The GDPR Template: Who the EU AI Act Will Actually Hurt

Photo: Unsplash

EU AI Act

The GDPR Template: Who the EU AI Act Will Actually Hurt

History from 2018 suggests it won't be the companies Brussels is targeting
EU AI ActregulationEuropean startupsGDPRAI policy

On May 25, 2018, the General Data Protection Regulation came into force. Brussels celebrated. Privacy advocates called it a historic victory. And for the first six months, the biggest story wasn’t about Google or Facebook facing consequences — it was about a wave of European startups quietly shutting down their mailing lists, geo-blocking American users, and in several cases, simply closing.

The GDPR’s actual first-year casualty list reads like a European tech obituary column nobody wanted to write. Ad-tech companies headquartered in Hamburg and Stockholm, not Mountain View. Data brokers in Warsaw and Amsterdam, not Menlo Park. A 2019 study by Jian Jia, Ginger Jin, and Lixin Ye estimated that GDPR reduced app development in Europe by roughly 36 percent among affected companies — and the companies most affected were not the ones the regulation was nominally targeting.

This is the GDPR template. Big Tech could afford the compliance apparatus. Everyone else couldn’t.

Eight years later, the EU AI Act is running the same script. Enforcement of the high-risk provisions began in earnest in February 2026, and the pattern emerging from Brussels, Berlin, and Warsaw is both predictable and quietly devastating to anyone paying attention.

What the GDPR Template Actually Looked Like

The theory behind GDPR was elegant. Large data processors would face proportional scrutiny for their data handling. Consent would be meaningful. Citizens would gain control. The reality diverged almost immediately.

Google and Facebook — the companies the regulation was most pointedly aimed at — hired armies of compliance lawyers, built sophisticated consent management platforms, and ultimately faced fines that amounted to minor line items in their quarterly reports. Google’s €50 million French fine in January 2019 represented approximately 0.04 percent of its 2018 revenue. The message to Big Tech was not “change your behavior.” It was “build better paperwork.”

Meanwhile, a startup building a B2B analytics tool in Tallinn with eight employees faced the same legal obligations as a trillion-dollar corporation, with none of the infrastructure to meet them. The legal uncertainty was perhaps worse than the regulation itself. Nobody knew what “legitimate interest” actually meant in practice. Nobody knew how long you could retain data for unspecified future business purposes. The 72-hour breach notification requirement assumed you had a legal team awake at 3 a.m. to receive the notification.

The EU AI Act is structurally different — it focuses on AI system risk rather than data — but the compliance asymmetry is identical. And in the first seven months of active enforcement, that asymmetry is already visible.

Risk Classification and Its Discontents

The Act divides AI systems into four categories: prohibited, high-risk, limited-risk, and minimal-risk. The prohibited tier covers things like social scoring systems and real-time biometric surveillance in public spaces (with exceptions). The high-risk tier is where the compliance burden lives — and it’s where the unintended consequences are breeding.

High-risk AI under the Act includes systems used in hiring, credit scoring, educational assessment, law enforcement, and critical infrastructure management. These systems face requirements for conformity assessments, technical documentation, human oversight mechanisms, transparency to deployers, and registration in an EU database. Legitimate requirements, every one of them. The problem isn’t the requirements. It’s who can actually meet them.

A large bank deploying an AI credit-scoring system has compliance departments, legal teams, vendor management offices, and audit infrastructure. They can absorb the cost. A fintech startup in Lisbon with 15 engineers building a lending platform for underserved small businesses — they cannot. Not without diverting engineering resources that were supposed to be building the product. And not without raising a funding round specifically to pay lawyers.

The Conformity Assessment for high-risk systems isn’t performed by a government body in most categories. Notified Bodies — private third-party certification organizations — handle it. There are currently fewer than 30 EU-designated Notified Bodies with AI competence across the entire bloc. Wait times for assessments are running six to nine months. The cost for a thorough assessment of a complex AI system sits somewhere between €50,000 and €300,000, depending on system complexity and the assessor’s market rate.

Fifty thousand euros is noise for an enterprise software company. It’s a funding event for a seed-stage startup.

The Companies Brussels Is Targeting (And Why They’re Fine)

Let’s be precise about who the EU AI Act is actually aimed at, rhetorically if not legally. The political energy behind the regulation came largely from concerns about foundational AI systems from OpenAI, Google, and Anthropic — systems that could, in theory, influence European society at scale. The GPAI (General Purpose AI) provisions were added partly in response to ChatGPT’s sudden cultural penetration in early 2023.

OpenAI’s compliance posture for the EU market is, as of August 2026, roughly what you’d expect from a company with a dedicated policy team, a Brussels office, and existential incentives to remain in the European market. They have published technical documentation for GPT-4o and o3 meeting the GPAI requirements, registered in the model transparency database, and hired a former European Parliament staffer to run EU regulatory affairs. Anthropic has done the same.

Neither company is particularly happy about the requirements. But neither company is at existential risk from them either.

The companies that face genuine existential pressure are the ones deploying high-risk AI in narrow vertical markets — the HR tech company in Munich that built a resume screening tool, the Polish credit union that uses a machine learning model for fraud detection, the Catalan health startup whose patient triage algorithm may or may not qualify as a “medical device AI system” under the Act’s interaction with the EU Medical Device Regulation.

That last category is particularly vicious. The AI Act and the MDR interact in ways that the regulators themselves have not fully resolved. A diagnostic AI system might face conformity assessment under both frameworks, with no clear delineation of which takes precedence when they conflict. Companies in this space aren’t resisting compliance. They’re genuinely unable to comply because nobody can tell them what compliance looks like.

The Consulting Industrial Complex

One industry is unambiguously thriving in the EU AI Act’s early enforcement period: AI compliance consulting.

The major law firms — Linklaters, Freshfields, CMS, Bird & Bird — all stood up dedicated AI Act practices throughout 2025 and are billing at capacity. The “Big Four” accounting firms have likewise pivoted significant resources. PwC’s EU AI Act compliance assessment practice reportedly generated more than €40 million in revenue in the first half of 2026. KPMG launched a “readiness review” product priced at €25,000 for mid-market companies.

This is not parasitic. The work is real; the legal questions are genuinely complex; the consultants are providing genuine value in the face of genuine uncertainty. But it is worth noting — with some precision — where the money flows. The compliance consulting ecosystem extracts revenue primarily from companies that cannot afford not to use it, not from companies that are the source of societal concern about AI.

The same dynamic shaped GDPR’s first years. Between 2018 and 2020, GDPR compliance consulting was a €1 billion industry across Europe. Data Protection Officers became a new professional category. The regulation created jobs — just mostly compliance jobs, not the technical engineering jobs that European AI needs.

What’s Different This Time

There are reasons to think the EU AI Act won’t simply replay the GDPR script. Some are encouraging; some are not.

The regulation does contain explicit carve-outs and proportionality measures for small and medium enterprises that GDPR conspicuously lacked. SMEs deploying low-risk AI don’t face the same documentation burden as large enterprises deploying high-risk AI. The EU AI Office has published sandbox guidelines that allow startups to test high-risk AI systems under regulatory supervision without full conformity assessment — a provision that approximately 47 companies have used as of August 2026.

But proportionality in writing and proportionality in practice differ. The enforcement powers sit with National Competent Authorities — one per member state — whose resources, interpretive stances, and enforcement cultures vary dramatically. Germany’s Federal AI Office, established in January 2026 with a staff of 120 and a €45 million annual budget, is the best-resourced NCA in the bloc. Portugal’s equivalent has a staff of 12 and shares budget with its data protection authority. Enforcement will not be consistent, and the inconsistency will advantage companies large enough to track and respond to divergent interpretations.

The honest version of this history, written from 2030, may conclude that the EU AI Act meaningfully protected European citizens from harmful AI applications. The GDPR has genuinely improved data practices at scale, even if imperfectly and asymmetrically. These regulations are not failures. They’re just rarely the victories that their architects advertised — and they rarely hurt who they claim to be targeting.

The GDPR template teaches one other lesson that Brussels has not absorbed. The companies best positioned to exploit regulatory compliance as a moat are the same companies the regulation was meant to discipline. Compliance complexity doesn’t humble incumbents. It installs them. The EU AI Act may end up being the most expensive thing that ever happened to a fintech founder in Vilnius who just wanted to build a better loan product.

That founder, by the way, probably isn’t a bad actor. They’re just not Google. And under the GDPR template, that’s the only characteristic that matters.

The Numbers Nobody Is Publishing

One of the persistent frustrations in assessing the EU AI Act’s early impact is the absence of systematic tracking of its business casualties.

When companies quietly restructure products to avoid high-risk classification, no database captures this. When a startup quietly closes its EU operations rather than navigate certification, it rarely issues a press release attributing the decision to the AI Act. When a VC declines to fund an EU healthcare AI company because the compliance pathway is too uncertain, the funding decline shows up in aggregate statistics without a specific cause attached.

The GDPR’s first-year casualties were similarly undercounted. The 2019 Jia, Jin, and Ye study on GDPR’s impact on app development was published a year after the regulation took effect, with data that required significant methodological effort to collect. The AI Act’s equivalent scholarship will take years to accumulate.

What we have instead is anecdote, survey data, and inference from investment trends. These are imperfect proxies. But they’re consistent enough to suggest that the template is running: large incumbents adapting; compliance industry thriving; early-stage innovation in high-risk verticals slowing. Whether the magnitude is comparable to GDPR’s first-year effects is unknown.

The EU AI Act’s proponents would argue the comparison is unfair — the regulation is designed for higher-stakes applications than GDPR, and the compliance overhead for those applications is proportionate to the harm they could cause. The argument has merit in principle. What it doesn’t resolve is the empirical question of whether the companies being slowed are the harmful ones or the beneficial ones. That answer requires data that doesn’t yet exist, collected over a timeline that extends past anyone’s current analysis horizon. The GDPR template suggests the answer will be uncomfortable. It usually is.

Get the next live webinar in your inbox

One email a month: the upcoming live event + free recording access for subscribers. No spam, unsubscribe anytime.