Operational notes Regulation

Italy's AI law (132/2025): what it actually adds to the EU AI Act

4 min read

Period engraving of Palazzo Montecitorio in an antique volume
The AI Act sets the European framework; Law 132/2025 decides how it applies in Italy.

While everyone was watching Brussels — the postponement of the AI Act’s high-risk obligations dominated the headlines for months — Italy did something no other Member State had yet done: it gave itself a comprehensive national law on artificial intelligence. This is Italian Law 132/2025 (Law No. 132 of 23 September 2025), in force since 10 October 2025. And in June 2026 the Council of Ministers approved the first package of implementing decrees. For anyone working with public administration, healthcare or regulated sectors, this law matters as much as the European regulation — and on some points, more.

What it does (and does not do)

Law 132/2025 does not duplicate the AI Act: it is a framework law that hooks onto it. It introduces no general obligations beyond those already in the European regulation, but it does three concrete things: it sets out the principles (transparency, proportionality, human accountability, data protection), it designs the national governance — with AgID (the Agency for Digital Italy) and ACN (the National Cybersecurity Agency) named as the reference authorities for AI — and it lays down sector-specific rules for the areas that matter most in Rome: healthcare, public administration, employment and justice.

The rest arrives by delegation: the Government has a mandate to complete the framework through implementing decrees, and the first package was approved by the Council of Ministers on 10 June 2026 — it includes the draft legislative decree that brings Italian law into line with the AI Act, governs the powers of the national authorities, and regulates the use of AI in education, the professions, employment, healthcare and public administration. In other words: Italy’s detailed rules are arriving now, and anyone waiting for Europe’s 2027 deadline before moving will find that the Italian calendar is shorter.

The points that affect operators

  • Healthcare: AI can support prevention, diagnosis and treatment choices, but the final decision remains with the doctor. Patients must be informed when AI is used; the systems — and the data that feed them — must be checked and updated periodically. It is the same rule we build in by design: control stays with whoever holds clinical responsibility.
  • Public administration: AI serves efficiency, but responsibility remains with the human official; transparency of the algorithms and staff training are mandatory. Anyone selling systems to public administration — or buying them — must be able to demonstrate this: it is exactly the kind of requirement that will end up in tender specifications.
  • Employment: the use of AI must be communicated to workers, and a national observatory monitors its impact. Choices that affect people require human oversight.
  • Criminal law: the law introduces the offence of unlawful distribution of AI-generated or AI-manipulated content (harmful deepfakes) and aggravating circumstances for offences committed with the assistance of AI. For businesses this means one precise thing: synthetic content must be labelled and governed, not only because of the AI Act.

Why it matters even if you “don’t do AI”

The wrong reading is “it concerns those who develop models”. The right one: it concerns anyone who uses AI systems in contexts that touch people — and with AI now built into management software, HR platforms and clinical systems, almost every organisation is a user. Italian law makes explicit what the AI Act calls human oversight: it takes a trained person, with real authority, and the ability to demonstrate how the system decides. A system built with human control embedded from the outset is compliant by design; one that bolts it on afterwards is a permanent building site.

What to do now

  1. Map where AI touches people: patients, citizens, employees, candidates. This is the perimeter of Law 132/2025, even before the European high-risk threshold.
  2. Formalise human accountability: who decides, with what information, with what ability to override the machine. Names, not job titles.
  3. Prepare the transparency notices: information for patients, citizens and workers wherever AI is in use — this is already required, not from 2027.
  4. Follow the implementing decrees: the June 2026 package is the first; penalties and operational detail arrive there. Anyone working with public administration would do well to read them before their own clients do.

Want to understand where Law 132/2025 touches your systems — or the ones you are about to buy? Half an hour with one of our experts for the map.

Sources