Tag Archives: chatgpt

HAL Can Compute, But Can HAL Copyright? Italy’s Answer for the AI Era

Think of HAL 9000, the ominously calm on-board computer from 2001: A Space Odyssey. HAL runs the ship, plays chess, holds a conversation, even claims to feel emotions – but the one thing HAL never does is sign anything. But could HAL place his name as author on anything – a painting, a poem? Or think of Ai-Da, the Oxford-built robot that paints portraits through cameras built into its eyes and a robotic arm guided by machine-learning algorithms, whose most famous work has been described as “the first self-portrait with no self.” HAL and Ai-Da raise, one in fiction and one in a gallery, the same question Italian lawmakers just answered in statutory form: can a machine be an author? The answer, for Italian copyright law, is now written into the text itself – and it matters for any business generating content with AI tools.

Italy’s Law No. 132/2025 (in force since October 10, 2025) is the first comprehensive national framework on artificial intelligence in Europe, designed to work alongside the EU AI Act. Its Article 25 amends Article 1 of the Italian Copyright Law (Law No. 633/1941), the core provision that defines which works qualify for copyright protection in Italy.

Before the reform, Article 1, first paragraph, of the Copyright Law simply read: works of intellectual endeavour of a creative character belonging to literature, music, figurative arts, architecture, theatre and cinematography are protected under this law, whatever the mode or form of their expression. The provision said nothing about who, or what, had to create the work – it only required intellectual endeavour and creative character, a gap that left the treatment of AI-generated output to interpretation.

The amendment inserts two changes into that same sentence. First, the word “human” is added immediately after “works of intellectual endeavour”, so the provision now protects works of human intellectual endeavour, not just intellectual endeavour in the abstract. Second, a new clause is added at the end: even where created with the aid of artificial intelligence tools, provided they constitute the result of the author’s intellectual work.

What actually changed, in practice:

  • The threshold question is now explicit in the text, not just in case law. Before the reform, Italian courts and commentators already generally assumed that copyright required a human creative act, drawing on the general theory of authorship. The reform writes that assumption directly into the statute, removing any doubt that a work generated entirely autonomously by a machine – with no human creative contribution, like HAL’s compositions with no composer behind them, or Ai-Da’s brushstrokes without a “self” behind them – falls outside protection.
  • AI-assisted works are not excluded, but they are conditioned. The law does not ban the use of AI tools in the creative process. A text generated with ChatGPT can still be protected — but only if the applicant can show that a genuine human creative intervention shaped the result, rather than the output being a pure automatism.
  • The burden of proof shifts to the author. Because the law now links protection to demonstrating that the result stems from the author’s intellectual work, businesses and creators using AI tools should keep records of their creative process-— prompts, iterations, selection choices, edits – as evidence they may need to produce if authorship or protectability is ever challenged.

Practical takeaway for businesses: document the human creative input behind AI-assisted content (prompts, edits, selection criteria) before relying on it as a protectable asset. Where multiple people or vendors are involved in an AI-assisted content pipeline, contracts should specify who is responsible for demonstrating that creative contribution and who owns the resulting rights. HAL, notably, had no human “director” feeding it prompts and making editorial choices – which is the missing ingredient the statute now requires. Your brand’s AI-generated content can have that missing ingredient, and with it a legal “self” behind the work – but remember to prove it!

AI Act Transparency Obligations Are Now in Force

Dear Readers,

I hope you had a great summer! While you were travelling, hiking, swimming or simply resting, article 50 of the AI Act has entered into force, which means that a number of transparency obligations are applicable.

1. YOUR ROLE. First things first: are you an AI provider or an AI deployer?

  • A provider of AI systems is a natural or legal person that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark; while
  • A deployer is a natural or legal person using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.

Providers and deployers have different obligations, which are summarized below.

2. PROVIDER’S OBLIGATIONS.

  • Providers must ensure that AI systems intended to interact directly with natural persons are designed so that those persons are informed they are interacting with an AI system, unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person.
  • Providers of AI systems that generate synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable, as far as technically feasible.

Providers have started to comply and use different technical solutions. Anthropic, for example, is using a watermarking technique, while Open AI and Google are using different strategies. No single marking technique meets Article 50(2) requirements of effectiveness, interoperability, robustness and reliability, and only an appropriate combination of techniques and detection mechanisms can satisfy them. Some point to a clear “Brussels effect” where the AI Act ends up applying beyond its scope.

3. DEPLOYER’S OBLIGATIONS.

  • Deployers of emotion recognition or biometric categorization systems must inform the natural persons exposed to the system of its operation and must process personal data in accordance with the GDPR and any other applicable data protection laws.
  • Deployers of AI systems that generate or manipulate image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. For evidently artistic, creative, satirical, fictional or analogous works, the obligation is limited to appropriate disclosure that does not hamper the display or enjoyment of the work.
  • Deployers of AI systems that generate or manipulate text published to inform the public on matters of public interest must disclose the artificial nature of the content, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

All information must be provided in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure.

The AI Office is tasked with encouraging codes of practice at Union level to facilitate the effective implementation of obligations regarding the detection and labelling of artificially generated or manipulated content. In fact, the voluntary Code of Practice on Transparency of AI-generated Content has already been signed by 190+ organizations and has been found by the EU Commission and the AI Office as an effective tool to aid compliance with article 50 of the AI Act.

In a world where AI systems have started to go rogue, perhaps the AI Act – with all its constraints to AI technology – can offer reassurance that the EU continues to pursue a human-centric, trustworthy AI.

The future of GDPR? Focus on Automated Decisions

The Digital Omnibus Proposal.  The so called “Digital Omnibus” regulation proposal promises to lighten the burden of compliance with data protection legislation. Its aim is “to ensure that the rules continue to be fit for supporting innovation and growth”. Europe is not giving up on privacy, but it is willing to simplify it.

EDPB and EDPS Chime In.  The proposal, published in November 2025, has recently been the subject matter of a joint opinion by the European Data Protection Board and the European Data Protection Supervisor. While these two bodies are apparently in favor of facilitating GDPR compliance and strengthening consistency in its application, they express significant concerns regarding the impact of the changes on the fundamental rights and freedoms of individuals. They also fear that the proposal will create additional legal uncertainties.

The GDPR of the Future.  Gitti and Partners is embarking in a series of blog posts to explain what the GDPR may look like if the Digital Omnibus proposal becomes law. Today we focus on changes to the provision on automated decisions.

Automated Decisions: from Right to Prohibition.  Article 22 of the current GDPR regulates automated individual decision-making. The current language of the provision frames the rule as a “right”: a data subject is entitled not to be subject to a decision based solely on automated processing, unless certain conditions apply. The new proposal, instead, shapes a similar rule as a prohibition.

Conditions for Automated Decisions.  The new proposal reads (new language highlighted in yellow): “1. A decision which produces legal effects for a data subject or similarly significantly affects him or her may be based solely on automated processing, including profiling, only where that decision: (a) is necessary for entering into, or performance of, a contract between the data subject and a data controller regardless of whether the decision could be taken otherwise than by solely automated means. […]”

While – as before – the automated decision is legitimate if necessary to enter into or perform a contract with the data subject, the novelty is that the necessity of the automated decision can be assessed “regardless of whether the decision could be taken otherwise than by solely automated means”. Therefore:

  • An automated decision that does not produce any legal effects is fine.
  • An automated decision producing legal effects may be based on automated processing only if the decision is necessary to enter into or perform a contract with the data subject.
  • No automated decision is allowed unless it is necessary to enter or perform a contract with the data subject.
  • In order to add certainty to the interpretation of the requirement of “necessity”, the proposal clarifies that the decision may be regarded as necessary also if the decision could be made by a human. In the words of the EDPB/EDPS opinion, “the requirement of necessity does not mean that the mere fact that a decision could theoretically also be taken by a human should prevent the controller from taking the decision by solely automated means”.
  • In short, “The fact that the decision could also be taken by a human does not prevent the controller from taking the decision by solely automated processing” (recital (38) of the Digital Omnibus proposal).

Bottom line: the data controller may choose a human decision process or an automated decision process so long as they are necessary to enter into or perform a contract with the data subject.

In conclusion, as shown in the “AI First” policy, the EU is now worried that AI may not be fully exploited. The above changes are supposed to encourage automated decisions even if such decisions could be taken by a human being.

Stay tuned for more angles of the Digital Omnibus.

Italy’s New AI Law: A Boost for Healthcare Research?


Italy has recently enacted its own “Artificial Intelligence Act”, set to take effect on October 10, 2025.

You might be wondering: Did we really need another layer of AI regulation? That was our initial reaction, too. But a closer look reveals that the Italian AI Law introduces several interesting provisions, especially in the healthcare sector, that could facilitate research for both public and private entities. Here are some highlights:

1. Healthcare Data Processing as Based on Public Interest

The law explicitly recognizes that the processing of health-related personal data by:

  • Public or private non-profit entities,
  • Research hospitals (IRCCS),
  • Private entities collaborating with the above for healthcare research,

is of “substantial public interest.” This significantly expands the scope of Article 9(2)(g) of the GDPR, offering a clearer legal basis for processing sensitive data in research contexts.

2. Secondary Use of Data

The law introduces a simplified regime for the secondary use of personal data without direct identifiers. In particular:

  • No new consent required, as long as data subjects are informed (even via a website).
  • Automatic authorization unless blocked by the Data Protection Authority within 30 days of notification.

This provision applies only to the entities mentioned above so it is limited in scope, but in any case significantly strengthens the framework for nonprofit research projects.

3. Freedom to Anonymize, Pseudonymize and Synthesize

Under Article 8(4) of the AI Law, processing data for anonymization, pseudonymization, or synthesization is always permitted, provided the data subject is informed. This is a major step forward in enabling privacy-preserving AI research.

4. Guidelines and Governance

The law delegates the creation of technical guidelines to:

  • AGENAS – for anonymization and synthetic data generation.
  • Ministry of Health – for processing health data in research, including AI applications.

It also establishes a national AI platform at AGENAS, which will act as the data controller for personal data collected and generated within the platform.


Final Thoughts

While the GDPR aimed to support research, its implementation often created legal uncertainty and operational hurdles. Italy’s AI Law appears to address some of these gaps, offering a more pragmatic and enabling framework for healthcare research.