Futura AI
it
All articles
  • Method
  • Compliance

How to choose an AI consulting firm in Italy

Four types of providers, the signals that separate a real production system from a demo, and the AI Act and Legge 132/2025 obligations a serious provider needs to handle.

by Daniele Grotti6 min read
Futura AI — How to choose an AI consulting firm in Italy

Italy’s AI market reached €1.8 billion in 2025, up 50% on the previous year, according to the Politecnico di Milano’s Artificial Intelligence Observatory. Demand is growing faster than qualified supply: in the same period, only 8% of Italian small and medium enterprises had started an AI project. That gap is where both serious providers and less serious ones operate, and it’s rarely obvious from a first meeting which is which.

There is no official ranking of the “best” AI consulting firms in Italy, and I’d be wary of anyone presenting one as an objective fact. What does exist are verifiable criteria for telling apart a provider who has shipped systems into production from one who has shipped demos, and a regulatory framework — European, and now Italian too — that a competent provider needs to translate into your project, not just cite.

Four types of providers, not one

Four families of providers operate in Italy, and conflating them is the first mistake in vendor selection.

Large generalist consulting firms — the global consultancies with an AI practice — bring structured method, international coverage and the ability to govern complex, multi-workstream programs. The typical limit is distance from execution: the team that wins the pitch is rarely the one writing the code, and costs reflect the structure, not just the work on your specific case.

System integrators know how to connect an AI system to existing IT infrastructure — ERP, records management, identity management — better than anyone. They tend to treat AI as a technical component to slot into an architecture already decided, with less attention to how the process and the people using it actually change.

AI-specialist boutiques — the category we fall into — offer concentrated vertical expertise and speed: a small core that follows the project from analysis to release, without internal approval layers to cross. The mirror-image limit is scale: a program with dozens of parallel initiatives across continents needs a structure a boutique doesn’t have, by design.

Training and adoption firms leave internal capability behind, not just a working system. They’re the right choice when the primary goal is team autonomy, less so when you need custom development for a process with specific constraints.

None of the four is “the best” in absolute terms. The right question isn’t which type wins, but which answers your problem: a large-scale transformation program needs structure and governance; a specific process with a tight deadline needs speed and direct execution.

The signals that matter before signing

We’ve written about this in more detail elsewhere — what to ask an AI vendor before signing remains the more operational guide. In short, five signals separate a serious provider from one that just presents well:

A genuinely production system, not a pilot stalled for months, with a contact willing to answer what didn’t work as expected — it’s the most informative question, because every project has hit friction, and the answer reveals how the provider behaves when things get complicated.

A measurement method stated before the project starts, not an isolated percentage afterward. If a provider cites an accuracy figure without saying on what sample, with what metric definition, and how below-threshold cases are handled, that number isn’t verifiable yet — it’s a claim.

Regulatory competence built into the project from day one, not a chapter added at the end. This applies to the AI Act as much as to Italy’s Legge 132/2025, covered below.

Price transparency built on the actual process — volumes, integrations, security constraints — not a price list applied across different contexts.

Continuity after release: maintenance, threshold updates, adapting the system as data or regulation changes. An AI system isn’t static, and a provider who treats it as a project closed at handover is underestimating the real work.

The AI Act and Legge 132/2025: what a provider needs to handle

Regulation (EU) 2024/1689 has been in force since 1 August 2024 and applies in phases. The ban on unacceptable-risk practices has been operational since 2 February 2025. From 2 August 2025, the obligations for GPAI models apply. From 2 August 2026, the Article 50 transparency obligations apply, along with full supervision and penalty powers.

The timeline for high-risk systems was amended in July 2026 by the Digital Omnibus, the simplification package that deferred — not cancelled — the most demanding deadlines: obligations for Annex III systems move from 2 August 2026 to 2 December 2027, and those for Annex I from 2 August 2027 to 2 August 2028. Part of the high-risk systems already in use by public authorities keep a longer deadline, set at 2030. A provider who doesn’t know this distinction — which obligations are already in force and which were deferred, and to what date — can’t guide you through your system’s risk classification.

The penalties under Articles 99 and 101 of the Regulation are unchanged: up to €35 million or 7% of worldwide annual turnover (whichever is higher) for prohibited practices; up to €15 million or 3% for non-compliance with other obligations, including those on high-risk systems; up to €7.5 million or 1% for supplying false information to authorities. For SMEs and startups, the lower of the absolute amount and the percentage always applies.

On top of this sits a distinctly Italian layer. Law No. 132 of 23 September 2025 — in force since 10 October 2025 — is the first national law in Europe that integrates the EU Regulation with provisions specific to the Italian legal system. Article 22 designates two competent authorities with distinct roles: the Agency for Digital Italy (AgID), responsible for notification, evaluation and accreditation of conformity assessment bodies, and the National Cybersecurity Agency (ACN), which takes on market surveillance — including inspection and sanctioning powers — and acts as the single point of contact with EU institutions. Article 23 allocates up to €1 billion from the venture-capital support fund for startups and SMEs investing in AI. The Government has twelve months from entry into force — so until 10 October 2026 — to adopt the implementing legislative decrees; the Council of Ministers gave preliminary approval to two of them on 10 June 2026, covering governance and liability.

For a client evaluating a provider, the practical question is simple: can they explain how these two frameworks — European and Italian — apply to your specific case, with what risk classification, what documentation and what system registry? A provider who can’t answer leaves an area uncovered that creates concrete obligations, not just reputational risk.

Why we’re writing about this

We treat risk classification as the first step of every Assessment, not paperwork added at the end of a project — we go into the same level of detail in our AI Act whitepaper, which we update whenever the regulatory calendar changes, as it did with the Digital Omnibus. If you’re evaluating a provider, ask them the same thing: not what the AI Act says in general, but how they’d apply it to your process.

If you already have a specific process in mind, an AI Assessment is the most direct way to test it — two weeks for a process map, a feasibility assessment, and, if the case doesn’t hold up, a recommendation not to proceed.

If this topic touches a real process in your organization, evaluate it with a focused AI Assessment.

Request an AI Assessment