Skip to content
The same city office building in summer, seen from across the street in a long exposure, the people on the pavement passing as soft streaks.

WHERE THE EXPOSURE DIFFERS

Same rulebook. Nine different answers.

Each sector page starts from what is actually true where you work: which duties apply, which do not, and what it takes to get AI into daily use. Pick yours, or start with a conversation about what you run.

WHY WE SPLIT IT UP

The rulebook is the same. The exposure is not.

Two organisations can run almost identical technology and still carry entirely different duties, because the EU AI Act classifies by area of use rather than by how advanced the system is. A scoring model for mortgages is high-risk. The transaction monitoring next to it is not.

So each sector page is written as a boundary rather than a brochure: what actually reaches you, what does not, and where the money and the time go. Half of our work in a regulated sector is telling you what you can stop worrying about.

What differs between sectors is the exposure, not the method. The capabilities are the same across all nine: the assessment, the strategy, the competence, the implementation, the adoption, the automation, the governance and the fractional leadership. The sector decides where you should start and what can wait.

If your sector is not here, it does not mean we do not work there. It means we have no particular insight to offer yet, and we would rather say so.

WHERE WE WORK

01

Public & social sector

Swedish public organisations are not short of AI reports, pilots and ambitions. What's missing is AI in operation: integrated with the systems your people work in, governed, and owned by you. That is the part we do. Fixed price, fixed scope, and typically procurable by direct award.

02

Financial services

Banks, insurers and fintechs run more AI than their inventories show, often inside vendor systems. The new rules don't fold into the Digital Operational Resilience Act (DORA) or the General Data Protection Regulation (GDPR). They ask different questions. We help you find what you run, classify what matters, and build governance your supervisor recognises.

03

Defence & security

For defence suppliers and the companies now entering the supply chain: AI as decision support, standing where your security analysis says it may stand, owned by you at handover. Delivered personally by our founder, because in this sector, few hands is the point.

04

Life sciences & healthcare

Nordic units of pharma and medtech groups, and clinics that can decide for themselves: we take AI from validated model to daily use, with the device rules, the AI rules, data protection and patient safety read together. Because that is exactly where projects die.

05

Associations & member organisations

Swedish unemployment funds are urged toward AI-based controls by their supervisor, straight into the precedent that ended a Swedish national agency's system. Unions face duties that already exist and are already passed by. We work at exactly this intersection: the partner model, the members' data, and the AI rules.

06

Energy & infrastructure

Municipal energy companies, grid owners, water utilities and district heating: we classify your systems with the primary law in hand, free the investments fear has frozen, and design the one thing no rulebook coordinates for you: an incident process that survives both clocks.

07

Industrial & manufacturing

Mid-size manufacturers and Swedish units of industrial groups: we take AI from promising pilot into daily use, as decision support built on your own data, machine logs included. Never monitoring, never control of your operation. And we will tell you something most suppliers won't: the heavy AI rules barely touch your factory.

08

Professional services

For mid-size law, audit and accounting practices, engineering consultancies, architects and agencies: this is a business-model question before it is a technology question, and it deserves a management conversation, not another pilot. AI that respects client confidentiality by design, built on the firm's own archive, owned by the firm.

09

Consumer goods & food production

For Swedish units of international food and consumer goods groups: forecasting, planning, quality and documentation that measurably improve, built on your own data, integrated into the systems you already run, owned by you. And we will start with the honest part: the AI rules you keep hearing about barely apply here.

ACROSS BORDERS

Nordic units of international groups

Some questions do not belong to a sector. Under the EU AI Act the duties follow the entity that deploys the system, not the group. If your AI decisions arrive from headquarters, they still land on your Swedish legal entity, and more is yours to decide than the deck admits.

What is already decided

The tools, the licences and the group policy. Worth reading closely before you plan around them.

What is still yours

The workflows, the data, the local legal sequence before go-live, and the order you adopt in.

QUESTIONS

Before you pick a sector.

The EU AI Act classifies by area of use rather than by industry, so the question has no clean sector answer. The heaviest duties still cluster where the Annex III areas are common: creditworthiness assessment of individuals and pricing in life and health insurance, recruitment and selection, education, essential services and law enforcement. The Annex III requirements apply from 2 December 2027, and Annex I, meaning AI embedded in products, from 2 August 2028.

Yes. The nine sector pages are the ones where Ampliro has something particular to say, not the boundary of where we work. The method is the same everywhere: establish what you actually run, settle what is worth building, and hand it over to your own people. A missing page only means we will not pretend to an insight we do not have.

No, not automatically. Being supervised by a financial, medicines or data protection authority does not decide the classification under the EU AI Act: the area of use does. Most systems in daily use carry transparency duties at most, which apply from 2 August 2026. Which of your systems land where is settled in an AI Readiness Assessment, and for the larger part of the portfolio the answer is usually reassuring.

Under the EU AI Act the duties follow the legal entity that puts the system into use, not the group. If the AI decisions arrive from a headquarters outside the Nordics, the responsibility still lands on the entity that deploys the system. More is yours to decide than the group deck admits: the workflows, your own data, the local legal sequence and the order you adopt in. We have written that out on the Nordic units page.

The method is the same across all nine: assessment, direction, build, adoption, handover. What differs is where we start and how much regulatory work is needed. In financial services and life sciences the weight sits early, on inventory and classification. In manufacturing and consumer goods it sits on getting pilots into daily use. Ampliro is independent of technology and vendors in every case, with no partner programmes.

Start with what you actually run.

One conversation settles which duties apply to your organisation, which do not, and what a first step costs. If the honest answer is that little applies to you, that is what you will hear.