Italy makes AI safety failures a criminal offense — up to five years, and the company can be liable too
Starting tomorrow, skipping safety measures on a high-risk AI system in Italy stops being a compliance problem and becomes a crime — punishable by prison, for individuals and their companies alike.

Tomorrow, Italy becomes the first European country to put AI governance failures in the criminal code. A new provision, Article 437-bis, makes it a crime to design, train or deploy a high-risk AI system without the safety measures the law demands — and the penalty is prison, not an administrative fine. The instrument that creates it, Legislative Decree No. 160 of 9 September 2026, was published in the Gazzetta Ufficiale No. 214 on 15 September and enters into force on 30 September.
For years, AI regulation meant audits, paperwork and fines — non-compliance priced in like a tax. Rome just changed the register. The provision targets failures to prevent malfunctions and unauthorised alterations in high-risk AI systems, and failures of human oversight, where those failures create a concrete danger to life, physical integrity, public safety or the security of the state.
What the new crime covers#
The decree adapts Italian law to the EU AI Act on two fronts — AI used by police forces, and civil and criminal liability — drawing its authority from Article 24 of Law No. 132 of 23 September 2025, Italy's framework AI statute. It follows a long gestation: preliminary government approval in June 2026, parliamentary scrutiny over the summer, final approval on 4 August, signature by President Sergio Mattarella and countersignature by Prime Minister Giorgia Meloni and six ministers.
Article 12 inserts Article 437-bis into the Criminal Code, headed in the original as the omitted adoption of security measures in AI systems and the unlawful alteration of those systems. It is an omission offence: liability attaches not to what someone did to the model, but to what they failed to do. The first paragraph covers anyone who, during the design, training, production or placing on the market of a high-risk AI system, skips the technical measures suitable to prevent malfunctions or alterations in how it operates — or skips the required human oversight. A fourth paragraph covers the intentional failure by professional users of high-risk systems to adopt oversight measures.
Legal analysis ties the provision to the AI Act itself: the malfunction limb maps to its risk-management duties (Article 9) and accuracy, robustness and cybersecurity requirements (Article 15); the oversight limb tracks the human-oversight obligations of Article 14. A malfunction here is not every misprediction — it is a failure of the system to operate as intended due to defects in data, software or design, like a diagnostic model steering doctors wrong because of a poisoned training set. Alterations mean external interventions that change behaviour: data poisoning, unauthorised retraining, quiet modification of model parameters.

The penalties#
According to analyses of the decree's text, the standard penalty is one to five years' imprisonment where the omission creates a concrete danger to life or to public or individual safety — rising to two to eight years where state security is at stake. Gross negligence is explicitly caught: a third paragraph extends liability to grossly negligent failures, not just deliberate ones.
Tampering gets its own, harsher tier: the second paragraph punishes the unlawful alteration of a high-risk system with two to six years where danger to life or safety follows, and three to ten years where state security is implicated. The provision's highest ceiling attaches to someone who deliberately rewrites how a system behaves — not to an engineer whose safeguards were merely thin. And two limiters keep the offence from swallowing ordinary engineering: criminal liability requires a concrete danger, and negligent conduct counts only when it is gross.
The company can be liable too#
The most consequential line sits outside the Criminal Code. Article 437-bis is added to the catalogue of predicate offences under Legislative Decree No. 231/2001 — Italy's corporate criminal liability framework — via a new Article 25-vicies. An AI safety failure can therefore trigger criminal liability for the company itself: fines of 600 to 1,000 units plus disqualifying sanctions such as bans on business activities.
The exposure is not fenced by nationality. Italian corporate-criminal proceedings routinely reach entities whose decision-makers sit elsewhere: if the conduct — or the danger it created — is in Italy, the offence follows. The same decree also rewrites the civil side, with access-to-evidence mechanisms and a rebuttable presumption of causation for injured parties, while making clear that an AI Act infringement does not automatically establish a right to compensation.

Why this matters#
The EU AI Act left criminal enforcement to the member states. Italy is the first to answer with prison terms — and every other member state now has a template for how far the stick can go. The timing is combustible: the decree enters into force in the same month OpenAI paused training of its most capable models after agents exceeded their instructions, and Florida asked a court to halt OpenAI's training outright. The gap between voluntary safety commitments and enforceable law is closing from both sides at once.
What to watch#
First, enforcement: the first prosecutions will define what “suitable” measures and “concrete danger” mean on frontier systems nobody fully understands. Second, the follow-on effect — whether Germany, France or Spain mirror the criminal approach or Italy stays an outlier. Third, the two-speed backdrop: Brussels' Digital Omnibus, in force since late July, is giving companies breathing room on some AI Act deadlines even as Rome tightens the criminal screws.
Sources
- Oxford Law Blogs — “Failure to Adopt Safety Measures in Artificial Intelligence Systems and Unlawful Alteration of Systems: Italy’s New Article 437-bis of the Criminal Code” (September 2026)
- NicFab Newsletter #39 — “Legislative Decree 160/2026: policing, civil liability and corporate liability” (22 September 2026)
- GamingTechLaw — “AI Criminal Liability in Italy: What Boards Must Know Now” (September 2026)
- LEXIA — “Data & Technology Innovation | September 2026 Insight” (11 September 2026)