YOUR
Search

    17.06.2026

    AI: Council of Ministers gives preliminary approval to two draft legislative decrees implementing law no. 132/2025


    Overview

    On 10 June 2026, exercising the powers delegated under Law No. 132/2025 (the Italian Law on Artificial Intelligence), the Council of Ministers granted preliminary approval to two draft legislative decrees concerning artificial intelligence, which are still subject to amendment. The first decree addresses the powers of national authorities, market surveillance, sanctions, regulatory sandboxes, training and employment-related provisions (the “Decree”). The second decree regulates the use of AI systems in policing activities and introduces provisions on civil and criminal liability. This briefing focuses on the first draft decree.

     

    Governance takes shape: authorities, coordination and regulatory sandbox

    The Agency for Digital Italy (AgID) is the national notifying authority, with responsibility for notification procedures and conformity assessment bodies. The National Cybersecurity Agency (ACN) is responsible for market surveillance and acts as the single point of contact. ACN is also responsible for the national registration of high-risk AI systems listed in Annex III, point 2, of the AI Act.

    The role of sectoral authorities remains unchanged: the Decree identifies the Bank of Italy, CONSOB and IVASS as the competent authorities within their respective fields, in addition to the Italian Data Protection Authority insofar as matters fall within its remit.

    The Decree also establishes a Coordination Committee within the Presidency of the Council of Ministers, to ensure coordination and cooperation among national authorities, other public administrations and independent authorities. The Committee may issue common guidelines for the conclusion of agreements and memoranda of understanding, as well as for the adoption of policy documents.

    The Decree also establishes the Italian AI Regulatory Sandbox — the regulatory sandbox provided for in Article 57 of the AI Act — which will be jointly managed by AgID and ACN.

     

    Sanctions: a graduated enforcement framework

    In accordance with the AI Act, the most serious infringements, relating to the prohibited practices set out in Article 5 of the AI Act, may result in fines of up to 35 million euros or, if higher, up to 7% of the undertaking’s total annual global turnover for the previous financial year. Lower maximum fines apply for other categories of infringements, including those imposed on providers and deployers in relation to high-risk AI systems, those applicable to notified bodies, and those concerning transparency and reporting to the authorities.

    The Decree also provides for non-monetary penalties for less serious infringements. As an alternative to financial penalties, the authorities may order that the infringement be remedied or require the publication of a statement setting out the infringement and identifying the responsible party. Sanctioning proceedings in the financial sector remain subject to the sector-specific procedures applied by the Bank of Italy, CONSOB and IVASS under the Italian Banking Act (TUB), the Consolidated Financial Act (TUF) and the Insurance Code, in accordance with the special regime applicable to financial institutions. 

     

    Employment: the final decision must remain human

    The Decree stipulates that, in employment-related decision-making processes, employers using AI systems must ensure that decisions concerning the establishment, modification or termination of the employment relationship, including disciplinary measures, are not taken solely on the basis of automated processing. The final decision must remain with a natural person exercising genuine and independent judgment.

    Upon request, the worker is entitled to receive, through human intervention, a clear and understandable explanation of the decision, including how the AI system influenced the decision-making process and the main parameters taken into account. Any dismissal carried out in breach of these provisions is null and void. This provides stronger protection than that currently available under Italian employment law: it will not be sufficient to state that “the final decision is made by a human” if, in practice, the AI system’s output substantially determines it.

    The Decree also establishes an explicit link between AI and occupational health and safety: the use of AI systems affecting work organisation, production rates, the way in which work is carried out, or safety-related decision-making processes must be taken into account in the workplace risk assessment (Documento di Valutazione dei Rischi – DVR) pursuant to Legislative Decree No. 81/2008.

     

    Training: a cross-cutting obligation

    The Decree devotes a substantial section to training, introducing measures for schools, teachers, adults, the public administration, universities, research institutions, regulated professions, the judiciary and the health sector. A total of €100 million has been allocated for teacher training under the national programme “PN Scuola e Competenze 2021–202”.

    For regulated professions, the Decree introduces obligations to ensure technical, legal and ethical competence in AI: professional bodies will have six months to update their regulations and twelve months to revise their fair remuneration criteria to reflect the risk classification of the AI system used. In the healthcare sector, AI will become part of the Continuing Medical Education (Educazione Continua in Medicina - ECM) programme, with the involvement of healthcare managers and the national “MIA” platform.

     

    What to do now

    The texts are not yet final, but there are two operational priorities.

    First, an initial review of the AI systems currently in use — distinguishing between prohibited practices, high-risk systems, systems subject to transparency obligations and low-risk systems — to prioritise compliance activities and to prepare of the required technical documentation: logs, risk assessments, human supervision, change logs and governance decisions.

    The second priority concerns HR processes that make use of AI systems. The Decree prohibits decisions relating to the establishment, modification or termination of an employment relationship (including disciplinary measures) from being taken solely on the basis of automated processing, and provides that any dismissal carried out in breach of these requirements is null and void. In practice, this requires a review of decision-making processes relating to staff selection, performance management, job assignments and disciplinary measures, ensuring that meaningful human oversight is in place and properly documented, rather than merely formal. Particular attention should be paid to candidate ranking and scoring systems, productivity monitoring tools, and software used for automated shift scheduling or workload allocation, where their outputs have a decisive influence on management decisions. From a contractual perspective, it will also be advisable to review the clauses in contracts with the AI system providers, in terms of algorithm transparency, access to logs and the allocation of liability in the event of a dispute.

    Raffaele Giarda joins ADVANT Nctm as new Partner
    ADVANT Nctm announces that Raffaele Giarda has joined the Firm as…
    Read more
    2025 annual report of the Italian Data Protection Authority: AI is accelerating, digital compliance must keep pace
    On 2 July 2026, at the Sala della Regina of Palazzo Montecitorio, the Italian…
    Read more
    AI Enters Trade Secret Protection
    On 10 June 2026, the Italian Council of Ministers approved two draft legislative…
    Read more
    Space Economy and Data Economy: the National Space Policy Strategic Document (DSPSN)
    The context and purpose of the National Space Policy Strategic Document…
    Read more
    Personal data governance in football clubs: data use as a strategic lever at the intersection of GDPR, security and value creation
    The football club as a data ecosystem (and as a media company) From a personal…
    Read more
    Tracking pixels in e-mails: the Data Protection Authority's new rules
    1. Introduction By Order No. 284 of 17 April 2026, published in the Official…
    Read more
    THE COMMISSION’S NEW GUIDELINES ON THE CLASSIFICATION OF HIGH-RISK AI SYSTEMS
    The context and structure of the Guidelines Regulation (EU) 2024/1689 (“AI…
    Read more
    WHY DID THE COURT OF ROME ANNUL THE DATA PROTECTION AUTHORITY’S ORDER ON OPENAI?
    Summary of the judgement On 18 March 2026, the Court of Rome annulled in its…
    Read more
    Cyber Resilience Act: the countdown has started
    With Regulation (EU) 2024/2847 (“Cyber Resilience Act” or “CRA”), the European…
    Read more