Italy has introduced a comprehensive national framework for artificial intelligence, adding another layer to Europe’s rapidly developing AI regulatory landscape.

Italy has become the first EU member state to adopt a comprehensive national law dedicated to artificial intelligence, marking an important development in Europe’s attempt to govern a technology already reshaping business, public administration and professional life.

The Italian Parliament approved Law No. 132/2025 on Artificial Intelligence, which was published in the Gazzetta Ufficiale on 25 September 2025 and entered into force on 10 October 2025. The legislation establishes national principles governing the research, development, deployment and use of AI, while expressly requiring its provisions to be interpreted consistently with the EU AI Act.

Rather than attempting to replace the EU framework, Italy’s approach is designed to operate alongside it. The law introduces additional national rules across several sensitive areas, including healthcare, employment, justice, education, public administration and intellectual property. Its stated objective is to promote a human-centred, transparent and responsible approach to AI while protecting fundamental rights and addressing economic and social risks.

One of the most significant features is the emphasis on human oversight. In sectors where AI may influence important decisions, the Italian framework reinforces the principle that technology should support rather than displace human responsibility. In healthcare, for example, AI may assist diagnosis and treatment, but final decision-making remains with medical professionals. Employers using AI in the workplace must also inform employees about its use.

The legislation also reaches into the increasingly complicated relationship between AI and intellectual property. AI-assisted works may receive copyright protection where they result from genuine human intellectual contribution, while certain forms of text and data mining are subject to limitations concerning copyrighted material.

Italy has also introduced criminal provisions addressing harmful uses of AI. The unlawful dissemination of AI-generated or manipulated content, including deepfakes where harm is caused, can trigger imprisonment of between one and five years, while the use of AI in crimes such as fraud and identity theft can lead to aggravated penalties.

The institutional architecture is equally significant. The Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN) have been designated as key national authorities for AI, while sector-specific regulators retain their existing powers. The framework also provides for a national strategy and measures intended to support technological development and investment.

Perhaps most interestingly, Italy has chosen to combine regulation with industrial policy. The legislation authorises up to €1 billion in state-backed investment to support companies active in AI, cybersecurity, quantum technologies and telecommunications. The message is clear: regulation is not being presented solely as a mechanism for limiting technological risk, but also as part of an attempt to build domestic technological capacity.

For businesses operating in Italy, the significance of the new framework will therefore extend beyond compliance with the EU AI Act. Organisations will need to consider how European requirements interact with additional national rules, sector-specific obligations and the responsibilities assigned to Italian authorities.

For the rest of Europe, Italy provides an interesting test case.

The EU AI Act was designed to create a harmonised regulatory framework across the Union. National legislation such as Italy’s raises a broader question about how much room member states should have to develop their own rules around a technology that is, by definition, difficult to contain within national borders.

That question will become increasingly important as AI regulation moves from broad principles to everyday implementation.

The European AI landscape is no longer being shaped by a single law. It is becoming a layered system in which the EU AI Act establishes the common framework, while national governments add their own rules around employment, healthcare, criminal law, copyright, public administration and other areas where AI intersects with existing legal systems.

Italy’s law may therefore prove significant not simply because Italy regulated AI first at the national level, but because it offers an early example of what the next stage of European AI governance could look like: one European framework, increasingly accompanied by national rules designed around local institutions, risks and policy priorities.

For companies, lawyers and technology developers, the practical lesson is straightforward. Understanding the AI Act may no longer be enough. The next phase of AI compliance will increasingly require understanding where AI is being used, under which national framework, and which additional obligations apply.

The European AI regulatory map is becoming more detailed.

Italy has just added another important piece to it.

Image: Ch Jawad