{"id":33883,"date":"2026-10-09T17:00:48","date_gmt":"2026-10-09T15:00:48","guid":{"rendered":"https:\/\/it.andersen.com\/?p=33883"},"modified":"2026-10-09T17:40:05","modified_gmt":"2026-10-09T15:40:05","slug":"ai-governance-and-compliance-the-evolution-of-the-regulatory-framework","status":"publish","type":"post","link":"https:\/\/it.andersen.com\/en\/ai-governance-and-compliance-the-evolution-of-the-regulatory-framework\/","title":{"rendered":"AI governance and compliance: the evolution of the regulatory framework"},"content":{"rendered":"\n<p><strong>Artificial intelligence<\/strong> is no longer merely a technological issue, but a matter of corporate governance. With the <strong>AI Act<\/strong>, the European and national regulatory framework is evolving. In this issue of the <strong>Compliance &amp; Risk Management <\/strong>Newsletter, professionals from Andersen\u2019s<strong> 231\/Privacy<\/strong> Service Line have examined the <strong>key regulatory developments relating to AI <\/strong>in order to highlight the ever-increasing importance of adopting compliance controls capable of mitigating the risks arising from the use of AI systems, thereby strengthening <strong>AI governance<\/strong>.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Digital Omnibus and the AI Act: new deadlines for high-risk systems<\/h2>\n\n\n\n<p>With the <strong>Digital Omnibus<\/strong>, the European institutions have also addressed the regulation of artificial intelligence. As regards the AI Act, the legislation does not alter the framework of the regulation but does affect the timetable for the application of certain obligations, in particular those relating to <strong>high-risk AI systems, <\/strong>postponing them to<strong> 2 December 2027 <\/strong>and<strong> 2 August 2028<\/strong>. Companies can use this additional time to build an <strong>AI governance <\/strong>model based on a concrete understanding of the AI tools they already use or are considering adopting. This means <strong>mapping AI systems, classifying their risk<\/strong>, identifying internal roles and responsibilities, defining <strong>approval procedures<\/strong>, setting rules for input and output data, and providing appropriate<strong> training<\/strong>. In practical terms, the postponement gives companies the opportunity to approach AI Act <strong>compliance<\/strong> in a more structured and gradual way, embedding it into their existing internal governance, control and risk management processes.\u202f<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Artificial intelligence in Legislative Decree 231\/2001<\/h2>\n\n\n\n<p><strong>Legislative Decree No. 160\/2026<\/strong>, implementing the AI Act (EU Regulation 2024\/1689), has come into force. It has introduced a new <strong>Article 25-vicies <\/strong>into Legislative Decree 231\/2001<strong>, <\/strong>entitled <em>\u2018Offences committed through the use of artificial intelligence systems<\/em>\u2019.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The decree introduces two predicate offences into the complex system of administrative liability for legal entities. The first is <strong>Article 437-bis <\/strong>of the<strong> Criminal <\/strong>Code, which punishes <strong>the failure to adopt technical security measures or human supervision of high-risk AI systems<\/strong>, as well as their unlawful alteration, provided that this results in a real danger to life, personal or public safety, or national security. The second is <strong>Article 612-quater of the Italian Criminal Code, <\/strong>which punishes so-called <strong>\u2018deepfake\u2019<\/strong> conduct.&nbsp;&nbsp;<\/p>\n\n\n\n<p>From a 231 perspective, it will therefore be necessary to verify, as part of the risk assessment, whether and how AI \u2013 particularly in high-risk systems \u2013 is used in business processes. Should the analysis reveal <strong>a concrete exposure to the risk <\/strong>of committing the newly introduced offences, the Model must identify specific <strong>control measures<\/strong>, such as criteria and limits for the use of AI, and the definition of roles and responsibilities with regard to the generation and dissemination of content.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">AI Act, Digital Omnibus and GDPR: the redefinition of legal bases and special categories of data<\/h2>\n\n\n\n<p>On 27 July 2026, Regulation (EU) 2026\/1744, the so-called <strong>\u2018AI Omnibus<\/strong>\u2019, came into force, amending <strong>the AI Act<\/strong>. The new text provides that providers may process special categories of data (<strong>so-called sensitive data<\/strong>), such as health-related data, to detect and correct biases in AI systems. This power, previously reserved for providers of high-risk AI systems, now extends to <strong>providers <\/strong>and deployers of other AI systems and models, provided that it is ensured that it is impossible to use synthetic or anonymised data, that additional enhanced security measures are adopted, that access to the data is restricted, and that the data is deleted once the bias has been corrected.&nbsp;<\/p>\n\n\n\n<p>The situation is different for the part of the Omnibus Act that amends the <strong>GDPR<\/strong>, which is still under discussion. The European Commission\u2019s proposal clarifies that the processing of personal data for the development and use of AI systems may be based on the data controller\u2019s <strong>legitimate interest<\/strong>. However, this does not constitute an automatic green light.&nbsp;&nbsp;<\/p>\n\n\n\n<p>As regards sensitive data, the proposal introduces two new exceptions to the prohibition set out in Article 9 of the GDPR. The first concerns <strong>sensitive data present incidentally in training datasets<\/strong>: such <strong>data <\/strong>is permitted provided the organisation takes appropriate measures to prevent its collection and to remove it if detected. The second allows the use of <strong>biometric data to verify identity<\/strong>, provided it remains under the exclusive control of the data subject.\u202f\u202f&nbsp;<\/p>\n\n\n\n<p>In any case, it is advisable to take steps to map the data used in AI projects, check for the presence of sensitive data in the datasets, and document the legal bases and security measures implemented.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Risk assessment put to the test by AI: new sensitive activities and protocols for human supervision<\/h2>\n\n\n\n<p>The risk manager maps the uses of AI within business processes and identifies <strong>sensitive activities<\/strong>: those in which an error, distorted data or omitted information could affect people, financial results or <strong>business continuity<\/strong>. For each one, they reconstruct what might happen, assess how likely it is and what damage it would cause. They then examine <strong>existing controls <\/strong>to determine whether the residual risk is acceptable to the organisation.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Human oversight <\/strong>must also stem from this analysis. Whoever approves a forecast must be able to verify the data and assumptions used; whoever reviews the anomalies flagged by the AI must also check a sample of the cases that were excluded. The protocol sets out who intervenes, at what stage, with what information, and with what authority to correct or halt the system. These checks must be documented, so that any errors detected can be used to update the <strong>risk assessment<\/strong>.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The risk manager does not simply add a signature to the process: they identify where the company may lose control of its own decisions and establish the conditions for continuing to use AI with confidence.&nbsp;<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Artificial intelligence is no longer merely a technological issue, but a matter of corporate governance. With the AI Act, the European and national regulatory framework is evolving. In this issue of the Compliance &amp; Risk Management Newsletter, professionals from Andersen\u2019s 231\/Privacy Service Line have examined the key regulatory developments relating to AI in order to [&hellip;]<\/p>\n","protected":false},"author":161,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[50],"tags":[],"class_list":["post-33883","post","type-post","status-publish","format-standard","hentry","category-insights"],"acf":[],"_links":{"self":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts\/33883","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/users\/161"}],"replies":[{"embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/comments?post=33883"}],"version-history":[{"count":1,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts\/33883\/revisions"}],"predecessor-version":[{"id":33886,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts\/33883\/revisions\/33886"}],"wp:attachment":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/media?parent=33883"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/categories?post=33883"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/tags?post=33883"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}