On-premise, in your own environment
The AI runs on infrastructure you already control. Documents never cross the boundary of your network, and administration stays with your IT department.
Solutions · Data protection and perimeter
First you establish which data may sit where. Then you choose where the model runs. Never the other way round.
On 30 June 2026 the transitional tolerance in the ACN regulation on digital infrastructure and cloud services for the public administration expired: no public body may stay on infrastructure already in use while waiting to migrate. Art. 3 requires data and services to be classified as ordinary, critical or strategic; art. 17 then fixes the cloud qualification level allowed — at least QC2 for critical data, QC3 or QC4 for strategic data. A generic AI assistant that has never been through that qualification cannot process a critical case file, however encrypted the traffic.
For companies the calendar is NIS2. Legislative Decree 138/2024 requires the management body to approve the risk-management measures and oversee their implementation (art. 23), and sets the deadline for adopting them (art. 24): October 2026 for the first wave of registered entities, 31 July 2027 for those registered later. In an inspection what counts is not what you did, it is what you can show. And the documents that show it — security architectures, supplier contracts, continuity plans — are themselves know-how: Legislative Decree 63/2018, which rewrote arts. 98-99 of the Italian Industrial Property Code, protects a trade secret only where measures reasonably adequate to keep it secret exist.
Solutions
We apply the ACN criteria to every set of data an AI would touch: ordinary, critical, strategic. We check whether you fall inside the National Cybersecurity Perimeter or the NIS2 obligations, where the class of the data is set by law, not by internal judgement.
From the class follow the qualification level allowed and the place where the model may run. Both delivery modes remain available throughout: on-premise in your environment, or the CSIDIA dedicated cloud, with its data centre in Italy. Dedicated, closed AI, disconnected from the open web.
Dedicated agents compare the real binder against the required measures, item by item: they flag what is missing and propose the correction. No document leaves the perimeter, and sign-off stays with the legal or engineering department.
We also say where we stop. Documents under the secrecy classifications of Italian Law 124/2007 and EU classified information require accredited environments and personal security clearances that no commercial platform, ours included, replaces.
A typical case, not a real client. A mid-sized public body: 400 employees, eleven applications in use, four of them in the cloud. It wants to introduce an AI assistant to summarise case files and reports. Before looking at a single tool, one question has to be answered — the one the rules put first: of that data, which is ordinary, which is critical, which is strategic.
The art. 3 criteria are applied to every set of data the AI would touch, service by service: ordinary, critical, strategic, with the reasoning written next to it. Where the data falls inside the National Cybersecurity Perimeter or the NIS2 obligations, the class is set by law: it is not assessed, it is recorded.
For each class you write down where that data lives today: which application, which supplier, which qualification level, where the data centres are, who has access. Across eleven applications the map closes in a few days; the places to look hardest are the ancillary services — backup, mail, collaboration tools.
The comparison is mechanical: critical data may sit only on services qualified at least QC2, strategic data only on QC3 or QC4. Out comes the list of everything in the wrong place, each item with the reason, the reference and the date from which it has been so.
First what is non-compliant today, then what becomes non-compliant at the next deadline. For every item: what moves, where, by when, who signs. The AI runs where the class allows — on-premise in the body’s own environment, or on a dedicated cloud with a dedicated VPN, a data centre in Italy and staffed premises.
Against the body’s real binder every required measure has three possible answers: it is there and approved, it is there but was never approved, it is not there. For the third case a draft text arrives to be assessed. Whoever approves and signs it is the body’s legal or engineering department, not the system.
On this example, six weeks or so pass between the first meeting and the signed map, two of them spent purely on collection. That is an estimate on a typical case, not a promise. At the end the body knows — before an inspection asks — what it can evidence, what it cannot, in which order to close the gaps, and which documents stay out of reach of any commercial platform, ours included. No case file leaves the body’s perimeter.
An illustrative example on a typical case: the assumptions are recalibrated on your own data.
The AI runs on infrastructure you already control. Documents never cross the boundary of your network, and administration stays with your IT department.
An environment reserved for a single client, a dedicated VPN, a data centre resident in Italy, in premises we staff ourselves. Nothing is shared with other clients.
In both cases the models are dedicated and closed, disconnected from the open web: nothing they read feeds third-party services. They are open-weight models, with the weights archived inside the perimeter where they run: the version you use changes when you decide it does.
The class of the data has to be settled first. Art. 3 of the ACN cloud regulation splits data and services into ordinary, critical and strategic; art. 17 then sets the qualification level allowed: at least QC2 for critical data, QC3 or QC4 for strategic data. A service that has never been through that qualification cannot handle a critical file, however encrypted the traffic is.
The classification is applied to every set of data an AI would touch, with the reasoning written next to it. Where the data falls inside the National Cybersecurity Perimeter or the NIS duties, the class is set by law: it is recorded, not assessed. The class then determines the qualification level allowed and where the model may run.
There are two modes: on-premise in the environment you already control, or a dedicated cloud — an environment reserved for a single client, a dedicated VPN, a data centre resident in Italy, in premises we staff ourselves. In both cases the models are dedicated and closed, disconnected from the open web.
Italian Legislative Decree 63/2018 protects a trade secret only where reasonably adequate steps are taken to keep it secret. Keeping the processing inside the perimeter is one of those steps, but on its own it is not enough: it has to be described and traced — who has access, through which channel, where the document is stored.
Data covered by the Perimeter duties is classified strategic by law: the architecture is constrained from the start and the levels allowed are QC3 or QC4. We also say where we stop: material covered by the state secrecy classifications of Italian law 124/2007 and EU classified information require accredited environments and personal security clearances that no commercial platform, ours included, replaces.
Other solutions
Assisted document compliance AI governance and compliance Analysis of sensitive data
The first step
A real use case, on your data, in production. Then it grows, week after week.
It starts with a session with our engagement expert. Your data stays yours, always.