Two implementing decrees under Law No. 132/2025 approved in final form
Artificial Intelligence
On 4 August 2026, the Council of Ministers approved in final form two legislative decrees implementing Regulation (EU) 2024/1689 (the “AI Act”), pursuant to the enabling delegation under Article 24 of Law No. 132 of 23 September 2025 (the “AI Law”).
The first decree governs the use of AI in policing activities. Real-time biometric identification is permitted only in exceptional cases, for limited periods and subject to prior authorisation by the judicial authority. The measure also introduces Article 437-bis of the Italian Criminal Code, which penalises the failure to adopt security measures for high-risk systems and the unlawful alteration of such systems, as a predicate offence under Legislative Decree No. 231/2001. In civil proceedings, injured parties are granted access to documentation, a rebuttable presumption of causation and a direct action against the insurer.
The second decree governs the powers of the authorities already designated under Article 20 of the AI Law (AgID for notifications, ACN for market surveillance, and the Bank of Italy, CONSOB and IVASS for financial services) and assigns supervisory powers to the Italian Data Protection Authority in the areas covered by Article 74(8) of the AI Act (law enforcement, border management, justice and democratic processes). A graduated sanctions framework is established, with maximum penalties lower than those set at EU level, and regulatory sandboxes are provided for, with particular attention to SMEs and start-ups. In employment, decisions on recruitment, management and termination of employment (including disciplinary measures and dismissals) may not be based exclusively on automated processing, failing which the dismissal shall be null and void.
At present, the texts have not yet been published in the Official Journal. The delegation under Article 24 of Law No. 132/2025 must be exercised within twelve months of its entry into force (10 October 2025), and therefore by 10 October 2026.
Digital operational resilience: Bank of Italy and IVASS guidance on advanced AI models
Cybersecurity | Artificial Intelligence
On 17 July 2026, the Bank of Italy and IVASS published two parallel communications on digital operational resilience and advanced artificial intelligence (AI) models, addressed respectively to supervised intermediaries and insurance and reinsurance undertakings. The Authorities note that latest-generation models may identify software vulnerabilities and rapidly generate ways of exploiting them, reducing the interval between discovery and attack.
In practice, referring to the Digital Operational Resilience Act (DORA), the Bank of Italy and IVASS call on operators to:
- review the Risk Appetite Framework (RAF), including the risks associated with frontier technologies, assign clear responsibilities, and ensure that management bodies have the necessary technological skills and receive continuous training;
- strengthen the management of ICT providers through ex ante selection criteria, contractual requirements, and controls over patch application and security monitoring;
- update the asset inventory, also classifying assets based on their exposure to the Internet and use of cloud services, and replace legacy systems that are no longer supported;
- accelerate vulnerability management, prioritising open-source software, externally exposed systems and zero-day vulnerabilities;
- strengthen authentication, authorisation, network segmentation and traffic monitoring;
- carry out periodic resilience, response and recovery testing, simulating realistic and progressively more complex scenarios.
Among the most immediate obligations, particular importance attaches to strengthening governance: the boards of directors, meeting jointly with the boards of statutory auditors, must prepare a report describing, for each area, the exposure, existing safeguards, deficiencies and priorities; the report must also include a work plan setting out the actions, timelines, investments and methods for verifying progress. It is also necessary to notify the competent supervisory authority of a designated corporate point of responsibility. The report and the plan must be submitted by 31 December 2026.
Data Act: from 12 September 2026, access by design becomes mandatory for new connected products
Data Governance
The Data Act has applied since 12 September 2025. However, from 12 September 2026, one of its most significant requirements for manufacturers and developers will take effect: the obligation laid down in Article 3(1) for connected products and related services placed on the market after that date.
Article 3(1) of the Data Act introduces a fundamental principle: smart devices, comprising hardware components, sensors and software—which may range from large industrial automation machinery to motor vehicles and everyday household appliances—placed on the market from 12 September 2026 must be designed, manufactured and developed in such a way that the data generated through their use, including the metadata necessary for their interpretation and use, are, by default (by design), easily and securely accessible to the user, free of charge, in a complete, structured, commonly used and machine-readable format. This is complemented by the obligation on the data holder to make the same information available to third parties where the user makes an explicit request, pursuant to Article 5 of the Data Act.
This requirement must be coordinated closely both with the obligations arising under the NIS2 Directive in the field of cybersecurity and its national implementing measures, and with the GDPR and national data protection legislation, whenever the information extracted from smart devices relates to natural persons.
In a context where data sharing, including non-personal data, becomes a regulatory obligation, rethinking data flows and the technical architecture of products becomes a key requirement for ensuring digital compliance, and 12 September will serve as a litmus test of the synergy between the legal and governance functions in managing this new requirement.
Compliance therefore requires the coordination of product design, data architecture, pre-contractual information, terms of use and agreements with third-party recipients of the data.
Green claims: new rules against greenwashing from 27 September
Consumer Protection | Sustainability
From 27 September 2026, Legislative Decree No. 30/2026, implementing Directive (EU) 2024/825, will strengthen the rules in the Italian Consumer Code on unfair commercial practices relating to environmental claims. In particular, the reform affects the use of generic environmental claims, permitting them only where adequately supported by recognised and demonstrable environmental performance.
Claims must be specific, accurate, verifiable and proportionate to the product characteristic to which they relate, avoiding the presentation of a limited benefit as relating to the product as a whole.
The use of environmental marks, labels and certification schemes is also restricted; these must be based on schemes that comply with regulatory requirements or have been established by public authorities.
Particular importance attaches to the prohibition on representing a product as climate-neutral, climate-impact-reduced or climate-positive where that result derives exclusively from offsetting emissions through carbon credits.
Future environmental performance claims are also covered; these must be based on clear, objective, publicly available and verifiable commitments and on a detailed implementation plan.
For businesses, this requires a dedicated governance framework for claims, with ex ante validation procedures and adequate traceability of the underlying evidence. In other words, each claim should be supported by an evidence dossier containing the data, calculation methodologies, tests, certifications and technical sources used. In anticipation of entry into force, it is therefore advisable to conduct an audit of packaging, advertising, websites and ESG communications.
Business incentives: new framework now in force; Nuova Sabatini confirmed
Corporate | Innovation & Incentives
On 3 August, Legislative Decree No. 138 of 26 June 2026, which reorganises the entire range of incentives administered by the Ministry of Enterprises and Made in Italy, was published in the Official Journal and entered into force on 18 August: of the 33 existing measures, 22 have been abolished, while public intervention is now focused on five remaining instruments, including, alongside the Sustainable Growth Fund and the SME Guarantee Fund, the Nuova Sabatini. For businesses with proceedings already commenced in relation to abolished incentives, the previous rules remain applicable by virtue of a specific safeguard clause.
From a financial perspective, the 2026 Budget Law (Law No. 199 of 30 December 2025) confirmed the measure’s refinancing in the amount of EUR 650 million for the 2026-2027 period (EUR 200 million for 2026 and EUR 450 million for 2027).
The reorganisation confirms the nature of Sabatini-ter as an automatic State aid scheme, but places it within a changing regulatory framework that warrants attention: the selection of only five incentive schemes signals a strategy of concentrating public resources, with potential future coordination measures among the remaining schemes. A further issue remains open: Ministerial Decree of 18 June 2025 extended to certain incentives the obligation to take out insurance cover against natural disasters and catastrophic events, and the corresponding adaptation of the Sabatini scheme has been entrusted to an interministerial decree that is still being finalised and could shortly become a new access requirement for beneficiary businesses.
Specifically, the Sabatini-ter scheme comprises four operational lines: the ordinary line, reserved for the purchase of capital goods and software (2.75% interest rate); the 4.0 line and the Green line, which provide for an increased interest rate of 3.575%, respectively, for technological investments falling within the Industry 4.0 Plan and for investments with reduced environmental impact, supported by the relevant certification; and, lastly, the Capitalisation line, intended for SMEs that approve an increase in share capital equal to at least 30% of the financing, with a contribution calculated at 5% for micro and small enterprises and at 3.575% for medium-sized enterprises.
Privacy and AI literacy training: operational obligations for businesses
Compliance
The GDPR and the AI Act place staff preparedness among the organisational safeguards that businesses and public bodies must adopt and be able to demonstrate: a recent enforcement action by the Italian Data Protection Authority and the commencement, in August 2026, of supervision of AI literacy make the issue directly verifiable by the authorities.
On the privacy side, the GDPR requires the controller and the processor to instruct persons acting under their authority and to adopt organisational measures appropriate to the risk, pursuant to Articles 29 and 32. In a decision of 11 June 2026, the Italian Data Protection Authority fined a local health authority (ASL), noting that none of the 44 employees in the relevant department had attended privacy training and that the instructions allegedly given orally had not been documented. The findings also included the failure to designate and document authorised persons and the controller’s inability to demonstrate adequate instructions and organisational measures.
Following the amendments introduced by the Digital Omnibus, Article 4 of the AI Act requires providers and deployers to take measures to support the development of AI literacy among staff and other persons using AI systems on their behalf, taking into account their technical knowledge, experience, education and training, and the context in which the systems are to be used. The Regulation nevertheless specifies that this obligation does not require a specific predetermined level of AI literacy to be ensured. Since 2 August 2026, responsibility for the application and supervision of this obligation has rested with the national market surveillance authorities. For high-risk systems, Article 26 adds a specific safeguard: the deployer must entrust human oversight to persons with the necessary competence, training and authority. A single undifferentiated course for the entire organisation is unlikely to be sufficient: content and depth must vary for users, supervisors, legal and compliance functions, technical teams and management, covering at least permitted uses, data that may be input, output limitations, oversight and incident escalation.
Training does not replace policies, technical controls and procedures, but enables people to apply them correctly and the organisation to demonstrate the measures adopted.
Focus
Transparency obligations for artificial intelligence: the European Commission’s guidelines
On 20 July 2026, the European Commission adopted the “Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (the ‘AI Act’)” (the “Guidelines”), which provide guidance on the transparency obligations applicable to providers (“provider”) and deployers (“deployer”) of artificial intelligence systems…
The United States accelerates its “Space Law Reform”
The United States aims to accelerate the development of commercial space transportation with an ambitious goal: achieving at least 1,000 launches and re-entries per year by 2030…