Skip to main content
Back to Blog
Regulatory News

Law 132/2025: obligations and Decree 160/2026, what to document

30 September 20269 min readObligoBoard Team

Law 132/2025 (Law No. 132 of 23 September 2025; Gazzetta Ufficiale, Serie Generale n. 223, 25 September 2025, Italian text on Normattiva) has been in force since 10 October 2025. Its first implementing decree, Legislative Decree No. 160 of 9 September 2026 (Gazzetta Ufficiale, Serie Generale n. 214, 15 September 2026, Italian text on Normattiva), has been in force since 30 September 2026. For anyone handling compliance in an Italian SME, the practical question is one: what must I be able to show, and to whom?

Here are the nine compliance tasks of Law 132/2025 and Decree 160/2026, four from the law and five from the decree (they are not duties for everyone): for each, what the rule says and what to document and do. This is process work: we do not tell you whether you are compliant, or whether a rule concerns your case. Where the scope is left open, we say so and point you to your adviser.

Law 132/2025: four tasks

For each of these tasks, if the conditions do not apply to you, keep a dated statement explaining why and re-confirm it every year: the annual cadence is a process choice, not a legal requirement.

Art. 11: informing workers

Article 11(2) provides that the employer or commissioning party informs the worker of the use of AI, in the cases and in the manner set out in Art. 1-bis of Legislative Decree No. 152 of 26 May 1997. The cases, content and manner are fixed by that article: read it.

To document and do: the list of AI tools used in the working relationship (name, provider, purpose, workers affected); your reading of Art. 1-bis for each; the information given and proof of delivery, without named recipient lists.

Art. 13: informing clients of a professional service

Article 13(2) provides that information on the AI systems the professional uses is communicated to the recipient of the service in clear, simple and exhaustive language.

To document and do: the list of systems used and for which activity; the text for the client, without jargon; dated proof of communication; an internal rule for keeping it current. It stays separate from your privacy notice: if the system processes the client's personal data, the GDPR continues to apply.

Art. 4: clear notices and children under 14

Article 4(3) provides that the information it refers to is given in clear and simple language, so as to guarantee the user knowledge of the risks and of the right to object. Paragraph 4 provides that access to AI technologies by children under fourteen requires the consent of the person exercising parental responsibility. The paragraphs are summarised here: read them in full.

To document and do: the personal-data processing linked to AI (system, data categories, purpose); the text of the information and where the user meets it; how a user can object and how you handle the request (for when the right applies, Art. 21 GDPR). If your service can be used by children under 14: how you establish age, with a proportionate method, and how you collect and keep consent. That consent does not replace the GDPR legal basis; if the basis is consent and the service is offered online directly to children, Art. 8 GDPR also applies (age threshold of 14: Art. 2-quinquies of the Italian Privacy Code). As evidence, upload procedures, not data about users or children.

Art. 7: healthcare

Article 7 contains three provisions: the data subject has the right to be informed about the use of AI technologies (paragraph 3); the decision always rests with the medical professionals (paragraph 5); paragraph 6 refers to systems that are reliable, periodically verified and updated. Paragraphs 5 and 6 are summarised: read the article in full.

To document and do: the list of systems used in healthcare; the information given to the patient; who decides, how they assess the system's output and where that is recorded (a record field, shown as a blank template); a verification cadence per system, with date, role, result and updates. If you process health data, consider Arts. 9 and 35 GDPR as well. No patient records as evidence: the proof is the procedure.

Legislative Decree 160/2026: five tasks

A note on dates, first

Article 437-bis of the Criminal Code concerns high-risk AI systems, not every use of AI. The obligations of Regulation (EU) 2024/1689 for Annex III high-risk systems apply from 2 December 2027; for Annex I systems, from 2 August 2028. Legislative Decree 160/2026 has been in force since 30 September 2026. How these dates combine for a system that already falls among the high-risk systems today is a question of interpretation to settle with a legal adviser: neither ObligoBoard nor this article resolves it. You can put the measures and reviews below in place now in any case.

Art. 12 and Art. 437-bis of the Criminal Code: human oversight

Article 12 of Legislative Decree 160/2026 inserts Art. 437-bis into the Criminal Code. The text concerns omitting technical safety measures and human-oversight measures for high-risk AI systems, with liability tied to further conditions set out in the article, and it contains a separate provision for a professional user who intentionally omits human-oversight measures. Whom each provision addresses, and when conduct amounts to an offence, depends on the full text and the facts: that is for your lawyer to assess. Here we cover only human oversight.

To document and do, for each high-risk system you provide or use: who carries out oversight (role, competence, authority to intervene or stop the system); the measures in writing; for providers, the instructions for use that describe them; for deployers, the application of the provider's instructions; how you check they are applied (training, checks, interventions, with dates); an annual review.

Art. 17: records ready for production

Article 17 concerns a court order to produce documents. Paragraph 2 indicates, among the documents, the logs referred to in Art. 12 of the Regulation, the risk-management documentation (Art. 9), the relevant information in the technical documentation (Art. 11) and that on human oversight (Art. 14). Paragraph 5 attaches to non-production a consequence on the evidence: to whom it applies and on what conditions is in the full text, to be read with your adviser. The work here is to know what you hold, where, and how quickly you can retrieve it, not to decide whether a document must be produced.

To document and do: a register with one row per set of documents (where it is, who holds it, how long you keep it, whether you or your provider hold it, and how quickly you obtain it); an annual retrieval test, with timings and results (how to note any gaps, agree with your adviser); who decides on production and how to handle personal data and trade secrets inside the documents.

Art. 20: disclosing insurance within 30 days

Article 20(1) provides that the person to whom the request is addressed communicates, within thirty days of receiving it, the existence of a civil-liability insurance contract relating to the damage alleged, the contract details and the name of the insurer. Who may make the request, in which proceedings, and with what consequences if it goes unanswered is in the full text: read it with your adviser.

To document and do: who receives the requests and where they arrive (a monitored PEC address); a sheet of your civil-liability policies; the thirty-day deadline in the calendar at each request; a reply template reviewed by your adviser. If you hold no policy, or are unsure whether a relevant one exists, ask your adviser how to answer: do not improvise.

Arts. 18 and 19: reviewing your liability posture

Article 18(1) provides that the causal link between the violation and the damage is presumed, unless proven otherwise. Article 19(1) provides that conformity, even if certified, does not of itself exclude the defendant's liability. Which violations and which proceedings these cover is in the full text. The review does not assess whether you are liable for anything: it helps you know what you have done and what you can show.

To document and do, if you provide or use AI systems: an up-to-date inventory; for each system, who could suffer damage, what measures you have taken and when; the documents that show them (which of them can serve as proof to the contrary is for the court, but keeping them in order is useful); what you did beyond the certificate of conformity; contracts and policies re-read; the review minute.

Art. 15 and Art. 25-vicies: mapping in the 231 model

Article 15 of Legislative Decree 160/2026 inserts Art. 25-vicies into Legislative Decree No. 231 of 8 June 2001, which refers to the offences in Arts. 437-bis and 612-quater of the Criminal Code (the latter introduced by Art. 26 of Law 132/2025). Which entities are subject to Legislative Decree 231/2001 is a question for your adviser: we take no position here.

For entities that are subject to it or have adopted a model, to document and do with your 231 adviser: identify the activities connected, for example, with high-risk AI systems or with generating synthetic content (which of them fall within the offences is for your adviser to assess); check whether the model's protocols and controls cover them; record the decision on updating the model, with date, reasons and the body that took it; repeat every year.

Finding them in ObligoBoard

The nine tasks are collected in the framework "Law 132/2025 — Artificial Intelligence (Italy)" (in Italian, "Legge 132/2025 — Intelligenza artificiale (Italia)"): each task has the article and the Gazzetta reference, guidance, and a place for dated evidence. Three things to know before adopting it:

  • It is visible to organisations whose country is Italy and must be adopted explicitly: it is not added on its own.
  • It sits alongside the European framework but does not depend on EU AI Act Essentials, and it does not pair with it automatically. Adopting both is your choice; the Starter plan includes 1 framework per organisation, so on Starter this framework takes up the only place available.
  • The tasks on Art. 437-bis and on records appear after ObligoBoard's AI Act intake, only where the result is high-risk (Annex III) as a provider or deployer. For importers, distributors and Annex I systems they are not activated automatically: if they concern you, talk to your adviser.

Adopt the framework in ObligoBoard: the trial lasts 14 days, with full Pro access and no credit card.

What's next

The deadline for a second implementing decree is 10 October 2026: see the roadmap for the current status.

General information, not legal advice; drafted with AI assistance. For any question of interpretation, in particular criminal law, consult your adviser.

Ready to make your record defensible?

Track the obligations that apply to you with the evidence attached, and export an audit-ready pack whenever you need it.

Start your free trial

Related Posts