Digitaliziran si

No Logs, No Defence: Italy Makes AI Documentation Court-Orderable

27 July 2026. Regulation (EU) 2026/1744 enters into force. Brussels pushes the AI Act’s high-risk obligations - logging, risk management, technical documentation, human oversight - from 2 August 2026 to 2 December 2027.

30 September 2026. Legislative Decree 160/2026 enters into force. Rome makes those same four categories of documents court-orderable in any damages claim involving an AI system. Today.

Sixty-five days apart. Nobody reconciled them. The text proves it.


What a Judge Can Now Order

Title II, Chapter II of the decree is five articles long. Arts. 16 to 20. Read them from the Gazzetta Ufficiale, not from a summary.

Scope (art. 16). Art. 17 applies to damages claims, contractual and extra-contractual, for harm caused in the use of an AI system. Any AI system. High-risk classification is irrelevant here. A consumer can sue in the court where they live. Art. 82 GDPR and the national transposition of the Product Liability Directive stay untouched.

Access to evidence (art. 17). On the claimant’s request, the judge orders the counterparty, or a third party holding it, to produce the evidence specifically pertinent to how the system works. The threshold: facts and elements that make the claim plausible, including the link between the system’s output and the harm. The decree then names what “evidence” includes:

The order is limited to what is necessary and proportionate. Trade secrets and confidential information are protected; art. 121-ter of the Industrial Property Code applies. Professional secrecy is not mentioned. Hold that thought.

Consequences (art. 17, paras 5 and 6). A party that fails to comply without justified reason: the judge may draw adverse inferences under art. 116 c.p.c.. If what’s missing is the listed documentation, the judge, having weighed all other evidence, treats the claimant’s alleged facts as admitted. A third party that refuses pays €1,500 to €10,000.

Causation (arts. 18 and 19). When the harm results from a breach of an AI Act obligation, the causal link is presumed. Rebuttable, but presumed. Compliance with the AI Act, even certified under Chapter III, Section 5, does not by itself exclude liability.

Insurance (art. 20). Before suing, the claimant may ask the alleged liable party whether it carries liability cover for the harm. Reply within 30 days: contract details, insurer’s name. Silence or an incomplete answer feeds the art. 116 inferences. If cover exists, the claimant has direct action against the insurer, within the policy limits. The decree does not mandate insurance.

flowchart TD
    A["Claimant alleges harm from an AI system<br>any risk class - art. 16(1)"] --> B{"Facts make the claim plausible?<br>art. 17(1)"}
    B -->|No| X["No order"]
    B -->|Yes| C["Judge orders production<br>from the party or a third party"]
    C --> D["Logs - art. 12 AI Act<br>Risk management - art. 9<br>Technical documentation - art. 11<br>Human oversight parameters - art. 14"]
    C --> E["Necessary and proportionate only<br>Trade secrets protected - art. 121-ter CPI<br>Professional secrecy: not mentioned"]
    D --> F{"Produced?"}
    F -->|Yes| G["Evidence on the record"]
    F -->|"Party refuses, no justified reason"| H["Adverse inferences - art. 116 c.p.c.<br>Listed documents missing:<br>claimant's facts deemed admitted"]
    F -->|"Third party refuses"| I["Fine EUR 1,500 - 10,000"]

The Directive That Wouldn’t Die

You’ve seen this structure before. Disclosure of evidence behind a plausibility threshold. A presumption against you if you don’t produce. A rebuttable presumption of causation. That’s arts. 3 and 4 of the AI Liability Directive proposal, COM(2022) 496.

The Commission withdrew it on 11 February 2025. “No foreseeable agreement.” Simplification. Competitiveness.

Italy read the withdrawal differently. Art. 24(5)(d) of Law 132/2025 - the national AI law I covered when it passed, mostly for its prison terms - delegated the government to regulate the burden of proof in AI liability cases, “taking into account the classification of AI systems” under the AI Act. Decree 160 is that delegation exercised, with a month to spare on the twelve-month deadline that started 10 October 2025.

And it went further than the directive ever did.

AI Liability Directive (COM(2022) 496)D.Lgs. 160/2026
StatusWithdrawn 11 Feb 2025In force 30 Sep 2026
Disclosure scopeHigh-risk AI systems only (art. 3)Any AI system (art. 16(1))
Claims coveredNon-contractual, fault-based (art. 1)Contractual and extra-contractual
If you don’t producePresumption of non-compliance with duty of careAdverse inferences; listed documents missing → facts deemed admitted
CausationRebuttable presumption, three cumulative conditions (art. 4)Presumed on breach of AI Act obligation, rebuttable (art. 18)
InsuranceNot addressedPre-suit disclosure request, direct action (art. 20)

The withdrawn directive only reached high-risk systems. Italy reaches everything the AI Act’s art. 3(1) definition can catch. Count what in your stack doesn’t qualify.


The Timing Problem

Here is where it gets uncomfortable.

Art. 17(2) lists four document categories by AI Act article number. All four are obligations of providers of high-risk systems. Under Regulation 2026/1744, those obligations apply to Annex III systems from 2 December 2027 and to Annex I embedded systems from 2 August 2028. Today, 30 September 2026, no provider in the EU is required by the AI Act to keep any of them.

When the Omnibus was proposed, I wrote that if you were racing to meet the August 2026 high-risk deadline, you “might be able to slow down.” As a reading of EU law, that held. In Italy, as of this morning, slowing down means meeting a disclosure order with nothing to produce.

Art. 18 presumes causation when harm results from a breach of an AI Act obligation. Which obligations can be breached today? Prohibited practices, since February 2025. GPAI model obligations, since August 2025. Art. 50 transparency, since August 2026, with a grace period to 2 December 2026 for watermarking on already-deployed systems. Not the high-risk chapter.

Art. 437-bis of the Criminal Code punishes omitting the security measures “provided for” high-risk systems. Provided for, yes. Applicable, not until December 2027. Whether a prosecutor can charge you today for omitting a measure the EU says you don’t need yet is a question the decree doesn’t answer and no court has faced.

flowchart LR
    A["11 Feb 2025<br>AILD withdrawn"] --> B["10 Oct 2025<br>Law 132/2025 in force<br>delegation starts"]
    B --> C["19 Nov 2025<br>Digital Omnibus proposed"]
    C --> D["19 Mar 2026<br>AG opinion, Rowicz C-159/25"]
    D --> E["27 Jul 2026<br>Reg. 2026/1744 in force<br>high-risk deferred"]
    E --> F["4 Aug 2026<br>Council of Ministers<br>adopts final decree text"]
    F --> G["30 Sep 2026<br>D.Lgs. 160/2026 in force"]
    G --> H["9 Dec 2026<br>PLD transposition deadline"]
    H --> I["2 Dec 2027<br>Annex III obligations apply"]
    I --> J["2 Aug 2028<br>Annex I obligations apply"]

The government’s final deliberation on the decree was 4 August 2026. Eight days after the Omnibus entered into force. Title I, the police chapter, got a safety valve: art. 21(2) says provisions that depend on the AI Act follow the AI Act’s own application dates. Title II, the civil and criminal chapter, got no such clause.

What this means in practice: art. 17(1) still works. The order covers “specifically pertinent evidence relating to the functioning of the system.” Whatever exists. Vendor logs. Prompts. Outputs. Review records. The four listed categories are examples, not a closed list.

And “without justified reason” in art. 17(5) has never been interpreted by any court. Do not be the test case.


Criminal Exposure: What 437-bis Actually Says

The summaries say “1 to 5 years.” Correct. The article has four paragraphs. Read all of them.

ConductDanger to life or public/individual safetyDanger to State security
Omitting technical security measures or human oversight, high-risk system (para 1)1-5 years2-8 years
Altering a high-risk system (para 2)2-6 years3-10 years
Para 1 conduct with gross negligence (para 3)reduced by one-third to one-sixthreduced by one-third to one-sixth
Professional user intentionally omitting human oversight (para 4)as para 1as para 1

Paragraph 4 is the one for deployers. Not providers. You. “Intentionally” is the operative word; ordinary negligence doesn’t reach it.

For companies, new art. 25-vicies of Decree 231/2001: 600 to 1,000 quotas for a 437-bis offence. At €258 to €1,549 per quota under art. 10 of the same decree, that’s roughly €155,000 to €1.55 million. Plus the interdictive sanctions of art. 9(2)(b)-(e), including a ban on contracting with public administration. The deepfake offence from Law 132/2025 (art. 612-quater) joins the catalogue at 200 to 700 quotas.

A note for readers outside Italy. Decree 231/2001 makes the company itself liable when its managers or employees commit a listed offence in its interest. The main defence is art. 6: the company is off the hook if, before the offence, it adopted and actually applied an organisation, management and control model fit to prevent that kind of offence, overseen by an independent supervisory body (Organismo di Vigilanza). That’s the “231 model” - a risk map, procedures and controls, offence by offence. It’s an Italian instrument, but it binds your Italian subsidiary too.

Every offence added to the catalogue needs its own section in the model. If you have a 231 model, it’s out of date as of this morning.


Annex III, point 8(a) of the AI Act covers systems used by or on behalf of a judicial authority to research and interpret facts and law. A drafting tool used by a law firm is not that. Recital 61 excludes purely ancillary administrative uses even inside courts. As a rule, your legal AI tool is not high-risk. That was never the same as safe - a California lawyer paid $10,000 to learn the difference.

So 437-bis doesn’t apply. Decree 231 doesn’t apply. The AI Act doesn’t require those four document categories. Arts. 17 and 20 apply anyway.

Two open points:

  1. Art. 17(3) and (4) protect trade secrets and confidential information. Professional secrecy, the privilege between you and your client, isn’t named. A disclosure order against a legal AI vendor’s logs may surface client material with no explicit shield in the decree.
  2. What counts as an “AI system” isn’t settled. In Rowicz (C-159/25), Advocate General Spielmann doubted at point 33 that Poland’s random case-allocation software qualifies under art. 3(1): predefined algorithms on fixed datasets, no post-deployment adaptability, no substantial autonomy. The judgment is pending. Until then, classify each tool and write down why.

The Loop, Revisited

In July, I argued that “a human reviewed it” is liability laundering unless you can prove it, and proposed a driving-mode memory for professional AI: model version, input context, output, reviewer identity, reviewer action, time on task, timestamps.

Ten weeks later, art. 17(2)(d) makes “parameters and arrangements for human oversight” court-orderable. The parameters describe how oversight is meant to work. Whether it did work in the case before the judge is shown by logs. Who checked, what, when. If those don’t exist, your parameters are a policy document with no evidence behind it.

The same article warned that insurers had started attaching AI exclusions to commercial liability policies. Art. 20 now lets a claimant ask you, before suing, whether you’re insured. Art. 20(3) lets the insurer raise against the claimant any exception from the contract that predates the loss. An AI exclusion is exactly such an exception. Direct action against an insurer that excluded AI is direct action against nothing.


What to Do This Week

  1. Classify every AI system. High-risk or not, under art. 6 and Annex III. Write the decision down with the reasoning. Everything else depends on this.
  2. Ask your provider three questions. What does it log? For how long? How does it hand the data over if a judge orders it? Get the answers into the contract, not an email thread.
  3. Log the review, not just the output. Reviewer, timestamp, action taken, time spent. The driving-mode memory. It is now evidence.
  4. Write the output-verification procedure. Then train people on it and keep the training records. A procedure nobody was trained on is a procedure nobody followed.
  5. Read your professional indemnity policy. Look for AI exclusions. Then read art. 20(3) again.
  6. Update the 231 model if you have an Italian entity. Add 437-bis and 612-quater to the risk map; art. 25-vicies is in force today.
  7. Watch two dates. 9 December 2026: the Product Liability Directive transposition deadline; the Italian draft decree is before Parliament now, and arts. 16(3) and 19 defer to it. 2 December 2027: high-risk obligations apply, and art. 17’s four categories stop being examples and become the law.

ISO 42001 gives you the scaffolding for items 1 to 4. It won’t make you compliant with the decree. It will make you able to produce something when the order arrives.


TL;DR

Brussels gave you until December 2027 to build the paper trail. Rome will ask for it at the first hearing.


Every article number above was checked against the decree as published in Gazzetta Ufficiale n. 214 of 15 September 2026. Title I - police use, biometric identification - is deliberately left out; it deserves its own piece. This is a reading of the statute, not legal advice. Research and drafting were done with AI assistance; the reading of the text and the opinions are human.

#En #AI #EU AI Act #Governance #Liability