Skip to content
  • Tax
    • M&A
    • International Tax
    • Transfer Pricing
    • Dispute Resolution
    • Business Incentives & Tax Credit
    • VAT and Indirect Taxes
    • Corporate Tax
  • Legal
    • M&A
    • Corporate Law
    • Litigation & Arbitration
    • Restructuring
    • Labor Law
    • Public Law
    • Data Protection
    • Sports Law
    • Compliance 231
    • AI Governance & Compliance
    • Intellectual Property
    • Medical Law
  • Corporate Finance
    • M&A
    • Business Valuation & Modeling
    • Debt Advisory
    • Real Estate Advisory
    • Track Record
  • Multidisciplinary Services
    • M&A
    • Deal Structure & Due Diligence
    • Private Client Services
    • Global Mobility
    • Sustainability
  • Industry
    • Agribusiness
    • Energy
    • Financial Services
    • Manufacturing
    • Real Estate
    • Technology
  • About Us
    • History
    • Press
    • Charity
    • Careers
    • Whistleblowing
  • News
    • Insights
    • Flash News
    • Events
    • Corporate News
  • Offices
  • Global Presence
  • Professionals
  • Careers
  • Contacts
Andersen Global
Andersen Consulting
  • IT
  • EN

Worldwide Locations:

  • Italy
    • Brazil
    • Canada*
    • Chile
    • France
    • Germany
    • Guatemala
    • Ireland*
    • Italy
    • Luxembourg
    • Mexico
    • Netherlands
    • Panama
    • Poland
    • Russia
    • Spain
    • Switzerland
    • United States
logo
  • Professionals
  • Careers
  • Contacts
  • Tax
    • M&A
    • International Tax
    • Transfer Pricing
    • Dispute Resolution
    • Business Incentives & Tax Credit
    • VAT and Indirect Taxes
    • Corporate Tax
  • Legal
    • M&A
    • Corporate Law
    • Litigation & Arbitration
    • Restructuring
    • Labor Law
    • Public Law
    • Data Protection
    • Sports Law
    • Compliance 231
    • AI Governance & Compliance
    • Intellectual Property
    • Medical Law
  • Corporate Finance
    • M&A
    • Business Valuation & Modeling
    • Debt Advisory
    • Real Estate Advisory
    • Track Record
  • Multidisciplinary Services
    • M&A
    • Deal Structure & Due Diligence
    • Private Client Services
    • Global Mobility
    • Sustainability
  • Industry
    • Agribusiness
    • Energy
    • Financial Services
    • Manufacturing
    • Real Estate
    • Technology
  • About Us
    • History
    • Press
    • Charity
    • Careers
    • Whistleblowing
  • News
    • Insights
    • Flash News
    • Events
    • Corporate News
  • Offices
  • Global Presence
Home » News » AI governance and compliance: the evolution of the regulatory framework

AI governance and compliance: the evolution of the regulatory framework

9 October 2026 | Insights

Compliance & Risk Management | October 2026

Artificial intelligence is no longer merely a technological issue, but a matter of corporate governance. With the AI Act, the European and national regulatory framework is evolving. In this issue of the Compliance & Risk Management Newsletter, professionals from Andersen’s 231/Privacy Service Line have examined the key regulatory developments relating to AI in order to highlight the ever-increasing importance of adopting compliance controls capable of mitigating the risks arising from the use of AI systems, thereby strengthening AI governance. 

Digital Omnibus and the AI Act: new deadlines for high-risk systems

With the Digital Omnibus, the European institutions have also addressed the regulation of artificial intelligence. As regards the AI Act, the legislation does not alter the framework of the regulation but does affect the timetable for the application of certain obligations, in particular those relating to high-risk AI systems, postponing them to 2 December 2027 and 2 August 2028. Companies can use this additional time to build an AI governance model based on a concrete understanding of the AI tools they already use or are considering adopting. This means mapping AI systems, classifying their risk, identifying internal roles and responsibilities, defining approval procedures, setting rules for input and output data, and providing appropriate training. In practical terms, the postponement gives companies the opportunity to approach AI Act compliance in a more structured and gradual way, embedding it into their existing internal governance, control and risk management processes. 

Artificial intelligence in Legislative Decree 231/2001

Legislative Decree No. 160/2026, implementing the AI Act (EU Regulation 2024/1689), has come into force. It has introduced a new Article 25-vicies into Legislative Decree 231/2001, entitled ‘Offences committed through the use of artificial intelligence systems’.  

The decree introduces two predicate offences into the complex system of administrative liability for legal entities. The first is Article 437-bis of the Criminal Code, which punishes the failure to adopt technical security measures or human supervision of high-risk AI systems, as well as their unlawful alteration, provided that this results in a real danger to life, personal or public safety, or national security. The second is Article 612-quater of the Italian Criminal Code, which punishes so-called ‘deepfake’ conduct.  

From a 231 perspective, it will therefore be necessary to verify, as part of the risk assessment, whether and how AI – particularly in high-risk systems – is used in business processes. Should the analysis reveal a concrete exposure to the risk of committing the newly introduced offences, the Model must identify specific control measures, such as criteria and limits for the use of AI, and the definition of roles and responsibilities with regard to the generation and dissemination of content.

AI Act, Digital Omnibus and GDPR: the redefinition of legal bases and special categories of data

On 27 July 2026, Regulation (EU) 2026/1744, the so-called ‘AI Omnibus’, came into force, amending the AI Act. The new text provides that providers may process special categories of data (so-called sensitive data), such as health-related data, to detect and correct biases in AI systems. This power, previously reserved for providers of high-risk AI systems, now extends to providers and deployers of other AI systems and models, provided that it is ensured that it is impossible to use synthetic or anonymised data, that additional enhanced security measures are adopted, that access to the data is restricted, and that the data is deleted once the bias has been corrected. 

The situation is different for the part of the Omnibus Act that amends the GDPR, which is still under discussion. The European Commission’s proposal clarifies that the processing of personal data for the development and use of AI systems may be based on the data controller’s legitimate interest. However, this does not constitute an automatic green light.  

As regards sensitive data, the proposal introduces two new exceptions to the prohibition set out in Article 9 of the GDPR. The first concerns sensitive data present incidentally in training datasets: such data is permitted provided the organisation takes appropriate measures to prevent its collection and to remove it if detected. The second allows the use of biometric data to verify identity, provided it remains under the exclusive control of the data subject.   

In any case, it is advisable to take steps to map the data used in AI projects, check for the presence of sensitive data in the datasets, and document the legal bases and security measures implemented.

Risk assessment put to the test by AI: new sensitive activities and protocols for human supervision

The risk manager maps the uses of AI within business processes and identifies sensitive activities: those in which an error, distorted data or omitted information could affect people, financial results or business continuity. For each one, they reconstruct what might happen, assess how likely it is and what damage it would cause. They then examine existing controls to determine whether the residual risk is acceptable to the organisation.  

Human oversight must also stem from this analysis. Whoever approves a forecast must be able to verify the data and assumptions used; whoever reviews the anomalies flagged by the AI must also check a sample of the cases that were excluded. The protocol sets out who intervenes, at what stage, with what information, and with what authority to correct or halt the system. These checks must be documented, so that any errors detected can be used to update the risk assessment.  

The risk manager does not simply add a signature to the process: they identify where the company may lose control of its own decisions and establish the conditions for continuing to use AI with confidence. 

    Downloads
  • Leggi la newsletter (PDF, 348.16 KB)
  • Read the newsletter (PDF, 340.67 KB)
door
Andersen
Menu
  • About us
  • Professionals
  • Offices
  • Insights
  • Careers
  • Contacts
Utilities
  • Privacy and Cookies
  • Terms & Conditions
  • Compliance 231
  • Andersen Global

©Andersen Tax LLC and Andersen Italia. Andersen Italia is the Italian member firm of Andersen Global, a Swiss verein comprised of legally separate, independent member firms located throughout the world providing services under their own name or the brand "Andersen,” "Andersen Tax," or "Andersen Tax & Legal," or "Andersen Legal." Andersen Global does not provide any services and has no responsibility for any actions of the member firms, and the member firms have no responsibility for any actions of Andersen Global. Your use of this website is subject to the terms and conditions governing it. Please read these terms and conditions before using the website.