Compliance
Compliance.
European compliance is not a constraint to be endured: it is the reason the system is built this way. Several of these rules ask for evidence that can only be produced when the infrastructure is under the control of the party accountable for it.
GDPR
Data in the EU, processing compliant with Regulation (EU) 2016/679. Articles 24 and 32 ask for measures you can describe and demonstrate, not declare: keeping the processing inside a perimeter you control is one of those measures, and it makes others possible — your own logs, audits whenever you want, usage rules that do not change without going through you. On its own it is not compliance: it has to be described and traced — who has access, over which channel, where the document is stored. Privacy by design as an architectural requirement, not a checkbox.
NIS2
Native compliance with Directive (EU) 2022/2555, transposed in Italy by Legislative Decree 138/2024, for critical infrastructure and essential entities. Risk-management measures are demonstrated with documents: approved policies, registers, supplier contracts, records of the checks performed. The platform is engineered for regulated environments, and produces by itself the part of that record that concerns what it does.
AI Act
Regulation (EU) 2024/1689. Article 26(6) requires the deployer to keep the system logs “to the extent that such logs are under their control”, for at least six months: if the supplier does not hand them over, the duty cannot be met. Article 25(4) requires a written agreement setting out the information, capabilities and technical access needed for compliance. Article 4 requires AI literacy measures, and since 27 July 2026 Regulation (EU) 2026/1744 has rewritten it as a duty of means. The duty is calibrated on what you control: the perimeter is not an alternative to compliance, it is its precondition.
Dual-use
Activities subject to authorisation are carried out in accordance with applicable law, in Italy and abroad.
Where we stop
Italian Law 124/2007 restricts knowledge of state-secret material to those called to essential functions, within the limits their task requires; EU classified information, governed by Council Decision 2013/488/EU, may be handled only on accredited systems. No commercial platform — ours included — replaces a state-accredited environment and the personal clearances that grant access to it. Where the data demands it, the architecture is not chosen: it is inherited from the classification.
The duties that follow from it, obligation by obligation and deadline by deadline: the solutions
The full AI Act calendar, entry by date: the guide