Contents

Artificial Intelligence
EU AI Act consulting: system classification, policies, AI governance, training.
Discover →
Cybersecurity
CISO-as-a-service consulting: posture, remediation roadmap, ongoing support.
Discover →The Italian Council of Ministers has given final approval to the two legislative decrees aligning national law with Regulation (EU) 2024/1689. The official press release dates the meeting to Tuesday 4 August 2026, session no. 185, while several outlets report the 5th.
The decrees exercise the delegation in article 24 of law no. 132 of 23 September 2025, closing a path that began with the preliminary examination on 10 June. In between came the opinions of the parliamentary committees, the Unified Conference and the data protection authority, and the texts came out of it changed.
The two decrees
The first covers the use of artificial intelligence systems in police activities and civil and criminal liability. The second the powers of the national authorities and the use of artificial intelligence in training and education.
As of 5 August neither is in the Official Gazette, so the full text is not yet readable. What is known comes from the Council of Ministers press release and from the reporting of those who followed the opinions.
What changed after the opinions
On post-hoc facial recognition video surveillance the press release states that minimum requirements for the reference database have been defined, with explicit deletion obligations and non-expansion guarantees for the data used in biometric comparison. Non-expansion means an already constituted archive cannot grow by adding material collected later.
Behind this change is opinion no. 531 of 14 July from the data protection authority, which had found that the automatic and indiscriminate biometric processing of everyone present in a venue did not appear coherent with article 26(10) of the regulation, which legitimises targeted searches for suspected or convicted persons. In the final text, according to the reporting, video surveillance collects images with no preventive biometric processing, recognition is triggered only after a confirmed offence and images are deleted after seven days, with longer retention where an investigation is open.
The position of the professional user of a high-risk system who intentionally fails to adopt human oversight measures becomes a standalone provision.
Local authorities are guaranteed participation, under their own agreed arrangements, in installing and maintaining the components, and a new article provides for the involvement of the Regions and the autonomous Provinces in the activities the decree governs. The powers granted to the data protection authority within its assigned roles are made explicit.
On employment, it has been specified that candidate search and selection do not fall among the final decisions on the constitution of the employment relationship.
The changes therefore concentrate on the processing of biometric data, on the participation of local authorities and on the powers of those who supervise. The architecture of the national authorities was left untouched.
Police and biometrics
The principle holding up the first decree is human oversight: a decision capable of producing adverse legal effects cannot be taken solely on the basis of automated processing, and final responsibility stays with the operator.
On real-time biometric identification the press release speaks of exceptional cases, limited periods and prior authorisation from the judicial authority. Those who have read the text specify which authority, and it is the most debated point: for prevention purposes authorisation comes from the public prosecutor, on a reasoned request, with a delimited territorial area and a duration of no more than fifteen days, renewable. The investigative channel is separate and goes through the judge for preliminary investigations, under the new article 359-ter of the code of criminal procedure.
Article 5 of the AI Act requires prior authorisation from a judicial authority or an independent administrative authority. The decree assigns it to the public prosecutor, who in Italy is part of the judiciary, rather than to a judge, as some in the majority had asked.
Constituting biometric databases through the massive and indiscriminate collection of photographs or images available online is prohibited, which is the practice several commercial facial recognition products were built on.
Post-hoc recognition, which works on already acquired material, follows a distinct set of rules, with minimum requirements on the reference database.
Dismissal by an automated system is void
Decisions on the constitution, modification or termination of an employment relationship, disciplinary ones included, cannot be taken exclusively on the basis of automated processing. A dismissal decided only by an automated system is void.
The ban does not cover preliminary candidate search and selection, which the opinions had explicitly placed outside the perimeter. The distinction matters in practice: automated CV screening does not fall under this rule, the decision on the relationship does.
Article 437-bis of the criminal code
The new article punishes the failure to adopt the security measures required for high-risk artificial intelligence systems and their unlawful alteration, with penalties graduated according to the legal interest put at risk.
On the June draft the ranges read by Sistema Penale were these: failure to adopt technical or human oversight measures, one to five years where it creates a concrete danger to the life or safety of a person, two to eight where the danger concerns public safety or state security; unlawful alteration, two to six years and three to ten in the same two cases, with the penalty cut by between a third and a sixth where the act is committed through gross negligence. It is a delitto, not a contravvenzione. On the final text the ranges may have changed.
This is the part that moves the centre of gravity: on the failure to adopt measures for a high-risk system the decree adds a dedicated criminal offence alongside the administrative penalties, operative once the text enters into force.
Who supervises what
The architecture is the one designed by law 132/2025 and confirmed in June:
| Authority | Role |
|---|---|
| AgID | notifying authority, accredits and supervises conformity assessment bodies |
| ACN | market surveillance authority and single point of contact with the EU institutions |
| Banca d’Italia, Consob, IVASS | sectoral supervision over banking, financial markets and insurance |
| Data protection authority | high-risk systems in law enforcement, borders, justice and democratic processes |
On training, the second decree brings artificial intelligence into school and university curricula, makes it a compulsory subject in continuing medical education and allocates 100 million euros for teacher training and for countering the risks tied to the abuse of digital platforms.
When they actually apply
The penalty regime is coordinated with Regulation (EU) 2026/1744 of 8 July 2026, the digital omnibus on AI, published in the EU Official Journal on 24 July and in force since the 27th. That is the measure that moved the main obligations on high-risk systems to 2 December 2027 for standalone systems and 2 August 2028 for those embedded in products.
The coordination is there so that Italy does not penalise conduct that is not yet required at European level. The obligations already applicable are the ones in force since 2 August 2026, namely the article 50 transparency duties and the rules on GPAI models.
What we think
Anyone using automated systems in HR processes has a deadline that does not depend on the European postponement: the nullity of an automated dismissal is Italian employment law, and it operates regardless of whether the system is classified as high risk. What needs checking is where, along the decision chain, a model output becomes a decision on the employment relationship without anyone taking it as their own.
The deletion obligations and the non-expansion guarantees apply to the reference database of post-hoc facial recognition video surveillance systems, so to police forces and to the local authorities taking part in installing them. A lawfully constituted archive will not be allowed to grow by accumulation, and that is a requirement you verify by looking at logs, not at policies.
Anyone running high-risk systems has one more criminal offence to put into the risk assessment, alongside the administrative penalties of the AI Act. It is the same shift that runs through AI governance in organisations: compliance stops being a documentary exercise and becomes an individual responsibility.
The text is still missing. Until publication in the Official Gazette the exact wording, which in criminal law and on nullity counts word by word, cannot be verified.
Sources
- Council of Ministers press release no. 185, 4 August 2026
- Law no. 132 of 23 September 2025
- Regulation (EU) 2024/1689, the AI Act
- Regulation (EU) 2026/1744, the digital omnibus on AI
- AI4Business: the Council of Ministers gives final approval to the Italian AI Act decrees
- Servicematica: Italy completes its AI Act implementation
- Agenda Digitale: how facial recognition changes with the Italian decree
- Sistema Penale: the offence of failing to adopt security measures
- Byte.it: the Italian decree and the differences with the AI Act
