Artificial Intelligence

We assist businesses, public authorities, and developers in the compliant use and deployment of artificial intelligence systems: from system classification and governance to contracts and training.

It is the Firm’s fastest-growing practice area. Since 2024, there has been a European framework, the AI Act, and since 2025, a national law, Law 132/2025; obligations are being phased in through 2027, with some — including prohibitions and AI literacy requirements — already in force.

AI is not a standalone area of law: it cuts across data protection, intellectual property, liability, and security. We address it in an integrated manner, working with the Firm’s technology partners and distinguishing between what the law requires and what the model actually does.

What we do

  • Classification — role (provider, deployer, importer) and risk class of the system under the AI Act.
  • AI compliance and governance — internal policies, technical documentation, conformity assessments, organisational safeguards, and allocation of responsibilities.
  • AI literacy — AI literacy programmes pursuant to Art. 4 of the AI Act, for both technical and non-technical audiences.
  • Data protection & AI — legal basis, DPIAs, transparency, and data subject rights in systems processing personal data.
  • IP & AI — training data and the text and data mining exception, ownership and use of generated outputs.
  • AI contracts — supply, licensing, allocation of liability, indemnities, and warranties.
  • AI Act — Regulation (EU) 2024/1689. The first horizontal regulatory framework for AI, based on a risk-based approach. In force since August 2024; prohibited practices and AI literacy obligations since February 2025; obligations for general-purpose AI (GPAI) models since August 2025; high-risk systems from 2026 (Annex III) and 2027 (Annex I).
  • Law 132/2025 — Italy’s first law on AI. In force since October 2025, it establishes principles and delegates powers to the Government; it designates AgID and ACN as national authorities and sets rules for businesses, public authorities, professionals, and citizens.
  • GDPR — Regulation (EU) 2016/679. Legal basis, transparency, and impact assessments for systems processing personal data. See the Privacy and DPO practice.
  • Intellectual property — Directive (EU) 2019/790. The exceptions for text and data mining are central to the lawfulness of training; ownership of outputs remains an open issue. See the Copyright and Intellectual Property practice.
  • Liability. The rules governing liability for damage caused by products and AI systems complete the framework of obligations applicable to providers and users.

How we work

The greatest risk with AI is treating it as a matter of documentation-only compliance. We start by looking at what the system actually does and which data it uses, and then build the compliance framework around it: doing it the other way round simply produces useless paperwork.

Would you like to be contacted?


Contact information