Skip to content
  • Tax
    • M&A
    • International Tax
    • Transfer Pricing
    • Dispute Resolution
    • Business Incentives & Tax Credit
    • VAT and Indirect Taxes
    • Corporate Tax
  • Legal
    • M&A
    • Corporate Law
    • Litigation & Arbitration
    • Restructuring
    • Labor Law
    • Public Law
    • Data Protection
    • Sports Law
    • Compliance 231
    • AI Governance & Compliance
    • Intellectual Property
    • Medical Law
  • Corporate Finance
    • M&A
    • Business Valuation & Modeling
    • Debt Advisory
    • Real Estate Advisory
    • Track Record
  • Multidisciplinary Services
    • M&A
    • Deal Structure & Due Diligence
    • Private Client Services
    • Global Mobility
    • Sustainability
  • Industry
    • Agribusiness
    • Energy
    • Financial Services
    • Manufacturing
    • Real Estate
    • Technology
  • About Us
    • History
    • Press
    • Charity
    • Careers
    • Whistleblowing
  • News
    • Insights
    • Flash News
    • Events
    • Corporate News
  • Offices
  • Global Presence
  • Professionals
  • Careers
  • Contacts
Andersen Global
Andersen Consulting
  • IT
  • EN

Worldwide Locations:

  • Italy
    • Brazil
    • Canada*
    • Chile
    • France
    • Germany
    • Guatemala
    • Ireland*
    • Italy
    • Luxembourg
    • Mexico
    • Netherlands
    • Panama
    • Poland
    • Russia
    • Spain
    • Switzerland
    • United States
logo
  • Professionals
  • Careers
  • Contacts
  • Tax
    • M&A
    • International Tax
    • Transfer Pricing
    • Dispute Resolution
    • Business Incentives & Tax Credit
    • VAT and Indirect Taxes
    • Corporate Tax
  • Legal
    • M&A
    • Corporate Law
    • Litigation & Arbitration
    • Restructuring
    • Labor Law
    • Public Law
    • Data Protection
    • Sports Law
    • Compliance 231
    • AI Governance & Compliance
    • Intellectual Property
    • Medical Law
  • Corporate Finance
    • M&A
    • Business Valuation & Modeling
    • Debt Advisory
    • Real Estate Advisory
    • Track Record
  • Multidisciplinary Services
    • M&A
    • Deal Structure & Due Diligence
    • Private Client Services
    • Global Mobility
    • Sustainability
  • Industry
    • Agribusiness
    • Energy
    • Financial Services
    • Manufacturing
    • Real Estate
    • Technology
  • About Us
    • History
    • Press
    • Charity
    • Careers
    • Whistleblowing
  • News
    • Insights
    • Flash News
    • Events
    • Corporate News
  • Offices
  • Global Presence
Home » News » AI & transparency: an indispensable pairing

AI & transparency: an indispensable pairing

10 September 2026 | Insights

Compliance & Risk Management | September 2026

Transparency has long been a cornerstone of the European legal framework, from the protection of personal data to consumer protection. With the AI Act, however, it takes on a specific role: to reduce the information asymmetry created by the opacity of many artificial intelligence systems. In this issue of the Compliance & Risk Management Newsletter, professionals from Andersen’s 231/Privacy Service Line have explored the relationship between the principle of transparency and the use of AI systems, with a view to highlighting the ever-increasing importance of adopting compliance measures capable of mitigating risks arising from the use of such systems, thereby strengthening organisational governance.  

AI ACT: New Transparency Rules for Businesses and Professionals 

As of August 2, 2026, the obligations provided for in Article 50 of the AI ACT shall apply. Unlike the requirements for high-risk systems, they depend on the system’s features and use. Providers of systems intended to interact directly with people must inform them that they are interacting with an AI, unless this is already evident. Providers of generative systems must also make synthetic outputs detectable in a machine-readable format. Deployers also have specific duties: those using emotion recognition or biometric categorisation systems must inform the individuals concerned; those disseminating deepfakes or certain AI-generated texts of public interest must disclose their artificial origin, subject to the exceptions provided for. 

Not everyone, therefore, is subject to the same obligations. For businesses and professionals, the first step is to identify their role – whether as a provider or a deployer – and to map out systems, outputs and recipients. Transparency thus becomes an operational obligation: knowing who does what, towards whom and by what means. 

Regulating the Use of AI in the Workplace Through the Code of Ethics 

Artificial intelligence is rapidly becoming integrated into business processes, offering new opportunities for efficiency and innovation, whilst at the same time introducing unprecedented risks: from the management of personal data and confidential information to the misuse of AI tools by employees. 

In this context, the Code of Ethics can serve as one of the tools through which a company defines the fundamental principles and rules for the responsible use of artificial intelligence. 

It can set out certain general principles of conduct, which must then be put into practice through policies, procedures and operational instructions. These include, for example, transparency in the use of AI, a ban on entering confidential information into unauthorised tools, human verification of outputs, and a ban on using AI for unlawful or discriminatory purposes. 

The Code of Ethics may also expressly refer to the need to use only AI tools approved by the company, thereby becoming a genuine ‘framework’ for AI governance, capable of guiding individual behaviour and strengthening a culture of compliance, in coordination with the system of corporate procedures, controls and responsibilities. 

Information requirement for emotion recognition and biometric categorization 

Anyone using emotion recognition or biometric categorisation systems as part of their business must inform the individuals concerned in advance about how the system works and must process personal data in accordance with data protection legislation (GDPR).  

On the operational side, it is therefore essential to identify the AI systems in use (e.g. access gates and attendance monitoring, contact centers with voice tone analysis, retail analytics on customers’ faces), specifying one’s role (provider or deployer, or both). Furthermore, it is advisable to check whether the system is subject to the prohibition set out in Article 5: from 2 February 2025, emotion recognition in the workplace and in educational establishments (except for medical or security purposes) and biometric categorisation aimed at inferring sensitive data will be prohibited. 

If the systems used are not subject to the ban, you must provide a notice in a clear and distinguishable manner, at the latest at the time of first exposure.  

Although the obligations for high-risk systems have been postponed until 2 December 2027 (Digital Omnibus), breaching transparency obligations already exposes organisations to fines of up to €15 million or 3 per cent of annual global turnover. It is therefore advisable to review the notices in place and examine the contractual clauses in agreements with suppliers.   

The Risk Manager’s Added Value in AI Governance 

Risk management often enters an organisation only after damage has occurred or a threat has become impossible to ignore. With AI, however, waiting means falling behind: we are in an exploratory phase where opportunities and consequences evolve together.  

The Risk Manager plays a pioneering role: researching, understanding and anticipating, because great capabilities can have equally significant impacts.  

The method remains that of risk assessment: identification, analysis and evaluation of risks, followed by risk treatment. Discriminatory content, unverified AI outputs in production or disclosure of confidential data are different but interconnected risks 

The limited availability of historical data makes it difficult to estimate probability and impact, but it is necessary to draw up a risk map and compare the residual risk with the risk appetite. A non-critical error may be tolerable if it occurs less frequently than human error; exposure to data breaches or cyber-attacks, however, is not. The Risk Manager’s added value emerges in the development of a risk treatment plan. It is therefore essential to define authorised GenAI tools, internal guidelines and procedures, and technical measures to ensure data security, as well as to train staff on AI and keeping management informed. Not simply bans, but concrete tools that transform risk into informed adoption and AI into value for the business. 

    Downloads
  • Leggi la newsletter (PDF, 712.03 KB)
  • Read the newsletter (PDF, 713.81 KB)
door
Andersen
Menu
  • About us
  • Professionals
  • Offices
  • Insights
  • Careers
  • Contacts
Utilities
  • Privacy and Cookies
  • Terms & Conditions
  • Compliance 231
  • Andersen Global

©Andersen Tax LLC and Andersen Italia. Andersen Italia is the Italian member firm of Andersen Global, a Swiss verein comprised of legally separate, independent member firms located throughout the world providing services under their own name or the brand "Andersen,” "Andersen Tax," or "Andersen Tax & Legal," or "Andersen Legal." Andersen Global does not provide any services and has no responsibility for any actions of the member firms, and the member firms have no responsibility for any actions of Andersen Global. Your use of this website is subject to the terms and conditions governing it. Please read these terms and conditions before using the website.