Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Regulation July 29, 2026 6 min

AI Act in Italy: the data protection authority becomes market surveillance authority for high-risk systems in justice, borders and democratic processes

A favourable opinion on the draft implementing decree, with one request that concerns every employer: extend the ban on automated decisions to assessments of performance, bonuses and career progression

TL;DR for the DPO

Italy is putting in place the national governance required by the AI Act. The data protection authority will supervise high-risk systems in five sensitive sectors and is asking to extend the ban on fully automated decisions to assessments of performance, bonuses and career progression. If a client uses AI tools in HR, this is the passage to watch.

What the draft decree provides

The measure defines the national governance and supervision system for artificial intelligence and designates the data protection authority as market surveillance authority for high-risk systems used in the areas most sensitive for fundamental rights: justice, law enforcement, immigration, border management and democratic processes. It also introduces rules for the financial and insurance sectors and promotes digital literacy and training on the informed use of AI in schools, universities and professional pathways.

The choice is not obvious. In many Member States supervision of high-risk systems has been assigned to newly created authorities or to technical agencies; here a significant share stays with the data protection authority, which brings an established investigative method and a settled body of administrative decisions. For a DPO it means that, at least in those sectors, the counterpart on both the AI Act and the GDPR will be the same.

The conditions set by the authority

  • Recognise the authority's power to adopt guidelines, recommendations and good practices, on a par with the other competent AI authorities. This is the request with the greatest impact on daily work: without that power there would be no interpretive source for a DPO to rely on.
  • Clarify the rules for applying the fines within its competence, in line with the Italian Privacy Code.
  • Involve the authority in the activities of the Italian AI regulatory sandbox.
  • Clarify the authority's role in the conformity assessment procedures for high-risk systems, for which the AI Act assigns it specific supervisory functions.
  • Extend the ban on decisions based solely on automated systems to assessments that may significantly affect the employment relationship, such as those concerning performance, the award of bonuses or career progression.
  • Adjust the authority's financial resources to the new competences assigned to it by EU law.

The condition that concerns every client

The last request has the broadest reach. Today the Article 22 GDPR prohibition covers decisions producing legal effects or similarly significant impact. If the decree took up the authority's proposal, performance appraisal, bonus allocation and career progression would be covered explicitly. Many companies already use internal scoring tools for these purposes without ever having classified them: it is worth inventorying them now, before classification becomes compulsory.

The second opinion: biometrics and law enforcement

In a separate opinion, also of 14 July 2026, the authority addressed the parts of the draft governing the use of AI by law enforcement, setting limits and safeguards for biometric data processing and remote biometric identification. It found the text broadly consistent with the AI Act and with delegating law no. 132/2025, while identifying points to be strengthened: clarifying the role of human oversight, defining responsibilities in research and testing projects more precisely, and reinforcing safeguards on the quality of the biometric databases used.

The sharpest passage concerns automated and generalised processing of biometric data of people entering public places or events: in the authority's view this is not consistent with the AI Act, which allows post-remote facial recognition only for targeted searches. Processing should take place solely on recordings already acquired and where there is a specific operational need, avoiding mass and preventive collection. The authority also asks for an express prohibition on using databases obtained through indiscriminate scraping or in breach of data protection law.

Why it matters now

The AI Act calendar was amended by the Digital Omnibus package: obligations for Annex III high-risk systems apply from 2 December 2027 and those for Annex I from 2 August 2028. The deferral concerns the dates, not the substance. An implementing decree defining who supervises, with what powers and what penalties, is exactly the kind of infrastructure needed before rather than after: when the obligations become enforceable, the competent authority will already be operational.

Official source:Italian Data Protection Authority - Newsletter no. 550 of 29 July 2026; opinions of 14 July 2026 [doc-web 10275626 and 10275606]

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free