# AI criminal liability in Italy: what article 437-bis requires

**AI criminal liability in Italy** becomes concrete on 30 September 2026. Italian legislative decree 160 of 2026 introduces article 437-bis of the criminal code and updates legislative decree 231 of 2001: companies must adopt technical safety measures and human oversight for high-risk artificial intelligence systems, and be able to prove it. The challenge is organisational before it is technological.

## On 30 September 2026, legislative decree 160/2026 enters into force

Legislative decree 9 September 2026, no. 160 was published in the Official Gazette on 15 September 2026 and enters into force on 30 September. It implements the enabling law of 23 September 2025, no. 132 and aligns Italian law with the European artificial intelligence regulation. The Council of Ministers had approved the final draft on 4 August 2026.

The measure acts on several fronts: the use of artificial intelligence systems in police work, the rules for high-risk systems, civil and criminal liability, and the adjustment of the sanctions system for legal entities. Two changes concern companies directly: article 437-bis of the criminal code and article 25-vicies of legislative decree 231 of 2001.

## The conduct punished by article 437-bis

The provision punishes anyone who fails to adopt the **technical safety measures** required for the design, training, production or placing on the market of high-risk artificial intelligence systems, and anyone who fails to put the necessary **human oversight** in place. It also covers unlawful alteration of the system.

The threshold is high. The offence is triggered when the omission creates a **concrete danger** to life or to public or individual safety. Negligent liability is limited to cases of **gross negligence**. The penalty ranges from one to five years of imprisonment and rises to two to eight years when the danger concerns State security. It is a general offence: anyone who failed to act can be held liable, not only the legal representative.

The structure mirrors omission offences in workplace criminal law, where the punished conduct is the failure to adopt the required precautions. Here the same logic moves to artificial intelligence systems.

## Corporate liability and the 231 model

Article 25-vicies of legislative decree 231 of 2001 adds article 437-bis to the list of predicate offences for the administrative liability of legal entities. A company can be held liable for an offence committed in its interest or to its advantage, with fines and disqualifying sanctions that can suspend its activity. The organisational model and the Supervisory Body take on an operational role: they become the instrument through which the entity shows it has controlled the risk.

The same article 25-vicies adds a second offence, already in force since 2025: article 612-quater of the criminal code, which punishes the **unlawful dissemination of content** generated or altered with artificial intelligence systems. It covers images, videos or voices falsified without consent and capable of misleading about their authenticity, with one to five years of imprisonment. The scope is broad: a single piece of generated and shared content can be enough, even outside high-risk systems.

## Risk follows the purpose of the system

The list of high-risk systems is in Annex III of the European regulation. The legislator describes concrete uses: the function of the system defines the perimeter. A system is high-risk when it is used to select or assess people, to decide on employment relationships, to assess creditworthiness, to set life and health insurance premiums, to assess access to essential services including healthcare, to manage education or to assist judicial activity.

The criterion is operational. A software house that integrates an artificial intelligence component into a security product falls within scope because of the purpose of that component. A small insurance agency that uses a life risk assessment tool falls within scope as a user. A manufacturing company that screens CVs with artificial intelligence falls within scope for that use.

## A construction company inside the perimeter

A structured construction company offers a useful case. It operates outside the sectors traditionally considered critical, and it manages frequent staff turnover, between labourers and administrative staff, with CV screening, candidate assessment, shift and site management, alongside payslips, sick leave and relations with cooperatives.

When CV screening runs through an artificial intelligence tool, that use falls under Annex III: the company becomes a user of a high-risk system and takes on the obligations set for those who deploy it. If artificial intelligence assesses performance or assigns tasks, high-risk status is joined by the question of remote monitoring of work, governed by article 4 of the Workers' Statute. Managing payslips and sick leave with traditional software stays outside the scope of the European regulation, while it still involves sensitive data and data protection obligations.

The perimeter is decided case by case, looking at the tool and the function. The company's sector matters little.

## The common logic across data and security rules

Article 437-bis belongs to a wider regulatory season. The European artificial intelligence regulation, the GDPR, the NIS2 directive, the Cyber Resilience Act and the digital operational resilience regulation for the financial sector converge on the same request: govern the systems, document the choices, be able to reconstruct what happened.

The rules differ in subject and in the authority that oversees them, while the underlying criterion remains risk governance. For a company this means one piece of mapping and control work can answer several obligations, provided it is done in advance.

## The proof of diligence

The new offence uses open concepts: concrete danger, gross negligence, suitable measures, human oversight. It does not list the necessary measures. The assessment will come later, before a judge, case by case. This is typical of organisational negligence, and it is worth stating plainly: the rule leaves it to the judge to decide what was adequate.

What changes is the weight of proof. What protects a company is the ability to show it did its duty in advance. The European regulation provides the technical benchmark for what is adequate for a high-risk system, and the required measures are verifiable:

- risk assessment and system documentation;
- quality control of the data used;
- activity logging for traceability of results;
- human oversight with defined responsibilities;
- clear information for the people who use the system;
- robustness, accuracy and cybersecurity.

Turning these measures into practice means mapping the systems in use, including those adopted by departments without a formal step, defining usage policies and permissions, keeping the logs, providing effective human review at critical points, training staff and tracking the checks. Organisational responsibility holds when it has a technological form: a register, a permission, an approved and dated check, documented training.

## The first step

The question to ask concerns the ability to reconstruct, tomorrow, how that system was used, by whom, with which controls and with what training. Companies that address the issue with serious mapping arrive prepared for 30 September; the others discover the perimeter on the day they have to prove it.

To set up the review and understand which business uses fall within the perimeter, EBM Solution supports companies with an initial analysis of the systems in use and the controls required.

---

Liability starts from where the data actually is, and [the perimeter that contracts cannot guarantee](/en/ecorner/2026/ai-data-security-local-inference.html) changes what a company can prove.

## Frequently asked questions

**What is the offence introduced by article 437-bis?**
Legislative decree 160 of 2026 punishes anyone who fails to adopt the technical safety measures or the human oversight required for high-risk artificial intelligence systems, when this creates a concrete danger to life or safety. The penalty ranges from one to five years of imprisonment and negligent liability is limited to gross negligence.

**Can a company outside the critical sectors be involved?**
Yes. The perimeter is defined by the use of the system; the company's sector is secondary. A manufacturing or construction company that uses artificial intelligence to screen staff or assess employees falls within the high-risk systems listed in Annex III of the European regulation.

**What does the company risk, beyond the individual person?**
Legislative decree 231 of 2001 provides for the administrative liability of the entity for offences committed in its interest, with fines and disqualifying sanctions that can suspend its activity. The organisational model and the Supervisory Body become the instruments through which the company shows it has controlled the risk.

**Which measures make diligence demonstrable?**
The European regulation indicates risk assessment, data quality, activity logging, human oversight, documentation and cybersecurity. In practice: mapping the systems, policies and permissions, logs, human review at critical points, documented training.

**Do deepfakes also fall under 231 liability?**
Yes. Article 25-vicies includes article 612-quater of the criminal code among the predicate offences. It punishes the dissemination, without consent, of images, videos or voices altered with artificial intelligence and capable of misleading. The provision also covers content generated outside high-risk systems.

## Sources

Legislative decree 9 September 2026, no. 160, provisions on artificial intelligence, civil and criminal liability and adjustment of the sanctions system — https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2026-09-09;160
Law 23 September 2025, no. 132, provisions and delegations to the Government on artificial intelligence, which introduces article 612-quater of the criminal code — https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:legge:2025-09-23;132
Legislative decree 8 June 2001, no. 231, rules on the administrative liability of legal persons, companies and associations — https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2001-06-08;231
Regulation (EU) 2024/1689, artificial intelligence regulation: Annex III on high-risk systems and user obligations — https://eur-lex.europa.eu/eli/reg/2024/1689/oj
European Commission, regulatory framework on artificial intelligence: high-risk systems and applicable obligations — https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
