A Governance Template, Not Just a Law
On June 10, 2026, Italy's Council of Ministers gave preliminary approval to two legislative decrees implementing Law 132/2025 — the national statute Rome adopted in 2025 as the EU's first comprehensive domestic AI law. The decrees do the unglamorous but consequential work every AI Act member state eventually has to do: naming who enforces it. The Agency for Digital Italy (AgID) becomes the notifying authority, accrediting and supervising the conformity-assessment bodies that certify high-risk AI systems. The National Cybersecurity Agency (ACN) becomes the market surveillance authority — with inspection and sanctioning powers — and Italy's single point of contact with the European Commission (Council of Ministers press release, June 10, 2026).
That split is worth taking seriously as institutional design, not just paperwork. The AI Act gives member states broad discretion over who plays these roles, and several governments have dithered. Italy divided the job cleanly — an innovation-promotion agency handles pre-market accreditation, a security agency handles post-market policing — rather than concentrating both functions in one body that inevitably prioritizes one over the other. For firms deploying high-risk AI in Italy, that clarity is itself a form of proportionate regulation: by the October 2026 delegation deadline set in Law 132/2025, they will know exactly which agency to call.
The Liability Trade Companies Are Being Asked to Accept
The second decree matters more for anyone actually building or deploying AI in Italy. It creates a civil liability framework establishing, per legal analysis of the decree text, "a presumption of the causal link where the damage stems from a breach of AI Act obligations" — meaning a claimant harmed by an AI system no longer has to prove the system caused their injury, only that the deployer violated an AI Act obligation (noze.it legal analysis of the decrees). Compliance with the AI Act neutralizes the presumption; non-compliance leaves a defendant starting the case already behind.
There is a real case for this. AI systems are opaque by design, and requiring an injured party to reverse-engineer a causal chain inside a black-box model is often an insurmountable evidentiary bar — one that would make the AI Act's substantive obligations unenforceable for individual claimants in practice. Presumed causation tied to a documented compliance failure is a narrower, more defensible tool than blanket strict liability for AI harms: it punishes non-compliance, not the technology. Firms that do the compliance work the AI Act already requires — documentation, risk assessments, human-oversight logs — earn the shield the presumption removes from everyone else. That is proportionate regulation working as intended.
Where the Model Breaks: Facial Recognition
The decree's police-AI provisions are where the "anthropocentric, proportionate" framing meets its hardest test — and where Italy's own regulator says it fails. The rule permits real-time remote biometric identification only with prior judicial authorization, capped "at most fifteen days, renewable by reasoned order," restricted to grave security threats, missing persons, or trafficking victims. Post-event facial recognition on existing footage is allowed only after a crime, with retained data required to be deleted within seven days if unused (noze.it).
On paper that tracks the AI Act's own carve-outs for law-enforcement biometric identification. In practice, the policing decree — advanced through a further parliamentary committee vote on July 29, 2026 — would let cameras at "sensitive locations" including political demonstrations and sports events capture and hold biometric data from every attendee for seven days by default, to be mined only if a crime later occurred there (ANSA, July 30, 2026).
Italy's Garante per la protezione dei dati personali reviewed that language and, in a formal opinion dated July 14, 2026 (Registry No. 531), found the ex-ante bulk collection incompatible with the AI Act's narrower "targeted" ex-post exception — recommending biometric processing be limited to specific operational need rather than automatic capture-then-filter, and warning against reference databases built through non-targeted scraping (Garante Privacy, Opinion 531/2026). The government maintains it "will continue to comply with European regulations…as it has done so far," and the dispute has already delayed a lower-house vote once (Biometric Update, July 2026).
That is a genuine legal question, not a manufactured one — continuous collection followed by retrospective filtering functionally resembles the live surveillance the AI Act restricts, whatever label attaches to the seven-day retention window. A judicially-bounded, 15-day warrant regime for genuine emergencies is a reasonable, evidence-based design. Blanket capture at broadly defined "sensitive locations" is a different instrument, and dressing it in the same statutory clothing risks discrediting the parts of the decree package that are actually well built: the governance split, the liability shield, and the €100 million committed to teacher AI-literacy training (Council of Ministers, June 10, 2026).
The October Clock
Law 132/2025 gives the government until October 2026 to finalize these decrees. Rome now has to choose between narrowing the biometrics provision to fit its own regulator's reading of the AI Act, or finalizing language the Garante has already flagged — inviting the European Commission to make the same argument later, at higher cost and to a less sympathetic audience. Getting the enforcement architecture right across two agencies was the harder institutional problem, and Italy largely solved it. Whether a rushed surveillance clause is allowed to undercut that work is the part still worth watching.