The Lean AI Governance Framework (LAIGF) is how we help companies, public administrations and professionals use AI in a compliant, secure and sustainable way. It starts from processes, not technology, and is designed to be usable by non-technical organizations too.
The framework builds on the references that matter: the EU AI Act (Regulation (EU) 2024/1689) as the legal constraint, the NIST AI Risk Management Framework as the operating method, and ISO/IEC 42001 as the path to certification. It is not tied to any platform: we choose tools to fit the context, without locking you into a single vendor.
Whoever is in the loop needs the time, the skills and the real power to intervene.
For us, human oversight is not a label added at the end of a project but a design choice. AI proposes; people validate, correct and decide.
Nine pillars
The framework is organized into nine pillars. The first one, Lean First, always comes before the others: you do not automate what you should eliminate.
Lean First
Process analysis and redesign before any technology choice, starting from how work is really done.
Compliance and intellectual property
An inventory of AI systems, risk classification, regulatory obligations and ownership of what AI produces.
Security and data
Protection of personal and business data, and control of Shadow AI and language-model vulnerabilities.
Output quality
Checking outputs and handling hallucinations and incidents before they reach customers or citizens.
Prompts and tokens
Designed, reusable prompts and the right model for each task: more quality, less waste.
AI costs
Planning and controlling spend by project and activity, so you know what each use really costs.
People and AI agents
AI literacy, human oversight protocols and clear rules for agents that act autonomously.
Vendors and continuity
Vendor assessment, alternatives for critical processes and a plan B if a service goes down.
Sustainability
The environmental and social impact of AI use, integrated into ESG reporting.
AI Act deadlines
Some obligations already apply, others arrive in the coming months. The postponement for high-risk systems does not suspend the obligations already in force.
- 2 February 2025
Prohibited practices and AI literacy
Prohibited AI practices banned; training obligation for those who use AI systems.
- 2 August 2025
General-purpose AI models (GPAI)
Transparency, copyright and safety obligations for large language models.
- 10 October 2025
Italian AI law (Law 132/2025)
National obligations for public administration, employment, healthcare and the professions.
- 2 August 2026
Transparency (Art. 50)
Chatbots, synthetic content and deepfakes must be disclosed and labelled.
- 2 December 2026
Marking of generated content
Machine-readable marking for generative systems already on the market.
- 2 December 2027
High-risk systems (Annex III)
HR, credit, education, healthcare, critical infrastructure: full obligations.
- 2 August 2028
Regulated products (Annex I)
Medical devices, machinery and other products with embedded AI.
Calendar updated to the Digital Omnibus (Regulation (EU) 2026/1744). For information only: this is not legal advice.
An 18-month path
Adopting the framework is not a one-off project. We introduce it in phases, adapted to each organization's context.
Foundation
Process analysis and AI readiness, system inventory, company AI policy, transparency compliance, basic training.
Compliance
Impact assessment of high-risk systems, security, output quality, human oversight protocols, vendor assessment.
Maturity
Prompt and cost control, sustainability, continuous monitoring and preparation for ISO/IEC 42001 certification.
Want to know where your organization stands? Let's start with an exploratory meeting.
Let's talk