The Law Does Not Scale Down
The EU AI Act is role- and risk-based, not size-based. If your recruitment tool, credit model, or triage system is high-risk under Annex III, you owe a risk-management system (Article 9), data governance (Article 10), technical documentation (Article 11 and Annex IV), human oversight (Article 14), a conformity assessment (Article 43), and registration (Article 49) — whether you employ 20 people or 20,000.
The penalties do not scale down either. Prohibited-practice breaches reach €35 million or 7% of global annual turnover; high-risk non-compliance reaches €15 million or 3%. A percentage-of-turnover fine is, by design, proportionate to the company — but the obligations that trigger it are fixed. A scale-up carries the full compliance burden on a fraction of the resources.
- •Same obligations: Articles 9, 10, 11, 14, 43, 49 apply regardless of headcount for in-scope high-risk systems.
- •Same fine ceilings: up to €35M / 7% (prohibited), €15M / 3% (high-risk), €7.5M / 1% (incorrect information).
- •Different budget: an SME rarely has an in-house AI-governance function, a GRC platform, or a professional-services line item.
A Barbelled Market
Walk the market and you find two clusters with a canyon between them. At one end: free tools — checklists, fine calculators, downloadable spreadsheets, a PDF template. Useful for orientation, but they capture a moment in time and leave the actual work — the evidence, the audit trail, the continuous monitoring — to you. When a regulator asks for proof, a spreadsheet is not a defence.
At the other end: enterprise GRC suites. Genuinely capable, genuinely deep — and sold through a sales cycle, priced in the tens of thousands per year, and often requiring a professional-services engagement to configure. They are built for a Fortune 500 legal and risk department that already has a team to run them.
The two ends both fail the middle
- Free tools under-serve: no evidence store, no obligation tracking, no continuous conformity, nothing to hand an auditor.
- Enterprise suites over-serve and over-charge: capabilities and price aimed at organisations with a governance team to operate them.
- Both assume the buyer already knows what they owe — neither classifies your systems or tells you which of the Act's articles actually apply to you.
Where Most of Europe Actually Sits
The overwhelming majority of organisations deploying AI in Europe are SMEs and mid-market companies. They are adopting AI in recruitment, customer service, credit, logistics and healthcare — precisely the Annex III domains the Act treats as high-risk. They carry real exposure, and they are the least equipped to absorb enterprise tooling or a legal department.
The Act's own drafters saw this coming. Article 62 obliges Member States to provide SME and start-up support measures — priority access to regulatory sandboxes, awareness and training, and, crucially, simplified technical documentation via a form the Commission provides. The regulation explicitly frames proportionate, accessible compliance as a policy goal, not a nice-to-have. The tooling market simply has not caught up to that intent.
- •Article 62: Member States must give SMEs and start-ups priority sandbox access, tailored awareness and training, and a communication channel for guidance.
- •Article 11 / Annex IV: SMEs may satisfy technical-documentation duties through a simplified Commission-provided form.
- •The intent is proportionality. The gap is that most software ignores it.
The Middle Is a Different Product, Not a Discount
Closing the gap is not about selling a cheaper enterprise suite. A stripped-down enterprise product is still an enterprise product — it still assumes you know which obligations apply and still expects you to operate it. The missing middle needs a genuinely different design: opinionated where enterprise tools are configurable, guided where they are blank, and priced so a founder can start the same afternoon with no procurement process and no sales call.
The trick is that depth and accessibility are not actually in tension. The depth can live where the user never has to see it — in a compliance engine that knows the Act article by article, maps obligations to your role and risk tier automatically, and generates the audit-ready documentation as a by-product of ordinary work. The simplicity lives in the experience on top. You answer plain-language questions; the engine does the legal reasoning.
What 'enterprise depth at SME price' means in practice
- Classification first: the system tells you whether you are a provider or deployer, and whether each AI system is prohibited, high-risk, limited-risk or minimal — before you spend a euro on the wrong obligations.
- Obligations derived, not looked up: the exact Articles you owe are generated from your role, risk tier and domain — no reading Annex III yourself.
- Evidence as a by-product: documentation, FRIAs, Declarations of Conformity and audit trails are produced as you work, not assembled in a panic before an audit.
- Self-serve pricing: start free, upgrade transparently, no sales cycle — the same reason SaaS displaced enterprise software everywhere else.
Why This Matters Now
The high-risk obligations are arriving, the AI-literacy duty (Article 4) is already in force, and supervisory authorities across the EU — Ireland's among the most active — have made AI Act enforcement a stated priority. The companies most exposed are precisely the ones the market has left in the middle. Proportionate compliance is now a competitive advantage: the scale-up that can prove conformity without a governance department ships faster, raises more easily, and sleeps better.
That is the space Veritome is built for. Enterprise depth in the engine; SME simplicity and price in the product. Not a spreadsheet you outgrow in a week, and not a platform you cannot afford — the option that should have been in the middle all along.