Italy has a dedicated national AI statute. Law No. 132/2025, in force since 10 October 2025, is often described as a second layer of duties on top of the EU AI Act. It is not, and it says so: Article 3, comma 5 provides that the law produces no new obligations beyond Regulation (EU) 2024/1689. What it does instead is name the national authorities, state principles, and legislate specific national matters, chiefly health data for research, AI in public administration, AI in judicial activity, copyright, and one new criminal offence. AgID is the notifying authority under Article 70 of the EU AI Act and ACN is the market surveillance authority and single point of contact, while Banca d'Italia, CONSOB and IVASS keep market surveillance in their own sectors. The obligations that actually bite on an Italian operator are the EU ones: Article 5 prohibited practices and Article 4 AI literacy since February 2025, GPAI model duties since August 2025, and Article 50 transparency since 2 August 2026. This guide explains what each layer requires and what the liability and insurance consequences are.
Key takeaways
- Legge 23 settembre 2025, n. 132 was published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 and entered into force on 10 October 2025. It runs to 28 articles in six Capi.
- Article 3, comma 5 states that the law produces no new obligations beyond Regulation (EU) 2024/1689 for AI systems and for general purpose AI models. Read the national statute as an allocation of authority and a set of sectoral national rules, not as an extra compliance layer.
- Article 20 designates AgID (Agenzia per l'Italia digitale) as the notifying authority under Article 70 of the EU AI Act, and ACN (Agenzia per la cybersicurezza nazionale) as the market surveillance authority and single point of contact with the EU institutions. Banca d'Italia, CONSOB and IVASS remain market surveillance authorities in their sectors under Article 74, paragraph 6.
- Article 26 inserts a new Article 612-quater of the codice penale on unlawful distribution of AI-generated or AI-altered content, punishable by reclusione from one to five years, and amends Article 61 and Article 294 of the codice penale, Article 2637 of the codice civile and Article 185 of Legislative Decree 58/1998.
- Article 24 delegates to the Government the adoption of legislative decrees within twelve months of entry into force, that is by 10 October 2026, both to align national law with Regulation (EU) 2024/1689 and to specify the treatment of unlawful development and use of AI systems.
- EU AI Act obligations already binding on Italian operators: Article 5 prohibited practices and Article 4 AI literacy since 2 February 2025, GPAI model obligations since 2 August 2025, Article 50 transparency since 2 August 2026.
- High-risk obligations were deferred by the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026. Annex III standalone systems apply from 2 December 2027 and Annex I from 2 August 2028.
- Directive (EU) 2024/2853, the revised Product Liability Directive, must be transposed by 9 December 2026. Standard commercial liability policies in Italy predate AI-specific risk categories, so coverage should be reviewed ahead of transposition.
Law No. 132/2025: Italy's national AI statute
The full title of the statute is Legge 23 settembre 2025, n. 132, Disposizioni e deleghe al Governo in materia di intelligenza artificiale. It was published in the Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 and entered into force on 10 October 2025. It runs to 28 articles in six Capi: general principles (Articles 1 to 6), sector provisions (Articles 7 to 18), national strategy, national authorities and promotion measures (Articles 19 to 24), user protection and copyright (Article 25), criminal provisions (Article 26), and financial and final provisions (Articles 27 and 28).
The law is notable for what it is not, and the statute is explicit about it. Article 3, comma 5 provides: "La presente legge non produce nuovi obblighi rispetto a quelli previsti dal regolamento (UE) 2024/1689 per i sistemi di intelligenza artificiale e per i modelli di intelligenza artificiale per finalita' generali." The law produces no new obligations beyond those already set by the EU AI Act for AI systems and for general purpose AI models. It creates no licensing or certification scheme, no general prohibition on AI deployment, and no prior authorisation requirement for commercial AI use.
Its practical weight lies elsewhere: it names the national authorities, sets out principles, legislates a set of specifically national matters that the EU AI Act does not touch, chiefly health data for research, use of AI in public administration and in judicial activity, copyright and criminal law, and it delegates further legislation to the Government. Article 24 gives the Government twelve months from entry into force, that is until 10 October 2026, to adopt legislative decrees aligning national law with Regulation (EU) 2024/1689 and specifying the treatment of unlawful development and use of AI systems.
The supervisory structure: AgID, ACN, and the sectoral supervisors
Article 20, comma 1 designates AgID (Agenzia per l'Italia digitale) and ACN (Agenzia per la cybersicurezza nazionale) as the national authorities for artificial intelligence. Comma 2 then splits the two roles the EU AI Act requires, and the split matters for any operator working out who to talk to.
AgID is the notifying authority. Article 20, comma 2 designates AgID "quale autorita' di notifica ai sensi dell'articolo 70" of Regulation (EU) 2024/1689. In the AI Act's architecture, the notifying authority is the body responsible for setting up and running the procedures for assessing, designating and monitoring conformity assessment bodies. AgID also carries the law's promotion and development functions for AI. It is not the body that polices deployed systems in the market.
ACN is the market surveillance authority. The same comma designates ACN "quale autorita' di vigilanza del mercato e punto di contatto unico con le istituzioni dell'Unione europea". Market surveillance is where inspection and sanctioning powers sit under the EU AI Act, and ACN is also Italy's single point of contact with the EU institutions. For an operator running AI systems in Italy, ACN is the supervisory interlocutor that matters most.
Article 20, comma 1 preserves the position of the financial supervisors: "ferma restando l'attribuzione alla Banca d'Italia, alla CONSOB e all'IVASS del ruolo di autorita' di vigilanza del mercato ai sensi e secondo quanto previsto dall'articolo 74, paragrafo 6, del regolamento (UE) 2024/1689." An insurer deploying AI in Italy therefore answers to IVASS as an AI Act market surveillance authority, not only as its prudential supervisor. Comma 4 preserves the powers of the Garante per la protezione dei dati personali and of AGCOM in its role as Digital Services Coordinator.
Separately, Article 19 places the national AI strategy with the Presidency of the Council of Ministers. The strategy is prepared and updated by the structure of the Presidency competent for technological innovation and digital transition, and approved at least every two years by the interministerial committee for digital transition. Article 19, comma 6 establishes a coordination committee, chaired by the President of the Council of Ministers or the delegated political authority, for guidance on bodies, organisations and foundations operating in digital innovation and artificial intelligence.
Workplace AI provisions under Law 132/2025
Italian labour law has long treated monitoring of workers with particular care. Article 4 of the Workers' Statute (Law 300/1970) restricts remote monitoring of workers through audio-visual equipment or other systems, permitting it only under a collective agreement with the union representatives or under authorisation from the labour inspectorate. That article is untouched by Law 132/2025 and continues to apply on its own terms.
What Law 132/2025 adds is shorter than it is often reported to be. Article 11 has three commas. Comma 1 states the purpose: AI is to be used to improve working conditions, protect the psychophysical integrity of workers, and raise the quality and productivity of work, consistently with EU law. Comma 2 requires that use of AI be safe, reliable and transparent and respect human dignity and data protection, and requires the employer or the client to inform workers in accordance with Article 1-bis of Legislative Decree 152/1997. Comma 3 requires that use of AI in the organisation of work guarantee workers' inviolable rights without discrimination on grounds including sex, age, ethnic origin, religion, sexual orientation, political opinion, and personal, social or economic condition.
The union channel therefore runs through Article 1-bis of Legislative Decree 152/1997, the transparency decree, not through a new procedure created by the AI law. That article requires the information about automated decision-making and monitoring systems to be communicated also to the company or unitary union representatives, and, where none exist, to the territorial offices of the nationally representative union associations. It also states expressly that Article 4 of Law 300/1970 continues to apply. An employer working out its duties should read Article 11 as a signpost to the transparency decree rather than as a freestanding obligation.
Two things frequently attributed to Law 132/2025 are not in it. Article 11 does not create a right for the worker to demand an explanation and a human re-examination of an automated employment decision, and it contains no rule that an AI output cannot be the sole basis for dismissal. Where a system is used for recruitment, performance assessment, promotion or termination it falls in Annex III, paragraph 4 of the EU AI Act, and the human oversight duty under Article 14 of the Regulation and the deployer duties under Article 26 of the Regulation apply on the deferred Annex III timetable. They come from the EU AI Act, not from the Italian statute.
Article 12 establishes an Osservatorio sull'adozione di sistemi di intelligenza artificiale nel mondo del lavoro at the Ministry of Labour and Social Policy, chaired by the Minister or a delegate, to define a strategy on the use of AI at work, monitor labour market effects, identify the sectors most affected, and promote training for workers and employers. The Minister was to constitute it by decree within 90 days of entry into force, and members serve without compensation. It is a policy body, not a supervisor, and it issues no obligations to operators.
Healthcare, research, and professional services
Law 132/2025 creates no new clinical approval requirement for AI medical devices. Article 7 sets the frame for health: AI contributes to prevention, diagnosis, treatment and therapeutic choice while the health professional keeps the decision, its introduction must not discriminate in access to care, and comma 3 gives the person concerned the right to be informed about the use of AI technologies. Comma 6 requires that health AI systems and the data they use be reliable, periodically verified and kept updated so as to minimise error and improve patient safety. In practice this is a disclosure and reliability duty rather than a new authorisation gate.
The research provisions are about data, not about publication practice. Article 8 permits public bodies, non-profit private bodies, IRCCS and private healthcare organisations taking part in research projects to process personal data, including health data, for the development of AI systems in prevention, diagnosis, treatment, drug development, rehabilitation technologies, medical devices and public health. Secondary use is allowed without fresh consent where the information duty can be discharged through a general notice on the controller's website, AGENAS may set anonymisation guidance based on international standards, and the processing has to be notified to the Garante with supporting documentation and may begin after thirty days absent a block. Article 9 leaves the detailed regime for health data processing for research to a decree of the Minister of Health, to be issued within 120 days of entry into force after consulting the Garante and the sector. Article 10 inserts a new Article 12-bis into Decree-Law 179/2012 on the electronic health record and gives AGENAS the design and operation of an AI platform providing non-binding support to health professionals.
Professional services matter in Italy because several liberal professions, among them avvocati, commercialisti, ingegneri and medici, are regulated by professional orders with disciplinary powers. Article 13 is short and directed at the individual professional rather than at the orders. Comma 1 confines the use of AI in the intellectual professions to activities that are instrumental and supporting, with the intellectual work that is the object of the engagement remaining predominant. Comma 2 requires, in order to preserve the relationship of trust between professional and client, that information about the AI systems the professional uses be communicated to the recipient of the service in clear, simple and exhaustive language. The article gives the ordini professionali no rule making or guidance mandate. Where AI is used to generate advice, assessments or documents presented under a professional's name, the professional retains liability for the output under the ordinary rules on professional negligence.
Judicial use and the integrity of proceedings
Italy has been cautious about AI in judicial proceedings, and Article 15 reflects that caution in a single controlling sentence. Comma 1 provides: "Nei casi di impiego dei sistemi di intelligenza artificiale nell'attivita' giudiziaria e' sempre riservata al magistrato ogni decisione sull'interpretazione e sull'applicazione della legge, sulla valutazione dei fatti e delle prove e sull'adozione dei provvedimenti." Every decision on the interpretation and application of the law, on the evaluation of facts and evidence, and on the adoption of measures is always reserved to the magistrate. Comma 2 leaves it to the Ministry of Justice to regulate the use of AI systems for the organisation of the justice service, the simplification of judicial work and ancillary administrative activity. Comma 4 tasks the Minister of Justice with training for magistrates.
Comma 3 is the operative one for suppliers. Pending full application of Regulation (EU) 2024/1689, the experimentation and use of AI systems in the ordinary courts requires authorisation from the Ministry of Justice, which consults the national authorities named in Article 20. A legal tech operator cannot simply sell into an Italian court and treat procurement as the only gate.
For operators providing AI research tools, document review platforms or case management systems to the Italian judiciary or to law firms, the design consequence follows from comma 1: these systems must be positioned and built as support tools, never as producers of the decision. The liability exposure where an erroneous output influences a proceeding is real, and professional indemnity coverage should be reviewed against the Italian professional liability standard.
The criminal provisions: Article 26
Capo V of the law consists of a single article. Article 26 is headed Modifiche al codice penale e ad ulteriori disposizioni penali, and it does four things.
- It inserts a new Article 612-quater into the codice penale, Illecita diffusione di contenuti generati o alterati con sistemi di intelligenza artificiale, punishing the distribution without consent of images, video or voice falsified or altered by means of AI systems and capable of misleading as to their genuineness. The penalty is reclusione from one to five years.
- It adds a new aggravating circumstance to Article 61 of the codice penale for the use of AI systems in the commission of an offence.
- It raises the penalty under Article 294 of the codice penale to reclusione from two to six years where the deception is committed by means of AI, and amends Article 2637 of the codice civile with reclusione from two to seven years where the conduct is committed by means of AI.
- It amends the copyright law of 1941 and Article 185 of Legislative Decree 58/1998 on financial intermediation, the latter carrying reclusione from two to seven years and a fine.
Two limits are worth stating plainly, because both are commonly overstated. Article 26 creates one new offence, not a general deepfake regime, and its object is the unlawful distribution of falsified content that is capable of misleading. And it creates no separate offence for platforms or intermediaries that host synthetic media produced by their users. Intermediary responsibility in Italy continues to be governed by the ordinary rules, not by a new duty introduced here.
For operators running generative AI platforms, content creation tools or social media services accessible in Italy, Article 26 interacts with the Article 50 transparency obligations under the EU AI Act, which have applied since 2 August 2026 and require AI-generated or AI-manipulated content to be marked. Failure to mark is an EU AI Act exposure enforced by the market surveillance authority. Article 612-quater is a separate, personal criminal exposure that attaches to whoever distributes the content.
EU AI Act obligations in force for Italian operators
The EU AI Act (Regulation (EU) 2024/1689) applies directly in Italy without national transposition. Since Article 3, comma 5 of Law 132/2025 states that the national statute adds no obligations beyond the Regulation, this is where an Italian operator's actual duties are found. The state of obligations as of August 2026 is as follows.
In force and binding now
Article 5 (prohibited practices). In force since 2 February 2025 and not deferred by the Digital Omnibus. Any Italian operator deploying a system that may fall within one of the prohibited categories should treat this as a live compliance requirement, not a future deadline, and should read Article 5 itself rather than a summary of it, since the categories are drafted narrowly and the exceptions matter.
Article 4 (AI literacy). In force since 2 February 2025 and not deferred by the Digital Omnibus. Providers and deployers must ensure AI literacy among staff and others operating AI on their behalf, proportionate to the system's risk and the operator's role. Documented training records are the standard evidence of compliance.
GPAI model obligations (Chapter V). In force since 2 August 2025 and not deferred by the Digital Omnibus. Most Italian businesses are deployers rather than model providers and are not caught by Chapter V, but an operator that develops or substantially modifies a general purpose AI model should work directly from Chapter V and from the AI Office's guidance, since this is the one part of the Regulation the AI Office enforces itself, under Article 101.
Article 50 (transparency obligations). In force since 2 August 2026. Deployers of chatbots and conversational AI must inform users that they are interacting with an AI system. Providers of emotion recognition or biometric categorisation systems must notify the persons subjected to them. AI-generated or AI-manipulated content must be marked. Article 50 was not deferred by the Digital Omnibus, so for an Italian operator this is a live obligation rather than a deadline to plan for.
Penalties framework (Article 99). The EU-level ceilings are EUR 35 million or 7 per cent of worldwide annual turnover for the Article 5 prohibited practices, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for supplying incorrect, incomplete or misleading information, whichever is higher, with the lower figure applying to SMEs and start-ups. These are enforced by the national market surveillance authorities, which in Italy means ACN, and Banca d'Italia, CONSOB and IVASS in their own sectors. They are not enforced by the AI Office, and they are not Italian law: they are the ceilings the Regulation sets. The AI Office holds a separate regime for general purpose AI models under Article 101, with a ceiling of EUR 15 million or 3 per cent.
The deferred high-risk timetable
High-risk system obligations. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026. Annex III high-risk obligations now apply from 2 December 2027, and Annex I from 2 August 2028. Annex III covers, among others, AI systems used in employment and worker management (paragraph 4), access to essential public services (paragraph 5), law enforcement (paragraph 6), migration and border management (paragraph 7), and administration of justice (paragraph 8). The deferral is settled law, not a proposal: any compliance plan still working to 2 August 2026 as the binding high-risk date is working to a date that no longer applies. It remains a deferral of the compliance date and not of the requirements, so the risk management system, technical documentation and human oversight work still has to be done.
Applying from 9 December 2026
Revised Product Liability Directive (EU) 2024/2853. Member States, Italy included, must transpose the revised directive into national law by 9 December 2026. The Italian transposing measure is what will determine how defective-product claims involving AI software are pleaded and defended in Italian courts. Operators developing or distributing AI software into the Italian market should be tracking the transposition and reviewing product liability coverage against it, rather than assuming existing wordings will carry over.
Insurance and liability implications
Because Law 132/2025 adds no new compliance obligations, the insurance question in Italy is not driven by the national statute. It is driven by the EU AI Act, by the new criminal offence in Article 612-quater, and by the ordinary Italian law of contract and tort under the Codice civile, which applies today with no grace period. Several categories deserve specific attention.
Professional indemnity
Italian professional indemnity policies for legal, medical, engineering, and accounting professionals typically cover negligence in the exercise of the professional's own judgment. Where AI-generated advice is presented to a client under the professional's name, the professional remains liable for it. The policy must cover AI-assisted output errors. Professionals and their insurers should verify that policy exclusions do not create a gap where the professional argues the error originated in the AI system and the insurer argues the error was not a professional act.
Workplace AI liability
If a worker challenges an employment decision taken with the assistance of an AI system and succeeds, the employer may face reinstatement orders, back pay and damages. The legal grounds are the ordinary ones, discrimination, unfair dismissal, and the information duty under Article 1-bis of Legislative Decree 152/1997, rather than a new cause of action created by the AI law. Whether employer liability insurance responds to employment-law claims arising from AI-assisted management decisions depends on policy language written before any of this was contemplated. Employment practices liability coverage should be reviewed.
Criminal exposure under Article 612-quater
Criminal liability under Article 26 is personal. It attaches to the person who distributes the falsified content, and the statute creates no offence of hosting for the platform itself. Where directors and officers of a company are exposed at all, it is under the ordinary rules on individual criminal responsibility. Directors and officers cover and criminal defence cover should be reviewed on that basis, and not on the assumption that the company as such has acquired a new criminal exposure.
Product liability from December 2026
Italy must transpose Directive (EU) 2024/2853 by 9 December 2026, and the transposing measure will set the terms on which defective-product claims involving AI software are brought in Italy. Operators who develop AI software for the market, or who import and distribute non-EU AI software in Italy, should treat that date as the point by which their product liability coverage needs to have been re-examined against the Italian implementing text.
Market instruments for AI-specific coverage
The specialist market is developing products aimed at these gaps. Munich Re aiSure has been written with Mosaic Insurance since 26 February 2026, with an initial capacity of EUR, USD or CAD 15 million. Armilla, a Lloyd's of London coverholder, provides affirmative AI liability insurance with a limit of up to USD 25 million per organisation. Armilla states that coverage may not be available in all jurisdictions and is offered only through properly licensed surplus lines brokers, so Italian availability has to be confirmed directly with the underwriter. The ElevenLabs AI agent policy announced on 12 February 2026 was written on the strength of AIUC-1 certification from the Artificial Intelligence Underwriting Company; no carrier is named in the announcement. Each of these is a young product line, and none of them was designed around Italian policy wordings.
Italian operators should discuss with their broker which of these instruments are available in the Italian market and what the interaction is with their existing CGL, professional indemnity, and cyber policies.
Practical compliance priorities for Italian operators in 2026
The following priorities reflect the current regulatory state. They are ordered by the urgency of the applicable deadline, not by estimated effort.
Immediate (obligations already in force). Complete an Article 5 prohibited-practices audit. Confirm that no deployed system falls into a prohibited category under the EU AI Act. Review AI literacy documentation and confirm that affected staff have received proportionate training consistent with Article 4. If you develop or distribute a GPAI model, confirm that GPAI model obligations under Chapter V have been met or that your provider has confirmed compliance.
Article 50 has applied since 2 August 2026, so it belongs in this immediate group rather than in a future one. Confirm that user-facing disclosure is live for chatbots and conversational AI, that persons subject to emotion recognition or biometric categorisation are notified, and that AI-generated or AI-manipulated content is marked.
If you employ workers in Italy and use AI in the organisation of work, confirm the worker information duty under Article 1-bis of Legislative Decree 152/1997 is met, including communication to the union representatives where that article requires it, and that Article 4 of Law 300/1970 is respected for any monitoring function.
To 2 December 2027 and 2 August 2028. If a system falls in Annex III, work to 2 December 2027; for Annex I, to 2 August 2028. Regulation (EU) 2026/1744 moved the compliance dates, not the substance, so the risk management system, technical documentation, logging and human oversight work is unchanged and the extra time is best spent on it. If the system will be used in the ordinary courts, note the separate Ministry of Justice authorisation required by Article 15, comma 3 of Law 132/2025.
Before 9 December 2026. Track the Italian transposition of Directive (EU) 2024/2853 and audit product liability coverage for AI software exposure against it. Review existing commercial general liability and professional indemnity policies for AI output error gaps. Discuss AI-specific endorsements with your broker.
Frequently asked questions
What is Law No. 132/2025 and when did it come into force?
Legge 23 settembre 2025, n. 132, Disposizioni e deleghe al Governo in materia di intelligenza artificiale, was published in the Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 and entered into force on 10 October 2025. It runs to 28 articles in six Capi: general principles, sector provisions, national strategy and national authorities, user protection and copyright, criminal provisions, and financial and final provisions. Article 3, comma 5 states that the law produces no new obligations beyond those set by Regulation (EU) 2024/1689.
Who are the designated AI authorities in Italy?
Article 20, comma 1 designates AgID (Agenzia per l'Italia digitale) and ACN (Agenzia per la cybersicurezza nazionale) as the national authorities for artificial intelligence. Comma 2 designates AgID as the notifying authority under Article 70 of the EU AI Act, and ACN as the market surveillance authority and single point of contact with the EU institutions. Comma 1 preserves Banca d'Italia, CONSOB and IVASS as market surveillance authorities under Article 74, paragraph 6. Comma 4 preserves the powers of the Garante per la protezione dei dati personali and of AGCOM as Digital Services Coordinator.
Does the EU AI Act apply to operators in Italy alongside Law 132/2025?
Yes, and the EU AI Act is where the obligations are. It applies directly in all EU Member States, including Italy, without national transposition. Law 132/2025 is not a second layer of duties: Article 3, comma 5 states that it produces no new obligations beyond Regulation (EU) 2024/1689. The national statute allocates authority, states principles, and legislates national matters the Regulation does not reach, among them health data for research, AI in public administration and in judicial activity, copyright, and criminal law.
What are the workplace provisions of Law 132/2025?
Article 11 has three commas: AI is to improve working conditions and protect the psychophysical integrity of workers; its use must be safe, reliable and transparent, with workers informed in accordance with Article 1-bis of Legislative Decree 152/1997; and its use in the organisation of work must not discriminate. The union communication runs through that decree, not through a procedure created by the AI law. Article 11 contains no rule that AI output cannot be the sole basis for dismissal and no freestanding right to human re-examination. Article 4 of Law 300/1970 continues to apply on its own terms. Article 12 establishes an Osservatorio at the Ministry of Labour, a policy body that issues no obligations to operators.
What criminal liability does Law 132/2025 create?
Article 26 inserts a new Article 612-quater into the codice penale, Illecita diffusione di contenuti generati o alterati con sistemi di intelligenza artificiale, punishing distribution without consent of AI-falsified images, video or voice capable of misleading as to their genuineness, with reclusione from one to five years. It also adds an aggravating circumstance to Article 61 of the codice penale, raises Article 294 of the codice penale to two to six years where the deception uses AI, amends Article 2637 of the codice civile with two to seven years, and amends Article 185 of Legislative Decree 58/1998. It creates no offence of hosting for platforms or intermediaries.
How does the revised Product Liability Directive affect AI operators in Italy?
Directive (EU) 2024/2853 must be transposed into national law by 9 December 2026. The Italian transposing measure will determine how defective-product claims involving AI software are brought and defended in Italy. Operators should track the transposition and review product liability coverage against it rather than assume existing wordings carry over.
What does the EIOPA AI governance opinion mean for Italian insurers?
EIOPA published its Opinion on Artificial Intelligence Governance and Risk Management on 6 August 2025, stating that it is addressed to national supervisors and follows a risk-based and proportionate approach. In Italy the relevant supervisor for insurance is IVASS, which Article 20, comma 1 of Law 132/2025 also preserves as a market surveillance authority for AI under Article 74, paragraph 6 of the EU AI Act. An opinion is supervisory guidance rather than binding regulation, but it shapes what supervisors expect.
What insurance gaps should Italian AI operators prioritise?
The principal gaps are professional indemnity policies that do not clearly cover AI-assisted professional service errors, commercial general liability policies drafted before AI-generated content harm was contemplated, and product liability coverage that has not been re-examined against the Italian transposition of Directive (EU) 2024/2853. Specialist products exist: Munich Re aiSure, written with Mosaic Insurance since 26 February 2026 at an initial capacity of EUR, USD or CAD 15 million, and Armilla, a Lloyd's of London coverholder offering affirmative AI liability insurance with a limit of up to USD 25 million per organisation. Availability for an Italian risk has to be confirmed with the underwriter.
What are the penalty levels under the EU AI Act for Italian operators?
Article 99 of the EU AI Act sets ceilings of EUR 35 million or 7 per cent of worldwide annual turnover for the Article 5 prohibited practices, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for incorrect, incomplete or misleading information, whichever is higher, with the lower figure for SMEs and start-ups. They are enforced by the national market surveillance authorities, which in Italy means ACN, and Banca d'Italia, CONSOB and IVASS in their sectors. The AI Office holds the separate general purpose AI regime under Article 101, with a ceiling of EUR 15 million or 3 per cent.
What should an Italian business do in the next 90 days?
First, complete an Article 5 prohibited-practices audit. Second, confirm AI literacy documentation under Article 4. Third, confirm Article 50 transparency is already implemented, since it has applied since 2 August 2026. Fourth, if employing workers in Italy using AI in the organisation of work, verify the information duty under Article 1-bis of Legislative Decree 152/1997 and compliance with Article 4 of Law 300/1970. Fifth, plan Annex III work to 2 December 2027 and Annex I to 2 August 2028 under Regulation (EU) 2026/1744, in force since 27 July 2026. Sixth, request an AI-specific coverage review from your broker ahead of the 9 December 2026 transposition deadline for Directive (EU) 2024/2853.
References
- Legge 23 settembre 2025, n. 132, Disposizioni e deleghe al Governo in materia di intelligenza artificiale, Gazzetta Ufficiale Serie Generale n. 223 del 25-09-2025, in force 10 October 2025. Consolidated text consulted at normattiva.it, urn:nir:stato:legge:2025-09-23;132 (Articles 3, 7, 8, 9, 10, 11, 12, 13, 14, 15, 19, 20, 24, 25 and 26 read in full on 17 August 2026).
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (EU AI Act), in particular Articles 4, 5, 26, 50, 70, 74, 99 and 101.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026, deferring Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028.
- Directive (EU) 2024/2853 on liability for defective products (revised Product Liability Directive), transposition deadline 9 December 2026.
- EIOPA, Opinion on Artificial Intelligence Governance and Risk Management, 6 August 2025, eiopa.europa.eu.
- Legge 20 maggio 1970, n. 300 (Statuto dei Lavoratori), Article 4.
- Decreto Legislativo 26 maggio 1997, n. 152, Article 1-bis, worker information duty on automated decision-making and monitoring systems.
- ElevenLabs AI agent insurance policy backed by AIUC-1 certification, announced 12 February 2026. aiuc.com/research/elevenlabs-secures-first-of-its-kind-ai-agent-insurance