AI Regulation Tracker / EU member state implementation
Italy's draft AI Act decree would put the Garante, not a new AI office, in the rights-sensitive seat
Two opinions from the data protection authority, adopted 14 July 2026 and published 29 July, clear the drafts with conditions. The workplace ask is weaker than the summary suggests.
What actually happened on 29 July?
The Garante put two opinions into the public record. Both were adopted at the same sitting on 14 July 2026 and both carry the same verdict, parere favorevole, with conditions. The 29 July date is the publication date in Newsletter no. 550. The authority did not vote on 29 July, and any account dating the decisions to that day is describing the press release.
The two drafts split the work. Atto del Governo n. 421 is the governance decree: fifty-one articles in five chapters covering the powers of the national authorities, the sanctions regime, the Italian AI sandbox and AI literacy. Atto del Governo n. 418 covers police use of AI and liability; the Garante opined on its Titles I and III only.
Neither creates a duty today. Italy's framework law, legge 132/2025, is already in force; these decrees are the machinery underneath it. We covered the cabinet stage in Italy's AI Law 132/2025 implementing decrees. The drafts have now reached Parliament and the data protection authority has put its conditions on the record.
Which AI systems would the Garante actually supervise?
The primary text is narrower and more technical than the summary. Article 5 of the draft governance decree designates the ACN as market surveillance authority under Article 70; Banca d'Italia, CONSOB and IVASS for high-risk AI used in financing and banking and credit services; and the Garante, in the decree's own words, limitatamente a quanto sancito all'articolo 74, paragrafo 8, del regolamento IA, limited to what Article 74(8) lays down.
That is a cross-reference, not a list. Article 74(8) of Regulation (EU) 2024/1689 covers high-risk systems in point 1 of Annex III, biometrics, in so far as the systems are used for law enforcement purposes, border management and justice and democracy, plus points 6, 7 and 8 of Annex III: Law enforcement; Migration, asylum and border control management; Administration of justice and democratic processes.
The Garante's own newsletter glosses this as giustizia, attivita di contrasto, immigrazione, gestione delle frontiere e processi democratici. Accurate as far as it goes, but it drops the Annex III point 1 biometrics limb, which is the one doing most of the work in the police decree. Read the cross-reference, not the summary.
Which regulator does each EU country put in this seat?
Article 74(8) gives member states a real choice: the data protection supervisory authority, or another body designated under Articles 41 to 44 of Directive (EU) 2016/680. Europe is answering country by country, and the answer decides who shows up and what that body already knows how to do.
| Member state | Body in the Article 74(8) seat | Legal status of that choice | What that body already does |
|---|---|---|---|
| Italy | Garante, the data protection authority | Draft. Article 5 of Atto del Governo n. 421 | GDPR enforcement, biometric and workplace-monitoring cases |
| Germany | Independent chamber inside the Bundesnetzagentur, for four Annex III categories | In force. KI-MIG, BGBl. 2026 I Nr. 223 | Telecoms, energy and rail regulation, product market surveillance |
| France | CNIL, the data protection authority, as a lead authority | Bill. DDADUE text, not yet enacted | GDPR enforcement, algorithmic and surveillance casework |
| Portugal | Not settled. ANACOM coordinates the Article 77 list of 14 bodies | Article 70 designation still not in law | Communications regulation, fundamental-rights coordination |
Germany is the sharp contrast. Its implementing act is already in force and routes four Annex III categories to a walled-off chamber inside a network regulator, with financial-sector AI going to BaFin, as we covered in Germany's AI Act implementing act and BaFin. Italy proposes the opposite instinct: the rights-sensitive categories go to the rights regulator. France is heading Italy's way, though its instrument is a bill, as set out in France's move to name the CNIL a lead AI Act regulator.
For a compliance officer this is not trivia. A network regulator opens a file about product conformity and technical documentation. A data protection authority opens a file about lawful basis, necessity, proportionality and retention, with inspection powers and a fining history in the biometric and employment contexts the AI Act touches.
What did the Garante ask for on workplace AI decisions?
This is the item with the widest reach and the one most likely to be overstated. Start with the draft itself. Article 40 of Atto del Governo n. 421 requires an employer using AI systems to guarantee that decisions, including those on the establishment, modification or termination of the employment relationship, are not adopted solely on the basis of automated processing, and that the final decision is always taken by a natural person with effective and autonomous authority. The worker gets an intelligible statement of reasons showing the parameters considered.
The Garante wants that reach widened. It says the prohibition potrebbe essere opportunamente esteso alle decisioni di carattere valutativo ... suscettibili di determinare implicazioni significative sul rapporto di lavoro, could appropriately be extended to evaluative decisions with significant implications for the employment relationship.
Now the qualification that matters. In the operative part of opinion no. 532 this is not one of the four conditions. Those concern the Garante's own powers: Article 11 guideline-making, a cross-reference of its sanctions procedure to Article 166 of the Codice privacy, which option under Article 31(9) of the AI Act Italy adopts for conformity-assessment responsibility, and adding the Garante to the Article 26 sandbox where projects involve personal data. The workplace item sits separately as l'osservazione ... relativa alla valutazione dell'opportunita di estendere, an observation on the opportunity of extending. The performance, bonus and career progression examples that ran in the press are in the newsletter summary, not the operative text. We are not repeating them as if they were.
So: an advisory suggestion, on a draft, that Parliament can ignore. If adopted it reaches every employer in Italy running an appraisal, bonus or promotion process with AI in the loop, not only AI vendors. Worth watching. Not worth budgeting against yet.
What did it ask for on biometrics and scraped databases?
Opinion no. 531 attaches seven conditions to the police decree. Two matter most.
On live processing, the Garante says the draft's provision for automated processing of the biometric data of all persons entering certain places or events does not appear consistent with Article 26(10) of the AI Act, which allows post-remote facial recognition only for targeted ex-post searches of persons suspected or convicted of an offence. Its condition is that biometric processing occur only ex post on recorded traces, on a specific operational need. The draft's phrase about places or events with public order and security needs could sweep in stadiums, concerts, demonstrations, stations and urban areas.
On scraped databases, the position is narrower than the headlines. The draft already carries a prohibition on scraping non mirato, untargeted scraping, defined in Article 2 and prohibited at Article 8(3), consistent with Article 5(1)(e) of the AI Act. Condition (g) asks for that same prohibition to be reproduced in Article 13, the article that would insert a new Article 359-ter into the code of criminal procedure, so the two read consistently. That is a drafting-consistency request, not a new ban.
Condition (d) is the one a technologist should read: reference databases used for identification need data-quality requirements, defined deletion, and a guarantee of non-incrementality, so each authorisation does not enlarge the comparison set.
What should a US professional with Italian exposure do now?
None of this binds anyone yet. The duty sits on the Italian legislature.
For planning, three things follow. If your firm sells or operates AI touching Italian policing, immigration, courts or elections, the counterparty to model is a data protection authority with an active biometric enforcement record, so your documentation should answer necessity and proportionality questions, not only conformity questions. If you employ people in Italy and use AI in appraisal, bonus or promotion workflows, track the draft Article 40 duty on human final decision-making; the observation is the tail risk that would extend it to evaluations. And if you wanted one EU-wide answer to who supervises high-risk AI, there is none. Four states, four answers, three legal statuses.
One more signal. The Garante said its current appropriations are insufficient for the competences being assigned to it. A regulator that says it is under-resourced while accepting a new mandate is telling you something about enforcement pace in year one.
Frequently asked questions
Has Italy enacted an AI Act implementing decree?
No. Both are still schemi di decreto legislativo, draft legislative decrees before Parliament as Atto del Governo n. 421 and n. 418, under Article 24 of legge 23 settembre 2025, n. 132. They carry no decree number and impose no obligations yet. The Garante's opinions, adopted 14 July 2026 and published in Newsletter no. 550 of 29 July 2026, are advisory acts on those drafts.
Which AI systems would the Garante supervise in Italy?
Article 5 of the draft designates the Garante as a market surveillance authority limited to Article 74(8) of the AI Act, which covers Annex III point 1 biometrics in so far as used for law enforcement, border management and justice and democracy, plus Annex III points 6, 7 and 8: law enforcement; migration, asylum and border control management; and administration of justice and democratic processes. The same article sends financing and banking AI to Banca d'Italia, CONSOB and IVASS, and makes the ACN the general market surveillance authority.
Did the Garante ask Italy to ban solely automated workplace decisions on performance and promotion?
It asked Parliament to consider it. In the operative part of opinion no. 532 the item is an osservazione, an observation on the opportunity of extending the Article 40 prohibition to decisioni di carattere valutativo with significant implications for the employment relationship. It is not one of the four conditions. The performance, bonus and career progression examples appear in the newsletter summary, not the operative text.
What did the Garante say about facial recognition at stadiums and public events?
In opinion no. 531 it said automated processing of the biometric data of everyone entering certain places or events does not appear consistent with Article 26(10) of the AI Act, which permits post-remote facial recognition only for targeted ex-post searches of persons suspected or convicted of an offence. Condition (f) is that biometric processing occur only ex post on recorded traces, on a specific operational need. It warned the draft's wording could reach stadiums, concerts, demonstrations, stations and urban areas.
Last verified: July 29, 2026