90975

Immagine creata con IAAI-generated image

Italy implements the AI Act: who supervises, what it costs and where the workplace ban stops

On 4 August 2026 the Italian Council of Ministers gave final approval to the two legislative decrees that align Italian law with Regulation (EU) 2024/1689, under the delegation contained in Article 24 of Law no. 132 of 23 September 2025. The first decree covers the use of artificial intelligence in policing and the related civil and criminal liability, the second the powers of the national authorities and the use of artificial intelligence in education, the professions, employment, healthcare and public administration. Three weeks earlier the Italian data protection authority, the Garante, had issued favourable opinions on both drafts, subject to conditions. On the point that touches workers most directly, the final text moved in the opposite direction to the one the authority had indicated.

Two decrees, one delegation

The available public source is press release no. 185 of the Council of Ministers, which sets out the essential content of the two measures and the changes made after the opinions of the parliamentary committees, of the Joint Conference and of the Garante. The final texts do not yet appear in the Italian Official Gazette, so what follows rests on that press release and on the two opinions of the authority, which are available in full. The distinction matters, because in this field the scope of an obligation is settled by the wording of the individual provision, not by a summary of it.

AgID notifies, ACN supervises, the Garante keeps Article 74

The second decree builds the national governance framework. The Agency for Digital Italy, AgID, is the notifying authority, responsible for the assessment, designation and notification of conformity assessment bodies and for monitoring that notified bodies continue to meet the requirements. The National Cybersecurity Agency, ACN, is the market surveillance authority. Alongside them, the Bank of Italy, the securities regulator Consob and the insurance regulator IVASS supervise high-risk systems used in the supply of financial services, while the Garante retains systems used in law enforcement, border management, justice and democracy, under Article 74(8) of the Regulation.

Designating the notifying authority is not an organisational detail. It is the step that makes the conformity assessment chain workable, the chain that providers of high-risk systems must go through carrying the quality management system required by Article 17. Without designated and notified bodies the obligation stays on paper and the procedure stays still.

Penalties below the European ceiling, sandboxes brought forward

The press release describes a graduated and proportionate penalty framework, with maximum limits lower than those laid down by the European Regulation and the possibility of non-financial measures for infringements of limited gravity. The decree has also been updated to reflect the amendments made to the AI Act by Regulation (EU) 2026/1744, through a cross-reference that ties the entry into force of the penalties to the actual entry into force of the corresponding obligations and prohibitions. It is an alignment clause that avoids the paradox of a national penalty becoming enforceable before the European obligation it is meant to protect, and it follows from the deferral of certain deadlines decided by the Digital Omnibus.

The measure then brings forward the operation of the regulatory sandboxes, with preferential treatment for small and medium-sized enterprises and for start-ups. On education and training, the press release points to updated national guidance and a permanent teacher training programme with an allocation of 100 million euros to counter the risks linked to the misuse of digital platforms and social networks, to literacy, reskilling and advanced training for public sector staff in cooperation with the National School of Administration and Formez, to judicial training entrusted to the School for the Judiciary, and to the compulsory inclusion of artificial intelligence training in the Continuing Medical Education programme. This is the chapter that Article 4 of the AI Act, as rewritten by the Digital Omnibus, largely left to national choices.

Decisions at work, and the boundary of recruitment

The provision likely to have the most immediate impact concerns the employment relationship. Decisions on the creation, modification or termination of the relationship, including disciplinary measures and dismissals, may not be taken solely on the basis of automated processing, and a dismissal issued in breach of that prohibition is void. The opinion of the Garante describes the drafted provision in more analytical terms: the final decision must always be taken by a natural person holding effective and autonomous power, the use of the systems must respect the worker’s dignity and privacy and the principle of non-discrimination, and the worker is entitled to an intelligible statement of reasons, indicating the weight of the artificial intelligence and the parameters taken into account. This is the same core as the right to understand the logic of a processing operation that the authority has already affirmed where a score decides access to a supply contract.

The final text, however, adds a clarification: the search for and selection of candidates does not count among the final decisions on the creation of the employment relationship, even where it results in a candidate not being admitted to the later stages of the selection process. Someone screened out by an automated tool is therefore not the subject of a decision for the purposes of this provision, however final that exclusion may be for the post applied for.

The Garante’s conditions and the open points of the press release

In opinion no. 532 of 14 July 2026 the authority gave a favourable opinion subject to four conditions and one observation. The conditions asked for the power to adopt guidelines, recommendations and best practices to be extended to the Garante in its own field, for the penalty procedure of the authority to be governed by a cross-reference to Article 166 of the Italian data protection Code, including the destination of the sums collected, for the text to specify which option under Article 31(9) of the Regulation is being adopted as regards responsibility for conformity assessment, and for the participation of the Garante in sandbox projects involving the processing of personal data, as Article 57(10) requires. The observation, by contrast, invited the government to consider extending the prohibition on solely automated decisions to evaluative decisions capable of producing significant implications for the employment relationship.

Comparing the opinion with the press release allows two findings to be stated with certainty. The involvement of the Garante in the sandboxes was introduced, so that condition was met. The observation on employment was not: where the authority asked for the prohibition to be widened to evaluative decisions, the final text narrowed it instead, carving out the selection of candidates. On the remaining conditions the press release says only that the powers granted to the Garante have been made explicit, limited to systems used in law enforcement, in migration and asylum and in border control management, a formulation that does not allow anyone to verify whether the power to issue guidelines, the cross-reference to Article 166 and the choice under Article 31(9) actually made it into the text. Only a reading of the articles, once published, will settle that. One further point raised in the opinion remains open, and no press release resolves it: the financial neutrality clause sits alongside budget allocations that the Garante itself describes as insufficient for the tasks being assigned to it.

Policing, biometrics and a new criminal offence

The first decree contains the first comprehensive set of rules on the use of artificial intelligence systems in policing, built on human oversight and human responsibility: decisions remain with the operator, and decisions producing adverse legal effects solely on the basis of automated processing are excluded. Real-time biometric identification is allowed in exceptional cases, for limited periods and subject to prior judicial authorisation, while building biometric databases through the untargeted mass collection of information from the web is prohibited. On the criminal side the decree introduces Article 437-bis into the Criminal Code, punishing the failure to adopt security measures in high-risk artificial intelligence systems and their unlawful alteration, with penalties graduated according to the legal interest placed at risk. On the civil side it strengthens the position of the injured party through access to the technical documentation of the system, a presumption of causation, an alternative forum close to the claimant’s residence and a direct action against the insurer.

Here too opinion no. 531 of 14 July 2026 set precise conditions: replacing the expression “qualified human review” with “human oversight”, prohibiting the use of sensitive operational data for research and experimentation and requiring synthetic data or masked or pseudonymised data instead, defining quality requirements, security measures, erasure periods and guarantees that the reference database will not grow incrementally for each authorised use, and confining the derogations from the duty to erase unlawfully acquired data. The press release confirms that the text was supplemented on the minimum requirements of the reference database, the erasure obligations and the non-incremental guarantee. On sensitive operational data it speaks instead of clarifying the processing arrangements for research and experimentation, which is not the substitution the authority had asked for.

What remains to be defined

The texts are missing. Until publication in the Official Gazette, Italy’s implementation of the AI Act can only be read in a press release, and no conformity assessment is built on a press release. The second-level instruments the two decrees presuppose are missing as well, from the measures of the directors general on the national registration of high-risk systems to the joint decrees that must define the composition, operation and eligibility criteria of the sandbox. In the meantime three things are already clear for anyone who has to organise. Providers and deployers of high-risk systems need to work out which authority will be looking at them, because the answer changes with the sector. Anyone who has built a quality management system needs to check that it will hold before notified bodies that AgID has yet to designate. And anyone recruiting with automated tools needs to know that the prohibition on final decisions does not cover candidate screening, while the obligations of the General Data Protection Regulation continue to do so.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article