CLIENT ALERT

Italy’s evolving AI framework: New litigation tools and expanding civil and corporate criminal liability risks

October 5, 2026

Read time: 14 min

Overview

Italy has completed a significant step in integrating the provisions of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) at the national level, by adopting national rules that complement those of EU origin. Indeed, Legislative Decree No. 160 of 9 September 2026 (Decree 160/2026), in force since 30 September 2026, creates a dedicated regime for:

  • Police use of AI.
  • New AI-specific criminal offenses with corporate exposure under Legislative Decree 231/2001.
  • Civil procedure and civil liability tools for anyone harmed by an AI system, including evidence disclosure, a rebuttable presumption of causation, and a direct action against liability insurers.
In depth

The EU framework in brief

The EU Artificial Intelligence Act (the AI Act), in force since 1 August 2024, classifies AI systems by risk. The classifications include:

  • A narrow set of generally prohibited practices (see Art. 5 of the AI Act), including manipulative or deceptive AI, exploitation of vulnerabilities, social scoring, certain predictive-policing systems, untargeted scraping of facial images, emotion recognition in workplaces and schools, and certain biometric categorization practices.
  • High-risk systems, including AI systems that are intended to be used as a safety component of a product, or which are themselves products, covered by the Union harmonization legislation and subject to a third-party conformity assessment; as well as AI systems used in critical infrastructure, education, employment, essential private and public services, law enforcement, migration and border management, and the administration of justice and democratic processes. These AI systems are subject to a full compliance regime involving risk management, data governance, technical documentation, logging, human oversight, and conformity assessment.
  • Limited-risk systems, such as chatbots or image processing software, which are subject mainly to transparency duties.
  • Minimal-risk systems, such as AI-enabled video games or spam filters, which are largely unregulated.

Under the Digital Omnibus Regulation (Regulation (EU) 2026/1744), in force since 27 July 2026, the following AI Act deadlines have been postponed:

  • For high-risk standalone systems (e., software applications operating independently of a regulated physical product, as listed in Annex III to the AI Act), postponed to 2 December 2027; and
  • For AI embedded in regulated products, such as medical devices (listed in Annex I to the AI Act), postponed to 2 August 2028.

Key features of Decree 160/2026

AI use in police activities

Decree 160/2026 introduces a detailed framework governing the use of AI systems by law enforcement authorities, under which AI systems may only be used as tools supporting police activities and human decision making.

Accordingly, before any AI-generated output can be relied upon in decisions or measures affecting individuals, it must be subject to qualified human review by designated personnel, with a documented and traceable review process.

The decree also imposes strict conditions on real-time and post-hoc biometric identification, including prior authorization by the competent judicial authority, limited duration, purpose-specific reference databases and mandatory deletion of unlawfully obtained results, as well as mandatory fundamental rights guarantees for persons under investigation, and data protection impact assessments for certain uses of biometric identification technologies.

New predicate offenses

Decree 160/2026 introduces a new provision (Art. 437-bis of the Italian Criminal Code) establishing criminal liability for the omission of mandatory safety safeguards and human oversight measures for high-risk AI systems, as well as for the unlawful alteration of such systems, in each case where the conduct endangers life or public or individual safety (with higher penalties where state security is endangered).

Through the new Art. 25-vicies of Legislative Decree 231/2001, the conduct covered by Art. 437-bis becomes a predicate offense for corporate liability. Art. 437-bis covers the following cases:

  • Intentional failures to adopt the technical safeguards required during the design, training, production, or placing on the market of high-risk AI systems, where those safeguards are intended to prevent malfunctions or alterations to the system’s functioning. The offense also covers the omission of human-oversight measures.
  • The unlawful alteration of a high-risk AI system.
  • Intentional failure, by a professional deployer of a high-risk AI system, to implement the legally required human oversight measures.
  • Grossly negligent commission of the omissions described in the first bullet above (with a penalty reduced by one-third to one-sixth).

Art. 25-vicies also extends corporate liability to the offense under Art. 612-quater of the Italian Criminal Code (unlawful dissemination of AI-generated or altered content).

The commission of the offense under new Art. 437-bis of the Italian Criminal Code may expose companies, under Art. 25-vicies of Legislative Decree 231/2001, to monetary penalties of 600 to 1,000 quotas (200 to 700 quotas for Art. 612-quater), in addition to disqualification sanctions, including a prohibition on contracting with public authorities; exclusion from public benefits and incentives; the suspension or revocation of licenses, authorizations, or concessions; and a ban on advertising goods or services.

Civil liability for AI-related harm

Decree 160/2026 does not create a new, strict liability cause of action, but it provides for significant procedural and evidentiary tools, as set out in Arts. 16 – 19:

  • In civil claims – whether contractual or non-contractual – for damages caused by the use of an AI system, the court may order the opposing party or a third party to disclose evidence specifically relevant to the functioning of the AI system, such as system logs, risk management documentation, relevant technical documentation, and information on human oversight measures. The claimant must, however, present facts and evidence making the claim plausible, including as regards the link between the output produced by the AI system and the damage suffered.
  • When disclosure creates a risk of revealing trade secrets or other confidential information, the court may adopt appropriate protective measures.
  • Unjustified non-compliance has significant consequences. Where a party fails to comply, the court may (i) deem the facts alleged by the claimant to be admitted, if the failure concerns the specified AI Act documentation, or (ii) otherwise draw evidentiary inferences. Where a third party fails to comply, the court may impose a monetary penalty between €1,500 and €10,000.
  • Where the damage derives from breach of an AI Act obligation, the causal link between the breach and the damage is presumed, subject to rebuttal.
  • AI Act conformity, even where certified, does not by itself exclude liability.

Other procedural provisions: Consumer venue and direct action against insurers

Art. 16(4) of Decree 160/2026 adds a supplementary venue at the claimant’s residence or domicile for individuals acting outside their trade or profession (i.e., consumers).

Art. 20 introduces two complementary mechanisms. First, any prospective claimant may ask the allegedly responsible party whether it holds liability insurance and that party must disclose the policy details and the insurer within 30 days (failure to do so may support adverse evidentiary inferences). Second, the claimant may bring a direct action against the insurer within the limits of the policy coverage. The allegedly responsible party must be joined as a necessary party in any such proceedings; policy defenses predating the event may be raised against the claimant; and the insurer retains a right of recourse against its insured.

Interaction with product liability

Decree 160/2026 expressly preserves claims under the Product Liability Directive (Directive (EU) 2024/2853) and its national implementing rules (Art. 16(3)).

We covered the core mechanics of the New Product Liability Directive (the PLD) in our October 2024 alert, “Key Features of the New EU Product Liability Directive”, including that:

  • The definition of ‘product’ is expanded, and it now includes AI systems, software, electricity, digital manufacturing files, and raw materials.
  • The definition of ‘defect’ is broadened, in order to apply to AI systems. Under the PLD, in assessing the defectiveness of a product, consideration must also be given to the effects on the product caused by its ability to continue learning or acquiring new functionality after it has been placed on the market or put into service, with the clarification that a product shall not be considered defective solely because a better product is placed on the market or because of any updates or improvements to it.
  • The scope of liable parties is expanded. In addition to the manufacturer, liability extends to the importer, the authorized representative, and the fulfilment (logistics) service provider; distributors and online platforms may be liable on a subsidiary basis if they fail to identify a responsible operator; and anyone who substantially modifies the product is treated as its manufacturer.
  • The burden of proof is eased for the injured party. More specifically, a rebuttable presumption has been established regarding (i) the defectiveness of the product (g., where the defendant fails to disclose relevant evidence, the product does not comply with mandatory safety requirements, or it obviously malfunctions) and (ii) the causal link between the defectiveness of the product and the damage, if the damage is of a kind typically consistent with the defect in question.
  • A specific form of discovery has also been introduced for this kind of litigation. EU Member States shall ensure that, when a claimant has presented sufficient evidence to support the plausibility of the claim for compensation, the defendant is required to disclose relevant evidence, with special protections for trade secrets.
  • The scope of compensable damages has been expanded to include the destruction or corruption of non-professional data and clinically verified psychological damages.
  • The expiry period for damages is set at 10 years from either (a) the date on which the defective product was placed on the market or (b) in the case of a substantially modified product, the date on which that product was made available following modification. For latent personal injuries, the expiry period is extended to 25 years.

The PLD must be transposed by 9 December 2026 and applies to products placed on the market or put into service after that date. Earlier products remain under the 1985 regime unless substantially modified afterward. Italy’s draft implementing decree (Atto del Governo n. 434) was transmitted to Parliament on 7 August 2026, remains under review, and has not yet been enacted.

As mentioned above, the PLD expressly includes AI software in the definition of ‘product’ and expands the scope of liable parties to anyone who makes substantial changes to the product, which can make a fine-tuner or integrator of a third-party AI model a strictly liable subject.

This must be coordinated with the amendment to Art. 25 of the AI Act as set forth by the Digital Omnibus Regulation, requiring an AI provider that loses ‘provider’ status – because a third party has substantially modified its system, for example – to cooperate with that new provider (for example, by sharing documentation and technical access needed for the new provider’s own conformity assessment).

In the case of a company that fine-tunes a licensed foundation model into a claims triage tool that qualifies as a high-risk system, the fine-tuning can be considered a ‘substantial modification’ that (i) shifts AI Act provider status – and core compliance duties – to the fine-tuner (once the relevant high-risk obligations apply), backed by a statutory right to the original developer’s cooperation, while (ii) simultaneously exposing the fine-tuner to strict liability under the PLD as a ‘manufacturer’ for defects introduced by the modification.

Businesses that integrate or fine-tune third-party AI should negotiate both consequences – the cooperation duty and the liability exposure – into the same contract clauses, rather than treating them as separate workstreams.

Combined litigation risk: Civil liability and corporate criminal liability

Decree 160/2026 and the PLD were drafted independently and address different problems: one is Italy’s domestic evidentiary toolkit for AI harm, while the other is an EU-wide strict liability regime for defective products generally.

However, Decree 160/2026 expressly preserves PLD claims, and Italy’s forthcoming decree implementing the PLD, which would replace Consumer Code Arts. 114 – 127, is expected to add its own disclosure and presumption mechanism running alongside Arts. 16 – 19 of Decree 160/2026. For litigation and risk-management purposes, the two regimes need to be read together.

For AI-related harm in Italy, claimants will generally be able to combine two substantive bases of liability with the procedural toolkit of Decree 160/2026, namely:

  1. Ordinary Civil Code tort liability (fault-based under Art. 2043 or, for dangerous activities, Art. 2050), which the Decree’s disclosure tools and, where an AI Act breach is alleged, a causation presumption, are designed to support;
  2. The PLD, once transposed (strict, defect based, and aided by its own disclosure and presumption toolkit, available regardless of AI Act compliance); and
  3. The procedural toolkit of Decree 160/2026 (Arts. 16 – 20), available in contractual and non-contractual damages actions alike, and capable of being combined with either basis above.

Nothing in any of these regimes requires a claimant to choose. For this reason, it should be expected for pleadings to run all three theories in parallel against overlapping sets of defendants, and defense strategy should assume that from the outset rather than reacting to it once a complaint is filed.

The PLD and Decree 160/2026 regimes are also on different clocks: Decree 160/2026 has been in force since 30 September 2026, while the PLD must be transposed into Italian law by 9 December 2026, and Italy’s implementing decree (Atto del Governo n. 434) remains under parliamentary review.

The AI Act’s own high-risk compliance deadlines, by contrast, were pushed back by the mid-2026 Digital Omnibus Regulation to 2 December 2027 (for standalone systems) and 2 August 2028 (for AI embedded in already-regulated products).

The result is that the PLD’s strict liability and the disclosure tools of Decree 160/2026 can both attach to an AI system even before the AI Act’s own compliance obligations for that system are due (the Art. 18 causation presumption, by contrast, requires a breach of an AI Act obligation that already applies, such as the Art. 5 prohibitions or the Art. 50 transparency duties). A company can therefore be sued under either regime for AI-related harm well before it is legally required to have the AI Act paperwork that would most naturally support a defense.

Corporate criminal liability must also be factored into risk analysis. Companies operating AI systems in Italy should consider the implications of the new Art. 25-vicies of Legislative Decree 231/2001, extending corporate liability to offenses concerning the safety, integrity, and human oversight of high-risk AI systems.

The new framework also requires companies to address not only intentional misconduct but also situations involving gross negligence in the adoption of technical safeguards or human oversight measures for high-risk AI systems. In practice, under the new framework, the risk is no longer limited to deliberate violations of AI-related obligations: a serious failure to design or implement adequate safety and oversight measures may itself become relevant from a corporate liability perspective.

Above all, the introduction of Art. 25-vicies of Legislative Decree 231/2001 brings AI-related risks directly within the notion of organizational fault on which Legislative Decree 231/2001 rests. As a result, what counts as an adequate organization, management, and control model pursuant to the Legislative Decree 231/2001 is likely to move beyond conventional compliance measures.

Organizational fault will still depend on a legal assessment: whether the company can be held liable for failing to adopt measures that could reasonably have been expected to prevent the offense. At the same time, that assessment will increasingly draw on the technical and regulatory standards that govern AI systems, including requirements on risk management, human oversight, monitoring, documentation, and staff training. The outcome is a more hybrid concept of organizational fault, where legal accountability is measured against a growing body of technical and governance benchmarks.

Practical implications and key takeaways

  • Treat disclosure requests under Decree 160/2026 and the PLD as a single workstream: Build one protocol now for what will be produced, in what form, and how trade secrets and confidential technical information will be protected – before a request arrives.
  • Do not rely on AI Act conformity certification as a shield in either regime: both Decree 160/2026 and the PLD’s presumption structure allow liability to be found notwithstanding formal conformity.
  • Keep AI Act risk management, logging, and human-oversight documentation audit-ready the year-round.
  • Map the AI supply chain against the PLD’s expanded circle of liable ‘economic operators,’ with particular attention to whether fine-tuning or reconfiguring a third-party model could make your business a ‘manufacturer’ in its own right.
  • In healthcare and other regulated sectors, anticipate the risk of parallel claims under multiple liability theories against different defendants (e.g., manufacturer, deployer, and professional) arising from the same adverse outcome. Revisit AI liability insurance.
  • Review and update the organization, management, and control model pursuant to Legislative Decree 231/2001 to reflect the introduction of Art. 25-vicies of Legislative Decree 231/2001 and the new corporate liability risks associated with Art. 437-bis of the Italian Criminal Code.
  • Reassess AI-related risk mapping to identify activities involving high-risk AI systems and evaluate potential exposure arising from safety failures, unlawful system alterations, and inadequate human oversight.
  • Maintain appropriate records and evidence of compliance activities, and implement and document human oversight procedures, ensuring that oversight responsibilities are clearly allocated, and establish dedicated reporting flows to the Supervisory Body concerning the measures taken to address the risks related to high-risk AI systems.
  • Track the Italian PLD-implementing decree through to final enactment – its evidentiary provisions are not yet in force and may change during parliamentary review.
Authors

Fabio Cozzi

Partner

Milan

Alberto Del Panta

Associate

Milan

Arcangela Gerbino

Associate

Milan

More insights