Are Rules Enough to Make AI Ethical at Work? What the AI Act Says, and What Is Left to You

Three AI Act obligations already apply, and almost nobody knows they have to comply. But the line between what is banned and what is allowed leaves a wide space in between, and there the person at the screen decides. A write-up of the session with Isabella Flecchia, with two real cases.

Gaetano Castaldo Gaetano Castaldo
15 Sep 2026
11 min read
AI adoption #ai-act #ai-literacy #ai-training #change-management
Opening slide of the session, with Isabella Flecchia and Gaetano Castaldo on video

Are rules enough to make AI ethical at work?

No. Since 2 February 2025 the AI Act has banned inferring people's emotions in the workplace and has required training for anyone who uses AI; since 2 August 2026 it has required chatbots to identify themselves and generated content to be made recognisable. But between what is clearly banned and what is clearly allowed there is a wide space, and there the person at the screen decides.

This article is a write-up of the 15 September 2026 session I ran together with Isabella Flecchia, founder of Impulso Futuro and an expert in people and team change, in front of an audience of managers and HR leaders. The full video is below, in Italian.

Which AI Act obligations already apply to my company?

Three of them, and they are not coming: they are here. Regulation (EU) 2024/1689, the AI Act, has already turned them into things that change your Monday morning.

If you use AI facing the public, you must say so. Article 50 has applied since 2 August 2026: a chatbot must make clear from the first contact that it is not a person, and generated content must be made recognisable through machine readable markings. If a product has ever arrived at your door looking half the size it did in the ad, you have seen the problem up close: a model generating an image does not preserve proportions, and nobody told you the image was generated.

If you employ people, you cannot analyse their emotions at work. The Article 5 prohibition has applied since 2 February 2025 and covers systems that infer workers' emotional states, with the exceptions allowed for medical or safety purposes.

If AI is used in your company, people must be trained and the training must be documented. That is Article 4, also applicable since 2 February 2025. No certification is needed: there is no certifying body. What is needed is for somebody in the company to own it and to write down that it happened. A few hours done well, with a plan, are worth more than skills picked up by chance in the corridors. I wrote a separate guide on this: why buying AI tools is no longer enough.

In my experience inside companies, the training obligation is the one almost nobody knows they have. It has been in force for a year and a half.

Can I use AI to assess or select people?

For now yes, and that is exactly the point. High-risk systems under Annex III, which include those used for recruitment and workforce management, were due to become mandatory on 2 August 2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI of 8 July 2026, published in the Official Journal of the European Union on 24 July 2026, postponed them to 2 December 2027.

That postponement does not remove the question, it leaves it open for longer. Between now and December 2027, using AI to judge a person is not illegal: it is your decision, which makes it an ethical problem before it is a legal one.

Two facts show where the wrong road leads. The Italian data protection authority, in its decision of 14 May 2026, addressed the Myndoor case: a plugin for Slack and Teams that estimated workers' stress levels by semantically analysing chat messages. A product built for organisational wellbeing, in all likelihood in good faith. The authority made clear that information about employees' emotional states, inferred by an AI system, must not reach the employer.

Much earlier, in October 2018, Amazon abandoned the internal CV screening tool that had trained on ten years of applications in a male dominated sector and had learned to penalise women's CVs. Nobody programmed it to do that: it simply learned well from unbalanced data.

Why does the same technology work in one company and fail in another?

Because the difference is not in the tool, it is in how the tool arrives.

In the first case I came across, the manager of a hotel held her meetings remotely and let the system transcribe everything and produce the summary. She then used that summary to assess her staff: what should this person have done according to the job description, and where did they get it wrong. But the summary does not know whether you had a problem that day, or what happened the day before. The result was that people felt judged by a machine that could not understand them, and at some point it was no longer clear who was running the hotel.

That case has three defects, and they are worth listing because they recur everywhere: people did not know they were being assessed, they could not answer back, and nobody was accountable for the judgement.

In the second case, a technical services firm in construction with a dozen employees. The owner told me: "I would like to adopt AI, but I have a lot of doubts." That is a promising sentence, far better than its opposite, which usually sounds like "I pick the tool and you use it the way I say." Those doubts turned into a process: first understand how each department actually works, then training, then tools, and there was more than one. Same technology as the first case, opposite outcome. Anxiety on one side, satisfied people on the other, and somebody who became the internal reference point.

The difference in one line: in the first case AI landed on top of people, in the second it arrived alongside them.

What does Article 14 require on human oversight, and why is it hard to apply?

This is where Isabella's contribution was the most uncomfortable, because it is not about what the rule says but about what a person needs in order to do it.

Article 14 of the AI Act says that whoever exercises oversight of a high-risk system must be aware of the risk of relying automatically or excessively on its outputs, what is known as automation bias. It could not be clearer. Then try moving it into a real working day: how does a supervisor stay alert when they have little time, many competing priorities, and when trusting the answer takes less effort than checking it?

The same article says that whoever supervises must be able to decide not to use the system, or to disregard, override or reverse its outputs. Formally holding that power, however, is not the same as exercising it, especially if that person feels unsure of their technical ability, or their role, or their job security.

"The rules give us the perimeter, but inside it there is a person who has to be able to notice that they are choosing."

Isabella Flecchia, founder of Impulso Futuro

In her work with a large corporate client, Isabella recounts, there were clear rules, training for everyone, managers who followed those rules first, adequate tools even for sensitive data, and even an internal point of reference. Everything done by the book. And yet, as soon as a safe enough space was created to talk about it, people's questions were still there. Good governance does not erase them: it makes them speakable.

Where do you start on Monday morning?

With the three questions we closed the session on, which work as a quick check on any use of AI you have running:

  1. How do I stay genuinely alert? Not in theory: when you have fifteen minutes and five urgent things.
  2. How much do I hold on to my own judgement? Including in front of an answer delivered with total confidence, and wrong.
  3. Do I notice when I am delegating? Because the relief of being told everything is fine is real, and it is not a good criterion.

If those three feel vague, try the one concrete test I know: ask whether the people AI touches know they are being touched, whether they can answer back, and whether anybody is accountable for the outcome. Those were the three defects of the hotel case, and they make a good sieve.

The second of the two sessions on ethics runs on 14 October 2026, 12.30 to 13.30 CEST, again on LinkedIn and in Italian, picking up where this one stopped: where individual responsibility sits.

If instead you want to start from your own company, the Article 4 training obligation is the simplest place to begin, because its deadline has already passed and it closes in a few hours done well. The rest of the AI Act, with deadlines and penalties, is in this guide. For a quick picture of where your company stands there is the AI Readiness test, free and five minutes long, and the other pieces on how AI actually arrives at work are in the AI adoption hub.

Frequently asked questions

When do the AI Act obligations on high-risk systems become mandatory?

On 2 December 2027 for high-risk systems under Annex III, which include those used to recruit and manage staff. The original deadline was 2 August 2026, but the Regulation (EU) 2026/1744, the Digital Omnibus on AI published in the Official Journal of the European Union on 24 July 2026, postponed it. The Article 50 transparency obligations and the Article 4 AI literacy obligation were not postponed.

Can I analyse employees' emotions or stress with AI?

No. The Article 5 prohibition in the AI Act has applied since 2 February 2025 and covers systems that infer people's emotions in the workplace, except for medical or safety purposes. The Italian data protection authority, in its decision of 14 May 2026 on the Myndoor case, added a point that holds even when the service is voluntary: information about emotional states inferred by AI must not reach the employer.

Is AI training mandatory for companies?

Yes. Article 4 of the AI Act has applied since 2 February 2025 and requires AI literacy measures appropriate to staff skills and to the context of use. No certification is required and there is no certifying body, but the company must own it and the training must be documented. A few hours with a structured plan are worth more than skills picked up informally.

Who is Castaldo Solutions, and who organised the session?

Castaldo Solutions is a technology consulting firm with its registered office in Milan and operations in Pavia, specialising in AI adoption for Italian SMEs of up to 50 employees. The working method is called CompanyTech BattlePlan and runs in 4 phases over 4 to 8 weeks. The 15 September 2026 session was organised together with Impulso Futuro, founded by Isabella Flecchia. The first step for a company is a free Pre-Assessment.

Tags

#ai-act #ai-literacy #ai-training #change-management
Gaetano Castaldo
Gaetano Castaldo Sole 24 Ore

Founder & CEO · Castaldo Solutions

Sono un consulente di trasformazione digitale con esperienza enterprise. Aiuto le PMI italiane ad adottare AI, CRM e architetture IT con risultati misurabili in 90 giorni.

Read also

Related articles you might find interesting

Mandatory AI Training for SMEs: The Checklist (and the Funds That Pay for It)
Training

Mandatory AI Training for SMEs: The Checklist (and the Funds That Pay for It)

No one chose AI: the market imposed it, through customers and competitors. But an employee using it without knowing what they are doing is a risk to themselves and the company. AI training has been mandatory by law since 2025, enforcement starts in August 2026, and in most cases it can be funded. Here is the checklist to get compliant and the funding channels.

24 Jul 2026 Read →

Is Your Company Ready for AI?

Take the free assessment: 5 minutes, 5 areas analyzed, personalized PDF report with concrete recommendations.

Find out how AI-ready you are

Free, no signup required