---
title: "AI Enters Italy's Corporate Liability Law: What the New Article 25-vicies Actually Covers"
url: https://zerofive.ai/en/blog/compliance/italy-decree-231-article-25-vicies-ai
canonical: https://zerofive.ai/en/blog/compliance/italy-decree-231-article-25-vicies-ai
language: en
published: 2026-08-18
updated: 2026-09-18
author: "ZeroFive.AI"
tags: AI Act, Legislative Decree 231/2001, Legislative Decree 160/2026, Article 25-vicies, corporate liability, 231 compliance model, AI governance
abstract: "Article 25-vicies of Italy's Decree 231/2001 after Decree 160/2026: offenses 437-bis and 612-quater, sanctions, timing, and compliance model updates."
---

# AI Enters Italy's Corporate Liability Law: What the New Article 25-vicies Actually Covers

> **Update, September 16, 2026.** The decree was published in Italy's Official Gazette No. 214 of September 15, 2026 as Legislative Decree No. 160 of September 9, 2026, and enters into force on September 30. This article has been reviewed against the official text: numbering and penalties are confirmed, while the description of Article 437-bis has been corrected compared with the August 18 version, which was based on the text approved by the Council of Ministers.

**In short.** The new Article 25-vicies of Legislative Decree 231/2001 makes companies liable for two AI-related offenses: failing to adopt safety and human oversight measures in high-risk AI systems, together with unlawfully altering those systems (Article 437-bis of the Criminal Code), and the unlawful dissemination of deepfakes (Article 612-quater). Monetary sanctions range from 600 to 1,000 quote for the first offense and from 200 to 700 quote for the second, alongside a selection of disqualifying sanctions. For those who use a high-risk system without having developed it, the offense requires that human oversight be omitted intentionally. Updating the 231 compliance model starts from the inventory of AI systems.

## Where the new liability comes from

The extension of corporate liability comes from a choice by the Italian legislature, exercised through the delegation in Article 24 of Law 132/2025, which asked the government to specify how administrative liability applies to entities for offenses tied to AI systems; the European regulation, on its own, does not provide for it. Decree 160/2026, whose first part governs the use of AI by police forces, carries out that delegation in Article 15, which inserts Article 25-vicies into Decree 231 under the heading "Offenses committed through the use of artificial intelligence systems".

The new article follows Article 25-undevicies in a catalog of predicate offenses that has grown almost every six months in recent years, and it brings into the 231 perimeter a risk that many companies had treated only as a technical or data protection issue.

## Two predicate offenses

| Offense | Monetary sanction for the entity | Disqualifying sanctions |
|---|---|---|
| Art. 437-bis Criminal Code, failure to adopt safety measures in AI systems and unlawful alteration of systems | 600 to 1,000 quote | Art. 9(2)(b), (c), (d), (e) |
| Art. 612-quater Criminal Code, unlawful dissemination of content generated or altered with AI systems | 200 to 700 quote | Art. 9(2)(b), (c), (d), (e) |

A quota is the unit Italian law uses to scale corporate fines to the offense and to the company's financial capacity. The disqualifying sanctions referenced are the suspension or revocation of authorizations, licenses, or concessions, a ban on contracting with public administration, exclusion from grants, financing, and subsidies, and a ban on advertising goods or services. Letter (a), the ban on carrying out the business activity, is left out, and it is the harshest sanction in the 231 system.

Article 612-quater, the deepfake provision, has existed since 2025, when Law 132 introduced it, and punishes anyone who distributes falsified images, videos, or voices without consent, capable of deceiving about their authenticity and causing unjust harm. Through Article 25-vicies it also becomes a predicate offense, when committed in the entity's interest or to its advantage.

## The structure of Article 437-bis

Article 437-bis, introduced by Article 12 of the decree, has four paragraphs with different addressees and conducts.

| Paragraph | Who | Conduct | Penalty |
|---|---|---|---|
| First | Anyone, in the design, training, production, and placing on the market of high-risk systems | Fails to adopt the required technical safety measures capable of preventing malfunctions or alterations, or fails to adopt human oversight measures | Imprisonment from 1 to 5 years if danger to life or to public or individual safety results; from 2 to 8 years if the danger concerns state security |
| Second | Anyone, outside the cases of the first paragraph | Alters high-risk AI systems | Imprisonment from 2 to 6 years; from 3 to 10 years if the danger concerns state security, unless the act constitutes a more serious offense |
| Third | Perpetrators of the first paragraph's acts | Same acts committed with gross negligence | Penalty reduced by one third to one sixth |
| Fourth | Professional user of high-risk systems | Intentionally fails to adopt human oversight measures | The penalties of the first paragraph, depending on the type of danger |

The first paragraph targets the chain that builds and markets the system, meaning the position the AI Act assigns to the provider and to upstream actors. The professional user, a figure close to the AI Act's deployer, has a dedicated rule in the fourth paragraph, which requires intentional omission: the gross negligence reduction in the third paragraph refers only to the first paragraph's acts, so no negligent form is provided for someone who uses a system without having developed it.

As drafted, every case requires that the conduct creates a danger to life, to public or individual safety, or to state security. A missing formal step does not, on its own, amount to the offense, which moves attention to human oversight as actually exercised, day by day, more than to its description in documents.

## When the rules bite

The decree is in force from September 30, 2026, yet Article 437-bis refers to the measures "required" for high-risk systems, and under the AI Act, after the Digital Omnibus (Regulation (EU) 2026/1744), those obligations apply from December 2, 2027 for Annex III systems and from August 2, 2028 for Annex I systems. How the two dates interact is a question criminal lawyers and the courts will settle.

For corporate organization the conclusion hardly changes. A 231 model describes safeguards that must exist before the risk materializes, and building them across a portfolio of AI systems takes months of work on inventory, contracts, and procedures.

## The mechanism that triggers corporate liability

For a company's liability to arise, the two conditions that apply across the whole 231 catalog must be met: the offense is committed in the entity's interest or to its advantage by a senior manager or a subordinate, and the entity fails to prove it adopted and effectively implemented a model suited to preventing it.

Organizational fault is a standard as old as the decree itself. What changes is its object, which now includes the upstream choices on AI systems, such as how they were selected, on what criteria they were configured, how continuously they were monitored, and how rigorously they were documented. The exemption remains available through the usual safeguards, a model adopted before the fact, a supervisory body with autonomous powers, and a disciplinary system, provided the model addresses algorithmic risk specifically rather than as a variant of generic IT risk.

## Updating the 231 model

| Activity | Output | Led by |
|---|---|---|
| AI system inventory | List with purpose, AI Act risk class, and the company's role in the value chain | Compliance with IT and process owners |
| Cross-check with 231 sensitive processes | Map of the points where a high-risk system touches an already exposed process | Compliance and supervisory body |
| Assignment of responsibilities | Names for adoption, configuration, oversight, and incident handling | Senior management |
| Human oversight procedures | Written rules on who intervenes, on which signals, and with what record | Process owner |
| Evidence retention | Logs, human interventions, and anomalies, with defined retention periods | IT and vendors, through contract clauses |
| Targeted training | Content differentiated by role | HR and compliance |

The evidence in the table also matters outside the criminal perimeter. In Articles 16 to 20, the same decree makes logs and oversight records subject to disclosure orders in civil claims for AI-related damage, with heavy consequences for those who fail to produce them, as we explain in our article on [evidence and causation](/en/blog/compliance/ai-damages-evidence-causation-italy-decree-160-2026).

## A parallel reform of Decree 231

At the same August 4, 2026 meeting, the Council of Ministers also approved a bill for a broader reform of Decree 231, covering among other things the statute of limitations for the administrative offense and the burden of proof in negligence-based offenses. That bill still has to go through the full parliamentary process, on a longer timeline than an implementing decree, and regulatory monitoring should keep the two reforms apart: Article 25-vicies is law from September 30, while the bill is still a proposal.

## Next step

Updating the 231 model starts from the inventory, because without knowing which systems are in use and in what role, none of the activities in the table has an object. The method is in our guide to the [AI system inventory](/en/blog/compliance/ai-system-inventory-iso-42001), and the AI Act obligations already binding are mapped in [AI Act August 2, 2026: what is actually binding](/en/blog/compliance/ai-act-august-2-2026-what-is-binding).

With the [AI Rating](/en/services/ai-rating) we also measure maturity on the AI Risk dimension, which covers compliance, security, and risk governance. To discuss your compliance model, [book an assessment meeting](https://calendly.com/fabiolalli/zerofive) or write to hello@zerofive.ai.

*This article describes the legislative text and its organizational implications and does not constitute legal advice.*

**Sources.** Legislative Decree No. 160 of September 9, 2026, Official Gazette, General Series, No. 214 of September 15, 2026, Articles 12 and 15; Legislative Decree No. 231 of June 8, 2001, Articles 9 and 25-vicies; Law No. 132 of September 23, 2025, Article 24; Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; Council of Ministers, press release of August 4, 2026.
