AI governance and compliance: the evolution of the regulatory framework
Compliance & Risk Management | October 2026
Artificial intelligence is no longer merely a technological issue, but a matter of corporate governance. With the AI Act, the European and national regulatory framework is evolving. In this issue of the Compliance & Risk Management Newsletter, professionals from Andersen’s 231/Privacy Service Line have examined the key regulatory developments relating to AI in order to highlight the ever-increasing importance of adopting compliance controls capable of mitigating the risks arising from the use of AI systems, thereby strengthening AI governance.
Digital Omnibus and the AI Act: new deadlines for high-risk systems
With the Digital Omnibus, the European institutions have also addressed the regulation of artificial intelligence. As regards the AI Act, the legislation does not alter the framework of the regulation but does affect the timetable for the application of certain obligations, in particular those relating to high-risk AI systems, postponing them to 2 December 2027 and 2 August 2028. Companies can use this additional time to build an AI governance model based on a concrete understanding of the AI tools they already use or are considering adopting. This means mapping AI systems, classifying their risk, identifying internal roles and responsibilities, defining approval procedures, setting rules for input and output data, and providing appropriate training. In practical terms, the postponement gives companies the opportunity to approach AI Act compliance in a more structured and gradual way, embedding it into their existing internal governance, control and risk management processes.
Artificial intelligence in Legislative Decree 231/2001
Legislative Decree No. 160/2026, implementing the AI Act (EU Regulation 2024/1689), has come into force. It has introduced a new Article 25-vicies into Legislative Decree 231/2001, entitled ‘Offences committed through the use of artificial intelligence systems’.
The decree introduces two predicate offences into the complex system of administrative liability for legal entities. The first is Article 437-bis of the Criminal Code, which punishes the failure to adopt technical security measures or human supervision of high-risk AI systems, as well as their unlawful alteration, provided that this results in a real danger to life, personal or public safety, or national security. The second is Article 612-quater of the Italian Criminal Code, which punishes so-called ‘deepfake’ conduct.
From a 231 perspective, it will therefore be necessary to verify, as part of the risk assessment, whether and how AI – particularly in high-risk systems – is used in business processes. Should the analysis reveal a concrete exposure to the risk of committing the newly introduced offences, the Model must identify specific control measures, such as criteria and limits for the use of AI, and the definition of roles and responsibilities with regard to the generation and dissemination of content.
AI Act, Digital Omnibus and GDPR: the redefinition of legal bases and special categories of data
On 27 July 2026, Regulation (EU) 2026/1744, the so-called ‘AI Omnibus’, came into force, amending the AI Act. The new text provides that providers may process special categories of data (so-called sensitive data), such as health-related data, to detect and correct biases in AI systems. This power, previously reserved for providers of high-risk AI systems, now extends to providers and deployers of other AI systems and models, provided that it is ensured that it is impossible to use synthetic or anonymised data, that additional enhanced security measures are adopted, that access to the data is restricted, and that the data is deleted once the bias has been corrected.
The situation is different for the part of the Omnibus Act that amends the GDPR, which is still under discussion. The European Commission’s proposal clarifies that the processing of personal data for the development and use of AI systems may be based on the data controller’s legitimate interest. However, this does not constitute an automatic green light.
As regards sensitive data, the proposal introduces two new exceptions to the prohibition set out in Article 9 of the GDPR. The first concerns sensitive data present incidentally in training datasets: such data is permitted provided the organisation takes appropriate measures to prevent its collection and to remove it if detected. The second allows the use of biometric data to verify identity, provided it remains under the exclusive control of the data subject.
In any case, it is advisable to take steps to map the data used in AI projects, check for the presence of sensitive data in the datasets, and document the legal bases and security measures implemented.
Risk assessment put to the test by AI: new sensitive activities and protocols for human supervision
The risk manager maps the uses of AI within business processes and identifies sensitive activities: those in which an error, distorted data or omitted information could affect people, financial results or business continuity. For each one, they reconstruct what might happen, assess how likely it is and what damage it would cause. They then examine existing controls to determine whether the residual risk is acceptable to the organisation.
Human oversight must also stem from this analysis. Whoever approves a forecast must be able to verify the data and assumptions used; whoever reviews the anomalies flagged by the AI must also check a sample of the cases that were excluded. The protocol sets out who intervenes, at what stage, with what information, and with what authority to correct or halt the system. These checks must be documented, so that any errors detected can be used to update the risk assessment.
The risk manager does not simply add a signature to the process: they identify where the company may lose control of its own decisions and establish the conditions for continuing to use AI with confidence.
- Leggi la newsletter (PDF, 348.16 KB)
- Read the newsletter (PDF, 340.67 KB)
