PERSPECTIVE8 min

The Missing Middle: Why EU AI Act Compliance Skips Most of the Economy

The EU AI Act's obligations follow the risk tier, not the size of the company — but the tooling built to serve them followed the budget. This is why mid-sized European businesses fall through the gap, what the Act actually concedes to SMEs, and what closing it takes.

V
Veritome Team
28.07.2026

Key Takeaways

  • 1The AI Act indexes obligations to risk tier and operator role — not to turnover or headcount. A high-risk system in a 40-person company carries the Article 8–15 requirement set in full.
  • 2The Act's actual SME concessions are narrow: simplified technical documentation (Art. 11(1) via Annex IV), priority sandbox access (Art. 62), proportionate fines (Art. 99(6)), and fee-scaled conformity assessment (Art. 43).
  • 3None of those concessions reduce the number of obligations. They reduce the paperwork burden of proving a few of them.
  • 4Enterprise GRC platforms price from roughly €14k–€46k per year and assume a dedicated risk team; consultancies quote €15k–€80k per system per year. Both assume a buyer the middle does not have.
  • 5The spreadsheet alternative fails not at tracking but at derivation, evidence freshness and proof — it cannot tell you which obligations apply, and it cannot show an auditor that a document is the one you signed.
  • 6Closing the gap is a software problem, not a discount problem: encode the Act once as a rules engine, and the marginal cost of serving a 40-person company approaches the cost of serving a 4,000-person one.

The Act Scales by Risk. The Market Scaled by Budget.

Regulation (EU) 2024/1689 is unusual among EU digital laws in how little it cares about the size of the company in front of it. The GDPR has a record-keeping carve-out under Article 30(5) for organisations under 250 employees. The NIS2 Directive scopes itself explicitly by size class. The AI Act does neither. Its obligations attach to what a system does and what role you play in putting it on the market — provider, deployer, importer, distributor — and to which of the four risk tiers it lands in.

The consequence is easy to state and uncomfortable to absorb. A 40-person recruitment company deploying an AI CV-screening tool is operating an Annex III high-risk system. So is a multinational bank doing credit scoring. The obligation sets are not identical — deployers owe Article 26 duties where providers owe the full Article 8–15 requirement set — but they are indexed to the same variables, and neither variable is headcount.

  • Risk tier + operator role determine your obligations — not turnover, not headcount
  • Annex III high-risk triggers the Art. 8–15 requirement set for providers
  • Deployers of high-risk systems owe Art. 26, plus Art. 27 FRIA where they are a public body or provide public services
  • Art. 4 AI literacy binds every provider and deployer, in every tier, already in force since 2 February 2025

The market that grew up to serve this regulation made the opposite assumption. It scaled by budget. At the top, the enterprise GRC platforms — priced from roughly €14,000 to €46,000 per year — assume a customer with a dedicated risk function, an internal owner for the tool, and the appetite to run an implementation project. Beneath them sit the consultancies, quoting somewhere between €15,000 and €80,000 per system per year, with a delivery model that produces a document rather than a capability. Below that: nothing. A spreadsheet, a PDF of the Act, and someone's evenings.

What the Act Actually Concedes to SMEs

It would be wrong to say the Act ignores smaller operators. It does make specific accommodations — they are simply narrower than the phrase 'SME provisions' suggests, and it is worth being precise about them, because a great deal of vendor copy is not.

  • Simplified technical documentation. Article 11(1) allows SMEs, including start-ups, to provide the Annex IV technical documentation in a simplified form, on a form to be specified by the Commission.
  • Priority sandbox access. Article 62 obliges Member States to give SMEs and start-ups priority access to AI regulatory sandboxes, free of charge where they meet the eligibility conditions.
  • Proportionate penalties. Article 99(6) provides that for SMEs and start-ups the administrative fine is the lower of the percentage and the fixed amount, rather than the higher — the inverse of the default rule in Article 99(3)–(5).
  • Fee-scaled conformity assessment. Article 43 requires Member States to set notified-body fees proportionately, taking the interests and needs of SMEs into account.
  • Guidance and support. Article 62 also directs Member States towards awareness-raising, communication channels and dedicated guidance for smaller operators.

Read that list again and notice what is missing. Every item reduces the cost or the paperwork of demonstrating compliance. Not one of them reduces the number of obligations you hold. Simplified Annex IV documentation is still Annex IV documentation. A proportionate fine is still a fine. Priority sandbox access is a route to supervised experimentation, not an exemption. The substance is unchanged; only the friction moves.

  • The SME provisions lower the cost of PROVING obligations — they do not remove obligations
  • Art. 99(6) makes the fine the LOWER of the two figures for SMEs — still up to €7.5M or 1% for the smallest band
  • Simplified Annex IV is a simplified FORM of the same technical file

Why the Spreadsheet Fails — and It Is Not Where You Think

Most mid-sized organisations start with a spreadsheet, and the usual criticism of that choice is that spreadsheets do not scale. That is true and largely beside the point. A well-kept spreadsheet tracks a hundred rows perfectly well. It fails on three things the Act specifically requires, and none of them is volume.

It cannot derive.

The hard question is not 'have I done obligation 14?' but 'which obligations do I hold at all?' That answer is a function of role, risk tier, Annex III area and a set of behavioural facts about the system — does it interact with people, does it generate content, does it infer emotion. Getting from those inputs to an obligation set is a derivation over the legal text, and a spreadsheet has nowhere to put the derivation. So somebody does it by hand, once, and the answer silently rots the moment the system or the interpretation changes.

It cannot tell you when proof goes stale.

Compliance evidence has a shelf life. A certificate lapses. A signed policy predates the model you actually shipped. A screenshot is from a version of the interface that no longer exists. Under Article 17 the quality-management system is a continuing obligation, and under Article 72 post-market monitoring is explicitly ongoing — so a cell that reads 'done' with no renewal date attached is recording a moment, not a state.

It cannot prove anything to a third party.

The output an authority or a customer's procurement team wants is not a status report. It is a document, and an answer to the question 'is this the document you signed, unaltered?' A spreadsheet cell cannot answer that. Neither can a PDF in a shared drive with a filename ending in _final_v3.

The Middle Is Not a Discount Segment

The instinctive commercial answer to an underserved middle is a cheaper tier of the enterprise product. That answer has been tried in every adjacent category and it rarely works, because the enterprise product's cost is not mostly in the software. It is in the implementation, the configuration, the customer-success motion and the assumption that a named internal owner will drive adoption. Halve the licence and you have halved the smallest line on the invoice.

The middle needs something structurally different: a product where the expertise is encoded once, in software, rather than delivered repeatedly, by people. If the Act's decision procedure — role × risk tier × domain, plus conditional logic over the system's behaviour — exists as a rules engine rather than as a consultant's judgement, then the marginal cost of serving a 40-person company approaches the marginal cost of serving a 4,000-person one. That is the only economics under which the middle gets served at all.

  • Encode the derivation once — the same inputs must always produce the same obligation set
  • Carry the article reference through to the screen, so every answer is checkable against the text
  • Give evidence a renewal cadence, so 'compliant' describes now rather than a Tuesday in March
  • Seal the outputs, so a third party can verify a document without trusting the sender

It also changes what the software is allowed to be uncertain about. A consultant can hedge; a rules engine cannot. If the obligation set is derived deterministically, the same system profile gives the same answer in November that it gave in March, and a decision you have to defend eighteen months later is reproducible rather than remembered. That property is worth more to a small compliance function than any amount of dashboard.

What This Means Before August 2026

The dates are not distant. Article 5's prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025. GPAI model obligations and the penalty regime followed on 2 August 2025. Article 50 transparency duties have applied since 2 August 2026. Regulation (EU) 2026/1744 deferred Annex III high-risk systems to 2 December 2027 and high-risk safety components of regulated products to 2 August 2028.

If you are in the middle, three things are worth doing now, and none of them requires a budget decision. Inventory the AI systems you actually operate, including the ones procured by a department rather than by IT — shadow AI is where classification surprises live. Establish role and risk tier per system, in writing, with the article reference attached, because that single determination drives everything downstream. And satisfy Article 4, which binds you already, applies whatever your risk tier, and is the cheapest obligation in the entire Act to discharge.

The middle is not a market segment that got overlooked by accident. It is the part of the European economy the Act binds and the compliance industry could not profitably reach. Closing that gap is a software problem — and, for once, that is good news, because software problems get cheaper.

Frequently Asked Questions

Does the EU AI Act have an exemption for small companies?

No. The Act indexes obligations to the risk tier of the system and your operator role, not to headcount or turnover. There is no equivalent of the GDPR's Article 30(5) record-keeping carve-out for organisations under 250 employees. What the Act does provide is a set of accommodations that reduce the burden of demonstrating compliance: simplified Annex IV technical documentation under Article 11(1), priority and free sandbox access under Article 62, proportionate fines under Article 99(6), and fee-scaling for notified-body conformity assessment under Article 43.

How are fines calculated for an SME?

Article 99 sets the general rule as the HIGHER of a fixed amount or a percentage of worldwide annual turnover — up to €35M or 7% for Article 5 prohibited practices, €15M or 3% for most other operator obligations, and €7.5M or 1% for supplying incorrect information to authorities. Article 99(6) inverts this for SMEs and start-ups: the fine is the LOWER of the two figures. That is a meaningful reduction for a small company, but it is not immunity.

We are a 40-person company deploying a third-party AI hiring tool. What do we owe?

AI systems intended for recruitment or selection of natural persons fall under Annex III, so you are a deployer of a high-risk system. Your duties sit primarily in Article 26: use the system in accordance with the provider's instructions for use, assign human oversight to people with the competence and authority to exercise it, ensure input data is relevant and sufficiently representative where you control it, monitor operation and inform the provider of risks or serious incidents, keep automatically generated logs for at least six months, and inform affected workers before putting the system into use. Article 4 AI literacy applies to you as well. If you are a public body or provide public services you additionally owe an Article 27 fundamental rights impact assessment.

Can we just use a spreadsheet?

For tracking, a spreadsheet is adequate at small volumes. It fails on three things the Act requires: it cannot derive which obligations apply to a given system from role, risk tier, domain and behavioural facts; it cannot track when a piece of evidence has gone stale, which matters because Article 17 quality management and Article 72 post-market monitoring are continuing obligations; and it cannot demonstrate to a third party that a document is the unaltered one you signed. The last point is the one that shows up in an audit.

When do the high-risk obligations actually apply?

The Act entered into force on 1 August 2024 and applies in stages under Article 113. Prohibited practices (Article 5) and AI literacy (Article 4) have applied since 2 February 2025. GPAI model obligations, the governance bodies and the penalty regime applied from 2 August 2025. Article 50 transparency duties have applied since 2 August 2026, while Regulation (EU) 2026/1744 deferred Annex III high-risk systems to 2 December 2027. High-risk safety components of regulated products under Article 6(1) follow on 2 August 2027.

What is the single most useful thing to do first?

Establish role and risk tier for every AI system you operate, in writing, with the article reference attached. Everything downstream — which obligations apply, which documents you must produce, whether you need a conformity assessment and EU database registration — is derived from that determination. Do it before you buy tooling, because it also tells you how much tooling you actually need.

EU AI Act updates, in your inbox

Deadlines, enforcement news and practical compliance guidance. One confirmation email first, then only the updates — one-click unsubscribe in every one.