Model 231 and the AI Act: AI governance enters the company.
By BoezioAI · Reading time: 9 minutes
Key points
- AI governance rests on two pillars: the institutional one (the Italian national authorities ACN and AgID) and the internal one, within organisations. The latter is not a formal box-ticking exercise but a management architecture coordinating ethical principles, legal requirements, internal functions and technical controls.
- The reference model already exists: the GDPR. Accountability, by design, impact assessments, records, training — European data governance is the matrix on which to build AI governance, and the DPO can evolve into an AI Compliance Officer.
- Art. 26 of Italian Law 132/2025 introduces aggravating circumstances for crimes committed through AI systems: many hit predicate offences under Legislative Decree 231/2001. Direct consequence: 231 organisational Models must be updated, with the "acceptable risk" threshold redefined downwards.
- Integrated compliance — 231, AI Act, Law 132/2025, GDPR — should be set up now: some AI Act obligations (AI literacy, prohibited practices, GPAI) already apply, and almost all the others will from 2 August 2026.
- "Adequate" organisational structures under Art. 2086 of the Italian Civil Code now run through AI too: failure to adopt the required organisational measures can ground directors' liability, entity liability and tort liability for organisational fault.
Italian Law no. 132/2025 designed the public architecture of Italy's AI governance, entrusting ACN and AgID with the role of national competent authorities. But the institutional side is only half the story. The other half — the one that directly concerns every company, firm and entity using AI systems — is the internal governance of technological risks and processes: not a compliance item to tick off, but an integrated management architecture in which legal and technical responsibility converge into a single infrastructure of trust.
The challenge is twofold: translating the requirements of the AI Act and Law 132/2025 into effective organisational practice, and developing internal assessment, monitoring and accountability systems that make compliance verifiable — towards authorities, users and the public.
1. The model already exists: it is called GDPR
Whoever has to build AI governance does not start from scratch. Regulation (EU) 2016/679 is the first complete experiment in systemic technology governance, and its logic — centred on the data controller and the accountability principle — introduced a paradigm of managerial compliance: not formal adherence to external obligations, but an internal system of rules, controls and documentation able to demonstrate compliance at any time.
The elements of that "matrix" are now mirrored, almost exactly, by AI regulation:
- Roles and responsibilities — internal functions (DPO, focal points, risk owners) and external controls by independent authorities anticipate the multi-level structure of the "AI governance chain";
- By design and by default — privacy by design becomes AI by design: security, fairness, robustness and rights protection built in from the design stage;
- Impact assessments — DPIAs anticipate the Fundamental Rights Impact Assessments (FRIA) and the AI Impact Assessments required for high-risk systems;
- Documentary accountability — records, traceability and audits find their parallel in the logging, documentation and transparency obligations of AI system providers;
- Training — the culture of compliance becomes the AI literacy required by Art. 4 of the AI Act of public and private operators.
📌 In this perspective the DPO can take on an evolutionary role as AI Compliance Officer or AI Governance Focal Point, ensuring coherence between data protection and algorithmic security, transparency and fairness — within the classic Plan-Do-Check-Act cycle.
2. The AI aggravating circumstances of Law 132/2025
With Art. 26, Law 132/2025 amended the Italian Criminal Code by introducing a general aggravating circumstance (in Art. 61) for cases where the use of AI systems constituted an "insidious means", hindered public or private defence or worsened the consequences of the offence, together with several special aggravating circumstances for acts committed through AI systems.
Beyond the interpretative doubts (the notion of "insidiousness" is as vague as it is hard to square with the principle of legal certainty), the operational point is another: the general aggravating circumstance is apt to apply to many predicate offences under Legislative Decree 231/2001 — from computer crimes and computer fraud (Arts. 24 and 24-bis) to market abuse, money laundering and self-laundering, and copyright offences (Arts. 25-sexies, 25-octies, 25-novies). And since AI use cases now cut across all business processes, the range of potentially affected offences extends to health and safety at work, environmental crimes, crimes against the public administration, corporate crimes.
Two special aggravating circumstances then directly hit heavyweight predicate offences: market rigging (Art. 2637 of the Civil Code) and market manipulation (Art. 185 of the Consolidated Finance Act). And Art. 25 of the same law, by extending copyright protection to works created with the aid of AI (provided they are the result of the author's intellectual work), correspondingly broadens the scope of the offence under Art. 171-ter of Law 633/1941 — itself a predicate offence.
3. The consequence: updating the 231 Model
For companies and entities using AI systems — in their internal organisation or in their production activity — the combined effect of Arts. 25 and 26 of Law 132/2025 and Art. 7 of Legislative Decree 231/2001 requires an update of the organisational Model, through the classic risk mapping, risk assessment and risk management process outlined in the Confindustria Guidelines. With three specific points of attention:
- Special sections — to be supplemented with the structure of the predicate offences aggravated by the use of AI, the identification of risk areas and the assessment of the degree of danger;
- Acceptable risk — the introduction of aggravating circumstances implies, by definition, a downward redefinition of the acceptable-risk threshold; the risk management system of Art. 9 of the AI Act for high-risk systems can serve as a reference scheme, up to the certifiable ISO/IEC 42001 standard;
- Supervisory Body — the OdV must "curate" the update as a function of impulse towards the management body, and then supervise the effective functioning of the updated Model.
⚠️ And that is not all: the delegation in Art. 24 of Law 132/2025 foreshadows autonomous criminal offences — punishable also for negligence — centred on the failure to adopt or update security measures in the production, circulation and professional use of AI systems, as well as clarified criteria for the liability of entities. AI compliance is set to weigh more, not less.
4. Beyond 231: integrated compliance
The 231 Model is necessary but not sufficient. What is needed is an approach combining 231, Law 132/2025 and the AI Act in a single compliance architecture — and it pays to set it up now, because some obligations of the European Regulation (AI literacy, prohibited practices, obligations for GPAI model providers) already apply, and almost all the others will from 2 August 2026 (subject to the postponements envisaged by the Digital Omnibus). Some building blocks to consider:
- Extended whistleblowing — Art. 87 of the AI Act applies the Whistleblowing Directive to breaches of the Regulation, and the Commission has activated an AI Act Whistleblower Tool for reports directly to the EU AI Office;
- Right to explanation — for high-risk systems, Art. 86 grants affected persons the right to an explanation of individual decision-making processes: internal structures must be able to answer;
- Value chain — the AI Act defines roles along the chain (provider, deployer, importer): responsibilities and risks must be mapped across the entire supply chain, consistently with the European fil rouge of CSRD and CSDDD;
- Adequate structures under Art. 2086 of the Civil Code — the relevance is two-sided: proper management may require incorporating automated processes into the structures set up by directors, but those tools must in turn be intrinsically adequate and compliant;
- Civil liability — as fault evolves into a "defect of adequate organisation", failure to adopt the organisational measures required by the AI Act can become a basis for liability for damages causally attributable to AI systems.
Frequently asked questions
My company already has a 231 Model: is a quick addition enough?
A real update is needed: mapping AI use cases across business processes, assessing the new aggravated offence risks, revising the special sections and protocols, training. A paragraph added in an annex will not pass the Model's adequacy test.
We have no high-risk systems: does the AI Act concern us anyway?
Yes. Staff AI literacy (Art. 4) and the ban on prohibited practices (Art. 5) apply to all operators, and using third-party generative systems raises governance, transparency and usage-policy issues in any event.
Where do you start?
With an inventory of the AI systems in use and the related roles (provider or deployer), followed by an integrated 231/AI Act/GDPR risk assessment. It is the same starting point the authorities expect to find documented.
BoezioAI: AI governance, from mapping to the Model
We support companies, entities and firms in building internal AI governance: system inventory and risk assessment, updating 231 Models and liaison with the Supervisory Body, integrated AI Act/GDPR/Law 132/2025 compliance, usage policies and training (AI literacy). The team's AI engineers handle the technical dimension; the Legal Tech lawyers the legal one — together, from day one.
Let's talk: info@boezioai.com · +39 329 7413254
Adaptation, authorised by the author, of a contribution by Avv. Dott. Comm. Dario Carta on the private governance of artificial intelligence; on the institutional pillar see the previous contribution "Legge italiana sull'IA, dalla compliance alla governance istituzionale" (NT+ Diritto, Il Sole 24 Ore). Key references: Reg. (EU) 2024/1689 (AI Act), Arts. 4, 5, 9, 10, 50, 86, 87; Italian Law no. 132 of 23 September 2025, Arts. 24-26; Legislative Decree 231/2001, Arts. 6, 7, 24, 24-bis, 25-ter, 25-sexies, 25-octies, 25-novies; Reg. (EU) 2016/679 (GDPR); Arts. 2086, 2381, 2391 of the Italian Civil Code; ISO/IEC 42001. This article is for information purposes only and does not constitute professional advice.