Italy deepfake regulation

Italy Makes Companies, Not Just Individuals, Pay for Deepfakes

Decree 160/2026 lets Italian courts ban firms from advertising for up to two years if they profit from unlawful AI-generated content.

Italy's New Corporate Deepfake Liability People of Internet Research · Italy 2 years Max advertising ban Courts can bar firms from advertis… 200-700 quotas Deepfake offense fine range Corporate fine range under new Art… 600-1,000 quotas AI safety-omission fine range Corporate fine range for Article 4… Dec 2, 2027 EU high-risk AI deadline The EU's own AI Act high-risk comp… peopleofinternet.com
Italy's New Corporate Deepfake Liabili… People of Internet Research · Italy 2 years Max advertising ban 200-700 quotas Deepfake offense fine range 600-1,000 quotas AI safety-omission … Dec 2, 2027 EU high-risk AI deadline peopleofinternet.com

Key Takeaways

A New Kind of Exposure for Corporate Italy

Italy's Council of Ministers signed Legislative Decree 160/2026 on September 9, 2026; it was published in the Gazzetta Ufficiale (Serie Generale n. 214) on September 15 and takes effect September 30 (Normattiva). The decree implements the EU AI Act (Regulation 2024/1689) through the delegated authority granted by Law 132/2025, covering AI use by police, civil liability, and — the part that will land hardest on boardrooms — criminal liability (ppc.land).

The headline mechanism is a new Article 25-vicies inserted into Legislative Decree 231/2001, Italy's two-decade-old corporate criminal liability statute. Until now, 231/2001 exposed companies to fines and operating restrictions when employees committed offenses like corruption or market manipulation "in the interest or to the advantage" of the firm. The new decree adds two AI-linked predicate offenses to that catalogue: a freshly created Article 437-bis of the Criminal Code (omitting safety measures on high-risk AI systems) and Article 612-quater, the deepfake-dissemination offense that Law 132/2025 introduced into the penal code effective October 10, 2025 (gamingtechlaw.com). Article 612-quater punishes distributing AI-altered images, video, or voice capable of misleading people about their authenticity, without the subject's consent.

What Companies Actually Face

The sanctions are tiered by unit ("quota"), a mechanism Italian law uses so fines scale with a company's financial condition rather than sitting at a flat amount. Article 437-bis violations carry 600–1,000 quotas; unlawful AI-content dissemination carries 200–700 — for larger firms, a court can push the euro total well past €1 million (gamingtechlaw.com). More consequential than the fines are the interdictive sanctions: suspension or revocation of authorizations, exclusion from public contracts and grants, and — the detail specific to this news — a prohibition on advertising goods or services for up to two years (ppc.land).

An advertising ban is a sharper instrument than a fine against a company that monetizes deepfake content — a synthetic-media ad-tech vendor, an influencer-marketing platform, or a firm that used AI-manipulated endorsements to sell a product. Cutting off its ability to advertise for two years hits the actual business model, not just the balance sheet. That is a defensible design choice, not overreach for its own sake.

Justice Minister Carlo Nordio framed the underlying criminal offense as targeting those who "design, omit security measures or alter AI system functioning" in ways that create concrete danger, distinguishing it from a blanket ban on AI-generated content itself (key4biz.it).

The Case For It — and Where It Overreaches

The strongest argument for extending 231/2001 to deepfakes is straightforward: Italy's corporate liability regime has never been optional window-dressing. It already covers bribery, fraud, and market abuse, and companies have spent two decades building compliance infrastructure — the modello organizzativo — around it. A firm can avoid liability entirely by showing it adopted and genuinely enforced a prevention model overseen by an independent supervisory body (gamingtechlaw.com). That is not a strict-liability trap; it is an incentive to build AI governance into existing compliance functions, the same way firms already govern anti-corruption risk. Given how cheaply deepfake ad content can now be produced and how asymmetric the harm is — a fabricated endorsement or a synthetic scam video can spread before a platform or regulator reacts — treating profit-driven deepfake distribution as a corporate offense, not just an individual one, closes a real accountability gap.

Where the decree strains is in scope and calibration. Article 437-bis's predicate offense for omitting human oversight of a high-risk AI system is not the same wrong as deliberately distributing a deepfake, yet both route through the same interdictive toolkit, including the advertising ban. A negligent oversight lapse — an understaffed compliance review, a vendor's audit trail gap — is a different order of culpability than knowingly monetizing a fabricated video, and Italian courts will need to use real discretion to keep the sanction proportionate to the two years, and defense costs, in an era where AI liability standards are still unsettled globally.

Ahead of, Not Behind, Brussels

What makes Italy's timing notable is that it is moving faster than the EU framework it is implementing. The AI Act's own high-risk compliance obligations for standalone systems were pushed back from August 2, 2026 to December 2, 2027 under the omnibus simplification deal Council and Parliament struck in mid-2026 (Pinsent Masons). Brussels gave industry more runway; Rome layered criminal and corporate liability on top before the underlying EU obligations even bite. Companies operating in Italy now face national deepfake and AI-oversight liability more than a year before the EU-wide high-risk rules they're meant to comply with take full effect — a sequencing gap worth watching as other member states decide how fast to move.

The decree also adds a civil-liability presumption: where an AI Act violation is shown, courts now presume a causal link to resulting damage unless the defendant proves otherwise (ppc.land) — shifting real evidentiary weight onto AI deployers in ordinary lawsuits, separate from the criminal track. Combined, the criminal, corporate, and civil pieces make Italy one of the first EU states to give deepfake enforcement real economic teeth rather than leaving it to platform takedown requests. The test now is whether prosecutors and courts apply the advertising-ban power to genuine bad actors — not as a blunt instrument against companies that made a good-faith compliance misstep on an AI system they didn't fully understand.

Sources & Citations

  1. Normattiva — Decreto Legislativo 9 settembre 2026, n. 160
  2. Pinsent Masons — EU AI Act high-risk deadline delay
  3. ppc.land — Italian firms face ad bans over AI content offences
  4. gamingtechlaw.com — AI Criminal Liability in Italy: What Boards Must Know Now
  5. key4biz.it — Deepfake, sanzioni per le aziende