Beyond the Algorithm:
Compliance as a New Strategic Asset in the Age of Artificial Intelligence

Artificial intelligence has moved beyond the stage of mere technological experimentation to establish itself as a key driver of business model transformation.
Nevertheless, companies’ willingness to integrate these systems into their workflows is now challenged by a complex regulatory framework, with compliance checks related to data protection and the safeguarding of fundamental rights and freedoms often posing a major challenge.
The adoption of these technologies cannot, in fact, be separated from a framework of “enhanced” legality, which requires coordination—above all between the GDPR (EU Regulation 2016/679) and the AI Act (EU Regulation 2024/1689)—and beyond: for example, when solutions are directed at employees, national protections such as the Workers’ Statute must also be taken into account.
The AI ACT (EU Regulation 2024/1689)
The AI Act adopts a risk-based regulatory approach based on the risk that the use of an artificial intelligence system could harm people’s health and safety or fundamental rights, taking into account, among other things, both the severity of the potential harm and the likelihood of it occurring. The legislation distinguishes, in particular, between AI practices that are prohibited because they pose an unacceptable risk, high-risk systems, and systems with minimal or no risk. Each category corresponds to a different level of regulation: ranging from prohibitions on uses deemed incompatible with the fundamental rights and values of the European Union to more limited obligations.
The AI Act took effect in 2024, and Article 113 set August 2, 2026, as the general effective date. However, the regulatory framework is evolving: for example, the recent Digital Omnibus (EU Regulation 2026/1744), among many other changes, introduced greater flexibility in the transition period, postponing certain compliance requirements to December 2, 2027, and August 2, 2028. The goal is to allow businesses to adapt more gradually, particularly while awaiting the development of more established technical standards and governance tools.
But be aware: many of these requirements are already fully in effect.
Among these, Article 4 on AI literacy is particularly significant, as it requires providers and deployers to adopt measures that are proportionate, documented, and consistent with their operational context to support the development of AI literacy among their staff as well as any other individuals involved in the operation and use of AI systems on their behalf.
And then there is Article 50, which deals with transparency: users must be informed when they interact with an AI system, and content that is artificially generated or manipulated must be identifiable—as, for example, in the case of deepfakes and content intended to inform the public on matters of general interest, in the cases provided for by the Regulation.
From Theory to Practice: A Case Handled by the Data Protection Authority
It is precisely this risk-based approach that makes a recent statement by the Data Protection Authority particularly noteworthy. The case demonstrates, in fact, that AI compliance cannot be limited to an abstract assessment of a system’s technical characteristics, but must take into account how that technology is actually used and what effects it may have on people.
In Decision No. 342 of 2026, the Authority addressed an artificial intelligence system capable of analyzing employees’ communications on platforms such as Slack and Microsoft Teams to identify potential signs of stress. The software had been designed with several safeguards: the employer could not access its employees’ individual data, and any reports made available to the employer were compiled in aggregated form. Thus, from a technical standpoint, the application appeared to place particular emphasis on privacy protection.
Yet the Data Protection Authority, while acknowledging that no violation of personal data protection had occurred through the use of the plug-in up to that point, warned of a risk that was far from theoretical: in a small company, even a seemingly anonymous report concerning a small number of employees could, through deductions and information already available, make it possible to identify the individuals concerned. Aggregating data does not always mean making it completely anonymous.
This teaches us a fundamental lesson: security isn't just a form to fill out, but an analysis that must be tailored to the specific reality of each office.
Where to start?
So where should we start?
First of all, you need to figure out what you're already using.
What AI systems does the company use? Who uses them, and for what purposes? What data is entered into them? And, most importantly, which decisions are supported or automated? This initial assessment makes it possible to identify the relevant systems and evaluate the risks associated with them, including to understand what obligations may arise, for example, under the AI Act and—when personal data is processed—under the GDPR.
However, simply understanding the systems is not enough. It is also necessary to build a system of rules and accountability around AI: role-based training, internal procedures and company policies, documentation of assessments and decisions made, as well as the preparation of the necessary disclosures. And it is necessary to establish oversight and monitoring mechanisms that allow for the verification of system behavior over time, the detection of anomalies, and intervention when risks change.
There is also another point that is often overlooked: the relationship with the providers of these technologies. Responsibility and guarantees of compliance, transparency, and traceability regarding the operation of the
The system, processing and transfer of personal data, the use of data for model training, security measures, and update management are among the aspects that warrant specific evaluation and cannot simply be left to the provider’s standard terms and conditions.
These are just a few pieces of a much broader puzzle: that said, the underlying message is simple—compliance isn’t something to be addressed only after the project is already complete. It is an integral part of the project, to be built in from the very beginning to guide innovation.
During the AI Super Power Master’s Program , we will have the opportunity to explore some of the regulatory issues related to the use of artificial intelligence, in order to gain a better understanding of the opportunities and factors to consider when choosing to implement or develop it within one’s business.
Regina Casolari, Esq.