---
title: "AI damage claims in Italy: evidence and causation under Legislative Decree 160/2026"
url: https://zerofive.ai/en/blog/compliance/ai-damages-evidence-causation-italy-decree-160-2026
canonical: https://zerofive.ai/en/blog/compliance/ai-damages-evidence-causation-italy-decree-160-2026
language: en
published: 2026-09-16
updated: 2026-09-18
author: "ZeroFive.AI"
tags: Legislative Decree 160/2026, AI civil liability, AI Act, burden of proof, AI documentation, AI insurance
abstract: "Italy's Decree 160/2026 on AI damage claims: disclosure of logs and records, presumed causation, limits of compliance, direct action against insurers."
---

# AI damage claims in Italy: evidence and causation under Legislative Decree 160/2026

**In short.** Italy's Legislative Decree 160/2026, in force from September 30, changes how courts handle claims for damage caused by an artificial intelligence system. A judge can order the disclosure of logs, technical documentation, risk management records, and human oversight parameters, and if those documents are withheld without a justified reason, the facts alleged by the claimant are deemed admitted. When the damage results from a breach of the AI Act, the causal link is presumed, while compliance, even when certified, does not by itself rule out liability. For a company using AI, governance documentation becomes evidence.

On September 15, 2026, Italy's Official Gazette No. 214 published Legislative Decree No. 160 of September 9, 2026, another piece of the national adaptation to Regulation (EU) 2024/1689. The text combines two distant subjects: the use of AI by police forces, which fills the first half, and civil and criminal liability tied to AI systems, which directly concerns businesses.

We cover the criminal side, with the new Article 437-bis of the Criminal Code and Article 25-vicies of Decree 231, in our [updated article on Legislative Decree 231/2001](/en/blog/compliance/italy-decree-231-article-25-vicies-ai). Here we look at Articles 16 to 20, the civil procedure tools available to anyone seeking compensation: five short articles that matter to whoever signs vendor contracts, approves insurance policies, and reports to the board, lawyer or not. ZeroFive is not a law firm, so we describe the text and its organizational consequences and leave interpretation to the courts and legal scholars.

## The scope of the new rules

Article 16 sets two levels. The rules on access to evidence apply to every damages claim, contractual or non-contractual, for harm caused through the use of an AI system, whatever its risk class. The presumption of causation and the rule on compliance apply only when the damage results from a breach of one or more AI Act obligations.

Two parallel regimes remain untouched: compensation under Article 82 of the GDPR, and the upcoming Italian law transposing Directive (EU) 2024/2853 on liability for defective products, which covers software and must be transposed by December 9, 2026. For individuals acting outside their business or profession, the decree adds jurisdiction for the court of their place of residence or domicile, so a consumer can sue close to home, even against a company based elsewhere.

## Disclosure of evidence

Article 17 allows the judge, at the request of the party claiming to have suffered damage, to order the other party or a third party to disclose evidence relating to how the system works. The condition is that the claimant presents facts and elements making the claim plausible, including the link between the system's output and the damage. The text names four categories of documents, all already required by the AI Act.

| Document | AI Act reference | What it lets you reconstruct | Who usually holds it |
|---|---|---|---|
| Automatic logs | Art. 12 | What the system did, when, and on which inputs | Provider; the deployer keeps those under its control (Art. 26) |
| Risk management system | Art. 9 | Which risks were known and how they were addressed | Provider |
| Technical documentation | Art. 11 | How the system was designed, trained, and tested | Provider |
| Human oversight parameters and arrangements | Art. 14 | Who could intervene, with which tools, and in which cases | Provider for the design, deployer for the implementation |

The order must be limited to what is necessary and proportionate, and the judge protects trade secrets and confidential information under Article 121-ter of the Italian Industrial Property Code. A party that fails to disclose without a justified reason faces two consequences of different weight: the judge may draw evidentiary inferences under Article 116 of the Code of Civil Procedure, and when the failure concerns the documents in the table, having weighed all other evidence, the judge treats the facts alleged by the claimant as admitted. A third party that fails to disclose, for instance a vendor holding logs its client cannot access, faces a fine of 1,500 to 10,000 euros.

For a company, this is the provision with the most immediate effect. A log register that does not exist, or that sits with a vendor without access clauses, stops being a gap to fix before the next audit and becomes a fact the court can hold against whoever should have kept it.

## The presumed causal link

Article 18 is a single sentence: when the damage results from the breach of one or more AI Act obligations, the causal link between breach and damage is presumed, unless proven otherwise. The wording is plainly circular, since it already assumes that the damage results from the breach, and courts will decide how much the claimant must prove before the presumption applies. The expected effect is a shift of the burden toward the defendant, who will have to prove a different origin for the damage.

Which AI Act obligations already apply therefore matters. The prohibited practices of Article 5 and the AI literacy duty of Article 4 have applied since February 2, 2025, the obligations on general-purpose AI models since August 2, 2025, and the transparency duties of Article 50 since August 2, 2026. After the Digital Omnibus (Regulation (EU) 2026/1744), the obligations for Annex III high-risk systems apply from December 2, 2027, and those for Annex I from August 2, 2028: from September 30 the presumption works on a narrow perimeter, which widens as the high-risk obligations come into application.

## Compliance as a partial defense

Article 19 states that the system's compliance with AI Act obligations, even when certified through the regulation's conformity assessment procedures, does not in itself exclude the defendant's liability, without prejudice to what the law transposing the defective products directive will provide.

The rule refers to certification under the AI Act, and its logic extends to any voluntary attestation, including an ISO/IEC 42001 certification of the management system. A certificate shows that a set of controls existed on a given date, while a court case turns on how the system behaved in that specific situation, and that proof comes from logs, oversight records, and documented decisions.

## Insurance and direct action

Article 20 concerns the CFO even before the legal department. Anyone planning to sue can ask the allegedly liable party whether it holds a liability insurance policy covering that damage, and the recipient must answer within thirty days, giving the policy details and the insurer's name. The request is not a precondition for suing, but a missing or incomplete answer can be used by the judge as an evidentiary inference.

The injured party then has a direct action against the insurer, within the policy limits, with the liable party joined as a necessary party to the proceedings. The insurer can raise contractual defenses that predate the incident and, after paying, recover from the insured to the extent it could have refused or reduced the payment. A policy that excludes damage caused by automated systems, or ties coverage to controls never put in place, leaves the company uncovered exactly when the claim arrives.

## A hypothetical example

A services company uses a third-party AI system to triage support requests and decide which cases reach a human agent. A customer whose request was closed automatically suffers a financial loss and sues, submitting the messages received and the timeline of events, so the judge orders disclosure of the decision logs and the human oversight arrangements.

Only then does the company discover that the logs stay on the vendor's servers for thirty days, that the contract does not provide for their release in litigation, and that the agents' supervision was never written down. The vendor can be ordered to disclose as a third party, but the company has nothing to produce on human oversight, and on that point the customer's allegations risk being treated as admitted. The example is illustrative, shows the mechanism, and does not describe a real case.

## Checks to run now

- Is there a register of the AI systems in use, with an owner for each and a risk classification under the AI Act?
- For each system, who keeps the logs, for how long, and in what exportable format?
- Do vendor contracts provide access to logs, technical documentation, and risk management records in case of litigation, on timelines compatible with a court order?
- Is human oversight written down, stating who intervenes, on which signals, and with what record of the intervention?
- Do liability policies cover damage caused by AI systems, and with which exclusions or conditions?
- Who in the company answers, within thirty days, a request about the existence of coverage?
- Does the 231 compliance model account for the new Article 25-vicies?

## Next step

Most of the questions above can only be answered after an inventory of systems and a clear picture of the evidence the company actually produces. For the method, start with our guide to the [AI system inventory](/en/blog/compliance/ai-system-inventory-iso-42001) and the one on the [minimum documentation of an AIMS](/en/blog/compliance/aims-minimum-documentation-iso-42001); obligations by role are covered in the [complete EU AI Act guide](/en/blog/compliance/eu-ai-act-complete-guide-obligations-liability-data).

With the [AI Rating](/en/services/ai-rating) we also measure maturity on the AI Risk dimension, which covers compliance, security, and risk governance. To discuss your case, [book an assessment meeting](https://calendly.com/fabiolalli/zerofive) or write to hello@zerofive.ai.

*This article describes the legislative text and its organizational implications and does not constitute legal advice.*

**Sources.** Legislative Decree No. 160 of September 9, 2026, Official Gazette, General Series, No. 214 of September 15, 2026, Articles 16-20; Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744, Articles 4, 5, 9, 11, 12, 14, 26, and 50; Regulation (EU) 2016/679, Article 82; Directive (EU) 2024/2853; Italian Code of Civil Procedure, Article 116; Legislative Decree No. 30 of February 10, 2005, Article 121-ter.
