AI in a company needs rules — yours
Every organisation using artificial intelligence tools needs to know which tools it uses, which data they process, which risks they create, which suppliers are involved and which responsibilities remain its own. This is not only a regulatory obligation: it is how to use AI without incidents involving personal data, confidential information and trade secrets.
Xion IT Group brings together IT, security and privacy skills to build a model of AI governance that is practical and proportionate, integrated with GDPR, cybersecurity and IT management — because in a company those three things live together.
Our route
- An inventory of the AI systems already in use: tools, integrations, departments involved, data processed and purposes;
- Risk classification in relation to people, processes, data, security and the AI Act’s requirements;
- A company AI policy — authorised tools, prohibited data, human oversight, responsibilities, traceability;
- GDPR and data protection in AI systems — legal bases, minimisation, roles, suppliers, DPIA and technical measures;
- AI literacy training for staff, managers and directors, with a practical slant;
- Periodic reviews and updating the framework as tools and rules change.
The package: Xion AI Governance & GDPR
For organisations already using ChatGPT, Copilot, Gemini or internal automation without defined rules: a census of the tools, an internal policy, rules on personal and confidential data, training, supplier verification and technical recommendations. A compact piece of work that puts things in order — before an incident does it for you.
The tool: GAPOFF
To make governance operational and documentable, Xion built GAPOFF (www.gapoff.it): the compliance operations platform that tracks GDPR, AI Act, NIS2 and ISO 27001 obligations in unified workflows. Policies, registers and deadlines leave the spreadsheets and enter a system that can be verified.
A concrete advantage
Anyone who relies on Xion for AI governance already has the skills to implement the measures in house: IT security, backup, access management and GDPR compliance are our daily work. The policy does not stay on paper: it gets implemented on the systems.
The deadlines that already affect companies today
The AI Act is not a subject for “the future”: it came into force on 1 August 2024 and applies in phases. Some obligations are already operative — the prohibition of certain practices and, above all, the requirement of AI literacy for anyone using artificial intelligence systems in a company, in force since February 2025. Other provisions, including those on general-purpose models and high-risk systems, follow a calendar running to 2027. The practical point is simple: ignoring the subject today means arriving unprepared at the deadlines that matter — and in the meantime, using AI tools without rules exposes you to privacy and reputational risk anyway.
The most frequent case: shadow AI
The situation we find most often is not the absence of AI but its uncontrolled presence. Staff using ChatGPT, Copilot or other free tools, uploading documents, emails and client data — with the best of intentions, and with nobody having defined what is allowed. This is shadow AI, and every day that passes increases the exposure. The first governance step is always the same: surface what is actually being used, assess the risks, and replace unmanaged use with approved tools and clear rules. Not to ban AI — to make it usable without putting the company at risk.
Proportionate governance, not bureaucracy
An AI governance project should not turn into a mountain of documents nobody will read. Our approach is proportionate to the real risk: for most smaller companies and professional firms, an inventory of the tools, a clear and concise usage policy, staff training and a few technical measures (access control, logs, supplier checks) are enough. The aim is not “compliance on paper” but being able to use AI every day in the confidence that you control the data, the responsibilities and the suppliers.
The three things to do, one by one
Three practical pages: the company AI policy, AI literacy training and the DPIA for artificial intelligence systems, which is needed only in certain cases and not for every tool.