Vai al contenuto

AI Act, GDPR and AI governance

Use artificial intelligence in your company safely, documented and compliant, with policy, training and technical measures.

In breve

The European regulation on artificial intelligence also covers organisations that merely use these systems, with lighter obligations than those who build them but not with none at all. The three things to do first hold regardless of any deadline: know which tools are already in use in the company, write one page of rules on what may be entered into them, and establish where the entered data ends up.

Regulation and engineering together

AI governance is not only a legal matter - it needs technical measures, access control, logs and supplier checks. We cover both sides.

Proportionate rules

Policy and procedures shaped to your organisation - without pointless bureaucracy, but with everything needed to demonstrate compliance.

People who know how

AI literacy training for management and staff - the regulatory requirement that is also the best defence against the risks.

AI in a company needs rules — yours

Every organisation using artificial intelligence tools needs to know which tools it uses, which data they process, which risks they create, which suppliers are involved and which responsibilities remain its own. This is not only a regulatory obligation: it is how to use AI without incidents involving personal data, confidential information and trade secrets.

Xion IT Group brings together IT, security and privacy skills to build a model of AI governance that is practical and proportionate, integrated with GDPR, cybersecurity and IT management — because in a company those three things live together.

Our route

  1. An inventory of the AI systems already in use: tools, integrations, departments involved, data processed and purposes;
  2. Risk classification in relation to people, processes, data, security and the AI Act’s requirements;
  3. A company AI policy — authorised tools, prohibited data, human oversight, responsibilities, traceability;
  4. GDPR and data protection in AI systems — legal bases, minimisation, roles, suppliers, DPIA and technical measures;
  5. AI literacy training for staff, managers and directors, with a practical slant;
  6. Periodic reviews and updating the framework as tools and rules change.

The package: Xion AI Governance & GDPR

For organisations already using ChatGPT, Copilot, Gemini or internal automation without defined rules: a census of the tools, an internal policy, rules on personal and confidential data, training, supplier verification and technical recommendations. A compact piece of work that puts things in order — before an incident does it for you.

The tool: GAPOFF

To make governance operational and documentable, Xion built GAPOFF (www.gapoff.it): the compliance operations platform that tracks GDPR, AI Act, NIS2 and ISO 27001 obligations in unified workflows. Policies, registers and deadlines leave the spreadsheets and enter a system that can be verified.

A concrete advantage

Anyone who relies on Xion for AI governance already has the skills to implement the measures in house: IT security, backup, access management and GDPR compliance are our daily work. The policy does not stay on paper: it gets implemented on the systems.

The deadlines that already affect companies today

The AI Act is not a subject for “the future”: it came into force on 1 August 2024 and applies in phases. Some obligations are already operative — the prohibition of certain practices and, above all, the requirement of AI literacy for anyone using artificial intelligence systems in a company, in force since February 2025. Other provisions, including those on general-purpose models and high-risk systems, follow a calendar running to 2027. The practical point is simple: ignoring the subject today means arriving unprepared at the deadlines that matter — and in the meantime, using AI tools without rules exposes you to privacy and reputational risk anyway.

The most frequent case: shadow AI

The situation we find most often is not the absence of AI but its uncontrolled presence. Staff using ChatGPT, Copilot or other free tools, uploading documents, emails and client data — with the best of intentions, and with nobody having defined what is allowed. This is shadow AI, and every day that passes increases the exposure. The first governance step is always the same: surface what is actually being used, assess the risks, and replace unmanaged use with approved tools and clear rules. Not to ban AI — to make it usable without putting the company at risk.

Proportionate governance, not bureaucracy

An AI governance project should not turn into a mountain of documents nobody will read. Our approach is proportionate to the real risk: for most smaller companies and professional firms, an inventory of the tools, a clear and concise usage policy, staff training and a few technical measures (access control, logs, supplier checks) are enough. The aim is not “compliance on paper” but being able to use AI every day in the confidence that you control the data, the responsibilities and the suppliers.

The three things to do, one by one

Three practical pages: the company AI policy, AI literacy training and the DPIA for artificial intelligence systems, which is needed only in certain cases and not for every tool.

Frequently asked questions

Why do AI and the GDPR have to be handled together?

Because most AI tools process data, documents, communications or personal information. Before they are used in a company you have to assess purposes, legal bases, security, suppliers, access and retention - exactly the questions an AI governance project answers.

Does the AI Act apply to smaller companies?

Yes, it can, depending on your role and the type of AI system used. The European AI Act came into force on 1 August 2024 and applies in stages - obligations such as AI literacy and the prohibition of certain practices have applied since February 2025. Even where the risk is low, transparency, training and supplier control remain essential.

Do we need a company policy to use AI?

Yes, it is strongly advisable. A policy defines the authorised tools, which data may be used, prohibited behaviour, responsibilities, controls and training - and it prevents uncontrolled use of personal or confidential data on unvetted tools.

Can we use ChatGPT or Copilot with client data?

Only after clear rules have been defined - which data may be entered, which provider processes it, with which settings, who has access and within what limits. It is the first exercise we work through together during the review.

What is a DPIA and when is one needed for AI?

A DPIA is a data protection impact assessment, required where processing may present high risks to individuals' rights - as happens with many AI systems that analyse personal data, profile people or support decisions.

Are the tools you already use compliant?

The AI Act and the GDPR apply to what entered the company without anyone deciding it, too. Let us establish which obligations genuinely affect you.