Governing AI: Ethics, Law, and Compliance

The pervasive integration of artificial intelligence into the decision-making architectures of our society presents us with a historical question, one that requires a prompt analysis free from alarmism.

Does the massive regulatory framework built to protect us represent a real safeguard against algorithmic opacity, or does it risk turning into a bureaucratic labyrinth that stifles innovation?

To decode the complexity of this transition, we cannot limit ourselves to mere legal technicalities. We must achieve a structural synthesis that unites universal ethics, civic vision, and rigorous business operations.

The Ethical Horizon and the Principle of Subsidiarity

The essential horizon for this reflection is provided to us by the recent encyclical letter Magnifica Humanitas [1]Pope Leo XIV, Encyclical Letter Magnifica Humanitas on the safeguarding of the human person in the age of artificial intelligence, May 15, 2026.

It stands as a manifesto of contemporary humanism, drawing an unequivocal line of principle. The text identifies the principle of subsidiarity as the true antidote to the drift of the technocratic paradigm.

In the digital era, this principle demands that algorithmic processes are not imposed from above in an opaque manner. On the contrary, the highest ethical thought reminds us that innovation must be oriented toward the common good through transparency, accountability, and genuine forms of participation, demanding independent audits, a clear readability of algorithms, equitable access to data, and recourse mechanisms accessible to all.

This is our foundational and overarching framework: we cannot delegate our future to an asymmetric technological power. However, for this humanistic inspiration to impact material reality, it must necessarily materialize into courageous action and corporate as well as workplace practices.

The Impact of Regulatory Policies and the Role of Intermediate Bodies

European and national lawmakers have responded to the technological challenge by enacting significant regulatory texts, such as the AI Act, the NIS2 Directive, and the recent Law No. 132/2025 [2]Law of September 23, 2025, No. 132, Provisions and delegations to the Government regarding artificial intelligence.

The intent to ensure that innovation does not translate into silent surveillance is an act of legal civilization. Yet, the structural application of this massive framework raises a critical technical and political question.

Regulatory ambition risks clashing with the intrinsically fluid nature of neural networks. Consider the complex issue of data sovereignty. Institutions firmly promote the localization of servers within continental borders; yet, technical investigation reveals that major cloud ecosystems frequently employ dynamic data routing solutions, diverting process computation to non-European computational nodes to organically manage latency peaks. Thus, believing it operates within the safe perimeter of privacy regulations, the enterprise unintentionally finds itself exporting strategic or sensitive information. In this scenario, we cannot ignore the geopolitical dimension and the impact of the so-called Brussels Effect. The European Union’s ambition to enforce global standards through regulation—as occurred in the past with the GDPR—now clashes with the nature of AI, which is not merely a commercial tool, but an asset of hegemonic power. While the West adopts a laissez-faire approach geared toward economic supremacy and the East shapes development through state control, Europe runs the real risk of establishing itself as a regulatory superpower while remaining a technological dwarf.

The issue of dynamic data routing to non-European nodes is emblematic of this material contradiction: jurisdictional claims and the resulting balkanization of the web (the so-called splinternet) routinely crash against the oligopoly of major global hyperscalers, the true holders of the foundational infrastructure. A further paradox unfolds in the clinical and labor law spheres. The law rightly mandates the principle of human-in-the-loop, reserving human decision-making power to protect citizens. However, this introduces the complex problem of synthetic liability [3]Synthetic liability in the AI era.

If a company ignores the predictive suggestion of the machine and the user suffers harm, will case law tend to condemn it for deviating from algorithmic evidence?

This dynamic generates what the sociology of technology—specifically through the thought of Madeleine Elish—defines as a moral crumple zone. Just as the front of a car is engineered to crumple and absorb the impact in order to protect the passenger cabin, the human being (or the company representing them), even when embedded in highly automated decision-making circuits via the human-in-the-loop principle, risks being kept in the process not to exercise genuine critical oversight, but to serve as a legal lightning rod. In the event of system failure, the professional ends up absorbing full legal responsibility, while also falling victim to automation bias—the natural psychological inclination to uncritically comply with the output provided by the machine.

It is within these systemic fault lines that the vital need for an intermediate dimension takes root. Caught between a State chasing Technology—each inherently moving at different speeds—and global providers holding the keys, an urgent need emerges for a new, mature, and conscious civic and political framework, highlighting the role of modern intermediate bodies. This calls for a policy direction that moves away from chasing post-hoc penalties in favor of genuine regulatory agility, safeguarding inviolable rights while simultaneously encouraging active participation and private initiative. The architecture of corporate compliance in the digital ecosystem

This synthesis between universal ethics and civic drive ultimately lands in the granular realm: the day-to-day operations of businesses.

Today, with the introduction of Article 437-bis of the Criminal Code penalizing the failure to adopt security measures in AI systems, along with the corresponding aggravating factors under Model 231, compliance ceases to be a mere paperwork formality.

Organizations must forge a digital criminal compliance architecture. To prevent debarment sanctions and protect management, a constructive outlook requires moving beyond siloed approaches, achieving a structural integration between international governance standards and the operational pragmatism of risk management frameworks [4]National Cybersecurity Agency, Guidelines for the implementation of cybersecurity regulations.

This methodological fusion allows organizations to measure and mitigate algorithmic risks, providing the supervisory body with objective, documentable metrics. Simultaneously, companies in their capacity as deployment entities must demand from vendors a structured Bill of Materials for software and AI models—an essential registry without which supply chain governance is impossible.

Furthermore, security does not end prior to deployment. Preliminary static testing proves inadequate against autonomous generative AI. It becomes necessary to engineer real-time compliance controls and adopt active execution-phase filters capable of intercepting logical anomalies in fractions of a second, combined with the practice of algorithmic attack simulations.

On a technical and organizational level, constructing this architecture demands the adoption of state-of-the-art international standards, such as the recent [5]ISO/IEC 42001 standard on AI management systems. Within this framework, the need to require vendors to provide a clear software bill of materials now takes the technical form of an AI-SBOM (Artificial Intelligence Software Bill of Materials), an indispensable declarative requirement. In parallel, operational security must grapple with evolving internal risks: the unsanctioned use of applications now manifests as Shadow AI. Inadvertently entering a trade secret into a public generative AI prompt is effectively equivalent to handing it over for training third-party vendor models.

To neutralize such structural vulnerabilities, purely static testing is obsolete; organizations must therefore not only engineer compliance by integrating AI Guardrails to intercept anomalies and prevent violations before they materialize into harm, but also foster an AI culture through training, now known as AI literacy.

Ultimately, every assessment protocol must translate into a measurable eradication of the unsanctioned use of unauthorized artificial intelligence, mapping and blocking the use of commercial applications by staff at the network level in order to neutralize the risk of exposing trade secrets and intellectual property at its root.

The analysis of the current landscape compels us to reach a clear-eyed realization. Attempting to govern the digital ecosystem solely through punitive measures is an ineffective path. An architecture for a digital humanism thus rests on the wisdom of an ethics that rejects opacity, the drive of collective action capable of constructively mediating between institutions and the market, and a dedicated focus on corporate compliance. Does a purely prohibitionist approach truly create safe spaces, or does it ultimately constrain initiative by pushing the finest “intelligence” elsewhere?

References and sources

References and sources
1 Pope Leo XIV, Encyclical Letter Magnifica Humanitas on the safeguarding of the human person in the age of artificial intelligence, May 15, 2026
2 Law of September 23, 2025, No. 132, Provisions and delegations to the Government regarding artificial intelligence
3 Synthetic liability in the AI era
4 National Cybersecurity Agency, Guidelines for the implementation of cybersecurity regulations
5 ISO/IEC 42001