AI liability in Italy: what Legislative Decree 160/2026 changes for businesses and professionals

By Massimo Leonardi · · Leggi in italiano

AI liability in Italy: what Legislative Decree 160/2026 changes for businesses and professionals
Quick answer. Italian Legislative Decree No. 160 of 9 September 2026 (Official Gazette No. 214 of 15 September 2026, in force since 30 September 2026) implements the delegation granted by Law No. 132/2025 and aligns Italian law with the EU AI Act. Besides regulating the use of AI by the police, it introduces a new criminal offence (Article 437-bis of the Criminal Code: failure to adopt safety and human-oversight measures in high-risk systems), a new Article 25-vicies of Legislative Decree 231/2001 on corporate liability, and new civil tools for damage claims: disclosure of technical documentation, a presumption of causation where the AI Act has been breached, the rule that certified conformity alone is no defence, and a direct action against the insurer.

Artificial intelligence is no longer only a matter of efficiency, innovation or EU compliance. In 2026 the Italian legislator went a step further and addressed the liability that arises from the professional use of AI systems.

Legislative Decree No. 160 of 9 September 2026 adds rules on the production, placing on the market and professional use of AI systems, with a focus on the civil and criminal consequences of omissions, security gaps and unlawful uses. It implements Law No. 132 of 23 September 2025 and aligns Italian law with Regulation (EU) 2024/1689, the AI Act.

One clarification matters: a large part of the decree governs the use of AI by law enforcement. The provisions on criminal and civil liability, however, apply generally and concern companies, professionals and anyone who uses AI systems in their business. Foreign companies operating in Italy, or using AI tools with Italian customers and employees, should take note.

1. From using AI to being liable for it

So far the debate has focused on transparency, data, risk classification and organisational duties. The Italian framework now also looks at the concrete conduct of those who use AI systems professionally.

The principle is simple: relying on an automated system does not remove the liability of whoever adopts it, integrates it into their processes or fails to put adequate security and control measures in place.

The decree does not create automatic liability for every system error: the substantive rules remain those of the Italian Civil Code. It mainly changes the tools, starting with evidence, that make it possible to enforce that liability in practice.

2. Security measures become central, including under criminal law

The decree inserts Article 437-bis into the Italian Criminal Code ("Failure to adopt security measures in artificial intelligence systems and unlawful alteration of systems"). It punishes with one to five years' imprisonment anyone who fails to adopt the technical security measures required for the design, training, production or placing on the market of high-risk AI systems, or the necessary human-oversight measures, where this endangers life or public or individual safety. If the danger concerns State security, the penalty is two to eight years.

The same provision punishes the alteration of high-risk systems, covers conduct committed with gross negligence and expressly addresses the professional user who intentionally fails to adopt human-oversight measures.

For companies, the new Article 25-vicies of Legislative Decree 231/2001 extends corporate liability to the offence under Article 437-bis (a fine of 600 to 1,000 quotas) and to the offence under Article 612-quater of the Criminal Code on the unlawful dissemination of AI-generated or altered content (200 to 700 quotas), with possible disqualification measures.

Documenting assessments, controls and internal responsibilities therefore becomes essential.

3. Professional use of AI requires human oversight

An AI output can be technically plausible yet legally wrong, discriminatory, incomplete or based on unreliable information. Human oversight is not a formality but a safeguard: whoever uses AI professionally must be able to understand, check and, where needed, correct the result.

For high-risk systems, human oversight is an AI Act requirement; under Decree 160/2026 its intentional omission by a professional user falls within the conduct covered by Article 437-bis.

4. Damage claims: the main change is evidence

Articles 16 to 20 introduce procedural tools for contractual and non-contractual damage claims relating to the use of AI systems.

| Tool | What it provides | Article | |---|---|---| | Disclosure of documentation | If the claim is plausible, the court orders the other party or a third party to disclose relevant evidence on how the system works: logs, risk management, technical documentation, human-oversight parameters. The order must be necessary and proportionate and protect trade secrets. | Art. 17 | | Failure to disclose | If a party fails to comply without good reason, the court may draw inferences; where the failure concerns the documentation listed in the provision, having assessed all other evidence, the court deems the facts alleged by the injured party admitted. A third party who fails to comply faces a monetary penalty. | Art. 17 | | Causation | If the damage results from a breach of one or more AI Act obligations, the causal link between breach and damage is presumed, unless proven otherwise. | Art. 18 | | Conformity | Conformity with the AI Act, even if certified, does not in itself exclude the defendant's liability. | Art. 19 | | Insurance | The injured party may ask the alleged liable party whether it is insured (reply within 30 days) and has a direct action against the insurer up to the policy limit. The decree does not introduce compulsory insurance. | Art. 20 |

Where the injured party is a consumer, the court of the consumer's place of residence or domicile also has jurisdiction (Article 16(4)).

5. The EU timeline: what already applies and what applies from 2027

Several rules of the decree refer to AI Act obligations. Under Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, obligations for high-risk systems have been postponed to 2 December 2027 for Annex III systems and to 2 August 2028 for systems embedded in Annex I products. The Article 5 prohibitions and the Article 50 transparency obligations, among others, already apply.

The postponement is not an exemption: it is time to get organised. The documentation kept today is what may be requested in court tomorrow.

6. Most exposed areas

Risks concentrate where AI output affects people, rights or economic decisions. Some of these areas, such as recruitment and creditworthiness assessment, are high-risk uses under the AI Act.

  • recruitment and personnel management;
  • creditworthiness or insurance assessment;
  • healthcare and professional services;
  • automated drafting of documents and opinions;
  • processing of personal and confidential data;
  • systems that directly affect people's rights, safety or integrity.

7. What businesses and professionals should do now

  • map the AI systems actually in use;
  • identify activities where output may have significant legal or economic effects;
  • assign responsibility for human oversight;
  • formalise verification, security and incident-management procedures;
  • keep logs and records of human checks;
  • secure access to suppliers' technical documentation;
  • review liability insurance policies, focusing on exclusions and limits;
  • update internal policies, contracts, compliance processes and, where adopted, the Decree 231 compliance model.

Conclusion

The real question for businesses is no longer only whether using an AI system is lawful, but whether the organisation can prove it used it in a controlled, secure and responsible way. For companies with interests in the United States, IIILEX also operates through its Miami, Florida office, IIILEX International.

Key sources

  • Legislative Decree No. 160 of 9 September 2026 (Official Gazette No. 214 of 15 September 2026).
  • Law No. 132 of 23 September 2025, Article 24.
  • Regulation (EU) 2024/1689 (AI Act).
  • Regulation (EU) 2026/1744 (Digital Omnibus on AI).
  • Legislative Decree No. 231 of 8 June 2001, Article 25-vicies.

Frequently asked questions

When does Legislative Decree 160/2026 apply?

It was published in Official Gazette No. 214 of 15 September 2026 and has been in force since 30 September 2026.

Does the decree only concern the police?

No. A significant part governs the use of AI by law enforcement, but the rules on criminal and civil liability also apply to businesses and professionals that design, market or use AI systems.

Does AI Act conformity protect against all liability?

No. Article 19 provides that conformity with the AI Act, even if certified, does not in itself exclude the defendant's liability.

Does an injured party still have to prove causation?

If the damage results from a breach of AI Act obligations, causation is presumed unless proven otherwise (Article 18). The breach and the damage must still be proven; otherwise ordinary rules apply.

Is insurance compulsory for AI users?

No. But if the liable party is insured, the injured party has a direct action against the insurer up to the policy limit and may ask about coverage, with a reply due within 30 days (Article 20).

What does a company risk under Decree 231/2001?

Article 25-vicies provides a fine of 600 to 1,000 quotas for the Article 437-bis offence and 200 to 700 quotas for the Article 612-quater offence, plus possible disqualification measures.

Contact the firm