The Act Scales by Risk. The Market Scaled by Budget.
Regulation (EU) 2024/1689 is unusual among EU digital laws in how little it cares about the size of the company in front of it. The GDPR has a record-keeping carve-out under Article 30(5) for organisations under 250 employees. The NIS2 Directive scopes itself explicitly by size class. The AI Act does neither. Its obligations attach to what a system does and what role you play in putting it on the market — provider, deployer, importer, distributor — and to which of the four risk tiers it lands in.
The consequence is easy to state and uncomfortable to absorb. A 40-person recruitment company deploying an AI CV-screening tool is operating an Annex III high-risk system. So is a multinational bank doing credit scoring. The obligation sets are not identical — deployers owe Article 26 duties where providers owe the full Article 8–15 requirement set — but they are indexed to the same variables, and neither variable is headcount.
- •Risk tier + operator role determine your obligations — not turnover, not headcount
- •Annex III high-risk triggers the Art. 8–15 requirement set for providers
- •Deployers of high-risk systems owe Art. 26, plus Art. 27 FRIA where they are a public body or provide public services
- •Art. 4 AI literacy binds every provider and deployer, in every tier, already in force since 2 February 2025
The market that grew up to serve this regulation made the opposite assumption. It scaled by budget. At the top, the enterprise GRC platforms — priced from roughly €14,000 to €46,000 per year — assume a customer with a dedicated risk function, an internal owner for the tool, and the appetite to run an implementation project. Beneath them sit the consultancies, quoting somewhere between €15,000 and €80,000 per system per year, with a delivery model that produces a document rather than a capability. Below that: nothing. A spreadsheet, a PDF of the Act, and someone's evenings.
What the Act Actually Concedes to SMEs
It would be wrong to say the Act ignores smaller operators. It does make specific accommodations — they are simply narrower than the phrase 'SME provisions' suggests, and it is worth being precise about them, because a great deal of vendor copy is not.
- Simplified technical documentation. Article 11(1) allows SMEs, including start-ups, to provide the Annex IV technical documentation in a simplified form, on a form to be specified by the Commission.
- Priority sandbox access. Article 62 obliges Member States to give SMEs and start-ups priority access to AI regulatory sandboxes, free of charge where they meet the eligibility conditions.
- Proportionate penalties. Article 99(6) provides that for SMEs and start-ups the administrative fine is the lower of the percentage and the fixed amount, rather than the higher — the inverse of the default rule in Article 99(3)–(5).
- Fee-scaled conformity assessment. Article 43 requires Member States to set notified-body fees proportionately, taking the interests and needs of SMEs into account.
- Guidance and support. Article 62 also directs Member States towards awareness-raising, communication channels and dedicated guidance for smaller operators.
Read that list again and notice what is missing. Every item reduces the cost or the paperwork of demonstrating compliance. Not one of them reduces the number of obligations you hold. Simplified Annex IV documentation is still Annex IV documentation. A proportionate fine is still a fine. Priority sandbox access is a route to supervised experimentation, not an exemption. The substance is unchanged; only the friction moves.
- •The SME provisions lower the cost of PROVING obligations — they do not remove obligations
- •Art. 99(6) makes the fine the LOWER of the two figures for SMEs — still up to €7.5M or 1% for the smallest band
- •Simplified Annex IV is a simplified FORM of the same technical file
Why the Spreadsheet Fails — and It Is Not Where You Think
Most mid-sized organisations start with a spreadsheet, and the usual criticism of that choice is that spreadsheets do not scale. That is true and largely beside the point. A well-kept spreadsheet tracks a hundred rows perfectly well. It fails on three things the Act specifically requires, and none of them is volume.
It cannot derive.
The hard question is not 'have I done obligation 14?' but 'which obligations do I hold at all?' That answer is a function of role, risk tier, Annex III area and a set of behavioural facts about the system — does it interact with people, does it generate content, does it infer emotion. Getting from those inputs to an obligation set is a derivation over the legal text, and a spreadsheet has nowhere to put the derivation. So somebody does it by hand, once, and the answer silently rots the moment the system or the interpretation changes.
It cannot tell you when proof goes stale.
Compliance evidence has a shelf life. A certificate lapses. A signed policy predates the model you actually shipped. A screenshot is from a version of the interface that no longer exists. Under Article 17 the quality-management system is a continuing obligation, and under Article 72 post-market monitoring is explicitly ongoing — so a cell that reads 'done' with no renewal date attached is recording a moment, not a state.
It cannot prove anything to a third party.
The output an authority or a customer's procurement team wants is not a status report. It is a document, and an answer to the question 'is this the document you signed, unaltered?' A spreadsheet cell cannot answer that. Neither can a PDF in a shared drive with a filename ending in _final_v3.
The Middle Is Not a Discount Segment
The instinctive commercial answer to an underserved middle is a cheaper tier of the enterprise product. That answer has been tried in every adjacent category and it rarely works, because the enterprise product's cost is not mostly in the software. It is in the implementation, the configuration, the customer-success motion and the assumption that a named internal owner will drive adoption. Halve the licence and you have halved the smallest line on the invoice.
The middle needs something structurally different: a product where the expertise is encoded once, in software, rather than delivered repeatedly, by people. If the Act's decision procedure — role × risk tier × domain, plus conditional logic over the system's behaviour — exists as a rules engine rather than as a consultant's judgement, then the marginal cost of serving a 40-person company approaches the marginal cost of serving a 4,000-person one. That is the only economics under which the middle gets served at all.
- •Encode the derivation once — the same inputs must always produce the same obligation set
- •Carry the article reference through to the screen, so every answer is checkable against the text
- •Give evidence a renewal cadence, so 'compliant' describes now rather than a Tuesday in March
- •Seal the outputs, so a third party can verify a document without trusting the sender
It also changes what the software is allowed to be uncertain about. A consultant can hedge; a rules engine cannot. If the obligation set is derived deterministically, the same system profile gives the same answer in November that it gave in March, and a decision you have to defend eighteen months later is reproducible rather than remembered. That property is worth more to a small compliance function than any amount of dashboard.
What This Means Before August 2026
The dates are not distant. Article 5's prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025. GPAI model obligations and the penalty regime followed on 2 August 2025. Article 50 transparency duties have applied since 2 August 2026. Regulation (EU) 2026/1744 deferred Annex III high-risk systems to 2 December 2027 and high-risk safety components of regulated products to 2 August 2028.
If you are in the middle, three things are worth doing now, and none of them requires a budget decision. Inventory the AI systems you actually operate, including the ones procured by a department rather than by IT — shadow AI is where classification surprises live. Establish role and risk tier per system, in writing, with the article reference attached, because that single determination drives everything downstream. And satisfy Article 4, which binds you already, applies whatever your risk tier, and is the cheapest obligation in the entire Act to discharge.
The middle is not a market segment that got overlooked by accident. It is the part of the European economy the Act binds and the compliance industry could not profitably reach. Closing that gap is a software problem — and, for once, that is good news, because software problems get cheaper.