Targeted amendments to Italy's National AI Strategy
Executive summary
While Italy's National AI Strategy largely identifies the right instruments to further develop the domestic AI ecosystem, it also exhibits areas for improvement. Specifically, it misses integration and development opportunities that could be readily enabled by Italy's own digital assets: anchoring the integration of AI in Public Administration to the country's existing DPI stack; leveraging the data collected through different DPI layers to support wider domestic AI development efforts; treating public data as a governed commons rather than a registry; extending the open-source mandate from AI research to production; and implementing a tiering framework to manage inference-related public spend. Further, some operational commitments are unclear on budgets, dated targets, and ownership rules, and a clearer, consequential approach to monitoring and transparency is needed. Below is an overview of four targeted amendments that, if implemented, could help address these gaps.
| Recommendation | Owner | Time horizon |
|---|---|---|
| R1. Prioritise the integration of AI systems in the country's DPI stack to kickstart AI adoption in Public Administration. | Foundation for AI + Department for Digital Transformation (DTD) + Agency for a Digital Italy (AgID) | 0–12 months |
| R2. Extend the open-source mandate from AI research to production; leverage the national supercomputer infrastructure; tier PA AI by use case to manage inference spend | Ministry of University and Research + Cineca + Foundation for AI | 0–18 months |
| R3. Convert Action A.1's Registry into a governed Italian Data Commons | Italian Digital Agency (AgID) + Privacy Ombudsman + Foundation for AI | Up to 24 months |
| R4. Make monitoring public and consequential | Foundation for AI + National Court of Auditors | From day 1 |
Background – Italy's AI readiness
Three main asymmetries define Italy's starting position.
Talent. Italy ranks seventh globally for AI publications and with initiatives such as the national AI PhD programme it is making a genuine effort to position itself as a European leader in AI research. Italy also leads the 4-year European Lighthouse for AI Sustainability (ELIAS) research project under Horizon Europe, and has established the Future Artificial Intelligence Research (FAIR) foundation, which coordinates a network of 53 universities and 83 companies and sustains over 350 researchers across ten hubs in frontier AI research. However, the operational impact of the national AI research ecosystem remains limited. As the strategy itself notes, only 1.5% of Italian graduates come from the ICT sector — the lowest share in the EU — and only 45.6% of citizens possess basic digital skills. AI adoption among Italian enterprises is also lagging: in 2024, the adoption rate of Italian companies was just 16.4%, compared to the EU average of 20%. Further, as of April 2026, 75% of Italian professionals familiar with at least one AI tool have never received structured training, even though 51% report a desire to do so. This asymmetry is undermining the country's ability to translate research strengths into AI-driven productivity gains.
Data. Italy holds significant public data assets, but these remain fragmented across central, 20 regional and roughly 7,900 municipal administrations. Such fragmentation poses a significant challenge for both horizontal and vertical AI integration across government, which requires well-documented, structured and standardised data. The risks of data fragmentation are twofold: it prevents government from realising the efficiency gains promised by comprehensive AI integration, and it limits the state's ability to share large volumes of high-quality, standardised, consent-based data with the private sector, constraining its role in the development of AI systems and applications. The strategy currently does not frame data fragmentation as a major risk to AI integration across Public Administration and, more broadly, the rest of the economy.
Infrastructure. With 18 supercomputers in the Top500 list, Italy ranks fourth in the world for installed computing power. The country also operates a comprehensive Digital Public Infrastructure (DPI) stack: SPID/CIE for identity, PagoPA for payments, ANPR for population registry, IO App as the single digital point of contact between citizens and Public Administration, and the Public National Data Platform (PDND) for data interoperability. None of these layers are recognised by the strategy as valuable levers for AI development and integration across Public Administration and the domestic economy more broadly, limiting its effectiveness.
Strategy review: strengths
The strategy presents three main strengths. The risk framing, detailing specific risks such as cultural homogenisation and ineffectiveness, is substantive and signals political maturity about implementation. The focus on supporting strategic, Made in Italy sectors such as agri-food, manufacturing, tourism, pharma and aerospace gives AI adoption a credible demand signal, consistent with mission-oriented innovation policy. Lastly, capacity commitments — the proposed extraordinary hiring plan for universities, research centres and enterprises, and the establishment of an AI department within the National School of Public Administration (SNA) — should prove effective in addressing the country's chronic brain drain.
Governance and regulatory stance
The strategy correctly anchors itself to the EU AI Act and commits to limit national regulatory efforts to limit compliance-related costs and complexity. However, two shortfalls should be addressed:
First, Action I.5 commits to deploy “support measures… to reduce the burdens of [AI-related] regulatory compliance and certifications” on private firms via “funding calls or by providing consulting services.” However, there is no budget assigned, no eligibility criteria, and no timeline or throughput targets are attached, leaving SMEs nothing concrete to plan against.
Second, the strategy (broadly) names operational sectoral arrangements only for aerospace. It takes no position on health, justice, defence or finance — four sectors where the EU's AI Act high-risk classifications collide with already complex regulatory regimes. Each requires Italy to designate competent authorities (such as the Italian Medicines Agency, or AIFA, for the health sector) and articulate how the obligations contained in the EU AI Act layer onto existing rules.
Strategy review: delivery gaps
Gap 1: trained officials with no shared architecture. Strategic actions such as PA.6 (AI in PA schools) will produce AI-savvy civil servants, while the remaining actions will likely hand them siloed sandboxes to deploy on, severely limiting opportunities to scale pilot projects. Adoption guidelines, procurement rules and individual departmental pilots only make sense if AI systems can draw on standardised, structured data and workflows that allow for scalability in the long run.
Italy already operates the rails on which a different pattern is possible. While Italy's DPI stack is still under development, existing layers (SPID/CIE, PagoPA, ANPR, IO App, PDND) can be leveraged to enable a more holistic integration of AI in government.
Gap 2: the open-source mandate is limited, no role for supercomputing infrastructure, no framework for matching AI models to use cases. The strategy commits state-funded research to producing models “made available in open source”, without extending that commitment to the large language and multimodal models provided for by Action R.3 or to the systems that will be procured by Public Administration under Action PA.2. Not extending the open-source mandate (with some exceptions) to these Actions will likely increase dependence on the proprietary technology of foreign companies, which is already substantial.
Secondly, the strategy is silent on Italy's supercomputing infrastructure: there are no mentions of how it could be leveraged to support AI development efforts by both the public and private sectors.
Lastly, there is no governance mechanism in place to manage the public cost of AI deployment at scale. This will negatively impact the state's ability to manage inference spend and the strategy's economic viability.
Gap 3: data registry, not data commons. Action A.1 delivers a “Registry of datasets and models”, which is necessary, but insufficient. The UK's Department for Science, Innovation and Technology guidelines highlight what is missing: a Data Quality Action Plan (DQAP) to enhance and sustain data quality within public organisations; treating data as a product, with named owners and Service Level Agreements; role-based access controls to ensure accountability; and drift and bias monitoring after deployment.
Currently, Italy's Foundation for AI (the institution charged with overseeing the implementation of the Strategy, as per action A.3) lacks the authority to compel individual PAs to release their data. Without it, the Italian large language and multimodal models, whose development is prescribed by Action R.3, might have to train on whatever scraps individual administrations agree to expose, rather than on a curated, representative national data corpus.
Gap 4: monitoring records compliance, not outcomes. The Strategy assigns monitoring and evaluation of its own implementation to the Foundation for AI (Action A.3) but does not specify what will be measured, against which baselines, or with what consequence for actions that underperform. As drafted, the monitoring function will record whether each action has been undertaken and whether allocated funds have been committed. It will not establish whether an AI deployment has improved a public service, at what unit cost, or for whom.
Four prioritised recommendations
R1. Re-anchor PA AI on the existing DPI stack (0–12 months). Re-scope the Strategy's Public Administration section as a DPI×AI programme. Identify a minimum of three citizen journeys already running on Italy’s digital infrastructure and apply shared AI capabilities – such as voice interaction, document processing and form assistance – across them.
Selecting the journeys. Two criteria should govern selection.
It runs on national infrastructure. Journeys administered through regional systems have to be built twenty times; journeys running on IO, PagoPA, ANPR or PDND are built once.
It assists with a decision the state has already taken. Journeys should not require AI to take formal action on behalf of the state. The formal act should already have been performed — the tax notice issued, the notification served — with the AI helping the citizen understand and comply with it, where necessary. Respecting this criterion at the outset keeps the programme clear of the EU AI Act's high-risk regime, which would otherwise apply and slow delivery considerably.
Below are four example journeys reflecting the criteria outlined above:
| Journey | Rails | Shared capability applied | Outcome measured |
|---|---|---|---|
| Local tax notices (IMU, TARI) | IO + PagoPA | Plain-language explanation of what is owed, why, by when, and what follows from non-payment | Share of notices settled before the deadline, and assistance requests (calls, emails and counter visits) per 1,000 notices — both measured before and after deployment |
| Legally-valid notifications (SEND) | IO + SEND | Explanation of what the notification says, the obligations and deadlines it carries, and the responses open to the recipient | Share of notifications opened and acted on within the statutory window, before and after deployment |
| Means-tested benefits (ISEE-dependent) | IO + INPS + PDND | Eligibility triage and form pre-fill from data the state already holds | Application completion rate and share of applications requiring correction, before and after deployment |
| Civil-status certificates and residence | ANPR + IO/IT-Wallet | Guided request and document routing | Time-to-issue and share of requests completed without a counter or portal visit, before and after deployment |
These capabilities explain, translate, extract and pre-fill. They do not determine entitlement. The eligibility triage in the benefits journey returns an indication and the reasoning behind it; the determination remains with INPS. Holding this line is what keeps the programme outside Annex III, and it should be stated in the programme mandate rather than left to implementers to infer.
Budget: redirect the strategy’s existing allocations for PA and residual NRRP Mission 1 funds.
Owners: Department for Digital Transformation and PagoPA; Agency for a Digital Italy (AgID); Foundation for AI.
Success metrics: three journeys live on IO within twelve months, with published pre- and post-deployment baselines; inference cost per interaction published for each live capability.
R2. Extend the open-source mandate from research to production; establish an access framework for the national supercomputer infrastructure; tier model selection by use case (0–18 months). Extend the open source commitment to the AI models whose development is prescribed by Action R.3, and to the procurement of AI systems prescribed by Action PA.2.
Establish a national, multi-client access framework for Italy's supercomputer infrastructure, with reserved compute allocations for open source model training, fine tuning and large scale batch inference, including dedicated access for SMEs and start-ups, in accordance with EuroHPC Joint Undertaking rules. Pursue a two-track development strategy, building a generalist Italian multilingual and multimodal foundation model, alongside smaller, distilled specialist models for PA domains.
Introduce a use-case tiering framework to ensure frontier, more expensive systems are used for more complex tasks, enabling systematic control over public inference expenditure.
Owners: Ministry of University and Research (MUR), Cineca, Foundation for AI.
Success metric: open Italian foundation model trained on Leonardo within eighteen months; SME/Startup compute quota hits at least 20% of the total allocation; tiering rules are published within six months.
R3. Convert Action A.1's Registry into a governed Italian Data Commons (up to 24 months). Adopt the UK DSIT four-pillar framework as the binding standard for PA datasets entering the Commons and publish a per-dataset AI-readiness scorecard. Establish a statutory Italian Data Commons Institution with collective governance — data owners, the privacy Ombudsman, citizen representation — and public interest-oriented licensing. This could be established within the Foundation for AI, whose creation is already envisaged by the Strategy.
Owners: Agency for a Digital Italy (AgID), Privacy Ombudsman, Foundation for AI.
Success metric: a set number of PA datasets graded Silver or Gold within twenty-four months.
R4. Make monitoring public and consequential (from day 1). Publish a public dashboard with three to five quantitative KPIs per individual Action (A.1–F.7) to be updated quarterly, each with baseline, dated target, spend (if applicable) and outcome. Implement eighteen-month reviews for every funded pilot project, defund underperformers and redirect residual funds to new ones. Carry out impact assessments for AI deployment in Public Administration, at least publishing their summaries. Mandate the Foundation for AI to draft an annual report to be handed to Parliament; periodically collect citizen insights through consultations via the IO App. Assign a budget, an eligibility rubric and a dated throughput target to Action I.5, allowing SMEs to plan accordingly.
Owners: Foundation for AI, National Court of Auditors.
Success metric: dashboard live within ninety days; first reviews within eighteen months; clarity on Action I.5 within four months.