the assessment logic and its effects on the decision; express their opinion to the lender; and request a review with human intervention.
The lender must inform the consumer of these rights before initiating the automated processing of their personal data for creditworthiness purposes. These rights complement the protections under GDPR (see 17 Data Protection) and the AI Act's high-risk classification of credit scoring systems.
Regulatory Expectations
In April 2026, the Bank of Italy’s Senior Deputy Governor, during a speech presenting the joint OECD/Bank of Italy report on “AI in Italian Financial Markets”, outlined three priority areas:
Particular emphasis was placed on managing third-party dependencies, which can propagate risk across the system in ways that are difficult to detect.
No information has been provided in this jurisdiction.
No information has been provided in this jurisdiction.
No information has been provided in this jurisdiction.
No information has been provided in this jurisdiction.
The Italian AI Law and Amendments to the Copyright Act
Italy is the first EU member state to adopt a comprehensive national AI law. Article 25 of the AI Law amended the LDA (Article 1) to expressly require that protected works be works of “human” creation, while clarifying that works created with the assistance of AI tools may be protected “provided they constitute the result of the author’s intellectual work”. The new Article 70-septies LDA confirms that the TDM exceptions (Articles 70-ter and 70-quater) apply to text and data extraction through AI models, including generative AI (see 3.6 Data, Information or Content Laws for detailed TDM analysis).
Patent and Copyright Protection
Under Italian and European patent law, AI algorithms are excluded from patentability as such, but technical applications producing concrete technical effects may qualify. Software code implementing AI systems may be protected as a literary work under the LDA, provided it meets the originality threshold. Datasets may benefit from sui generis database protection (Articles 102-bis and 102-ter LDA). Trade secrets protection for model weights and training methodologies is also available under Articles 98-99 CPI.
Human Authorship Requirement under Italian Law
Under Italian law, neither patent nor copyright systems recognise AI as a legal subject. The CPI requires inventors to be natural persons; the LDA attributes authorship exclusively to natural persons. The AI Law codified this by amending Article 1 LDA to require that protected works be works of “human” ingenuity (see 1.1 General Legal Background for the legislative framework). At the same time, Article 1 now expressly provides that works created with AI assistance may be protected “provided they constitute the result of the author’s intellectual work”. To this end, factors such as iterative prompt refinement, output selection and substantial post-editing may establish the requisite human contribution. Works generated entirely by AI without qualifying human contribution fall outside copyright and moral rights protection.
Italian Case Law
No Italian case law has yet interpreted the AI Law’s new human authorship requirement, given its recent entry into force (October 2025). However, prior case law on algorithmically generated works offers relevant guidance. In Cass. civ. Sez. I, 16 January 2023, No. 1107, the Supreme Court considered a fractal image created using mathematical software - not AI in the contemporary sense, but an automated process. The Court declared the ground inadmissible as a new issue raised for the first time in cassation. However, it noted that the use of software to generate an image is “compatible with the elaboration of a work of authorship with a degree of creativity that would only need to be scrutinised with greater rigour” and that “a factual assessment would have been necessary to verify whether and to what extent the use of the tool had absorbed the creative elaboration of the artist who used it.” This reasoning suggests Italian courts will focus on whether the human exercised sufficient creative control over the automated process, rather than categorically excluding software-assisted works (see also 4.1 Precedent-Setting Judicial Decisions for pending litigation on AI training, RTI/Medusa v Perplexity).
Copyright Infringement and TDM Exceptions under Italian Law
Training AI models on copyrighted works might involve acts of reproduction within the meaning of Article 2 InfoSoc Directive. Italy transposed the TDM exceptions through Articles 70-ter (research organisations) and 70-quater (commercial use, subject to opt-out) LDA. The new Article 70-septies, introduced by the AI Law, expressly confirms that reproductions and extractions for TDM through AI models, including generative AI, are permitted in accordance with Articles 70-ter and 70-quater, subject to the Berne Convention (see 3.6 Data, Information or Content Laws for the opt-out mechanism analysis). As mentioned above, Italian law leaves the choice of technical mechanism to rightholders, creating uncertainty about what constitutes a valid and enforceable opt-out. The GPAI Code of Practice might fill this gap by endorsing protocols “already consolidated in web crawling practice”, but its voluntary nature and “best efforts” clauses have drawn criticism as insufficiently binding.
On the other side, the key concern remains the absence of independent verification that AI developers effectively exclude opted-out content. This is compounded by: (i) the limited granularity of transparency obligations under Article 53 AI Act, which requires only a “sufficiently detailed summary” of training data rather than work-by-work disclosure; and (ii) the lack of formal requirements for exercising the opt-out in Italian law.
Licensing and Collective Management
While at global level commercial AI developers are increasingly entering licensing agreements with content owners and Collective Management Organisations (CMOs), who are exploring collective licensing mechanisms. At the time of writing there is only one notable case in the Italian landscape: Musixmatch, an Italian-based lyrics and music data company, entered AI licensing agreements with three major music publishers (Sony Music Publishing, Universal Music Publishing Group, and Warner Chappell Music) gaining access to catalogues of over 15 million musical works to develop analytical and non-generative AI services, with compensation flowing to publishers and songwriters (2025).
No Italian CMO has, at the time of writing, publicly announced it concluded a formal licensing agreement for AI training. However, several have taken preparatory steps. SIAE (the main authors and publishers’ CMO) has exercised a collective opt-out from TDM, reserving reproduction rights for its entire repertoire, and has amended its standard licences to expressly exclude TDM/AI training uses. SCF (neighbouring rights for major labels) has revised its mandate agreement to exclude AI-generated recordings from protection and is reassessing policies in light of the majors’ deals with AI platforms (Udio, Suno). Industry associations (FIEG, for newspaper publishers, and AIE, book publishers) have advocated for simplified opt-out mechanisms, shared licensing models, fair compensation, and declared insertion of explicit TDM/AI reservation clauses in their publications. Other performers’ CMOs (Nuovo IMAIE, LEA, Itsright) have not yet publicly adopted specific measures.
AI-Related IP Litigation in Italy
The only IP/copyright litigation brought in Italy at the time of writing and concerning the use of protected works for AI training is RTI SpA and Medusa Film SpA v Perplexity AI Inc., filed on 3 December 2025 before the Civil Court of Rome. The claimants allege that Perplexity scraped and reproduced their audiovisual content without authorisation to train its “Sonar” LLM, invoking Articles 1, 2, 45, and 78-ter LDA as well as the three-step test under the Berne Convention, and seek injunctive relief and damages (see 4.1 Precedent-Setting Judicial Decisions for further discussion).
AI-Generated Works Under Italian Copyright Law
Under Italian and EU copyright law, works generated entirely by AI without meaningful human creative input do not qualify for protection. The AI Law codified this by amending Article 1 LDA to require “human” ingenuity (see 16.1 IP Protection for AI Assets).
Human-AI Collaborative Works and Ownership
Where humans interact meaningfully with AI – eg, through iterative prompt refinement, output selection, substantial editing or integration with original content - the resulting work may qualify for protection. As discussed in 16.2 AI as Inventor/Author, the AI Law amended the LDA to permit protection for AI-assisted works “provided they constitute the result of the author’s intellectual work”. Ownership vests in the natural person who made the qualifying creative contribution.
Moral Rights
For AI-assisted works qualifying for protection, the human author retains moral rights under Italian law, including the right of attribution and integrity (Articles 20-24 LDA). These rights are personal and inalienable. Works generated entirely by AI without qualifying human contribution fall outside moral rights protection, as there is no author in whom such rights could vest.
Italian law does not contain specific provisions on foundation models, open-source AI licensing, derivative works, fine-tuning rights, or model merging/distillation. The applicable framework is the EU AI Act: Article 2(12) which exempts AI systems released under free and open-source licences from certain obligations (unless high-risk), and Article 53(2) which grants GPAI providers transparency exemptions where model parameters, architecture and usage information are publicly available. GPAI models with systemic risks remain fully regulated regardless of licensing model.
Personal data processing for AI training under Italian law requires strict compliance with GDPR and the Italian Privacy Code.
Lawful basis remains a critical issue. The DPA’s ChatGPT orders (March–April 2023) confirmed that large-scale data collection for training must rely on a valid legal basis, while later scrutiny of GEDI Gruppo Editoriale data-sharing with a major LLM provider has cast doubt on the suitability of legitimate interests in this context. A more specific framework has emerged under Article 8 of the AI Law, which recognises certain AI-driven scientific research in healthcare as a substantial public interest task under Article 9(2)(g) GDPR, subject to conditions such as non-identifiability and prior DPA notification.
Purpose limitation and data minimisation are also key constraints. The DPA’s 2025 decision fining Menarini Silicon Biosystems SpA identified, inter alia, unclear purposes and retention periods in AI health-data training. Similarly, the 2024 warning to GEDI emphasised that data subjects could not reasonably expect journalistic archive data to be repurposed for AI training.
On data minimisation, the Italian tax administration’s approach (exclusion of data falling under Articles 9 and 10 GDPR from automated risk analysis) remains a benchmark.
Data subject rights (including access, erasure and objection) remain fully applicable, albeit difficult to operationalise in trained models. In the ChatGPT case, the DPA required mechanisms for correction or deletion of outputs as a condition for lifting its temporary ban.
Processing of special category data is generally prohibited absent specific derogations. In a 2024 decision against the Municipality of Trento, the DPA sanctioned AI surveillance involving Articles 9 and 10 GDPR data without adequate legal bases and sufficient anonymisation safeguards.
Anonymisation and pseudonymisation are strictly interpreted by the Italian DPA; ineffective techniques may still trigger GDPR applicability, as shown in the 2023 Thin Srl case, where allegedly anonymised health data remained identifiable. The 2023 “Decalogue” on AI in healthcare further stresses data accuracy, robustness of anonymisation, and documentation of training metrics and data quality assessments.
Finally, accountability requires documentation, bias monitoring and privacy-by-design, reinforced by the AI Law and DPA guidance, including the AI healthcare Decalogue and 2024 web scraping guidance.
AI deployment in Italy is governed by a layered framework (inclusive of the GDPR, the Italian Privacy Code, and the AI Law) imposing strict requirements on lawful bases, transparency, and data subject rights.
Italian DPA enforcement shows that each personal data processing by AI must rely on a clearly identified legal basis. In the 2023-2025 Replika chatbot case, the DPA challenged the controller’s reliance on contractual necessity, including as regards the processing of children’s data. Similarly, in its 2024 warning to GEDI Gruppo Editoriale, the DPA scrutinised the use of legitimate interests for the transfer of personal data to an LLM provider, finding that insufficient transparency and unclear role allocation undermined the asserted legal basis.
Transparency is a central enforcement focus in AI-driven processing and has been repeatedly addressed in DPA enforcement actions, including those concerning Menarini Silicon Biosystems SpA, Replika, and the 2024 Foodinho case.
Data subject rights are also strongly protected. In particular, the DPA has consistently stressed the right to obtain human intervention and to contest automated decisions. In the 2024 Foodinho decision, the DPA found that two algorithmic systems had been deployed without implementing GDPR safeguards for automated decision-making, including riders’ rights to human intervention, to express their point of view, and to challenge algorithmic outcomes. The Italian Supreme Court of Cassation (Judgment No. 28358 of 10 October 2023) further clarified that, for consent to be valid, the underlying algorithm must be described in an intelligible manner.
Children’s data is subject to enhanced safeguards under the AI Law, which requires parental consent for access to AI technologies or related processing by children under 14, and clear, accessible information for older minors. Enforcement actions, including the Replika case, addressed the absence of effective age-verification mechanisms and risks posed to minors by AI chatbots.
Finally, data retention in AI systems is under increasing scrutiny, with recent decisions (including Menarini Silicon Biosystems and Replika) criticising unclear retention periods and requiring greater transparency on storage practices and data transfers in AI contexts.
Italian data governance requirements for AI systems are shaped also by GDPR, the Italian Privacy Code, DPA guidance, and the AI Law.
Data protection impact assessments under Article 35 GDPR are typically a key requirement for AI processing, consistently emphasised by the DPA, including in its Decalogue for AI in healthcare, the 2024 Municipality of Trento decision, and Opinion No. 276/2022 on the tax administration’s use of ML for risk assessment.
The principle of data protection by design and by default is equally fundamental; it has been repeatedly addressed by the DPA (including in the Decalogue and the 2024 web scraping guidance), and further strengthened by the AI Law requiring data quality, security, transparency, and ongoing, proportionate monitoring.
Controller-processor relationships in AI supply chains are particularly critical, requiring clear allocation of roles and responsibilities, robust due diligence, and auditable oversight of providers. In this respect, the DPA’s 2024 warning to GEDI Gruppo Editoriale highlighted risks of unclear processing roles and ineffective data subject rights where an LLM provider acts as an independent controller.
Finally, cross-border data transfers for AI training and deployment must comply with GDPR Chapter V and EDPB guidance. The 2022 Clearview AI decision confirms that large-scale web scraping cannot circumvent EU transfer rules. The 2025 Replika decision required clarification of international transfers in privacy policies, reflecting scrutiny of transfers of Italian users’ personal data to countries lacking an adequate level of protection.
In July 2025, AGCM opened proceedings against Meta concerning the integration of Meta AI into WhatsApp (Case A576). The investigation was expanded in November 2025 to address WhatsApp’s new Business Solution Terms barring rival AI chatbot providers from the platform. In December 2025, AGCM adopted interim measures ordering Meta to suspend the contested policy. The authority expressed concerns that control over a dominant messaging platform could be leveraged to exclude AI competitors, representing one of Italy’s first formal antitrust investigations at the intersection of AI services and platform dominance. The European Commission subsequently opened parallel proceedings on the same conduct.
Also in December, AGCM closed proceedings against DeepSeek (Case PS12942), accepting commitments from the Chinese platform. Though formally a consumer protection matter (see 4.1 Precedent-Setting Judicial Decisions for details), this illustrates the authority’s willingness to scrutinise AI service providers. The proceeding addressed LLM hallucinations and resulted in commitments requiring enhanced user disclosure of AI output limitations, demonstrating how existing unfair commercial practice rules under the Consumer Code can effectively regulate AI services.
Cybersecurity requirements applicable to AI systems stem primarily from EU and national frameworks, rather than AI-specific legislation. Key instruments include the NIS2 Directive (Directive (EU) 2022/2555), the National Cybersecurity Perimeter regime (Decree-Law No. 105/2019), and ACN technical guidance. AI systems are not regulated as a standalone category but fall within broader network and information systems used by essential and important entities. Although AI-specific threats are not expressly regulated in Italy, they are indirectly covered by NIS2 obligations requiring the implementation of proportionate technical and organisational measures to manage cybersecurity risks and incident reporting. Such obligations apply where incidents significantly impact service continuity or integrity, and must be notified to competent authorities and CSIRT Italia within the statutory deadlines, regardless of AI use.
NIS2 also expressly addresses supply chain security, requiring risk assessments and management of suppliers and ICT/AI-related third parties, including cloud and software providers, through appropriate contractual, technical and organisational safeguards to ensure resilience. It further covers vulnerability management and disclosure, also relevant to AI tools.
Finally, AI use in cybersecurity defence is not specifically regulated but permitted, provided compliance with cybersecurity, data protection, and accountability requirements, including appropriate governance, oversight, and auditability.
In Italy, the ESG dimensions of AI are addressed through the AI Law and related soft-law instruments, encompassing environmental sustainability, non-discrimination, and governance principles.
Article 3 of the AI Law includes sustainability among core principles. The AgID draft Guidelines for AI Development in PA require energy efficiency, computational proportionality, and sustainability criteria across the AI stack. Article 3 also enshrines non-discrimination, transparency, explainability, and human oversight. Article 11 mandates that workplace AI be safe, transparent, protect worker dignity, ensure human oversight, and prohibit discrimination (see 14 Employment). Article 12 establishes the Observatory on AI in the Workplace.
In Italy, AI governance frameworks are shaped by the interplay between the AI Act and national implementing legislation. The AI Law designates ACN and AgID as the competent authorities responsible for AI oversight (see 5.1 Regulatory Agencies), while sector-specific regulators (Bank of Italy, CONSOB, IVASS) retain market surveillance powers for financial services AI. The AgID Guidelines on AI Development and Procurement (though still a draft, see 3.3 Jurisdictional Directives) will provide operational guidance for public administrations, requiring risk management systems, fundamental rights impact assessments (FRIAs), human oversight mechanisms, and transparent documentation throughout the AI lifecycle. For certain deployers of high-risk AI systems (eg, in financial and insurance services), Article 27 of the AI Act mandates FRIAs, which can be integrated with existing GDPR Data Protection Impact Assessments.