Regulatory Landscape
Italy holds a distinctive place in AI regulation history as the first country to take enforcement action against a major generative AI service. The Garante per la protezione dei dati personali’s March 2023 temporary ban of ChatGPT over GDPR violations sent shockwaves through the industry and demonstrated that existing data protection law could be a powerful tool for AI oversight.
Italy’s regulatory approach combines EU-level requirements (the AI Act, GDPR) with proactive national enforcement, particularly around data protection and privacy. The country’s data protection authority has been among the most aggressive in Europe in scrutinizing AI services.
Key Laws
The EU AI Act applies directly in Italy as in all member states, with prohibited practices enforceable from February 2025. Italy is developing national implementation legislation to designate market surveillance authorities, establish national penalty regimes, and create coordination mechanisms between existing regulators.
The Garante’s actions against ChatGPT resulted in OpenAI implementing age verification, improving privacy disclosures, and providing opt-out mechanisms for training data—requirements that influenced AI companies’ approach to the entire European market.
Italy’s national AI strategy, updated in 2024, emphasizes AI in public administration, protection of cultural heritage and the Italian language, research investment, and workforce upskilling.
Enforcement
The Garante has demonstrated willingness to act swiftly against AI companies, using GDPR authority to impose conditions on AI services processing Italian citizens’ data. AGCOM oversees AI in media and communications, while AgID handles AI in government services. Fines under GDPR can reach 4% of global turnover, while the EU AI Act adds additional penalty mechanisms.
Business Impact
Italy’s aggressive enforcement posture means AI companies must prioritize Italian compliance within their European strategy. The ChatGPT precedent established that launching AI services without adequate data protection measures risks immediate regulatory action. Companies deploying AI in Italy face scrutiny from multiple regulators and should expect that the Italian authorities will be among the first to test enforcement boundaries under the EU AI Act.