AI PILLAR

Within the Intelligent Business Agility framework, Artificial Intelligence (AI) is not experienced as an isolated technological tool or as a threat to the centrality of human talent. Instead, it is configured as a widespread amplifier, designed to actively support the organization at any level, from the purely strategic to the highly operational.
The daily management of digital assets associated with these technologies is entirely overseen by the Digital Governance Enabling Process Area (EPA). To enable the organization to unleash this potential in a targeted and efficient manner, the enabler’s action develops along three fundamental axes of implementation:
- Data Fluency: defining a clear and rigorous data management action with the primary objective of properly feeding the AI algorithms used in the organization.
- Algorithms and Models: specific training of local models calibrated to respond to the actual operational needs of the company and its processes.
- Usage Patterns: systematic adoption of the best technological patterns based on the context of use, such as conversational AI (conversational AI) and agentic AI (agentic AI).
The Two AI Activator+
The fluid and secure integration of Artificial Intelligence into Harmoniq's operations is structured and executed through two key activators (AI Activator+):
- AI ACT: the framework that guides human-AI interaction, ensuring that technology always acts as an enabler and never as a replacement for People.
- AI Platform: the set of enabling technologies, infrastructures, and platforms that allow the actual operational integration between humans and machines.
The AI ACT Architecture: Principles, Promises, and Guidelines
The AI ACT represents Harmoniq's technological constitution. To ensure that ethics do not remain a theoretical abstraction, the document is structured in an extremely logical and pragmatic cascading format: PRINCIPLES → PROMISES → GUIDELINES.
The framework rests on six core principles, each declined into concrete commitments and mandatory application rules:
1. Inclusiveness (Inclusività)
AI must enhance the capability of every single individual, acting as a catalyst for different personal sensitivities and refusing to operate as a homogenizing filter.
-
- Promises:
- Non-discriminatory datasets: we promise to use training sets that reflect the actual diversity of our customers and employees.
- Segment testing: we promise to test the algorithmic impact on different market segments to prevent and neutralize hidden biases.
- Positive Cognitive Friction: we promise to use AI not only to passively confirm our ideas, but to actively challenge human biases (groupthink) and offer divergent perspectives.
- Guidelines:
- Privacy by Design: integrating the protection of personal data as a native design requirement from the very beginning of the software, excluding late or artificial additions.
- Non-Discrimination Testing Protocol: executing structured tests to verify that AI outputs do not discriminate based on protected characteristics before delivery to the customer. It is mandatory to produce a "Fairness Report" demonstrating a disparity threshold in line with current regulations.
- Accessibility Standards: adopting explicit directives as minimum accessibility standards for all AI-powered digital deliverables. Compliance with these parameters must be verified through automated tests and accompanied by manual reviews for screen readers on the main flows.
2. Transparency (Trasparenza)
The functioning of any Artificial Intelligence system must always be understandable to evaluate its action and build operational trust.
-
- Promises:
- Explicit standards: we promise clear standards of explanation (explainability) to avoid the "Black Box" effect.
- Traceability: we promise complete traceability of decisions: who decided what, when, and on what input data.
- Pre-release validation: we promise never to go live ("Live") in production without a validation phase in a controlled environment ("Sand Box").
- Guidelines:
- Client Communication: attaching to every proposal a brief standard document explaining which AIs are used, for what purpose, what data they process, how results are validated, and how the client can request clarifications.
- AI Literacy: developing mandatory training plans for staff, documenting them adequately as proof of compliance.
- Explainability Standard: explaining clearly how to evaluate AI outputs, making the most relevant factors explicit.
- AI Watermarking: every content generated by AI must be clearly distinguishable from human content through watermarks or labels.
3. Accountability (Responsabilità)
Ethics and Data Privacy are the supporting pillars to guarantee a responsible use of AI platforms.
-
- Promises:
- Orchestrated Responsibility: we promise that no data will end up in unauthorized hands, nor without clear design boundaries. The human always remains the orchestrator and the one responsible for the objective, without the AI being slowed down by stopping every single action.
- Safety Mechanisms: we promise to always keep manual security procedures (kill-switch) activatable to guarantee service continuity and control.
- Data Governance: we promise to protect sensitive data through a centralized control that allows its use only for appropriate purposes and its deletion when requested.
- Guidelines:
- RACI Matrix AI Governance: always defining an R/A/C/I matrix for every critical decision on AI. The matrix must clarify the roles for adopting tools, managing incidents, and the annual review.
- AI Tool Inventory Registry: maintaining a centralized registry of all AI tools in use. The registry must be updated with each new adoption to comply with the required documentation.
- Incident Notification Procedure: establishing an incident registry and a strict procedure in case of a data breach.
- Vendor Due Diligence: subjecting every AI supplier to a questionnaire before adoption, verifying regulatory compliance, data retention policies, audit trails, and data localization. Assigning a score and conducting an annual review for existing suppliers.
4. Sustainability (Sostenibilità)
AI must operate while actively supporting long-term well-being, minimizing ecological and social impact.
-
- Promises:
- Ecological Footprint: we promise to measure and optimize the energy consumption of our models (Green AI).
- Social Impact: we promise to evaluate the social and economic impact of algorithms to prevent negative effects on the human skills of collaborators.
- No Obsolescence: we promise not to introduce aspects of planned technological obsolescence.
- Guidelines:
- Annual Review Clause: introducing an explicit clause requiring the annual review of the entire AI ethics and compliance document at a fixed interval.
- Energy KPI System: creating and feeding an Energy KPI System that tracks tokens consumed for each project, the estimate of CO2 equivalent emitted, and the comparison with the previous month's data. The information must be updated at appropriate intervals, and its results must be mandatory in the closure report of each individual project.
- Supply Chain AI Assessment: extending the logic of the Energy KPI System to third-party suppliers. Before adoption, it is necessary to request energy consumption data from platform providers, giving priority to suppliers certified as carbon-neutral. The target KPI (objective) must be established annually and measured constantly.
5. Privacy and Security (Privacy e Sicurezza)
The protection of personal data and platform security are native design requirements (by design), indispensable to protect the rights of individuals and guarantee the reliability of the solutions.
-
- Promises:
- Assessment and Data Minimization: we promise to evaluate the impact of every AI system on personal data in advance and to collect only the strictly necessary information.
- Training and Retention Governance: we promise to manage training data with maximum transparency regarding origin and consents, and not to keep it beyond the agreed time.
- Cybersecurity and Robustness: we promise to rigorously test the security and solidity of our AI systems before any release to prevent vulnerabilities and attacks.
- Guidelines:
- DPIA (Data Protection Impact Assessment): it is mandatory to perform an assessment, before use, of the data that will be employed by AI platforms to analyze necessity, proportionality, and risks.
- Data Minimization Policy: applying an internal policy that specifies the minimum set of data necessary for each category of AI project. Collecting additional data without documented justification is prohibited. Data must be anonymized or pseudonymized as soon as possible.
- Training Data Governance: in the creation and/or refinement of models for clients, it is mandatory to apply a specific policy for training data that verifies origin, licenses, consents, quality, and includes a bias audit.
- Data Retention Rules: strict maximum retention periods must be respected for: client project data, training/test data, AI logs, for traceability purposes. A certified deletion with secure overwriting is required.
- AI Security Testing Protocol: executing security tests on AI systems before release into production. For all (basic) projects, prompt injection testing and output sanitization are required. For high-risk (advanced) projects, adversarial input testing and checks on model robustness are required.
6. Purpose and Impact (Scopo e Impatto)
The use of AI must be guided by a clear and transparent objective, and directed by an ethical perimeter.
-
- Promises:
- Preventive Risk Assessment: we promise not to start any AI-Empowered initiative without first evaluating potential risks, impact on stakeholders, and the reversibility of choices.
- Transparency of Use and Declaration of Intent: we promise to explicitly and transparently declare the purposes of using AI tools, precisely delimiting the boundary between the action of the machine and the human decision.
- Ethical Limits and In-itinere Monitoring: we promise to categorically reject the development of AI solutions that violate fundamental rights ("Red lines") and to monitor during development that the AI-Empowered initiative does not deviate from the initially established ethical principles.
- Guidelines:
- Impact Assessment: before starting any AI-Empowered initiative, it is mandatory to evaluate the impact that AI adoption has on a series of key factors. The result of the analysis must be adequately formalized and archived in the initiative's repository, in compliance with the risk management system.
- AI Purpose Statement: a disclosure specifying unequivocally how AI will be used must be attached to every proposal or contract involving the use of AI. This statement must be updated whenever the scope changes, communicating the update appropriately.
- Ethics Guardrails: defining the Ethical Guardrails for the initiative, which implement current regulations, contextualizing and strengthening them where and when appropriate.
- Ethical Review Gate: periodically, during the development of an AI-Empowered initiative, it is mandatory to proceed with a formal review of the Impact Assessment.