Share This Article
AI criminal liability is no longer a question of how much a fine would cost, it is a question of who signs off on a system and what happens to that person, and to the company, if the system causes harm.
Italy has now answered that question, and the answer travels beyond its borders. On 15 September 2026, Italy has adopted a legislative decree adapting Italian law to the AI Act, completing the delegation contained in Law No. 132/2025 introducing provisions that already led to major discussions. In particular:
- A new offence entered the Criminal Code, Article 437-bis, punishing the omission of safety measures in high-risk AI systems, and
- That offence simultaneously became a trigger for corporate criminal liability, entering the catalogue of predicate offences under Legislative Decree 231/2001 through a dedicated new article devoted to crimes committed with the use of AI systems.
If your organisation operates in Italy, sells into Italy or has an Italian subsidiary or a branch, this concerns you, because the exposure follows the conduct and the place where the offence is committed rather than the nationality of the parent company, and Italian corporate criminal proceedings routinely reach entities whose decision makers sit somewhere else entirely.
Why AI criminal liability changes the decision
Administrative fines under the AI Act are serious and they are budgeted for, because a fine is ultimately a cost that the company absorbs, whereas AI criminal liability is faced by a person and no budget line covers it.
That difference reaches the approval stage of every AI project. When the downside was monetary, governance could be weighed against expected benefits and it usually lost the comparison, while now that the downside includes personal exposure for the people who approved the deployment, the question is no longer how much this could cost but whether the person who authorised the system can show what they did before authorising it.
In the incidents I handle, that evidence either exists or does not, and it is never created afterwards.
What Article 437-bis punishes
The offence covers whoever omits the technical safety measures required to prevent malfunctions or alterations, or omits human oversight measures, across the design, training, production, placing on the market or professional use of high-risk AI systems.
Liability is not triggered by the omission alone, because the provision requires what Italian criminal law calls concrete danger, meaning a real and demonstrable risk to a protected interest in the specific circumstances rather than an abstract possibility that harm might occur.
The penalties then follow the interest at stake, running from one to five years of imprisonment where life or individual safety is exposed and from two to eight years where the danger reaches public safety or the security of the State, while a second limb of the provision deals with outside interference, punishing whoever, remaining external to the system lifecycle, alters its functioning, with two to six years in the base case and three to ten years in the aggravated ones.
Where the omissive conduct is committed with gross negligence the penalty is reduced by between one third and one sixth, on the model of Article 590-sexies of the Criminal Code, which governs negligent liability for death or personal injury in healthcare, the intention being to confine criminal relevance to macroscopic departures from diligence in a field that is changing very quickly and to leave ordinary technical error outside the perimeter.
In the scenarios listed above, if the crime is challenged, the individual(s) within the company responsible for the decisions that led to the violation will be personally liable and might be convicted. But there is no just a personal liability, as the legislative decree provides a corporate criminal liability.
How corporate criminal liability works in Italy
For readers outside Italy this is where the analysis stops resembling most other European systems, so the mechanics are worth setting out.
Legislative Decree 231/2001 established a regime under which a company is sanctioned directly when a specified offence is committed by its senior managers or its employees in the interest or to the advantage of the company, and only offences included in a defined statutory list, known as predicate offences, can trigger it, which is why adding an offence to that list is a significant legislative act and why what has just happened to AI matters.
Two features deserve attention from anyone used to a different system:
- The sanction is imposed on the entity itself, in its own proceedings, alongside any case brought against the individuals involved, and
- The company has a genuine defence rather than mere mitigation where it can show that it had adopted and effectively implemented an organisational, management and control model designed to prevent offences of that kind, overseen by an independent supervisory body.
The compliance model referred above shall not be confused with the ethical code of conduct that many companies already have. It is a control framework that needs to be tailored on Italian law. Also, if the model that does not address AI risk cannot function as a defence against an AI predicate offence.
On sanctions, the new provision applies a monetary penalty of between six hundred and one thousand units for Article 437-bis and between two hundred and seven hundred units for the deepfake offence under Article 612-quater introduced by Law 132/2025, and since Italian corporate sanctions are expressed in units rather than in euro, with the court setting the monetary value of each unit within a statutory range according to the financial condition of the entity, the same number of units produces very different amounts for a small supplier and for a multinational, reaching well above one million euro at the upper end.
Interdictive sanctions apply as well and in practice they hurt considerably more than the money, since they include the suspension or revocation of authorisations, the prohibition on contracting with the public administration, the exclusion from grants and financing and the prohibition on advertising goods or services, while interdiction from carrying on the business activity was left out on proportionality grounds, which is the one piece of good news in the package.
The regime of civil liability for AI related conducts also changes
The same decree provides that
- In case of claims for damages related to AI related activities, the court can issue a disclosure order requiring “the other party or the third party in possession of such evidence to produce the specifically relevant evidence pertaining to the operation of the artificial intelligence system, when the petitioner presents facts and evidence sufficient to establish a prima facie case for the claim, including with regard to the connection between the result produced by the artificial intelligence system and the alleged damage” – This disclosure obligation appears to go beyond what already provided under the EU AI Act and courts might adopt a broad interpretation extending the obligation to developers of AI systems;
- When the damage results from a breach of one or more obligations set forth in the EU AI Act, “a causal link between the breach and the damage is presumed, unless proven otherwise” – There is a reversal of the burden of proof obliging the defendant to prove to have properly acted, rather than the opposite scenario which is what ordinarily happens; and
- In case of claims for damages connected to the usage of AI, an injured party can bring a direct claim for damages against the liability insurer of the person allegedly responsible for the damage, within the limits of the insurance coverage – This provision gives an extremely powerful tool in the hands of claimants.
Why deployers are inside the perimeter, not outside it
The conduct covered by Article 437-bis and the potential damage claims run across design, training, production, placing on the market and professional use, and that list is not accidental because it tracks the value chain of the EU AI Act from provider through to deployer and distributor, with the consequence that AI criminal liability, and the corporate exposure that follows from it, reaches every company that professionally uses high-risk AI systems developed by somebody else.
Most organisations I speak to assume that criminal exposure for AI belongs to whoever built the model, which is not the case, because if you deploy a high-risk system in your operations the duty to maintain safety measures and human oversight is yours and remains yours for as long as the system runs, and buying that system from a reputable vendor moves nothing at all.
One consequence deserves attention on the procurement side, since if your exposure depends on measures that only the provider can implement and on information that only the provider holds, then your contracts need to secure both, and most AI supply agreements signed in the last two years do neither.
What changes in case of AI agents
A recommendation engine proposes, whereas an agent books, negotiates, executes and decides, increasingly without a human approving each step.
Read Article 437-bis with that shift in mind and the exposure becomes clearer, because the offence is built around two elements that agents complicate, the first being the adequacy of the technical measures preventing malfunction and the second being human oversight, which the provision treats as an autonomous duty whose omission is punishable in itself, so that an agent operating with wide autonomy and no meaningful oversight point is, in the terms of this provision, the paradigm case.
The investigative consequence follows naturally, because the chain between a management decision and a harmful outcome becomes longer and more autonomous, and the question of who authorised what stops being an organisational detail and becomes the centre of the case. If an agent takes an action creating concrete danger, the first requests will concern who decided to deploy it, what testing was performed on its impact, what limits constrained what it could do, and who was monitoring it when the situation deteriorated.
I advise a growing number of organisations that are introducing AI agents into their operations and in many of them none of those four questions has a documented answer, because systems reach production without prior impact testing, without guardrails and without any governance model capable of monitoring how they behave over time, which under a regime of administrative fines was a commercial risk and under a regime of AI criminal liability is a different order of decision, usually one that nobody in the organisation has consciously taken.
The interest or advantage test, and where it points
Corporate liability requires that the offence was committed in the interest or to the advantage of the company, and that connecting factor, which prosecutors have to establish, is what links an individual’s conduct to the entity.
On this particular offence the advantage is easy to identify and that is precisely the problem, because it consists of the saving on safety measures, meaning the controls not implemented, the testing not performed, the oversight function not staffed and the monitoring never built.
The structure is uncomfortable, because the same organisational failure risks being counted twice, once in the conduct itself and once again in the organisational fault that founds corporate liability, and Italian commentators have flagged the point alongside a textual overlap in the first paragraph where public safety appears in both the base and the aggravated bands, neither of which was resolved at the parliamentary stage and both of which will be argued.
For a board the practical reading is simpler, since any decision to defer AI safety spending now produces a documentary trail pointing directly at the advantage element of a corporate criminal case.
One complication worth holding in mind
The offence attaches to high-risk AI systems and the European framework for high-risk systems has just moved, because the Digital Omnibus, Regulation (EU) 2026/1744 of 8 July 2026 published on 24 July, postpones the application of the high-risk provisions while leaving the rest of the AI Act in place.
The tempting conclusion is that there is time, but the safer reading is that the classification exercise cannot wait, because a company that has not established which of its systems are high-risk cannot know which of them sit inside Article 437-bis and will not be able to show, later on, that it ever looked.
What to put in place
None of the protective measures are exotic and most of them make the AI project work better in any event:
- Map the AI systems in use and classify them, since inventories are usually the missing piece, particularly for AI embedded in third party HR, CRM, security and procurement software and for generative tools that staff adopted on their own initiative;
- Test the impact before the system goes live and keep the assessment, covering what the system can do, what can go wrong and who could be harmed, because the value of that document lies not in the analysis itself but in the proof that the analysis happened.
- Build the human oversight function and give it both a name and the authority to stop the system, since the provision treats missing oversight as punishable conduct in its own right, which makes this the single measure with the clearest link to the offence.
- Set the boundary between autonomy and authorisation in writing, defining what an agent may do alone and what requires a human decision, because systems inherit the limits that somebody defined for them and where nobody defined any, the limits are whatever the model happens to produce.
- Fix the supply chain contracts on security measures, oversight support, incident information, audit rights and cooperation in a proceeding, because your exposure depends on things that your provider controls.
- Update the 231 compliance model that operates as a defence, which for groups with Italian operations means revisiting the local organisational model rather than the global policy suite, since the defence depends on the Italian document and on evidence that it was actually implemented and supervised.
Organisations that want to understand where they stand on AI criminal liability usually start with an assessment of the AI systems in use and of the governance around them, which is a defined exercise with a defined scope and costs a fraction of what it costs to reconstruct the same information under pressure.
On a similar issue, you can read the following article “AI Act Investigations: How to Handle the First Information Requests“.

