Pulsantiera di navigazione Home Page
Pagina Facebook Pagina Linkedin Canale Youtube Italian version
News
Legal news

INFORMATION TECHNOLOGY

Data Protection Authority; favourable opinion on the draft legislative decree aligning Italian legislation with the AI Act.

The Data Protection Authority has issued a favourable opinion, subject to conditions and observations, on the draft legislative decree intended to bring Italian law into line with the AI Act regarding competent authorities, market surveillance, testing and training. The opinion, No. 532 of 14 July 2026, concerns Government Bill No. 421, which was provisionally approved by the Council of Ministers on 10 June 2026 and subsequently submitted to Parliament: the text therefore does not yet constitute the final legislative decree.

The draft identifies AgID and the National Cybersecurity Agency (ACN) as the national authorities for artificial intelligence. AgID will act as the notifying authority for bodies responsible for conformity assessments, whilst the ACN will assume the general role of market supervisory authority.

Specific powers are assigned to the Bank of Italy, Consob and IVASS in relation to AI systems used in the respective financial, banking, credit and insurance sectors. The Data Protection Authority, on the other hand, will act as the supervisory authority for high-risk systems used in the particularly sensitive areas specified in Article 74(8) of the AI Act, including law enforcement, border and immigration management, the administration of justice and democratic processes.

The framework also regulates the Italian AI Sandbox, jointly managed by AgID and ACN, where providers and developers will be able to test artificial intelligence systems in a controlled environment. Measures are also provided for training in schools, universities and vocational courses, with a particular focus on the responsible use of AI, the protection of personal data, security and non-discrimination.

Whilst considering the framework to be, on the whole, consistent with the AI Act and with Italian Law No. 132/2025, the Data Protection Authority has requested certain additions. Firstly, the Authority requests that the Data Protection Authority, and not just AgID, ACN and the financial authorities, be expressly granted the power to adopt guidelines, recommendations and best practices. This power is deemed necessary to ensure the uniform application of the rules in sectors where the use of AI directly affects data protection and other fundamental rights.

The decree should also specify that sanction proceedings falling within the Data Protection Authority’s remit will be governed by Article 166 of the Privacy Code, whilst also clarifying the allocation of proceeds from sanctions.

Further action is required regarding conformity assessment. Since the AI Act assigns the Data Protection Authority specific functions in relation to high-risk systems falling within its remit, the legislator will need to clarify whether the State will assume direct responsibility for the relevant assessment activities or whether the different insurance regime provided for by the European Regulation will apply.

The draft entrusts the management of the Italian Sandbox to AgID and ACN, but does not expressly provide for the Data Protection Authority’s participation in projects involving the processing of personal data. According to the Authority, this omission must be rectified: Article 57(10) of the AI Act requires the involvement of data protection authorities when activities carried out within a sandbox include processing subject to the GDPR. Consultation with the Data Protection Authority must therefore take place right from the design stage of the trial and not only after any issues have arisen.

Particular attention is paid to the use of artificial intelligence in employment relationships. The framework stipulates that decisions on the establishment, modification or termination of an employment relationship may not be taken solely through automated processing, and that the final decision must rest with a person possessing effective autonomy.

The Data Protection Authority proposes extending this safeguard to include assessment decisions likely to have a significant impact on the employment relationship, such as those relating to performance measurement, the awarding of bonuses, job classification and career progression.

Employers must also inform employees in advance, respect their dignity, confidentiality and the principle of non-discrimination, and provide a comprehensible explanation of their decisions, specifying the role played by the AI system and the main parameters used.

Stampa la pagina