AccuroAI
Products
What We Do
Solutions
Company
Resources
Book a demo
← Blog·AI Compliance10 min read

Italy's AI Law: Courts Can Now Order Your AI Act Logs as Evidence

Since 30 September 2026, an Italian civil court hearing a damages claim over the use of an AI system can order production of evidence on how the system worked, including AI Act logs and oversight documentation. A party that fails to comply without a justified reason can see the claimant's facts treated as admitted. We read Legislative Decree 160/2026 and Law 132/2025 in the Gazzetta Ufficiale and set out what they require, what they do not, and what to log and keep.

S
Sofia Reyes
Head of Compliance
Oct 9, 2026

Since 30 September 2026, an Italian civil court hearing a damages claim over the use of an AI system can order the other side, or a third party that holds them, to produce evidence about how the system worked. Article 17 of Legislative Decree 9 September 2026, no. 160 names four kinds of material that count: the logs under Article 12 of the EU AI Act, the risk management documentation, the relevant parts of the technical documentation, and information on how human oversight was set up. A party that ignores the order without a justified reason can find the claimant's version of the facts treated as admitted.

That changes what a log is for. Until now most compliance teams kept AI records for a regulator or an auditor. In Italy the same records can now be requested by the person suing you.

The decree is narrower than some summaries suggest. This post sticks to the text published in the Gazzetta Ufficiale, Italy's official journal, and marks where that text is silent.

Last verified: 9 October 2026, against the Gazzetta Ufficiale text of Law 132/2025 and Legislative Decree 160/2026, Normattiva, and the Italian government's press release no. 185 of 5 August 2026.

What does Italy's AI framework consist of?

Three instruments, at three different stages. The first is Law 23 September 2025, no. 132, in force since 10 October 2025, which set national principles and delegated the detail to the government. The second is Decree 160/2026, published on 15 September 2026 and in force fifteen days later. A further decree, on the national authorities' powers and on AI in training and work, was approved by the Council of Ministers on 4 August 2026. As of early October 2026 we could not find it on Normattiva, the state's legislation database.

InstrumentWho it bindsWhat it requires or allowsEvidence you would need
Law 132/2025, Art. 11(2)Employers and clients who commission workTell the worker that AI is used, in the cases set by Article 1-bis of Legislative Decree 152/1997The AI systems that touch work decisions, and each worker's notice
Law 132/2025, Art. 13(2)Members of the intellectual professions (lawyers, accountants and similar)Tell the client, in clear and simple language, about the AI systems usedWhich tools were used on which engagement, and the client disclosure
Decree 160/2026, Art. 17Any party to a damages claim over the use of an AI system, and third parties holding evidenceThe court may order production of evidence on how the system workedLogs, risk and technical documentation, oversight settings, retrievable for the event in dispute
Decree 160/2026, Art. 18 and 19Defendants where the harm stems from a breach of an AI Act obligationCausal link presumed unless disproved; conformity alone is no defenseProof that the obligation was met, or that the breach did not cause the harm
Criminal code, Art. 437-bis (inserted by Decree 160/2026, Art. 12)Anyone who omits required measures for a high-risk system, including professional usersPrison where omitted safety or oversight measures create danger to life or safetyRecords showing oversight measures were adopted and operating
Second decree (approved 4 August 2026, not yet published)Employers, per the government's summaryNo hiring, change or termination decision based solely on automated processingProof of a human decision behind each one

What did Law 132/2025 already require?

Two disclosure duties matter most to an enterprise. Article 11(2) says the employer or client "è tenuto a informare il lavoratore dell'utilizzo dell'intelligenza artificiale", that is, must inform the worker of the use of AI, in the cases and in the manner laid down by Article 1-bis of Legislative Decree 152/1997. That older provision covers fully automated decision-making or monitoring systems that feed into hiring, managing or ending a working relationship, assigning tasks, or evaluating performance. So the duty is tied to those uses. It does not reach every chatbot on every desk.

Article 13 covers the intellectual professions. AI may be used only for instrumental and support activities, with the professional's own intellectual work prevailing, and information about the systems used must be communicated to the client in language that is "chiaro, semplice ed esaustivo": clear, simple and complete.

Article 20 names the authorities. AgID, the digital agency, is the notifying authority. ACN, the national cybersecurity agency, is the market surveillance authority, with inspection and sanctioning tasks. Banca d'Italia, CONSOB and IVASS keep their role for the financial sector, and the powers of the Garante, the data protection authority, are untouched.

What exactly can a court order under Article 17?

Start with scope. Article 16(1) applies Article 17 to actions for damages, "sia contrattuale sia extracontrattuale" (in contract or in tort), caused in the use of an AI system. The text does not limit this to high-risk systems.

The claimant has to earn the order. A judge acts on the request of the party alleging harm, and only when that party presents facts and elements that make the claim plausible, including the link between the system's output and the damage. The order then covers evidence "specificamente pertinenti", specifically relevant, to the functioning of the system. Paragraph 3 limits it to what is necessary and proportionate, and paragraph 4 tells the judge to protect trade secrets and confidential information.

Paragraph 2 lists what falls within that evidence: the logs ("registri") under Article 12 of Regulation (EU) 2024/1689, the risk management documentation under Article 9, relevant information in the technical documentation under Article 11, and information on the parameters and methods of human oversight under Article 14.

Notice who holds those documents. They are mostly provider-side artifacts, and the order can be addressed to "l'altra parte o al terzo che ne dispone", the other party or a third party that has them. A deployer sued by a customer may therefore need records its vendor keeps. A deployer that is not a party at all can still receive an order.

What happens if you cannot produce them?

Paragraph 5 works in two steps. If a party fails to comply, even partly, without a justified reason, the judge may draw inferences from that conduct under Article 116 of the civil procedure code. Where the failure concerns the documentation listed in paragraph 2, the judge, "valutato ogni altro elemento di prova" (having weighed every other piece of evidence), "ritiene come ammessi i fatti allegati dall'istante": treats the facts alleged by the applicant as admitted.

It is not automatic. The court still looks at everything else in the file, and a justified reason is a defense. A third party that fails to comply faces a fine of 1,500 to 10,000 euros.

The decree does not say what counts as a justified reason. Whether "we deleted it under our retention schedule" or "our vendor would not give it to us" qualifies is a question for Italian counsel, and eventually for the courts.

What do Articles 18 and 19 add?

Article 18 is one sentence. When the damage derives from the violation of one or more obligations under the AI Act, the causal link between the violation and the damage is presumed, "salvo prova contraria", unless the contrary is proved. Read it carefully: the text presumes causation, not the breach.

Article 19 closes an exit. Conformity with the AI Act, even where certified, "non esclude di per sé la responsabilità del convenuto": it does not by itself rule out the defendant's liability.

Who can go to prison under Article 437-bis?

Article 12 of the decree inserts a new offense into the criminal code. Its first paragraph punishes anyone who omits the technical security measures required for the design, training, production or placing on the market of high-risk AI systems, or who omits human oversight measures, with one to five years in prison. The condition matters: the penalty applies "quando da tali omissioni derivi pericolo per la vita o l'incolumità pubblica o individuale", when the omission creates danger to life or to public or individual safety. Danger to state security raises the range to two to eight years, and gross negligence reduces the penalty.

Deployers get their own paragraph. The "utilizzatore professionale", the professional user of a high-risk system, is punished with the same penalties if they intentionally omit human oversight measures and one of those dangers results. The decree does not use the AI Act's word "deployer", so how far the two terms overlap is a point to confirm with counsel.

So this is not a prison term for a missing checkbox. It needs a high-risk system, an omission, and resulting danger; for the professional user it also needs intent. Companies are exposed too, because Article 15 adds the offense to Legislative Decree 231/2001, Italy's corporate liability law, with a fine of 600 to 1,000 quotas (the unit that law uses) and disqualification measures.

How does this fit with the EU AI Act timeline?

Awkwardly, for now. The documents Article 17 names are creatures of the AI Act's high-risk chapter. Provider logging capability is Article 12, human oversight is Article 14 and Article 26(2), and Article 26(6) makes deployers keep automatically generated logs under their control for at least six months. The Digital Omnibus, Regulation (EU) 2026/1744, moved those obligations for stand-alone high-risk systems to 2 December 2027, as our note on the Digital Omnibus delay explains.

The Italian civil chapter has no matching delay that we could find. Article 21(2) defers to the AI Act's own dates only for Title I, the policing rules. A court can already order "specifically relevant" evidence about any AI system's functioning; the four named document types are examples of what falls within it. The decree also contains no transitional rule on whether Article 17 reaches proceedings that were already pending on 30 September.

One practical gap follows. Six months is the AI Act's floor for deployer logs, and a damages claim can arrive well after that. Ask counsel which limitation period applies to your exposure before you set retention.

What should a multinational with Italian operations do now?

  • Build the inventory first. You cannot produce records for a system you did not know was in use. List every AI system and tool used in or for Italy, who uses it, and for which decisions.
  • Decide what you log, per decision. A court asks about one event involving one person. Check that you can pull the input, the output, the user and the human sign-off for a single decision without rebuilding it from several systems.
  • Set retention against litigation, not only the six-month floor. Write down the reason for each period.
  • Get vendor access in writing. Where the provider holds the logs or the technical file, the contract should say how fast you can obtain them and in what form.
  • Evidence human oversight. Record who reviewed, what they could override, and when they did.
  • Refresh worker and client notices under Articles 11 and 13 of Law 132/2025.

A written policy is the cheapest place to start. Our AI acceptable use policy template is useful here because it gives you the document that says which tools are approved for which work, which is the baseline a worker notice, a client disclosure and a court file all refer back to.

Where does tooling help, and where does it not?

Notices and contracts are work for legal and HR. The part software can carry is the record of use. AccuroAI discovers 1,400+ AI tools, so the inventory covers what staff adopted on their own as well as what procurement bought. It enforces policy at the point of use, redacting or blocking sensitive data in line using 40+ data classifiers, and it writes each of those events to an audit log attributed to a user and a tool.

Be clear about the limit. That log is your record of how your people used an AI system. It is not the provider's Article 12 log or technical documentation, which you still have to obtain from the vendor. What it gives you is an answer to the first questions a claim raises: which tool, which user, what data, what control applied, on what date. Our guide to building an AI agent audit log sets out the fields worth capturing.

Frequently asked questions

Does Article 17 apply only to high-risk AI systems?

No. Article 16(1) applies it to damages claims over the use of "un sistema di intelligenza artificiale", any AI system. The criminal offense in Article 437-bis is the part limited to high-risk systems.

Can a regulator use Article 17?

It is a civil procedure tool for a claimant in a damages action. Regulators have separate powers: ACN under the AI framework, and the Garante under the GDPR, which our GDPR and enterprise AI guide covers.

Is the ban on automated dismissals in force?

Not as far as we can verify. According to the government's press release no. 185, the second decree provides that decisions on establishing, changing or ending an employment relationship, including disciplinary measures and dismissals, cannot be adopted solely on the basis of automated processing, and that a dismissal in breach is void. Candidate search and selection are not treated as final hiring decisions, the release adds. We have not read the decree's text, so we cite no article numbers.

Has anyone been ordered to produce logs yet?

We know of no reported order as of early October 2026. For enforcement under the AI Act itself, see our EU AI Act enforcement tracker, and the AI compliance hub for other jurisdictions.

This is not legal advice. The Italian is quoted from the Gazzetta Ufficiale and the English renderings are ours; where the decree is silent, as it is on justified reasons and pending cases, ask Italian counsel.

Sources

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoRun the free assessment

15 enterprises secured · under 38ms p99 · live on your own estate in 72 hours