01 · Register
Register of systems
Every AI system used in the company, catalogued: purpose, owner, data, risk. Including shadow AI.
Art. 26
Policy, register, human oversight, evidence. Every rule we write leaves a trace that an auditor — or you — can check. No façade seals.
Governance is what makes AI usable without fear.
01 · Why govern
Tools used without tracking, company data in the hands of unapproved services, outputs never checked. This is shadow AI: when it matters — an audit, an incident, a client — your word is not enough.
The AI Act provides for penalties of up to €35 million or 7% of total worldwide annual turnover for prohibited practices (Art. 5); for the other obligations, penalties reach up to €15 million or 3% (Art. 99). SMEs are subject to the lower of the two amounts.
Reg. (EU) 2024/1689, Arts. 5 and 99 · Law No. 132 of 23 September 2025
02 · What governing means
"Governing AI" stays an abstraction until it takes a verifiable form. Here are the five pillars we build on — each with its anchor to the AI Act and, above all, with the proof it leaves behind.
01 · Register
Every AI system used in the company, catalogued: purpose, owner, data, risk. Including shadow AI.
Art. 26
02 · Risk
Every use placed in its AI Act category, from prohibited uses to minimal risk, with the obligations that follow.
Arts. 5, 6, 50
03 · People
A competent person oversees the high-risk systems. AI proposes, the human decides.
Art. 14
04 · Rules
Who can use what, with which data, within which limits. Written and assigned, not implicit.
Art. 26
05 · Evidence
Every decision leaves a retained trace: logs kept for at least six months, ready for an inspection.
Art. 26(6)
03 · How we make it verifiable
In short: a rule does not stay on paper. It is applied in the process, leaves recorded evidence and passes to a person when a check is needed.
Rule
Definedwritten, not implicitApplication
In the processwhere the work happensEvidence
Recordedtracked and retainedOversight
The person decidesThe verification chain
Six steps, from rule to audit readiness. Tap a step to see what it leaves behind.
The usage rule, in writing.
What it leaves: a written policy and assigned roles — not rules implicit in people's heads.
The risk of each system.
What it leaves: each system placed on prohibited / high-risk / transparency / minimal, with the obligations that follow (Arts. 5, 6, 50).
The system in the register.
What it leaves: an entry in the register of systems with purpose, owner, data and review date (Art. 26).
With a competent person.
What it leaves: human-oversight points defined on the high-risk systems. AI proposes, the person decides (Art. 14).
The evidence, over time.
What it leaves: logs kept for at least six months, ready for an inspection (Art. 26(6)).
Ready for readiness and audit.
What it leaves: documentation and controls aligned, ready for an ISO/IEC 42001 readiness or for an audit.
Why this concerns you even if you do not "develop" AI: anyone who uses an AI system in the course of their professional activity is a deployer (deployer/user). For high-risk systems, the deployer has specific obligations — including human oversight and the retention of logs (Art. 26).
Reg. (EU) 2024/1689, Arts. 14, 26 and 50
04 · AI Act & ISO 42001, no myth
The AI Act classifies systems into four levels: prohibited (Art. 5), high-risk (Art. 6 and Annex III), transparency obligations (Art. 50) and minimal risk. We identify where your system sits and which obligations follow.
Reg. (EU) 2024/1689, Arts. 5, 6, 50 and Annex III
Following the Digital Omnibus (adopted by the Council of the EU on 29 June 2026), the obligations for high-risk systems apply from 2 December 2027 (stand-alone systems, Annex III) and from 2 August 2028 (AI embedded in regulated products, Annex I).
Digital Omnibus, Council of the EU, 29 June 2026 · "as from" dates, an evolving framework
Myth vs reality
On ISO/IEC 42001 we are clear — and it is a mark of seriousness, not a limitation.
ISO/IEC 42001:2023 · voluntary standard, complementary to the AI Act
The sources, in detail
Every obligation we cite is traceable back to its official source. Our Regulations pages explain, for each rule, what the source says and how to read it for an SME.
Risk, deployer obligations, transparency and penalties.
Open the page →Italy's first national AI law: authorities and principles.
Open the page →Legal basis, personal data and processing in the use of AI.
Open the page →The AI management system: voluntary, complementary to the Act.
Open the page →05 · Governance in action
A simplified extract of how the register of systems we build with you looks: each system, its risk, the active controls.
Define the real perimeter with an AI Entry Assessment. Govern
Illustrative example — real client data never appears on this site
06 · Proportionate governance
Governance must not weigh more than the problem it solves. We calibrate it to your reality — and to only the obligations that genuinely concern you.
Only the obligations that genuinely concern you: first we understand which, then we act.
Start from an assessment and grow only if you see value. No imposed corporate apparatus.
No mandated software: we govern what you already use, with technology neutrality.
The team stays autonomous: governance must not depend on us to work.
The first step
The starting point is the AI Entry Assessment: a map of systems, gap analysis on AI Act and ISO/IEC 42001, a prioritised roadmap. From there, every rule will have its proof.