No Logs, No Defence: Italy Makes AI Documentation Court-Orderable
27 July 2026. Regulation (EU) 2026/1744 enters into force. Brussels pushes the AI Act’s high-risk obligations - logging, risk management, technical documentation, human oversight - from 2 August 2026 to 2 December 2027.
30 September 2026. Legislative Decree 160/2026 enters into force. Rome makes those same four categories of documents court-orderable in any damages claim involving an AI system. Today.
Sixty-five days apart. Nobody reconciled them. The text proves it.
What a Judge Can Now Order
Title II, Chapter II of the decree is five articles long. Arts. 16 to 20. Read them from the Gazzetta Ufficiale, not from a summary.
Scope (art. 16). Art. 17 applies to damages claims, contractual and extra-contractual, for harm caused in the use of an AI system. Any AI system. High-risk classification is irrelevant here. A consumer can sue in the court where they live. Art. 82 GDPR and the national transposition of the Product Liability Directive stay untouched.
Access to evidence (art. 17). On the claimant’s request, the judge orders the counterparty, or a third party holding it, to produce the evidence specifically pertinent to how the system works. The threshold: facts and elements that make the claim plausible, including the link between the system’s output and the harm. The decree then names what “evidence” includes:
- the automatic logs of art. 12 AI Act
- risk management documentation (art. 9)
- technical documentation (art. 11)
- parameters and arrangements for human oversight (art. 14)
The order is limited to what is necessary and proportionate. Trade secrets and confidential information are protected; art. 121-ter of the Industrial Property Code applies. Professional secrecy is not mentioned. Hold that thought.
Consequences (art. 17, paras 5 and 6). A party that fails to comply without justified reason: the judge may draw adverse inferences under art. 116 c.p.c.. If what’s missing is the listed documentation, the judge, having weighed all other evidence, treats the claimant’s alleged facts as admitted. A third party that refuses pays €1,500 to €10,000.
Causation (arts. 18 and 19). When the harm results from a breach of an AI Act obligation, the causal link is presumed. Rebuttable, but presumed. Compliance with the AI Act, even certified under Chapter III, Section 5, does not by itself exclude liability.
Insurance (art. 20). Before suing, the claimant may ask the alleged liable party whether it carries liability cover for the harm. Reply within 30 days: contract details, insurer’s name. Silence or an incomplete answer feeds the art. 116 inferences. If cover exists, the claimant has direct action against the insurer, within the policy limits. The decree does not mandate insurance.
flowchart TD
A["Claimant alleges harm from an AI system<br>any risk class - art. 16(1)"] --> B{"Facts make the claim plausible?<br>art. 17(1)"}
B -->|No| X["No order"]
B -->|Yes| C["Judge orders production<br>from the party or a third party"]
C --> D["Logs - art. 12 AI Act<br>Risk management - art. 9<br>Technical documentation - art. 11<br>Human oversight parameters - art. 14"]
C --> E["Necessary and proportionate only<br>Trade secrets protected - art. 121-ter CPI<br>Professional secrecy: not mentioned"]
D --> F{"Produced?"}
F -->|Yes| G["Evidence on the record"]
F -->|"Party refuses, no justified reason"| H["Adverse inferences - art. 116 c.p.c.<br>Listed documents missing:<br>claimant's facts deemed admitted"]
F -->|"Third party refuses"| I["Fine EUR 1,500 - 10,000"]
The Directive That Wouldn’t Die
You’ve seen this structure before. Disclosure of evidence behind a plausibility threshold. A presumption against you if you don’t produce. A rebuttable presumption of causation. That’s arts. 3 and 4 of the AI Liability Directive proposal, COM(2022) 496.
The Commission withdrew it on 11 February 2025. “No foreseeable agreement.” Simplification. Competitiveness.
Italy read the withdrawal differently. Art. 24(5)(d) of Law 132/2025 - the national AI law I covered when it passed, mostly for its prison terms - delegated the government to regulate the burden of proof in AI liability cases, “taking into account the classification of AI systems” under the AI Act. Decree 160 is that delegation exercised, with a month to spare on the twelve-month deadline that started 10 October 2025.
And it went further than the directive ever did.
| AI Liability Directive (COM(2022) 496) | D.Lgs. 160/2026 | |
|---|---|---|
| Status | Withdrawn 11 Feb 2025 | In force 30 Sep 2026 |
| Disclosure scope | High-risk AI systems only (art. 3) | Any AI system (art. 16(1)) |
| Claims covered | Non-contractual, fault-based (art. 1) | Contractual and extra-contractual |
| If you don’t produce | Presumption of non-compliance with duty of care | Adverse inferences; listed documents missing → facts deemed admitted |
| Causation | Rebuttable presumption, three cumulative conditions (art. 4) | Presumed on breach of AI Act obligation, rebuttable (art. 18) |
| Insurance | Not addressed | Pre-suit disclosure request, direct action (art. 20) |
The withdrawn directive only reached high-risk systems. Italy reaches everything the AI Act’s art. 3(1) definition can catch. Count what in your stack doesn’t qualify.
The Timing Problem
Here is where it gets uncomfortable.
Art. 17(2) lists four document categories by AI Act article number. All four are obligations of providers of high-risk systems. Under Regulation 2026/1744, those obligations apply to Annex III systems from 2 December 2027 and to Annex I embedded systems from 2 August 2028. Today, 30 September 2026, no provider in the EU is required by the AI Act to keep any of them.
When the Omnibus was proposed, I wrote that if you were racing to meet the August 2026 high-risk deadline, you “might be able to slow down.” As a reading of EU law, that held. In Italy, as of this morning, slowing down means meeting a disclosure order with nothing to produce.
Art. 18 presumes causation when harm results from a breach of an AI Act obligation. Which obligations can be breached today? Prohibited practices, since February 2025. GPAI model obligations, since August 2025. Art. 50 transparency, since August 2026, with a grace period to 2 December 2026 for watermarking on already-deployed systems. Not the high-risk chapter.
Art. 437-bis of the Criminal Code punishes omitting the security measures “provided for” high-risk systems. Provided for, yes. Applicable, not until December 2027. Whether a prosecutor can charge you today for omitting a measure the EU says you don’t need yet is a question the decree doesn’t answer and no court has faced.
flowchart LR
A["11 Feb 2025<br>AILD withdrawn"] --> B["10 Oct 2025<br>Law 132/2025 in force<br>delegation starts"]
B --> C["19 Nov 2025<br>Digital Omnibus proposed"]
C --> D["19 Mar 2026<br>AG opinion, Rowicz C-159/25"]
D --> E["27 Jul 2026<br>Reg. 2026/1744 in force<br>high-risk deferred"]
E --> F["4 Aug 2026<br>Council of Ministers<br>adopts final decree text"]
F --> G["30 Sep 2026<br>D.Lgs. 160/2026 in force"]
G --> H["9 Dec 2026<br>PLD transposition deadline"]
H --> I["2 Dec 2027<br>Annex III obligations apply"]
I --> J["2 Aug 2028<br>Annex I obligations apply"]
The government’s final deliberation on the decree was 4 August 2026. Eight days after the Omnibus entered into force. Title I, the police chapter, got a safety valve: art. 21(2) says provisions that depend on the AI Act follow the AI Act’s own application dates. Title II, the civil and criminal chapter, got no such clause.
What this means in practice: art. 17(1) still works. The order covers “specifically pertinent evidence relating to the functioning of the system.” Whatever exists. Vendor logs. Prompts. Outputs. Review records. The four listed categories are examples, not a closed list.
And “without justified reason” in art. 17(5) has never been interpreted by any court. Do not be the test case.
Criminal Exposure: What 437-bis Actually Says
The summaries say “1 to 5 years.” Correct. The article has four paragraphs. Read all of them.
| Conduct | Danger to life or public/individual safety | Danger to State security |
|---|---|---|
| Omitting technical security measures or human oversight, high-risk system (para 1) | 1-5 years | 2-8 years |
| Altering a high-risk system (para 2) | 2-6 years | 3-10 years |
| Para 1 conduct with gross negligence (para 3) | reduced by one-third to one-sixth | reduced by one-third to one-sixth |
| Professional user intentionally omitting human oversight (para 4) | as para 1 | as para 1 |
Paragraph 4 is the one for deployers. Not providers. You. “Intentionally” is the operative word; ordinary negligence doesn’t reach it.
For companies, new art. 25-vicies of Decree 231/2001: 600 to 1,000 quotas for a 437-bis offence. At €258 to €1,549 per quota under art. 10 of the same decree, that’s roughly €155,000 to €1.55 million. Plus the interdictive sanctions of art. 9(2)(b)-(e), including a ban on contracting with public administration. The deepfake offence from Law 132/2025 (art. 612-quater) joins the catalogue at 200 to 700 quotas.
A note for readers outside Italy. Decree 231/2001 makes the company itself liable when its managers or employees commit a listed offence in its interest. The main defence is art. 6: the company is off the hook if, before the offence, it adopted and actually applied an organisation, management and control model fit to prevent that kind of offence, overseen by an independent supervisory body (Organismo di Vigilanza). That’s the “231 model” - a risk map, procedures and controls, offence by offence. It’s an Italian instrument, but it binds your Italian subsidiary too.
Every offence added to the catalogue needs its own section in the model. If you have a 231 model, it’s out of date as of this morning.
Legal AI: Not High-Risk, Still Discoverable
Annex III, point 8(a) of the AI Act covers systems used by or on behalf of a judicial authority to research and interpret facts and law. A drafting tool used by a law firm is not that. Recital 61 excludes purely ancillary administrative uses even inside courts. As a rule, your legal AI tool is not high-risk. That was never the same as safe - a California lawyer paid $10,000 to learn the difference.
So 437-bis doesn’t apply. Decree 231 doesn’t apply. The AI Act doesn’t require those four document categories. Arts. 17 and 20 apply anyway.
Two open points:
- Art. 17(3) and (4) protect trade secrets and confidential information. Professional secrecy, the privilege between you and your client, isn’t named. A disclosure order against a legal AI vendor’s logs may surface client material with no explicit shield in the decree.
- What counts as an “AI system” isn’t settled. In Rowicz (C-159/25), Advocate General Spielmann doubted at point 33 that Poland’s random case-allocation software qualifies under art. 3(1): predefined algorithms on fixed datasets, no post-deployment adaptability, no substantial autonomy. The judgment is pending. Until then, classify each tool and write down why.
The Loop, Revisited
In July, I argued that “a human reviewed it” is liability laundering unless you can prove it, and proposed a driving-mode memory for professional AI: model version, input context, output, reviewer identity, reviewer action, time on task, timestamps.
Ten weeks later, art. 17(2)(d) makes “parameters and arrangements for human oversight” court-orderable. The parameters describe how oversight is meant to work. Whether it did work in the case before the judge is shown by logs. Who checked, what, when. If those don’t exist, your parameters are a policy document with no evidence behind it.
The same article warned that insurers had started attaching AI exclusions to commercial liability policies. Art. 20 now lets a claimant ask you, before suing, whether you’re insured. Art. 20(3) lets the insurer raise against the claimant any exception from the contract that predates the loss. An AI exclusion is exactly such an exception. Direct action against an insurer that excluded AI is direct action against nothing.
What to Do This Week
- Classify every AI system. High-risk or not, under art. 6 and Annex III. Write the decision down with the reasoning. Everything else depends on this.
- Ask your provider three questions. What does it log? For how long? How does it hand the data over if a judge orders it? Get the answers into the contract, not an email thread.
- Log the review, not just the output. Reviewer, timestamp, action taken, time spent. The driving-mode memory. It is now evidence.
- Write the output-verification procedure. Then train people on it and keep the training records. A procedure nobody was trained on is a procedure nobody followed.
- Read your professional indemnity policy. Look for AI exclusions. Then read art. 20(3) again.
- Update the 231 model if you have an Italian entity. Add 437-bis and 612-quater to the risk map; art. 25-vicies is in force today.
- Watch two dates. 9 December 2026: the Product Liability Directive transposition deadline; the Italian draft decree is before Parliament now, and arts. 16(3) and 19 defer to it. 2 December 2027: high-risk obligations apply, and art. 17’s four categories stop being examples and become the law.
ISO 42001 gives you the scaffolding for items 1 to 4. It won’t make you compliant with the decree. It will make you able to produce something when the order arrives.
TL;DR
- D.Lgs. 160/2026 in force 30 September 2026: judges order production of AI logs, risk management, technical documentation and human-oversight parameters in damages claims involving any AI system (arts. 16-17).
- Refuse without justified reason: adverse inferences; listed documents missing → claimant’s facts deemed admitted. Third parties: €1,500-€10,000 (art. 17).
- Causation presumed on breach of AI Act obligations; certified compliance does not exclude liability (arts. 18-19).
- Claimant may demand insurance disclosure; 30-day reply; direct action against the insurer, but contractual exclusions predating the loss are opposable (art. 20).
- New art. 437-bis c.p.: 1-5 years for omitting security or oversight measures in high-risk systems; up to 10 years for alteration endangering State security. Art. 25-vicies D.Lgs. 231: 600-1,000 quotas, roughly €155K-€1.55M.
- The high-risk obligations the decree references were deferred by Reg. 2026/1744 to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), 65 days before the decree took effect. Title II has no transitional clause.
- The AI Liability Directive was withdrawn in February 2025. Italy rebuilt it nationally and widened it from high-risk to all AI systems.
- Legal AI tools are, as a rule, not high-risk (Annex III 8(a) covers judicial authorities). Arts. 17 and 20 apply regardless. Professional secrecy is not mentioned in the disclosure rules.
- AG Spielmann in Rowicz doubts random case allocation is an “AI system” at all. Classify each tool. Document why.
Brussels gave you until December 2027 to build the paper trail. Rome will ask for it at the first hearing.
Every article number above was checked against the decree as published in Gazzetta Ufficiale n. 214 of 15 September 2026. Title I - police use, biometric identification - is deliberately left out; it deserves its own piece. This is a reading of the statute, not legal advice. Research and drafting were done with AI assistance; the reading of the text and the opinions are human.