Italian legal counsel · Technology & AI

Technology and artificial intelligence

Italian and EU legal advice for designing, acquiring and deploying digital and AI systems with coherent contracts, governance and accountability.

01 / Scope

Issues we address

Legal analysis begins with the operating facts. These are recurring questions, but scope and priorities are defined for each project.

  1. 01Determining AI Act roles and risk classification by reference to the actual intended use rather than generic product labels.
  2. 02Negotiating development, SaaS, cloud and licensing terms where data, models, outputs, service levels and third-party dependencies remain fluid.
  3. 03Coordinating AI governance, GDPR, cybersecurity, intellectual property and product liability in one decision-making framework.
  4. 04Responding to system changes, incidents, complaints or regulatory requests while preserving evidence and operational continuity.

02 / Services

Legal services

The work may cover one issue or coordinate several workstreams. Scope, assumptions and deliverables are agreed before the engagement.

AI Act governance

System and role mapping, risk classification, policies, records, instructions, human oversight and escalation processes.

Technology agreements

Drafting and negotiation of software development, SaaS, cloud, API, integration, maintenance, service-level and open-source terms.

Data and models

Contractual treatment of datasets, training, reuse, outputs, trade secrets, access rights and restrictions across the technology chain.

Intellectual property

Ownership of code and deliverables, licences, AI-assisted outputs, branding and protection of confidential know-how.

Liability and incidents

Risk allocation, notification processes, evidence preservation and coordination with privacy and cybersecurity workstreams.

Technology due diligence

Legal review of products, suppliers and technology assets for corporate transactions, partnerships and procurement.

03 / Framework

Essential legal framework

The applicable framework depends on the activity, parties and jurisdictions. The following sources are a starting point, not an exhaustive list.

Regulation (EU) 2024/1689

The AI Act follows a risk-based model and assigns different obligations and timelines to providers, deployers, importers and distributors.

GDPR and data law

Lawful basis, transparency, minimisation, impact assessment and automated decision-making remain relevant whenever personal data are involved.

Directive (EU) 2022/2555

Technology governance may need to align with NIS2 security, incident handling and supply-chain controls.

Copyright, software and trade secrets

Code, datasets, documentation and know-how require separate analysis of ownership, licences, exceptions and confidentiality.

04 / Method

A method built around the matter

The Firm combines legal analysis with an understanding of the operational context. Advice identifies assumptions, dependencies and decisions rather than presenting regulation in the abstract.

Map the facts

We identify the operating model, parties, documents, technologies, decisions and deadlines.

Define the framework

We distinguish binding duties, contractual choices, uncertainties and issues requiring technical input.

Set priorities

Options are presented with consequences, dependencies and a sequence that the organisation can execute.

Support execution

We assist with documents, negotiations, internal decisions and engagement with counterparties or authorities.

06 / FAQ

Frequently asked questions

Do all AI systems face the same obligations?

No. The analysis depends on whether the technology falls within the relevant definition, the organisation's role, the intended purpose and the risk level.

Is a standard SaaS agreement enough for an AI service?

Not necessarily. Inputs and outputs, model changes, metrics, audit rights, third-party dependencies, intellectual property, security and remedies require focused treatment.

Does AI Act compliance replace GDPR compliance?

No. The regimes interact but have different triggers and duties. Cybersecurity, consumer, product and sector-specific rules may also apply.

When should legal review begin?

Ideally before the model, architecture and principal contracts are fixed, so that requirements and responsibilities can be built into the project.

Discuss the Italian or EU dimension of your project.

Describe the activity, the decision to be made and any deadline. An initial exchange helps identify conflicts, scope and the information required. Sending an enquiry does not create a lawyer-client relationship.

Contact the Firm