AI and the legal professions: compulsory training and remuneration linked to the risk associated with the tool

Following Legislative Decree 160/2026 on policing and accountability, Legislative Decree 179/2026, which came into force on 23 October, sets out the rules for the training of lawyers and magistrates and paves the way for the adjustment of fair remuneration for professionals based on the risk associated with the system used. It declares employer decisions made solely by an algorithm to be null and void and protects training data as trade secrets: a safeguard that also carries weight in legal proceedings

Working process startup. Businessman working with new finance project at office with laptop, tablet and graph data documents on his desk

9' min read

Translated by AI
Versione italiana

9' min read

Translated by AI
Versione italiana

On 15 September, the Official Gazette published Legislative Decree No. 160 of 9 September 2026, which came into force on 30 September. The decree regulates the use of artificial intelligence in policing and sets out the scope of criminal and civil liability. Three weeks later, the second piece of legislation was issued: Legislative Decree No. 179 of 7 October 2026, published in Official Journal No. 234 of 8 October and in force from 23 October. Both implement the delegated powers under Article 24 of Law No. 132 of 23 September 2025. The first 35 of the 54 articles of Legislative Decree 179 bring the legal framework into line with Regulation (EU) 2024/1689, the AI Act, and allocate supervisory and sanctioning powers amongst AgID, ACN, the Bank of Italia, Consob, Ivass and the Data Protection Authority. However, several provisions directly concern lawyers, in-house legal counsel, judges and judicial administration staff. The second decree alters three aspects of their work: how they are trained, how professionals’ remuneration may be structured, and the matters on which litigation may arise.

Continuing professional development: a minimum number of hours required

Loading...

The most immediate change for the regulated professions is set out in Article 47. Initial and continuing training courses organised by the professional bodies must include programmes on digital literacy and training in the use of AI systems. The decree sets out the minimum content for these programmes across three levels:

  • technical: how the systems work, what they are capable of and what their limitations are within their respective sectors. The text expressly refers to ‘questioning and instruction techniques’, i.e. prompting;
  • legal: the AI Act and national implementing regulations;
  • ethical: the professional’s responsibility in the use of AI, the duty to inform the client and the anthropocentric principle set out in Article 1, paragraph 1, of Law No. 132/2025.

Professional bodies cannot decide whether to participate. For each continuing professional development assessment period, there is a minimum number of hours set aside for AI, which the decree does not specify: this will be determined by the regulations of each professional category. The national councils of professional bodies and associations, including the National Bar Council, have six months to bring their regulations into line, with a deadline of 23 April 2027. They must follow the procedures laid down for each category, including any required opinion or approval from the supervisory authority. This obligation also applies to courses organised by umbrella organisations of associations representing non-regulated professions (Article 3 of Law No. 4/2013), where AI is relevant to their activities. Under Article 43, professional bodies and trade associations may organise these courses in partnership with universities, public research bodies and higher education institutions for the arts, music and dance (AFAM). The provision reinforces Article 13 of Law No. 132/2025 with regard to the training programme. That article restricts the use of AI in intellectual professions to instrumental and support activities, where intellectual work predominates, and requires clients to be informed. This information is now also a subject of compulsory training.

Fair compensation: the system’s risk class matters

Article 49 introduces a new provision that is set to spark debate. According to the provision, the use of AI systems by professionals “may result in an adjustment to the fair remuneration” provided for under Law No. 49/2023. The parameters must take into account the risk class of the system as defined by the AI Act. The provision does not specify whether the adjustment will be upwards or downwards and operates within the scope of Law No. 49/2023, that is, in dealings with banks, insurance companies and their subsidiaries and agents, businesses with more than 50 employees or more than 10 million euros in turnover, and the public administration. The following must be incorporated within 12 months:

  • the decrees on the parameters provided for in Article 9 of Decree-Law No. 1/2012;
  • the decrees on the parameters adopted pursuant to Article 1(1)(c) of Law No. 49/2023 on fair remuneration;
  • for lawyers, the decree on legal fees under Article 13(6) of Law No. 247/2012.

The choice of risk class as a benchmark might suggest that particular attention should be paid to the liabilities associated with the use of AI, rather than simply to time savings. This is, however, merely an interpretation: the actual impact on remuneration will depend on the implementing parameters, which will need to clarify how to translate the regulatory criterion into economic values.

Judges: training in human surveillance

With regard to justice, Article 46 sets out the training programmes provided for in Article 15(4) of Law No. 132/2025 for staff in the administration of justice. They must, first and foremost, ensure compliance with the literacy requirements of Article 4 of the AI Act. They comprise technical modules, including interrogation and investigation techniques and cyber security, and legal modules, with particular emphasis on the principles and limitations of Article 15 of Law No. 132/2025. That provision always reserves to the judge the final decision on the interpretation and application of the law, the assessment of facts and evidence, and the adoption of measures. The courses must also address the impact of AI on the organisation of the judiciary and on individuals’ rights. Training will be tailored to the functions performed, the context of use and the risk level of the systems employed, and must be updated periodically. The most significant point is in paragraph 3: when high-risk systems are used, the training must provide the skills necessary for human oversight required by Article 26(2) of the AI Act. Systems classified as high-risk under the AI Act include, amongst others, those intended to support judicial activities in the cases identified in Annex III to the Regulation. In such cases, the Regulation requires that human oversight be entrusted to individuals possessing the necessary competence, training and authority: the training is specifically designed to provide judges with this competence. The training of judges is the responsibility of the Higher School of the Judiciary, in accordance with the guidelines set out by the Minister of Justice. The Ministry is responsible for other staff and may enter into agreements with the School to organise joint courses. Article 30 also provides for regulatory sandboxes for AI models and systems ‘applicable to judicial activities’. The procedures for their establishment, management and operation will be set out in one or more regulations adopted by Prime Ministerial Decree, on the proposal of AgID and ACN and after consultation with the Ministry of Justice. These will be controlled environments in which to develop and test these tools in accordance with the AI Act.

Employment: purely algorithmic decision, dismissal invalid

Loading...

For labour law experts, the main change is Article 41: it concerns final decisions on the establishment, modification and termination of the employment relationship, including disciplinary measures and performance appraisals. An employer using AI systems must ensure that these decisions are not taken solely on the basis of automated processing. The final decision must always rest with a natural person ‘who exercises effective and independent authority’, a formulation that excludes mere token human oversight. Unlike Article 22 of the GDPR, the employee’s consent does not constitute an exception to the prohibition. The penalty is clear: any dismissal ordered in breach of the prohibition is null and void, as are any other decisions taken in the same manner. The employee may also, upon request and through the intervention of a natural person, obtain a ‘comprehensible explanation’ of the decision, which must indicate any impact of AI systems on the decision-making process and the main parameters taken into account. This right is in addition to the information required under Article 1-bis of Legislative Decree No. 152/1997, to be provided before processing begins, the right of access to the data collected, and the rights provided for in Articles 13, 15 and 22 of the GDPR. However, the prohibition does not apply to the search for and selection of candidates , which are not considered final decisions on the establishment of the employment relationship, even when they result in candidates not being admitted to subsequent stages of the selection process. It is likely that litigation will centre on this aspect, not least because the AI Act still classifies systems used for recruitment as high-risk.

Sanctions, complaints and financial arbitrators

The maximum amounts of the penalties (Article 23) are the same as those set out in the AI Act:

  • prohibited practices: up to 35 million euros or, if higher, 7 per cent of annual global turnover;
  • Obligations of suppliers, deployers, authorised representatives, importers, distributors and notified bodies, including transparency (Article 50) and the reporting of serious incidents (Article 73): up to 15 million or, if higher, 3 per cent;
  • inaccurate, incomplete or misleading information provided to notified bodies or authorities: up to 7.5 million or, if higher, 1 per cent.

For SMEs and innovative start-ups, however, the lower amount applies, in accordance with Article 99(6) of the AI Act. The decree introduces additional provisions of its own. It provides for a further bracket, up to €1 million or, if higher, 0.5 per cent of turnover, for breaches of the obligations set out in Articles 27 (fundamental rights impact assessment) and 86 (right to an explanation) of the Regulation. When calculating the fine , it is taken into account whether the breached obligation is “substantive or formal”. For breaches of minor seriousness or danger, Article 22 allows, as an alternative to a financial penalty, non-financial measures: an order to remedy the breach or, if the breach has ceased, a public statement of the breach. If the order is not complied with, the financial penalty is increased by up to one third, subject to the maximum limits. Law No. 689/1981 applies to the proceedings, insofar as it is compatible, but not Article 16: payment of a reduced amount is excluded. The Bank of Italia, Consob and Ivass, on the other hand, follow their own procedures, namely Article 145 of the Consolidated Banking Act (TUB), Article 195 of the Consolidated Financial Act (TUF) and Articles 311-septies and 324-octies of the Private Insurance Code; for the Data Protection Authority, Article 166 of the Data Protection Code applies. The decisions will be published in extract form, indicating any appeal lodged and its outcome. Article 18 guarantees full adversarial proceedings in complaints. A complaint lodged with the wrong authority must be forwarded ex officio to the competent authority. Furthermore, the ABF, the ACF and the Insurance Arbitrator may rule on appeals concerning breaches of the AI Act committed by participating financial institutions, within their respective areas of competence.

Data and algorithms protected as trade secrets

Article 52 adds a paragraph 1-bis to Article 98 of the Industrial Property Code. The protected confidential information expressly includes “data, algorithms and mathematical methods for training artificial intelligence systems”: model architectures, optimisation functions, training procedures and configurations, as well as any other technical and computational elements useful for the development of such systems. The requirements of confidentiality, economic value and reasonably adequate protective measures remain necessary. Article 53 confirms that disputes fall within the jurisdiction of specialised commercial divisions. This provision must be read in conjunction with Legislative Decree No. 160/2026. Article 17 of that decree provides that, in actions for compensation for damage caused by the use of an AI system, whether contractual or non-contractual, the court, at the request of the injured party, order the other party or a third party to produce evidence regarding the system’s operation, where the claimant has established a prima facie case. The order may relate to system logs, risk management documentation, technical documentation and human supervision parameters. However, it must remain necessary and proportionate and safeguard trade secrets and confidential information, including through the provisions of Article 121-ter of the Industrial Property Code, which specifically protects the trade secrets referred to in Article 98 during legal proceedings. If the party fails to comply without justifiable reason, even only in part, the court may infer evidence therefrom pursuant to Article 116 of the Code of Civil Procedure; if the failure to comply relates to the documentation listed in the provision, the court, having assessed all other evidence, shall deem the facts alleged by the claimant to be established. A third party who fails to comply without justifiable cause shall be liable to a fine of between 1,500 and 10,000 euros. For in-house lawyers, therefore, verifying that the confidentiality measures regarding datasets and models are indeed ‘reasonably adequate’ becomes a practical task: without the classification as a secret, the substantive protection afforded by Articles 98 and 99 of the Industrial Property Code is lost; in proceedings for damages, Article 17 of Legislative Decree No. 160/2026 continues, however, to protect confidential information, but only as a limitation on the order to produce evidence.

Two decrees, a single framework

Legislative Decree No. 160/2026 introduced Article 437-bis into the Criminal Code, which punishes the failure to implement security measures or human surveillance in high-risk systems and, as a separate offence, the tampering with such systems, in both cases where this results in a danger to life or to public or individual safety or to national security; a professional user who intentionally fails to provide human surveillance is also liable. It has also inserted Article 25-vicies into Legislative Decree No. 231/2001, which extends the liability of legal entities to the offences under Articles 437-bis and 612-quater of the Criminal Code. In civil proceedings, Article 18 presumes a causal link, unless the contrary is proved, where the damage arises from a breach of obligations under the AI Act. Article 19 specifies that the system’s compliance, even if certified, does not in itself exclude liability. For consumers seeking compensation, the court of the place where they have their residence or domicile also has jurisdiction (Article 16). Article 20 allows the injured party to ask, in advance, the party they consider liable for the damage whether they are covered by civil liability insurance in respect of that damage. This request is not a prerequisite for bringing proceedings, but the addressee must reply within thirty days: in the event of a failure to reply or an incomplete reply, the court may treat this as evidence. Above all, the injured party has a direct claim against the insurance company, within the limits of the policy’s maximum cover, with the alleged liable party as a necessary co-defendant. Legislative Decree No. 179/2026 complements this framework in terms of professional competence. The first decree sets out who is liable and how the damage is to be proven. The second decree sets out how lawyers and judges must prepare to use AI and paves the way for adjusting the fair remuneration of professionals according to the risk posed by the systems used. For the legal profession, there are two key deadlines to note: 23 April 2027 for the training regulations and 23 October 2027 for the new remuneration parameters.

 

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti