Italy is the first EU Member State to have introduced into its criminal law stand-alone offences and aggravating circumstances targeting the unlawful use of artificial intelligence.
A company uses a language model to train its internal assistant on a database of texts downloaded from the web. An employee creates a deepfake video to discredit a colleague. An algorithm builds thousands of fake digital identities to manipulate a share price. Until 10 October 2025, none of these acts met with a criminal-law response in the Italian legal system. Law no. 132 of 23 September 2025 changes that.
A direct intervention in the Criminal Code with new offences, new aggravating circumstances and new liabilities for entities. Above all, a bold choice.
This article analyses its practical implications.
The regulatory framework
Law No. 132 of 23 September 2025, published in the Gazzetta Ufficiale on 25 September 2025 and in force since 10 October 2025, is Italy’s first comprehensive regulatory framework dedicated to artificial intelligence.
The law follows in the wake of Regulation (EU) 2024/1689, the so-called European AI Act, and stands out for a clear-cut choice: rather than merely setting out ethical principles or system-level recommendations, it intervenes directly in substantive criminal law with new offences and specific aggravating circumstances.
Chapter V of Law 132/2025, entitled “Criminal provisions” and consisting of Article 26, is probably the most significant innovation from a systemic standpoint, introducing stand-alone criminal offences and specific aggravating circumstances for the unlawful use of artificial intelligence.
Italy is the first EU Member State to pass legislation of this kind.
The new offence: Article 612-quater of the Criminal Code
Article 26 inserts into the Criminal Code the new Article 612-quater, which punishes the “unlawful dissemination of content generated or altered by means of artificial intelligence” with imprisonment of one to five years, with the aim of tackling deepfakes and digital manipulation.
The new provision fills a gap in protection that had already caused considerable embarrassment.
Before its introduction, the criminal-law response to unlawful synthetic content (images, video or audio manipulated to attribute to a person conduct they never engaged in) had to rely on offences not designed for this purpose: defamation through the press, harassment, and revenge porn under Article 612-ter of the Criminal Code. All with obvious interpretative strain.
The new Art. 612-quater, by contrast, identifies the AI-generated or AI-altered nature of the content itself as the defining element of the unlawful conduct, reflecting the specific wrongfulness of a tool capable of producing forgeries indistinguishable from reality.
From a technical and legal standpoint, the offence requires: the generation or alteration of content by means of artificial intelligence systems; the dissemination of such content; and, presumably, the intent to harm the reputation, dignity or privacy of the person depicted.
Its placement is no accident: it follows Art. 612-ter (revenge porn), showing the legislator’s intention to build a micro-system protecting the person’s digital identity.
The common aggravating circumstance: the new no. 11-undecies of Art. 61 of the Criminal Code
The provision with the greatest impact is the introduction of a new general aggravating circumstance. Article 26(1)(a) adds number 11-decies (rectius: 11-undecies in the final numbering) to Article 61 of the Criminal Code, under which an offence is aggravated when committed “through the use of artificial intelligence systems, where these, by their nature or by the manner of their use, have constituted an insidious means, or where their use has in any event hindered public or private defence, or aggravated the consequences of the offence”.
The provision serves a cross-cutting function, designed to punish more severely conduct in which the use of artificial intelligence results in greater harmfulness, reduced scope for defence or more serious harmful consequences of the act.
In other words: when AI is used not as an ancillary tool but as an element that qualitatively increases the harmfulness of the conduct, it justifies a harsher penalty.
The scope of application is deliberately broad.
The new aggravating circumstance applies to any offence (from fraud to threats, from unauthorised access to computer systems to extortion) whenever AI has made the act more insidious, hindered the victim’s defence or worsened its consequences.
There is no shortage of issues of coordination with the existing structure of the Code. The new aggravating circumstance overlaps in particular with impaired defence under Article 61(5) of the Criminal Code (which already punishes anyone who takes advantage of circumstances capable of hindering public or private defence) and with the aggravating circumstance of the use of fraudulent means.
The risk of overlap will require consistent case law, particularly where AI is used, for example, to personalise phishing attacks at scale or to build fake digital identities for fraud.
The special aggravating circumstances: financial markets and political rights
Similar aggravating circumstances have been introduced for offences against political rights, for market rigging and for market manipulation when committed by means of artificial intelligence.
For financial manipulation carried out by means of AI, the penalty can reach six years’ imprisonment.
It is an understandable criminal policy choice: markets are particularly vulnerable to algorithmic price-distortion strategies, while the integrity of the democratic vote requires stronger protection against automated disinformation campaigns.
The provisions on copyright deserve a separate mention.
In the field of copyright, the reform extends criminal liability to acts, carried out by means of artificial intelligence systems, of reproducing or extracting text or data from works available online or in databases, in breach of Articles 70-ter and 70-quater of Law 633/1941.
This is the most sensitive point of intersection between the AI law and the information market: unauthorised training of language models on protected works thus enters the sphere of criminal relevance.
Implications for the 231 system
AI-related offences enter the catalogue of Legislative Decree 231/2001, making organisations liable for unlawful algorithmic conduct.
Companies will need to update their 231 Organisational Models, introducing control and audit protocols for AI systems. This extension of the list of predicate offences requires organisations to completely rethink their risk mapping and control protocols, treating AI as a cross-cutting variable in decision-making processes.
Concluding remarks
Law 132/2025 takes an unprecedented step in the European landscape: it turns AI from an object of administrative regulation into a basis for criminal liability.
The choice is bold and technically demanding.
The provision on the common aggravating circumstance, in particular, calls for a case-by-case assessment: did the AI system genuinely make the conduct more insidious? Did it hinder the defence?
Establishing this will require of judges a technical expertise that cannot be taken for granted.
In short, the challenge for legal practitioners is twofold: to master the new offences and to help build, including through the courts, the legal culture of artificial intelligence that the law presupposes but cannot, on its own, guarantee.
About Marco Tupponi
A lawyer admitted to practise before the Italian Supreme Court, specialising in national and international commercial law, Technology Law and artificial intelligence, he is an adjunct professor at the University of Bologna, Forlì campus. Founder of Studio Tupponi, De Marinis, Russo & Partners, he works with ICE, the Ministry of Foreign Affairs, the Ministry of Enterprises and Made in Italy and Il Sole 24 Ore. He is also a member of the ICC Commission on Tech Law and AI and the author of numerous publications, including the Manuale di Diritto Commerciale Internazionale.
On Bliss Faculty
Bliss Faculty is Bliss Agency’s editorial column featuring signed contributions from leading Italian university lecturers and researchers. Each article draws on its authors’ scientific expertise and is edited, distributed and optimised entirely by the Bliss team, bringing Italian academic excellence to an online audience.
Domande frequenti
My company uses AI tools to produce texts and communications materials. Are we exposed to criminal risk?
The productive use of AI tools is not in itself criminally relevant. Art. 612-quater punishes the dissemination of AI-generated content with the intent to harm the reputation, dignity or privacy of a specific person. Using AI to write a press release or commercial copy does not fall within the offence. The risk arises when generated content is used to attribute to someone conduct or statements that never occurred, with specific intent. The dividing line is the intent to harm, not the tool.
Does the new aggravating circumstance apply to any offence, or only to cybercrimes?
To any offence. This is the most significant choice made by Law 132/2025 at a systemic level. The new common aggravating circumstance is inserted into Art. 61 of the Criminal Code and applies whenever AI has made the conduct more insidious, hindered the victim’s defence or worsened its consequences, regardless of the category of offence. Fraud, extortion, stalking, threats: if AI has amplified the harm caused by the act, the aggravating circumstance applies. How it interacts with existing aggravating circumstances (impaired defence, fraudulent means) will require case law that does not yet exist.
Unauthorised training of models on protected works is now a criminal offence. How does this apply in practice?
With the same evidentiary difficulties as any large-scale cybercrime. The provision is clear in scope: unauthorised training on protected works under Articles 70-ter and 70-quater of Law 633/1941 becomes criminally relevant. But proving that a specific model was trained on a specific protected work without authorisation requires forensic technical expertise that Italian case law has not yet developed. The provision exists. Its effective enforcement will depend on investigators’ ability to establish conduct that takes place in opaque technical environments.
What exactly do we need to add to our Model 231?
At least three elements. A map of the AI systems in use within the company and of the decision-making processes in which they play a part. A periodic audit protocol on staff use of AI tools, with particular attention to contexts involving contact with third parties (clients, suppliers, markets). An internal reporting system for anomalous conduct involving AI. Law 132/2025 extends the catalogue of predicate offences under Legislative Decree 231/2001 to AI-related offences: a Model 231 that does not treat AI as a risk variable is now formally inadequate.
If an employee uses the company’s AI systems to commit an offence without the company’s knowledge, who is liable?
It depends on the organisational structure and on the adequacy of the Model 231. If the company had suitable control protocols and the employee acted by circumventing them, criminal liability remains with the individual. If the Model has gaps or controls were absent, the organisation may be held liable under Legislative Decree 231/2001. The individual liability of the employee and that of the organisation are not mutually exclusive: they can coexist. This is why updating the Model 231 is a condition of concrete protection for the organisation.
Fonti e riferimenti
- Normattiva, Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale
- Gazzetta Ufficiale, Legge 23 settembre 2025, n. 132
- Gazzetta Ufficiale, Avviso di rettifica alla Legge 23 settembre 2025, n. 132
- Senato della Repubblica, Articolo 26 – Modifiche al codice penale e ad ulteriori disposizioni penali
- Parlamento europeo e Consiglio dell’Unione europea, Regolamento (UE) 2024/1689 sull’intelligenza artificiale
- Beatrice Fragasso, Profili penalistici della legge sull’intelligenza artificiale: osservazioni a prima lettura
- ANCE, Legge 23 settembre 2025, n. 132: le modifiche al D.Lgs. 231/2001

