10

Immagine creata con IAAI-generated image

The AI Act on the horizon: what will happen to Italian municipalities?

The AI Act’s prohibitions apply from 2 February 2025, most of its provisions from 2 August 2026, while the obligations for high-risk systems slip — by effect of the Digital Omnibus — to 2 December 2027 and 2 August 2028. Italian municipalities are part of this moving calendar too: not spectators, but deployers of AI systems, from intelligent video-surveillance to essential services. What must — and can no longer — local administrations do?

When discussing the AI Act, attention runs to the big tech companies. But the Regulation, with its risk-based approach, closely concerns public administrations too and, in particular, municipalities: not as providers of AI systems but, in the generality of cases, as deployers — users of systems developed by third parties, from “intelligent” video-surveillance to the management of local public services. This seems the right place to clarify what is already prohibited for local authorities, what will become mandatory, and the deadlines, redrawn by the recent Digital Omnibus.

What is already prohibited: the bans applicable from 2 February 2025

Under Article 113 of the AI Act, the Regulation “applies from 2 August 2026. However: (a) Chapters I and II apply from 2 February 2025”. Chapter II sets out the prohibited AI practices: for municipalities, therefore, the bans are already law in force, and were not touched by the Omnibus deferrals. Two prohibitions in particular touch local administrative experience closely. The first is the ban on social scoring under Article 5(1)(c), which strikes down AI systems for the evaluation or classification of natural persons based on their social behaviour or personal characteristics where the score leads to detrimental treatment in contexts unrelated to those in which the data were collected, or unjustified or disproportionate treatment. Anything but theoretical for Italian local authorities, as the season of “points-based citizenship” projects — on which the Garante had already opened scrutiny in 2022 — demonstrates.

The second front is biometric surveillance in public spaces, with the prohibitions and strict conditions of Article 5 on remote biometric identification — terrain on which the Garante had intervened even before the AI Act’s applicability, fining the Municipality of Trento for the “intelligent” surveillance projects Marvel and Protector and stigmatising “the massive and invasive processing carried out”, with the warning that “such forms of surveillance in public spaces may alter people’s behaviour and also condition the exercise of democratic freedoms”.

High risk for administrations: Annex III

The prospective core of the Regulation, for municipalities, is however Annex III: it covers, among others, AI systems used in fields such as biometrics, education, employment and — of most interest to local authorities — access to essential public and private services. Those who employ such systems as deployers will be bound, among other things, by the obligations of Article 26 (use in accordance with instructions, human oversight, monitoring) and, as bodies governed by public law, by the fundamental-rights impact assessment under Article 27. As to deadlines, the picture was redrawn by the Digital Omnibus on AI, finally approved by the European Parliament on 16 June 2026: the obligations for high-risk AI systems will apply from 2 December 2027 for stand-alone systems and from 2 August 2028 for those embedded as safety components. This is crucial for municipal offices: the deferral of the high-risk obligations is not a suspension of the AI Act. The bans operate from 2 February 2025; most provisions from 2 August 2026; and the time gained until December 2027 should be used to map the systems in use, qualify them against Annex III and prepare governance, skills and documentation.

What to do now: a minimum road map for local authorities

In the light of the above, we indicate, non-exhaustively, the operational lines we consider priorities. First, mapping the AI systems in use or being acquired, from video-surveillance to citizen-service chatbots, with their qualification: prohibited practice, high risk, limited or minimal risk. Second, the immediate check of compliance with the Article 5 prohibitions, with particular regard to any behavioural-scoring mechanism and any surveillance project in public spaces; a check to be carried out together with GDPR oversight, which remains fully applicable — legal basis, impact assessment under Article 35, measures against re-identification, as the Trento affair teaches. Third, preparation for the deployer obligations for high-risk systems: qualified human oversight, staff training, record-keeping, information of data subjects and the fundamental-rights impact assessment — obligations presupposing skills that authorities should start building now, not in November 2027. Finally, attention to the simplifications and support tools, from the national regulatory sandboxes expected by August 2027 to the harmonised standards under development within CEN-CLC/JTC 21.

Conclusions

For Italian municipalities the AI Act is no longer on the horizon: it is largely already here. The bans have been in force for a year and a half, most provisions apply from 2 August 2026, and the deferral of high risk to 2027-2028 is a time for preparation, not a moratorium. The Trento affair, even before the AI Act, showed how costly — economically and reputationally — an innovation not overseen by the law can be. In the light of the above, one wonders whether local administrations, often lacking dedicated technical skills, will manage to use the time that separates them from the 2027 deadlines to take stock of the systems in use, classify them against Annex III and build the necessary competences, rather than wait for the last useful month, as the Trento affair already warns against doing.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project