Italy - National AI Law (132/2025)
Law No. 132 of September 23, 2025 - Provisions and Delegations to the Government on Artificial Intelligence
Legge n.132 del 23 settembre 2025 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale (National Law on Artificial Intelligence)
Italy
RAI-IT-NA-LND2SXX-2025Italy - National AI Law (132/2025) is In Force in Italy as of 9 Sep 2026, according to gazzettaufficiale.it.
ActGovernance and OversightConformity Assessment and RegistrationEnforcement and PenaltiesLegge n. 132, enacted by the Italian Parliament in 2025, establishes national AI governance rules, sector obligations, and criminal sanctions for developers, deployers, and public bodies in Italy. The law took effect on 10 October 2025 and is currently in force. Compliance and market surveillance are supervised by AgID and ACN.
Summary
Legge 23 September 2025, n.132 is Italy's comprehensive national act on artificial intelligence, published in Gazzetta Ufficiale (GU n.223, 25 September 2025) and entering into force on 10 October 2025. The law establishes principles and objectives for research, experimentation, development, adoption and use of AI systems, emphasizing human-centric (anthropocentric) application, protection of fundamental rights, data protection and cybersecurity. It expressly interprets and applies in conformity with the EU AI Act (Regulation (EU) 2024/1689), while adding national governance structures, sectoral rules, enforcement mechanisms and penal provisions adapted to Italy's legal and institutional context.
Key institutional arrangements include designation of the Agenzia per l'Italia Digitale (AgID) and the Agenzia per la Cybersicurezza Nazionale (ACN) as the national authorities for AI, with AgID responsible for promotion, notification and conformity-assessment procedures and ACN responsible for market surveillance, inspections and cybersecurity oversight. The Presidency of the Council (through the competent structure for innovation and digital transition) leads national strategy and coordination; a Committee for coordination and a Committee of interministerial direction are provided to align ministerial action and monitor implementation. The law provides delegations to the Government to adopt technical and implementing decrees (decreti legislativi and decreti ministeriali) to specify conformity assessment, accreditation, notification processes, thresholds, sanctions and procedural details.
Sector provisions cover healthcare (AI as clinical decision support with mandatory human oversight and patient information), employment (rules for AI use in recruitment, performance evaluation and workplace monitoring), public administration (rules for procurement, adoption and experimentation), copyright (treatment of works created with AI and obligations to disclose AI use), and financial markets (adjustments to offences such as market manipulation and disclosure obligations where AI is used). The law introduces new criminal provisions, notably Art. 612-quater c.p. criminalising illicit dissemination of AI-generated or altered images, video or audio that causes unjust damage to a person (punishable by 1–5 years' imprisonment, with procedural rules for complaints and public-interest prosecutions). It also directs legislative action to clarify criminal and administrative liability linked to omissions in safety measures for AI systems that pose concrete danger to life, public safety or national security.
Compliance obligations set out documentation, record-keeping, risk assessments, testing and human oversight requirements, registration/notification (as aligned with the EU regime), and obligations on providers, deployers and professional users. Market surveillance, conformity assessment and accreditation schemes will be implemented jointly by AgID and ACN, with supervisory roles reserved for sectoral supervisors (Banca d'Italia, CONSOB, IVASS) where applicable. Administrative fines, corrective measures and criminal sanctions are provided; delegated measures will define precise sanctioning ranges and procedural rules.
The law represents Italy's attempt to combine alignment with EU harmonised rules with national priorities (innovation support, industrial policy, strategic autonomy and sectoral specificity). It creates a detailed implementation roadmap (biennial national AI strategy, delegated decrees, experimental sandboxes) and resources for promotion, monitoring and enforcement. Primary official sources include the Gazzetta Ufficiale publication of the law and explanatory materials from AgID and parliamentary documentation.
Full article
Read full text ↗Overview
Legge 23 September 2025, n.132 "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" is the national statute establishing Italy's domestic framework for artificial intelligence. Published in the Gazzetta Ufficiale - Legge 23 settembre 2025, n. 132, the law enters into force on 10 October 2025 and is explicitly designed to operate in conformity with the European AI Act (Regulation (EU) 2024/1689). It codifies principles (anthropocentrism, transparency, proportionality, security, non‑discrimination), delegates implementing powers to the Government and sets up a governance architecture led by the Presidency of the Council with technical roles for AgID and the National Cybersecurity Agency (ACN). The law covers sectoral rules (healthcare, labour, public administration, finance), conformity assessment, market surveillance, penal offences for misuse of AI (including a new deepfake offence), and provisions on data, copyright and user protection. For an authoritative summary by the designated promotion agency, see AgID - AI.
Definitions
The law adopts and references the AI-related definitions used by EU Regulation 2024/1689 and clarifies national-specific terms. Key defined concepts include: "system of artificial intelligence" (broadly covering models, algorithms, software and associated data pipelines); "provider" (natural or legal person who develops and places an AI system on the market or puts it into service); "user" and "professional user" (entities deploying or employing AI in the course of economic activity); "high-risk AI systems" (as per EU lists and national extensions); "deployment" and "use"; and procedural terms such as "notification", "conformity assessment" and "market surveillance". The law also defines unlawful dissemination of AI-generated or altered content for penal purposes and clarifies terms for criminal imputability connected to AI-driven processes.
Governance and Institutional Framework
Article 19–21 create a layered governance architecture. The Presidency of the Council (structure for innovation and digital transition) prepares and updates the national AI strategy, to be approved biennially by the interministerial committee. The Act designates the Agenzia per l'Italia Digitale (AgID) and the Agenzia per la Cybersicurezza Nazionale (ACN) as the national authorities for AI (Art. 20). AgID is tasked with promotion, innovation facilitation, notification management and accreditation of conformity-assessment bodies. ACN is designated as the market surveillance and inspection authority, with powers for cybersecurity oversight, inspections and sanctions. Sectoral supervisors (Banca d'Italia, CONSOB, IVASS) retain market oversight powers for financial/insurance sectors. A coordinating committee of director generals from AgID, ACN and the Presidency of the Council ensures operational alignment; a wider ministerial committee ensures policy direction (including defence, research, health, and economy ministries). The law also mandates collaboration with the Data Protection Authority and the Communications Authority where their competences intersect.
Key Focus Areas
The statute addresses multiple substantive domains: (1) fundamental rights and non-discrimination – requiring impact assessments and safeguards where AI affects rights; (2) data governance and privacy – alignment with GDPR and specific obligations for datasets used to train models deployed in Italy; (3) safety, testing and conformity – mandatory risk assessment, documentation and technical testing for high‑risk systems, with accreditation of conformity assessors carried out under AgID supervision; (4) transparency and disclosure – obligations to label synthetic content and to inform users when AI supports decision‑making, especially in healthcare and employment; (5) employment and workplace use – specific provisions require information to workers about AI use and protections limiting surveillance and unjustified automated profiling; (6) public administration and procurement – guidelines and rules for experimentation and procurement emphasizing interoperability, accessibility and auditability; (7) copyright and creative works – rules clarifying attribution, authorship and rights where AI substantially contributes to creative outputs; (8) market and financial integrity – adjustments to market abuse provisions where AI is used to influence markets; and (9) criminal law – introduction of Art. 612‑quater (illicit dissemination of AI‑generated or altered content) and directives to clarify criminal/administrative liability linked to safety omissions.
Implementation Framework
The Act delegates to the Government a program of implementing decrees to define: the lists and thresholds of high‑risk systems appropriate for Italy; detailed procedures for notification and conformity assessment; accreditation criteria for conformity assessors; sanctions and fines scales; procedural rules for inspections; sectoral rules for healthcare platforms and financial services; and funding and incentive schemes for research and SMEs. It requires the Presidency of the Council to publish a biennial national AI strategy and funds targeted initiatives (including experimentation sandboxes and competency programs). AgID and ACN must coordinate issuance of technical guidelines and linee guida, and create joint testbeds for compliance testing. The delegated measures will also specify registration and record‑keeping formats, and the interplay with national cybersecurity obligations and the NIS2 regime.
Monitoring and Evaluation
The law sets monitoring duties: AgID and ACN must produce annual monitoring reports on strategy implementation, market compliance and risks; results are transmitted to Parliament. The statute provides for metrics and monitoring targets (adoption projects, research investments, cybersecurity incidents) and requires the Presidency to evaluate socio‑economic impacts. It mandates sample audits, systematic market surveillance on high‑risk systems and a public register (to be implemented) of certain AI systems placed on the market or put into service. The Act links monitoring outputs to funding, research incentives and updates to the national strategy.
Penalties, Liability, and Appeals
The law establishes a mixed sanctioning regime. Administrative fines, corrective measures (recall, suspension, withdrawal) and public remediation orders will be available for regulatory breaches and are to be quantified in forthcoming delegated decrees. On the criminal side, Art. 612‑quater c.p. criminalises the illicit dissemination of images, video or audio falsified or altered by AI causing unjust damage, punishable with imprisonment (1–5 years) and initiated by complaint or ex officio in specified situations. The Act also mandates legislative clarification on imputability for crimes/administrative offences committed via AI, and contemplates liability for omission or failure to adopt safety measures where such omissions create concrete danger to life, public safety or national security. Affected parties retain administrative and judicial appeal routes; procedural details for sanctions and appeal bodies will be specified in implementing measures.
Relationship to Other Instruments
The statute is explicitly designed to be consistent with and complementary to: Regulation (EU) 2024/1689 (AI Act), GDPR (Regulation (EU) 2016/679), NIS2 and other sectoral EU rules, the Italian Data Protection Code and existing sectoral legislation for health, finance and labour. It modifies or interacts with the Civil Code, the Penal Code, the Testo Unico della Finanza and public procurement rules where necessary. The law also references existing national strategies (Italian AI Strategy and AgID guidance) and creates a path for delegated acts to coordinate domestic regulatory instruments.
International Alignment
While implementing a national approach, Legge n.132/2025 seeks alignment with EU harmonisation under the AI Act and with international standards on AI safety, cybersecurity and human rights. The law designates national contact points (AgID as notification authority and ACN as market surveillance and single contact point to EU institutions) to ensure coordination with EU bodies and cross‑border enforcement. It encourages participation in international testbeds, standards bodies and research cooperation, and foresees adaptation of national lists of high‑risk systems to EU delegated acts and globally recognised standards.
Implementation Timeline
| Milestone | Deadline / Date |
|---|---|
| Publication in Gazzetta Ufficiale | 2025-09-25 |
| Entry into force (vacatio legis expired) | 2025-10-10 |
| Biennial National AI Strategy first update due | Within 24 months of entry into force (by 2027-10-10) |
| Government delegated decrees (conformity, sanctions, thresholds) | Staged; implementing decree schedule set by Law (see articles delegating powers) — expected 2025–2026 |
| Establishment of joint AgID–ACN testbeds and public register | To be defined in implementing acts; monitoring reports annually |
Sources and References
| Source | Type |
|---|---|
| Gazzetta Ufficiale — Legge 23 settembre 2025, n. 132 (Atto completo) | Primary Source |
| AgID — Intelligence Artificial pages and guidance | Primary Source (Agency) |
| Parliamentary dossier and preparatory documents (Camera dei Deputati) | Primary Source |
Requirements for a company
What an organisation has to do under Italy - National AI Law (132/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
6- Adopt safety measures for AI systems to prevent risks to life, public safety, or national security.Providers and deployers of AI systems
- Label all synthetic content generated or altered by artificial intelligence systems.Providers and deployers of AI systems
- Conduct mandatory risk assessments, documentation, and technical testing for high-risk AI systems before deployment.Providers of high-risk AI systems
- Inform workers when artificial intelligence systems are used in employment decisions or workplace processes.Employers using AI in workplace management
- Inform patients and users when artificial intelligence is used to support decision-making in healthcare services.Healthcare providers and medical deployers
- Conduct impact assessments where artificial intelligence systems affect fundamental human rights.Providers and deployers of AI systems affecting fundamental rights
Must not do
2- Never disseminate AI-generated or altered media that falsifies reality and causes unjust damage to individuals.All individuals and legal entities operating in Italy
- Do not use workplace AI systems for unjustified automated profiling or worker surveillance.Employers using AI in workplace management
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Italy - National AI Law (132/2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | All individuals and legal entities operating in Italy | Never disseminate AI-generated or altered media that falsifies reality and causes unjust damage to individuals. “illicit dissemination of images, video or audio falsified or altered by AI causing unjust damage” | Oct 10, 2025 | Article 612-quater c.p. | Critical |
| 2 | Providers and deployers of AI systems | Adopt safety measures for AI systems to prevent risks to life, public safety, or national security. “failure to adopt safety measures where such omissions create concrete danger to life, public safety or national security” | Oct 10, 2025 | — | Critical |
| 3 | Providers and deployers of AI systems | Label all synthetic content generated or altered by artificial intelligence systems. “obligations to label synthetic content and to inform users when AI supports decision‑making” | Oct 10, 2025 | — | Critical |
| 4 | Employers using AI in workplace management | Do not use workplace AI systems for unjustified automated profiling or worker surveillance. “protections limiting surveillance and unjustified automated profiling” | Oct 10, 2025 | — | Critical |
| 5 | Providers of high-risk AI systems | Conduct mandatory risk assessments, documentation, and technical testing for high-risk AI systems before deployment. “mandatory risk assessment, documentation and technical testing for high‑risk systems” | Before placing on market | — | Critical |
| 6 | Employers using AI in workplace management | Inform workers when artificial intelligence systems are used in employment decisions or workplace processes. “specific provisions require information to workers about AI use and protections limiting surveillance” | Oct 10, 2025 | — | Important |
| 7 | Healthcare providers and medical deployers | Inform patients and users when artificial intelligence is used to support decision-making in healthcare services. “inform users when AI supports decision‑making, especially in healthcare and employment” | Oct 10, 2025 | — | Important |
| 8 | Providers and deployers of AI systems affecting fundamental rights | Conduct impact assessments where artificial intelligence systems affect fundamental human rights. “requiring impact assessments and safeguards where AI affects rights” | Before deployment | — | Important |
Related Regulations
More AI regulation in Italy
© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 9 Sep 2026 using Gemini 3.6 Flash