Until recently, the AI Act could present itself as “the world’s first regulatory framework for artificial intelligence”. Today, mapping the rules governing AI – whether soft or hard law, and whether general or sector-specific – requires extensive comparative research and a thorough knowledge of each legal system. Indeed, numerous supranational and national rules now affect, to varying degrees, the uses of this technology and, indirectly, its development, by establishing principles and limitations. The question, in short, is no longer whether artificial intelligence should be regulated, but at what level and through which instruments.
One need only look at the United States. At the federal level, President Trump continues to sign executive orders aimed at freeing AI from regulatory constraints in order to promote global competition; at the opposite end, individual States, which retain residual powers in the absence of federal pre-emption, continue to introduce state-level regulations with a high degree of differentiation. These range from California – the jurisdiction that has undoubtedly developed the most layered regulatory framework – which has adopted the Artificial Intelligence Training Data Transparency Act and the Transparency in Frontier Artificial Intelligence Act, to Texas, with its Responsible Artificial Intelligence Governance Act. The list could go on for some time – Colorado, Illinois, New York, Tennessee, Utah – with a highly complex set of policy choices, in some cases divergent from one another.
That the alternative between regulating and not regulating AI has now been superseded is most recently confirmed by Dario Amodei’s appeal, We Must Pace the Frontier: a text which, it should be noted, places the responsibility for slowing the frontier primarily on voluntary coordination among laboratories and on independent evaluators integrated into the process, and which, precisely for this reason, has been criticized by those who believe that the speed limit should be set by the State, rather than by industry.
The US experience nevertheless clearly demonstrates what is best avoided: differentiated rules at state level, lacking a uniform framework, merely increase the costs of navigating the regulatory landscape for citizens and businesses alike.
Against this backdrop, the European Union, which through the AI Act has sought to establish common rules, must contend with its own institutional structure and, in particular, with the fact that it is not a federal state. The impact of artificial intelligence extends across many areas falling within national competence. For this reason too, Regulation (EU) 2024/1689 leaves the regulation of important legal institutions to the Member States. Law No. 132 of 2025 falls within the implementation of those provisions. Indeed, in implementing the AI Act, the national legislature has identified the governance authorities responsible for applying AI regulation within the national territory, including supervising compliance and sanctioning unlawful conduct. Article 20 accordingly identifies the “National Authorities for Artificial Intelligence”, entrusting the Agenzia per l’Italia Digitale (AgID) with promoting innovation and defining compliance and certification processes for high-risk systems; supervisory powers and, where appropriate, the power to impose sanctions are instead entrusted to the Agenzia per la Cybersicurezza Nazionale (ACN), in coordination with the powers of the Bank of Italy, Consob and IVASS within their respective sectors.
Even at this stage, one might criticize the excessive fragmentation resulting from the number of authorities called upon to apply the Regulation. On closer examination, however, that fragmentation is already inherent in the AI Act and could hardly have been overcome. Moreover, for those involved in digital regulation, the real problem is not so much the enforcement of the AI Act as the overlap among the many authorities responsible for enforcing the many sector-specific regulations: the DSA, entrusted to AGCOM; the DMA, to the Italian Competition Authority (AGCM); and the GDPR, to the Italian Data Protection Authority.
Apart from the provisions required by the references contained in the AI Act, Law No. 132 otherwise seeks to formulate policy responses to highly significant social demands, some of which are difficult for the law to resolve but which the law nevertheless seeks, at least, to steer. This is the case, for example, of the provisions requiring AI systems to “improve” the National Health Service (Article 7) or to “increase the efficiency” of public administrations (Article 14): objectives that are indisputable and cannot be postponed, but whose achievement does not depend on a legal provision.
Almost confirming the difficulty of regulating such a complex field, Law No. 132 establishes certain rules and principles while delegating the regulation of crucial aspects to the Government (Article 24). In implementation of that delegation, on 4 August 2026 the Council of Ministers definitively approved two legislative decrees: one, currently pending publication, “concerning the powers of national authorities and the use of artificial intelligence in education”; the other, already published – Legislative Decree No. 160 of 9 September 2026 – ”concerning the use of artificial intelligence systems for police activities and civil and criminal liability”.
Without going into detail, the point of particular interest within the multilevel regulatory framework is the need to govern this field through instruments capable of providing technical detail to the principles laid down in the enabling legislation and of adapting rapidly to technological developments. This is a task for legislative decrees, but even more so for secondary legislation and the soft law of the regulatory authorities.
Regardless of the opportunities and critical issues that national legislation may introduce, the conclusion is that, insofar as part of it was required, the Italian legislature could otherwise, in a context of over-regulation, have limited itself to implementing the AI Act, avoiding additional provisions. It should nevertheless be acknowledged that many of those provisions are principles, and it will be for the legal system to implement them appropriately, without adding obstacles and restrictions to innovation, which has by now become a decisive factor in the country’s competitiveness.
This is where the role of legal professionals – and, in particular, in-house counsel and private-practice lawyers – becomes crucial: to develop and support, both in courtrooms and through compliance, an interpretation capable of making the balance between innovation and the protection of rights a reality, so that the opportunities offered by these technologies are not held back by unreasonable and, in some cases, self-referential regulation. While awaiting the simplification that should come with the Digital Omnibus, which is still under discussion in Brussels, what is at stake is the competitiveness of both the country and the European Union.