Marco Combetto

AI & Digital Transformation — Public Sector · AI Act · Data Science

AI Act Compliance Checklist — Italian Public Administration

Consultancy engagement — operational task list

Rule: all phases must be completed. Skipping any single item = non-compliant deployment.


PHASE 1 — Use Case Definition

  • Define the intended AI use case
  • Classify the data involved (public / sensitive / classified)
  • Determine if the use case falls under AI Act high-risk categories
  • Identify which compliant deployment path applies:
    • EU-approved GPAI via controlled environment
    • Open-source LLM deployed internally
    • Sector-specific AI platform certified for PA use

PHASE 2 — Model Assessment (AI Act)

  • Identify the candidate AI model or system
  • Verify whether the model appears on the EU AI Office systemic-risk list
  • If systemic risk applies: confirm provider compliance with AI Act GPAI obligations (robustness, evaluations, incident reporting, cybersecurity, transparency)
  • Document model status explicitly in: DPIA, security assessment, and contract

  • Conduct DPIA (Data Protection Impact Assessment)
  • Obtain DPO formal approval
  • Verify GDPR Art. 28 processor qualification of the provider
  • Confirm no training on PA data (contractual clause)
  • Confirm EU-only data residency
  • Include Standard Contractual Clauses (SCCs) in the contract
  • Verify AgID guidelines alignment (AI and cloud)

PHASE 4 — Infrastructure Control

  • Select compliant hosting — one of:
    • Dedicated EU cloud tenant (Azure EU / AWS Europe Sovereign / Google EU)
    • National sovereign cloud (Polo Strategico Nazionale – Italy)
    • On-premise deployment
  • Confirm physical data location in EU
  • Confirm EU legal jurisdiction only
  • Confirm no third-country admin access
  • Verify access via private API endpoints (not public SaaS UI)
  • Implement RBAC (role-based access control)
  • Activate logging and audit trails

PHASE 5 — Cybersecurity

  • Conduct cybersecurity risk assessment (ACN framework / ISO 27001 alignment)
  • Verify encryption at rest and in transit
  • Define and document incident notification procedures
  • Obtain ACN validation (or equivalent cybersecurity certification)

PHASE 6 — Procurement

  • Verify procurement route: public tender or framework agreement (e.g., Consip/MePA)
  • Exclude any direct or informal adoption of commercial SaaS tools
  • Confirm involvement of the public procurement authority

PHASE 7 — Contract

  • Sign Data Processing Agreement (DPA)
  • Include no-training clause (prompts and outputs not used for model training)
  • Include EU-only processing clause
  • Define liability and breach notification clauses
  • Confirm configurable and limited data retention
  • Confirm encryption obligations are contractually enforced

PHASE 8 — Governance & Approvals

  • Obtain DPO sign-off
  • Obtain AgID alignment confirmation
  • Obtain ACN cybersecurity validation
  • Confirm procurement authority sign-off

PHASE 9 — Operations

  • Activate operational monitoring and logging
  • Define mandatory human oversight for all decision-support outputs
  • Document and enforce forbidden uses (see below)

Reference: Permitted vs. Forbidden Uses

✅ Permitted

  • Document drafting
  • Internal decision support
  • Citizen service automation
  • Code generation
  • Data summarization

❌ Forbidden

  • Feeding classified data without clearance
  • Automated legal decisions without human validation
  • Biometric or high-risk profiling without AI Act safeguards
  • Using public ChatGPT UI (or equivalent SaaS) with institutional data

“EU-approved GPAI in a controlled environment” is not innovation freedom.
It is regulated industrial deployment.