AI Act: the police and biometrics decree is published

Legislative decree 160 of 9 September 2026 appeared in the Italian Official Gazette on 15 September and takes effect on the 30th. It adds the new Article 437-bis of the criminal code, which also reaches the professional deployer who omits human oversight, and a civil chapter that makes four AI Act artefacts disclosable in court while presuming the causal link. One of the two decrees approved in August is out; the other is not.

AIComplianceGovernanceAI ActComplianceGovernanceBiometricsCriminal lawCivil liabilityRegulation 2024/1689Human oversightSMEs
Contents
  1. The publication order says something
  2. Title I: policing, biometrics and training
  3. The new Article 437-bis, which is not only about makers
  4. The civil chapter touches far more companies
  5. What we think
  6. Sources
Four figures on Italian legislative decree 160 of 2026 as published in the Official Gazette
Figures from the text as published in the Official Gazette. Sources at the end.

On 5 August we wrote about the two AI Act adaptation decrees given final approval by the Italian Council of Ministers, and closed with a caveat: neither was in the Official Gazette, so the exact wording could not be checked. Half of that caveat falls away today.

Official Gazette, General Series no. 214 of 15 September 2026 carries legislative decree 160 of 9 September 2026, adapting national law to Regulation (EU) 2024/1689 “as regards the use of artificial intelligence systems for policing activities and civil and criminal liability”. It runs to 22 articles across three titles. It takes effect on 30 September 2026.

The other decree, the one on national authorities, coordination, the regulatory sandbox and the training of the judiciary, is not in the Gazette yet.

The publication order says something

Of the two texts approved together on 4 August, the one touching biometrics, facial recognition and the criminal code comes out first. The one that formally designates the authorities and coordinates their powers follows later.

That is not a procedural detail. In two weeks obligations and criminal offences take effect, while the supervisory architecture meant to accompany them is still working its way to publication. It is the same gap we found last week in the Cyber Resilience Act, where the delegation to the Government existed and the delegated decree did not.

Title I: policing, biometrics and training

The first title governs the use of AI systems by the bodies, offices and commands of the police forces. Article 1 sets a boundary worth reading, because it frames everything else: the title “does not create obligations beyond those laid down by Regulation (EU) 2024/1689” for systems used for policing purposes. The decree implements the regulation without adding obligations of its own.

The provisions apply in compliance with the principles “of proportionality, non-discrimination, human oversight and transparency” referred to in Article 3 of law 132/2025.

Chapter III is the one that gives the decree its name in press coverage, and it covers three distinct things worth keeping apart because their regimes differ: labelling, filtering and categorisation of biometric data (Article 7); real-time remote biometric identification for prevention or protection purposes; and post facto facial recognition for law enforcement. Chapter II deals with research, development, training, testing and use, and devotes an article to the training of police personnel (Article 6).

The new Article 437-bis, which is not only about makers

Article 12 inserts Article 437-bis into the criminal code, after Article 437, under the heading “Failure to adopt security measures in artificial intelligence systems and unlawful alteration of systems”. Now that the text is readable, its four paragraphs can be reported for what they say.

First paragraph. Anyone who fails to adopt the technical security measures required for the design, training, production and placing on the market of high-risk systems, suitable to prevent malfunctions or alterations, “or fails to adopt human oversight measures”, faces one to five years’ imprisonment where the omission gives rise to danger to life or to public or individual safety. Where the danger concerns State security, two to eight years.

Second paragraph. Anyone who alters high-risk systems outside the cases in the first paragraph faces two to six years where danger to life or safety follows, and three to ten where the danger concerns State security.

Third paragraph. Where the conduct in the first paragraph is committed through gross negligence, the penalty is reduced by between a third and a sixth.

Fourth paragraph. This is the passage that changes who is in scope. “A professional deployer of high-risk artificial intelligence systems who intentionally fails to adopt human oversight measures is punished with the penalties laid down in the first paragraph”, under the same conditions of danger.

So the provision extends beyond those who build systems and place them on the market: it reaches the company that operates one, if human oversight lapses by choice. For anyone weighing whether to put a high-risk system inside a business process, human oversight stops being a line in the technical documentation and becomes a condition for staying outside a criminal offence.

Articles 13 and 14 amend the code of criminal procedure and its implementing provisions.

The civil chapter touches far more companies

Articles 16 to 20 build the procedural tools for compensation of damage caused by the use of AI systems, and they are the part that gets less coverage while concerning many more organisations than police biometrics.

Article 17, access to evidence. On application by the party claiming damage, the court orders the other party or a third party to disclose evidence on how the system works, where the applicant presents facts “capable of making the claim plausible”. What is disclosable is listed, and it is four artefacts the AI Act already requires:

  • the logs under Article 12 of the regulation;
  • the documentation of the risk management system under Article 9;
  • the relevant information in the technical documentation under Article 11;
  • the information on parameters and arrangements for human oversight under Article 14.

The order is limited to what is necessary and proportionate, and the court protects trade secrets by applying Article 121-ter of the industrial property code. The sanction for non-compliance is severe: where a party fails to disclose without justification the court may draw evidential inferences, and where the failure concerns those four documents the court, “having weighed every other item of evidence, treats the facts alleged by the applicant as admitted”. A third party who fails to comply faces a fine of 1,500 to 10,000 euro.

Article 18, presumption of the causal link. It is one line long: “Where the damage results from the breach of one or more obligations laid down by Regulation (EU) 2024/1689, the causal link between the breach and the damage is presumed, unless proved otherwise”.

The chapter is completed by Article 20, which provides a direct action against the insurer, and Article 16, on scope and the consumer’s forum.

What we think

Taken together, Article 17 and Article 18 change the nature of AI Act documentation. Until now logs, risk management, technical documentation and the description of human oversight were filings to show an authority during an inspection. From the end of the month they are evidence in civil proceedings, with a presumption working against whoever breached the obligations and a precise procedural consequence for whoever cannot produce them.

For anyone arriving in court without those four artefacts the consequence is procedural before it is administrative: having weighed the other evidence, the court treats the facts alleged by the other side as admitted.

It is the same direction we saw in the Cyber Resilience Act a few days ago, where the obligation is triggered not by a score but by reliable evidence of exploitation. Two different rules, the same shift: what counts is the evidence you can produce when somebody asks for it.

The three things to do before 30 September are ordinary and do not require waiting for the second decree. Establish which systems in use are high-risk, because the whole decree hangs off that classification. Check that the four artefacts in Article 17 actually exist for each of them, are current, and can be retrieved on litigation timescales rather than archaeological ones. Write down who exercises human oversight, with what powers and what tracking, because the fourth paragraph of 437-bis looks precisely at the intentional omission of that measure.

This is the ground DataGovern works on: it holds documentary evidence with the source attached and keeps the audit trail of analyses and human approvals, which is exactly what Article 17 asks you to disclose and what Article 18 makes decisive. As always, it does not produce automatic compliance: it cuts manual work and makes the part you have to demonstrate retrievable, while responsibility stays with whoever puts the system into service.

On the missing decree we wait. Until it appears, the formal arrangement of the authorities and their coordination powers is what can be derived from law 132/2025, not from a readable implementing text.

Sources

Need support?Under attack?Service Status
Need support?Under attack?Service Status