Artificial Intelligence and Corporate Liability under Legislative Decree No. 231/2001: Why Organisational Models Must Be Updated

Artificial Intelligence and Corporate Liability under Legislative Decree No. 231/2001: Why Organisational Models Must Be Updated
The adoption of artificial intelligence tools across business processes—from recruitment and procurement to management control and predictive marketing—is fundamentally reshaping the way companies operate. Less immediately apparent, yet equally significant, is the impact these technologies have on the corporate administrative liability regime established by Legislative Decree No. 231 of 8 June 2001 (“Legislative Decree No. 231/2001”). Those responsible for corporate compliance should now consider whether their Organisation, Management and Control Model (the “Model”) remains capable of preventing criminal offences where decisions, or the processes supporting them, are increasingly delegated to algorithms.

Where AI Introduces New Predicate Offence Risks

The use of AI systems in business processes does not, in itself, create new criminal offences. What changes is the manner in which the predicate offences already contemplated by Legislative Decree No. 231/2001 may be committed—or may in future be committed following the expansion of the catalogue of predicate offences—often in ways that are less visible than direct human conduct.

In procurement processes and public tender procedures, an AI system used to select suppliers or formulate bids may, if improperly configured or trained on biased data, generate outcomes capable of amounting to corruption or bid-rigging offences, thereby giving rise to liability for offences against the public administration.

In data processing and cyber security, the use of AI for large-scale data analysis increases exposure to the cyber offences provided for under Article 24-bis of Legislative Decree No. 231/2001, particularly where systems access, aggregate or transfer data without adequate safeguards.

Within financial management and accounting, algorithms employed for predictive analysis or reporting may, if insufficiently supervised, contribute to inaccurate financial representations capable of giving rise to corporate offences.

In manufacturing environments, AI systems applied to occupational health and safety—for example, in workforce scheduling or risk monitoring—may generate liability where their recommendations are followed uncritically without meaningful human oversight, with potential implications for the offences referred to in Article 25-septies.

A further cross-cutting issue concerns algorithmic discrimination in recruitment processes or customer assessment. Although such discrimination does not invariably constitute a predicate offence in itself, it exposes organisations to significant reputational risks, litigation and, in certain circumstances, criminal liability where discriminatory practices amount to more serious unlawful conduct.

The underlying principle is clear: whenever a corporate decision is supported or generated by an algorithm, the question arises as to who bears responsibility and, above all, whether the organisation had implemented appropriate controls to prevent the misuse or unsupervised operation of that technology.

The Interaction with the EU Artificial Intelligence Act

The framework governing predicate offences under Legislative Decree No. 231/2001 must now be considered alongside Regulation (EU) 2024/1689 (the AI Act), which entered into force on 1 August 2024 and whose provisions will apply progressively according to the level of risk posed by the AI systems concerned.

For AI systems classified as high-risk, the AI Act imposes obligations relating to risk management, data quality, technical documentation, transparency and human oversight. In substance, many of these obligations overlap with the preventive controls that an effective Model under Legislative Decree No. 231/2001 should already incorporate.

Companies that are adapting their governance frameworks to comply with the AI Act therefore have an opportunity to update their Model concurrently, avoiding duplication while developing a coherent internal control framework in which the safeguards required by European AI legislation and those required under Legislative Decree No. 231/2001 reinforce one another.

The June 2026 Turning Point: Proposed New Article 25-

vicies

The regulatory landscape has recently acquired a significant new element.

On 10 June 2026, the Italian Council of Ministers gave preliminary approval to a draft legislative decree implementing Regulation (EU) 2024/1689 and Law No. 132 of 23 September 2025. Article 17 of the draft introduces a new Article 25-vicies into Legislative Decree No. 231/2001, entitled “Offences Committed Through the Use of Artificial Intelligence Systems”.

It is important to be precise regarding the current legal position. At present, this is merely a draft legislative decree approved on a preliminary basis. It must still be reviewed by the competent Parliamentary Committees, the State-Regions Conference and the Italian Data Protection Authority (Garante per la protezione dei dati personali), and may therefore be amended before receiving final approval. Nevertheless, its overall structure already warrants careful consideration.

The proposed Article 25-vicies expands the catalogue of predicate offences by introducing two new criminal offences, likewise created by the draft decree: Articles 437-bis and 612-quater of the Italian Criminal Code.

Article 437-bis is not structured as a single, uniform offence but comprises several distinct scenarios.

Paragraph 1 establishes an omission-based offence involving concrete endangerment. It criminalises the failure to adopt appropriate technical measures to prevent malfunctions or manipulation of high-risk AI systems, as well as the failure to implement the necessary supervisory measures, where such omissions create a concrete risk to life or personal safety. More severe penalties apply where the danger concerns public safety or State security.

Paragraph 2 establishes a separate intentional offence based on active conduct, consisting of the manipulation of a high-risk AI system.

Paragraph 3 introduces a mitigating circumstance applicable to the omission-based offence where the conduct results from gross negligence rather than intentional misconduct.

Accordingly, it would be technically inaccurate to characterise Article 437-bis as a purely omission-based offence. Rather, a distinction must be drawn between the omission-based offence under paragraph 1 and the active offence under paragraph 2.

The proposed Article 612-quater, introduced by the draft implementing decree under Law No. 132/2025, criminalises the non-consensual transfer, publication or dissemination of AI-generated or AI-manipulated content—commonly referred to as deepfakes, including images, videos or voice recordings—where such conduct causes harm to the individual portrayed.

From a legal perspective, the mechanism for attributing liability to the organisation remains unchanged. Liability under the proposed Article 25-vicies arises only where one of these offences is committed by a senior manager or subordinate acting in the interest of, or to the benefit of, the organisation, and where the offence was made possible by an organisational failure on the part of the entity, in accordance with the general framework established by Articles 5, 6 and 7 of Legislative Decree No. 231/2001.

Issues Raised in Legal Scholarship: Emerging Interpretative Challenges

The discussion now moves from established law to matters of legal interpretation, and it is important to distinguish between the two, particularly as the proposed legislation has not yet entered into force.

Academic commentators have identified at least three principal areas of concern.

The first concerns identifying the person responsible for failing to implement the required safety measures. Questions arise as to whether liability should rest with the developer, programmer, system integrator or the organisation deploying the AI system, particularly given that the traditional principles governing defective product liability may be ill-suited to AI systems capable of learning from data and adapting their behaviour over time.

The second issue relates to the inherent unpredictability of certain AI systems, arising both from machine learning and from the phenomenon of so-called black box algorithms, in which the relationship between input data and resulting outputs cannot be fully reconstructed.

According to a number of commentators, this makes it particularly difficult to establish the organisational fault required to trigger corporate liability, especially where gross negligence under paragraph 3 of Article 437-bis is alleged. The concern expressed in legal scholarship is that this may ultimately lead to forms of liability approaching strict liability.

The third issue concerns the potential interpretation of Article 8 of Legislative Decree No. 231/2001, which permits corporate liability even where the individual responsible for the predicate offence has not been identified or is not criminally liable.

Some commentators have questioned whether this provision could also apply where the individual offender has been identified but lacks the requisite criminal intent or fault.

The preferable interpretation, however, rejects such an extension, as it would amount to an impermissible analogy in malam partem in criminal law. Where no criminal offence exists because the individual lacks the necessary culpability, the prerequisite for the organisation’s administrative liability likewise falls away.

These remain interpretative considerations which will ultimately be tested in practice once the legislation enters into force, rather than principles already established by case law.

Updating the Organisation, Management and Control Model

One of the most challenging aspects concerns the very nature of many artificial intelligence systems, often described as “black boxes” because the relationship between input data and the resulting output cannot always be fully reconstructed. This characteristic sits uneasily alongside one of the fundamental principles underpinning Models adopted pursuant to Legislative Decree No. 231/2001: the traceability of decisions and the verifiability of internal controls.

A Model developed on the assumption that all material decisions can always be attributed to an identifiable individual risks failing to capture the risks arising from partially automated processes. Consequently, updating the Model cannot be limited to a generic reference to the use of technological tools. Instead, it requires a dedicated risk-mapping exercise, similar to those previously undertaken in relation to cyber risks and personal data protection.

Where business processes involve AI systems, an effective update of the Model requires, above all, a structured methodology rather than a mere checklist of control measures. One practical approach, already adopted by several organisations, is to proceed through progressive stages, beginning with the overall governance of AI within the organisation before moving on to the formal revision of the Model itself.

The first stage consists of identifying all AI systems currently in use or under development and classifying them in accordance with the AI Act’s risk-based approach, distinguishing whether the organisation acts as the provider or the deployer of each system. This preliminary assessment is indispensable, since both the type of AI system—for example, a recruitment decision-support system as opposed to a robotic device used in manufacturing—and the organisation’s role determine not only the obligations imposed by the AI Act but also the nature of the potential predicate offences that may arise.

The second stage concerns the establishment of an internal AI governance framework. This should take the form of formally adopted corporate policies defining the objectives and principles governing the use of AI, allocating responsibilities across the various business functions, and avoiding the concentration of oversight exclusively within the IT department. It should also include regular reporting to senior management on the operation of AI systems, particularly those classified as high-risk, together with procedures for risk management and incident handling.

Within more complex organisations, or where AI plays a particularly significant role, consideration may also be given to appointing a dedicated AI Governance Officer responsible for coordinating regulatory compliance across the business, or alternatively assigning these responsibilities to the existing Risk & Compliance function, where one already exists.

Only after these governance measures have been implemented should the organisation proceed to the third stage: the formal revision of its Model under Legislative Decree No. 231/2001.

Several key areas should be addressed.

The first concerns the integration of the existing risk assessment. Rather than simply associating AI-enabled business processes with generic categories of predicate offences, the assessment should evaluate the actual characteristics of each AI system, including the degree of algorithmic opacity, the quality of the training data and the level of decision-making autonomy delegated to the system. This enables a more realistic assessment of the likelihood that criminal conduct may occur.

Secondly, organisations should introduce dedicated protocols governing the acquisition, configuration and operation of AI systems. These protocols should require genuine human oversight, particularly where high-impact decisions are involved, rather than a merely formal endorsement of the system’s output.

Thirdly, particular emphasis should be placed on traceability. Organisations should be able to reconstruct which data were used, which version of the AI system generated a specific output and who ultimately validated the final decision. Without such documentation, it becomes difficult both for the Supervisory Body (Organismo di Vigilanza—the supervisory body established under Legislative Decree No. 231/2001) to perform its monitoring functions and, should proceedings arise, for the organisation to demonstrate the effective implementation of its Model.

A further area concerns the management of third-party AI providers. Appropriate contractual provisions should require transparency regarding the operation of AI systems, software updates and training methodologies, while also granting audit rights, including to the Supervisory Body.

Finally, organisations should provide targeted training for personnel using AI systems so that they understand both the capabilities and limitations of those technologies and avoid relying upon them uncritically. The Code of Ethics should likewise be updated to incorporate principles governing the responsible use of artificial intelligence within the organisation. Reporting lines to the Supervisory Body should also be expanded to include the mapping of AI systems in use, the outcomes of audits and monitoring activities, together with any anomalies or incidents identified.

As regards the development of an AI risk management framework, a useful—albeit non-binding—technical reference is UNI CEI ISO/IEC 42001, which establishes requirements for implementing, maintaining and continuously improving an artificial intelligence management system. It may therefore serve as a common framework for aligning compliance under Legislative Decree No. 231/2001 with broader organisational AI governance measures.

Finally, a brief observation should be made concerning the proposed Article 25-vicies discussed above. Pending its final approval, organisations developing or deploying AI systems classified as high-risk under the AI Act can already begin preparing by including this prospective category of predicate offence within their risk-mapping exercises, assessing whether appropriate technical and supervisory safeguards are in place to prevent malfunctions or manipulation of high-risk AI systems, and adopting protocols designed to prevent the non-consensual dissemination of AI-generated content, including where third parties unconnected with the organisation may be affected.

The formal revision of the Model should, however, be completed only once the legislative text has been definitively approved, and organisations should closely monitor the progress of the parliamentary approval process.

An Operational Checklist

For organisations wishing to commence this process, an initial compliance review should include identifying all AI systems currently in use, classifying them according to both risk category and relevance to existing—and prospective—predicate offences, including those envisaged under the proposed Article 25-vicies. It should also include verifying the existence of effective human validation procedures for automated decision-making, reviewing contractual provisions governing relationships with technology suppliers, assessing the adequacy of staff training programmes, updating reporting procedures to the Supervisory Body so that they expressly cover the use of AI within sensitive business processes, and monitoring the parliamentary approval process for the draft legislative decree approved on 10 June 2026 in order to update the Model promptly once the legislation enters into force.

Conclusions

Artificial intelligence is not, in itself, an additional source of risk beyond those already addressed—or soon to be introduced—under Legislative Decree No. 231/2001. Rather, it acts as a multiplier, increasing the number of ways in which existing risks may materialise, frequently in forms that are less visible and more difficult to attribute.

The proposed Article 25-vicies, specifically designed to address offences committed through the use of AI systems, adds a further dimension to this landscape and is likely to present businesses—and legal scholars alike—with significant interpretative challenges concerning organisational fault and the inherent unpredictability of algorithmic decision-making.

Organisations that have already integrated AI into their operations, as well as those planning to do so, should therefore regard the revision of their Organisation, Management and Control Model not as a purely formal compliance exercise, but as an opportunity to develop a more robust governance framework capable of reconciling technological innovation with the effective prevention of corporate criminal risk.

Lawyer Eduardo Guarente

Related Posts
Newsletter

Iscriviti per ricevere i nostri aggiornamenti

* campi obbligatori