11 Aug 2026

AI Compliance for European Companies: From Regulations to GFT Solutions

From European AI regulations to practical solutions for ensuring compliance, security, and innovation in businesses.
gft-contact-mattia-gallegati.png
Mattia Gallegati
AI Solutions Leader
blogAbstractMinutes
blogAbstractTimeReading
genericImageAlt
AI
Regulations and Compliance
Blog
2026
contact
share
The AI Act, or EU Regulation 2024/1689, is the world’s first comprehensive legal framework governing the development, placing on the market, and use of artificial intelligence systems.

It is not a recommendation or a voluntary standard, but rather a binding law. The legislation marks a very important step in the regulator’s approach to the development of AI systems; however, it is important to be aware that the AI Act is legislation designed to govern a technology that is constantly evolving. Because of this, the legislation has yet to fully address some of the complexities introduced by generative artificial intelligence and, above all, by autonomous agentic systems—the true frontier of contemporary AI.

The recent Digital Omnibus legislative package, approved in June 2026, significantly altered the compliance timeline, postponing what had been imminent critical deadlines: stand-alone high-risk systems must comply by December 2, 2027, while those integrated into other regulated products have until August 2, 2028*.

This extension does not imply a setback in the compliance process; on the contrary, it represents a strategic opportunity. The best practices in governance, oversight, and transparency mandated by the AI Act are not temporary obligations, but risk management principles that remain relevant regardless of regulatory deadlines. Smart organizations will not view the Digital Omnibus as a delay in compliance, but rather as valuable time to implement stronger, more proactive governance.

1.1 General Scope of Application: Who Is Subject to the AI Act

The first thing to understand is that the regulation has a very broad scope and applies to various actors in the artificial intelligence value chain.

  • Suppliers and providers. Those who develop an AI system or model to bring it to market under their own name or brand. This includes both large tech companies and startups that distribute AI solutions.
  • Professional users or deployers. Companies , public administrations, and organizations that use AI systems as part of their professional activities. It does not matter whether they developed the AI internally or acquired it from a third party: they must still comply with the law’s requirements.
  • Importers and distributors. Entities that introduce AI systems developed elsewhere into the European Union market.

A crucial point: the European AI Act has extraterritorial reach. It also applies to companies established outside the EU if their AI systems or the outputs generated by those systems are used within the territory of the Union. Only purely personal uses and systems used exclusively for scientific research and development purposes are exempt.

What does this mean? For example, it means that a California-based startup that distributes a chatbot used by European companies, or a Japan-based cloud services provider that processes EU user data, are both subject to the AI Act.

1.2 The Basis of the Regulations: The 4 Levels of Risk

The regulatory framework is based on an approach that classifies the risk posed by AI systems into four categories, each of which is subject to progressively stricter requirements.

  1. Unacceptable risk, i.e., practices that are entirely prohibited. These systems are prohibited because they pose a clear and unacceptable threat to people’s rights and dignity. This category includes:
  • Social scoring systems (overall classification of citizens based on social behavior);
  • Subliminal manipulation techniques (messages perceived subconsciously to alter behavior or exploit vulnerable individuals);
  • Real-time remote biometric identification by law enforcement in public spaces (with rare exceptions for serious crimes);
  • Biometric classification based on sensitive data (AI that categorizes people by ethnicity, religion, or sexual orientation);
  • Emotion recognition in the workplace or at school.
  1. High risk. This includes systems used in critical sectors with high social impact, such as human resources (staff selection, promotion decisions), education (exam grading, determining access to educational programs), critical infrastructure, justice, and law enforcement. These systems are not prohibited, but they require complex governance that includes: rigorous ex ante assessment, continuous risk management systems, high-quality and unbiased training data, detailed technical documentation, mandatory human oversight, full traceability, and adequate cybersecurity measures. For example, an AI system that supports hiring decisions is high-risk; it must undergo stringent controls, document how it makes decisions, be regularly tested for bias based on gender, ethnicity, or other protected characteristics, and, finally, there must always be a person who supervises and can override the generated output.
  2. Limited risk. Applies primarily to systems such as chatbots, virtual assistants, and GenAI models. Risk governance here translates to transparency requirements: the user must be explicitly informed that they are interacting with a machine or that the content they are viewing or hearing has been artificially generated. A chatbot interacting with a bank’s customers must clearly state that it is not a human agent, just as a social media video featuring a CEO as a “digital avatar” explaining a business decision must be clearly labeled as artificial content.
  3. Minimal or no risk. This category includes most systems currently in use: spam filters, generative text AI, and simple recommendation systems. Use is unrestricted, and there are no specific regulatory obligations, although voluntary adherence to codes of ethics is recommended.

1.3 What Can Businesses Do to Adapt?

Companies are required to implement risk management measures, depending on their role in the value chain.

  • Suppliers must implement certifiable quality management systems, prepare and maintain detailed technical documentation, obtain CE conformity, and register high-risk systems in a European database managed by national authorities.
  • Users—that is, companies and organizations that acquire and use AI systems—are required to use AI in strict accordance with the supplier’s instructions, ensure effective human oversight, monitor operation and report anomalies, maintain logs of all interactions, and inform workers in advance. For public entities or private essential services—such as public services for citizens, banks, and healthcare—a“Fundamental Rights Impact Assessment” is also mandatory, documenting how the system might impact rights such as privacy, non-discrimination, and the right of access.
  • Training and literacy. All entities must implement training programs to promoteAI Culture among their staff. This, too, is not merely a recommendation but a genuine obligation. Developers and users must be able to recognize the limitations, biases, and risks of the technology they use.

1.4 How GFT Supports AI Compliance for Businesses

It is clear, therefore, that organizations today face a critical challenge: understanding how to map their AI systems, assess their risk profile in accordance with the EU AI Act, and implement the necessary controls and governance—all while maintaining their ability to innovate and the functionality of their processes and services.

AI governance cannot be a static exercise tied to a one-time compliance effort. It must be a dynamic, operational system that is continuously active and integrated into the company’s decision-making processes.

1.4.1 GOS (Governance Operating System): An Iterative System for Continuous Governance

This is the principle on which GFT developed GOS, or Governance Operating System, an end-to-end automated framework that overcomes the limitations of manual processes and static checklists.

GOS operates through three key components:

  1. a Governance Operating Model (GOM), which defines strategies, roles, and responsibilities;
  2. an Impact-to-Risk-to-Policy (IRP) Framework, which maps risks in accordance with ISO 42001 and the EU AI Act, automatically analyzes use cases, calculates impacts, and translates mitigation decisions into machine-readable rules;
  3. a Governance Operating Platform (GOP), which applies, controls, and monitors these rules across all company systems in real time.

GFT’s solution is modular to enable users to:

  • classify the AI Act risk level and identify the key articles triggered;
  • implement and control agents in production;
  • translate business rules into authorization/blocking decisions at runtime;
  • integrate monitoring and alerting, and automatically generate or validate the technical documentation required by the AI Act.

The results are measurable: based on use cases and real-world scenarios, we’ve estimated a 42% reduction in the time required to govern each use case, an infrastructure that’s always audit-ready, and the elimination of silos between technical, legal, compliance, and business teams. Above all, it ensures that compliance controls are applied at the exact moment AI interacts with data and decisions—thus providing “by design” governance, which is more effective than any ex post review.

Let’s clarify with Spagna exactly which components are software modules and which are the underlying approach and methodology, and let’s explain this clearly.

1.4.2 Smart Compliance and Contract Intelligence: Vertical Automation for Critical Workflows

As part of the (GOP) solution, GFT has developed two vertical agent-based solutions that automate the two most critical and time-consuming document workflows for compliance: the technical validation of AI dossiers and the analysis of supplier contracts.

  • Smart Compliance is a tool that automatically validates company documents against checklists and technical or regulatory requirements. Since one of the most critical aspects of the EU AI Act is the creation and maintenance of the technical dossier, Smart Compliance has been powered by a best-practice checklist to verify whether AI system documentation (AI Technical Dossier) is indeed complete, of high quality, and compliant prior to the deployment of the AI system, transforming a manual and error-prone process into a structured and repeatable verification.
  • Contract Intelligence is a framework based on Agentic AI that automates contract compliance, integrating the requirements of the AI Act and the DORA Regulation. It operates through three functionalities: Assessment and Governance (automated contract analysis and calculation of regulatory risk levels), Remediation (a dashboard that actively suggests action plans and remediation policies), and Explainability (transparent reconstruction of the reasons behind each finding). The results of a proof of concept in the banking sector demonstrated up to a 4-fold increase in operational productivity, savings of approximately 1,200 hours per year, and a 50% reduction in contract review time.

1.4.3 AI Governance Assessment Roadmap: A Thoughtful Approach to Compliance

Regulatory compliance, therefore, begins with awareness. Many companies have AI systems in production without true visibility into their level of risk, where the gaps lie, and what roadmap to follow to move forward strategically and securely.

GFT Italy has developed its own methodological framework to establish and measure the maturity of an AI governance framework by jointly evaluating six key macro-areas:

  1. Processes and Oversight, including the quality of the overall governance process, approval gates, and automation;
  2. Transparency and Ethics: explainability of AI systems, ethical frameworks, and reproducibility of results;
  3. Adoption and Impact: visibility and monitoring of the actual impact of systems;
  4. Traceability: quality of functional and technical traceability;
  5. Compliance, verifies the presence of key elements supporting compliance with regulations such as the AI Act, GDPR, and DORA, as well as international standards such as ISO 42001, ensuring structured and regulation-oriented governance;
  6. Training and Change Management: quality of training and maturity of human supervision.

This framework is not an academic exercise but serves as a strategic foundation to support the AI Governance Officer and corporate management, defining a realistic and progressive roadmap toward maturity and full compliance.

Ultimately, the law remains an important reference point but may not be sufficient in light of current technological challenges; this makes it all the more essential for companies to adopt an approach that goes beyond minimum compliance, anticipating regulatory gaps with sound internal practices.

In a regulatory landscape that is already complex and, at times, still incomplete, having a clear understanding of their starting point allows organizations to move forward with confidence, anticipating inevitable future regulatory updates and ensuring security and business continuity.

*Deadlines updated as of July 20, 2026

Got Questions? We’re Happy to Help.

gft-contact-mattia-gallegati.png

Mattia Gallegati

AI Solutions Leader
message
dataProtectionDeclaration