Why was ZenIA created?
The question is no longer whether to adopt AI, but how to do so while remaining in control.
The issue is no longer whether to adopt Artificial Intelligence in one’s processes, but how to do so without losing control over data, accountability, and compliance. The requirements are clear: less time spent on repetitive tasks involving certified email (PEC), document registration, routing, and retrieval; fewer formal and substantive errors in official documents, procedures, and classifications; and demonstrable compliance with the AI Act, Law 132/2025, AgID Guidelines, GDPR, CAD, and NIS2/ACN.
ZenIA was created to address these needs within ZenShare UP—Interzen’s cloud-native platform for automating processes in public and private enterprises. AI enhances the value of modules already in use (such as digital records management, document management, BPM workflows, long-term archiving, and digital signatures) within organizations’ actual processes, leveraging data, permissions, and operation logs already managed by ZenShare UP.
What is ZenIA?
Three non-negotiable criteria
Three non-negotiable criteria
Coordination, rules, the operations log, and consumption monitoring remain within the platform; language models (LLMs) are external, replaceable services with no direct access to the organization's data.
Compliant from the design stage
Compliance is not an obligation added downstream, but an architectural constraint present from the system's inception.
The operator remains in control.
Human oversight of every decision, with AI autonomy limited to the L3 level defined by AgID: the artificial intelligence makes proposals, while the human makes the decision.
Guiding principles ZenIA
AI governance remains at the center.
AI is part of the platform's controlled processes, never an autonomous component: ZenShare UP understands the procedures, documents, regulations, and the AI itself.
Governance separated from models
Coordination, rules, the operations log, and consumption tracking remain internal; language models are external, interchangeable services with no direct access to the organization's data.
The person at the center
Effective, timely, and documented human oversight: control points, and the ability to make corrections and halt operations. Maximum autonomy at Level 3, while Levels 4 and 5 are excluded by design.
Replaceable components
Agents, as well as cognitive and motor tools, evolve and are replaced without affecting processes and data—eliminating dependence on a single vendor or specific hardware.
Zero-trust security
Security by design, least privilege, data minimization; defense against typical AI attacks (malicious instructions, data poisoning). No ungoverned instructions to the models.
Economic and environmental sustainability
Measurement of consumption by organization and use case, thresholds and limits, and model selection based on cost and quality: models scaled to the purpose, including small-scale ones.
Regulations on Artificial Intelligence
What requirements must an AI meet within an organization
Adopting artificial intelligence within an organization is not merely a technological choice; European and national regulations establish precise requirements regarding human oversight, transparency, traceability, and data protection that every AI system must meet—and that the organization must be able to demonstrate it complies with.
Regulation (EU) 2024/1689 applies to all Artificial Intelligence systems. It classifies systems by risk level (minimal, limited, high, prohibited) and mandates automatic event logging, transparency for system users, effective human oversight, and the provision of information to those interacting with the AI.
They define the reference architecture (orchestrator, agents, tools, models, data) and the levels of autonomy from L0 to L5: ZenIA stops at L3, with levels L4 and L5 excluded. A seven-phase lifecycle and four profiles—ranging from basic operator to controller—are also included.
Each organization maintains its own rules: an internal policy on AI usage and a register of systems in use; risk classification for each use case (including a DPIA and, in cases of high risk, an FRIA); and the roles of those who approve AI proposals and those accountable for the decision.
In addition to these, there are Law 132/2025 on artificial intelligence (centrality of the individual, Art. 3), the GDPR, the CAD, and the NIS2/ACN regulations.
In ZenIA, AI is governed by design: compliance is integrated from the design stage, not added as an afterthought.
The catalogue
A catalog of 27 use cases, spanning two key areas.
FOR THE END USER
Assistants integrated into the modules, designed for officials, executives, project managers (RUPs), and citizens: records management and document handling, knowledge and search, compliance, assisted drafting, procedures and workflows, decision-making and data analysis, procurement, and citizen services.
FOR IMPLEMENTATION AT THE ORGANIZATION (DELIVERY)
Supporting those implementing ZenShare UP within the organization: configuration and customization, data migration, integrations, training and documentation, and software development.
Records management and document handling, knowledge and research, assisted drafting, configuration and migration
Records management and document handling, knowledge and research, assisted drafting, configuration and migration
Decision-making and data analysis, citizen services, featuring predictive and conversational capabilities.
The use case is developed in collaboration with the organization, using the ZenIA Use Case Sheet (Assessment).
01
✓ Problem to solve and KPI to improve
✓ Is there an intervention in proceedings? Effects on third parties?
✓ Data processed: personal, special category, judicial
✓ Role of AI: assistance, recommendation, automation, generation
✓ AI Act risk level
✓ Who approves at the checkpoint, who is responsible
02
specifications
✓ Customer problem
✓ Need
✓ Business objective and technical objective of the agent
✓ Viable solution: the use case flow
✓ Expected and measurable benefits
03
Assessment
✓ Compliance and regulations
✓ Data
✓ Infrastructure and cloud
✓ Safety
✓ AI Governance
✓ Procedures and use cases
✓ Economic aspects
04
process specifications
✓ End-to-end process and step sheet
✓ Human-in-the-loop and limits of autonomy
✓ Chain agent → specializer → engine
✓ Data scope and permissions
✓ Compliance, audits, and traceability
✓ Risks and mitigations
The agent decides which action to perform, the specialist provides the cognitive expertise, the engine is the underlying technology. No call escapes the Control Plane: every step is traced on audit and can be reconstructed during the inspection.
Protocol Assistant use case: first it recognizes the procedure, then it proposes the classification.
Via PEC. The assistant recognizes its nature and analyzes the content and attachments.
Identify which of the organization's administrative procedures—among those mapped in the Governance area—the document belongs to.
The classification scheme derives from the process: a deterministic association, by rule. It extracts the metadata and proposes the file.
Arranges for registration and proposes the competent office and the assignee.
The operator verifies, corrects if necessary, and confirms: the AI proposes, the official decides.
Why start with the administrative process. The functioning of any organization relies on administrative processes, which—by law (Law 241/1990)—have a defined structure comprising a designated officer, specific stages, deadlines, and formal acts. In ZenShare UP, processes are mapped within the Governance area and linked to a specific classification category; once the process is identified, classification is no longer an AI estimate but a definitive, verifiable organizational rule applied consistently by all staff. This is where AI delivers the greatest value with the least risk.
- Reason: every AI proposal explains the reason why.
- Traceability: everything recorded and verifiable.
- Control: human confirmation before any effect.
- Perimeter: data and documents remain within the organization.
BPMN Generation Use Case: from process mapping to automatically generated workflows and web forms.
01. Starting point
- Procedure Section: subject matter, officer in charge, timeframes, acts, and documents requested and produced.
- Procedure Section: operational steps, phases (initiation, preliminary review, decision-making, supplementary), offices involved, controls.
02. ZenIA interprets and generates
- Domain agent: reads the mapping and breaks it down into steps, decisions, and responsibilities.
- Cognitive tools: verify consistency and completeness against organizational rules.
03. Generated result
- BPMN 2.0 flow: activities, decisions, swimlanes, approval processes.
- Linked web forms: fields, constraints, conditional logic, process variables, and document metadata.
04. Manual finalization
- Review and correction: the person responsible for configuration checks the proposed workflow and webforms, adapts them, and approves them.
- Publication: the proceeding is ready for implementation.
- Less modeling time: the initial design of the flow and webforms is ready in hours, not days.
- Consistency guaranteed: the mapped process and the executed workflow match.
- Alignment with the analysis: the workflow stems from the analysis and mapping shared with the organization.
- Faster startup: the organization becomes operational sooner, with fewer configuration errors.
In summary
AI proposes, the person decides
Orchestration, policies, auditing, and metering remain within ZenShare UP; the LLMs are external, replaceable, and have no direct access to the data.
AI Act, Law 132/2025, AgID Guidelines, GDPR, CAD, and NIS2/ACN as foundational architectural constraints.
27 use cases for real organizational processes: less time, fewer errors, demonstrable compliance.