AI Policy · V1.0
AI Policy
How Valuemate governs the development, adoption and use of Artificial Intelligence internally and in the services offered to clients, in line with Regulation (EU) 2024/1689 (EU AI Act).
AI Policy · V1.0
How Valuemate governs the development, adoption and use of Artificial Intelligence internally and in the services offered to clients, in line with Regulation (EU) 2024/1689 (EU AI Act).
This AI Policy integrates and operationally specifies the AI ethical principles set out in Valuemate's Code of Ethics (sec. 4.3), in line with Regulation (EU) 2024/1689 (the EU AI Act) and consistent with the GDPR and the ICT risk management framework already adopted for NIS2.
It applies to all Artificial Intelligence systems developed, adopted or offered by Valuemate: internal tools supporting operations, AI features embedded in services (e.g. Service Desk, StockWave, AI-LAB), and solutions built for clients as part of AI Services.
The Policy defines accountability roles, risk classification criteria, human oversight requirements, transparency obligations and incident management procedures for the use of AI at Valuemate. It applies to directors, employees and collaborators, and, where relevant, to suppliers and partners who develop or integrate AI systems on the company's behalf.
Valuemate establishes a cross-functional committee (Legal, Compliance, DPO, CISO, Head of AI or technical lead) responsible for: approving the adoption of new medium- or high-risk AI systems; maintaining the register of active AI systems; overseeing periodic audits; validating human oversight procedures for the most critical use cases.
Every significant AI system has an internally identified owner, responsible for keeping its technical documentation up to date, monitoring its operation, and acting as the point of contact for anomalies or reports.
Before adoption, every AI system is classified according to a four-tier approach consistent with the taxonomy of Regulation (EU) 2024/1689:
For every system classified as high or specific risk, Valuemate identifies by name the people responsible for supervision, who must: understand the system's capabilities and limitations; be able to correctly interpret its outputs; be able to decide at any time not to use the system, to disregard its output, or to halt its execution. No AI-assisted output is used operationally without human verification, consistent with what is already established in the Code of Ethics.
When a client or user interacts with one of Valuemate's AI systems, or receives content generated by it, they are clearly informed, unless this is already evident from the context of use. Synthetic content intended for publication carries an indication of its artificial origin.
Data processed by AI systems follows the same confidentiality and protection principles already in force across the organisation (GDPR, NIS2 security measures). High-risk systems undergo bias assessment before adoption and periodic review, to identify and mitigate any discriminatory distortions.
A malfunction, a clearly erroneous output, or a detected misuse of an AI system is reported to the system owner and, for high-risk or systemic cases, to the AI Ethics & Governance Committee, which assesses its impact and any corrective measures, in coordination with the incident management procedures already in place for cybersecurity.
Valuemate promotes AI Literacy programmes tailored by role: governance and accountability principles for management; conscious use and bias awareness for operational staff; data security and prompt injection prevention for IT and cybersecurity.
This Policy is updated periodically to reflect regulatory developments (in particular the implementing decrees of Law 132/2025) and the technological evolution of the AI systems adopted. For the complete regulatory framework, see Valuemate's EU AI Act white paper (available in Italian).
Version V1.0, 23/07/2026 · Approved · Valid until a new version is issued.
Manage consent by category. Technical cookies are always active as they are required for the site to work. The others stay off until you enable them.
Required for navigation and basic features (e.g. language and theme preference). No consent needed.
Aggregated statistics on site usage (e.g. Google Analytics) to improve content.
Profiling cookies and embedded third-party content (e.g. social, video, maps).