ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting
6.2 Cybersecurity and AI Cybersecurity obligations relating to artificial intelli - gence (AI) systems arise primarily from the EU’s risk- based regulatory approach to AI, and intersect with general cybersecurity and data protection require - ments. Security is treated as a foundational element of trustworthy AI and encompasses robustness, resil - ience against manipulation, and protection of model components and data throughout the life cycle. In practice, cybersecurity obligations in the AI context require organisations to manage risks associated with data poisoning, model theft and unauthorised access, and to ensure that supply-chain dependencies do not undermine system integrity. These obligations are implemented through organisational governance, secure development practices and continuous moni - toring rather than through isolated technical controls. The convergence between AI governance and cyber - security regulation reflects the recognition that digital risks are increasingly interconnected and require co- ordinated management. 6.3 Cybersecurity in the Healthcare Sector Cybersecurity obligations in the healthcare sector arise from the convergence of cross-sector cyber - security regimes, data protection requirements and sector-specific risk considerations. Healthcare pro - viders and operators of health information systems are subject to organisational and technical security obligations designed to protect sensitive health data and to ensure the availability and integrity of critical services according to NIS2. Connected medical devices and digital health tech - nologies introduce additional cybersecurity consid - erations, as vulnerabilities may affect patient safety and continuity of care. Product security obligations therefore interact with healthcare regulation and pro - curement practices. Incident response and notifica - tion duties in healthcare environments require par - ticular sensitivity to operational continuity and to the potential impact on patients and public trust. Cyber - security governance in this sector integrates techni - cal resilience with heightened ethical and regulatory expectations.
cessors are required to implement appropriate techni - cal and organisational measures to ensure a level of security appropriate to the risk. Cyber-incidents that compromise the confidentiality, integrity or availability of personal data frequently trigger parallel obligations under cybersecurity and data protection frameworks. The breach notification regime requires that personal data breaches be assessed promptly and, where risk thresholds are met, notified to the competent super - visory authority within prescribed timeframes. Com - munication to affected individuals is required where a high risk to rights and freedoms is identified. These obligations necessitate close co-ordination between cybersecurity incident response and data protection governance to ensure consistency and accuracy in assessments and communications. The interaction between cybersecurity regulation and data protection law reinforces the need for integrated governance structures. Organisations are expected to align incident classification, escalation and reporting processes so that cybersecurity events are managed holistically and in compliance with overlapping legal regimes. The overlap between cybersecurity incident manage - ment and personal data breach assessment requires organisations to operate integrated decision-making processes. Technical incident-response teams, legal functions and data protection governance structures must co-ordinate in real time to assess the nature and impact of incidents and to determine applica - ble notification obligations. Fragmented handling of cybersecurity and data protection aspects increases the risk of inconsistent assessments and delayed or inaccurate notifications. Supervisory authorities increasingly expect that organisations document the reasoning underlying breach assessments and notification decisions. This documentation supports accountability and enables ex post review of incident handling. As a result, cyber - security governance and data protection compliance converge in practice, reinforcing the need for aligned policies, shared escalation pathways and consistent communication strategies.
221 CHAMBERS.COM
Powered by FlippingBook