News · Governance · 8 September 2026

Model 231 and the AI Act: AI governance enters the company.

By BoezioAI · Reading time: 9 minutes

Key points

  • AI governance rests on two pillars: the institutional one (the Italian national authorities ACN and AgID) and the internal one, within organisations. The latter is not a formal box-ticking exercise but a management architecture coordinating ethical principles, legal requirements, internal functions and technical controls.
  • The reference model already exists: the GDPR. Accountability, by design, impact assessments, records, training — European data governance is the matrix on which to build AI governance, and the DPO can evolve into an AI Compliance Officer.
  • Art. 26 of Italian Law 132/2025 introduces aggravating circumstances for crimes committed through AI systems: many hit predicate offences under Legislative Decree 231/2001. Direct consequence: 231 organisational Models must be updated, with the "acceptable risk" threshold redefined downwards.
  • Integrated compliance — 231, AI Act, Law 132/2025, GDPR — should be set up now: some AI Act obligations (AI literacy, prohibited practices, GPAI) already apply, and almost all the others will from 2 August 2026.
  • "Adequate" organisational structures under Art. 2086 of the Italian Civil Code now run through AI too: failure to adopt the required organisational measures can ground directors' liability, entity liability and tort liability for organisational fault.

Italian Law no. 132/2025 designed the public architecture of Italy's AI governance, entrusting ACN and AgID with the role of national competent authorities. But the institutional side is only half the story. The other half — the one that directly concerns every company, firm and entity using AI systems — is the internal governance of technological risks and processes: not a compliance item to tick off, but an integrated management architecture in which legal and technical responsibility converge into a single infrastructure of trust.

The challenge is twofold: translating the requirements of the AI Act and Law 132/2025 into effective organisational practice, and developing internal assessment, monitoring and accountability systems that make compliance verifiable — towards authorities, users and the public.

1. The model already exists: it is called GDPR

Whoever has to build AI governance does not start from scratch. Regulation (EU) 2016/679 is the first complete experiment in systemic technology governance, and its logic — centred on the data controller and the accountability principle — introduced a paradigm of managerial compliance: not formal adherence to external obligations, but an internal system of rules, controls and documentation able to demonstrate compliance at any time.

The elements of that "matrix" are now mirrored, almost exactly, by AI regulation:

📌 In this perspective the DPO can take on an evolutionary role as AI Compliance Officer or AI Governance Focal Point, ensuring coherence between data protection and algorithmic security, transparency and fairness — within the classic Plan-Do-Check-Act cycle.

2. The AI aggravating circumstances of Law 132/2025

With Art. 26, Law 132/2025 amended the Italian Criminal Code by introducing a general aggravating circumstance (in Art. 61) for cases where the use of AI systems constituted an "insidious means", hindered public or private defence or worsened the consequences of the offence, together with several special aggravating circumstances for acts committed through AI systems.

Beyond the interpretative doubts (the notion of "insidiousness" is as vague as it is hard to square with the principle of legal certainty), the operational point is another: the general aggravating circumstance is apt to apply to many predicate offences under Legislative Decree 231/2001 — from computer crimes and computer fraud (Arts. 24 and 24-bis) to market abuse, money laundering and self-laundering, and copyright offences (Arts. 25-sexies, 25-octies, 25-novies). And since AI use cases now cut across all business processes, the range of potentially affected offences extends to health and safety at work, environmental crimes, crimes against the public administration, corporate crimes.

Two special aggravating circumstances then directly hit heavyweight predicate offences: market rigging (Art. 2637 of the Civil Code) and market manipulation (Art. 185 of the Consolidated Finance Act). And Art. 25 of the same law, by extending copyright protection to works created with the aid of AI (provided they are the result of the author's intellectual work), correspondingly broadens the scope of the offence under Art. 171-ter of Law 633/1941 — itself a predicate offence.

3. The consequence: updating the 231 Model

For companies and entities using AI systems — in their internal organisation or in their production activity — the combined effect of Arts. 25 and 26 of Law 132/2025 and Art. 7 of Legislative Decree 231/2001 requires an update of the organisational Model, through the classic risk mapping, risk assessment and risk management process outlined in the Confindustria Guidelines. With three specific points of attention:

⚠️ And that is not all: the delegation in Art. 24 of Law 132/2025 foreshadows autonomous criminal offences — punishable also for negligence — centred on the failure to adopt or update security measures in the production, circulation and professional use of AI systems, as well as clarified criteria for the liability of entities. AI compliance is set to weigh more, not less.

4. Beyond 231: integrated compliance

The 231 Model is necessary but not sufficient. What is needed is an approach combining 231, Law 132/2025 and the AI Act in a single compliance architecture — and it pays to set it up now, because some obligations of the European Regulation (AI literacy, prohibited practices, obligations for GPAI model providers) already apply, and almost all the others will from 2 August 2026 (subject to the postponements envisaged by the Digital Omnibus). Some building blocks to consider:

Frequently asked questions

My company already has a 231 Model: is a quick addition enough?

A real update is needed: mapping AI use cases across business processes, assessing the new aggravated offence risks, revising the special sections and protocols, training. A paragraph added in an annex will not pass the Model's adequacy test.

We have no high-risk systems: does the AI Act concern us anyway?

Yes. Staff AI literacy (Art. 4) and the ban on prohibited practices (Art. 5) apply to all operators, and using third-party generative systems raises governance, transparency and usage-policy issues in any event.

Where do you start?

With an inventory of the AI systems in use and the related roles (provider or deployer), followed by an integrated 231/AI Act/GDPR risk assessment. It is the same starting point the authorities expect to find documented.

BoezioAI: AI governance, from mapping to the Model

We support companies, entities and firms in building internal AI governance: system inventory and risk assessment, updating 231 Models and liaison with the Supervisory Body, integrated AI Act/GDPR/Law 132/2025 compliance, usage policies and training (AI literacy). The team's AI engineers handle the technical dimension; the Legal Tech lawyers the legal one — together, from day one.

Let's talk: info@boezioai.com · +39 329 7413254

Adaptation, authorised by the author, of a contribution by Avv. Dott. Comm. Dario Carta on the private governance of artificial intelligence; on the institutional pillar see the previous contribution "Legge italiana sull'IA, dalla compliance alla governance istituzionale" (NT+ Diritto, Il Sole 24 Ore). Key references: Reg. (EU) 2024/1689 (AI Act), Arts. 4, 5, 9, 10, 50, 86, 87; Italian Law no. 132 of 23 September 2025, Arts. 24-26; Legislative Decree 231/2001, Arts. 6, 7, 24, 24-bis, 25-ter, 25-sexies, 25-octies, 25-novies; Reg. (EU) 2016/679 (GDPR); Arts. 2086, 2381, 2391 of the Italian Civil Code; ISO/IEC 42001. This article is for information purposes only and does not constitute professional advice.

← All news