Operational Guidelines for Companies and SMEs – 2

In the previous Bulletin we outlined the regulatory and ethical framework established by the Ministry of Labour Decree (DM 180 of 17 December 2025) regarding the introduction of Artificial Intelligence in the workplace. We examined the impact of the AI Act, which classifies systems used for the recruitment and management of workers as “high risk,” and we explored the principles of the “human-centric” approach promoted by the Ministry to safeguard professional dignity, prevent algorithmic discrimination, and curb the risks of invasive surveillance.

Continuing the analysis of the measure, this second installment moves into the operational core of the Guidelines. While the first part focused on the value framework and fundamental rights, the attention now shifts to business practice.

In this Bulletin we will illustrate the six-phase roadmap suggested by the document to help companies—particularly SMEs—integrate AI systems in a safe, compliant, and sustainable manner.

We will explore the key steps of this methodical path:

  • From the preliminary assessment of digital maturity (AI Readiness) and the strategic planning of internal governance,
  • to the testing phase through pilot projects in controlled environments and the subsequent scaling of technologies,
  • and finally the two crucial cross-cutting phases: continuous risk monitoring and the enhancement of human capital through upskilling and reskilling policies aimed at preventing digital exclusion.

Lastly, we will translate the Ministry’s guidance into practical corporate compliance implications by examining the concrete actions required of employers: from the obligation to map and classify AI systems to updating the Risk Assessment Document (DVR) in order to mitigate psychosocial risks linked to “automation stress,” while ensuring full compliance with Article 22 of the GDPR and with the limits on remote monitoring established by the Workers’ Statute.

Guidelines

The Guidelines propose a structured six-phase pathway to support companies—especially SMEs—in integrating AI systems.

The document distinguishes between four “vertical” (sequential) phases and two “cross-cutting” phases that accompany the entire process.

The suggested approach is methodical and includes:

  1. Preliminary Assessment (AI Readiness): Analysis of digital maturity, the quality of available data, and internal skills.
  2. Strategic Planning and Governance: Definition of objectives, introduction of internal policies, and appointment of responsible roles (e.g., a Chief AI Officer or involvement of the Data Protection Officer – DPO).
  3. Experimentation (Pilot Projects): Testing in controlled environments or regulatory sandboxes to assess risks and benefits before large-scale deployment.
  4. Implementation and Scaling: Gradual integration into business processes while ensuring interoperability with existing systems.
  5. Monitoring and Risk Management (Cross-cutting): Continuous cycle of ethical audits, performance verification, and algorithm updates.
  6. Enhancement of Human Capital (Cross-cutting): Investment in upskilling and reskilling to prevent technological exclusion.

Condividi

Post Recenti

Workshop – Come realizzare una FRIA

Beyond the Algorithm: Safeguarding the Human in the Age of Artificial Intelligence

Energy Telemarketing: Law 49/2026 Changes the Rules of the Game – 2