ACN cloud rules: past the 30 June 2026 deadline, critical data is non-compliant
7 min read
30 June 2026 passed three weeks ago. From that date, says Article 11(10) of the Regulation on digital infrastructures and cloud services for the public administration (Italy’s National Cybersecurity Agency, ACN, Director General’s determination of 27 June 2024, in force since 1 August 2024), no public body may keep processing its data on infrastructure “already in use” while it finishes migrating: the transitional tolerance has expired for everyone, no exceptions. Anyone right now evaluating a cloud AI assistant to summarise case files, confidential reports or registry records — or worse, who already has one in production — must answer a question that comes before any technical evaluation: is that service qualified for the classification level of the data it is about to handle? If the answer is no, and the data is not “ordinary”, the body is non-compliant today, not in a year. The underlying thesis is simple and uncomfortable: for this kind of data, the law predetermines the architecture. It is not the IT department that chooses where a model runs — it is the data’s classification that decides it, before any model is chosen at all.
The three regimes that decide where data can sit
Article 3 of the ACN Regulation — adopted under Article 33-septies(4) of Decree-Law no. 179 of 18 October 2012 (converted, with amendments, by Law no. 221 of 17 December 2012), a function that Decree-Law no. 82 of 14 June 2021 (converted by Law no. 109 of 4 August 2021), Article 7(1)(m) and (m-ter), assigned to ACN together with the qualification of cloud services for the public administration — requires every public body to classify its data and digital services into three classes: ordinary, where compromise causes no material harm; critical, where compromise could harm functions relevant to society, health, public safety or the country’s economic wellbeing; strategic, where compromise could harm national security. This is not left to the body’s discretion: data subject to the obligations of Decree-Law no. 105 of 21 September 2019 (converted by Law no. 133 of 18 November 2019, the National Cybersecurity Perimeter) is classified “strategic” by operation of law; data subject to Legislative Decree no. 65 of 18 May 2018 (the NIS implementation) is “critical” or “strategic” depending on its national relevance. A body inside the Perimeter that only now discovers it must classify its systems is not discovering a new obligation — it has had it since that data first existed.
The qualification level is not an IT footnote
Article 17 splits cloud services offered by private providers into four qualification levels (QC1-QC4), scaled to cyber risk and sector standards. Paragraph 4 closes off any room for interpretation: critical data may only be delivered through services qualified at least QC2; strategic data only through QC3 or QC4. A generic AI assistant — however good on the benchmarks, however reassuring the contract — that has never gone through this qualification process is, by definition, below QC1: it cannot lawfully process a critical case file, no matter how encrypted the traffic is. And for strategic data, Annex 2 of the Regulation adds a requirement that is pure jurisdictional sovereignty written into a technical schedule: every request for data access by a non-EU entity must be reported to ACN and granted only after explicit authorisation from the public body; metadata must be processed on infrastructure within EU territory. This is not a “sovereigntist” preference: it is a compliance requirement that no non-EU provider, however capable, can meet by contract — it can only declare that it meets it, which is a different thing entirely.
When data is classified, cloud is not even the right question
There is then a level the ACN Regulation does not touch at all, because it lives under a different body of law. Law no. 124 of 3 August 2007 reserves state secret status (Article 39) for acts, documents and information whose disclosure would harm the integrity of the state: knowledge of them is restricted “exclusively” to those called to perform essential functions, within the limits indispensable to their task (Article 39(2)). Article 42 sets out four secrecy classifications — segretissimo, segreto, riservatissimo, riservato (top secret, secret, very confidential, confidential) — assigned to restrict access to those cleared by institutional function, not by rank. No commercial chatbot, no SaaS product however qualified at QC4, can ever be the recipient of a classified document: this is not a technical security problem — access itself is legally barred to anyone without the required personal clearance. The same holds, at EU level, for EU classified information (EUCI) governed by Council Decision 2013/488/EU: four levels — from RESTREINT UE/EU RESTRICTED to TRÈS SECRET UE/EU TOP SECRET — that may only be processed on accredited communication and information systems (CIS), never on generic commercial infrastructure. Telling these three regimes apart is not a lawyer’s nicety: a body that processes a critical case file on unqualified AI is in administrative breach; one that uploads a classified document into a commercial chatbot may be committing an offence of an entirely different order.
Closing the gap by design
The thread linking ACN qualification, the Perimeter and the classified-information regime is the same one: for this data, the architecture is not chosen, it is inherited from the classification. Anyone designing AI adoption by starting from the model — “let’s take the best available LLM and work out how to secure it afterwards” — is building something their own legal system will never let them put into production on critical or strategic data, as the Palantir FedStart case shows: even the most mature accreditation ecosystem in the world starts from the data’s legal perimeter, not from the product. That is why we work backwards: first the data classification under ACN’s criteria, then the architecture that class requires. For ordinary and critical data, the answer is a dedicated, closed AI, disconnected from the open web, in two modes: on-premise, installed in the client’s own environment; or CSIDIA’s dedicated cloud — an environment reserved for the single client, accessed via a dedicated VPN, with the data centre resident in Italy, in premises we directly guard — never with the non-EU access the Regulation prohibits for strategic data. For state secrets and EUCI, technical honesty requires saying it plainly: no commercial platform, including ours, is a substitute for a state-accredited environment. That is the principle our platform is built on: knowing which of the three regimes you are designing for, before writing a single line of configuration.
What to do now
- Classify before choosing a vendor: apply the criteria in Article 3 of the ACN Regulation to every dataset an AI would touch, before looking at a single commercial demo.
- Check the vendor’s QC level on the ACN catalogue, not on the brochure: a service that is not in the catalogue is, for the purposes of the Regulation, unqualified.
- Check whether you fall inside the Cybersecurity Perimeter or under NIS obligations: if so, your data is already “critical” or “strategic” by law, not by your own assessment.
- Do not conflate the regimes: a critical case file needs a qualified cloud; a classified document needs personal clearance and an accredited environment — two different problems, with two different solutions.
Want to know which of the three regimes your data actually falls under, and which architecture the law requires as a result? Half an hour with one of our experts for the first map.
Sources
- Regulation on digital infrastructures and cloud services for the public administration — National Cybersecurity Agency, 27 June 2024 (acn.gov.it)
- Law no. 124 of 3 August 2007 — Intelligence system for the security of the Republic and new rules on secrecy (Normattiva)
- Decree-Law no. 105 of 21 September 2019 — National Cybersecurity Perimeter (Normattiva)
- Council Decision 2013/488/EU — security rules for protecting EU classified information (EUR-Lex)