STRATEGY7 min

The Missing Middle: Enterprise Depth, SME Price

Why EU AI Act compliance software forces SMEs to choose between under-powered free tools and unaffordable enterprise GRC platforms — and what a purpose-built middle option looks like.

V
Veritome Team
20.07.2026

Key Takeaways

  • 1The EU AI Act applies the same obligations — and the same fines of up to €35M or 7% of global turnover — to a 20-person scale-up as to a multinational. The law does not scale down; only the budget does.
  • 2The compliance-software market is barbelled: free checklists and fine calculators at one end, six-figure enterprise GRC platforms (bought through a sales cycle and a professional-services contract) at the other.
  • 3Most European AI adopters are SMEs and mid-market companies that fall in the gap — too exposed for a spreadsheet, too small for OneTrust-class tooling.
  • 4The Act itself anticipates this: Article 62 mandates SME support measures and simplified technical documentation, acknowledging that proportionate compliance is a policy goal, not a luxury.
  • 5The missing middle is not a cheaper enterprise suite — it is a different product: opinionated, obligation-engine-driven, and priced so a founder can start today without a procurement process.
  • 6Depth and accessibility are not a trade-off. The depth can live in the engine; the simplicity lives in the experience.

The Law Does Not Scale Down

The EU AI Act is role- and risk-based, not size-based. If your recruitment tool, credit model, or triage system is high-risk under Annex III, you owe a risk-management system (Article 9), data governance (Article 10), technical documentation (Article 11 and Annex IV), human oversight (Article 14), a conformity assessment (Article 43), and registration (Article 49) — whether you employ 20 people or 20,000.

The penalties do not scale down either. Prohibited-practice breaches reach €35 million or 7% of global annual turnover; high-risk non-compliance reaches €15 million or 3%. A percentage-of-turnover fine is, by design, proportionate to the company — but the obligations that trigger it are fixed. A scale-up carries the full compliance burden on a fraction of the resources.

  • Same obligations: Articles 9, 10, 11, 14, 43, 49 apply regardless of headcount for in-scope high-risk systems.
  • Same fine ceilings: up to €35M / 7% (prohibited), €15M / 3% (high-risk), €7.5M / 1% (incorrect information).
  • Different budget: an SME rarely has an in-house AI-governance function, a GRC platform, or a professional-services line item.

A Barbelled Market

Walk the market and you find two clusters with a canyon between them. At one end: free tools — checklists, fine calculators, downloadable spreadsheets, a PDF template. Useful for orientation, but they capture a moment in time and leave the actual work — the evidence, the audit trail, the continuous monitoring — to you. When a regulator asks for proof, a spreadsheet is not a defence.

At the other end: enterprise GRC suites. Genuinely capable, genuinely deep — and sold through a sales cycle, priced in the tens of thousands per year, and often requiring a professional-services engagement to configure. They are built for a Fortune 500 legal and risk department that already has a team to run them.

The two ends both fail the middle

  • Free tools under-serve: no evidence store, no obligation tracking, no continuous conformity, nothing to hand an auditor.
  • Enterprise suites over-serve and over-charge: capabilities and price aimed at organisations with a governance team to operate them.
  • Both assume the buyer already knows what they owe — neither classifies your systems or tells you which of the Act's articles actually apply to you.

Where Most of Europe Actually Sits

The overwhelming majority of organisations deploying AI in Europe are SMEs and mid-market companies. They are adopting AI in recruitment, customer service, credit, logistics and healthcare — precisely the Annex III domains the Act treats as high-risk. They carry real exposure, and they are the least equipped to absorb enterprise tooling or a legal department.

The Act's own drafters saw this coming. Article 62 obliges Member States to provide SME and start-up support measures — priority access to regulatory sandboxes, awareness and training, and, crucially, simplified technical documentation via a form the Commission provides. The regulation explicitly frames proportionate, accessible compliance as a policy goal, not a nice-to-have. The tooling market simply has not caught up to that intent.

  • Article 62: Member States must give SMEs and start-ups priority sandbox access, tailored awareness and training, and a communication channel for guidance.
  • Article 11 / Annex IV: SMEs may satisfy technical-documentation duties through a simplified Commission-provided form.
  • The intent is proportionality. The gap is that most software ignores it.

The Middle Is a Different Product, Not a Discount

Closing the gap is not about selling a cheaper enterprise suite. A stripped-down enterprise product is still an enterprise product — it still assumes you know which obligations apply and still expects you to operate it. The missing middle needs a genuinely different design: opinionated where enterprise tools are configurable, guided where they are blank, and priced so a founder can start the same afternoon with no procurement process and no sales call.

The trick is that depth and accessibility are not actually in tension. The depth can live where the user never has to see it — in a compliance engine that knows the Act article by article, maps obligations to your role and risk tier automatically, and generates the audit-ready documentation as a by-product of ordinary work. The simplicity lives in the experience on top. You answer plain-language questions; the engine does the legal reasoning.

What 'enterprise depth at SME price' means in practice

  • Classification first: the system tells you whether you are a provider or deployer, and whether each AI system is prohibited, high-risk, limited-risk or minimal — before you spend a euro on the wrong obligations.
  • Obligations derived, not looked up: the exact Articles you owe are generated from your role, risk tier and domain — no reading Annex III yourself.
  • Evidence as a by-product: documentation, FRIAs, Declarations of Conformity and audit trails are produced as you work, not assembled in a panic before an audit.
  • Self-serve pricing: start free, upgrade transparently, no sales cycle — the same reason SaaS displaced enterprise software everywhere else.

Why This Matters Now

The high-risk obligations are arriving, the AI-literacy duty (Article 4) is already in force, and supervisory authorities across the EU — Ireland's among the most active — have made AI Act enforcement a stated priority. The companies most exposed are precisely the ones the market has left in the middle. Proportionate compliance is now a competitive advantage: the scale-up that can prove conformity without a governance department ships faster, raises more easily, and sleeps better.

That is the space Veritome is built for. Enterprise depth in the engine; SME simplicity and price in the product. Not a spreadsheet you outgrow in a week, and not a platform you cannot afford — the option that should have been in the middle all along.

Frequently Asked Questions

Does the EU AI Act apply to small businesses?

Yes. The Act is based on the role you play (provider, deployer, importer, distributor) and the risk tier of the AI system, not on company size. An SME deploying a high-risk AI system carries the same core obligations — risk management, data governance, technical documentation, human oversight, conformity assessment, registration — as a large enterprise. Fines are a percentage of turnover, so they scale with the company, but the underlying duties do not scale down.

What is the 'missing middle' in AI compliance software?

It is the gap between free tools (checklists, fine calculators, spreadsheets) that leave you exposed and unable to prove compliance, and enterprise GRC suites that cost tens of thousands a year and assume you have a governance team to run them. Most European AI adopters — SMEs and mid-market companies — fall in between: too exposed for a spreadsheet, too small for enterprise tooling.

Does the EU AI Act offer anything specifically for SMEs?

Yes. Article 62 requires Member States to provide SME and start-up support: priority access to regulatory sandboxes, tailored awareness and training, and a channel for guidance. Article 11 and Annex IV allow SMEs to meet technical-documentation duties through a simplified form the Commission provides. The Act explicitly treats proportionate, accessible compliance as a goal.

Can compliance software be both deep and simple?

Yes — the two are only in tension if the depth is exposed to the user. When the legal depth lives in a compliance engine that classifies systems and derives obligations automatically, the person using the product answers plain-language questions while the engine does the reasoning. Audit-ready documentation is generated as a by-product. That is how enterprise-grade rigour reaches an SME-grade experience and price.

How much does EU AI Act compliance cost for a scale-up?

It varies with how many AI systems you run and their risk tiers, but the biggest hidden cost is usually the delay and legal risk of doing it manually — Irish firms report multi-week product delays from manual documentation. Purpose-built middle-market tooling is designed to be self-serve and start free, so the entry cost is time, not a procurement cycle, and the ongoing cost is a transparent subscription rather than an enterprise contract.

Why is proportionate compliance a competitive advantage?

Because the obligations and the enforcement are arriving now, and the companies most exposed are the ones the market under-serves. A scale-up that can demonstrate conformity without standing up a governance department ships faster, passes investor and customer due diligence more easily, and avoids the fine exposure — turning a regulatory burden into a proof point.

EU AI Act updates, in your inbox

Deadlines, enforcement news and practical compliance guidance. One confirmation email first, then only the updates — one-click unsubscribe in every one.