Italy’s AI Act implementing decree needs redrafting: what the Garante asked for
7 min read
On 29 July 2026, in newsletter no. 550, the Italian data protection authority (the Garante) made public two opinions adopted at the same sitting on 14 July: no. 531 and no. 532. They concern the two draft legislative decrees through which Italy aligns its law with Regulation (EU) 2024/1689. Both are favourable. Both are favourable subject to conditions — that is, each comes with a list of the points the authority says must be worded differently.
Two decrees, not one
Almost every account mentions only one. The delegated powers in article 24 of Law no. 132 of 23 September 2025 were split across two texts, both sent over by the Presidency of the Council of Ministers – Department for Legal and Legislative Affairs.
Government Act no. 421 is the governance decree: fifty-one articles in five Chapters, covering the powers of the national authorities and the use of AI in education, the professions, employment, healthcare and public administration. It is the subject of opinion no. 532 and of the Garante President’s hearing on 21 July before the Chamber’s joint IX and X Committees. Government Act no. 418 instead governs the use of AI systems for policing: opinion no. 531 examines its Titles I and III.
Who supervises what
The governance decree answers the question that turns up in every tender document and has so far been answered by guesswork. Article 4 designates AgID as the national notifying authority, responsible for assessing, designating and notifying conformity assessment bodies. Article 5 identifies the market surveillance authorities: the National Cybersecurity Agency (ACN) as the general one; the Bank of Italy, CONSOB and IVASS for high-risk systems used in the provision of lending and of banking and credit services; and the Garante, confined to the areas in article 74(8) of the Regulation — justice, law enforcement, migration, border management and democratic processes.
The rest is machinery: national registration of high-risk systems sits with ACN (article 14), articles 19 to 25 build the penalty regime, and article 26 establishes the Italian AI regulatory sandbox, run jointly by AgID and ACN.
The practical consequence: “who supervises us” has more than one answer, and the answer depends on the use of the system, not on who supplies it. The same model inside two different processes leads to two different authorities.
The four conditions on the governance decree
Opinion no. 532 makes clearance conditional on four changes: amending article 11 “by extending to the Garante the powers set out there” — guidelines, recommendations and good practice, today reserved to the AI authorities and the financial ones; cross-referring to article 166 of the Privacy Code for the authority’s own penalty procedure; stating which of the two options in article 31(9) of the Regulation is being taken on responsibility for conformity assessment; and amending article 26 to provide for the Garante’s participation in sandbox projects involving the processing of personal data, as article 57(10) requires.
The third is the least eye-catching and the most consequential for buyers: whether the State answers directly for conformity assessment, or an insured notified body does, decides who you turn to when a certificate turns out to be wrong.
The part that reaches the most companies: decisions about staff
Article 40 requires an employer using AI systems to ensure that decisions — including those on the formation, variation or termination of the employment relationship — are not taken solely on the basis of automated processing: the final decision must be taken by “a natural person with effective and autonomous authority”, and the worker is entitled to “an intelligible statement of reasons for the decision, indicating the weight of the AI and the parameters taken into account”. It follows directly from the disclosure duty already in force.
Here the Garante does not set a condition but makes an observation: extend the prohibition to “decisions of an evaluative nature, liable to have significant implications for the employment relationship”. At the hearing the scope was spelled out — performance, bonuses, career progression. If the observation is taken up, the model-assisted annual appraisal falls under the same regime as dismissal.
The second opinion: biometrics, reference databases and private installers
Opinion no. 531 is the more technical of the two and matters well beyond police forces, because its seven conditions read as seven drafting rules for contracts.
In article 3(4), “qualified human review” should be replaced by “human oversight”, which is broader than review alone and matches article 14 of the Regulation. In article 4, on research projects with outside parties, the ban on sharing sensitive operational data should extend “to the mere use of such data”, allowing instead “synthetic data, subject to an assessment of how representative they are or, with appropriate safeguards, real data subject to masking or other forms of pseudonymisation”. Anyone who has signed a development contract recognises the problem: training on production data is the shortcut nobody later knows how to close.
In article 8 — real-time biometric identification, subject to authorisation by the public prosecutor — the “reference database” must be defined in its nature, whether created ad hoc for each authorisation or standing, with data quality requirements, deletion periods and “guarantees of non-incrementality”, so that each new authorisation does not widen the comparison set.
In article 10, on retrospective facial recognition, processing must take place “exclusively ex post on recorded footage”, not at the moment of capture: the phrase “places or events in respect of which public order and security requirements arise” could cover “stadiums, concerts, demonstrations, stations, major events, urban areas”, with the risk of mass, pre-emptive collection. And here the private party appears: subsection 12 allows venue operators, event organisers and promoters to carry out installation and maintenance, while the police headquarters retains “full and exclusive availability of the systems provided on loan”. The authority asks that their “role, from a data protection standpoint” be clarified: the draft regulates ownership of the results, not who is controller and who is processor.
What to do now
One. In your inventory of systems, record next to each one the competent authority given its use: ACN, a financial authority or the Garante. It is the line missing from almost every internal register.
Two. Replace “human review” with “human oversight” in your documents, and describe the techniques rather than the intention. For staff decisions, check that a person with effective and autonomous authority over the final call exists — and knows they have it.
Three. In development and acceptance testing contracts, prohibit real production data and require synthetic or masked data; for every comparison set, put in writing its nature, its deletion periods and the ban on incremental growth.
Four. Do not conflate the fundamental rights impact assessment under article 27 with the data protection impact assessment. The Garante says so for Legislative Decree 51/2018; outside that perimeter the same logic applies to article 35 GDPR.
What is not written yet
The text of the two drafts is not published by the Garante: you read it through the opinions, which describe the articles one by one. It is not known whether or how far the conditions will be accepted, nor when the decrees will be finally adopted. The only deadline already written down, in the policing draft, is transitional: systems already under contract or in development when it enters into force must be brought into line “within one year”. A year that runs from a date that does not yet exist.
How we handle it
All of this is decided on confidential documents: tender specifications, development contracts, impact assessments, records of processing. That is why we run the analysis with dedicated, closed AI, detached from the open web, in two modes: on-premise in the client’s own environment, or on a dedicated cloud — an environment reserved for the single client, with a dedicated VPN, the data centre in Italy and premises we staff ourselves. Which of the two suits you also depends on models and infrastructure, and we have written a separate page on that. In both cases the document never leaves the perimeter: that is the principle behind our platform.
Do you know which authority supervises the AI systems you already run? Half an hour with one of our experts is enough for a first map.
Sources
- Garante, opinion no. 531 of 14 July 2026 on Titles I and III of the draft decree aligning Italian law with Reg. (EU) 2024/1689 — doc. web 10275606
- Garante, opinion no. 532 of 14 July 2026 on the powers of the national authorities and AI in education — doc. web 10275626
- Garante newsletter no. 550 of 29 July 2026 — doc. web 10275843
- Hearing of the Garante President on Government Act no. 421, Chamber of Deputies, 21 July 2026 — doc. web 10273842