Legislative Decree 231/2001 · Offences committed with AI
Your 231 compliance model does not know about artificial intelligence yet
The Italian Council of Ministers has given final approval to an offence that punishes the use of a high-risk AI system without human oversight, and which the draft brings into the list of predicate offences for corporate liability. The text has not yet reached the Official Journal: that gap is exactly the time you have.
A word first on what this note is about, for a reader outside Italy. Italian Legislative Decree no. 231 of 8 June 2001 makes a company itself liable — with fines, disqualification measures and confiscation — for a closed list of offences committed in its interest by its directors or its staff. The company's defence is an organisational and compliance model that is adequate, effectively implemented and monitored by an internal supervisory body, the Organismo di Vigilanza. That list is about to grow.
Your 231 model lists the offences the company can commit. If it has been updated recently it reaches as far as cybercrime and tax offences, and for each one it identifies the exposed process, the protocol covering it and who answers for it. Almost certainly it contains not a line about the system that has been assigning warehouse shifts for the past eight months, or the one rejecting defective parts on the line. In a few months that line will be needed.
What was decided on 4 August.
On 4 August 2026 the Italian Council of Ministers gave final approval to two legislative decrees adapting Italian law to Regulation (EU) 2024/1689, the AI Act, under the delegated powers contained in Italian Law no. 132 of 23 September 2025. The first of the two concerns the use of artificial intelligence in policing and contains the criminal provisions; the second sets out the national supervisory architecture, entrusted to AgID, the Agency for Digital Italy, and to the National Cybersecurity Agency.
The decree that matters here is the first, because it inserts into the Italian Criminal Code a new Article 437-bis, punishing the failure to adopt security measures in high-risk artificial intelligence systems and their unlawful alteration, with penalties graded according to the interest placed at risk. The same decree strengthens the position of anyone harmed by an AI system: access to the technical documentation, a presumption of causation, a court close to the claimant's residence and a direct action against the defendant's insurer.
It is worth being precise about where matters stand, because it changes the arithmetic of the timetable. "Final approval" means the content is settled, not that the rule is in force: at the date of this note the decree does not appear to have been published in the Italian Official Journal, and until it is it produces no effect. The version that can be discussed in detail therefore remains the draft approved at first reading on 10 June 2026, together with the amendments that the Council of Ministers' press release states were introduced after the opinions of the parliamentary committees, of the Joint Conference and of the Italian data protection authority. The final text will be read in the Official Journal, and on some points it may differ from the June version.
The two offences entering the list.
In the draft decree, the new family of predicate offences enters Legislative Decree no. 231 of 8 June 2001 through an Article 25-vicies, headed "Offences committed through the use of artificial intelligence systems", which refers to two offences: the new one in the Criminal Code and one that has already been in force for almost a year.
| Provision | What it punishes | Status |
|---|---|---|
| Italian Criminal Code, Article 437-bis — inserted by the legislative decree adapting Italian law to the AI Act | Failing, in the design, training, production, placing on the market or professional use of high-risk AI systems, to adopt technical measures suitable to prevent malfunctions and alterations, or human oversight measures, where actual danger results. The unlawful alteration of the system is punished as well. | Given final approval on 4 August 2026, not yet published. |
| Italian Criminal Code, Article 612-quater — inserted by Law 132/2025 | Distributing without consent images, video or voices altered or generated with artificial intelligence systems, in a manner apt to deceive as to their authenticity and causing unjust harm to the person. | In force since 10 October 2025. |
The second row of that table is the easier one to underestimate. The offence has existed for months and nobody had to wait for an implementing decree: what is missing today is only the link to corporate liability. A promotional video in which an executive's voice has been reconstructed, a spokesperson's face generated from a real person, an internal announcement produced with a voice clone: these are uses that inside a company go through marketing, not through compliance, and that nobody today classifies as a 231 risk.
Why it concerns companies that merely use AI.
There is a widespread, and convenient, belief that the rules on artificial intelligence concern those who build it. In the new criminal offence that is not so: among the forms of conduct covered is "professional use", alongside design and production. And the Council of Ministers' press release expressly notes that, after the parliamentary opinions, "the position of the professional user of high-risk systems who intentionally fails to adopt human oversight measures has been set out in a separate provision". The legislator, in other words, was looking precisely at the company that buys the system and puts it into production.
Which systems. Annex III to Regulation (EU) 2024/1689 classifies as high-risk, among others, systems used for recruitment, for the allocation of tasks, for monitoring and evaluating the performance of workers, for creditworthiness assessment and for access to essential services. To these are added systems acting as safety components of products already subject to European harmonisation: machinery, medical devices, lifts. It is a list in which a mid-sized manufacturer almost always finds at least two entries.
The offence does not arise when the system gets it wrong. It arises when nobody was required to be watching.
This is the point that concerns the supervisory body. Corporate liability under Legislative Decree 231/2001 presupposes that the offence was committed in the company's interest or to its advantage by someone in a senior position or by someone under another's direction, and the company's defence is an organisational model that is adequate, effectively implemented and monitored. Where the offence consists in an omission — not having identified who checks the system's output, or not having done so in a way that leaves a record — the adequate model and the elements of the offence come dangerously close to each other. The missing protocol is the very thing that completes the offence.
The gap between the offence and the European deadlines.
The reasonable objection is that the European obligations on high-risk systems have been postponed. That is true: Regulation (EU) 2026/1744, in force since 27 July 2026, moved to 2 December 2027 the obligations for the Annex III systems and to 2 August 2028 those for systems that are safety components of regulated products.
The postponement, however, moved the obligations, not the classification: Annex III already sets out today which systems are high-risk, and no company will be able to argue in 2028 that it did not know beforehand which category its software fell into. As for how the two timetables fit together, the Council of Ministers' press release states that the second decree — the one on governance — contains "a provision making the entry into force of the penalties conditional on the actual entry into force of the corresponding obligations and prohibitions". That is said of the administrative penalties in that decree. Whether a similar link applies to the criminal offence, the press release does not say: it is one of the first things to check when the text appears in the Official Journal, and anyone who tells you today that they know for certain is interpreting, not reading.
There is also a more mundane reason not to wait. Updating a 231 model is not a two-week exercise: it requires mapping the exposed processes, drafting the protocols, a resolution of the board, information flows to the supervisory body and training for the people who will have to apply those protocols. A company that starts when the rule is in force starts a year late.
What the supervisory body can do now.
None of these steps requires knowing the final text, and none is wasted if the text changes in its details.
- Ask for the inventory, not for reassurance. Not "do we use artificial intelligence?", but the list of systems in production with the process they affect, the date they were introduced and the function that bought them. In a good many companies half of those systems never went through the IT department.
- Separate out the high-risk ones. An entry-by-entry comparison with Annex III to Regulation (EU) 2024/1689 and with the products subject to harmonisation. It is the only step that calls for a legal reading, and it is the one that decides the size of everything else.
- Put a name to the human oversight. For each high-risk system: who checks it, what they must be able to stop, how often, and where a record of the check remains. Oversight that leaves no record is, in proceedings, the same as oversight that never happened.
- Bring the protocols into the model. A dedicated special section, information flows to the supervisory body, and a duty to report when a new system goes into production — which is the moment when, today, nobody tells anybody.
- Reread the supplier contracts. The technical documentation, the operating logs and the instructions for use, without which oversight cannot be demonstrated, are held by the vendor: if they are not written into the contract, you will not have them when you need them. That is the subject of an earlier note.
- Fix the date of the review. On the day the decree appears in the Italian Official Journal, the work done must be checked against the real text. The same applies to the other implementing decrees under Law 132/2025, whose delegated powers expire on 10 October 2026.
A closing remark on the order of priorities. Faced with a new criminal provision, the temptation is to update the document first: add the special section, attach the list of offences, file the board resolution. But a model that lists Article 437-bis of the Italian Criminal Code without knowing which systems the company actually uses is not a defence: it is written proof that the risk had been recognised and left uncovered.
Sources
- Council of Ministers of 4 August 2026 — press release of the Italian government: final approval of the two legislative decrees adapting Italian law to the AI Act, describing the new Article 437-bis of the Criminal Code and the separate provision on the professional user. It is the available source until the decree is published in the Official Journal. Text in Italian.
- Italian Law no. 132 of 23 September 2025 — provisions and legislative delegations on artificial intelligence, on Normattiva. It contains the delegated powers in Article 24 and introduced Article 612-quater of the Criminal Code. Text in Italian.
- Italian Legislative Decree no. 231 of 8 June 2001 — rules on the administrative liability of entities, on Normattiva. Article 25-vicies would be inserted into it by the decree awaiting publication. Text in Italian.
- Regulation (EU) 2024/1689 — the AI Act, consolidated text on EUR-Lex, updated to 27 July 2026; in particular Article 14 on human oversight, Article 26 on the obligations of deployers and Annex III on high-risk classification.
- Regulation (EU) 2026/1744 — the Digital Omnibus on AI, 8 July 2026, in force since 27 July 2026: it postpones to 2 December 2027 the obligations on the high-risk systems of Annex III and to 2 August 2028 those on systems that are safety components of regulated products.