When compliance is built into infrastructure, a 10-person SME can meet EU AI Act standards like a Fortune 500 — without needing a Fortune 500 legal team
Authors/Creators
Description
Abstract
Ten People. One EU AI Act. One Infrastructure-Level Compliance Layer. A More Level Playing Field.
The EU AI Act establishes an important framework for trustworthy AI. A continuing challenge, however, is ensuring that the practical cost of compliance does not fall disproportionately on smaller European companies.
Large organizations can distribute regulatory obligations across dedicated legal, engineering, governance, cybersecurity, and audit teams. For a ten-person company, many of the same obligations may need to be addressed by the founders and engineers who are also responsible for developing and commercializing the product.
This paper examines a conceptual alternative: moving selected recurring compliance functions away from individually engineered application-level processes toward reusable infrastructure-level capabilities.
At a high level, such an approach could allow relevant purpose, jurisdiction, authorization, privacy, accountability, and governance conditions to accompany digital or AI operations in machine-verifiable form. Rather than requiring every SME to independently recreate similar compliance processes for each application, platform, partner, or market, common infrastructure could potentially support more consistent implementation across multiple environments.
The conceptual framework considers privacy-preserving identity, jurisdiction-aware governance, execution-time compliance evaluation, and automatically generated evidence of relevant governance decisions. These concepts are represented broadly through the VI, CJT, and related execution-time governance models.
The proposal is intentionally implementation-neutral. It does not prescribe a particular token structure, cryptographic construction, identity mechanism, validation algorithm, audit-record format, trusted hardware architecture, protocol, or enforcement implementation.
Nor is the framework intended to replace the EU AI Act, GDPR, or other European digital legislation. Its purpose is to explore whether common technical infrastructure could make implementation of existing obligations more scalable and economically accessible.
For SMEs, the potential benefit is straightforward: less repetitive compliance engineering, more predictable implementation effort, easier expansion across platforms and jurisdictions, and more engineering capacity available for product development and innovation.
For Europe, the broader policy question is whether sophisticated compliance infrastructure should remain something primarily affordable to large organizations or whether parts of that capability could eventually become standardized and accessible to companies regardless of size.
Infrastructure-level compliance could therefore contribute to a more level competitive environment without reducing the underlying protections established by European law.
The principle is simple: large organizations can afford compliance as a permanent organizational function; small companies often cannot. Reusable compliance infrastructure offers a research direction for reducing that asymmetry while preserving Europe’s regulatory objectives and supporting innovation.