YOUR
Search

    20.09.2026

    Artificial intelligence putting corporate governance to the test: adequate arrangements, model 231 and liability


    The use of artificial intelligence is (also) progressively becoming part of companies’ decision-making and operational processes: from personnel selection to the management of relationships with customers and suppliers, from data analysis to the preparation of documents, as well as internal control and investigative activities.

    The legal debate has focused predominantly on the obligations introduced by the AI Act and on the classification of systems according to their respective level of risk. For corporate bodies, however, the issue is broader. The adoption of artificial intelligence tools is not merely a technological or regulatory compliance choice, but a decision that affects the organisation of the company, its decision-making processes and its control system.

    Artificial intelligence therefore represents a new test of the adequacy of organisational, administrative and accounting arrangements and raises questions directly connected with the duties and liabilities of directors, the board of statutory auditors, the Supervisory Body (Organismo di Vigilanza) and other control functions. The issue is not to identify new forms of liability, but to assess how established duties – relating to organisation, information and oversight – should be applied in a technological context characterised by greater complexity, speed and opacity.

     

    A governance choice, not merely a technological one

    Article 2086 of the Italian Civil Code requires an entrepreneur operating in corporate or collective form to establish organisational, administrative and accounting arrangements appropriate to the nature and size of the business.

    As is known, the adequacy of such arrangements cannot be assessed in the abstract, but must be assessed in light of the business carried on, the complexity of the organisation and the risks actually assumed. From this perspective, the introduction of artificial intelligence systems into business processes may make it necessary to update existing arrangements.

    It is worth emphasising that there is a circular relationship between organisational arrangements and information flows: information flows function effectively if the arrangements are adequate, but, in order to be adequate, the arrangements must in turn ensure an effective exchange of information within the company. Artificial intelligence systems are relevant from both perspectives: they fall within the notion of technical arrangements – and, as such, are subject to the duty of adequacy – even when they are used exclusively to facilitate the flow of information among corporate bodies.

    This approach now finds significant support in positive law. The recent reform of the Consolidated Law on Finance (Testo Unico della Finanza -TUF) expressly brought the use and monitoring of artificial intelligence systems within the scope of the administrative, organisational and accounting arrangements of listed companies. New Article 123-bis requires companies to describe the policies adopted concerning the use and monitoring of new technologies – including AI systems – as well as their policies for managing cyber risks and cybersecurity. New Article 149-ter, from the internal control perspective, requires verification that continuous, automated and predictive monitoring systems are adequate and proportionate to the nature and size of the company. Although these provisions apply to listed companies, they reflect a broader trend: the use of artificial intelligence is no longer merely a technological or regulatory issue, but has become an integral part of corporate governance and enterprise risk management.

    The first step should be to identify the AI systems used within the organisation. In many companies, these tools are in fact adopted autonomously by individual functions, sometimes through general-purpose applications, without a centralised decision and without their use being adequately mapped.

    This may give rise to a form of “shadow AI” comparable, in certain respects, to the phenomenon of shadow IT: tools that are often used outside the company’s authorisation and control processes, with resulting risks relating to the confidentiality of information, the protection of personal data, intellectual property, cybersecurity and the reliability of outputs.

    Adequate arrangements should instead enable the company to know at least:

    • which AI systems are being used;
    • for what purposes and within which processes;
    • which data are entered or processed;
    • who is authorised to use them;
    • which individuals are responsible for their selection, configuration and supervision;
    • which controls are in place over the outputs produced;
    • how decisions taken with the support of such systems are documented.

    This does not necessarily require the creation of new structures or functions. Rather, AI governance should be integrated into existing safeguards, with responsibilities, decision-making procedures and information flows defined consistently with the characteristics of the company.

     

    The role of the board of directors

    The adoption of artificial intelligence systems may, within certain limits, fall within management decisions entrusted to the discretion of directors. The decision, however, must be preceded by an informed and reasonable process.

    The business judgment rule protects entrepreneurial discretion and prevents the merits of management decisions from being reviewed solely on the basis of a negative outcome. It does not, however, remove from judicial scrutiny the process through which the decision was taken, nor does it protect manifestly irrational decisions adopted in the absence of the necessary information or without an adequate assessment of the relevant risks.

    Where a decision has been taken with the support of an artificial intelligence system, the business judgment rule can operate only provided that the directors have adequately substantiated their decision. The reasoning is relevant in both directions: both where the intention is to follow the algorithm’s recommendation and where the decision is to depart from it. In the absence of an explicit and reasoned justification, there is a risk that the decision may amount to mere uncritical adherence to the machine’s output – making it impossible to reconstruct ex post the reasoning followed by the directors and to verify the methodological soundness of the decision. From this perspective, the reasoning constitutes the principal safeguard against decision-making becoming overly dependent on the system’s output and is a necessary condition for management discretion to be regarded as having been effectively exercised.

    Before introducing an AI system into a material business process, directors should therefore verify, including with the support of the relevant functions:

    • the purpose pursued and the benefits reasonably expected;
    • the reliability of the system and the quality of the data used;
    • the legal, operational, reputational and security risks;
    • the possibility of explaining and verifying the results produced;
    • the existence of effective human oversight;
    • the adequacy of the contractual terms applied by the provider;
    • the possibility of conducting audits and controls;
    • the arrangements for monitoring following implementation.

    Ultimate responsibility for the decision cannot be transferred either to the artificial intelligence system or to the technology provider. Similarly, reliance on AI should not result in a substantially uncontrolled delegation to IT functions or external consultants.

    The greater the extent to which the system is intended to affect strategic decisions, the exercise of corporate powers or the rights of employees, customers and other stakeholders, the greater the level of involvement of the corporate bodies and the degree of formalisation of the relevant decision-making process should be.

     

    Delegation, information flows and the duty to act on an informed basis

    AI governance also intersects with the rules governing delegations and information flows under Articles 2381-bis and 2381-ter of the Italian Civil Code.

    Delegated bodies are required to ensure that the organisational, administrative and accounting arrangements are adequate to the nature and size of the business. On the basis of the information received, the board of directors assesses their adequacy; all directors are also required to act on an informed basis.

    The use of AI should therefore be reflected in the periodic information flows addressed to the board, at least where it concerns significant processes. The information should include not only a list of ongoing projects, but also the risks identified, any incidents or malfunctions recorded, the results of the checks carried out and any corrective measures adopted.

    With specific reference to the artificial intelligence systems adopted, the information provided by the delegated bodies to the board should cover at least: the origin of the system and the identity of the provider; the data used for its development and training; how it operates; the reasons for choosing it over the alternatives available on the market; and the degree of transparency and the main reliability parameters. Only on the basis of such information can the board be regarded as adequately informed and effectively perform its function of assessing the adequacy of the organisational arrangements.

    In this context, it may be appropriate to appoint an internal officer or establish an interdisciplinary committee involving, depending on the size and structure of the company, the legal, compliance, risk management, IT, cybersecurity, privacy, internal audit and human resources functions.

    Some companies have adopted more structured solutions, establishing a board committee dedicated to technological matters – with preparatory, proposal and advisory functions vis-à-vis the full board – or appointing a specific algorithm officer responsible for continuously assessing the transparency, adequacy and proper functioning of the algorithmic systems employed. The latter role is particularly useful in view of the self-learning capabilities of algorithms, which may cause them to modify their behaviour over time, making continuous and systematic oversight necessary rather than merely episodic supervision.

    The objective is not to bureaucratise innovation, but to ensure that decisions are taken by individuals with the necessary expertise and on the basis of sufficient, verifiable and documented information.

     

    Oversight by the Board of Statutory Auditors

    The board of statutory auditors is likewise required to address the use of artificial intelligence within the corporate organisation.

    The duty to oversee the adequacy of the organisational arrangements and their actual functioning does not entail a technical assessment of individual algorithms. It does, however, require the board of statutory auditors to verify the existence of a corporate process capable of identifying, assessing and managing the risks associated with the use of AI.

    The board may therefore request information, inter alia, on the existence of an internal policy, the allocation of responsibilities, training activities, the systems considered to present the greatest risks, the results of audits and any incidents that may have occurred.

    The complete absence of information flows concerning tools already used in significant business processes could be an indication that the organisational arrangements are inadequate or, at the very least, that they need to be updated.

     

    Artificial Intelligence and Model 231

    The introduction of AI systems also requires an assessment of their possible implications for the organisational, management and control model adopted pursuant to Legislative Decree No. 231/2001 (the “Model 231”). AI, in fact, does not merely add new risks to the catalogue of risks already mapped: it may substantially alter the risk assessment of sensitive activities – changing the probability, manner and scale of potentially unlawful conduct – and thereby put the adequacy of the existing model to the test in practice.

    AI may affect the risk of committing various predicate offences. By way of example, this includes the manipulation of information and documents, cyber offences, copyright infringements, corporate offences, corrupt practices and the improper use of confidential information.

    Technology can certainly strengthen controls by making it possible to analyse large volumes of data and identify anomalies that would be difficult to detect through traditional checks. At the same time, however, it may increase the speed, scale and difficulty of tracing unlawful conduct.

    The Model 231 risk assessment should therefore consider which sensitive activities involve the use of artificial intelligence systems and assess whether the existing protocols remain adequate. It may be necessary to update procedures concerning authorisations, segregation of duties, data management, traceability of operations, supplier selection and document retention.

    Particular attention should be paid to the allocation of responsibilities. The presence of an automated process cannot create a control-free area in which it is impossible to establish who authorised the use of the system, verified the result or took the final decision.

    The Supervisory Body is not required to replace directors or technical functions in managing AI systems. Within the scope of its duties, however, it should receive sufficient information to assess the impact of such tools on Model 231 risks and on the effective implementation of the model. Information flows to the Supervisory Body could concern, inter alia, the introduction of AI systems into sensitive activities, any incidents, anomalies or unauthorised uses, and the results of audits and monitoring activities. The use of artificial intelligence may, in turn, support certain of the Supervisory Body’s control activities, provided that it does not replace critical assessment of the results and that the principles of proportionality, confidentiality and reliability are respected.

     

    AI in Internal Investigations

    A further area of particular interest concerns the use of artificial intelligence in internal investigations.

    AI tools can facilitate the analysis of large volumes of documents, communications and corporate data, identifying connections, anomalies or recurring patterns that may be useful for investigative purposes. Their use nevertheless requires specific safeguards: the origin and quality of the data must be verified, discriminatory or misleading results must be prevented, the confidentiality of information must be ensured and the rights of the persons involved must be protected.

    An algorithmic output should never, on its own, be regarded as conclusive evidence of unlawful conduct. It must be possible to reconstruct the method followed and subject the results to effective human review. The decision to take disciplinary measures, make a report or pursue further action must remain entrusted to competent individuals, on the basis of verified elements and in compliance with the applicable safeguards.

     

    The interface with the AI Act

    > Regulation (EU) 2024/1689 – the AI Act – establishes a framework based on the level of risk associated with different systems and provides, as applicable, for obligations concerning risk management, data quality, documentation, record-keeping and traceability, transparency, human oversight and monitoring.

    These obligations do not exhaust the issue of corporate governance of AI, but they help define the substantive content of the safeguards that companies must adopt. Even where a system does not fall within the category of high-risk systems, its use may nevertheless be relevant to the proper organisation of the company and to the duties of its corporate bodies.

    Compliance with the AI Act and the adequacy of organisational arrangements therefore operate on distinct but interconnected levels: the former concerns compliance with the obligations laid down by European legislation; the latter requires a broader and proportionate assessment of the ways in which the company governs its activities and the associated risks.

     

    Towards integrated artificial intelligence governance

    Artificial intelligence does not automatically give rise to new forms of directors’ liability. It does, however, require existing duties to be applied to a technological context characterised by greater complexity, speed and opacity.

    For corporate bodies, the point is not to know in detail how every system works technically, but to ensure that the company has the expertise, procedures and controls necessary to use it in an informed manner.

    Effective governance should systematically consider which artificial intelligence systems are being used and for what purposes, who authorises their introduction and assumes responsibility for them, which risks are assessed before implementation and what forms of human oversight are actually provided for. It is also necessary to verify that outputs are traceable and verifiable, that contractual relationships with providers adequately regulate matters relating to data, confidentiality, auditing, security and liability, that corporate bodies and control functions receive adequate information flows, and that the Model 231 and corporate procedures have been updated in light of the new risks.

    Innovation should not be hindered, but properly governed. Precisely the ability to integrate artificial intelligence responsibly and with a greater awareness of its potential and risks into corporate organisational arrangements and control systems will be one of the most significant indicators of the quality of corporate governance in the years to come.

     

    1>^ “Shadow AI” refers to the use of artificial intelligence systems or tools that are not authorised, inventoried or otherwise governed by the organisation. The expression derives from the concept of “shadow IT”, which refers to the use of IT applications, services or infrastructure outside the company’s approval and control processes.

    ADVANT Nctm steps up its focus on the digital economy: launch of the Digital, Tech and Data Department
    ADVANT Nctm is taking a further step forward in the digital economy with the…
    Read more
    Data breach notification: what changes with the EDPB common template
    On 10 June 2026, the European Data Protection Board (“EDPB”) adopted a draft…
    Read more
    GEMA v. Suno: a new european precedent on the relationship between generative AI and copyright
    The very recent judgment handed down by the Regional Court of Munich in the GEMA…
    Read more
    Online contracts and terms requiring specific approval: the Italian Supreme Court reconsiders an established practice
    By Order No. 20945 of 20 June 2026, the Third Civil Division of the Italian…
    Read more
    Chat Control: where does the UE proposal on combating children sexual abuse online stand?
    For more than four years, the European Union has been negotiating a proposal for…
    Read more
    EU KIDS Act: Brussels rewrites the rules for digital services for Minors
    On 17 September 2026, the European Commission presented its proposal for a…
    Read more
    THE RULES OF ARTIFICIAL INTELLIGENCE: FROM THE “PRIMACY” OF THE AI ACT TO MULTILEVEL FRAGMENTATION
    Until recently, the AI Act could present itself as “the world’s first regulatory…
    Read more
    ARTIFICIAL INTELLIGENCE: NEW CRIMINAL LAW IMPLICATIONS REGARDING CORPORATE LIABILITY UNDER ITALIAN LEGISLATIVE DECREE No. 231/2001
    On 15 September 2026, Legislative Decree No. 160 of 9 September 2026 (the…
    Read more