Failure to Adopt Safety Measures in Artificial Intelligence Systems and Unlawful Alteration of Systems: Italy’s New Article 437-bis of the Criminal Code
Posted:
Time to read:
The relationship between artificial intelligence (‘AI’) regulation, business and corporate (criminal) liability has become an increasingly important issue in Europe. Although the EU AI Act establishes a comprehensive regulatory framework for AI systems, it leaves Member States with considerable discretion as to whether, and how, criminal law should complement its enforcement in relation to certain business activities. Italy’s new implementation which will enter into force on 30 September 2026 (for the legislative process see here, here and here) of the AI Act deserves particular attention, as it may mark an important step in the evolution of AI compliance in Europe.
This blog post examines Italy’s Article 437-bis of the Criminal Code, which criminalises certain failures to adopt safety measures and, under specific circumstances, to implement human oversight in relation to high-risk AI systems. The provision is one of the first explicit criminal offences in Europe targeting AI governance failures, with significant implications for corporate compliance and business activities. It is therefore a development worth monitoring for all businesses operating in Italy, as well as for other EU Member States that will need to implement the AI Act.
Italy’s New Crime: Failure to Adopt Safety Measures in Artificial Intelligence Systems and Unlawful Alteration of Systems
On 15 September 2026, Legislative Decree No. 160 of 9 September 2026 was published in the Gazzetta Ufficiale, adapting Italian law to Regulation (EU) 2024/1689 (the AI Act) with regard to the use of AI systems.
In the preceding months, on 10 June 2026, the Italian Government had approved, on a preliminary basis, two draft legislative decrees aimed at implementing key aspects of the AI Act. Following parliamentary scrutiny, the Government approved the two legislative decrees in final form on 4 August 2026.
Among the new measures, one stands out for its potential implications for corporate compliance. The legislation will introduce a new Article 437-bis into the Italian Criminal Code, establishing the offence of ‘Failure to Adopt Safety Measures in Artificial Intelligence Systems and Unlawful Alteration of AI Systems’.
The new crime is of particular interest for Italian businesses and multinational companies developing, deploying, or commercialising AI systems in the Italian market. The Decree also provides for the inclusion of Article 437-bis within the scope of Legislative Decree No. 231/2001, Italy’s corporate liability framework. This means that the offence could give rise not only to individual criminal liability but also to liability for the company itself.
The first paragraph of Article 437-bis of the Italian Criminal Code establishes an omission-based offence. The provision aims to address failures to take the necessary measures at different stages of the lifecycle of high-risk AI systems. Relevant conduct may occur during the design, training, production, and placing on the market of such systems. The fourth paragraph addresses the intentional failure by professional users of high-risk AI systems to adopt human oversight measures.
Liability under this new provision may arise in two main circumstances. The first concerns the failure to adopt appropriate technical measures to prevent malfunctions or alterations affecting the operation of high-risk AI systems. The second relates to the failure to implement adequate human oversight measures.
Failure to Adopt Appropriate Technical Measures to Prevent Malfunctions or Alterations Affecting the Operation of High-Risk AI Systems
The first scenario appears to be closely connected with several provisions of the AI Act, most notably Article 9 on risk management systems, but also, among others, Article 15 on accuracy, robustness, and cybersecurity.
Article 9(2)(a)-(d) requires establishing and maintaining a continuous and iterative risk management process throughout the entire lifecycle of high-risk AI system, including regular review and updates.
In particular, Article 9 requires companies to:
- Identify and analyse the known and reasonably foreseeable risks to health, safety, and fundamental rights;
- Estimate and evaluate the risks that may arise during its intended use and reasonably foreseeable misuse;
- Assess other risks that may emerge;
- Implement targeted mitigation measures to address identified risks.
The requirement that technical measures must be “suitable to prevent malfunctions or alterations in the operation” of high-risk AI systems raises an important question: what type of failures fall within the scope of the provision?
According to scholars, not every error affecting an AI system should necessarily qualify as a malfunction. In light of the AI Act framework, a malfunction may be understood as a failure of the system to operate as intended due to defects affecting data, software, or system design. Examples may include a medical AI system generating incorrect diagnostic recommendations due to flaws in its training dataset or software updates, or a facial recognition system failing to correctly identify authorised users.
The concept of “alterations in the operation” appears instead to refer to external interventions or unauthorised modifications that change the behaviour of the system. Examples may include data poisoning attacks or unauthorised modifications to model parameters.
Failure to Implement Human Oversight Measures
The second scenario concerns the failure to implement human oversight measures, a requirement that directly relates to Article 14 of the AI Act on human oversight. Among the various obligations set out in Article 14, particular relevance should be given to paragraphs 3(a) and 3(b), which identify two possible and potentially complementary forms of human oversight measures for high-risk AI systems:
- Provider-integrated measures: measures incorporated into the system before it is placed on the market or put into service, where technically feasible;
- Deployer-implemented measures: measures identified by the provider before the system is placed on the market and intended to be implemented by the deployer of the system.
Under the current text, however, criminal liability would arise only where the failure to adopt the required technical measures or to implement the required human oversight measures creates a concrete danger to life or individual physical integrity, or to public safety or the security of the State.
Additional Forms of Liability under Article 437-bis
The same conduct may also give rise to liability under paragraph 3 of Article 437-bis where committed with gross negligence. Paragraph 2, meanwhile, concerns the unlawful alteration of high-risk artificial intelligence systems. Even in those cases, criminal liability arises where the alteration results in a concrete danger to life or individual physical integrity, or where it poses a concrete danger to public safety or the security of the State.
Conclusions
The legislation introduces a further element of compliance risk for businesses involved in the development, deployment, or use of high-risk AI systems in Italy. In particular, providers and deployers may face an expansion of their duties of care and organisational responsibilities towards the AI systems under their control.
At the same time, the requirement of a concrete danger threshold, together with the limitation of negligent liability to cases of gross negligence, appears designed to avoid criminalising every technical deviation or operational error. Instead, the provision would reserve criminal intervention for failures that are genuinely capable of endangering life, individual physical integrity, public safety, or the security of the State.
Marco Di Donato is a PhD Candidate at the University of Verona and the University of Málaga.
Share: