Enforcement per member state
AI Act enforcement in Italy
Last verification round: 2026-08-10
- Who supervises · designated
- National Cybersecurity Agency (ACN)
- Single point of contact
- Agenzia per la Cybersicurezza Nazionale (ACN)
- Implementing law
- in force
The situation in this country
Italy was the first EU Member State with its own national AI law (Law 132/2025, in force since 10 October 2025). Article 20 designates AgID as notifying authority and ACN as market surveillance authority and single point of contact; sectoral regulators (Banca d'Italia, CONSOB, IVASS) keep their roles. Implementing decrees covering governance and sanctions received preliminary approval on 10 June 2026 and must be finalised by October 2026. No fine or formal investigation under the AI Act is known yet.
Obligations at play here
What has happened
2026-06-10 | Consiglio dei Ministri
Council of Ministers gives preliminary approval to two implementing decrees under Law 132/2025
On 10 June 2026 the Council of Ministers gave preliminary approval to two legislative decrees: one on governance, the powers of AgID and ACN and AI training, and one on police use, biometrics and civil and criminal responsibility. The texts are now with the parliamentary committees and must be finalised within the twelve-month delegation window (by October 2026).
Governo Italiano, comunicato stampa Consiglio dei Ministri n. 177
2025-10-10 | Parlamento italiano
Law 132/2025: first national AI law in the EU enters into force
Law No. 132 of 23 September 2025 (Official Gazette 25 September 2025) entered into force on 10 October 2025. It complements the AI Act with national principles, sectoral rules for health, justice, labour and public administration, and delegations to the government for implementing decrees, including the sanctions regime.
2025-10-10 | Italiaanse regering
AgID and ACN designated as national AI Act authorities
Article 20 of Law 132/2025 designates AgID as notifying authority and ACN as market surveillance authority and single point of contact towards the EU institutions. ACN is listed as the national competent authority on the European Commission's official AI Act Service Desk.
2024-12-20 | Garante per la protezione dei dati personali
Italian authority fines OpenAI 15 million euros
The Garante closed its ChatGPT investigation with a 15 million euro fine for training on personal data without an appropriate legal basis and inadequate information. The Court of Rome annulled the fine on 18 March 2026: after OpenAI established itself in Ireland, jurisdiction ran through the one-stop-shop mechanism, and the court never reached the substantive allegations. Since 2 August 2025, GPAI models carry their own documentation and transparency duties under the AI Act, enforced by the AI Office rather than national privacy authorities.
Garante, besluit 2 november 2024, bekendgemaakt 20 december 2024
2023-03-30 | Garante per la protezione dei dati personali
Italian authority imposes temporary limitation on ChatGPT
The Garante imposed a temporary processing limitation on OpenAI for ChatGPT over the lack of a legal basis and of age verification. The limitation was lifted at the end of April 2023 after OpenAI took measures. The case showed early on that European authorities can directly affect generative AI; the transparency and information duties for such systems now sit in Article 50 of the AI Act.
2022-03-09 | Garante per la protezione dei dati personali
Italian authority fines Clearview AI 20 million euros
The Garante fined Clearview AI 20 million euros for collecting facial images from the internet without a legal basis to build a biometric search database. Untargeted scraping of facial images to build facial recognition databases has been explicitly prohibited under Article 5 of the AI Act since 2 February 2025.