Operational notes Regulation

A Corporate AI Policy: Since 2025, No Longer a Choice — a Legal Obligation

8 min read

A verification stamp resting on an open page of legal text
A policy never written and training never logged survive no audit — internal or regulatory.

Update (28 July 2026) — Regulation (EU) 2026/1744, in force since 27 July, has replaced Article 4 of the AI Act: the obligation stands and the date remains 2 February 2025, but it shifts from an obligation of result (“ensure a sufficient level”) to an obligation of means (“take measures to support the development”). The section below is updated to the text in force; the operational conclusions do not change.

Monday morning, sales office of a manufacturing SME. The sales manager has to close a complex quote before lunch: he opens ChatGPT on his personal account — the same one he uses in the evening for everything else — and pastes in the confidential price list, two clauses from a framework contract, the customer’s data to personalise the quote. It works: the quote is out in ten minutes instead of two hours. Nobody in IT knows, and nobody will until something goes wrong. In the next room, an engineer pastes in proprietary code to get it fixed; in HR, someone uploads twenty CVs for a quick screening. This isn’t a case of unruly staff: it’s a company that has never written a single line on what can be done with AI — and that, without realising it, has already stopped being compliant.

The Obligation Almost Nobody Meets

Since 2 February 2025, Article 4 of Regulation (EU) 2024/1689 (the AI Act) has applied, under Article 113, third paragraph, point (a). It binds providers and deployers of AI systems: every company that uses them, not just those that build them.

On 27 July 2026, when Regulation (EU) 2026/1744 — the AI Omnibus — entered into force, that article was replaced (Article 1(5)). It was not repealed: it changed in kind. The text now in force says providers and deployers “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used”. And it adds a sentence that was not there before: “This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual”.

The difference is not cosmetic. Before, you had to “ensure, to their best extent, a sufficient level” of literacy: an obligation of result, measured against a yardstick — “sufficient” — that nobody had ever defined. Now you have to take measures that support its development: an obligation of means. Recital 8 of the Omnibus states the reasoning openly: stringent obligations “would not be suitable for all types of providers and deployers” and create “an additional compliance burden, particularly for smaller enterprises”. New paragraphs 2 and 3 add the supporting scaffolding: the Commission and the Member States are to support compliance, SMEs in particular, and the Commission is to publish practical examples on the single information platform; the Board is to adopt recommendations setting out common objectives.

What changes for a company that has done nothing: nothing. The duty to act stands, and the date is still 2 February 2025 — the Omnibus rewrote Article 113(a) without touching it. What changes is what can be held against you: not that you failed to reach a level, but that you failed to take measures. That is a lower bar, and an easier one to document — which is precisely why failing it weighs more.

Article 4 has no dedicated penalty tier under Article 99, and the Omnibus did not give it one: the single new point in paragraph 4 concerns the obligations under Article 25. We are far from prohibited practices (up to €35 million or, for undertakings, 7% of total worldwide annual turnover for the preceding financial year, whichever is higher) and from breaches of the high-risk and transparency obligations (€15 million or 3%, whichever is higher). But it is not an obligation without consequences: it is the missing piece of evidence every time a more serious incident lands under a regulator’s lens — exposed personal data, a disclosed trade secret, a prohibited practice discovered by chance. No policy, no training log: in an investigation, that is an aggravating factor that writes itself.

The Trade Secret That Evaporates

For most Italian businesses, the more concrete risk isn’t an AI Act fine: it’s losing legal protection over what makes them competitive. Directive (EU) 2016/943 and Legislative Decree 63/2018, which rewrote Articles 98-99 of the Italian Industrial Property Code, protect a trade secret under three cumulative conditions: the information must be secret, it must have commercial value precisely because it is secret, and its holder must have subjected it to measures reasonably adequate to keep it secret. It is the third condition that an AI policy builds — and that its absence dismantles. A price list, a technical specification, a production algorithm pasted into a public chatbot, with no written prohibition in place, is the best evidence that those “reasonably adequate” measures never existed. If the secret ends up with a competitor, a court doesn’t look at intentions: it looks at whether the company had done what the law required. Without a policy, trade-secret protection evaporates at precisely the moment it would be needed.

GDPR: Processing Nobody Authorised

Where the price list or contract contains data on identifiable individuals — a customer contact, a job candidate, a colleague named in a memo — the GDPR is triggered. Articles 5(2) (accountability), 24 (controller responsibility) and 32 (security of processing) require the company to demonstrate, not merely declare, that processing is under control. An employee who pastes personal data into an unauthorised consumer service creates processing that the controller neither knows about nor governs: by definition, it sits outside the scope of Article 24. If that data ends up exposed, failure to notify has already been penalised: it was one of four findings that in 2024 cost OpenAI a €15 million fine from Italy’s data protection authority, following the March 2023 ChatGPT data breach — the same 72-hour notification duty (Articles 33-34 GDPR) is impossible to meet if the incident is never even seen. The Italian authority has shown the same scrutiny over workers’ data, blocking a plug-in that read employees’ stress levels from workplace chats, and over less transparent foreign providers, blocking DeepSeek in January 2025 for the same transparency gaps already seen with ChatGPT: the same caution applies, even more so, when it’s the employee alone pushing data outside the perimeter.

Organisations within NIS2 scope (Legislative Decree 138/2024) have one more reason not to delay. Article 23 requires management bodies to approve cybersecurity risk-management measures, oversee their implementation, and undergo adequate training themselves, extending it to staff. Uncontrolled AI use — personal accounts, corporate data on never-vetted third-party servers — is itself an unmanaged cybersecurity risk: an AI policy is one of the measures that NIS2 already demands of anyone within scope.

What the Policy Must Contain, Now

  1. A tool map by data class: what’s allowed (public text, rewording) and what’s forbidden on unapproved services — always: personal data of customers and colleagues, trade secrets, proprietary code, contracts.
  2. Written prohibitions, not implied ones: the policy must be signed, dated, communicated — not an email forgotten in a manager’s inbox.
  3. Documented training: attendance logs, materials, dates. Since the Omnibus this counts for more, because it is exactly the proof Article 4 now asks for — measures taken, not a level reached — and it is the one thing an inspection can actually verify.
  4. An approved alternative: the point that decides whether the policy holds or gets bypassed. A policy made only of bans loses, because staff want to use AI regardless — banning it without offering a safe tool just shifts use onto personal phones, exactly as shadow AI teaches.
  5. Periodic audits: checking that what’s written matches what actually happens, not just once at the policy’s adoption.

How We Solve It

The policy only becomes enforceable once the approved alternative genuinely exists — not as a promise, as an architecture. That’s why we build dedicated, closed AI systems, disconnected from the open web, in two modes: on-premises, within the client’s own environment, or delivered from our dedicated cloud — an environment reserved for the single client, dedicated VPN access, a data centre resident in Italy, premises we staff directly. Either way, staff work as fast as they would with a public chatbot, but the data never leaves the perimeter the company controls — and that is where AI literacy, trade-secret protection and GDPR accountability stop being a risk. It’s the principle our platform is built on, and it holds too for those who have already tackled the security of their own LLM systems or manuals compliant with the Machinery Regulation: the same perimeter work, done on data instead of documents.

Don’t yet have an AI policy, or unsure whether the one you have would survive an audit? Half an hour with one of our experts is enough for the first map.

Sources