Italian AI Act decrees: final approval, tighter biometrics and automated dismissals void

The Italian Council of Ministers has given final approval to the two legislative decrees aligning national law with Regulation (EU) 2024/1689. Real-time biometric identification only with judicial authorisation, a ban on databases built by scraping the web, dismissal by an automated system declared void, a new article 437-bis of the criminal code and penalties aligned with the digital omnibus postponement.

AIPAAI ActLaw 132/2025ComplianceBiometricsEmployment LawAgIDACNData Protection AuthorityPublic Sector
Contents
  1. The two decrees
  2. What changed after the opinions
  3. Police and biometrics
  4. Dismissal by an automated system is void
  5. Article 437-bis of the criminal code
  6. Who supervises what
  7. When they actually apply
  8. What we think
  9. Sources
Four figures on the final approval of the Italian decrees aligning national law with the AI Act: the Council of Ministers gave final approval in session no. 185 of 4 August 2026, exercising the delegation in article 24 of law 132 of 2025, after the preliminary examination of 10 June and the opinions of the parliamentary committees, the Unified Conference and the data protection authority; real-time biometric identification allowed only in exceptional cases, for limited periods and with prior authorisation from the judicial authority, with a ban on databases built by collecting images from the web; decisions on the constitution, modification and termination of an employment relationship cannot be solely automated, so a dismissal decided by an automated system is void, while preliminary candidate selection stays outside; the new article 437-bis of the criminal code punishes the failure to adopt security measures on high-risk systems and their unlawful alteration. A note at the bottom says that as of 5 August the two texts are not yet in the Official Gazette, so the exact wording cannot be verified
The state of the decrees as of 5 August. Sources at the end.

The Italian Council of Ministers has given final approval to the two legislative decrees aligning national law with Regulation (EU) 2024/1689. The official press release dates the meeting to Tuesday 4 August 2026, session no. 185, while several outlets report the 5th.

The decrees exercise the delegation in article 24 of law no. 132 of 23 September 2025, closing a path that began with the preliminary examination on 10 June. In between came the opinions of the parliamentary committees, the Unified Conference and the data protection authority, and the texts came out of it changed.

The two decrees

The first covers the use of artificial intelligence systems in police activities and civil and criminal liability. The second the powers of the national authorities and the use of artificial intelligence in training and education.

As of 5 August neither is in the Official Gazette, so the full text is not yet readable. What is known comes from the Council of Ministers press release and from the reporting of those who followed the opinions.

What changed after the opinions

On post-hoc facial recognition video surveillance the press release states that minimum requirements for the reference database have been defined, with explicit deletion obligations and non-expansion guarantees for the data used in biometric comparison. Non-expansion means an already constituted archive cannot grow by adding material collected later.

Behind this change is opinion no. 531 of 14 July from the data protection authority, which had found that the automatic and indiscriminate biometric processing of everyone present in a venue did not appear coherent with article 26(10) of the regulation, which legitimises targeted searches for suspected or convicted persons. In the final text, according to the reporting, video surveillance collects images with no preventive biometric processing, recognition is triggered only after a confirmed offence and images are deleted after seven days, with longer retention where an investigation is open.

The position of the professional user of a high-risk system who intentionally fails to adopt human oversight measures becomes a standalone provision.

Local authorities are guaranteed participation, under their own agreed arrangements, in installing and maintaining the components, and a new article provides for the involvement of the Regions and the autonomous Provinces in the activities the decree governs. The powers granted to the data protection authority within its assigned roles are made explicit.

On employment, it has been specified that candidate search and selection do not fall among the final decisions on the constitution of the employment relationship.

The changes therefore concentrate on the processing of biometric data, on the participation of local authorities and on the powers of those who supervise. The architecture of the national authorities was left untouched.

Police and biometrics

The principle holding up the first decree is human oversight: a decision capable of producing adverse legal effects cannot be taken solely on the basis of automated processing, and final responsibility stays with the operator.

On real-time biometric identification the press release speaks of exceptional cases, limited periods and prior authorisation from the judicial authority. Those who have read the text specify which authority, and it is the most debated point: for prevention purposes authorisation comes from the public prosecutor, on a reasoned request, with a delimited territorial area and a duration of no more than fifteen days, renewable. The investigative channel is separate and goes through the judge for preliminary investigations, under the new article 359-ter of the code of criminal procedure.

Article 5 of the AI Act requires prior authorisation from a judicial authority or an independent administrative authority. The decree assigns it to the public prosecutor, who in Italy is part of the judiciary, rather than to a judge, as some in the majority had asked.

Constituting biometric databases through the massive and indiscriminate collection of photographs or images available online is prohibited, which is the practice several commercial facial recognition products were built on.

Post-hoc recognition, which works on already acquired material, follows a distinct set of rules, with minimum requirements on the reference database.

Dismissal by an automated system is void

Decisions on the constitution, modification or termination of an employment relationship, disciplinary ones included, cannot be taken exclusively on the basis of automated processing. A dismissal decided only by an automated system is void.

The ban does not cover preliminary candidate search and selection, which the opinions had explicitly placed outside the perimeter. The distinction matters in practice: automated CV screening does not fall under this rule, the decision on the relationship does.

Article 437-bis of the criminal code

The new article punishes the failure to adopt the security measures required for high-risk artificial intelligence systems and their unlawful alteration, with penalties graduated according to the legal interest put at risk.

On the June draft the ranges read by Sistema Penale were these: failure to adopt technical or human oversight measures, one to five years where it creates a concrete danger to the life or safety of a person, two to eight where the danger concerns public safety or state security; unlawful alteration, two to six years and three to ten in the same two cases, with the penalty cut by between a third and a sixth where the act is committed through gross negligence. It is a delitto, not a contravvenzione. On the final text the ranges may have changed.

This is the part that moves the centre of gravity: on the failure to adopt measures for a high-risk system the decree adds a dedicated criminal offence alongside the administrative penalties, operative once the text enters into force.

Who supervises what

The architecture is the one designed by law 132/2025 and confirmed in June:

AuthorityRole
AgIDnotifying authority, accredits and supervises conformity assessment bodies
ACNmarket surveillance authority and single point of contact with the EU institutions
Banca d’Italia, Consob, IVASSsectoral supervision over banking, financial markets and insurance
Data protection authorityhigh-risk systems in law enforcement, borders, justice and democratic processes

On training, the second decree brings artificial intelligence into school and university curricula, makes it a compulsory subject in continuing medical education and allocates 100 million euros for teacher training and for countering the risks tied to the abuse of digital platforms.

When they actually apply

The penalty regime is coordinated with Regulation (EU) 2026/1744 of 8 July 2026, the digital omnibus on AI, published in the EU Official Journal on 24 July and in force since the 27th. That is the measure that moved the main obligations on high-risk systems to 2 December 2027 for standalone systems and 2 August 2028 for those embedded in products.

The coordination is there so that Italy does not penalise conduct that is not yet required at European level. The obligations already applicable are the ones in force since 2 August 2026, namely the article 50 transparency duties and the rules on GPAI models.

What we think

Anyone using automated systems in HR processes has a deadline that does not depend on the European postponement: the nullity of an automated dismissal is Italian employment law, and it operates regardless of whether the system is classified as high risk. What needs checking is where, along the decision chain, a model output becomes a decision on the employment relationship without anyone taking it as their own.

The deletion obligations and the non-expansion guarantees apply to the reference database of post-hoc facial recognition video surveillance systems, so to police forces and to the local authorities taking part in installing them. A lawfully constituted archive will not be allowed to grow by accumulation, and that is a requirement you verify by looking at logs, not at policies.

Anyone running high-risk systems has one more criminal offence to put into the risk assessment, alongside the administrative penalties of the AI Act. It is the same shift that runs through AI governance in organisations: compliance stops being a documentary exercise and becomes an individual responsibility.

The text is still missing. Until publication in the Official Gazette the exact wording, which in criminal law and on nullity counts word by word, cannot be verified.

Sources

Need support?Under attack?Service Status
Need support?Under attack?Service Status