AI Regulation in Italy.
As of August 6, 2026, Italy has an AI-specific national law, Law No. 132/2025, but it mainly provides a framework for governance and sector-specific rules rather than replacing the EU AI Act, which is the primary source of AI obligations. Businesses must also consider the GDPR, Italy’s Privacy Code, the Digital Services Act, consumer and cybersecurity laws, with enforcement involving ACN, AgID, the Italian Data Protection Authority, AGCOM, consumer authorities, and sector regulators.
In force today6 instruments
Get the remaining 4 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.
Already subscribed? Unlock →
- Italy's delegated legislation under Law No. 132/2025, including measures adapting national law to the EU AI Act and specifying liability and unlawful AI uses.
- EU AI Act implementation guidance, harmonised standards, codes of practice and national procedures for supervision, conformity assessment and penalties.
- The revised high-risk AI timetable: December 2, 2027 for Annex III systems and August 2, 2028 for Annex I product-safety systems, subject to the detailed implementation framework.
Pending and recent legislation8 measures
Live from the Global AI Policy Radar.
Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?
Yes. Italy’s Law No. 132/2025 entered into force on October 10, 2025. It is mainly a framework, governance and sectoral law, and does not replace the directly applicable EU AI Act or its harmonized product obligations.
Who are the key regulators for AI?
AgID and ACN are Italy’s designated national AI authorities. The Italian Data Protection Authority, AGCOM, consumer authorities and sector regulators also have important powers, depending on the AI system and its use. ACN and AgID are making enforcement operational.
Which rules apply to AI systems today?
The EU AI Act is the main AI-specific regime, with prohibitions and AI-literacy duties already applying and GPAI obligations in force. GDPR and Italy’s Privacy Code, the Digital Services Act, the Italian Consumer Code and cybersecurity rules such as the Italian NIS2 Decree may also apply. Italy’s Law No. 132/2025 adds national principles and sectoral rules for areas including health, work, public administration, justice, education and copyright.
What is coming next, and when?
The EU AI Act’s high-risk obligations have revised implementation dates under the 2026 Digital Omnibus. Obligations for Annex III systems are scheduled for December 2, 2027, while those for Annex I systems are scheduled for August 2, 2028. Italy’s AI law also delegates further implementing legislation.
What are the enforcement and penalty risks?
Authorities are already acting against AI-related privacy and digital risks, including issues involving training data, scraping, chatbots, biometric data and synthetic media. Noncompliance may also trigger action under the DSA, consumer law and cybersecurity rules, depending on the deployment. The source identifies enforcement powers and active scrutiny but does not specify penalty amounts.
Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.