{"id":11459,"date":"2026-09-25T15:51:04","date_gmt":"2026-09-25T13:51:04","guid":{"rendered":"https:\/\/www.htt.it\/?p=11459"},"modified":"2026-09-25T18:47:10","modified_gmt":"2026-09-25T16:47:10","slug":"ai-governance-digital-agency-eu-ai-act","status":"publish","type":"post","link":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/","title":{"rendered":"AI Governance in in the agency"},"content":{"rendered":"\n\n<!-- SECTION -->\n<section  class=\"   whitesection\" style=\"\">\n    <div class=\"testo-colonna-centrale htt-generic-text\">\n        <div class=\"htt-container\">\n            <article class=\"htt-magazine-article htt-ai-governance\"\n         aria-labelledby=\"ai-governance-title\"><\/p>\n<header class=\"htt-article-header\">\n<p class=\"htt-eyebrow\">AI Governance &amp; Security<\/p>\n<h1 id=\"ai-governance-title\">\nAI Governance in Digital Agencies: Policies, AI Literacy and Controls under the EU AI Act<br \/>\n<\/h1>\n<p class=\"htt-article-lead\">\nArtificial intelligence is now part of everyday workflows in marketing, software development, data analysis and content production. For companies choosing a digital partner, however, the question should no longer be simply <strong>\u201cDoes our agency use AI?\u201d<\/strong>, but rather <strong>\u201cHow does it use AI, what happens to our data and what controls are in place?\u201d<\/strong>\n<\/p>\n<\/header>\n<figure class=\"htt-article-hero\">\n<p><img loading=\"lazy\" decoding=\"async\"\n src=\"https:\/\/www.htt.it\/wp-content\/uploads\/2026\/09\/Sgai_eu_act_ai_htt-1024x572.webp\"\n alt=\"AI Governance at HT&amp;T: EU AI Act, data protection, AI literacy and human oversight\"\n width=\"1024\"\n height=\"572\"\n class=\"aligncenter size-large wp-image-11450\"\n\/><figcaption>\nAI Governance combines policies, data protection, staff training, risk management and human oversight.<br \/>\n<\/figcaption><\/figure>\n<div class=\"htt-answer-box\"\n     role=\"note\"\n     aria-label=\"Article summary\"><\/p>\n<p><strong>In brief<\/strong><\/p>\n<ul>\n<li>Under <strong>Article 4 of the EU AI Act<\/strong>, providers and deployers of AI systems must take measures to support the development of AI literacy among staff and other people operating AI systems on their behalf.<\/li>\n<li>The <strong>2026 Digital Omnibus on AI<\/strong> confirmed this obligation while clarifying that organisations are not required to guarantee a specific level of AI literacy for every individual.<\/li>\n<li><strong>AI Governance<\/strong> turns legal, security and organisational requirements into practical rules: approved tools, permitted data, role-based training, human oversight and incident management.<\/li>\n<li>One of the most common organisational risks is <strong>Shadow AI<\/strong>: employees using unauthorised AI tools or approved tools in ways that expose confidential or client information.<\/li>\n<li>For companies selecting a digital partner, AI governance is becoming an additional indicator of organisational maturity, alongside cybersecurity, quality management and data protection.<\/li>\n<\/ul>\n<\/div>\n<section aria-labelledby=\"agency-ai-data\">\n<h2 id=\"agency-ai-data\">Do you know what happens to your data when your agency uses AI?<\/h2>\n<p>\nChatGPT, Claude, Gemini, Copilot and other AI-based systems have rapidly become part of professional workflows.\n<\/p>\n<p>\nIn 2026, it would probably be more unusual to find a digital agency that does not use artificial intelligence than one that uses it every day.\n<\/p>\n<p>\nThe real issue is therefore no longer <strong>whether an agency uses AI<\/strong>.\n<\/p>\n<p>\nCompanies should ask a different set of questions before entrusting a partner with their data, platforms, campaigns, source code or business information.\n<\/p>\n<div class=\"htt-highlight-box\"\n     role=\"note\"\n     aria-label=\"Key AI governance question\"><\/p>\n<p>\n<strong>What information is entered into AI systems, which tools are approved, who checks the outputs and who remains accountable for the final work?<\/strong>\n<\/p>\n<\/div>\n<p>\nUncontrolled use of AI can introduce risks involving data protection, confidential information, intellectual property, inaccurate outputs, model hallucinations, cybersecurity and regulatory compliance.\n<\/p>\n<p>\nAt HT&amp;T Consulting, we therefore chose to treat artificial intelligence not simply as another productivity tool, but as a <strong>governance issue<\/strong>.\n<\/p>\n<p>\nWe have implemented an internal <strong>AI Management System and AI Governance framework<\/strong> covering policies, responsibilities, risk assessment, authorised tools, human oversight and a formal AI literacy programme.\n<\/p>\n<\/section>\n<section aria-labelledby=\"what-ai-governance\">\n<h2 id=\"what-ai-governance\">What is AI Governance?<\/h2>\n<div class=\"htt-answer-box\"\n     role=\"note\"\n     aria-label=\"Definition of AI Governance\"><\/p>\n<p>\n<strong>AI Governance is the set of policies, responsibilities, processes and controls an organisation uses to manage the use of artificial intelligence.<\/strong>\n<\/p>\n<p>\nFor a digital agency, this includes deciding which AI tools may be used, what information may be processed, how new systems and vendors are assessed, how employees are trained, which outputs require human review and how incidents or inappropriate uses are handled.\n<\/p>\n<\/div>\n<p>\nThis approach is consistent with the broader concept of an Artificial Intelligence Management System.\n<\/p>\n<p>\nThe international standard <strong>ISO\/IEC 42001<\/strong>, for example, specifies requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System within an organisation.\n<\/p>\n<div class=\"htt-highlight-box\"\n     role=\"note\"\n     aria-label=\"Clarification about ISO IEC 42001\"><\/p>\n<p>\n<strong>Implementing an internal AI Management System does not automatically mean being ISO\/IEC 42001 certified.<\/strong>\n<\/p>\n<p>\nCertification is a separate assessment and certification process. The underlying management principle, however, is relevant to any organisation: AI should be governed as a business process rather than treated as an uncontrolled collection of tools.\n<\/p>\n<\/div>\n<\/section>\n<section aria-labelledby=\"shadow-ai\">\n<h2 id=\"shadow-ai\">Shadow AI: one of the hidden risks inside organisations<\/h2>\n<p>\nOne of the most underestimated risks for companies is <strong>Shadow AI<\/strong>: the use of AI services outside approved corporate policies, processes or technology environments.\n<\/p>\n<p>\nFor example, an employee might upload a client document to a free AI service, paste proprietary source code into a chatbot, analyse CRM data using an unapproved platform or share information covered by a confidentiality agreement.\n<\/p>\n<p>\nThe problem is not necessarily the technology itself.\n<\/p>\n<p>\nThe problem is <strong>using technology without clear rules defining what may be done with it and which information may be processed<\/strong>.\n<\/p>\n<p>\nAI Governance should therefore begin with a clear classification of tools, environments, use cases and information.\n<\/p>\n<\/section>\n<section aria-labelledby=\"ai-tool-classification\">\n<h2 id=\"ai-tool-classification\">A practical AI tool classification model<\/h2>\n<p>\nHT&amp;T&#8217;s internal policy classifies AI environments according to the level of organisational control, the characteristics of the service and the type of data that may be processed.\n<\/p>\n<div class=\"htt-governance-grid\"\n     role=\"list\"\n     aria-label=\"AI tool classification\"><\/p>\n<article class=\"htt-governance-card htt-governance-card--green\"\n         role=\"listitem\"><\/p>\n<h3>Class A: Managed business environments<\/h3>\n<p>\nTools and business licences selected for professional use and configured according to corporate policies.\n<\/p>\n<p>\nThese environments are preferred for operational activities requiring higher levels of control, subject to the specific terms of the service and internal information-handling rules.\n<\/p>\n<\/article>\n<article class=\"htt-governance-card htt-governance-card--yellow\"\n         role=\"listitem\"><\/p>\n<h3>Class B: Approved public tools<\/h3>\n<p>\nThese tools may only be used for activities compatible with their risk classification.\n<\/p>\n<p>\nPersonal data, credentials, proprietary code, confidential client information or documents covered by NDAs must not be entered where the relevant service conditions or internal policies do not allow it.\n<\/p>\n<\/article>\n<article class=\"htt-governance-card htt-governance-card--red\"\n         role=\"listitem\"><\/p>\n<h3>Class C: Unapproved tools<\/h3>\n<p>\nThese tools cannot be used for business operations until the appropriate assessment has been completed.\n<\/p>\n<p>\nIntroducing a new AI service is therefore not simply a matter of individual preference: it requires an organisational evaluation.\n<\/p>\n<\/article>\n<\/div>\n<p>\nThe goal is not to prevent employees from using artificial intelligence.\n<\/p>\n<p>\n<strong>AI Governance creates the conditions that allow organisations to use AI more confidently and consistently.<\/strong>\n<\/p>\n<\/section>\n<section aria-labelledby=\"ai-literacy\">\n<h2 id=\"ai-literacy\">AI Literacy: knowing how to use ChatGPT is not enough<\/h2>\n<p>\n<strong>Article 4 of the EU AI Act<\/strong> introduces an important requirement for organisations that provide or deploy AI systems.\n<\/p>\n<p>\nProviders and deployers must take measures to support the development of AI literacy among their staff and other people dealing with the operation and use of AI systems on their behalf.\n<\/p>\n<p>\nThose measures should take into account factors such as technical knowledge, experience, education, training and the context in which AI systems are used.\n<\/p>\n<p>\nArticle 4 has applied since <strong>2 February 2025<\/strong>, while national market surveillance authorities are responsible for supervision and enforcement under the applicable enforcement framework.\n<\/p>\n<div class=\"htt-highlight-box\"\n     role=\"note\"\n     aria-label=\"Changes introduced by the Digital Omnibus on AI\"><\/p>\n<p><strong>What changed with the 2026 Digital Omnibus on AI?<\/strong><\/p>\n<p>\nRegulation (EU) 2026\/1744 amended Article 4 while preserving AI literacy as an obligation for providers and deployers.\n<\/p>\n<p>\nThe revised wording clarifies an important point: organisations must take measures to support AI literacy, but they are <strong>not required to guarantee a specific level of AI literacy for each individual employee<\/strong>.\n<\/p>\n<p>\nIn practical terms, organisations need an approach appropriate to their people, AI systems, activities and risks.\n<\/p>\n<\/div>\n<div class=\"htt-highlight-box\"\n     role=\"note\"\n     aria-label=\"Role based AI training principle\"><\/p>\n<p>\n<strong>A marketer, project manager, software developer and governance officer do not need the same AI training.<\/strong>\n<\/p>\n<\/div>\n<p>\nFor this reason, HT&amp;T has implemented a role-based AI literacy programme covering different levels of knowledge and operational responsibility.\n<\/p>\n<div class=\"htt-levels\"\n     role=\"list\"\n     aria-label=\"HT&#038;T AI literacy levels\"><\/p>\n<div class=\"htt-level\" role=\"listitem\">\n<h3>AI-1 \u2014 Foundation<\/h3>\n<p>\nCore AI principles, privacy, security, compliance, responsible use, key risks and internal company rules.\n<\/p>\n<\/div>\n<div class=\"htt-level\" role=\"listitem\">\n<h3>AI-2 \u2014 Operational<\/h3>\n<p>\nProfessional use of generative AI, prompting techniques, output validation, hallucination management, fact-checking and applications in marketing, communication and project management.\n<\/p>\n<\/div>\n<div class=\"htt-level\" role=\"listitem\">\n<h3>AI-3 \u2014 Advanced<\/h3>\n<p>\nAPI integrations, automation, Retrieval-Augmented Generation, AI agents, interoperability protocols, software development and security considerations related to AI systems.\n<\/p>\n<\/div>\n<div class=\"htt-level\" role=\"listitem\">\n<h3>AI-4 \u2014 Governance<\/h3>\n<p>\nRisk assessment, vendor assessment, internal audits, oversight, incident management, policy updates and continuous monitoring of the AI governance framework.\n<\/p>\n<\/div>\n<\/div>\n<p>\nFor a broader overview of the regulatory framework, transparency requirements and implementation deadlines, read our guide to the <a href=\"https:\/\/www.htt.it\/en\/eu-ai-act-business-chatbots-ai-generated-content\/\">EU AI Act for businesses, chatbots and AI-generated content<\/a>.\n<\/p>\n<\/section>\n<section aria-labelledby=\"italian-context\">\n<h2 id=\"italian-context\">A note on the Italian regulatory context<\/h2>\n<p>\nHT&amp;T is an Italian company operating within both the European and Italian regulatory frameworks.\n<\/p>\n<p>\nItaly&#8217;s <strong>Law No. 132 of 23 September 2025<\/strong> introduced national provisions concerning artificial intelligence.\n<\/p>\n<p>\nAmong other measures, Article 13 addresses the use of AI in intellectual professions and requires professionals to provide clients with clear, simple and comprehensive information concerning the AI systems used in the professional activity.\n<\/p>\n<p>\nFor international clients, the broader lesson is relevant beyond Italy: <strong>transparency about how AI is used is increasingly becoming part of the trust relationship between companies and their professional partners.<\/strong>\n<\/p>\n<\/section>\n<section aria-labelledby=\"human-oversight\">\n<h2 id=\"human-oversight\">Human Oversight: AI can assist, but accountability remains human<\/h2>\n<p>\nOne of the principles of our AI Governance framework is that artificial intelligence does not automatically replace professional responsibility.\n<\/p>\n<p>\nA generative model can accelerate research, suggest copy, support software development, identify patterns or process large volumes of information.\n<\/p>\n<p>\nThat does not mean its output should automatically be treated as correct.\n<\/p>\n<div class=\"htt-quote-box\"\n     role=\"note\"\n     aria-label=\"Human oversight principle\"><\/p>\n<p>\n<strong>An AI output is an input for a professional. It is not a transfer of accountability.<\/strong>\n<\/p>\n<\/div>\n<p>\nDepending on the activity, HT&amp;T therefore applies human review processes such as editorial review, fact-checking, code review, data validation or approval by the person responsible for the project.\n<\/p>\n<p>\nThis becomes particularly important when AI-assisted outputs are delivered to clients or published externally.\n<\/p>\n<\/section>\n<section aria-labelledby=\"ai-transparency\">\n<h2 id=\"ai-transparency\">Transparency, AI-generated content and Article 50<\/h2>\n<p>\n<strong>Article 50 of the EU AI Act<\/strong> establishes transparency requirements for specific AI systems and use cases.\n<\/p>\n<p>\nThese include requirements concerning certain AI-generated or manipulated outputs, interactions with AI systems, deepfakes and specific content intended to inform the public.\n<\/p>\n<p>\nThis does not mean that every piece of content created with AI assistance must carry the same label in every situation.\n<\/p>\n<p>\nRequirements depend on the role of the organisation, the type of AI system, the type of content and how it is used.\n<\/p>\n<p>\nFor some text published to inform the public, the regulatory framework also considers situations in which content undergoes human review or editorial control and a natural or legal person retains editorial responsibility.\n<\/p>\n<p>\nAt the same time, technologies such as <strong>C2PA and Content Credentials<\/strong> are helping create a technical infrastructure through which the origin and modification history of digital content can be made verifiable.\n<\/p>\n<p>\nWe explored this topic in greater detail in our guide to <a href=\"https:\/\/www.htt.it\/en\/c2pa-content-credentials\/\">C2PA and Content Credentials<br \/>\n<\/a>, including how provenance metadata, digital signatures and emerging durable credentials can help make the origin of digital content more verifiable.\n<\/p>\n<\/section>\n<section aria-labelledby=\"integrated-governance\">\n<h2 id=\"integrated-governance\">AI Governance should not operate separately from information security<\/h2>\n<p>\nAn AI Management System is useful only if it is connected to the rest of the organisation.\n<\/p>\n<p>\nAI Governance should interact with existing processes for information security, access control, vendor management, employee training, incident management, business continuity, quality management and data protection.\n<\/p>\n<p>\nAt HT&amp;T, the AI Governance framework builds on an established certified management environment that includes <strong>ISO 9001<\/strong> for quality management, <strong>ISO\/IEC 27001<\/strong> for information security, <strong>ISO\/IEC 27017<\/strong> and <strong>ISO\/IEC 27018<\/strong> for cloud security and protection of personal information in cloud environments, together with other organisational governance standards.\n<\/p>\n<p>\nWe explain this organisational model in more detail in our overview of <a href=\"https:\/\/www.htt.it\/en\/iso-9001-27001-uni-pdr-125-certified-digital-agency\/\">HT&amp;T as an ISO-certified digital agency<br \/>\n<\/a>, where we describe how quality management, information security and organisational governance work together.\n<\/p>\n<p>\nThe principle is straightforward: <strong>AI governance should become part of the organisation&#8217;s existing system of controls rather than another isolated policy document.<\/strong>\n<\/p>\n<\/section>\n<section aria-labelledby=\"choose-ai-agency\">\n<h2 id=\"choose-ai-agency\">How can you tell whether a digital agency uses AI safely?<\/h2>\n<p>\nWhen selecting a digital agency or technology partner, companies increasingly need to assess how that supplier uses artificial intelligence.\n<\/p>\n<p>\nAsking <strong>\u201cDo you use AI?\u201d<\/strong> tells you very little.\n<\/p>\n<p>\nMore useful questions include:\n<\/p>\n<div class=\"htt-checklist-box\"\n     role=\"region\"\n     aria-labelledby=\"agency-checklist-title\"><\/p>\n<h3 id=\"agency-checklist-title\">AI Governance checklist for evaluating a digital partner<\/h3>\n<ul>\n<li>Does the agency have a formal AI policy?<\/li>\n<li>Are AI tools assessed and approved before employees use them?<\/li>\n<li>Are there clear rules defining which categories of data may or may not be processed by AI systems?<\/li>\n<li>Is there a process for evaluating new AI vendors and services?<\/li>\n<li>Does the agency provide formal AI literacy training?<\/li>\n<li>Is training adapted to different roles and risk levels?<\/li>\n<li>Are AI-generated outputs reviewed by people where appropriate?<\/li>\n<li>Are there procedures for reporting and managing AI-related incidents or inappropriate use?<\/li>\n<li>Are responsibilities for AI use clearly assigned?<\/li>\n<li>Are AI governance, privacy, cybersecurity and information security managed together?<\/li>\n<\/ul>\n<\/div>\n<p>\nA mature digital supplier should be able to answer these questions clearly rather than simply stating that it uses \u201centerprise AI\u201d or \u201csecure AI tools\u201d.\n<\/p>\n<\/section>\n<section aria-labelledby=\"client-benefits\">\n<h2 id=\"client-benefits\">What does AI Governance actually change for the client?<\/h2>\n<p>\nAn AI Management System should not exist merely to create policies and documentation.\n<\/p>\n<p>\nIt should change the way work is carried out.\n<\/p>\n<div class=\"htt-process-box\"\n     role=\"img\"\n     aria-label=\"HT&#038;T process: controlled data, controlled tools, verified outputs and human accountability\"><\/p>\n<p>\n<strong>Controlled Data \u2192 Controlled Tools \u2192 Verified Outputs \u2192 Human Accountability<\/strong>\n<\/p>\n<\/div>\n<h3>Greater control over client information<\/h3>\n<p>\nEmployees know which information may be used in different AI environments and which data requires additional protection or must not be transferred to external services.\n<\/p>\n<h3>Lower Shadow AI risk<\/h3>\n<p>\nThe adoption of new AI tools is governed by the organisation rather than left entirely to individual decisions.\n<\/p>\n<h3>More reliable outputs<\/h3>\n<p>\nValidation, fact-checking and human oversight reduce the risk of incorrect generative outputs reaching clients or being published.\n<\/p>\n<h3>Clear accountability<\/h3>\n<p>\nAI supports professional work without removing responsibility from the people and organisations delivering the service.\n<\/p>\n<h3>Better traceability<\/h3>\n<p>\nPolicies, assessments, training records and operating procedures make it easier to understand how AI is being used across the organisation.\n<\/p>\n<\/section>\n<section aria-labelledby=\"governance-innovation\">\n<h2 id=\"governance-innovation\">Good AI Governance makes it easier to use AI well<\/h2>\n<p>\nPolicies, approvals and controls may appear to make artificial intelligence harder to use.\n<\/p>\n<p>\nIn practice, the opposite can happen.\n<\/p>\n<p>\nWithout rules, organisations often move between two extremes: allowing employees to use almost any AI service without oversight or blocking AI because the risks appear too difficult to manage.\n<\/p>\n<p>\nA structured governance framework creates an environment in which experimentation and innovation can take place with clearer boundaries.\n<\/p>\n<div class=\"htt-highlight-box\"\n     role=\"note\"\n     aria-label=\"AI governance and innovation principle\"><\/p>\n<p>\n<strong>Governing AI does not necessarily mean using it less. It means being able to use it more deliberately because the organisation understands the boundaries.<\/strong>\n<\/p>\n<\/div>\n<\/section>\n<section aria-labelledby=\"conclusion\">\n<h2 id=\"conclusion\">When choosing a digital partner, ask how they govern AI<\/h2>\n<p>\nArtificial intelligence can improve productivity, accelerate analysis and support innovation.\n<\/p>\n<p>\nTechnology alone, however, tells you very little about the quality of the process behind its use.\n<\/p>\n<p>\nA company entrusting a partner with data, digital platforms, source code, advertising campaigns, analytics, content and strategy should therefore also consider that partner&#8217;s <strong>maturity in the use of artificial intelligence<\/strong>.\n<\/p>\n<p>\nIt is not enough to know which AI tools the agency uses.\n<\/p>\n<p>\nCompanies should understand <strong>what information can be processed, which controls are applied, how employees are trained, how new systems are assessed and who remains accountable for the outputs<\/strong>.\n<\/p>\n<p>\nThat is the principle we have applied at HT&amp;T Consulting: using artificial intelligence as an amplifier of professional expertise while maintaining governance, security and human oversight.\n<\/p>\n<p>\nYou can also learn more about <a href=\"https:\/\/www.htt.it\/en\/agency\/\">HT&amp;T Consulting&#8217;s approach to digital strategy, data, performance and certified project governance<\/a>.\n<\/p>\n<div class=\"htt-cta-box\"\n     role=\"region\"\n     aria-labelledby=\"cta-ai-title\"><\/p>\n<h2 id=\"cta-ai-title\">Looking for a digital agency with structured processes and strong data protection practices?<\/h2>\n<p>\nHT&amp;T supports companies across digital development, ecommerce, performance marketing, data, automation and artificial intelligence.\n<\/p>\n<p>\nOur approach combines innovation with information security, governance and human accountability, helping organisations build digital projects that are consistent with their goals, data and risk profile.\n<\/p>\n<p>\n<a class=\"htt-button\"\n   href=\"https:\/\/www.htt.it\/en\/contact\/\"\n   aria-label=\"Contact HT&#038;T Consulting about digital projects, AI governance and secure AI adoption\">Talk to HT&amp;T<\/a>\n<\/p>\n<\/div>\n<\/section>\n<section aria-labelledby=\"faq-ai-governance\">\n<h2 id=\"faq-ai-governance\">Frequently asked questions about AI Governance<\/h2>\n<div class=\"htt-faq\">\n<details class=\"htt-faq-item\">\n<summary>What is an AI Management System?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nAn AI Management System is a structured set of policies, responsibilities, processes and controls used by an organisation to govern the introduction and use of artificial intelligence. It can cover AI inventories, risk assessment, staff training, human oversight, vendor management and incident procedures.\n<\/p>\n<\/div>\n<\/details>\n<details class=\"htt-faq-item\">\n<summary>Does the EU AI Act require companies to provide AI training?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nArticle 4 of the EU AI Act requires providers and deployers of AI systems to take measures to support the development of AI literacy among staff and other people operating or using AI systems on their behalf. Measures should take account of technical knowledge, experience, education, training and the context in which the systems are used.\n<\/p>\n<\/div>\n<\/details>\n<details class=\"htt-faq-item\">\n<summary>Does every company need an AI policy?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nThe EU AI Act does not simply state that every company must create a document called an \u201cAI Policy\u201d. However, organisations using AI need practical measures to manage obligations, risks, responsibilities and AI literacy. A formal AI policy can be an effective way to define approved tools, permitted data, responsibilities, training requirements, human review and incident procedures.\n<\/p>\n<\/div>\n<\/details>\n<details class=\"htt-faq-item\">\n<summary>What changed with the 2026 Digital Omnibus on AI?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nRegulation (EU) 2026\/1744 amended several parts of the AI Act. Regarding AI literacy, it maintained the obligation for providers and deployers to take measures supporting AI literacy while clarifying that they are not required to guarantee a specific level of AI literacy for each individual.\n<\/p>\n<\/div>\n<\/details>\n<details class=\"htt-faq-item\">\n<summary>Are an internal AI Management System and ISO\/IEC 42001 certification the same thing?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nNo. An organisation may establish its own AI Management System or governance framework. ISO\/IEC 42001 is an international standard specifying requirements for an Artificial Intelligence Management System. Certification against ISO\/IEC 42001 is a separate formal assessment and certification process.\n<\/p>\n<\/div>\n<\/details>\n<details class=\"htt-faq-item\">\n<summary>Can a digital agency enter client data into ChatGPT or other AI tools?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nThere is no single answer that applies to every tool, account configuration or category of data. Organisations must consider the information involved, service terms, account settings, contractual obligations, data protection requirements and internal policies. This is why a mature AI governance framework defines which environments may be used and which categories of information are permitted.\n<\/p>\n<\/div>\n<\/details>\n<details class=\"htt-faq-item\">\n<summary>What is Shadow AI?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nShadow AI is the use of artificial intelligence tools or services outside an organisation&#8217;s approved processes, systems or policies. It can increase the risk of confidential information, personal data, intellectual property or proprietary code being handled inappropriately.\n<\/p>\n<\/div>\n<\/details>\n<details class=\"htt-faq-item\">\n<summary>How should a company evaluate a digital agency&#8217;s use of AI?<\/summary>\n<div class=\"htt-faq-content\">\n<p>\nUseful indicators include formal AI policies, approved-tool processes, data-handling rules, vendor assessment, role-based AI literacy programmes, human oversight, incident management and integration between AI governance, privacy and information security. Relevant information-security certifications can provide additional evidence of organisational maturity.\n<\/p>\n<\/div>\n<\/details>\n<\/div>\n<\/section>\n<section class=\"htt-sources\"\n         aria-labelledby=\"sources-title\"><\/p>\n<h2 id=\"sources-title\">Official sources and further reading<\/h2>\n<div class=\"htt-sources-grid\">\n<article class=\"htt-source-card\">\n<h3>European Artificial Intelligence Act<\/h3>\n<p>\nOfficial text of Regulation (EU) 2024\/1689 laying down harmonised rules on artificial intelligence.\n<\/p>\n<p>\n<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/1689\/oj\"\n   target=\"_blank\"\n   rel=\"noopener noreferrer\"><br \/>\nRead the EU AI Act on EUR-Lex<br \/>\n<\/a>\n<\/p>\n<\/article>\n<article class=\"htt-source-card\">\n<h3>European Commission \u2014 AI Literacy<\/h3>\n<p>\nEuropean Commission guidance and information on AI literacy requirements under Article 4 of the AI Act.\n<\/p>\n<p>\n<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/ai-talent-skills-and-literacy\"\n   target=\"_blank\"\n   rel=\"noopener noreferrer\"><br \/>\nRead the European Commission guidance<br \/>\n<\/a>\n<\/p>\n<\/article>\n<article class=\"htt-source-card\">\n<h3>Digital Omnibus on AI<\/h3>\n<p>\nRegulation (EU) 2026\/1744 amending parts of the EU AI Act, including Article 4 on AI literacy.\n<\/p>\n<p>\n<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2026\/1744\/oj\"\n   target=\"_blank\"\n   rel=\"noopener noreferrer\"><br \/>\nRead Regulation (EU) 2026\/1744<br \/>\n<\/a>\n<\/p>\n<\/article>\n<article class=\"htt-source-card\">\n<h3>ISO\/IEC 42001<\/h3>\n<p>\nInternational standard specifying requirements for establishing, implementing, maintaining and continually improving an Artificial Intelligence Management System.\n<\/p>\n<p>\n<a href=\"https:\/\/www.iso.org\/standard\/81230.html\"\n   target=\"_blank\"\n   rel=\"noopener noreferrer\"><br \/>\nExplore ISO\/IEC 42001<br \/>\n<\/a>\n<\/p>\n<\/article>\n<article class=\"htt-source-card\">\n<h3>Italian Law No. 132\/2025<\/h3>\n<p>\nItalian national provisions concerning artificial intelligence, relevant to HT&amp;T&#8217;s domestic regulatory environment.\n<\/p>\n<p>\n<a href=\"https:\/\/www.gazzettaufficiale.it\/eli\/id\/2025\/09\/25\/25G00143\/sg\"\n   target=\"_blank\"\n   rel=\"noopener noreferrer\"><br \/>\nRead the law in the Italian Official Gazette<br \/>\n<\/a>\n<\/p>\n<\/article>\n<\/div>\n<\/section>\n<section class=\"htt-related-content\"\n         aria-labelledby=\"htt-further-reading-title\"><\/p>\n<h2 id=\"htt-further-reading-title\">Further reading from HT&amp;T Magazine<\/h2>\n<div class=\"htt-sources-grid\">\n<article class=\"htt-source-card\">\n<h3>EU AI Act: What Changes for Businesses, Chatbots and AI Content<\/h3>\n<p>\nA practical guide to the European AI Act, including transparency requirements, AI-generated content, chatbot obligations and implementation deadlines.\n<\/p>\n<p>\n<a href=\"https:\/\/www.htt.it\/en\/eu-ai-act-business-chatbots-ai-generated-content\/\"><br \/>\nRead our EU AI Act guide<br \/>\n<\/a>\n<\/p>\n<\/article>\n<article class=\"htt-source-card\">\n<h3>C2PA and Content Credentials: How They Will Change the Web<\/h3>\n<p>\nHow Content Credentials, signed provenance information and emerging technical standards can help make the origin and modification history of digital content more verifiable.\n<\/p>\n<p>\n<a href=\"https:\/\/www.htt.it\/en\/c2pa-content-credentials\/\"><br \/>\nExplore C2PA and Content Credentials<br \/>\n<\/a>\n<\/p>\n<\/article>\n<article class=\"htt-source-card\">\n<h3>HT&amp;T Consulting: Certified Excellence<\/h3>\n<p>\nHow HT&amp;T integrates quality management, information security and organisational governance through ISO 9001, ISO\/IEC 27001 and related certifications.\n<\/p>\n<p>\n<a href=\"https:\/\/www.htt.it\/en\/iso-9001-27001-uni-pdr-125-certified-digital-agency\/\"><br \/>\nDiscover HT&amp;T&#8217;s certified governance model<br \/>\n<\/a>\n<\/p>\n<\/article>\n<\/div>\n<\/section>\n<\/article>\n        <\/div>\n    <\/div>\n<\/section>\n\n\n\n<style data-wp-block-html=\"css\">\n\/* =========================================================\n   HT&T MAGAZINE - AI GOVERNANCE\n   ========================================================= *\/\n\n.htt-ai-governance {\n  --htt-bg: #ffffff;\n  --htt-bg-soft: #f6f8fb;\n  --htt-bg-accent: #eef4ff;\n  --htt-text: #1b2430;\n  --htt-text-soft: #5d6875;\n  --htt-border: #dfe5ec;\n  --htt-primary: #1f5eff;\n  --htt-primary-dark: #143ea8;\n  --htt-green: #1d7a46;\n  --htt-green-bg: #eef9f3;\n  --htt-yellow: #8a6412;\n  --htt-yellow-bg: #fff8df;\n  --htt-red: #9d3535;\n  --htt-red-bg: #fff0f0;\n  --htt-radius: 18px;\n  --htt-radius-sm: 12px;\n  --htt-shadow: 0 14px 38px rgba(19, 31, 51, 0.07);\n\n  color: var(--htt-text);\n  line-height: 1.75;\n}\n\n\n\/* =========================================================\n   HEADER\n   ========================================================= *\/\n\n.htt-ai-governance .htt-article-header {\n  margin-bottom: 3rem;\n}\n\n.htt-ai-governance .htt-eyebrow {\n  display: inline-block;\n  margin: 0 0 1rem;\n  padding: 0.45rem 0.8rem;\n  border-radius: 999px;\n  background: var(--htt-bg-accent);\n  color: var(--htt-primary-dark);\n  font-size: 0.82rem;\n  font-weight: 700;\n  letter-spacing: 0.05em;\n  text-transform: uppercase;\n}\n\n.htt-ai-governance .htt-article-header h1 {\n  margin: 0 0 1.25rem;\n  font-size: clamp(2rem, 4vw, 3.8rem);\n  line-height: 1.08;\n  letter-spacing: -0.035em;\n}\n\n.htt-ai-governance .htt-article-lead {\n  max-width: 980px;\n  margin: 0;\n  font-size: clamp(1.08rem, 2vw, 1.32rem);\n  line-height: 1.65;\n  color: var(--htt-text-soft);\n}\n\n\n\/* =========================================================\n   TYPOGRAPHY\n   ========================================================= *\/\n\n.htt-ai-governance section {\n  margin: 4.5rem 0;\n}\n\n.htt-ai-governance h2 {\n  margin: 0 0 1.35rem;\n  font-size: clamp(1.65rem, 3vw, 2.45rem);\n  line-height: 1.15;\n  letter-spacing: -0.025em;\n}\n\n.htt-ai-governance h3 {\n  margin: 0 0 0.75rem;\n  font-size: 1.22rem;\n  line-height: 1.3;\n}\n\n.htt-ai-governance p {\n  margin: 0 0 1.25rem;\n}\n\n.htt-ai-governance a {\n  color: var(--htt-primary);\n  text-decoration-thickness: 1px;\n  text-underline-offset: 3px;\n  transition: color 0.2s ease;\n}\n\n.htt-ai-governance a:hover,\n.htt-ai-governance a:focus-visible {\n  color: var(--htt-primary-dark);\n}\n\n.htt-ai-governance a:focus-visible,\n.htt-ai-governance summary:focus-visible {\n  outline: 3px solid rgba(31, 94, 255, 0.28);\n  outline-offset: 4px;\n}\n\n\n\/* =========================================================\n   GENERIC BOXES\n   ========================================================= *\/\n\n.htt-ai-governance .htt-highlight-box,\n.htt-ai-governance .htt-answer-box,\n.htt-ai-governance .htt-quote-box,\n.htt-ai-governance .htt-process-box {\n  margin: 2rem 0;\n  padding: 1.6rem 1.8rem;\n  border-radius: var(--htt-radius);\n}\n\n.htt-ai-governance .htt-highlight-box {\n  border: 1px solid #cfe0ff;\n  background:\n    linear-gradient(\n      135deg,\n      rgba(31, 94, 255, 0.08),\n      rgba(31, 94, 255, 0.02)\n    );\n}\n\n.htt-ai-governance .htt-answer-box {\n  position: relative;\n  padding-left: 2rem;\n  border: 1px solid var(--htt-border);\n  border-left: 5px solid var(--htt-primary);\n  background: var(--htt-bg-soft);\n}\n\n.htt-ai-governance .htt-quote-box {\n  border-left: 5px solid var(--htt-primary);\n  background: #f8faff;\n  font-size: 1.12rem;\n}\n\n.htt-ai-governance .htt-process-box {\n  border: 1px solid #cfdcff;\n  background: var(--htt-bg-accent);\n  text-align: center;\n}\n\n.htt-ai-governance .htt-process-box p {\n  margin: 0;\n  font-size: clamp(1.05rem, 2vw, 1.35rem);\n  line-height: 1.5;\n}\n\n.htt-ai-governance .htt-highlight-box p:last-child,\n.htt-ai-governance .htt-answer-box p:last-child,\n.htt-ai-governance .htt-quote-box p:last-child {\n  margin-bottom: 0;\n}\n\n\n\/* =========================================================\n   GOVERNANCE CARDS - SEMAFORO\n   ========================================================= *\/\n\n.htt-ai-governance .htt-governance-grid {\n  display: grid;\n  grid-template-columns: repeat(3, minmax(0, 1fr));\n  gap: 1.5rem;\n  margin: 2rem 0;\n}\n\n.htt-ai-governance .htt-governance-card {\n  position: relative;\n  padding: 1.6rem;\n  border: 1px solid var(--htt-border);\n  border-radius: var(--htt-radius);\n  box-shadow: var(--htt-shadow);\n}\n\n.htt-ai-governance .htt-governance-card::before {\n  content: \"\";\n  display: block;\n  width: 42px;\n  height: 6px;\n  margin-bottom: 1.15rem;\n  border-radius: 999px;\n}\n\n.htt-ai-governance .htt-governance-card p:last-child {\n  margin-bottom: 0;\n}\n\n.htt-ai-governance .htt-governance-card--green {\n  background: var(--htt-green-bg);\n  border-color: #cce8d7;\n}\n\n.htt-ai-governance .htt-governance-card--green::before {\n  background: var(--htt-green);\n}\n\n.htt-ai-governance .htt-governance-card--yellow {\n  background: var(--htt-yellow-bg);\n  border-color: #eadca8;\n}\n\n.htt-ai-governance .htt-governance-card--yellow::before {\n  background: var(--htt-yellow);\n}\n\n.htt-ai-governance .htt-governance-card--red {\n  background: var(--htt-red-bg);\n  border-color: #efcccc;\n}\n\n.htt-ai-governance .htt-governance-card--red::before {\n  background: var(--htt-red);\n}\n\n\n\/* =========================================================\n   AI LEVELS\n   ========================================================= *\/\n\n.htt-ai-governance .htt-levels {\n  display: grid;\n  grid-template-columns: repeat(2, minmax(0, 1fr));\n  gap: 1.5rem;\n  margin: 2rem 0;\n}\n\n.htt-ai-governance .htt-level {\n  position: relative;\n  padding: 1.6rem 1.6rem 1.6rem 1.9rem;\n  border: 1px solid var(--htt-border);\n  border-radius: var(--htt-radius);\n  background: #fff;\n  box-shadow: var(--htt-shadow);\n}\n\n.htt-ai-governance .htt-level::before {\n  content: \"\";\n  position: absolute;\n  top: 1.6rem;\n  left: 0;\n  width: 5px;\n  height: 42px;\n  border-radius: 0 5px 5px 0;\n  background: var(--htt-primary);\n}\n\n.htt-ai-governance .htt-level p:last-child {\n  margin-bottom: 0;\n}\n\n\n\/* =========================================================\n   CHECKLIST\n   ========================================================= *\/\n\n.htt-ai-governance .htt-checklist-box {\n  margin: 2rem 0;\n  padding: 1.8rem;\n  border: 1px solid var(--htt-border);\n  border-radius: var(--htt-radius);\n  background: var(--htt-bg-soft);\n}\n\n.htt-ai-governance .htt-checklist-box ul {\n  margin: 1.2rem 0 0;\n  padding: 0;\n  list-style: none;\n}\n\n.htt-ai-governance .htt-checklist-box li {\n  position: relative;\n  margin: 0;\n  padding: 0.8rem 0 0.8rem 2rem;\n  border-bottom: 1px solid rgba(120, 130, 145, 0.16);\n}\n\n.htt-ai-governance .htt-checklist-box li:last-child {\n  border-bottom: 0;\n}\n\n.htt-ai-governance .htt-checklist-box li::before {\n  content: \"\u2713\";\n  position: absolute;\n  top: 0.8rem;\n  left: 0;\n  width: 1.35rem;\n  height: 1.35rem;\n  border-radius: 50%;\n  background: var(--htt-primary);\n  color: #fff;\n  font-size: 0.78rem;\n  font-weight: 800;\n  line-height: 1.35rem;\n  text-align: center;\n}\n\n\n\/* =========================================================\n   CTA\n   ========================================================= *\/\n\n.htt-ai-governance .htt-cta-box {\n  margin-top: 2.5rem;\n  padding: clamp(1.8rem, 4vw, 3rem);\n  border-radius: 24px;\n  background:\n    linear-gradient(\n      135deg,\n      #172640 0%,\n      #1d3d75 55%,\n      #1f5eff 120%\n    );\n  color: #fff;\n}\n\n.htt-ai-governance .htt-cta-box h2 {\n  max-width: 850px;\n  margin-bottom: 1rem;\n  color: #fff;\n}\n\n.htt-ai-governance .htt-cta-box p {\n  max-width: 850px;\n  color: rgba(255, 255, 255, 0.88);\n}\n\n.htt-ai-governance .htt-button {\n  display: inline-flex;\n  align-items: center;\n  justify-content: center;\n  min-height: 48px;\n  margin-top: 0.5rem;\n  padding: 0.8rem 1.25rem;\n  border: 2px solid #fff;\n  border-radius: 999px;\n  background: #fff;\n  color: #172640;\n  font-weight: 700;\n  text-decoration: none;\n  transition:\n    transform 0.2s ease,\n    background 0.2s ease,\n    color 0.2s ease;\n}\n\n.htt-ai-governance .htt-button:hover,\n.htt-ai-governance .htt-button:focus-visible {\n  background: transparent;\n  color: #fff;\n  transform: translateY(-1px);\n}\n\n\n\/* =========================================================\n   SOURCES \/ BIBLIOGRAPHY\n   ========================================================= *\/\n\n.htt-ai-governance .htt-sources {\n  padding-top: 1rem;\n  border-top: 1px solid var(--htt-border);\n}\n\n.htt-ai-governance .htt-sources-grid {\n  display: grid;\n  grid-template-columns: repeat(3, minmax(0, 1fr));\n  gap: 1.5rem;\n  margin-top: 2rem;\n}\n\n.htt-ai-governance .htt-source-card {\n  padding: 1.5rem;\n  border: 1px solid var(--htt-border);\n  border-radius: var(--htt-radius);\n  background: var(--htt-bg-soft);\n}\n\n.htt-ai-governance .htt-source-card h3 {\n  margin-bottom: 0.65rem;\n  font-size: 1.05rem;\n}\n\n.htt-ai-governance .htt-source-card p {\n  color: var(--htt-text-soft);\n}\n\n.htt-ai-governance .htt-source-card p:last-child {\n  margin-bottom: 0;\n}\n\n\n\/* =========================================================\n   RESPONSIVE\n   ========================================================= *\/\n\n@media (max-width: 980px) {\n  .htt-ai-governance .htt-governance-grid,\n  .htt-ai-governance .htt-sources-grid {\n    grid-template-columns: 1fr;\n  }\n\n  .htt-ai-governance .htt-levels {\n    grid-template-columns: 1fr 1fr;\n  }\n}\n\n@media (max-width: 720px) {\n  .htt-ai-governance section {\n    margin: 3.2rem 0;\n  }\n\n  .htt-ai-governance .htt-levels {\n    grid-template-columns: 1fr;\n  }\n\n  .htt-ai-governance .htt-highlight-box,\n  .htt-ai-governance .htt-answer-box,\n  .htt-ai-governance .htt-quote-box,\n  .htt-ai-governance .htt-process-box,\n  .htt-ai-governance .htt-checklist-box {\n    padding: 1.35rem;\n  }\n\n  .htt-ai-governance .htt-governance-card,\n  .htt-ai-governance .htt-level,\n  .htt-ai-governance .htt-source-card {\n    padding: 1.35rem;\n  }\n\n  .htt-ai-governance .htt-process-box p {\n    font-size: 1rem;\n  }\n}\n\n\n\/* =========================================================\n   REDUCED MOTION\n   ========================================================= *\/\n\n@media (prefers-reduced-motion: reduce) {\n  .htt-ai-governance *,\n  .htt-ai-governance *::before,\n  .htt-ai-governance *::after {\n    scroll-behavior: auto !important;\n    transition: none !important;\n  }\n}\n<\/style>\n\n<script type=\"application\/ld+json\"> { \"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [ { \"@type\": \"Question\", \"name\": \"What is an AI Management System?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"An AI Management System is a structured set of policies, responsibilities, processes and controls used by an organisation to govern the introduction and use of artificial intelligence. It can cover AI inventories, risk assessment, staff training, human oversight, vendor management and incident procedures.\" } }, { \"@type\": \"Question\", \"name\": \"Does the EU AI Act require companies to provide AI training?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"Article 4 of the EU AI Act requires providers and deployers of AI systems to take measures to support the development of AI literacy among staff and other people operating or using AI systems on their behalf. Measures should take account of technical knowledge, experience, education, training and the context in which the systems are used.\" } }, { \"@type\": \"Question\", \"name\": \"Does every company need an AI policy?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"The EU AI Act does not simply state that every company must create a document called an AI Policy. However, organisations using AI need practical measures to manage obligations, risks, responsibilities and AI literacy. A formal AI policy can be an effective way to define approved tools, permitted data, responsibilities, training requirements, human review and incident procedures.\" } }, { \"@type\": \"Question\", \"name\": \"What changed with the 2026 Digital Omnibus on AI?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"Regulation (EU) 2026\/1744 amended several parts of the AI Act. Regarding AI literacy, it maintained the obligation for providers and deployers to take measures supporting AI literacy while clarifying that they are not required to guarantee a specific level of AI literacy for each individual.\" } }, { \"@type\": \"Question\", \"name\": \"Are an internal AI Management System and ISO\/IEC 42001 certification the same thing?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"No. An organisation may establish its own AI Management System or governance framework. ISO\/IEC 42001 is an international standard specifying requirements for an Artificial Intelligence Management System. Certification against ISO\/IEC 42001 is a separate formal assessment and certification process.\" } }, { \"@type\": \"Question\", \"name\": \"Can a digital agency enter client data into ChatGPT or other AI tools?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"There is no single answer that applies to every tool, account configuration or category of data. Organisations must consider the information involved, service terms, account settings, contractual obligations, data protection requirements and internal policies. A mature AI governance framework should define which environments may be used and which categories of information are permitted.\" } }, { \"@type\": \"Question\", \"name\": \"What is Shadow AI?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"Shadow AI is the use of artificial intelligence tools or services outside an organisation's approved processes, systems or policies. It can increase the risk of confidential information, personal data, intellectual property or proprietary code being handled inappropriately.\" } }, { \"@type\": \"Question\", \"name\": \"How should a company evaluate a digital agency's use of AI?\", \"acceptedAnswer\": { \"@type\": \"Answer\", \"text\": \"Useful indicators include formal AI policies, approved-tool processes, data-handling rules, vendor assessment, role-based AI literacy programmes, human oversight, incident management and integration between AI governance, privacy and information security. Relevant information-security certifications can provide additional evidence of organisational maturity.\" } } ] } <\/script>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":20,"featured_media":11439,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[120,121],"tags":[1240,1242,1346,95,1208,94,1344,1348],"class_list":["post-11459","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-en","category-best-practice-en","tag-ai-compliance","tag-ai-literacy","tag-ai-security","tag-intelligenza-artificiale-en","tag-eu-ai-act","tag-expertises-en","tag-human-oversight","tag-iso-42001"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI Governance in Digital Agencies: EU AI Act &amp; Data Security .<\/title>\n<meta name=\"description\" content=\"How can companies choose a digital agency that uses AI safely? AI governance, AI literacy, data protection, human oversight and EU AI Act.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI Governance in Digital Agencies: EU AI Act &amp; Data Security\" \/>\n<meta property=\"og:description\" content=\"How can companies choose a digital agency that uses AI safely? AI governance, AI literacy, data protection, human oversight and EU AI Act.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/\" \/>\n<meta property=\"og:site_name\" content=\"HT&amp;T Consulting\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/HttConsulting\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-25T13:51:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-25T16:47:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.htt.it\/wp-content\/uploads\/2026\/09\/eu-act-ai-sgai.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1044\" \/>\n\t<meta property=\"og:image:height\" content=\"1044\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Massimiliano Baldocchi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@htt\" \/>\n<meta name=\"twitter:site\" content=\"@htt\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Massimiliano Baldocchi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/\"},\"author\":{\"name\":\"Massimiliano Baldocchi\",\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/#\\\/schema\\\/person\\\/d097314406f9b8bb2bef7c594d83388c\"},\"headline\":\"AI Governance in in the agency\",\"datePublished\":\"2026-09-25T13:51:04+00:00\",\"dateModified\":\"2026-09-25T16:47:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/\"},\"wordCount\":6,\"publisher\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.htt.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/eu-act-ai-sgai.webp\",\"keywords\":[\"AI Compliance\",\"AI Literacy\",\"AI Security\",\"artificial intelligence\",\"EU AI Act\",\"Expertises\",\"Human Oversight\",\"ISO 42001\"],\"articleSection\":[\"AI\",\"Best practice\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/\",\"url\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/\",\"name\":\"AI Governance in Digital Agencies: EU AI Act & Data Security\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.htt.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/eu-act-ai-sgai.webp\",\"datePublished\":\"2026-09-25T13:51:04+00:00\",\"dateModified\":\"2026-09-25T16:47:10+00:00\",\"description\":\"How can companies choose a digital agency that uses AI safely? AI governance, AI literacy, data protection, human oversight and EU AI Act.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.htt.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/eu-act-ai-sgai.webp\",\"contentUrl\":\"https:\\\/\\\/www.htt.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/eu-act-ai-sgai.webp\",\"width\":1044,\"height\":1044,\"caption\":\"EU Act AI SGAI HT&T\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/ai-governance-digital-agency-eu-ai-act\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.htt.it\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI Governance in in the agency\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.htt.it\\\/en\\\/\",\"name\":\"HT&T Consulting\",\"description\":\"Scale-up your digital business\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.htt.it\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.htt.it\\\/en\\\/#\\\/schema\\\/person\\\/d097314406f9b8bb2bef7c594d83388c\",\"name\":\"Massimiliano Baldocchi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ee74c8fcce5556dd1c917b477e84c173a025529c0ebe30126a3a3857209ac3f7?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ee74c8fcce5556dd1c917b477e84c173a025529c0ebe30126a3a3857209ac3f7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ee74c8fcce5556dd1c917b477e84c173a025529c0ebe30126a3a3857209ac3f7?s=96&d=mm&r=g\",\"caption\":\"Massimiliano Baldocchi\"},\"description\":\"Massimiliano Baldocchi \u00e8 CEO di HT&amp;T Consulting e da oltre 30 anni opera nel settore della comunicazione, del marketing e del digitale. Laureato in Informatica presso l'Universit\u00e0 di Pisa, coordina la visione strategica dell'agenzia accompagnando aziende e brand nella definizione di strategie integrate tra dati, creativit\u00e0 e tecnologia.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/massimilianobaldocchi\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI Governance in Digital Agencies: EU AI Act & Data Security .","description":"How can companies choose a digital agency that uses AI safely? AI governance, AI literacy, data protection, human oversight and EU AI Act.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/","og_locale":"en_US","og_type":"article","og_title":"AI Governance in Digital Agencies: EU AI Act & Data Security","og_description":"How can companies choose a digital agency that uses AI safely? AI governance, AI literacy, data protection, human oversight and EU AI Act.","og_url":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/","og_site_name":"HT&amp;T Consulting","article_publisher":"https:\/\/www.facebook.com\/HttConsulting","article_published_time":"2026-09-25T13:51:04+00:00","article_modified_time":"2026-09-25T16:47:10+00:00","og_image":[{"width":1044,"height":1044,"url":"https:\/\/www.htt.it\/wp-content\/uploads\/2026\/09\/eu-act-ai-sgai.webp","type":"image\/webp"}],"author":"Massimiliano Baldocchi","twitter_card":"summary_large_image","twitter_creator":"@htt","twitter_site":"@htt","twitter_misc":{"Written by":"Massimiliano Baldocchi","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/#article","isPartOf":{"@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/"},"author":{"name":"Massimiliano Baldocchi","@id":"https:\/\/www.htt.it\/en\/#\/schema\/person\/d097314406f9b8bb2bef7c594d83388c"},"headline":"AI Governance in in the agency","datePublished":"2026-09-25T13:51:04+00:00","dateModified":"2026-09-25T16:47:10+00:00","mainEntityOfPage":{"@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/"},"wordCount":6,"publisher":{"@id":"https:\/\/www.htt.it\/en\/#organization"},"image":{"@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/#primaryimage"},"thumbnailUrl":"https:\/\/www.htt.it\/wp-content\/uploads\/2026\/09\/eu-act-ai-sgai.webp","keywords":["AI Compliance","AI Literacy","AI Security","artificial intelligence","EU AI Act","Expertises","Human Oversight","ISO 42001"],"articleSection":["AI","Best practice"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/","url":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/","name":"AI Governance in Digital Agencies: EU AI Act & Data Security","isPartOf":{"@id":"https:\/\/www.htt.it\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/#primaryimage"},"image":{"@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/#primaryimage"},"thumbnailUrl":"https:\/\/www.htt.it\/wp-content\/uploads\/2026\/09\/eu-act-ai-sgai.webp","datePublished":"2026-09-25T13:51:04+00:00","dateModified":"2026-09-25T16:47:10+00:00","description":"How can companies choose a digital agency that uses AI safely? AI governance, AI literacy, data protection, human oversight and EU AI Act.","breadcrumb":{"@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/#primaryimage","url":"https:\/\/www.htt.it\/wp-content\/uploads\/2026\/09\/eu-act-ai-sgai.webp","contentUrl":"https:\/\/www.htt.it\/wp-content\/uploads\/2026\/09\/eu-act-ai-sgai.webp","width":1044,"height":1044,"caption":"EU Act AI SGAI HT&T"},{"@type":"BreadcrumbList","@id":"https:\/\/www.htt.it\/en\/ai-governance-digital-agency-eu-ai-act\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.htt.it\/en\/"},{"@type":"ListItem","position":2,"name":"AI Governance in in the agency"}]},{"@type":"WebSite","@id":"https:\/\/www.htt.it\/en\/#website","url":"https:\/\/www.htt.it\/en\/","name":"HT&T Consulting","description":"Scale-up your digital business","publisher":{"@id":"https:\/\/www.htt.it\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.htt.it\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.htt.it\/en\/#\/schema\/person\/d097314406f9b8bb2bef7c594d83388c","name":"Massimiliano Baldocchi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ee74c8fcce5556dd1c917b477e84c173a025529c0ebe30126a3a3857209ac3f7?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ee74c8fcce5556dd1c917b477e84c173a025529c0ebe30126a3a3857209ac3f7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ee74c8fcce5556dd1c917b477e84c173a025529c0ebe30126a3a3857209ac3f7?s=96&d=mm&r=g","caption":"Massimiliano Baldocchi"},"description":"Massimiliano Baldocchi \u00e8 CEO di HT&amp;T Consulting e da oltre 30 anni opera nel settore della comunicazione, del marketing e del digitale. Laureato in Informatica presso l'Universit\u00e0 di Pisa, coordina la visione strategica dell'agenzia accompagnando aziende e brand nella definizione di strategie integrate tra dati, creativit\u00e0 e tecnologia.","sameAs":["https:\/\/www.linkedin.com\/in\/massimilianobaldocchi\/"]}]}},"_links":{"self":[{"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/posts\/11459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/comments?post=11459"}],"version-history":[{"count":9,"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/posts\/11459\/revisions"}],"predecessor-version":[{"id":11468,"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/posts\/11459\/revisions\/11468"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/media\/11439"}],"wp:attachment":[{"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/media?parent=11459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/categories?post=11459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.htt.it\/en\/wp-json\/wp\/v2\/tags?post=11459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}