TwinEthos homeRequest access

Law

Italy Law 132/2025 (AI law)

Agenzia per la cybersicurezza nazionale (ACN) and Agenzia per l'Italia digitale (AgID) as national AI authorities (Art. 20); Garante per la protezione dei dati personali for data processing · IT · 8 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: www.normattiva.it.

Trust and provenance 3 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 8 of 8 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 8
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 8 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 8.
Audit standard
8 of 8 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
10 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 8 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Tell users in plain language about the processing of their data by AI systems, its risks, and their right to object (Italy, Law 132/2025 Art. 4(3))

Law 132/2025, Art. 4(3) (plain-language information on AI data processing; right to object) · official text · In force: applies since 10 Oct 2025 · IT

From 2025-10-10, Italian Law 132/2025 Art. 4(3) requires the information and communications on data processing connected with the use of AI systems to be given in clear and simple language, so that the user can know the risks and exercise the right to object to authorised processing of their personal data. Detect a privacy notice (informativa) that never mentions the AI processing next to the right to object.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Oct 2025
Official source
Law 132/2025, Art. 4(3) (plain-language information on AI data processing; right to object) · captured 2 Oct 2026 · anchor hash (SHA-256) 57127c6057c6… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Notices outside the repository
  • In-product notices at the AI feature not named as privacy notices
  • The notice may be served from a CMS outside the repository; a repository copy may lag the published notice.

Who it applies to

  • Duty falls on: controller
  • Controllers whose use of AI systems processes users' personal data in Italy: the information and communications on that processing are in clear and simple language, show the risks, and enable the right to object (GDPR Art. 21). In force since 2025-10-10. Art. 3(5) (no obligations beyond the AI Act) and the overlap with GDPR Arts. 12-13 and 21 are questions for counsel (review flag).
  • Not covered:
    • Activities for national security purposes by the intelligence bodies (Law 124/2007 Arts. 4, 6, 7), cybersecurity and resilience activities of the National Cybersecurity Agency, national defence activities of the Armed Forces, and police activities against the crimes of Law 146/2006 Art. 9(1)(b), (b-ter) for national security (Law 132/2025 Art. 6(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Describe the AI processing in the notice at collection in plain language, and wire an objection route that stops it for the person.

A section of the privacy notice, and a short notice at the AI feature itself, that says an AI system processes the person's data, for which purposes, that the processing is automated, and what the main risks are, in plain language for the people who use the feature (children included where they can use it). Next to it, an objection route (a setting, form or endpoint) that records the objection and that the AI pipeline checks before processing that person's data, so objecting has an effect rather than only being stated.

Where it goes: 1 application source code, 2 data models, 14 user-facing text.

What this provision adds:

  • Write the information on the AI processing in clear and simple language and include its risks.
  • Name the right to object to authorised processing and how to exercise it, next to the AI processing information.

Example (Privacy notice (informativa)), before:

## Informativa privacy
Trattiamo i tuoi dati per fornire il servizio e migliorarlo.

After:

## Informativa privacy
Trattiamo i tuoi dati per fornire il servizio e migliorarlo.

### Uso dell'intelligenza artificiale
Le domande che scrivi all'assistente sono elaborate da un sistema di intelligenza artificiale per
risponderti e per classificare la richiesta. Il trattamento e' automatizzato; i rischi principali sono
risposte inesatte e l'invio del testo al nostro fornitore del modello. Puoi opporti in ogni momento da
Impostazioni > Privacy > Assistente IA: da quel momento i tuoi dati non sono piu' inviati al modello.

Control: People whose data an AI feature processes are not told about that processing in plain language, or not told how to object. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id it-law-132.ai-processing-information-and-objection · review status: primary source derived

Binding law — in force

AI text and data mining only on lawfully accessed works whose use the rightholders have not reserved (Italy, Law 633/1941 Arts. 70-septies, 70-quater)

Law 132/2025, Art. 25(1)(b) (new Art. 70-septies of Law 633/1941: text and data mining by AI) · official text · In force: applies since 10 Oct 2025 · IT

Italian Law 132/2025 Art. 25(1)(b) inserted Art. 70-septies into the Copyright Law (633/1941): reproductions and extractions from works or other materials available online or in databases lawfully accessed, for text and data mining through AI models and systems, including generative AI, are permitted in conformity with Arts. 70-ter and 70-quater. Art. 70-quater(1) allows text and data mining only where the use has not been expressly reserved by the rightholders. Detect a crawler that collects web content for training with no robots.txt or TDM-reservation check.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Oct 2025
Official source
Law 132/2025, Art. 25(1)(b) (new Art. 70-septies of Law 633/1941: text and data mining by AI) · captured 2 Oct 2026 · anchor hash (SHA-256) b22d3a673f44… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Reservations stated in site terms or metadata other than robots.txt and TDMRep
  • Datasets bought from third parties
  • A crawler may honour reservations through a shared fetch helper in another module; follow the fetch call before reporting.

Who it applies to

  • Duty falls on: any person
  • Anyone who reproduces or extracts works or other materials from networks or databases for text and data mining through AI models or systems, where Italian copyright law applies: the access must be lawful and, outside the research-organisation exception of Art. 70-ter, the use must not have been expressly reserved by the rightholders (Art. 70-quater(1)); copies may be kept only as long as the mining needs (70-quater(2)). In force since 2025-10-10 for Art. 70-septies (Art. 70-quater since 2021). Which machine-readable reservations count as 'expressly reserved' (robots.txt, TDMRep, metadata, terms) and when Italian law applies to training abroad are questions for counsel (review flag).
  • Not covered:
    • Research organisations and cultural heritage institutions mining for scientific research under Art. 70-ter, which does not depend on the rightholders' reservation (Law 633/1941 Art. 70-ter, read, not stored)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Gate every dataset entering pre-training or fine-tuning on a recorded lawful source and licence, and consent-filter or scrub personal information first.

A gate in the data pipeline between collection (load_dataset, crawlers, Common Crawl WARC readers, exports of user chats) and training (Trainer, SFTTrainer, fine_tuning.jobs.create) that keeps only records whose source and licence are on an allowlist, checks robots.txt before crawling, drops user content without a training-consent flag, and runs PII detection and anonymisation on the rest. It writes a provenance manifest per shard (source, licence, retrieval date, consent basis, filters applied) kept with the model version, alongside the IP clearance record and the data-quality measures applied. Base models you fine-tune get the same source and licence entry.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts.

What this provision adds:

  • Before mining a page or database for AI training, check the rightholders' reservation (robots.txt, TDMRep tdm-reservation, metadata) and skip reserved content; keep copies only as long as the mining needs.

Example (Hugging Face datasets + TRL + Presidio), before:

ds = load_dataset('json', data_files='crawl/*.jsonl', split='train')
trainer = SFTTrainer(model=model, train_dataset=ds)
trainer.train()

After:

ALLOWED_LICENSES = {'cc-by-4.0', 'cc0-1.0', 'apache-2.0', 'licensed-by-contract'}
analyzer, anonymizer = AnalyzerEngine(), AnonymizerEngine()

def scrub(row):
    hits = analyzer.analyze(text=row['text'], language=LANG)
    row['text'] = anonymizer.anonymize(text=row['text'], analyzer_results=hits).text
    return row

ds = load_dataset('json', data_files='crawl/*.jsonl', split='train')
ds = ds.filter(lambda r: r['license'] in ALLOWED_LICENSES).map(scrub)
write_provenance_manifest(ds, out='manifests/shard-000.json')
trainer = SFTTrainer(model=model, train_dataset=ds)
trainer.train()

Control: GenAI training data without lawful source / IP / consent controls. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Rule id it-law-132.ai-tdm-respects-rights-reservation · review status: primary source derived

Binding law — in force

Tell patients when AI technologies are used in their care (Italy, Law 132/2025 Art. 7(3))

Law 132/2025, Art. 7(3) (right to be informed of the use of AI) · official text · In force: applies since 10 Oct 2025 · IT

From 2025-10-10, Italian Law 132/2025 Art. 7(3) gives the person concerned the right to be informed about the use of AI technologies in health care. Detect patient-facing consent or information material (consenso informato, informativa) in a product that uses AI in care but never mentions AI.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Oct 2025
Official source
Law 132/2025, Art. 7(3) (right to be informed of the use of AI) · captured 2 Oct 2026 · anchor hash (SHA-256) c402020ce5d5… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Information given orally or on paper
  • Patient portals served from a CMS
  • Only meaningful in a product that uses AI in care; the material for the AI-assisted service may live elsewhere.

Who it applies to

  • Duty falls on: deployer, individual professional
  • Sectors: healthcare
  • Health care providers and professionals in Italy that use AI technologies in prevention, diagnosis, treatment or therapeutic choice: the patient has the right to be informed of that use. In force since 2025-10-10. The law sets no form or timing for the information; whether it binds the software vendor or only the provider, and whether Art. 3(5) limits it, are questions for counsel (review flag).
  • Not covered:
    • Activities for national security purposes by the intelligence bodies (Law 124/2007 Arts. 4, 6, 7), cybersecurity and resilience activities of the National Cybersecurity Agency, national defence activities of the Armed Forces, and police activities against the crimes of Law 146/2006 Art. 9(1)(b), (b-ter) for national security (Law 132/2025 Art. 6(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.

A notice step in the decision workflow itself (application intake, underwriting, eligibility, applicant or employee scoring, diagnostic support) that runs before the model call, e.g. send_admt_notice(consumer) ahead of underwrite(), or a notice block rendered on the intake page the person submits from. The notice says that AI is used in the decision, for what, and how to get more information or ask for review, and its delivery is stored with the decision (notice id, channel, timestamp). The template lives in the repo so its content is reviewable; a privacy-policy paragraph alone is not on the decision path.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Inform the patient that AI technologies are used in their prevention, diagnosis, treatment or therapeutic choice; the law prescribes no form, so consent forms, the informativa or visit summaries serve.

Example (FastAPI + OpenAI SDK), before:

@app.post('/applications')
def apply(app_in: Application):
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    return {'decision': underwrite(resp.choices[0].message.content)}

After:

@app.post('/applications')
def apply(app_in: Application):
    notice = send_admt_notice(app_in.applicant_id, template='ai_decision_notice_v2')
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    decision = underwrite(resp.choices[0].message.content)
    db.decisions.insert(app_in.id, decision, notice_id=notice.id)
    return {'decision': decision, 'ai_notice': notice.text}

Control: Consequential AI decision without consumer notice. The same guard addresses 8 items with binding law in 7 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id it-law-132.health-ai-patient-informed · review status: primary source derived

Binding law — in force

Health AI systems and the data they use must be reliable, periodically verified and updated (Italy, Law 132/2025 Art. 7(6))

Law 132/2025, Art. 7(6) (health AI and its data reliable, periodically verified and updated) · official text · In force: applies since 10 Oct 2025 · IT

From 2025-10-10, Italian Law 132/2025 Art. 7(6) requires AI systems used in health care, and the data they use, to be reliable and periodically verified and updated to minimise the risk of errors and improve patient safety. Detect a health AI repository with no scheduled verification of the model's accuracy (evaluation job, monitoring or revalidation report).

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Oct 2025
Official source
Law 132/2025, Art. 7(6) (health AI and its data reliable, periodically verified and updated) · captured 2 Oct 2026 · anchor hash (SHA-256) aa3d200d83d3… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Who it applies to

  • Duty falls on: provider, deployer
  • Sectors: healthcare
  • Providers and users of AI systems in Italian health care: the systems and their data are reliable and periodically verified and updated. In force since 2025-10-10. The law sets no interval or method; what 'periodically' requires is a question for counsel (review flag).
  • Not covered:
    • Activities for national security purposes by the intelligence bodies (Law 124/2007 Arts. 4, 6, 7), cybersecurity and resilience activities of the National Cybersecurity Agency, national defence activities of the Armed Forces, and police activities against the crimes of Law 146/2006 Art. 9(1)(b), (b-ter) for national security (Law 132/2025 Art. 6(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.

A validation stage that runs whenever a decision model is trained, fine-tuned, or retrained (the same module or pipeline step as fit(), Trainer, xgb.train, or fine_tuning.jobs.create) and again on a recurring schedule against recent decisions: accuracy and error rates per group, selection rates and disparity metrics (fairlearn MetricFrame, demographic_parity_difference, AIF360 disparate impact), and drift. Results go to a versioned validation report alongside a datasheet or data card for the training data, and a threshold gate blocks promotion of a model version whose metrics regress until a named owner reviews and records a decision. The validation cadence and owner are written in the model's validation record.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts, 13 tests and evals.

What this provision adds:

  • Verify and update the health AI system and its data periodically to minimise errors; record the interval and each verification.

Example (scikit-learn + fairlearn), before:

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
joblib.dump(clf, 'models/credit_v4.joblib')

After:

from fairlearn.metrics import MetricFrame, selection_rate, demographic_parity_difference
from sklearn.metrics import accuracy_score

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
y_pred = clf.predict(X_test)
mf = MetricFrame(metrics={'accuracy': accuracy_score, 'selection_rate': selection_rate},
                 y_true=y_test, y_pred=y_pred, sensitive_features=A_test)
dpd = demographic_parity_difference(y_test, y_pred, sensitive_features=A_test)
write_validation_report('credit_v4', mf.by_group, dpd)
if dpd > MAX_DPD:
    raise SystemExit('bias gate failed: owner review required before release')
joblib.dump(clf, 'models/credit_v4.joblib')

Control: AI decision system without regular accuracy/bias validation. The same guard addresses 5 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id it-law-132.health-ai-periodic-verification · review status: primary source derived

Binding law — in force

Health AI only supports prevention, diagnosis, treatment and therapeutic choice; the decision always rests with the physician (Italy, Law 132/2025 Art. 7(5))

Law 132/2025, Art. 7(5) (AI supports; the decision is always the physician's) · official text · In force: applies since 10 Oct 2025 · IT

From 2025-10-10, Italian Law 132/2025 Art. 7(5) makes AI systems in health care a support for prevention, diagnosis, treatment and therapeutic choice, leaving the decision always to the medical professional. Detect model output written to a clinical record (diagnosis, prescription, treatment plan, FHIR Condition, CarePlan or MedicationRequest) with no physician sign-off or draft status.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Oct 2025
Official source
Law 132/2025, Art. 7(5) (AI supports; the decision is always the physician's) · captured 2 Oct 2026 · anchor hash (SHA-256) 1d49764bfef5… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Clinical writes through an EHR SDK not named here
  • Sign-off enforced in a separate service
  • The sign-off may be enforced by the EHR the code writes to; confirm the resource status before reporting.

Who it applies to

  • Duty falls on: deployer, provider
  • Systems covered: consequential decision
  • Sectors: healthcare
  • Providers and users of AI systems in Italian health care (prevention, diagnosis, treatment, therapeutic choice): the AI supports, and the decision remains the physician's. In force since 2025-10-10. Whether a clinical-decision-support product must technically prevent unsupervised decisions, or only the provider must organise physician review, is a question for counsel (review flag).
  • Not covered:
    • Activities for national security purposes by the intelligence bodies (Law 124/2007 Arts. 4, 6, 7), cybersecurity and resilience activities of the National Cybersecurity Agency, national defence activities of the Armed Forces, and police activities against the crimes of Law 146/2006 Art. 9(1)(b), (b-ter) for national security (Law 132/2025 Art. 6(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

What this provision adds:

  • Store AI output as a draft or preliminary record that a physician confirms or changes; the physician's decision, not the model's, becomes the clinical record.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id it-law-132.health-ai-physician-decides · review status: primary source derived

Binding law — in force

Professionals must tell clients, clearly and fully, which AI systems they use; AI only supports the intellectual work (Italy, Law 132/2025 Art. 13)

Law 132/2025, Art. 13(2) (professional informs the client of AI systems used) · official text · In force: applies since 10 Oct 2025 · IT

From 2025-10-10, Italian Law 132/2025 Art. 13 limits AI in the intellectual professions to instrumental and support activities, with the professional's intellectual work prevailing, and requires the professional to communicate the information on the AI systems used to the client in clear, simple and exhaustive language. Detect a professional's engagement letter or client terms that never mention AI, in a practice product that uses it.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Oct 2025
Official source
Law 132/2025, Art. 13(2) (professional informs the client of AI systems used) · captured 2 Oct 2026 · anchor hash (SHA-256) 97341ece793a… · 5 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Information given in person or by e-mail
  • Terms held in a document-management system
  • Only meaningful in a practice that uses AI in client work; the information may be given in another document.

Who it applies to

  • Duty falls on: individual professional
  • Members of the intellectual professions in Italy (professioni intellettuali: regulated professions such as lawyers, accountants, engineers, physicians acting as professionals) who use AI systems in serving a client: the client is told, clearly, simply and exhaustively, which AI systems are used, and AI is used only for instrumental and support activities. In force since 2025-10-10. It reaches software where the professional's practice product (client portal, document assistant) uses AI; whether it binds the software vendor is a question for counsel (review flag).
  • Not covered:
    • Activities for national security purposes by the intelligence bodies (Law 124/2007 Arts. 4, 6, 7), cybersecurity and resilience activities of the National Cybersecurity Agency, national defence activities of the Armed Forces, and police activities against the crimes of Law 146/2006 Art. 9(1)(b), (b-ter) for national security (Law 132/2025 Art. 6(1))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Open each GenAI conversation on a licensed-professional service path with a prominent statement that the person is interacting with generative AI.

Mark which routes serve clients of a licensed or state-certified practice (clinical, legal, financial, mental-health advice) and, on those routes, have the session-start handler emit a prominent disclosure as the first thing the person sees, before any generated reply. Keep the wording in a constant the UI renders unchanged (e.g. 'You are interacting with generative AI, not a human professional'). The disclosure belongs to the conversation start of each such path, not to an account-signup screen or terms page that the person may have seen once.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Tell the client which AI systems the professional uses, in clear, simple and exhaustive language.
  • Keep AI to instrumental and support activities, with the professional's own intellectual work prevailing.

Example (FastAPI + Anthropic SDK), before:

@app.post('/advisor/sessions')
def start_session(user=Depends(current_client)):
    return {'session_id': sessions.create(user.id), 'messages': []}

After:

GENAI_DISCLOSURE = 'You are interacting with generative AI, not a human professional.'

@app.post('/advisor/sessions')
def start_session(user=Depends(current_client)):
    sid = sessions.create(user.id)
    return {'session_id': sid,
            'messages': [{'role': 'assistant', 'content': GENAI_DISCLOSURE}]}
# later turns: client.messages.create(model=MODEL, max_tokens=1024, system=ADVISOR_PROMPT, messages=history)

Control: GenAI in regulated occupation without proactive disclosure. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required

Rule id it-law-132.professional-ai-client-information · review status: primary source derived

Binding law — in force

Employers must inform workers about the use of AI and automated decision or monitoring systems (Italy, Law 132/2025 Art. 11(2); D.Lgs. 152/1997 Art. 1-bis)

Law 132/2025, Art. 11(2) (safe, transparent workplace AI; employer informs the worker) · official text · In force: applies since 10 Oct 2025 · IT

From 2025-10-10, Italian Law 132/2025 Art. 11(2) requires workplace AI to be safe, reliable and transparent and obliges the employer or principal to inform the worker of the use of AI in the cases and manner of D.Lgs. 152/1997 Art. 1-bis: before work starts, the aspects of the relationship the systems affect, their purposes, logic and functioning, the data and main parameters used to program or train them, the control measures and correction processes, and their accuracy, robustness, cybersecurity and potentially discriminatory impacts, in a transparent, structured, commonly used and machine-readable format, also to worker representatives. Detect an AI employment-decision or monitoring system with no worker information document.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Oct 2025
Official source
Law 132/2025, Art. 11(2) (safe, transparent workplace AI; employer informs the worker) · captured 2 Oct 2026 · anchor hash (SHA-256) f57c3fe0f9d3… · 8 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Who it applies to

  • Duty falls on: employer
  • Systems covered: automated decision
  • Sectors: employment
  • Employers and principals (public or private) in Italy that use AI, including fully automated decision or monitoring systems giving indications relevant to hiring, management or termination, task assignment, surveillance, evaluation or performance: inform each worker before work starts with the content of D.Lgs. 152/1997 Art. 1-bis(2), in a structured, machine-readable format, also to worker representatives (1-bis(6)). Systems protected by industrial and commercial secrecy are excluded (1-bis(8)). In force since 2025-10-10. Whether Art. 11(2) reaches AI that is not fully automated, and how far the trade-secret exclusion goes, are questions for counsel (review flag).
  • Not covered:
    • Activities for national security purposes by the intelligence bodies (Law 124/2007 Arts. 4, 6, 7), cybersecurity and resilience activities of the National Cybersecurity Agency, national defence activities of the Armed Forces, and police activities against the crimes of Law 146/2006 Art. 9(1)(b), (b-ter) for national security (Law 132/2025 Art. 6(1))
    • Systems protected by industrial and commercial secrecy (D.Lgs. 152/1997 Art. 1-bis(8))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Notify applicants and employees, in the application flow, HR portal, or handbook they actually receive, that AI is used in each employment decision before it is applied to them.

An employee-facing notice tied to each AI-assisted employment process (resume screening, promotion ranking, performance or discipline scoring, scheduling), placed where people meet that process: application-flow copy, the careers page, the HR portal, or a handbook AI section. The pipeline that calls score_applicant or rank_employees records which notice version each person received, and checks that record before scoring so a new AI use case cannot go live for people who were never told. One generic hiring disclaimer does not cover promotion, discipline, or termination uses.

Where it goes: 1 application source code, 2 data models, 14 user-facing text.

What this provision adds:

  • Before work starts, tell each worker the aspects of the relationship the system affects, its purposes, logic and functioning, the data and main parameters used to program or train it, its control and correction measures, and its accuracy, robustness, cybersecurity and discriminatory impacts.
  • Provide the information in a transparent, structured, commonly used and machine-readable format, and also to the workers' representatives.

Example (Python HR scoring job (scikit-learn)), before:

def rank_employees(team_id):
    staff = hr.employees(team_id)
    return model.predict_proba(features(staff))[:, 1]

After:

def rank_employees(team_id):
    staff = hr.employees(team_id)
    missing = [e.id for e in staff if not hr.ai_notice_received(e.id, use='promotion_ranking')]
    if missing:
        raise NoticeMissing(f'AI-use notice not yet given to {len(missing)} employees')
    return model.predict_proba(features(staff))[:, 1]

Control: Employer uses AI in employment decisions without notifying the employee. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Rule id it-law-132.workplace-ai-worker-information · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.