AI Enters Italy's Corporate Liability Law: What the New Article 25-vicies Actually Covers
On August 4, 2026, Italy's Council of Ministers gave final approval to the decree adding artificial intelligence to the predicate offenses under corporate liability law. Scope, penalties, and what compliance models need to change.
Editor's note: this article is current as of August 18, 2026. As of that date, both decrees have received final approval from the Council of Ministers on August 4, 2026, but have not yet been published in the Official Gazette. Until publication, article numbering and effective dates remain subject to confirmation against the official text. We will review and update this piece once the decree is published.
A National Decree, Not the AI Act, Opens the Door
On August 4, 2026, Italy's Council of Ministers gave final approval to two implementing decrees that complete the national adaptation to Regulation (EU) 2024/1689, the AI Act. One of them, the decree governing the use of artificial intelligence in police activities and introducing related criminal offenses, touches a piece of law companies have known for two decades: Legislative Decree 231/2001, which governs the administrative liability of entities.
Worth being precise here, because the coverage of this decree has produced more than one shortcut in recent weeks. The European regulation does not, on its own, extend liability to companies. That extension comes from a choice made by the Italian legislature, exercised through the delegation contained in Law 132/2025, which instructed the government to specify the criteria for attributing administrative liability to entities for offenses connected to AI systems. The decree approved on August 4, in the version of Government Act No. 418 transmitted to Parliament, executes that delegation by inserting a new article into the catalog of predicate offenses: Article 25-vicies, titled "Offenses committed through the use of artificial intelligence systems." It sits right after Article 25-undevicies, added barely a year earlier by the law on crimes against animals, a catalog that has expanded almost every six months in recent years, with AI now joining it as one more entry.
The text is final from the government's side, pending publication in the Official Gazette. Until that happens, the current wording of Decree 231 remains in force, and no organizational model needs rewriting around an article that has not yet been published. The scope, however, is now settled. Worth knowing before it becomes urgent.
On what was already binding from August 2, 2026 independently of this decree, the exact scope of the AI Act's obligations is mapped out in AI Act August 2, 2026: What Is Actually Binding.
Two Offenses, a Narrow Perimeter
Article 25-vicies does not create blanket liability for any AI Act violation a company might commit. It ties the entity to two specific offenses, both of recent origin.
The first is Article 437-bis of the Criminal Code, "Failure to adopt safety measures in AI systems and unlawful alteration of systems," introduced by the same decree. The second is Article 612-quater, "Unlawful dissemination of content generated or altered through AI systems," the deepfake provision, which punishes anyone who distributes falsified images, videos, or voices without consent when they are capable of deceiving about their authenticity and cause unjust harm. This second offense has existed since 2025, introduced directly by Law 132. What changes now is that it also enters the catalog of offenses that can trigger liability for the entity, when committed in its interest or to its advantage.
The penalties are calibrated differently for the two offenses. For 437-bis, the monetary sanction ranges from 600 to 1,000 quote, the unit Italian law uses to scale corporate fines to the offense and the company's financial capacity. For 612-quater, it ranges from 200 to 700 quote. Both carry the possibility of disqualifying sanctions, though not the full range available under Decree 231: the text applies only the suspension or revocation of authorizations and licenses, a ban on contracting with public administration, exclusion from grants and financing, and a ban on advertising goods or services. Left out is the total suspension of business activity, the harshest sanction on the books. A choice that says something about the proportionality the legislature wanted to preserve, at least in this first version of the text.
Three Paragraphs, Three Different Conducts
Reading Article 437-bis carefully matters to avoid two opposite mistakes: underestimating it, on the assumption it only concerns AI developers, or overestimating it, fearing that any malfunction becomes a crime.
The first paragraph punishes anyone who, in the design, training, production, market placement, or professional use of a high-risk AI system, fails to adopt technical or human oversight measures suited to preventing alterations or malfunctions, when concrete danger to life, public or individual safety, or state security results. It is a special-subject offense: it applies to those occupying a position in the AI value chain as defined by the AI Act, not to anyone in a company who happens to use an intelligent tool. The second paragraph is a standalone offense, covering anyone who alters the functioning of a system without holding lawful control over it. The third introduces the negligent form, with the penalty reduced by one third to one sixth and anchored to gross negligence rather than any technical deviation, an explicit safeguard against turning every algorithmic imperfection into a criminal offense, in a field where technical standards move faster than case law.
The filter that makes all of this operational is concrete danger. What matters is whether a missing safety protocol actually produced, or was capable of producing, a real risk to interests of primary rank, not the formal absence of a document on file. It shifts the weight from form to substance, and in practice it will make the quality of human oversight actually exercised day to day the decisive factor, not its description in a compliance binder.
Which framework does your company actually need?
AI Rating measures maturity across the four areas of the model and shows where to start, with priorities and estimated effort.
Start your AI RatingFrom the Offense to the Entity: What Triggers Liability
For a company's liability to be triggered, Decree 231 requires two further conditions, common to every offense in the catalog: that the crime was committed in the entity's interest or to its advantage by someone in a senior position or a subordinate, and that the organization fails to prove it had adopted and effectively implemented a model suited to preventing it.
This is where the issue stops being purely criminal and becomes organizational. Organizational fault, the standard Italian judges use to assess whether a company's compliance model was genuinely adequate, is a concept as old as the decree itself. What changes is its scope of application, which now reaches the choices made upstream on the AI systems a company deploys: how they were selected, on what criteria configured, with what continuity monitored, with what rigor documented.
The exemption remains available, as for every other predicate offense: a compliance model adopted before the fact, a supervisory body with genuinely autonomous powers of initiative and control, a disciplinary system that sanctions internal violations. For that model to hold up in court, though, it needs to show it specifically anticipated algorithmic risk, rather than treating it as a minor variant of generic IT risk.
A Compliance Model Does Not Get Updated With a Paragraph
Adding a section on artificial intelligence to an existing compliance model, without touching anything else, is unlikely to survive serious judicial scrutiny.
Mapping comes first: which AI systems are in use, where, at what risk level under the AI Act's classification, and at what point in the value chain the company sits, as provider, importer, or professional user. That map needs to be cross-referenced against the sensitive processes already identified in the 231 model, because a high-risk AI system embedded in a process already flagged as exposed multiplies the attention required rather than simply adding to it. Accountability needs to be real, not just documented: who decides to adopt a system, who configures it, who monitors it, who intervenes when something goes wrong, with verifiable rather than declared autonomy. Evidence, in turn, needs to be preserved over time: logs of automated decisions, traces of human interventions, records of anomalies detected, the kind of material that, in the event of an investigation, allows anyone to reconstruct what happened and who did what.
The practical steps on the AI Act's general obligations, a useful starting point before touching the 231 model, are set out in AI Act, 2 August 2026: what actually kicks in and the actions to take now.
One Reform Inside Another
One element deserves separate attention, because it risks getting folded into the rest. On that same August 4, 2026, in the same meeting, the Council of Ministers also approved a bill, not a decree, for a deeper reform of Decree 231/2001 itself. It touches issues such as the statute of limitations for the administrative offense and the burden of proof in negligence-based offenses, matters that have nothing to do with artificial intelligence but will affect the same regulatory framework. That bill still needs to be presented to Parliament and go through the full legislative process, on a timeline necessarily longer than that of a decree implementing a delegation already voted into law.
The two reforms run on different tracks, at different speeds, but they will end up touching the same text almost at the same time. For anyone tracking regulatory change, keeping them separate makes the difference between knowing what changes now and what might change months from now.
What ties both together has not changed in twenty years: an organization answers for how it chose to organize itself, not for the error in isolation. Artificial intelligence does not shift that principle. It only makes the scope of its application more explicit, and the margin narrower for those who had not yet taken it seriously.
Primary sources: Council of Ministers, press releases No. 177 (June 10, 2026) and August 4, 2026 (governo.it); Government Act No. 418, XIX Legislature (Italian Senate); Law No. 132 of September 23, 2025; Legislative Decree No. 231 of June 8, 2001; Regulation (EU) 2024/1689 (AI Act). Decree text not yet published in the Official Gazette as of the writing date (August 18, 2026): verify final numbering against the published text.