AI Readiness Assessment.
Fixed scope, fixed price, typically procurable by direct award. Two ways in: you ran a pilot that stalled, or you haven't started. The output is a decision basis your leadership and your lawyers can both stand on.

THE GAP
AI Sweden's mapping of the sector, published in November 2024, found AI initiatives in 263 of Sweden's 290 municipalities, nine in ten, counting everything from a single training session to technology in production. Far fewer are running it in daily operations, and the pattern repeats across agencies and regions: studies, pilots and strategies that never reach the case handler's screen.
The Swedish National Audit Office (Riksrevisionen), in its April 2025 report, examined 1,094 state digitalisation projects run between 2013 and 2024 and found 31 cancelled without result, at a cost of 1.6 billion kronor, with half of all projects exceeding budget or timeline.
The most common failure isn't dramatic. It's an investment that quietly dies in a drawer.
When public organisations name the brakes themselves, the same three recur: legal uncertainty, competence gaps, and a weak negotiating position against vendors. Our model is a direct answer to all three.
Legal uncertainty is met with a calm, verified reading of the rules and a decision basis that keeps the purpose from drifting. The competence gap is met from the leadership team down.
The negotiating position is met with independence: we have no partner programmes and nothing to sell you but the advice, so we sit on your side of the table.
Fixed price, fixed scope, and we carry the overrun. That is our answer to the audit findings.
THE RULES
Public bodies carry stricter duties under the EU AI Act than private ones: registration in the EU database before deployment, information duties toward the individuals affected and toward employee representatives, and a fundamental rights impact assessment, FRIA, before first use of a high-risk system.
The dates and details live on our EU AI Act page. The principle to hold on to is that the duties attach before use, not after.
This is not paperwork for its own sake. In a national agency's model for picking temporary parental benefit cases for fraud investigation, a woman who had made no error was more than 1.7 times as likely to be wrongly flagged as a man who had made none. That is the finding of Svenska Dagbladet and Lighthouse Reports, published in November 2024 from data released by the Swedish Social Insurance Inspectorate (Inspektionen för socialförsäkringen, ISF). Supervision followed, and the system was taken out of service. That is precisely the harm a fundamental rights impact assessment exists to catch, and it happened anyway.
The lesson isn't fear. It's that the assessment has to be done for real, by people who understand both the workflow and the data.
The AI Act is EU law, and each member state names its own supervisory authorities. Sweden has not finished doing so: the Swedish Post and Telecom Authority (Post- och telestyrelsen, PTS) holds an interim mandate as national competent authority until the end of 2026, and a public inquiry has proposed it for the permanent role.
The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) handles AI that processes personal data. Its inspection of a region's AI transcription service, opened in May 2026, rests on data protection law rather than on the AI Act. That is where the pressure lands first.
For high-risk systems you already run, a transitional arrangement exists, but it has an outer limit: a public body must have them in compliance by 2 August 2030 in any case. Read it as planning security, not as a reason to wait. New systems follow the ordinary calendar.
OUR POSITION
Compliance is an operating capability, not a document. Buy a FRIA you cannot operate, and you have bought a binder.
FOUR DELIVERABLES, ALL BOUNDED
Fixed scope, fixed price, typically procurable by direct award. Two ways in: you ran a pilot that stalled, or you haven't started. The output is a decision basis your leadership and your lawyers can both stand on.
Built to production criteria, run until it holds, and transferred to you: code, documentation, evaluation framework, trained owners. When we leave, nothing breaks.
Risk classification, registration readiness, and the impact assessment built as a working process your organisation can run, not a binder. Sold as a head start, never as panic.
Leadership sessions delivered by Ampliro in the management team. Role-specific programmes for staff through AIUC, our education arm. The AI literacy duty starts where accountability sits.
Trusted by teams at
PROOF
Our work in the sector spans an AI pre-study for Arbetsgivarverket, and strategy and training across agencies, municipalities, courts and state-owned companies. The consultant who leads your engagement is the person who delivered those.
PROCUREMENT
Procurement thresholds are set nationally within the EU framework. In Sweden, the assessment is typically scoped to be procurable by direct award (direktupphandling), so you can start without a full tender.
Larger engagements run through framework call-offs or open tenders, and the decision basis we hand over is written to survive a procurement: clear requirements, clear ownership.
Unclear requirements are one of the audit office's most cited failure causes, so we treat requirement quality as part of the deliverable, not an afterthought.
One more thing procurement teams appreciate: the Swedish Agency for Digital Government (Myndigheten för digital förvaltning, DIGG) has warned that vendor partnerships can sit uneasily with procurement law. We have no partner programmes, so that question never arises with us. Fixed price. We carry the overrun.
QUESTIONS
The fundamental rights impact assessment, FRIA, is carried out before a high-risk system is used for the first time and then kept current as the system changes. Article 27 of the EU AI Act binds public bodies and private actors providing public services, and in addition every deployer of creditworthiness assessment or of pricing in life and health insurance. Critical infrastructure under Annex III point 2 is exempt. The duty applies from 2 December 2027. We build the assessment as an operating process with named owners, not a one-off document.
A public body must bring its existing high-risk systems into compliance by 2 August 2030 under Article 111.2 of the EU AI Act, and that deadline is unconditional. The relief attached to leaving a system substantially unchanged applies to other deployers, not to public bodies. New systems follow the ordinary calendar, meaning 2 December 2027 for Annex III and 2 August 2028 for Annex I.
A requirement that data stays inside the EU does not rule out AI for a public body, it rules out certain solutions. Model choice, hosting and architecture are design decisions we make with your requirements as constraints, including EU hosting and on-premise paths where warranted. The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten) is also the authority that has examined AI in Sweden so far, and that supervision rests on data protection law. Sovereignty is a requirement we design for, not an obstacle.
A stalled AI pilot is the most common starting point we see in the public sector, and one of two doors into the AI Readiness Assessment. We examine why it stalled: data, integration, governance or adoption. You get either a scoped path to operation or an honest recommendation to stop. The assessment has fixed scope and a fixed price.
One vendor dependency is not traded for another, because everything we build transfers to you: code, models, documentation and evaluation framework. The documentation is written so that any competent partner can take it forward, including one that is not us. It also carries your own record of compliance, which matters for as long as no harmonised standards under the EU AI Act have been published. No retainer is required.
A smaller municipality or a delimited agency is exactly what the AI Readiness Assessment is built for, where a director-general or a head of digitalisation actually holds the mandate and the decision path is short. Scope is set by your size rather than by a template, and the work is measured in weeks. The multi-year procurement cycles of the largest authorities are a different world, and rarely ours.
The first step is normally procurable by direct award. The AI Readiness Assessment is scoped to fall under the Swedish threshold for a direct award (direktupphandling), so the work can start without a full tender. Larger engagements run through framework call-offs or open tenders, and the decision basis we hand over is written to survive a procurement: clear requirements, clear ownership. We have no partner programmes and we do not resell technology, so the vendor-tie question the Swedish Agency for Digital Government (DIGG) has warned about never arises with us.
INSIGHTS

NIS2 scope in Sweden is settled by six provisions, and the assessment rests on the operator itself. The size threshold moves in both directions, and essential or important answers another question.
Read the analysis
The CLOUD Act follows the provider's control over the data, not the address of the server. What decides the question is not the American statute but which of your own rules is the strictest.
Read the analysis