Skip to content
AI Exposure Scan under Italian Law 132/2025 | BCAUN.IT

Home/Services/AI Exposure Scan

S2 · Law 132/2025 & AI Act · Diagnostic

Italy has its own AI law. Does your business comply?

Law 132/2025 has applied since 10 October 2025 — the first national artificial intelligence statute in the European Union, layered on top of the AI Act. Almost no business operating in Italy has been assessed against it. This tells you which obligations attach to yours, and which of them you currently fail.

Fee€5,000–8,000
Turnaround7 business days
Signed byItalian qualified counsel
DeliverableExposure report and obligations register

What the law actually requires

Not a copy of the AI Act. A national layer with its own duties.

Italy did not wait. Law 132/2025 was adopted on 23 September 2025 and entered into force on 10 October 2025, making Italy the first member state with a domestic AI statute sitting alongside Regulation 2024/1689. It governs the use of artificial intelligence in the workplace, in healthcare, in scientific research and in the regulated professions, and it created a criminal offence for the unlawful dissemination of AI-generated or altered content, punishable by one to five years.

Two legislative decrees completing the framework were approved preliminarily by the Council of Ministers on 10 June 2026 and remain subject to change. The first sets governance and sanctions; the second covers civil and criminal liability. We tell you which findings bite today and which arrive with the decrees, because that distinction decides what you fix first.

In force today

Duties that already apply

  • Employers must inform employees where AI is used, and disclose the system's logic, data parameters, accuracy metrics and human oversight arrangements
  • Healthcare: patients must be told when AI supports a decision, and the clinician retains the decision
  • Research: pseudonymised personal data may be reused for research subject to prior notification of the data protection authority, with a thirty-day review period
  • Criminal liability for unlawful dissemination of AI-generated or altered content
  • A national observatory monitors the effects of AI in the workplace
Draft decrees · 10 June 2026

What is coming, in draft

  • AgID as the national notifying authority; ACN for market surveillance and as single point of contact
  • Banca d'Italia, CONSOB, IVASS and the data protection authority keep their sectors
  • A regulatory sandbox operated jointly by AgID and ACN
  • Sanctions up to €35 million or 7% of worldwide turnover for prohibited practices
  • No employment decision may rest on automated processing alone; a human decision-maker is required, and dismissals in breach are void

The finding that moves people

A dismissal in breach is not a fine. It is void.

Most regulatory exposure is financial and can be provisioned. This one is not. Under the draft decree, an employment decision that rests on automated processing alone is defective, and a dismissal made that way is void — which means reinstatement, back pay and a live employment dispute, not a line in the accounts.

The systems that create this exposure are rarely called AI internally. Applicant ranking, absence and shift scheduling, performance scoring, productivity monitoring and automated flagging all qualify, and most were bought as ordinary HR software.

Whatever else a client defers after this scan, we advise that this workstream is not one of them.

Who needs one

Six situations, and only one of them is a deal.

Unlike our screening work, this does not require a transaction. A business already operating in Italy is already in scope.

Case 01

You employ people in Italy and use AI anywhere in HR

Recruitment, scheduling, performance or monitoring. The workplace disclosure duties apply now, and the employment-decision rule is coming.

Case 02

A foreign group deploying a global tool locally

A system procured centrally and rolled out to the Italian entity carries Italian obligations that the group's own compliance review will not have considered.

Case 03

Healthcare, finance or insurance

Each has its own overlay, and its own supervisor keeping jurisdiction alongside AgID and ACN.

Case 04

You are about to buy an Italian business

Then this is one half of an entry clearance, and it should be produced on the same facts as the screening.

Case 05

Your board has asked what the AI Act means for Italy

And the honest answer is that the AI Act is only part of it. This gives them the Italian-specific answer in writing.

Case 06

You are preparing to raise or to sell

A documented AI position is becoming a standard diligence request. Producing it under pressure is more expensive than producing it now.

What we need from you

The inventory is the hard part, and it is yours.

Almost every scan finds systems the client did not list, because they were bought as scheduling, scoring or workflow software. We ask about function rather than about labels, which surfaces most of them.

The seven-day clock starts when the inventory is complete. We will tell you on day one if it plainly is not.

01

Systems that rank, score or sort people

Applicants, employees, customers, patients or counterparties — however the vendor describes the product.

02

Systems that allocate or schedule

Shifts, routes, workloads, cases and appointments.

03

Systems that generate content

Text, images, audio or video used externally, and where a human reviews before publication.

04

Where each is used, and who decides

The use case determines the duty; who signs off determines whether the human-decision requirement is met.

05

Vendor documentation

Model cards, technical files, DPAs and the contractual allocation of responsibility.

06

Employee information notices

What staff were told, in what document, and when — as opposed to what the policy says.

07

Headcount and entity structure in Italy

Who employs the people the systems touch, and under which entity.

08

Sector authorisations

Any licence or supervision that brings a sectoral regulator into the picture.

The seven days

From inventory to a signed position.

The order matters: classification decides which duties attach, and only then is it worth testing whether they are met. Assessing compliance against the wrong tier is the commonest way an AI review wastes a client's money.

Day 1

Conflicts and inventory review

Conflicts cleared, then the inventory tested for what is missing from it. Function-based questions rather than a request to list your AI.

Days 2–3

Classification

Each system placed under the AI Act risk tiers and, separately, under the sector rules of Law 132/2025. The two do not map onto one another.

Day 4

Workplace and employment testing

Whether employees were actually informed, whether logic, data parameters, accuracy metrics and oversight were disclosed, and whether a human decision-maker is genuinely in the loop.

Day 5

Sector overlay and supervision

Where health, finance or insurance rules apply, and which authority would come first — AgID, ACN, or the sectoral regulator.

Day 6

Gap ranking

Findings ordered by severity and, separately, by enforceability date: in force today, or arriving with the decrees.

Day 7

Review, signature, delivery

Reviewed and signed by Italian qualified counsel, delivered with a call to walk your team through the register.

What you receive

A report, and a register you keep using.

The report is read once. The register is the artefact that survives — the document you hand to an auditor, a buyer or a regulator, and the thing an ongoing retainer updates as the decrees land.

AI Exposure Report and Obligations Register Signed · PDF report · register as a working file
§ 1

Conclusion

Where the business stands in one page: how many systems are in scope, how many obligations are unmet, and which three things to do first.

§ 2

System inventory as assessed

Every system we were shown, plus the ones the review surfaced, with what each does and who it touches.

§ 3

Classification

Each system under the AI Act tiers and under Law 132/2025, with the reasoning — not an assertion of a risk level.

§ 4

Obligations and gaps

What attaches to each system, whether it is met, and what the evidence is. Ranked by severity and by enforceability date.

§ 5

The employment finding

Stated separately, because the consequence of getting it wrong is a void dismissal rather than a penalty.

§ 6

Remediation plan

Actions with named owners and dates, ordered so that the enforceable-today items come first.

Annex

Obligations register

A versioned working file: every obligation, its status, its owner and the evidence held. Built to be maintained rather than filed.

Fair questions

What clients ask first.

We already did AI Act readiness at group level.

Useful, and it covers part of this. What a group review will not have covered is the Italian layer: the workplace disclosure duties in their Italian form, the employment-decision rule, the Italian supervisory split between AgID, ACN and the sectoral regulators, and the criminal provision on generated content.

We are happy to work from your existing classification rather than redo it, which shortens the engagement and reduces the fee.

We do not use AI.

Almost every business that says this uses at least one system that qualifies. The question we ask is not whether you use AI, but whether anything ranks, scores, sorts, allocates or generates. Applicant tracking, shift optimisation, fraud flagging and productivity dashboards are the usual finds.

The decrees are still in draft. Why not wait?

Because the statute has been in force since October 2025 and its workplace duties do not depend on the decrees. Waiting also means doing the inventory under time pressure once penalties are live rather than at your own pace now. We separate the two categories explicitly so you can defer the second with your eyes open.

Is this a technical audit?

No, and we say so plainly. We classify systems and identify the obligations that attach, working with a technical reviewer where classification requires it. We do not test models for bias, we do not evaluate performance, and we are not a conformity assessment body. Where that work is needed, we say so and introduce specialists.

Fee and terms

Fixed after scoping. Scaled to the inventory.

The range reflects how many systems are in scope and how regulated the sector is. Five systems in a services business sits at the bottom; thirty systems in an insurer, with a sectoral overlay, sits at the top. We quote after a short scoping call and confirm in writing before work begins.

What is included

Classification, obligations mapping, testing against the workplace and employment rules, the ranked gap list, the remediation plan, the register, Italian counsel signature and a call with your team.

What is not

Remediation itself, which is a separate engagement. Model testing and bias auditing. Conformity assessment. GDPR review beyond the interface with AI. Software selection.

Keeping it current

The framework is half-built. The AI regulatory retainer maintains the register against the decrees as they are finally adopted, and converts to an annual review once the framework settles.

Questions

Before you engage.

Does Law 132/2025 apply to us if our company is not Italian?

It applies to the use of AI in Italy. A foreign group employing people in Italy, serving Italian patients or customers, or operating an Italian entity is within scope for those activities, whoever owns the company and wherever the system was procured.

How does this interact with the EU AI Act?

The AI Act sets the horizontal framework; Law 132/2025 adds Italian rules on top for the workplace, healthcare, research and the professions, and allocates supervision to Italian authorities. Compliance with one does not establish compliance with the other, which is why the report classifies each system under both.

What happens if an authority asks before we have done this?

You will be asked for the same things the register contains: what systems you run, how they are classified, what employees were told and who makes the decisions. Assembling that under a deadline is the expensive version of this engagement.

Can you work from our existing AI inventory?

Yes, and it shortens the engagement. We will still test it for omissions, because the systems most often missing are the ones nobody classified as AI when the inventory was built.

Is the register something we can maintain ourselves?

Yes. It is delivered as a working file with owners and evidence fields, and it is designed to be updated by your team. The retainer exists for clients who would rather the tracking of legal changes stayed with us.

Request a scan

Find out what Italy requires of your AI.

Tell us what your business does in Italy, roughly how many systems rank, score, allocate or generate, and whether you employ people here. We confirm scope and fee within one business day.

ConflictsChecked before facts are discussed in detail

Fees shown are indicative ranges for engagements of typical scope, confirmed in writing before work begins; they are not a binding quotation. This page is general information about Law 132/2025 on artificial intelligence and Regulation (EU) 2024/1689. It is not legal advice, it does not create a lawyer–client relationship, and it must not be relied on for any decision. Descriptions of implementing decrees refer to measures approved preliminarily by the Council of Ministers on 10 June 2026 that remain subject to change before final adoption. Legal positions are issued only under engagement and are signed by Italian qualified counsel.