Alessandro Del Ninno
News
Artificial Intelligence and Liability: Legislative Decree No. 160/2026 Introduces New Obligations and Risks for Businesses.
ARTIFICIAL INTELLIGENCE
15/09/2026

On 15 September 2026, Legislative Decree No. 160 of 9 September 2026 was published in the Italian Official Gazette, General Series No. 214. The Decree is entitled “Adaptation of national legislation to the provisions of Regulation (EU) 2024/1689 […] concerning the use of artificial intelligence systems for law-enforcement activities and civil and criminal liability”. The Decree will enter into force on 30 September 2026.

The measure represents one of the main domestic legislative steps taken to implement and complement the European regulatory framework on artificial intelligence and gives effect to the delegation of legislative powers contained in Law No. 132 of 23 September 2025. Its significance, however, is not confined to public security authorities: alongside rules governing the use of AI by law-enforcement authorities, the Decree introduces provisions of general application concerning criminal liability, the administrative liability of legal entities under Legislative Decree No. 231/2001, and compensation for damage caused through the use of artificial intelligence systems.

For businesses, therefore, the publication of Legislative Decree No. 160/2026 marks a particularly significant step in the evolution of the AI Act from a framework primarily focused on regulatory compliance into a body of rules capable of producing consequences also in the fields of civil and criminal liability.

AI in law-enforcement activities: human oversight, biometrics and facial recognition

Title I of the Decree regulates the research, development, testing and use of AI systems and models in law-enforcement activities, expressly providing that such systems must perform an instrumental and supporting role in relation to human decision-making.

Where the results of automated processing are intended to be used in acts or measures capable of affecting individuals’ legal rights or interests, the Decree requires qualified human review. High-risk systems must also be subject to effective human oversight, entrusted to appropriately skilled and adequately trained personnel.

Particular attention is paid to the use of biometric data. The Decree regulates both real-time remote biometric identification, which is permitted only for specified purposes and subject to a detailed authorisation regime, and post-remote facial recognition using video-surveillance systems incorporating AI components. Among other things, the Decree expressly prohibits biometric databases created through untargeted scraping and generalised or indiscriminate forms of facial recognition.

The use of real-time biometric identification systems also requires a prior fundamental rights impact assessment under Article 27 of the AI Act, together with the data protection impact assessment required under Legislative Decree No. 51/2018. Such uses must be recorded through tamper-proof logs retained for five years and must be specifically notified to the Italian Data Protection Authority.

Of interest also to technology companies is the possibility for law-enforcement authorities, within the framework of specific research and testing projects, to cooperate with universities, research bodies and public and private entities. The relevant agreements must expressly regulate intellectual property rights in research outputs, derived models, training data and software, as well as the respective data-protection roles of the parties involved and their respective liabilities.

A new criminal offence relating to the security of high-risk AI systems

Title II is of particular relevance to the private sector. Article 12 of the Decree introduces into the Italian Criminal Code a new Article 437-bis, entitled “Failure to adopt security measures in artificial intelligence systems and unlawful alteration of systems”.

The new provision criminalises the failure to adopt the technical security measures required in the design, training, production or placing on the market of high-risk AI systems, where such measures are intended to prevent malfunctions or alterations, as well as the failure to implement the necessary human-oversight measures, where such omissions give rise to a danger to life or to public or individual safety. The offence is punishable by one to five years’ imprisonment, increased to two to eight years where it gives rise to a threat to national security.

The provision also criminalises the alteration of high-risk AI systems where this gives rise to a danger to life or to public or individual safety, with further aggravated penalties where national security is endangered. A separate offence also applies to a professional user of a high-risk AI system who intentionally fails to implement human-oversight measures where that omission gives rise to the dangers specified in the provision.

The provision is particularly significant because it does not attach criminal liability to a merely formal breach of the AI Act. Rather, criminal relevance arises in respect of specified omissions or conduct relating to system security and human oversight where the concrete danger required by the statutory offence is present.

Artificial intelligence expressly enters the Legislative Decree 231/2001 corporate liability framework

One of the developments of most immediate relevance to businesses is contained in Article 15, which introduces into Legislative Decree No. 231/2001 a new Article 25-vicies, entitled “Offences committed through the use of artificial intelligence systems”.

The catalogue of predicate offences capable of triggering the administrative liability of legal entities is therefore extended to include:

  • the new offence under Article 437-bis of the Criminal Code, concerning failure to adopt security measures in high-risk AI systems and unlawful alteration of such systems, for which the entity may be subject to a financial penalty ranging from 600 to 1,000 units;
  • the offence under Article 612-quater of the Criminal Code, concerning the unlawful dissemination of images, videos or voices falsified or altered through AI systems, for which the applicable financial penalty ranges from 200 to 700 units;
  • in respect of both offences, the disqualification measures referred to in Article 9(2)(b), (c), (d) and (e) of Legislative Decree No. 231/2001 are also applicable.

Naturally, the inclusion of an offence in the Legislative Decree No. 231/2001 catalogue does not automatically result in corporate liability. The general statutory requirements must still be met, including the commission of the offence in the interest or for the benefit of the entity by one of the persons identified by the legislation.

For companies that develop, market or use AI systems, however, the amendment requires a concrete reassessment of their Legislative Decree No. 231/2001 risk mapping. In particular, organisational and management models should be reviewed to determine whether processes relating to the design, development, validation, security, human oversight and use of AI systems give rise to risk areas relevant to the new predicate offences.

Damage caused by AI: changes also to civil proceedings

Articles 16 to 20 are equally significant, introducing specific procedural mechanisms for contractual and non-contractual claims for damages caused in connection with the use of AI systems.

The first major development concerns access to evidence. At the request of a person claiming to have suffered damage, the court may order the opposing party or a third party to disclose specifically relevant evidence concerning the operation of the AI system, provided that sufficient elements are produced to make the claim prima facie plausible and to establish a connection between the system’s output and the alleged damage.

The documents that may be subject to a disclosure order expressly include system logs, risk-management documentation, technical documentation and information concerning the arrangements for human oversight. The legislation provides safeguards for trade secrets and confidential information, while attaching significant procedural consequences to a failure to comply with an order for disclosure: where the failure concerns such documentation, the court may, having regard to the other evidence available, deem the facts alleged by the injured party to have been established. A third party that fails to comply without justified grounds may also be subject to a financial penalty ranging from EUR 1,500 to EUR 10,000.

The practical consequence is clear: documentation required under the AI Act also acquires an evidentiary function. Logs, risk-management records, technical documentation and records of human oversight are no longer merely compliance evidence to be produced to supervisory authorities, but may become central elements in the company’s defence in damages litigation.

Even more significant is the provision establishing a presumption of causation. Where damage results from the breach of one or more obligations laid down by the AI Act, the Decree provides that the causal link between the breach and the damage is presumed, subject to proof to the contrary.

The legislature further specifies that compliance of the system with the requirements of the AI Act, even where certified through the mechanisms provided for by the Regulation, does not in itself exclude the defendant’s liability. Regulatory compliance therefore does not constitute a “safe harbour” against claims for damages.

For natural persons bringing proceedings outside the course of their business or professional activities, jurisdiction is also conferred on the court of the place where the injured person resides or is domiciled.

Direct action against the insurer: a new element in AI risk management

The Decree also introduces a provision of particular importance from an insurance perspective.

Before bringing a claim for damages, the injured party may ask the person considered liable whether that person has civil-liability insurance covering the relevant damage. The recipient of the request must disclose, within thirty days, whether such insurance exists, together with the policy details and the name of the insurer.

The injured party is also granted a genuine direct right of action against the insurance undertaking, within the limits of the policy coverage. An insurer that has paid compensation retains, subject to the conditions laid down by the provision, a right of recourse against the insured.

For businesses developing or using AI systems, the provision makes it advisable to verify not merely the formal existence of insurance coverage, but also whether liability policies effectively cover risks arising from the use of artificial intelligence, including any exclusions, limits of indemnity, disclosure obligations and recourse clauses.

Fact sheet – Legislative Decree No. 160/2026 at a glance

The Decree consists of 22 Articles divided into three Titles. Title I (Articles 1-10) governs the use of AI systems in law-enforcement activities, including research and testing, training, human oversight, biometric-data processing, real-time remote biometric identification and post-remote facial recognition. Title II (Articles 11-20) addresses criminal and civil liability: it introduces Article 437-bis of the Criminal Code, regulates the procedural use of biometric identification, amends the rules governing seizure of online content generated also through AI, introduces the new Article 25-vicies into Legislative Decree No. 231/2001 and establishes specific rules governing claims for damages relating to AI systems. Title III (Articles 21-22) contains transitional and financial provisions; AI systems already covered by contracts or already being developed, tested or used in law-enforcement activities are granted a one-year period to comply with the provisions of Chapter II of Title I.

What businesses should assess now

Legislative Decree No. 160/2026 makes clear that compliance with the AI Act should be integrated into a broader enterprise risk-management framework. Businesses concerned should assess, in particular, the classification of the AI systems they use and whether any qualify as high-risk systems; the adequacy of security measures and human-oversight arrangements; the retention of logs and technical documentation capable of serving an evidentiary function; the updating of risk mapping and organisational models under Legislative Decree No. 231/2001; internal procedures governing the creation and dissemination of synthetic content; liability and indemnity provisions in contracts with providers and suppliers; and the adequacy of insurance coverage in light of the new liability scenarios.

The most significant systemic development is that compliance and liability are becoming increasingly interconnected. Compliance with the AI Act remains essential, but is not, in itself, sufficient to exclude civil liability; conversely, breaches of the obligations imposed by the EU Regulation may directly affect the evidentiary framework, while certain conduct relating to the security of high-risk systems may give rise to criminal liability and, where the statutory conditions are met, to the liability of the entity under Legislative Decree No. 231/2001.

For businesses, AI governance must therefore increasingly be integrated with Legislative Decree No. 231/2001 compliance, cybersecurity, product safety, litigation management and insurance coverage, moving beyond an approach confined to formal compliance with the AI Act.