Skip to content

Blog

D.Lgs. 160/2026 on artificial intelligence: what changes in civil and criminal liability

Simone Checcoli

D.Lgs. 160/2026 brings Italian law into line with the AI Act and enters into force on 30 September 2026. In lawsuits for damage linked to an artificial intelligence system, the court can order the evidence to be disclosed also by the third party that holds it, and if an AI Act obligation is breached the causal link is presumed, unless proven otherwise.

Its full name is decreto legislativo 9 settembre 2026, n. 160 (legislative decree no. 160 of 9 September 2026), published in the Gazzetta Ufficiale (Italy’s Official Journal) on 15 September; the AI Act is Regulation (EU) 2024/1689. The title names three subjects: the use of AI in policing, civil liability and criminal liability. The last two concern anyone who has put an AI function into the company’s software, whether a model that classifies incoming documents or an assistant that answers customers on the portal.

The opinion on a specific case comes from a lawyer. Here are the questions to take to them, and the ones to take to the supplier before signing or renewing a contract.

When it applies: from 30 September 2026, and high risk slips to 2027 and 2028

The rules that apply to any AI system apply from 30 September 2026; those that depend on AI Act obligations follow the European timetable, which has changed in the meantime.

Article 16 says that the rules on access to evidence in article 17 apply to actions for compensation of damage, both contractual and non-contractual, caused in the use of an artificial intelligence system. No restriction to high risk.

The same article, in paragraph 2, limits articles 18 and 19 to cases where the damage derives from the breach of one or more obligations of Regulation (EU) 2024/1689. And this is where the second date comes in. Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, published in the Official Journal of the European Union on 24 July 2026, set new deadlines for the AI Act’s obligations on high-risk systems: 2 December 2027 for stand-alone systems, 2 August 2028 for those embedded in products.

Until those dates, then, the obligations that the regulation reserves for high-risk systems do not apply yet. What this means for the presumption in article 18 is a question for the lawyer. Access to evidence, on the other hand, applies straight away, to everyone.

The practical consequence is one: a contract signed today with a supplier, for software the company will use for years, may still be in force in December 2027. The clauses needed then are written now.

First question: is it an artificial intelligence system?

It is if it meets the definition in article 3 of the AI Act, to which article 11 of the decree refers. It is the first text to read, and it comes before any discussion of risk.

A recommendation engine on a B2B e-commerce site, or a classifier that sorts support requests, falls within scope if it meets those definitions. The answer should be asked of the lawyer with the technical description of the system in hand, including what it decides on its own.

Then there is the word “contractual”. The damage can hit any third party, and it can hit a customer with whom you have signed a contract. If your portal uses a model to decide something that concerns customers, for example which request to give priority to or which offer to show, article 16 also covers the actions that arise from that contract.

Who has to disclose the evidence on AI (article 17)

For any AI system, at the request of whoever claims to have suffered the damage, the court orders the other party or “the third party that holds it” to disclose the specifically relevant evidence on how the system works. The claimant must present facts and evidence capable of making the claim plausible, and the order is limited to what is necessary and proportionate to the claim.

Among the evidence, paragraph 2 lists the logs, the documentation on the risk management system, the relevant information from the technical documentation and the information on the parameters and methods of human oversight. These are documents that the regulation requires of high-risk systems, with the timetable seen above: today the order can be given for any system, but those documents may not exist yet.

The consequences of refusing are different for those who are party to the case and those who are not. If the party, without justified reason, does not disclose the documentation on the list, the court, having weighed every other piece of evidence, treats the facts alleged by the claimant as admitted. The third party that, without justified reason, does not comply is ordered to pay a financial penalty from €1,500 to €10,000.

If the order reaches the company and the documents are held by the supplier, what matters is what the contract allows it to obtain. Whether not having them is a justified reason is a question for the lawyer; having them available removes it.

When the causal link is presumed (article 18)

When the damage derives from the breach of one or more AI Act obligations, the causal link between the breach and the damage is presumed, unless proven otherwise.

For each system, then, the question is which obligations of the regulation concern it and from which date. For high risk the answer has the two deadlines of 2027 and 2028; for the other obligations the timetable has to be reconstructed with the lawyer, system by system.

Does AI Act conformity certification rule out liability?

Not on its own. Under article 19, without prejudice to the legislation transposing Directive (EU) 2024/2853, the system’s conformity with AI Act obligations, even if certified under Chapter III, Section 5, does not in itself rule out the defendant’s liability. Like article 18, it applies when the damage derives from the breach of an obligation of the regulation.

With the postponement, for a high-risk system that certification may not exist yet. With or without a certificate, it pays to be able to reconstruct how the system was built and how it behaves: what data it was trained or configured with, and how it was tested before going into production. This is material the company must be able to retrieve even when the system was written by someone else.

What offence does article 437-bis introduce, and what changes in the 231 (art. 25-vicies)?

The decree inserts article 437-bis into the codice penale (criminal code). It punishes anyone who fails to adopt the technical safety measures required for the design, training, production or placing on the market of high-risk AI systems, or fails to adopt human oversight measures, when those omissions give rise to a danger to life or to public or individual safety.

The paragraph that most closely concerns a company that uses the system is the last one: it punishes the professional user of high-risk systems who intentionally fails to adopt human oversight measures, if that danger arises. The condition of danger applies in both cases.

Article 25-vicies enters d.lgs. 231/2001 (the Italian law on the liability of organisations for offences): for 437-bis the organisation is subject to a financial penalty of six hundred to one thousand quotas, plus the disqualification sanctions of article 9, paragraph 2, letters b), c), d) and e), of the same decree.

In software, human oversight becomes a function to design like the others: what a person sees of what the system is deciding, how they stop it, what trace the intervention leaves. Which measures are “required” for a given system is a question for the lawyer. Whoever updates the 231 organisational model will need to know from the IT department where those measures are, in the code and in the procedures.

The question to take to the lawyer: which of the company’s systems could fall among the high-risk ones, and from which date.

Can the software supplier receive the disclosure order?

It can, if it is not a party to the case and holds logs and documentation: in that case it can be “the third party that holds it” under article 17, and if it does not comply without justified reason the financial penalty is its own. An AI function can arrive inside software written by others, or as a cloud service called by an integration. The company, meanwhile, has to answer in court with what it manages to obtain.

Before signing the next contract, or renewing the current one, there are four questions the supplier should settle in writing.

  • Who owns the code, and where it is: in a repository the company has access to, or only on the supplier’s machines.
  • Where the model and the data run, and who can access them.
  • What the system logs when it decides or suggests something, for how long it keeps it, and whether the company can extract it without asking the supplier’s permission.
  • What is handed over at the end of the project, and what remains available if the relationship ends.

On the first and the last question, the code and the handover, our commitment is written in the frequently asked questions on the page about tailored software: “Source, documentation and development environments are your property, and they stay yours even if one day you change supplier.” On the other two the answer depends on where the system runs.

A case: the model on the client’s servers

For a public administration in Emilia-Romagna we built software for transcribing minutes. Speech recognition, on-premise installation, two months of work with three people: two on the backend, one on the frontend.

The audio does not leave the client’s infrastructure. The speech recognition model runs in the on-premise installation, on the client’s machines, and no third-party service sits between the recording and the final text.

The case says nothing about how that system is classified under the regulation. We tell it for one of the four questions, where the model and the data run, which that project answered with the installation.

On-premise installation has its own costs, and for many systems a cloud service is the sensible choice. In that case the same four questions should be asked of whoever runs the service, and the answers should go into the contract.

What to decide, and when

From 30 September 2026, access to evidence and its consequences apply, for any AI system. The decisions that do not wait:

  • The inventory. Which systems use a model, whether they fall within the definitions in article 3 of the regulation, who wrote them and where they run.
  • The contracts. Code, data, logs and documentation: what the supplier hands over and what remains accessible to the company, even after the relationship ends. A contract signed now can also cover the period when the high-risk obligations arrive.

Before 2 December 2027, with the lawyer, for the systems that could be high risk: which obligations of the regulation will apply, how human oversight is designed, and whether the certification of Chapter III, Section 5 is needed.

A similar problem, in your company?