Solutions · AI governance and compliance

AI in your company, under demonstrable control.

An inventory of what is actually in use, a policy that survives an inspection, documented training, and an approved alternative people adopt. Decisions stay human, and stay logged.

A verification stamp resting on an open page of legal text

The obligation has been in force since 2 February 2025.

Art. 4 of Regulation (EU) 2024/1689 requires providers and deployers — that is, every organisation that uses AI systems, not only those that build them — to take measures supporting the AI literacy of their staff: since 27 July 2026 Regulation (EU) 2026/1744 has replaced that article, turning it from an obligation of result into one of means. In Italy, law 132/2025, in force since 10 October 2025, adds to this: responsibility for the decision stays with the person in healthcare, public administration, employment and justice. For anyone selling to or buying for the public sector, AgID's guidelines on development and procurement — consultation closed in April 2026, final version still pending — will bring an AI Bill of Materials, an exit strategy and conformity sheets into tender documents. Policies and training registers are the first thing an inspection checks: without them, the evidence is missing.

Meanwhile AI is already inside, usually unauthorised. Surveys converge: in most companies more than half of the people using AI at work do so on unauthorised personal accounts, and for the most part do not declare it. A blanket ban does not shrink the practice, it moves it to the personal phone. Every price list, contract or line of code pasted into a public chatbot weakens trade-secret protection (Legislative Decree 63/2018, reasonably adequate measures) and creates processing the controller neither knows nor governs (GDPR, arts. 24 and 32).

Solutions

How order gets restored.

01

Inventory of what is in use.

Declared and undeclared systems, including the AI features already embedded in ERP, HR software and office tools. We start from the facts, not from the org chart.

02

Roles, risk, obligations.

For each system: are you a provider or a deployer under Regulation (EU) 2024/1689, which risk class, which data it processes, which duties and deadlines follow.

03

Policy, training, traceability.

A map of permitted tools by data class, written and signed prohibitions, a training register, logging of AI-assisted decisions and a periodic audit.

04

The approved alternative.

A dedicated, closed AI, disconnected from the open web: on-premise in your environment or on our dedicated cloud in Italy. Without a tool people actually use, the policy gets bypassed.

An example, step by step.

A typical case, not a real client. A services company with 600 employees and no written AI policy. Management’s estimate is “a few dozen people using a public chatbot”; in the example the census reaches 34 distinct tools, in use across nine departments: twenty-one never authorised, and eight of them AI features already switched on inside software bought for something else.

  1. 01

    Census of the tools.

    It starts from the facts: traffic to AI services, licences on the books, AI features embedded in ERP and HR software, plus an anonymous questionnaire to staff. In two weeks the list is closed, with who uses what and for what purpose.

  2. 02

    Risk and data touched.

    For each tool you establish whether you are a provider or a deployer, which risk class it falls into and which data it processes. The three or four cases that actually matter surface — the ones where price lists, contracts or personal data go in — and everything else drops down the list.

  3. 03

    Policy and training.

    The policy states what is permitted by data class, what is forbidden and how a new tool is requested; it is signed, dated and communicated. Training sessions leave materials, dates and attendance behind: without that trail, literacy under art. 4 cannot be evidenced at all.

  4. 04

    The internal tool goes live.

    A dedicated, closed tool — on-premise in your environment or on a dedicated cloud in Italy — does the same things people were doing outside: summarising, rewriting, searching internal documents. It also sees the company’s own documents, which a public service does not. It goes live one department at a time.

  5. 05

    Periodic review.

    Every six months the census is run again and compared with the policy. If a new tool appears, management decides whether to permit it, replace it or ban it: the decision stays with people, the system only shows what has changed.

On this example, within one quarter management has the paperwork to show: an inventory with role and risk class, a signed policy, a training register, logging of AI-assisted decisions. That timeframe is an estimate on a typical case, not a promise. Behaviour changes too — in the example the use of personal accounts falls because the internal tool is more useful, not because one more prohibition arrived. Price lists, contracts and personal data never travel outside the perimeter.

An illustrative example on a typical case: the assumptions are recalibrated on your own data.

What you are left with.

  • An inventory of the AI systems in use with role (provider or deployer) and risk classification, shadow AI included.
  • An AI policy written with you, signed and communicated: permitted tools by data class, explicit prohibitions, a route to request new tools.
  • A verifiable training register — materials, dates, attendance — which is the material evidence art. 4 asks for.
  • Documentation ready for an inspection or a tender: roles, impact assessments, tender clauses, and the questions to put to a general-purpose model provider.
  • One authorised AI tool inside the perimeter, with traceability of prompts, answers and AI-assisted decisions.

Who has this problem.

  • Executive teams and boards accountable for AI use without knowing how much is already circulating.
  • IT and security teams that see traffic to unapproved AI services and have no alternative to offer.
  • Legal, compliance and DPO functions that must evidence literacy, roles and traceability in an inspection.
  • Public bodies that must align development and procurement with Italian law 132/2025 and the AgID guidelines now being finalised.

Two delivery modes.

On-premise, in your own environment

The AI runs on infrastructure you already control. Documents never cross the boundary of your network, and administration stays with your IT department.

Dedicated cloud, in Italy

An environment reserved for a single client, a dedicated VPN, a data centre resident in Italy, in premises we staff ourselves. Nothing is shared with other clients.

In both cases the models are dedicated and closed, disconnected from the open web: nothing they read feeds third-party services. They are open-weight models, with the weights archived inside the perimeter where they run: the version you use changes when you decide it does.

Frequently asked questions.

  • Is a corporate AI policy really a legal obligation, and who can write ours so that it survives an inspection?

    Art. 4 of Regulation (EU) 2024/1689 has applied since 2 February 2025 and, in the text as replaced by Regulation (EU) 2026/1744, requires providers and deployers to take measures supporting the AI literacy of their staff. The policy is how that duty is evidenced: which tools are allowed for which class of data, written prohibitions, a route for requesting new tools. We draft it with you; signing and communicating it stay with management.

  • Who can help us work out whether we are a provider or a deployer under the AI Act, and which obligations actually apply to us?

    The qualification is done system by system, not company-wide: for each one you establish the role, the risk class, the data processed and the deadlines that follow. The inventory starts from facts — traffic to AI services, licences on the books, AI features already switched on inside ERP and HR tools — not from the org chart.

  • What must we require by contract from whoever supplies us a general-purpose AI model?

    Technical documentation of the model, information for downstream integrators, a copyright compliance policy, a summary of the content used for training, and adherence to the Commission’s code of practice. Since 2 August 2026 the general-purpose model obligations are enforceable, so the documentation exists: ask for it in writing and archive the answers.

  • How do we document the staff AI literacy required by art. 4 of the AI Act?

    With materials, dates and attendance records. That is the material evidence an inspection can actually verify: sessions leave a register, the policy is signed and communicated, the inventory is redone periodically. Without a written trace the duty reads as unmet even where the training did happen.

  • Do we need an impact assessment for the AI system we are introducing, and who sets it up?

    It depends on the role and risk class, which the inventory establishes. Where one is needed, the data protection impact assessment and the fundamental rights one overlap to a large extent and are best produced from a single analysis. We set them up; approval stays with whoever answers for the decision.

Other solutions

The first step

Operational from week one.

A real use case, on your data, in production. Then it grows, week after week.

30 minutes video call €150 free July promotion
Start an operational trial

It starts with a session with our engagement expert. Your data stays yours, always.