← Global AI Policy Radar · Methodology
Jurisdiction Baseline · AI × Policy

AI Regulation in Italy.

At a glance
AI-Specific Law
Yes; Law 132/2025 sets framework and sector rules
EU AI Act
Core AI rules; high-risk duties phase through 2028
Data And Privacy
GDPR requires lawful basis, transparency and safeguards
Digital And Consumer Rules
Platforms face transparency; consumers need clear, supportable claims

As of August 6, 2026, Italy has an AI-specific national law, Law No. 132/2025, but it mainly provides a framework for governance and sector-specific rules rather than replacing the EU AI Act, which is the primary source of AI obligations. Businesses must also consider the GDPR, Italy’s Privacy Code, the Digital Services Act, consumer and cybersecurity laws, with enforcement involving ACN, AgID, the Italian Data Protection Authority, AGCOM, consumer authorities, and sector regulators.

In force today6 instruments
EU AI Act partially in forceAI-specific
This is the core AI-specific regime for companies placing AI systems or general-purpose AI models on the Italian market or deploying them in Italy. Prohibited practices and AI-literacy obligations apply, GPAI obligations apply, and the 2026 Digital Omnibus revised the timing of many high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems.
AI / automated decisionsDisclosureSafety & security
Law No. 132/2025 on Artificial Intelligence in forceAI-specific
Italy's national AI law entered into force on October 10, 2025. It sets national principles and sectoral rules for areas including health, work, public administration, justice, education and copyright, designates AgID and ACN as national AI authorities, and delegates further implementing legislation, but it does not replace the EU AI Act's harmonized product obligations.
AI / automated decisionsDisclosureSafety & security
Unlock the full baseline

Get the remaining 4 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.

Already subscribed? Unlock →

General Data Protection Regulation and Italian Privacy Code in force
Any AI system processing personal data must have a lawful basis, meet transparency, purpose limitation, minimization, security and data-subject rights requirements, and address automated decision-making where applicable. Italy's Privacy Code supplements the GDPR, and the Italian Data Protection Authority has actively scrutinized AI training data, scraping, chatbots, biometric data and synthetic media.
Data processingDisclosureMinors
Digital Services Act in force
The DSA applies when AI is used in an online platform, hosting service, search engine, recommender system, advertising system or content-moderation workflow. It requires notice-and-action processes, transparency around recommender systems and advertising, safeguards for minors, and additional systemic-risk controls for very large platforms and search engines.
Content moderationDisclosureMinors
Italian Consumer Code in force
Consumer-facing AI products and services remain subject to rules against misleading commercial practices, hidden advertising, unfair contract terms, inadequate pre-contract information and defective digital content or services. AI claims about accuracy, autonomy, safety, personalization or expected results must be supportable and presented clearly.
Consumer protectionDisclosure
Italian NIS2 Decree, Legislative Decree No. 138/2024 in force
For entities in covered essential and important sectors, including certain digital infrastructure, cloud, managed service, health, energy, transport and public-sector environments, AI deployments fall within broader cybersecurity risk-management, incident-reporting, supply-chain and management-accountability duties. It is not an AI law, but it can materially govern the security architecture and operational controls of AI systems.
Safety & securityPrudential
Also worth noting
  • Italy's delegated legislation under Law No. 132/2025, including measures adapting national law to the EU AI Act and specifying liability and unlawful AI uses.
  • EU AI Act implementation guidance, harmonised standards, codes of practice and national procedures for supervision, conformity assessment and penalties.
  • The revised high-risk AI timetable: December 2, 2027 for Annex III systems and August 2, 2028 for Annex I product-safety systems, subject to the detailed implementation framework.
Pending and recent legislation8 measures
IT C.2927 Bill C.2927: Provisions to Protect Personal Identity Against the Dissemination of Images and Audio or Video Content Produced or Modified Usi
Introduced · 2026-08-04
The bill would protect personal identity from the dissemination of images, audio, or video generated or altered using software, digital applications, or AI systems. It addresses synthetic media and manipulated content that may impersonate or affect an individual.
IT S.2004 S.2004, Provisions on urban planning and the siting of high-density computing infrastructure (data centers and hyperscale data centers)
Introduced · 2026-08-04
The bill establishes provisions governing urban planning and the siting of high-density computing infrastructure, including data centers and hyperscale data centers. It is a standard legislative initiative introduced by Senator Elena Sironi.
IT C.2992 C.2992, Provisions establishing interdisciplinary educational pathways in lower- and upper-secondary schools to promote knowledge and respo
Introduced · 2026-06-29
The bill would establish interdisciplinary educational programs in Italian lower- and upper-secondary schools focused on understanding and using artificial intelligence systems responsibly. It was introduced by Deputy Patty L’Abbate as an ordinary bill.
IT S.1821 S.1821, Delegation to the Government for the Organization, Establishment, Development, and Strengthening of Data Centers
Advancing · 2026-06-23
The bill delegates authority to the Government to organize, establish, develop, and expand data-processing centers. It addresses national data-center and computing infrastructure policy.
IT S.1259 S.1259, Delegation to the Government on the Organization, Expansion, and Technological Development of Data Centers
Advancing · 2026-06-23
The bill would delegate authority to the Italian Government to establish measures concerning the organization, expansion, and technological development of data-processing centers. It is currently under examination in committee.
IT C.2847 C.2847, Provisions on the Use of Artificial Intelligence and Distributed Ledgers in Social Services and Interventions
Introduced · 2026-05-15
The bill establishes provisions governing the use of artificial intelligence and distributed-ledger technologies in the delivery of social services and interventions. The available record does not provide further details on specific requirements or safeguards.
IT C.2936 Bill C.2936: Introduction of an Occupational Impact Assessment for Artificial Intelligence Systems Affecting the Organization and Performanc
Introduced · 2026-05-15
The bill would introduce occupational impact assessments for AI systems that affect how work is organized and performed. It also establishes measures to protect human labor and employment from adverse effects of AI deployment.
IT C.2813 Bill C.2813, Provisions on Minors’ Use of Interactive Services That Simulate Human Conversations Through Generative Artificial Intelligence
Introduced · 2026-05-06
The bill addresses minors’ use of interactive services that simulate human conversations using generative AI systems. Its specific regulatory requirements are not detailed in the available description.

Live from the Global AI Policy Radar.

Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?

Yes. Italy’s Law No. 132/2025 entered into force on October 10, 2025. It is mainly a framework, governance and sectoral law, and does not replace the directly applicable EU AI Act or its harmonized product obligations.

Who are the key regulators for AI?

AgID and ACN are Italy’s designated national AI authorities. The Italian Data Protection Authority, AGCOM, consumer authorities and sector regulators also have important powers, depending on the AI system and its use. ACN and AgID are making enforcement operational.

Which rules apply to AI systems today?

The EU AI Act is the main AI-specific regime, with prohibitions and AI-literacy duties already applying and GPAI obligations in force. GDPR and Italy’s Privacy Code, the Digital Services Act, the Italian Consumer Code and cybersecurity rules such as the Italian NIS2 Decree may also apply. Italy’s Law No. 132/2025 adds national principles and sectoral rules for areas including health, work, public administration, justice, education and copyright.

What is coming next, and when?

The EU AI Act’s high-risk obligations have revised implementation dates under the 2026 Digital Omnibus. Obligations for Annex III systems are scheduled for December 2, 2027, while those for Annex I systems are scheduled for August 2, 2028. Italy’s AI law also delegates further implementing legislation.

What are the enforcement and penalty risks?

Authorities are already acting against AI-related privacy and digital risks, including issues involving training data, scraping, chatbots, biometric data and synthetic media. Noncompliance may also trigger action under the DSA, consumer law and cybersecurity rules, depending on the deployment. The source identifies enforcement powers and active scrutiny but does not specify penalty amounts.

Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.

Need a company-specific assessment? Explore Nomos →