Is your company already using artificial intelligence?
Put clear rules in place without losing control.
Artificial intelligence is already part of everyday business processes: emails, document and data analysis, content creation, recruitment, customer support and operational decision-making. Yet it is often used before the company has decided who may use which tools, with what data and under what controls.
Loyce Legal advises companies that develop, purchase or use AI systems. We map actual use cases, identify the applicable obligations and create policies, procedures and contracts that enable innovation while protecting data, people, know-how and reputation.
REQUEST AN INITIAL CONSULTATION
Why an AI policy is necessary even without an official AI project
The most common risk is not the absence of artificial intelligence, but its uncontrolled use: personal accounts, unapproved tools and business information entered into external platforms without knowing how it will be stored or reused. This is commonly known as “shadow AI”.
A generic policy downloaded from the internet is not enough. An effective AI policy must reflect the company’s actual tools and processes and establish:
• which systems are approved and which uses are prohibited or require prior approval;
• which data and documents must not be entered into AI tools, with specific rules for personal data, confidential information and trade secrets;
• when human review is mandatory and who remains responsible for the final decision;
• how to assess the reliability and completeness of outputs and identify possible discrimination;
• how to report errors, incidents or misuse and how the rules will be reviewed over time.
The AI Act also requires providers and professional users of AI systems to ensure a sufficient level of AI literacy among the people who work with those systems. Policy and training must therefore be coordinated and tailored to the roles involved and the actual risks.
What must a company govern when it uses AI?
The AI Act does not treat every system in the same way. Obligations depend on the company’s role, the system’s intended purpose and the context in which it is used. Data protection, employment law, intellectual property rights, confidentiality obligations and contractual rules continue to apply at the same time.
Effective governance should therefore address the following areas in a coordinated manner:
• an inventory of tools and use cases, including applications adopted independently by individual departments;
• classification under the AI Act and identification of the company’s obligations as a provider, deployer, importer or distributor;
• protection of personal data, any required data protection impact assessment, access security and information retention;
• the use of AI in employment, recruitment and staff assessment, with particular attention to transparency, human oversight and discrimination risks;
• ownership and permitted use of text, images, software and other content created or processed using AI;
• contracts with vendors and SaaS platforms, including service levels, audit rights, data use, subcontractors, incidents and allocation of liability;
• alignment with privacy, cybersecurity, internal procedures and, where applicable, the Organisational Model under Italian Legislative Decree no. 231/2001.
An AI system’s output is not an independent decision. The company remains responsible for how the system is selected, configured and used. Human oversight must therefore be effective, competent and capable of being documented.
From mapping to policy: a process built around your business
Loyce Legal uses a practical method designed to support innovation and focus safeguards where the actual risks lie.
1. Mapping. We identify the tools already in use, the processes involved, the data processed and the people affected.
2. Legal risk assessment. We assess the AI Act, privacy, employment, intellectual property, contracts and compliance, distinguishing mandatory obligations from recommended measures.
3. Governance. We define roles, responsibilities, approvals, levels of control and workflows for authorising new tools.
4. Documentation. We prepare the AI policy, operational instructions, system inventory, vendor clauses, notices and procedures for incidents and periodic reviews.
5. Training and updates. We develop role-specific programmes for management, HR, legal, IT, compliance and users and keep the framework aligned with legal and technological developments.
The result is not a file that remains on a shelf. It is a set of rules people can understand and use every day: clear for employees, verifiable by management and defensible towards customers, business partners and authorities.
Why choose Loyce Legal?
To use AI with CONTROL.
We start from the way AI is actually used within the business. We distinguish low-risk applications from those requiring approval, assessment or stricter controls, avoiding rules that are unnecessarily abstract.
To protect DATA, PEOPLE AND KNOW-HOW.
An effective policy reduces the risk of confidential information, personal data or protected content being disclosed or used improperly. We establish clear rules and identifiable responsibilities.
To bring INNOVATION AND COMPLIANCE together.
Our team combines expertise in the AI Act, privacy, employment, intellectual property, contracts and Italian Legislative Decree no. 231/2001. The company receives one coordinated solution built around its operational priorities rather than a collection of separate opinions.