Italy Italy AI strategy national framework

Italy's AI Act Decrees Give Regulators Real Teeth, But Independence Questions Stay Unresolved

Rome's Aug. 4 decrees arm ACN and AgID with AI Act powers and a new criminal offense, but independence and biometric oversight gaps remain.

Italy's AI Act Enforcement Decrees, by the Numbers People of Internet Research · Italy 1–5 yrs Prison Term For Security Failure Base penalty under new Art. 437-bi… 15 days Biometric ID Authorization Cap Max duration a prosecutor may auth… 7 days Biometric Data Retention Limit Facial-recognition data collected … peopleofinternet.com
Italy's AI Act Enforcement Decrees, by… People of Internet Research · Italy 1–5 yrs Prison Term For Security Failure 15 days Biometric ID Authorization Cap 7 days Biometric Data Retention Limit peopleofinternet.com

Key Takeaways

Italy's Council of Ministers gave final approval on August 4, 2026 to the two legislative decrees implementing Law 132/2025, the national statute Rome enacted last October to sit alongside the EU AI Act (Regulation 2024/1689). With this step — Press Release No. 185 of the Consiglio dei Ministri — Italy becomes the first EU member state to complete a full domestic enforcement architecture for the Act: who polices AI systems, what happens when a high-risk system fails, and how far police may go with biometric surveillance.

A First-Mover Enforcement Architecture

The first decree assigns the Agenzia per la Cybersicurezza Nazionale (ACN) the role of national market-surveillance authority and single point of contact with the European AI Board, giving it inspection, information-gathering and sanctioning powers over high-risk AI systems placed on the Italian market. AgID (Agenzia per l'Italia Digitale) becomes the notifying authority, accrediting and supervising the conformity-assessment bodies that certify those systems. Sector regulators — Banca d'Italia, Consob and IVASS — retain oversight of AI used in banking, markets and insurance, while the Garante per la protezione dei dati personali keeps jurisdiction over AI used in law enforcement, border management, justice and democratic processes. A coordination committee at the Prime Minister's office is meant to keep these overlapping mandates from producing conflicting rulings.

Criminalizing Insecure AI

The second decree, covering AI in policing and civil/criminal liability, inserts a new offense into the Penal Code: Article 437-bis. It punishes the omission of mandatory security measures on high-risk AI systems, and their unlawful alteration, when either creates a concrete danger to life, public safety or state security. Reported penalty ranges run 1 to 5 years' imprisonment for the base offense, rising to roughly 2 to 8 years where public safety or state security is at stake, with liability for negligence requiring gross negligence rather than ordinary technical error — a deliberate guardrail against criminalizing routine bugs. Corporate liability under Legislative Decree 231/2001 extends exposure to the companies operating these systems, not just individual engineers or executives.

Biometric Identification: Narrowed, Not Banned

Real-time remote biometric identification in public spaces is prohibited by default and permitted only for two narrow purposes: preventing an imminent terrorist attack or grave threat to life, or locating missing persons and victims of trafficking or sexual exploitation. Police need advance authorization from a public prosecutor specifying purpose, area and duration, capped at fifteen days and renewable only by further order; an emergency procedure allows immediate activation with oral notice to the prosecutor, followed by written authorization within 24 hours and a prosecutorial decision within another 24. Collected biometric data must be deleted within seven days, and the decree explicitly bars building databases through mass, untargeted scraping of the web — a direct answer to Clearview-AI-style scraping.

The Case For This Framework

The strongest argument for these decrees is legal certainty. The AI Act left enforcement architecture to member states, and without a functioning national authority, Italian companies deploying high-risk AI would face an accountability vacuum — no one to certify conformity, no one to inspect, no clear penalty schedule. Criminalizing negligent failure to secure high-risk AI systems is a proportionate response to real harms: an autonomous vehicle, a medical-triage model or an industrial-control AI that malfunctions because a company skipped mandated safeguards is not a hypothetical risk. And a flat ban on real-time facial recognition, with no exceptions, would have left police unable to respond to an unfolding terrorist attack or a child abduction — genuinely hard cases regulators elsewhere have fudged rather than resolved.

Where the Design Falls Short

Two gaps undercut the framework's credibility. First, per Cleary Gottlieb's analysis of the law, the European Commission has already raised concerns that ACN and AgID lack the independence the AI Act requires of market-surveillance authorities — both sit within the executive branch's orbit, and ACN in particular is Italy's cybersecurity and national-security agency auditing the same government's own AI deployments. Second, and more concretely, Il Post's reporting on the finalized decree confirms that biometric-identification authorization rests with a public prosecutor rather than an independent judge — a break from how comparable surveillance powers are authorized elsewhere in Italian criminal procedure, where an investigating magistrate, not the party bringing the case, signs off. The seven-day retention limit and fifteen-day authorization cap are meaningful constraints, but they sit on a weaker procedural foundation than they should.

Italy deserves credit for being first to operationalize the AI Act rather than leaving it as aspirational text. But as other member states look to Rome's decrees as a template, the fix is straightforward: give ACN and AgID demonstrable independence from the ministries whose AI deployments they audit, and route biometric-surveillance authorization through an investigating judge rather than a prosecutor. Enforcement clarity without independent checks is not proportionate regulation — it's just faster enforcement.

Sources & Citations

  1. Consiglio dei Ministri, Comunicato Stampa n. 185
  2. Legge 23 settembre 2025, n. 132 — Gazzetta Ufficiale
  3. Il Post: decree on police facial recognition
  4. Cleary Gottlieb: Italy adopts first national AI law
  5. noze: AI law implementing decrees analysis