READ BEFORE YOU DECIDE
What bears on the decision in front of you.
Every piece is written to hold up in a decision, with its sources in plain view and its limits written out.
Ampliro Insights
New analysis in your inbox, roughly weekly.
Used only to send Ampliro Insights. More in the privacy policy.
RECENTLY PUBLISHED

Shadow AI is not a security threat to lock out
Shadow AI is described as a security threat, but 57 per cent of employees hide their AI use and almost half breach policy. A ban does not move the behaviour, it makes it invisible, and the duty already sits with the employer.
The practice9 min readAI Act Article 50: what actually has to be labelled
Article 50 has applied since 2 August 2026, and most people read AI labelling as meaning that anything AI touched has to be marked. The regulation is narrower: two of the five disclosure duties are the provider's, and the exemption for ordinary editing applies to that one. Three are left that are yours.
The rules8 min readWhat the DORA regulation requires of your provider's providers
The register of information under the DORA regulation tells you who your providers are. Since the summer of 2025 knowing is not enough, because an answer from your provider does not move the responsibility for what sits underneath.
Decision support6 min readA chief AI officer is countable. Who decides is not
76 per cent of organisations report having a chief AI officer. The appointment is the countable part, but it is the last three AI decisions that show who actually decides.
The practice6 min readFood manufacturing bought AI for language, not for production
The share of Swedish food producers using at least one AI technology went from 4.71 to 21.39 percent in two years. The share using AI for production processes fell over the same period, and that decides what the sector figure is worth to you.
Decision support8 min readWhat an AI readiness assessment measures, and what it must never claim
More than half of employees say they conceal their AI use. That turns every figure built on asking into a floor rather than a level, and it is the whole difference between a diagnosis and a score.
The rules10 min readWhich authority supervises the AI Act in Sweden
Sweden has divided the AI Act between five authorities. The split follows the point numbers in Annex III rather than industry, which is why schools and waterworks got the same regulator.
The rules9 min readWho NIS2 covers in Sweden, and who decides it
NIS2 scope in Sweden is settled by six provisions, and the assessment rests on the operator itself. The size threshold moves in both directions, and essential or important answers another question.
The technology9 min readWhy last year's benchmark figure cannot be compared with this year's
The model releases got the attention. Meanwhile almost every serious measurer published a correction to its own instrument, and one withdrew its measure entirely. That decides how a vendor's figure should be read.
The rules7 min readWho reports what when NIS2, DORA and the AI Act overlap
Sweden's Cybersecurity Act exempts firms covered by DORA from incident reporting altogether. The two cyber clocks therefore never start together, and what remains is the deadline nobody gave an outer limit.
The rules5 min readThe DORA register lists your AI without calling it AI
The DORA register covers every contractual arrangement for an ICT service and never asks whether the service uses AI. That is why it holds more of your AI than an inventory that goes looking for AI.
The practice7 min readTwo reporting clocks start when an AI system fails in critical infrastructure
The AI Act allows two days rather than fifteen when a serious incident disrupts critical infrastructure. The obligation is the provider's, but the clock can start running the moment your control room understood what had happened.
The technology9 min readWhen an AI agent is ready for production, and when a rule is enough
A benchmark saying an AI agent can do the task answers the wrong question. The question that decides the cost is how often it does, and there is a measure for that.
The rules7 min readThe Machinery Directive is going. What governs the AI inside
A machine with AI inside looked as though it carried two sets of requirements. Since late July the Machinery Directive and its successor decide alone, and the rules replacing the others are not written yet.
The practice8 min readWhat actually stops AI in healthcare, and which deadline now applies
The guidance the medtech sector cites most often gives 2 August 2027. That date no longer holds. And the obstacle healthcare regions actually report is neither the regulator nor the technology.
Decision support9 min readEurope has caught up on adoption. It has not caught up on use
The share of firms that have adopted generative AI is now effectively the same in the EU as in the US. The share using it in more than two activities is not. The difference is not the technology but how many people can use it, and that is also what is left of Article 4 after this summer's amendment.
The rules9 min readThe EU AI Act high-risk deadline moved. Four things did not
The EU AI Act's high-risk regime moved to 2027 and 2028 in an amendment that took effect this month. A plain reading of what moved, what did not, and which duties still land on 2 August.
The practice6 min readWho from the union was there when the digital system arrived
In Sweden 88 percent say employees should be involved when new technology is introduced. A Swedish union has measured what actually happens, and the distance between the two is not a matter of opinion.
The technology5 min readMachine logs can be analysed before the integration is built
A language model was run across 16,316 maintenance logs and corrected the maintenance type on one record in four. The logs carried the answer all along; the summaries built from them did not, and that is the difference between owning data and having asked it anything.
Decision support5 min readWho gets the hour AI saves
71 percent of in-house counsel expect their outside firms to change commercial models. 28 percent of law firms have changed pricing in response to AI, and in that distance it gets decided whether the gain becomes a discount or a margin.
The practice8 min readWhich AI tools are actually being used, and where that shows
You do not need to ask which AI tools are being used. The answer is already in the licence data, and it says something uncomfortable: over a third of licences sit unused while AI spend grows faster than anything else.
Decision support10 min readWho decides whether the data may sit with an American provider
The CLOUD Act follows the provider's control over the data, not the address of the server. What decides the question is not the American statute but which of your own rules is the strictest.
Decision support9 min readAI is no longer a licence cost. It is a consumption nobody owns
A licence per person is predictable by construction. A consumption cost is unpredictable for the same reason. Most organisations budgeted the second in the mould of the first, and find out once the money is already spent. The question is not which model is cheapest, but what a finished task costs in your organisation and who owns that line.
The rules11 min readWhat the protective security analysis must say about AI tools
The content requirement is not in the Act. The ordinance says what the analysis must identify, the agency regulations list the steps, and which regulation applies depends on who supervises you.
The practice8 min readDo you know whether your AI programme worked, and what would show it
Adoption is no longer the question. A third of Nordic organisations have AI in production across the business. But a quarter have no formal metrics, and then nothing can answer whether it got better.
Decision support9 min readThe most expensive AI project is the one that never got a no
The figure that 95 per cent of AI programmes return nothing currently carries half the market's argument. It cannot bear that weight. The conclusion it is used for is still broadly right, for a better reason.
Decision support9 min readIs AI banned in security-sensitive work, and what do the rules actually say
The assumption that AI is banned in security-sensitive work is false. Sweden's Security Service writes the opposite: its use will become necessary. What exists are separation requirements, and they follow the classification.
The rules8 min readDoes AI have to be procured, and what actually decides it in Sweden
The Public Procurement Act lists six procedures exhaustively, and none of them is tied to a technology. What decides whether a purchase must be advertised is its value. Yet most pilots are stopped by a legal uncertainty that is not there.
ALSO HERE
The words these pieces use.
The analysis above is written in the Act's own vocabulary: provider and deployer, high-risk system, presumption of conformity. Terms explains thirty-four of them, with what they get confused with, where they sit in the regulation, and the decision each one leads to.
Ampliro Insights
New analysis, roughly weekly.
We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.
We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.