-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
Italian Law No. 132 of 23 September 2025 (“Law 132/2025”), the national framework law on artificial intelligence, in force since 10 October 2025, adopts the definition set out in Article 3(1) of Regulation (EU) 2024/1689 (“AI Act”). Under Article 2 of Law 132/2025, an “AI system” is a system defined by Article 3, point (1), of the AI Act, and an “AI model” is the model defined by Article 3, point (63), thereof. For matters not expressly addressed, Law 132/2025 refers back to the AI Act’s definitions. Accordingly, the applicable definition is the one provided by the AI Act, which defines an AI system as “a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments”.
The European Commission provides an interpretation of this definition in its “Guidelines on the Definition of an Artificial Intelligence System under the AI Act”.
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
Yes, Italy has developed a national strategy for AI. In April 2024, AgID (Agenzia per l’Italia Digitale, i.e., the Italian authority with competence on various digital matters) and the Department for Digital Transformation (a branch pertaining to the Office of the President of the Council of Ministers) published an executive summary of the Italian AI Strategy, which outlines the framework of Italy’s AI strategy for the period stemming from 2024 to 2026, structured around four key pillars:
- Scientific Research: The strategy emphasizes enhancing the national AI research ecosystem by fostering collaboration among universities, research centers, and businesses. It aims to support the development of innovative startups, attract and retain talent, and promote advanced AI research.
- Public Administration: The plan includes using AI to improve the efficiency of public administration and provide better services to citizens. This involves developing AI systems for interoperability, ensuring proper data management, and training public personnel in AI.
- Business and Industry: The strategy aims to integrate AI into Italy’s industrial and entrepreneurial sectors, especially within SMEs, to boost competitiveness and innovation. It supports collaboration between ICT companies and research institutions, enhances regulatory and certification processes, and promotes AI adoption among SMEs through funding and development of AI solutions.
- Education and Training: Addressing the shortage of AI skills, the strategy proposes enhancing AI education across all levels, from schools to PhD programs. It includes initiatives for upskilling and reskilling workers in both the public and private sectors and promoting AI literacy among the general population.
The strategy also underscores the importance of ethical AI, focusing on privacy, security, gender issues, and environmental sustainability. It aims to ensure AI development and deployment adhere to these principles.
The strategy is supported by public investments and involves multiple stakeholders, including the Ministry of Enterprises and Made in Italy, the Ministry of University and Research, and the Ministry of Technological Innovation and Digital Transition.The document provided a comprehensive understanding of the Italian government’s AI objectives and prepared the groundwork for the domestic AI law that has since been enacted as Law 132/2025, which complements the AI Act by addressing specific sectors within Italy.
Law 132/2025 has since placed the national strategy on a statutory footing. Under Article 19, the strategy is prepared and periodically updated by the department of the Presidency of the Council of Ministers responsible for technological innovation and digital transition, in agreement with the national AI authorities, and is approved at least every two years by the Interministerial Committee for the Digital Transition (CITD), with the monitoring results transmitted annually to Parliament. A revision of the 2024-2026 Strategy is accordingly expected within this biennial cycle.
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
Italy has taken steps to address the regulation of AI through a combination of national regulation, guidelines and alignment with EU initiatives, in particular in the context of the AI Act.
1. AI Act
The EU AI Act, which applies in Italy given its status as an EU Member State, aims to establish a harmonized legal framework for AI across the EU. The AI Act establishes a harmonised, risk-based regulatory framework for AI across the EU and applies directly in Italy, according to its phased application timetable. High-risk AI systems will face stringent requirements, including mandatory risk assessments, data governance standards, and transparency obligations.
2. Italian AI Law (Law 132/2025)
Italian Law No. 132/2025 represents Italy’s first comprehensive legislative effort to regulate AI, in alignment with the AI Act. Enacted on 23 September 2025 and in force since 10 October 2025, the Law sets out a normative framework encompassing general principles, sector-specific rules, supervisory mechanisms, and delegated powers to the Government for further legislative development. The Government must now exercise those delegations through implementing legislative decrees within twelve months of entry into force (i.e., by 10 October 2026). As of early July 2026, the first schemes of such decrees — concerning, among other things, the powers of the national authorities and AI training and literacy, and, separately, the use of AI in policing together with related civil and criminal liability profiles — had been approved only at preliminary examination by the Council of Ministers (10 June 2026) and are therefore not yet in force.
The legislation is built around an anthropocentric approach to AI, promoting responsible innovation while protecting fundamental rights. It mandates compliance with EU rules and integrates core values such as transparency, non-discrimination, human oversight, and cybersecurity. The Law also establishes that the Italian government will support AI-driven economic growth, encourage innovation ecosystems, and facilitate access to high-quality datasets for research and industry.
Sector-specific applications are addressed. For instance, in healthcare, AI is framed as a support tool to enhance diagnostics, treatment, and patient care, without replacing human decision-making. Special safeguards are imposed for minors and individuals with disabilities. In the labour sector, AI must uphold workers’ rights, and a new monitoring body will monitor its impact on employment. The use of AI by liberal professions is further regulated, by including disclosure obligations vis-à-vis the client, where the professional wishes to leverage AI in the context of their work. The Law also sets boundaries for the use of AI in the judiciary, reserving decision-making powers exclusively to judges, and in public administration, where it is intended as a tool to streamline services without displacing human accountability.
To implement and oversee the AI framework, including the AI Act, the Law designates AgID (Agenzia per l’Italia Digitale) and ACN (Agenzia per la Cybersicurezza Nazionale) as national authorities. These bodies are charged, respectively, with accrediting notified bodies tasked with conducting third-party conformity assessments on providers of high-risk AI systems, and with supervising cybersecurity and market compliance. Other sector-specific authorities are also foreseen, in particular Banca d’Italia and CONSOB in the banking sector, and IVASS in the insurance field.
3. National Strategy for Artificial Intelligence (AI) 2024-2026
As mentioned in the answer above, AgID published the executive summary of the National Strategy for AI, which outlines the strategic vision for the development and use of AI in Italy, focusing on 4 pillars (scientific research, public administration, business and education). The strategy includes non-binding guidelines and policy measures, including ethical recommendations on AI use, focus on transparency and fairness, and public-private partnerships. This strategy is not legally binding, but aims to guide national efforts and funding allocations (e.g., via the Italian declination of the Next Generation EU, i.e., the Piano Nazionale di Ripresa e Resilienza (“PNRR”) – the National Recovery and Resilience Plan).
4. Guidelines by the Italian Data Protection Authority
The Italian Data Protection Authority has issued guidelines on the ethical and legal use of AI, emphasizing the importance of data protection and privacy. In particular, the Authority has published a Decalogue for the implementation of national health services through AI systems, and the Guidelines for defending personal data from web scraping (more on this at Question 15). Furthermore, the Authority has conducted investigations into ChatGPT, DeepSeek and other generative AI models for compliance with the GDPR. The investigation and subsequent sanction against OpenAI — one of the first enforcement actions in the EU for GDPR violations by a large language model (LLM) provider — has been highly influential. The case demonstrated the determination of the Italian Authority to enforce the GDPR’s applicability in the complex context of generative AI, drawing significant public and regulatory attention across the EU and setting an early precedent for enforcement in this area.
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
Transparency and explainability obligations stem primarily from the AI Act, which applies in Italy. For high-risk AI systems, providers must ensure that operation is sufficiently transparent to enable deployers to interpret and use the output (Article 13), maintain technical documentation and automatic logging, and undergo a conformity assessment before the system is placed on the market. Separately, Article 50 imposes transparency duties: persons must be informed when they interact with an AI system, and content that is artificially generated or manipulated (including deepfakes and synthetic text, image, audio or video) must be marked and disclosed as such. Outputs produced by generative AI systems must be labelled in a machine-readable way. Finally, in case of deployment of biometric-based AI systems, including emotion recognition, affected individuals must be informed in advance of their operation. These transparency obligations become applicable from 2 August 2026 or from 2 December 2026 (depending on the type of system).
Law 132/2025 reinforces these principles at national level. Specific disclosure duties apply across sectors: patients have the right to be informed of the use of AI in healthcare (Article 7); public administrations must ensure the “knowability” of how the AI functions and the traceability of its use (Article 14); and, most notably for professional services, members of the liberal professions must inform the client — in clear, simple and exhaustive language — of the AI systems they use (Article 13).
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
Most notably under the AI Act, high-risk AI systems must be designed to allow effective human oversight, including the ability to monitor their operation, to intervene and to override the system (Article 14). Law 132/2025 elevates human oversight to a general principle: AI must be developed and applied in compliance with human autonomy and decision-making power, ensuring human supervision and intervention (Article 3).
The Law translates this principle into sector-specific reservations of human decision-making. In healthcare, AI is a support tool and the decision always remains with the medical professional (Article 7). In the intellectual professions, AI may be used only for instrumental and support activities, with the human intellectual work remaining predominant (Article 13). In public administration, the natural person remains solely responsible for the measures and proceedings in which AI is used, the technology serving a merely instrumental and supporting function (Article 14). In the judiciary, every decision on the interpretation and application of the law, the assessment of facts and evidence, and the adoption of measures is always reserved to the judge (Article 15).
Where solely automated decisions produce legal or similarly significant effects on individuals, Article 22 GDPR provides further safeguards, including the right to obtain human review and challenge the decision, while Decree-Law No. 62/2026 specifies and enhances this right in the platform work sector.
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
Yes. Non-discrimination and gender equality are express general principles of Law 132/2025: the development and use of AI must respect the principles of non-discrimination and equality of the sexes (Article 3). In healthcare, the introduction of AI may not select or condition access to care according to discriminatory criteria (Article 7). In the employment context, AI used to organise and manage the employment relationship must safeguard the worker’s inviolable rights, without discrimination on grounds of sex, age, ethnic origin, religious belief, sexual orientation, political opinions and personal, social or economic conditions (Article 11).
Under the AI Act, providers of high-risk AI systems must apply data governance measures, including the examination of training, validation and testing datasets for possible biases capable of leading to discrimination, and must ensure appropriate data quality (Article 10). These requirements operate alongside Italy’s body of anti-discrimination law — transposing the EU Race, Employment Equality and gender-equality directives (e.g., Legislative Decrees No. 215/2003 and No. 216/2003 and the Code of Equal Opportunities) — which applies to AI-driven decisions affecting protected grounds, in particular in employment and in access to goods and services.
On the case-law side, the Court of Bologna found unlawful the “Frank” algorithm used by Deliveroo to allocate work among riders: by penalising riders who did not honour booked sessions, the system indirectly disadvantaged those who, for example, exercised their right to strike, and the court ordered the platform to compensate the claimant trade unions. The case illustrates how apparently neutral algorithmic criteria can produce indirect discrimination, and how existing anti-discrimination and labour-law principles already apply to algorithmic management.
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
In Italy, the legal framework governing defective AI systems is influenced by several areas of law, including consumer protection, product liability, and special regulations.
In Italy, AI systems which are embedded as components in products, or AI systems which are products themselves, are subject to the Italian product liability framework, when such AI systems produce damages to individuals. Today, the framework is governed by Legislative Decree No. 206 of 2005, the “Consumer Code”, which implements both the EU Product Liability Directive (Directive 85/374/EEC) and the EU General Product Safety Directive (Directive 2001/95/EC).
However, it should be noted that in November 2024, such framework has been revamped at the EU level by the entry into force of Directive (EU) 2024/2853. EU Member States, including Italy, are required to transpose at the national level the rules set forth by the new Directive, by 9 December 2026 at the latest. This upcoming framework is meant to modernize the Union’s product liability rules, adapting them to the complexities in the chain of responsibility that derives from the data-driven economy. As such, the new framework expressly tackles software, AI systems and connected products (IoT), setting forth new rules that are more favorable to the claimant, in terms of both the burden of proof and disclosure rights vis-à-vis the manufacturer.
Still, the current framework – pending the transposition of the new Directive – holds producers and suppliers liable for any damage caused by defective products, which may include AI systems. Consumers can seek compensation from the producer if the AI system does not meet the safety standards they are entitled to expect.
Aside from civil liability, AI systems providers and deployers may face administrative fines in case where they fail to comply with applicable rules.
In this respect, although not yet applicable in full, the EU AI Act creates a comprehensive regulatory framework for AI across the EU, including Italy. This regulation adopts a risk-based approach, classifying AI systems into different risk categories and imposing varying levels of obligations and requirements on providers and deployers to ensure safety and compliance. The regulation provides for pecuniary sanctions up to 7% of the global annual turnover of a company; however, it does not establish an ad-hoc right for compensation in favor of individuals that have suffered damages from AI systems.Data protection remedies can also be invoked by the individual (as “data subject”) that has suffered damages from AI systems as a result of data protection violations taking place where the AI system has processed their personal data. Pecuniary sanctions under the GDPR may reach up to 4% of the global annual turnover of a company. In case where the individual has suffered damages as a result of AI data protection violations, the GDPR provides for a right to compensation.
In terms of liability, in Italy, while there is not a specific liability regime for AI systems, both civil and criminal liability rules may apply when damage is caused by such systems. A combination of traditional legal principles and rules (concepts such as the special liability for defective products, responsibility from hazardous activity, fault-based liability and liability for things) and recent legislative developments — particularly Law 132/2025— shapes the current and future liability framework. Below is an overview.
Civil liability for damages caused by AI systems in Italy has traditionally been governed by a combination of contractual and extra-contractual rules, notably:
- Art. 1218 of the Italian Civil Code (contractual liability): Establishes the debtor’s liability for failure to perform exactly as promised, unless the debtor can prove that the non-performance was due to an event beyond their control (force majeure).
- Art. 2043 of the Italian Civil Code (general clause for tort-based liability): Outside of a contractual relationship, any person who causes unjust harm to another through intentional misconduct or negligence is obliged to compensate for the damage.
- Art. 2050 of the Italian Civil Code (liability for dangerous activities): Applies when the activity involving AI systems is considered inherently dangerous due to the technology’s complexity and potential risks. The operator is liable unless they prove they took all appropriate measures to prevent harm.
- Art. 2051 of the Italian Civil Code (liability for things in custody): May be applied to AI systems considered as “things” under custody, whereby the custodian (e.g., developer, deployer, or user with effective control) is liable for damages unless they prove that the damage resulted from an unforeseeable and unavoidable event (force majeure).
Concerning criminal liability, Law 132/2025 introduced a new criminal offence in the Italian Criminal Code (Article 612-quater, titled “Illicit dissemination of artificially generated or manipulated content”), which provides as follows (authors’ translation):
Anyone who causes unjust harm to a person by disclosing, publishing, or otherwise disseminating – without their consent – images, videos, or audio recordings that have been falsified or altered through the use of artificial intelligence systems and are capable of misleading others about their authenticity, shall be punished with imprisonment from one to five years […].
In this regard, to trigger the criminal provision it is arguably necessary that harm to others (e.g., economic, reputational, moral) occurs through the sending, delivery, assignment publication or dissemination of AI-generated audio or audiovisual material. Also, in order to protect other constitutionally guaranteed rights (e.g., freedom of expression, right to satire), a constitutive element of the offense concerns the suitability of the material to mislead as to its genuineness or origin.
Similar provisions have been included for the criminal provision related to corporate or banking market rigging (Article 2637 Civil Code).
The Law 132/2025 also introduced a new aggravating circumstance under Article 61 of the Criminal Code, when AI is used as an “insidious means” in the commission of a crime. The aggravating circumstance can apply to all existing criminal offences, thus leading to a higher sentence for the offender(s) in case when AI is used as an “insidious means” to commit a crime.
-
What cybersecurity obligations apply to AI systems?
Cybersecurity is considered as a constitutive element for trustworthy AI. Law 132/2025 requires cybersecurity to be ensured throughout the entire life cycle of AI systems and general-purpose AI models, on a proportionate, risk-based approach, together with specific security controls ensuring resilience against attempts to alter the system’s use, intended behaviour, performance or security settings (Article 3). Under the AI Act, providers of high-risk AI systems must design them to achieve appropriate levels of accuracy, robustness and cybersecurity, including resilience against attempts to manipulate the system through AI-specific cyberattack techniques such as data or model poisoning (Article 15).
At institutional level, Law 132/2025 designates the National Cybersecurity Agency (ACN) as one of the two national AI authorities, responsible for supervision — including inspection and sanctioning powers — of AI systems and for their cybersecurity profiles (Article 20), and tasks the ACN with promoting AI as a resource to strengthen national cybersecurity (Article 18).
These obligations operate alongside Italy’s general cybersecurity framework, which also applies to AI systems, where applicable: the NIS2 regime (Directive (EU) 2022/2555, transposed by Legislative Decree No. 138/2024), the national cybersecurity law (Law No. 90/2024), and, for the financial sector, the DORA Regulation (Regulation (EU) 2022/2554) on digital operational resilience.
AI cybersecurity in Italy is therefore governed by a layered framework combining the AI Act’s product-level security requirements, the life-cycle principle of Law 132/2025, and the horizontal NIS2, DORA and GDPR regimes.
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
Currently, in Italy there is no specific insurance coverage tailored on the use of AI systems. Traditional insurance policies designed for civil liability, cybersecurity, product liability, and directors’ liability can be customized to address the risks associated with AI systems by providing further coverage.
Under the Law 132/2025, in exercising the delegation powers, the Government, in addition to the general principles and guidelines set out in Article 32 of Law No. 234 of 24 December 2012, can make the necessary amendments, additions, and repeals to the current legislation, including that concerning insurance, in order to ensure proper and full compliance with the AI Act.
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
No. Under the current Italian and European patent framework, an artificial intelligence system cannot be named as the inventor in a patent application filed in Italy.
Italian patent law requires the inventor to be designated in the patent application, and the legal framework is still built around the attribution of inventorship to a human person. Although the Italian Industrial Property Code does not contain a specific rule expressly addressing AI-generated inventions, the current position is that an AI system lacks legal personality and cannot hold the personal status of inventor. An AI system may be used as a tool in the inventive process, including as a sophisticated technical tool, but it cannot itself be designated as the inventor.
This position is consistent with the approach taken under the European Patent Convention. In the DABUS cases, the European Patent Office confirmed that a machine is not an inventor within the meaning of the EPC and refused applications in which the AI system DABUS had been designated as inventor.
The issue was treated as a formal requirement concerning the designation of the inventor, separate from the substantive patentability of the claimed invention.
Accordingly, an invention involving the use of AI is not excluded from patent protection merely because AI was used in the research or development process. However, the patent application must identify one or more human inventors who made the relevant inventive contribution. The applicant or patent owner may be a company or another legal person, where the rights have been acquired by law, contract, employment rules or assignment, but that is a separate question from inventorship.
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
The Law 132/2025 sets forth in Article 25 a set of rules that introduced significant changes to the Italian Copyright Law (Law No. 633/1941). A modification to Article 1 of Copyright Law allows works generated with the assistance of AI to be protected by copyright, provided that (i) the works originate from human intellect, and (ii) the forms of expression generated with the assistance of AI are the result of the author’s intellectual work. While this provision grounds a human-centric view of AI, it raises interpretive doubts, as it shifts onto the author the burden of proving the creativity and relevance of their contribution. Furthermore, the wording is arguably unclear, as it does not indicate how the author’s intellectual work is to be assessed, whether quantitatively or qualitatively.
Law 132/2025 also introduced of a new Article 70-septies into the Italian Copyright Law. The provision does not create a standalone opt-out regime for AI training. Rather, it states that reproductions and extractions from works or other materials available online or in databases for text and data mining through AI systems, including generative AI systems, are permitted in accordance with Articles 70-ter and 70-quater of the Copyright Law. The rights-reservation mechanism, including reservation by machine-readable means for online content, derives from the broader text and data mining framework under Article 4 of Directive (EU) 2019/790 and its Italian implementation.
Beside the new Law 132/2025, the case law provides some insights on new regulatory trends in Italy. More precisely, in Ruling No. 1107 of 09.01.2023, the Italian Supreme Court of Cassation ruled that the reproduction of an image constitutes infringement of the creator’s copyright, even in cases where the creative process was perfected by making use of a software. According to the Supreme Court, in fact, the use of digital technology for the realization of a work does not in itself preclude the possibility of recognizing the work as the fruit of the intellect, except in cases where the use of technology has not predominantly absorbed the creative elaboration of the artist. The protection of the work, therefore, would be guaranteed in the case where the creative elaboration of a human is significant, while in the case where the creative contribution of a human is marginal, traditional protections cannot be leveraged.
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
Beside all the already mentioned issues related to the use of AI, when deploying AI systems in the workplace several labor law provisions must be considered to ensure compliance.
Workplace surveillance & privacy
Italian labor law imposes strict limits on employers’ possibility to monitor employees. Article 4 of the Workers’ Statute (Statuto dei Lavoratori) regulates the use of surveillance equipment, which may include AI systems which process workers’ personal data. The provision prohibits the use of any tool which is directly intended to monitor or surveil the performance of workers. Furthermore, it mandates that installing systems which may indirectly entail the monitoring of workers may take place only for specific and documented purposes (which must be related to organizational, production, occupational, safety, or protection of company assets). Moreover, the deployment of such tools must always subject to a prior agreement with trade union representatives or, when those are not present or where an agreement is nor reached, to a prior authorization from the comptentent Labour Inspectorate (Ispettorato del Lavoro), at the local or national level depending on the circumstances.
Discrimination and Bias
AI systems must not be used in a way that discriminates against employees based on protected grounds such as race, gender, age, or religion, pursuant to Italian anti-discrimination law in the workplace, which transposes the relevant EU directives. Ensuring that AI algorithms do not perpetuate unlawful biases is crucial. AI systems used for performance evaluations must be fair, transparent, and non-discriminatory. Employers must ensure that such systems do not lead to discriminatory treatment of the worker.
Health and Safety
The use of AI should not create new health and safety risks for workers. Employers are responsible for ensuring a safe working environment, which includes assessing and mitigating risks associated with new technologies. The introduction of AI can lead to increased stress, anxiety or other kinds of negative emotions amongst employees, so employers should consider the psychological impact and provide appropriate support.
AI Act Compliance
The AI Act classifies as “high-risk” the AI systems used in the context of employment, workers’ management and access to self-employment, pursuant to Article 6(2) and Annex III, point 4.
As such, those AI systems must, inter alia, comply with strict requirements including comprehensive risk assessments, robust human oversight to ensure human intervention when necessary, thorough documentation and record-keeping obligations, accuracy, robustness, cybersecurity standards, transparency obligations regarding the functioning and decision-making processes of the AI, as well as ongoing monitoring and appropriate corrective actions when risks or malfunctions are identified.
The Law 132/2025 introduces a dedicated regulatory framework for the use of AI in the workplace (Articles 11-12), establishing clear principles aimed at ensuring that AI enhances, rather than undermines, workers’ rights. It mandates that AI systems be used to improve working conditions, productivity, and the protection of workers’ psychophysical integrity, while explicitly prohibiting practices that compromise human dignity or violate data protection and non-discrimination norms. The Law 132/2025 requires employers to inform workers transparently when AI is used in employment contexts, including hiring and performance evaluation, and emphasizes the necessity of maintaining human oversight over all automated decision-making processes. Furthermore, the legislation establishes a national Observatory on AI in the labor market, tasked with monitoring the effects of AI deployment across sectors, promoting training initiatives, and guiding future labor strategies in alignment with evolving technological standards.
Transparency and Accountability
Employers must ensure that AI systems are transparent and that workers understand how these systems make decisions affecting them.
In Italy, Legislative Decree No. 104/2022 (the so-called “Transparency Decree”), transposing Directive (EU) 2019/1152, introduced specific transparency obligations for employers regarding the use of automated decision-making and monitoring systems. Employers must provide the worker with clear information about how these systems function, their purposes, the types of decisions they make, and their potential implications for employees.In the employment context, the so-called Transparency Decree (Legislative Decree No. 104/2022, transposing Directive (EU) 2019/1152) already requires employers to disclose the use of fully automated decision-making or monitoring systems and to explain their logic, purposes and effects. More recently, Decree-Law No. 62 of 30 April 2026 on platform work introduced, for workers managed through automated or algorithmic systems, information obligations and a right, on request, to an “intelligible explanation” and to human review of automated decisions affecting working conditions or pay (Article 14).
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
Italy, as a member of the European Union, is subject to the GDPR. The use of AI must therefore comply with GDPR requirements, and with the complementary Italian privacy provisions (D.lgs 196/2003, the “Privacy Code”).
Starting from the above, it should be noted that not all AI systems leverage personal data. For those that do, however, the privacy issues can be categorized into several areas:
- Security: AI systems often require large datasets, which may include personal information. Ensuring the security of this data is paramount to prevent breaches that could lead to unauthorized access, misuse, or loss of personal data.
- Legal basis for processing data: AI applications must have a legal basis for data processing (from training to use). Ensuring that consent is genuinely informed and voluntary is a significant challenge.
- Data Minimization and Purpose Limitation: According to GDPR principles, data collected should be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. AI systems should not collect excessive data and must clearly define the purpose of data collection to avoid misuse.
- Transparency and Accountability: AI systems have to be transparent in their operations. This includes providing explanations about how AI decisions are made, which can be challenging given the complexity of many AI algorithms. Ensuring accountability involves keeping detailed records of data processing activities and decisions made by AI systems.
- Right to Rectification and Erasure: Under GDPR, individuals have the right to have inaccurate personal data rectified and to request the erasure of their data. Implementing these rights within AI systems can be complex, especially if the data has been integrated into decision-making processes.
- Automated Decision-Making and Profiling: GDPR restricts decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect individuals.
- Surveillance and Tracking: AI technologies, such as facial recognition and predictive analytics, can be used for extensive surveillance and tracking of individuals, leading to concerns about invasion of privacy.
Guidelines and rulings by the Italian Data Protection Authority
The Italian Data Protection Authority (Garante) has issued guidance on the lawful and ethical use of AI. It has published a Decalogue for the deployment of national health services through AI systems and, in May 2024, a document titled “Guidance to Protect Personal Data from Web Scraping”, addressed to website operators as data controllers and suggesting measures to protect their content against scraping, including for AI-training purposes.
The most significant enforcement action concerned OpenAI’s ChatGPT. In March 2023 the Garante ordered a temporary limitation of processing, citing the lack of a legal basis, inadequate information to users and the absence of age verification: the service was restored after OpenAI introduced corrective measures. On 2 November 2024 the Garante closed the proceeding with a €15 million fine and an order to run a six-month public-awareness campaign. During the investigation OpenAI established its EU headquarters in Ireland, making the Irish Data Protection Commission the lead authority for future matters.
By judgment No. 4153/2026 of 18 March 2026, however, the Court of Rome annulled the sanction. The court upheld OpenAI’s preliminary objection that, once a single EU establishment had been set up in Ireland, competence over the cross-border processing passed to the one-stop-shop mechanism and the lead supervisory authority; it did not examine the merits of the alleged GDPR breaches, which continue in cooperation before the Irish authority (the court’s reasons, since published, rest on EDPB Opinion 8/2019 and treat the adoption of the final decision — not the timing of the alleged breaches — as the moment that fixes competence). The key takeaway is that, although the Garante was the first EU authority to confront generative AI under the GDPR, the substantive questions — lawful basis for training on personal data, adequacy of information, and protection of minors — remain open, and enforcement against globally established providers is increasingly governed by the one-stop-shop allocation of competence.
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
Data scraping is not specifically regulated in Italy, but it is regulated by several different bodies of law, especially the legislation on personal data protection, unfair competition, intellectual property, including copyright and sui generis right on the protection of databases. For instance, EU law grants a sui generis protection to database creators based on a substantial investment criterion in obtaining, verifying, or presenting database contents. Directive 96/9/EC grants exclusive rights to database makers, allowing them to charge for database use and select licensees. In this scenario, legal disputes often arise regarding whether a scraped website constitutes a protected database, with courts assessing investment and extraction substantiality.
Moreover, data scraping may be lawful under exceptions, most notably the text and data mining exception (see Directive (EU) 2019/790 on copyright in the Digital Single Market), which Italy has incorporated in 2021 within Article 70-ter of the Italian Copyright Law (Law 22 April 1941, no. 633).
The text and data mining (TDM) exception allows the use of copyrighted works and other materials to automatically analyze large amounts of text and data to extract information, patterns, or trends. Under EU and Italian law, there is a mandatory exception for scientific research by research organizations and a broader optional exception for other purposes, provided rights holders have not expressly reserved their rights.
While Italy has not produced landmark judgments exclusively on data scraping for AI training, in May 2024 the Italian Data Protection Authority has published a document titled “Guidance to Protect Personal Data from Web Scraping”, addressed at website owner (in their vest of data controllers) and suggesting several measures to protect their content against web-scraping.
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
A significant challenge in assessing the legality of data scraping lies in interpreting website’s terms of service and whether they constitute enforceable contracts. Most scraping activities fall under ‘browsewrap’ agreements, raising questions about their enforceability. Courts have grappled with the issue of whether scrapers can be held liable for violating Terms of Service to which they never explicitly agreed, highlighting the complexities of regulating online behaviour.
In general, any ban on web-crawlers made by a website exclusively through the “robots.txt” file is not usually considered to be legally enforceable, per se.
In any case, pursuant to Article 70-ter of the Italian Copyright Law (Law 22 April 1941, no. 633), in line with Directive (EU) 2019/790, website owners can legally prevent crawlers to extract data from their website by expressly reserving such right.
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
Under Law 132/2025, which complements the EU AI Act, Italy has two national authorities responsible for supervising the use and development of AI: AgID (Agenzia per l’Italia Digitale) and ACN (Agenzia per la Cybersicurezza Nazionale). AgID is the notifying authority, with competence for the procedures and functions of notification, evaluation, accreditation and monitoring of the bodies tasked with verifying the conformity of high-risk AI systems. ACN is the national market surveillance authority — with inspection and sanctioning powers and responsibility for cybersecurity profiles — except in the banking sector, where this competence is exercised by the Bank of Italy and CONSOB, and in the insurance sector, where it is exercised by IVASS. The Garante per la protezione dei dati personali retains its data protection powers and AGCOM acts as Digital Services Coordinator.
As to enforcement tools, in exercising the delegation under Article 24 of Law 132/2025 the Government is to confer on these authorities the supervisory, inspection and sanctioning powers provided by the AI Act, including the administrative fines under Article 99 of the Regulation, which may reach up to 7% of worldwide annual turnover for the most serious infringements..
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
As of 2026, the adoption of artificial intelligence by Italian businesses is growing rapidly, but it remains selective rather than fully widespread.
According to Banca d’Italia’s 2026 analysis, based on the INVIND survey, 32% of Italian industrial and service firms with at least 20 employees were using AI tools at the beginning of 2026. However, intensive integration remains much more limited, at around 5%. AI adoption in Italy should therefore be described as accelerating, but still uneven and often experimental, with AI mainly used to optimise existing business processes rather than to create new products or services.
Adoption is significantly higher among large enterprises and in the services sector. The main business functions affected are commercial activities, production of goods and services, and administrative processes. Generative AI is most commonly used for text generation, while other relevant applications include chatbots, AI agents, data analysis, summarisation and code generation tools.
The sectors leading adoption are those with stronger digital intensity. The available official data point in particular to IT and information services, telecommunications, audiovisual and digital content activities, and, based on sector-specific evidence, banking, insurance and financial services. Manufacturing is also relevant, especially for process optimisation and predictive analytics, but it should not be presented as the leading sector in general terms.
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
Italian law firms and legal departments are increasingly recognizing the benefits of integrating AI into their workflows. Some notable examples include:
- Legal Research: AI platforms can assist lawyers by providing comprehensive and accurate legal research. These tools can search through vast legal databases, case law, statutes, and regulations to find pertinent information, saving time and improving the quality of research. For instance, there are AI-powered tools which synthesize the ruling of courts.
- Automation of Routine Tasks: Routine legal tasks such as drafting standard documents and organizing case files can be automated using AI, freeing up lawyers to focus on more complex and value-added activities. AI-powered tools can quickly review large volumes of documents, identify relevant information, and highlight potential risks or inconsistencies. This is particularly useful in due diligence processes in the context of mergers and acquisitions.
- Contract Analysis and Management: AI solutions can analyze and manage contracts by extracting key terms, identify obligations, and flag non-standard clauses. This helps in streamlining contract lifecycle management and ensuring compliance with legal standards.
The use of AI in the Italian legal sector raises significant regulatory and ethical issues, particularly concerning data protection, confidentiality, accuracy, and accountability. Lawyers must comply with the GDPR and uphold professional secrecy, especially when using AI systems that process or store sensitive client data externally. There is concern about the accuracy and reliability of AI-generated outputs, as errors or “hallucinations” could expose professionals to liability.
Importantly, Article 13 of the Law 132/2025 addresses these issues in the context of intellectual professions, including legal services. It states that AI may only be used to support and assist professional activities, without replacing the predominant human intellectual input. To preserve the trust-based relationship between professional and client, the Law 132/2025 requires that professionals clearly inform clients — using plain and clear language — about any AI systems used in the delivery of services.
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
Challenges:
• Job displacement and role changes are concerns, with the potential for AI to automate routine tasks, leading to job displacement or changes in job roles, and requiring preparation for and management of this transition in job functions, necessitating adaptation and upskilling.
• Overreliance on potentially wrong outputs: Dependence on these outputs without critical assessment can lead to erroneous legal advice and flawed strategies, jeopardizing client advice. Balancing AI insights with human expertise is crucial to maintaining reliable legal practice and mitigating AI’s limitations.
• Data Protection and cybersecurity: data privacy and security is another major challenge, as lawyers will face several cases in which data is processed by AI systems, while needing to have strict data privacy and security standards, also taking into account increased cybersecurity risks inherent to AI.
• Legal liability: lawyers will address responsibility and accountability issues, including allocating liability among human operators, AI developers, and AI systems.
• Discrimination: bias and fairness pose challenges, as AI algorithms may have inherent biases that could lead to unfair or discriminatory outcomes, requiring mechanisms to ensure transparency and explainability in AI decisions, and to correctly address the accountability on the stakeholders involved in the processing.
Opportunities:
• Enhanced Efficiency and Productivity: AI can automate routine and time-consuming tasks such as document review, legal research, and contract analysis, allowing lawyers to focus on more complex and strategic work and enhancing overall productivity while reducing operational costs.
• Predictive Analytics: AI enables lawyers to analyze legal data, extract valuable insights, and make informed predictions. For instance, AI can assist in determining the likelihood of success for actions, predicting rulings, and automating legal research and drafting. This can increase efficiency, reduce costs, and broaden access to legal services.
• Document Automation and Contract Analysis: AI-powered tools can help automating the drafting of legal documents, saving time and reducing certain human errors.
• Legal Research and Analysis: AI can assist lawyers in conducting legal research, analyzing precedents, and identifying relevant case laws or regulations. Legal research platforms can use AI to enhance the accuracy of legal research outcomes.
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?
In the next 12 months, significant legal developments in AI in Italy are likely to focus on several key areas:
1. EU AI Act Applicability and the Italian AI Law
Italian stakeholders already need to comply with the AI Act. Its prohibitions on unacceptable AI practices and its AI-literacy obligations have applied since 2 February 2025, and the regime for general-purpose AI models has applied since 2 August 2025. The bulk of the obligations for high-risk AI systems apply from 2026 and 2027, although the timetable for certain high-risk requirements is being pushed forward to 2027 and 2028 depending on the type of systems, in light of the ongoing “AI Omnibus” reform.
In the meantime, Italy has enacted Law 132/2025, which inter alia requires the Government to implement legislative decrees by 10 October 2026 in order to enact specific elements of the law; the first schemes were approved at preliminary examination by the Council of Ministers on 10 June 2026 and are not yet in force. AI operators established or operating in Italy will need to follow these decrees closely, as they will lay down important nuances regarding the Italian implementation of the AI Act, in particular on data and algorithms used to train AI systems, civil and criminal liability, and the use of AI in policing.
2. Intellectual Property (IP) and AI
Questions around the ownership of AI-generated works and inventions are already becoming more pressing. Italian law may see updates or new interpretations in this area, especially concerning the protection of IP created by, or with the assistance of, AI.
3. AI in Employment and Labor
The impact of AI on the workforce will continue to be a significant area of legal concern. This includes issues related to AI-driven automation and worker rights. Legal frameworks might be updated to address the challenges and opportunities presented by AI in the labor market.
In this respect, in the upcoming months AI operators established or operating in Italy should monitor the Italian transposition of the Platform Work Directive (Directive (EU) 2024/2831) which provides new rules aimed at ensuring that Gig Economy platforms must ensure inter alia appropriate human oversight of AI systems used to manage platform workers, as well as a right to explanation for important decisions that directly affect the workers. Platforms are also forbidden from processing certain types of personal data belonging to workers, such as data on someone’s emotional or psychological state and personal beliefs. The Directive must be transposed by Member States, including Italy, by 2 December 2026. Italy has, in the meantime, partly anticipated these requirements: Decree-Law No. 62/2026, in force since 1 May 2026, already grants platform workers information obligations regarding algorithmic management, a right to an intelligible explanation of automated decisions, and human review of those decisions.
Italy: Artificial Intelligence
This country-specific Q&A provides an overview of Artificial Intelligence laws and regulations applicable in Italy.
-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
-
What cybersecurity obligations apply to AI systems?
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?