On September 15, 2026 Legislative Decree 160/2026 was published in the Italian Official Gazette (no. 214/2026) and it came into force on September 30. It is the first of two implementing decrees of Law 132/2025 on artificial intelligence. It introduces a new crime in the criminal code, brings AI into the corporate liability regime of Legislative Decree 231/2001, and changes the rules on who has to prove what when someone claims damages. If you run a business and use AI tools, it is worth reading calmly and without alarm. This text is information, and it does not replace the advice of a lawyer.
What we know, and what we don't
We know that the new article 437-bis of the criminal code provides for imprisonment from 1 to 5 years for anyone who omits technical safety measures in high-risk AI systems, during design, training, production or placing on the market, when this creates danger to life or public safety. The penalty rises to 2 to 8 years if the danger concerns state security. According to the law firm WST, the decree also covers the unlawful alteration of these systems (2 to 6 years, aggravated to 3 to 10) and punishes the professional user who omits human oversight, with the same 1 to 5 year penalty.
For companies, article 25-vicies of Legislative Decree 231/2001 provides a fine of 600 to 1,000 quotas for the safety omission and 200 to 700 quotas for the unlawful spreading of artificial content, the so-called deepfakes (article 612-quater). Disqualification sanctions are added, such as the suspension of authorizations or a ban on contracting with public administration. On the civil side, if the damage comes from a violation of the AI Act requirements, the link between violation and damage is presumed, unless proven otherwise, and the judge can ask for the system's documentation. A compliance certification, on its own, is not enough to rule out liability.
From the pages we read, we don't know which tools count as high-risk systems: that classification comes from the European AI Act, which we did not read for this article. We also don't know how judges will apply the rules, since they have been in force for only a few days. Anyone who explains with certainty what each small business risks is guessing.
What it means for a small business
The heaviest penalties concern those who design, produce or place high-risk systems on the market, and those who use them professionally without proper human oversight. A shop that uses an AI assistant to write social media captions, based on what we read, does not look like the typical case. This is our own reading, the sources do not give this example. The useful point is more practical: the rule shifts attention to what you use, who checks it and what you have put in writing. Those who already have a 231 organizational model need to assess whether to update it. Those who publish synthetic images or voices have one more reason to know where they come from and who they belong to.
What to do
- List the AI tools you use. Include the hidden ones inside other programs: management software, website chatbot, tools for subtitles or translations.
- Next to each tool, write what it is for and who checks the results. One line per entry is enough.
- Ask your suppliers how they classify their product under the AI Act. Keep the answer, because it is part of your documentation.
- If a tool affects decisions that touch people, have a professional look at the case before going further.
- If you have a 231 model, ask whoever maintains it whether it needs updating for the new rule.
- Keep track of human review. Who reread, when, with what outcome.
What to avoid
- Buying "compliance kits" that promise total protection. No source guarantees it, and even a certification does not rule out liability.
- Switching everything off out of fear. The decree is about safety and oversight, and it does not ban the use of AI.
- Forgetting your suppliers' AI. If it is inside a program you use, it belongs on your list.
- Creating synthetic voices or faces of real people without permission. The unlawful spreading of artificial content has its own penalty, so ask for advice first.
A hypothetical example
Hypothetical example: a small communications agency with five people uses an AI assistant for drafts, a website chatbot supplied by an outside company and a tool that generates video subtitles. The owner opens a sheet with three columns: tool, what it is for, who checks it. The owner writes to the chatbot supplier to ask how the product is classified and saves the answer. Then comes the decision that every text from the assistant is reread by a person before it goes out, and that gets written down too. One hour of work, and from that day every new tool goes into the sheet before it is used.
The point, in short
Since September 30, AI has more precise criminal and liability rules, with the greatest weight on those who work with high-risk systems. For a small business the sensible move is an updated list, someone who checks and some written proof. If you want to understand where to start, or you have already talked to a supplier about this, write to us at info@sarabi.cloud and tell us your case.
Sources: PQA, Legislative Decree 160/2026 and AI, Osservatorio 231 and WST.
Have a similar case or a doubt? Write to us at info@sarabi.cloud.