September 24, 2026
AI audit trails: what changes under Legislative Decree 160/2026
Starting september 30, 2026, Italian courts can order the disclosure of AI system logs and audit trails under Legislative Decree 160/2026. Here is what companies need to know.
An AI system’s audit trail is a chronological record of what the system did: which data it received, which output it produced, which model version was active, and which human operator reviewed, edited, or dismissed that result. A system log merely records that software ran; an audit trail reconstructs the rationale behind a decision and the human oversight that accompanied it. Starting September 30, 2026, with the entry into force of Legislative Decree 160/2026, this record carries legal weight as evidence. Anyone seeking damages caused by an AI system can obtain a court order requiring the disclosure of operational logs and technical documentation. If a company fails to produce them, the contested facts risk being deemed legally admitted.
Across factories and enterprise offices, AI already inspects lots on manufacturing lines, prioritizes work orders, and screens job applications. When a defective component slips past an automated quality check, or an algorithmic decision causes third-party harm, affected parties do not cross-examine the machine. They hold the company and its executive leadership accountable. At that stage, demonstrating professional diligence requires structured, time-stamped, and tamper-resistant evidence.
For executive teams, the implications are immediate and practical. Being able to reconstruct, even months down the line, how a system operated and who supervised it now carries weight on three distinct fronts: civil liability, corporate liability under Legislative Decree 231/2001, and, for high-risk systems, personal criminal liability for individuals.
What changes starting September 30, 2026?
Legislative Decree No. 160 of September 9, 2026, published in Italy’s Official Gazette on September 15, enacts the delegation under Italy’s National AI Framework Law (Law 132/2025) and aligns national law with the European AI Act. Comprising 22 articles, the decree dedicates its first section to law enforcement AI use, ranging from facial recognition to real-time remote biometric identification. Its second section addresses enterprises directly across three distinct dimensions.
- On the criminal front, a new offense is introduced: Article 437-bis of the Italian Criminal Code. It targets anyone across the lifecycle of a high-risk AI system who fails to adopt mandatory technical safety measures or human oversight protocols, whenever such failure creates a danger to human life or bodily safety. Penalties range from one to five years of imprisonment, increasing if national security is endangered. Professional deployers who intentionally omit human oversight face identical criminal penalties.
- On the corporate liability front, this offense is incorporated into the catalog of predicate crimes under Legislative Decree 231/2001 alongside the unlawful dissemination of deepfakes, exposing companies to financial penalties up to 1000 quotas and prohibitive sanctions, such as bans on contracting with public authorities.
- On the civil litigation front, procedural evidence rules change for damages claims involving AI systems, regardless of their risk category.
On this third front, an audit trail transitions from a technical best practice into decisive courtroom evidence.
A calendar clarification is necessary here. Regulation (EU) 2026/1744, known as the Digital Omnibus, has postponed compliance deadlines for high-risk AI systems listed under Annex III of the AI Act (such as recruitment and workforce screening tools) to December 2, 2027. For AI embedded into regulated safety products, such as machinery and medical devices, the date is August 2, 2028. This postponement does not suspend Italy’s new procedural rules: starting September 30, anyone claiming damages can petition judges to order disclosure of evidence regarding the operation of any AI system. How judges will evaluate documents required by the AI Act for high-risk categories that are not yet mandatory remains to be seen. In any case, companies waiting until 2027 to organize their logs will find themselves already behind.
Why operational logs matter more than compliance certificates
One might assume that obtaining a formal compliance certificate shields a company from liability. The decree explicitly rejects this: compliance with AI Act obligations, even when certified, does not in itself exclude liability (Article 19). A certification merely asserts that a system complies with high-level design specifications. In litigation, something else matters entirely: what transpired on that specific date, with that specific input, in front of which human operator.
The procedural mechanism established by the decree relies directly on operational records across three sequential stages.
The first stage is access to evidence (Article 17). A plaintiff presenting plausible facts to support their claim can obtain a judicial order compelling the defendant to produce operational logs, risk management documentation, technical specifications, and human oversight parameters. The second stage governs failure to cooperate: if an enterprise fails to produce these records without justified grounds, the court, having assessed remaining evidence, can treat the plaintiff’s allegations as admitted facts. The third stage introduces a statutory presumption (Article 18): whenever harm stems from an infringement of AI Act requirements, the causal link between the violation and the harm is legally presumed. While the enterprise retains the right of rebuttal, the burden falls on the company to prove that the damage originated from another cause.
In practice, that proof can only be constructed from logs.
A deficient audit trail creates a double disadvantage: the company cannot produce what the court demands, and it cannot overturn the causal presumption. While the decree obligates courts to keep disclosure orders proportionate and safeguards trade secrets, the burden of maintaining complete, structured records rests entirely on the company.
What must an AI audit trail record?
The decree does not provide an itemized data dictionary. Instead, it references the logging requirements set out by the AI Act for high-risk systems and the parameters governing human oversight. In practice, for every substantive output produced by a system, the audit trail should capture:
- Exactly when the output was generated, via a certified, reliable timestamp;
- Which model version and system configuration were active;
- Which input data were processed, or where those datasets are archived;
- What output the model produced;
- Who reviewed it and what action was taken (confirmed, modified, or rejected);
- Which subsequent anomalies, runtime incidents, or remedial actions followed.
Beyond individual entries, two overarching system properties are paramount. The first is record integrity: guaranteeing that no entry has been retroactively altered. The second is a retention policy aligned with litigation timelines, as disputes often arise months after the operative event.
To ensure integrity, an established and proven approach is the hash chain, highlighted by industry guidance from AIPIA (Italian Association of AI Professionals) as a cornerstone for defensible records. Each entry receives a cryptographic hash calculated not only on its own payload but also incorporating the hash of the preceding entry. Modifying a single value in an older record breaks the mathematical signature of all downstream entries, exposing tampering during verification without requiring a manual review of historical data. On its own, however, hashing is not enough. Systems also require WORM (Write Once, Read Many) storage media that prevent overwriting, robust encryption at rest and in transit, and continuous monitoring that leaves no administrative access unlogged.
A notable benchmark appears within the decree itself. For sensitive biometric identification systems deployed by law enforcement, lawmakers mandated automatically recorded, unalterable log files retained for five years (Articles 9 and 10). While the decree does not formally mandate this specific standard for private companies, it serves as a reliable yardstick: a log that can be edited after the fact carries little evidentiary weight in court.
How to demonstrate human oversight
Human oversight is where technical audit trails intersect directly with criminal exposure. For enterprises deploying high-risk systems professionally, criminal liability arises when human oversight is intentionally omitted and this omission endangers individuals. Designating an oversight manager on paper is insufficient; organizations must prove that designated staff actively exercised oversight, and exactly when.
Consider two practical scenarios. On a computer-vision quality inspection line, the audit log must record which operator validated a flagged lot rejection, at what exact hour, and based on which visual frame. In an AI-assisted recruitment workflow (classified as high-risk under the AI Act), the record should show which HR professional re-evaluated an automatically filtered candidate profile, including the final decision reached. If these review checkpoints rely solely on memory or untraceable email threads, courts will find it difficult to accept that meaningful supervision took place.
The same principle applies to personnel qualifications: logging who received what training, on which system, and on what date is an integral component of the audit trail.
Do deployers of third-party AI need an audit trail?
Yes, within a proportionate scope. An SME or professional practice utilizing off-the-shelf, third-party AI tools does not train foundational models, and therefore does not need to document algorithmic training. However, it must still track which tools it operates, on what data, and who verified the results. For these organizations, an essential, structured log—even managed via a disciplined database or controlled spreadsheet—should capture each substantive use case:
- Timestamp (date and time);
- System name and specific version;
- Business purpose and requesting team member;
- Type of input data processed, noting whether data were anonymized;
- Summary of the generated output;
- Outcome of human review (accepted, modified, rejected) paired with a brief explanatory rationale;
- Identity of the operator conducting pre-use validation.
This does not require the architectural complexity of an enterprise banking system. The pivotal field is the human rationale: without a logged explanation of why an output was accepted or overturned, proving months later that a human actively evaluated the recommendation becomes nearly impossible. Because the new evidentiary rules apply across all AI categories, consistent logging provides an indispensable defense against claims.
Who stores the logs: the enterprise or the vendor?
Many enterprise AI systems are delivered via external vendors, meaning logs frequently reside on external cloud infrastructure. The decree accounts for this: disclosure orders can be served directly against third parties holding evidentiary records, and third parties refusing to comply without justified cause face administrative fines ranging from 1500 to 10000 euros. Nevertheless, the defendant enterprise remains on the front line, forced to construct its defense using records outside its direct control and subject to third-party turnaround times.
Commercial agreements with AI vendors must therefore be reassessed around four essential questions:
- Where are system logs hosted, and what is the applicable retention schedule;
- In what format and within what timeframes will the vendor deliver logs upon notice of a claim or dispute;
- Whether the vendor is contractually obligated to implement an immediate litigation hold upon notification of an incident;
- How trade secrets and intellectual property are protected for both parties during court-mandated disclosures.
These same considerations apply in reverse for providers delivering AI systems to enterprise clients. Including our own teams at Aidia.
Operational priorities for the coming weeks
Legal analyses of the decree recommend an eight-point roadmap for enterprises. Viewed through the lens of audit readiness, organizations can focus on seven practical steps:
- Conduct an inventory of all active AI systems, including vendor solutions, identifying those falling into high-risk categories;
- Define systematically what telemetry is logged, where it is stored, and for how long;
- Secure logs against unauthorized modification, or at minimum ensure all administrative edits are tracked;
- Establish a litigation hold procedure to freeze logs and technical evidence as soon as an incident, complaint, or claim arises;
- Document assigned human oversight personnel along with their verified training credentials;
- Update corporate compliance frameworks (such as Model 231) and reporting workflows toward Supervisory Bodies;
- Review commercial insurance coverage, keeping in mind that claimants can formally inquire about AI liability insurance, requiring a response within 30 days.
An effective audit trail must be engineered before an incident occurs. Afterward, organizations are left assembling incomplete fragments.
How we approach traceability at Aidia
Across the industrial projects we deliver, traceability is always decided during the design phase: retrofitting it onto an active production environment costs significantly more and leaves critical data gaps. In our custom computer-vision and quality-inspection deployments, we embed a comprehensive digital audit trail designed to meet rigorous manufacturing requirements. With our AVA suite, deployments can run fully on-premise, ensuring operational logs, telemetry, and business data never leave the client’s perimeter.
No technology platform, ours or anyone else’s, can absolve an enterprise of its statutory duties: the decree makes this unequivocal. A well-engineered architecture accomplishes something far more practical: it equips the business to prove definitively what happened.
If you are mapping your AI deployments and want to identify where your audit trail may be incomplete, contact us.
Frequently Asked Questions
What is an audit trail for an artificial intelligence system?
An AI audit trail is a chronological, tamper-evident log of system operations: which data were ingested, which output was generated, which model version was active, and which human interventions took place. It enables organizations to reconstruct how and why a system arrived at a specific conclusion, even months later. Starting September 30, 2026, it serves as admissible evidence in liability litigation.
Does Legislative Decree 160/2026 mandate an audit trail for all companies?
Not explicitly as a universal administrative obligation. Technical logging is a direct mandate under the EU AI Act for high-risk systems, with compliance dates for Annex III use cases set for December 2, 2027. However, the Italian decree allows claimants to demand disclosure of operational evidence for any AI system, meaning organizations lacking audit records face acute evidentiary vulnerability.
What happens if a company fails to disclose logs ordered by a court?
If an enterprise fails to comply with a judicial disclosure order without justified cause, the judge may draw adverse inferences. Where non-compliance concerns core AI documentation (logs, risk management files, technical documentation, human oversight records), the court may treat the plaintiff’s allegations as admitted facts.
Does an AI audit trail risk exposing enterprise trade secrets in litigation?
The risk exists, and the decree explicitly provides for it. Disclosure orders must remain proportionate and limited to what is strictly necessary. Where trade secrets are implicated, courts apply protective measures under Article 121-ter of the Italian Industrial Property Code, restricting access, ordering confidential proceedings, and redacting sensitive commercial information.
Does an AI Act conformity certificate eliminate corporate liability?
No. The decree expressly provides that compliance with AI Act obligations, even when formally certified, does not automatically eliminate liability. A certificate verifies baseline conformity; litigation turns on demonstrating what occurred in a specific instance, which requires granular audit logs.
Can third-party AI vendors be compelled to produce logs in court?
Yes. Courts may issue disclosure orders directly to third parties holding relevant evidence, such as cloud providers or SaaS vendors. Third parties failing to comply without justified grounds face administrative fines between 1500 and 10000 euros. Enterprises should address disclosure timelines and log custody directly in vendor contracts.
Sources
- Gazzetta Ufficiale della Repubblica Italiana, DECRETO LEGISLATIVO 9 settembre 2026, n. 160, (26G00179) (GU Serie Generale n.214 del 15-09-2026), Gazzetta Ufficiale
- Nadia Martini, “AI e responsabilità d’impresa, cosa cambia e come adeguarsi”, (21 settembre 2026) Agenda Digitale
- Francesco Machina Grifeo, “Intelligenza artificiale, dal 30 settembre nuove regole su responsabilità e riconoscimento facciale”, (16 settembre 2026) Il Sole 24 Ore

Marta Magnini
Digital Marketing & Communication Assistant at Aidia, graduated in Communication Sciences and passionate about performing arts.
At Aidia, we develop AI-based software solutions, NLP solutions, Big Data Analytics, and Data Science. Innovative solutions to optimize processes and streamline workflows. To learn more, contact us or send an email to info@aidia.it.
Latest news

September 30, 2026
AI token costs: why being able to switch models matters

September 24, 2026
AI audit trails: what changes under Legislative Decree 160/2026

September 21, 2026
What is enshittification?
