Skip to main content
Resources · AI for SMEs

Before grafting AI, understand it.

Practical guides and deep-dives on how an Italian SME really adopts artificial intelligence: where to start, which departments, which sectors, which tools and which compliance controls. The questions you ask yourself before you choose — with cited answers, not slogans.

Where your SME sits on the AI-maturity curve
  1. Awareness

  2. Active

  3. Operational

  4. Systemic

  5. Transformational

Source: Gartner AI maturity model. Most Italian SMEs sit between Awareness and Active — the goal is not to reach the top, but to take the right next step.

All resources, by path

Topic paths

32 resources

Latest updates

  1. Publishing with AI in five languages: what actually breaks, and how you catch it before the reader does This site ships in Italian, English, French, Spanish and Dutch through an AI transcreation pipeline: here is the defect register that came out of it, with names and causes. Five real classes — the French verb that, on a legal subject, turns a statement of fact into something very close to an accusation; the substantive error propagated identically across all five languages because it sat upstream of the per-locale pass; datelines written in a format none of the five languages actually uses; the missing revision marker visible to the reader (that one is already fixed and in production); and the best of the lot, the only class where the copy is right and the code is wrong — two components searching the headline for the string "AI" and never finding "IA", leaving French and Spanish with a flat title while raising no error and leaving no translation key missing. Then the controls the localization industry already runs, any of which would have caught them: the MQM taxonomy with its seven dimensions across three severity levels, the structure underneath ISO 5060:2024 and ISO 11669:2024; back-translation, which is not round-trip machine translation but an independent linguist retranslating without ever having seen the original; the three-tier glossary enforced before the text reaches a reviewer, with a named owner and a review calendar; the 10% native-reviewer sample, raised on high-risk content instead of held flat; language-aware date, number and currency formatters, and pseudolocalization. It closes with a checklist ordered by risk and the rule that cost us most to skip: a pattern defect is closed on the repository, not on the file. 10 min read
  2. From 2 August you have to tell customers they are talking to an AI On 2 August 2026 the transparency obligations of article 50 of the EU AI Act start to bite, and most of what is being written about them is wrong: the Digital Omnibus — adopted by the European Parliament on 16 June and by the Council on 29 June 2026 — postponed the obligations on high-risk systems (Annex III to 2 December 2027, Annex I to 2 August 2028), not article 50. What the rule says paragraph by paragraph and, above all, who it binds: paragraph 1 falls on the provider, paragraph 4 on you, the deployer. The “unless this is obvious” exception, and the decisive one for text that has been through human editorial review with a named person responsible. The real arithmetic of the fines: article 99 runs up to 15 million or 3% of worldwide turnover, but for an SME paragraph 6 sets the cap at the lower figure — the 3%, not the 15 million everyone quotes at you. And the part almost nobody writes: disclosing AI costs nothing in itself, what costs is the timing and the framing of the disclosure — Luo's field experiment (2019, over 6,200 customers, purchases down more than 79.7% if you disclose before the interaction, the effect softened if you disclose after), the task dependence in Castelo (2019), the counter-evidence in Logg (2019) and the joint human-plus-AI framing in Ulqinaku (2025). With the AGCM investigations into DeepSeek, Mistral and NOVA AI closed with commitments on disclaimers, Legislative Decree 145/2007 for B2B claims, the Klarna case on automation promised and then walked back, and the list of what to do before 2 August. 11 min read
  3. The Italian SMEs already using AI (and what they built) While many still ask whether AI is ready for a small business, some Italian SMEs have already put it into production: T-Trade Group (39 people, an in-house AI assistant), DMM and FormBags on the factory floor. With data from the Politecnico di Milano observatory and Zucchetti, and why 76% of the field still being open is an opportunity, not a warning. 9 min read
  4. You don't need more AI: you need to redesign a department The reason almost no AI project reaches the P&L isn't the model: it's that companies gave everyone access to the tools without redesigning the processes around them. With data from Deloitte (State of AI in the Enterprise 2026), MIT NANDA (The GenAI Divide) and McKinsey (State of AI 2025) as third-party evidence of the gap, and why for an SME redesigning a single department is genuinely within reach today. 6 min read
Find your starting point

Which department should you start with?

Two questions, one tailored first graft: which department and which obstacle to tackle first — with the right playbook and the next step toward adoption.

The departments

  1. Sales →

    Sequenced follow-up and CRM hygiene: the high-frequency repetitive work. The negotiation stays with the human.

  2. Marketing →

    Content at volume with the brand voice under control and clear success criteria from day one.

  3. Operations →

    The monitor → catch the exception → act earlier loop, at high frequency. Not one-off decisions.

  4. Finance and administration →

    Reconciliations and dunning behind an audit gate: permissions, a human approval threshold, a complete trail.

  5. HR →

    Screening and routing with mandatory human review: no decision about people without a human signing it off.

  6. Customer support →

    Automated triage and first replies, with an agent on the delicate cases.

  7. Software development →

    The first review pass on pull requests and the test scaffolding: the whole cycle, not just completion in the editor. The merge call stays with the human.

The first obstacle

  1. Scattered or incomplete data

    We start from a map of the department’s sources: the first graft uses only the data that is already clean, the rest comes later.

  2. Limited in-house skills

    The playbook leaves behind an “AI owner” of one or two people. You do not need a data team: you need a method.

  3. Risk and compliance (EU AI Act)

    Every workflow is born with the governance block attached: DPIA, logs and human-in-the-loop wherever the risk calls for it.

    See the compliance overlay
  4. The team has little time

    We graft onto a single high-frequency case: value in weeks, not a transformation programme.

Take the AI readiness test — 2 min
1 · Which department do you want to start with?
2 · What is your first obstacle? (optional)
Start here

Method and roadmap: where to start

Before 'which tool do I buy' comes a journey. Here is the sequence: understanding where you are, choosing the first use case, and recognising who can really help you graft AI in — not sell you yet another tool.

  1. The first 90 days of AI adoption at an SME: a roadmap 'Which tool do I buy?' is the third question, not the first. First comes a journey, and the journey has a precise shape: the first 30 days for the foundations, the first 90 for momentum. A roadmap calibrated for the SME that brings together the three steps almost everyone gets wrong — weeks 1-2 knowing where you are (the readiness snapshot by domain, not an opaque number), weeks 3-6 a single use case with an owner who has a name, and the minimum controls from day 1 and not from day 90 (risk tier, DPIA, human in the loop, traceability). With the three checkpoints at 30/60/90 days and the reason why 29% of projects die in exactly this window. 10 min read
  2. Getting the team to adopt AI: how to overcome resistance to change in an SME The question every owner asks right after the one about cost: "I'll buy it, but will the team actually use it?". Adoption isn't a technology problem, it's a people problem — and the AI nobody uses has zero ROI, however good the demo. The three rational forms of resistance that stall adoption (the fear of being replaced, distrust of the tool, the cost of the new habit), why adoption is a curve you climb one stage at a time — resistance, curiosity, use, habit — and not a switch to flip, the manager's four levers that don't cost a licence (visible sponsorship, a quick win, "augmented not replaced" proven, an owner with a name) and why "we implement it" makes the change take root: implementation done well IS change management, not a separate activity that comes after. 11 min read
  3. How to measure the ROI of AI in an SME: a method, not a promise "Is it worth the spend? and how do I prove it?" is the question that matters more than any demo — and the one the market answers most confusingly. The ROI of AI isn't a figure to request from a vendor: it's a quantity you measure, and you only measure it well if you decide upfront what to look at. The method for an SME: the cost side in full (the TCO the demos don't show — not just the subscription, but integration, data, training, internal time, governance), the value side named and measurable (hours freed, errors avoided, cash timing, capacity without hires), and the three moves that separate a serious measurement from a feeling — choose the KPIs first, measure the baseline, then the delta. With the buy-versus-build payback ranges (one to six months against twelve to twenty-four), the return numbers read honestly, and the four mistakes that inflate the ROI or hide it. 11 min read
  4. How much does AI really return? 95% of pilots don't earn back — here's where the return is (and how long it takes) There's one number no vendor puts on a slide: according to MIT, roughly 95% of generative-AI pilots produce no measurable impact on the bottom line, and the PwC 2026 survey confirms 56% of CEOs see no return at all. It's not a problem of model quality — it's the "learning gap", the implementation divide. The honest ROI and payback expectations for an SME, from the cited numbers: where the return really concentrates (back-office and operations, not the sales chatbot, where half the budget goes), why buying succeeds twice as often as building (67% against 33%), the real payback times (Gartner: only 28% of initiatives fully earn back, 20% fail; Deloitte: just 6% with a return under a year; BCG: real ROI ~10% against the 20% expected — the honest frame is two to four years, not twelve months) and why cutting staff doesn't correlate with better returns. The reading that puts Innesti back at the centre: ROI isn't decided by the model, it's decided by the implementation. 10 min read
  5. AI adoption for SMEs: consultant, free course or playbook? How to choose The hard question isn't which tool, but whom to turn to. Three offers compete for the same SME budget — the free course that teaches but doesn't implement, traditional consulting read across its three tiers (and the four red flags of the bad kind), the ready-made playbook — and they occupy different moments of the same journey. How to recognise a serious engagement, the phased shape that works, and what you're really buying when you choose between building bespoke and grafting in a method that's already built. 9 min read
  6. Buy or build your AI? Choosing the platform for an SME Before 'which tool do I buy' comes a weightier question: is it better to buy a ready-made platform or build bespoke? The three axes you decide on (uniqueness, data sensitivity, strategic value), the volume threshold beyond which building pays off, and the hybrid that in 2026 is almost the standard — buy the model, graft in the logic. Then the landscape of tools you actually 'buy' with, read not by price list but by pricing model and stack: Make for cost per operation, Zapier for coverage, n8n for agentic depth and data control, Copilot Studio and Agentforce only if you already live in that world. 9 min read
  7. What a per-department AI Workflow Design contains: the anatomy of a playbook A serious AI-adoption playbook isn't a folder of slides: it has a recognisable structure. The two axes that hold it up — navigation by department versus phase, free catalogue versus maturity model — read through the two most instructive public templates (GitHub's playbook of pillars and 30/90/ongoing phases; Microsoft's five-level maturity model with its split of roles). And the skeleton calibrated for an SME: a department entry point, a phase for every use case, a one-or-two-person AI owner covering five functions, governance wired to the workflow. The five questions with which to judge any playbook put in front of you. 9 min read
  8. How to spot a credible AI proof: reading a vendor's case study (or ROI claim) before you sign A vendor shows you a polished case study or a "300% ROI" — how do you tell whether it's credible before you sign? The analyst's lens in seven points. Verifiability beats polish: blind-but-verified testimonials earn 60% trust against 64% for named ones — just four points — if the anonymous version offsets it with rich specifics (Edelman 2025 ranks the formats: primary research 70% > experts 64% > peers 62% > testimonials 55% > awards 42%). Why the numbers alone aren't enough: only 14% of CFOs see measurable AI impact and 71% think standard ROI metrics are ill-suited — the point isn't a bigger number, but stating how it was measured. The model to imitate (Forrester's Total Economic Impact: independent interviewer, customers live 6+ months, four-part model, risk-adjustment), the two flaws that sink a proof (no baseline/counterfactual, survivorship bias), the live reference call as proof stronger than a PDF, the evidence gap (67% of buyers have ruled out a vendor over untrustworthy proof) and the checklist for reading any AI proof before you sign. 10 min read
  9. Why the AI giants aren't calling your SME (and who is) Anthropic, OpenAI, Google DeepMind and Mistral sell to large enterprises through the Big Four and the big integrators, not to your company: seven dated deals (Anthropic × Deloitte with Claude to 470,000 people and 15,000 certified, October 2025; Accenture × OpenAI reselling the playbooks to clients; the forward-deployed engineering practices with Microsoft and Google/DeepMind; PwC and KPMG × Anthropic; Capgemini × Mistral) show the channel is the reseller, not the SME. The pricing keeps you out too: Claude's Enterprise plan starts at 20 seats, and the forward-deployed-engineer model — roughly $5.5 billion combined spend by Anthropic and OpenAI in May 2026 — is by explicit admission reserved for "marquee accounts", not the mid-market (Forbes, PYMNTS). From the SME side the gap shows: only 14% of small businesses have fully integrated AI, held back by privacy (50%), technical expertise (49%), tool selection (48%) and training (73%) — an implementation gap, not one of awareness (Goldman Sachs). Our reading: the giants feed large enterprises via integrators and embedded engineers, nobody productizes hands-on implementation for the SME — that's the seat an "innesto" implementation occupies, forward-deployed at the scale of a small company. 10 min read
  10. You don't need more AI: you need to redesign a department The reason almost no AI project reaches the P&L isn't the model: it's that companies gave everyone access to the tools without redesigning the processes around them. With data from Deloitte (State of AI in the Enterprise 2026), MIT NANDA (The GenAI Divide) and McKinsey (State of AI 2025) as third-party evidence of the gap, and why for an SME redesigning a single department is genuinely within reach today. 6 min read
  11. How to spot a design made by AI (and the questions to ask before you sign) Three agencies, three proposals, the same site: purple gradient, blurred glass, a headline a competitor could paste verbatim. It isn't copying: it's the default setting of a generative tool, and the cause is documented. Here is how to spot it at a glance, and eight questions to put to the vendor before you sign, none of which requires technical knowledge. 9 min read
  12. Publishing with AI in five languages: what actually breaks, and how you catch it before the reader does This site ships in Italian, English, French, Spanish and Dutch through an AI transcreation pipeline: here is the defect register that came out of it, with names and causes. Five real classes — the French verb that, on a legal subject, turns a statement of fact into something very close to an accusation; the substantive error propagated identically across all five languages because it sat upstream of the per-locale pass; datelines written in a format none of the five languages actually uses; the missing revision marker visible to the reader (that one is already fixed and in production); and the best of the lot, the only class where the copy is right and the code is wrong — two components searching the headline for the string "AI" and never finding "IA", leaving French and Spanish with a flat title while raising no error and leaving no translation key missing. Then the controls the localization industry already runs, any of which would have caught them: the MQM taxonomy with its seven dimensions across three severity levels, the structure underneath ISO 5060:2024 and ISO 11669:2024; back-translation, which is not round-trip machine translation but an independent linguist retranslating without ever having seen the original; the three-tier glossary enforced before the text reaches a reviewer, with a named owner and a review calendar; the 10% native-reviewer sample, raised on high-risk content instead of held flat; language-aware date, number and currency formatters, and pseudolocalization. It closes with a checklist ordered by risk and the rule that cost us most to skip: a pattern defect is closed on the repository, not on the file. 10 min read
Department by department

Where AI truly pays off, function by function

Adoption doesn't start 'from the company': it starts from a department. Where AI delivers a real return in sales, marketing, administration, operations, HR, support and legal — read honestly, with the numbers and with the copilot-versus-autonomy choice calibrated for the SME.

  1. AI in the SME development team: what actually works (and what doesn't) Software development is the department Innesti itself lives in: this site and our products are written, reviewed and shipped every day by a fleet of agents. In 2026 a small team can design, write, review and ship to production with a reach that six months ago took twice the people — stage by stage (code, review, testing, CI/CD, operations), with the real numbers underneath. One caveat that counts: measure the gain on your own work, not the demo — the METR study proves it — and start with augmentation before autonomy. 11 min read
  2. AI in SME marketing: where it truly pays off (and where it wears down the brand) Where AI in marketing delivers a real return and where it's still hype. The loops that work (budget optimisation, lead scoring, personalisation), the numbers read honestly, the figure that matters more than any ROI — the 29% of projects abandoned within 90 days — and the marketing-specific risk no demo shows you: brand-tone drift, with the countermeasure and the augmentation-versus-autonomy choice for an SME. 9 min read
  3. AI in SME administration and finance: what to really automate (and what never to leave running alone) Where AI in administration and finance delivers a real return for an SME — from accounts payable to the close and to forecasting — and where the promised return hasn't arrived yet. The most delicate case of all: an agent that can move money doesn't pass an audit without a human in the loop. The copilot-versus-autonomous-agent choice, the numbers read honestly, and the control an auditor asks for before ROI. 9 min read
  4. AI in SME operations: what to automate (and why to start small) Where AI in operations delivers a real return — stock replenishment, logistics exceptions, predictive maintenance, procurement intake — and why projects fail here more than anywhere else. The uncomfortable fact no demo shows: the vast majority of AI agents never reach production, and not for technical reasons. The scoping discipline — one monitoring loop only, then you extend — and choosing the tool in a market where pricing is opaque. 9 min read
  5. AI in HR and customer support at SMEs: where it pays off (and where it becomes a legal risk) The two departments that touch people directly — candidates and customers — are where AI promises the most and where a mistake costs the most. Where it truly pays off (screening and onboarding in HR, deflecting simple cases in support), the SME segment most underserved today, the numbers read honestly (support wins fast, HR is more uncertain) and — the trait that makes these two departments unlike any other — the highest legal bar of all: the precedent on liability for what a chatbot says and the high-risk classification of automated recruitment in the EU AI Act. With the copilot-versus-autonomy choice calibrated for an SME. 10 min read
  6. AI and the legal function: where AI invents a ruling that doesn't exist — and how to keep a filing defensible Legal is the department with the highest liability bar: here the way to fail isn't adoption, it's accuracy. From Mata v. Avianca (2023, citations invented by ChatGPT, attorneys sanctioned) to Stanford RegLab measuring an error rate of around 33% for Westlaw's AI research tool and over 17% for Lexis+ AI: even paid legal tools hallucinate at rates that matter. The US legal press has documented a wave of sanctions in 2026 for fake citations — a trend, reported and to be read with caution, not an independently verified fact. The resolution is governance: attorney supervision with independent verification of every citation (not “read for plausibility”, ABA Formal Opinion 512), the client-disclosure duty of Italy's Legge 132/2025 and the Consiglio Nazionale Forense template. Then the economics for an SME (enterprise tools like Harvey or CoCounsel stay too expensive; the viable band is Spellbook, Genie AI, TheLawGPT; contract review −80–85% of the time), the Italian market (55.3% of lawyers use AI per Censis–Cassa Forense; digital spend of professional practices is 2.01 billion) and where to start without putting a practice at risk. 10 min read
Sector by sector

The same AI, read for your sector

Adoption changes shape depending on what you do: those who produce have public incentives that co-fund the intervention, a professional practice already has AI bundled into its software and underuses it, a retailer has cheap, available tools but only one in four have really integrated them, and a firm that moves goods can't find staff — tens of thousands of workers short — and uses AI as a lever for capacity more than savings, and a builder is the sector most willing to invest yet doesn't trust the output yet — in construction the barrier isn't cost but trust — and a firm in agrifood has two different buyers, the field and the processor, and is the most subsidy-dependent sector of all, with the new Agriculture 4.0 credit as the hook. Here AI adoption re-read sector by sector, with the numbers and the right lever for each.

Sectors 9 min read

AI in SME manufacturing: the incentive before the pitch (Transizione 5.0 and voucher)

Manufacturing is the only sector where the State co-funds AI adoption: the iperammortamento 180% covers the software that makes an existing machine “intelligent”, and the Voucher Doppia Transizione 2026 (150 million, up to 70% of costs, applications from 8 July) addresses cost itself — the barrier 43% of companies cite first. How to start from the incentive and not from the tool, the pilot with the sharpest before/after (predictive maintenance −45% downtime and −25% costs, quality control), the numbers read honestly (44% at positive ROI within 12 months, but the majority stalls at PoC) and the Brescia lesson: you begin with ready-made tools, custom comes later.

Read the resource
  1. AI in professional practices: it's already in your software (and you're not using it) For an accountant or a labour consultant the AI question isn't “which tool do I buy”, but “why am I not using the one I already have”: the practice-management incumbents — TeamSystem, Zucchetti, Wolters Kluwer/Bluenext, DataLog — all shipped native AI features in 2025–2026, included in the subscription and largely switched off. 34.1% of practices already use it consistently (heading for 71.9% in three years) and ICT spend is worth 2.01 billion euro (+3%). The missing piece isn't the tool, it's the workflow around it: which features to switch on (accounting OCR, deadlines, triage), how to measure the hours freed, and why those hours, reinvested into higher-value advisory, are the real return — more revenue, not just efficiency. With compliance (EU AI Act, human oversight) wired to every flow. 9 min read
  2. AI in retail: 81% have tried it, 1 in 4 have integrated it (the gap is your opportunity) In retail the AI conversation almost always starts with cost — and it's the wrong diagnosis: the tools are cheap and available, often already inside the platforms you use. Only 15.7% of Italian SMEs use at least one AI technology (up from 7.7% in 2024, versus 53.1% of large firms), and 81% make some use of it but only 1 in 4 have integrated it into their workflows. That gap is Innesti's promise in one sentence: access isn't the problem, implementation is. Where it pays off (demand forecasting, personalization, service, in-store), how to pick a single workflow and take it past the pilot, and why the barrier isn't cost but the skill to integrate — with compliance (EU AI Act, customer data) attached to every workflow. 9 min read
  3. AI in logistics: only 27% have it in the TMS, the world is at 96% (and you're short 60,000 people) In logistics and transport the brake on AI isn't cost, nor a tool to buy: it's the labour you can't find. The sector is short of roughly 60,000 professionals, and while 96% of global transport leaders already use AI somewhere, in Italy only 27% have integrated it into their TMS — 3 companies in 10. Italian SMEs trail not just the large firms, but their own global competitors. Here AI isn't a luxury: it's the capacity lever that remains when hiring no longer suffices. Where it pays off (dynamic route planning, shipment tracking, forecasting inside the TMS, predictive fleet maintenance), why the 27-versus-96 gap is an advantage still available, and how to attach training and compliance (EU AI Act, human oversight) to every workflow. 10 min read
  4. AI in construction: 67% want to invest, 8% have — the brake is trust (and EdilIA is coming) Construction is the sector that wants to move and can't: 67% of building firms are willing to invest in AI and 51% consider it indispensable, yet real adoption is the lowest of all (9.7% EU consideration, 8% structured projects in Italy against 71% of large firms). The brake isn't cost, skills or staffing — it's trust: scepticism over the reliability of the output, in a sector that answers to clients and heritage authorities. Meanwhile the State is digitalising the permit itself (EdilIA, DPCM 2026, automatic response in 180 seconds via SPID; BIM mandatory on public tenders above 2 million euro from 2025), creating real urgency. How to start from the lowest-risk pilot to build trust (forecasting delays and variations, the digital building record), the four use cases read from the most controllable to the most regulated (permit verification on BIM/IFC, predictive maintenance) and why the human signature on the filing is what makes the result defensible. 9 min read
  5. AI in agrifood: 8% of the fields, 18% of the processors — and the new Agriculture 4.0 credit pays 40% Agrifood is the only sector with two different buyers: just 8% of farmers use AI, but in food processing that climbs to 18% and another 55% say they want to try it. And it's the most subsidy-dependent sector of all — barely 21% of farms would invest in smart or AI solutions without a public incentive. In 2026 the right hook arrives: the Agriculture 4.0 tax credit (2026 Budget Law) covers 40% of the spend, up to 1 million euro per firm, and it's written around software and data — AI adoption is directly the target of the credit, not an add-on. How to read Italian Agriculture 4.0 (a 2.5-billion market, +9%; 42% of firms with at least one smart solution but only 9% "mature"), the four use cases read from the closest to adoption (traceability and quality control for processors) to the furthest (AI in the open field), and the move no other sector shares: open on the credit, close on the sale to cooperatives and consortia, processors first then the fields. 10 min read
  6. The Italian SMEs already using AI (and what they built) While many still ask whether AI is ready for a small business, some Italian SMEs have already put it into production: T-Trade Group (39 people, an in-house AI assistant), DMM and FormBags on the factory floor. With data from the Politecnico di Milano observatory and Zucchetti, and why 76% of the field still being open is an opportunity, not a warning. 9 min read
Compliance

Rules and governance: doing it defensibly

Adopting AI without getting hurt by the AI Act, the GDPR and the Garante. What really changes for an SME, and the controls that make a use case defensible before an auditor or an incident, and how to vet the AI vendor you entrust with your data and processes.

  1. From 2 August you have to tell customers they are talking to an AI On 2 August 2026 the transparency obligations of article 50 of the EU AI Act start to bite, and most of what is being written about them is wrong: the Digital Omnibus — adopted by the European Parliament on 16 June and by the Council on 29 June 2026 — postponed the obligations on high-risk systems (Annex III to 2 December 2027, Annex I to 2 August 2028), not article 50. What the rule says paragraph by paragraph and, above all, who it binds: paragraph 1 falls on the provider, paragraph 4 on you, the deployer. The “unless this is obvious” exception, and the decisive one for text that has been through human editorial review with a named person responsible. The real arithmetic of the fines: article 99 runs up to 15 million or 3% of worldwide turnover, but for an SME paragraph 6 sets the cap at the lower figure — the 3%, not the 15 million everyone quotes at you. And the part almost nobody writes: disclosing AI costs nothing in itself, what costs is the timing and the framing of the disclosure — Luo's field experiment (2019, over 6,200 customers, purchases down more than 79.7% if you disclose before the interaction, the effect softened if you disclose after), the task dependence in Castelo (2019), the counter-evidence in Logg (2019) and the joint human-plus-AI framing in Ulqinaku (2025). With the AGCM investigations into DeepSeek, Mistral and NOVA AI closed with commitments on disclaimers, Legislative Decree 145/2007 for B2B claims, the Klarna case on automation promised and then walked back, and the list of what to do before 2 August. 11 min read
  2. AI governance in an SME: the controls that make a use case defensible Complying with the AI Act is one question; governing a use case so it holds up to an inspection, an incident or an auditor is another. The governance block that accompanies every workflow (risk tier → DPIA → labels → mitigations → oversight), why a 'standard' DPIA misses AI's own risks — opacity, drift, memorisation, the right to be forgotten — the MIT taxonomy as a shared vocabulary of risk, and the two operational controls that count more than all the written policy: human in the loop and traceability. 9 min read
  3. Is the AI vendor you're about to adopt trustworthy? SOC 2, ISO 42001 and what to ask before you sign Almost every AI tool an SME adopts is a third-party SaaS, often American, and the answer you get to "can we trust you?" is always the same: "we're SOC 2 Type II certified". But SOC 2 isn't a law, it's an AICPA attestation of security hygiene — and on AI it says almost nothing. What Type I and Type II really mean, the five questions to ask the vendor before you sign (does the scope name the AI features or only "the Platform"? is the model provider a declared subprocessor? does your data feed the training?), the three things SOC 2 will never tell you (bias, explainability, hallucinations), why the AI-specific standard to ask for is instead ISO/IEC 42001, and why in Italy SOC 2 replaces nothing under the GDPR or the AI Act — it counts only as one piece of the DPIA. 9 min read
  4. Is AI-written code secure? What the independent studies say — and what to put in the contract The serious risk of AI in development isn't the perceived quality of the code: it's security — and it isn't visible on delivery, it shows up months later, when the code is yours. The independent academic studies say three distinct things. Roughly 40% of 1,689 programs generated by Copilot across 89 scenarios contained a vulnerability (Pearce et al., "Asleep at the Keyboard?", IEEE S&P 2022). A model's refusals don't survive the working flow: the same 204 harmful prompts, refused 808 times out of 816 in direct chat, produced a harmful completion 816 times out of 816 once embedded in an ordinary multi-turn workflow in the editor (Kumar & Maple, Alan Turing Institute, 2026) — the protection sits at conversation level, the work happens at workflow level. And across 61,837 CI runs in 2,355 repositories, a higher frequency of AI-generated pull requests comes with lower workflow success rates: a correlation, not a cause. The five clauses to put in a supplier contract — who reviews and ahead of what, SAST and secret scanning as an obligation, who owns a vulnerability found after delivery, what the pipeline is allowed to execute, where your code ends up. 9 min read

From theory to your business. We graft AI in.

Want to know which department to start from in your company? Take the free assessment, or let's talk directly.

32
Operational AI guides, free and no sign-up
5
Languages localized across the EU

We use cookies and similar technologies to improve your experience, analyse traffic and personalise content.

Cookie preferences

Necessary cookies Always on

Essential for the site to work. They cannot be disabled.

They help us understand how you use the site so we can improve your experience.

Used to show you relevant ads and measure campaigns.

They let us personalise content and features.