Skip to main content
v2026.11,858 entries · CC-BY 4.0

Italy’s D.Lgs. 160/2026: Police AI, Biometrics and AI Liability

Decreto legislativo 9 settembre 2026, n. 160 was published in Gazzetta Ufficiale n. 214 on 15 September 2026 and takes effect on 30 September 2026, ten days before the Law 132/2025 delegation expires. It closes the gap our Law 132/2025 page openly left open. Three Titles and 22 articles: a police-AI regime with two parallel biometric authorisation tracks capped at fifteen renewable days, a new article 437-bis of the criminal code punishing the omission of security and human-oversight measures in high-risk AI systems as an offence of danger, entity liability under a new article 25-vicies of D.Lgs. 231/2001, and civil remedies that enact nationally the disclosure duty and rebuttable causation presumption the withdrawn EU AI Liability Directive would have harmonised.

Written and maintained by CASRAI Editorial Board

Last updated

Last verified against primary sources: 25 September 2026. Written from the Gazzetta Ufficiale text of the decree, not from secondary summaries.

Our guide to Italy’s Law 132/2025, the national AI statute that sits inside the EU AI Act, ends with an admission. It sets out the statute’s delegation calendar — three legislative-decree delegations, all expiring on 10 October 2026 — and then says plainly that we had verified the deadline from the consolidated text but had not verified from primary sources whether each delegated decree had been adopted.

One of them now has been. Decreto legislativo 9 settembre 2026, n. 160 was published in Gazzetta Ufficiale Serie Generale n. 214 on 15 September 2026. Its full rubric is a mouthful, and the mouthful is informative:

Adeguamento della normativa nazionale alle disposizioni del regolamento (UE) 2024/1689 del Parlamento europeo e del Consiglio, del 13 giugno 2024, che stabilisce regole armonizzate sull’intelligenza artificiale, in materia di utilizzo dei sistemi di intelligenza artificiale per l’attività di polizia e di responsabilità civile e penale.

Two subjects, one instrument: AI in policing, and civil and criminal liability for AI.

When it takes effect, and why the date is not in the decree

The decree contains no entry-into-force article. It runs to Article 22 — a financial-invariance clause — and then straight to the promulgation formula, dated Rome, 9 September 2026, signed by President Mattarella and countersigned by Prime Minister Meloni and the ministers for European affairs, the interior, justice, foreign affairs, defence and economy, with the Guardasigilli’s visto.

Because no article derogates from it, the ordinary Italian vacatio legis applies: fifteen days from publication. Publication on 15 September 2026 therefore puts the decree in force on 30 September 2026. As this page is written, on 25 September 2026, the decree is published law that has not yet begun to apply — and the delegation it exercises expires ten days after it does begin.

Which delegation it exercises

The preamble is specific: the decree is adopted under Law 132/2025 article 24, commi 1, 2 lettera h), 3 e 5. That matters for anyone tracking the parent statute’s calendar, because it means a single instrument discharges two of the three legislative-decree delegations our Law 132/2025 page lists:

Delegation in Law 132/2025 Subject Status as at 25 September 2026
Article 24(1) Aligning national law to Regulation (EU) 2024/1689 Exercised in part by D.Lgs. 160/2026
Article 24(2)(h) A dedicated regime for AI in policing Exercised by Title I of D.Lgs. 160/2026
Article 24(3) Unlawful creation and use of AI systems Exercised by Title II, Chapter I
Article 16 Organic regime for training data, algorithms and mathematical methods We found no adopted decree; unverified

A companion scheme — covering the powers of the national authorities, market surveillance, sanctions, regulatory sandboxes, training and labour provisions — received preliminary Council of Ministers approval alongside this one on 10 June 2026. We have not been able to verify that it has since been published in the Gazzetta Ufficiale, and this page does not describe it as adopted. Anyone who needs that answer should check the Gazzetta Ufficiale directly.

The shape of the decree: three Titles, 22 articles

Title Chapter Articles Subject
I — AI in police activity I 1–2 Purpose and scope; definitions
II 3–6 Research, testing, development, training, validation and use; scientific collaboration; regulatory sandboxes; police training
III 7–10 Biometric labelling and categorisation; real-time remote biometric identification; impact assessment, logging and notification; post facial recognition on video surveillance
II — Offences and remedies I 11–15 Criminal code, criminal procedure and entity-liability amendments
II 16–20 Civil procedural tools for compensating AI-caused damage
III — Final provisions I 21–22 Transitional regime; financial invariance

Article 1(3) repeats the anti-gold-plating discipline that runs through the parent statute: Title I “non comporta nuovi obblighi rispetto a quelli previsti dal regolamento (UE) 2024/1689” — it imposes no obligations beyond those the Regulation already sets for AI systems used in police activity. Article 2 does not write fresh definitions either; it borrows the Regulation’s.

Title I: what Italy’s police forces may build, and with whom

Articles 3 to 6 govern the pipeline rather than the deployment. Article 3 subjects research, experimentation, development, training, adoption, validation and use of AI for police purposes to constitutional rights, EU law and the principles of proportionality, non-discrimination, human oversight and transparency carried over from article 3 of Law 132/2025. Article 6 requires each police force to run AI courses at its own training institutes, with a stated minimum syllabus: how the systems work, and — explicitly — “i limiti, i bias e gli errori” of them, plus awareness of the legal and ethical implications.

Article 5 does something narrower and more technical. It declares itself the legal basis, for the purposes of article 59(2) of the AI Act and of legislative decree 51/2018 (Italy’s law-enforcement data-protection transposition), for police forces to process personal data — including criminal-offence data and the special categories at article 3(37) of the Regulation — inside AI regulatory sandboxes. The Garante must be involved where the sandbox processes personal data, and a DPCM is still required to define how the police sandbox track coordinates with the general article 57 sandbox. That regulation does not exist yet.

Article 4 is a research-contracts provision, and a strict one

Article 4 lets police forces enter research and scientific-experimentation collaborations with “università, enti di ricerca e soggetti pubblici e privati”, including through in-house or wholly State-controlled companies, subject to EU competition and State-aid rules. The conditions attached to that permission are where the provision earns attention:

  • The collaboration agreement must contain clauses excluding the sharing of sensitive operational data, and excluding the collaborating party’s acquisition or use — even indirect — of AI systems, their hardware and software resources, or AI-integrated devices that have been trained for police activity. Synthetic data, or real data subjected to masking or pseudonymisation, are the permitted route.
  • The agreement must expressly allocate intellectual property, industrial property and economic-exploitation rights in the research results, derived models, training data and software, by reference to the industrial property code (D.Lgs. 30/2005) and to article 64 of DPR 382/1980.
  • The agreement must specify the data-protection roles of each participant — controller, joint controller or processor — and the corresponding obligations, security measures and processing documentation.
  • In every case, ownership of models trained on sensitive operational data stays with the police force.

For a university research office in Italy, that is a named set of mandatory contract terms for a specific category of sponsor. It is a narrow research-administration surface, but a real one, and it is the only part of this decree that is.

Biometrics: Italy proceduralised rather than prohibited

The AI Act bans real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, then carves out exceptions at article 5(1)(h) and requires member states that want to use them to lay down authorisation rules. Italy has now laid them down, and it has laid down two parallel tracks with different authorising authorities — a distinction that secondary coverage tends to collapse.

Article 8 of the decree New article 359-ter c.p.p. (inserted by article 13) Article 10 of the decree
Technique Real-time remote biometric identification Real-time remote biometric identification Post facial recognition on video surveillance
Context Prevention; search for a missing person or for victims of abduction, trafficking or sexual exploitation Criminal proceedings: confirming identity of, or targeted search for, a suspect; fugitives; specific victims Criminal proceedings: targeted search for a suspect
Who applies Questore, provincial commander of the Carabinieri or Guardia di Finanza, or heads of the central services Public prosecutor Public prosecutor, on the application of the judicial police officers who started the system
Who authorises Procuratore della Repubblica at the tribunal of the district capital Giudice per le indagini preliminari, by reasoned decree Giudice per le indagini preliminari, by reasoned decree
Maximum period A specific event, or the strictly necessary time, in any case not more than 15 days, renewable by the prosecutor by reasoned decree for successive 15-day periods The strictly necessary time, in any case not more than 15 days, renewable by the judge by reasoned decree for successive 15-day periods No fixed window; authorisation must be sought within 48 hours of activation and granted within the next 48 hours
Urgency route Start on the questore‘s or commander’s disposition after oral communication to the prosecutor; request within 24 hours; prosecutor decides within 24 hours Prosecutor by reasoned decree, communicated to the judge within 24 hours, validated within 48; in extreme urgency judicial police may start, refer within 12 hours An exception, not an urgency route: see below

Two limits apply to both real-time tracks and deserve to be read together, because they are the operative constraint on scope:

  • The scope of the authorisation is fixed on its face. The authorising decree must delimit the geographic area of application and name the persons specifically sought. It is not a warrant to watch a place.
  • The reference database is purpose-built and disposable. Comparison may run only against a database appropriate to the specific purpose. It is assembled afresh for each use, contains only biometric data pertinent to that purpose, is deleted when the authorisation expires, and must not accumulate across authorisations. Databases fed wholly or partly by untargeted scraping, or constituted in breach of data-protection law, are prohibited outright.

Article 359-ter also constrains the underlying offence: sufficient indicia of one of the offences listed in Annex II to the AI Act, punishable by a maximum of not less than four years’ imprisonment.

Article 10’s exception is the loosest provision in Chapter III and worth flagging. Tracking article 26(10) of the AI Act, no judicial authorisation is required where post facial recognition is used exclusively after an offence has been committed, solely for the initial identification of a person potentially suspected of it, on the basis of objective and verifiable elements directly connected to the offence. In that case the use runs under the direct and exclusive responsibility of a named officer — the public-security officer designated by the questore, or the judicial police officer handling the case.

Throughout Chapter III the sanction for getting the procedure wrong is evidentiary rather than penal: the system is stopped, all personal data, results and outputs are deleted (unless they constitute corpo del reato), and the results may not be used.

Article 9: the assurance layer

Before any real-time use on either track, the controller must complete a fundamental-rights impact assessment under article 27 of the AI Act and a data-protection impact assessment under articles 23–24 of D.Lgs. 51/2018. Every use is automatically written to immutable log files containing at least the article 12(3) AI Act data, retained for five years and accessible only to competent authorities for lawfulness verification, internal control, or in criminal proceedings. After use, the controller notifies the Garante under article 5(4) of the Regulation — but only after a nulla osta from the competent judicial authority, which may defer the notification for up to three months, renewable once, where there are specific secrecy needs.

Article 9(5) then hands the Interior Ministry, with Justice and after hearing the Garante and the national AI authorities, a decree to set the minimum technical reliability and accuracy requirements, periodic performance monitoring with particular regard to detecting and mitigating bias or discriminatory effects, minimum requirements for reference databases, and the technical and organisational security measures. Until that decree exists, the accuracy floor for these systems is undefined. It does not exist yet.

Article 437-bis: omitting a security control becomes a crime

Article 12 of the decree inserts a new article 437-bis into the criminal code, immediately after article 437 — the long-standing offence of omitting workplace accident-prevention measures. The placement is a deliberate systematic signal: this is an industrial-safety offence, applied to AI.

Its rubric is “Omessa adozione di misure di sicurezza nei sistemi di intelligenza artificiale e alterazione illecita dei sistemi”. The penalty ladder, from the Gazzetta Ufficiale text:

Conduct Resulting danger Penalty
Omitting the technical security measures prescribed for the design, training, production or placing on the market of high-risk AI systems, suitable to prevent malfunctions or alterations of their operation; or omitting human-oversight measures Danger to life, or to public or individual safety 1 to 5 years’ imprisonment
Danger to State security 2 to 8 years’ imprisonment
Altering high-risk AI systems, outside the cases above, unless the act constitutes a more serious offence Danger to life, or to public or individual safety 2 to 6 years’ imprisonment
Danger to State security 3 to 10 years’ imprisonment
Any of the first-paragraph conduct committed by gross negligence (colpa grave) As above Penalty reduced by one-third to one-sixth
A professional user of high-risk AI systems who intentionally omits human-oversight measures Respectively, danger to life/public or individual safety, or to State security The first-paragraph penalties

Three features are worth separating out, because summaries tend to blur them.

It is an offence of danger, not of harm. Nothing in article 437-bis requires anyone to have been injured. The result element is the creation of danger — to life, to public or individual safety, or to State security. Prosecution does not wait for an accident.

It reaches deployers, not only developers. The fourth paragraph creates a distinct liability for the utilizzatore professionale who intentionally omits human-oversight measures. An organisation that buys a high-risk system and switches off the human in the loop is inside the offence, not outside it.

Its content is imported from the AI Act. The prohibited omission is defined by reference to the security and human-oversight measures “previste” for high-risk systems — that is, the ones the Regulation and its harmonised standards require. The criminal norm is a shell; the Regulation fills it. Anyone working through our EU AI Act high-risk system compliance checklist is, in Italy from 30 September 2026, also working through the elements of a criminal offence.

Entity liability, and a quiet upgrade for the deepfake offence

Article 15 inserts a new article 25-vicies into D.Lgs. 231/2001, Italy’s corporate administrative-liability regime:

  • For article 437-bis: a pecuniary sanction of 600 to 1,000 quote.
  • For article 612-quater — the AI deepfake offence created by article 26 of Law 132/2025 — a pecuniary sanction of 200 to 700 quote.
  • In both cases, the interdictive sanctions at article 9(2)(b), (c), (d) and (e) of D.Lgs. 231/2001 apply.

The second bullet is an addition to the parent statute rather than a restatement of it. Law 132/2025 created 612-quater as an offence for natural persons; it did not attach entity liability. This decree does. Italian organisations with a 231 compliance model now have two AI predicate offences to map into it.

Article 14 makes a smaller change in the same direction, amending article 104(1)(e-bis) of the criminal-procedure implementing provisions so that it refers to material “generati anche con sistemi di intelligenza artificiale” rather than to the personal profile.

Title II, Chapter II: Italy enacts what the EU withdrew

The civil half of the decree is short — five articles — and its significance is disproportionate to its length, because of what happened in Brussels first.

The Commission’s proposed AI Liability Directive (COM(2022) 496) would have harmonised two mechanisms across the EU: court-ordered disclosure of evidence about high-risk AI systems, and a rebuttable presumption of causality. The Commission announced its withdrawal in the 2025 work programme, and the withdrawal took effect in October 2025. Articles 17 and 18 of this decree enact both mechanisms in Italian law.

Article 16 (scope). Article 17 applies to claims for damage, contractual and non-contractual, caused in the use of an AI system. Articles 18 and 19 apply more narrowly — only where the damage derives from breach of one or more AI Act obligations. Article 82 GDPR and the national transposition of the new Product Liability Directive (EU) 2024/2853 are expressly preserved. Where the injured party is a natural person acting outside any business or professional activity, the court of their residence or domicile is also competent.

Article 17 (access to evidence). On the application of the party alleging damage, the court orders the other party, or a third party holding it, to produce specifically relevant evidence about how the AI system worked — provided the applicant presents facts making the claim plausible, including as to the link between the system’s output and the damage. The named categories track the Regulation directly: article 12 logs, article 9 risk-management documentation, relevant parts of the article 11 technical documentation, and the article 14 human-oversight parameters. Orders are limited to what is necessary and proportionate, with trade secrets protected through article 121-ter of the industrial property code.

The consequences of non-production are the teeth. A party that fails to comply without justification exposes itself to adverse inferences under article 116 of the code of civil procedure — and where the failure concerns the listed documentation, the court, having weighed all other evidence, treats the applicant’s alleged facts as admitted. A non-complying third party is fined EUR 1,500 to EUR 10,000.

Article 18 (presumption of causation). One sentence: where the damage derives from breach of one or more AI Act obligations, the causal link between the breach and the damage is presumed, subject to proof to the contrary.

Article 19 (conformity is not a defence). Conformity with the Regulation’s obligations, “anche se certificata” under Chapter III, Section 5, does not in itself exclude the defendant’s liability. A CE mark is evidence, not immunity.

Article 20 (direct action against the insurer). A prospective claimant may ask the person they consider responsible whether they carry liability cover; the answer is due within thirty days and an omitted or incomplete answer draws an adverse inference, though the enquiry is not a condition of bringing the claim. The injured party then has a direct action against the insurer, within policy limits, with pre-loss policy defences opposable, the insurer’s recourse against its insured preserved, and the alleged wrongdoer as a necessary joined party. This is the motor-insurance model transplanted to AI — which makes the absence of a corresponding duty to insure conspicuous, a gap we examine in why no jurisdiction yet requires AI liability insurance.

The transitional rule is narrower than it looks

Article 21(1) gives each police force one year from entry into force — to 30 September 2027 — to bring into compliance AI systems that are, at that date, the subject of contracts, in development or testing for police purposes, or already in use.

Read the object of that obligation carefully: compliance is required “con le disposizioni del capo II del titolo I”. Chapter II is articles 3 to 6 — the research, development, collaboration, sandbox and training provisions. The biometric provisions in Chapter III get no transitional grace period. Coverage that reports “a year to adapt” without that qualification is reporting the rule too broadly. Article 21(2) adds that for Title I provisions whose application is set by or depends on the AI Act, the Regulation’s own timetable governs.

How this connects to NIKOLAI

NIKOLAI is CASRAI’s own independent frontier-AI-safety dictionary. It is not endorsed by any lab, evaluator or regulator, and its crosswalk rows are shadow mappings — CASRAI’s reading of a published document — unless an organisation has filed a Mapping Declaration of its own.

The element this decree touches most directly is security control, in track N6 — Mitigations and security. NIKOLAI defines it as an individual security measure, identified by name and mapped to external control catalogues where possible. The reason the definition is built that way is that a registry needs to record which control, not merely that controls exist.

Article 437-bis is an unusually direct argument for that design. The offence turns on the absence of a specific measure: the technical security measures prescribed for a defined lifecycle stage, or the human-oversight measures. Under Italian law from 30 September 2026, “we have a security programme” is not a defence and not an answer; the question is which named control was required and whether it was in place when the danger arose. A safety disclosure that describes controls only in aggregate cannot answer it. That is exactly the gap NIKOLAI’s named-and-mapped element is meant to close — and it is worth noting that no lab currently publishes at that granularity.

What this page does not claim

  • We do not describe the companion governance and training decree as adopted. It received preliminary Council of Ministers approval on 10 June 2026; we have not verified publication in the Gazzetta Ufficiale.
  • We have not verified whether the article 16 training-data delegation in Law 132/2025 has been exercised.
  • The implementing measures this decree itself requires — the article 9(5) interior-ministry decree on accuracy and bias monitoring, and the article 5(4) DPCM on sandbox coordination — did not exist as at 25 September 2026.
  • We make no claim about how Italian courts will construe the danger element of article 437-bis, or about how often the biometric authorisation routes will be used. There is no practice yet; the decree is not in force.
  • Secondary coverage of this decree is not consistent on the penalty structure and the authorisation window. Where this page gives a number, it is taken from the Gazzetta Ufficiale text linked below.

Frequently asked questions

Is D.Lgs. 160/2026 in force?

Not yet, as at 25 September 2026. It was published in Gazzetta Ufficiale n. 214 on 15 September 2026 and contains no entry-into-force article, so the ordinary fifteen-day vacatio legis applies and it takes effect on 30 September 2026.

Does the decree legalise live facial recognition in Italy?

It does not authorise general deployment. It provides the national authorisation procedure the AI Act requires of member states that want to rely on the article 5(1)(h) exceptions, and it does so restrictively: prior authorisation from a prosecutor (prevention, missing persons and victims) or a preliminary-investigations judge (criminal proceedings), a maximum of fifteen days renewable in fifteen-day blocks, a delimited geographic area, named individuals, a purpose-built non-incremental reference database, a ban on scraped databases, a prior fundamental-rights impact assessment, five-year immutable logs, and post-use notification to the Garante.

Does article 437-bis apply to companies outside Italy?

It is an Italian criminal provision and operates under ordinary Italian criminal jurisdiction, so the question is where the relevant conduct and danger are located rather than where a company is incorporated. The related entity liability under the new article 25-vicies of D.Lgs. 231/2001 also carries that regime’s own prerequisites: the offence must be committed in the entity’s interest or to its advantage, and liability is not automatic from an employee’s breach.

How does this differ from the deepfake offence in Law 132/2025?

They are separate offences with different structures. Article 612-quater, created by article 26 of Law 132/2025, punishes the unlawful dissemination of AI-generated or AI-altered images, video or voice causing unjust harm. Article 437-bis punishes an omission — failing to put required security or human-oversight measures in place around a high-risk AI system — where danger results. This decree does connect them at one point: article 25-vicies now attaches corporate liability to both.

Does it create a duty to insure against AI damage?

No. Article 20 gives an injured party a direct action against an insurer where liability cover exists, and a pre-action right to ask whether it does. It does not require anyone to buy cover.

Does the decree affect research organisations?

Narrowly. Article 4 lets police forces collaborate with universities, research bodies and private parties on police-AI research, and prescribes mandatory contract terms: exclusion of sensitive operational data, a bar on the partner acquiring or indirectly using systems trained for police work, express allocation of IP and economic-exploitation rights by reference to the industrial property code and article 64 of DPR 382/1980, express allocation of data-protection roles, and police ownership of models trained on sensitive operational data. Article 5 provides the legal basis for police processing of criminal-offence and special-category data in AI sandboxes. The broader research-data provisions for AI sit in articles 8 and 9 of the parent statute, not here.

Primary sources

  • Decreto legislativo 9 settembre 2026, n. 160, Gazzetta Ufficiale Serie Generale n. 214, 15 September 2026 — Gazzetta Ufficiale text (PDF).
  • Legge 23 settembre 2025, n. 132, Disposizioni e deleghe al Governo in materia di intelligenza artificiale, article 24 — the enabling delegation.
  • Regulation (EU) 2024/1689, articles 5, 9, 11, 12, 14, 26, 27, 57 and 59, and Annex II.
  • Decreto legislativo 18 maggio 2018, n. 51 (law-enforcement data protection) and decreto legislativo 8 giugno 2001, n. 231 (entity liability).

Related reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about Italy’s D.Lgs. 160/2026: Police AI, Biometrics and AI Liability

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →