There is a provision of Law No 132 of 23 September 2025 that almost always goes unnoticed and which, in our view, carries greater weight than many declarations of principle. Article 4(4) provides that a minor who has reached the age of fourteen may give consent to the processing of data connected with the use of artificial intelligence systems “provided that the information and communications referred to in paragraph 3 are easily accessible and comprehensible” (Official Gazette (Gazzetta Ufficiale)). Comprehensibility here ceases to be a quality of the information and becomes a condition for the effectiveness of the act. If the minor is not in a position to understand, his or her consent is not validly given, however unimpeachable the document submitted to him or her may be.
It is a construction that deserves attention, because the rest of European transparency law still operates, for the most part, on the level of the obligation to provide information and not on that of the cognitive result.
The principle and the obligations: Article 12 of Regulation (EU) 2016/679
The starting point remains Article 12(1) of the General Data Protection Regulation, which requires the controller to provide information “in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child”. Recital 39 adds that the information must be “easily accessible and easy to understand”, and recital 58 observes that providing information in electronic form is of particular relevance “in situations where the proliferation of actors and the technological complexity of practice make it difficult for the data subject to know and understand whether, by whom and for what purpose personal data relating to him or her are being collected”.
It is worth fixing the distinction on which the whole argument rests. Articles 13 and 14 govern the content of the information, Article 12 governs its form, and the principle of transparency in Article 5(1)(a) is something further than both. The Italian Data Protection Authority (Garante) said so clearly in a 2025 decision: the transparency obligations “do not define the entire scope of the principle of transparency”, and their breach amounts to a breach of the principle only “where characterised by elements of seriousness and systematic nature” (Garante).
The icons of Article 12(7): a power left to the Commission
Paragraph 7 of the same Article 12 provides that the information “may be provided in combination with standardised icons in order to give in an easily visible, intelligible and clearly legible manner a meaningful overview of the intended processing”, and paragraph 8 empowers the Commission to adopt a delegated act determining their content and procedures. This is a power and not an obligation, and the solution the legislature had envisaged to overcome the limits of legal text depends entirely on the Commission’s initiative.
In another area the instrument has been adopted: for the labelling of content generated by artificial intelligence, the Commission has published an official set of icons (European Commission). The comparison between the two areas is instructive.
Article 50 of the AI Act: marking, information and perceptibility
Regulation (EU) 2024/1689 builds transparency on two distinct obligations. Article 50(1) requires that anyone interacting with an artificial intelligence system be informed of it, “unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect”. Paragraph 2 requires providers of systems generating synthetic content to mark it “in a machine-readable format” and make it detectable as artificially generated or manipulated. Paragraph 4 obliges deployers to disclose that content constitutes a deep fake, with a qualification for evidently artistic, creative, satirical or fictional works.
The provision that matters here, however, is paragraph 5: the information “shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure” and “shall conform to the applicable accessibility requirements” (European Commission). These are two requirements of result, not of content: the timing and the perceptibility. It should be recalled that the obligations under Article 50 apply from 2 August 2026, while 2 December 2026 marks the end of the four-month transitional period granted by the Digital Omnibus to providers of systems generating synthetic content already placed on the market before 2 August.
The Code of Practice and the guidelines of July 2026
The framework was completed in the summer of 2026. On 10 June the final version of the Code of Practice on Transparency of AI-generated Content was published, drawn up by independent experts in a process facilitated by the AI Office and divided into a section for providers and one for deployers; by the end of July some one hundred and ninety entities had signed up to it (European Commission). Adherence is voluntary, and those who do not adhere must demonstrate compliance by alternative means of equivalent adequacy.
On 20 July 2026 the Commission then adopted the guidelines on the implementation of the transparency obligations under Article 50, addressed to competent authorities, providers and deployers (European Commission). Those dealing with compliance will have to read them alongside the Code: the former says what to do, the latter how to do it in a manner recognised as adequate. We have already addressed this arrangement, and its interaction with marking, when writing on the transparency of content generated by artificial intelligence.
Deceptive design patterns: the interface as an obstacle to information
The shift from the document to the user’s experience was made by the European Data Protection Board (EDPB) with its guidelines on deceptive design patterns in social media platform interfaces, adopted in their final version on 14 February 2023. They state that the obligation under Article 12(1) concerns not only privacy notices and the exercise of rights, but “any information and communication relating to the processing of personal data”, and they describe the category of “Left in the dark”, the interface designed so as to hide information or control tools, or to leave the user uncertain as to how his or her data are processed (EDPB).
The most useful passage, however, is an example. A breach notification informing the data subject that “special categories of personal data” have been compromised is legally accurate and substantially useless, because the average user does not know that this formula denotes, among other things, his or her health data. The information has been provided and has not been conveyed. It is proof that the legal correctness of a text and its communicative fitness are two independent properties.
On the digital services side, Article 25 of Regulation (EU) 2022/2065 on digital services prohibits providers of online platforms from designing, organising or operating their interfaces in a way that deceives or manipulates recipients, or that otherwise materially distorts or impairs their ability to make free and informed decisions. It is, however, a residual prohibition, which paragraph 2 of the same article declares inapplicable to practices already covered by the rules on unfair commercial practices and by the data protection regulation.
Law No 132/2025: two formulas and one addressee
Beyond Article 4, the Italian law returns to the subject in a provision directly concerning those who practise an intellectual profession. Article 13(2) provides that, “in order to ensure the relationship of trust between professional and client, information on the artificial intelligence systems used by the professional shall be communicated to the recipient of the intellectual service in clear, simple and exhaustive language”.
The adjectives are three, and the last is the most demanding, because it asks for completeness from a text that must remain simple. It should be added that Article 13 sets no quantitative threshold and knows no criterion of significant contribution: the parameter is qualitative, and it is the prevalence of intellectual work. As for Article 4(3), its scope should be read precisely: it concerns “information and communications relating to the processing of data” connected with the use of artificial intelligence systems, not every piece of information relating to the use of those systems.
Critical aspects: the privacy notice as evidence in one’s own favour
The enforcement decisions we have examined concern privacy notices that are incomplete, misleading or drafted in a language the recipient does not speak, and obstacles placed in the way of the exercise of rights; the case of the complete and correct but incomprehensible notice does not appear among them. The most recent one confirms this: on 21 July 2026 the French data protection authority (CNIL) fined an IT consultancy company three hundred thousand euro because, of two hundred and sixty-five erasure requests received in 2024, one hundred and sixty-six persons had received no information on the outcome and twenty-seven had received it after the one-month time limit; the defence argument that the data had been erased automatically was rejected, because erasure does not dispense with informing the person who made the request (CNIL). It is a decision on Articles 12 and 17, but it punishes silence and delay, not obscurity. Among the most significant Italian cases of the year is that of a credit institution fined, by decision No 613 of 3 September 2026, more than five and a half million euro, in which the Garante observed that it is not sufficient for the customer’s “no” to be recorded by a system if the organisation is then unable to guarantee that it is actually applied (Garante).
We consider this absence to be significant. The way in which transparency is constructed means that the privacy notice produces, first and foremost, an evidential effect in favour of whoever drafts it: it demonstrates compliance. The cognitive benefit for the recipient is a hoped-for outcome, not an element of the legal test, and indeed almost no one measures it. As long as this remains so, the controller’s rational incentive is to write the most defensible document, not the most comprehensible one, and the two objectives diverge systematically: the former rewards technical completeness, the latter selection.
Where the law has sought to invert this relationship, it has done so with a precise technique: it has linked comprehensibility to a legal effect. That is what Article 4(4) of the Italian law does with regard to the minor’s consent, and it is what Article 50(5) of the AI Act does, in a different form, when it fixes the moment at which the information must reach the person. These are the two points at which transparency ceases to be a document and becomes a result. The rest still depends on the goodwill of whoever writes, and on this ground the European obligation of artificial intelligence literacy, which we discussed when commenting on the rewriting of Article 4 of the AI Act, intervenes from the opposite side, that of the recipient.
Conclusions
Comprehensibility is today regulated as a modality of informing and not as its outcome, with two exceptions that deserve to be brought into the system: the consent of the minor between fourteen and eighteen years of age, valid only if the information is accessible and comprehensible, and the obligation to reach the person at the latest at the time of the first interaction or exposure. For the professional falling within Article 13 of Law No 132/2025, the practical consequence is immediate: the information on the systems employed does not serve to protect the person providing it, it serves to preserve the relationship of trust, and a document the client does not understand does not fulfil that function.
Author: Valentina Grazia Sapuppo








