Italy has put criminal law behind the EU AI Act before most member states have settled their own enforcement plans. Legislative Decree No. 160 of 9 September 2026 was published in the Gazzetta Ufficiale (no. 214) on 15 September and takes effect on 30 September 2026. It is the first major implementing measure under Law 132/2025, Italy's framework AI statute, and it adapts national law to Regulation (EU) 2024/1689 (Normattiva).
What the decree does
The decree has three layers. The first is a new Criminal Code Article 437-bis. It penalises failing to adopt technical measures against malfunctions or unlawful alterations of high-risk AI systems, and failing to apply required human oversight. Liability arises only where the failure creates a concrete danger to life or physical integrity, to public safety, or to the security of the State, according to the Oxford Business Law Blog. ppc.land reports the sentencing ranges: one to five years for omitting security or oversight measures, two to eight where State security is endangered, and up to ten years for unlawfully altering a high-risk system.
The second layer is corporate. A new Article 25-vicies extends Legislative Decree 231/2001. ppc.land reports fines of 600 to 1,000 quote for Article 437-bis offences, plus interdictive sanctions lasting three months to two years. These include licence suspension, exclusion from public contracts and a ban on advertising goods or services.
The third layer is civil. Courts may order disclosure of AI documentation, including the logs required by AI Act Article 12. Where damage follows a breach of the AI Act, causation is presumed unless the defendant rebuts it. Injured parties get a direct action against liability insurers, within policy limits (PG Legal).
The strongest case for Rome's approach
The case for this design is real. High-risk AI is meant to be used in settings such as infrastructure, health and public services, where failures can hurt people who never chose the system. Administrative fines alone can be priced in as a cost of doing business. AI Act Article 99 caps fines for high-risk breaches at EUR 15 million or 3% of worldwide turnover, and lower for SMEs (AI Act Article 99). A credible criminal backstop deters the worst behaviour. Log disclosure and a causation presumption also address a real problem: victims of opaque systems cannot otherwise reach the evidence. The decree is also narrower than it might have been. The concrete-danger threshold keeps ordinary bugs and compliance slips out of the criminal courts.
Where the design is weak
The difficulty is what the decree leaves undefined. Prison terms attach to failing to adopt "appropriate" measures against "malfunctions", and the Oxford analysis itself notes that not every error affecting an AI system should count as a malfunction. Engineers and compliance officers must guess where that line falls, and the guess now carries a custodial risk. Meanwhile the technical standards that would define "appropriate" are still being built at EU level. Criminal law works best when the conduct it forbids is knowable in advance.
The civil presumption raises a similar problem. Once any AI Act obligation is breached, causation between the breach and the damage is presumed. A paperwork failure that had nothing to do with the harm can still tilt a lawsuit against the deployer. The presumption is rebuttable, but the burden of rebutting it falls on the party that may be least able to reconstruct what a model did. Combined with court-ordered log disclosure, this rewards firms that keep exhaustive records and penalises those that do not. Large incumbents can absorb that cost; startups and small municipal deployers will feel it more.
Corporate sanctions add pressure. A licence suspension or advertising ban is an existential threat to a small company, and the decree applies it before any settled body of case law exists. The predictable response is defensive: firms avoid deploying AI in the sectors the law most wants served well, or geo-fence Italy out of their products.
What a proportionate implementation would look like
Nothing here requires repealing the decree. Three adjustments would keep the deterrent and reduce the chilling effect:
- Prosecutorial guidance that ties Article 437-bis to recognised harmonised standards and documented risk management, so that good-faith compliance is a clear defence.
- A safe harbour for rebuttal: courts should treat contemporaneous logs and risk documentation as strong evidence against the causation presumption, so record-keeping pays off.
- SME-sensitive sanctioning for interdictive measures, with warnings and remediation windows before suspension.
Insurers may end up doing some of this work. Direct action makes them a first port of call for claimants, and PG Legal notes that the decree does not mandate AI insurance but changes claims dynamics. Underwriters who price on documented governance will push deployers toward the practices the law wants. That is a market mechanism regulators should encourage, not crowd out.
The bottom line
Italy deserves credit for taking AI harms seriously and for limiting the criminal offence to concrete danger. But criminal liability and evidentiary presumptions are blunt tools, and blunt tools need precise definitions. The decree enters into force on 30 September 2026. Whether it protects the public without freezing Italian AI deployment will depend on how prosecutors and courts read "appropriate" and "malfunction" in the first few cases. Other member states drafting their own regimes should copy the concrete-danger threshold and pair it with clearer standards.