Wednesday, Sep 30 | --:--
Back to home

Italy Puts High-Risk AI Oversight Failures Under Criminal Code Art. 437-bis

Legislative Decree 160/2026 enters into force on September 30, inserting Criminal Code Art. 437-bis for intentional omission of required high-risk AI security and human-oversight measures when that omission creates concrete danger. Prison exposure — on LCA Studio Legale’s English reading of the decree — sits beside new 231 entity liability. The contrast with Washington’s same-window voluntary ‘morally binding’ accord is the point: one capital chose criminal exposure; the other chose self-policing with no legal force.

Times of AI Desk 5 min read Rome, Italy View as Markdown
Cover illustration for Italy Puts High-Risk AI Oversight Failures Under Criminal Code Art. 437-bis

While Washington sold a voluntary audit stack with no legal force, Rome put high-risk AI governance failures onto the criminal code. The force date is the news: the text was published earlier in September; September 30, 2026 is when it bites.

Legislative Decree No. 160 of 9 September 2026 (GU Serie Generale No. 214 of 15 September 2026) entered into force today, per Normattiva’s consolidated notice (entrata in vigore 30/09/2026). The decree aligns Italian law with the EU AI Act on police use of AI and on civil and criminal liability. For operators, the spine is not another administrative fine schedule. It is Art. 437-bis of the Criminal Code — and entity exposure under Legislative Decree 231/2001.

What Art. 437-bis does

Article 12 of the decree inserts Art. 437-bis, titled (in LCA Studio Legale’s English practical summary) “Failure to adopt security measures in artificial intelligence systems and unlawful tampering with such systems.” The provision, on LCA’s reading, distinguishes four scenarios for high-risk AI systems:

  • Intentional omission of required technical security measures (suited to preventing malfunctions or alterations) or of human-oversight measures in design, training, production, or placing on the market — when the omission creates concrete danger to public or individual life or safety. LCA cites imprisonment of one to five years; two to eight years where the danger is to State security.
  • Unlawful tampering with high-risk systems, with related (higher) ranges where danger follows.
  • The same omissions punishable for gross negligence, with a reduced penalty.
  • Professional users who intentionally omit human-oversight measures, again where concrete danger follows.

Those year ranges are LCA’s English practical summary of the published decree, not this desk’s independent translation of every Italian clause on Normattiva. Treat them as the working English map until a court or ministry guidance sharpens the edges. The mechanism that matters for the trade is already clear from both Normattiva’s force date and LCA: intentional omission of required high-risk security or human oversight, tied to concrete danger, is now a criminal pathway — not only an AI Act administrative one.

Article 15 adds Art. 25-vicies to Legislative Decree 231/2001 (“Offences committed through the use of artificial intelligence systems”), bringing entity administrative liability (financial quotas and disqualification-type sanctions, on LCA’s account) for Art. 437-bis predicates and for related deepfake dissemination offences already in Law 132/2025. LCA’s compliance note is blunt: inventory high-risk systems, document security and human-oversight controls, and refresh the 231 Model. That is advice from counsel, not a finding that any lab has already been charged.

The decree also regulates police biometric and real-time remote identification with prosecutor / GIP authorization gates — Title I material that matters for Italian public bodies, and that is adjacent to, not identical with, the private-operator criminal exposure in Art. 437-bis.

The same-window contrast

Hours earlier in the US news cycle, Trump and the CEOs of Anthropic, OpenAI, Google, Meta, Nvidia, and xAI signed a voluntary Joint Commitment on Frontier Responsibilities: internal controls, an internal monitoring team, a company-chosen independent external auditor, and a board committee — morally binding in Trump’s words, without legal force in the wires’ reading of the text, and with no duty to publish audit findings.

Italy’s force-date event is the hard contrast. One jurisdiction chose a criminal omission offence for high-risk AI security and human-oversight failures that create concrete danger. The other chose a multi-lab self-policing accord that leaves codification optional. Labs, integrators, and professional users with Italian exposure now face a compliance bar that is not the same instrument as Washington’s assurance channel — and not reducible to “the EU AI Act already covers this.”

Limits

  • Prison ranges and 231 quota bands above follow LCA Studio Legale’s English practical summary (dated to the force date). Normattiva is the official Italian consolidated text; this piece does not claim a line-by-line independent translation of every penalty clause.
  • “Concrete danger” (pericolo concreto) is an Italian criminal-law trigger. How prosecutors will charge early cases is not yet known; do not invent enforcement anecdotes.
  • The decree is broader than Art. 437-bis (police AI, biometrics, civil tools). This file’s stake is the criminal / 231 exposure for high-risk security and oversight omissions.
  • No claim here that any named US frontier lab has been investigated under 437-bis. The contrast is institutional posture in the same news window.

Sources

Prior Coverage

Earlier Times of AI reporting on this thread.

Scroll to continue reading