Tuesday, 08 September 2026 PDT | 06:51 AM
The 1 News Alt Logo Text Smart News for Global Indians

Artificial Intelligence in Italy: Compliance Roadmap after the Digital Omnibus

AI News September 08, 2026 06:00 PM
Artificial Intelligence in Italy: Compliance Roadmap after the Digital Omnibus

Artificial intelligence: opportunity and regulatory challenge

Artificial intelligence (AI) is a rapidly evolving technology capable of processing inputs and generating outputs such as predictions, content, recommendations or decisions. In practical terms, AI enables systems to interpret data and their environment, identify patterns, solve problems and act towards defined objectives through computational models and algorithms.

Its economic potential is significant. AI can improve forecasting, optimise operations and resource allocation, personalise services and products, and create competitive advantages across sectors such as healthcare, manufacturing, agriculture, energy, transport and logistics, finance, education, media, infrastructure management, public services and environmental monitoring.

The same capabilities, however, can create material and non-material risks for individuals, organisations and society. Depending on the context, AI may affect health and safety, privacy and data protection, non-discrimination, employment, intellectual property, product safety, cybersecurity, democratic processes and access to essential services. The regulatory challenge is therefore not to prevent the use of AI, but to ensure that innovation is accompanied by proportionate governance, accountability and safeguards.

At European level, AI is primarily governed by Regulation (EU) 2024/1689 (the Artificial Intelligence Act or AI Act), which entered into force on 1 August 2024. The AI Act establishes a horizontal legal framework for the development, placing on the market, putting into service and use of AI systems and general-purpose AI models in the European Union. Its objectives include supporting innovation and the uptake of trustworthy, human-centric AI while ensuring a high level of protection of health, safety and fundamental rights.

The framework has already evolved. Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI), in force since 27 July 2026, amended the AI Act in order to simplify implementation, clarify certain obligations and adjust the timetable for high-risk AI systems. The result is not a reduction of the importance of AI governance, but a more differentiated compliance roadmap.

The Digital Omnibus also revised Article 4 on AI literacy. Providers and deployers must now take measures to support the development of AI literacy among staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context in which the systems are used and the persons or groups affected. This is a more proportionate formulation than the original obligation to ensure a sufficient level of AI literacy, but it still requires organisations to adopt demonstrable and context-specific measures.

The Omnibus further introduced new prohibited practices into Article 5 concerning, under the conditions laid down by the Regulation, AI systems that generate or manipulate non-consensual intimate or sexually explicit material relating to identifiable individuals and child sexual abuse material. These new prohibitions will apply from 2 December 2026. It also created a transitional period until 2 December 2026 for certain providers of systems already placed on the market before 2 August 2026 to comply with the machine-readable marking obligations for synthetic content under Article 50(2).

A risk-based architecture: not all AI is regulated in the same way

One of the central features of the AI Act is its risk-based architecture. It is important, however, not to treat this as a simple five-level scale. The Regulation distinguishes between prohibited AI practices, high-risk AI systems, systems subject to specific transparency obligations and other AI systems for which the regulatory burden is lighter. General-purpose AI models (GPAI models) are governed by a separate set of rules, and certain GPAI models may be classified as presenting systemic risk under Article 51.

For businesses, this distinction is essential. The first compliance question is not simply whether an organisation uses AI, but what role it performs under the AI Act and what type of system or model is involved. A company may act, depending on the use case, as provider, deployer, importer, distributor, product manufacturer or authorised representative, with materially different obligations.

High-risk classification also requires a careful legal analysis. Systems listed in Annex III may be high-risk because of the context in which they are used, for example in recruitment and worker management, access to certain essential services, biometrics or other specifically regulated areas. Other systems may qualify as high-risk under Article 6(1) because they are safety components of products, or products themselves, covered by the Union harmonisation legislation listed in Annex I and subject to third-party conformity assessment. The Digital Omnibus has clarified aspects of the concept of a safety component and postponed the application of the corresponding high-risk requirements.

The same precision is required for impact assessments. A Fundamental Rights Impact Assessment (FRIA) under Article 27 is not a general obligation applicable to every company or every AI system. It applies to the deployers and use cases identified by that provision. Following the Digital Omnibus, where relevant obligations are already addressed in a data protection impact assessment under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, the FRIA may cross-refer to or incorporate the relevant parts of that assessment. This facilitates integration between AI governance and existing privacy accountability processes without eliminating the need for a distinct legal analysis.

The AI Act follows a phased application timetable, which has now been materially amended by the Digital Omnibus. The main milestones are:

Enforcement: EU sanctions and a more differentiated national layer

Non-compliance can lead to significant sanctions. Under Article 99 AI Act, infringements of the prohibited practices in Article 5 may be subject to administrative fines of up to EUR 35 million or, for undertakings, up to 7% of total worldwide annual turnover for the preceding financial year, subject to the Regulation’s rules on proportionality and the specific treatment of smaller operators. Other infringements are subject to lower but still material tiers of fines. The Digital Omnibus has also broadened the range of enforcement measures available to Member States, expressly referring to warnings and non-monetary measures in addition to penalties and administrative fines.

This means that AI compliance should not be assessed only through the lens of the highest headline fine. The actual risk profile depends on the relevant obligation, the operator’s role, the size and economic viability of the organisation, the seriousness and duration of the infringement, the affected individuals and the effectiveness of the organisation’s governance and remediation measures.

The Italian framework: Law No. 132/2025 and the pending implementing decrees

Italy has added a national layer to the European framework through Law No. 132 of 23 September 2025, in force since 10 October 2025. The law establishes national principles for the development and use of AI and contains sector-specific provisions as well as delegations to the Government to align Italian law with the AI Act.

On 4 August 2026, the Italian Council of Ministers approved in final examination two legislative decrees implementing those delegations. At the time of writing, the decrees are still awaiting publication in the Italian Official Journal and should therefore not yet be treated as legislation in force. Their final legal wording must be checked upon publication.

According to the Government’s final communication, the first decree regulates the use of AI systems in police activities and introduces new rules on criminal and civil liability. In particular, it provides for a new Article 437-bis of the Italian Criminal Code concerning failures to adopt safety measures for high-risk AI systems and unlawful alterations of such systems, with penalties graduated according to the legal interest placed at risk. The same decree is also expected to strengthen civil redress mechanisms for persons harmed by AI systems.

The second decree further defines the Italian governance and enforcement architecture, centred on AgID as notifying authority and ACN as market surveillance authority, alongside sectoral supervisory competences. It also introduces a more granular and proportionate national sanctioning framework, with maximum levels below the EU ceilings and the possibility of non-pecuniary measures for less serious infringements. The Government has expressly indicated that the framework has been aligned with the Digital Omnibus so that national sanctions become applicable in line with the actual application of the corresponding AI Act obligations and prohibitions.

For companies operating in Italy, this creates an increasingly multi-layered risk environment. AI-related conduct may trigger not only the AI Act but, depending on the facts, also data protection, cybersecurity, consumer, product safety, employment, intellectual property, civil liability and criminal-law consequences. Once the implementing decrees are published, the interaction between EU administrative enforcement, national sanctions and potential corporate liability will need to be reassessed on the basis of the final text.

What should companies and organisations do now?

The postponement of certain high-risk obligations should not be interpreted as a reason to delay AI governance. On the contrary, organisations now have a clearer implementation window in which to build a structured and auditable compliance framework before the most demanding high-risk requirements become applicable.

The first step is an AI inventory and role-mapping exercise. Organisations should identify AI systems and GPAI models that are developed, purchased, embedded in products, integrated into business processes or used by employees, and determine the relevant operator role under the AI Act. Particular attention should be paid to embedded and decentralised uses of generative AI, which may not appear in traditional IT asset registers.

The second step is legal and risk classification. This should include screening for prohibited practices under Article 5, high-risk classification under Article 6 and Annex III, transparency obligations under Article 50, GPAI-related requirements, and any sector-specific rules. The analysis should be integrated with GDPR, cybersecurity, intellectual property, employment, product safety and other relevant legal frameworks.

The third step is impact assessment and remediation. Depending on the use case, this may involve a DPIA, a FRIA, security and robustness assessments, human oversight controls, data-governance measures, contractual protections, vendor due diligence, logging and documentation requirements, transparency notices, incident management and internal escalation mechanisms.

Finally, governance must be continuous. AI systems evolve through model updates, configuration changes, new datasets, additional integrations and new business uses. Compliance therefore requires periodic monitoring, clear ownership, escalation paths and evidence that risks and controls are reviewed over time. Some organisations may centralise these responsibilities in an AI governance committee or an AI Officer function; others may distribute them across Legal, Compliance, Privacy, Cybersecurity, Risk, HR, Procurement and IT. The appropriate model depends on the organisation, but accountability should be explicit and auditable.