VIVALDI18 Governa

AI governance and compliance

AI governance and AI Act compliance

Integrating artificial intelligence into an organisation means governing technology, data, people and responsibilities. VIVALDI18 helps identify the tools in use, understand risks and obligations, and build appropriate rules, processes and controls.

ANTONIO AI is VIVALDI18 STUDIO's AI orientation assistant: it helps frame the question, does not provide legal opinions and does not replace professional assessment.

In summary

When it's useful

AI tools are already in use or about to be adopted without rules, roles or decision criteria.

What you get

  • An inventory of use cases, data and suppliers
  • Criteria for permitted, limited or forbidden uses
  • A governance plan with declared human oversight

First step

A Responsible Technology CHECK: initial inventory, risks, priorities and an in-depth plan.

Request the first step

Stated limits. This is not a legal assessment referring to a specific organisation and does not replace specialist legal review.

AI enters organisations before the rules do

  • Some AI tools are already in use, but we don't know exactly which ones.
  • People use generative assistants on their own initiative.
  • It isn't clear what data is being entered into these systems.
  • We are considering introducing a new AI-based service.
  • We don't know which suppliers are involved or under what conditions.
  • There are no shared internal rules on permitted, limited or forbidden uses.
  • It isn't defined who authorises the adoption of a new tool.
  • We don't know when explicit human oversight is needed.

Artificial intelligence is not just a technological tool: it brings data, processes, responsibilities, people, suppliers and risks that need to be governed.

What the work covers

Areas are activated based on the situation: they are not all always included.

AI mapping

We reconstruct which systems and services are actually used, by whom and for what purpose.

  • Inventory of AI systems and services
  • Officially adopted tools
  • Spontaneous staff use and shadow AI
  • Purpose of each use
  • People and functions involved
  • Suppliers
  • Categories of data used

Assessment

We analyse context, the organisation's role and risks, without automatisms or predefined conclusions.

  • The organisation's role in using the system
  • Context of use
  • Preliminary classification of systems
  • Organisational, data and rights-related risks
  • Any interaction with personal data
  • Need for human oversight
  • Impact on accessibility and inclusion, where relevant

Governance

We define who decides, who authorises, who checks and how choices remain traceable.

  • Internal responsibilities and authorisation levels
  • Procedure for adopting new tools
  • AI usage policy
  • Criteria for permitted, limited or forbidden uses
  • Exception management
  • Traceability of decisions
  • Handling incidents and misuse

Data and privacy

When systems process personal data, AI governance and data protection must be read together.

  • Minimisation and purpose limitation
  • Legal bases
  • Privacy by design and by default
  • DPIA when necessary
  • Retention and special categories of data
  • Transfers and suppliers
  • Data entered into generative systems
  • Privacy roles and responsibilities

Suppliers

External tools come with very different conditions, processing and levels of control.

  • Assessment of external tools
  • Terms of use
  • Data processing
  • Location and transfers
  • How the supplier uses the data
  • Available levels of control
  • Documentation and contractual responsibilities

People and AI literacy

Governance works when the people using the tools know what they can do, what they must not do, and why.

  • AI training and literacy
  • Risk awareness
  • Correct use of tools
  • Internal procedures
  • Responsibilities of people using AI systems
  • Human oversight

Transparency

Where relevant, the use of AI must be recognisable to whoever receives the service or content.

  • Information to users and recipients
  • Artificially generated or modified content
  • Interaction with AI systems
  • Transparency of processes
  • Responsibility for decisions

When systems process personal data, the work intertwines with the Privacy / DPO expertise.

The VIVALDI18 path

Phase 01
Map
Identifying AI tools, uses, data, suppliers and people involved.
Phase 02
Assess
Analysis of context, risks, obligations and responsibilities.
Phase 03
Define
Internal rules, policy, roles, authorisations and criteria of use.
Phase 04
Adapt
Interventions on processes, documentation, privacy, suppliers and controls.
Phase 05
Prepare people
AI literacy, training and operational guidance for conscious use.
Phase 06
Oversee
Ongoing control, updating procedures and assessing new tools or uses.

Privacy & AI Governance Check

This is the application of the VIVALDI18 CHECK model to this topic: an initial check to reconstruct the tools used, data, processes, responsibilities, risks and priorities for action.

  1. Tools
  2. Data
  3. People
  4. Obligations
  5. Risks
  6. Priorities
  7. Action plan

VIVALDI18 CHECK

Understanding the situation, the risks and the priorities.

VIVALDI18 PROGETTO

Acting on rules, processes and documentation.

VIVALDI18 PRESIDIO

Keeping control over time.

Possible results of the work

Adaptable examples for the project: not mandatory documentation in every case.

  • Map of AI tools
  • Internal register of uses
  • Map of data and suppliers
  • Preliminary assessment of obligations
  • Risk / priority matrix
  • AI usage policy
  • Approval procedure for new tools
  • Rules for generative systems
  • Guidance on data that can be entered
  • Internal roles and responsibilities
  • Human oversight procedures
  • AI literacy and training plan
  • Supplier assessment
  • Remediation plan
  • Periodic review system

We don't separate technology, rules and people

Within the same project VIVALDI18 can coordinate design, organisation, processes, privacy, AI governance, accessibility, Customer Experience and communication under a single lead. It is the most effective way to prevent privacy, artificial intelligence and accessibility from being treated as separate compartments.

Illustrative scenarios

Examples built to illustrate the type of work. They are not real cases or VIVALDI18 clients.

Local authority

A public-facing digital assistant to introduce, defining data, human oversight and transparency.

SME

Generative tools already used by staff, without shared rules or criteria on data that can be entered.

Non-profit

AI-assisted analysis of sensitive information, with roles and responsibilities to clarify.

Startup

A new AI-based digital service to assess, together with suppliers, before launch.

Frequently asked questions

Do you know which AI tools are used in your organisation?

We can start from what happens today: tools, data, people and suppliers. From there it becomes possible to define proportionate rules, priorities and controls.