Italy's Decree 160 Is Now in Force (September 30, 2026): Direct Action Against AI Insurers, Presumed Causation, and Facts-Deemed-Admitted Sanctions
The entry-into-force watch has fired: Italy's Legislative Decree no. 160 of 9 September 2026 (Gazzetta Ufficiale no. 214, September 15) entered into force on September 30, 2026, as tracked by Digital Policy Alert's timeline ("in force — 30 Sep 2026") and confirmed by LCA Studio Legale: "Legislative Decree No. 160 of 9 September 2026 will enter into force on 30 September 2026... It was adopted in implementation of Law No. 132/2025." IAPP likewise notes the decree "regulates police use of AI, introduces statutory criminal sanctions, expands corporate administrative liability and establishes specialized civil litigation mechanisms."
With the decree live, the civil chapter's mechanics are now operative law, and CMS's September 30 analysis details what claimants and insurers gain:
- Art. 20 — direct action against the insurer. "Anyone who has suffered damage caused by an AI system may bring a direct action against the insurer providing civil liability coverage to the party responsible for the damage." The claimant may first ask the allegedly liable party whether it carries professional insurance; that party must respond within 30 days with policy details, and a failed or incomplete response "may be taken into account as evidence" by the court. The action is capped at policy limits; the insurer may raise only contractual defences arising before the loss; the liable party must be joined as a necessary co-defendant.
- Art. 17 — compelled evidence with teeth. Courts may order disclosure of "logs, technical documentation, risk management records and human oversight documentation." Non-compliance is sanctioned by deeming "the facts alleged by the injured party... admitted"; a non-party failing to disclose faces a sanction.
- Art. 18 — presumed causation. "If the damage results from a breach of obligations under the AI Act, the causal link is presumed.1"
- Art. 19 — compliance is not a safe harbor. "Compliance with the AI Act, including through certification, does not in itself exclude liability."
CMS flags the open questions enterprises and insurers are already wrestling with: Article 20 never defines who the "liable party" is (overlap risk between liability regimes), which post-loss defences the insurer is barred from raising, which policy line the direct action attaches to, and the anomaly that the direct action exists "without a framework" — Italy imposed none of the three elements (mandatory insurance, compulsory underwriting, regulated policy content) that normally anchor direct-action regimes in Italian law. Practical consequence: "Producers, professional users and deployers of high-risk AI systems will need adequate third-party liability insurance policies," and underwriting models must be rebuilt around presumed causation and the diminished weight of certification.
Combined with the criminal offence (Art. 437-bis — neglecting safety of a high-risk AI system) and the expanded 231 corporate-liability regime, Italy is now the first EU member state where AI governance failures carry simultaneously criminal, corporate-administrative, and claimant-friendly civil exposure. See the prior revision for the criminal anatomy, and EU PLD Transposition Countdown: Three States Done, Twelve in the Pipeline — and National Divergences Emerging Under a Maximum-Harmonization Directive for the parallel EU-level strict-liability track arriving December 9, 2026.
-
An instance of AI Act safety duties now harden into criminal offences and liability presumptions. — Italy's decree now in force converts AI Act breaches into presumed causation, direct insurer actions, deemed-admission evidence sanctions, and a new criminal offence — the hardening of AI Act duties into liability and crime, live. ↩︎