What Was Approved
On August 4, 2026, Italy's Council of Ministers gave definitive approval to two legislative decrees implementing Law 132/2025, the national AI statute Parliament passed on September 17, 2025 — making Italy the first EU member state to enact a domestic law layered on top of the bloc-wide AI Act, Regulation (EU) 2024/1689 (IAPP). The framework law, a 28-article text published in the Gazzetta Ufficiale on September 25, 2025 and in force since October 10, entered its implementation phase after the Council's preliminary sign-off on June 10, 2026 (Gazzetta Ufficiale). The two decrees finalized last week split cleanly: one governs national AI institutions, education, healthcare, and labor; the other covers policing, biometric surveillance, and criminal liability (governo.it, Comunicato n. 185).
Governance: Two Agencies, One Regulator Left Standing at the Border
The first decree names the Agency for Digital Italy (AgID) as the national notifying authority — accrediting the bodies that certify high-risk AI systems — while the National Cybersecurity Agency (ACN) becomes market surveillance authority and Italy's single point of contact with Brussels. Sector regulators keep their lanes: Banca d'Italia, CONSOB and IVASS retain oversight of high-risk systems in finance, while the data protection authority (Garante) keeps explicit jurisdiction over AI used in law enforcement, migration, asylum and border control (noze.it). This is a sensible division of labor: rather than inventing a single AI super-regulator, Italy routes AI oversight through agencies that already understand the sectors they're policing. The alternative — a green-field AI authority with no institutional memory in finance or health — has been criticized elsewhere in Europe as slower and more error-prone.
Police Use: Real Limits, Not Just Rhetoric
The policing decree is where the law does its most concrete work. Real-time biometric identification by police now requires judicial authorization, is confined to specific threats or missing-persons cases, and is capped at fifteen days, renewable only by reasoned order (noze.it). Building biometric databases through indiscriminate web scraping is barred outright, and any adverse decision generated by a police AI system requires human review beyond the system's raw output — codifying the human-in-the-loop principle rather than leaving it as a policy aspiration (governo.it). Civil liberties advocates will rightly note that "judicial authorization" and "exceptional circumstances" are only as strong as the courts enforcing them, and fifteen-day renewable windows can become de facto permanent if renewal is rubber-stamped. That's a legitimate oversight question for Parliament and the Garante to monitor going forward — but as a starting legal text, the decree's specificity is considerably tighter than the vague "appropriate safeguards" language many jurisdictions have settled for.
Labor Protections That Actually Bite
On employment, the decree bars firms from basing hiring, disciplinary action, or termination "solely" on automated processing; a dismissal made in violation is void, not merely subject to a fine (governo.it). The Ministry of Labour, which co-drafted this chapter, frames it as an attempt to let firms adopt AI in active labor-market management and hiring pipelines without workers losing due-process protections along the way (Ministero del Lavoro). Employers will argue — fairly — that "solely automated" is a vague enough standard to invite litigation over any AI-assisted decision that a human nominally rubber-stamped. Regulators should clarify what counts as meaningful human review quickly, before ambiguity chills legitimate automation in HR systems that speeds up genuinely fair processes like scheduling and benefits administration.
The €100 Million Bet on Classroom AI Literacy
The most novel piece is a €100 million fund for a standing national teacher-training plan on AI, covering how algorithmic systems work, how to spot bias and error, and how to use generative AI safely in classrooms (governo.it). This is the right kind of intervention: rather than banning AI tools from schools or leaving teachers to figure it out alone, Rome is funding the human capital needed to use them well. It is also, notably, spending rather than restricting — a rare move in AI policy, where the reflex is usually prohibition first.
Our Take
Italy's approach so far avoids the two failure modes that plague national AI regulation: it doesn't duplicate the EU AI Act's risk classifications, and it doesn't leave enforcement to a single overstretched new agency. Routing oversight through AgID, ACN, and existing sectoral regulators, while writing genuinely specific limits into police biometric use, is a template other member states implementing their own AI Act carve-outs should study. The open question is execution — whether the Garante's border and migration jurisdiction gets adequately resourced, and whether "solely automated" litigation clarifies quickly enough that employers don't simply avoid AI-assisted HR tools altogether. Proportionate regulation only stays proportionate if the follow-through matches the text.