
EU AI Act readiness consulting in Italy and across Europe. We establish what Regulation (EU) 2024/1689 actually requires of your organisation after the Digital Omnibus, classify your AI systems against it, and build governance your teams can run without standing up a compliance department.
Where the law stands today
The AI Act is not a single deadline. Some duties have been in force for a while, others arrive in stages, and the Digital Omnibus moved the heaviest ones without touching anything else. Reading that as a general reprieve is the expensive mistake, because the parts left alone are the ones already being enforced.
Which of those actually touches you depends on what your systems do, not on what your sector is called. Most organisations discover their real exposure only after an inventory, usually through a tool the business calls “the ATS” or “the scoring model we have always had”.
We maintain a separate, dated page with the full calendar, the state of the harmonised standards and the Italian framework, updated whenever something moves: EU AI Act: deadlines and current status.
What we do
EU AI Act, from strategy to implementation. We work on technical and operational adherence: analysis of the requirements, of the reference standards that apply to them, and of the evidence that shows the work was actually done. Legal opinions stay with your counsel.
Strategy first: the approach, before the checklist
Before any inventory, we agree what the AI Act means for this specific organisation: which parts of the business it touches, what the target operating model for AI should look like, what gets built internally and what gets bought, and which decisions belong to the board rather than to a project team. Compliance work that starts from a template produces a template. Compliance work that starts from a strategy produces something the business will still use in 2028.
Inventory: including the systems nobody registered
We build a working inventory of every AI system in use, in development, or arriving through a supplier. That includes models procured directly, tools built internally on LLM APIs, and the agentic features that enterprise platforms switch on through routine updates. Provenance, purpose, data access and action scope for each entry, because an inventory without those four fields is a list, and a list does not survive the first question from an auditor or a procurement team.
Risk classification as scoping, documented and defensible
Each system is scoped against Article 5 prohibitions, the Annex III categories, the Annex I product route, and the Article 50 transparency triggers. This is technical and operational scoping that tells you where the exposure sits and what work follows. Legal qualification of a borderline case stays with your counsel, and we prepare the file they need to make that call quickly. Where a system sits on a boundary, we record the reasoning and the named decision-maker rather than the conclusion alone. Classification that cannot be reconstructed six months later is classification you will do twice.
Requirements and reference standards
Compliance sits on two layers: what the Regulation requires, and which technical standard tells you how to satisfy it. The second layer is the unstable one right now, and it is where most of the confusion in the market comes from.
The second layer is the one that moves. What carries a presumption of conformity under Article 40 at any given moment is a question of what has been cited in the Official Journal, not of what has been approved, published, or sold to you as certified. We check that for your case instead of assuming it, and we keep the current state of the standards layer on a separate dated page rather than in this one.
Our work here is to read your obligations under Articles 9 to 15 and 17, identify which published standards you can already build against, and mark clearly where a requirement has no settled standard yet and a documented internal method is the honest answer. The published layer includes ISO/IEC 42001:2023 for the management system, ISO/IEC 23894:2023 for risk management guidance, ISO/IEC 42005:2025 for impact assessment, ISO/IEC 12792:2025 for transparency taxonomy, plus the sector layer where it applies, which in medical devices means ISO 13485, ISO 14971 and IEC 62304.
One correction worth making early, because it is sold often: an ISO/IEC 42001 certificate does not make an organisation AI Act compliant. It is a solid foundation and a good signal to a customer. EN 18286 is a separate document written for a different purpose, and treating the two as interchangeable stores up a problem for the conformity assessment.
Transparency: the obligations already running
Article 50 is the live obligation for most organisations. We map where synthetic content, conversational agents and AI-assisted publishing actually appear in your workflows, define the disclosure and marking approach, and set the operational rules with the teams that publish, so the duty survives contact with a content calendar. Where the marking duty for systems already on the market applies to you, that becomes a workstream with its own date and a named owner.
Governance, ownership and human oversight
A named owner with authority, an AI policy that people can follow, an intake process that classifies new systems before they go live, and human oversight designed as a real control rather than a paragraph. We align the structure to ISO/IEC 42001 where certification is a commercial objective, and keep it proportionate where it is not.
Technical documentation and the evidence trail
For anything classified high-risk, documentation work starts well before the obligation bites and matures toward whichever date applies to your route: risk management, data governance, logging, accuracy and robustness, human oversight measures, post-market monitoring. The requirements in Annex IV are stable, which is precisely why the documentation can be built while the standards layer is still settling around it. Waiting for the harmonised text before starting is how organisations lose a year.
Supply chain, contracts and the answers procurement wants
Article 25 obliges upstream providers to cooperate with downstream ones, and the Digital Omnibus put breaches of that duty in the 15 million euro or 3 percent penalty band. We check what your model and platform suppliers have actually committed to, what evidence they can produce, and what your contracts say about who carries the marking, documentation and oversight burden. The output is usually a short list of clauses to renegotiate and a reusable answer set for customer due diligence.
Who this is for
Digital health and life sciences. Where we are most at home. AI inside a medical device or an in-vitro diagnostic follows the Annex I route, with its own later date, an existing conformity assessment path and a notified body relationship that all have to be reconciled rather than duplicated. A hospital deploying diagnostic or triage support sits somewhere else in the Act again. MDR 2017/745, IVDR 2017/746, ISO 13485, ISO 14971 and IEC 62304 need to line up with the AI Act instead of running alongside it.
Deployers in Annex III territory. Recruitment and worker management, credit scoring and insurance pricing, education and vocational training, access to essential services, critical infrastructure, biometrics. Most organisations discover they are in scope only after the inventory, usually through a tool the business calls “the ATS” or “the scoring model we have always had”.
Manufacturers with AI inside other regulated products. Machinery, vehicles and the rest of the Annex I list, where the Digital Omnibus also narrowed the definition of safety component and moved the Machinery Regulation between Annex I sections. Both changes can alter whether a system is high-risk at all.
SMEs and small mid-caps. The Digital Omnibus extended AI Act relief measures to a new small mid-cap category: fewer than 750 employees and turnover up to 150 million euro or a balance sheet up to 129 million euro. Simplified documentation templates, proportionate quality management and priority sandbox access are worth checking against your actual figures.
R&I consortia with an AI component. Horizon Europe, Digital Europe, EIC and PNRR projects where the grant agreement, the ethics appraisal and the AI Act all have to agree with each other. This is where a compliance answer written in isolation tends to cost the project time it does not have.
Organisations already being asked. Procurement questionnaires, investor due diligence, insurance renewals, enterprise customer contracts. Commercial pressure arrives before regulatory pressure, and it is already here.
How the work runs
01 · MAP. A structured discovery across business units and suppliers produces the AI system inventory, with owner, purpose, data access and action scope for each system. You get a document you can hand to a board, a customer or an auditor.
02 · CLASSIFY. Each system is assessed against the prohibitions, the high-risk routes and the transparency triggers, with the reasoning recorded. The output is a gap list ordered by regulatory date and by commercial exposure, not by ease of execution.
03 · BUILD. Governance structure, ownership, intake process, transparency operating rules, technical documentation for high-risk systems, and the training that makes the Article 4 AI literacy obligation real rather than declared. We work with your teams and alongside your legal counsel.
04 · SUSTAIN. A pre-audit rehearsal against the questions auditors, customers and insurers actually ask, plus a regulatory watch that tells you when something in the calendar changes. The AI Act has moved once already. It will be interpreted continuously.
Why OneSynergy
You are not hiring a firm. You are hiring people. OneSynergy is the professional brand of Fulvio Domenico Marchetti and a network of senior independent specialists, each working under their own name and their own professional identity. No pyramid, no juniors learning the regulation on your engagement.
Inside the conformity machinery, not only alongside it. Fulvio Domenico Marchetti is currently project-managing the host institution of Italy’s first platform for conformity certification of high-risk AI systems under the AI Act. That work sits on the other side of the table from most consulting, because it concerns how conformity gets assessed, by whom, and against what. It is also why this page can tell you plainly that no harmonised standard carries a presumption of conformity yet, at a moment when certificates are being sold as though one did.
Regulation and funding in the same conversation. Most AI Act advisers do compliance. Most innovation consultants do funding. Projects break at the seam between the two, when a compliance answer contradicts a grant commitment or an ethics appraisal disagrees with a risk classification. Funding has been Fulvio Domenico Marchetti’s backbone for twenty-four years, with more than 20 million euro in EU and national funding designed, won and managed across FP7, Horizon 2020, Horizon Europe, EIT, Interreg, ESA and ERDF. Both sides stay in the same conversation instead of going to two suppliers who never speak to each other.
We work alongside legal counsel, not instead of it. Legal qualification of a borderline classification belongs to lawyers, and we say so on the first call. What we add is the strategic and operational layer that turns legal advice into something an organisation can actually run.
A published track record on this file. OneSynergy has been publishing on the AI Act since April 2026, from the months when the original high-risk deadline still stood, through the Omnibus agreement, the amending Regulation, the transparency layer under Article 50 and the governance gap in agentic AI deployments. The analysis is public and dated, so you can judge the reading before you buy the advice.
Turin, working across Europe. Italian context where it matters, and European reach where the client operates in more than one member state. The Italian layer is the awkward one. Law 132/2025 set up a national framework with its own authorities and its own implementing decrees, drafted against a European calendar that has since moved underneath them. Organisations operating in Italy have to read the national and the European layer together, and we keep the state of the Italian one on a separate dated page.
How to engage the network
One conversation to start. No intake form, no onboarding sequence. You speak with Fulvio Domenico Marchetti, once, and describe the situation as it actually is. That conversation is where the perimeter gets defined, and it costs nothing.
The perimeter is built around you. This page deliberately does not list a package. An organisation running forty AI systems across five countries and one with a single recruitment tool and an anxious procurement department need very different first months. What stays constant is the method: map, classify, build, sustain. What changes is the depth, the sequence and where you start.
Who actually turns up. Named senior professionals, selected for this specific problem, each working under their own name and their own professional identity. AI Act work rarely fits inside one head. It usually needs someone holding the strategy, someone technical on the model and data side, and real sector depth. The network composes that group for the assignment, from its own members and, where a competence is missing, from named specialists brought in for that engagement. It is composed for the assignment and released afterwards.
The objection worth raising first. A network of independent professionals invites a fair question: who answers for the result. One name stays for the whole engagement. The commitment is written before the work starts. Each professional carries their own name and their own professional standing into your project. And the limit, said plainly: if your procurement requires a single contracting counterparty of a certain size, a specific insurance profile, or several hundred person-days against a fixed deadline, a structured firm is the better answer for that piece of work. We would rather tell you on the first call than three weeks into it.
No agency margin. There is no pyramid to pay for, so the budget buys senior time instead of overhead.
A continuing presence, when a project is the wrong shape. Some organisations need a senior professional holding AI governance over time rather than a closed project: reviewing new systems as they arrive, keeping the documentation alive, absorbing the next regulatory change. It tends to be the right answer for anyone who has to reach their own high-risk date with a working internal capability instead of a folder of documents.
A seat in the consortium, for funded projects. Where the work belongs inside a Horizon Europe, Digital Europe, EIC or PNRR project, the network can join as a partner and carry the AI Act workstream from inside the consortium instead of advising it from the outside.
Start the conversation
Bring us the messy version. A rough list of AI systems, a procurement questionnaire you cannot answer, or a suspicion that something in the business is running without oversight.
Thirty minutes, no commitment, and you will leave the call knowing which obligations apply to you and which dates matter. If it turns into an engagement, the perimeter gets scoped in that same conversation. If it does not, you keep the map.
Talk to the network
Tell us which systems you are worried about and where you are in the process. The first conversation has no perimeter and no cost, and it ends with a plain answer on whether this is something we can help with.
If you prefer email, write to info@onesynergy.eu.
Not sure where you stand? Start with the free Digital Readiness Score, 23 questions, about ten minutes.
OneSynergy provides strategic, technical and operational support on the EU AI Act. We do not provide legal advice or legal compliance opinions, and we work alongside your legal counsel.
The full regulatory calendar, the state of the harmonised standards and the Italian framework are kept up to date on a separate page: EU AI Act: deadlines and current status.
