Law No 132 of 23 September 2025, laying down “Provisions and delegations to the Government on artificial intelligence”, has been in force since 10 October 2025 (Official Gazette (Gazzetta Ufficiale)). On 4 August 2026 the Council of Ministers gave final approval to the two legislative decrees exercising the delegations it contains (press release No 185); the first was published on 15 September and enters into force on the 30th, the second does not yet appear to have been published, while the twelve-month deadline for exercising the delegations expires on 10 October 2026. Beyond the calendar, a reading of the twenty-eight articles reveals a principle common to all the sectoral provisions: the decision is reserved to the natural person. The doctor, the judge, the public official, the professional and the employer cannot transfer to a system the choice that the law assigns to them. This is a reservation of human decision-making whose effectiveness depends, as will be explained, on the capacity of those who exercise it to understand what the system has produced.
A relationship of conformity, not a second track of obligations
Two provisions fix the relationship between the national law and European law better than any paraphrase. Article 1(2) provides that the provisions of the law “shall be interpreted and applied in conformity with Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024” (EUR-Lex). Article 3(5) adds that the law “does not create new obligations in addition to those laid down by Regulation (EU) 2024/1689 for artificial intelligence systems and for general-purpose artificial intelligence models”.
We consider this to be the correct key to interpretation, and a more precise one than the current formula according to which the law “is added” to the AI Act. No second track of compliance obligations on systems is opened. The law intervenes where the Regulation leaves room to the Member States, namely authorities, penalties, criminal law and procedure, and in the fields of domestic competence: healthcare, employment, the intellectual professions, public administration, justice and copyright. Those who organise compliance starting from the national text proceed from a mistaken premise: the obligations on systems remain the European ones, with the calendar redrawn by the Digital Omnibus, Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July, which deferred the application of Chapter III, Sections 1, 2 and 3, to 2 December 2027 for high-risk systems within the meaning of Article 6(2) and Annex III, and to 2 August 2028 for those within the meaning of Article 6(1) and Annex I.
The reservation of decision-making: the doctor, the judge, the public official, the professional
The core of the law lies in five provisions which say, in different formulas, the same thing.
In healthcare, Article 7(5) establishes that artificial intelligence systems “constitute a support in the processes of prevention, diagnosis, treatment and therapeutic choice, without prejudice to the decision, which is always reserved to those practising the medical profession”. In judicial activity, Article 15(1) reserves “always” to the judge “every decision on the interpretation and application of the law, on the assessment of the facts and evidence and on the adoption of measures”. In public administration, Article 14(2) provides that use is to take place “in an instrumental and supporting function to the activity of issuing administrative measures”, in compliance with the decision-making power “of the person who remains solely responsible for the measures and the proceedings”; paragraph 1 requires that use be knowable and traceable.
For the intellectual professions Article 13 adopts a qualitative criterion: use is permitted “solely for the exercise of activities instrumental and supportive to the professional activity and with the prevalence of the intellectual work forming the subject of the service”, and information on the systems used must be communicated to the client “in clear, simple and exhaustive language”. The text provides for no threshold and no criterion of significant contribution: it is unconditional, and any quantitative parameter circulating in practice is interpretative elaboration, not law.
On employment, by contrast, a clarification is needed, because the current reading is often imprecise. Article 11 contains no prohibition of wholly automated decisions. Paragraph 2 prescribes that use be “safe, reliable, transparent”, that it not take place “in conflict with human dignity” nor infringe the confidentiality of data, and requires that the worker be informed in the cases and in the manner set out in Article 1-bis of Legislative Decree No 152 of 26 May 1997; paragraph 3 prohibits discrimination. The prohibition of decisions based solely on automated processing belongs to the implementing decree, and in any event Article 22 of Regulation (EU) 2016/679 is an autonomous and pre-existing basis. In this field the framework has evolved elsewhere too, as we observed with regard to platform work and ILO Convention No 193.
The implementing package: authorities, employment, police activities
The two decrees approved on 4 August exercise distinct delegations under Article 24: on the one hand the adaptation of national legislation to Regulation (EU) 2024/1689, on the other the regulation of cases of unlawful creation and use of artificial intelligence systems. The first of the two is already positive law: it is Legislative Decree No 160 of 9 September 2026, published in the Official Gazette (Gazzetta Ufficiale) of 15 September and in force from the 30th of the same month (Official Gazette (Gazzetta Ufficiale)). The second, on the powers of the national authorities and on training, does not appear to have been published at the time of writing, and what concerns it must therefore be read as announced content.
As regards the authorities, the law had already identified the national authorities in Article 20: the Agency for Digital Italy as notifying authority within the meaning of Article 70 of the AI Act and the National Cybersecurity Agency for market surveillance and as single point of contact, with the Bank of Italy, CONSOB and IVASS within the meaning of Article 74(6), and with the powers of the Italian Data Protection Authority (Garante) and of AGCOM expressly preserved. According to what has been communicated, the decree adds the designation of the Garante as market surveillance authority within the meaning of Article 74(8) of the AI Act, and therefore for high-risk systems used in law enforcement, in migration and asylum, in border management, in the administration of justice and in democratic processes; the earlier operation of the regulatory sandboxes, with preferential treatment for small and medium-sized enterprises and for start-ups; a system of penalties which, as the press release itself specifies, provides for maximum limits lower than those of the European Regulation; and a training plan for teachers on the use of social media and digital platforms. On employment, the decree introduces the prohibition on adopting, solely on the basis of automated processing, decisions on the establishment, modification or termination of the employment relationship, including disciplinary measures and dismissals, with the nullity of any dismissal given in breach of the prohibition; the draft decree, in the version that circulated, also grants the worker the right to obtain an intelligible statement of reasons indicating the influence of the system and the parameters considered. We have dealt with this framework at greater length in the article on the Italian implementation of the AI Act.
Decree No 160 is divided into three titles and twenty-two articles. The first title concerns the use of artificial intelligence in police activities, and here a distinction should be noted which current summaries tend to overlook: authorisations for real-time remote biometric identification follow two different tracks. Outside criminal proceedings, for the purposes of prevention and for the search for missing persons or victims of certain offences, Article 8 assigns the authorisation to the public prosecutor at the court of the district capital, for a period not exceeding fifteen days, which may be extended, with delimitation of the territorial area and indication of the persons sought. Within criminal proceedings, the new Article 359-ter of the Code of Criminal Procedure instead entrusts the authorisation to the judge for preliminary investigations, with similar delimitations and with detailed rules for urgent cases. In both cases a breach of the conditions entails the deletion of the data and the inadmissibility of the results; Article 8 also provides for the immediate interruption of the processing.
This is accompanied by the prohibition on feeding biometric databases through “untargeted scraping” techniques, defined in Article 2 and prohibited both in Article 8 and in Article 359-ter, and by the rule that the comparison database must be formed “specifically for each use”, deleted upon expiry of the authorisation and not “capable of incremental population with respect to previous authorisations”. Article 10 finally excludes that facial recognition systems may be used “for the purposes of generalised or indiscriminate biometric control and identification of persons”.
The second title contains the criminal and civil provisions. The new Article 437-bis of the Criminal Code punishes with imprisonment of one to five years the failure to adopt technical security measures or human oversight on high-risk systems, where this gives rise to a danger to life or physical safety, with aggravated penalties if the danger concerns the security of the State and a mitigated negligent form. The fourth paragraph, which is the most significant innovation for businesses, extends the offence to the professional user who intentionally omits human oversight. The new Article 25-vicies of Legislative Decree No 231 of 8 June 2001 brings both Article 437-bis and Article 612-quater within the liability of entities. On the civil side, Articles 16 to 20 introduce an order for the disclosure of evidence relating to the functioning of the system, a rebuttable presumption of causation where the damage results from the breach of an obligation under the European Regulation, the rule that conformity with the Regulation does not in itself exclude liability, a concurrent forum in the place of residence of the injured consumer and a direct action against the insurer.
The conditions set by the Garante and the distance from the final text
On 14 July 2026 the Garante issued two opinions on the draft decrees: No 531 on Titles I and III of the draft concerning the use of artificial intelligence systems for police activities and the provisions on civil and criminal liability, and No 532 on the draft concerning the powers of the national authorities and the use of artificial intelligence in training. On 21 July the President of the Authority was heard by the Chamber of Deputies on the latter draft.
The conditions set on the first draft were seven, from point (a) to point (g), technical and, in our view, far from marginal. Five deserve to be recalled: the replacement of the expression “qualified human review” with “human oversight”, for alignment with Article 14(4)(d) of the AI Act; data quality requirements for the reference database, with security measures, deletion periods and guarantees of the “non-incremental nature of the comparison set” for each individual authorised use; the processing of biometric data permitted exclusively after the fact on recorded footage; the inclusion of the prohibition on using databases obtained through “untargeted scraping” techniques; and, for research and experimentation, the use of synthetic data or of real data subject to masking or pseudonymisation in place of sensitive operational data.
The comparison with the published text yields a precise result: of these five, four have been taken up, and the “non-incremental nature of the comparison set” appears with the Garante’s formula in Article 9(5) and with the rule on incremental population in Articles 8 and 359-ter. The first has not been taken up. Article 3(4) retains the formula “qualified human review”; paragraph 5 places “human oversight” alongside it for high-risk systems only, with a reference to Article 14 of the Regulation as a whole and not to paragraph 4, point (d); Article 6 introduces a third expression, “qualified human oversight”. Within the same decree, therefore, three different formulas coexist to designate the human safeguard, and this is not a lexical detail: the human oversight of Article 14 of the Regulation is an obligation of design on the provider and of organisation on the user, with defined content; the “qualified human review of the results of automated processing” is a subsequent check on the result produced. The use of interchangeable names for different legal concepts will make it more difficult to ascertain exactly what is owed.
On the second draft the Garante formulated, among other things, an observation inviting consideration of whether to extend the prohibition of decisions based solely on automated processing to “decisions of an evaluative nature, capable of having significant implications for the employment relationship”, and pointed out that the funds allocated to the Authority are “at present insufficient in relation to its functional needs”. On this point the final text, as far as has been communicated, moves in the opposite direction, specifying that the search for and selection of applications do not in themselves constitute a final decision even where they exclude candidates from subsequent stages. It is a choice that merits attention: those who do not pass the preliminary selection receive no decision to challenge, and yet they are already excluded from the procedure.
Copyright and the new criminal offences
Article 25 amends Law No 633 of 22 April 1941, inserting the adjective “human” alongside “works of the intellect” and specifying that protection applies “even where created with the aid of artificial intelligence tools, provided that they constitute the result of the author’s intellectual work”, and introducing a new Article 70-septies on reproductions and extractions by models and systems, including generative ones, within the limits of Articles 70-ter and 70-quater.
Article 26 is not confined, as is often read, to the new offence concerning falsified content. It introduces a general aggravating circumstance in Article 61 of the Criminal Code, numbered 11-undecies by effect of the notice of correction published in Official Gazette (Gazzetta Ufficiale) No 242 of 17 October 2025, amends Article 294 on the offence against political rights, Article 2637 of the Civil Code on market rigging, Article 171 of the Copyright Law and Article 185 of the Consolidated Law on Finance. The new Article 612-quater punishes with imprisonment of one to five years anyone who causes unjust harm by disseminating without consent “images, videos or voices falsified or altered through the use of artificial intelligence systems and capable of misleading as to their genuineness”; the offence is prosecutable on complaint, save for the cases in which prosecution is ex officio. It should be recalled that the criminal safeguard does not absorb the administrative one, and that synthetic content remains a processing of personal data even where the purpose is satirical, as the Garante had occasion to clarify in the case we commented on.
What human oversight does not see: algorithmic bias
It is here that the blind spot of the law emerges. The prohibition of discrimination is stated twice, in Article 7(2) for access to healthcare services and in Article 11(3) for the employment relationship, but the text does not indicate how algorithmic discrimination is to be sought, measured and documented. The reservation of human decision-making presupposes that the person is able to recognise the system’s error; if the error is a statistical distortion distributed across thousands of cases, the person deciding on the individual case is in no position to detect it, because what is before them is the case and not the distribution.
The tools, then, must be sought elsewhere. Recital 71 of Regulation (EU) 2016/679 requires the controller to adopt appropriate technical and organisational measures to prevent “discriminatory effects” based on the protected factors. Article 10(2) of the AI Act requires, for high-risk systems, “data governance” practices which include, in point (f), “examination in view of possible biases” and, in point (g), “appropriate measures to detect, prevent and mitigate” those biases. The exceptional processing of special categories of data for the purposes of bias detection and correction, which until July was found in paragraph 5 of the same Article, is now governed by the new Article 4a introduced by the Digital Omnibus, which extends its scope beyond high-risk systems while specifying that it “does not create any obligation to conduct such bias detection and correction”. Article 14(4)(b) finally requires those exercising human oversight to remain aware “of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system”, which the text calls “automation bias”. The combination of these three provisions outlines an obligation which the national law neither repeats nor attenuates: the reservation of decision-making must be organised, not merely declared.
We consider two clarifications necessary, because the public debate neglects them. The first is that algorithmic discrimination rarely passes through the protected factor: it passes through apparently neutral variables that stand in for it, the postcode, the year in which a qualification was obtained, continuity of contributions, the time band of connection. Excluding ethnic origin from the training data does not eliminate the variable that substitutes for it, and only makes it harder to notice. The second is that the distortion does not reside solely in the data, but also in the definition of the objective. A system that optimises retention in service produces different outcomes from one that optimises first-week productivity, and the choice between the two is not technical: it is a decision of corporate policy that no fairness indicator corrects downstream. In a neighbouring field, that of scoring systems applied to persons, we have already dwelt on this in discussing digital cities and the prohibition of social scoring.
Critical aspects: comprehensibility as a condition of responsibility
The law assigns responsibility to a determined person. Article 14(2) says so for public administration in the clearest terms: the person “remains solely responsible”. It is a clear choice and, we consider, a correct one, because it avoids chasing artificial legal personalities and brings attribution back to where it can be enforced. It remains to be said, however, that responsibility and attributability do not coincide. Attributing an outcome to someone is a formal operation; making that person effectively responsible requires that they be able to understand what they are putting their signature to. Where this condition is lacking, the reservation of decision-making becomes a reservation of liability, that is to say an instrument for identifying in advance who will answer for an outcome they were in no position to control.
Hence the importance of the duty to inform, which the law expresses in Article 4(3) with the formula “clear and simple”, and in Article 13(2) with the more demanding “clear, simple and exhaustive”. Informing and making understood are not the same operation. An accurate but incomprehensible notice satisfies the letter of the provision and betrays its function, and the professional who hands it to the client has transferred no awareness, but has merely constituted evidence in their own favour. Comprehensibility, in this framework, is not a drafting requirement: it is the condition of validity of the responsibility that the law intends to affirm. On the side of competence, the European obligation of AI literacy, which we dealt with in commenting on the rewriting of Article 4 of the AI Act, is today the safeguard that makes the reservation of decision-making more than a fiction: without a minimum of competence, human oversight is a formal compliance exercise.
There is, then, a deeper reason why we consider Article 15 to be the most important provision of the law. Reserving to the judge the interpretation of the law and the assessment of the facts and evidence is not an organisational precaution: it is the recognition that legal reasoning is not a calculation. Formalisation may hold in simple proceedings, with few determinate and quantifiable variables; it does not hold in complex proceedings, where several connected rules, divergent interpretations and an assessment of the facts that remains argumentative all come into play. This is the reason why automation, in law, may occupy the investigative and documentary phase but not the decision, and why Article 13 speaks of the prevalence of intellectual work rather than fixing a percentage.
There remains uncovered, finally, the case in which the system is not a tool but an agent: one which autonomously performs a sequence of actions on the outside world, as we observed with regard to the Meta settlement and artificial intelligence agents. In that scenario the question is no longer who decides, but who answers for a sequence of actions that no person has deliberated. Law 132/2025, built around the figure of the supporting tool, offers no answer, and nor does the AI Act offer one in full.
Conclusions
Law 132/2025 does not add European obligations, it presupposes them. Its own contribution is to have written, sector by sector, that the decision belongs to a person, and to have built around this affirmation a framework of authorities, of safeguards and, for the first time in a systematic manner, of criminal offences. It is a coherent framework, and its effectiveness depends on two elements that the text leaves open. The first is the calendar: of the two decrees approved on 4 August 2026, one has been published, No 160, in force from 30 September, while the one on authorities and training does not yet appear to have been published a few days before the expiry of the delegation, set for 10 October 2026; the delegation under Article 16 on data, algorithms and training methods does not appear to have been exercised. The second is substance: a reservation of human decision-making works if the person deciding has the tools to see what the system has done and on what data, and those tools are not in the national law but in Articles 4a, 10 and 14 of the AI Act and in Article 25 of Regulation (EU) 2016/679. Those who organise compliance starting from the Italian text will find a declaration of principle; the tools for giving it effect are found in European law.
Author: Valentina Grazia Sapuppo








