The first of the comprehensive EU AI laws establishes prison sentences of one to five years for the creation of deepfakes and other types of content found to cause harm, as well as enhanced penalties for existing crimes that are supported by the use of AI.
Italy passed Senate Act No. 1146-B in mid-September, the first law of its type in the bloc to address a wide range of AI-related crimes in alignment with the EU AI Act. The law also sets a minimum age of 14 for children to make use of AI services without parental consent. The bill further addresses the widespread practice of mass data scraping needed to feed AI training, and further specifies the terms under which copyrighted works can be used.
Italy produces first EU AI law criminalizing use & spread of harmful content
The first-of-its-kind EU AI law was championed by Prime Minister Giorgia Meloni’s government and passed by the Italian parliament as an assurance of safe and privacy-respecting use of AI paired with terms included to foster innovation, such as the authorization of a one billion euro state-backed fund to provide venture capital to companies active in the space.
One of the most noteworthy elements is the potential criminalization of content created with AI and dissemination of it, should it be judged to have caused real-world harm. This obviously includes sexual abuse materials, but also seems to have been specifically drafted with an eye toward the increasingly sophisticated use of “deepfakes” in fraud schemes. There are now multiple incidents of criminals pulling off a representation of a business leader’s voice to convince a target to provide access or authorize a payment, including at least one in which a real-time fake voice was paired with old video of a legitimate Zoom conference call.
In addition to this new category of penalty, which can include one to five years in jail, the EU AI law establishes stronger penalties for an assortment of related offenses that involve fraud and identity theft. There are some new legal obligations for employers to be transparent with employees about use of AI in workplaces as well, and health care professionals can use AI to assist with diagnosis and care decisions but must have a human make the final decision and must fully inform patients of how it is being used.
The new age restriction is also in keeping with prior actions by Italy, which was the first nation in the bloc to temporarily ban ChatGPT (in March 2023) over concerns about whether the personal information and privacy of children was being properly protected. Users of chatbots will now be required to first obtain parental consent if they are under the age of 14.
New EU AI law addresses scraping and copyright claims
The new EU AI law also sets some clearer terms about how AI data scrapers can make use of the mountains of content they need to train on. The path is largely clear for data scrapers to train on non-copyrighted content, but AI firms will have to be wary of using anything under copyright; some exceptions can be made for authorised research institutions engaged in scientific projects. This element refers to the existing terms of the EU’s 2019 DSM Directive, which does require some copyright holders to affirmatively “opt out” of being scraped. However, the EU Parliament has been weighing the prospect of changing the DSM to provide copyright holders with more automatic protection for content that is openly published and available on the internet.
On the other end of copyright terms, the new EU AI law specifies some protections for content that was developed with assistance by AI; rights can be protected under the law if it demonstrates “intellectual effort” and does not otherwise violate elements of copyright law.
Though it is the first of the EU AI laws of this type, the bill took nearly a year of debate in parliament and revision; it ultimately passed 77-55. It also comes well ahead of the full rollout of the EU AI Act, which went into force in August 2024 but is moving forward in phases that do not fully complete until 2030. Rules regarding general purpose AI models, such as chatbots, only began to go live at the start of August of this year and compliance with all regulations is not fully mandatory until August 2027 (though many are in force by August 2026). The broader EU AI law focuses heavily on “high risk” AI systems and mandates model evaluations, adversarial testing, and reports on “serious” incidents and “national level” risks.
Enforcement of the new EU AI law will primarily be the charge of the Agency for Digital Italy (AgID) and the National Cybersecurity Agency (ACN), with the Department for Digital Transformation (DDT) in charge of broader AI strategy for the nation.

