Skip to content
Reference Guide AI Act & Italian Law

⚖️ EVIDE & AI Act

Evidence for Regulatory Requirements and Disputes

When the functioning of an AI system needs to be examined, it helps to be able to reconstruct the operational context, the available artefacts, the documented human oversight and the sequence of events. EVIDE contributes to preserving and making verifiable the material received, within a declared perimeter.

Section 1

1. Explore the detailed framework in your language

This page is EVIDE's English-language regulatory reference. The detailed evidentiary-defensibility framework it draws on is also available in four other languages, on EVIDE's AI Governance Dispute Defense Layer page.

Section 2

2. Regulatory requirements and evidentiary questions

Regulatory obligations under the AI Act fall on specific addressees - mainly providers (who develop or have developed the AI system) and deployers (who use it under their own authority). The table below keeps that distinction explicit, and separates what the regulation requires from how EVIDE can help document it.

Regulatory areaEvidence questionHow EVIDE can help
Event logging & log preservation
Art. 12 (provider) · Art. 26(6) (deployer)
Providers must design high-risk systems to enable automatic event logging. Deployers must then keep those logs, to the extent under their control, for at least six months. Can the retained logs later be related to an independently anchored reference? EVIDE can receive and retain a submitted log file directly, computing its own hash and keeping it available for retrieval - or, for a log held externally, anchor the sender's declared reference and hash without itself verifying that the external file exists or matches it.
Human oversight documentation
Art. 14 (provider) · Art. 26(2) (deployer)
Providers must design for effective human oversight; deployers must assign it to competent, trained individuals with the necessary authority. Can a specific instance of human review or intervention be shown, rather than only asserted? EVIDE can preserve a declared record of an oversight event - what was reviewed, by whom it was declared to be reviewed, what action followed - as submitted, within the agreed scope.
Risk management & technical documentation
Art. 9 · Art. 11 (provider)
Providers must maintain a risk management system and technical documentation covering the system's design, risks and mitigations. Can the state of that documentation at a given point in time be fixed and later verified? EVIDE can receive and retain submitted documentation directly, computing its own hash - or, for documentation held externally, anchor the sender's declared reference and hash without itself verifying the external material's existence or content.
Incident monitoring & reconstruction
Art. 72 (provider) · Art. 26(5) (deployer)
Providers must monitor system performance after deployment; deployers must monitor operation and inform the provider or market surveillance authority of emerging risks. After an incident, can the sequence of declared events be reconstructed from material preserved independently of the system itself? EVIDE can preserve, as submitted within scope, the declared sequence of inputs, classifications, actions and human interventions associated with an event, so later reconstruction does not depend solely on the system's own account.
External review & disputes
General - applies across providers and deployers
When a decision or outcome is challenged, can material be presented that was preserved before the dispute began, by a party independent of the one being examined? EVIDE's role is to preserve declared material independently and make its anchoring verifiable. What weight that material carries in a given review or dispute is for the examining authority, not EVIDE, to determine.
These rows describe candidate uses of EVIDE against documented AI Act obligations. Depending on how material is submitted, EVIDE either receives and retains the file itself or anchors a declared, externally-held reference; in neither case does preservation or anchoring by itself establish the truth of the content or that the declared events took place. These rows do not state that any particular organisation has adopted EVIDE for this purpose, and they do not substitute for legal advice on how a specific obligation applies to a specific system.

Section 3

3. Italian national legislation — D.Lgs. 160/2026

The obligations above come from Regulation (EU) 2024/1689 (the AI Act), which applies across the Union. Separately, Italy has adopted national legislation that is relevant to the same questions but operates under its own rules.

Italian national legislation — D.Lgs. 160/2026

Legislative Decree 9 September 2026, no. 160 (in force from 30 September 2026) introduces, among other things, Article 437-bis of the Italian Criminal Code and Articles 17 to 19 on civil proceedings. These are Italian national provisions. Whether and how they apply to a given system, organisation or dispute must be assessed case by case, with qualified legal advice.

Art. 437-bis of the Criminal Code: criminalises the omission of required technical security measures or human-oversight measures, and the alteration of a high-risk AI system, when concrete danger to life, to public or individual safety, or to State security results. Grave negligence and intentional omission by a professional user are separately addressed.

Articles 17-19 of the decree (civil proceedings): Article 17 lets a court order disclosure of material relevant to how an AI system functioned; Article 18 provides a rebuttable presumption of causal link where damage results from a breach of AI Act obligations; Article 19 states that certified conformity with the AI Act does not by itself exclude liability.

Note: "Article 17" here refers to Article 17 of this Italian decree (access to evidence). It is a different provision from Article 17 of the EU AI Act itself, which concerns providers' quality management systems. The two should not be confused.

Section 4

4. What EVIDE does not do

  • EVIDE supports reconstruction within the boundary of the material actually preserved.
  • EVIDE does not replace security measures, human oversight or risk management.
  • EVIDE does not automatically certify compliance with the AI Act.
  • EVIDE does not determine lawfulness, fault or responsibility.
  • EVIDE does not guarantee the admissibility or sufficiency of its records as evidence.
  • Anchoring alone does not automatically establish the truth of the original content.
External evidentiary deposit is not a general obligation under the AI Act. The Regulation does not require it, and this page does not present it as such. At the same time, internally produced logs are not without evidentiary value - they can be relevant. The distinction EVIDE addresses is about independent anchoring and later verification, not about whether internal records count at all.

References