Contents

Artificial Intelligence
EU AI Act consulting: system classification, policies, AI governance, training.
Discover →DataGovern
Governance of compliance documentation: policies, evidence and registers kept together and up to date.
Discover DataGovern →
Admina Enterprise
AI governance: audit trail, PII redaction and bidirectional policies on any model, open-weight or proprietary, local or remote.
Explore Admina →Where it stands
Draft legislative decree AG 421 is the instrument by which Italy aligns national law with Regulation (EU) 2024/1689, the AI Act, for the part covering the powers of national authorities and the use of artificial intelligence in training. The Council of Ministers approved it in preliminary reading on 10 June 2026, and it is the direct sequel to the implementing decrees of Law 132/2025 we wrote about at the time.
Since then it has entered the parliamentary stage, which is where it sits now. It was assigned to the Chamber’s joint Committees IX (Transport) and X (Productive Activities) on 7 July, with an opinion due by 16 August 2026, and to Committee XIV (EU Policies) on 8 July, with a deadline of 17 August. Hearings ran through the second half of July: on 22 July those heard included ACN deputy director general Nunzia Ciardi, the builders’ association ANCE and the Fiat Research Centre, with sessions devoted to police use of AI systems and to civil and criminal liability.
The committees’ opinion is not binding, but it is the moment when the text can still change before final approval.
What it contains
The decree runs to more than thirty articles and works on two levels.
Governance. Articles 4 to 12 distribute competences across six bodies: AgID as notifying authority and for the national sandbox, ACN for supervision and cybersecurity, then the Bank of Italy, CONSOB and IVASS for their respective sectors, with the data protection authority on data and fundamental rights. Article 7 provides for cooperation agreements on data sharing and rapid response mechanisms; Article 12 sets up a coordination committee with a strategic steering role. Articles 13 to 18 define the administrative powers: supervision, inspection, monitoring, experimentation. Articles 26 to 29 govern the regulatory sandbox, Italy’s testing space for AI.
Sectoral areas. The text intervenes on five fronts: training and professions, employment relationships and worker health and safety, healthcare, and public administration.
For anyone trying to get their bearings, the practical point of the first part is that the counterpart changes. Until now the question “who do I answer to if I run a high-risk AI system” had no Italian answer; with this decree it has one, and it depends on the sector you operate in.
The timing problem
There is a fact here worth lining up with the dates, because neither piece of news makes it obvious on its own.
The decree aligns Italian law with Regulation (EU) 2024/1689. On 24 July 2026, while the committees were in the middle of hearings, that regulation was amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal and in force since 27 July. The Omnibus moves the high-risk deadlines to 2 December 2027 (standalone, Annex III) and 2 August 2028 (embedded in products, Annex I), sets 2 August 2027 for establishing national sandboxes, lightens the AI literacy obligations and adds two new prohibited practices from 2 December 2026.
The Italian decree devotes four articles to the sandbox, which the Omnibus now places in mid-2027. The committees’ opinion is due on 16 August, three weeks after the European amendment entered into force. That is exactly the window in which to check that the two texts speak the same language, and this is the kind of alignment that is expensive to get wrong.
The four knots raised in hearings
The hearings surfaced four questions the text, as it stands, does not close.
1. Human oversight has no defined skills. The AI Act and the decree require human supervision of high-risk systems, but no provision identifies the professional competences of whoever has to actually check the inputs and validate the outputs. There is no recognition of roles such as the AI auditor or algorithm auditor. In plain terms: the obligation exists, the profile of the person discharging it does not, and under inspection that difference shows.
2. “Steering” AI is left unclassified. There is a category of systems that fits none of the existing boxes: those able to shape preferences, beliefs and behaviour, including political behaviour, through personalisation and behavioural profiling. They are neither banned nor high-risk, so they are nothing. The point weighs most exactly where the decree intervenes, in training and the public sector.
3. Regulatory obsolescence is structural. AI’s development cycle is now faster than the pace of lawmaking. The decree governs today’s systems, and the freshly amended AI Act is the practical proof: the European framework changed while the Italian one was still being drafted.
4. There is no adaptive regulation mechanism. No permanent updating device exists. The available instruments (guidelines, sandbox) are useful but not enough to keep pace. Among the additions proposed in the hearings: professional auditing standards in Article 7, guidelines on steering AI systems in Article 11, an annual report to Parliament on emerging risks in Article 12, and turning the sandbox into an instrument of continuous regulatory learning.
What a company can do now
The decree is not in force and the text may change, so there is nothing to implement today. There are three things worth doing while the process closes.
Work out which authority covers you. If you operate in finance, insurance, healthcare or the public sector, your counterpart will not be the same as a manufacturer’s. Knowing it in advance changes who you write to when you need a clarification.
Reread the deadlines with the Omnibus dates. Anyone who planned around the 2 August 2026 threshold now has until 2 December 2027 for standalone systems. That is time gained, not time off: the nearest deadline is still transparency on artificially generated content, on 2 December 2026.
Build the traceability now. Whatever the final text says, human oversight and risk assessment will require showing who saw what and when. That is a logging requirement, and it is built beforehand, not afterwards.
What we think
The first of the four points is the one that strikes us as most concrete, and it is also the one we work on. An obligation of human oversight without a definition of who exercises it produces, in practice, a signature on a form. The difference between real and formal oversight lies in whether someone can reconstruct what the system proposed, what the person changed and on what basis: without an audit trail there is no demonstrable oversight, only a declaration. That is the plane we built Admina on, and the same logic as the OISG paradigm.
The second point, steering AI, is the hardest and the most interesting. A system that personalises training content or institutional communication is not high-risk under Annex III, yet it shapes what people end up thinking. The decree touches training and the public sector, precisely the contexts where that effect carries most weight. We have no solution to offer and will not pretend otherwise: we record that the gap was flagged to the people who can still close it.
On the third and fourth we are more cautious than those raising them. That technology outruns the law is true and hardly new, and every proposal for “adaptive regulation” carries a question of democratic legitimacy that an article cannot settle: who updates the rule between one parliamentary passage and the next, and with what mandate. The annual report to Parliament on emerging risks strikes us as the soundest of the proposed additions, precisely because it keeps the decision where it belongs.
For anyone who has to comply, the underlying reading is the usual one. Dates move, obligations stay, and the part that takes longest, namely knowing which AI systems run in your organisation, on what data and under whose responsibility, does not depend on which version of the decree is approved. That is the work DataGovern makes repeatable and that AI Act consulting exists to set up properly the first time.
Sources
- Agenda Digitale: Decree AG 421 on AI in Italy, governance, controls and open risks
- Chamber of Deputies: government acts submitted for opinion
- Law 132 of 23 September 2025 on Normattiva
- Regulation (EU) 2024/1689 (AI Act) on EUR-Lex
- Diritto Bancario: the Digital Omnibus on AI in the EU Official Journal
