Share This Article
AI criminal liability is no longer a question of how much a fine would cost, it is a question of who signs off on a system and what happens to that person, and to the company, if the system causes harm.
Italy has now answered that question, and the answer travels beyond its borders. On 4 August 2026 the Council of Ministers gave final approval to the two legislative decrees adapting Italian law to the AI Act, completing the delegation contained in Law No. 132/2025, and I covered the wider package in this article. What deserves separate treatment is the part that reaches individuals and companies directly, because it changes both how a deployment decision should be taken and who carries the consequences of taking it.
Two things happened at the same moment. A new offence entered the Criminal Code, Article 437-bis, punishing the omission of safety measures in high-risk AI systems, and that offence simultaneously became a trigger for corporate criminal liability, entering the catalogue of predicate offences under Legislative Decree 231/2001 through a dedicated new article devoted to crimes committed with the use of AI systems.
If your organisation operates in Italy, sells into Italy or has an Italian subsidiary, this concerns you, because the exposure follows the conduct and the place where the offence is committed rather than the nationality of the parent company, and Italian corporate criminal proceedings routinely reach entities whose decision makers sit somewhere else entirely.
Why AI criminal liability changes the decision
Administrative fines under the AI Act are serious and they are budgeted for, because a fine is ultimately a cost that the company absorbs, whereas AI criminal liability is faced by a person and no budget line covers it.
That difference reaches the approval stage of every AI project. When the downside was monetary, governance could be weighed against expected benefits and it usually lost the comparison, while now that the downside includes personal exposure for the people who approved the deployment, the question is no longer how much this could cost but whether the person who authorised the system can show what they did before authorising it.
In the incidents I handle, that evidence either exists or it does not, and it is never created afterwards.
What Article 437-bis punishes
The offence covers whoever omits the technical safety measures required to prevent malfunctions or alterations, or omits human oversight measures, across the design, training, production, placing on the market or professional use of high-risk AI systems.
Liability is not triggered by the omission alone, because the provision requires what Italian criminal law calls concrete danger, meaning a real and demonstrable risk to a protected interest in the specific circumstances rather than an abstract possibility that harm might occur.
The penalties then follow the interest at stake, running from one to five years of imprisonment where life or individual safety is exposed and from two to eight years where the danger reaches public safety or the security of the State, while a second limb of the provision deals with outside interference, punishing whoever, remaining external to the system lifecycle, alters its functioning, with two to six years in the base case and three to ten years in the aggravated ones.
Where the omissive conduct is committed with gross negligence the penalty is reduced by between one third and one sixth, on the model of Article 590-sexies of the Criminal Code, which governs negligent liability for death or personal injury in healthcare, the intention being to confine criminal relevance to macroscopic departures from diligence in a field that is changing very quickly and to leave ordinary technical error outside the perimeter.
The placement in the Code says more than the text does, because Article 437-bis sits next to Article 437, which for decades has policed the failure to install equipment designed to prevent workplace accidents, so Italian law has effectively decided that failing to secure an AI system belongs to the same family as failing to install a safety guard on a machine, and anyone who has lived through a workplace safety investigation will know what that comparison implies about how these files tend to be built.
How corporate criminal liability works in Italy
For readers outside Italy this is where the analysis stops resembling most other European systems, so the mechanics are worth setting out.
Legislative Decree 231/2001 established a regime under which a company is sanctioned directly when a specified offence is committed by its senior managers or its employees in the interest or to the advantage of the company, and only offences included in a defined statutory list, known as predicate offences, can trigger it, which is why adding an offence to that list is a significant legislative act and why what has just happened to AI matters.
Two features deserve attention from anyone used to a different system. The sanction is imposed on the entity itself, in its own proceedings, alongside any case brought against the individuals involved, and the company has a genuine defence rather than mere mitigation where it can show that it had adopted and effectively implemented an organisational, management and control model designed to prevent offences of that kind, overseen by an independent supervisory body. The practical implication is direct, because a model that does not address AI risk cannot function as a defence against an AI predicate offence.
On sanctions, the new provision applies a monetary penalty of between six hundred and one thousand units for Article 437-bis and between two hundred and seven hundred units for the deepfake offence under Article 612-quater introduced by Law 132/2025, and since Italian corporate sanctions are expressed in units rather than in euro, with the court setting the monetary value of each unit within a statutory range according to the financial condition of the entity, the same number of units produces very different amounts for a small supplier and for a multinational, reaching well above one million euro at the upper end.
Where the legislator positioned the offence tells you more than the numbers do, because the explanatory report accompanying the decree places it in the high band of the catalogue and adopts as its express benchmark the predicate offence covering manslaughter and personal injury caused by breaches of workplace safety rules, which means that AI safety failures have been ranked, quite deliberately, alongside industrial safety failures.
Interdictive sanctions apply as well and in practice they hurt considerably more than the money, since they include the suspension or revocation of authorisations, the prohibition on contracting with the public administration, the exclusion from grants and financing and the prohibition on advertising goods or services, while interdiction from carrying on the business activity was left out on proportionality grounds, which is the one piece of good news in the package.
Why deployers are inside the perimeter, not outside it
This is the point that most companies get wrong when they read the headline.
The conduct covered by Article 437-bis runs across design, training, production, placing on the market and professional use, and that list is not accidental because it tracks the value chain of the EU AI Act from provider through to deployer and distributor, with the consequence that AI criminal liability, and the corporate exposure that follows from it, reaches every company that professionally uses high-risk AI systems developed by somebody else.
Most organisations I speak to assume that criminal exposure for AI belongs to whoever built the model, which is not the case, because if you deploy a high-risk system in your operations the duty to maintain safety measures and human oversight is yours and remains yours for as long as the system runs, and buying that system from a reputable vendor moves nothing at all.
One consequence deserves attention on the procurement side, since if your exposure depends on measures that only the provider can implement and on information that only the provider holds, then your contracts need to secure both, and most AI supply agreements signed in the last two years do neither.
What changes when the system acts on its own
A recommendation engine proposes, whereas an agent books, negotiates, executes and decides, increasingly without a human approving each step.
Read Article 437-bis with that shift in mind and the exposure becomes clearer, because the offence is built around two elements that agents complicate, the first being the adequacy of the technical measures preventing malfunction and the second being human oversight, which the provision treats as an autonomous duty whose omission is punishable in itself, so that an agent operating with wide autonomy and no meaningful oversight point is, in the terms of this provision, the paradigm case.
The investigative consequence follows naturally, because the chain between a management decision and a harmful outcome becomes longer and more autonomous, and the question of who authorised what stops being an organisational detail and becomes the centre of the case. If an agent takes an action creating concrete danger, the first requests will concern who decided to deploy it, what testing was performed on its impact, what limits constrained what it could do, and who was monitoring it when the situation deteriorated.
I advise a growing number of organisations that are introducing agents into their operations and in many of them none of those four questions has a documented answer, because systems reach production without prior impact testing, without guardrails and without any governance model capable of monitoring how they behave over time, which under a regime of administrative fines was a commercial risk and under a regime of AI criminal liability is a different order of decision, usually one that nobody in the organisation has consciously taken.
The interest or advantage test, and where it points
Corporate liability requires that the offence was committed in the interest or to the advantage of the company, and that connecting factor, which prosecutors have to establish, is what links an individual’s conduct to the entity.
On this particular offence the advantage is easy to identify and that is precisely the problem, because it consists of the saving on safety measures, meaning the controls not implemented, the testing not performed, the oversight function not staffed and the monitoring never built.
The structure is uncomfortable, because the same organisational failure risks being counted twice, once in the conduct itself and once again in the organisational fault that founds corporate liability, and Italian commentators have flagged the point alongside a textual overlap in the first paragraph where public safety appears in both the base and the aggravated bands, neither of which was resolved at the parliamentary stage and both of which will be argued.
For a board the practical reading is simpler, since any decision to defer AI safety spending now produces a documentary trail pointing directly at the advantage element of a corporate criminal case.
One complication worth holding in mind
The offence attaches to high-risk AI systems and the European framework for high-risk systems has just moved, because the Digital Omnibus, Regulation (EU) 2026/1744 of 8 July 2026 published on 24 July, postpones the application of the high-risk provisions while leaving the rest of the AI Act in place.
The tempting conclusion is that there is time, but the safer reading is that the classification exercise cannot wait, because a company that has not established which of its systems are high-risk cannot know which of them sit inside Article 437-bis and will not be able to show, later on, that it ever looked.
What to put in place
None of the protective measures are exotic and most of them make the AI project work better in any event.
Map the AI systems in use and classify them, since inventories are usually the missing piece, particularly for AI embedded in third party HR, CRM, security and procurement software and for generative tools that staff adopted on their own initiative.
Test the impact before the system goes live and keep the assessment, covering what the system can do, what can go wrong and who could be harmed, because the value of that document lies not in the analysis itself but in the proof that the analysis happened.
Build the human oversight function and give it both a name and the authority to stop the system, since the provision treats missing oversight as punishable conduct in its own right, which makes this the single measure with the clearest link to the offence.
Set the boundary between autonomy and authorisation in writing, defining what an agent may do alone and what requires a human decision, because systems inherit the limits that somebody defined for them and where nobody defined any, the limits are whatever the model happens to produce.
Fix the supply chain contracts on security measures, oversight support, incident information, audit rights and cooperation in a proceeding, because your exposure depends on things that your provider controls.
Update the compliance model that operates as a defence, which for groups with Italian operations means revisiting the local organisational model rather than the global policy suite, since the defence depends on the Italian document and on evidence that it was actually implemented and supervised.
Organisations that want to understand where they stand on AI criminal liability usually start with an assessment of the AI systems in use and of the governance around them, which is a defined exercise with a defined scope and costs a fraction of what it costs to reconstruct the same information under pressure.

