IT

EN

Artificial Intelligence

Artificial Intelligence and Criminal Law: What’s New in Law 132/2025

Law No. 132 of 2025 brings artificial intelligence directly into Italian criminal law, introducing a new offense for deepfakes, aggravating circumstances related to the use of AI, and new copyright protections. For businesses, professionals, and legal practitioners, this changes the scope of liability when an intelligent system becomes a tool for committing a crime.

Italy is the first Member State of the European Union to have introduced autonomous criminal offenses and aggravating circumstances aimed at the unlawful use of artificial intelligence into its criminal-law system.

A company uses a language model to train its internal assistant on a database of texts downloaded from the web. An employee creates a deepfake video to discredit a colleague. An algorithm builds thousands of false digital identities to manipulate a stock. Until 10 October 2025, none of these conducts found a criminal-law response in the Italian legal system. Law no. 132 of 23 September 2025 changes this condition.

A direct intervention in the Criminal Code with new offenses, new aggravating circumstances and new responsibilities for entities. But above all, a courageous choice.

This article analyses its concrete implications.

The regulatory framework

Law no. 132 of 23 September 2025, published in the Official Gazette on 25 September 2025 and entered into force on 10 October 2025, constitutes Italy’s first organic regulatory framework dedicated to artificial intelligence.

The measure follows the path of Regulation (EU) 2024/1689, the so-called European AI Act, and stands out for a clear policy choice. Not merely to set out ethical principles or system recommendations, but to intervene directly in substantive criminal law with new offenses and specific aggravating circumstances.

Chapter V of Law 132/2025, entitled “Criminal provisions” and consisting of Article 26, probably represents the most significant innovation from a systemic point of view, introducing autonomous criminal offenses and specific aggravating circumstances for the unlawful use of artificial intelligence.

Italy is the first EU Member State to approve legislation of this kind.

The new offense: Art. 612-quater of the Criminal Code

Article 26 inserts into the Criminal Code the new Article 612-quater, which punishes the “unlawful dissemination of content generated or altered through artificial intelligence” with imprisonment from one to five years, with the aim of countering deepfakes and digital manipulation.

The new provision fills a protection gap that had already created more than a few difficulties.

Before its introduction, the criminal-law response to unlawful synthetic content (images, videos or audio manipulated to attribute conduct never carried out to a person) had to rely on offenses not designed for this purpose: defamation through the press, harassment, revenge porn under Article 612-ter of the Criminal Code. All with evident interpretative strain.

The new Article 612-quater, instead, directly identifies the AI-generated or AI-altered nature of the content as the element characterizing the unlawful conduct, emphasizing the specific wrongfulness of a means capable of producing falsifications indistinguishable from reality.

From a technical-legal standpoint, the offense requires: the generation or alteration of content through artificial intelligence systems; the dissemination of such content; and, presumably, the intent to harm the reputation, dignity or privacy of the person represented.

Its placement is not accidental: it follows Article 612-ter (revenge porn), demonstrating the legislature’s intention to build a micro-system for protecting the person’s digital identity.

The common aggravating circumstance: the new no. 11-undecies of Art. 61 of the Criminal Code

The aspect with the greatest impact is the introduction of a new common aggravating circumstance. Article 26, paragraph 1, letter a), introduces into Article 61 of the Criminal Code number 11-decies (rectius: 11-undecies in the final numbering), according to which the offense is aggravated when committed “through the use of artificial intelligence systems, when those systems, by their nature or by the manner in which they are used, have constituted an insidious means, or when their use has in any event hindered public or private defense, or aggravated the consequences of the offense”.

The provision has a transversal function, intended to punish more severely conduct in which the use of artificial intelligence results in greater offensiveness, a reduction in defensive possibilities or an aggravation of the harmful consequences of the act.

In other words: AI, when used not as an accessory tool but as an element that qualitatively enhances the harmfulness of the conduct, justifies aggravated treatment.

The scope of application is deliberately broad.

The new aggravating circumstance applies to any offense (from fraud to threats, from unauthorized access to computer systems to extortion) whenever AI has made the action more insidious, hindered the victim’s defense or aggravated its consequences.

Coordination issues with the pre-existing structure of the Code are not lacking. The new aggravating circumstance interacts in particular with the reduced-defense circumstance under Article 61 no. 5 of the Criminal Code (which already punishes those who take advantage of circumstances capable of hindering public or private defense) and with the aggravating circumstance involving the use of fraudulent means.

The risk of overlap will require a uniform jurisprudential approach, especially in cases where AI is used, for example, to personalize phishing attacks at scale or to build false digital identities in fraud.

Special aggravating circumstances: financial markets and political rights

Similar aggravating circumstances have been introduced for offenses against political rights, market manipulation and financial manipulation when committed through artificial intelligence.

For financial manipulation through AI, the sentence can reach up to six years’ imprisonment.

It is an understandable criminal-policy choice: markets are particularly vulnerable to algorithmic strategies for distorting prices, while the integrity of democratic voting requires stronger protection against automated disinformation campaigns.

The intervention on copyright deserves separate mention.

In copyright matters, the reform extends criminal relevance to conduct carried out through artificial intelligence systems involving the reproduction or extraction of texts or data from works available online or in databases, in violation of Articles 70-ter and 70-quater of Law 633/1941.

This is the most delicate point of intersection between AI law and the information market: unauthorized training of language models on protected works thus enters the sphere of criminal relevance.

Implications for the 231 system

AI-related offenses enter the catalogue of Legislative Decree 231/2001, making entities liable for unlawful algorithmic conduct.

Companies will have to update their 231 Organizational Models, providing control and audit protocols for AI systems. This extension of the catalogue of predicate offenses requires organizations to rethink risk mapping and control protocols as a whole, inserting AI as a transversal variable in decision-making processes.

Concluding considerations

Law 132/2025 takes an unprecedented step in the European landscape: it transforms AI from an object of administrative regulation into a basis for criminal liability.

The choice is courageous and technically demanding.

The rule on the common aggravating circumstance, in particular, requires a case-by-case assessment: did the AI system really make the conduct more insidious? Did it hinder the defense?

Establishing this will require judges to have technical expertise that cannot be taken for granted.

The challenge for legal practitioners, then, is twofold: to master the new offenses and to help build, also through litigation, that legal culture of artificial intelligence that the law presupposes but cannot, on its own, guarantee.


About Marco Tupponi

A Supreme Court lawyer specializing in national and international commercial law, Technology Law and artificial intelligence, he is an adjunct professor at the University of Bologna, Forlì campus. Founder of Studio Tupponi, De Marinis, Russo & Partners, he collaborates with ICE, the Ministry of Foreign Affairs, the Ministry of Enterprises and Made in Italy and Il Sole 24 Ore. He is also a member of the ICC Tech Law and AI Commission and author of numerous publications, including the Manual of International Commercial Law.

About Bliss Faculty

Bliss Faculty is the editorial section of Bliss Agency that hosts signed contributions by high-profile Italian university professors and researchers. Each article is born from the scientific expertise of its authors and is edited, distributed and optimized entirely by the Bliss team, to bring Italian academic excellence to the online public.

Domande frequenti

My company uses AI tools to produce texts and communication materials. Are we exposed to criminal risks?

The productive use of AI tools is not in itself criminally relevant. Article 612-quater punishes the dissemination of AI-generated content with the intention of harming the reputation, dignity or privacy of a specific person. Those who use AI to write a press release or a commercial text do not fall within the offense. The risk arises when generated content is used to attribute to someone conduct or statements they never made, with specific intent. The dividing line is the harmful intention, not the means.

Does the new aggravating circumstance apply to any offense or only cybercrimes?

To any offense. This is the most significant systemic choice made by Law 132/2025. The new common aggravating circumstance enters Article 61 of the Criminal Code and applies whenever AI has made the conduct more insidious, hindered the victim’s defense or aggravated its consequences, regardless of the category of offense. Fraud, extortion, stalking, threats: if AI has amplified the harmfulness of the action, the aggravating circumstance applies. Coordination issues with existing aggravating circumstances (reduced defense, fraudulent means) will require a jurisprudential approach that does not yet exist.

Unauthorized training of models on protected works is now a criminal offense. How does it apply in practice?

With the same evidentiary difficulties as any large-scale cyber offense. The rule is clear in scope: unauthorized training on protected works under Articles 70-ter and 70-quater of Law 633/1941 becomes criminally relevant. But proving that a specific model was trained on a specific protected work, without authorization, requires forensic technical expertise that Italian case law has not yet developed. The rule exists. Its effective application will depend on investigators’ ability to ascertain conduct taking place in technically opaque environments.

What do we concretely need to add to our 231 Model?

At least three elements. A mapping of the AI systems used by the company and of the decision-making processes in which they intervene. A periodic audit protocol on the use of AI tools by staff, with particular attention to contexts involving third parties (customers, suppliers, markets). An internal reporting system for anomalous conduct involving AI. Law 132/2025 extends the catalogue of predicate offenses under Legislative Decree 231/2001 to AI-related offenses: a 231 Model that does not consider AI as a risk variable is now formally inadequate. If an employee uses company AI systems to commit an offense without the company’s knowledge, who is liable? It depends on the organizational structure and the adequacy of the 231 Model. If the company had suitable control protocols and the employee acted by circumventing them, criminal liability remains with the natural person. If the Model is deficient or controls were absent, the entity may be held liable under Legislative Decree 231/2001. The employee’s individual liability and the entity’s liability do not exclude one another: they can coexist. This is why adapting the 231 Model is a concrete protection condition for the organization.

Fonti e riferimenti
  1. Normattiva, Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale
  2. Gazzetta Ufficiale, Legge 23 settembre 2025, n. 132
  3. Gazzetta Ufficiale, Avviso di rettifica alla Legge 23 settembre 2025, n. 132
  4. Senato della Repubblica, Articolo 26 – Modifiche al codice penale e ad ulteriori disposizioni penali
  5. Parlamento europeo e Consiglio dell’Unione europea, Regolamento (UE) 2024/1689 sull’intelligenza artificiale
  6. Beatrice Fragasso, Profili penalistici della legge sull’intelligenza artificiale: osservazioni a prima lettura
  7. ANCE, Legge 23 settembre 2025, n. 132: le modifiche al D.Lgs. 231/2001
BLISS®© 2026. ALL RIGHTS RESERVED
Aggiornato il 17 September 2026

Brand Advisory

Brand Positioning
Brand Architecture
Archetypal Models
Identity Systems
Audit
Consulting
Advisory
Growth
Application of strategy in markets
Brand control system
Global activation framework
Strategic validation of initiatives

Operations

Photography
Video Production
Campaign Shooting
Cinematic Content
Visual Identity
Graphic Systems
3D Design
Motion Assets
UI/UX Design
Web Development
E-Commerce
Platform Maintenance
Google Ads
Meta Ads
SEO Optimization
AI Optimization
AI Visibility
Semantic Authority
Generative Citability
LLM Digital PR
Assistenza Whatsapp: +39 3772117290
 

[email protected]