AI Governance and 231: how corporate responsibility is changing
Unsplash
Unsplash· 5 min read
Recent regulatory interventions at both national and European levels have progressively defined a framework aimed at guiding companies in the conscious management of AI, offering criteria and principles to steer its integration into organizational processes. While the structural and ubiquitous adoption of technology in production and decision-making dynamics is undeniable, the real challenge today is its governability; the paradigm shift necessary to produce a cultural and managerial evolution within organizations, capable of ensuring oversight, transparency, and traceability of algorithmic tools. Attention cannot be limited to formal compliance but must extend to the construction of governance structures consistent with the complexity of the ongoing transformation, emphasizing responsibility from a Business Ethics perspective, the quality of decisions, and the protection of stakeholders as central elements of corporate competitiveness and sustainability.
Law no. 132/2025, read in conjunction with Regulation (EU) 2024/1689 (AI Act), the Digital Omnibus Package, and Legislative Decree 231/2001, defines the regulatory framework within which to definitively move beyond compliance understood as formal fulfillment and inaugurate an era of substantial governability of automated processes. The use of artificial intelligence systems, once a neutral technological variable, becomes a structural factor of legal, social, and reputational risk that directly affects the company's organizational structure and the criteria for attributing corporate liability. This results in a profound transformation of the "231 Model," required to implement effective governance of algorithmic systems throughout their entire life cycle. In this context, the very notion of the "suitability" of the organizational model takes on a dynamic and technological character: a suitable model is one that allows for the understanding, monitoring, and directing of the use of artificial intelligence within the organization, integrating it into decision-making processes and control systems in a conscious manner. In this perspective, AI governance naturally intertwines with corporate sustainability and a renewed focus on business ethics, understood as a responsibility involving not only the company but the entire supply chain.
Law no. 132/2025 has outlined the national structure of AI governance, impacting the criminal system and providing a delegation for adapting legal categories to new technological risks. Simultaneously, the AI Act has introduced a regulatory model based on a risk-based approach, with graduated obligations and reinforced safeguards for high-risk systems, while the Digital Omnibus intervenes on the temporal and application coordination of these disciplines, influencing corporate compliance planning. The result is a multi-level regulatory framework that requires a systemic and integrated reading, as the various sources converge in defining new organizational standards and corporate responsibility.
In this context lies Art. 26 of Law 132/2025, which introduces a general aggravating circumstance for crimes committed through AI systems, as well as special aggravating circumstances for specific cases, including agiotage and market manipulation: an intervention that directly affects the area of "predicate offenses" under Legislative Decree 231/2001, potentially expanding their relevance whenever the illicit act is carried out or facilitated by algorithmic tools.
The use of AI can, in fact, interfere with cybercrimes, market abuse, money laundering offenses, copyright violations, as well as corporate, environmental, or crimes against the public administration, where the algorithm constitutes a means of execution or facilitation of the conduct. The resulting effect impacts the overall setup of the system: the area of crime-risk tends to expand, and the threshold of acceptable risk is recalibrated in light of the peculiar impact that the use of AI can exert in terms of greater social danger. Consequently, risk assessment under Legislative Decree 231/2001 is called to measure itself against this evolution, including a careful mapping of AI use cases and a precise evaluation of the risk profiles connected to their concrete implementation.
The AI Act discipline also intertwines with Art. 86, which recognizes—in relation to the high-risk AI systems listed in Annex III—a right to an explanation of individual decision-making processes for the individuals concerned. This entails the need for companies to establish structures suitable not only for preventing crimes but also for responding effectively to requests for transparency, inspections by competent authorities, and reporting obligations. The substantial governability of the algorithm is also measured by its ability to "account for" its decisions.
Furthermore, the structure outlined by the AI Act affects the configurability of the value chain by distinguishing roles and responsibilities among providers, deployers, importers, and distributors. This articulation involves a multi-level distribution of compliance obligations according to a logic of interdependence that makes risk management inherently network-based. The governability of AI thus assumes a systemic dimension achieved through the construction of a complex ecosystem of internal controls, protected reporting mechanisms, and safeguards along the supply chain.
Integrated compliance, therefore, is configured as a multi-level architecture: internal (231 model, reporting channels, audits), external (contractual relationships and supply chain controls), and institutional (interaction with national and European authorities). It is in this interaction that the difference between merely declared governance and the substantial governability of the algorithmic enterprise is measured.
In this perspective, the governability of AI also becomes a parameter for the adequacy of organizational structures under Art. 2086 of the Civil Code and for correct administration, imposing on management bodies the conscious and controlled integration of automated systems into decision-making processes. The lack of AI governance safeguards can, in fact, be relevant not only for the purposes of liability under Legislative Decree 231/2001 but also as an indicator of organizational fault and inadequacy of the structure, affecting the assessment of professional diligence and the overall sustainability of the enterprise.
The new regulatory framework requires considering AI governance not as a specialized segment of compliance, but as an organizing criterion for the entire system of corporate responsibility. The substantial governability of automated processes thus becomes a qualifying parameter for the adequacy of the 231 model, an index of the solidity of organizational structures, and the credibility of the ESG strategy.
This article is also published on SDA Bocconi Insight, in Italian. illuminem Voices is a democratic space presenting the thoughts and opinions of leading Sustainability & Energy writers, their opinions do not necessarily represent those of illuminem.
illuminem briefings

AI · Corporate Governance
Andrea Bonime-Blanc

Green Tech · AI
illuminem briefings

Power Grid · AI
The Wall Street Journal

AI · Ethical Governance
The Washington Post

AI · Public Governance
energynews

Green Tech · Sustainable Business